NetBSD/pkgsrc qlZ0RcOsecurity/openssl Makefile PLIST

   openssl: updated to 3.6.4

   OpenSSL 3.6.4 is a security patch release. The most severe CVE fixed
   in this release is Moderate.

   This release incorporates the following bug fixes and mitigations:

   Fixed QUIC server being able to trigger double free when processing
   INITIAL packet.
   (CVE-2026-18798)

   Fixed heap buffer overflow in CMS key unwrapping.
   (CVE-2026-63072)

   Fixed invalid pointer dereference in CMP server via crafted protectionAlg.
   (CVE-2026-63076)

   Fixed unbounded memory growth in QUIC server incoming channel queue.
   (CVE-2026-14456)

    [27 lines not shown]
VersionDeltaFile
1.190+4-4security/openssl/distinfo
1.28+5-1security/openssl/PLIST
1.319+2-2security/openssl/Makefile
+11-73 files

NetBSD/pkgsrc 7m2dJbswww Makefile, www/wiki-tui DESCR distinfo

   Actually remove the package now
VersionDeltaFile
1.1934+1-2www/Makefile
1.23+1-1www/wiki-tui/distinfo
1.15+1-1www/wiki-tui/cargo-depends.mk
1.4+1-1www/wiki-tui/PLIST
1.29+1-1www/wiki-tui/Makefile
1.2+0-0www/wiki-tui/DESCR
+5-66 files

NetBSD/pkgsrc z2eFObLdoc CHANGES-2026

   doc: Updated net/croc to 11.3.2
VersionDeltaFile
1.5522+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc gzWemZunet/croc Makefile go-modules.mk

   croc: Update to 11.3.2

   Highlights
   Automatically advertises and negotiates experimental-derp-attach-group-v1 in normal supported builds.
   Two v11.3.2 peers use eight striped streams over four raw-direct paths with no flags.
   Mixed-version peers remain compatible through one-stream legacy Attach.
   Raw setup retains one-stream manager fallback, with croc relay fallback in automatic mode.

   11.3.1

   Highlights
   Pins derphole to github.com/schollz/derphole v0.18.2-croc.1 while preserving its upstream module identity.
   Adds modular AttachGroup bundle and lifecycle support for the qualified eight-stream/four-path topology.
   Keeps automatic AttachGroup advertisement disabled in this release; peers continue using compatible legacy DERP Attach until activation is qualified separately.
   Reduces CI cost by avoiding duplicate branch-push validation and reserving full cross-platform builds for main and manual runs.

   What’s Changed
   DERP transport: connection bundles, client-local providers, clean group-close handling, and safe striped-sender teardown.
   Benchmarks: consolidated 8/4 qualification data and benchmark-only build tagging.

    [2 lines not shown]
VersionDeltaFile
1.10+9-9net/croc/distinfo
1.10+2-2net/croc/go-modules.mk
1.43+1-1net/croc/Makefile
+12-123 files

NetBSD/pkgsrc 4ome3ysdoc CHANGES-2026

   doc: Updated www/resterm to 1.3.1
VersionDeltaFile
1.5521+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 3uRgbftwww/resterm Makefile go-modules.mk

   resterm: Update to 1.3.1

   Fixes
   Shorter request URLs
   The base-url setting
   Host and port targets
   Other fixes
VersionDeltaFile
1.34+135-129www/resterm/distinfo
1.25+44-42www/resterm/go-modules.mk
1.38+1-1www/resterm/Makefile
+180-1723 files

NetBSD/pkgsrc 8ctNDFVwww Makefile

   www/wiki-tui: remove pkg

   Abandoned upstream.
   Alternative available in tree, see www/wikid
VersionDeltaFile
1.1933+2-1www/Makefile
+2-11 files

NetBSD/pkgsrc QgKAsjYwww Makefile

   remove wiki-tui
VersionDeltaFile
1.1932+1-2www/Makefile
+1-21 files

NetBSD/pkgsrc WWMhnzsdoc CHANGES-2026

   doc: Updated sysutils/broot to 1.59.0
VersionDeltaFile
1.5520+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc vElPKdzsysutils/broot Makefile cargo-depends.mk

   sysutils/broot: update to 1.59.0

    - new shell_command verb attribute: run a command through a shell (sh -c / cmd /C) so &&, ; and pipes work, without leaving broot - Fix #1145
    - fix invalid official Mac binary (duplicate linked dylib) with new build chain - Fix #1194
    - Sixel graphics support for image preview, auto-detected: works in iterm2, Windows Terminal 1.22+ and Sixel-capable Unix terminals (foot, mlterm, xterm built
    with Sixel, recent WezTerm). Kitty remains the preferred protocol when available. Note: this requires broot to be compiled with sixel feature
    (eg cargo install broot --features sixel) - Fix #568 - Thanks @jamison-wilde
    - High-Res images in Rio terminal (detect it to enable the Kitty image protocol) - Fix #1179
    - fix content-exact match line number off-by-one when the match starts at the first byte of a line (broot jumped to the line above) - Thanks @YuriNachos
    - new :no_action internal, doing nothing, which can be used to disable a key - Fix #328
    - fix: detect a duplicate broot server name instead of silently overtaking the running server - Fix #1065 - Thanks @YuriNachos
    - fix preview transformers extension matching not working with double extensions such as .tar.gz - Fix #1195
    - strip escape sequences from displayed names to prevent OSC injections - Fix #1188 - Thanks @carfeii
    - fall back to numeric uid/gid instead of ???? when the user or group name can't be resolved, which is always the case on statically linked musl
    builds - Fix #1075
    - fix panic on a content regex matching the empty string at the end of a line ending with a control char (eg cr/$/ on a CRLF file)
    - fix Windows paths (containing backslashes) being mangled by the launcher's eval when using :cd and similar; also fixes escaping of paths containing
    a single quote - Fix #1100 - Thanks @Cyrus580529
    - fix br failing on Windows/PowerShell when the temp path contains a space (e.g. a space in the Windows username) - Fix #788 - Thanks @chinhkrb113

    [3 lines not shown]
VersionDeltaFile
1.128+493-454sysutils/broot/distinfo
1.112+163-150sysutils/broot/cargo-depends.mk
1.133+3-3sysutils/broot/Makefile
+659-6073 files

NetBSD/pkgsrc oKd0fK1doc CHANGES-2026

   doc: Updated net/ttl to 0.22.0
VersionDeltaFile
1.5519+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc vXc3gjVnet/ttl Makefile cargo-depends.mk

   net/ttl: update to 0.22.0

   What's Changed

       chore(deps): bump the cargo-dependencies group across 1 directory with 12 updates by @dependabot[bot] in #125
       chore(deps): bump the cargo-dependencies group across 1 directory with 3 updates by @dependabot[bot] in #127
       chore: clippy 1.98 nits (prerequisite) by @lance0 in #130
       chore(deps): bump lru 0.18.0 → 0.18.2 (LAN-1114) by @lance0 in #128
       perf(tui): skip snapshot+draw when idle (LAN-1222 experiment) by @lance0 in #129
       chore(tui): make the render fingerprint exhaustive over its inputs by @lance0 in #131
VersionDeltaFile
1.7+94-91net/ttl/distinfo
1.7+30-29net/ttl/cargo-depends.mk
1.7+2-2net/ttl/Makefile
+126-1223 files

NetBSD/pkgsrc 9NHlVV2doc CHANGES-2026

   doc: Updated math/py-lap to 0.5.13nb2
VersionDeltaFile
1.5518+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc jU9btNbmath/py-lap distinfo Makefile, math/py-lap/patches patch-__lapjv__cpp___lapjv.pyx

   py-lap: depend on fixed cython, remove workaround patch

   Bump PKGREVISION.
VersionDeltaFile
1.7+3-2math/py-lap/Makefile
1.4+1-2math/py-lap/distinfo
1.2+1-1math/py-lap/patches/patch-__lapjv__cpp___lapjv.pyx
+5-53 files

NetBSD/pkgsrc k0L0KEhdoc CHANGES-2026

   doc: Updated devel/py-cython to 3.3.0nb1
VersionDeltaFile
1.5517+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc Jxl8iUJdevel/py-cython Makefile distinfo, devel/py-cython/patches patch-Cython_Utility_ModuleSetupCode.c patch-Cython_Utility_Optimize.c

   py-cython: fix isfinite() problem using upstream patch.

   Bump PKGREVISION.
VersionDeltaFile
1.1+43-0devel/py-cython/patches/patch-Cython_Utility_Optimize.c
1.1+22-0devel/py-cython/patches/patch-Cython_Utility_ModuleSetupCode.c
1.102+3-1devel/py-cython/distinfo
1.122+2-1devel/py-cython/Makefile
+70-24 files

NetBSD/pkgsrc sjO8MHndoc CHANGES-2026

   Updated editors/xournalpp, archivers/par2
VersionDeltaFile
1.5516+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc BXSXipWarchivers/par2 Makefile distinfo

   par2: updated to 1.3.0

   1.3.0

   Issues:
     * Missing include src/utf8.h

   PRs:
     * Bump actions/checkout from 6 to 7
     * Bump cross-platform-actions/action from 1.2.0 to 1.3.0
     * Fix macOS unoptimised builds (more general building improvements for the github workflows)
     * Printing performance tweaks
VersionDeltaFile
1.30+4-4archivers/par2/distinfo
1.38+2-2archivers/par2/Makefile
+6-62 files

NetBSD/pkgsrc rtYIQXweditors/xournalpp Makefile distinfo

   xournalpp: updated to 1.3.7

   1.3.7

   This is a new minor version of Xournal++ with bug fixes and improvements from the community.

   Fixed Lua API changeToolColor not recognizing some tool names
   Fixed failing assertion when right clicking
   Updated translations
VersionDeltaFile
1.27+4-4editors/xournalpp/distinfo
1.104+2-2editors/xournalpp/Makefile
+6-62 files

NetBSD/pkgsrc vYGEfQfdoc CHANGES-2026

   Updated devel/msgpack, devel/protobuf-language-server
VersionDeltaFile
1.5515+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc jvn0lWzdevel/protobuf-language-server Makefile distinfo

   protobuf-language-server: updated to 0.1.8

   0.1.8
   Highlight full import line on command hover
VersionDeltaFile
1.7+4-4devel/protobuf-language-server/distinfo
1.24+2-3devel/protobuf-language-server/Makefile
+6-72 files

NetBSD/pkgsrc a6ktntLdevel/msgpack Makefile distinfo

   msgpack: updated to 7.0.2

   7.0.2
   Fix integer overflow on msgpack_unpacker_expand_buffer().
VersionDeltaFile
1.20+4-4devel/msgpack/distinfo
1.27+2-2devel/msgpack/Makefile
+6-62 files

NetBSD/pkgsrc Ym7NbJzdoc CHANGES-2026

   doc: Updated net/py-zeroconf to 0.150.0nb1
VersionDeltaFile
1.5514+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc CIjFEs8net/py-zeroconf Makefile PLIST

   py-zeroconf: adapt PLIST for cython 3.3.0

   cython 3.3.0 is more strict in checking signatures, which stops it
   building the C extension for py-zeroconf.

   Reported this upstream, remove the .so files from the PLIST for now.

   Bump PKGREVISION.
VersionDeltaFile
1.13+0-18net/py-zeroconf/PLIST
1.64+6-2net/py-zeroconf/Makefile
+6-202 files

NetBSD/pkgsrc cm5vhHmdoc CHANGES-2026

   doc: Updated biology/py-macs2 to 2.2.9.1nb3
VersionDeltaFile
1.5513+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 7ZjI4DKbiology/py-macs2 distinfo Makefile, biology/py-macs2/patches patch-MACS2_IO_CallPeakUnit.pyx

   py-macs2: fix build with Cython 3.3.0

   Bump PKGREVISION.
VersionDeltaFile
1.2+13-3biology/py-macs2/patches/patch-MACS2_IO_CallPeakUnit.pyx
1.5+2-2biology/py-macs2/distinfo
1.16+2-2biology/py-macs2/Makefile
+17-73 files

NetBSD/pkgsrc f2gtz2Ldoc CHANGES-2026

   doc: Updated devel/py-kivy to 2.3.1nb5
VersionDeltaFile
1.5512+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc WdTba6Gdevel/py-kivy distinfo Makefile, devel/py-kivy/patches patch-kivy_graphics_instructions.pyx

   py-kivy: fix build with Cython 3.3.0

   Bump PKGREVISION.
VersionDeltaFile
1.1+18-0devel/py-kivy/patches/patch-kivy_graphics_instructions.pyx
1.27+2-2devel/py-kivy/Makefile
1.6+2-1devel/py-kivy/distinfo
+22-33 files

NetBSD/pkgsrc EAyVDOldoc CHANGES-2026

   doc: Updated audio/fasttracker2 to 2.23
VersionDeltaFile
1.5511+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 1CIwLmVaudio/fasttracker2 Makefile distinfo, audio/fasttracker2/patches patch-src_ft2__diskop.c patch-CMakeLists.txt

   audio/fasttracker2: Update to 2.23

   Changes since 2.22:

   v2.23 - 23.08.2026
     * Fixed: If the "WAV exporting" screen was open, the "Render
       individual tracks" checkbox would have a much taller clickable
       area than it should, which could interfere with for example moving
       sample loops in the sample editor screen or interacting with the
       pattern editor.
     * Fixed: Several of the functions in Smp. Ed. -> Effects didn't set
       the "song is modified" flag.
     * Fixed: When zapping the song, the Disk Op. module filename wasn't
       reset
     * The Zap dialog's text was maybe a bit unclear. Changed from "Total
       devastation of the..." to "What do you want to clear?". Also
       changed the "All" button to "Everything".
VersionDeltaFile
1.12+20-30audio/fasttracker2/patches/patch-CMakeLists.txt
1.137+5-6audio/fasttracker2/distinfo
1.154+2-2audio/fasttracker2/Makefile
1.9+1-1audio/fasttracker2/patches/patch-src_ft2__diskop.c
+28-394 files