460,858 commits found in 79 milliseconds
Pullup ticket #7207 - requested by taca
www/nginx: Security fix
Revisions pulled up:
- www/nginx/Makefile 1.195
- www/nginx/distinfo 1.144
---
Module Name: pkgsrc
Committed By: kim
Date: Tue Jul 21 03:42:05 UTC 2026
Modified Files:
pkgsrc/www/nginx: Makefile distinfo
Log Message:
nginx: Update to 1.30.4
Changes with nginx 1.30.4 15 Jul 2026
[17 lines not shown ] Pullup ticket #7206 - requested by taca
lang/ruby33: Security fix
Revisions pulled up:
- lang/ruby/rubyversion.mk 1.327
- lang/ruby33/Makefile 1.13
- lang/ruby33/PLIST 1.11
- lang/ruby33/distinfo 1.19
- lang/ruby33/patches/patch-lib_erb.rb deleted
- lang/ruby33/patches/patch-lib_erb_version.rb deleted
- lang/ruby33/patches/patch-test_erb_test__erb.rb deleted
---
Module Name: pkgsrc
Committed By: taca
Date: Sat Jul 18 14:09:03 UTC 2026
Modified Files:
pkgsrc/lang/ruby: rubyversion.mk
[27 lines not shown ] Pullup ticket #7204 - requested by taca
textproc/p5-YAML-Syck: Security fix
Revisions pulled up:
- textproc/p5-YAML-Syck/Makefile 1.43
- textproc/p5-YAML-Syck/distinfo 1.24
---
Module Name: pkgsrc
Committed By: wiz
Date: Fri Jul 17 06:14:44 UTC 2026
Modified Files:
pkgsrc/textproc/p5-YAML-Syck: Makefile distinfo
Log Message:
p5-YAML-Syck: update to 1.47.
1.47 Jul 13 2026
[48 lines not shown ] Pullup ticket #7202 - requested by morr
editors/vim-share: Bug fix
Revisions pulled up:
- editors/vim-share/distinfo 1.243
- editors/vim-share/version.mk 1.179
---
Module Name: pkgsrc
Committed By: morr
Date: Fri Jul 31 13:26:12 UTC 2026
Modified Files:
pkgsrc/editors/vim-share: distinfo version.mk
Log Message:
Update vim to version 9.2.0859
Changes:
[14 lines not shown ] dnscontrol: Update to 4.45.0 (go-modules.mk typo fix)
Pullup ticket #7200 - requested by taca
textproc/p5-XML-Bare: Security fix
Revisions pulled up:
- textproc/p5-XML-Bare/Makefile 1.22
- textproc/p5-XML-Bare/distinfo 1.8
---
Module Name: pkgsrc
Committed By: wiz
Date: Thu Jul 16 17:46:07 UTC 2026
Modified Files:
pkgsrc/textproc/p5-XML-Bare: Makefile distinfo
Log Message:
p5-XML-Bare: fix CVE-2026-13401
using upstream patch
[2 lines not shown ] NetBSD /pkgsrc Mk2le7c — devel/userspace-rcu distinfo Makefile, devel/userspace-rcu/patches patch-src_urcu-call-rcu-impl.h patch-src_urcu-call-rcu-impl.h Pullup ticket #7199 - requested by taca
devel/usrespace-rcu: Bug fix
Revisions pulled up:
- devel/userspace-rcu/Makefile 1.20
- devel/userspace-rcu/distinfo 1.16
- devel/userspace-rcu/patches/patch-src_urcu-call-rcu-impl.h 1.1
---
Module Name: pkgsrc
Committed By: he
Date: Tue Jul 14 17:59:22 UTC 2026
Modified Files:
pkgsrc/devel/userspace-rcu: Makefile distinfo
Added Files:
pkgsrc/devel/userspace-rcu/patches: patch-src_urcu-call-rcu-impl.h
Log Message:
[6 lines not shown ] doc: Updated net/dnscontrol to 4.45.0
dnscontrol: Update to 4.45.0
Changelog
Provider-specific changes:
• fdc38db: AUTODNS: support two factor authentication via TOTP (#4626) (@leon-th)
• 278b963: NAMECHEAP: just skip the failing tests (#4635) (@willpower232)
CI/CD:
• f8f1cae: Build(deps): Bump brace-expansion from 5.0.7 to 5.0.9 (#4629) (@dependabot[bot])
Dependencies:
• 9d334eb: CHORE: Update dependencies (#4628) (@TomOnTime)
Other changes and improvements:
• c097900: BUG: SPF flattening no longer drops the last term of an include with no "all" (#4630) (@shuvamk)
• 637fbaf: BUG: preview no longer errors when a zone will be created by push (#4612) (@lopster568)
• c15de40: Prep release (#4643) (@TomOnTime)
• 96f64d3: Release v4.45.0 (#4644) (@TomOnTime)
lang/rexx-regina: Replace one more interpreter
doc: Add update of lang/rexx-regina to 3.9.6
doc: Updated lang/rexx-regina to 3.9.7
lang/rexx-regina: Update to 3.6.7
* My previous commit updates this to 3.9.6 silently.
Include changes for 3.9.6 here.
Changelog:
3.9.7:
* Bugs Fixed:
- #580 Missing files in SVN trunk (target Windows)
- #587 https://regina-rexx.sourceforge.io/ Sourceforge links mostly broken
- #595 Unexpected NUL bytes from changestr()
- #596 stream(filename,"C","OPEN WRITE REPLACE") fails, but "CREATE" works
- #598 Implicit command doesn't recognize arguments
- #600 Erroneous syntax error 37
- #602 Error "System resources exhausted" on Haiku
- #606 regina.dll reports WIN8 for Windows 11 systems
- #607 Visual C++ 4.0 build is broken
- #609 CENTER regression
- #610 CALL X(SIGL) passes **updated** SIGL as ARG(1)
[35 lines not shown ] lang/rexx-regina: Honor LDFLAGS
lang/rexx-imc: Fix build with GCC 14 and honor LDFLAGS
Updated lang/nodejs*
nodejs22: updated to 22.23.2
22.23.2 'Jod' (LTS)
Notable Changes
(CVE-2026-56846 ) http2: retain header memory in session accounting (Matteo Collina) – High
(CVE-2026-56848 ) http2: defer rst stream while in scope (Matteo Collina) – High
(CVE-2026-58043 ) permission: avoid granting radix split nodes (RafaelGSS) – High
(CVE-2026-56850 ) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
(CVE-2026-58040 ) https: bind identity checks to session reuse (Matteo Collina) – Medium
(CVE-2026-58042 ) dns: handle large resolveAny address replies (RafaelGSS) – Medium
(CVE-2026-58045 ) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
(CVE-2026-56847 ) permission: enforce fs write permission for trace events (RafaelGSS) – Low
(CVE-2026-58039 ) permission: check final report output path (RafaelGSS) – Low
(CVE-2026-58044 ) http: reject requests exceeding max header count (Matteo Collina) – Low
deps: update llhttp to 9.4.3 (Paolo Insogna)
deps: update undici to 6.28.0 (Node.js GitHub Bot)
doc: Updated www/osticket to 1.18.4
www/osticket -- update to v1.18.4
Upstream Changelog:
osTicket v1.18.4
Security
security: Latest Patches 06/2026 (52c366f, 5afdf54, c54a6ac,
1e39bf1, feccb6a, 6eb6b98, 078516e, 98abb05, e52e010, fd96bba,
7bbd8ab, ba6217a, 580e1c8, b535782, 5963797, d590a97, eaebe01,
b4cc092, d457c14, 5600f94, 5ff9795, 119cefe, b4ede88, 2a0c388,
6558b33)
XXX pull-up candidate
nodejs24: updated to 24.18.1
24.18.1 'Krypton' (LTS)
Notable Changes
(CVE-2026-56846 ) http2: retain header memory in session accounting (Matteo Collina) – High
(CVE-2026-56848 ) http2: defer rst stream while in scope (Matteo Collina) – High
(CVE-2026-58043 ) permission: avoid granting radix split nodes (RafaelGSS) – High
(CVE-2026-56850 ) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
(CVE-2026-58040 ) https: bind identity checks to session reuse (Matteo Collina) – Medium
(CVE-2026-58041 ) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
(CVE-2026-58042 ) dns: handle large resolveAny address replies (RafaelGSS) – Medium
(CVE-2026-58045 ) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
(CVE-2026-56847 ) permission: enforce fs write permission for trace events (RafaelGSS) – Low
(CVE-2026-58039 ) permission: check final report output path (RafaelGSS) – Low
(CVE-2026-58044 ) http: reject requests exceeding max header count (Matteo Collina) – Low
deps: update llhttp to 9.4.3 (Paolo Insogna)
deps: update undici to 7.29.0 (Node.js GitHub Bot)
nodejs: updated to 26.5.1
26.5.1 (Current)
Notable Changes
(CVE-2026-56848 ) http2: defer rst stream while in scope (Matteo Collina) – High
(CVE-2026-58043 ) permission: avoid granting radix split nodes (RafaelGSS) – High
(CVE-2026-56850 ) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
(CVE-2026-58040 ) https: bind identity checks to session reuse (Matteo Collina) – Medium
(CVE-2026-58041 ) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
(CVE-2026-58042 ) dns: handle large resolveAny address replies (RafaelGSS) – Medium
(CVE-2026-58045 ) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
(CVE-2026-56847 ) permission: enforce fs write permission for trace events (RafaelGSS) – Low
(CVE-2026-58039 ) permission: check final report output path (RafaelGSS) – Low
(CVE-2026-58044 ) http: reject requests exceeding max header count (Matteo Collina) – Low
deps: update llhttp to 9.4.3 (Paolo Insogna)
deps: update undici to 8.9.0 (Node.js GitHub Bot)
Updated devel/glib2*
glib2: updated to 2.88.3
Overview of changes in GLib 2.88.3, 2026-07-29
* Fix potential miscompilation with GCC 17 with `G_GNUC_CONST` on `get_type()`
functions
* Bugs fixed:
- G_GNUC_CONST vs get_type comes home to roost (Sam James)
- (CVE-2026-15588 ) Security report: GDBusServer pre-authentication DoS
via unbounded SASL line buffering (Philip Withnall)
- !5225 Backport !5223 “Drop G_GNUC_CONST for *_get_type” to glib-2-88
- !5241 Backport !5240 “gdbusauth: Limit length of lines read from client” to
glib-2-88
- !5242 Backport !5238 “gpoll: Correctly zero-out heap-allocated fd_sets on
macOS” to glib-2-88
- !5243 gdbusauth: Unmark a new string as translatable
- !5259 Backport !5248, !5249: several Meson/gcc fixes to glib-2-88
Updated www/nghttp2[-tools], devel/cmake[-gui]
cmake[-gui]: updated to 4.4.2
4.4.2
This version made no changes to documented features or interfaces. Some
implementation updates were made to support ecosystem changes and/or fix
regressions.
nghttp2[-tools]: updated to 1.70.0
1.70.0
Require C++23
Adopt Designated initializers part1
Adopt Designated initializers part2
Adopt Designated initializers part3
tests: Make const values static const
src: Rewrite util::split_str and its variants
src: Adopt std::string::resize_and_overwrite
src: Pass std::chrono::{time_point,duration} by value
Bump mruby to 4.0.0
src: Fix warning "space between quotes and suffix is deprecated in C++23"
lib, tests: Use C-style comment
src: Avoid std::chrono::high_resolution_clock
src: Add noexcept to user-defined literals
src: Replace std::optional with std::expected
src/util: Adopt std::expected for error handling
[110 lines not shown ] www/drupal11: allow PHP 8.5
No functional change.
* mediawiki 1.46 supports from PHP 8.3 to 8.5:
<https://www.drupal.org/docs/getting-started/system-requirements/php-requirements>.
* php/json.mk is required when a package supports prior to PHP 8.0 and
require php-json pacakge.
www/mediawiki: allow PHP 8.5
No functional change.
* mediawiki 1.46 supports from PHP 8.3 to 8.5:
<https://www.mediawiki.org/wiki/Compatibility>
* php/json.mk is required when a package supports prior to PHP 8.0 and
require php-json pacakge.
NetBSD /pkgsrc 1ZKOPOR — cross/ppc-morphos-gcc Makefile, cross/ppc-morphos-gcc/files const-baserel.diff cross/ppc-morphos-gcc: Updated const-baserel.diff
- Fix inconsistent categorization for section
- Never reference rodata via r13
Updated archivers/libarchive, devel/catch2