py-last: update to 7.2.0.
Changed
Drop support for Python 3.10 (#549) @hugovk
Fixed
Only retry transient network failures (#544) @hugovk
Add and fix more Ruff lint rules (#546) @hugovk
Update deploy actions for metadata version 2.5 (#545) @hugovk
py-google-auth-httplib2: update to 0.4.4.
0.4.4 (2026-10-01)
repair broken and stale repository URLs in package metadata (#18498) (54dbd12), refs #18497
0.4.3 (2026-09-29)
declare Python3.15 support (05b0c34)
py-filelock: update to 4.0.10.
4.0.10
♻️ refactor(util): test helpers via public locks by @gaborbernat in #764
🐛 fix(singleton): reject conflicting async and lease options by @kokotatan in #765
4.0.9
📝 docs(util): correct write and break guarantees by @pralav-25 in #762
🐛 fix(read-write): close db fd after connect by @gaborbernat in #763
4.0.8
🐛 fix(read-write): refuse cross-thread write release by @feiiiiii5 in #761
4.0.7
🐛 fix(mode): require owner read and write by @gaborbernat in #760
py-configargparse: update to 1.8.0.
Values for mutually exclusive options now follow the usual override order (#164, #358)
Python 3.14 is now supported and tested in CI (#359)
rspamd: update to 4.2.1.
4.2.1: 01 Oct 2026
** Bug fixes **
* [CritFix] http: Do not size the body from a chunk size or Content-Length sent by the peer (a huge chunk size caused a heap overflow)
* [CritFix] http: Keep zero-copy reads inside the body (use-after-free when a finish handler replaces the body)
* [CritFix] fstring: Refuse a length that cannot be allocated (the size wrapped and later writes went out of bounds)
* [CritFix] cryptobox: Fail closed on low order public keys (an uninitialised shared secret was cached and used to decrypt fuzzy requests)
* [CritFix] hiredis: Keep the socket until async cleanup (assertion abort when redis is down)
* [Fix] http_parser: Refuse a message framed by both Content-Length and Transfer-Encoding
* [Fix] http_parser: Check Content-Length and chunk sizes before they overflow
* [Fix] http: Finish the last trailer of a chunked message and keep chunk framing out of encrypted inner bodies
* [Fix] http: Apply timeouts at the correct I/O stage
* [Fix] maps: Use the HTTP body length instead of the shared memory size (garbage in large chunked maps and their cache)
* [Fix] maps: Keep the previous map on failed reloads, reject truncated zstd frames and write the whole map on /savemap
* [Fix] maps: Skip the HTTP cache header when reading cdb maps
* [Fix] maps: Do not leak the shared memory mapping on errors
* [Fix] fuzzy_storage: Bound the TCP backlog, meter unauthenticated error replies and enforce key expiry for writes and deletes
[24 lines not shown]
openexr: update to 3.5.2.
Add post-release upstream patch to fix build on NetBSD, instead of
local patches.
Upstream now has NetBSD CI!
3.5.2 (October 2, 2026)
Patch release that introduces the use of OpenJPH's built-in LUT to
apply the decode/encode transfer function for lossy LJ2K compression.
:warning: WARNING: EXR files written by OpenEXR v3.5.0 and v3.5.1
using lossy LJ2K compression lack the LUT in their codestream and
should be regenerated. This v3.5.2 release includes a backwards
compatibility fallback so that such files can be successfully decoded,
but for best results, please regenerate any files using LJ2K written
by v3.5.0 and v3.5.1.
Also in this release:
[7 lines not shown]
libplist: update to 2.8.0.
Set TEST_TARGET.
Version 2.8.0
~~~~~~~~~~~~~
- Changes:
* Convert plist_array_set_item, plist_array_append_item, plist_array_insert_item,
plist_array_remove_item, plist_array_item_remove, plist_dict_set_item,
plist_dict_remove_item, and plist_dict_merge from void to plist_err_t return
type so that memory allocation and other errors can be reported
* Make #PLIST_ARRAY and #PLIST_DICT iterators opaque; add plist_array_free_iter
and plist_dict_free_iter to release them
* Add JSON coercion support for non-JSON plist types
* Add OpenStep coercion support for non-OpenStep plist types
* Add circular reference detection to all format writers
* Prevent deep nesting of plist structures in all input/output formats
* plistutil: Use getopt for solid option parsing
[29 lines not shown]