NetBSD/pkgsrc 2DFxIvfdoc TODO

   doc/TODO: + gmic-4.0.
VersionDeltaFile
1.27690+2-1doc/TODO
+2-11 files

NetBSD/pkgsrc jOrKVnNdoc CHANGES-2026

   doc: nerd-fonts update to 3.5.0
VersionDeltaFile
1.4951+21-1doc/CHANGES-2026
+21-11 files

NetBSD/pkgsrc Vmf0Novfonts/nerd-fonts-3270 distinfo, fonts/nerd-fonts-Agave distinfo

   nerd-fonts*: update to 3.5.0

   Three glyph set updates
   Finally Braille glyphs matching the 'cell' size exactly
   Two new fonts
   All fonts updated
VersionDeltaFile
1.4+4-4fonts/nerd-fonts-Hack/distinfo
1.7+4-4fonts/nerd-fonts-AurulentSansMono/distinfo
1.7+4-4fonts/nerd-fonts-Arimo/distinfo
1.7+4-4fonts/nerd-fonts-AnonymousPro/distinfo
1.7+4-4fonts/nerd-fonts-Agave/distinfo
1.7+4-4fonts/nerd-fonts-3270/distinfo
+24-2415 files not shown
+82-8221 files

NetBSD/pkgsrc IVEh0Dzcross/ppc-morphos-gcc Makefile, cross/ppc-morphos-gcc/files const-baserel.diff

   cross/ppc-morphos-gcc: Exclude DECL_ARTIFICIAL from .rodata -> .sdata move
VersionDeltaFile
1.12+2-2cross/ppc-morphos-gcc/Makefile
1.4+1-1cross/ppc-morphos-gcc/files/const-baserel.diff
+3-32 files

NetBSD/pkgsrc uOd73pFdoc TODO CHANGES-2026

   doc: Updated devel/pkgconf to 3.0.5
VersionDeltaFile
1.27689+1-2doc/TODO
1.4950+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc 5gcurwAdevel/pkgconf Makefile distinfo

   pkgconf: update to 3.0.5.

   Changes from 3.0.4 to 3.0.5:
   ----------------------------

   * Correctness fixes:
     - Shell quoting and backslash escapes in pc(5) properties are now consumed
       once, after variable substitution, instead of while splitting the property
       beforehand.  Quoting arriving from a variable is therefore treated like
       quoting written inline, --variable reports a value as the .pc file spells
       it, and fragments are escaped exactly once when rendered.  This supersedes
       the 3.0.4 fix, which unescaped whitespace at parse time and so hid the
       escaping from consumers such as cmake's FindPkgConfig.
       See https://github.com/pkgconf/pkgconf/issues/575 and
       https://github.com/pkgconf/pkgconf/issues/579.
     - Metadata queries no longer consult Conflicts rules between the modules named
       on the command line, as reporting metadata does not combine them into a
       build.  This covers --license, --license-file, --modversion, --path,
       --print-provides, --print-requires, --print-requires-private,

    [41 lines not shown]
VersionDeltaFile
1.36+4-4devel/pkgconf/distinfo
1.41+2-2devel/pkgconf/Makefile
+6-62 files

NetBSD/pkgsrc a7QKKtfdoc TODO

   doc/TODO: + pkgconf-3.0.5, prometheus-3.13.2, qtcreator-20.0.1.
VersionDeltaFile
1.27688+4-3doc/TODO
+4-31 files

NetBSD/pkgsrc 2KhXbCZdoc TODO CHANGES-2026

   doc: Updated security/libssh to 0.12.1
VersionDeltaFile
1.27687+1-2doc/TODO
1.4949+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc hXRT2X3security/libssh PLIST Makefile, security/libssh/patches patch-tests_torture.c

   libssh: update to 0.12.1.

   version 0.12.1 (released 2026-07-21)
    * Security:
      * CVE-2026-15370: Stack buffer overflow in SFTP server longname construction
      * CVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key
      * CVE-2026-59843: Denial of service via zero advertised channel packet size
      * CVE-2026-59844: Denial of service via oversized SFTP read length
      * CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure
      * CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion
      * CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification
      * CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs
      * CVE-2026-59849: Denial of service via automatic certificate authentication loop
      * CVE-2026-59850: Use-after-free via data callbacks on closed channels
      * CVE-2026-59851: Authentication bypass via missing GSSAPI principal check
      * Zero-initialize every ssh_string
    * Compatibility:
      * Fix compatibility with C23 / gcc16
      * Allow hybrid ML-KEM key exchange in FIPS mode

    [53 lines not shown]
VersionDeltaFile
1.3+7-7security/libssh/patches/patch-tests_torture.c
1.37+5-5security/libssh/distinfo
1.25+2-2security/libssh/PLIST
1.60+2-2security/libssh/Makefile
+16-164 files

NetBSD/pkgsrc D2vmayidoc CHANGES-2026 TODO

   doc: Updated emulators/mame to 0.289
VersionDeltaFile
1.27686+2-3doc/TODO
1.4948+2-1doc/CHANGES-2026
+4-42 files

NetBSD/pkgsrc Bgym99wemulators/mame Makefile distinfo

   mame: update to 0.289.

   After two long months, MAME 0.289 is ready, and it’s an undeniably
   massive update! But before we talk about emulation, there are a
   few more mundane things to mention. The sdljoy joystick input module
   now supports game controllers with up to 128 buttons. Finally,
   outputs have been overhauled, improving performance and fixing
   issues, but you may need to update your configuration if you’ve
   got external programs hooked up, and some artwork files may need
   updating.

   You’ll notice a number of systems and coprocessor cards based around
   NS32000 family CPUs are now working. If you aren’t familiar with
   it, the NS32000 architecture was one of the first single-chip CPU
   families with a 32-bit ALU. It used a highly orthogonal instruction
   set with clear influences from Digital Equipment Corporation’s
   earlier work. In retrospect, it didn’t have enough registers, the
   instruction encoding was too complex, it took them too long to
   overtake Motorola’s 68k family’s performance, and bugs in the

    [31 lines not shown]
VersionDeltaFile
1.168+4-4emulators/mame/distinfo
1.106+8-0emulators/mame/PLIST
1.233+2-3emulators/mame/Makefile
+14-73 files

NetBSD/pkgsrc wjHs7Jhcross/ppc-morphos-gcc Makefile, cross/ppc-morphos-gcc/files no-shrink-wrap-for-baserel.diff

   cross/ppc-morphos-gcc: Disable shrink wrap for baserel code
VersionDeltaFile
1.1+23-0cross/ppc-morphos-gcc/files/no-shrink-wrap-for-baserel.diff
1.11+3-2cross/ppc-morphos-gcc/Makefile
+26-22 files

NetBSD/pkgsrc Vixz2Jkdoc TODO CHANGES-2026

   doc: Updated textproc/moor to 2.16.2
VersionDeltaFile
1.27685+1-2doc/TODO
1.4947+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc srraY6Itextproc/moor Makefile go-modules.mk

   moor: update to 2.16.2.

   2.16.2

   Before this release, a file that the syntax highlighter saw as one
   single token -- a file holding nothing but a number, for example --
   came out with every character in the same color.

   With this release, highlighting that would look uniform is skipped and
   the text is shown plain. Thanks @knirch for reporting #445!

   Also in this release:

       On Windows, arrow and function keys now work immediately after
       returning from an editor opened with "v", instead of being ignored for
       up to a tenth of a second
       Faster .zst decompression on arm64 (Apple Silicon), and corrupt .zst
       input now reports an error rather than decoding to garbage
       Compressed files and streams are now properly closed, so moor no

    [31 lines not shown]
VersionDeltaFile
1.29+58-145textproc/moor/distinfo
1.10+18-47textproc/moor/go-modules.mk
1.43+2-3textproc/moor/Makefile
+78-1953 files

NetBSD/pkgsrc K3MPIpAmisc/kstars Makefile, multimedia/dvdauthor Makefile

   *: recursive bump for OpenJPH
VersionDeltaFile
1.52+2-2sysutils/fastfetch/Makefile
1.49+2-2multimedia/t-rec/Makefile
1.71+2-2multimedia/olive-editor/Makefile
1.20+2-2multimedia/frei0r/Makefile
1.110+2-2multimedia/dvdauthor/Makefile
1.101+2-2misc/kstars/Makefile
+12-1271 files not shown
+154-14677 files

NetBSD/pkgsrc AzmWncwdoc TODO CHANGES-2026

   doc: Updated graphics/OpenJPH to 0.31.0
VersionDeltaFile
1.27684+1-2doc/TODO
1.4946+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc I1nP6t1graphics/OpenJPH PLIST Makefile

   OpenJPH: update to 0.31.0.

   This release has a few fixes, new features, and many people contributed to it.
   Importantly, this release adds Qfactor.

   This release however breaks API and ABI.
VersionDeltaFile
1.13+4-4graphics/OpenJPH/distinfo
1.16+2-2graphics/OpenJPH/Makefile
1.8+1-2graphics/OpenJPH/PLIST
+7-83 files

NetBSD/pkgsrc QnGarusdoc TODO CHANGES-2026

   doc: Updated textproc/rumdl to 0.2.49
VersionDeltaFile
1.27683+1-2doc/TODO
1.4945+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc SD6yOKotextproc/rumdl cargo-depends.mk Makefile

   rumdl: update to 0.2.49.

   0.2.49 - 2026-08-02

   Security

       config: keep an extends target's path and contents out of messages about it (72bcb49)

       An extends value is expanded from the environment before it is resolved, so naming the resolved path in an error or warning printed environment variable values wherever that message went, which under CI is the build log. extends also points at an arbitrary path, so a target that is not valid TOML had its offending line quoted back. A file reached through extends is now named by the reference as written, and its own text is never repeated. A config you name yourself is unchanged, and rumdl config, the language server's report to its editor, and RUST_LOG=debug still show resolved paths.

       Reported privately by Shuvam Kumar.

   Fixed

       md072: keep every trailing newline when sorting frontmatter keys (a5e7c40)
       fix-utils: measure fix ranges against the content the rule read (2ed4238)
       md044: read a wikilink's display text, not the page name it hides (51d584e)
       md039: keep wikilinks and nested images intact when trimming link text (aabd859)
       md045,md057,md044: stop reporting wiki embeds as images (1147d17)

    [85 lines not shown]
VersionDeltaFile
1.47+7-4textproc/rumdl/distinfo
1.49+2-2textproc/rumdl/Makefile
1.19+1-0textproc/rumdl/cargo-depends.mk
+10-63 files

NetBSD/pkgsrc fHY6wVkdoc TODO CHANGES-2026

   doc: Updated graphics/zxing-cpp to 3.1.1
VersionDeltaFile
1.27682+1-2doc/TODO
1.4944+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc RcCB8VLgraphics/zxing-cpp Makefile distinfo

   zxing-cpp: update to 3.1.1.

   Patch release

       QRCode: improve Version 1 detection rate
       QRCode: fix detection regression in 3.1.0
       python: fix use of 'None' keyword usage and wrong '**kwargs' tag
       MicroPDF417: fix out of bounds access
       MultiFormatWriter: fix BarcodeFormat::Aztec and QRCodeModel2 support
       Android: make binary a little smaller (hidden symbols)
       PDF417: match codewords using integer arithmetic by @nyluke in #1138
       ReedSolomon: add missing header for GCC-16 by @parona-source in #1137
VersionDeltaFile
1.12+4-4graphics/zxing-cpp/distinfo
1.20+2-2graphics/zxing-cpp/Makefile
+6-62 files

NetBSD/pkgsrc iKi5irgdoc TODO CHANGES-2026

   doc: Updated www/py-websockets to 17.0.1
VersionDeltaFile
1.27681+1-2doc/TODO
1.4943+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc fkmj5k2www/py-websockets Makefile distinfo

   py-websockets: update to 17.0.1.

   trio support.
VersionDeltaFile
1.21+22-10www/py-websockets/PLIST
1.30+4-4www/py-websockets/distinfo
1.37+2-2www/py-websockets/Makefile
+28-163 files

NetBSD/pkgsrc X6UPzeIdoc TODO CHANGES-2026

   doc: Updated time/py-pytz to 2026.3.0.1
VersionDeltaFile
1.27680+1-2doc/TODO
1.4942+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc YMmJ1H0time/py-pytz Makefile distinfo

   py-pytz: update to 2026.3.0.1.

   Timezone updates.
VersionDeltaFile
1.65+4-4time/py-pytz/distinfo
1.73+3-3time/py-pytz/Makefile
+7-72 files

NetBSD/pkgsrc hiRRb05doc CHANGES-2026

   doc: Updated security/py-cryptography_vectors to 50.0.0
VersionDeltaFile
1.4941+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc xkW36q2security/py-cryptography_vectors Makefile distinfo

   py-cryptography_vectors: update to 50.0.0.

   Match py-cryptography.
VersionDeltaFile
1.37+9-0security/py-cryptography_vectors/PLIST
1.81+4-4security/py-cryptography_vectors/distinfo
1.84+2-2security/py-cryptography_vectors/Makefile
+15-63 files

NetBSD/pkgsrc hp5DYTwdoc TODO CHANGES-2026

   doc: Updated security/py-cryptography to 50.0.0
VersionDeltaFile
1.27679+1-2doc/TODO
1.4940+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc xE1N1ivsecurity/py-cryptography Makefile PLIST

   py-cryptography: update to 50.0.0.

   50.0.0 - 2026-07-31
   ~~~~~~~~~~~~~~~~~~~

   * **SECURITY ISSUE**:
     :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
     and its PEM and S/MIME variants no longer expose distinguishable errors or
     timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
     act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
     A random key is now substituted on failure, as described in :rfc:`3218`.
     Credit to **@X1AOxiang** for reporting the issue
   * Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
     Everything FFDH is deprecated, including the types in
     ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
     parameters with the key loading APIs. Users should migrate to a more
     modern key exchange algorithm.
   * Added ``xof()`` class methods to
     :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and

    [51 lines not shown]
VersionDeltaFile
1.120+34-34security/py-cryptography/distinfo
1.26+10-10security/py-cryptography/cargo-depends.mk
1.41+6-1security/py-cryptography/PLIST
1.148+2-2security/py-cryptography/Makefile
+52-474 files

NetBSD/pkgsrc VQn1VqBdoc TODO CHANGES-2026

   doc: Updated audio/py-beets to 2.13.1
VersionDeltaFile
1.27678+1-2doc/TODO
1.4939+2-1doc/CHANGES-2026
+3-32 files