summaryrefslogtreecommitdiff
path: root/www
AgeCommit message (Collapse)AuthorFilesLines
2020-06-26Pullup ticket #6244 - requested by niapkgsrc-2020Q1bsiegert3-3/+38
www/midori: bugfix Revisions pulled up: - www/midori/Makefile 1.130 - www/midori/distinfo 1.30 - www/midori/patches/patch-core_browser.vala 1.1 --- Module Name: pkgsrc Committed By: nia Date: Tue Jun 16 13:54:25 UTC 2020 Modified Files: pkgsrc/www/midori: Makefile distinfo Added Files: pkgsrc/www/midori/patches: patch-core_browser.vala Log Message: midori: Fix typing / and backspace in the URL bar. Noticed by benny on twitter PKGREVISION++
2020-06-17Pullup ticket #6240 - requested by tacabsiegert2-8/+10
www/ruby-websocket-extensions: security fix Revisions pulled up: - www/ruby-websocket-extensions/Makefile 1.4 - www/ruby-websocket-extensions/distinfo 1.3 --- Module Name: pkgsrc Committed By: taca Date: Sun Jun 14 15:57:43 UTC 2020 Modified Files: pkgsrc/www/ruby-websocket-extensions: Makefile distinfo Log Message: devel/ruby-websocket-extensions: update to 0.1.5 Update ruby-websocket-extensions to 0.1.5. pkgsrc change: * Add "USE_LANGUAGES= # none". * Change LICENSE to apache-2.0. ### 0.1.5 / 2020-06-02 - Remove a ReDoS vulnerability in the header parser (CVE-2020-7663) ### 0.1.4 / 2019-06-10 - Fix a deprecation warning for using the `=~` operator on `true` - Change license from MIT to Apache 2.0
2020-06-08Pullup ticket #6224 - requested by tacabsiegert3-10/+11
www/ruby-em-http-request: security fix Revisions pulled up: - www/ruby-em-http-request/Makefile 1.5 - www/ruby-em-http-request/PLIST 1.5 - www/ruby-em-http-request/distinfo 1.6 --- Module Name: pkgsrc Committed By: taca Date: Tue Jun 2 13:46:43 UTC 2020 Modified Files: pkgsrc/www/ruby-em-http-request: Makefile PLIST distinfo Log Message: www/ruby-em-http-request: update to 1.1.6 Update ruby-em-http-request to 1.1.6. 1.1.6 (2020-06-02) - Merge TLS verification patch from Faraday (CVE-2020-13482) - IPv6 literal support
2020-06-08Pullup ticket #6223 - requested by tacabsiegert2-7/+7
www/ruby-puma: security fix Revisions pulled up: - www/ruby-puma/Makefile 1.23 - www/ruby-puma/distinfo 1.18 --- Module Name: pkgsrc Committed By: taca Date: Sun May 24 13:47:49 UTC 2020 Modified Files: pkgsrc/www/ruby-puma: Makefile distinfo Log Message: www/ruby-puma: update to 4.3.5 Update ruby-puma to 4.3.5. 4.3.4/4.3.5 and 3.12.5/3.12.6 / 2020-05-22 Each patchlevel release contains a separate security fix. We recommend simply upgrading to 4.3.5/3.12.6. * Security Fix: Fixed two separate HTTP smuggling vulnerabilities that used the Transfer-Encoding header. CVE-2020-11076 and CVE-2020-11077.
2020-06-04Pullup ticket #6221 - requested by niabsiegert2-371/+371
www/firefox68-l10n: dependent update Revisions pulled up: - www/firefox68-l10n/Makefile 1.14 - www/firefox68-l10n/distinfo 1.11 --- Module Name: pkgsrc Committed By: nia Date: Wed Jun 3 13:05:58 UTC 2020 Modified Files: pkgsrc/www/firefox68-l10n: Makefile distinfo Log Message: firefox68-l10n: sync with firefox68
2020-06-04Pullup ticket #6220 - requested by niabsiegert3-7/+26
www/firefox68: security fix Revisions pulled up: - www/firefox68/Makefile 1.22 - www/firefox68/distinfo 1.16 - www/firefox68/patches/patch-build_moz.configure_rust.configure 1.1 --- Module Name: pkgsrc Committed By: nia Date: Wed Jun 3 13:00:24 UTC 2020 Modified Files: pkgsrc/www/firefox68: Makefile distinfo Added Files: pkgsrc/www/firefox68/patches: patch-build_moz.configure_rust.configure Log Message: firefox68: Update to 68.9.0 Security Vulnerabilities fixed in Firefox ESR 68.9 #CVE-2020-12399: Timing attack on DSA signatures in NSS library #CVE-2020-12405: Use-after-free in SharedWorkerService #CVE-2020-12406: JavaScript Type confusion with NativeTypes #CVE-2020-12410: Memory safety bugs fixed in Firefox 77 and Firefox ESR 68.9
2020-06-04Pullup ticket #6216 - requested by tacabsiegert3-14/+11
www/drupal8: security fix Revisions pulled up: - www/drupal8/Makefile 1.32-1.33 - www/drupal8/PLIST 1.26 - www/drupal8/distinfo 1.28 --- Module Name: pkgsrc Committed By: rillig Date: Sat May 2 13:40:18 UTC 2020 Modified Files: pkgsrc/www/drupal8: Makefile Log Message: www/drupal8: remove SUBST block for nonexistent file --- Module Name: pkgsrc Committed By: taca Date: Wed May 20 16:31:27 UTC 2020 Modified Files: pkgsrc/www/drupal8: Makefile PLIST distinfo Log Message: www/drupal8: update to 8.7.14 Update drupal8 to 8.7.14. 8.7.14 (2020-05-20) -- Security update View usage statistics for this release Release notes Maintenance and security release of the Drupal 8 series. This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcement: * Drupal core - Moderately critical - Third-party library - SA-CORE-2020-002 No other fixes are included.
2020-06-04Pullup ticket #6215 - requested by tacabsiegert3-8/+9
www/drupal7: security fix Revisions pulled up: - www/drupal7/Makefile 1.64 - www/drupal7/PLIST 1.25 - www/drupal7/distinfo 1.49 --- Module Name: pkgsrc Committed By: taca Date: Wed May 20 16:22:15 UTC 2020 Modified Files: pkgsrc/www/drupal7: Makefile PLIST distinfo Log Message: www/drupal7: update to 7.70 Update drupal7 to 7.70. Drupal 7.70, 2020-05-19 ----------------------- - Fixed security issues: - SA-CORE-2020-002 - SA-CORE-2020-003
2020-06-04Pullup ticket #6214 - requested by tacabsiegert4-20/+20
www/ruby-rails60: security fix Revisions pulled up: - databases/ruby-activerecord60/PLIST 1.2 - databases/ruby-activerecord60/distinfo 1.2-1.3 - devel/ruby-activejob60/distinfo 1.2-1.3 - devel/ruby-activemodel60/distinfo 1.2-1.3 - devel/ruby-activestorage60/distinfo 1.2-1.3 - devel/ruby-activesupport60/distinfo 1.2-1.3 - devel/ruby-railties60/distinfo 1.2-1.3 - mail/ruby-actionmailbox60/distinfo 1.2-1.3 - mail/ruby-actionmailer60/distinfo 1.2-1.3 - textproc/ruby-actiontext60/distinfo 1.2-1.3 - www/ruby-actioncable60/distinfo 1.2-1.3 - www/ruby-actionpack60/distinfo 1.2-1.3 - www/ruby-actionview60/distinfo 1.2-1.3 - www/ruby-rails60/distinfo 1.2-1.3 --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:15:25 UTC 2020 Modified Files: pkgsrc/devel/ruby-activesupport60: distinfo Log Message: devel/ruby-activesupport60: update to 6.0.3 Update ruby-activesupport60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * `Array#to_sentence` no longer returns a frozen string. Before: ['one', 'two'].to_sentence.frozen? # => true After: ['one', 'two'].to_sentence.frozen? # => false *Nicolas Dular* * Update `ActiveSupport::Messages::Metadata#fresh?` to work for cookies with expiry set when `ActiveSupport.parse_json_times = true`. *Christian Gregg* --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:16:16 UTC 2020 Modified Files: pkgsrc/devel/ruby-activemodel60: distinfo Log Message: devel/ruby-activemodel60: updat to 6.0.3 Update ruby-activemodel60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:16:55 UTC 2020 Modified Files: pkgsrc/devel/ruby-activejob60: distinfo Log Message: devel/ruby-activejob60: update to 6.0.3 Update ruby-activejob60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * While using `perform_enqueued_jobs` test helper enqueued jobs must be stored for the later check with `assert_enqueued_with`. *Dmitry Polushkin* * Add queue name support to Que adapter *Brad Nauta*, *Wojciech Wnętrzak* --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:17:34 UTC 2020 Modified Files: pkgsrc/www/ruby-actionview60: distinfo Log Message: www/ruby-actionview60: update to 6.0.3 Update ruby-actionview60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * annotated_source_code returns an empty array so TemplateErrors without a template in the backtrace are surfaced properly by DebugExceptions. *Guilherme Mansur*, *Kasper Timm Hansen* * Add autoload for SyntaxErrorInTemplate so syntax errors are correctly raised by DebugExceptions. *Guilherme Mansur*, *Gannon McGibbon* --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:18:09 UTC 2020 Modified Files: pkgsrc/www/ruby-actionpack60: distinfo Log Message: www/ruby-actionpack60: update to 6.0.3 Update ruby-actionpack60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * Include child session assertion count in ActionDispatch::IntegrationTest `IntegrationTest#open_session` uses `dup` to create the new session, which meant it had its own copy of `@assertions`. This prevented the assertions from being correctly counted and reported. Child sessions now have their `attr_accessor` overriden to delegate to the root session. Fixes #32142 *Sam Bostock* --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:18:56 UTC 2020 Modified Files: pkgsrc/databases/ruby-activerecord60: PLIST distinfo Log Message: databases/ruby-activerecord60: update to 6.0.3 Update ruby-activerecord60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * Recommend applications don't use the `database` kwarg in `connected_to` The database kwarg in `connected_to` was meant to be used for one-off scripts but is often used in requests. This is really dangerous because it re-establishes a connection every time. It's deprecated in 6.1 and will be removed in 6.2 without replacement. This change soft deprecates it in 6.0 by removing documentation. *Eileen M. Uchitelle* * Fix support for PostgreSQL 11+ partitioned indexes. *Sebastián Palma* * Add support for beginless ranges, introduced in Ruby 2.7. *Josh Goodall* * Fix insert_all with enum values Fixes #38716. *Joel Blum* * Regexp-escape table name for MS SQL Add `Regexp.escape` to one method in ActiveRecord, so that table names with regular expression characters in them work as expected. Since MS SQL Server uses "[" and "]" to quote table and column names, and those characters are regular expression characters, methods like `pluck` and `select` fail in certain cases when used with the MS SQL Server adapter. *Larry Reid* * Store advisory locks on their own named connection. Previously advisory locks were taken out against a connection when a migration started. This works fine in single database applications but doesn't work well when migrations need to open new connections which results in the lock getting dropped. In order to fix this we are storing the advisory lock on a new connection with the connection specification name `AdisoryLockBase`. The caveat is that we need to maintain at least 2 connections to a database while migrations are running in order to do this. *Eileen M. Uchitelle*, *John Crepezzi* * Ensure `:reading` connections always raise if a write is attempted. Now Rails will raise an `ActiveRecord::ReadOnlyError` if any connection on the reading handler attempts to make a write. If your reading role needs to write you should name the role something other than `:reading`. *Eileen M. Uchitelle* * Enforce fresh ETag header after a collection's contents change by adding ActiveRecord::Relation#cache_key_with_version. This method will be used by ActionController::ConditionalGet to ensure that when collection cache versioning is enabled, requests using ConditionalGet don't return the same ETag header after a collection is modified. Fixes #38078. *Aaron Lipman* * A database URL can now contain a querystring value that contains an equal sign. This is needed to support passing PostgresSQL `options`. *Joshua Flanagan* * Retain explicit selections on the base model after applying `includes` and `joins`. Resolves #34889. *Patrick Rebsch* --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:20:09 UTC 2020 Modified Files: pkgsrc/mail/ruby-actionmailer60: distinfo Log Message: mail/ruby-actionmailer60: update to 6.0.3 Update ruby-actionmailer60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:20:46 UTC 2020 Modified Files: pkgsrc/mail/ruby-actionmailbox60: distinfo Log Message: mail/ruby-actionmailbox60: update to 6.0.3 Update ruby-actionmailbox60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * Update Mandrill inbound email route to respond appropriately to HEAD requests for URL health checks from Mandrill. *Bill Cromie* --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:21:24 UTC 2020 Modified Files: pkgsrc/www/ruby-actioncable60: distinfo Log Message: www/ruby-actioncable60: update to 6.0.3 Update to ruby-actioncable60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:22:16 UTC 2020 Modified Files: pkgsrc/devel/ruby-railties60: distinfo Log Message: devel/ruby-railties60: update to 6.0.3 Update ruby-railties60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * Cache compiled view templates when running tests by default When generating a new app without `--skip-spring`, caching classes is disabled in `environments/test.rb`. This implicitly disables caching view templates too. This change will enable view template caching by adding this to the generated `environments/test.rb`: ````ruby config.action_view.cache_template_loading = true ```` *Jorge Manrubia* * `Rails::Application#eager_load!` is available again to load application code manually as it was possible in previous versions. Please, note this is not integrated with the whole eager loading logic that runs when Rails boots with eager loading enabled, you can think of this method as a vanilla recursive code loader. This ability has been restored because there are some use cases for it, such as indexers that need to have all application classes and modules in memory. *Xavier Noria* * Generators that inherit from NamedBase respect `--force` option *Josh Brody* * Regression fix: The Rake task `zeitwerk:check` supports eager loaded namespaces which do not have eager load paths, like the recently added `i18n`. These namespaces are only required to respond to `eager_load!`. *Xavier Noria* --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:22:55 UTC 2020 Modified Files: pkgsrc/devel/ruby-activestorage60: distinfo Log Message: devel/ruby-activestorage60: update to 6.0.3 Update ruby-activestorage60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:23:36 UTC 2020 Modified Files: pkgsrc/textproc/ruby-actiontext60: distinfo Log Message: textproc/ruby-actiontext60: update to 6.0.3 Update ruby-actiontext60 to 6.0.3. ## Rails 6.0.3 (May 06, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Sat May 16 14:24:28 UTC 2020 Modified Files: pkgsrc/www/ruby-rails60: distinfo Log Message: www/ruby-rails60: update to 6.0.3 Finally, update ruby-rails60 to 6.0.3. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:10:27 UTC 2020 Modified Files: pkgsrc/devel/ruby-activesupport60: distinfo Log Message: devel/ruby-activesupport60: update to 6.0.3.1 Update ruby-activesupport60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * [CVE-2020-8165] Deprecate Marshal.load on raw cache read in RedisCacheStore * [CVE-2020-8165] Avoid Marshal.load on raw cache value in MemCacheStore --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:11:10 UTC 2020 Modified Files: pkgsrc/devel/ruby-activemodel60: distinfo Log Message: devel/ruby-activemodel60: update to 6.0.3.1 Update ruby-activemodel60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:11:43 UTC 2020 Modified Files: pkgsrc/devel/ruby-activejob60: distinfo Log Message: devel/ruby-activejob60: update to 6.0.3.1 Update ruby-activejob60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:12:16 UTC 2020 Modified Files: pkgsrc/www/ruby-actionview60: distinfo Log Message: www/ruby-actionview60: update to 6.0.3.1 Update ruby-actionview60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * [CVE-2020-8167] Check that request is same-origin prior to including CSRF token in XHRs --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:12:50 UTC 2020 Modified Files: pkgsrc/www/ruby-actionpack60: distinfo Log Message: www/ruby-actionpack60: update to 6.0.3.1 Update ruby-actionpack60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * [CVE-2020-8166] HMAC raw CSRF token before masking it, so it cannot be used to reconstruct a per-form token * [CVE-2020-8164] Return self when calling #each, #each_pair, and #each_value instead of the raw @parameters hash --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:13:24 UTC 2020 Modified Files: pkgsrc/databases/ruby-activerecord60: distinfo Log Message: databases/ruby-activerecord60: update to 6.0.3.1 Update ruby-activerecord60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:14:04 UTC 2020 Modified Files: pkgsrc/mail/ruby-actionmailer60: distinfo Log Message: mail/ruby-actionmailer60: update to 6.0.3.1 Update ruby-actionmailer60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:14:41 UTC 2020 Modified Files: pkgsrc/mail/ruby-actionmailbox60: distinfo Log Message: mail/ruby-actionmailbox60: update to 6.0.3.1 Update ruby-actionmailbox60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:15:14 UTC 2020 Modified Files: pkgsrc/www/ruby-actioncable60: distinfo Log Message: www/ruby-actioncable60: update to 6.0.3.1 Update ruby-actioncable60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:15:47 UTC 2020 Modified Files: pkgsrc/devel/ruby-railties60: distinfo Log Message: devel/ruby-railties60: update to 6.0.3.1 Update ruby-railties60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:16:26 UTC 2020 Modified Files: pkgsrc/devel/ruby-activestorage60: distinfo Log Message: devel/ruby-activestorage60: update to 6.0.3.1 Update ruby-activestorage60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * [CVE-2020-8162] Include Content-Length in signature for ActiveStorage direct upload --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:17:01 UTC 2020 Modified Files: pkgsrc/textproc/ruby-actiontext60: distinfo Log Message: textproc/ruby-actiontext60: update to 6.0.3.1 Update ruby-actiontext60 to 6.0.3.1. ## Rails 6.0.3.1 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 17:17:45 UTC 2020 Modified Files: pkgsrc/www/ruby-rails60: distinfo Log Message: www/ruby-rails60: update to 6.0.3.1. Finally, update ruby-rails60 to 6.0.3.1.
2020-06-01Pullup ticket #6213 - requested by tacabsiegert4-20/+20
www/ruby-rails52: security fix Revisions pulled up: - lang/ruby/rails.mk patch - databases/ruby-activerecord52/distinfo 1.4 - devel/ruby-activejob52/distinfo 1.4 - devel/ruby-activemodel52/distinfo 1.4 - devel/ruby-activestorage52/distinfo 1.4 - devel/ruby-activesupport52/distinfo 1.4 - devel/ruby-railties52/distinfo 1.4 - mail/ruby-actionmailer52/distinfo 1.4 - www/ruby-actioncable52/distinfo 1.4 - www/ruby-actionpack52/distinfo 1.4 - www/ruby-actionview52/distinfo 1.4 - www/ruby-rails52/distinfo 1.4 --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:33:41 UTC 2020 Modified Files: pkgsrc/devel/ruby-activesupport52: distinfo Log Message: devel/ruby-activesupport52: update to 5.2.4.3 Update ruby-activesupport52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * [CVE-2020-8165] Deprecate Marshal.load on raw cache read in RedisCacheStore * [CVE-2020-8165] Avoid Marshal.load on raw cache value in MemCacheStore --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:34:47 UTC 2020 Modified Files: pkgsrc/devel/ruby-activemodel52: distinfo Log Message: devel/ruby-activemodel52: update to 5.2.4.3 Update ruby-activemodel52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:35:30 UTC 2020 Modified Files: pkgsrc/devel/ruby-activejob52: distinfo Log Message: devel/ruby-activejob52: update to 5.2.4.3 Update ruby-activejob52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:36:18 UTC 2020 Modified Files: pkgsrc/www/ruby-actionview52: distinfo Log Message: www/ruby-actionview52: update to 5.2.4.3 Update ruby-actionview52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * [CVE-2020-8167] Check that request is same-origin prior to including CSRF token in XHRs --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:36:58 UTC 2020 Modified Files: pkgsrc/www/ruby-actionpack52: distinfo Log Message: www/ruby-actionpack52: update to 5.2.4.3 Update ruby-actionpack52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * [CVE-2020-8166] HMAC raw CSRF token before masking it, so it cannot be used to reconstruct a per-form token * [CVE-2020-8164] Return self when calling #each, #each_pair, and #each_value instead of the raw @parameters hash --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:37:46 UTC 2020 Modified Files: pkgsrc/www/ruby-actioncable52: distinfo Log Message: www/ruby-actioncable52: update to 5.2.4.3 Update ruby-actioncable52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:38:35 UTC 2020 Modified Files: pkgsrc/databases/ruby-activerecord52: distinfo Log Message: databases/ruby-activerecord52: update to 5.2.4.3 Update ruby-activerecord52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:39:12 UTC 2020 Modified Files: pkgsrc/devel/ruby-activestorage52: distinfo Log Message: devel/ruby-activestorage52: update to 5.2.4.3 Update ruby-activestorage52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * [CVE-2020-8162] Include Content-Length in signature for ActiveStorage direct upload --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:39:54 UTC 2020 Modified Files: pkgsrc/mail/ruby-actionmailer52: distinfo Log Message: mail/ruby-actionmailer52: update to 5.2.4.3 Update ruby-actionmailer52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:40:32 UTC 2020 Modified Files: pkgsrc/devel/ruby-railties52: distinfo Log Message: devel/ruby-railties52: update to 5.2.4.3 Update ruby-railties52 to 5.2.4.3. ## Rails 5.2.4.3 (May 18, 2020) ## * No changes. --- Module Name: pkgsrc Committed By: taca Date: Tue May 19 15:41:07 UTC 2020 Modified Files: pkgsrc/www/ruby-rails52: distinfo Log Message: www/ruby-rails52: update to 5.2.4.3 Finally, update ruby-rails52 to 5.2.4.3.
2020-05-26Pullup ticket #6210 - requested by adambsiegert2-7/+7
www/py-httplib2: security fix Revisions pulled up: - www/py-httplib2/Makefile 1.24-1.25 - www/py-httplib2/distinfo 1.21-1.22 --- Module Name: pkgsrc Committed By: adam Date: Wed May 20 15:29:53 UTC 2020 Modified Files: pkgsrc/www/py-httplib2: Makefile distinfo Log Message: py-httplib2: updated to 0.18.0 0.18.0 IMPORTANT security vulnerability CWE-93 CRLF injection Force %xx quote of space, CR, LF characters in uri. Special thanks to Recar https://github.com/Ciyfly for discrete notification. https://cwe.mitre.org/data/definitions/93.html 0.17.4 Ship test suite in source dist https://github.com/httplib2/httplib2/pull/168 --- Module Name: pkgsrc Committed By: adam Date: Thu May 21 06:19:59 UTC 2020 Modified Files: pkgsrc/www/py-httplib2: Makefile distinfo Log Message: py-httplib2: updated to 0.18.1 0.18.1 explicit build-backend workaround for pip build isolation bug "AttributeError: 'module' object has no attribute '__legacy__'" on pip install
2020-05-13Pullup ticket #6191 - requested by niabsiegert2-371/+371
www/firefox68-l10n: dependent update Revisions pulled up: - www/firefox68-l10n/Makefile 1.13 - www/firefox68-l10n/distinfo 1.10 --- Module Name: pkgsrc Committed By: nia Date: Sat May 9 13:21:31 UTC 2020 Modified Files: pkgsrc/www/firefox68-l10n: Makefile distinfo Log Message: firefox68-l10n: Sync with firefox68
2020-05-13Pullup ticket #6190 - requested by niabsiegert3-16/+13
www/firefox68: security fix Revisions pulled up: - www/firefox68/Makefile 1.20 - www/firefox68/PLIST 1.6 - www/firefox68/distinfo 1.15 --- Module Name: pkgsrc Committed By: nia Date: Sat May 9 13:08:01 UTC 2020 Modified Files: pkgsrc/www/firefox68: Makefile PLIST distinfo Log Message: firefox68: Update to 68.8.0 Security Vulnerabilities fixed in Firefox ESR 68.8 #CVE-2020-12387: Use-after-free during worker shutdown #CVE-2020-12388: Sandbox escape with improperly guarded Access Tokens #CVE-2020-12389: Sandbox escape with improperly separated process types #CVE-2020-6831: Buffer overflow in SCTP chunk input validation #CVE-2020-12392: Arbitrary local file access with 'Copy as cURL' #CVE-2020-12393: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection #CVE-2020-12395: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8
2020-05-06Pullup ticket #6183 - requested by tacabsiegert3-8/+16
www/drupal8: security fix Revisions pulled up: - www/drupal8/Makefile 1.31 - www/drupal8/PLIST 1.25 - www/drupal8/distinfo 1.27 --- Module Name: pkgsrc Committed By: taca Date: Sun Apr 26 09:18:43 UTC 2020 Modified Files: pkgsrc/www/drupal8: Makefile PLIST distinfo Log Message: www/drupal8: update to 8.7.12 Update drupal8 to 8.7.12. Release notes Maintenance and security release of the Drupal 8 series. This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcement: * Drupal core - Moderately critical - Third-party library - SA-CORE-2020-001 No other fixes are included. Which release do I choose? Security coverage information * Sites on 8.7.x will receive security coverage until June 3, 2020 (when Drupal 8.9.0 is scheduled for release). * Versions of Drupal 8 prior to 8.7.x are end-of-life and do not receive security coverage. Important update information No changes have been made to the .htaccess, web.config, robots.txt or default settings.php files in this release, so upgrading custom versions of those files is not necessary if your site is already on the previous release.
2020-04-30Pullup ticket #6179 - requested by tacabsiegert5-19/+133
www/squid4: security fix Revisions pulled up: - www/squid4/Makefile 1.6-1.7 - www/squid4/distinfo 1.4-1.6 - www/squid4/patches/patch-acinclude_os-deps.m4 1.1-1.2 - www/squid4/patches/patch-configure 1.3-1.5 - www/squid4/patches/patch-src_ip_Intercept.cc 1.1 --- Module Name: pkgsrc Committed By: sborrill Date: Thu Apr 9 09:45:20 UTC 2020 Modified Files: pkgsrc/www/squid4: Makefile distinfo pkgsrc/www/squid4/patches: patch-configure Added Files: pkgsrc/www/squid4/patches: patch-acinclude_os-deps.m4 patch-src_ip_Intercept.cc Log Message: Fix IPFilter transparent proxy support by: - including correct headers in configure tests - using correct autoconf value output by configure Bump PKGREVISION --- Module Name: pkgsrc Committed By: sborrill Date: Thu Apr 9 16:27:15 UTC 2020 Modified Files: pkgsrc/www/squid4: distinfo pkgsrc/www/squid4/patches: patch-acinclude_os-deps.m4 patch-configure Log Message: Generate correct #defines for the IPFilter IPv6 detection with no trailing underscores --- Module Name: pkgsrc Committed By: mef Date: Thu Apr 23 13:52:24 UTC 2020 Modified Files: pkgsrc/www/squid4: Makefile distinfo pkgsrc/www/squid4/patches: patch-configure Log Message: (www/squid4) Updated to 4.10 (and clear pkglint one point in patch) Changes to squid-4.11 (18 Apr 2020): - Bug 5036: capital 'L's in logs when daemon queue overflows - Bug 5022: Reconfigure kills Coordinator in SMP+ufs configurations - Bug 5016: systemd thinks Squid is ready before Squid listens - kerberos_ldap_group: fix encryption type for cross realm check - HTTP: Ignore malformed Host header in intercept and reverse proxy mode - Fix Digest authentication nonce handling - Supply ALE to request_header_add/reply_header_add - ... and some documentation updates - ... and some compile fixes
2020-04-11Pullup ticket #6156 - requested by niabsiegert2-371/+371
www/firefox68-l10n: dependent update Revisions pulled up: - www/firefox68-l10n/Makefile 1.12 - www/firefox68-l10n/distinfo 1.9 --- Module Name: pkgsrc Committed By: nia Date: Fri Apr 10 11:02:33 UTC 2020 Modified Files: pkgsrc/www/firefox68-l10n: Makefile distinfo Log Message: firefox68-l10n: Update to 68.7.0 Sync with firefox68.
2020-04-11Pullup ticket #6155 - requested by niabsiegert2-8/+8
www/firefox68: security fix Revisions pulled up: - www/firefox68/Makefile 1.17 - www/firefox68/distinfo 1.14 --- Module Name: pkgsrc Committed By: nia Date: Fri Apr 10 10:41:50 UTC 2020 Modified Files: pkgsrc/www/firefox68: Makefile distinfo Log Message: firefox68: Update to 68.7.0 Security Vulnerabilities fixed in Firefox ESR 68.7 #CVE-2020-6828: Preference overwrite via crafted Intent from malicious Android application #CVE-2020-6827: Custom Tabs in Firefox for Android could have the URI spoofed #CVE-2020-6821: Uninitialized memory could be read when using the WebGL copyTexSubImage method #CVE-2020-6822: Out of bounds write in GMPDecodeData when processing large images #CVE-2020-6825: Memory safety bugs fixed in Firefox 75 and Firefox ESR 68.7
2020-04-09Pullup ticket #6153 - requested by wizbsiegert3-11/+14
www/apache24: Security fix Revisions pulled up: - www/apache24/Makefile 1.89 - www/apache24/PLIST 1.32 - www/apache24/distinfo 1.42 --- Module Name: pkgsrc Committed By: wiz Date: Mon Apr 6 08:27:26 UTC 2020 Modified Files: pkgsrc/www/apache24: Makefile PLIST distinfo Log Message: apache: update to 2.4.43. Changes with Apache 2.4.43 *) mod_ssl: Fix memory leak of OCSP stapling response. [Yann Ylavic] Changes with Apache 2.4.42 *) mod_proxy_http: Fix the forwarding of requests with content body when a balancer member is unavailable; the retry on the next member was issued with an empty body (regression introduced in 2.4.41). PR63891. [Yann Ylavic] *) mod_http2: Fixes issue where mod_unique_id would generate non-unique request identifier under load, see <https://github.com/icing/mod_h2/issues/195>. [Michael Kaufmann, Stefan Eissing] *) mod_proxy_hcheck: Allow healthcheck expressions to use %{Content-Type}. PR64140. [Renier Velazco <renier.velazco upr.edu>] *) mod_authz_groupfile: Drop AH01666 from loglevel "error" to "info". PR64172. *) mod_usertrack: Add CookieSameSite, CookieHTTPOnly, and CookieSecure to allow customization of the usertrack cookie. PR64077. [Prashant Keshvani <prashant2400 gmail.com>, Eric Covener] *) mod_proxy_ajp: Add "secret" parameter to proxy workers to implement legacy AJP13 authentication. PR 53098. [Dmitry A. Bakshaev <dab1818 gmail com>] *) mpm_event: avoid possible KeepAliveTimeout off by -100 ms. [Eric Covener, Yann Ylavic] *) Add a config layout for OpenWRT. [Graham Leggett] *) Add support for cross compiling to apxs. If apxs is being executed from somewhere other than its target location, add that prefix to includes and library directories. Without this, apxs would fail to find config_vars.mk and exit. [Graham Leggett] *) mod_ssl: Disable client verification on ACME ALPN challenges. Fixes github issue mod_md#172 (https://github.com/icing/mod_md/issues/172). [Michael Kaufmann <mail michael-kaufmann.ch>, Stefan Eissing] *) mod_ssl: use OPENSSL_init_ssl() to initialise OpenSSL on versions 1.1+. [Graham Leggett] *) mod_ssl: Support use of private keys and certificates from an OpenSSL ENGINE via PKCS#11 URIs in SSLCertificateFile/KeyFile. [Anderson Sasaki <ansasaki redhat.com>, Joe Orton] *) mod_md: - Prefer MDContactEmail directive to ServerAdmin for registration. New directive thanks to Timothe Litt (@tlhackque). - protocol check for pre-configured "tls-alpn-01" challenge has been improved. It will now check all matching virtual hosts for protocol support. Thanks to @mkauf. - Corrected a check when OCSP stapling was configured for hosts where the responsible MDomain is not clear, by Michal Karm Babacek (@Karm). - Softening the restrictions where mod_md configuration directives may appear. This should allow for use in <If> and <Macro> sections. If all possible variations lead to the configuration you wanted in the first place, is another matter. [Michael Kaufmann <mail michael-kaufmann.ch>, Timothe Litt (@tlhackque), Michal Karm Babacek (@Karm), Stefan Eissing (@icing)] *) test: Added continuous testing with Travis CI. This tests various scenarios on Ubuntu with the full test suite. Architectures tested: amd64, s390x, ppc64le, arm64 The tests pass successfully. [Luca Toscano, Joe Orton, Mike Rumph, and others] *) core: Be stricter in parsing of Transfer-Encoding headers. [ZeddYu <zeddyu.lu gmail.com>, Eric Covener] *) mod_ssl: negotiate the TLS protocol version per name based vhost configuration, when linked with OpenSSL-1.1.1 or later. The base vhost's SSLProtocol (from the first vhost declared on the IP:port) is now only relevant if no SSLProtocol is declared for the vhost or globally, otherwise the vhost or global value apply. [Yann Ylavic] *) mod_cgi, mod_cgid: Fix a memory leak in some error cases with large script output. PR 64096. [Joe Orton] *) config: Speed up graceful restarts by using pre-hashed command table. PR 64066. [Giovanni Bechis <giovanni paclan.it>, Jim Jagielski] *) mod_systemd: New module providing integration with systemd. [Jan Kaluza] *) mod_lua: Add r:headers_in_table, r:headers_out_table, r:err_headers_out_table, r:notes_table, r:subprocess_env_table as read-only native table alternatives that can be iterated over. [Eric Covener] *) mod_http2: Fixed rare cases where a h2 worker could deadlock the main connection. [Yann Ylavic, Stefan Eissing] *) mod_lua: Accept nil assignments to the exposed tables (r.subprocess_env, r.headers_out, etc) to remove the key from the table. PR63971. [Eric Covener] *) mod_http2: Fixed interaction with mod_reqtimeout. A loaded mod_http2 was disabling the ssl handshake timeouts. Also, fixed a mistake of the last version that made `H2Direct` always `on`, regardless of configuration. Found and reported by <Armin.Abfalterer@united-security-providers.ch> and <Marcial.Rion@united-security-providers.ch>. [Stefan Eissing] *) mod_http2: Multiple field length violations in the same request no longer cause several log entries to be written. [@mkauf] *) mod_ssl: OCSP does not apply to proxy mode. PR 63679. [Lubos Uhliarik <luhliari redhat.com>, Yann Ylavic] *) mod_proxy_html, mod_xml2enc: Fix build issues with macOS due to r1864469 [Jim Jagielski] *) mod_authn_socache: Increase the maximum length of strings that can be cached by the module from 100 to 256. PR 62149 [<thorsten.meinl knime.com>] *) mod_proxy: Fix crash by resolving pool concurrency problems. PR 63503 [Ruediger Pluem, Eric Covener] *) core: On Windows, fix a start-up crash if <IfFile ...> is used with a path that is not valid (For example, testing for a file on a flash drive that is not mounted) [Christophe Jaillet] *) mod_deflate, mod_brotli: honor "Accept-Encoding: foo;q=0" as per RFC 7231; which means 'foo' is "not acceptable". PR 58158 [Chistophe Jaillet] *) mod_md v2.2.3: - Configuring MDCAChallenges replaces any previous existing challenge configuration. It had been additive before which was not the intended behaviour. [@mkauf] - Fixing order of ACME challenges used when nothing else configured. Code now behaves as documented for `MDCAChallenges`. Fixes #156. Thanks again to @mkauf for finding this. - Fixing a potential, low memory null pointer dereference [thanks to @uhliarik]. - Fixing an incompatibility with a change in libcurl v7.66.0 that added unwanted "transfer-encoding" to POST requests. This failed in directy communication with Let's Encrypt boulder server. Thanks to @mkauf for finding and fixing. [Stefan Eissing] *) mod_md: Adding the several new features. The module offers an implementation of OCSP Stapling that can replace fully or for a limited set of domains the existing one from mod_ssl. OCSP handling is part of mod_md's monitoring and message notifications. If can be used for sites that do not have ACME certificates. The url for a CTLog Monitor can be configured. It is used in the server-status to link to the external status page of a certicate. The MDMessageCmd is called with argument "installed" when a new certificate has been activated on server restart/reload. This allows for processing of the new certificate, for example to applications that require it in different locations or formats. [Stefan Eissing] *) mod_proxy_balancer: Fix case-sensitive referer check related to CSRF/XSS protection. PR 63688. [Armin Abfalterer <a.abfalterer gmail.com>]
2020-04-09Pullup ticket #6151 - requested by niabsiegert2-371/+371
www/firefox68-l10n: dependent update Revisions pulled up: - www/firefox68-l10n/Makefile 1.11 - www/firefox68-l10n/distinfo 1.8 --- Module Name: pkgsrc Committed By: nia Date: Sat Apr 4 17:02:34 UTC 2020 Modified Files: pkgsrc/www/firefox68-l10n: Makefile distinfo Log Message: firefox68-l10n: Update to 68.6.1 Sync with firefox68.
2020-04-09Pullup ticket #6150 - requested by niabsiegert2-7/+7
www/firefox68: security fix Revisions pulled up: - www/firefox68/Makefile 1.16 - www/firefox68/distinfo 1.13 --- Module Name: pkgsrc Committed By: nia Date: Sat Apr 4 15:26:42 UTC 2020 Modified Files: pkgsrc/www/firefox68: Makefile distinfo Log Message: firefox68: Update to 68.6.1 Security Vulnerabilities fixed in Firefox 74.0.1 and Firefox ESR 68.6.1 #CVE-2020-6819: Use-after-free while running the nsDocShell destructor #CVE-2020-6820: Use-after-free when handling a ReadableStream
2020-03-29firefox: remove removed patch-config__make_system_wrappers.py from distinfowiz1-2/+1
2020-03-29epiphany: Needs itstoolnia1-1/+2
2020-03-29www/ruby-net-http-persistent: missing from previos committaca1-1/+2
Commit one more missing file in previous commit.
2020-03-29regen ( 3.0.1 to 3.1.0)mef1-5/+5
2020-03-29Don't hack __isinf for libc++, it makes things worse.joerg2-18/+3
2020-03-27Skip configure.in as we patch configure alreadyjoerg1-1/+3
2020-03-27Resolve conflict with std::this_thread.joerg4-1/+101
2020-03-27libproxy: Doesn't need gmakenia1-2/+3
2020-03-27www/w3m: fix -Wchar-subscriptsrillig2-1/+31
2020-03-27firefox: fix 74.0 debug build packaginggutteridge1-1/+2
2020-03-26tscrape: Add patch-tscrape.c to distinfoleot2-3/+4
It was accidentally missed in last commit. Thanks <wiz> for noticing it! PKGREVISION++
2020-03-25p5-CGI-Simple: Update to 1.25nia2-7/+7
1.25 2020-02-10 MANWAR - Merged PR #9, thanks @ktat. 1.24 2020-02-07 MANWAR - Addressed issue RT #125383 raised by SREZIC. 1.23 2020-02-06 MANWAR - Fixed issue RT #131590, samesite parameter can be "None" as well.
2020-03-24libmicrohttpd: Update to 0.9.70nia2-8/+7
Sat 08 Feb 2020 09:12:54 PM CET Fixed 100-continue handling for PATCH method (#6068). Fixed FTBFS from wrong #endif position for certain builds (#6025). Fixed connection overflow issue when combining MHD_USE_NO_LISTEN_SOCKET with MHD_USE_THREAD_PER_CONNECTION (#6036). Updated m4 script to fix FTBFS when using -Werror=unused-but-set-parameter (#6078). Releasing libmicrohttpd 0.9.70. -CG Thu Dec 26 14:43:27 CET 2019 Adding fix for urlencoding of keys without values in post-processor logic. -CG Tue 24 Dec 2019 03:32:18 PM CET Adding patch from Ethan Tuttle with test case for urlencoding in post-processor for keys without values. -CG/ET
2020-03-24goaccess: Add an option for ssl support.roy2-6/+11
2020-03-24py-asgiref: updated to 3.2.6adam2-7/+13
3.2.6: * local.Local now works in all threading situations, no longer requires periodic garbage collection, and works with libraries that monkeypatch threading (like gevent)
2020-03-23goaccess: Add support for Tokyo Cabinet to persist dataroy1-0/+14
2020-03-23goaccess: Add support for Tokyo Cabinet to persist dataroy3-6/+12
2020-03-23www/squidview: update to 0.86taca3-24/+8
Update squidview to 0.86. pkgsrc change: switch to use squid4/Makefile.common instead of squid3. 0.86 February 2017 - fix clang compiler warning, thanks http://people.freebsd.org/~danilo/ 0.85 Janurary 2017 - another result code, thanks Yuri Voinov 0.84 December 2016 - INM result code as 'U' - unmodified thanks Yuri Voinov 0.82-0.83: May 2016 - add more squid result codes thanks to Yuri Voinov for the suggestions, corrections 0.81: January 2015 - squid result code update thanks to Yuri Voinov for the suggestion
2020-03-23tscrape: Backport upstream patch to fetch tweet with multiple js-stream-itemleot2-1/+21
Previously, without that patch, some tweets were accidentally not parsed. PKGREVISION++
2020-03-23php-nextcloud: Update to 18.0.2ryoon3-8/+15
Changelog: 18.0.2 Changes [stable18] disable timeout on app install via cli (server#19439) [stable18] Show proper file name when fetching details fails (server#19441) [stable18] Don't create invalid users (server#19451) [stable18] when we receive intentional empty whats new info, do not try to show it (server#19470) [stable18] Reduce flow logging at INFO level, move to DEBUG (server#19481) [stable18] Continue with next foreach iteration (server#19516) [stable18] Allow to overwrite the path on the cache event (server#19522) [stable18] Move RefreshWebcalJob logic to a proper service so that it may be called independently (server#19573) [stable18] Make sure the secondary view registered for systemtags has an id (server#19574) [stable18] Strip of users home path from share api message (server#19591) [stable18] FIx logging in accessibility controller (server#19607) [stable18] Change the route generation of AuthPublicShareController.php (server#19610) Replace tab character with space (server#19612) [stable18] remove noise from detectUuid and cache results (server#19624) [stable18] Make sure that the transfer details are present in the database during the cron run (server#19628) [stable18] Fix hover state color of drag-n-drop with theming and dark mode (server#19630) [stable18] Correctly trim long cyrillic note (server#19636) [stable18] Hash event UID to make sure it's not too long for PushProvider notifications (server#19639) [stable18] Theme search results (server#19690) [stable18] Also cache avatars when it's not allowed (server#19696) [stable18] Revive the "send email to new users" toggle for the user form (server#19702) [stable18] Fix non-centered no javascript message (server#19715) [stable18] Allow single file downloads so the video player works again (server#19729) [stable18] Add message for DoesNotExistException (server#19744) Fetch translate for Tags from files app (server#19762) [stable18] Various user settings fixes (server#19767) [stable18] Do not allow transfer ownership when the user isn't the owner (server#19773) [stable18] Introduce a default refresh rate app setting for calendar subscriptions (server#19784) [stable18] Fix regex for office documents (server#19800) [stable18] Fix filename and popover menu misalignment (server#19802) [stable18] Fix avatar in file list for users with an @ in the uid (server#19803) [stable18] Fix "Error loading the shares list TypeError: "this is undefined"" fo… (server#19824) [stable18] Prevent self-xss via invalid mysql user name on install screen (server#19830) [stable18] Correctly set up Application class (activity#430) [stable18] Chunk deleting of rows from the activity table (activity#435) [stable18] Fix 18 public folder (files_videoplayer#153) [stable18] Move to github actions (files_videoplayer#156) [stable18] Fix push notifications for multibyte notifications (notifications#576) [stable18] Prevent delete for impersonated users (notifications#582) [stable18] Delete unknown devices (notifications#583) [stable18] Fix long message (notifications#584) [stable18] ignore unavailable storages while scanning for albums (photos#211) [stable18] Don't flatten out albums (photos#213) [stable18] Avoid line breaks after long device names in "df" command (serverinfo#177) [stable18] Do not print errors if time server config is not available (serverinfo#178) [stable18] Change sidebar file while changing file in slideshow (viewer#405) 18.0.1 Changes [stable18] Fix cursor on disabled contenteditable divs (server#18961) Bump style-loader from 1.1.2 to 1.1.3 (server#18982) [stable18] Increase the timeout for app downloads (server#19025) [stable18] Fix loaded controller check (server#19060) [stable18] Allow to await the sidebar (server#19089) [stable18] expose Argon2 options (as we did for bcrypt) (server#19094) [stable18] fix multiselect actions for files (server#19108) [stable18] Adjust filelist color handling to new dark theme value (server#19117) [stable18] Reduce legacy event log level to debug (server#19118) [stable18] New file menu needs to be above the filelist header (server#19119) [stable18] Do not invert avatar colors when dark theme is enabled (server#19121) [stable18] Use the target for file notifications (server#19149) [stable18] Use correct appid for talk (server#19150) [stable18] add hub bundle for easy installation on upgraded instances (server#19153) [stable18] apps can have polyamorous relationships with bundles (server#19166) [stable18] Use themed favicon-fb (server#19189) [stable18] Fix "Call to undefined method OCA\\WorkflowEngine\\Entity\\File::t()" (server#19190) [stable18] Fix query selector for inverted icons (server#19206) [stable18] Do not encode contacts menu mailto links (server#19207) [stable18] Give the sharing tab a unique id so it also opens properly on other languages (server#19212) [stable18] WebcalRefreshJob: Fix reading refresh rate (server#19228) [stable18] Make sure to catch php errors during job execution (server#19269) [stable18] Center Buttons (server#19271) [stable18] Use the l10n from settings (server#19277) [stable18] Use proper andwhere clause (server#19278) [stable18] Add move (and firstlogin) option to transferownership service (server#19279) [stable18] for the DB ot pick an index specify the object_type (server#19283) [stable18] owner transfer multiselect fixes (server#19291) [stable18] Allow respecting PASSWORD_DEFAULT (server#19292) [stable18] Keep the modification time during decryptFile (server#19297) [stable18] Fix data Apache2 .htaccess typo (server#19302) [stable18] Fix display of DTEND for multi-day all-day event (server#19308) [stable18] do not overwrite global user auth credentials with empty values (server#19315) [stable18] Fix occ maintenance:install database connect failure (server#19326) [stable18] Fix event type (server#19330) [stable18] Array access on int will fail on php7.4 (server#19332) [stable18] Make sure the default share provider does not execute for other things (server#19334) [stable18] Disable link shares of disabled users (server#19340) [stable18] Prevent archieved download on secure view (server#19360) [stable18] Log Flow activity (server#19396) [stable18] Allow to serve static webm directly (server#19420) 18.0.1 final (server#19422) [stable18] Allow to serve static mp4 directly (server#19428) [stable18] Update master php testing versions (activity#417) Update stable18 target versions (activity#418) [stable18] Update master php testing versions (files_pdfviewer#164) Update stable18 target versions (files_pdfviewer#165) Update stable18 target versions (files_texteditor#194) Update stable18 target versions (firstrunwizard#274) Update stable18 target versions (logreader#313) [stable18] Update master php testing versions (nextcloud_announcements#64) Update stable18 target versions (nextcloud_announcements#65) Update stable18 target versions (notifications#547) [stable18] Add linting via github actions (notifications#555) [stable18] Support Strict VoIP push notifications for iOS 13 SDK (notifications#565) [stable18] Update master php testing versions (password_policy#93) Update stable18 target versions (password_policy#94) [stable18] Lint with github actions (photos#153) [stable18] No more drone. Do it all on github actions (photos#158) [stable18] Respect .noimage and .nomedia files (photos#160) [stable18] added headers for your photos and favs (photos#172) [stable18] Fix/actions (photos#174) [stable18] Fix url escaping (photos#175) [stable18] Use actions from tutorial (photos#181) Update stable18 target versions (privacy#323) Update stable18 target versions (recommendations#182) Update stable18 target versions (serverinfo#170) [stable18] Update master php testing versions (survey_client#104) Update stable18 target versions (survey_client#105) [stable18] GitHub actions/lint (viewer#368) Fix url escaping (viewer#370) [stable18] Adjust tests syntax & formatting (viewer#379) [stable18] Use actions from tutorial (viewer#385) [stable18] Revert "Fix url escaping" (viewer#396)
2020-03-22goaccess: Use the curses framework rather than just linking to ncursesroy2-8/+8
goaccess requires getmouse(3).
2020-03-22goaccess: Fix build by including stdarg.hroy3-1/+31
Other source files include this, so this should be a safe change.
2020-03-22www/p5-libapreq2: remove ignored SUBST blockrillig4-16/+10
The file env/Makefile.in doesn't exist anymore, and the other Makefile.in files don't run apxs anymore.
2020-03-22php-phrasea2: override CXX instead of LIBTOOL. Suggested by joerg@.tnn1-3/+4
2020-03-22php-phrasea2: work around libtool issuetnn1-1/+5
2020-03-22www/py-*: fix test dependencies for Python 2.7rillig3-4/+18
2020-03-22py-pylint-django: updated to 2.0.14adam2-7/+7
Version 2.0.14: Add support for Django 3.0 and Python 3.8 Support ASGI.
2020-03-21Restrict some more rails packages to Ruby 2.5+joerg3-3/+6
2020-03-21www/ruby-sawyer: update to 0.8.2taca3-15/+10
Update ruby-sawyer to 0.8.2. pkgsrc change: add "USE_LANGAUGES= # none". No release notes available, but it relax version dependency. For more information, please refer: <https://github.com/lostisland/sawyer/compare/v0.8.1...v0.8.2>.
2020-03-21www/ruby-faraday: update to 0.17.3taca3-8/+46
Update ruby-faraday to 0.17.3. This is not latest version of faraday but www/ruby-faraday_middleware require prior to 1.0. ## v0.17.3 Fixes: * Reverts changes in error classes hierarchy. #1092 (@iMacTia) * Fix Ruby 1.9 syntax errors and improve Error class testing #1094 (@BanzaiMan, @mrexox, @technoweenie) Misc: * Stops using `&Proc.new` for block forwarding. #1083 (@olleolleolle) * Update CI to test against ruby 2.0-2.7 #1087, #1099 (@iMacTia, @olleolleolle, @technoweenie) * require FARADAY_DEPRECATE=warn to show Faraday v1.0 deprecation warnings #1098 (@technoweenie) ## v0.17.1 Final release before Faraday v1.0, with important fixes for Ruby 2.7. Fixes: * RaiseError response middleware raises exception if HTTP client returns a nil status. (#1042) Misc: * Fix Ruby 2.7 warnings (#1009) * Add `Faraday::Deprecate` to warn about upcoming v1.0 changes. (#1054, #1059, #1076, #1077) * Add release notes up to current in CHANGELOG.md (#1066) * Port minimal rspec suite from main branch to run backported tests. (#1058) ## v0.17.0 This release is the same as v0.15.4. It was pushed to cover up releases v0.16.0-v0.16.2. ## v0.15.4 * Expose `pool_size` as a option for the NetHttpPersistent adapter (#834)