Commit Graph

79063 Commits

Author SHA1 Message Date
Bernd Kuhls
086bd1dd48 package/python-parso: bump version to 0.8.5
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 23:58:06 +02:00
Bernd Kuhls
e747a64979 package/python-networkx: bump version to 3.5
Release notes:
https://github.com/networkx/networkx/releases/tag/networkx-3.5

Updated license hash due to copyright year bump:
c22ad5579d

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
1617498a20 package/python-mypy: bump version to 1.18.2
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
765b1c5dbe package/python-multidict: bump version to 6.7.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
70e29b930e package/python-mistune: bump version to 3.1.4
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
6e223d30a8 package/python-markdown2: bump version to 2.5.4
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
94ba029438 package/python-mako: bump version to 1.3.10
Release notes:
https://github.com/sqlalchemy/mako/releases/tag/rel_1_3_10
https://github.com/sqlalchemy/mako/releases/tag/rel_1_3_9

Update license hash due to copyright year bump:
798abe413d

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
2510757e5e package/python-libevdev: bump version to 0.12
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
fac3063334 package/python-lark: bump version to 1.3.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
55a80f89d7 package/python-httplib2: bump version to 0.31.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
9c015e6018 package/python-hiredis: bump version to 3.2.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
d3523439f2 package/python-hid: bump version to 1.0.8
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:27 +02:00
Bernd Kuhls
e4e257ff24 package/python-grpc-requests: bump version to 0.1.21
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
e302e09a52 package/python-greenlet: bump version to 3.2.4
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
bdd02a191a package/python-googleapis-common-protos: bump version to 1.70.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
6c03908f2a package/python-google-auth: bump version to 2.41.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
542f81825f package/python-google-api-core: bump version to 2.26.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
1e7fc05e86 package/python-fonttools: bump version to 4.60.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
9b91180520 package/python-flatbuffers: bump version to 25.9.23
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
d1888e3915 package/python-fire: bump version to 0.7.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
1f9fe88282 package/python-falcon: bump version to 4.1.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
a66e0bf8f1 package/python-executing: bump version to 2.2.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
cbdd5b816d package/python-evdev: bump version to 1.9.2
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 22:10:26 +02:00
Bernd Kuhls
7f8f523cd2 package/python-esptool: bump version to 5.1.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
b550f71450 package/python-email-validator: bump version to 2.3.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
853e3609c1 package/python-dtschema: bump version to 2025.8
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
f53d6a83a9 package/python-decorator: bump version to 5.2.1
Changelog: https://github.com/micheles/decorator/blob/5.2.1/CHANGES.md

Updated license hash due to copyright year bump:
eac33cb79f

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
a9d699def2 package/python-daphne: bump version to 4.2.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
fd46a9af3a package/python-cssselect: bump version to 1.3.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
720cdb39f2 package/python-cheroot: bump version to 11.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
17d0d7d85e package/python-channels: bump version to 4.3.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
e4aec355ff package/python-certifi: bump version to 2025.10.5
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
8372c94839 package/python-canopen: bump version to 2.4.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
783642dc23 package/python-cachetools: bump version to 6.2.1
Changelog:
https://github.com/tkem/cachetools/blob/v6.2.1/CHANGELOG.rst

Updated license hash due to copyright year bumps:
https://github.com/tkem/cachetools/commits/v6.2.1/LICENSE

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
dc7167dcf6 package/python-bsdiff4: bump version to 1.2.6
Changelog:
https://github.com/ilanschnell/bsdiff4/blob/1.2.6/CHANGELOG.txt

Updated license hash due to copyright year bump:
9eefc06cef

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
b1d2870ae0 package/python-botocore: bump version to 1.40.50
Changelog: https://github.com/boto/botocore/blob/1.40.50/CHANGELOG.rst

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
6decca08a2 package/python-boto3: bump version to 1.40.50
Changelog: https://github.com/boto/boto3/blob/1.40.50/CHANGELOG.rst

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
ffb71b5ecc package/python-bluezero: bump version to 0.9.1
Release notes:
a4b2731aff

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
f98a4ca3a2 package/python-bitarray: bump version to 3.7.2
Changelog:
https://github.com/ilanschnell/bitarray/blob/3.7.2/CHANGE_LOG

Updated license hash due to copyright year bump:
0d64d33960

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
04cee5ed8a package/python-bitstring: bump version to 4.3.1
Release notes:
https://github.com/scott-griffiths/bitstring/releases/tag/bitstring-4.3.1

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
7d51fadc06 package/python-asyncssh: bump version to 2.21.1
Changelog:
https://github.com/ronf/asyncssh/blob/v2.21.1/docs/changes.rst

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
1ad2443369 package/python-async-lru: bump version to 2.0.5
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Bernd Kuhls
6bf65a90a5 package/python-aexpect: bump version to 1.8.0
Removed patch which is included in this release.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-14 20:44:13 +02:00
Titouan Christophe
684462bbe8 package/modsecurity2: security bump to v2.9.12
See the release notes:
- https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.11
- https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.12

This fixes the following vulnerabilities:
- CVE-2025-52891:
    ModSecurity is an open source, cross platform web application firewall
    (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before
    2.9.11, an empty XML tag can cause a segmentation fault. If
    SecParseXmlIntoArgs is set to On or OnlyArgs, and the request type is
    application/xml, and at least one XML tag is empty (eg <foo></foo>),
    then a segmentation fault occurs. This issue has been patched in
    version 2.9.11. A workaround involves setting SecParseXmlIntoArgs to
    Off.
    https://www.cve.org/CVERecord?id=CVE-2025-52891

- CVE-2025-54571:
    ModSecurity is an open source, cross platform web application firewall
    (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below,
    an attacker can override the HTTP response’s Content-Type, which could
    lead to several issues depending on the HTTP scenario. For example, we
    have demonstrated the potential for XSS and arbitrary script source
    code disclosure in the latest version of mod_security2. This issue is
    fixed in version 2.9.12.
    https://www.cve.org/CVERecord?id=CVE-2025-54571

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-13 20:44:19 +02:00
Titouan Christophe
bd47e35e57 package/redis: security bump to v8.2.2
See the release notes:
https://github.com/redis/redis/blob/8.2.2/00-RELEASENOTES

This fixes the following vulnerabilities (in the Lua scripting engine):
- CVE-2025-46817:
    Redis is an open source, in-memory database that persists on disk.
    Versions 8.2.1 and below allow an authenticated user to use a
    specially crafted Lua script to cause an integer overflow and
    potentially lead to remote code execution The problem exists in all
    versions of Redis with Lua scripting. This issue is fixed in version
    8.2.2.
    https://www.cve.org/CVERecord?id=CVE-2025-46817

- CVE-2025-46818:
    Redis is an open source, in-memory database that persists on disk.
    Versions 8.2.1 and below allow an authenticated user to use a
    specially crafted Lua script to manipulate different LUA objects and
    potentially run their own code in the context of another user. The
    problem exists in all versions of Redis with LUA scripting. This issue
    is fixed in version 8.2.2. A workaround to mitigate the problem
    without patching the redis-server executable is to prevent users from
    executing LUA scripts. This can be done using ACL to block a script by
    restricting both the EVAL and FUNCTION command families.
    https://www.cve.org/CVERecord?id=CVE-2025-46818

- CVE-2025-46819:
    Redis is an open source, in-memory database that persists on disk.
    Versions 8.2.1 and below allow an authenticated user to use a
    specially crafted LUA script to read out-of-bound data or crash the
    server and subsequent denial of service. The problem exists in all
    versions of Redis with Lua scripting. This issue is fixed in version
    8.2.2. To workaround this issue without patching the redis-server
    executable is to prevent users from executing Lua scripts. This can be
    done using ACL to block a script by restricting both the EVAL and
    FUNCTION command families.
    https://www.cve.org/CVERecord?id=CVE-2025-46819

- CVE-2025-49844:
    Redis is an open source, in-memory database that persists on disk.
    Versions 8.2.1 and below allow an authenticated user to use a
    specially crafted Lua script to manipulate the garbage collector,
    trigger a use-after-free and potentially lead to remote code
    execution. The problem exists in all versions of Redis with Lua
    scripting. This issue is fixed in version 8.2.2. To workaround this
    issue without patching the redis-server executable is to prevent users
    from executing Lua scripts. This can be done using ACL to restrict
    EVAL and EVALSHA commands.
    https://www.cve.org/CVERecord?id=CVE-2025-49844

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-13 20:37:34 +02:00
Titouan Christophe
f32e6aa226 docs/website/download.html: fix latest releases dates
The website download page was updated for the latest releases of
2025.{02,05,08} in [1], but the column "Latest release date" wasn't
updated.

Moreover, indicate that 2025.05.3 is the EOL stable release.

[1] e5501d7b1a

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2025-10-13 14:03:19 +02:00
Bernd Kuhls
3fef7cbb6d package/linux-headers: drop 6.16.x option
The 6.16.x series is now EOL upstream, so drop the linux-headers
option and add legacy handling for it.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-12 22:53:37 +02:00
Bernd Kuhls
fec2d492a4 {linux, linux-headers}: bump 6.{6, 12, 16, 17}.x series
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-12 22:53:30 +02:00
Bernd Kuhls
ae29b86dc4 package/x265: bump version to 4.1
Release notes:
4.1: https://mailman.videolan.org/pipermail/x265-devel/2024-November/014095.html
4.0: https://mailman.videolan.org/pipermail/x265-devel/2024-September/013940.html
3.6: https://mailman.videolan.org/pipermail/x265-devel/2024-April/013664.html

Rebased patch 0001 and removed patch 0002 due to upstream commit
4bf31dc15f

Added patches 0002 & 0003 to fix build with CMake 4.x.

Added patch 0004 and adjusted _CONF_OPTS to fix non-NEON build.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-12 18:49:55 +02:00
Bernd Kuhls
c5ce3417f4 package/which: bump version to 2.23
Release notes:
https://cgit.git.savannah.gnu.org/cgit/which.git/tree/NEWS?id=3e2c8f8acc3a333b66b06de234bc9324c6fe5500

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-10-12 18:46:30 +02:00