NetBSD/pkgsrc UNWNOsudoc CHANGES-2026

   Updated www/freenginx-devel to 1.31.4
VersionDeltaFile
1.5780+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc j44x5pNwww/freenginx-devel Makefile distinfo

   www/freenginx-devel: update from 1.31.3 to 1.31.4

   Sponsored by:        tipi.work

   <ChangeLog>

   *) Bugfix: the "index" directive used old values of non-cacheable
      variables.

   *) Bugfix: variables with side effects might cause incorrect results
      during variable substitution and "no buffer space in script copy"
      alerts.

   *) Bugfix: a segmentation fault might occur in a worker process when
      using regular expression captures with the
      "proxy_cache_background_update" directive or the
      ngx_http_slice_module.

   *) Bugfix: in the ngx_http_perl_module; the bug had appeared in 1.31.3.

    [13 lines not shown]
VersionDeltaFile
1.18+4-4www/freenginx-devel/distinfo
1.21+2-3www/freenginx-devel/Makefile
+6-72 files

NetBSD/pkgsrc phrRpK9doc CHANGES-2026

   Updated www/freenginx to 1.30.1nb3
   Updated www/freenginx-devel to 1.31.3nb2
VersionDeltaFile
1.5779+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc jMXjRunwww/freenginx-devel options.mk Makefile, www/freenginx-devel/patches extra-patch-njs-quickjs

   www/freenginx-devel: update njs 1.0.0 -> 1.0.1

   Bump PKGREVISION.

   Sponsored by:        tipi.work

   <ChangeLog>

   nginx modules:

   *) Security: fixed an access control bypass in js_access when an
      asynchronous request body continuation threw an exception or
      produced an unhandled rejection.  Previously, nginx could continue
      processing the request as though the js_access check had succeeded.
      Thanks to Ta Duc Thien.

   *) Security: fixed a worker process crash when reading
      Response.statusText after an upstream server returned a status
      line with an empty reason phrase.

    [46 lines not shown]
VersionDeltaFile
1.2+4-4www/freenginx-devel/patches/extra-patch-njs-quickjs
1.17+4-4www/freenginx-devel/distinfo
1.10+2-2www/freenginx-devel/options.mk
1.20+2-2www/freenginx-devel/Makefile
+12-124 files

NetBSD/pkgsrc pJRaDdCwww/freenginx options.mk Makefile, www/freenginx/patches extra-patch-njs-quickjs

   www/freenginx: update njs 1.0.0 -> 1.0.1

   Bump PKGREVISION.

   Sponsored by:        tipi.work

   <ChangeLog>

   nginx modules:

   *) Security: fixed an access control bypass in js_access when an
      asynchronous request body continuation threw an exception or
      produced an unhandled rejection.  Previously, nginx could continue
      processing the request as though the js_access check had succeeded.
      Thanks to Ta Duc Thien.

   *) Security: fixed a worker process crash when reading
      Response.statusText after an upstream server returned a status
      line with an empty reason phrase.

    [46 lines not shown]
VersionDeltaFile
1.2+4-4www/freenginx/patches/extra-patch-njs-quickjs
1.10+4-4www/freenginx/distinfo
1.8+2-2www/freenginx/options.mk
1.12+2-2www/freenginx/Makefile
+12-124 files

NetBSD/pkgsrc MwmEU4Gdoc CHANGES-2026

   doc: Updated www/snac to 2.95
VersionDeltaFile
1.5778+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc t7ibBhuwww/snac PLIST Makefile

   snac: update to 2.95. Changes:

   ## 2.95

   Fixed a bug in the notification page that made snac hang forever while
   trying to read abnormally big files.

   Improved support for text-only web browsers: it's now possible to
   configure a set of web browser user-agent strings that will receive
   simpler HTML in the private timeline web UI. Basically, it consists in
   avoiding `details` / `summary` HTML tags as much as possible.

   Added some fixes to media proxy code.

   Fixed EmojiReact code to allow any emoticon defined in `emojis.json`,
   not only those with colon-wrapped identifiers.

   Fixed a bug in notification filtering (paging was sometimes incorrect).


    [181 lines not shown]
VersionDeltaFile
1.41+4-4www/snac/distinfo
1.53+2-3www/snac/Makefile
1.6+1-0www/snac/PLIST
+7-73 files

NetBSD/pkgsrc 1xQE4E8doc CHANGES-2026

   doc: Updated devel/ruby-redmine61 to 6.1.4
VersionDeltaFile
1.5777+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc iuciJJTdevel/ruby-redmine61 PLIST Makefile, devel/ruby-redmine61/patches patch-Gemfile

   develr/ruby-redmine61: update to 6.1.4

   6.1.4 (2026-08-25)

   Security fixes:

   * Defect #44249: API requests can affect a user's session and circumvent
     security policies

   * Defect #44308: Stored XSS in Redmine Textile Formatter via < notextile >
     Tag-Restoration ("Frankenstein tag")

   * Defect #44309: Nested issue-relations endpoints bypass source issue
     visibility

   * Defect #44310: Child project inherit_members updates bypass
     member-management authorization

   * Patch #44371: Filter key parameter from logging
VersionDeltaFile
1.4+5-5devel/ruby-redmine61/distinfo
1.7+4-5devel/ruby-redmine61/Makefile
1.4+4-4devel/ruby-redmine61/patches/patch-Gemfile
1.4+2-1devel/ruby-redmine61/PLIST
+15-154 files

NetBSD/pkgsrc Ti7kMSMdoc CHANGES-2026

   doc: Updated devel/ruby-redmine60 to 6.0.11
VersionDeltaFile
1.5776+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc BumTjg3devel/ruby-redmine60 PLIST distinfo

   develr/ruby-redmine60: update to 6.0.11

   6.0.11 (2026-08-25)

   Security fixes:

   * Defect #44249: API requests can affect a user's session and circumvent
     security policies

   * Defect #44308: Stored XSS in Redmine Textile Formatter via < notextile >
     Tag-Restoration ("Frankenstein tag")

   * Defect #44309: Nested issue-relations endpoints bypass source issue
     visibility

   * Defect #44310: Child project inherit_members updates bypass
     member-management authorization

   * Patch #44371: Filter key parameter from logging
VersionDeltaFile
1.18+5-6devel/ruby-redmine60/Makefile
1.11+4-4devel/ruby-redmine60/distinfo
1.8+2-1devel/ruby-redmine60/PLIST
+11-113 files

NetBSD/pkgsrc e3htgUfdoc CHANGES-2026

   doc: Updated devel/ruby-google-protobuf to 4.36.1
VersionDeltaFile
1.5775+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc Bv3x5dzdevel/ruby-google-protobuf PLIST Makefile

   devel/ruby-google-protobuf: update to 4.36.1

   4.36.0 (2026-08-20)

   * Json/upb: Implement json EnumValueName for upb (0e8519e)

   4.36.1 (2026-08-31)

   No change except auto generated files?
VersionDeltaFile
1.18+4-4devel/ruby-google-protobuf/distinfo
1.23+2-3devel/ruby-google-protobuf/Makefile
1.6+3-1devel/ruby-google-protobuf/PLIST
+9-83 files

NetBSD/pkgsrc kFH8S24doc CHANGES-2026

   doc: Updated devel/ruby-curses to 1.7.0
VersionDeltaFile
1.5774+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc NCF3Ombdevel/ruby-curses Makefile distinfo

   devel/ruby-curses: update to 1.7.0

   1.6.1 (2026-08-24)

   * Merge pull request #153 from shugo/fix/wstat-build-error:
     Do not build demos on mingw

   1.7.0 (2026-08-24)

   * Merge pull request #154 from shugo/use-pdcursesmod:
     Use PDCursesMod instead of forked PDCurses
VersionDeltaFile
1.17+691-245devel/ruby-curses/PLIST
1.42+4-4devel/ruby-curses/distinfo
1.41+2-2devel/ruby-curses/Makefile
+697-2513 files

NetBSD/pkgsrc vbMSgzEdoc CHANGES-2026

   Updated devel/atf, devel/py-pyvcd
VersionDeltaFile
1.5773+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc pC4g1uPdevel/py-pyvcd PLIST Makefile

   py-pyvcd: updated to 0.5.0

   pyvcd-0.5.0 (2026-08-11)

   * Breaking changes:

     * Raise the minimum supported Python version to 3.10
     * Model `Timescale.magnitude` as a plain `int`. `TimescaleMagnitude` remains
       as an `IntEnum` whose members compare equal to their integer values, but
       code such as `timescale.magnitude.value` must become
       `timescale.magnitude`.

   * Reader features, aligning `vcd.reader` with the corpus of real-world VCD
     files collected by the `wellen`__ waveform library:

     * Accept the nonstandard SystemVerilog and VHDL scope and variable types
       emitted by GHDL, nvc, Verilator, QuestaSim, and fst2vcd
     * Accept nine-state std_logic values, e.g. ``bUUUU``, in scalar and vector
       value changes

    [11 lines not shown]
VersionDeltaFile
1.4+4-4devel/py-pyvcd/distinfo
1.6+3-4devel/py-pyvcd/Makefile
1.3+1-2devel/py-pyvcd/PLIST
+8-103 files

NetBSD/pkgsrc UwPLUKadevel/atf PLIST distinfo, devel/atf/patches patch-atf-c_detail_process.c

   atf: updated to 0.24

   0.24

   Major Changes
   * This version of ATF requires C++-20 to build/function.
   * This version of ATF focused heavily on correctness and memory management
     issues discussed in 77. While most of the issues are believed to be resolved,
     some issues may still remain.
   * The `atf::text::duplicate(..)` API and tests were removed.

   Feature Enhancements
   * Issue 105: Widen our process status capabilties

   Docs
   * Issue 107: Clarify the semantics of ATF_{CHECK,REQUIRE}_ERRNO()
   * Issue 124: atf-check.1: Add missing -r flag to synopsis
   * Issue 127: atf-c.3: Fix test case addition in ATF_TP_ADD_TCS synopsis example
VersionDeltaFile
1.1+17-0devel/atf/patches/patch-atf-c_detail_process.c
1.29+5-6devel/atf/Makefile
1.27+5-4devel/atf/distinfo
1.22+2-2devel/atf/PLIST
+29-124 files

NetBSD/pkgsrc Kq5wYE1doc CHANGES-2026

   Updated devel/lutok
VersionDeltaFile
1.5772+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc FJcNUKHdevel/lutok Makefile distinfo

   lutok: updated to 0.6.3

   0.6.3

   This release contains [mostly] developer-workflow related changes. Many of these changes were ported over from
   the [freebsd/atf](https://github.com/freebsd/atf) repository.
VersionDeltaFile
1.7+13-13devel/lutok/PLIST
1.12+4-4devel/lutok/distinfo
1.18+2-2devel/lutok/Makefile
+19-193 files

NetBSD/pkgsrc Mc3HLrBdoc CHANGES-2026

   Updated www/py-django-admin-rangefilter, www/py-django-bootstrap5
VersionDeltaFile
1.5771+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc QSzI0Jkwww/py-django-bootstrap5 Makefile distinfo

   py-django-bootstrap5: updated to 26.3

   26.3 (2026-08-28)

   - Drop support for Django 4.2 (EOL).
   - Add support for Django 6.1.
   - Recognize `month` and `datetime-local` input-type widget subclasses as form-control widgets, enabling addons and floating labels for them
   - **Breaking:** Rewrite `radio_select.html` to forward each option's own attrs (fixing custom attrs like `data-total` from a custom `create_option()` being silently dropped on `RadioSelect`/`CheckboxSelectMultiple`) and to stop leaking `disabled`/`required`/`form`/an always-empty `class=""` onto the non-form-control wrapper `<div>`
   - Fix `server_side_validation` not propagating from `bootstrap_form`/`bootstrap_formset` to field renderers
   - Fix placeholder being set on color and range inputs
   - Fix bugs in `url_replace_param`, jinja2 helpers, and `BaseRenderer.render`; add AGENTS.md
   - Add `label` argument to `bootstrap_field` to override a field's label text without touching the form definition — works with horizontal/floating layout and as the default placeholder
   - Add `label_class` setting so a default label CSS class can be set globally
   - Support `addon_before`/`addon_after` on `Select` widgets, excluding `SelectMultiple` and `RadioSelect`
   - Add `layout` setting to set a default layout for forms and fields
   - Update default Bootstrap to 5.3.8.
   - Add `input_class` argument to `bootstrap_field`
   - Warn when `layout="floating"` is used with `addon_before` or `addon_after`
   - Add a maintenance-round section and release-note ordering convention to MAINTAINING.md.

    [7 lines not shown]
VersionDeltaFile
1.9+4-4www/py-django-bootstrap5/distinfo
1.11+3-3www/py-django-bootstrap5/Makefile
+7-72 files

NetBSD/pkgsrc ZGZPIgOwww/py-django-admin-rangefilter Makefile distinfo

   py-django-admin-rangefilter: updated to 0.15.0

   0.15.0
   - Fix `FieldError: Unsupported lookup 'range__gte'` when rendering the quick select filters with admin facets enabled
VersionDeltaFile
1.39+4-4www/py-django-admin-rangefilter/distinfo
1.41+2-2www/py-django-admin-rangefilter/Makefile
+6-62 files

NetBSD/pkgsrc zDERpDUdoc CHANGES-2026

   Updated devel/py-colorlog, databases/py-sqlalchemy, textproc/py-sphinx-autodoc-typehints
VersionDeltaFile
1.5770+4-1doc/CHANGES-2026
+4-11 files

NetBSD/pkgsrc uE2Qu3mtextproc/py-sphinx-autodoc-typehints Makefile distinfo

   py-sphinx-autodoc-typehints: updated to 3.13.5

   3.13.5
   fix(annotations): expand aliases from unread modules
VersionDeltaFile
1.45+4-4textproc/py-sphinx-autodoc-typehints/distinfo
1.55+2-2textproc/py-sphinx-autodoc-typehints/Makefile
+6-62 files

NetBSD/pkgsrc yzc8ivvdatabases/py-sqlalchemy Makefile distinfo

   py-sqlalchemy: updated to 2.0.52

   2.0.52

   [platform] [bug]

   Python 3.15 support has been added and tested, including minimal changes for full compatibility.

   orm

   [orm] [bug]

   Fixed a result-column misalignment bug in ORM-enabled UPDATE statements where synchronize_session="fetch" is in use, either explicitly or because the statement uses constructs such as CTEs that implicitly select for it. Columns in rows returned by .returning() could be returned under incorrect keys (e.g. row[SomeClass.a] returning the value of a different column), a problem most likely to manifest under concurrent workloads. ORM DELETE statements were not affected.

   [orm] [bug]

   Fixed bug where a failed Session.bulk_insert_mappings(), Session.bulk_update_mappings() or Session.bulk_save_objects() call could leave the Session permanently in a “flushing” state, such as when the transaction could not be begun because a previous flush had left it needing a rollback. Unlike Session.flush(), the bulk methods set the internal flushing flag and began the transaction outside of the try/finally block that resets it, so that neither Session.rollback() nor Session.close() would clear it, and every subsequent flush would raise InvalidRequestError: Session is already flushing. Pull request courtesy Hamody We.

   [orm] [bug]

    [66 lines not shown]
VersionDeltaFile
1.88+4-4databases/py-sqlalchemy/distinfo
1.102+2-2databases/py-sqlalchemy/Makefile
+6-62 files

NetBSD/pkgsrc ASSmHbidoc CHANGES-2026

   doc: Updated databases/ruby-sequel to 5.108.0
VersionDeltaFile
1.5769+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc gOdy5TCdatabases/ruby-sequel Makefile distinfo

   databases/ruby-sequel: update to 5.108.0

   5.108.0 (2026-09-01)

   * Support :allow_migration_number option for TimestampMigrator (jeremyevans)

   * Recognize additional disconnect errors in the mysql and mysql2 adapters
     (sdalu) (#2382)

   * Deprecate Sequel.require (jeremyevans)

   * Add ndims, position, positions, prepend, sample, shuffle, and trim to
     pg_array_ops extension (jeremyevans)

   * Support :select and :select_where options for Postgres
     Dataset#insert_conflict on PostgreSQL 19+ (jeremyevans)

   * Support cast* methods directly on Postgres::PGArray instances
     (jeremyevans)

    [6 lines not shown]
VersionDeltaFile
1.149+4-4databases/ruby-sequel/distinfo
1.150+2-2databases/ruby-sequel/Makefile
+6-62 files

NetBSD/pkgsrc ek1vhJCdevel/py-colorlog Makefile distinfo

   py-colorlog: updated to 6.12.0

   6.12.0
   Fix LevelFormatter KeyError on unlisted or custom log levels
VersionDeltaFile
1.7+4-4devel/py-colorlog/distinfo
1.10+2-2devel/py-colorlog/Makefile
+6-62 files

NetBSD/pkgsrc F83PM8odoc CHANGES-2026

   doc: Updated archivers/ruby-zip to 3.6.0
VersionDeltaFile
1.5768+2-1doc/CHANGES-2026
+2-11 files