Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (1m)  pkgsrc-2024Q1 (14d)  pkgsrc-2023Q4 (42d)  pkgsrc-2023Q2 (74d)  pkgsrc-2023Q3 (154d) 

2024-05-12 18:48:01 UTC Now

2018-04-28 23:32:52 UTC MAIN commitmail json YAML

2018-04-28 20:19:12 UTC MAIN commitmail json YAML

2018-04-28 20:15:29 UTC MAIN commitmail json YAML

doc: Updated print/poppler to 0.64.0

(wiz)

2018-04-28 20:15:18 UTC MAIN commitmail json YAML

poppler*: update to 0.64.0

Release 0.64.0
        core:
        * Workaround form field text not being drawn on broken files. Bug #103245
        * Add read only setter for form fields
        * Add support for Link Hide action
        * Add support for Next actions in Links
        * Fix parsing of Annot focus out actions
        * Fix PDFDoc::checkHeader() for PDFs smaller than 1 KiB. Bug #105674
        * Add const to several classes and members
        * gfile: Fix build on some platforms
        * Fix issues with on malformed documents. Bug #105972, #105969, #106059, #106061
        * Several small code improvements

        qt5:
        * Allow setting of Form visibility status
        * Allow setting of Form read only status
        * Add support for Link Hide action
        * Add support for Next actions in Links
        * ArthurOutputDev: Implement axialShadedFill
        * ArthurOutputDev: Implement drawImageMask. Bug #105531
        * ArthurOutputDev: Implement Type3 font support

        utils:
        * pdfsig: Add -dump which writes signatures to disk. Bug #104881

        glib:
        * less deprecated calls

        build system:
        * bring back the option to disable GObject introspection
        * Add iconv include dir when compiling
        * Make it possible to build poppler without fontconfig. Default for Android

(wiz)

2018-04-28 19:52:58 UTC MAIN commitmail json YAML

doc/TODO: add some

+ MesaLib-18.0.2, gimp-2.10, libjpeg-turbo-2.0, mysql-server-8.0,
  wine-devel-3.7.

(wiz)

2018-04-28 19:28:53 UTC MAIN commitmail json YAML

xfce4-tumbler: PKGREVISION bump for ffmpegthumbnailer bump

(wiz)

2018-04-28 19:28:30 UTC MAIN commitmail json YAML

doc: Updated multimedia/ffmpegthumbnailer to 2.2.0

(wiz)

2018-04-28 19:28:20 UTC MAIN commitmail json YAML

ffmpegthumbnailer: update to 2.2.0.

FFmpegThumbnailer 2.2.0
- New option to prefer embedded image metadata over video content (command line argument: -m)
- Fixed 'Resource temporarily unavailable' errors when using ffmpeg < 3.0

FFmpegThumbnailer 2.1.2
- Restored deinterlace functionality using the libavfilter library (additional ffmpeg dependency)
- Additional video mime types added to the thumbnailer file
- Take rotation metadata into account when generating thumbnails

FFmpegThumbnailer 2.1.1
- Buildable agains latest ffmpeg (currently breaks deinterlacing)
- Fallback when smart frame detection fails (thanks to johnnydeez)
- Add MPEG-TS (MTS) support (thanks to marcinn)

FFmpegThumbnailer 2.1.0
- The library is now completely silent on std out and err by default
- A callback can be registered to listen to logging messages
- Fixed cmake installation directories (thanks to Vallimar)
- Fixed dimension calculation for anamorphic streams (Thanks to Richard Zurad)
- Fixed static library filename

FFmpegThumbnailer 2.0.10
- Migrated to github
- Use cmake instead of autotools
- Remove stderr logging

FFmpegThumbnailer 2.0.9
- Fixed gio library loading issue
- Support udp sources (thanks to tchristensen)
- No longer support older ffmpeg versions

(wiz)

2018-04-28 19:10:34 UTC MAIN commitmail json YAML

doc: Updated www/webkit-gtk to 2.20.1

(wiz)

2018-04-28 19:10:13 UTC MAIN commitmail json YAML

webkit-gtk: update to 2.20.1.

WebKitGTK+ 2.20.1 released!

    Improve error message when Gigacage cannot allocate virtual memory.
    Add missing WebKitWebProcessEnumTypes.h to webkit-web-extension.h.
    Improve web process memory monitor thresholds.
    Fix a web process crash when the web view is created and destroyed quickly.
    Fix a network process crash when load is cancelled while searching for stored HTTP auth credentials.
    Fix the build when ENABLE_VIDEO, ENABLE_WEB_AUDIO and ENABLE_XSLT are disabled.
    Fix several crashes and rendering issues.
    Translation updates: Brazilian Portuguese, Czech.

WebKitGTK+ 2.20.0 released!

    New API to retrieve and delete cookies with WebKitCookieManager.
    New web process API to detect when form is submitted via JavaScript.
    Several improvements and fixes in the touch/gestures support.
    Support for the ���system��� CSS font family.
    Complex text rendering improvements and fixes.
    Added a low power mode.
    More complete and spec compliant WebDriver implementation.

(wiz)

2018-04-28 13:57:05 UTC MAIN commitmail json YAML

net/py-grpcio-tools: Add missing patch file

This should have been included in the import.

(minskim)

2018-04-28 13:18:08 UTC MAIN commitmail json YAML

doc: Updated sysutils/p5-File-Copy-Recursive to 0.44

(schmonz)

2018-04-28 13:18:03 UTC MAIN commitmail json YAML

Update to 0.44. From the changelog:

- Issue #18: fix t/05.legacy-pathmk_unc.t for recent updates (thanks zdm)
- pull request #16 - strip down list of prerequisites to modules that are safe to use high on
  the CPAN river (thanks karenetheridge)

(schmonz)

2018-04-28 12:30:21 UTC MAIN commitmail json YAML

doc: Updated emulators/PC6001VX to 2.33.0

(tsutsui)

2018-04-28 12:29:53 UTC MAIN commitmail json YAML

PC6001VX: update to 2.33.0.

pkgsrc changes:
* png files for README.html are no longer installed (embedded into the htlm)

Upstream changelog:

2.33.0 2018/04/28

* Support FFMpeg4.0.
* Changed Video Capture bitrate to YouTube recommended value.
  (video:4Mbps,audio:128Kbps)
* Embedded images to README.html. So doc folder is no longer distributed
  with Windows binary.

(tsutsui)

2018-04-28 09:41:04 UTC MAIN commitmail json YAML

doc: Added fonts/woff2 version 1.0.2

(wiz)

2018-04-28 09:40:54 UTC MAIN commitmail json YAML

fonts/Makefile: + woff2

(wiz)

2018-04-28 09:40:39 UTC MAIN commitmail json YAML

fonts/woff2: import woff2-1.0.2

This is a library for handling web fonts in the Web Open Font Format
(WOFF), version 2.0.

(wiz)

2018-04-28 06:59:41 UTC MAIN commitmail json YAML

2018-04-28 01:42:44 UTC MAIN commitmail json YAML

doc: Updated inputmethod/ibus and ibus-python to 1.5.18

(tsutsui)

2018-04-28 01:40:07 UTC MAIN commitmail json YAML

ibus, ibus-python: update to 1.5.18.

pkgsrc changes:
- explicitly specify USE_TOOLS+=gmsgfmt to handle msgfmt --desktop
- pull an upstream change to fix a configure bug in 1.5.18
- use a new unicode character database

Upstream changes (from https://github.com/ibus/ibus/releases):

1.5.18

* tools: Do not change keymaps with 'use-system-keyboard-layout' c360818
* src: Fix GVariant leaks (Carlos Garnacho) 1cbe867
* src: Added some error handlings from a code review f5e0752
* src: Add libgobject.so to LDADD for Debian libtool (Danny) a28fa74
* src: Reintroduce the hex mode keybind with an environment variable
  (Aaron Muir Hamilton) 88b9a93
* ui/gtk3: Translate input method name in ibus (Peng Wu) 0ab0dd3
* Added DBus filtering against malware bfe57d2
* Implement Unicode choice on Emojier e17c998 4cfd5ad d1ebb3d fc54b0c afe60c1
* Implement ibus-extension-gtk3 for the global keybinding fb07f64 c57b7c3
* Disable panel extension for 'gdm' and 'liveuser' user 7ccbd21 ece320b
* ui/gtk3: Set title string in gnome-shell 56c67b1
* Add ISSUE_TEMPLATE ff611a4 9f2699c
* Updated translations 366963d 73b420f

(tsutsui)

2018-04-28 01:24:46 UTC MAIN commitmail json YAML

doc: Added net/py-grpcio-tools version 1.11.0

(minskim)

2018-04-28 01:24:40 UTC MAIN commitmail json YAML

net/Makefile: Add py-grpcio-tools

(minskim)

2018-04-28 01:24:37 UTC MAIN commitmail json YAML

net/py-grpcio-tools: Import version 1.11.0

grpcio-tools is a package for gRPC Python tools.

(minskim)

2018-04-28 01:17:52 UTC MAIN commitmail json YAML

doc: Added net/py-grpcio version 1.11.0

(minskim)

2018-04-28 01:17:29 UTC MAIN commitmail json YAML

2018-04-28 01:16:30 UTC MAIN commitmail json YAML

2018-04-28 01:10:47 UTC MAIN commitmail json YAML

doc: Added textproc/unicode-character-database version 10.0.0

(tsutsui)

2018-04-28 01:09:17 UTC MAIN commitmail json YAML

textproc/Makefile: + unicode-character-database

(tsutsui)

2018-04-28 01:07:59 UTC MAIN commitmail json YAML

textproc/unicode-character-database: import unicode-character-database-10.0.0

The Unicode Character Database (UCD) consists of a number of data files
listing Unicode character properties and related data. It also includes
data files containing test data for conformance to several important
Unicode algorithms. Full documentation for the UCD can be found in
Unicode Standard Annex #44, Unicode Character Database.
http://www.unicode.org/reports/tr44/

These data files are required by the latest ibus-1.5.18.

(tsutsui)

2018-04-28 01:01:17 UTC MAIN commitmail json YAML

doc: Updated textproc/cldr-emoji-annotation to 33.0.0.1

(tsutsui)

2018-04-28 01:00:52 UTC MAIN commitmail json YAML

cldr-emoji-annotation: update to 33.0.0.1.

pkgsrc changes:

- use gmake to handle upstream configure.ac changes

Upstream announcement:
http://cldr.unicode.org/index/downloads/cldr-33

Unicode CLDR 33 provides an update to the key building blocks for
software supporting the world's languages. This data is used by all
major software systems for their software internationalization and
localization, adapting software to the conventions of different
languages for such common software tasks.

This release had a limited submission phase. The focus was on
improvements to emoji keywords and to the Odia and Assamese locales,
addition of typographic names data, and improvements to the structure
for specifying keyboard layouts.

(tsutsui)

2018-04-27 20:53:14 UTC MAIN commitmail json YAML

mk/tools/create.mk: revert filtering duplicate tool names

The "split" program is not managed by the tools framework. It just has a
wrapper that is placed into the same directory. This is confusing since
intuitively, "split" is a tool like many others.

The "duplicate script for target" warning from Make is therefore correct,
albeit obscure.

Currently, neither the pkgsrc infrastructure nor pkglint check for
allowed tool names.

(rillig)

2018-04-27 20:37:47 UTC MAIN commitmail json YAML

Add biology/ncbi-blast+

(bacon)

2018-04-27 20:30:24 UTC MAIN commitmail json YAML

Add ncbi-blast+

(bacon)

2018-04-27 20:28:28 UTC MAIN commitmail json YAML

2018-04-27 20:16:36 UTC MAIN commitmail json YAML

mk/tools/create.mk: sort tools before creating the wrapper targets

The TOOLS_CREATE variable is only ever appended to, without checking for
duplicates. In some rare cases, this produces warnings about
doubly-defined make targets. An example is adding USE_TOOLS+=strip to
pkgtools/pkglint:

".../mk/tools/create.mk" line 149: warning:
    duplicate script for target ".../work/.tools/bin/strip" ignored

The above line number 149 is zero-based, which in reality means the
duplicate definition is in line 150.

(rillig)

2018-04-27 20:00:20 UTC pkgsrc-2018Q1 commitmail json YAML

Mention last batch of pullup tickets

(bsiegert)

2018-04-27 19:53:52 UTC pkgsrc-2018Q1 commitmail json YAML

Pullup ticket #5738 - requested by morr
www/wordpress: security fix

Revisions pulled up:
- www/wordpress/Makefile                                        1.77
- www/wordpress/distinfo                                        1.62

---
  Module Name:    pkgsrc
  Committed By:  morr
  Date:          Mon Apr 16 10:22:10 UTC 2018

  Modified Files:
          pkgsrc/www/wordpress: Makefile distinfo

  Log Message:
  Update to version 4.9.5.

  This maintenance release fixes 28 bugs in 4.9, including fixes for Customizer, media library, error notices, and some security fixes. Twenty Seventeen bundled theme and Hello Dolly bundled plugin have also been updated.

  WordPress versions 4.9.4 and earlier are affected by three security issues.

  More changes at https://codex.wordpress.org/Version_4.9.5.

(bsiegert)

2018-04-27 17:48:39 UTC MAIN commitmail json YAML

doc: Updated net/grpc to 1.11.0

(minskim)

2018-04-27 17:47:27 UTC MAIN commitmail json YAML

net/grpc: Update to 1.11.0

Notable changes since 1.7.2:
- Requires protobuf>=3.5.0
- Exec_ctx has been made a thread_local, and is no longer to be passed
  as a function parameter.
- LB policies request re-resolution without shutting down
- On server, include receiving HTTP/2 settings in handshake timeout
- C++ headers are moved from include/grpc++ to include/grpcpp. Headers
  in include/grpc++ are deprecated
- Experimental gRPC-C++ Cocoapods podspec
- Several features of core have been removed from the surface or GPR
  API: grpc_alarm, gpr_join_host_port, gpr_cmdline, gpr_subprocess,
  gpr_tls, gpr_avl, and gpr_thd
- Add core underpinnings for TLS session ticket support
- Experimental support for configurable retries

(minskim)

2018-04-27 15:09:05 UTC MAIN commitmail json YAML

doc: Updated x11/gtk3 to 3.22.30

(wiz)

2018-04-27 15:08:55 UTC MAIN commitmail json YAML

gtk3+: update to 3.22.30.

Overview of Changes in GTK+ 3.22.30
===================================

* gtk-demo has a new 'Widgetbowl' demo

* The wayland backend now supports the stable xdg-shell protocol

* Bugs fixed:
  #28 Adwaita: Selection mode styling flickers
  #83 Completion popup on non-default GdkDisplay freezes GtkFileChooserDialog
  #88 GtkSpinButton: Buttons aren't de/sensitised as they were in GTK+ 3
#114 All Wayland apps crash when focused (gtk_gesture_multi_press_end→...
#129 Segfault in `wl_proxy_marshal()`
#132 GtkTextView auto-scrolling to insert mark upon focus changes due to...
#141 GtkEntry: add a way to set the font to monospace
#146 GtkExpander arrow is not dimmed when the Expander is not :sensitive
#156 Transfer annotation for gtk_gl_area_new is incorrect
#157 Crashes in gdkdisplay-wayland when clicking any button/menu item
#163 Unable to explicitly set GtkModelButton role
705509 notebook popup window on tabs shows underscores
745128 Search is useless for translated app names
748784 GtkProgressBar text cannot be superimposed on the progress bar
791939 Add xdg-shell (stable) support
792632 Emoji Chooser: section buttons have no tooltips
793062 Crash under gdk_wayland_window_attach_image()

(wiz)

2018-04-27 14:57:39 UTC MAIN commitmail json YAML

doc: Updated misc/calibre to 3.22.1

(wiz)

2018-04-27 14:57:30 UTC MAIN commitmail json YAML

calibre: update to 3.22.1.

- version: 3.22.1
  date: 2018-04-19

  new features:
    - title: "Edit book: Add a tool to upgrade books from EPUB 2 to EPUB 3 (Tools->Upgrade book internals)"
      description: "Automatically upgrades metadata, converts the NCX table of contents and adds required manifest annotations"
      type: major

    - title: "Add support for the FBZ format (zipped FB2)"

    - title: "Kindle driver: Change the height of generated thumbnails to 500px, needed for the Oasis 2017"

    - title: "Edit book: When bulk renaming files add an option to rename by the order in which the files appear in the book."

    - title: "Polishing: Recognize titlepages that are marked as covers in the EPUB 3 landmarks section"

    - title: "Edit Book: Automatically updated the modified timestamp in the OPF when saving EPUB 3 books."

    - title: "Remove the ISBNDB metadata plugin as ISBNDB no longer allows free lookups."

  bug fixes:
    - title: "EPUB 3 metadata: If the book defines more than one author sort value for an author use the first instead of the last"

    - title: "Check Book: Dont warn for nav document not in spine in EPUB 3 books"

    - title: "Linux installer: Fix umask question not working with the recommended install command because stdin is a pipe"

    - title: "Browser viewer: Show an error message when trying to use the Sync function without being logged in"

    - title: "When setting cover from a PDF file and the user clicks cancel, do not delete the existing cover"

(wiz)

2018-04-27 14:46:41 UTC MAIN commitmail json YAML

doc: Updated lang/vala to 0.40.4

(wiz)

2018-04-27 14:46:29 UTC MAIN commitmail json YAML

vala: update to 0.40.4.

Vala 0.40.4
===========
* Various improvements and bug fixes:
  - girparser: Add support for NoAccessorMethod metadata

* Bindings:
  - glib-2.0: Mark str parameter of Variant.take_string() as owned
  - gstreamer: Update from 1.15+ git master
  - gtk+-*.0: Set NoAccessorMethod on Gtk.Radio*.group properties
    (Regression in gtk+-3.0)
  - gtk+-4.0: Update to 3.93.0+fc6018f1
  - json-glib-1.0: Mark return-type of gvariant_deserialize*() as nullable
  - webkit2gtk-4.0: Update to 2.20.1

(wiz)

2018-04-27 14:38:52 UTC MAIN commitmail json YAML

doc: Updated security/py-certifi to 2018.4.16

(wiz)

2018-04-27 14:38:41 UTC MAIN commitmail json YAML

py-certifi: update to 2018.4.16.

No changelog found, assuming update to latest mozilla certs.

(wiz)

2018-04-27 14:37:21 UTC MAIN commitmail json YAML

doc: Updated graphics/py-cairo to 1.17.0

(wiz)

2018-04-27 14:37:09 UTC MAIN commitmail json YAML

py-cairo: update to 1.17.0.

1.17.0 - 2018-04-15
-------------------

* :class:`cairo.Surface` and :class:`cairo.Device` can now be used as context
  managers. :bug:`103`
* Fix a leak when a cairo error was raised.
* Fix a leak when a mapped surface was GCed instead of unmapped.
* Make it possible to use the C API with Python 3 outside of the compilation
  unit doing the import by defining ``PYCAIRO_NO_IMPORT``. :bug:`110`
* Implement PEP 561 (added a py.typed marker)

(wiz)

2018-04-27 14:26:51 UTC MAIN commitmail json YAML

doc: Updated graphics/libwebp to 1.0.0

(wiz)

2018-04-27 14:26:41 UTC MAIN commitmail json YAML

libwebp: update to 1.0.0.

- 4/2/2018: version 1.0.0
  This is a binary compatible release.
  * lossy encoder improvements to avoid chroma shifts in various circumstances
    (issues #308, #340)
  * big-endian fixes for decode, RGBA import and WebPPictureDistortion
  Tool updates:
    gifwebp, anim_diff - default duration behavior (<= 10ms) changed to match
                        web browsers, transcoding tools (issue #379)
    img2webp, webpmux - allow options to be passed in via a file (issue #355)

(wiz)

2018-04-27 14:26:32 UTC MAIN commitmail json YAML

mk: Describe tiff option.

(wiz)

2018-04-27 14:24:35 UTC MAIN commitmail json YAML

doc: Updated net/libsoup to 2.62.1

(wiz)

2018-04-27 14:24:26 UTC MAIN commitmail json YAML

libsoup: update to 2.62.1.

Changes in libsoup from 2.62.0 to 2.62.1:

* Fix digest authentication with encoded URIs
  [#794208, Claudio Saavedra]
* Avoid unaligned memory accesses in WebSocket implementation
  [#794421, Rolf Eike Beer]
* Use base domain to decide if cookies are third-party
  [#792130, Michael Catanzaro]
* Fix crash under soup_socket_new()
  [#762138, Milan Crha]

(wiz)

2018-04-27 14:19:36 UTC MAIN commitmail json YAML

doc: Updated devel/libgsf to 1.14.43

(wiz)

2018-04-27 14:19:29 UTC MAIN commitmail json YAML

Update GLPI to v9.2.3

From the release announcement:

* Hide closed tasks on central,
* Quick search in saved searches panel,
* Fix image in FAQ for anonymous users,
* Possibility to add an analytics javascript,
* Various fixes on components,
* And many more!

The full changelog is available here for more details:
https://github.com/glpi-project/glpi/milestone/24?closed=1

(hauke)

2018-04-27 14:19:25 UTC MAIN commitmail json YAML

libgsf: update to 1.14.43.

libgsf 1.14.43

Morten:
* Handle modtime for memory mapped files.

Corentin No�l and Rico Tzschichholz:
* Introspection fixes.

(wiz)

2018-04-27 14:16:34 UTC MAIN commitmail json YAML

doc: Updated textproc/gsed to 4.5

(wiz)

2018-04-27 14:16:23 UTC MAIN commitmail json YAML

gsed: update to 4.5.

* Noteworthy changes in release 4.5 (2018-03-31) [stable]

** Bug fixes

  sed now fails when matching very long input lines (>2GB).
  Before, sed would silently ignore the regex without indicating an
  error. [Bug present at least since sed-3.02]

  sed no longer rejects comments and closing braces after y/// commands.
  [Bug existed at least since sed-3.02]

  sed -E --posix no longer ignores special meaning of '+','?','|' .
  [Bug introduced in the original implementation of --posix option in
  v4.1a-5-gba68fb4]

  sed -i now creates selinux context based on the context of the symlink
  instead of the symlink target. [Bug present since at least sed-4.2]
  sed -i --follow-symlinks remains unchanged.

  sed now treats the sequence '\x5c' (ASCII 92, backslash) as literal
  backslash character, not as an escape prefix character.
  [Bug present since sed-3.02.80]
  Old behavior:
    $ echo z | sed -E 's/(z)/\x5c1/' # identical to 's/(z)/\1/'
    z
  New behavior:
    $ echo z | sed -E 's/(z)/\x5c1/'
    \1

(wiz)

2018-04-27 14:07:04 UTC MAIN commitmail json YAML

doc: Updated sysutils/liblognorm to 2.0.5

(fhajny)

2018-04-27 14:06:56 UTC MAIN commitmail json YAML

sysutils/liblognorm: Update to 2.0.5.

- bugfix: es_str2cstr leak in string-to v1 parser
- make "make check" "succeed" on solaris 10
- some mostly cosmetic fixes detected by Coverity Scan

(fhajny)

2018-04-27 14:02:49 UTC MAIN commitmail json YAML

doc: Updated security/vault to 0.10.1

(fhajny)

2018-04-27 14:02:41 UTC MAIN commitmail json YAML

security/vault: Update to 0.10.1.

DEPRECATIONS/CHANGES:

- `vault kv` and Vault versions: In 0.10.1 some issues with `vault kv` against
  v1 K/V engine mounts are fixed. However, using 0.10.1 for both the server
  and CLI versions is required.
- Mount information visibility: Users that have access to any path within a
  mount can now see information about that mount, such as its type and
  options, via some API calls.
- Identity and Local Mounts: Local mounts would allow creating Identity
  entities but these would not be able to be used successfully (even locally)
  in replicated scenarios. We have now disallowed entities and groups from
  being created for local mounts in the first place.

FEATURES:

- X-Forwarded-For support: `X-Forwarded-For` headers can now be used to set the
  client IP seen by Vault. See the TCP listener configuration
  page for details.
- CIDR IP Binding for Tokens: Tokens now support being bound to specific
  CIDR(s) for usage. Currently this is implemented in Token Roles; usage can be
  expanded to other authentication backends over time.
- `vault kv patch` command: A new `kv patch` helper command that allows
  modifying only some values in existing data at a K/V path, but uses
  check-and-set to ensure that this modification happens safely.
- AppRole Local Secret IDs: Roles can now be configured to generate secret IDs
  local to the cluster. This enables performance secondaries to generate and
  consume secret IDs without contacting the primary.
- AES-GCM Support for PKCS#11 [BETA] (Enterprise): For supporting HSMs,
  AES-GCM can now be used in lieu of AES-CBC/HMAC-SHA256. This has currently
  only been fully tested on AWS CloudHSM.
- Auto Unseal/Seal Wrap Key Rotation Support (Enterprise): Auto Unseal
  mechanisms, including PKCS#11 HSMs, now support rotation of encryption keys,
  and migration between key and encryption types, such as from AES-CBC to
  AES-GCM, can be performed at the same time (where supported).

IMPROVEMENTS:

- auth/approle: Support for cluster local secret IDs. This enables secondaries
  to generate secret IDs without contacting the primary
- auth/token: Add to the token lookup response, the policies inherited due to
  identity associations
- auth/token: Add CIDR binding to token roles
- cli: Add `vault kv patch`
- core: Add X-Forwarded-For support
- core: Add token CIDR-binding support
- identity: Add the ability to disable an entity. Disabling an entity does not
  revoke associated tokens, but while the entity is disabled they cannot be
  used.
- physical/consul: Allow tuning of session TTL and lock wait time
- replication: Dynamically adjust WAL cleanup over a period of time based on
  the rate of writes committed
- secret/ssh: Update dynamic key install script to use shell locking to avoid
  concurrent modifications
- ui: Access to `sys/mounts` is no longer needed to use the UI - the list of
  engines will show you the ones you implicitly have access to (because you have
  access to to secrets in those engines)

BUG FIXES:

- cli: Fix `vault kv` backwards compatibility with KV v1 engine mounts
- identity: Persist entity memberships in external identity groups across
  mounts
- identity: Fix error preventing authentication using local mounts on
  performance secondary replication clusters
- replication: Fix issue causing secondaries to not connect properly to a
  pre-0.10 primary until the primary was upgraded
- secret/gcp: Fix panic on rollback when a roleset wasn't created properly
- secret/gcp: Fix panic on renewal
- ui: Fix IE11 form submissions in a few parts of the application
- ui: Fix IE file saving on policy pages and init screens
- ui: Fixed an issue where the AWS secret backend would show the wrong menu
- ui: Fixed an issue where policies with commas would not render in the
  interface properly
- ui: Corrected the saving of mount tune ttls for auth methods
- ui: Credentials generation no longer checks capabilities before making
  api calls. This should fix needing "update" capabilites to read IAM
  credentials in the AWS secrets engine

(fhajny)

2018-04-27 13:53:08 UTC MAIN commitmail json YAML

doc: Updated databases/py-peewee to 3.3.1

(fhajny)

2018-04-27 13:52:59 UTC MAIN commitmail json YAML

databases/py-peewee: Update to 3.3.1.

- Fixed long-standing bug in 3.x regarding using column aliases with
  queries that utilize the ModelCursorWrapper (typically queries with
  one or more joins).
- Fix typo in model metadata code, thanks @klen.
- Add examples of using recursive CTEs to docs.

(fhajny)

2018-04-27 09:45:04 UTC MAIN commitmail json YAML

Updated lang/perl5, databases/p5-gdbm

(adam)

2018-04-27 09:44:27 UTC MAIN commitmail json YAML

perl5: updated to 5.26.2

5.26.2:

Security
[CVE-2018-6797] heap-buffer-overflow (WRITE of size 1) in S_regatom (regcomp.c)
A crafted regular expression could cause a heap buffer write overflow, with control over the bytes written.
[CVE-2018-6798] Heap-buffer-overflow in Perl__byte_dump_string (utf8.c)
Matching a crafted locale dependent regular expression could cause a heap buffer read overflow and potentially information disclosure.
[CVE-2018-6913] heap-buffer-overflow in S_pack_rec
pack() could cause a heap buffer write overflow with a large item count.
Assertion failure in Perl__core_swash_init (utf8.c)
Control characters in a supposed Unicode property name could cause perl to crash. This has been fixed.

Updated Modules and Pragmata
Module::CoreList has been upgraded from version 5.20170922_26 to 5.20180414_26.
PerlIO::via has been upgraded from version 0.16 to 0.17.
Term::ReadLine has been upgraded from version 1.16 to 1.17.
Unicode::UCD has been upgraded from version 0.68 to 0.69.

Selected Bug Fixes
The readpipe() built-in function now checks at compile time that it has only one parameter expression, and puts it in scalar context, thus ensuring that it doesn't corrupt the stack at runtime.
Fixed a use after free bug in pp_list introduced in Perl 5.27.1.
Parsing a sub definition could cause a use after free if the sub keyword was followed by whitespace including newlines (and comments).
The tokenizer now correctly adjusts a parse pointer when skipping whitespace in an ${identifier} construct.
Accesses to ${^LAST_FH} no longer assert after using any of a variety of I/O operations on a non-glob.
sort now performs correct reference counting when aliasing $a and $b, thus avoiding premature destruction and leakage of scalars if they are re-aliased during execution of the sort comparator.
Some convoluted kinds of regexp no longer cause an arithmetic overflow when compiled.
Fixed a duplicate symbol failure with -flto -mieee-fp builds. pp.c defined _LIB_VERSION which -lieee already defines.
A NULL pointer dereference in the S_regmatch() function has been fixed.
Failures while compiling code within other constructs, such as with string interpolation and the right part of s///e now cause compilation to abort earlier.

(adam)

2018-04-27 07:45:33 UTC MAIN commitmail json YAML

Updated textproc/py-natsort, www/py-raven

(adam)

2018-04-27 07:45:09 UTC MAIN commitmail json YAML

py-raven: updated to 6.7.0

6.7.0:
[Sanic] Added support for sanic.
[Core] Disabled dill logger by default
[Core] Added SENTRY_NAME, SENTRY_ENVIRONMENT and SENTRY_RELEASE environment variables
[Core] DSN secret is now optional
[Core] Added fix for cases with exceptions in repr
[core] Fixed bug with mutating record.data

(adam)

2018-04-27 07:00:41 UTC MAIN commitmail json YAML

py-natsort: updated to 5.3.0

5.3.0:
Fix bug in assessing fastnumbers version at import-time.
Add ability to consider unicode-decimal numbers as numbers.

(adam)

2018-04-27 06:57:40 UTC MAIN commitmail json YAML

Updated databases/py-sqlalchemy, databases/py-sqlalchemy-utils

(adam)

2018-04-27 06:57:21 UTC MAIN commitmail json YAML

py-sqlalchemy-utils: updated to 0.33.2

0.33.2:
Added support for universal wheels.
Fixed usage of template0 and template1 with postgres database functions.

(adam)

2018-04-27 06:51:55 UTC MAIN commitmail json YAML

py-sqlalchemy: updated to 1.2.7

SQLAlchemy release 1.2.7:
Release 1.2.7 includes some dialect-specific fixes as well as a small number of SQL and ORM related fixes.

(adam)

2018-04-27 06:47:50 UTC MAIN commitmail json YAML

Updated net/openvpn, security/py-m2crypto

(adam)

2018-04-27 06:47:25 UTC MAIN commitmail json YAML

py-m2crypto: updated to 0.30.0

0.30.0:
- Various small typos (Windows builds, Fix SSL.Connection.__del__)
- The project is now Linux-distribution agnostic
- Replace all old-style classes with the new ones (it shouldn't cause
  any problems, but feel free to file an issue, if it does)
- Do not by-pass a potential transfer decoding in m2urllib2
- Update M2Crypto.six with 1.11.0 and replace our local workarounds with
  new functions.
- SSLv3 just removed.
- Don't support Python 2.6 on Windows anymore. Windows users don't have
  python as a system package, so they are usually more likely to upgrade
  anyway.

(adam)

2018-04-27 06:40:28 UTC MAIN commitmail json YAML

openvpn: 2.4.6

OpenVPN 2.4.6
management: Warn if TCP port is used without password

Correct version in ChangeLog - should be 2.4.5, was mistyped as 2.4.4
Fix potential double-free() in Interactive Service (CVE-2018-9336)
preparing release v2.4.6 (ChangeLog, version.m4, Changes.rst)

manpage: improve description of --status and --status-version

Make return code external tls key match docs

Delete the IPv6 route to the "connected" network on tun close
Management: warn about password only when the option is in use
Avoid overflow in wakeup time computation

Add missing #ifdef SSL_OP_NO_TLSv1_1/2

Check for more data in control channel

(adam)

2018-04-27 06:01:08 UTC MAIN commitmail json YAML

multimedia/Makefile: add vlc2

(wiz)

2018-04-26 17:30:36 UTC MAIN commitmail json YAML

2018-04-26 15:47:33 UTC MAIN commitmail json YAML

doc: Updated lang/php70 to 7.0.30

(taca)

2018-04-26 15:46:57 UTC MAIN commitmail json YAML

lang/php70: update to 7.0.30

26 Apr 2018 PHP 7.0.30

- Exif:
  . Fixed bug #76130 (Heap Buffer Overflow (READ: 1786) in exif_iif_add_value).
  (Stas)

- iconv:
  . Fixed bug #76249 (stream filter convert.iconv leads to infinite loop on
    invalid sequence). (Stas)

- LDAP:
  . Fixed bug #76248 (Malicious LDAP-Server Response causes Crash). (Stas)

- Phar:
  . Fixed bug #76129 (fix for CVE-2018-5712 may not be complete). (Stas)

29 Mar 2018 PHP 7.0.29

- FPM:
  . Fixed bug #75605 (Dumpable FPM child processes allow bypassing opcache
    access controls). (Jakub Zelenka)

(taca)

2018-04-26 15:44:47 UTC MAIN commitmail json YAML

doc: Updated lang/php72 to 7.2.5

(taca)

2018-04-26 15:44:15 UTC MAIN commitmail json YAML

lang/php72: Reset PKGREVISION

(taca)

2018-04-26 15:43:39 UTC MAIN commitmail json YAML

doc: Updated lang/php71 to 7.1.17

(taca)

2018-04-26 15:43:03 UTC MAIN commitmail json YAML

lang/php72: update to 7.2.5

26 Apr 2018, PHP 7.2.5

- Core:
  . Fixed bug #75722 (Convert valgrind detection to configure option).
    (Michael Heimpold)

- Date:
  . Fixed bug #76131 (mismatch arginfo for date_create). (carusogabriel)

- Exif:
  . Fixed bug#76130 (Heap Buffer Overflow (READ: 1786) in exif_iif_add_value).
    (Stas)

- FPM:
  . Fixed bug #68440 (ERROR: failed to reload: execvp() failed: Argument list
    too long). (Jacob Hipps)
  . Fixed incorrect write to getenv result in FPM reload. (Jakub Zelenka)

- GD:
  . Fixed bug #52070 (imagedashedline() - dashed line sometimes is not visible).
    (cmb)

- intl:
  . Fixed bug #76153 (Intl compilation fails with icu4c 61.1). (Anatol)

- iconv:
  . Fixed bug #76249 (stream filter convert.iconv leads to infinite loop on
    invalid sequence). (Stas)

- ldap:
  . Fixed bug #76248 (Malicious LDAP-Server Response causes Crash). (Stas)

- mbstring:
  . Fixed bug #75944 (Wrong cp1251 detection). (dmk001)
  . Fixed bug #76113 (mbstring does not build with Oniguruma 6.8.1).
    (chrullrich, cmb)

- ODBC:
  . Fixed bug #76088 (ODBC functions are not available by default on Windows).
    (cmb)

- Opcache:
  . Fixed bug #76094 (Access violation when using opcache). (Laruence)

- Phar:
  . Fixed bug #76129 (fix for CVE-2018-5712 may not be complete). (Stas)

- phpdbg:
  . Fixed bug #76143 (Memory corruption: arbitrary NUL overwrite). (Laruence)

- SPL:
  . Fixed bug #76131 (mismatch arginfo for splarray constructor).
    (carusogabriel)

- standard:
  . Fixed bug #74139 (mail.add_x_header default inconsistent with docs). (cmb)
  . Fixed bug #75996 (incorrect url in header for mt_rand). (tatarbj)

(taca)

2018-04-26 15:42:15 UTC MAIN commitmail json YAML

lang/php: update php71 to 7.1.17

Oops, should be commited with previous one.

(taca)

2018-04-26 15:41:04 UTC MAIN commitmail json YAML

lang/php71: update to 7.1.17

26 Apr 2018, PHP 7.1.17

- Date:
  . Fixed bug #76131 (mismatch arginfo for date_create). (carusogabriel)

- Exif:
  . Fixed bug#76130 (Heap Buffer Overflow (READ: 1786) in exif_iif_add_value).
    (Stas)

- FPM:
  . Fixed bug #68440 (ERROR: failed to reload: execvp() failed: Argument list
    too long). (Jacob Hipps)
  . Fixed incorrect write to getenv result in FPM reload. (Jakub Zelenka)

- GD:
  . Fixed bug #52070 (imagedashedline() - dashed line sometimes is not visible).
    (cmb)

- iconv:
  . Fixed bug #76249 (stream filter convert.iconv leads to infinite loop on
    invalid sequence). (Stas)

- intl:
  . Fixed bug #76153 (Intl compilation fails with icu4c 61.1). (Anatol)

- ldap:
  . Fixed bug #76248 (Malicious LDAP-Server Response causes Crash). (Stas)

- mbstring:
  . Fixed bug #75944 (Wrong cp1251 detection). (dmk001)
  . Fixed bug #76113 (mbstring does not build with Oniguruma 6.8.1).
    (chrullrich, cmb)

- Phar:
  . Fixed bug #76129 (fix for CVE-2018-5712 may not be complete). (Stas)

- phpdbg:
  . Fixed bug #76143 (Memory corruption: arbitrary NUL overwrite). (Laruence)

- SPL:
  . Fixed bug #76131 (mismatch arginfo for splarray constructor).
    (carusogabriel)

- standard:
  . Fixed bug #75996 (incorrect url in header for mt_rand). (tatarbj)

(taca)

2018-04-26 13:43:17 UTC MAIN commitmail json YAML

doc: Updated devel/p5-Capture-Tiny to 0.48

(wiz)

2018-04-26 13:43:08 UTC MAIN commitmail json YAML

p5-Capture-Tiny: update to 0.48.

0.48      2018-04-22 09:01:08+02:00 Europe/Oslo

  - No changes from 0.47-TRIAL

0.47      2017-07-26 10:34:24-04:00 America/New_York (TRIAL RELEASE)

  [Fixed]

  - Appends PID to random file names for tee signalling to avoid
    random name collision when used in multiple forked children.

(wiz)

2018-04-26 13:34:14 UTC MAIN commitmail json YAML

doc: Updated devel/p5-B-Hooks-EndOfScope to 0.24

(wiz)

2018-04-26 13:34:05 UTC MAIN commitmail json YAML

p5-B-Hooks-EndOfScope: update to 0.24.

0.24      2018-04-21 14:11:08Z
  - no changes since last trial release

0.23      2018-03-17 23:33:09Z (TRIAL RELEASE)
  - improve use of constants in compile-time perl version checks

0.22      2018-03-17 19:31:37Z (TRIAL RELEASE)
  - Fix memory corruption on perls 5.8.0 - 5.8.3

(wiz)

2018-04-26 13:33:24 UTC MAIN commitmail json YAML

doc: Updated devel/p5-Async-Interrupt to 1.24

(wiz)

2018-04-26 13:33:16 UTC MAIN commitmail json YAML

p5-Async-Interrupt: update to 1.24.

1.24 Tue Apr 17 21:24:11 CEST 2018
- actually rewnew was missing, not wrongly documented. silly.

1.23 Tue Apr 17 21:18:24 CEST 2018
- ->renew is actually called ->post_fork, fix documentation.
        - use stability canary.

(wiz)

2018-04-26 13:32:11 UTC MAIN commitmail json YAML

doc: Updated devel/p5-App-cpanminus to 1.7044

(wiz)

2018-04-26 13:32:03 UTC MAIN commitmail json YAML

p5-App-cpanminus: update to 1.7044.

1.7044  2018-04-19 13:54:29 CEST
  [Improvements]
      - Support zip files with comments (skaji) #560
      - Use metacpan download_url API (haarg) #522

(wiz)

2018-04-26 13:31:18 UTC MAIN commitmail json YAML

doc: Updated devel/p5-Alien-Build to 1.41

(wiz)

2018-04-26 13:31:09 UTC MAIN commitmail json YAML

p5-Alien-Build: update to 1.41.

1.41      2018-04-24 06:19:18 -0400
  - before and after directives in alienfile triggers requirement on Alien::Build 1.40

1.40_01  2018-04-12 09:21:05 -0400
  - Add before and after directives to alienfile syntax

(wiz)

2018-04-26 13:26:12 UTC MAIN commitmail json YAML

Updated textproc/py-phonenumbers, finance/py-braintree

(adam)

2018-04-26 13:25:32 UTC MAIN commitmail json YAML

py-braintree: updated to 3.45.0

3.45.0
Add support for US Bank Account verifications API

(adam)

2018-04-26 13:23:36 UTC MAIN commitmail json YAML

py-phonenumbers: updated to 8.9.4

8.9.4:
The new release contains mostly metadata changes.

(adam)

2018-04-26 12:48:26 UTC MAIN commitmail json YAML

doc: Updated databases/p5-DB_File to 1.841

(wiz)

2018-04-26 12:48:12 UTC MAIN commitmail json YAML

p5-DB_File: update to 1.841.

1.841 2 Apr 2018

  * #124944 allow ppport.h-less builds in core

(wiz)

2018-04-26 12:47:41 UTC MAIN commitmail json YAML

doc: Updated converters/p5-JSON-MaybeXS to 1.004000

(wiz)

2018-04-26 12:47:33 UTC MAIN commitmail json YAML

p5-JSON-MaybeXS: update to 1.004000.

Depend on p5-Cpanel-JSON-XS.

1.004000 - 2018-04-19
- added true and false subs so they can be used via JSON::MaybeXS rather than
  only JSON() exported sub.

(wiz)

2018-04-26 12:45:52 UTC MAIN commitmail json YAML

doc: Added converters/p5-Cpanel-JSON-XS version 4.02

(wiz)

2018-04-26 12:45:43 UTC MAIN commitmail json YAML

converters/Makefile: + p5-Cpanel-JSON-XS

(wiz)

2018-04-26 12:45:19 UTC MAIN commitmail json YAML

converters/p5-Cpanel-JSON-XS: import p5-Cpanel-JSON-XS-4.02

This module converts Perl data structures to JSON and vice versa.
Its primary goal is to be *correct* and its secondary goal is to
be *fast*.  To reach the latter goal it was written in C.

As this is the n-th-something JSON module on CPAN, what was the
reason to write yet another JSON module? While it seems there are
many JSON modules, none of them correctly handle all corner cases,
and in most cases their maintainers are unresponsive, gone missing,
or not listening to bug reports for other reasons.

The cPanel fork has additional bug fixes and interoperability
improvements.

(wiz)

2018-04-26 09:39:18 UTC MAIN commitmail json YAML

spidermonkey185: Fix build on SunOS 64-bit.

SpiderMonkey makes assumptions about memory layout that break in a 64-bit SunOS
environment, so limit mmap() to the lower 32-bit address space.  Provides a
workaround for https://bugzilla.mozilla.org/show_bug.cgi?id=577056

(jperkin)

2018-04-26 07:57:40 UTC MAIN commitmail json YAML

Added multimedia/ffmpeg4, multimedia/ffplay4

(adam)

2018-04-26 07:56:58 UTC MAIN commitmail json YAML

ffmpeg4/ffplay4: added version 4.0

version 4.0:
- Bitstream filters for editing metadata in H.264, HEVC and MPEG-2 streams
- Dropped support for OpenJPEG versions 2.0 and below. Using OpenJPEG now
  requires 2.1 (or later) and pkg-config.
- VDA dropped (use VideoToolbox instead)
- MagicYUV encoder
- Raw AMR-NB and AMR-WB demuxers
- TiVo ty/ty+ demuxer
- Intel QSV-accelerated MJPEG encoding
- PCE support for extended channel layouts in the AAC encoder
- native aptX and aptX HD encoder and decoder
- Raw aptX and aptX HD muxer and demuxer
- NVIDIA NVDEC-accelerated H.264, HEVC, MJPEG, MPEG-1/2/4, VC1, VP8/9 hwaccel decoding
- Intel QSV-accelerated overlay filter
- mcompand audio filter
- acontrast audio filter
- OpenCL overlay filter
- video mix filter
- video normalize filter
- audio lv2 wrapper filter
- VAAPI MJPEG and VP8 decoding
- AMD AMF H.264 and HEVC encoders
- video fillborders filter
- video setrange filter
- nsp demuxer
- support LibreSSL (via libtls)
- AVX-512/ZMM support added
- Dropped support for building for Windows XP. The minimum supported Windows
  version is Windows Vista.
- deconvolve video filter
- entropy video filter
- hilbert audio filter source
- aiir audio filter
- aiff: add support for CD-ROM XA ADPCM
- Removed the ffserver program
- Removed the ffmenc and ffmdec muxer and demuxer
- VideoToolbox HEVC encoder and hwaccel
- VAAPI-accelerated ProcAmp (color balance), denoise and sharpness filters
- Add android_camera indev
- codec2 en/decoding via libcodec2
- muxer/demuxer for raw codec2 files and .c2 files
- Moved nvidia codec headers into an external repository.
  They can be found at http://git.videolan.org/?p=ffmpeg/nv-codec-headers.git
- native SBC encoder and decoder
- drmeter audio filter
- hapqa_extract bitstream filter
- filter_units bitstream filter
- AV1 Support through libaom
- E-AC-3 dependent frames support
- bitstream filter for extracting E-AC-3 core
- Haivision SRT protocol via libsrt
- segafilm muxer
- vfrdet filter

(adam)

2018-04-26 07:55:21 UTC MAIN commitmail json YAML

2018-04-26 07:53:40 UTC MAIN commitmail json YAML

Updated textproc/py-sphinx, time/py-pendulum

(adam)

2018-04-26 07:53:20 UTC MAIN commitmail json YAML

py-pendulum: updated to 1.5.1

1.5.1
Fixed set() not acception the tz keyword argument.
Fixed datetime() not setting the timezone to UTC by default.

1.5.0
Added the datetime() helper.
Added the set() method to set properties.
Added the is_utc() and is_local() methods.
year_(), month_(), day_(), hour_(), minute_(), second_(), microsecond_() are now deprecated.
timezone_() and tz_() are now deprecated.
timestamp_() is now deprecated.
with_date_time(), with_time_from_string() and with_timestamp() are now deprecated.
between() is now deprecated.
min_(), max_(), minimum(), maximum() are now deprecated.
is_today(), is_yesterday(), is_tomorrow() and is_same_day() are now depecreated.
is_sunday() -> is_saturday() are now deprecated.
The utc and local properties are now deprecated. Use is_utc() and is_local() instead.

(adam)

2018-04-26 07:49:29 UTC MAIN commitmail json YAML

py-sphinx: updated to 1.7.4

Release 1.7.4:
Bugs fixed
* domains: Crashed with duplicated objects
* latex: sphinx.writers.latex causes recusrive import

(adam)

2018-04-26 06:21:27 UTC MAIN commitmail json YAML

xfce4-orage: fix PKGREVISION

(markd)

2018-04-25 22:48:29 UTC MAIN commitmail json YAML

doc: Updated multimedia/phonon-qt5-backend-vlc to 0.9.0nb9

(kamil)

2018-04-25 22:48:18 UTC MAIN commitmail json YAML

phonon-qt5-backend-vlc: Bump PKGREVISION

Follow up dependency update for multimedia/phonon-backend-vlc.

(kamil)

2018-04-25 22:45:51 UTC MAIN commitmail json YAML

doc: Updated multimedia/phonon-backend-vlc to 0.9.0nb2

(kamil)

2018-04-25 22:45:40 UTC MAIN commitmail json YAML

phonon-backend-vlc: Switch dependency to multimedia/vlc2

Bump PKGREVISION.

(kamil)

2018-04-25 22:43:37 UTC MAIN commitmail json YAML

doc: Updated multimedia/kaffeine to 1.3.1nb8

(kamil)

2018-04-25 22:42:27 UTC MAIN commitmail json YAML

kaffeine: Switch dependency to multimedia/vlc2

Bump PKGREVISION to 8.

(kamil)

2018-04-25 22:39:48 UTC MAIN commitmail json YAML

doc: Added multimedia/vlc2 version 2.2.6

(kamil)

2018-04-25 22:39:02 UTC MAIN commitmail json YAML

multimedia/vlc2: import vlc2-2.2.6

VideoLAN is a project of French students from the Ecole Centrale Paris
and developers from all over the world. Its main goals is MPEG streaming
on a network, but it also features a standalone multimedia player. The
VideoLAN Server can stream video read from a hard disk, a DVD player,
a satellite card or an MPEG 2 compression card, and unicast or multicast
it on a network. The VideoLAN Client can read the stream from the network
and display it. It can also be used to display video read locally on
the computer : DVDs, VCDs, MPEG and DivX files and from a satellite
card. It is multi-plaform : Linux, Windows, Mac OS X, BeOS, BSD, Solaris,
QNX, iPaq... The VideoLAN Client and Server now have a full IPv6 support.

This package ships the 2.2.x version of VLC.

(kamil)

2018-04-25 21:44:44 UTC MAIN commitmail json YAML

2018-04-25 21:44:40 UTC MAIN commitmail json YAML

Removed multimedia/vlc20

(kamil)

2018-04-25 21:42:05 UTC MAIN commitmail json YAML

2018-04-25 21:38:53 UTC MAIN commitmail json YAML

2018-04-25 21:37:36 UTC MAIN commitmail json YAML

doc: Updated parallel/paexec to 1.1.0

(cheusov)

2018-04-25 21:37:11 UTC MAIN commitmail json YAML

Update paexec to 1.1.0

  paexec:
    - add new option -0. It works just like in "xargs -0".
    - add new option -J.
    - add new option -mw=.
    - fix help message display by -h.
    - -md= now allows no delimiter mode in -g mode.
    - -c and -C override each other if one is implied after another.

  Add new tool "paargs". It is a wrapper over paexec(1) that
  simplifies use of paexec.

  Fix transport_broken_rnd test script.

  This fixes regression test on Solaris.

  Update man page for paexec(1).

(cheusov)

2018-04-25 19:25:12 UTC MAIN commitmail json YAML

multimedia/x264-devel: Go back to disabled assembler on SunOS, fixes build.

(fhajny)

2018-04-25 16:44:01 UTC MAIN commitmail json YAML

doc: Updated www/drupal7 to 7.59

(taca)

2018-04-25 16:43:35 UTC MAIN commitmail json YAML

www/drupal7: update to 7.59

Drupal 7.59, 2018-04-25
-----------------------
- Fixed security issues (remote code execution). See SA-CORE-2018-004.

(taca)

2018-04-25 15:42:26 UTC MAIN commitmail json YAML

doc: Updated net/youtube-dl to 20180425

(leot)

2018-04-25 15:42:12 UTC MAIN commitmail json YAML

youtube-dl: Update net/youtube-dl to 20180425

pkgsrc changes:
- Adjust patches/patch-youtube__dl_postprocessor_ffmpeg.py to prefer ffmpeg3
  over ffmpeg2

Changes:
version 2018.04.25

Core
* [utils] Fix match_str for boolean meta fields
+ [Makefile] Add support for pandoc 2 and disable smart extension (#16251)
* [YoutubeDL] Fix typo in media extension compatibility checker (#16215)

Extractors
+ [openload] Recognize IPv6 stream URLs (#16136, #16137, #16205, #16246,
  #16250)
+ [twitch] Extract is_live according to status (#16259)
* [pornflip] Relax URL regular expression (#16258)
- [etonline] Remove extractor (#16256)
* [breakcom] Fix extraction (#16254)
+ [youtube] Add ability to authenticate with cookies
* [youtube:feed] Implement lazy playlist extraction (#10184)
+ [svt] Add support for TV channel live streams (#15279, #15809)
* [ccma] Fix video extraction (#15931)
* [rentv] Fix extraction (#15227)
+ [nick] Add support for nickjr.nl (#16230)
* [extremetube] Fix metadata extraction
+ [keezmovies] Add support for generic embeds (#16134, #16154)
* [nexx] Extract new azure URLs (#16223)
* [cbssports] Fix extraction (#16217)
* [kaltura] Improve embeds detection (#16201)
* [instagram:user] Fix extraction (#16119)
* [cbs] Skip DRM asset types (#16104)

version 2018.04.16

Extractors
* [smotri:broadcast] Fix extraction (#16180)
+ [picarto] Add support for picarto.tv (#6205, #12514, #15276, #15551)
* [vine:user] Fix extraction (#15514, #16190)
* [pornhub] Relax URL regular expression (#16165)
* [cbc:watch] Re-acquire device token when expired (#16160)
+ [fxnetworks] Add support for https theplatform URLs (#16125, #16157)
+ [instagram:user] Add request signing (#16119)
+ [twitch] Add support for mobile URLs (#16146)

(leot)

2018-04-25 15:24:07 UTC MAIN commitmail json YAML

doc: Updated time/todotxt to 2.11.0

(leot)

2018-04-25 15:23:55 UTC MAIN commitmail json YAML

todotxt: Update time/todotxt to 2.11.0

pkgsrc changes:
- Add support for the test suite (this needs gmake as a test tool dependency)
- Fix the shebang of test shell script with REPLACE_BASH and also add a
  SUBST to fix a shebang in the middle of scripts (needed in shell script part
  of the test suite).
  REPLACE_INTERPRETER only adjust the shebang in the first line of the file.
- Add patches/patch-tests_test-lib.sh to just use `date -r' in non-GNU and
  non-macOS lands. By default the current date is used and then the test will
  definitely fails. While there are no guarantees that the date(1) available on
  the system supports `-r' option it is probably better to try using it (indeed
  this make all the date tests happy on NetBSD and probably also on FreeBSD and
  OpenBSD according a quick skim of their date(1) man pages).
- Also install USAGE.md document (it is referenced by README.md).

Changes:
## [2.11.0] - 2018-03-26
### Added
- Added support for `$XDG_CONFIG_HOME` config file/actions location
- Created [CODE_OF_CONDUCT.md](/CODE_OF_CONDUCT.md) ([#217])
- Created [CHANGELOG.md](/CHANGELOG.md) ([#218])

### Changed
- Updated `add` command to accept lowercase priority ([#230])
- Clean tests and version file in Makefile. Don't ignore errors in tests.
- Updated [README.md](/README.md) ([#219])
- Update Downloads links to point at the Releases page ([#228])
- Set the executable bit when preparing releases ([#156])

### Fixes
- Update links to use https
- Suppress todo.sh error messages when invoked during completion ([#8])

(leot)

2018-04-25 12:57:44 UTC MAIN commitmail json YAML

doc: Updated audio/asunder to 2.8

(triaxx)

2018-04-25 12:57:24 UTC MAIN commitmail json YAML

asunder: update to 2.8.

pkgsrc: add options.mk for optional encoders

Changes:
3 Oct 2015 - 2.8
=================
- Updates to Sweedish, Norwegian, Russian, and Danish translations.
- Fixed a couple of (unlikely) memory corruption bugs and some minor memory leaks.

26 Jan 2015 - 2.7
=================
- Added an option (enabled by default) to rip much faster.

24 Nov 2014 - 2.6
=================
- Added 64 translations generated by the OSTD ( http://littlesvr.ca/ostd ): Afrikaans, Amharic, Aragonese, Assamese, Azerbaijani, Belarusian, Bengali, Breton, Welsh, Dzongkha, Persian, Fulah, Faroese, Western, Irish, Gujarati, Hindi, Haitian, Armenian, Interlingua, Indonesian, Icelandic, Georgian, Kazakh, Centra, Korean, Kurdish, Kirghiz, Latin, Luxembourgish, Ganda, Lithuanian, Malagasy, Macedonian, Malayalam, Mongolian, Marathi, Malay, Burmese, Nepali, Occitan, Oriya, Panjabi, Pushto, Romanian, Kinyarwanda, Sinhala, Tamil, Telugu, Thai, Turkmen, Tagalog, Tatar, Uighur, Ukrainian, Urdu, Uzbek, Uzbek (Cyrillic), Vietnamese, Walloon, Wolof, Xhosa, Yiddish, and Zulu
- Updated Simplified Chinese, Czeck, Italian, and Norwegean translations.

(triaxx)

2018-04-25 12:25:00 UTC MAIN commitmail json YAML

Updated www/py-cheroot, www/py-cherrypy

(adam)

2018-04-25 12:24:40 UTC MAIN commitmail json YAML

py-cherrypy: updatede to 14.2.0

v14.2.0
* :issue:1680 via :pr:1683: HTTP Basic Auth supports :rfc:7617 UTF-8
  charset decoding where possible. Uses latin1 as a fallback.

v14.1.0
* :cr-pr:37: Add support for peercreds lookup over UNIX domain socket.
  This enables app to automatically identify "who's on the other
  end of the wire".

  This is how you enable it::

    server.peercreds: True
    server.peercreds_resolve: True

  The first option will put remote numeric data to WSGI env vars:
  app's PID, user's id and group.

  Second option will resolve that into user and group names.

  To prevent expensive syscalls, data is cached on per connection
  basis.

(adam)

2018-04-25 12:23:49 UTC MAIN commitmail json YAML

py-cheroot: updated to 6.2.4

v6.2.4

- Fix missing resolve_peer_creds argument in
  :py:class:cheroot.wsgi.Server being bypassed into
  :py:class:cheroot.server.HTTPServer.

- :pr:85: Revert conditional dependencies. System packagers should
  honor the dependencies as declared by cheroot, which are defined
  intentionally.

(adam)

2018-04-25 12:20:54 UTC MAIN commitmail json YAML

pkg_install-20180425: correctly detect package names in PKG_DBDIR

If PKG_DBDIR is /foo and a path like /foobar is given, it is not below
PKG_DBDIR, so don't translate it into a package name look up. The old
logic for giving a path to PKG_DBDIR remains for legacy compat.

(joerg)

2018-04-25 12:12:52 UTC MAIN commitmail json YAML

doc: Updated databases/py-peewee to 3.3.0

(fhajny)

2018-04-25 12:12:43 UTC MAIN commitmail json YAML

databases/py-peewee: Update to 3.3.0. Clean up.

- Added support for SQLite's new ON CONFLICT clause, which is modelled
  on the syntax used by Postgresql and will be available in SQLite
  3.24.0 and onward.
- Added better support for using common table expressions and a
  cleaner way of implementing recursive CTEs, both of which are also
  tested with integration tests (as opposed to just checking the
  generated SQL).
- Modernized the CI environment to utilize the latest MariaDB
  features, so we can test window functions and CTEs with MySQL (when
  available).
- Reorganized and unified the feature-flags in the test suite.

(fhajny)

2018-04-25 11:27:31 UTC MAIN commitmail json YAML

texlive-collection-latexextra: add tex-changes

(markd)

2018-04-25 11:25:51 UTC MAIN commitmail json YAML

texlive-collection-plaingeneric: add tex-lambda-lists

(markd)

2018-04-25 11:17:23 UTC MAIN commitmail json YAML

update tex-pgfgantt{,-doc} and add tex-changes{,-doc}

(markd)

2018-04-25 11:13:07 UTC MAIN commitmail json YAML

tex-pgfgantt{,-doc}: update to 5.0

This major update includes:
* a new key 'decade' for \gantttitlecalendar
* a new key 'time slot unit' for using one day, month or year per time
slot; this key replaces 'compress calendar' % a new macro \ganttvrule
for drawing arbitrary vertical rules (similar to the today rule), as
well as associated keys 'vrule', 'vrule offset', 'vrule label font',
and 'vrule label text' % a new key 'expand chart', which specifies that
a chart should expand horizontally to a given dimension % a new key
'title label text', which allows fine-tuning of title label formatting
% compatibility with the amsgen package

(markd)

2018-04-25 11:05:20 UTC MAIN commitmail json YAML

tex-lambda-lists: add TEXLIVE_REV HOMEPAGE and LICENSE

(markd)

2018-04-25 11:02:42 UTC MAIN commitmail json YAML

print: add tex-changes{,-doc}

(markd)

2018-04-25 11:00:45 UTC MAIN commitmail json YAML

tex-changes{,-doc}: add version 2.0.4

The package allows the user to manually markup changes of text,
such as additions, deletions, or replacements. Changed text is
shown in a different colour; deleted text is crossed out. The
package allows definition of additional authors and their
associated colour. It also allows you to define a markup for
authors or annotations. A bash script is provided for removing
the changes.

(markd)

2018-04-25 08:08:43 UTC MAIN commitmail json YAML

Updated emulators/qemu, textproc/py-sphinx

(adam)

2018-04-25 08:08:21 UTC MAIN commitmail json YAML

py-sphinx: updated to 1.7.3

1.7.3:
Bugs fixed
* autodoc loses the first staticmethod parameter
* autosummary: too wide two column tables in PDF builds
* Latex customization via _templates/longtable.tex_t is broken
* imgconverter: confused by convert.exe of Windows
* On windows, Sphinx crashed when drives of srcdir and outdir are different
* autodoc ignores type annotated variables
* wrong URLs on warning messages
* latex: latex_show_urls assigns incorrect footnote numbers if hyperlinks exists inside substitutions
* latex with class memoir Error: Font command \sf is not supported
* latex: too slow in proportion to number of auto numbered footnotes
* htmlhelp: The entries in .hhp file is not ordered
* toctree directive tries to glob for URL having query_string
* html search: Upper characters problem in German
* latex: Compilation for German docs failed with LuaLaTeX and XeLaTeX
* duplicated labels detector does not work well in parallel build
* Crashed with extension which returns invalid metadata

(adam)

2018-04-25 07:56:05 UTC MAIN commitmail json YAML

qemu: updated to 2.12.0

2.12.0:

Incompatible changes
The deprecated CLI options "-tdf", "-no-kvm-pit" and "-drive boot=on|off" have been removed (they only emitted a warning since QEMU 1.3.0).
The deprecated CLI option "-net channel" has been removed. You can use "-netdev user,guestfwd=..." instead.
The deprecated CLI option "-hdachs" has been removed. You can specify the disk geometry e.g. via -device ide-hd,cyls=c,heads=h,secs=s instead.
The deprecated way of configuring SCSI devices with "-drive if=scsi" on x86 has been removed. Use an appropriate SCSI controller together "-device scsi-hd" or "-device scsi-cd" and a corresponding "-blockdev" parameter instead.
The deprecated way of configuring a "host", "serial", "disk" or "net" USB device with "-usbdevice" has been removed. Use "-device usb-..." instead.
The deprecated HMP commands "usb_add" and "usb_del" have been removed. Use "device_add" and "device_del" as replacement instead.
The deprecated HMP commands "host_net_add" and "host_net_remove" have been removed. Use "netdev_add" and "netdev_remove" instead.
The deprecated way of dumping network traffic with "-net dump" has been removed. Use "-object filter-dump" instead.
The deprecated "spapr-pci-vfio-host-bridge" device has been removed (from qemu-system-ppc64). It is not needed for vfio since QEMU v2.6.0 anymore.
Deprecated options and features
qemu-system-ppcemb is deprecated. Use qemu-system-ppc instead.
The parameters "serial", "trans", "secs", "heads", "cyls" and "addr" of the "-drive" option are now deprecated. Use the corresponding options of "-device" instead.
The "-nodefconfig" option is now deprecated. Use "-no-user-config" instead.
The "-s390-squash-mcss" parameter for the s390-ccw-virtio machine is now deprecated. It has been made obsolete by allowing to put any device into any channel subsystem image (unrestricted cssids).
The parameter "handle" of the "-fsdev" and "-virtfs" options is now depecrated. Use "local" instead.
The qmp command "query-cpus" is now deprecated. Use the new "query-cpus-fast" qmp command instead, which does not interrupt all running vCPUs. (However, there is a known bug that in 2.12, the "query-cpus-fast" command reports bogus architecture information for all architectures except "x86" and "s390".)
While "-net" is not deprecated yet, you are encouraged to use the new option "-nic" instead of "-net", as it provides a simpler and better interface ("-nic user" replaces the old "-net nic -net user").
The "-no-frame" parameter is now deprecated and will be removed together with SDL 1.2 in a future release.
The "-balloon" parameter is deprecated, use "-device virtio-balloon" instead.
The "-rtc-td-hack", "-localtime" and "-startdate" parameters are deprecated. You can use the "-rtc" parameter instead.
The "handle" backend for 9pfs is deprecated.
Consult the "Deprecated Features" appendix for the full list of historically deprecated features/options.

Future incompatible changes
Three options are using different names on the command line and in configuration file. In particular:
The "acpi" configuration file section matches command-line option "acpitable";
The "boot-opts" configuration file section matches command-line option "boot";
The "smp-opts" configuration file section matches command-line option "smp".
-readconfig will standardize on the name for the command line option.
Behavior of automatic calculation of SMP topology when some SMP topology options for -smp are omitted (sockets, cores, threads) will change in the future. If guest ABI needs to be preserved on upgrades while using the SMP topology options, users should either set set all options explicitly (sockets, cores, threads), or omit all of them.
Devices "allwinner-a10", "pc87312", "ssi-sd" will be configured with explicit properties instead of implicitly. This is unlikely to affect users.
For x86, specifying a CPUID feature with both "+feature/-feature" and "feature=on/off" will cause a warning. The current behavior for this combination ("+feature/-feature" wins over "feature=on/off") will be changed so that "+feature" and "-feature" will be synonyms for "feature=on" and "feature=off" respectively).
The read-only block drivers "bochs", "cloop" and "dmg" as well as "rbd" and "vvfat" in certain read-only configurations will no longer enable read-only mode automatically. It will be necessary to specify "read-only=on" explicitly on the command line and in QMP commands for the setup to keep working; the default "read-only=off" setting will result in an error.
On s390x, using KVM with a Linux host kernel version < 3.15 has been broken since QEMU version 2.10. This will not be fixed unless a need is communicated (otherwise the code will be removed in the near future, so that you need at least Linux kernel version 3.15 on the host to run KVM on System z)

(adam)

2018-04-25 07:06:58 UTC MAIN commitmail json YAML

Updated devel/py-test, devel/py-pip

(adam)

2018-04-25 07:06:36 UTC MAIN commitmail json YAML

py-pip: updated to 10.0.1

10.0.1:
Features
Switch the default repository to the new "PyPI 2.0" running at https://pypi.org/.

Bug Fixes
Fix a bug that made get-pip.py unusable on Windows without renaming.
Fix a TypeError when loading the cache on older versions of Python 2.7.
Fix and improve error message when EnvironmentError occurs during installation.
A crash when reinstalling from VCS requirements has been fixed.
Fix PEP 518 support when pip is installed in the user site.

Vendored Libraries
Upgrade distlib to 0.2.7

(adam)

2018-04-25 06:57:01 UTC MAIN commitmail json YAML

py-test: updated to 3.5.1

Pytest 3.5.1:
Bug Fixes
Reset sys.last_type, sys.last_value and sys.last_traceback before each test executes. Those attributes are added by pytest during the test run to aid debugging, but were never reset so they would create a leaking reference to the last failing test窶冱 frame which in turn could never be reclaimed by the garbage collector.
pytest.raises now raises TypeError when receiving an unknown keyword argument.
pytest.raises now works with exception classes that look like iterables.

Improved Documentation
Fix typo in caplog fixture documentation, which incorrectly identified certain attributes as methods.

Trivial/Internal Changes
Added a more indicative error message when parametrizing a function whose argument takes a default value.
Remove internal _pytest.terminal.flatten function in favor of more_itertools.collapse.
Import some modules from collections.abc instead of collections as the former modules trigger DeprecationWarning in Python 3.7.
record_property is no longer experimental, removing the warnings was forgotten.
Mention in documentation and CLI help that fixtures with leading _ are printed by pytest --fixtures only if the -v option is added.

(adam)

2018-04-25 06:00:37 UTC MAIN commitmail json YAML

2018-04-25 05:57:58 UTC MAIN commitmail json YAML

2018-04-25 05:53:53 UTC MAIN commitmail json YAML

2018-04-25 05:51:20 UTC MAIN commitmail json YAML

libical: update to 3.0.3

Version 3.0.3:
--------------
* VTODO COMPLETED property can be a DATE-TIME or DATE (for backward compatibility)
* Improved recurrence iteration

Version 3.0.2:
--------------
* No longer attempt to detect the need for -DUSE_32BIT_TIME_T with MSVC
* New CMake option ICAL_BUILD_DOCS which can be used to disable the docs target
* Fix threading hang in BSD type systems (OpenBSD, MacOS,...)
* Build with Ninja improvements

Version 3.0.1:
--------------
* Built-in timezones updated to tzdata2017c
* Fix a multi-threaded deadlock in icaltimezone_load_builtin_timezone()
* Fix a CMake problem with parallel builds

Version 3.0.0:
--------------
* Relicense from MPL 1.0 to MPL 2.0 (keep dual license for LGPL v2.1)
* Requires CMake v3.1.0 or higher along with various CMake and buildsystem fixes
* Added a 'make uninstall'
* Fixed use-after-free issues and some memory leaks
* Built-in timezones updated to tzdata2017b
* More accurate VTIMEZONE generation when using the system time zone data (when
  USE_BUILTIN_TZDATA=False)
* icalvalue_as_ical_string() returns "TRUE" (non-zero) or "FALSE" (zero) values only.
* New icalvalue.h convenience macros: ICAL_BOOLEAN_TRUE and ICAL_BOOLEAN_FALSE
* Better value type checking of property values when parsing
* icalvalue_new/set_date and icalvalue_new/set_datetime now enforce DATE and DATE-TIME
  values respectively
* draft-ietf-calext-extensions (RFC 7986) support added
* Parameter values are now en/decoded per RFC 6868
* Removed is_utc from icaltimetype struct
    * Set icaltimetype.zone to icaltimezone_get_utc_timezone() to change a time to UTC
    * Use icaltime_is_utc() to check if a time is in UTC
* Added support for VPATCH component
* New publicly available functions:
    + icalproperty_set_parent (icalproperty_get_parent was already public)
    + icalvalue_get_parent (icalvalue_set_parent was already public)
    + icalparameter_set_parent
    + icalparameter_get_parent
    + icalvalue_new_datetimedate (DATE or DATE-TIME)
    + icalvalue_set_datetimedate
    + icalvalue_get_datetimedate
    + icalrecur_iterator_set_start
    + icalcomponent_normalize()
    + icalproperty_normalize()
* Removed deprecated functions:
    + icaltime_from_timet (use icaltime_from_timet_with_zone)
    + icaltime_start_day_of_week (use icaltime_start_day_week)
    + icalproperty_remove_parameter (use icalproperty_remove_parameter_by_kind)
    + icalproperty_string_to_enum (use icalproperty_kind_and_string_to_enum)
* Signature changed for functions:
    + VObject *Parse_MIME_FromFileName(const char *fname)
    + icalgauge *icalgauge_new_from_sql(const char *sql, int expand)
    + const char *icallangbind_property_eval_string(icalproperty *prop, const char *sep)
    + const char *icallangbind_property_eval_string_r(icalproperty *prop, const char *sep)
    + void set_zone_directory(const char *path)
    + icalcalendar *icalcalendar_new(const char *dir)
    + int icalrecur_expand_recurrence(const char *rule, time_t start, int count, time_t *array)

Version 2.0.0:
--------------
* WARNING: Version 2 IS NOT Binary Compatible with Older Versions
* Version 2 is Source Compatible with Older Versions
* Lots of source code scrubbing
* [New] RSCALE support (requires libicu from http://www.icu-project.org)
* [New] CalDAV attachment support (draft-ietf-calext-caldav-attachments)
* [New] Resurrect the Berkeley DB storage support
* [Bug] issue83: Incorrect recurrence generation for weekly pattern
* Handle RRULEs better
* Handle threading better

(markd)

2018-04-24 13:09:01 UTC MAIN commitmail json YAML

Updated www/py-pylint-django, www/py-django-countries

(adam)

2018-04-24 13:08:43 UTC MAIN commitmail json YAML

py-django-countries: updated to 5.3

5.3:
Iterating a Countries object now returns named tuples. This makes things nicer when using {% get_countries %} or using the country list elsewhere in your code.

(adam)

2018-04-24 13:06:15 UTC MAIN commitmail json YAML

py-pylint-django: updated to 0.11

0.11:
New JsonResponseChecker that looks for common anti-patterns with http responses returning JSON.

(adam)

2018-04-23 15:29:03 UTC MAIN commitmail json YAML

doc: Updated databases/py-peewee to 3.2.5

(fhajny)

2018-04-23 15:28:54 UTC MAIN commitmail json YAML

databases/py-peewee: Update to 3.2.5.

- Added ValuesList for representing values lists.
- DateTimeField, DateField and TimeField will parse formatted-string
  before sending to the database. Previously this only occurred when
  reading values from the database.

(fhajny)

2018-04-23 15:22:09 UTC MAIN commitmail json YAML

parallel/slurm-wlm: Add SUPERCEDES following rename

OK wiz@

(bacon)

2018-04-23 14:57:57 UTC MAIN commitmail json YAML

2018-04-23 14:42:03 UTC MAIN commitmail json YAML

2018-04-23 14:31:11 UTC MAIN commitmail json YAML

doc: Updated www/contao45 to 4.5.8

(taca)

2018-04-23 14:30:45 UTC MAIN commitmail json YAML

www/contao45: update to 4.5.8

Contao 4.5.7 (2018-04-04)

Contao version 4.5.7 is available.  The bugfix release fixes a few minor
issues including a problem with validating the request token and a problem
with rendering custom layout sections.

Contao 4.5.8 (2018-04-18)

Contao version 4.5.8 is available.  The bugfix release fixes an XSS
vulnerability in the system log of the back end (CVE-2018-10125).

CVE-2018-10125

With a manipulated request, an attacker can implant a script which is executed
when a logged in back end user opens the system log.  The attacker themselves
does not have to be logged in.

The problem affects Contao 3.0.0 to 3.5.34, 4.0.0 to 4.4.17 and 4.5.0 to
4.5.7. We highly recommend you to update.

(taca)

2018-04-23 14:19:21 UTC MAIN commitmail json YAML

doc: Updated www/contao44 to 4.4.18

(taca)

2018-04-23 14:19:00 UTC MAIN commitmail json YAML

www/contao44: update to 4.4.18

Contao 4.4.17 (2018-04-04)

Contao version 4.4.17 is available.  The bugfix release fixes a few minor
issues including a problem with rendering custom layout sections.

Contao 4.4.18 (2018-04-18)

Contao version 4.4.18 is available.  The bugfix release fixes an XSS
vulnerability in the system log of the back end (CVE-2018-10125).

CVE-2018-10125

With a manipulated request, an attacker can implant a script which is executed
when a logged in back end user opens the system log.  The attacker themselves
does not have to be logged in.

The problem affects Contao 3.0.0 to 3.5.34, 4.0.0 to 4.4.17 and 4.5.0 to
4.5.7. We highly recommend you to update.

(taca)

2018-04-23 14:00:44 UTC MAIN commitmail json YAML

doc: Updated www/contao35 to 3.5.35

(taca)

2018-04-23 14:00:18 UTC MAIN commitmail json YAML

www/contao35: update to 3.5.35

Version 3.5.35 (2018-04-18)
---------------------------

### Fixed
Fix an XSS vulnerability in the system log (see CVE-2018-10125).

CVE-2018-10125

With a manipulated request, an attacker can implant a script which is executed
when a logged in back end user opens the system log.  The attacker themselves
does not have to be logged in.

The problem affects Contao 3.0.0 to 3.5.34, 4.0.0 to 4.4.17 and 4.5.0 to
4.5.7. We highly recommend you to update.

(taca)

2018-04-23 13:56:58 UTC MAIN commitmail json YAML

doc: Update of mail/roundcube to 1.2.8

mail/roundcube
mail/roundcube-plugin-enigma
mail/roundcube-plugin-password
mail/roundcube-plugin-zipdownload

(taca)

2018-04-23 13:55:00 UTC MAIN commitmail json YAML

mail/roundcube: update to 1.2.8

This is a security update to the stable version 1.2.  It fixes a recently
reported vulnerability allowing IMAP command injection via a GET parameters.
More details about this are published under CVE-2018-9846.

The second fix is about a missed remote content blocking on HTML messages with
specially crafted image and style tags.

We strongly recommend to update all productive installations of Roundcube
1.2.x.  Please do backup your data before updating!

CHANGELOG

* Fix check_request() bypass in places using get_uids() [CVE-2018-9846]
  (#6238)

* Fix possible IMAP command injection vulnerability [CVE-2018-9846] (#6229)

* Fix security issue in remote content blocking on HTML image and style tags
  (#6178)

(taca)

2018-04-23 13:51:19 UTC MAIN commitmail json YAML

Updated time/p5-DateTime-Locale to 1.19

(wen)

2018-04-23 13:50:01 UTC MAIN commitmail json YAML

Update to 1.19

Upstream changes:
1.19    2018-04-21

- Fix handling of a locale (nds) that does not provide a native name for its
  own locale code. This is a bug in CLDR, but since it exists we should handle
  it sanely.

- If you attempted to thaw a DateTime::Locale::FromData object in a process
  that had not loaded DateTime::Locale this would fail. Reported by Gregor
  Herrmann. GH #18.

(wen)

2018-04-23 13:44:46 UTC MAIN commitmail json YAML

Updated www/p5-Dancer2 to 0.206000

(wen)

2018-04-23 13:43:21 UTC MAIN commitmail json YAML

Update to 0.206000

Upstream changes:
0.206000  2018-04-19 22:09:46-04:00 America/New_York

    [ BUG FIXES ]
    * GH #1090, #1406: Replace HTTP::Body with HTTP::Entity::Parser in
      Dancer2::Core::Request. (Russell @veryrusty Jenkins)
    * GH #1292: Fix multiple attribute definitions within Plugins
      (Nigel Gregoire)
    * GH #1304: Fix the order by which config files are loaded, independently
      of their filename extension (Alberto Sim探es, Russell @veryrusty Jenkins)
    * GH #1400: Fix infinite recursion with exceptions that use circular
      references. (Andre Walker)
    * GH #1430: Fix `dancer2 gen` from source directory when Dancer2 not
      installed. (Tina @perlpunk M端ller - Tina)
    * GH #1434: Add `validate_id` method to verify a session id before
      requesting the session engine fetch it from its data store.
      (Russell @veryrusty Jenkins)
    * GH #1435, #1438: Allow XS crush_cookie methods to return an arrayref
      of values. (Russell @veryrusty Jenkins)
    * GH #1443: Update copyright year (Joseph Frazer)
    * GH #1445: Use latest HTTP::Headers::Fast (Russell @veryrusty Jenkins)
    * PR #1447: Fix missing build requires (Mohammad S Anwar)

    [ ENHANCEMENTS ]
    * PR #1354: TemplateToolkit template engine will log (at debug level)
      if a template is not found. (Kiel R Stirling, Russell @veryrusty Jenkins)
    * GH #1432: Support Content-Disposition of inline in
      send_file() (Dave Webb)
    * PR #1433: Verbose testing in AppVeyor (Graham Knop)

    [ DOCUMENTATION ]
    * GH #1314: Documentation tweaks (David Precious)
    * GH #1317: Document serializer configuration (sdeseille)
    * GH #1386: Add Hello World example (Gabor Szabo)
    * PR #1408: List project development resources (Steve Dondley)
    * PR #1426: Move performance improvement information from Migration guide
      to Deployment (Pedro Melo)

0.206000_02 2018-04-09 21:48:24-04:00 America/New_York (TRIAL RELEASE)

    [ BUG FIXES ]
    * GH #1090, #1406: Replace HTTP::Body with HTTP::Entity::Parser in
      Dancer2::Core::Request. (Russell @veryrusty Jenkins)
    * GH #1304: Fix the order by which config files are loaded, independently
      of their filename extension (Alberto Sim探es, Russell @veryrusty Jenkins)
    * GH #1400: Fix infinite recursion with exceptions that use circular
      references. (Andre Walker)
    * GH #1430: Fix `dancer2 gen` from source directory when Dancer2 not
      installed. (Tina @perlpunk M端ller - Tina)
    * GH #1434: Add `validate_id` method to verify a session id before
      requesting the session engine fetch it from its data store.
      (Russell @veryrusty Jenkins)
    * GH #1435, #1438: Allow XS crush_cookie methods to return an arrayref
      of values. (Russell @veryrusty Jenkins)
    * GH #1443: Update copyright year (Joseph Frazer)
    * GH #1445: Use latest HTTP::Headers::Fast (Russell @veryrusty Jenkins)

    [ ENHANCEMENTS ]
    * PR #1354: TemplateToolkit template engine will log (at debug level)
      if a template is not found. (Kiel R Stirling, Russell @veryrusty Jenkins)
    * GH #1432: Support Content-Disposition of inline in
      send_file() (Dave Webb)
    * PR #1433: Verbose testing in AppVeyor (Graham Knop)

    [ DOCUMENTATION ]
    * GH #1317: Document serializer configuration (sdeseille)
    * PR #1426: Move performance improvement information from Migration guide
      to Deployment (Pedro Melo)

(wen)

2018-04-23 13:33:06 UTC MAIN commitmail json YAML

Updated textproc/p5-XML-FeedPP to 0.95

(wen)

2018-04-23 13:32:11 UTC MAIN commitmail json YAML

Update to 0.95

Upstream changes:
version 0.95: Sat 21 Apr 01:15:08 CEST 2018
    * fixed #35061: use guid for uniqueness, when available.
      (thanks to avbidder)
    * improved #58422: XML::FeedPP cannot be subclassed.
      (thanks to bitcard)
    * remove useless XML::FeedPP::Common layer
    * fixed #71318: save use of timegm
      (thanks to Brian Gomes Bascoy)
    * fixed #72523: merge of items in channel changes guid
      (thanks to Никулин Юрий)
    * fixed #78407: Empty item in RSS-feed breaks processing
      (thanks to colink)
    * fixed #84798: forgot the 'use' in the documentation
      (thanks to jidanny)
    * fixed #87373: ignore namespace prefixes when you collect a value
      (thanks to Jesse Quinn)
    * fixed #124569: timegm should be called with 4-digit year
      (thanks to bitcardbmw)
    * fixed #125052: returns HASH for empty field
      (thanks to Mark Overmeer)

2011/05/09 (0.45_01) ** DEVELOPER RELEASE
    * supports subclassing. t/47_subclass_content.t added.
      https://rt.cpan.org/Public/Bug/Display.html?id=58422
      (thanks to bitcard)

(wen)

2018-04-23 13:28:56 UTC MAIN commitmail json YAML

Updated textproc/p5-PDF-Table to 0.10.1

(wen)

2018-04-23 13:28:02 UTC MAIN commitmail json YAML

2018-04-23 13:26:31 UTC MAIN commitmail json YAML

Updated www/p5-URI to 1.74

(wen)

2018-04-23 13:25:17 UTC MAIN commitmail json YAML

Update to 1.74

Upstream changes:
1.74      2018-04-22 12:30:44Z
    - avoid 'uninitialized' warning in URI::File when host has no domain name
      set (PR#53, thanks Shoichi Kaji!)

(wen)

2018-04-23 12:02:17 UTC MAIN commitmail json YAML

Updated devel/py-pathlib2, textproc/py-openpyxl

(adam)

2018-04-23 12:01:48 UTC MAIN commitmail json YAML

py-openpyxl: updated to 2.5.3

2.5.3:
Bugfixes:
* Warning level too aggressive.
* Alignment and protection values not saved for named styles.
* Deleting elements from a legend doesn窶冲 work.
* Index names repeated for every row in dataframe.
* Worksheet protection not being stored.
* Exception raised when reading a tooltip.

(adam)

2018-04-23 11:59:26 UTC MAIN commitmail json YAML

py-pathlib2: updated to 2.3.2

Version 2.3.2
- Hotfix for broken setup.py.

Version 2.3.1
- Fix tests for systems where filesystem encoding only supports ascii.
- Use modern setuptools syntax for specifying conditional scandir
  dependency.
- Remove legacy use of support module from old pathlib module.
  This fixes the tests for Python 3.6.
- Drop the "from __future__ import unicode_literals" and -Qnew tests
  as it introduced subtle bugs in the tests, and maintaining separate
  test modules for these legacy features seems not worth the effort.
- Drop Python 3.2 support, as scandir no longer supports it.

(adam)

2018-04-23 08:58:52 UTC MAIN commitmail json YAML

Updated devel/p5-Module-CPANfile to 1.1003

(wen)

2018-04-23 08:58:05 UTC MAIN commitmail json YAML

Update to 1.1003

Upstream changes:
1.1003  2018-04-22 01:54:46 CEST
        - Make options written back with save()
        - Documented options_for_module method
        - Internal refactoring

(wen)

2018-04-23 08:56:19 UTC MAIN commitmail json YAML

Updated devel/p5-Module-CoreList to 5.20180420

(wen)

2018-04-23 08:53:29 UTC MAIN commitmail json YAML

Update to 20180420

Upstream changes:
5.20180420
  - Updated for v5.27.11

5.20180414_26
  - Updated for v5.26.2

5.20180414_24
  - Updated for v5.24.4

(wen)

2018-04-23 08:50:46 UTC MAIN commitmail json YAML

Updated devel/p5-Module-Build-XSUtil to 0.19

(wen)

2018-04-23 08:42:39 UTC MAIN commitmail json YAML

Update to 0.19

Upstream changes:
0.19 2018-04-17T14:51:20Z
    - Use File::Copy::Recursive::Reduced instead File::Copy::Recursive(#13)
        (jkeenan)

(wen)

2018-04-23 08:38:22 UTC MAIN commitmail json YAML

Added sysutils/p5-File-Copy-Recursive-Reduced version 0.006

(wen)

2018-04-23 08:35:03 UTC MAIN commitmail json YAML

Add p5-File-Copy-Recursive-Reduced

(wen)

2018-04-23 08:33:26 UTC MAIN commitmail json YAML

Import File-Copy-Recursive-Reduced-0.006 as p5-File-Copy-Recursive-Reduced.

File::Copy::Recursive::Reduced is intended as a not-quite-drop-in replacement
for certain functionality provided by CPAN distribution File-Copy-Recursive. The
library provides methods similar enough to that distribution's fcopy(),
dircopy() and rcopy() functions to be usable in those CPAN distributions often
described as being part of the Perl toolchain.

(wen)