Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (0m)  pkgsrc-2024Q1 (14d)  pkgsrc-2023Q4 (42d)  pkgsrc-2023Q2 (74d)  pkgsrc-2023Q3 (153d) 

2024-05-12 16:57:31 UTC Now

2024-05-12 16:56:38 UTC MAIN commitmail json YAML

doc/TODO: +passenger

+ passenger-6.0.20.

(taca)

2024-05-12 16:52:13 UTC MAIN commitmail json YAML

doc: Updated mail/milter-manager to 2.2.7

(taca)

2024-05-12 16:51:56 UTC MAIN commitmail json YAML

2024-05-12 16:41:20 UTC MAIN commitmail json YAML

doc: Updated www/php-concrete-cms to 9.2.9

(taca)

2024-05-12 16:40:58 UTC MAIN commitmail json YAML

www/php-concrete-cms: update to 9.2.9

(I've accidently update Makefile while dropping php80 support.)

9.2.9 2024-05-08

Enhancements:

* Notifications: Added notifications in the interface about the new
  marketplace coming in Concrete CMS 9.3.0.
* File Upload Limits: Increased the upload limit for drag-and-drop file
  uploads to 4GB (subject to PHP configuration limits).
* System Help: Removed ���concrete5��� from the system help messages.

Bug Fixes:

* Dashboard Permissions: Fixed the issue where Add Pages/Navigate Sitemap
  icons were displayed in the Dashboard to users without permission to
  perform these operations.
* Page List Filtering: Addressed the issue with Page List Custom Topics
  Category Filtering not working after version 9.2.2.
* Multisite Form Submission: Fixed the issue where form submissions execute
  on incorrect pages when multisite is enabled.
* Calendar Block: Corrected errors when using the calendar block in lightbox
  mode with non-lightbox supporting themes.
* Date Time Widget: Ensured the Date Time Widget is correctly translated.
* Email Validation: Fixed bugs preventing user email validation prompts when
  required.
* Deprecation Error: Addressed the "Decrement on bool" deprecation error in
  page statistics.
* Miscellaneous Fixes: Various minor fixes for PHP 8 compatibility,
  including removal of obsolete lines and fixing typos in configurations.

(taca)

2024-05-12 16:35:45 UTC MAIN commitmail json YAML

doc: Updated www/ruby-selenium-webdriver to 4.20.1

(taca)

2024-05-12 16:35:31 UTC MAIN commitmail json YAML

www/ruby-selenium-webdriver: update to 4.20.1

4.20.0 (2024-04-24)

* Add CDP for Chrome 124 and remove 121

* Making Selenium Manager a thin wrapper (#13386)

  - This change has been made to make it easier to maintain and improve, the
    interface has changed and if users were invoking it, they might
    experience issues.  Selenium Manager is still in beta and these type of
    changes are expected.

4.20.1 (2024-04-25)

* Returned accidentally removed DriverFinder.path and deprecated it.

(taca)

2024-05-12 16:33:38 UTC MAIN commitmail json YAML

doc: Updated www/ruby-multipart-post to 2.4.1

(taca)

2024-05-12 16:33:22 UTC MAIN commitmail json YAML

www/ruby-multipart-post: update to 2.4.1

2.4.1 (2024-05-07)

* Modernize gem.

(taca)

2024-05-12 16:31:55 UTC MAIN commitmail json YAML

doc: Updated www/ruby-html-proofer to 5.0.9

(taca)

2024-05-12 16:31:37 UTC MAIN commitmail json YAML

www/ruby-html-proofer: update to 5.0.9

5.0.9 (2024-05-07)

What's Changed

* Bump actions/checkout from 3 to 4 by @dependabot in #805
* [skip test] Release v5.0.9 by @github-actions in #838

New Contributors

* @github-actions made their first contribution in #838

(taca)

2024-05-12 16:30:20 UTC MAIN commitmail json YAML

doc: Updated www/ruby-faraday-retry to 2.2.1

(taca)

2024-05-12 16:30:03 UTC MAIN commitmail json YAML

www/ruby-faraday-retry: update to 2.2.1

2.2.1 (2024-04-15)

What's Changed

* Document "methods" option with its type as a list of Symbols by
  @olleolleolle in #30
* Update docs reference to RaiseError middleware by @Drowze in #32
* Add Ruby 3.3 to CI matrix by @m-nakamura145 in #33
* Improve README.md about exceptions config by @mi-wada in #35
* Check for Faraday::UploadIO while rewinding by @iMacTia in #37
* Bump actions/checkout from 3 to 4 by @dependabot in #38

New Contributors

* @Drowze made their first contribution in #32
* @m-nakamura145 made their first contribution in #33
* @mi-wada made their first contribution in #35
* @dependabot made their first contribution in #38

(taca)

2024-05-12 16:28:50 UTC MAIN commitmail json YAML

doc: Updated www/ruby-css-parser to 1.17.1

(taca)

2024-05-12 16:28:27 UTC MAIN commitmail json YAML

www/ruby-css-parser: update to 1.17.1

1.17.1 (2024-04-07)

* Improve security by using File.read instead of IO.read #149

(taca)

2024-05-12 16:26:32 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-s3 to 1.149.1

(taca)

2024-05-12 16:26:16 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-s3: update to 1.149.1

1.149.1 (2024-05-06)

* Issue - Fix bug where destination bucket default encryption was
  inadvertently overridden by source object encryption.

(taca)

2024-05-12 16:25:26 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-core to 3.195.0

(taca)

2024-05-12 16:25:09 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-core: update to 3.195.0

3.195.0 (2024-05-10)

* Feature - Updated Aws::SSOOIDC::Client with the latest API changes.

* Feature - Updated request parameters for PKCE support.

3.194.2 (2024-05-07)

* Issue - Fix issue where ConnectionPool size iteration would prevent a new
  key from being added to the pool.

(taca)

2024-05-12 16:24:23 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-partitions to 1.927.0

(taca)

2024-05-12 16:24:07 UTC MAIN commitmail json YAML

www/ruby-aws-partitions: update to 1.927.0

1.927.0 (2024-05-10)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.926.0 (2024-05-09)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.925.0 (2024-05-06)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

(taca)

2024-05-12 16:22:39 UTC MAIN commitmail json YAML

doc: Updated time/ruby-hitimes to 3.0.0

(taca)

2024-05-12 16:22:24 UTC MAIN commitmail json YAML

time/ruby-hitimes: update to 3.0.0

3.0.0 (2024-05-01)

* Migrated to SemaphoreCI for doing full test runs on all active ruby
  versions.
* Remove the dependency on Process.clock_getres as it is unreliable.

* This has the effect of deprecating some Hitimes constants that had been
  documented as public. These are now removed as this is a major version
  update
Hitimes::CLOCK_RESOLUTION_NANOSECONDS
Hitimes::CLOCK_RESOLUTION_SECONDS
Hitimes::INSTANT_CONVERSION_FACTOR
Hitimes.clock_resolution_description
Hitimes.clock_description
* Added Rubocop for some coding consistency
* Updated the supported ruby version to be 3.0 and up
* Updated all dependencies
* Changed how all the assert_delta style tests were done so they were not so
  flakey
* Hitimes will now emit a warn message if it ends up using CLOCK_REALTIME
* Hitimes will raise an exception if it cannot find a valid clock id. This
  is a bug and a message to file a report is in the exception

(taca)

2024-05-12 16:20:28 UTC MAIN commitmail json YAML

doc: Updated textproc/ruby-review to 5.9.0

(taca)

2024-05-12 16:19:51 UTC MAIN commitmail json YAML

textproc/ruby-review: udpate to 5.9.0

5.9.0 (2024-05-04)

Bug Fixes

* LATEXBuilder: fix the spacing for @<code>, @<tt>, @<tti>, @<ttb> to be
  more appropriate. Also improved handling of PDF bookmarks (#1906, #1907).

Enhancements

* differentiated between JIS B and ISO B paper sizes in review-jlreq.cls
  Users Guide (#1904).
* fix typos in config.yml.sample (#1909).

Contributors

* @munepi
* @koshikawa

(taca)

2024-05-12 16:18:23 UTC MAIN commitmail json YAML

doc: Updated textproc/ruby-kramdown-rfc2629 to 1.7.11

(taca)

2024-05-12 16:18:07 UTC MAIN commitmail json YAML

textproc/ruby-kramdown-rfc2629: update to 1.7.11

1.7.9 (2024-04-20)

* Add option nested_ol_types

  Set globally in {::options nested_ol_types="1, i, a" /}
  or for a single <ol in an IAL {: nested_ol_types="1 (%i) A"}

  The value needs to be an array of <ol type= values, expressed as one of:

  1. A YAML array
  2. A string that will be split on commas (with optional blank space following)
  3. A string that will be split on blank space

  When testing this, an HTML rendering issue might cause some confusion:
  ietf-tools/xml2rfc#1122

1.7.10 (2024-04-21)

* Also take nested_ol_types from YAML kramdown_options

  As in

kramdown_options:
  nested_ol_types: 1, i, a

  (overridden by ::options and by pseudo-attribute on <ol)

1.7.11 (2024-04-21)

* Add option ol_start_at_first_marker

  kramdown_options:
    ol_start_at_first_marker: true

  Default: false (for backward compatibility)

  If true, an ordered list (<ol) will use the number in its first
  marker (1 for 1. etc.) as the default value of the start= attribute.

  (Increase commonmark compatibility)

(taca)

2024-05-12 16:14:54 UTC MAIN commitmail json YAML

doc: Updated sysutils/ruby-facter to 4.7.0

(taca)

2024-05-12 16:14:40 UTC MAIN commitmail json YAML

sysutils/ruby-facter: update to 4.7.0

4.7.0 (2024-04-09)

Enhancements

* Support for OpenBSD.  Added support for OpenBSD. This addition contributed
  by community member buzzdeee. FACT-3163

Resolved issues

* Re-add Ruby 2.5 support. Added support for Ruby 2.5.
* Use of cloud provider facts can result in nil dereferences. Patched the
  two cloud providers' access to metadata to avoid nil dereferences.
* Evaluate confine block in case-insensitive way.  Previously, when a user
  provided a confine block, Facter would downcase the value when evaluating
  it.  This change retains the existing behavior of evaluating a confine
  block with a downcased fact value, while adding evaluation with the raw
  fact value to ensure expected behavior.

(taca)

2024-05-12 16:12:28 UTC MAIN commitmail json YAML

doc: Updated security/ruby-sshkit to 1.22.2

(taca)

2024-05-12 16:12:07 UTC MAIN commitmail json YAML

security/ruby-sshkit: update to 1.22.2

1.22.2 (2024-04-30)

Bug Fixes

* Avoid calling closed? outside of synchronize block (#534) @djmb

(taca)

2024-05-12 16:11:03 UTC MAIN commitmail json YAML

doc: Updated security/ruby-rex-text to 0.2.58

(taca)

2024-05-12 16:10:41 UTC MAIN commitmail json YAML

security/ruby-rex-text: update to 0.2.58

0.2.58 (2024-05-10)

* Land #70, Upversion Github actions

(taca)

2024-05-12 16:09:13 UTC MAIN commitmail json YAML

doc: Updated security/ruby-airbrussh to 1.5.2

(taca)

2024-05-12 16:08:53 UTC MAIN commitmail json YAML

security/ruby-airbrussh: update to 1.5.2

1.5.2 (2024-04-12)

This is a gem housekeeping release. No user-facing changes.

Housekeeping

* Migrate from CircleCI to GitHub Actions (#155, #156) @mattbrictson

(taca)

2024-05-12 16:03:53 UTC MAIN commitmail json YAML

doc: Updated net/ruby-train-core to 3.12.3

(taca)

2024-05-12 16:03:37 UTC MAIN commitmail json YAML

net/ruby-train-core: update to 3.12.3

3.12.1 (2024-04-15)

* Add missing require for OpenStruct library #775 (Vasu1105)

3.12.2 (2024-04-15)

* Turn off vendor cache #774 (Vasu1105)

3.12.3 (2024-04-16)

Merged Pull Requests

* gem: pin down googleauth gem to below 1.9 #773 (ahasunos)

(taca)

2024-05-12 15:59:51 UTC MAIN commitmail json YAML

doc: Updated net/ruby-ruby_smb to 3.3.7

(taca)

2024-05-12 15:59:34 UTC MAIN commitmail json YAML

net/ruby-ruby_smb: update to 3.3.7

3.3.5 (2024-04-12)

* Land #264, Handle SMB2 compound related requests

3.3.6 (2024-04-25)

* Land #266, Add SamrQueryInformationDomain support

3.3.7 (2024-04-30)

* Land #265, Add GetKeySecurity and SetKeySecurity

(taca)

2024-05-12 15:56:08 UTC MAIN commitmail json YAML

doc: Updated net/ruby-recog to 3.1.5

(taca)

2024-05-12 15:55:48 UTC MAIN commitmail json YAML

net/ruby-recog: update to 3.1.5

3.1.5

No changes available.

(taca)

2024-05-12 15:16:26 UTC MAIN commitmail json YAML

doc: Updated net/ruby-pcaprub to 0.13.2

(taca)

2024-05-12 15:16:09 UTC MAIN commitmail json YAML

net/ruby-pcaprub: update to 0.13.2

0.13.2 (2024-04-22)

* Add support for x64-mingw-ucrt
* bundle: update git.
* Add github actions support
* Add support for windows tests on Github actions
* pcap: get rid of pcap_lookupdev.

(taca)

2024-05-12 15:13:38 UTC MAIN commitmail json YAML

doc: Updated net/ruby-nio4r to 2.7.3

(taca)

2024-05-12 15:13:18 UTC MAIN commitmail json YAML

net/ruby-nio4r: update to 2.7.3

2.7.2 (2024-05-07)

* Modernize gem (list all authors, etc).
* Drop official support for Ruby 2.4.

2.7.3 (2024-05-07)

* Fix JRuby release version.
* Don't build extensions twice.

(taca)

2024-05-12 15:10:36 UTC MAIN commitmail json YAML

doc: Updated mail/ruby-mime-types-data to 3.2024.0507

(taca)

2024-05-12 15:10:20 UTC MAIN commitmail json YAML

mail/ruby-mime-types-data: update to 3.2024.0507

3.2024.0507 (2024-05-07)

* Updated the Apache and IANA media registry entries as of release date

(taca)

2024-05-12 15:09:10 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-rspec-mocks to 3.13.1

(taca)

2024-05-12 15:08:52 UTC MAIN commitmail json YAML

devel/ruby-rspec-mocks: update to 3.13.1

3.13.1 (2024-05-08)

Bug Fixes:

* Use RSpec::Support::Mutex in RSpec::Mocks::Proxy to avoid issues from
  stubbing ::Mutex#new. (Eric Mueller, #1575)

(taca)

2024-05-12 15:06:47 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-regexp_parser to 2.9.1

(taca)

2024-05-12 15:06:32 UTC MAIN commitmail json YAML

devel/ruby-regexp_parser: update to 2.9.1

2.9.1 (2024-05-11)

Fixed

* fixed unnecessary $LOAD_PATH searches at load time
  thanks to Koichi ITO

(taca)

2024-05-12 15:04:51 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-i18n to 1.14.5

(taca)

2024-05-12 15:04:36 UTC MAIN commitmail json YAML

devel/ruby-i18n: udpate to 1.14.5

1.14.5 (2024-05-06)

What's Changed

* Explicitly bundle racc gem for Ruby 3.3+ by @amatsuda in #690
* Optimize I18n::Locale::Fallbacks#[] for recursive locale mappings by @uiur
  in #692
* Add I18n.interpolation_keys by @tom-lord in #682
* Fix syntax in documentation for I18n::Backend::Base.interpolate by
  @tom-lord in #691
* Fix that escaped interpolations with reserved keywords raised
  ReservedInterpolationKey by @Bilka2 in #688

New Contributors

* @uiur made their first contribution in #692
* @tom-lord made their first contribution in #682
* @Bilka2 made their first contribution in #688

(taca)

2024-05-12 15:02:55 UTC MAIN commitmail json YAML

doc: Updated converters/ruby-Ascii85 to 1.1.1

(taca)

2024-05-12 15:02:36 UTC MAIN commitmail json YAML

converters/ruby-Ascii85: update to 1.1.1

1.1.1 (2024-05-09)

* Make bin/ascii85 Ruby 3.2-compatible (thanks @tylerwillingham)
* Improve error handling of bin/ascii85 slightly

(taca)

2024-05-12 15:01:02 UTC MAIN commitmail json YAML

doc: Updated www/ruby-rack to 3.0.11

(taca)

2024-05-12 15:00:18 UTC MAIN commitmail json YAML

www/ruby-rack: update to 3.0.11

3.0.11 (2024-05-10)

* Backport #2062 to 3-0-stable: Do not allow BodyProxy to respond to to_str,
  make to_ary call close. (#2062, @jeremyevans)

(taca)

2024-05-12 14:42:22 UTC MAIN commitmail json YAML

lang/php/common.mk: update "# used by" lines

(taca)

2024-05-12 14:41:38 UTC MAIN commitmail json YAML

lang/php: drop php80 support

(taca)

2024-05-12 14:40:48 UTC MAIN commitmail json YAML

doc: Removed lang/php80

(taca)

2024-05-12 14:39:41 UTC MAIN commitmail json YAML

2024-05-12 14:39:03 UTC MAIN commitmail json YAML

lang/Makefile: remove php80

(taca)

2024-05-12 14:36:46 UTC MAIN commitmail json YAML

2024-05-12 14:29:27 UTC MAIN commitmail json YAML

doc: Updated databases/pear-DB to 1.12.2

(taca)

2024-05-12 14:29:10 UTC MAIN commitmail json YAML

databases/pear-DB: update to 1.12.2

1.12.2 (2024-04-15)

Changelog:

* Task: Manage E_DEPRECATED #27
* Task: Remove CVS id that no longer makes sense #30
* Bug: Bug in DB/oci8.php ... oci_fetch_array called with wrong parameters
  #33 #34
* Bug: Errors raised in DB_storage::toString() if there are multi-column
  keys, on PHP >= 7 #35
* Bug: sqlite3 back-end incorrectly refers to 'resource' objects #38 #39

(taca)

2024-05-12 14:27:18 UTC MAIN commitmail json YAML

doc: Updated net/pear-Net_SMTP to 1.12.1

(taca)

2024-05-12 14:27:03 UTC MAIN commitmail json YAML

net/pear-Net_SMTP: update to 1.12.1

1.12.1 (2024-04-15)

Changelog:

* Bug: Don't enable GSSAPI method if principal is not set (#81) (#82)

(taca)

2024-05-12 14:24:32 UTC MAIN commitmail json YAML

doc: Updated devel/php-xdebug to 3.3.2

(taca)

2024-05-12 14:24:11 UTC MAIN commitmail json YAML

devel/php-xdebug: update to 3.3.2

pkgsrc change: drop support for php80 (PHP 8.0).

3.3.2 (2024-04-15)

Fixed bugs:

* Fixed issue #2216: With PHP8.3 and Apache 2.4.58 error_reporting() causing
  Apache process to hang
* Fixed issue #2230: Crash when xdebug and blackfire extensions are active
* Fixed issue #2233: High and continuous Apache server CPU use

(taca)

2024-05-10 15:51:12 UTC MAIN commitmail json YAML

doc: Updated lang/php83 to 8.3.7

(taca)

2024-05-10 15:50:34 UTC MAIN commitmail json YAML

lang/php83: update to 8.3.7

I missed update of 8.3.6.

PHP 8.3.7 (2024-05-09)

- Core:
  . Fixed zend_call_stack build with Linux/uclibc-ng without thread support.
    (Fabrice Fontaine)
  . Fixed bug GH-13772 (Invalid execute_data->opline pointers in observer fcall
    handlers when JIT is enabled). (Bob)
  . Fixed bug GH-13931 (Applying zero offset to null pointer in
    Zend/zend_opcode.c). (nielsdos)
  . Fixed bug GH-13942 (Align the behavior of zend-max-execution-timers with
    other timeout implementations). (K辿vin Dunglas)
  . Fixed bug GH-14003 (Broken cleanup of unfinished calls with callable convert
    parameters). (ilutov)
  . Fixed bug GH-14013 (Erroneous dnl appended in configure). (Peter Kokot)
  . Fixed bug GH-10232 (If autoloading occurs during constant resolution
    filename and lineno are identified incorrectly). (ranvis)
  . Fixed bug GH-13727 (Missing void keyword). (Peter Kokot)

- Fibers:
  . Fixed bug GH-13903 (ASAN false positive underflow when executing copy()).
    (nielsdos)

- Fileinfo:
  . Fixed bug GH-13795 (Test failing in ext/fileinfo/tests/bug78987.phpt on
    big-endian PPC). (orlitzky)

- FPM:
  . Fixed bug GH-13563 (Setting bool values via env in FPM config fails).
    (Jakub Zelenka)

- Intl:
  . Fixed build for icu 74 and onwards. (dunglas)

- MySQLnd:
  . Fix shift out of bounds on 32-bit non-fast-path platforms. (nielsdos)

- Opcache:
  . Fixed bug GH-13433 (Segmentation Fault in zend_class_init_statics when
    using opcache.preload). (nielsdos)
  . Fixed incorrect assumptions across compilation units for static calls.
    (ilutov)

- OpenSSL:
  . Fixed bug GH-10495 (feof on OpenSSL stream hangs indefinitely).
    (Jakub Zelenka)

- PDO SQLite:
  . Fix GH-13984 (Buffer size is now checked before memcmp). (Saki Takamachi)
  . Fix GH-13998 (Manage refcount of agg_context->val correctly).
    (Saki Takamachi)

- Phar:
  . Fixed bug GH-13836 (Renaming a file in a Phar to an already existing
    filename causes a NULL pointer dereference). (nielsdos)
  . Fixed bug GH-13833 (Applying zero offset to null pointer in zend_hash.c).
    (nielsdos)
  . Fix potential NULL pointer dereference before calling EVP_SignInit. (icy17)

- PHPDBG:
  . Fixed bug GH-13827 (Null pointer access of type 'zval' in phpdbg_frame).
    (nielsdos)

- Posix:
  . Fix usage of reentrant functions in ext/posix. (Arnaud)

- Session:
  . Fixed bug GH-13856 (Member access within null pointer of type 'ps_files' in
    ext/session/mod_files.c). (nielsdos)
  . Fixed bug GH-13891 (memleak and segfault when using ini_set with
    session.trans_sid_hosts). (nielsdos, kamil-tekiela)
  . Fixed buffer _read/_write size limit on windows for the file mode. (David Carlier)

- Streams:
  . Fixed file_get_contents() on Windows fails with "errno=22 Invalid
    argument". (Damian W坦jcik)
  . Fixed bug GH-13264 (Part 1 - Memory leak on stream filter failure).
    (Jakub Zelenka)
  . Fixed bug GH-13860 (Incorrect PHP_STREAM_OPTION_CHECK_LIVENESS case in
    ext/openssl/xp_ssl.c - causing use of dead socket). (nielsdos)
  . Fixed bug GH-11678 (Build fails on musl 1.2.4 - lfs64). (Arnaud)

- Treewide:
  . Fix gcc-14 Wcalloc-transposed-args warnings. (Cristian Rodr鱈guez)

PHP 8.3.6 (2024-04-10)

- Standard:
. Fixed bug GHSA-fjp9-9hwx-59fq (mb_encode_mimeheader runs endlessly for some
    inputs). (CVE-2024-2757) (Alex Dowad)
. Fix bug GH-13932 (Attempt to fix mbstring on windows build) (msvc). (David Carlier)

(taca)

2024-05-10 15:08:17 UTC MAIN commitmail json YAML

doc: Updated lang/php82 to 8.2.19

(taca)

2024-05-10 15:07:21 UTC MAIN commitmail json YAML

lang/php82: update to

PHP 8.2.19 (2024-05-09)

- Core:
  . Fixed bug GH-13772 (Invalid execute_data->opline pointers in observer fcall
    handlers when JIT is enabled). (Bob)
  . Fixed bug GH-13931 (Applying zero offset to null pointer in
    Zend/zend_opcode.c). (nielsdos)
  . Fixed bug GH-13942 (Align the behavior of zend-max-execution-timers with
    other timeout implementations). (K辿vin Dunglas)
  . Fixed bug GH-14003 (Broken cleanup of unfinished calls with callable convert
    parameters). (ilutov)
  . Fixed bug GH-14013 (Erroneous dnl appended in configure). (Peter Kokot)
  . Fixed bug GH-10232 (If autoloading occurs during constant resolution
    filename and lineno are identified incorrectly). (ranvis)
  . Fixed bug GH-13727 (Missing void keyword). (Peter Kokot)

- Fibers:
  . Fixed bug GH-13903 (ASAN false positive underflow when executing copy()).
    (nielsdos)

- FPM:
  . Fixed bug GH-13563 (Setting bool values via env in FPM config fails).
    (Jakub Zelenka)

- Intl:
  . Fixed build for icu 74 and onwards. (dunglas)

- MySQLnd:
  . Fix shift out of bounds on 32-bit non-fast-path platforms. (nielsdos)

- Opcache:
  . Fixed incorrect assumptions across compilation units for static calls.
    (ilutov)

- OpenSSL:
  . Fixed bug GH-10495 (feof on OpenSSL stream hangs indefinitely).
    (Jakub Zelenka)

- PDO SQLite:
  . Fix GH-13984 (Buffer size is now checked before memcmp). (Saki Takamachi)
  . Fix GH-13998 (Manage refcount of agg_context->val correctly).
    (Saki Takamachi)

- Phar:
  . Fixed bug GH-13836 (Renaming a file in a Phar to an already existing
    filename causes a NULL pointer dereference). (nielsdos)
  . Fixed bug GH-13833 (Applying zero offset to null pointer in zend_hash.c).
    (nielsdos)
  . Fix potential NULL pointer dereference before calling EVP_SignInit. (icy17)

- PHPDBG:
  . Fixed bug GH-13827 (Null pointer access of type 'zval' in phpdbg_frame).
    (nielsdos)

- Posix:
  . Fix usage of reentrant functions in ext/posix. (Arnaud)

- Session:
  . Fixed bug GH-13856 (Member access within null pointer of type 'ps_files' in
    ext/session/mod_files.c). (nielsdos)
  . Fixed bug GH-13891 (memleak and segfault when using ini_set with
    session.trans_sid_hosts). (nielsdos, kamil-tekiela)
  . Fixed buffer _read/_write size limit on windows for the file mode. (David Carlier)

- Streams:
  . Fixed file_get_contents() on Windows fails with "errno=22 Invalid
    argument". (Damian W坦jcik)
  . Fixed bug GH-13264 (Part 1 - Memory leak on stream filter failure).
    (Jakub Zelenka)
  . Fixed bug GH-13860 (Incorrect PHP_STREAM_OPTION_CHECK_LIVENESS case in
    ext/openssl/xp_ssl.c - causing use of dead socket). (nielsdos)
  . Fixed bug GH-11678 (Build fails on musl 1.2.4 - lfs64). (Arnaud)

- Treewide:
  . Fix gcc-14 Wcalloc-transposed-args warnings. (Cristian Rodr鱈guez)

(taca)

2024-05-05 17:31:09 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-s3 to 1.149.0

(taca)

2024-05-05 17:30:52 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-s3: update to 1.149.0

1.149.0 (2024-04-30)

* Feature - Support S3 Access Grants authentication.  Access Grants can be
  enabled with the access_grants option, and custom options can be passed
  into the access_grants_credentials_provider option.  This feature requires
  aws-sdk-s3control to be installed.

* Feature - Add RBS signatures for customizations of S3.

1.148.0 (2024-04-25)

* Feature - Code Generated Changes, see ./build_tools or aws-sdk-core's
  CHANGELOG.md for details.

1.147.0 (2024-04-16)

* Feature - Code Generated Changes, see ./build_tools or aws-sdk-core's
  CHANGELOG.md for details.

* Issue - Omit ContentType plugin when generating presigned url.

(taca)

2024-05-05 17:29:34 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-kms to 1.80.0

(taca)

2024-05-05 17:29:20 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-kms: update to 1.80.0

1.80.0 (2024-04-25)

* Feature - Code Generated Changes, see ./build_tools or aws-sdk-core's
  CHANGELOG.md for details.

1.79.0 (2024-04-12)

* Feature - This feature supports the ability to specify a custom rotation
  period for automatic key rotations, the ability to perform on-demand key
  rotations, and visibility into your key material rotations.

(taca)

2024-05-05 17:28:03 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-secretsmanager to 1.92.0

(taca)

2024-05-05 17:27:48 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-secretsmanager: update to 1.92.0

1.92.0 (2024-04-25)

* Feature - Code Generated Changes, see ./build_tools or aws-sdk-core's
  CHANGELOG.md for details.

(taca)

2024-05-05 17:26:57 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-core to 3.194.1

(taca)

2024-05-05 17:26:35 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-core: update to 3.194.1

3.194.1 (2024-05-03)

* Issue - Update EC2 protocol to not serialize empty lists.

3.194.0 (2024-04-30)

* Feature - Add an API private cache for S3 Express and Access Grants.

3.193.0 (2024-04-25)

* Feature - Updated Aws::STS::Client with the latest API changes.

* Feature - Updated Aws::SSOOIDC::Client with the latest API changes.

* Feature - Updated Aws::SSO::Client with the latest API changes.

* Issue - Update event stream documentation.

* Issue - Move InvocationId plugin to all clients.

* Issue - Handle event streaming content-sha256 header in the signer plugin.

* Issue - Add the event stream content type to initial requests.

* Issue - Fix standard and adaptive retry mode for event streams.

* Issue - Add authority to http2 headers.

* Issue - Do not treat single members in event stream structures as implicit
  payloads.

* Issue - Do not wait for initial response headers to start sending input
  events.

3.192.1 (2024-04-18)

* Issue - Drop key/value pair if value is nil when deserializing json maps.

3.192.0 (2024-04-16)

* Feature - Updated Aws::STS::Client with the latest API changes.

* Feature - Update serializing/deserializing for all protocols to align with
  Smithy protocol-tests.

* Issue - Allow nil values in lists and maps.

* Issue - Populate headers for XML and JSON error responses.

* Issue - Support fractional seconds when parsing DateTime timestamps.

* Issue - Correctly serialize flattened lists for Query protocol.

* Issue - Correctly serialize payload name in Rest-XML requests.

* Issue - Fix an issue where Rest-XML requests do not have a default
  Content-Type header applied.

* Issue - Apply appropriate Content-Type header for payloads in Rest
  services.

* Issue - Correctly serialize URI label bindings in Rest requests.

* Issue - Correctly serialize and parse header bindings in Rest services.

* Issue - Ensure that null and empty headers are not sent in Rest requests.

* Issue - Ensure keys in query maps do not override modeled keys in Rest
  requests.

* Issue - Ensure empty blob payloads are omitted in Rest requests.

* Issue - Support parsing of NaN, Infinity and -Infinity float values.

* Issue - Apply appropriate xmlName for flattened lists and maps in Rest-XML
  services.

* Issue - Handle serializing of different formats of xmlNamespace on shapes.

* Issue - Fix deserializing of an empty blob to produce an empty string.

* Issue - Fix deserializing an empty self-closed blob to produce an empty
  string.

* Issue - Support parsing of different formats of error data in Rest-XML
  services.

(taca)

2024-05-05 17:24:09 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-partitions to 1.924.0

(taca)

2024-05-05 17:23:48 UTC MAIN commitmail json YAML

www/ruby-aws-partitions; update to 1.924.0

1.924.0 (2024-05-03)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.923.0 (2024-05-01)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.922.0 (2024-04-29)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.921.0 (2024-04-26)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.920.0 (2024-04-25)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.919.0 (2024-04-24)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.918.0 (2024-04-23)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.917.0 (2024-04-22)

* Feature - Added support for enumerating regions for Aws::Route53Profiles.

1.916.0 (2024-04-18)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.915.0 (2024-04-17)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.914.0 (2024-04-16)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.913.0 (2024-04-11)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.912.0 (2024-04-10)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.911.0 (2024-04-09)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.910.0 (2024-04-08)

* Feature - Added support for enumerating regions for Aws::ControlCatalog.

(taca)

2024-05-05 17:06:13 UTC MAIN commitmail json YAML

doc: Updated net/ruby-dnsruby to 1.72.1

(taca)

2024-05-05 17:05:58 UTC MAIN commitmail json YAML

net/ruby-dnsruby: update to 1.72.1

1.72.1 (2024-04-16)

* Add issuemail CAA record support - thanks Ryan Doherty!

(taca)

2024-05-05 17:04:11 UTC MAIN commitmail json YAML

doc: Updated misc/ruby-method_source to 1.1.0

(taca)

2024-05-05 17:03:56 UTC MAIN commitmail json YAML

misc/ruby-method_source: update to 1.1.0

1.1.0 (2024-04-15)

* Added MethodSource.clear_cache
* Added support for RUBYOPT="--enable-frozen-string-literal"

(taca)

2024-05-05 17:02:46 UTC MAIN commitmail json YAML

doc: Updated graphics/ruby-RMagick to 6.0.0

(taca)

2024-05-05 17:02:30 UTC MAIN commitmail json YAML

graphics/ruby-RMagick: update to 6.0.0

RMagick 6.0.0 (2024-05-02)

Improvements

* Improve compatibility of Image#pixel_color value for ImageMagick 6 and 7
  (#1591)

* Add missing constants (#1580)

* Loosen ImageMagick version check between compiled and runtime (#1526)

Bug Fixes

* Transform image according to Info#colorspace (#1594)

* Sync Image::Info attributes to image object (#1593)

* Fix install error on Windows MINGW environment (#1588)

* Fix header checks in order to use aligned_malloc expectedly (#1579)

Breaking Changes

* Change method that returns a color name to return a hex string (#1592)

    o The following methods return RGBA hex string as color name. The hex
      string length is according to color depth.

Image#background_color
Image#border_color
Image#colormap
Image#matte_color
Image#transparent_color
Info#background_color
Info#border_color
Info#matte_color
Info#transparent_color

    o  Change default value of argument

        - The hex argument of Pixel#to_color has true by default.

* Drop ruby-mswin environment support on Windows (#1587)

* Drop Ruby 2.x support (#1540)

* Drop ImageMagick 6.7 support (#1539)

(taca)

2024-05-05 16:58:36 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-tins to 1.33.0

(taca)

2024-05-05 16:58:17 UTC MAIN commitmail json YAML

devel/ruby-tins: update to 1.33.0

1.33.0 (2024-04-17)

* test process convenience method
* Support ruby 3.3

(taca)

2024-05-05 16:55:24 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-term-ansicolor to 1.8.0

(taca)

2024-05-05 16:55:09 UTC MAIN commitmail json YAML

devel/ruby-term-ansicolor: update to 1.8.0

Reset MAINTAINER.

1.8.0 (2024-04-13)

* Add hyperlink support.

(taca)

2024-05-05 16:53:02 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-simpleidn to 0.2.2

(taca)

2024-05-05 16:52:47 UTC MAIN commitmail json YAML

devel/ruby-simpleidn: update to 0.2.2

0.2.2 (2024-04-26)

No release note nor change log.

* Update supporting Ruby's versions.
* No code change except VERSION.

(taca)

2024-05-05 16:46:09 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-mocha to 2.2.0

(taca)

2024-05-05 16:45:54 UTC MAIN commitmail json YAML

devel/ruby-mocha: update to 2.2.0

2.2.0 (2024-04-10)

External changes

* Support multiple methods in responds_with matcher (f086b7e4, #578) -
  thanks to @vlad-pisanov for the suggestion
* Add block syntax for sequences (93fdffd, #61)
* Improve sequence failure message (0800c6ff, #60)
* Drop support for Ruby v2.0 (85848fb0, #642)
* Include the original test name in expired stub error messages (ca3ff8eb,
  #641, #642) - thanks to @casperisfine
* Avoid rubocop directive ending up in YARD docs (2a9ee81a)
* Update docs to fix those for Mock#method_missing (cee0bad6)
* Reinstate missing CNAME for GitHub Pages site (da67bb0d)
* Use Ruby v1.9 Hash syntax in docs (6de20726, #625)
* Add missing YARD tag for API#sequence name param (343c5979)
* Add missing YARD tag for API#states name param (f798df83)

Internal changes

* Tidy up Minitest vs MiniTest references (#626, #614, #615) - thanks to
  @zenspider & @Maimer for their help
* Add Ruby v3.3 to CI build matrix (ce31b544)

(taca)

2024-05-05 16:43:18 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-curses to 1.4.5

(taca)

2024-05-05 16:43:03 UTC MAIN commitmail json YAML

devel/ruby-curses: update to 1.4.5

1.4.5 (2024-04-23)

What's Changed

* Added dependabot.yml for actions by @hsbt in #72
* Bump actions/checkout from 2 to 3 by @dependabot in #73
* Add x permission to samples by @dvarrui in #71
* Bump actions/checkout from 3 to 4 by @dependabot in #82
* Add macOS directives to install curses with menu support by @AlexB52 in
  #84
* Add documentation of TERM by @shugo in #81

New Contributors

* @dependabot made their first contribution in #73
* @AlexB52 made their first contribution in #84

(taca)

2024-05-05 16:41:47 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-async to 2.11.0

(taca)

2024-05-05 16:41:28 UTC MAIN commitmail json YAML

devel/ruby-async: update to 2.11.0

2.10.2 (2024-04-15)

What's Changed

* Update readme.md - fixing a typo by @peychinov in #313
* Add source_code_uri to published gemspec.

New Contributors

* @peychinov made their first contribution in #313

Contributors

* @peychinov

2.11.0 (2024-05-04)

What's Changed

* Update dependency on console gem and modernize usage.  by @ioquatix in
  #315

Contributors

* @ioquatix

(taca)

2024-05-05 16:29:51 UTC MAIN commitmail json YAML

doc: Updated databases/ruby-sequel to 5.80.0

(taca)

2024-05-05 16:29:35 UTC MAIN commitmail json YAML

databases/ruby-sequel: update to 5.80.0

5.80.0 (2024-05-01)

* Support Dataset#skip_locked on MariaDB 10.6+ (simi) (#2150)

* Avoid allocating datasets in cases where the returned dataset would be the
  same as the receiver (jeremyevans)

* Add provenance dataset extension, which includes comments in queries
  showing how and where the dataset was built (jeremyevans)

(taca)

2024-05-05 16:26:33 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-console to 1.25.2

(taca)

2024-05-05 16:26:14 UTC MAIN commitmail json YAML

devel/ruby-console: update to 1.25.2

1.23.7 (2024-04-20)

* The exception backtrace should be split into at most 3 pieces.

1.24.0 (2024-04-22)

* Add compatible shim for Exception#detailed_message. (#58)
* Better output formatting of options.

1.25.0 (2024-05-03)

* Separation of output formatting from log generation/schema. (#60)
* Use Console::CapturedOutput everywhere.
* Improve getting started guide.
* Remove test file.
* Add guidelines for custom events.
* Set minimum version of fiber-local gem.
* Compatibility with previous event argument.

1.25.1 (2024-05-03)

* Add tests for Console::Event::Spawn.

1.25.2 (2024-05-04)

* Apply subject/level filtering in Filter#call.

(taca)

2024-05-05 16:20:31 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-fiber-local to 1.1.0

(taca)

2024-05-05 16:20:10 UTC MAIN commitmail json YAML

devel/ruby-fiber-local: update to 1.1.0

1.1.0 (2024-05-02)

* Use Fiber storage for inheritance/dynamic scope. (#3)
* Expose fiber_local_attribute_name and add test.

(taca)

2024-05-05 16:11:51 UTC MAIN commitmail json YAML

doc: Added devel/ruby-fiber-storage version 0.1.0

(taca)

2024-05-05 16:10:44 UTC MAIN commitmail json YAML

devel/Makefile: add and enable ruby-fiber-storage

(taca)

2024-05-05 16:10:02 UTC MAIN commitmail json YAML

devel/ruby-fiber-storage: add package version 0.1.0

This package is required by new version of devel/ruby-fiber-local
package.

Fiber::Storage

This gem provides a shim for Fiber.[], Fiber.[]=, Fiber#storage,
Fiber#storage=, which was introduced in Ruby 3.2.

Motivation

Ruby 3.2 introduces inheritable fiber storage for per-request or
per-operation state.  This gem provides a shim for Ruby 3.1 and earlier to
make adoption easier.  It isn't able to provide the full range of features,
but it should be sufficient for most use cases.

Notably, it does not support inheritance across threads or lazy Enumerator.
This is a limitation of the shim implementation.

(taca)

2024-05-05 14:43:05 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-redmine51 to 5.1.2nb1

(taca)

2024-05-05 14:42:49 UTC MAIN commitmail json YAML

devel/ruby-redmine51: relax dependency

Remove upper bound version for ruby-sqlite3 dependency.

Bump PKGREVISION.

(taca)

2024-05-05 14:42:29 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-redmine50 to 5.0.8nb1

(taca)

2024-05-05 14:42:01 UTC MAIN commitmail json YAML

devel/ruby-redmine50: relax dependency

Remove upper bound version for ruby-sqlite3 dependency.

Bump PKGREVISION.

(taca)

2024-04-25 15:19:40 UTC MAIN commitmail json YAML

doc: Updated mail/rspamd to 3.8.4nb1

(taca)

2024-04-25 15:19:22 UTC MAIN commitmail json YAML

mail/rspamd: allow rc.d script to reload

Bump PKGREVISION.

(taca)

2024-04-25 15:14:49 UTC MAIN commitmail json YAML

doc/pkg-vulnerabilities: add CVE-2024-27282

Add CVE-2024-27282 for ruby31-base, ruby32-base and ruby33.

(taca)

2024-04-25 15:12:26 UTC MAIN commitmail json YAML

doc: Updated lang/ruby33 to 3.3.1

(taca)

2024-04-25 15:12:05 UTC MAIN commitmail json YAML

lang/ruby33: update to 3.3.1

This is security release.  Note CVE-2024-27280 and CVE-2024-27281 were
already fixed by ruby31-base-3.3.0nb1.

3.3.1 (2024-04-23)

* CVE-2024-27282: Arbitrary memory address read vulnerability with Regex
  search
* CVE-2024-27281: RCE vulnerability with .rdoc_options in RDoc

(taca)

2024-04-25 15:06:30 UTC MAIN commitmail json YAML

doc: Updated lang/ruby32-base to 3.2.4

(taca)

2024-04-25 15:06:11 UTC MAIN commitmail json YAML

lang/ruby32-base: update to 3.2.4

This is security release.  Note CVE-2024-27280 and CVE-2024-27281 were
already fixed by ruby31-base-3.2.3nb3.

3.2.4 (2024-04-23)

* CVE-2024-27282: Arbitrary memory address read vulnerability with Regex
  search
* CVE-2024-27281: RCE vulnerability with .rdoc_options in RDoc
* CVE-2024-27280: Buffer overread vulnerability in StringIO

(taca)

2024-04-25 14:52:54 UTC MAIN commitmail json YAML

doc: Updated lang/ruby31-base to 3.1.5

(taca)

2024-04-25 14:51:54 UTC MAIN commitmail json YAML

lang/ruby31-base: update to 3.1.5

This is security release.  Note CVE-2024-27280 and CVE-2024-27281 were
already fixed by ruby31-base-3.1.4nb3.

3.1.5 (2024-04-23)

Security release.

* CVE-2024-27282: Arbitrary memory address read vulnerability with Regex
  search
* CVE-2024-27281: RCE vulnerability with .rdoc_options in RDoc
* CVE-2024-27280: Buffer overread vulnerability in StringIO

(taca)

2024-04-20 14:03:04 UTC MAIN commitmail json YAML

doc: Updated net/bind918 to 9.18.26nb1

(taca)

2024-04-20 14:02:40 UTC MAIN commitmail json YAML

net/bind918: fix blocklist handling

Apply change of revision 1.21 in NetBSD base which fixed PR bin/58170.

Bump PKGREVISION.

(taca)

2024-04-20 14:02:03 UTC MAIN commitmail json YAML

doc: Updated net/bind916 to 9.16.50nb1

(taca)

2024-04-20 14:01:08 UTC MAIN commitmail json YAML

net/bind916: fix blocklist handling

Apply change of revision 1.21 in NetBSD base which fixed PR bin/58170.

Bump PKGREVISION.

(taca)

2024-04-18 13:40:50 UTC MAIN commitmail json YAML

doc/TODO: update clmav entry

+ clamav-1.3.1.

(taca)

2024-04-18 13:40:11 UTC MAIN commitmail json YAML

doc: Updated net/bind916 to 9.16.50

(taca)

2024-04-18 13:39:53 UTC MAIN commitmail json YAML

net/bind916: update to 9.16.50

9.16.50 (2024-04-17)

This release marks the end of maintenance for the BIND 9.16 branch.

6364. [protocol] Add RESOLVER.ARPA to the built in empty zones.
[GL #4580]

6338. [func] Optimize slabheader placement, so the infrastructure
records are put in the beginning of the slabheader
linked list. [GL !8675]

(taca)

2024-04-18 13:38:29 UTC MAIN commitmail json YAML

doc: Updated net/bind918 to 9.18.26

(taca)

2024-04-18 13:37:53 UTC MAIN commitmail json YAML

net/bind918: update to 9.18.62

9.18.26 (2024-04-17)

6364. [protocol] Add RESOLVER.ARPA to the built in empty zones.
[GL #4580]

6363. [bug] dig/mdig +ednsflags=<non-zero-value> did not re-enable
EDNS if it had been disabled. [GL #4641]

6361. [bug] Some invalid ISO 8601 durations were accepted
erroneously. [GL #4624]

6360. [bug] Don't return static-stub synthesised NS RRset.
[GL #4608]

6359. [bug] Fix bug in Depends (keymgr_dep) function. [GL #4552]

6351. [protocol] Support for the RESINFO record type has been added.
[GL #4413]

6346. [bug] Cleaned up several minor bugs in the RBTDB dbiterator
implementation. [GL !8741]

6345. [bug] Added missing dns_rdataset_disassociate calls in
validator.c:findnsec3proofs. [GL #4571]

6340. [test] Fix incorrectly reported errors when running tests
with `make test` on platforms with older pytest.
[GL #4560]

6338. [func] Optimize slabheader placement, so the infrastructure
records are put in the beginning of the slabheader
linked list. [GL !8675]

6334. [doc] Improve ARM parental-agents definition. [GL #4531]

6333. [bug] Fix the DNS_GETDB_STALEFIRST flag, which was defined
incorrectly in lib/ns/query.c. [GL !8683]

6330. [doc] Update ZSK minimum lifetime documentation in ARM, also
depends on signing delay. [GL #4510]

6328. [func] Add workaround to enforce dynamic linker to pull
jemalloc earlier than libc to ensure all memory
allocations are done via jemalloc. [GL #4404]

6326. [bug] Changes to "listen-on" statements were ignored on
reconfiguration unless the port or interface address was
changed, making it impossible to change a related
listener transport type. Thanks to Thomas Amgarten.
[GL #4518] [GL #4528]

6325. [func] Expose the TCP client count in statistics channel.
[GL #4425]

6324. [bug] Fix a possible crash in 'dig +nssearch +nofail' and
'host -C' commands when one of the name servers returns
SERVFAIL. [GL #4508]

6313. [bug] When dnssec-policy is in effect the DNSKEY's TTLs in
the zone where not being updated to match the policy.
This lead to failures when DNSKEYs where updated as the
TTLs mismatched. [GL #4466]

(taca)

2024-04-13 03:12:37 UTC MAIN commitmail json YAML

doc/pkg-vulnerabilities: add entries for php-7.4 and php-8.0

(taca)

2024-04-13 03:11:38 UTC MAIN commitmail json YAML

doc/eol-packages: php74 and php80

PHP 7.4 and PHP 8.0 are EOL.

(taca)

2024-04-13 03:10:35 UTC MAIN commitmail json YAML

2024-04-13 02:54:05 UTC MAIN commitmail json YAML

doc: Updated lang/php81 to 8.1.28

(taca)

2024-04-13 02:53:35 UTC MAIN commitmail json YAML

lang/php81: update to 8.1.27

This release includes security fixes.

11 Apr 2024, PHP 8.1.28

- Standard:
  . Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command
    parameter of proc_open). (CVE-2024-1874) (Jakub Zelenka)
  . Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to
    partial CVE-2022-31629 fix). (CVE-2024-2756) (nielsdos)
  . Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true,
    opening ATO risk). (CVE-2024-3096) (Jakub Zelenka)

(taca)

2024-04-13 02:52:28 UTC MAIN commitmail json YAML

doc: Updated lang/php83 to 8.3.5

(taca)

2024-04-13 02:51:54 UTC MAIN commitmail json YAML

lang/php83: update to 8.3.5

This release includes security fixes.

11 Apr 2024, PHP 8.3.5

- Core:
  . Fixed GH-13569 (GC buffer unnecessarily grows up to GC_MAX_BUF_SIZE when
    scanning WeakMaps). (Arnaud)
  . Fixed bug GH-13612 (Corrupted memory in destructor with weak references).
    (nielsdos)
  . Fixed bug GH-13446 (Restore exception handler after it finishes). (ilutov)
  . Fixed bug GH-13784 (AX_GCC_FUNC_ATTRIBUTE failure). (Remi)
  . Fixed bug GH-13670 (GC does not scale well with a lot of objects created in
    destructor). (Arnaud)

- DOM:
  . Add some missing ZPP checks. (nielsdos)
  . Fix potential memory leak in XPath evaluation results. (nielsdos)

- FPM:
  . Fixed GH-11086 (FPM: config test runs twice in daemonised mode).
    (Jakub Zelenka)
  . Fix incorrect check in fpm_shm_free(). (nielsdos)

- GD:
  . Fixed bug GH-12019 (add GDLIB_CFLAGS in feature tests). (Michael Orlitzky)

- Gettext:
  . Fixed sigabrt raised with dcgettext/dcngettext calls with gettext 0.22.5
    with category set to LC_ALL. (David Carlier)

- MySQLnd:
  . Fix GH-13452 (Fixed handshake response [mysqlnd]). (Saki Takamachi)
  . Fix incorrect charset length in check_mb_eucjpms(). (nielsdos)

- Opcache:
  . Fixed GH-13508 (JITed QM_ASSIGN may be optimized out when op1 is null).
    (Arnaud, Dmitry)
  . Fixed GH-13712 (Segmentation fault for enabled observers when calling trait
    method of internal trait when opcache is loaded). (Bob)

- Random:
  . Fixed bug GH-13544 (Pre-PHP 8.2 compatibility for mt_srand with unknown
    modes). (timwolla)
  . Fixed bug GH-13690 (Global Mt19937 is not properly reset in-between
    requests when MT_RAND_PHP is used). (timwolla)

- Session:
  . Fixed bug GH-13680 (Segfault with session_decode and compilation error).
    (nielsdos)

- SPL:
  . Fixed bug GH-13685 (Unexpected null pointer in zend_string.h). (nielsdos)

- Standard:
  . Fixed bug GH-11808 (Live filesystem modified by tests). (nielsdos)
  . Fixed GH-13402 (Added validation of `\n` in $additional_headers of mail()).
    (SakiTakamachi)
  . Fixed bug GH-13203 (file_put_contents fail on strings over 4GB on Windows).
    (divinity76)
  . Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command
    parameter of proc_open). (CVE-2024-1874) (Jakub Zelenka)
  . Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to
    partial CVE-2022-31629 fix). (CVE-2024-2756) (nielsdos)
  . Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true,
    opening ATO risk). (CVE-2024-3096) (Jakub Zelenka)
    Fixed bug GHSA-fjp9-9hwx-59fq (mb_encode_mimeheader runs endlessly for some
    inputs). (CVE-2024-2757) (Alex Dowad)

(taca)

2024-04-13 02:50:21 UTC MAIN commitmail json YAML

doc: Updated lang/php82 to 8.2.18

(taca)

2024-04-13 02:49:41 UTC MAIN commitmail json YAML

lang/php82: update to 8.2.18

This release includes security fixes.

11 Apr 2024, PHP 8.2.18

- Core:
  . Fixed bug GH-13612 (Corrupted memory in destructor with weak references).
    (nielsdos)
  . Fixed bug GH-13784 (AX_GCC_FUNC_ATTRIBUTE failure). (Remi)
  . Fixed bug GH-13670 (GC does not scale well with a lot of objects created in
    destructor). (Arnaud)

- DOM:
  . Add some missing ZPP checks. (nielsdos)
  . Fix potential memory leak in XPath evaluation results. (nielsdos)
  . Fix phpdoc for DOMDocument load methods. (VincentLanglet)

- FPM
  . Fix incorrect check in fpm_shm_free(). (nielsdos)

- GD:
  . Fixed bug GH-12019 (add GDLIB_CFLAGS in feature tests). (Michael Orlitzky)

- Gettext:
  . Fixed sigabrt raised with dcgettext/dcngettext calls with gettext 0.22.5
    with category set to LC_ALL. (David Carlier)

- MySQLnd:
  . Fix GH-13452 (Fixed handshake response [mysqlnd]). (Saki Takamachi)
  . Fix incorrect charset length in check_mb_eucjpms(). (nielsdos)

- Opcache:
  . Fixed GH-13508 (JITed QM_ASSIGN may be optimized out when op1 is null).
    (Arnaud, Dmitry)
  . Fixed GH-13712 (Segmentation fault for enabled observers when calling trait
    method of internal trait when opcache is loaded). (Bob)

- PDO:
  . Fix various PDORow bugs. (Girgias)

- Random:
  . Fixed bug GH-13544 (Pre-PHP 8.2 compatibility for mt_srand with unknown
    modes). (timwolla)
  . Fixed bug GH-13690 (Global Mt19937 is not properly reset in-between
    requests when MT_RAND_PHP is used). (timwolla)

- Session:
  . Fixed bug GH-13680 (Segfault with session_decode and compilation error).
    (nielsdos)

- Sockets:
  . Fixed bug GH-13604 (socket_getsockname returns random characters in the end
    of the socket name). (David Carlier)

- SPL:
  . Fixed bug GH-13531 (Unable to resize SplfixedArray after being unserialized
    in PHP 8.2.15). (nielsdos)
  . Fixed bug GH-13685 (Unexpected null pointer in zend_string.h). (nielsdos)

- Standard:
  . Fixed bug GH-11808 (Live filesystem modified by tests). (nielsdos)
  . Fixed GH-13402 (Added validation of `\n` in $additional_headers of mail()).
    (SakiTakamachi)
  . Fixed bug GH-13203 (file_put_contents fail on strings over 4GB on Windows).
    (divinity76)
  . Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command
    parameter of proc_open). (CVE-2024-1874) (Jakub Zelenka)
  . Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to
    partial CVE-2022-31629 fix). (CVE-2024-2756) (nielsdos)
  . Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true,
    opening ATO risk). (CVE-2024-3096) (Jakub Zelenka)

- XML:
  . Fixed bug GH-13517 (Multiple test failures when building with
    --with-expat). (nielsdos)

(taca)

2024-04-09 16:40:54 UTC MAIN commitmail json YAML

doc: Updated databases/ruby-odbc to 0.999992

(taca)

2024-04-09 16:40:41 UTC MAIN commitmail json YAML

databases/ruby-odbc: update to 0.999992

ChangeLog says that it was released on 2023-09-04 but Ruby gem released on
2024-04-09.

0.999992

* update to compile with newer Ruby releases
* allow tuning GC threshold

(taca)

2024-04-09 16:35:13 UTC MAIN commitmail json YAML

doc: Updated net/pear-Net_Sieve to 1.4.7

(taca)

2024-04-09 16:34:46 UTC MAIN commitmail json YAML

net/pear-Net_Sieve: update to 1.4.7

1.4.8 (2024-04-08)

Changelog:

* Add support of OAUTHBEARER
* PHPDoc improvements/fixes
* Short array syntax

(taca)

2024-04-07 15:18:38 UTC MAIN commitmail json YAML

doc: Updated www/ruby-selenium-webdriver to 4.19.0

(taca)

2024-04-07 15:18:19 UTC MAIN commitmail json YAML

www/ruby-selenium-webdriver: update to 4.19.0

4.19.0 (2024-03-27)

* Add CDP for Chrome 123 and remove 120
* Avoid over-escaping browser path (#13632)
* Add full RBS support (#13234)

(taca)

2024-04-07 15:17:12 UTC MAIN commitmail json YAML

doc: Updated www/ruby-rack-cache to 1.17.0

(taca)

2024-04-07 15:16:57 UTC MAIN commitmail json YAML

www/ruby-rack-cache: update to 1.17.0

1.17.0 (2024-04-05)

What's Changed

* Ensure invalidate doesn't mutate response x-status key by @timdef in #25

New Contributors

* @timdef made their first contribution in #25

(taca)

2024-04-07 15:15:51 UTC MAIN commitmail json YAML

doc: Updated www/ruby-css-parser to 1.17.0

(taca)

2024-04-07 15:15:38 UTC MAIN commitmail json YAML

www/ruby-css-parser: update to 1.17.0

1.17.0 (2024-04-06)

* Added user_agent as an option to Parser #146

(taca)

2024-04-07 15:14:27 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-s3 to 1.146.1

(taca)

2024-04-07 15:14:12 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-s3: update to 1.146.1

1.146.1 (2024-03-28)

* Issue - Fix bug where thread_count option was not being respected for
  multipart uploads.

1.146.0 (2024-03-18)

* Feature - Fix two issues with response root node names.

1.145.0 (2024-03-15)

* Feature - Documentation updates for Amazon S3.

1.144.0 (2024-03-13)

* Feature - This release makes the default option for S3 on Outposts request
  signing to use the SigV4A algorithm when using AWS Common Runtime (CRT).

1.143.1 (2024-03-12)

* Issue - Include original part errors in message when aborting multipart
  upload fails (#2990).

(taca)

2024-04-07 15:13:12 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-secretsmanager to 1.91.0

(taca)

2024-04-07 15:12:53 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-secretsmanager: update to 1.91.0

1.91.0 (2024-03-27)

* Feature - Documentation updates for Secrets Manager

(taca)

2024-04-07 15:12:09 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-core to 3.191.6

(taca)

2024-04-07 15:11:51 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-core: update to 3.191.6

3.191.6 (2024-04-02)

* Issue - Performance optimization: ensure presence and order of instance
  variables in PluginOptions (#3002).

3.191.5 (2024-03-26)

* Issue - Fix EC2Metadata and InstanceProfileCredentials to respect the port
  from a configured endpoint from code, ENV, or shared config.

(taca)

2024-04-07 15:11:04 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-partitions to 1.909.0

(taca)

2024-04-07 15:10:48 UTC MAIN commitmail json YAML

www/ruby-aws-partitions: update to 1.909.0

1.909.0 (2024-04-05)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.908.0 (2024-04-04)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.907.0 (2024-04-03)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.906.0 (2024-04-02)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.905.0 (2024-04-01)

* Feature - Added support for enumerating regions for Aws::Deadline.

1.904.0 (2024-03-29)

* Feature - Added support for enumerating regions for Aws::CodeConnections.

1.903.0 (2024-03-28)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.902.0 (2024-03-27)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.901.0 (2024-03-26)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.900.0 (2024-03-25)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

1.899.0 (2024-03-18)

* Feature - Updated the partitions source data the determines the AWS
  service regions and endpoints.

(taca)

2024-04-07 15:08:35 UTC MAIN commitmail json YAML

doc: Updated security/ruby-sshkit to 1.22.1

(taca)

2024-04-07 15:08:17 UTC MAIN commitmail json YAML

security/ruby-sshkit: update to 1.22.1

1.22.1 (2024-04-01)

Bug Fixes

* Explicitly require base64 to fix missing constant error with net-ssh
  7.2.2+ (#532) @mattbrictson

Housekeeping

* Fix failing tests on ruby head (#533) @mattbrictson
* Bump toolmantim/release-drafter from 5.25.0 to 6.0.0 (#530) @dependabot

(taca)

2024-04-07 15:06:51 UTC MAIN commitmail json YAML

doc: Updated security/ruby-rex-text to 0.2.57

(taca)

2024-04-07 15:06:36 UTC MAIN commitmail json YAML

security/ruby-rex-text: update to 0.2.57

0.2.57 (2024-03-28)

* land #69, add buffer/comment support

(taca)

2024-04-07 15:03:32 UTC MAIN commitmail json YAML

doc: Updated security/ruby-rex-socket to 0.1.57

(taca)

2024-04-07 15:03:14 UTC MAIN commitmail json YAML

security/ruby-rex-socket: update to 0.1.57

0.1.57 (2024-03-25)

* Land #66, update is_name to support underscores

(taca)

2024-04-07 14:57:23 UTC MAIN commitmail json YAML

doc: Updated security/ruby-net-ssh to 7.2.3

(taca)

2024-04-07 14:57:09 UTC MAIN commitmail json YAML

security/ruby-net-ssh: update to 7.2.3

7.2.3 (2024-04-02)

No documentation.  But it looks like a little improvement to Rakefile.

(taca)

2024-04-07 14:54:00 UTC MAIN commitmail json YAML

doc: Updated net/ruby-train-core to 3.12.0

(taca)

2024-04-07 14:53:43 UTC MAIN commitmail json YAML

net/ruby-train-core: update to 3.12.0

3.12.0 (2024-03-28)

Merged Pull Requests

* CHEF-7180: Configures sonarqube for code coverage anlaysis #758 (Vasu1105)
* Adds missing configuration for coverage pipeline #760 (Vasu1105)
* CHEF-7180: Fix configuration values in sonar configuration file #761
  (Vasu1105)
* Fix: Update ruby base image to bullseye in CI tests #765 (ahasunos)
* CHEF-8598: Add support for curve25519 key exchange #764 (ahasunos)
* Upgrade Google REST API Client to latest #757 (balasubramanian-s)
* Revert "Upgrade Google REST API Client to latest" #766 (Vasu1105)
* CHEF-8031- Upgrade GCP client libraries #767 (balasubramanian-s)

(taca)

2024-04-07 14:50:01 UTC MAIN commitmail json YAML

doc: Updated net/ruby-dnsruby to 1.72.0

(taca)

2024-04-07 14:49:46 UTC MAIN commitmail json YAML

net/ruby-dnsruby: update to 1.72.0

1.72.0 (2024-03-28)

* Fix compatibility with the --enable-string-literal Ruby option - thanks
  Jean byroot Boussier!

(taca)

2024-04-07 14:48:11 UTC MAIN commitmail json YAML

doc: Updated graphics/ruby-RMagick to 5.5.0

(taca)

2024-04-07 14:47:52 UTC MAIN commitmail json YAML

graphics/ruby-RMagick: update to 5.5.0

5.5.0 (2024-04-06)

Improvements

* Add RBS signatures (#1458)
* Remove unnecessary type check in KernelInfo#{unity_add, scale} (#1514)
* Remove unnecessary type check in Image#{morphology, morphology_channel}
  (#1513)
* Improve HatchFill.new to accept Pixel object as color (#1512)
* Fix GraphicContext#font_weight to accept Numeric object (#1510)
* Improve GraphicContext#font_weight to accept Symbol object (#1509)
* Improve Stretchable#viewbox to use implicitly conversioned value (#1507)
* Improve RVG::Transformable#rotate to convert to Float implicitly (#1506)
* Fix Image#modulate in order to accept negative number (#1505)
* Improve Image#modulate to accept "NN%" form string (#1504)
* Implicit conversion to string with methods that expect a string (#1496)
* Coerce to string instead of using #to_s (#1495)
* Coerce to string where pass object into string interpolation (#1494)
* Fix Draw#{fill_opacity, opacity, stroke_opacity} to correctly handle
  arguments (#1492)
* Fix Draw#{interline_spacing, interword_spacing, kerning} to correctly
  handle arguments that can be converted to Float (#1491)
* Remove unnecessary type check in KernelInfo methods (#1489)
* Generate compile_flags.txt for clangd for development (#1488)
* Fix Draw#{stroke_dasharray, stroke_miterlimit} to accept object which has
  #to_f method (#1486)
* Fix Image#composite_affine to accept ImageList object (#1484)
* Fix Image#add_compose_mask to accept ImageList object (#1483)
* Fix incorrect number of required arguments in ArgumentError (#1482)
* Fix ImageList#sort! that should return self (#1481)
* Fix ImageList#eql? that should not raise exception if can't compare
  (#1479)
* Fix ImageList#<=> that should return nil if can't compare (#1478)
* Add DrawAttribute module to simplify Draw, DrawOptions and PolaroidOptions
  (#1477)
* Add missing attribute writer methods in Image::{DrawOptions,
  PolaroidOptions} (#1476)
* Add Image::PolaroidOptions#affine= (#1475)
* Add Image::PolaroidOptions#tile= (#1474)
* Attribute writer methods should return passed value (#1473)
* Return self with ImageList if Image's method return self (#1472)
* Fix Image#clut_channel to accept ImageList object (#1471)
* Fix Magick::GradientFill#fill and Magick::TextureFill#fill to accept
  ImageList object (#1467)

Bug Fixes

* Fix typo in order to fix NoMethodError (#1515)
* Sync compression value in order fix the problem of compression being
  ignored by ImageMagick 7 (#1503)
* Add PKG_CONFIG_PATH for ImageMagick 7 in order to fix installation error
  on macOS (#1501)

(taca)

2024-04-07 14:44:24 UTC MAIN commitmail json YAML

doc: Updated finance/ruby-braintree to 4.20.0

(taca)

2024-04-07 14:44:10 UTC MAIN commitmail json YAML

finance/ruby-braintree: update to 4.20.0

4.20.0 (2024-03-26)

* Deprecate credit method in credit_card and credit_card_gateway
* Deprecate sale method in credit_card and credit_card_gateway
* Add domains parameter support to ClientToken::generate

(taca)

2024-04-07 14:42:53 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-ole to 1.2.13.1

I've missed to write these.

1.2.13 (2024-03-28)

* Drop defunct Travis sudo: false directive (github #27, olleolleolle).
* Fix broken '-y' command line option (github #20).

> 1.2.13.1 (2024-03-28)
>
> * Try using gemspec metadata to see if it will update rubygems homepage
>  link.

(taca)

2024-04-07 14:41:25 UTC MAIN commitmail json YAML

devel/ruby-ole: update to 1.2.13.1

1.2.13.1 (2024-03-28)

* Try using gemspec metadata to see if it will update rubygems homepage
  link.

(taca)

2024-04-07 14:39:50 UTC MAIN commitmail json YAML

doc: Updated devel/ruby-async to 2.10.1

(taca)

2024-04-07 14:39:34 UTC MAIN commitmail json YAML

devel/ruby-async: update to 2.10.1

2.10.0 (2024-03-27)

* Introduce Async::Task#defer_stop by @ioquatix in #310

2.10.1 (2024-03-27)

* Raise stop directly in #defer_stop. by @ioquatix in #311

(taca)

2024-04-07 14:37:12 UTC MAIN commitmail json YAML

doc: Updated databases/ruby-sequel to 5.79.0

(taca)

2024-04-07 14:36:56 UTC MAIN commitmail json YAML

databases/ruby-sequel: update to 5.79.0

5.79.0 (2024-04-01)

* Support create_or_replace_view with :materialized option on PostgreSQL
  (nashby) (#2144)

* Support :unlogged_tables_default Database option on Postgres for making
  created tables unlogged by default (jeremyevans) (#2134)

* Add Dataset#select_prepend for prepending to the current selected columns
  (jeremyevans) (#2139)

(taca)

2024-04-07 14:00:54 UTC MAIN commitmail json YAML

doc/pkg-vulnerabilities: add several php-concrete-cms entries

php{80,81,82}-concrete-cms<9.2.8 XSS
CVE-2024-2753
CVE-2024-3178
CVE-2024-3179
CVE-2024-3180
CVE-2024-3181

(taca)

2024-04-07 13:59:24 UTC MAIN commitmail json YAML

doc: Updated www/php-concrete-cms to 9.2.8

(taca)

2024-04-07 13:59:05 UTC MAIN commitmail json YAML

www/php-concrete-cms: update to 9.2.8

9.2.8 (2024-04-02)

Bug Fixes

* Fixed bug where c5:info console command would fail when run on a Concrete
  webroot if that webroot was not yet an installed Concrete site.

* Fixed bug where logout link in toolbar would not work when user was logged
  in as an editor who could not view the Dashboard (thanks ounziw)

Security Updates

* Created CVE-2024-2753 Stored XSS on the calendar color settings screen and
  fixed it with commit 11988 Prior to the fix, a rogue administrator could
  put malicious javascript on the Concrete CMS color setting screen which
  would have would have been triggered by and affected users who accessed
  the color settings screen.  The Concrete CMS security team gave this
  vulnerability a CVSS v3.1 score of 2.0 with a vector of
  AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N

  Thank you Rikuto Tauchi for reporting HackerOne 2433383.

* Created CVE-2024-3178 Cross-site Scripting (XSS) - Advanced File Search
  Filter and fixed it with commit 11988 for version 9 and commit 11989 for
  version 8.  Prior to the fix, a rogue administrator could add malicious
  code in the file manager because of insufficient validation of
  administrator provided data.  All administrators have access to the File
  Manager and hence could create a search filter with the malicious code
  attached.  The Concrete CMS security team gave this vulnerability a CVSS
  v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L

  Thank you Guram (javakhishvili) for reporting HackerOne 949443

* Created CVE-2024-3179 Stored XSS in the Custom Class page editing and
  fixed it with commit 11988 for version 9 and commit 11989 for version 8.
  Prior to the fix, a rogue administrator could insert malicious code in the
  custom class field due to insufficient validation of administrator
  provided data.  Concrete CMS version 9.2.8 and 8.5.13 no longer allow any
  non alphanumeric characters in this CSS class.  The Concrete CMS security
  team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of
  AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L Thank you Alexey Solovyev for
  reporting HackerOne 918129.

* Created and fixed [CVE-2024-3180]
  (https://nvd.nist.gov/vuln/detail/CVE-2024-3180) Prior to fix, stored XSS
  could be executed by a rogue administrator adding malicious code to the
  link-text field when creating a block of type file.  Fixed with commit
  11988 for version 9 and commit 11989 for version 8.  The Concrete CMS
  security team gave this vulnerability a CVSS v3.1 sore of 3.1 with a
  vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L Thank you Alexey Solovyev
  for reporting HackerOne 903356

* Created CVE-2024-3181 Stored XSS in the Search Field.  Prior to the fix,
  stored XSS could be executed by an administrator changing a filter to
  which a rogue administrator had previously added malicious code.  The
  Concrete Team fixed this with commit 11988 for version 9 and commit 11989
  for version 8. Thank you Alexey Solovyev for reporting HackerOne 918142

(taca)

2024-04-07 13:52:01 UTC MAIN commitmail json YAML

doc: Updated net/pear-Net_SMTP to 1.12.0

(taca)

2024-04-07 13:51:31 UTC MAIN commitmail json YAML

www/php-concrete-cms: update to 9.2.8

9.2.8 (2024-04-02)

(taca)

2024-04-04 15:29:56 UTC MAIN commitmail json YAML

doc/TODO: +apache

+ apache-2.4.59.

(taca)

2024-03-24 14:46:37 UTC MAIN commitmail json YAML

doc: Updated www/ruby-rack2 to 2.2.9

(taca)

2024-03-24 14:46:24 UTC MAIN commitmail json YAML

www/ruby-rack2: update to 2.2.9

2.2.9 (2023-03-21)

* Return empty when parsing a multi-part POST with only one end
  delimiter. (#2104, [@alpaca-tc])

(taca)

2024-03-24 14:45:31 UTC MAIN commitmail json YAML

doc: Updated www/ruby-rack to 3.0.10

(taca)

2024-03-24 14:45:02 UTC MAIN commitmail json YAML

www/ruby-rack: update to 3.0.10

3.0.10 (2024-03-21)

* Backport #2104 to 3-0-stable: Return empty when parsing a multi-part POST
  with only one end delimiter. (#2164, @JoeDupuis)

(taca)

2024-03-24 14:43:18 UTC MAIN commitmail json YAML

doc: Updated www/ruby-excon to 0.110.0

(taca)

2024-03-24 14:43:04 UTC MAIN commitmail json YAML

www/ruby-excon: update to 0.110.0

0.110.0 (2024-03-12)

* update bundled default certificates

(taca)

2024-03-24 14:41:56 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-s3 to 1.146.0

(taca)

2024-03-24 14:41:40 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-s3: update to 1.146.0

1.146.0 (2024-03-18)

* Feature - Fix two issues with response root node names.

1.145.0 (2024-03-15)

* Feature - Documentation updates for Amazon S3.

1.144.0 (2024-03-13)

* Feature - This release makes the default option for S3 on Outposts request
  signing to use the SigV4A algorithm when using AWS Common Runtime (CRT).

1.143.1 (2024-03-12)

* Issue - Include original part errors in message when aborting multipart
  upload fails (#2990).

(taca)

2024-03-24 14:40:58 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-kms to 1.78.0

(taca)

2024-03-24 14:40:34 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-kms: update to 1.78.0

1.78.0 (2024-03-18)

* Feature - Adds the ability to use the default policy name by omitting the
  policyName parameter in calls to PutKeyPolicy and GetKeyPolicy

(taca)

2024-03-24 14:39:40 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-sdk-core to 3.191.4

(taca)

2024-03-24 14:39:24 UTC MAIN commitmail json YAML

www/ruby-aws-sdk-core:::: update to 3.191.4

3.191.4 (2024-03-15)

* Issue - Ensure output unions work correctly with stub_responses.

(taca)

2024-03-24 14:38:43 UTC MAIN commitmail json YAML

doc: Updated www/ruby-aws-partitions to 1.899.0

(taca)