Automatic conversion of the NetBSD pkgsrc CVS module, use with care
Find a file
morr 140315b125 Maintenance and security update to version 5.2.4.
Changes:
5.2.4:

Props to Evan Ricafort for finding an issue where stored XSS (cross-site scripting) could be added via the Customizer.
Props to J.D. Grimes who found and disclosed a method of viewing unauthenticated posts.
Props to Weston Ruter for finding a way to create a stored XSS to inject Javascript into style tags.
Props to David Newman for highlighting a method to poison the cache of JSON GET requests via the Vary: Origin header.
Props to Eugene Kolodenker who found a server-side request forgery in the way that URLs are validated.
Props to Ben Bidner of the WordPress Security Team who discovered issues related to referrer validation in the admin.

5.2.3:
#38415: New Custom Link menu item has a wrong fallback label
#45739: Block Editor: $editor_styles bug.
#45935: A URL in do_block_editor_incompatible_meta_box function does not have classic-editor__forget parameter
#46757: Media Trash: The Bulk Media options when in the Trash shouldn’t provide two primary buttons
#46758: Media Trash: Primary button(s) should be on the left
#46899: Ensure that tables generated by the Settings API have no semantics
#47079: Incorrect version for excerpt_allowed_blocks filter
#47113: Media views: dismiss notice button is invisible
#47145: Feature Image dialog does not follow the dialog pattern
#47190: Twenty Seventeen: Native audio and video embeds have no focus state.
#47340: Twenty Nineteen: Revise Latest Posts block styles to support post content options.
#47386: Fix headings hierarchy in the legacy Custom Background and Custom Header pages
#47390: Improve accessibility of forms elements within some “form-table” forms
#47414: Twenty Seventeen: Button block preview has extra spacing within button
#47458: Fix tab sequence order in the Media attachment browser
#47489: Emoji are substituted in preformatted blocks
#47502: Media modal bottom toolbar cuts-off content in Internet Explorer 11
#47538: Minor Verbiage Update – Switch ‘developer time’ for ‘a developer’
#47543: Twenty Seventeen: buttons don’t change color on hover and focus
#47561: Plugin: View details popup layout issue
#47603: My account toggle on admin bar not visible at high zoom levels
#47604: Undefined variable: locked in wp-admin/edit-form-blocks.php
#47687: Use alt tags for gallery images in editor
#47688: Color hex code in color picker displayed in RTL instead of LTR on RTL install (take 2)
#47693: customizer Color picker should get closed when click on color picker area.
#47723: Adding a custom link in nav-menus.php doesn’t trim whitespace
#47758: Font sizes on installation screen are too small
#47835: PHP requirement always set to null for plugins
#47888: Adding a custom link in menu via Customize doesn’t trim whitespace.

Security Fixes
Props to Simon Scannell of RIPS Technologies for finding and disclosing two issues. The first, a cross-site scripting (XSS) vulnerability found in post previews by contributors. The second was a cross-site scripting vulnerability in stored comments.
Props to Tim Coen for disclosing an issue where validation and sanitization of a URL could lead to an open redirect.
Props to Anshul Jain for disclosing reflected cross-site scripting during media uploads.
Props to Zhouyuan Yang of Fortinet’s FortiGuard Labs who disclosed a vulnerability that for cross-site scripting (XSS) in shortcode previews.
Props to Ian Dunn of the Core Security Team for finding and disclosing a case where reflected cross-site scripting could be found in the dashboard.
Props to Soroush Dalili (@irsdl) from NCC Group for disclosing an issue with URL sanitization that can lead to cross-site scripting (XSS) attacks.
In addition to the above changes, we are also updating jQuery on older versions of WordPress. This change was added in 5.2.1 and is now being brought to older versions.
2019-10-23 07:25:20 +00:00
archivers archivers/ruby-archive-tar-minitar: update to 0.8 2019-10-22 07:33:37 +00:00
audio alure: use a PLIST variable to account for different names on macos. 2019-10-23 00:17:54 +00:00
benchmarks dnsperf: update to 2.3.2. Changed upstream to DNS-OARC. 2019-10-16 10:05:28 +00:00
biology py-pydicom: Update to 1.3.0 2019-10-01 14:45:29 +00:00
bootstrap bootstrap/bootstrap: prevent --wrkdir from being a symlink 2019-09-13 20:10:35 +00:00
cad (cad/gtkwave) Updated 3.3.100 to 3.3.101 2019-10-17 15:12:51 +00:00
chat Rename audio/portaudio-devel to audio/portaudio 2019-10-20 11:10:47 +00:00
comms delete ancient Asterisk 11.* 2019-09-22 20:00:31 +00:00
converters Recursive revbump for poppler 0.81.0 2019-10-19 12:46:04 +00:00
cross nios2-gcc41: Remove, successor nios2-gcc. 2019-10-17 20:56:39 +00:00
databases Switch sphinx to versioned deps. 2019-10-21 21:19:35 +00:00
devel py-test5: added version 5.2.1 2019-10-22 18:39:38 +00:00
distfiles
doc doc: Added emulators/cannonball version 0.3.20190924 2019-10-23 00:22:59 +00:00
editors Rename audio/portaudio-devel to audio/portaudio 2019-10-20 11:10:47 +00:00
emulators Added cannonball to Makefile SUBDIRs. 2019-10-23 00:22:11 +00:00
filesystems Add mkspiffs 0.2.3 2019-10-07 10:13:16 +00:00
finance py-braintree: updated to 3.57.1 2019-10-16 14:31:23 +00:00
fonts spleen: update to 1.5.0. 2019-10-07 08:41:10 +00:00
games games/fltk-sudoku: Update to 1.3.5 2019-10-21 10:04:12 +00:00
geography Rename audio/portaudio-devel to audio/portaudio 2019-10-20 11:10:47 +00:00
graphics py-Pillow: updated to 6.2.1 2019-10-22 18:45:02 +00:00
ham Switch sphinx to versioned deps. 2019-10-21 21:55:03 +00:00
inputmethod ibus: update PLIST to actually match for cldr-emoji-annotation-35.12.14971.0. 2019-09-14 11:34:18 +00:00
lang lang/pear: update Archive_Tar to 1.4.8 2019-10-22 07:46:25 +00:00
licenses licenses: amaya was removed 2019-09-09 11:42:33 +00:00
mail mail/dovecot2-pigeonhole: update to 0.5.8 2019-10-22 13:26:19 +00:00
math R: drop maintainership 2019-10-20 03:29:10 +00:00
mbone mbone/rtptools: fix location of HTML documentation 2019-10-12 20:14:08 +00:00
meta-pkgs ruby-gnome: Update to 3.4.1. 2019-10-19 08:25:17 +00:00
misc Fix sphinx-build binary name 2019-10-21 22:15:10 +00:00
mk Prepare for compat80 package. 2019-10-15 11:15:49 +00:00
multimedia mate-media: update to 1.22.2 2019-10-21 23:08:52 +00:00
net youtube-dl: Update to 20191022 2019-10-22 06:31:13 +00:00
news About 0.146 2019-10-15 18:09:21 +00:00
packages
parallel lld: updated to 9.0.0 2019-10-19 14:01:36 +00:00
pkgtools pkgtools/R2pkg: remove unused code 2019-10-19 22:10:58 +00:00
print Add print/xpdf4. 2019-10-22 22:21:26 +00:00
regress regress/check-perms: add test for broken CHECK_PERMS_AUTOFIX 2019-09-19 23:53:36 +00:00
security Update pev to version 0.80 2019-10-22 16:37:05 +00:00
shells shells/bash2-doc: fix location of HTML documentation 2019-10-12 20:51:48 +00:00
sysutils Fix sphinx-build binary name 2019-10-21 22:15:10 +00:00
templates
textproc py-xmlschema: added version 1.0.15 2019-10-22 17:32:02 +00:00
time Fix sphinx-build binary name 2019-10-21 22:15:10 +00:00
wm wm/flwm: Update to 1.16 2019-10-18 10:40:40 +00:00
www Maintenance and security update to version 5.2.4. 2019-10-23 07:25:20 +00:00
x11 Use gnu++11 to fix undefined reference to allocate, from joerg 2019-10-21 23:58:04 +00:00
Makefile
pkglocate
README README: minor grammatical fix 2019-01-29 03:11:03 +00:00

$NetBSD: README,v 1.21 2019/01/29 03:11:03 gutteridge Exp $

pkgsrc is a framework for building software on UNIX-like systems.

To use, bootstrap using:
    cd pkgsrc/bootstrap/
    ./bootstrap

build packages, use:
    cd pkgsrc/category/package-name
    $PREFIX/bin/bmake install

Where $PREFIX is where you've chosen to install packages (typically /usr/pkg)

Bugs and patches can be filed in the following link (use category 'pkg'):
https://www.netbsd.org/cgi-bin/sendpr.cgi?gndb=netbsd

To fetch the main CVS repository:
    cvs -d anoncvs@anoncvs.NetBSD.org:/cvsroot checkout -P pkgsrc

It's also possible to contribute through pkgsrc wip (work in progress), for
more information, see http://pkgsrc.org/wip/users/

Please see doc/pkgsrc.txt for information.