OpenBSD/src C5RMoqIusr.bin/ssh ssh-keysign.c

   repair ssh-keysign after pledge changes;
   spotted/tested by naddy@ ok deraadt@
VersionDeltaFile
1.80+4-4usr.bin/ssh/ssh-keysign.c
+4-41 files

OpenBSD/ports HDr5EHTwww/yt-dlp Makefile distinfo

   www/yt-dlp: update to 2026.03.17
VersionDeltaFile
1.77+2-2www/yt-dlp/Makefile
1.69+2-2www/yt-dlp/distinfo
+4-42 files

OpenBSD/ports 5DLalMDwww/py-yt-dlp-ejs distinfo Makefile

   www/py-yt-dlp-ejs: update to 0.8.0
VersionDeltaFile
1.5+2-2www/py-yt-dlp-ejs/distinfo
1.6+1-1www/py-yt-dlp-ejs/Makefile
+3-32 files

OpenBSD/ports cSr4c9unet/py-pf Makefile, net/py-pf/patches patch-pf__struct_py

   struct pf_queue_bwspec changed 'absolute' to uint64_t in pfvar.h 1.541
VersionDeltaFile
1.7+8-8net/py-pf/patches/patch-pf__struct_py
1.19+2-2net/py-pf/Makefile
+10-102 files

OpenBSD/src N7BE39Ousr.bin/openssl speed.c

   openssl speed: add benchmarking support for ML-KEM

   Add support for benchmarking ML-KEM key encapsulation mechanisms to
   openssl speed.  The following operations are measured:

   - key generation
   - encapsulation
   - decapsulation

   Two parameter sets are supported:

     mlkem768
     mlkem1024

   The benchmark can be invoked using the following options:

     mlkem       run all ML-KEM benchmarks
     mlkem768    run ML-KEM-768 benchmarks
     mlkem1024   run ML-KEM-1024 benchmarks

    [6 lines not shown]
VersionDeltaFile
1.51+179-2usr.bin/openssl/speed.c
+179-21 files

OpenBSD/src fEnV2hwlib/libcrypto cert.pem

   sync with Mozilla root CA store, ok tb@

   - remove CommScope CA (they requested it themselves;
   https://bugzilla.mozilla.org/show_bug.cgi?id=1994866)

   - add new cert:
   /C=HU/L=Budapest/O=Microsec Ltd./2.5.4.97=VATHU-23584497/CN=e-Szigno TLS Root CA 2023
VersionDeltaFile
1.34+41-173lib/libcrypto/cert.pem
+41-1731 files

OpenBSD/ports fJfY9kAwww/webkitgtk4 distinfo Makefile, www/webkitgtk4/patches patch-Source_WebCore_platform_graphics_gbm_MemoryMappedGPUBuffer_cpp

   Update to webkitgtk{41,60}-2.52.0.
VersionDeltaFile
1.10+1-8www/webkitgtk4/pkg/PFRAG.webkitgtk60
1.4+2-2www/webkitgtk4/patches/patch-Source_WebCore_platform_graphics_gbm_MemoryMappedGPUBuffer_cpp
1.143+2-2www/webkitgtk4/distinfo
1.254+1-1www/webkitgtk4/Makefile
1.37+0-1www/webkitgtk4/pkg/PLIST
1.9+1-0www/webkitgtk4/pkg/PFRAG.no-webkitgtk60
+7-146 files

OpenBSD/ports PFUZcdOtextproc/xmlwf distinfo Makefile

   update xmlwf to expat 2.7.5
VersionDeltaFile
1.13+4-4textproc/xmlwf/distinfo
1.21+1-1textproc/xmlwf/Makefile
+5-52 files

OpenBSD/ports pKuYz4Ftextproc/libxml Makefile, textproc/libxml/pkg PLIST

   the "@pkgpath textproc/libxml,-python" marker by itself isn't enough to merge
   any (now removed) py3-libxml-* packages into libxml, so python 3.12 -> 3.13
   updates (i.e. openbsd 7.8 -> -current) were still failing. Add an @conflict
   as well to force the old package to be removed.
VersionDeltaFile
1.246+1-0textproc/libxml/Makefile
1.44+1-0textproc/libxml/pkg/PLIST
+2-02 files

OpenBSD/ports NbefjUeprint/ghostscript/gnu distinfo Makefile, print/ghostscript/gnu/patches patch-configure

   print/ghostscript/gnu: Update to 10.07.0

   ok (with tweaks) sthen@
VersionDeltaFile
1.32+2-2print/ghostscript/gnu/distinfo
1.12+2-2print/ghostscript/gnu/patches/patch-configure
1.140+1-1print/ghostscript/gnu/Makefile
+5-53 files

OpenBSD/ports hcd2oeOcomms/rtl_433 Makefile

   cc1: error: unrecognized command line option "-Wvla"

   base-gcc doesn't have -Wvla. Move to ports-gcc to fix build on sparc64
VersionDeltaFile
1.2+4-0comms/rtl_433/Makefile
+4-01 files

OpenBSD/ports cHH9jWsgraphics/vulkan-tools distinfo Makefile

   missed to include vulkan-tools in the vulkan update, spotted by volker@
VersionDeltaFile
1.20+2-2graphics/vulkan-tools/distinfo
1.29+1-1graphics/vulkan-tools/Makefile
+3-32 files

OpenBSD/ports MrUjMszdevel/intellij Makefile distinfo

   devel/intellij: update to 2025.3.4
VersionDeltaFile
1.116+2-3devel/intellij/Makefile
1.82+2-2devel/intellij/distinfo
+4-52 files

OpenBSD/src kBaRI1Rusr.sbin/bgpd session_bgp.c

   remove extra spaces in logs, ok claudio
VersionDeltaFile
1.7+7-7usr.sbin/bgpd/session_bgp.c
+7-71 files

OpenBSD/ports gznhQc2mail/roundcubemail distinfo Makefile, mail/roundcubemail/pkg PLIST-main

   update to roundcubemail-1.6.14
   various security fixes, https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
VersionDeltaFile
1.7.4.2+27-0mail/roundcubemail/pkg/PLIST-main
1.95.2.3+2-2mail/roundcubemail/distinfo
1.191.2.3+1-2mail/roundcubemail/Makefile
+30-43 files

OpenBSD/ports XUqwT5rmail/roundcubemail distinfo Makefile, mail/roundcubemail/pkg PLIST

   update to roundcubemail-1.6.14
   various security fixes, https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
VersionDeltaFile
1.75+27-0mail/roundcubemail/pkg/PLIST
1.99+2-2mail/roundcubemail/distinfo
1.195+1-1mail/roundcubemail/Makefile
+30-33 files

OpenBSD/ports RBA1Xi9security Makefile

   py-omemo-dr was not linked to the build properly
VersionDeltaFile
1.777+1-0security/Makefile
+1-01 files

OpenBSD/ports A47rToqsecurity/py-omemo-dr Makefile

   py-omemo-dr: bump after HOMEPAGE change for pypi
VersionDeltaFile
1.7+1-1security/py-omemo-dr/Makefile
+1-11 files

OpenBSD/src OikH7Ahusr.sbin/bgpd util.c

   typo: Extended Nexhop Encoding (Nexthop)
VersionDeltaFile
1.99+2-2usr.sbin/bgpd/util.c
+2-21 files

OpenBSD/src IsJBD0iusr.bin/calendar calendar.c

   /dev/null is no longer implicitly permitted by some pledges, so explicitly
   unveil it. fixes calendar -a. ok deraadt
   calendar also needs to unveil cpp / sendmail, I forgot to make install
   when I was testing :(  from James J. Lippard
   sendmail/cpp only need "x" no "rx" unveil; ok deraadt
   from sthen@

   this is errata/7.7/029_calendar.patch.sig
VersionDeltaFile
1.37.28.2+7-1usr.bin/calendar/calendar.c
+7-11 files

OpenBSD/src XoMavKmusr.bin/calendar calendar.c

   /dev/null is no longer implicitly permitted by some pledges, so explicitly
   unveil it. fixes calendar -a. ok deraadt
   calendar also needs to unveil cpp / sendmail, I forgot to make install
   when I was testing :(  from James J. Lippard
   sendmail/cpp only need "x" no "rx" unveil; ok deraadt
   from sthen@

   this is errata/7.8/023_calendar.patch.sig
VersionDeltaFile
1.37.26.2+7-1usr.bin/calendar/calendar.c
+7-11 files

OpenBSD/ports FlTXxiewww/nghttp2 distinfo Makefile

   update to nghttp2-1.68.1
   https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6
VersionDeltaFile
1.68.2.1+2-2www/nghttp2/distinfo
1.77.2.1+1-1www/nghttp2/Makefile
+3-32 files

OpenBSD/ports TjzGXGkwww/nghttp2 distinfo Makefile

   update to nghttp2-1.68.1
   https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6
VersionDeltaFile
1.70+2-2www/nghttp2/distinfo
1.79+1-1www/nghttp2/Makefile
+3-32 files

OpenBSD/ports hPkQLJFnet/stayrtr distinfo Makefile

   update to stayrtr-0.6.4
VersionDeltaFile
1.7+2-2net/stayrtr/distinfo
1.10+1-1net/stayrtr/Makefile
+3-32 files

OpenBSD/ports EajEamUbooks/JLS distinfo Makefile

   Oof, JLS 25 is latest.
VersionDeltaFile
1.9+2-2books/JLS/distinfo
1.14+1-1books/JLS/Makefile
+3-32 files

OpenBSD/ports uYTh2Ovbooks/JLS distinfo Makefile

   Update JLS to JDK24.
VersionDeltaFile
1.8+2-2books/JLS/distinfo
1.13+1-1books/JLS/Makefile
+3-32 files

OpenBSD/ports mooRiKLtextproc/asciidoctor distinfo Makefile

   Minor bump asciidoctor 2.0.23 -> 2.0.26
VersionDeltaFile
1.5+2-2textproc/asciidoctor/distinfo
1.13+1-1textproc/asciidoctor/Makefile
+3-32 files

OpenBSD/src r6NHhMTlib/libexpat Changes, lib/libexpat/lib xmlparse.c expat_external.h

   Update libexpat to version 2.7.5.

   Relevant for OpenBSD are security fixes #1158 #1161 #1162 #1163,
   other changes #1156 #1153.  Library bump is not necessary.
   CVE-2026-32776 CVE-2026-32777 CVE-2026-32778

   tested and OK tb@
VersionDeltaFile
1.46+54-11lib/libexpat/lib/xmlparse.c
1.34+53-12lib/libexpat/Changes
1.10+31-1lib/libexpat/tests/misc_tests.c
1.9+27-3lib/libexpat/tests/basic_tests.c
1.3+27-0lib/libexpat/tests/nsalloc_tests.c
1.11+1-1lib/libexpat/lib/expat_external.h
+193-286 files not shown
+199-3412 files

OpenBSD/ports O9NgN55lang/python/3 Makefile, lang/python/3/files CHANGES.OpenBSD

   update to python-3.12.13 and patch for recent security fixes.
   backports from tb, .ok tb@ kmos@

   https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/
   Reject control characters in 'http.cookies.Morsel.update' (CVE-2026-3644)

   https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/
   Fix C stack overflow (CVE-2026-4224) when an Expat parser with a registered
   'ElementDeclHandler' parses inline DTD containing deeply nested content model.
VersionDeltaFile
1.2.2.1+23-35lang/python/3/patches/patch-Modules_pyexpat_c
1.1.2.1+15-21lang/python/3/patches/patch-Lib_test_test_pyexpat_py
1.1.2.1+15-16lang/python/3/patches/patch-Lib_test_test_http_cookies_py
1.1.2.1+12-10lang/python/3/patches/patch-Lib_http_cookies_py
1.15.2.1+4-1lang/python/3/Makefile
1.2.4.1+4-0lang/python/3/files/CHANGES.OpenBSD
+73-832 files not shown
+76-868 files

OpenBSD/ports b7cKapblang/python/3 Makefile, lang/python/3/patches patch-Lib_test_test_http_cookies_py patch-Lib_http_cookies_py

   update to python-3.13.12 and patch for recent security fixes. ok tb@ kmos@

   https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/
   Reject control characters in 'http.cookies.Morsel.update' (CVE-2026-3644)

   https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/
   Fix C stack overflow (CVE-2026-4224) when an Expat parser with a registered
   'ElementDeclHandler' parses inline DTD containing deeply nested content model.
VersionDeltaFile
1.1+79-0lang/python/3/patches/patch-Lib_test_test_http_cookies_py
1.1+71-0lang/python/3/patches/patch-Lib_http_cookies_py
1.2+65-1lang/python/3/patches/patch-Modules_pyexpat_c
1.1+47-0lang/python/3/patches/patch-Lib_test_test_pyexpat_py
1.11+17-0lang/python/3/pkg/PLIST-tests
1.23+1-5lang/python/3/Makefile
+280-63 files not shown
+288-89 files