FreeBSD/ports 23741b7ports-mgmt/poudriere-dsh2dsh distinfo Makefile

ports-mgmt/poudriere-dsh2dsh: Update 3.4.99.20260304 => 3.4.99.20260415

Upstream changes:
- Pkg 2.7.0 support
- write_atomic: Add a C implementation
- Hooks: Remove example.org
- Fix build on older releases

PR:             294575
Sponsored by:   UNIS Labs
DeltaFile
+3-3ports-mgmt/poudriere-dsh2dsh/distinfo
+1-1ports-mgmt/poudriere-dsh2dsh/Makefile
+1-0ports-mgmt/poudriere-dsh2dsh/pkg-plist
+5-43 files

FreeBSD/ports 965c6f7lang/python314 Makefile, lang/python314/files patch-gh-148169-fix-webbrowser-_action_substitution-bypass-of-dash-prefix-check

lang/python314: Fix incomplete mitigation of webbrowser.open()

Cherry-pick fix to resolve
Incomplete mitigation of CVE-2026-4519,
%action expansion for command injection to webbrowser.open()

Obtained from:  GitHub repo
                https://github.com/python/cpython/pull/148516
Security:       CVE-2026-4786
                cf75f572-378a-11f1-a119-e36228bfe7d4
DeltaFile
+66-0lang/python314/files/patch-gh-148169-fix-webbrowser-_action_substitution-bypass-of-dash-prefix-check
+1-1lang/python314/Makefile
+67-12 files

FreeBSD/ports 013edbclang/python314 pkg-plist Makefile, lang/python314/files patch-gh-148395-fix-possible-uaf-in-decompressors

lang/python314: Security update + other fixes

Fix critical use-after-free bug in LZMA/BZ2/ZLib decompressor routines
when reusing decompressor instances after a MemoryError was raised from
one.

While here:

- fix DEBUG build/package (several %%ABI%% were in the wrong place
  in pkg-plist that caused failed installs)
- switch to using system textproc/expat2 library
- issue warnings in pre-test that IPV6, PYMALLOC are required and
  DEBUG also breaks one self-test
- bump PORTREVISION
- drop LTOFULL again and make LTO use =full

References:
https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3
https://www.cve.org/CVERecord?id=CVE-2026-6100

    [6 lines not shown]
DeltaFile
+65-0lang/python314/files/patch-gh-148395-fix-possible-uaf-in-decompressors
+21-21lang/python314/pkg-plist
+18-11lang/python314/Makefile
+104-323 files

FreeBSD/ports 22584e7security/vuxml/vuln 2026.xml

security/vuxml: Add entry for Python CVE-2026-6100

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor
and gzip.GzipFile

Obtained from:  GitHub repo
Security:       b8e9f33c-375d-11f1-a119-e36228bfe7d4
                CVE-2026-6100
DeltaFile
+41-0security/vuxml/vuln/2026.xml
+41-01 files

FreeBSD/ports 97f22e4security/vuxml/vuln 2026.xml

security/vuxml: Add entry for Python CVE-2026-4786

Incomplete mitigation of CVE-2026-4519,
%action expansion for command injection to webbrowser.open()

Obtained from:  GitHub repo
Security:       CVE-2026-4786
                cf75f572-378a-11f1-a119-e36228bfe7d4
DeltaFile
+35-0security/vuxml/vuln/2026.xml
+35-01 files

FreeBSD/ports 75fdac0www/sogo Makefile pkg-plist, www/sogo/files patch-general.make patch-Tests_Unit_GNUmakefile

www/sogo: Update to 5.12.7

5.12.7 is a major release as it fixes 2 major vulnerabilities, 5.12.6
addresses another vulnerability.

While at it:
o pet portlint,
o make the installed configuration file for sysutils/logrotate useable
  out of the box by replacing sogo:sogo with sogod:sogod,
o make the installed sogo-backup.sh useable out of the box by:
  - correcting the path to sogo-tool,
  - changing the function definitions to match sh(1) syntax, saving a
    dependency on shells/bash, and
  - installing it as executable.

Approved by:    acm (maintainer)
Security:       https://www.sogo.nu/news/2026/sogo-v5126-released.html
Security:       https://www.sogo.nu/news/2026/sogo-v5127-released.html
Differential Revision:  https://reviews.freebsd.org/D56426
DeltaFile
+11-7www/sogo/Makefile
+17-0www/sogo/pkg-plist
+4-4www/sogo/files/patch-general.make
+4-3www/sogo/files/patch-Tests_Unit_GNUmakefile
+3-3www/sogo/files/patch-Tools_SOGoToolUpdateSecret.m
+3-3www/sogo/distinfo
+42-201 files not shown
+44-227 files

FreeBSD/ports f6b9067devel/sope distinfo Makefile, devel/sope/files patch-configure

devel/sope: Update to 5.12.7

This is a minor update, fixing contact searches containing 2 dots.
While at it, pet portlint.

Approved by:    acm (maintainer)
Differential Revision:  https://reviews.freebsd.org/D56425
DeltaFile
+3-3devel/sope/distinfo
+3-3devel/sope/files/patch-configure
+2-2devel/sope/Makefile
+8-83 files

FreeBSD/ports 460d9f3devel/cargo-readme distinfo Makefile.crates

devel/cargo-readme: Update to 3.3.2
DeltaFile
+113-129devel/cargo-readme/distinfo
+55-63devel/cargo-readme/Makefile.crates
+1-2devel/cargo-readme/Makefile
+169-1943 files

FreeBSD/ports 04460f5emulators/emu64 Makefile pkg-plist, emulators/emu64/files patch-src_widget__file__browse.h patch-src_src.pro

emulators/emu64: Remove from tree

Broken for months in tree and unmaintained

PR:             289037
DeltaFile
+0-36emulators/emu64/Makefile
+0-27emulators/emu64/pkg-plist
+0-13emulators/emu64/files/patch-src_widget__file__browse.h
+0-13emulators/emu64/pkg-message
+0-11emulators/emu64/files/patch-src_src.pro
+0-11emulators/emu64/files/patch-src_savepng.c
+0-1114 files not shown
+1-11610 files

FreeBSD/ports 063f3eemultimedia/lebiniou pkg-plist Makefile, multimedia/lebiniou-data pkg-plist Makefile

multimedia/lebiniou*: Remove from tree

Broken for months and last activity upstream in 2024

PR:             289066
DeltaFile
+0-1,721multimedia/lebiniou-data/pkg-plist
+0-133multimedia/lebiniou/pkg-plist
+0-46multimedia/lebiniou/Makefile
+0-20multimedia/lebiniou-data/Makefile
+0-14multimedia/lebiniou/pkg-descr
+0-6multimedia/lebiniou-data/pkg-descr
+0-1,9404 files not shown
+2-1,94810 files

FreeBSD/ports 6d72fbdaudio/soundtouch Makefile distinfo, audio/soundtouch/files patch-CMakeLists.txt

audio/soundtouch: Update to 4.0.1

* Add USES= pathfix to fix install location of pkgconfig file and
  make build logs consistent
* Change CFLAGS to CXXFLAGS for i386

PR:             294149
Approved by:    maintainer timeout, 2+ weeks
DeltaFile
+5-5audio/soundtouch/files/patch-CMakeLists.txt
+5-4audio/soundtouch/Makefile
+3-3audio/soundtouch/distinfo
+1-1audio/soundtouch/pkg-plist
+14-134 files

FreeBSD/ports 7702e88. MOVED, multimedia Makefile

multimedia/dvdstyler: Remove from tree

Broken in tree for months and last upstream activity in 2024

PR:             289482
DeltaFile
+0-334multimedia/dvdstyler/pkg-plist
+0-75multimedia/dvdstyler/Makefile
+0-12multimedia/dvdstyler/pkg-descr
+0-3multimedia/dvdstyler/distinfo
+0-1multimedia/Makefile
+1-0MOVED
+1-4256 files

FreeBSD/ports c1d6483www/libmicrohttpd distinfo Makefile, www/libmicrohttpd/files patch-src_microhttpd_connection.c patch-src_include_microhttpd.h

www/libmicrohttpd: Update to 1.0.4

Backport upstream commits 4f049186bfe22ba12c07279f2eef99293798a710 and
a083613d8405fa3ad7f6bc5bbbb635d0f50799e0

References:
https://git.gnunet.org/gnunet/libmicrohttpd/commit/4f049186bfe22ba12c07279f2eef99293798a710.html
https://git.gnunet.org/gnunet/libmicrohttpd/commit/a083613d8405fa3ad7f6bc5bbbb635d0f50799e0.html

Changelog: https://github.com/Karlson2k/libmicrohttpd/blob/d30316fda936111ad5d4f8b1fde7747c289468b6/ChangeLog

PR:             294534
Reviewed by:    Hung-Yi Chen <gaod at hychen.org> (maintainer)
DeltaFile
+16-0www/libmicrohttpd/files/patch-src_microhttpd_connection.c
+11-0www/libmicrohttpd/files/patch-src_include_microhttpd.h
+3-3www/libmicrohttpd/distinfo
+3-2www/libmicrohttpd/Makefile
+1-2www/libmicrohttpd/pkg-plist
+34-75 files

FreeBSD/ports fe66689net-im/vesktop Makefile

net-im/vesktop: Improve port

* Don't extract into WRKDIR
* Extract the files we want by using pipe instead of writing tarball
  to disk and then extracting it

PR:             294489
Reviewed by:    Céleste Ornato <celeste at ornato.com>
DeltaFile
+8-8net-im/vesktop/Makefile
+8-81 files

FreeBSD/ports 9b1cae6games/suika3 Makefile distinfo

games/suika3: Update to 26.04.9

PR:             294504
Approved by:    arrowd (co-mentor)
DeltaFile
+23-14games/suika3/Makefile
+3-3games/suika3/distinfo
+26-172 files

FreeBSD/ports a926302devel/aws-crt-cpp distinfo Makefile

devel/aws-crt-cpp: Update to 0.38.5

ChangeLog: https://github.com/awslabs/aws-crt-cpp/releases/tag/v0.38.5
DeltaFile
+3-3devel/aws-crt-cpp/distinfo
+1-1devel/aws-crt-cpp/Makefile
+4-42 files

FreeBSD/ports 7d8a9cearchivers/unadf distinfo Makefile

archivers/unadf: Update to 0.10.7

ChangeLog: https://github.com/adflib/ADFlib/releases/tag/v0.10.7
DeltaFile
+3-3archivers/unadf/distinfo
+1-1archivers/unadf/Makefile
+1-1archivers/unadf/pkg-plist
+5-53 files

FreeBSD/ports 0eda8c7editors/zile Makefile

editors/zile: Fix build after 852c6720

852c6720: "devel/libgnuregex: Fix building after gnulib update"
DeltaFile
+2-4editors/zile/Makefile
+2-41 files

FreeBSD/ports a52819caudio/libkcompactdisc pkg-plist Makefile, misc/minuet/files patch-CMakeLists.txt

KDE: Update KDE Gear to 26.04.0

Announcement: https://kde.org/announcements/gear/26.04.0/

Ports changes:

audio/libkcompactdisc:
 - Remove port, no longer shipped with KDE Gear

deskutils/kdeconnect-kde:
 - Add dependency on libei

misc/minuet:
 - Add missing dependencies
 - Add patch to restore parity with Linux

net/krdc:
 - Update dependencies


    [2 lines not shown]
DeltaFile
+114-0multimedia/kdenlive/pkg-plist
+0-79audio/libkcompactdisc/pkg-plist
+34-0net/mimetreeparser/pkg-plist
+27-0x11-fm/konqueror/pkg-plist
+0-20audio/libkcompactdisc/Makefile
+16-0misc/minuet/files/patch-CMakeLists.txt
+191-99275 files not shown
+945-871281 files

FreeBSD/ports a3462bb. MOVED

MOVED: Record removal of audio/libkcompactdisc
DeltaFile
+1-0MOVED
+1-01 files

FreeBSD/ports ed51ce6devel/umbrello pkg-plist

devel/umbrello: Fix PLIST_SUB abuse
DeltaFile
+9-9devel/umbrello/pkg-plist
+9-91 files

FreeBSD/ports fc76cb7. MOVED

MOVED: Record graphics/libkdcraw unflavorization
DeltaFile
+2-0MOVED
+2-01 files

FreeBSD/ports c83d351editors/calligra pkg-plist

editors/calligra: Fix PLIST_SUB abuse
DeltaFile
+1-1editors/calligra/pkg-plist
+1-11 files

FreeBSD/ports dce4742graphics/libkdcraw Makefile pkg-plist.qt5

graphics/libkdcraw: remove Qt5 flavor in preparation for Gear 26.04 update

Qt5 is not supported anymore.
DeltaFile
+6-13graphics/libkdcraw/Makefile
+0-18graphics/libkdcraw/pkg-plist.qt5
+18-0graphics/libkdcraw/pkg-plist
+0-18graphics/libkdcraw/pkg-plist.qt6
+24-494 files

FreeBSD/ports 30ffcf0graphics Makefile

graphics/Makefile: connect libkdcraw-qt5
DeltaFile
+1-0graphics/Makefile
+1-01 files

FreeBSD/ports bc5050dgraphics/krita Makefile

graphics/krita: switch to libkdcraw-qt5
DeltaFile
+2-1graphics/krita/Makefile
+2-11 files

FreeBSD/ports f073e90Mk/Uses kde.mk

Mk/Uses/kde.mk: libkdcraw is Qt6 only now
DeltaFile
+2-5Mk/Uses/kde.mk
+2-51 files

FreeBSD/ports 0a763c2graphics/libkdcraw-qt5 Makefile pkg-plist

graphics/libkdcraw-qt5: copy from graphics/libkdcraw at qt5

and stick to the last release with Qt5 support.
DeltaFile
+30-0graphics/libkdcraw-qt5/Makefile
+18-0graphics/libkdcraw-qt5/pkg-plist
+3-0graphics/libkdcraw-qt5/distinfo
+2-0graphics/libkdcraw-qt5/pkg-descr
+53-04 files

FreeBSD/ports dec5656Mk/Uses kde.mk

Uses/kde.mk: Update comment
DeltaFile
+5-2Mk/Uses/kde.mk
+5-21 files

FreeBSD/ports 25dc02fmail/mailpit distinfo Makefile, mail/mailpit/files patch-package-lock.json

mail/mailpit: Update to 1.29.7
DeltaFile
+16-16mail/mailpit/files/patch-package-lock.json
+7-7mail/mailpit/distinfo
+1-2mail/mailpit/Makefile
+24-253 files