py-w3lib: updated to 2.5.0
2.5.0 (2026-09-30)
New features:
- Added support for Python 3.15
- Added :func:`~w3lib.url.add_http_if_no_scheme`, ported from Scrapy, which
adds ``http`` as the default scheme to a URL that has none
- ``w3lib.url.parse_qsl_to_bytes``, :func:`~w3lib.url.url_query_parameter`,
:func:`~w3lib.url.add_or_replace_parameter`,
:func:`~w3lib.url.add_or_replace_parameters` and
:func:`~w3lib.url.canonicalize_url` now accept a *separator* (or
*query_separator* for :func:`~w3lib.url.canonicalize_url`) keyword argument,
to support query strings that use a separator other than ``&``
- :func:`~w3lib.html.get_base_url` and :func:`~w3lib.html.get_meta_refresh`
[150 lines not shown]
py-itemloaders: updated to 1.5.0
itemloaders 1.5.0 (2026-09-29)
- **Backward-incompatible change:** when an Item Loader instantiates the
item itself, from :attr:`~ItemLoader.default_item_class`, the field
defaults of that item are no longer treated as collected data, so they no
longer go through processors and no longer get combined with the values
you add. They still reach the loaded item for fields that get no data.
To get the old behavior, pass the item yourself, e.g.
``ItemLoader(item=MyItem())``.
- **Backward-incompatible change:** sets and iterators other than generators,
such as the result of :func:`map`, are now collected value by value, like
lists, tuples and generators already were, instead of as a single value.
To collect one of them as a single value, wrap it in a list, e.g.
``loader.add_value("tags", [{"a", "b"}])``.
[19 lines not shown]
py-apycula: updated to 0.34
0.34
Fix RAW_ALU_LUT.
GitHub CI: updated workflows to avoid Node.js version warnings
Add GW_JTAG support for TangNano20k / GW2A-18C (under instruction from YRabbit)
Yosys 0.96
Fix bypass register attributes in DSP
Fix LVDS and IBUFs in one bank.
fix unassigned offx variable in get_pll_bels
BUGFIX. PLL's bels offsets
GW5AT-60B. Implement the clocks.
py-pebble: updated to 5.2.3
5.2.3
Fixes:
- Issue 169: fix pool's context parameter type annotation.
- Issue 170: correctly report the pool's status in case of
internal error.
py-wcwidth: updated to 0.9.2
0.9.2 *2026-10-04*
* **Bugfix** `wrap()`_ should omit an empty line as output, like `textwrap.wrap()`_
* **Bugfix** `clip()`_ when using non-default argument, ``tabsize=0``
* **Bugfix** regional-indicator pairs (flags) when corrected for terminals that show lone regional
indicators as narrow (xterm, wezterm, VTE, and others) in `wcstwidth()`_ and `width()`_
fast_float: updated to 8.3.1
8.3.1
Keep chars_format::javascript out of the common hot path
Restore the simple loop in fastfloat_strncasecmp
Fold the format at compile time under clang, mark cold checks unlikely
Fix std::float16_t rounding of subnormal ties and fast-path overflow
Average branch misses over the repetitions in the benchmark
drop the unreachable tail of parse_mantissa
CI: pin Alpine to v3.22 to fix setup-alpine failures
Reorder parsed_number_string_t fields to avoid padding
Add manually triggered release workflow; fix on-release asset upload
Update to MIMEDefang 3.7.1:
- upstream changed the name of the DISTFILE, this should be fixed better
- appease pkglint somewhat
Changelog
New features and fixes of MIMEDefang versions.
MIMEDefang 3.7.1 2026-07-14
* add autoscaling support to activate or deactivate workers when needed
* add Mail::MIMEDefang::Async module to run multiple tasks in parallel
* add Mail::MIMEDefang::BIMI module with BIMI support
* add Mail::MIMEDefang::TLSPolicy module for MTA-STS and DANE/TLSA policy checks
* add support for ClamAV scan using TCP/IP on localhost
* improve md_graphdefang_log with new per_message parameter
* add md_graphdefang_log_array for logging arbitrary numbers of values
* add -A flag to mimedefang-multiplexor for worker scheduling logging
* add -k flag to mimedefang-multiplexor for adaptive autoscaling
* fix strip CR before LF at header fold points in INPUTMSG
[21 lines not shown]
cyrus-imapd312: Update to Cyrus IMAPd 3.12.4.
____________________________________________________________________________________________
Cyrus IMAP 3.12.4 Release Notes
Changes since 3.12.3
Security fixes
* CVE-2026-61907: JMAP snooze bypasses destination-mailbox ACL
An authenticated user with insert permissions on another user's snoozed mailbox could cause
insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to
the user, despite having no insert permissions to the target mailbox.
Reported by: Michael Lynch (mtlynch.io).
* CVE-2026-61908: JMAP email-header blob ID out-of-bounds index
An authenticated user could attempt to download a specially crafted JMAP blob ID of the form
H<emailid>-<index>, which could read past the end of the internal blob_headers array during
download, exposing adjacent heap memory.
[136 lines not shown]
Update to 0.000005
Upstream changes:
0.000005 2026-04-17 11:29:35-07:00 America/Los_Angeles
- Require Importer 0.025+ so `use Importer Importer => 'import'` works
(older Importer versions like 0.014 lack 'import' in IMPORTER_MENU,
causing "Importer does not export &import" at load time)
0.000004 2026-04-15 14:34:09-07:00 America/Los_Angeles
- Add havejump() to check if a named jump point is currently set
Update to 3.101
Upstream changes:
3.101 2026-04-13 13:31:24-04:00 America/New_York
- fix auto-using of Log::Fmt::XS, which was straight up broken
3.100 2026-04-01 10:35:56-04:00 America/New_York
- when present, use Log::Fmt::XS for emitting logfmt
- abstract out logfmt tests for use in both Log::Fmt and Log::Fmt::XS
test suites (but don't consider this public yet)
3.013 2025-10-15 10:12:50-04:00 America/New_York
- typo fixes and spec clarifications
3.012 2025-10-14 12:39:48-04:00 America/New_York
- [ BREAKING CHANGE (BARELY) ]
Log::Fmt now includes a formal specification of the logfmt grammar we
implement, as well as a description of algorithmns to correctly
encode strings. The code has been updated to fall in line, meaning:
[4 lines not shown]
Update to 1.19
Upstream changes:
1.19 2026-07-06
- Fix mass CPAN tester FAILs on OpenBSD (29 of 32 reports for 1.18): the
smoker host's 10 SysV semaphore-set slots (kern.seminfo.semmni=10) were
pre-exhausted by stale sets leaked from previously crashed runs, so
nearly every tie died with semget ENOSPC ("Could not create semaphore
set: No space left on device"), and each failing run leaked further
resources
- _tie(): an IPC_PRIVATE segment is now removed when semaphore-set
creation (or the initial lock) fails. shmget(IPC_PRIVATE) always
creates a fresh segment regardless of the 'create' attribute, and a
private segment is unreachable by key after the croak, so it leaked
invisibly (~4 segments per failed suite run on the wedged smoker)
- clean_up_testing(): added a second pass that reclaims orphaned
testing-tagged semaphore sets whose segment is already gone; these pin
a SEMMNI slot forever and were invisible to the ipcs -m based scan.
New regression test t/82-stale-ipc-reclaim.t
[261 lines not shown]
Update to Cyrus IMAPd 3.10.4.
Cyrus IMAP 3.10.4 Release Notes
Changes since 3.10.3
Security fixes
* CVE-2026-61907: JMAP snooze bypasses destination-mailbox ACL
An authenticated user with insert permissions on another user's snoozed mailbox could cause
insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to
the user, despite having no insert permissions to the target mailbox.
Reported by: Michael Lynch (mtlynch.io).
* CVE-2026-61908: JMAP email-header blob ID out-of-bounds index
An authenticated user could attempt to download a specially crafted JMAP blob ID of the form
H<emailid>-<index>, which could read past the end of the internal blob_headers array during
download, exposing adjacent heap memory.
Reported by: Ahmed Said.
* CVE-2026-61909: CalDAV/CardDAV multiget bypasses per-href ACL
[35 lines not shown]
Update to 20260402.0
Upstream changes:
20260402.0 Thu Apr 2 2026
Bug fixes:
- GH #271, GH #164 - Detect undefined command in arrayref at harness parse
time instead of deferring to start() (PR #272)
- pipe_writer drops input when data is the string "0" due to redundant
boolean test on input buffer (PR #264)
- Callback filter evaluates return in list context to distinguish empty
return from the string "0", preventing infinite loop on Win32 (PR #264)
- GH #240 - Skip pty output assertions on BSD/Darwin due to known pty
drain timing issues on short-lived children (PR #274)
- Implement proper Windows command-line parsing per Microsoft C/C++ rules,
fixing argument parsing failures with single-quoted strings containing
whitespace (PR #273)
Maintenance:
- Add shebang to eg/synopsis_scripting (PR #275)
20260401.0 Wed Apr 1 2026
[108 lines not shown]
Update to 1.31
Upstream changes:
1.31 2026-05-24 Todd Rinaldo <toddr at cpan.org>
Bug Fixes:
* GH #91, PR #94 - Fix v1.27 regression where _open_tty() always passed
O_NOCTTY, preventing make_slave_controlling_terminal() from acquiring
a controlling terminal via the POSIX-standard open-without-O_NOCTTY
mechanism (it was forced to fall through to an explicit TIOCSCTTY
ioctl). _open_tty() now takes an optional noctty flag (default 1 for
backward compatibility); make_slave_controlling_terminal() passes 0.
* GH #92, PR #93 - Fix openpty() detection on Fedora 33-34 / glibc
2.32-2.33 where LTO flags (-flto=auto) caused the libc-only compile
probe to falsely succeed, producing "undefined symbol: openpty" at
runtime. Try -lutil before libc; harmless on systems where openpty
lives in libc (glibc 2.34+, musl) and necessary where it doesn't.
Maintenance:
* PR #90 - Address CPANTS kwalitee issues: add LICENSE, SECURITY.md,
and CONTRIBUTING.md; add META `provides` for IO::Tty, IO::Pty, and
[172 lines not shown]