Bernd Kuhls
dddd5de2b6
package/python-pygments: bump version to 2.20.0
...
https://github.com/pygments/pygments/blob/2.20.0/CHANGES
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:24 +02:00
Bernd Kuhls
123136b246
package/python-pyasn1: security bump version to 0.6.3
...
https://github.com/pyasn1/pyasn1/blob/v0.6.3/CHANGES.rst
Fixes CVE-2026-30922.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:24 +02:00
Bernd Kuhls
1b9f5d6ed0
package/python-proto-plus: bump version to 1.27.2
...
https://github.com/googleapis/google-cloud-python/blob/main/packages/proto-plus/CHANGELOG.md
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:24 +02:00
Bernd Kuhls
97fa1b70ca
package/python-poetry-core: bump version to 2.3.2
...
https://github.com/python-poetry/poetry-core/blob/2.3.2/CHANGELOG.md
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:24 +02:00
Bernd Kuhls
2be360a44d
package/python-platformdirs: bump version to 4.9.6
...
https://github.com/tox-dev/platformdirs/blob/4.9.6/docs/changelog.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:24 +02:00
Bernd Kuhls
f8000bbbfb
package/python-pip: bump version to 26.1
...
https://github.com/pypa/pip/blob/26.1/NEWS.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
f6045bd27c
package/python-pdm-backend: bump version to 2.4.8
...
https://github.com/pdm-project/pdm-backend/releases/tag/2.4.8
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
889f971d39
package/python-pathspec: bump version to 1.1.1
...
https://github.com/cpburnz/python-pathspec/blob/v1.1.1/CHANGES.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
66dab62b47
package/python-patch-ng: bump version to 1.19.1
...
https://github.com/conan-io/python-patch-ng/releases/tag/1.19.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
c53fcad220
package/python-packaging: bump version to 26.2
...
https://github.com/pypa/packaging/blob/26.2/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
11a430cfaf
package/python-more-itertools: bump version to 11.0.2
...
https://github.com/more-itertools/more-itertools/blob/v11.0.2/docs/versions.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
9252f73ffc
package/python-matplotlib: security bump version to 3.10.9
...
https://github.com/matplotlib/matplotlib/releases/tag/v3.10.9
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
af7cb9be2a
package/python-marshmallow: bump version to 4.3.0
...
https://github.com/marshmallow-code/marshmallow/blob/4.3.0/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
703a7bde26
package/python-marshmallow-sqlalchemy: bump version to 1.5.0
...
https://github.com/marshmallow-code/marshmallow-sqlalchemy/blob/1.5.0/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
5aca3c0433
package/python-mako: bump version to 1.3.12
...
https://github.com/sqlalchemy/mako/releases/tag/rel_1_3_11
https://github.com/sqlalchemy/mako/releases/tag/rel_1_3_12
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
2286c4a02c
package/python-lmdb: security bump version to 2.2.0
...
https://github.com/jnwatson/py-lmdb/blob/py-lmdb_2.2.0/ChangeLog
Version 2.1.0 fixes the following CVEs:
- **CVE-2019-16224**: heap buffer overflow via `MDB_DUPFIXED` without
`MDB_DUPSORT` in on-disk `md_flags`. (#429 )
- **CVE-2019-16225**: `SIGSEGV` from `P_DIRTY` flag set on mmap'd disk pages,
causing `mdb_page_touch()` to skip copy-on-write. (#429 )
- **CVE-2019-16226**: out-of-bounds `memmove` in `mdb_node_del` via corrupt
`mn_hi` making `NODEDSZ()` huge. (#429 )
- **CVE-2019-16227**: NULL pointer dereference of `mc_xcursor` when
`F_DUPDATA` is set on a node in a non-DUPSORT database. (#429 )
- **CVE-2019-16228**: divide-by-zero from zero `mm_psize` in meta page
header. (#429 )
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
ac6b204e02
package/python-librt: bump version to 0.9.0
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
522da23ccb
package/python-installer: bump version to 1.0.0
...
https://github.com/pypa/installer/releases/tag/1.0.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
7330ecb682
package/python-hiredis: bump version to 3.3.1
...
https://github.com/redis/hiredis-py/releases/tag/v3.3.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
b50e6b48d9
package/python-greenlet: bump version to 3.5.0
...
https://greenlet.readthedocs.io/en/latest/changes.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
93126ad1f3
package/python-googleapis-common-protos: bump version to 1.74.0
...
https://github.com/googleapis/google-cloud-python/blob/main/packages/googleapis-common-protos/CHANGELOG.md
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
9b9ba84a41
package/python-google-api-core: bump version to 2.30.3
...
https://github.com/googleapis/google-cloud-python/blob/main/packages/google-api-core/CHANGELOG.md
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
6f49639d8c
package/python-flask-wtf: bump version to 1.3.0
...
https://github.com/pallets-eco/flask-wtf/releases/tag/v1.3.0
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
738fcefad6
package/python-flask-smorest: bump version to 0.47.0
...
https://github.com/marshmallow-code/flask-smorest/blob/0.47.0/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
790b9185df
package/python-filelock: bump version to 3.29.0
...
https://github.com/tox-dev/filelock/blob/3.29.0/docs/changelog.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
536875e989
package/python-fastapi: bump to version 0.136.1
...
https://fastapi.tiangolo.com/release-notes/#01361-2026-04-23
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
c2a90f9621
package/python-editables: bump version to 0.6
...
https://github.com/pfmoore/editables/blob/0.6/CHANGELOG.md
Updated license hash due to removal of DOS line endings.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
cd15955792
package/python-dtschema: bump version to 2026.4
...
https://github.com/devicetree-org/dt-schema/releases/tag/v2026.04
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
6628b4f51b
package/python-dbus-fast: bump version to 4.0.4
...
https://github.com/Bluetooth-Devices/dbus-fast/releases/tag/v4.0.1
https://github.com/Bluetooth-Devices/dbus-fast/releases/tag/v4.0.2
https://github.com/Bluetooth-Devices/dbus-fast/releases/tag/v4.0.3
https://github.com/Bluetooth-Devices/dbus-fast/releases/tag/v4.0.4
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
5a430a6f92
package/python-cryptography: bump to version 47.0.0
...
https://cryptography.io/en/47.0.0/changelog/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
c7cbf6bd2b
package/python-click: bump version to 8.3.3
...
https://click.palletsprojects.com/en/stable/changes/#version-8-3-3
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
4662c679e7
package/python-certifi: bump version to 2026.4.22
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
b676a4f51b
package/python-cbor2: security bump version to 5.9.0
...
https://github.com/agronholm/cbor2/blob/5.9.0/docs/versionhistory.rst
Fixes CVE-2026-26209.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
7e98e745c4
package/python-botocore: bump version to 1.43.1
...
https://github.com/boto/botocore/blob/1.43.1/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
68cdf123d4
package/python-boto3: bump version to 1.43.1
...
https://github.com/boto/boto3/blob/1.43.1/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
ab7bd853fa
package/python-bleak: bump version to 3.0.1
...
https://github.com/hbldh/bleak/blob/v3.0.1/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
6b2e8baf2e
package/python-bitarray: bump version to 3.8.1
...
https://github.com/ilanschnell/bitarray/blob/3.8.1/CHANGE_LOG
Updated license hash due to copyright year bump:
730c524980
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
e2db3fda4c
package/python-attrs: bump version to 26.1.0
...
https://www.attrs.org/en/stable/changelog.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
11e5013d97
package/python-async-lru: bump version to 2.3.0
...
https://github.com/aio-libs/async-lru/blob/v2.3.0/CHANGES.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
e3491e3e58
package/python-anyio: bump to 4.13.0
...
https://anyio.readthedocs.io/en/stable/versionhistory.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
0613918784
package/python-aiohttp: bump version to 3.13.5
...
https://github.com/aio-libs/aiohttp/blob/v3.13.5/CHANGES.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-03 16:48:23 +02:00
Bernd Kuhls
fdcbe271af
package/openvpn: bump version to 2.7.4
...
https://github.com/OpenVPN/openvpn/blob/v2.7.4/Changes.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 18:36:53 +02:00
Bernd Kuhls
b8a0093495
{linux, linux-headers}: bump 5.{10, 15}.x / 6.{1, 6, 12, 18}.x / 7.0.x series
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 13:54:46 +02:00
Giulio Benetti
d230af8bba
DEVELOPERS: add Giulio Benetti to wireshark
...
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 13:46:29 +02:00
Giulio Benetti
1880965a3b
package/wireshark: security bump to v4.4.15
...
For more information on the version bump, see:
- https://www.wireshark.org/docs/relnotes/wireshark-4.4.15.html
Fixes the following vulnerabilities:
CVE-2026-5409, CVE-2026-5408, CVE-2026-5406, CVE-2026-5407, CVE-2026-5299,
CVE-2026-5401, CVE-2026-5404, CVE-2026-5403, CVE-2026-5405, CVE-2026-5654,
CVE-2026-5657, CVE-2026-5656, CVE-2026-5653, CVE-2026-6538, CVE-2026-6537,
CVE-2026-6535, CVE-2026-6534, CVE-2026-6533, CVE-2026-6532, CVE-2026-6531,
CVE-2026-6530, CVE-2026-6529, CVE-2026-6527, CVE-2026-6524, CVE-2026-6523,
CVE-2026-6521, CVE-2026-6520, CVE-2026-6519, CVE-2026-6522, CVE-2026-6870,
CVE-2026-6869, CVE-2026-6868.
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 13:33:36 +02:00
Bernd Kuhls
6935bc7412
package/thrift: security bump version to 0.23.0
...
https://github.com/apache/thrift/blob/v0.23.0/CHANGES.md
Fixes the following CVEs:
CVE-2026-41636: https://seclists.org/oss-sec/2026/q2/236
CVE-2026-41607: https://seclists.org/oss-sec/2026/q2/237
CVE-2026-41606: https://seclists.org/oss-sec/2026/q2/238
CVE-2026-41605: https://seclists.org/oss-sec/2026/q2/239
CVE-2026-41604: https://seclists.org/oss-sec/2026/q2/240
CVE-2026-41602: https://seclists.org/oss-sec/2026/q2/241
CVE-2026-41603: https://seclists.org/oss-sec/2026/q2/242
CVE-2025-48431: https://seclists.org/oss-sec/2026/q2/243
This commit also adds "Public Domain" in THRIFT_LICENSE, after
upstream commit [1] added a new sha256 implementation with that
license. The LICENSE file hash is also updated accordingly.
[1] 1e5fa4b9b3
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 13:28:46 +02:00
Bernd Kuhls
0d5ce9ed84
package/proftpd: security bump version to 1.3.9a
...
https://github.com/proftpd/proftpd/blob/v1.3.9a/NEWS
Fixes CVE-2026-42167.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
[Julien: use tag in NEWS URL in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 13:10:01 +02:00
Bernd Kuhls
d459d257c3
package/gnutls: security bump to version 3.8.13
...
https://lists.gnupg.org/pipermail/gnutls-help/2026-April/004922.html
Fixes the following CVEs:
CVE-2026-33845
CVE-2026-33846
CVE-2026-3832
CVE-2026-3833
CVE-2026-42009
CVE-2026-42010
CVE-2026-42011
CVE-2026-42012
CVE-2026-42013
CVE-2026-42014
CVE-2026-42015
CVE-2026-5260
CVE-2026-5419
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 11:57:37 +02:00
Bernd Kuhls
8940fae607
package/libcurl: security bump to version 8.20.0
...
https://curl.se/ch/8.20.0.html
https://curl.se/docs/security.html
Fixes the following CVEs:
https://curl.se/docs/CVE-2026-7168.html
https://curl.se/docs/CVE-2026-7009.html
https://curl.se/docs/CVE-2026-6429.html
https://curl.se/docs/CVE-2026-6276.html
https://curl.se/docs/CVE-2026-6253.html
https://curl.se/docs/CVE-2026-5773.html
https://curl.se/docs/CVE-2026-5545.html
https://curl.se/docs/CVE-2026-4873.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 11:51:58 +02:00
Bernd Kuhls
3f6d37ab9a
package/exim: security bump version to 4.99.2
...
https://lists.exim.org/lurker/message/20260429.121733.f58d9686.en.html
Fixes CVEs:
CVE-2026-40684 Possible crash with malicious DNS data when using musl libc
On systems using musl libc (not glibc) due to an oddity in octal printing
it is possible to crash the connection instance when malformed DNS data
is present in PTR records.
CVE-2026-40685 Possible OOB read/write on corrupt JSON in header
configurations using json operators on invalid externally-provided input
could trigger heap corruption.
CVE-2026-40686 Possible OOB read with large UTF8 trailing characters
configurations using utf8 operators on malformed utf8 in headers could
trigger OOB reads and might trigger some data leak if error
messages are required for subsequent emails in the current connection
and similar malformed headers are present.
CVE-2026-40687 Possible OOB read/write with SPA authenticator
in configurations using the SPA authentication driver to a hostile/compromised
external SPA/NTLM connnection it is possible to trigger an OOB read/write
and crash the connection instance or possibly leak heap data to the instance.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2026-05-02 11:44:51 +02:00