NetBSD/pkgsrc 5r2tVnOgraphics/librsvg Makefile

   librsvg: additional dylib post-install fixup
VersionDeltaFile
1.188+2-1graphics/librsvg/Makefile
+2-11 files

NetBSD/pkgsrc 5lqJISwdevel/go-nbreader Makefile, devel/go-review Makefile

   Revbump all Go packages after Go 1.26 update
VersionDeltaFile
1.44+2-2devel/gotests/Makefile
1.98+2-2devel/go-sys/Makefile
1.36+2-2devel/go-swagger/Makefile
1.52+2-2devel/go-staticcheck/Makefile
1.93+2-2devel/go-review/Makefile
1.90+2-2devel/go-nbreader/Makefile
+12-12205 files not shown
+422-391211 files

NetBSD/pkgsrc 1XQGoo8doc CHANGES-2026

   doc: Updated lang/go126 to 1.26.6
VersionDeltaFile
1.5298+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc 2GrXlp8lang/go version.mk, lang/go125 distinfo PLIST

   go: update to 1.25.13 and 1.26.5 (security)

   These releases include 10 security fixes following the security policy:

   - x/mod/sumdb/tlog: fix transparency log tile verification bypass

     A malicious GOPROXY was previously capable of forging
     up to two sumdb tiles that allow for a requested module
     to bypass the GOSUMDB check and persist attacker-controlled
     module content to a local Go module cache.

     This attack allows for a malicious GOPROXY to serve
     malicious module content that cannot be detected
     by evaluating the transparency log.

     All tiles are now correctly verified against their parents.

     In order to determine if you have been affected:


    [117 lines not shown]
VersionDeltaFile
1.7+4-4lang/go126/distinfo
1.15+4-4lang/go125/distinfo
1.7+8-0lang/go126/PLIST
1.10+8-0lang/go125/PLIST
1.252+3-3lang/go/version.mk
+27-115 files

NetBSD/pkgsrc DrAapA2emulators/ntvcm/files ntvcm.1

   Flipped letters in naem, stupid acronyms...

   Spotted by John D. Baker - thanks!
VersionDeltaFile
1.2+2-2emulators/ntvcm/files/ntvcm.1
+2-21 files

NetBSD/pkgsrc eiGGdnydoc CHANGES-2026

   doc: Updated sysutils/xplr to 1.1.1
VersionDeltaFile
1.5297+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc BZszzfrsysutils/xplr Makefile cargo-depends.mk

   sysutils/xplr: update to 1.1.1

   What's Changed

       fix(search): fixed a bug that caused results to reshuffle during search.
       other(search): xplr search will default to the default skim algorithm.

   Others:

       deps: upgraded dependencies.
       docs: fix nonexistent util function in upgrade guide by @latent-9 in #777
       ubuntu(snap): @mikoloism helped fix Ubuntu snap build.
VersionDeltaFile
1.66+673-433sysutils/xplr/distinfo
1.41+223-143sysutils/xplr/cargo-depends.mk
1.66+4-4sysutils/xplr/Makefile
+900-5803 files

NetBSD/pkgsrc zU9lRhtdoc CHANGES-2026

   doc: Updated sysutils/dua-cli to 2.42.1
VersionDeltaFile
1.5296+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 13CtVrxsysutils/dua-cli cargo-depends.mk distinfo

   sysutils/dua-cli: update to 2.42.1

   v2.42.1
   *the same as 2.42, and:

   Starting directories with a large amount of files, like 50k, now see a 5x speedup on macOS and Windows as bulk-reading is also done there. Note also that this is still a small absolute difference, 100ms vs 500ms, but a good demonstration of how much large trees with a lot of such directories will benefit by this, as these small absolute improvements accumulate.

   v2.42.0
   The headline or this release is ~30% better traversal performance on macOS due to the usage of bulk-metadata APIs on supported filesytems.
   Bug Fixes

       sanitize control characters in marked path output
       dua-cli's interactive TUI is built on ratatui, which protects the
       paths it renders on screen. But marking a file for deletion and then
       quitting prints that file's path directly to the terminal after the
       TUI has already released terminal control, bypassing ratatui's
       protective rendering entirely. A scanned file's name has no character
       restrictions, so a crafted file name can inject terminal escape
       sequences into the printed path.

    [4 lines not shown]
VersionDeltaFile
1.55+4-4sysutils/dua-cli/distinfo
1.55+4-4sysutils/dua-cli/Makefile
1.42+0-0sysutils/dua-cli/cargo-depends.mk
+8-83 files

NetBSD/pkgsrc vEUvw2hdoc TODO CHANGES-2026

   doc: Updated math/ggml to 0.20.0
VersionDeltaFile
1.27749+2-1doc/TODO
1.5295+2-1doc/CHANGES-2026
+4-22 files

NetBSD/pkgsrc 6ob0AIGmath/ggml PLIST Makefile

   ggml: update to 0.20.0

   no summary available
VersionDeltaFile
1.8+4-4math/ggml/distinfo
1.2+2-2math/ggml/PLIST
1.8+2-2math/ggml/Makefile
+8-83 files

NetBSD/pkgsrc F3ov6yXdoc CHANGES-2026

   doc: Updated www/resterm to 1.1.0
VersionDeltaFile
1.5294+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc RNVXoSjwww/resterm go-modules.mk Makefile

   resterm: Update to 1.1.0

   Changelog

   Path completion
   Resterm now shows matching files and directories in the open and save dialogs, and while entering supported commands.
VersionDeltaFile
1.27+3-3www/resterm/distinfo
1.29+1-1www/resterm/Makefile
1.18+0-0www/resterm/go-modules.mk
+4-43 files

NetBSD/pkgsrc lLjYTShnet/rrsync Makefile, net/rsync Makefile Makefile.common

   rsync, rrsync: put some shared values into Makefile.common
VersionDeltaFile
1.1+13-0net/rsync/Makefile.common
1.2+3-8net/rrsync/Makefile
1.136+2-8net/rsync/Makefile
+18-163 files

NetBSD/pkgsrc sTtcpbCdoc CHANGES-2026

   doc: Updated net/inetutils to 2.8nb1
VersionDeltaFile
1.5293+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc JjTMmMInet/inetutils Makefile distinfo, net/inetutils/patches patch-talkd_talkd.c patch-talkd_intalkd.h

   inetutils: fix CVE-2026-19720 using upstream patch.

   Bump PKGREVISION.
VersionDeltaFile
1.1+223-0net/inetutils/patches/patch-talkd_announce.c
1.1+24-0net/inetutils/patches/patch-talkd_intalkd.h
1.1+23-0net/inetutils/patches/patch-talkd_talkd.c
1.10+4-1net/inetutils/distinfo
1.14+2-1net/inetutils/Makefile
+276-25 files

NetBSD/pkgsrc c04sM5Xdoc CHANGES-2026

   doc: Updated textproc/py-libxml2 to 2.15.3
VersionDeltaFile
1.5292+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc TBJUE7tdoc CHANGES-2026

   doc: Updated textproc/libxml2 to 2.15.3
VersionDeltaFile
1.5291+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc Fx7SIkLtextproc/libxml2 Makefile.common distinfo

   libxml2: update to 2.15.3.

   From Showta Ishizaki in PR 60591.

   v2.15.3: Apr 15 2026

   ### Security

   - parser: Pass userData to SAX text callbacks in xmlParseReference (type-confusion)
   - entities: copy children in xmlCopyEntity
   - c14n: Fix Type confusion in xmlC14NProcessAttrsAxis
   - python: Do not decref string after adding to the list (double-free / use-after-free)
   - c14n: Reuse tmp_str, xmlStrcat reallocates *cur (double-free)

   ### Improvements

   - schemas: Fix relative schemaLocation resolution in XSI assembly in streaming mode
   - xmlreader: propagate reader resource loaders to validator parsers
   - python: Make python bindings python2 compatible

    [44 lines not shown]
VersionDeltaFile
1.158+4-4textproc/libxml2/distinfo
1.32+2-2textproc/libxml2/Makefile.common
+6-62 files

NetBSD/pkgsrc V0eRphzeditors/emacs30-nox11 version.mk

   emacs30-nox11: fix typo

   Reported by Showta Ishizaki in PR 60590.
VersionDeltaFile
1.2+2-2editors/emacs30-nox11/version.mk
+2-21 files

NetBSD/pkgsrc zjnSpG1doc CHANGES-2026

   doc: Updated www/gitea to 1.27.2
VersionDeltaFile
1.5290+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc JJ1aNyOwww/gitea Makefile go-modules.mk

   www/gitea: update to 1.27.2

   Changes in 1.27.2:

   * SECURITY
     - Fix: update collaborator access mode and httpsign
     - Refactor: external render
     - Fix(actions): resolve pull_request_target reusable workflows at the
       base commit
     - Refactor: markup render
     - Fix(deps): update dependency mermaid to v11.16.1
     - Fix(auth): set WebAuthn user verification per request
     - Fix: render highlight language
   * ENHANCEMENTS
     - enhance: add missing npm package metadata properties
   *  BUGFIXES
     - fix(actions): keep github.event.inputs as strings for
       workflow_dispatch
     - fix(actions): let a rerun of selected jobs read the previous

    [419 lines not shown]
VersionDeltaFile
1.45+523-559www/gitea/distinfo
1.22+320-302www/gitea/PLIST
1.13+173-185www/gitea/go-modules.mk
1.140+2-2www/gitea/Makefile
+1,018-1,0484 files

NetBSD/pkgsrc 9eUpHs8doc pkg-vulnerabilities

   pkg-vulnerabilities: Remove libxml2 entry for CVE-2025-12863

   The CVE was rejected on 2025-11-20, see
   <https://gitlab.gnome.org/GNOME/libxml2/-/issues/1012#note_2608283>.

   Via PR pkg/60591 from Showta Ishizaki, thanks!
VersionDeltaFile
1.779+1-2doc/pkg-vulnerabilities
+1-21 files

NetBSD/pkgsrc YO0HWWedoc pkg-vulnerabilities

   pkg-vulnerabilities: Update libxml2 entries fixed in 2.15.2

   Via PR pkg/60591 from Showta Ishizaki, thanks!
VersionDeltaFile
1.778+6-6doc/pkg-vulnerabilities
+6-61 files

NetBSD/pkgsrc YPcHFjQdoc pkg-vulnerabilities

   pkg-vulnerabilities: CVE-2025-69720 was fixed in ncurses-6.6

   According upstream NEWS it was fixed in 20251213 and 6.6 was released
   on 20251230.

   Reported via PR pkg/60589 from Showta Ishizaki, thanks!
VersionDeltaFile
1.777+2-2doc/pkg-vulnerabilities
+2-21 files

NetBSD/pkgsrc 0Gve365doc CHANGES-2026

   doc: Updated security/ca-certificates to 20260601
VersionDeltaFile
1.5289+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc M31G9d2security/ca-certificates Makefile distinfo

   ca-certificates: Update to 20260601

   ca-certificates (20260601) unstable; urgency=medium

     * Remove ca-certificates-local example (closes: #988912, #1127101).
     * Update Mozilla certificate authority bundle to version 2.86
       The following certificate authority was added (+):
       + e-Szigno TLS Root CA 2023
       The following certificate authorities were removed (-):
       - QuoVadis Root CA 2
       - QuoVadis Root CA 3
       - DigiCert Assured ID Root CA
       - DigiCert Global Root CA
       - DigiCert High Assurance EV Root CA
       - SwissSign Gold CA - G2
       - SecureTrust CA
       - Secure Global CA
       - COMODO Certification Authority
       - Certigna

    [18 lines not shown]
VersionDeltaFile
1.10+3-26security/ca-certificates/PLIST
1.15+4-4security/ca-certificates/distinfo
1.18+2-2security/ca-certificates/Makefile
+9-323 files

NetBSD/pkgsrc Oj42lcydoc CHANGES-2026

   doc: Added net/rrsync version 3.5.0
VersionDeltaFile
1.5288+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc MfXcyZQnet Makefile, net/rrsync PLIST distinfo

   Add net/rrsync
VersionDeltaFile
1.1+40-0net/rrsync/Makefile
1.1+6-0net/rrsync/DESCR
1.1+5-0net/rrsync/distinfo
1.1640+2-1net/Makefile
1.1+3-0net/rrsync/PLIST
+56-15 files

NetBSD/pkgsrc 5jTrTbXdoc CHANGES-2026

   doc: Added textproc/py-braceexpand version 0.1.7
VersionDeltaFile
1.5287+2-1doc/CHANGES-2026
+2-11 files