--- - branch: pkgsrc-2015Q3 date: Mon Oct 26 21:01:16 UTC 2015 files: - new: 1.33.2.1 old: '1.33' path: pkgsrc/www/drupal7/Makefile pathrev: pkgsrc/www/drupal7/Makefile@1.33.2.1 type: modified - new: 1.12.4.1 old: '1.12' path: pkgsrc/www/drupal7/PLIST pathrev: pkgsrc/www/drupal7/PLIST@1.12.4.1 type: modified - new: 1.26.2.1 old: '1.26' path: pkgsrc/www/drupal7/distinfo pathrev: pkgsrc/www/drupal7/distinfo@1.26.2.1 type: modified id: 20151026T210116Z.2cb285eab57627ad787c6d48a6457c31863369f4 log: "Pullup ticket #4845 - requested by taca\nwww/drupal7: security fix\n\nRevisions pulled up:\n- www/drupal7/Makefile 1.34-1.35\n- www/drupal7/PLIST 1.13\n- www/drupal7/distinfo \ 1.27-1.28\n\n---\n Module Name:\tpkgsrc\n \ Committed By:\twen\n Date:\t\tSun Oct 18 03:30:53 UTC 2015\n\n Modified Files:\n \tpkgsrc/www/drupal7: Makefile PLIST distinfo\n\n Log Message:\n \ Update to 7.40\n\n Upstream changes:\n Drupal 7.40, 2015-10-14\n -----------------------\n \ - Made Drupal's code for parsing .info files run much faster and use much less\n \ memory.\n - Prevented drupal_http_request() from returning an error when it receives a\n 201 through 206 HTTP status code.\n - Added support for autoloading traits via the registry on sites running PHP\n 5.4 or higher.\n \ - Allowed the user-picture.tpl.php theme template to have HTML classes besides\n \ the default \"user-picture\" class printed in it (markup change).\n - Fixed the URL text filter to convert e-mail addresses with plus signs into\n mailto: links.\n - Added alternate text to file icons displayed by the File module, to improve\n accessibility (string change, and minor API addition to theme_file_icon()).\n \ - Changed one-time login link failure messages to be displayed as errors or\n \ warnings as appropriate, rather than as regular status messages (minor UI\n \ change and data structure change).\n - Changed the default settings.php configuration to exclude private files from\n the \"404_fast_paths\" behavior.\n \ - Changed the page that displays filter tips for a particular text format, for\n example filter/tips/full_html, to return \"page not found\" or \"access denied\"\n if the format does not exist or the user does not have access to it. This\n change adds a new menu item to the Filter module's hook_menu() entry (minor\n data structure change).\n - Added a new hook, hook_block_cid_parts_alter(), to allow modules to alter the\n cache keys used for caching a particular block.\n \ - Made drupal_set_message() display and return messages when \"0\" is passed in\n as the message to set.\n - Fixed non-functional \"Files displayed by default\" setting on file fields.\n - The \"worker callback\" provided in hook_cron_queue_info() and the \"finished\"\n callback specified during batch processing can now be any PHP callable\n instead of just functions.\n - Prevented drupal_set_time_limit() from decreasing the time limit in the case\n where the PHP maximum execution time is already unlimited.\n - Changed the default thousand marker for numeric fields from a space (\"1 000\")\n to nothing (\"1000\") (minor UI change: https://www.drupal.org/node/1388376).\n - Prevented malformed theme .info files (without a \"name\" key) from causing\n exceptions during menu rebuilds. If an .info file without a \"name\" key is\n found in a module or theme directory, Drupal will now use the module or\n theme's machine name as the display name instead.\n - Made the format column in the {date_format_locale} database table\n \ case-sensitive, to match the equivalent column in the {date_formats} table.\n \ - Fixed a bug in the Statistics module that caused JavaScript files attached to\n a node while it is being viewed to be omitted from the page.\n - Added an optional 'project:' prefix that can be added to dependencies in a\n module's .info file to indicate which project the dependency resides in (API\n addition: https://www.drupal.org/node/2299747).\n - Fixed various bugs that occurred after hooks were invoked early in the Drupal\n bootstrap and that caused module_implements() and drupal_alter() to cache an\n incomplete set of hook implementations for later use.\n - Set the X-Content-Type-Options header to \"nosniff\" when possible, to prevent\n certain web browsers from picking an unsafe MIME type.\n - Prevented the database API from executing multiple queries at once on MySQL,\n \ if the site's PHP version is new enough to do so. This is a secondary defense\n \ against SQL injection (API change: https://www.drupal.org/node/2463973).\n \ - Fixed a bug in the Drupal 6 to Drupal 7 upgrade path which caused the upgrade\n \ to fail when there were multiple file records pointing to the same file.\n \ - Numerous small bug fixes.\n - Numerous API documentation improvements.\n \ - Additional automated test coverage.\n\n---\n Module Name:\tpkgsrc\n Committed By:\ttaca\n Date:\t\tThu Oct 22 09:59:44 UTC 2015\n\n Modified Files:\n \tpkgsrc/www/drupal7: Makefile distinfo\n\n Log Message:\n Update drupal7 to 7.41.\n\n Drupal 7.41, 2015-10-21\n -----------------------\n - Fixed security issues (open redirect). See SA-CORE-2015-004.\n" module: pkgsrc subject: 'CVS commit: [pkgsrc-2015Q3] pkgsrc/www/drupal7' unixtime: '1445893276' user: bsiegert