slony1: limit allowed pgsql version
Officially supports 15, but builds up to 17;
using types from pgsql breaks with 18, so only allow <=17.
While here, fix build on -current
nuclei: Update to 3.11.1
pkgsrc changes:
- Drop MAINTAINERship
Changes:
v3.11.1
New Features
* Improving lua script with args and values
Bug Fixes
* feat(lib): reuse metadata cache across thread-safe scans
Maintenance
* Bump dependencies
v3.11.0
Breaking Change
* Signed templates required for JavaScript protocol
Starting with v3.11.0, custom templates that use the `javascript:`
protocol must be digitally signed before Nuclei will load or execute
[43 lines not shown]
dnsx: Update to 1.3.1
pkgsrc changes:
- Drop MAINTAINERship
Changes:
v1.3.1
* Bumped version to 1.3.1
v1.3.0
New Features
- Added automatic wildcard DNS detection with `-auto-wildcard`, supporting multiple registrable roots and A/AAAA-based filtering
- Added customizable output templates with `-output-template` (`-ot`), including fields such as `{{host}}`, `{{a}}`, `{{aaaa}}`, `{{ip}}`, and `{{query-time}}`
- Added query timing through the `query-time` response field
- Added inline and comma-separated host input support
Bug Fixes
- Fixed JSON and raw output filtering by the requested record type
- Fixed DNS parsing to process only the answer section and ignore unrelated AUTHORITY or ADDITIONAL records
- Improved wildcard-domain validation and normalization, including support for values such as `*.Example.COM.`
[8 lines not shown]
sops: Update to 3.13.3
Changes:
3.13.3
Improvements:
* CLI help improvement
* Dependency updates
Bugfixes:
* Fix a bug introduced in 3.13.2 that computes a wrong MAC during decryption
for sequences (YAML lists) that contain a comment
* Fix ``completion`` subcommands so that they do not have an empty line before
the shebang
3.13.2
Improvements:
* Dependency updates
* Fix typos in documentation
Bugfixes:
* When using `--user` in the `sops exec-file` and `sops exec-env` subcommands,
[92 lines not shown]
gallery-dl: Update to 1.32.16
pkgsrc changes:
- Switch HOMEPAGE to Codeberg, upstream migrated their repository there
Changes:
Too many changes to mention, sorry, please see:
- <https://codeberg.org/mikf/gallery-dl/releases> (for 1.32.16..1.31.10)
- <https://github.com/mikf/gallery-dl/releases> (for older ones)
But there are extractor additions, improvements, fixes and some
extractor removals.
There is also a new server mode that can be invoked via
`gallery-dl --server' that accepts URLs via IPC.
direnv: Update to 2.38.2
Changes:
2.38.2
======
* fix(zsh): load the .envrc in a new shell and on cd from shell functions again
* fix(fish): stop completions from breaking after the first prompt
* fix(pixi): require_allowed for the manifest file as well
rlwrap: Update to 0.48
Changes:
0.48
----
- rlwrap would mess up history when compiled with readline-8.3
- allow full user control of word-breakers with
--break-chars='precisely:...'
- simplify handling of --prompt-colour, enable general (ANSI)
color codes for e.g. 256-color terminals
- --filter 'filter_commandline $with <shell_matachars' would
not find filters in $RLWRAP_FILTERDIR
- rlwrap in vi mode would not always honour show-mode-in-prompt
- make 'pipeline' filter find filters in $RLWRAP_FILTERDIR; add
-i option to 'logger' and 'logger.py'
- add example filter null2.py (to show how to make argparse print
filter help with 'rlwrap -z filter')
socat: Update to 1.8.1.3
Changes:
1.8.1.3:
Testing:
The new SOCKS5_OVERFL test for CVE-2026-56123 failed on platforms with
non-bash default shell (false positive).
1.8.1.2:
Security:
Socat security advisory 10
CVE-2026-56123
There was a possible heap overflow in the socks5 client code. It could
be triggered by connecting to a malicious socks5 server that expected
this connection and had knowledge about details of the client binary
code.
Only builds with C signed char (vs.unsigned char) are affected.
Thanks to Tristan Madani for finding and reporting this issue, and for
[22 lines not shown]