p5-GD: update to 2.91.
2.91 * t/affine.t: compare affineInvert(scale(2,3))'s result with an
epsilon (1e-6) instead of exact is_deeply, since -Duselongdouble
perls compute the division in extended precision, giving a
last-few-ULP-different 1/3 than a plain double (GH #68).
* Bumped $VERSION in GD::Image, GD::Image_pm.PL and GD::Polygon to
2.91, in sync with GD.pm; these were left un-bumped in 2.90.
2.90 * Add JXL, UHDR support for new libgd-2.4.0 (from git)
- JXL: newFromJxl/newFromJxlData readers, jxl() writer
(lossless/distance/effort), magic-byte autodetection in new().
- UHDR: new GD::UHDR class (newFromFile/newFromData, width/height/
hasGainMap, resize/crop/rotate/mirror, file/write, getSdr).
- Work around libgd 2.4.0 gd.h no longer declaring gdImageBoundsSafe().
* IMAGEQUANT: trueColorToPaletteSetMethod/SetQuality and the
GD_QUANT_* constants for the libimagequant-backed quantizer.
Guard for installations without libimagequant.
Fix imagequant feature autodetection in Makefile.PL (libimagequant
surfaces in gdlib.pc's Libs.private, not Requires.private).
[60 lines not shown]
libxkbcommon: buildlink libxml2
xkbregistry.pc has Requires.private: libxml-2.0
While marked as private, cmake still checks for libxml-2.0.pc and
fails if not found. Encountered while updating sysutils/deskflow to 1.27:
-- Package 'libxml-2.0', required by 'xkbregistry', not found
expat: update to 2.9.0.
Release 2.9.0 Mon October 5 2026
Security fixes:
#1392 CVE-2026-102633 -- Integer overflow in function
expat_realloc on 32bit platforms
#1393 CVE-2026-77214 -- Validate parameter `len` against available
buffer capacity in XML_ParseBuffer
Bug fixes:
#1387 lib: Handle OOM when copying encodingName in XML_ParserReset
New features:
#1327 lib: Introduce new "Properties API" to get and set
scalar properties for a single parser instance.
There are six new functions:
- XML_GetPropertyBool
- XML_GetPropertyDouble
- XML_GetPropertyUInt64
[50 lines not shown]
security/openssh: pull in fix from the main NetBSD source tree for PR#60563.
This tests for vwrite() instead of read() in atomicio.c, so
as to avoid the renaming shenanigans done by SSP of read().
Thanks to riastradh@ for pointing me in the right direction.
Bump PKGREVISION.
Update to 0.013
Upstream changes:
0.013 2024-10-18
- fixed extends not being cleaned up by "no Moo"
- rename internal role used to be in under the namespace of the main module
- fix the reported location of the error to be the caller
- fix object being partially constructed before checking arguments
- add -late option, allowing non-attribute arguments to be handled in BUILD
0.012 2024-10-16
- drop strictures prerequisite
- minor Pod cleanups
- revise Dist::Zilla packaging
Update to 1.82
Upstream changes:
1.82 2026-01-10 21:22:39 CET
* Fix compilations on 5.12 and earlier. (Grinnz)
1.81 2026-01-09 21:41:05 CET
* Fixed breakage from 1.80.
* Try to resolve wild dzil auto-version.
1.80 2026-01-09 11:39:15 CET
* Fixed problems with the multi-author feature in last release.
(Thanks, @ryoskzypu!)
1.79 2026-01-03 14:57:20 CET
* GH #79: `--force` will only overwrite files it needs to generate
* Minimum perl version in generated distros (and Module::Starter) is 5.8.3
* GH #25: Multiple authors are now supported (Hunter McMillen)
* GH #84: `Module::Starter::Simple::create_distro()` now returns files created
* Add `--github` option with issue tracker in README/POD, replacing CPANRatings
(Dimitrios Kechagias)
* Remove link to CPANRatings (lnation)
[2 lines not shown]