mk: stop passing relro linker flags to compiler
The relro flags are added to LDFLAGS, and that should be sufficient.
Packages not honoring LDFLAGS need to be fixed anyway, and clang
complains about the flags on the compiler command line.
www/chromium: update to 150.0.7871.128
* 150.0.7871.128
This update includes 7 security fixes. Please see the Chrome Security Page for more information.
[N/A][516987782] Critical CVE-2026-15899: Use after free in CameraCapture. Reported by Google on 2026-05-27
[N/A][523750584] Critical CVE-2026-15900: Use after free in GPU. Reported by Google on 2026-06-14
[N/A][533446300] Critical CVE-2026-15901: Use after free in Network. Reported by Google on 2026-07-10
[N/A][522436154] High CVE-2026-15902: Use after free in Cast. Reported by Google on 2026-06-10
[TBD][531503216] High CVE-2026-15903: Out of bounds read and write in V8. Reported by OpenAI Codex Security (amyb) on 2026-07-06
[N/A][532925350] High CVE-2026-15904: Use after free in Ozone. Reported by Google on 2026-07-09
[N/A][532970574] High CVE-2026-15905: Use after free in Aura. Reported by Google on 2026-07-09
* 150.0.7871.124
This update includes 15 security fixes. Please see the Chrome Security Page for more information.
[N/A][517100492] Critical CVE-2026-15764: Use after free in Ozone. Reported by Google on 2026-05-27
[N/A][518007484] Critical CVE-2026-15765: Use after free in Ozone. Reported by Google on 2026-05-29
[N/A][514010477] High CVE-2026-15766: Uninitialized Use in Skia. Reported by Google on 2026-05-17
[43 lines not shown]
textproc/typst: update to 0.15.1
Library
Text
- Updated New Computer Modern fonts to version 8.1.1, fixing a bug where the regular weight of the math
font was still using the old calligraphic letterforms that were supposed to live in stylistic set 6
Math
- Fixed a regression where alignment points did not work correctly when placed within lr / matched delimiters
- Fixed a regression where op elements could be vertically misaligned
Layout
- Fixed a bug where gaps could appear in multi-page lists with number-align / marker-align set to an
alignment with a vertical component
[15 lines not shown]
sysutils/dua-cli: update to 2.38.1
This release fixes a long-standing bug where NO_COLOR=1 would make all styling disapear, including
the selection indicator itself. Now it's usable, finally.
Bug Fixes
- only strip colors when NO_COLOR is enabled
shells/oh-my-posh: update to 29.33.0
v29.33.0
Features
- shell: support vimode segment in fish (302c3df), closes #5438
- spotify: detect ads on macOS and Linux (36a96bb)
v29.32.0
Features
- config: add generic language segment type (e98db08)
emulators/jgenesis: update to 0.13.1
New Features
- (Genesis) Added a new enabled-by-default option to automatically force 6-button controllers into 3-button mode when running a game that has known compatibility issues with 6-button controllers, such as Golden Axe II (#682)
- (PC Engine) Added support for the Turbo Tap (i.e. multiple emulated gamepads, up to 5)
- Holding the rewind and fast forward hotkeys together now rewinds at increased speed, based on the configured fast forward multiplier (#674)
- Added a right click cut/copy/paste menu to the Cheats text edit box (#678)
Improvements
- (Genesis) When the "remove sprite-per-scanline limits" setting is enabled with a game that has known compatibility issues with it (read: Sonic 1), the emulator now shows a message at game boot noting that this may cause glitches
- I did this instead of forcing it off because it does reduce sprite flickering during gameplay; it just also causes a major glitch on the title screen, unfortunately
- (32X) SH-2 invalid memory address accesses are no longer logged to console by default; on Windows, this fixes potential slowdown in games that frequently access invalid addresses, e.g. Pitfall: The Mayan Adventure
- When mapping gamepad analog triggers to inputs, it should no longer be possible to accidentally map "trigger released" to anything (#674)
Fixes
- (Genesis) Fixed the 68000 DIVU/DIVS instructions setting the Z and N flags incorrectly when the division overflows; this fixes Blood Shot sometimes allowing you to see part of a wall that's supposed to be behind you and then freezing (#679)
- (GBA) Improved accuracy of IWRAM open bus emulation, based on the openbuster test ROM (#676)
devel/serie: update to 0.8.1
What's Changed
- Update GitHub Actions workflows by @lusingander in #157
- Add stash user command variable by @lusingander in #160
- Preserve search state on refresh by @lusingander in #161
py-coverage: updated to 7.15.2
7.15.2 — 2026-07-15
- Fix: one of the performance improvements in 7.15.1 (pull 2215) dramatically
increased memory use during reporting for large projects. Now we use a
different approach that is both faster and slimmer than 7.15.0. Fixes `issue
2229`_.
py-peewee: updated to 4.2.6
4.2.6
* A missed outer join is now cached as an absent relation instead of being
written through the foreign-key descriptor. The fk id on the source
instance keeps the column's value (previously it was overwritten with
`None`), and accessing the attribute on a non-null fk returns `None`
instead of raising `DoesNotExist`.
4.2.5
* Fix anonymous sub-select keeping a stale `id()`-based hash after `clone()`.
4.2.4
* Fix derived table joined in an expression subquery losing its FROM alias.
[6 lines not shown]
py-pebble: updated to 5.2.1
5.2.1
Fixes:
- Issue 160: fix resource leak on pools created within child
processes.
- Issue 163: fix regression leading to deadlock when a pool's
worker is terminated while owning the channel locks.
taglib: updated to 2.3.1
TagLib 2.3.1 (Jul 20, 2026)
* Matroska: Fix crash when seek head is invalid or missing.
* Matroska: Check element length, support unknown size length, skip invalid
elements.
* Matroska: Allow Chapters without a ChapterUID.
* Fix data length indicator check for compressed ID3v2 frames.
* MP4: Use `LongLong` instead of `UInt` for `cnID` atom to support large
catalog IDs.
* MP4: Fix destructor and assignment operator for `MP4::Chapter`.
* MP4: Let `hasiXMLData()`, `hasBEXTData()` track on-disk state rather than
in-memory state.
* MP4: Support NI STEM atoms with 64-bit length.
* MP4: Enlarge limit number of MP4 atoms at top level.
* MP4: Avoid excessive sample allocations with invalid `stsc` for QT chapters.
* XM: Correctly save XM tracker files with samples.
gurk: update to 0.10.0.
## [0.10.0] - 2026-07-19
This release significantly improves startup time and memory usage: messages
are no longer loaded into memory all at once at startup, but fetched in a
window around the current selection directly from the database. As a result,
the app starts fast regardless of the size of the message history.
### 🚀 Features
- Add XDG, env var, and CLI support for config/data paths (#523)
- Replace text with emoji while typing (#549)
- Support tab to autocomplete emoji (#558)
### 🐛 Bug Fixes
- Assure data dir exists (#547)
- Don't clear unread messages when navigating channels (#534)
[15 lines not shown]
rumdl: update to 0.2.37.
Added
reflow: add atomic_spans configuration and refactor inline wrapping (#742) (aeabec1)
Changed
BREAKING: the MD013 emphasis-spans option is renamed to atomic-spans (default true), with inverted meaning (emphasis-spans = true is now atomic-spans = false). Configs setting the old key should migrate; it is no longer recognized
Fixed
reflow: keep code spans atomic when wrapping would collapse whitespace (d43618b)
Note updates to lang/gcc14 and lang/gcc14-libs:
lang/gcc14 to 14.3.0nb2
lang/gcc14-libs to 14.3.0nb3
Primarily build fix for NetBSD/powerpc 11.* with active PAX_MPROTECT.
lang/gcc14: Add changes to make this build on NetBSD/macppc 11.0_RC6.
This pulls over changes to config/rs6000/ and gcc/config.gcc from
our in-tree gcc instance of gcc14, while preserving existing Homebrew-
related changes to gcc/config.gcc.
The most important fix is that on NetBSD/powerpc, -msecure-plt is enabled
by default, so that resulting executables can be run with PAX_MPROTECT
active. Otherwise, we end up with executables with sections which have
both "write" and "execute" turned on, which PAX_MPROTECT rejects. Ref.
the entries for .plt and .got sections in "readelf -a".
Fixes PR#60439.
Bump PKGREVISION for both gcc14 and gcc14-libs, to adhere to rules in comments,
even though this *should* be a single-arch build fix, since I had to merge
the patch to gcc/config.gcc.
xload: update to 1.2.1.
Alan Coopersmith (8):
Improve man page formatting
man page: fix warnings from `mandoc -T lint`
gitlab CI: drop the ci-fairy check-mr job
Strip trailing whitespace from source files
meson: Add option to build with meson
meson: include libintl.h when checking for gettext()
meson: include headers when checking for other functions
xload 1.2.1