NetBSD/pkgsrc xzsvx9Udevel/jj distinfo, devel/jj/patches patch-.._vendor_serde__bser-0.4.0_src_ser_mod.rs

   devel/jj: add a patch to fix the build on big-endian hosts.

   This applies the change from this upstream pull request:
   https://github.com/facebook/watchman/pull/1238

   Admittedly I'm not able to figure out which version of the
   serde_bser crate has the fix and why it's not in devel/jj: the
   crate appears to be version 0.4.0 both in devel/jj and at the head
   of the github development branch, and this fix is in one but
   not the other.

   Reported upstream at https://github.com/jj-vcs/jj/issues/9992.
VersionDeltaFile
1.1+45-0devel/jj/patches/patch-.._vendor_serde__bser-0.4.0_src_ser_mod.rs
1.38+2-1devel/jj/distinfo
+47-12 files

NetBSD/pkgsrc lfoBR40doc CHANGES-2026

   doc: Updated sysutils/yazi to 26.8.15
VersionDeltaFile
1.5301+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc Hee1HHRsysutils/yazi Makefile cargo-depends.mk

   yazi: update to 26.8.15.

   Added

       Drag and drop (#4005, #4225)
       Trash bin (#4144, #4204, #4212)
       Bulk create (#3793)
       Make help menu a command palette (#4074)
       Input history (#4104)
       Automatic dark/light theme switching (#4196)
       Experimental %y, %Y, %t, %T, %yN, %YN, %tN, %TN shell formatting parameters (#4108)
       Custom VFS provider (#4118)
       Make visual mode support wraparound scrolling (#4101)
       H/M/L Vim-like motion for moving cursor relative to viewport (#3970)
       Context-aware icons for inputs (#4080)
       Show file icons in trash/delete/overwrite confirmations (#4096)
       Dynamic keymap Lua API (#4031)
       Dynamic Lua API for preloader, spotter, fetcher (#4235)
       Configurable border for the which component (#4189)

    [42 lines not shown]
VersionDeltaFile
1.32+859-1,051sysutils/yazi/distinfo
1.28+285-349sysutils/yazi/cargo-depends.mk
1.38+5-2sysutils/yazi/Makefile
+1,149-1,4023 files

NetBSD/pkgsrc O5a60u2doc CHANGES-2026

   doc: Updated devel/compiledb-go to 1.7.0
VersionDeltaFile
1.5300+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc duaOkLpdevel/compiledb-go Makefile go-modules.mk

   compiledb-go: update to 1.7.0.

   feat: update existing compilation database by @fcying in #14
   fix: merge legacy compilation database paths by @fcying in #15
   refactor: harden command parsing and make wrapping by @fcying in #16
   feat: add compiler argument option by @fcying in #17
   feat: add predefined compiler macros by @fcying in #18
   fix: record source commands without -c by @fcying in #19
   fix: align Python compatibility details by @fcying in #20
   dev by @fcying in #21
   fix: harden compiler command detection by @fcying in #22
   feat: improve make integration by @fcying in #23
   feat: embed POSIX shell interpreter by @fcying in #24
   feat: improve platform compatibility by @fcying in #25
   refactor: clarify path handling domains by @fcying in #26
   test: add build log memory benchmarks by @fcying in #27
   refactor: parse shell commands with AST by @fcying in #28
   feat: expand GNU compiler response files by @fcying in #29
   fix: track recursive Make directories by @fcying in #31
   docs: rewrite README by @fcying in #32
VersionDeltaFile
1.11+28-13devel/compiledb-go/distinfo
1.4+8-3devel/compiledb-go/go-modules.mk
1.29+3-4devel/compiledb-go/Makefile
+39-203 files

NetBSD/pkgsrc VQtq7tydoc CHANGES-2026

   doc: Updated databases/p5-DBI to 1.652
VersionDeltaFile
1.5299+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc jxEP9i4databases/p5-DBI Makefile distinfo

   p5-DBI: update to 1.652.

   1.652 - 2026-08-15, H.Merijn Brand & Robert Rothenberg
       * DBI now requires perl-5.12, driven by CVE's
       * Fix test for perl configured without threads (caught by perl-5.45.1)
       * Small doc fix, (issue#155), thanks Dick Franks
       * Add suggested dependency (issue#145), thanks Dick Franks
       * Force placeholder limit on :# and :p# too (CVE-2026-73194)
       * Limit statements to 292 Mb in preparse (CVE-2026-73193)
       * Add a security policy (issue#174)
       * Add dbm_updatable_key attribute to DBD::DBM to configure how keys are updated
       * Fix missing import in DBI::DBD::SqlEngine
       * Fix !Caller2 caller loss when $^P is set (PR#184) (Thanks Paul)
VersionDeltaFile
1.64+4-4databases/p5-DBI/distinfo
1.101+2-3databases/p5-DBI/Makefile
+6-72 files

NetBSD/pkgsrc 5cCB2a7security/zoneminder Makefile

   security/zoneminder: Move to ffmpeg8

   A different program had trouble building with old zoneminder, which
   prompted me to flip to ffmpeg8 and test.
VersionDeltaFile
1.110+5-5security/zoneminder/Makefile
+5-51 files

NetBSD/pkgsrc 5r2tVnOgraphics/librsvg Makefile

   librsvg: additional dylib post-install fixup
VersionDeltaFile
1.188+2-1graphics/librsvg/Makefile
+2-11 files

NetBSD/pkgsrc 5lqJISwdevel/go-nbreader Makefile, devel/go-review Makefile

   Revbump all Go packages after Go 1.26 update
VersionDeltaFile
1.44+2-2devel/gotests/Makefile
1.98+2-2devel/go-sys/Makefile
1.36+2-2devel/go-swagger/Makefile
1.52+2-2devel/go-staticcheck/Makefile
1.93+2-2devel/go-review/Makefile
1.90+2-2devel/go-nbreader/Makefile
+12-12205 files not shown
+422-391211 files

NetBSD/pkgsrc 1XQGoo8doc CHANGES-2026

   doc: Updated lang/go126 to 1.26.6
VersionDeltaFile
1.5298+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc 2GrXlp8lang/go version.mk, lang/go125 distinfo PLIST

   go: update to 1.25.13 and 1.26.5 (security)

   These releases include 10 security fixes following the security policy:

   - x/mod/sumdb/tlog: fix transparency log tile verification bypass

     A malicious GOPROXY was previously capable of forging
     up to two sumdb tiles that allow for a requested module
     to bypass the GOSUMDB check and persist attacker-controlled
     module content to a local Go module cache.

     This attack allows for a malicious GOPROXY to serve
     malicious module content that cannot be detected
     by evaluating the transparency log.

     All tiles are now correctly verified against their parents.

     In order to determine if you have been affected:


    [117 lines not shown]
VersionDeltaFile
1.7+4-4lang/go126/distinfo
1.15+4-4lang/go125/distinfo
1.7+8-0lang/go126/PLIST
1.10+8-0lang/go125/PLIST
1.252+3-3lang/go/version.mk
+27-115 files

NetBSD/pkgsrc DrAapA2emulators/ntvcm/files ntvcm.1

   Flipped letters in naem, stupid acronyms...

   Spotted by John D. Baker - thanks!
VersionDeltaFile
1.2+2-2emulators/ntvcm/files/ntvcm.1
+2-21 files

NetBSD/pkgsrc eiGGdnydoc CHANGES-2026

   doc: Updated sysutils/xplr to 1.1.1
VersionDeltaFile
1.5297+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc BZszzfrsysutils/xplr Makefile cargo-depends.mk

   sysutils/xplr: update to 1.1.1

   What's Changed

       fix(search): fixed a bug that caused results to reshuffle during search.
       other(search): xplr search will default to the default skim algorithm.

   Others:

       deps: upgraded dependencies.
       docs: fix nonexistent util function in upgrade guide by @latent-9 in #777
       ubuntu(snap): @mikoloism helped fix Ubuntu snap build.
VersionDeltaFile
1.66+673-433sysutils/xplr/distinfo
1.41+223-143sysutils/xplr/cargo-depends.mk
1.66+4-4sysutils/xplr/Makefile
+900-5803 files

NetBSD/pkgsrc zU9lRhtdoc CHANGES-2026

   doc: Updated sysutils/dua-cli to 2.42.1
VersionDeltaFile
1.5296+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 13CtVrxsysutils/dua-cli cargo-depends.mk distinfo

   sysutils/dua-cli: update to 2.42.1

   v2.42.1
   *the same as 2.42, and:

   Starting directories with a large amount of files, like 50k, now see a 5x speedup on macOS and Windows as bulk-reading is also done there. Note also that this is still a small absolute difference, 100ms vs 500ms, but a good demonstration of how much large trees with a lot of such directories will benefit by this, as these small absolute improvements accumulate.

   v2.42.0
   The headline or this release is ~30% better traversal performance on macOS due to the usage of bulk-metadata APIs on supported filesytems.
   Bug Fixes

       sanitize control characters in marked path output
       dua-cli's interactive TUI is built on ratatui, which protects the
       paths it renders on screen. But marking a file for deletion and then
       quitting prints that file's path directly to the terminal after the
       TUI has already released terminal control, bypassing ratatui's
       protective rendering entirely. A scanned file's name has no character
       restrictions, so a crafted file name can inject terminal escape
       sequences into the printed path.

    [4 lines not shown]
VersionDeltaFile
1.55+4-4sysutils/dua-cli/distinfo
1.55+4-4sysutils/dua-cli/Makefile
1.42+0-0sysutils/dua-cli/cargo-depends.mk
+8-83 files

NetBSD/pkgsrc vEUvw2hdoc TODO CHANGES-2026

   doc: Updated math/ggml to 0.20.0
VersionDeltaFile
1.27749+2-1doc/TODO
1.5295+2-1doc/CHANGES-2026
+4-22 files

NetBSD/pkgsrc 6ob0AIGmath/ggml PLIST Makefile

   ggml: update to 0.20.0

   no summary available
VersionDeltaFile
1.8+4-4math/ggml/distinfo
1.2+2-2math/ggml/PLIST
1.8+2-2math/ggml/Makefile
+8-83 files

NetBSD/pkgsrc F3ov6yXdoc CHANGES-2026

   doc: Updated www/resterm to 1.1.0
VersionDeltaFile
1.5294+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc RNVXoSjwww/resterm go-modules.mk Makefile

   resterm: Update to 1.1.0

   Changelog

   Path completion
   Resterm now shows matching files and directories in the open and save dialogs, and while entering supported commands.
VersionDeltaFile
1.27+3-3www/resterm/distinfo
1.29+1-1www/resterm/Makefile
1.18+0-0www/resterm/go-modules.mk
+4-43 files

NetBSD/pkgsrc lLjYTShnet/rrsync Makefile, net/rsync Makefile Makefile.common

   rsync, rrsync: put some shared values into Makefile.common
VersionDeltaFile
1.1+13-0net/rsync/Makefile.common
1.2+3-8net/rrsync/Makefile
1.136+2-8net/rsync/Makefile
+18-163 files

NetBSD/pkgsrc sTtcpbCdoc CHANGES-2026

   doc: Updated net/inetutils to 2.8nb1
VersionDeltaFile
1.5293+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc JjTMmMInet/inetutils Makefile distinfo, net/inetutils/patches patch-talkd_talkd.c patch-talkd_intalkd.h

   inetutils: fix CVE-2026-19720 using upstream patch.

   Bump PKGREVISION.
VersionDeltaFile
1.1+223-0net/inetutils/patches/patch-talkd_announce.c
1.1+24-0net/inetutils/patches/patch-talkd_intalkd.h
1.1+23-0net/inetutils/patches/patch-talkd_talkd.c
1.10+4-1net/inetutils/distinfo
1.14+2-1net/inetutils/Makefile
+276-25 files

NetBSD/pkgsrc c04sM5Xdoc CHANGES-2026

   doc: Updated textproc/py-libxml2 to 2.15.3
VersionDeltaFile
1.5292+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc TBJUE7tdoc CHANGES-2026

   doc: Updated textproc/libxml2 to 2.15.3
VersionDeltaFile
1.5291+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc Fx7SIkLtextproc/libxml2 Makefile.common distinfo

   libxml2: update to 2.15.3.

   From Showta Ishizaki in PR 60591.

   v2.15.3: Apr 15 2026

   ### Security

   - parser: Pass userData to SAX text callbacks in xmlParseReference (type-confusion)
   - entities: copy children in xmlCopyEntity
   - c14n: Fix Type confusion in xmlC14NProcessAttrsAxis
   - python: Do not decref string after adding to the list (double-free / use-after-free)
   - c14n: Reuse tmp_str, xmlStrcat reallocates *cur (double-free)

   ### Improvements

   - schemas: Fix relative schemaLocation resolution in XSI assembly in streaming mode
   - xmlreader: propagate reader resource loaders to validator parsers
   - python: Make python bindings python2 compatible

    [44 lines not shown]
VersionDeltaFile
1.158+4-4textproc/libxml2/distinfo
1.32+2-2textproc/libxml2/Makefile.common
+6-62 files

NetBSD/pkgsrc V0eRphzeditors/emacs30-nox11 version.mk

   emacs30-nox11: fix typo

   Reported by Showta Ishizaki in PR 60590.
VersionDeltaFile
1.2+2-2editors/emacs30-nox11/version.mk
+2-21 files

NetBSD/pkgsrc zjnSpG1doc CHANGES-2026

   doc: Updated www/gitea to 1.27.2
VersionDeltaFile
1.5290+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc JJ1aNyOwww/gitea Makefile go-modules.mk

   www/gitea: update to 1.27.2

   Changes in 1.27.2:

   * SECURITY
     - Fix: update collaborator access mode and httpsign
     - Refactor: external render
     - Fix(actions): resolve pull_request_target reusable workflows at the
       base commit
     - Refactor: markup render
     - Fix(deps): update dependency mermaid to v11.16.1
     - Fix(auth): set WebAuthn user verification per request
     - Fix: render highlight language
   * ENHANCEMENTS
     - enhance: add missing npm package metadata properties
   *  BUGFIXES
     - fix(actions): keep github.event.inputs as strings for
       workflow_dispatch
     - fix(actions): let a rerun of selected jobs read the previous

    [419 lines not shown]
VersionDeltaFile
1.45+523-559www/gitea/distinfo
1.22+320-302www/gitea/PLIST
1.13+173-185www/gitea/go-modules.mk
1.140+2-2www/gitea/Makefile
+1,018-1,0484 files