NetBSD/pkgsrc gaQgOh5 — doc CHANGES-2026

   doc: Updated net/tor to 0.4.9.14
VersionDeltaFile
1.6797+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc v1u8o7v — net/tor Makefile distinfo

   tor: update to 0.4.9.14.

   Changes in version 0.4.9.14 - 2026-10-07
     Another week, another security release. This again contains major bugfixes
     related to high severity issues. The fixes affect all Tor components: relay,
     client, onion service and authority. We strongly recommend upgrading as soon
     as possible.

     o Major bugfixes (conflux, relay, security):
       - Only accept a CONFLUX_LINK cell on a plain OR circuit, and refuse
         to turn a (pending) conflux leg into an introduction or rendezvous
         point. Previously a client could link a rendezvous-point circuit
         into a conflux set and then, with a forged sequence number in the
         LINK cell, make the relay tear the set down from inside the
         rendezvous splice, triggering a fatal assertion in
         assert_circuit_ok(). Also reject a LINK/LINKED cell whose
         last_seqno_recv is above what we ever sent on the set. Fixes bug
         41328; bugfix on 0.4.8.1-alpha.


    [114 lines not shown]
VersionDeltaFile
1.147+4-4net/tor/distinfo
1.203+2-2net/tor/Makefile
+6-62 files

NetBSD/pkgsrc SkKm1So — multimedia/gst-plugins1-bad PLIST.Linux

   gst-plugins1-bad: fix PLIST.Linux after update
VersionDeltaFile
1.11+4-4multimedia/gst-plugins1-bad/PLIST.Linux
+4-41 files

NetBSD/pkgsrc 9dkn3iR — doc CHANGES-2026

   doc: Updated www/resterm to 1.13.3
VersionDeltaFile
1.6796+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc ch4O0lw — www/resterm go-modules.mk Makefile

   resterm: Update to 1.13.3

   Quoted options
VersionDeltaFile
1.58+3-3www/resterm/distinfo
1.64+1-1www/resterm/Makefile
1.49+0-0www/resterm/go-modules.mk
+4-43 files

NetBSD/pkgsrc zOHPba8 — doc CHANGES-2026

   doc: Fix PKGPATH for net/dnscap

   The PKGNAME has a `2' suffix but PKGPATH is still net/dnscap.

   Pointed out by pkg-changes2html htutils script via www@.
VersionDeltaFile
1.6795+2-2doc/CHANGES-2026
+2-21 files

NetBSD/pkgsrc 4Ea4WMV — databases/mongodb Makefile

   mongodb: revert Makefile 1.97 to enable Python 3.13 again

   ok wiz
VersionDeltaFile
1.106+2-2databases/mongodb/Makefile
+2-21 files

NetBSD/pkgsrc 024SlqK — doc CHANGES-2026

   doc: Updated www/resterm to 1.13.2
VersionDeltaFile
1.6794+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc GEsFCou — www/resterm go-modules.mk Makefile

   resterm: Update to 1.13.2

   Trace budgets
   OpenAPI imports
   Workflow conditions and loops
   RestermScript errors
   CLI exit codes
VersionDeltaFile
1.57+3-3www/resterm/distinfo
1.63+1-1www/resterm/Makefile
1.48+0-0www/resterm/go-modules.mk
+4-43 files

NetBSD/pkgsrc ayd7qfw — doc CHANGES-2026

   Updated devel/cargo-nextest, lang/nodejs
VersionDeltaFile
1.6793+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc itcB7RE — lang/nodejs Makefile distinfo, lang/nodejs/patches patch-deps_histogram_src_hdr__histogram.c patch-common.gypi

   nodejs: updated to 26.11.1

   26.11.1 (Current)

   - Revert "build: toggle doc-kit verbosity based on V" (Antoine du Hamel)
   - Revert "build, doc: move to redesign" (Antoine du Hamel)
   - Revert "tools: bump the doc group in /tools/doc with 4 updates" (Antoine du Hamel)
VersionDeltaFile
1.15+7-7lang/nodejs/patches/patch-common.gypi
1.333+5-6lang/nodejs/distinfo
1.362+2-2lang/nodejs/Makefile
1.2+1-1lang/nodejs/patches/patch-deps_histogram_src_hdr__histogram.c
+15-164 files

NetBSD/pkgsrc mypkGDg — devel/cargo-nextest Makefile cargo-depends.mk

   cargo-nextest: updated to 0.9.148

   0.9.148

   Changed

   For setup scripts, slow-timeout no longer accepts on-timeout = "pass", and nextest now reports a configuration error if it is specified. A setup script that times out always fails the run. Previously, this setting was accepted but handled inconsistently: the timed-out script was counted as a failure, but the run was not cancelled.
   Internal dependency updates: guppy updated to 0.19.1, and target-spec updated to 3.7.0, updating built-in targets to Rust 1.98.

   Fixed

   Stress runs now exit with a non-zero code if any iteration failed. Previously, with fail-fast disabled, the exit code reflected only the last iteration, so a stress run with failures in earlier iterations exited with code 0 if the last iteration passed.

   Stress runs now always run at least one iteration. Previously, --stress-duration with a very short duration (such as 1ns) could finish without running any tests.

   Runs stopped by immediate fail-fast (--max-fail N:immediate) are now treated as failed rather than cancelled. Previously, in stress runs, the summary read 0 passed; cancelled due to test failure and the failing iteration was not counted as failed.

   When the global timeout fires with immediate fail-fast enabled, nextest now reports the global timeout as the reason the run was cancelled. Previously, the tests terminated by the timeout counted as failures, so nextest printed a second Cancelling due to test failure line and reported a test failure as the reason.


    [11 lines not shown]
VersionDeltaFile
1.26+52-58devel/cargo-nextest/distinfo
1.26+16-18devel/cargo-nextest/cargo-depends.mk
1.30+2-2devel/cargo-nextest/Makefile
+70-783 files

NetBSD/pkgsrc bprbZyi — doc CHANGES-2026

   doc: Updated graphics/libvips to 8.18.7
VersionDeltaFile
1.6792+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 71h7bIm — graphics/libvips Makefile distinfo

   libvips: update to 8.18.7.

   Fix test target.

   20/9/26 8.18.7

   - tiffload: copy colormaps on page load [Ada Logics]
   - buildlut: limit output lut size [Ada Logics]
   - tiffload: check for undersized jp2k tiles [Ada Logics]
   - hough_line: improve bounds check [Ada Logics]
   - pdfiumload: check for buffer too small [Ada Logics]
   - tiffload: check rgba settings between directories [Tanto Security]
   - uhdrload: calculate gain map scale factor using round-to-nearest [lovell]
   - jp2ksave: tag as UNTRUSTED [kleisauke]
   - header: only parse EXIF metadata for blob values [Shopify]
   - jp2kload: more size validation [Akokonunes]

   25/8/26 8.18.6


    [170 lines not shown]
VersionDeltaFile
1.3+7-7graphics/libvips/PLIST
1.3+4-4graphics/libvips/distinfo
1.20+4-3graphics/libvips/Makefile
+15-143 files

NetBSD/pkgsrc IY8d0W5 — doc CHANGES-2026

   net/dnscap: note update of package to 2.5.2 (and rename package to dnscap2)
VersionDeltaFile
1.6791+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 9seS2vS — net/dnscap distinfo PLIST, net/dnscap/patches patch-Makefile.in

   net/dnscap: Update dnscap from version 1.4.1 (from 2015) to 2.5.1

   Prompted by jperkin's MacOS 27 bulk build results

   10+ years of changes are too many to summarise here, but TL;DR is that

   + there are a lot more dependencies (on a lot of archivers/compression
     libraries), openssl, and ldns,
   + the package name in pkgsrc is now dnscap2,
   + and dnscap now supports plugins (${PREFIX}/bin/dnscap-rssm-rssac002
     is one such).
VersionDeltaFile
1.7+17-4net/dnscap/Makefile
1.2+18-0net/dnscap/PLIST
1.7+4-5net/dnscap/distinfo
1.3+1-1net/dnscap/patches/patch-Makefile.in
+40-104 files

NetBSD/pkgsrc lYSb7GE — doc CHANGES-2026

   p5-DBD-mysql4 addition, ess update
VersionDeltaFile
1.6790+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc GqRugsT — math/ess distinfo Makefile, math/ess/patches patch-doc_newfeat.texi patch-test_ess-test.el

   ess: update to 26.05.0

   14 years worth of updates.
VersionDeltaFile
1.10+24-79math/ess/PLIST
1.1+42-0math/ess/patches/patch-doc_installation.texi
1.40+16-15math/ess/Makefile
1.9+14-6math/ess/distinfo
1.1+17-0math/ess/patches/patch-test_ess-test.el
1.1+15-0math/ess/patches/patch-doc_newfeat.texi
+128-1003 files not shown
+145-1029 files

NetBSD/pkgsrc WZE81vU — devel/rt5 options.mk

   rt5: add a mariadb option
VersionDeltaFile
1.2+5-2devel/rt5/options.mk
+5-21 files

NetBSD/pkgsrc J49SvJr — databases Makefile, databases/p5-DBD-mysql4 distinfo DESCR

   p5-DBD-mysql4: re-add version 4.050nb8 here

   as p5-DBD-mysql>=5 only supports mysql>=8 and not MariaDB.
VersionDeltaFile
1.1+26-0databases/p5-DBD-mysql4/Makefile
1.1+15-0databases/p5-DBD-mysql4/DESCR
1.1+5-0databases/p5-DBD-mysql4/distinfo
1.758+2-1databases/Makefile
+48-14 files

NetBSD/pkgsrc lfm6ZN6 — www/mailman3-web distinfo Makefile, www/mailman3-web/patches patch-pyproject.toml

   mailman3-web: bump the highest version of django claimed to be supported.
VersionDeltaFile
1.1+16-0www/mailman3-web/patches/patch-pyproject.toml
1.12+2-2www/mailman3-web/Makefile
1.6+2-1www/mailman3-web/distinfo
+20-33 files

NetBSD/pkgsrc ku1uwEG — www/py-hyperkitty distinfo Makefile, www/py-hyperkitty/patches patch-pyproject.toml patch-hyperkitty_forms.py

   py-hyperkitty: bump the highest version of django claimed to be supported.
   also fix issue with tag widget rendering properly with Django 5.2
VersionDeltaFile
1.1+34-0www/py-hyperkitty/patches/patch-hyperkitty_forms.py
1.1+16-0www/py-hyperkitty/patches/patch-pyproject.toml
1.5+3-1www/py-hyperkitty/distinfo
1.12+3-1www/py-hyperkitty/Makefile
+56-24 files

NetBSD/pkgsrc EOGPVZm — www/py-postorius distinfo Makefile, www/py-postorius/patches patch-pyproject.toml

   py-postorius: bump the highest version of django claimed to be supported.
VersionDeltaFile
1.1+16-0www/py-postorius/patches/patch-pyproject.toml
1.9+2-2www/py-postorius/Makefile
1.5+2-1www/py-postorius/distinfo
+20-33 files

NetBSD/pkgsrc zcz6hGr — www/tinyproxy/files tinyproxy.sh

   tinyproxy: have rc.d script create /var/run/tinyproxy if missing

   Have the example tinyproxy rc.d script in files/tinyproxy.sh create
   the pid directory (@VARBASE@/run/tinyproxy) if it is not present
   using start_precmd (e.g. as is done in /etc/rc.d/mdnsd).  Needed
   for cases where we reboot and /etc/rc.d/clearcritlocal deletes
   the old pid directory from /var/run.
VersionDeltaFile
1.5+10-1www/tinyproxy/files/tinyproxy.sh
+10-11 files

NetBSD/pkgsrc r2GZW7V — www/py-django-mailman3 distinfo Makefile, www/py-django-mailman3/patches patch-pyproject.toml

   py-django-mailman3: bump the highest version of django claimed to be supported.
VersionDeltaFile
1.1+16-0www/py-django-mailman3/patches/patch-pyproject.toml
1.8+2-2www/py-django-mailman3/Makefile
1.5+2-1www/py-django-mailman3/distinfo
+20-33 files

NetBSD/pkgsrc afMiJE8 — doc CHANGES-2026

   Updated security/flawfinder, devel/py-mocket
VersionDeltaFile
1.6789+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc jcGho2n — devel/py-mocket Makefile distinfo

   py-mocket: updated to 3.14.5

   3.14.5

   Pinning right version for typing-extensions
   Preserve encoded query parameters in recorded requests
VersionDeltaFile
1.21+4-4devel/py-mocket/distinfo
1.21+2-2devel/py-mocket/Makefile
+6-62 files

NetBSD/pkgsrc xsNUWnz — security/flawfinder distinfo Makefile

   flawfinder: updated to 2.0.20

   2.0.20
     Fix unlikely vulnerabilities (involving malicious filenames/text
     in analyzed systems) and implement various improvements
   * Fix security vulnerabilities found by Gemini:
     - Terminal injection in standard output: apply strip_controls() to
       level and category in show().
     - Terminal injection in CSV output: apply strip_controls() to all
       untrusted fields in show_csv() (category, name, warning,
       suggestion, note, context_text).
     - XML injection in SonarQube output: use quoteattr() for all XML
       attributes in output_sonar().
     - Defense-in-depth: restrict setattr in Hit.__init__ to an allowlist
       of known keys used by rule definitions, countering pickle attacks.
       We previously warned to not load untrusted pickle files, but
       completely preventing attacks is better.
     - Shell injection in CI/CD file entrypoint.sh:
       quoted args with "$@" and moved output filename to

    [86 lines not shown]
VersionDeltaFile
1.3+8-7security/flawfinder/PLIST
1.32+7-6security/flawfinder/Makefile
1.13+4-4security/flawfinder/distinfo
+19-173 files

NetBSD/pkgsrc jn6dMho — doc CHANGES-2026

   Updated devel/py-click-repl, devel/py-cachetools
VersionDeltaFile
1.6788+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc FMfLUCQ — devel/py-cachetools Makefile distinfo

   py-cachetools: updated to 7.2.1

   v7.2.1 (2026-10-05)

   - Improve error handling for ``RRCache.popitem()`` when the cache is
     empty.
   - Minor style and documentation improvements.
   - Update CI environment.


   v7.2.0 (2026-09-16)

   - Deprecate use of ``cache=None`` to suppress caching with the
     ``@cached`` decorator.
   - Add support for Python 3.15.
   - Minor test improvements.
   - Minor documentation updates.
VersionDeltaFile
1.41+4-4devel/py-cachetools/distinfo
1.42+3-3devel/py-cachetools/Makefile
+7-72 files