NetBSD/pkgsrc sTtcpbCdoc CHANGES-2026

   doc: Updated net/inetutils to 2.8nb1
VersionDeltaFile
1.5293+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc JjTMmMInet/inetutils Makefile distinfo, net/inetutils/patches patch-talkd_talkd.c patch-talkd_intalkd.h

   inetutils: fix CVE-2026-19720 using upstream patch.

   Bump PKGREVISION.
VersionDeltaFile
1.1+223-0net/inetutils/patches/patch-talkd_announce.c
1.1+24-0net/inetutils/patches/patch-talkd_intalkd.h
1.1+23-0net/inetutils/patches/patch-talkd_talkd.c
1.10+4-1net/inetutils/distinfo
1.14+2-1net/inetutils/Makefile
+276-25 files

NetBSD/pkgsrc c04sM5Xdoc CHANGES-2026

   doc: Updated textproc/py-libxml2 to 2.15.3
VersionDeltaFile
1.5292+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc TBJUE7tdoc CHANGES-2026

   doc: Updated textproc/libxml2 to 2.15.3
VersionDeltaFile
1.5291+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc Fx7SIkLtextproc/libxml2 Makefile.common distinfo

   libxml2: update to 2.15.3.

   From Showta Ishizaki in PR 60591.

   v2.15.3: Apr 15 2026

   ### Security

   - parser: Pass userData to SAX text callbacks in xmlParseReference (type-confusion)
   - entities: copy children in xmlCopyEntity
   - c14n: Fix Type confusion in xmlC14NProcessAttrsAxis
   - python: Do not decref string after adding to the list (double-free / use-after-free)
   - c14n: Reuse tmp_str, xmlStrcat reallocates *cur (double-free)

   ### Improvements

   - schemas: Fix relative schemaLocation resolution in XSI assembly in streaming mode
   - xmlreader: propagate reader resource loaders to validator parsers
   - python: Make python bindings python2 compatible

    [44 lines not shown]
VersionDeltaFile
1.158+4-4textproc/libxml2/distinfo
1.32+2-2textproc/libxml2/Makefile.common
+6-62 files

NetBSD/pkgsrc V0eRphzeditors/emacs30-nox11 version.mk

   emacs30-nox11: fix typo

   Reported by Showta Ishizaki in PR 60590.
VersionDeltaFile
1.2+2-2editors/emacs30-nox11/version.mk
+2-21 files

NetBSD/pkgsrc zjnSpG1doc CHANGES-2026

   doc: Updated www/gitea to 1.27.2
VersionDeltaFile
1.5290+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc JJ1aNyOwww/gitea Makefile go-modules.mk

   www/gitea: update to 1.27.2

   Changes in 1.27.2:

   * SECURITY
     - Fix: update collaborator access mode and httpsign
     - Refactor: external render
     - Fix(actions): resolve pull_request_target reusable workflows at the
       base commit
     - Refactor: markup render
     - Fix(deps): update dependency mermaid to v11.16.1
     - Fix(auth): set WebAuthn user verification per request
     - Fix: render highlight language
   * ENHANCEMENTS
     - enhance: add missing npm package metadata properties
   *  BUGFIXES
     - fix(actions): keep github.event.inputs as strings for
       workflow_dispatch
     - fix(actions): let a rerun of selected jobs read the previous

    [419 lines not shown]
VersionDeltaFile
1.45+523-559www/gitea/distinfo
1.22+320-302www/gitea/PLIST
1.13+173-185www/gitea/go-modules.mk
1.140+2-2www/gitea/Makefile
+1,018-1,0484 files

NetBSD/pkgsrc 9eUpHs8doc pkg-vulnerabilities

   pkg-vulnerabilities: Remove libxml2 entry for CVE-2025-12863

   The CVE was rejected on 2025-11-20, see
   <https://gitlab.gnome.org/GNOME/libxml2/-/issues/1012#note_2608283>.

   Via PR pkg/60591 from Showta Ishizaki, thanks!
VersionDeltaFile
1.779+1-2doc/pkg-vulnerabilities
+1-21 files

NetBSD/pkgsrc YO0HWWedoc pkg-vulnerabilities

   pkg-vulnerabilities: Update libxml2 entries fixed in 2.15.2

   Via PR pkg/60591 from Showta Ishizaki, thanks!
VersionDeltaFile
1.778+6-6doc/pkg-vulnerabilities
+6-61 files

NetBSD/pkgsrc YPcHFjQdoc pkg-vulnerabilities

   pkg-vulnerabilities: CVE-2025-69720 was fixed in ncurses-6.6

   According upstream NEWS it was fixed in 20251213 and 6.6 was released
   on 20251230.

   Reported via PR pkg/60589 from Showta Ishizaki, thanks!
VersionDeltaFile
1.777+2-2doc/pkg-vulnerabilities
+2-21 files

NetBSD/pkgsrc 0Gve365doc CHANGES-2026

   doc: Updated security/ca-certificates to 20260601
VersionDeltaFile
1.5289+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc M31G9d2security/ca-certificates Makefile distinfo

   ca-certificates: Update to 20260601

   ca-certificates (20260601) unstable; urgency=medium

     * Remove ca-certificates-local example (closes: #988912, #1127101).
     * Update Mozilla certificate authority bundle to version 2.86
       The following certificate authority was added (+):
       + e-Szigno TLS Root CA 2023
       The following certificate authorities were removed (-):
       - QuoVadis Root CA 2
       - QuoVadis Root CA 3
       - DigiCert Assured ID Root CA
       - DigiCert Global Root CA
       - DigiCert High Assurance EV Root CA
       - SwissSign Gold CA - G2
       - SecureTrust CA
       - Secure Global CA
       - COMODO Certification Authority
       - Certigna

    [18 lines not shown]
VersionDeltaFile
1.10+3-26security/ca-certificates/PLIST
1.15+4-4security/ca-certificates/distinfo
1.18+2-2security/ca-certificates/Makefile
+9-323 files

NetBSD/pkgsrc Oj42lcydoc CHANGES-2026

   doc: Added net/rrsync version 3.5.0
VersionDeltaFile
1.5288+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc MfXcyZQnet Makefile, net/rrsync PLIST distinfo

   Add net/rrsync
VersionDeltaFile
1.1+40-0net/rrsync/Makefile
1.1+6-0net/rrsync/DESCR
1.1+5-0net/rrsync/distinfo
1.1640+2-1net/Makefile
1.1+3-0net/rrsync/PLIST
+56-15 files

NetBSD/pkgsrc 5jTrTbXdoc CHANGES-2026

   doc: Added textproc/py-braceexpand version 0.1.7
VersionDeltaFile
1.5287+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc Ly008VQtextproc Makefile, textproc/py-braceexpand distinfo DESCR

   Add textproc/py-braceexpand
VersionDeltaFile
1.1+18-0textproc/py-braceexpand/Makefile
1.1+11-0textproc/py-braceexpand/PLIST
1.1+7-0textproc/py-braceexpand/DESCR
1.1+5-0textproc/py-braceexpand/distinfo
1.1599+2-1textproc/Makefile
+43-15 files

NetBSD/pkgsrc DucpDp4doc TODO CHANGES-2026

   doc: Updated net/croc to 11.1.0
VersionDeltaFile
1.27748+1-2doc/TODO
1.5286+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc pEGS1q7net/croc PLIST Makefile

   croc: Update to 11.1.0

   What's Changed
   fix: --store rendering by @schollz in #1233
   fix unbounded stored-transfer lock state by @abhinavgulisetty in #1238
   feat: allow sending to multiple users Fixes #1130 by @schollz in #1239
VersionDeltaFile
1.3+193-187net/croc/distinfo
1.3+63-61net/croc/go-modules.mk
1.33+5-5net/croc/Makefile
1.2+2-1net/croc/PLIST
+263-2544 files

NetBSD/pkgsrc 2Zj4Hgsdoc TODO

   doc/TODO: + croc-11.0.3, samba4-4.24.6.
VersionDeltaFile
1.27747+3-1doc/TODO
+3-11 files

NetBSD/pkgsrc DPs068Adoc CHANGES-2026

   doc: Updated emulators/PC6001VX to 4.4.0
VersionDeltaFile
1.5285+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 25pVjk7emulators/PC6001VX options.mk distinfo, emulators/PC6001VX/patches patch-src_console.cpp patch-CMakeLists.txt

   PC6001VX: update to 4.4.0

   pkgsrc changes:

   - update definitions for cmake per upstream changes
   - make NOJOYSTIC, NOAVI, NOMONITOR, and DELAY_TIMER_MS_DEFAULT values
     configurable in CMakefile.txt
   - switch to using ffmpeg8 to sync version with qt6-qtmultimedia
   - remove unnecessary qt6-qt5compat that should have be removed since 4.3.0
   - remove unnecessary obsolete definitions
   - remove a patch fixed in upstream

   Upstream changes:
    https://eighttails.seesaa.net/article/521347022.html
    https://github.com/eighttails/PC6001VX/blob/v4.4.0/README.adoc#%E6%9B%B4%E6%96%B0%E5%B1%A5%E6%AD%B4

   4.4.0 2026/08/15

   PC6001VX 4.4.0 release

    [7 lines not shown]
VersionDeltaFile
1.1+139-0emulators/PC6001VX/patches/patch-CMakeLists.txt
1.126+8-12emulators/PC6001VX/Makefile
1.7+5-5emulators/PC6001VX/options.mk
1.55+5-5emulators/PC6001VX/distinfo
1.2+1-1emulators/PC6001VX/patches/patch-src_console.cpp
+158-235 files

NetBSD/pkgsrc w5bAFDMdoc CHANGES-2026

   doc: Updated www/chromium to 151.0.7922.137
VersionDeltaFile
1.5284+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc mXGWk6Swww/chromium Makefile distinfo

   chromium: update to 151.0.7922.137

   * 151.0.7922.137
   This update includes 5 security fixes. Please see the Chrome Security Page for more information.

   [$500][535000102] High CVE-2026-19556: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-15
   [N/A][534867485] High CVE-2026-19557: Use after free in TabStrip. Reported by Google on 2026-07-14
   [N/A][536676756] High CVE-2026-19558: Use after free in Extensions. Reported by @bean5oup on 2026-07-20
   [N/A][540100588] High CVE-2026-19559: Use after free in HTML. Reported by Google on 2026-07-28
   [N/A][540482895] High CVE-2026-19560: Use after free in Blink. Reported by WinD39 - Huynh Dinh Vu on 2026-07-30
VersionDeltaFile
1.55+9-9www/chromium/distinfo
1.73+2-2www/chromium/Makefile
+11-112 files

NetBSD/pkgsrc NlF4TGzdevel/guile-slib PLIST Makefile, devel/guile22-slib Makefile

   guile-slib: Convert to Makefile.common

   Override PKGNAME to be guile-slib, instead of the guile20-slib that it
   ought to be, to avoid dealing with changing it for now.

   Works as well as the old package does, which is:
VersionDeltaFile
1.60+7-43devel/guile-slib/Makefile
1.18+3-3devel/guile-slib/PLIST
1.4+3-2devel/guile30-slib/Makefile.common
1.13+1-3devel/guile22-slib/Makefile
+14-514 files

NetBSD/pkgsrc ipaLXKLdevel/guile-slib Makefile, devel/guile22-slib PLIST Makefile

   devel/guile22-slib: Convert to Makefile.common

   Replace the guile22-slib Makefile with an include of Makefile.common.

   guile30-slib: Restore load path env variable, but point it to destdir,
   so that the catalog can find slib when the symlink exists in the
   being-built destdir but does not exist in the system, because the
   package is not yet installed.
VersionDeltaFile
1.12+5-35devel/guile22-slib/Makefile
1.59+1-7devel/guile-slib/Makefile
1.3+6-2devel/guile30-slib/Makefile.common
1.4+3-3devel/guile22-slib/PLIST
+15-474 files

NetBSD/pkgsrc 0GpUAvsdevel/guile30-slib PLIST Makefile.common

   devel/guile30-slib: Rototill installation comments

   Read and explain the contradictory instructions from slib and guile,
   and follow guile's instructions.  Explain to future self everything
   I'm likely to forget, as guided by what I forgot since I last read
   guile-slib several years ago.

   Slightly clean up by dropping an environment variable during catalgo
   build that is not actually used.

   Hoist guile's site dir to variable.
VersionDeltaFile
1.2+68-21devel/guile30-slib/Makefile.common
1.2+3-3devel/guile30-slib/PLIST
+71-242 files

NetBSD/pkgsrc QmD86Iadoc pkg-vulnerabilities

   pkg-vulnerabilities: Update pattern for CVE-2022-0711

   Fixed in 2.6.0, via <https://bugzilla.redhat.com/show_bug.cgi?id=2053666>.
VersionDeltaFile
1.776+2-2doc/pkg-vulnerabilities
+2-21 files

NetBSD/pkgsrc 9pBO2i7doc CHANGES-2026

   doc: Updated databases/lmdb to 1.0.1nb1
VersionDeltaFile
1.5283+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc i9jeiyvdatabases/lmdb Makefile distinfo, databases/lmdb/patches patch-libraries_liblmdb_Makefile

   lmdb: restore usage of LDFLAGS from pkgsrc

   Bump PKGREVISION.
VersionDeltaFile
1.11+12-12databases/lmdb/patches/patch-libraries_liblmdb_Makefile
1.43+2-2databases/lmdb/distinfo
1.30+2-1databases/lmdb/Makefile
+16-153 files