Commit graph

18831 commits

Author SHA1 Message Date
gutteridge
4809d06f0f firefox: note new cbindgen and NSS minimum dependencies
cbindgen is now >= 0.8.7 and NSS is now >= 3.44.1.
2019-07-12 03:52:13 +00:00
gutteridge
eabd6085ec firefox: note Rust dependency is now >= 1.34.0 2019-07-12 01:17:33 +00:00
ryoon
ca6148bc87 Update to 16.0.3
Changelog:
16.0.3
Changes
    Do not fail hard on new user mail error (server#16189)
    Fix redirect after rescanFailedIntegrityCheck to "Overview" page (server#16244)
    Fix permissions for drag-n-drop uploads (server#16249)
    Try to delete the cypress folder of the viewer app (server#16297)
    Send browser notifications again (notifications#373)

16.0.2
Changes
    Update ca bundle (server#15553)
    Update ca bundle checker (server#15554)
    User management/subadmin: rephrase ambiguous error message (server#15575)
    Update shipped.json to include privacy and recommendations (server#15592)
    Show supported apps in app management (server#15593)
    Update CRL due to revoked cookbook.crt (server#15628)
    Only show sharing section if it has content (server#15649)
    Remove quota feedback if no link set (server#15666)
    Allow redis cluster to use password (server#15686)
    Don't run repair step for every individual user, outsource that to background job (server#15718)
    Check the actual status code for 204 and 304 (server#15724)
    [Security] Bump tar from 2.2.1 to 2.2.2 (server#15728)
    Don't notify admins if no potentially over exposing links found (server#15745)
    Also allow dragging below the file list (server#15754)
    Change text color in search box in darktheme, ref #15598 (server#15768)
    Check for free space on touch (server#15772)
    Search files by id in shared storages last (server#15799)
    Hide newFile menu if quota is set to 0B (server#15856)
    Add core/js/dist/ to l10nignore (server#15948)
    Add LDAP integr. test for receiving share candidates with group limitation (server#15984)
    Remove auto focus of share input field on dialog open, fix #15261 (server#16010)
    LDAP) API: return one base properly when multiple are configured (server#16015)
    Handle storage exceptions when trying to set mtime (server#16038)
    Fix LDAP Wizard forgetting groups on select with search (server#16051)
    Revert "Fix userid casting in notifications" (server#16068)
    Fix appid argument for integrity:check-app (server#16080)
    Fix full text search for groupfolders (server#16082)
    Fall back to black for non-color values (server#16089)
    Check if uploading to lookup server is enabled before verifying (server#16091)
    Allow apps to store longer messages in the comments API (server#16105)
    Invalidates user when plugin reported deletion success (server#16112)
    Fix download link included in public share page with hidden download (server#16125)
    Better check reshare permissions (server#16127)
    Verify that paths are valid for recursive local move (server#16128)
    Don't allow to disable encryption via the API (server#16133)
    Do not show a internet connectivity warning if internet access is dis… (server#16146)
    Update Nextcloud version in docs link (server#16157)
    Allow apps to overwrite the maximum length when reading from database (server#16177)
    RefreshWebcalJob: replace ugly Regex with standard php utils (server#16201)
    Better check reshare permissions part2 (server#16211)
    Fix "unshare group share from self" activity (activity#380)
    Fix load of character maps (files_pdfviewer#141)
    [Security] Bump axios from 0.18.0 to 0.18.1 (firstrunwizard#192)
    Correctly show errors when setting the password (gallery#529)
    Blacklist using .noimage (gallery#533)
    Update dependabot deps in stable16 (notifications#359)
    Increase size of icon bubble for more visibility (notifications#368)
    Add app description to readme and appinfo (privacy#133)
    Catch and filter share that can't be found (recommendations#79)
    [Security] Bump axios from 0.18.0 to 0.18.1 (recommendations#92)
    [Security] Bump tar from 2.2.1 to 2.2.2 (viewer#113)
    [Security] Bump axios from 0.18.0 to 0.19.0 (viewer#117)
2019-07-11 12:05:34 +00:00
ryoon
828fbd3f7c Update to 68.0
* Sync with www/firefox-68.0
2019-07-11 11:34:31 +00:00
ryoon
6e7c053228 Update to 68.0
Changelog:

New
    Dark mode in reader view expands so that windows are also dark on the controls, sidebars and toolbars.

    Improved extension security and discovery:
        New reporting feature in about:addons allows you to report security and performance issues with extensions and themes.
        Redesigned extensions dashboard in about:addons provides easy access to information about your extensions, including data and settings access required by each extension.
        Find high quality, secure extensions via the Recommended Extensions program in about:addons, which now displays user count and ratings for each extension. "Recommended” badges for these extensions also appear on AMO. More extensions will be added over time.

    Cryptomining and fingerprinting protections are added to strict content blocking settings in Privacy & Security preferences.

    WebRender will roll out to Windows 10 users with AMD graphics cards.

    Windows Background Intelligent Transfer Service (BITS) update download support, which allows Firefox update downloads to continue when Firefox is closed.

Fixed

    Various security fixes

    Local files can no longer access other files in the same directory.

Security fixes:
#CVE-2019-9811: Sandbox escape via installation of malicious language pack
#CVE-2019-11711: Script injection within domain through inner window reuse
#CVE-2019-11712: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects
#CVE-2019-11713: Use-after-free with HTTP/2 cached stream
#CVE-2019-11714: NeckoChild can trigger crash when accessed off of main thread
#CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a segmentation fault
#CVE-2019-11715: HTML parsing error can contribute to content XSS
#CVE-2019-11716: globalThis not enumerable until accessed
#CVE-2019-11717: Caret character improperly escaped in origins
#CVE-2019-11718: Activity Stream writes unsanitized content to innerHTML
#CVE-2019-11719: Out-of-bounds read when importing curve25519 private key
#CVE-2019-11720: Character encoding XSS vulnerability
#CVE-2019-11721: Domain spoofing through unicode latin 'kra' character
#CVE-2019-11730: Same-origin policy treats all files in a directory as having the same-origin
#CVE-2019-11723: Cookie leakage during add-on fetching across private browsing boundaries
#CVE-2019-11724: Retired site input.mozilla.org has remote troubleshooting permissions
#CVE-2019-11725: Websocket resources bypass safebrowsing protections
#CVE-2019-11727: PKCS#1 v1.5 signatures can be used for TLS 1.3
#CVE-2019-11728: Port scanning through Alt-Svc header
#CVE-2019-11710: Memory safety bugs fixed in Firefox 68
#CVE-2019-11709: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8
2019-07-11 11:32:40 +00:00
nia
2f0184d881 Update the Python HOMEPAGEs that I missed earlier. 2019-07-09 23:02:28 +00:00
nia
680f78bd82 libsass: Seems to fail with gcc7 unless cmath is included 2019-07-09 20:31:33 +00:00
nia
6d4e298675 Use https for readthedocs.io. 2019-07-09 11:35:14 +00:00
schwarz
983254b5ec Updated www/micro_httpd to 20140814
(no change documentation found)
2019-07-08 21:20:28 +00:00
leot
7216ecd24c ruby-net-http-persistent: Adjust ruby-connection_pool dependency pattern
Match the semantic of `~>' in the gem.
2019-07-08 16:26:39 +00:00
leot
b70ef27424 ruby-net-http-persistent: Update to 3.0.1
pkgsrc changes:
 - Add missing dependency to ruby-connection_pool

Changes:
No changelog available, mostly documentation improvements and misc bug
fixes according commits.
2019-07-08 16:24:43 +00:00
nia
c66ee34855 Follow some http->https redirects. 2019-07-08 10:36:25 +00:00
adam
87b19e266e py-autobahn: updated to 19.7.1
19.7.1
fix: implement client side payload exceed max size; improve max size exceeded handling
fix: detect when our transport is "already" closed at connect time
fix: XBR examples
2019-07-08 07:49:07 +00:00
adam
2f33f4e5de py-pylint-django: updated to 2.0.10
Version 2.0.10:
- Suppress no-member for ManyToManyField.
- Fix UnboundLocalError with ForeignKey(to=).
2019-07-08 07:41:44 +00:00
adam
64dcef60a6 py-asgiref: updated to 3.1.4
3.1.4:
* Fixed an incompatibility with Python 3.5 introduced in the last release.
2019-07-08 07:36:57 +00:00
nia
ea01e39d68 snownews: Support OpenSSL 1.1. 2019-07-07 18:13:23 +00:00
adam
7a7f40b160 py-asgiref: updated to 3.1.3
3.1.3:
* async_timeout has been removed as a dependency, so there are now no required
  dependencies.
* The WSGI adapter now sets REMOTE_ADDR from the ASGI client.
2019-07-06 23:00:04 +00:00
adam
570107277e py-soupsieve: updated to 1.9.2
1.9.2
- **FIX**: Shortcut last descendant calculation if possible for performance.
- **FIX**: Fix issue where `Doctype` strings can be mistaken for a normal text node in some cases.
- **FIX**: A top level tag is not a `:root` tag if it has sibling text nodes or tag nodes. This is an issue that mostly manifests when using `html.parser` as the parser will allow multiple root nodes.
2019-07-06 22:49:00 +00:00
wen
1920080f57 Update to 1.33.0
Upstream changelog is too long, please visit:
https://www.mediawiki.org/wiki/Release_notes/1.33
2019-07-06 14:57:07 +00:00
adam
7b52bbbaf6 py-flask-jwt-extended: updated to 3.20.0
3.20.0:
Look for JWTs in the same order that they are defined in JWT_TOKEN_LOCATION.
2019-07-05 07:57:02 +00:00
nia
f2a99fa92b elinks: Support OpenSSL 1.1. Based on the FreeBSD Ports patches.
While here, define LICENSE.

Bump PKGREVISION.
2019-07-04 12:15:04 +00:00
adam
da54db0aeb py-waitress: updated to 1.3.0
1.3.0:

Deprecations

- The send_bytes adjustment now defaults to 1 and is deprecated
  pending removal in a future release.

Features

- Add a new outbuf_high_watermark adjustment which is used to apply
  backpressure on the app_iter to avoid letting it spin faster than data
  can be written to the socket. This stabilizes responses that iterate quickly
  with a lot of data.

- Stop early and close the app_iter when attempting to write to a closed
  socket due to a client disconnect. This should notify a long-lived streaming
  response when a client hangs up.

- Adjust the flush to output SO_SNDBUF bytes instead of whatever was
  set in the send_bytes adjustment. send_bytes now only controls how
  much waitress will buffer internally before flushing to the kernel, whereas
  previously it used to also throttle how much data was sent to the kernel.
  This change enables a streaming app_iter containing small chunks to
  still be flushed efficiently.

Bugfixes

- Upon receiving a request that does not include HTTP/1.0 or HTTP/1.1 we will
  no longer set the version to the string value "None". See

- When a client closes a socket unexpectedly there was potential for memory
  leaks in which data was written to the buffers after they were closed,
  causing them to reopen.

- Fix the queue depth warnings to only show when all threads are busy.

- Trigger the app_iter to close as part of shutdown. This will only be
  noticeable for users of the internal server api. In more typical operations
  the server will die before benefiting from these changes.

- Fix a bug in which a streaming app_iter may never cleanup data that has
  already been sent. This would cause buffers in waitress to grow without
  bounds. These buffers now properly rotate and release their data.

- Fix a bug in which non-seekable subclasses of io.IOBase would trigger
  an exception when passed to the wsgi.file_wrapper callback.
2019-07-03 20:36:51 +00:00
adam
cfd9ef45fd py-cherrypy: updated to 18.1.2
v18.1.2
Restore a native WSGI-less HTTP server support.
Reduce log level for non-error events in win32.py
2019-07-03 19:59:47 +00:00
adam
ac4e0efcfd py-grappelli_safe: updated to 0.5.2
0.5.2:
Bug fixes
2019-07-03 19:55:56 +00:00
adam
7170d61b52 py-bottle: updated to 0.12.17
0.12.17:
Bug fixes.
2019-07-03 19:52:53 +00:00
adam
02bf0c4992 py-mod_wsgi: updated to 4.6.7
Version 4.6.7:

Bugs Fixed
Fix Windows build errors due to Python 3.7+ not providing empty function stubs for PyOS_AfterFork_Child() and PyOS_AfterFork_Parent().


Version 4.6.6:

Bugs Fixed
Fix compilation failures when using Python 3.8.

Features Changed
When running mod_wsgi-express it will do a search for the location of bash and sh when defining the shell to use for the generated apachectl. The shell used can be overridden using --shell-executable option. This is to get around issue with FreeBSD not having /bin/bash.

New Features
The Apache request ID is accessible in request events as request_id.
The per request data dictionary accessible using mod_wsgi.request_data() is now also accessible in events as request_data.
2019-07-03 19:50:33 +00:00
nia
a71a26c408 Use https for pear.php.net. 2019-07-03 07:28:21 +00:00
nia
77cb240288 Use https for github. 2019-07-03 07:19:03 +00:00
hauke
74bfdd9c4e Update to GLPI v9.4.3, with security and bug fixes.
- (security) Prevent execution of XSS on rich text,
- (security) Prevent xss attack on user picture,
- Fix performance issues when using entities,
- New "Prevent take into account" action on tickets business rules,
- New "Status" criterion on tickets business rules,
- Change and problem tasks can now be marked as private,

The full changelog is available under
<https://github.com/glpi-project/glpi/milestone/36?closed=1>
2019-07-02 12:23:41 +00:00
adam
36119cc1b1 py-google-api-python-client: depend on py-google-auth; re-enable Python 2.7; use TEST_DEPENDS 2019-07-02 12:06:13 +00:00
leot
753cdcc0af webkit-gtk: Update to 2.24.3
pkgsrc changes:
 - Remove not needed dependency to gnutls and add missing dependency to
   libtasn1 (previously indirectly picked up via gnutls)
 - Remove patch-Source_WebCore_platform_graphics_gstreamer_MediaPlayerPrivateGStreamerBase.cpp,
   fix is now present in 2.24.3.
 - Remove a no more needed hunk in
   patch-Source_JavaScriptCore_assembler_ARM64Assembler.h.

Changes:
2.24.3
======
 - Deprecate WebSQL APIs.
 - Make Previous/Next gesture work in RTL mode.
 - Fix content disappearing when using CSS transforms.
 - Fix rendering artifacts in youtube volume button.
 - Fix trapezoid artifact in github comment box.
 - Fix video pause that sometimes caused to skip to finish.
 - Fix volume level changes when playing a video.
 - Fix HLS streams being slow to start.
 - Fix some radio streams that could not be played.
 - Fix the build with older versions of GStreamer.
 - Fix the build with video and audio disabled.
 - Fix several crashes and rendering issues.
 - Translation updates: Brazilian Portuguese.
2019-07-02 10:48:08 +00:00
adam
30880c3b86 py-google-apitools: updated to 0.5.30
0.5.30:
Unknown changes.
2019-07-02 10:08:19 +00:00
wen
5d1573a4af Update to 0.208000
Upstream changes:
0.208000  2019-06-19 10:21:16-04:00 America/New_York

    [ BUG FIXES ]
    * PR #1493: Fix body not being sent on forward (Johannes Piehler)
    * PR #1498: Load missing Encode in logger role (simbabque)
    * PR #1501: Set :raw when copying files to new project (xenu)
    * GH #1502: Update jquery (racke)

    [ ENHANCEMENTS ]
    * GH #1320: Implement prepare_app keyword (Sawyer X)

    [ DOCUMENTATION ]
    * Tidy up Cookbook POD. (Mohammad S Anwar)
2019-07-02 07:40:26 +00:00
adam
6d9bcc3d92 py-landslide: updated to 1.1.6
v1.1.6
Fix packaging again

v1.1.5
Fix packaging

v1.1.4
Setup Travis CI
Update Python versions in setup.py
Pin dependency versions to fix markdown issue
2019-07-02 04:19:59 +00:00
adam
416e638f17 py-flask-jwt-extended: updated to 3.19.0
3.19.0:
Adds support for using multiple algorithms for decoding JWTs.
2019-07-02 03:36:18 +00:00
nia
6138584c0f p5-CGI: HOMEPAGE 404s rather than redirecting. fix it. 2019-07-01 22:01:19 +00:00
nia
314d0da6b3 Follow some remaining search.cpan.org redirects. 2019-07-01 21:35:32 +00:00
adam
5a5b61ea49 sassc: updated to 3.6.1
3.6.1:
This is the SassC for LibSass 3.6.1
2019-07-01 19:15:02 +00:00
adam
537ee7a7ec py-django2: updated to 2.2.3
Django 2.2.3
Fix CVE-2019-12781: Incorrect HTTP detection with reverse-proxy connecting via HTTPS
Fixed a regression in Django 2.2 where Avg, StdDev, and Variance crash with filter argument
Fixed a regression in Django 2.2.2 where auto-reloader crashes with AttributeError, e.g. when using ipdb
2019-07-01 18:26:22 +00:00
adam
5e47ee7900 py-django: updated to 1.11.22
Django 1.11.22:
Fix CVE-2019-12781: Incorrect HTTP detection with reverse-proxy connecting via HTTPS
2019-07-01 18:23:52 +00:00
jaapb
817dc4b557 Added ocaml-cohttp to Makefile SUBDIRs 2019-07-01 15:49:47 +00:00
jaapb
90c3678280 Added package www/ocaml-cohttp, an OCaml http library.
Cohttp is an OCaml library for creating HTTP daemons. It has a portable
HTTP parser, and implementations using various asynchronous programming
libraries. It's needed as a dependency for some ocaml-git options.
2019-07-01 15:48:53 +00:00
adam
52d30966a5 py-test-django: updated to 3.5.1
3.5.1:
Bugfixes
Fix compatibility with pytest 5.x
2019-07-01 11:02:31 +00:00
ryoon
57d0806c39 Recursive revbump from boost-1.70.0 2019-07-01 04:07:44 +00:00
nia
d5c846b3af Update packages using a search.cpan.org HOMEPAGE to metacpan.org.
The former now redirects to the latter.

This covers the most simple cases where http://search.cpan.org/dist/name
can be changed to https://metacpan.org/release/name.

Reviewed by hand to hopefully make sure no unwanted changes sneak in.
2019-06-30 20:14:13 +00:00
fox
69bb668d89 cliqz: update to 1.27.4
Changes since 1.27.3:

Merge with Firefox 67.0.4
2019-06-29 13:42:18 +00:00
nia
cefdcb69eb Follow some redirects. 2019-06-24 10:36:50 +00:00
nia
ec7cdd43bb Remove amaya.
It's unmaintained by upstream for most of this decade (even then, this
is an old version), and broken in bulk builds since at least last year.

Discussed on pkgsrc-users@.
2019-06-23 09:21:30 +00:00
nia
6c8c451a77 Use https for all invisible-island.net HOMEPAGEs. 2019-06-22 11:37:13 +00:00
fox
ecf52512e9 cliqz: update to 1.27.3
Changes since 1.27.2:

Merge with Firefox 67.0.3
2019-06-22 09:21:46 +00:00