summaryrefslogtreecommitdiff
path: root/net/wget
AgeCommit message (Collapse)AuthorFilesLines
2022-10-26*: bump PKGREVISION for libunistring shlib major bumpwiz1-2/+2
2022-06-28*: recursive bump for perl 5.36wiz1-1/+2
2022-03-08wget: update to 1.21.3.wiz2-7/+6
* Noteworthy changes in release 1.21.3 (2022-02-26) ** Fix computation of total bytes downloaded during FTP trasnfers (#61277) ** Add option to select TLS 1.3 on the command line ** Fix HSTS build issues on some 64-bit big-endian systems ** Hide password during status report in --no-verbose ** Remove a sprurious print statement that showed up even during --quiet ** Some more cleanups and bug-fixes
2021-12-08revbump for icu and libffiadam1-2/+2
2021-10-26net: Replace RMD160 checksums with BLAKE2s checksumsnia1-2/+2
All checksums have been double-checked against existing RMD160 and SHA512 hashes Not committed (merge conflicts...): net/radsecproxy/distinfo The following distfiles could not be fetched (fetched conditionally?): ./net/citrix_ica/distinfo citrix_ica-10.6.115659/en.linuxx86.tar.gz ./net/djbdns/distinfo dnscache-1.05-multiple-ip.patch ./net/djbdns/distinfo djbdns-1.05-test28.diff.xz ./net/djbdns/distinfo djbdns-1.05-ignoreip2.patch ./net/djbdns/distinfo djbdns-1.05-multiip.diff ./net/djbdns/distinfo djbdns-cachestats.patch
2021-10-07net: Remove SHA1 hashes for distfilesnia1-2/+1
2021-09-29revbump for boost-libsadam1-1/+2
2021-09-12wget: remove unused patch after updatewiz1-17/+0
2021-09-12wget: update to 1.21.2.wiz3-10/+9
* Noteworthy changes in release 1.21.2 (2021-09-07) ** Support for autoconf 2.71 ** Fix a double free in FTP when using an absolute path ** Release tarballs no longer have a dependency on Python. ** --page-requisites will now also download links marked as "alternate stylesheet" or "icon"
2021-05-24*: recursive bump for perl 5.34wiz1-2/+2
2021-04-21revbump for boost-libsadam1-1/+2
2021-01-14Use the macro used elsewhere to fix build on at least macOS. Alsoschmonz2-1/+19
build-tested on CentOS 7 and Tribblix m24.
2021-01-12wget: Update to 1.21.1ryoon4-38/+7
Changelog: * Noteworthy changes in release 1.21.1 (2021-01-09) ** Fix compilation on MacOS and Solaris 9 ** Resove bashism from configure.ac ** Fix a compilation warning on 32-bit systems
2021-01-08Instead of auto-choosing openssl if gnutls is not selected, useschmonz1-3/+5
PKG_OPTIONS_OPTIONAL_GROUPS and allow building with neither. The default remains openssl.
2021-01-08Apply upstream patch to fix compilation error on macOS and Solaris 9.schmonz2-1/+16
2021-01-04wget: remove patch for perl-5.18wiz2-50/+1
2021-01-04wget: update to 1.21.wiz5-57/+62
* Changes in Wget 1.21 ** Improve the number of translated strings ** Remove all uses of alloca In some places the length of untrusted strings has been used, e.g. strings from the command line or from remote. ** Fix buffer overflows in progress bar code in some locales ** Fix two null pointer accesses ** Amend cookie file header to be recognized by the 'file' command ** Post Handshake Authentication for OpenSSL ** Require gettext version 0.19.3+ ** Add configure flags --enable-fsanitize-ubsan, --enable-fsanitize-asan and --enable-fsanitize-msan for gcc and clang ** Make several smaller fixes, enhance fuzzing, enhance building
2020-11-05*: Recursive revbump from textproc/icu-68.1ryoon1-2/+2
2020-08-31*: bump PKGREVISION for perl-5.32.wiz1-2/+2
2020-06-02Revbump for icuadam1-2/+2
2020-05-22revbump after updating security/nettleadam1-2/+2
2020-04-12Recursive revision bump after textproc/icu updateadam1-2/+2
2020-03-08*: recursive bump for libffiwiz1-2/+2
2020-01-18all: migrate several HOMEPAGEs to httpsrillig1-2/+2
pkglint --only "https instead of http" -r -F With manual adjustments afterwards since pkglint 19.4.4 fixed a few indentations in unrelated lines. This mainly affects projects hosted at SourceForce, as well as freedesktop.org, CTAN and GNU.
2020-01-18*: Recursive revision bump for openssl 1.1.1.jperkin1-2/+2
2020-01-16*: Remove USE_OLD_DES_API.jperkin1-2/+1
OpenSSL 1.1.1d no longer ships des_old.h, and the time for this being necessary appears to be behind us.
2019-11-03net: align variable assignmentsrillig1-5/+5
pkglint -Wall -F --only aligned --only indent -r No manual corrections.
2019-08-11Bump PKGREVISIONs for perl 5.30.0wiz1-2/+2
2019-07-20*: recursive bump for nettle 3.5.1wiz1-2/+2
2019-05-26wget: Fix https:// handling with OpenSSL 1.1.1leot3-2/+51
Backport upstream commit 14e3712b8c39165219fa227bd11f6feae7b09a33 to fix https:// handling when openssl.cnf file is not found. PKGREVISION++
2019-04-07Update wget to 1.20.3, which fixes CVE-2019-5953gutteridge2-8/+7
It appears that the buffer overflow issue referred to is the same in both 1.20.2 and 1.20.3 (they had to fix the fix). Upstream changelog: * Changes in Wget 1.20.3 ** Fixed a buffer overflow vulnerability * Changes in Wget 1.20.2 ** NTLM authentication will retry under certain cases ** Fixed a buffer overflow vulnerability
2019-04-03Recursive revbump from textproc/icuryoon1-1/+2
2019-02-10updating wget to 1.20.1, which fixes CVE-2018-20483spz2-8/+7
Upstream changelog: * Changes in Wget 1.20.1 ** --xattr is no longer default since it introduces privacy issues. ** --xattr saves the Referer as scheme/host/port, user/pw/path/query/fragment are no longer saved to prevent privacy issues. ** --xattr saves the Original URL without user/password to prevent privacy issues. * Changes in Wget 1.20 ** Add new option `--retry-on-host-error` to treat local errors as transient and hence Wget will retry to download the file after a brief waiting period. ** Fixed multiple potential resource leaks as found by static analysis ** Wget will now not create an empty wget-log file when running with -q and -b switches together ** When compiled using the GnuTLS >= 3.6.3, Wget now has support for TLSv1.3 ** Now there is support for using libpcre2 for regex pattern matching ** When downloading over FTP recursively, one can now use the --{accept,reject}-regex switches to fine-tune the downloaded files ** Building Wget from the git sources now requires autoconf 2.63 or above. Building from the Tarballs works as it used to.
2018-12-09revbump after updating textproc/icuadam1-2/+2
2018-11-04Enable the psl option by default for wget.bsiegert2-4/+4
Enabling the PSL is a good thing for security and privacy, as it protects against all sorts of cookie shenanigans. Bump revision.
2018-08-22Recursive bump for perl5-5.28.0wiz1-1/+2
2018-07-28Add a "psl" option (off by default) to build wget with PSL.bsiegert1-2/+12
This improves privacy by restricting cookies to a well-known list of public suffixes. We can consider turning that option on by default in the future. Fixes PR pkg/53459.
2018-05-07wget: update to 1.19.5.wiz2-8/+7
* Changes in Wget 1.19.5 * Fix cookie injection (CVE-2018-0494) * Enable TLS1.3 with recent OpenSSL environment * New option --ciphers to set GnuTLS / OpenSSL ciphers directly * Updated CSS grammar to CSS 2.2 * Fixed several memleaks found by OSS-Fuzz * Fixed several buffer overflows found by OSS-Fuzz * Fixed several integer overflows found by OSS-Fuzz * Several minor bug fixes * Changes in Wget 1.19.4 * A major bug that caused GZip'ed pages to never be decompressed has been fixed * Support for Content-Encoding and Transfer-Encoding have been marked as experimental and disabled by default * Changes in Wget 1.19.3 * Prevent erroneous decompression of .gz and .tgz files with broken servers * Added support for HTTP 308 Permanent Redirect response * Fix a segfault in some cases where the Content-Type header is not sent * Support OpenSSL 1.1 builds without using deprecated features * Fix netrc file detection on Windows * Several minor bug fixes
2018-04-17Add p11-kit to gnutls/bl3.mk and bump dependencies.wiz1-1/+2
2017-11-23wget: update to 1.19.2.wiz4-95/+8
* Changes in Wget 1.19.2 * Fix CVE-2017-13089 (Stack overflow in HTTP protocol handling) * Fix CVE-2017-13090 (Heap overflow in HTTP protocol handling) * New option --compression for gzip Content-Encoding * New option --[no]-netrc to control .netrc parsing * Added GNU extensions to .netrc parsing * Improved IDNA 2003 compatibility * Fix VPATH issues * Improved and extended the test suite * Support Wayback Machine's X-Archive-Orig-last-modified * Several bug fixes
2017-11-14wget: Use devel/libidn2 and adjust `idn' option logic in options.mkleot2-4/+7
Since wget-1.19, libidn2 is needed for the IDN/IRIs support. Adjust the `idn' package option logic to reflect that and explicitly ask for it via CONFIGURE_ARGS. This should also fix the build without the `idn' option selected pointed out by john heasley via PR pkg/52726. Bump PKGREVISION
2017-10-26wget: patches for VE-2017-13089 and CVE-2017-13090tez4-3/+80
2017-05-15Add a patch for CVE-2017-6508 from upstream.kim2-2/+12
2017-02-20Update to 1.19.1ryoon4-81/+7
Changelog: * Changes in Wget 1.19.1 * Fix bugs, a regression, portability/build issues * Add new option --retry-on-http-error * Changes in Wget 1.19 * New option --use-askpass=COMMAND. Fetch user/password by calling an external program. * Use IDNA2008 (+ TR46 if available) through libidn2 * When processing a Metalink header, --metalink-index=<number> allows to process the header's application/metalink4+xml files. * When processing a Metalink file, --trust-server-names enables the use of the destination file names specified in the Metalink file, otherwise a safe destination file name is computed. * When processing a Metalink file, enforce a safe destination path. Remove any drive letter prefix under w32, i.e. 'C:D:file'. Call libmetalink's metalink_check_safe_path() to prevent absolute, relative, or home paths: https://tools.ietf.org/html/rfc5854#section-4.1.2.1 https://tools.ietf.org/html/rfc5854#section-4.2.8.3 * When processing a Metalink file, --directory-prefix=<prefix> sets the top of the retrieval tree to prefix for Metalink downloads. * When processing a Metalink file, reject downloaded files which don't agree with their own metalink:size value: https://tools.ietf.org/html/rfc5854#section-4.2.16 * When processing a Metalink file, with --continue resume partially downloaded files and keep fully downloaded files even if they fail the verification. * When processing a Metalink file, create the parent directories of a "path/file" destination file name: https://tools.ietf.org/html/rfc5854#section-4.1.2.1 https://tools.ietf.org/html/rfc5854#section-4.2.8.3 * On a recursive download, append a .tmp suffix to temporary files that will be deleted after being parsed, and create them readable/writable only by the owner. * New make target 'check-valgrind' * Fix several bugs * Fix compatibility issues
2016-10-30add a patch for CVE-2016-7098 from upstreamspz3-3/+60
2016-09-19Recursive PKGREVISION bump for gnutls shlib major bump.wiz1-2/+2
2016-07-09Bump PKGREVISION for perl-5.24.0 for everything mentioning perl.wiz1-1/+2
2016-06-11Updated wget to 1.18.wiz3-8/+23
* Changes in Wget 1.18 * By default, on server redirects to a FTP resource, use the original URL to get the local file name. Close CVE-2016-4971. This introduces a backward-incompatibility for HTTP->FTP redirects and any script that relies on the old behaviour must use --trust-server-names. * Check the HSTS file is not world-writable before using it. * Parse <img srcset> attributes on a recursive download. * Fix problem with SNI server names having trailing dot(s) * New options --bind-dns-address and --dns-servers. * When Wget is built with libiconv, it now converts non-ASCII URIs to the locale's codeset when it creates files. The encoding of the remote files and URIs is taken from --remote-encoding, defaulting to UTF-8. The result is that non-ASCII URIs and files downloaded via HTTP/HTTPS and FTP will have names on the local filesystem that correspond to their remote names.
2016-03-05Bump PKGREVISION for security/openssl ABI bump.jperkin1-1/+2
2015-12-13Update wget to 1.17.1:wiz3-40/+7
* Changes in Wget 1.17.1 * Fix compile error when IPv6 is disabled or SSL is not present. * Fix HSTS memory leak. * Fix progress output in non-C locales. * Fix SIGSEGV when -N and --content-disposition are used together. * Add --check-certificate=quiet to tell wget to not print any warning about invalid certificates.