git: updated to 2.56.0
Git v2.56 Release Notes
UI, Workflows & Features
Advice shown by "git status" when the local branch is behind or has
diverged from its push branch has been updated to suggest "git pull
<remote> <branch>".
The handling of promisor-remote protocol capability has been updated
to allow the other side to add to the list of promisor remotes via the
promisor.acceptFromServerURL configuration variable.
The ort merge backend has been hardened against corrupt trees by
ensuring it aborts under appropriate error conditions.
[180 lines not shown]
py-cftime: updated to 1.6.6
version 1.6.6 (release tag v1.6.6rel)
* added new CF calendar "tai", which is the same as proleptic_gregorian but is only
valid for dates after 1958-01-01.
misc/rozi: update to 0.0.27
Added
rozi pane reveal --target <ID> scrolls a Scrollable strip to show a pane without moving focus. It also works when the pane's workspace is off screen, and does not change the shared layout. (#78)
rozi split --size COLSxROWS opens a pane at the requested terminal size until a UI displays it. Each dimension must be between 1 and 1000 cells. (#80)
The palette has a Mark UI recording… command while the UI is recording. It has no default key. (#79)
Changed
Sidebar descriptions now leave at least three cells between the label and description. Activity project headers keep the project name and truncate branch names from the start. Worktree rows keep their status and hover action while truncating the branch name first. (#81)
UI recording can hide its REC badge for one recording with rozi record start ui --hide-indicator, or for all UI recordings with [recording] ui_indicator = false. (#79)
Fixed
Copy feedback now includes the final character or cell that was copied. (No PR link was provided.)
When a recording ends on its own, the UI shows a toast with its path. A failed recording reports the error, and a recording that fails to finish after a stop request is labeled as failed. (#79)
Compatibility
[6 lines not shown]
pgpdump: updated to 0.38
0.38 2026/09/25
* Support RFC 9580 (OpenPGP v6): v6 keys, signatures, and one-pass
signatures, X25519/X448/Ed25519/Ed448, PKESK/SKESK v6, SEIPD v2,
AEAD (EAX, OCB, GCM), Argon2 S2K, Padding packet, and new
subpackets. Armor without CRC24 is also accepted.
* Support the post-quantum algorithms of RFC 9980: ML-DSA-65+Ed25519,
ML-DSA-87+Ed448, SLH-DSA-SHAKE-128s/128f/256s, ML-KEM-768+X25519, and
ML-KEM-1024+X448.
* Support the OCB Encrypted Data packet (tag 20) and version 5
Symmetric-Key Encrypted Session Key packets generated by GnuPG
(LibrePGP).
* Support LibrePGP version 5 keys and signatures generated by GnuPG.
* Show the LibrePGP meanings of feature flags 0x02 and 0x04, and the
names of signature subpackets 34, 37, and 38, and the LibrePGP
signature subpackets 40 (Literal Data Meta Hash) and 41 (Trust Alias).
* Use the RFC 9580 names EdDSALegacy (pub 22), Ed25519Legacy, and
[8 lines not shown]
py-fonttools: updated to 4.66.1
4.66.1 (released 2026-09-29)
- [designspaceLib] When splitting a DesignSpace v5 document with ``makeNames=True``
(as ``varLib.build_many`` does), family and style names set explicitly on an
instance now take precedence over the ones computed from the STAT labels, in
all languages, and a PostScript name is no longer made up from the labels for
an instance that has its own style name
- [cmap] Decompiling a format 4 subtable whose ``idRangeOffset`` points outside
``glyphIndexArray`` now raises ``TTLibError``. A negative index used to silently
map the code point to the wrong glyph, and one past the end raised a bare
``AssertionError``
- [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte
row is 32768 or higher, which failed with ``struct.error``
py-atpublic: updated to 8.0.1
8.0.1 (2026-09-21)
* The source distribution ships ``tests/``, ``docs/``, and ``conftest.py`` again. 8.0.0 shipped
only ``src/public/``, so downstream packagers had no way to run the test suite against the
released sdist. (:GL:`30`)
* The ``install`` extra now requires ``atpublic-install >= 1.0.0``. Unbounded it could resolve to
the ``0.1.0a1`` prerelease, since installers fall back to a prerelease for a requirement that has
no final release. ``atpublic-install`` in turn now requires ``atpublic >= 8.0.0``, the first
final release to export ``install()`` from the package itself.
8.0.0 (2026-09-18)
New features
* ``public()`` and ``private()`` now accept a single positional argument, which can be an object
imported from another module, a module or submodule, or a string. The resolved name is added to
[35 lines not shown]
hunspell: updated to 1.7.4
1.7.4
- New --trace option, and Hunspell::set_trace_callback in the library,
to report how each word was accepted or rejected, for dictionary
developers
- Add version macros in hunversion.h, and
Hunspell_get_library_version / Hunspell::get_library_version
- Search $XDG_DATA_HOME/hunspell (default ~/.local/share/hunspell)
and the hunspell folder of each $XDG_DATA_DIRS entry for
dictionaries, and %APPDATA%\hunspell on Windows
- Search LibreOffice's dictionary folders, recursively, on Windows and
POSIX
- New --no-default-personal option to leave out ~/.hunspell_<dict>
- Fix morphological analysis of compound words whose parts carry
affixes
- CHECKCOMPOUNDPATTERN conditions match flags from continuation
classes
- Much faster ICONV handling with a trie (ssvb), and shorter ICONV/REP
[12 lines not shown]
iperf3: updated to 3.22
3.22
Security notes
Thanks to Claude and Ada Logics for finding and reporting two
potential security vulnerabilities. One is a remote
use-after-free in iperf_server_api.c (ANT-2026-E5BA80X9 /
CVE-2026-101283) and the other is a heap buffer overflow in
iperf_auth.c (ANT-2026-FXH14FHV / CVE-2026-101276).
Thanks to Justin Stitt for reporting and fixing a heap-buffer
overflow was fixed in iperf_auth.c.
Thanks to Ravindu Lakmina Munaweera (Github: @Ravi-lk) for
reporting and fixing a DOS infinite-loop (CVE-2026-102253).
Thanks to Dirk Müller for finding and reporting an issue with
[30 lines not shown]
py-slugify: updated to 9.1.2
9.1.2
- Skip the transliteration backend for ASCII-only input under both algorithms, avoiding the ~3 MB text-unidecode table import for the common ASCII case. Output is unchanged, including the frozen legacy differential
py-astroid: updated to 4.3.3
4.3.3
Bug Fixes
Preserve the length of inferred list and tuple concatenations when an element
has multiple possible values. An ambiguous or uninferable element is now
represented as unknown instead of being expanded into multiple sequence items.
Fix TypeError in ClassDef.getitem when __class_getitem__ is uninferable.
Fix AssertionError in NodeNG.root() when inferring Class.__bases__, which previously returned a parentless Tuple.