Commit graph

272553 commits

Author SHA1 Message Date
taca
13bb6ff47d lang/php56: Update to 5.6.32
* pkgsrc change: remove post-extract which is not required any more.
* including securiy fixes.

26 Sep 2017, PHP 5.6.32

- Date:
  . Fixed bug #75055 (Out-Of-Bounds Read in timelib_meridian()). (Derick)

- mcrypt:
  . Fixed bug #72535 (arcfour encryption stream filter crashes php). (Leigh)

- PCRE:
  . Fixed bug #75207 (applied upstream patch for CVE-2016-1283). (Anatol)
2017-10-27 08:45:06 +00:00
nat
3ac2d4c072 Enable oss dma backend for NetBSD-8.
Bump PKG_REVISION.

OK wiz@.
2017-10-27 01:28:53 +00:00
tsutsui
b9556488fc doc: Updated multimedia/adobe-flash-player to 27.0.0.183 2017-10-26 15:10:17 +00:00
tsutsui
57f9461a99 adobe-flash-player: update to 27.0.0.183.
Upstream announcement:

 https://helpx.adobe.com/flash-player/release-note/fp_27_air_27_release_notes.html

October 25, 2017

In today's release, we've updated Flash Player with an importantfunctional
fix impacting Flex content and recommend those users impacted update.
2017-10-26 15:09:21 +00:00
tez
aa189a0299 doc: wget patches for CVE-2017-13089 and CVE-2017-13090 2017-10-26 15:02:21 +00:00
tez
ed9b20ecfe wget: patches for VE-2017-13089 and CVE-2017-13090 2017-10-26 15:01:38 +00:00
schmonz
73d6fc2182 doc: Updated net/djbdns to 1.05nb12 2017-10-26 14:48:46 +00:00
schmonz
72ae9477c4 b.root-servers.net has changed IP (old one still works for a while).
Bump PKGREVISION.
2017-10-26 14:42:51 +00:00
fhajny
a812fff77c doc: Updated lang/nodejs to 8.8.1 2017-10-26 09:13:06 +00:00
fhajny
8f7441c811 Update lang/nodejs to 8.8.1.
- net: Fix timeout with null handle issue. This is a regression in 8.8.0
2017-10-26 09:12:55 +00:00
adam
53223175ed Updated www/nghttp2, security/py-m2crypto 2017-10-26 07:12:34 +00:00
adam
8aab303a9a py-m2crypto: updated to 0.27.0
0.27.0:
- Fix licence: it is MIT, not BSD
- At least minimal support of SNI in httpslib.
- Small bugfixes and cleanups.
- More effort to make build system more robust (now should work even on
  Debian LTS).
- Restore m2.rsa_set_e() and m2.rsa_set_n().
- Make sure that every exceptional return throws and exception and vice
  versa.
2017-10-26 07:08:10 +00:00
maya
67bc9d9670 doc: Updated print/ghostscript-gpl to 9.06nb15 2017-10-26 07:01:53 +00:00
maya
64b12cf9a6 ghostscript-gpl: use system tiff instead of outdated builtin.
bump pkgrevision
2017-10-26 07:01:33 +00:00
adam
d10beed58a nghttp2: updated to 1.27.0
nghttp2 v1.27.0
build: Fixed accidental compiler flags concatenation for MSVC
build: Reduce libxml2 version requirement to 2.6.26
asio: Support for Windows / MinGW
h2load: Print out h2 header fields with --verbose option
nghttpx: Send non-final response to HTTP/1.1 or HTTP/2 client only
2017-10-26 06:57:37 +00:00
maya
43faa1e1a4 doc: Updated print/ghostscript-gpl to 9.06nb14 2017-10-26 04:41:57 +00:00
maya
ba47aa3967 ghostscript-gpl: always avoid building builtin (outdated) zlib
It is currently builtin into libgs.so.

bump PKGREVISION
2017-10-26 04:41:37 +00:00
minskim
ba59200839 doc: Added devel/py-logbook version 1.1.0 2017-10-25 22:17:53 +00:00
minskim
1119c0495e devel/Makefile: Add py-logbook 2017-10-25 22:17:13 +00:00
minskim
8fb6a96719 devel/py-logbook: Import version 1.1.0 from pkgsrc-wip
Logbook is a logging system for Python that replaces the standard
library's logging module. It was designed with both complex and simple
applications in mind and the idea to make logging fun.

Packaged by Kamel Derouiche and improved/updated by wiz@ and me.
2017-10-25 22:16:31 +00:00
khorben
06f67b3ba7 Add support for CFLAGS and LDFLAGS
This notably fixes building with RELRO enabled.

Bump PKGREVISION, since this generates a different binary now that SSP and
FORTIFY are enabled.
2017-10-25 22:04:30 +00:00
khorben
d47c7eb361 Add support for LDFLAGS
This notably fixes building with RELRO enabled.
2017-10-25 21:59:33 +00:00
khorben
2420cdd2bb Add support for LDFLAGS
This notably fixes building with RELRO enabled.
2017-10-25 21:45:38 +00:00
khorben
65f113ceee Add support for LDFLAGS
This notably fixes building with RELRO enabled.
2017-10-25 21:32:35 +00:00
khorben
6f28218edc Set the license to the GNU GPL (version 2) 2017-10-25 21:30:42 +00:00
khorben
2ecbd1fe72 Add support for CFLAGS and LDFLAGS
This notably fixes building with RELRO enabled.

Bump PKGREVISION, since this generates a different binary now that SSP and
FORTIFY are enabled.
2017-10-25 21:17:13 +00:00
wiz
14a27ba44d py-flask-limiter: fix PLIST
requires.txt is also installed with python-3.x
2017-10-25 20:46:21 +00:00
fhajny
1e54165a0c Enable bfs 2017-10-25 14:58:46 +00:00
fhajny
b4d16dd505 doc: Added sysutils/bfs version 1.1.3 2017-10-25 14:58:06 +00:00
fhajny
8adbc24d2f Import bfs-1.1.3 as sysutils/bfs.
bfs is a variant of the UNIX find command that operates breadth-first
rather than depth-first.
2017-10-25 14:57:50 +00:00
maya
535389d3bd doc: Updated shells/fish to 2.6.0nb3 2017-10-25 14:48:00 +00:00
maya
5a5d357503 fish: don't install own version of pcre2, delete hopefully
unneeded file (from pcre2 configure)

bump pkgrevision
2017-10-25 14:47:40 +00:00
fhajny
bbc0eda09c www/lighttpd: Fix build on SunOS. 2017-10-25 14:27:20 +00:00
ryoon
c1ab0ebfb8 Updated www/apache-tomcat85 to 8.5.23 2017-10-25 14:20:00 +00:00
ryoon
59f8bfe957 Update to 8.5.23
Changelog:
    A fix for CVE-2017-12617.
    Stricter validation of the HTTP Host header.
    Add ExtractingRoot, a new WebResourceRoot implementation that extracts JARs to the work directory for improved performance when deploying packed WAR files.
    Added support for the OpenSSL SSL_CONF API. To support this the minimum required Tomcat Native version is 1.2.14.
2017-10-25 14:18:47 +00:00
fhajny
c225ae9f91 doc: Updated lang/nodejs4 to 4.8.5 2017-10-25 13:56:15 +00:00
fhajny
c2595be473 Update lang/nodejs4 to 4.8.5.
zlib:
- CVE-2017-14919 - In zlib v1.2.9, a change was made that causes an
  error to be raised when a raw deflate stream is initialized with
  windowBits set to 8. On some versions this crashes Node and you cannot
  recover from it, while on some versions it throws an exception.
  Node.js will now gracefully set windowBits to 9 replicating the legacy
  behavior to avoid a DOS vector.
2017-10-25 13:56:01 +00:00
fhajny
7827053698 doc: Updated lang/nodejs6 to 6.11.5 2017-10-25 13:45:29 +00:00
fhajny
6254d2aab3 Update lang/nodejs6 to 6.11.5.
zlib:
- CVE-2017-14919 - In zlib v1.2.9, a change was made that causes an
  error to be raised when a raw deflate stream is initialized with
  windowBits set to 8. On some versions this crashes Node and you cannot
  recover from it, while on some versions it throws an exception.
  Node.js will now gracefully set windowBits to 9 replicating the legacy
  behavior to avoid a DOS vector.
2017-10-25 13:45:18 +00:00
fhajny
1a979ed98b doc: Updated lang/nodejs to 8.8.0 2017-10-25 12:33:23 +00:00
fhajny
8d4da6626a Update lang/nodejs to 8.8.0.
crypto:
- expose ECDH class

http2:
- http2 is now exposed by default without the need for a flag
- a new environment variable NODE_NO_HTTP2 has been added to allow
  userland http2 to be required
- support has been added for generic Duplex streams

module:
- resolve and instantiate loader pipeline hooks have been added
  to the ESM lifecycle

zlib:
- CVE-2017-14919 - In zlib v1.2.9, a change was made that causes
  an error to be raised when a raw deflate stream is initialized
  with windowBits set to 8. On some versions this crashes Node and
  you cannot recover from it, while on some versions it throws an
  exception. Node.js will now gracefully set windowBits to 9
  replicating the legacy behavior to avoid a DOS vector.
2017-10-25 12:33:12 +00:00
jaapb
ea2d145333 doc: Updated devel/ocaml-migrate-parsetree to 1.0.6 2017-10-25 11:02:17 +00:00
jaapb
643a0bac39 Updated devel/ocaml-migrate-parsetree to version 1.0.6.
This version has support for ocaml 4.06, and includes several other
minor bugfixes and improvements.
2017-10-25 11:01:58 +00:00
leot
f3f006ca5e doc: Updated print/mupdf to 1.11nb5 2017-10-25 11:00:14 +00:00
leot
c7c4a4eefa mupdf: backport patches to fix several possible security issues
Backport patches from upstream to address CVE-2017-14685, CVE-2017-14686,
CVE-2017-14687, CVE-2017-15369 and CVE-2017-15587.

These will not be needed for the next mupdf stable release.

Bump PKGREVISION.
2017-10-25 11:00:03 +00:00
maya
ece69eff2a fzf: spoon feed information about how to setup key bindings
zsh might have a better mechanism, but this works!
2017-10-25 10:42:13 +00:00
maya
a3f5531907 doc: Updated shells/fish to 2.6.0nb2 2017-10-25 09:33:06 +00:00
maya
719664a431 fish: use variadic tparm on netbsd curses.
don't mess with the declaration of tparm_solaris_kludge unnecessarily.

uwe thinks the non-variadic tparm is wrong (so might be broken for
solaris curses), but I'm not sure how to correct it.

PR pkg/52649

bump PKGREVISION
2017-10-25 09:32:38 +00:00
adam
4620bf5782 Updated devel/py-flake8-import-order 2017-10-25 09:12:27 +00:00
adam
9454565629 py-flake8-import-order: updated to 0.14
0.14:
* Fixed I201 error raising for cryptography style.
* Added I202 error when there is an additional newline in a section of
  imports.
* Added ``ntpath`` and ``os2emxpath`` to stdlib list.
2017-10-25 09:11:59 +00:00