Commit graph

16834 commits

Author SHA1 Message Date
adam
5e2ebcfe58 py-django-countries: update to 4.6.2
Version 4.6.2
Use transparency layer for flag sprites.
2017-09-26 17:16:16 +00:00
wiz
8dbc902911 p5-Apache-Test: update to 1.40.
1.40 Sep 6 2016

Specify licence (Apache 2.0) in META.yml. [Steve Hay, CPAN RT#111359]

Fix broken POD. [Steve Hay]

Switch argument order in "openssl gendsa". [rjung]

Add (limited) checks for *_SAN_*_n and *_DN_Email variables. [kbrand]

Update key sizes and message digest to what is common in 2015. [kbrand]
2017-09-26 15:01:51 +00:00
wiz
d09df76ecf p5-Apache-LogFormat-Compiler: update to 0.35.
0.35 2017-03-08T04:10:07Z

   - fixed test. load module from relative path.

0.34 2017-03-07T03:18:42Z

   - re package with Minilla v3
2017-09-26 15:00:26 +00:00
wiz
3014fed310 p5-Alien-GvaScript: update to 1.45.
1.45 04.06.2017
  - fix #121658 : . no longer in @INC in Perl 5.26 (Graham Ollis&Slaven_Rezic++)
2017-09-26 14:58:51 +00:00
wiz
06bd0ca307 *: remove qt3 and the packages using it, including KDE3
Announced in https://mail-index.netbsd.org/pkgsrc-users/2017/09/10/msg025556.html
2017-09-26 10:26:54 +00:00
adam
58748300b7 nghttp2: update to 1.26.0
nghttp2 v1.26.0
* docs: Fix some typos in the nghttpx how-to
* build: Update Dockerfile.android
* build: Refactoring include directories for build as CMake subdirectory (add_subdirectory(nghttp2))
* nghttpx: Fix OCSP related error when building with BoringSSL
* h2load: Fix bug that timing script stalls with -m1
* h2load: Reservoir sampling
* h2load: Add timing-based load-testing in h2load
2017-09-26 07:05:05 +00:00
jlam
eb0346be1b www/siege: Fix installation if ${PKG_SYSCONFBASE} != ${PREFIX}/etc.
The software Makefiles try to install example configuration files
directly into $(sysconfdir), which is set during the configure
stage to ${PKG_SYSCONFDIR} == ${PREFIX}/etc/siege.  However, pkgsrc
standards require that the example configuration files be installed
into ${PREFIX}/share/examples/siege ( ${EGDIR} ).

Pass sysconfdir=${EGDIR} to the bmake(1) process during the install
stage so that the Makefile recipe will install the example files
into the correct location.

Remove the "install" substitution class that was trying to do the
same thing but which fails if ${PKG_SYSCONFBASE} != ${PREFIX}/etc.

Bump the PKGREVISION due to changes in the installed files if the
package is built with default settings.  Fix discussed with nils@
in private correspondence.
2017-09-25 22:39:56 +00:00
wiedi
acb227c17e goaccess: fix build on SunOS
Needs c99
2017-09-22 22:18:01 +00:00
maya
fa56fcc71d ap2-perl: missing PKGREVISION bump from perl 5.26 update
PR pkg/52507: ap24-perl module upgrade breaks Apache HTTPd v2.4
2017-09-22 09:59:30 +00:00
morr
475cadd78a Security update to version 4.8.2
Security issues:
- $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi). WordPress core is not directly vulnerable to this issue, but we’ve added hardening to prevent plugins and themes from accidentally causing a vulnerability. Reported by Slavco.
- A cross-site scripting (XSS) vulnerability was discovered in the oEmbed discovery. Reported by xknown of the WordPress Security Team.
- A cross-site scripting (XSS) vulnerability was discovered in the visual editor. Reported by Rodolfo Assis (@brutelogic) of Sucuri Security.
- A path traversal vulnerability was discovered in the file unzipping code. Reported by Alex Chapman (noxrnet).
- A cross-site scripting (XSS) vulnerability was discovered in the plugin editor. Reported by 陈瑞琦 (Chen Ruiqi).
- An open redirect was discovered on the user and term edit screens. Reported by Yasin Soliman (ysx).
- A path traversal vulnerability was discovered in the customizer. Reported by Weston Ruter of the WordPress Security Team.
- A cross-site scripting (XSS) vulnerability was discovered in template names. Reported by Luka (sikic).
- A cross-site scripting (XSS) vulnerability was discovered in the link modal. Reported by Anas Roubi (qasuar).

And 6 other fixes:

* Emoji
- #41584 - Upgrade Twemoji to 2.5.0
- #41852 - Fix UN flag test by returning the correct value.

*I18N
- #41794 - Support numbers in locales during installation

* Security
- #13377 - Add more sanitization in _cleanup_header_comment

*Widgets
- #41596 - New Text Widget recognizes HTML but does not render it in the front end
- #41622 - Text widget can show DOMDocument::loadHTML() warnings in admin when is_legacy_widget method is called

More on https://codex.wordpress.org/Version_4.8.2
2017-09-21 19:24:46 +00:00
schmonz
82dbb9d930 Add upstream patch to fix build with po4a 0.52. 2017-09-20 02:57:31 +00:00
taca
ec28c80372 cleanup: remove unnecessary RUBY_VERSIONS_ACCEPTED
Remove unnecessary RUBY_VERSIONS_ACCEPTED since ruby21 removed.
2017-09-19 16:36:07 +00:00
wiz
1026272e56 Fix URL in comment. 2017-09-18 13:34:51 +00:00
wiz
d5ee4f67b4 apache24: fix "Optionsbleed" security bug
See https://blog.fuzzing-project.org/60-Optionsbleed-HTTP-OPTIONS-method-can-leak-Apaches-server-memory.html

Bump PKGREVISION.
2017-09-18 13:24:05 +00:00
taca
d2e4a9e780 www/contao44: update to 4.4.0
release announce:

Contao 4.4.5 is available		18.09.2017 10:28 by Leo Feyer

Contao version 4.4.5 is available.  The bugfix release fixes several issues
including a problem with the install tool and a problem with SVG images in
Internet Explorer.  In addition, the back end theme has been adjusted again
and some of the previous changes have been revised.
2017-09-18 12:19:55 +00:00
maya
33ebf687dc revbump for requiring ICU 59.x 2017-09-18 09:52:56 +00:00
taca
b39ef4d534 www/ruby-websocket-driver: update to 0.7.0
### 0.7.0 / 2017-09-11

* Add `ping` and `pong` to the set of events users can listen to
2017-09-18 01:11:36 +00:00
taca
7eaf96ef91 www/ruby-faraday_middleware: update to 0.12.2
0.12.2 (2017/08/04)

* Fixes race condition issue with rubygems.org


0.12.1 (2017/08/03)

* Fixes support for Oj < 3.3.3 (#163)
* Adds support for parser_options on MultiXML and SafeYAML parsers


0.12.0 (2017/07/28)

* Replace rash with rash_alt (#136)
* Allow write_options to be specified for FaradayMiddleware::Caching (#155)
* Add support for passing options to JSON.parse (#156)
* Parse YAML safely (#157)
* Handle responses with missing Location header (#159)
* Removes support for ruby < 1.9.3 (#162)
2017-09-18 01:07:42 +00:00
wiz
ef141a6b79 Reset maintainer 2017-09-16 19:26:41 +00:00
wiz
7e25dfc00f py-autobahn: follow redirect 2017-09-16 08:50:30 +00:00
adam
092eb1aa64 py-channels: update to 1.1.8
1.1.8
* Reverted recent JS fixes for subprotocols on some phones as they do not work
  in Chrome.
2017-09-16 06:51:54 +00:00
adam
15b6448d86 py-channels: update to 1.1.7
1.1.7:
* Fixed compatability with Django 1.10 and below
* JS library: Fixed error with 1006 error code
2017-09-15 12:49:07 +00:00
adam
4f8769987e py-autobahn: update to 17.9.2
17.9.2
new: allow setting correlation URI and anchor flag in WAMP messages from user code
fix: WebSocket proxy connect on Python 3 (unicode vs bytes bug)
2017-09-15 12:47:04 +00:00
martin
2463f2d5db firefox52: hacks for sparc64/big endian platforms
While graphics support for big endian platforms ist still not quite
right, we prefer slightly garbled display (or missing items) over
browser crashes.
2017-09-13 10:03:47 +00:00
wiz
a08ccc4150 recursive bump for qt5-qtwebkit dependency change 2017-09-12 13:51:59 +00:00
martin
7032e3af16 Make it buildable on sparc64. 2017-09-12 07:39:08 +00:00
wiz
7f590eba34 Remove htmlfix, dead upstream. 2017-09-12 05:51:29 +00:00
taca
07346b0671 Make bash dependecny to runtime only. 2017-09-11 16:21:22 +00:00
taca
9cffbdf3a3 Make bash dependecny to runtime only. 2017-09-11 16:08:41 +00:00
taca
aaea926951 Update ruby-jekyll-gist to 1.4.1.
## 1.4.1 / 2017-06-21

  * Don't ask .empty? until it's a String. (#38)
  * rename Liquid 4 `has_key?` to `key?` to add compatibility for liquid 4 (#41)
  * Test against Ruby 2.1 to 2.4 (#45)
2017-09-11 16:03:17 +00:00
taca
d6bde360cd Update ruby-jekyll to 3.5.2.
3.5.2 (2017/8/18)

* Backport #6281 for v3.5.x: Fix Drop#key? so it can handle a nil argument (#6288)
* Backport #6280 for v3.5.x: Guard against type error in absolute_url (#6287)
* Backport #6266 for v3.5.x: Memoize the return value of Document#url (#6301)
* Backport #6273 for v3.5.x: delegate StaticFile#to_json to StaticFile#to_liquid (#6302)
* Backport #6226 for v3.5.x: Reader#read_directories: guard against an entry not being a directory (#6304)
* Backport #6247 for v3.5.x: kramdown: symbolize keys in-place (#6303)


3.5.1 (2017/7/18)

Minor Enhancements

* Use Warn for deprecation messages (#6192)
* site template: Use plugins key instead of gems (#6045)

Bug Fixes

* Backward compatiblize URLFilters module (#6163)
* Static files contain front matter default keys when to_liquid'd (#6162)
* Always normalize the result of the relative_url filter (#6185)

Documentation

* Update reference to trouble with OS X/macOS (#6139)
* added BibSonomy plugin (#6143)
* add plugins for multiple page pagination (#6055)
* Update minimum Ruby version in installation.md (#6164)
* [docs] Add information about finding a collection in site.collections (#6165)
* Add {%raw%} to Liquid example on site (#6179)
* Added improved Pug plugin - removed 404 Jade plugin (#6174)
* Linking the link (#6210)
* Small correction in documentation for includes (#6193)
* Fix docs site page margin (#6214)

Development Fixes

* Add jekyll doctor to GitHub Issue Template (#6169)
* Test with Ruby 2.4.1-1 on AppVeyor (#6176)
* set minimum requirement for jekyll-feed (#6184)
2017-09-11 16:02:12 +00:00
taca
1066247e7e Update ruby-selenium-webdriver to 3.5.2.
pkgsrc change: update HOMEPAGE.

Chantes are too many to write here, please refer:
<https://github.com/SeleniumHQ/selenium/releases>.
2017-09-11 15:48:35 +00:00
taca
d48f9eb8b1 Update ruby-rack-contrib to 1.6.0.
1.6.0 (2017/09/01)

* Rack::PostBodyContentTypeParser: if the middleware is told a POST body is
  JSON, but it doesn't parse as JSON, then... it's not really JSON, and the
  request is now rejected with a 400 response. Thanks to Yukihiko SAWANOBORI
  (@sawanoboly) for the fix.

1.5.0 (2017/07/19)

After an extended hiatus, rack-contrib maintenance is back on track. This
is a tidy-up release, merging things that have sat around for far too long.

* git-version-bump has now been moved to being a development dependency,
  thanks to Tobias Haagen Michaelsen.

* Rack::AcceptLocale can be restricted to a set of enforced locales, thanks to
  Paco Guzman.

* Rack::NotFound's path argument is now optional, thanks to Ed Morley.

* Rack::BounceFavicon now has a description and tests, thanks to Steven
  Wilkin.

* The automated Travis CI suite now tests all supported Ruby versions up to
  2.4, which necessitated a few small changes.
2017-09-11 15:43:46 +00:00
taca
cce596b9e1 Update ruby-rack-cache to 1.7.1
1.7.1 (2017/09/06)

* Documentation fix.
* Fix nil warnings.
* Return current date if the Date header is not parseable.
2017-09-11 15:40:27 +00:00
taca
53a13d4fa4 Update ruby-patron to 0.9.1.
### 0.9.1

o Added ssl_version options `TLSv1_1`, `TLSv1_2`, `TLSv1_3` for explicitly
  forcing the SSL version

    * requires the appropriate versions of libCURL and OpenSSL installed to
      support these new options
    * reference: https://curl.haxx.se/libcurl/c/CURLOPT_SSLVERSION.html

o Added a new `:http_version` option with `HTTPv1_1` and `HTTPv2_0` values to
  explicitly set the HTTP version of HTTP/1.1 or HTTP/2.0

    * requires the appropriate versions of libCURL and OpenSSL installed to
      support these new options
    * reference: https://curl.haxx.se/libcurl/c/CURLOPT_HTTP_VERSION.html

o Updates the gem release procedure for more convenience, using the updated
  Rubygems.org tasks

o Update a few minor dependencies and documentation to be Ruby
  2.4.1-compatible, add 2.4.1. to Travis CI matrix

o Add `Session#download_byte_limit` for limiting the permitted download size.

  This can be very useful in dealing with untrusted download sources, which
  might attempt to send very large responses that would overwhelm the
  receiving client.

o Add `Patron.libcurl_version_exact` which returns a triplet of major, minor
  and patch libCURL version numbers. This can be used for more fine-grained
  matching when using some more esoteric Curl features which might not
  necessarily be available on libCURL Patron has been linked against.
2017-09-11 15:35:37 +00:00
taca
f77f0c6492 Update ruby-mustermannto 1.0.1.
**Mustermann 1.0.1** (2017-08-26)

#### Docs
* Updating readme to list Ruby 2.2 as minimum
* Fix rendering of HTML table
* Update summary and description in gemspec file.

#### Fixes
* avoid infinite loop by removing comments when receiving extended regexp
* avoid unintended conflict of namespace
* use Regexp#source instead of Regexp#inspect
2017-09-11 15:20:20 +00:00
taca
facd14de62 Update ruby-faraday to 0.13.1.
0.13.1 (2017/8/18)

* Fixes an incompatibility with Addressable::URI being used as uri_parser

0.13.0 (2017/8/15)

* Dynamically reloads the proxy when performing a request on an absolute
  domain (#701)
* Prefer #hostname over #host. (#714)
* Adapter support for Net::HTTP::Persistent v3.0.0 (#619)
* Fixes an edge-case issue with response headers parsing (missing HTTP header)
  (#719)

0.12.2 (2017/07/21)

* Parse headers from aggregated proxy requests/responses (#681)
* Guard against invalid middleware configuration with warning (#685)
* Do not use :insecure option by default in Patron (#691)
* Fixes an issue with HTTPClient not raising a Faraday::ConnectionFailed
  (#702)
* Fixes YAML serialization/deserialization for Faraday::Utils::Headers (#690)
* Fixes an issue with Options having a nil value (#694)
* Fixes an issue with Faraday.default_connection not using
  Faraday.default_connection_options (#698)
* Fixes an issue with Options.merge! and Faraday instrumentation middleware
  (#710)
2017-09-11 14:52:27 +00:00
wen
9f40e1c8a9 Update to 3.3.2
Upstream changes:
Here is the full list of fixed issues in 3.3.2.

Highlights

    MDL-59492 - Gray out hidden courses in the new course overview block
    MDL-57412 - Setting "Always link course sections" should apply consistently in Boost and Clean/More
    MDL-58196 - "Require grade to pass" in quiz completion settings must be checked only with "Require grade", otherwise it does not work and causes confusions
    MDL-57698 - Bug fix: Backup and restore cause deadlock with sqlsrv driver

Fixes and improvements

    MDL-55912 - Assignment: when blind marking is enabled, students should receive teacher participant number in the email and not their own
    MDL-54607 - Calendar export should not export events without duration as full-day events, i.e. assignment due dates have time component that was lost during export
    MDL-59490 - Bug fix: LTI does not work when activity has a long name
    MDL-55937 - Assignment: fixed error when viewing attachments of team submission
    MDL-59511, MDL-59746, MDL-59539, MDL-59869 - Multiple fixes in OAuth 2 services (Google, OwnCloud, Nextcloud, etc)
    MDL-35290 - My private files should continue working even if some files in filesystem are currently unreadable
    MDL-57259 - Fixed bug that caused multiple debugging messages in error.log when teachers use assignment grading
    MDL-56646 - Assignment: changing maximum grade of the module could result in negative grades in assignment which were pushed as "0" to the gradebook. This bug was fixed and will not happen in the future. However, according to Moodle policy, no existing grades were changed. Teachers will see the warning that there are erroneous grades and will be able to fix all of them with one click
    MDL-54965 - Database module: fixed SQL error when you edit an entry after having added a new picture/file field
    MDL-46495 - When uploading courses the setting "Completion tracking" should be set to the site default
    MDL-59262 - Courses made via course request or "Upload course" tool should respect default course sections
    MDL-59442 - Some third party modules had very big icons in the Default activity completion page
    MDL-38129 - Grade export of user profile fields can now work with uppercase letters in the fields names
    MDL-59317 - Performance improvements on the messages page
    MDL-57246 - Trying to view a forum without the capability may lead you to a broken page.
    MDL-59287 - Generate calendar event for "Expected completed on" for all modules.
    MDL-55364 - Forum headers alignment on narrow screens
    MDL-57649 - Lesson: Fixed bug deleting files unrelated to the pages being deleted
    MDL-59195 - Assignments: when switching role to student teacher should be able to view group submissions
    MDL-59068 - Lesson: Restore the behaviour of "No, I just want to go on to the next question"

Security issues

A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version
2017-09-11 12:08:18 +00:00
abs
b58acac2a6 Drop www/p5-HTML-FixEntities & textproc/p5-Text-Substitute - unmaintained by author (me) 2017-09-11 09:57:39 +00:00
jmcneill
0eaca2bd7f Fix PLIST 2017-09-10 17:39:34 +00:00
taca
5f6e898949 Update ruby-raindrops to 0.19.0.
=== raindrops 0.19.0 - Rack 2.x middleware compatibility / 2017-08-09 23:52 UTC

  This release fixes Rack 2.x compatibility for the few users of
  Raindrops::Middleware
  <https://bogomips.org/raindrops/Raindrops/Middleware.html>.
  Thanks to Dmytro Shteflyuk for this release.

  No need to upgrade unless you use Raindrops::Middleware with
  Rack 2.x.

  There's also a few minor, inconsequential cleanups.

  Dmytro Shteflyuk (1):
        Properly override respond_to? in Raindrops::Middleware::Proxy

  Eric Wong (2):
        Ruby thread compatibility updates
        tcp_info: remove unnecessary extconf.h include
2017-09-10 16:20:33 +00:00
taca
cf7a983b46 Update thin to 1.7.2.
== 1.7.2 Bachmanity
 * Add config support for ssl_version and ssl_cipher_list [frameworked]
2017-09-10 16:19:05 +00:00
taca
19b33b9e3f Update ruby-css-parser to 1.6.0.
Version 1.6.0

* Handles font-size/ line-height shorthand with spaces
2017-09-10 16:17:12 +00:00
taca
779edc90c4 Update ruby-capybara to 2.15.1.
# Version 2.15.1

Release date: 2017-08-04

### Fixed

*  `attach_file` with no extension/MIME type when using the `:rack_test` driver
   [Thomas Walpole]

# Version 2.15.0

Release date: 2017-08-04

### Added

*  `sibling` and `ancestor` finders added [Thomas Walpole]
*  Added ability to pass options to registered servers when setting
*  Added basic built-in driver registrations `:selenium_chrome` and
   `:selenium_chrome_headless` [Thomas Walpole]
*  Add `and_then` to Capybara RSpec matchers which behaves like the previous
   `and` compounder. [Thomas Walpole]
*  Compound RSpec expectations with Capybara matchers now run both matchers
   inside a retry loop rather than waiting for one to pass/fail before
   checking the second.  Will make `#or` more performant and confirm both
   conditions are true "simultaneously" for `and`.  [Thomas Walpole] If you
   still want the
*  Default filter values are now included in error descriptions [Thomas Walpole]
*  Add `Session#refresh` [Thomas Walpole]
*  Loosened restrictions on where `Session#within_window` can be called from
   [Thomas Walpole]
*  Switched from `mime-types` dependency to `mini_mime` [Jason Frey]
2017-09-10 16:14:59 +00:00
gavan
ca207f8a94 Replace interpreters 2017-09-10 11:07:08 +00:00
gavan
cee90c5ae4 Fix interpreters 2017-09-10 11:06:10 +00:00
jaapb
098ac1404f No substantive changes, but a lot of patches to make package work with
ocaml-lwt 3 and js_of_ocaml 3. These are all in the upstream github, so
should be removed with the next release.
2017-09-08 17:14:34 +00:00
jaapb
83fa17b52e No substantive changes, but a lot of patches to make Ocsigen work with
ocaml-lwt 3. Most of these are already in the upstream github, so should
be removed at the next release.
2017-09-08 17:10:46 +00:00
adam
891cde26b9 17.9.1:
new: allow setting correlation ID in WAMP messages from user code
fix: distribute LICENSE file in all distribution formats (using setup.cfg metadata)
2017-09-08 11:09:35 +00:00
jaapb
410a1001fa Recursive revbump associated with update of ocaml to 4.05 2017-09-08 09:51:18 +00:00