head 1.18;
access;
symbols
pkgsrc-2026Q3:1.17.0.2
pkgsrc-2026Q3-base:1.17
pkgsrc-2026Q2:1.16.0.4
pkgsrc-2026Q2-base:1.16
pkgsrc-2026Q1:1.16.0.2
pkgsrc-2026Q1-base:1.16
pkgsrc-2025Q4:1.15.0.2
pkgsrc-2025Q4-base:1.15
pkgsrc-2025Q3:1.14.0.4
pkgsrc-2025Q3-base:1.14
pkgsrc-2025Q2:1.14.0.2
pkgsrc-2025Q2-base:1.14
pkgsrc-2025Q1:1.12.0.4
pkgsrc-2025Q1-base:1.12
pkgsrc-2024Q4:1.12.0.2
pkgsrc-2024Q4-base:1.12
pkgsrc-2024Q3:1.11.0.2
pkgsrc-2024Q3-base:1.11
pkgsrc-2024Q2:1.10.0.2
pkgsrc-2024Q2-base:1.10
pkgsrc-2024Q1:1.9.0.2
pkgsrc-2024Q1-base:1.9
pkgsrc-2023Q4:1.8.0.2
pkgsrc-2023Q4-base:1.8
pkgsrc-2023Q3:1.6.0.2
pkgsrc-2023Q3-base:1.6
pkgsrc-2023Q2:1.5.0.2
pkgsrc-2023Q2-base:1.5
pkgsrc-2023Q1:1.3.0.2
pkgsrc-2023Q1-base:1.3
pkgsrc-2022Q4:1.2.0.2
pkgsrc-2022Q4-base:1.2;
locks; strict;
comment @# @;
1.18
date 2026.10.01.07.48.34; author adam; state Exp;
branches;
next 1.17;
commitid Il17vTocjugOlKXG;
1.17
date 2026.08.13.12.26.36; author adam; state Exp;
branches;
next 1.16;
commitid uK5mcbH3OK1PstRG;
1.16
date 2026.03.04.06.51.45; author adam; state Exp;
branches;
next 1.15;
commitid YGZczgUfr9NLOCwG;
1.15
date 2025.10.10.12.57.12; author adam; state Exp;
branches;
next 1.14;
commitid nJ7VhcBRGcs4v1eG;
1.14
date 2025.06.04.14.14.17; author adam; state Exp;
branches;
next 1.13;
commitid QGsnv8s0FZxH2AXF;
1.13
date 2025.04.09.14.47.58; author adam; state Exp;
branches;
next 1.12;
commitid 0IRavEVzlaBB1oQF;
1.12
date 2024.12.05.07.51.12; author adam; state Exp;
branches;
next 1.11;
commitid aVLjViiPBheYJhAF;
1.11
date 2024.09.09.15.50.30; author adam; state Exp;
branches;
next 1.10;
commitid pNKjnwfx6xQHb9pF;
1.10
date 2024.04.08.12.49.33; author adam; state Exp;
branches;
next 1.9;
commitid 81Mu3aXP9tch8l5F;
1.9
date 2024.02.07.08.02.11; author adam; state Exp;
branches;
next 1.8;
commitid xBoC3o5ZZmjuvtXE;
1.8
date 2023.12.11.10.23.43; author adam; state Exp;
branches;
next 1.7;
commitid sjBbPNM5hn6B92QE;
1.7
date 2023.10.02.19.59.04; author adam; state Exp;
branches;
next 1.6;
commitid i3hUMTWH7gatA5HE;
1.6
date 2023.08.25.08.28.22; author adam; state Exp;
branches;
next 1.5;
commitid mw3wi7aDwRq4Z8CE;
1.5
date 2023.06.08.10.04.26; author adam; state Exp;
branches;
next 1.4;
commitid JBWxLUIUyv9V18sE;
1.4
date 2023.04.06.11.30.37; author adam; state Exp;
branches;
next 1.3;
commitid R8CnuF9kkk6Mw2kE;
1.3
date 2023.02.09.10.48.15; author adam; state Exp;
branches;
next 1.2;
commitid 7KlrD9YLEJvN5QcE;
1.2
date 2022.12.07.11.55.37; author adam; state Exp;
branches;
next 1.1;
commitid FjXv9wnktKcgwC4E;
1.1
date 2022.10.31.09.50.40; author adam; state Exp;
branches;
next ;
commitid dJ2usVQFvHvi1RZD;
desc
@@
1.18
log
@python311 py311-html-docs: updated to 3.11.17
3.11.17
Security
gh-158446: Fix a crash or incorrect output that could occur when formatting a float or complex with a precision close to the platform’s INT_MAX. PyOS_double_to_string() now raises ValueError for any precision of that magnitude, regardless of presentation type or value, as the format string parsers already did for precisions above INT_MAX.
gh-156793: asyncio: loop.start_tls() and loop.create_connection() now validate the server_hostname argument if an ssl.SSLContext is passed with check_hostname set to True, emitting DeprecationWarning if server_hostname is missing. (This will raise ValueError in Python 3.13 and later.)
gh-156793: ssl.SSLContext.wrap_bio() now validates its server_side, server_hostname and session arguments similar to ssl.SSLContext.wrap_socket(), but for backward compatiblity reasons emits DeprecationWarning instead of ValueError.
In particular, a context with check_hostname enabled and no server_hostname passed to wrap_bio() now emits DeprecationWarning to indicate the hostname wasn’t checked. (In Python 3.13 and later, this raises ValueError.)
gh-157265: In tarfile, when extracting a link falls back to extracting a member of the archive, skip the member when the filter function returns None when called with the extracted member’s name replaced with the link’s.
gh-157190: Fixed a vulnerability in the tarfile data and tar extraction filters where a crafted archive using a hard link to a symbolic link could change the permissions and modification time of a file outside the destination directory, and expose its contents inside the extracted tree. This addresses CVE 2026-82049.
gh-157953: Update bundled libexpat to version 2.8.5.
gh-156002: Bound the amount of data zipfile decompresses per read for members compressed with bzip2, LZMA, or Zstandard, matching the existing limit for deflate. A small archive member could previously expand into an unbounded allocation even when read in small chunks.
gh-155999: Fix the tarfile tar and data extraction filters creating directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.
gh-156293: Fix a crash in ssl when an sni_callback switches a connection to another SSLContext and the context that carries the callback is no longer referenced by the application. Servers that keep their sni_callback context alive (the usual case when it wraps the listening socket or is stored on the server object) were not affected. This addresses CVE-2026-19445.
gh-155292: Change the stringprep module and encodings.idna codec to not consider Unicode codepoint attributes beyond those defined in RFC 3454.
gh-155694: Fix CVE-2026-15806 by scoping HTTPPasswordMgr credentials to the URL scheme, preventing credentials stored for an HTTPS URL from being used for a matching HTTP URL, while URIs without a scheme continue to match any scheme.
Library
gh-156002: zipfile again reads members through a third-party decompressor installed by monkey-patching the private _get_decompressor() to return an object that only implements old BZ2Decompressor API from Python 3.3. Note that decompressors without needs_input and two-argument decompress() are vulnerable to CVE 2026-15310.
gh-156353: Fix configparser parsing when using whitespace in delimiters.
Build
gh-155757: Set the --argv0 argument to wasmtime for WASI builds so the test suite passes. Otherwise the calculated paths to the stdlib for frozen modules is incorrect.
@
text
@$NetBSD: distinfo,v 1.17 2026/08/13 12:26:36 adam Exp $
BLAKE2s (python-3.11.17-docs-html.tar.bz2) = f31e82b93b8e3c7a068a6e5c13535a990ef4209d33359fca5cb18859b5b606f2
SHA512 (python-3.11.17-docs-html.tar.bz2) = fe809039a00bd353bf176e7f239c11d6ae14228cd734fabdbac6bb5d894e083fc87e65e47d40a58e0b5b2c27654a6e31379b36f42dd3631575e19d518b395117
Size (python-3.11.17-docs-html.tar.bz2) = 8022556 bytes
@
1.17
log
@python311 py311-html-docs: updated to 3.11.16
3.11.16
macOS
gh-137586: Invoke osascript with absolute path in webbrowser and turtledemo.
Tests
gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it’s not supported. Patch by Victor Stinner.
Security
gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE-2026-72522.
gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service.
gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings.
gh-152216: Update bundled libexpat to version 2.8.2.
gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback.
gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached.
gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree.
gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE-2025-4330.
gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.
gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @@YLChen-007 via GHSA-w4q2-g22w-6fr4.
gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE-2026-45186.
gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report.
gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter.
gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs.
gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later.
gh-149017: Update bundled libexpat to version 2.8.0.
gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop.
gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, and bz2.BZ2Decompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer.
gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check.
gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped.
gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage.
gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method.
gh-145986: xml.parsers.expat: Fixed a crash caused by unbounded C recursion when converting deeply nested XML content models with ElementDeclHandler(). This addresses CVE-2026-4224.
gh-145599: Reject control characters in http.cookies.Morsel update() and js_output(). This addresses CVE-2026-3644.
gh-145506: Fixes CVE-2026-2297 by ensuring that SourcelessFileLoader uses io.open_code() when opening .pyc files.
gh-144370: Disallow usage of control characters in status in wsgiref.handlers to prevent HTTP header injections. Patch by Benedikt Johannes.
gh-143930: Reject leading dashes in URLs passed to webbrowser.open().
gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values.
Library
gh-109638: Fix exponential time in csv.Sniffer.sniff() for a sample which contains many quote characters. A doubled quote character is now also detected in a field which contains the delimiter or a line break.
gh-98820: Fix quadratic time in csv.Sniffer.sniff() for a sample which contains quoted fields, in particular for a single column of quoted fields.
gh-149231: In tomllib, the number of parts in TOML keys is now limited.
gh-146083: Update bundled libexpat to version 2.7.5.
gh-141707: Don’t change tarfile.TarInfo type from AREGTYPE to DIRTYPE when parsing GNU long name or link headers.
gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects to tune protections against billion laughs attacks. Patch by Bénédikt Tran.
gh-100372: ssl.SSLContext.load_verify_locations() no longer incorrectly accepts some cases of trailing data when parsing DER.
Build
gh-153438: Update Windows build and installer tooling and documentation to use the current download URL for nuget.exe.
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.16 2026/03/04 06:51:45 adam Exp $
d3 3
a5 3
BLAKE2s (python-3.11.16-docs-html.tar.bz2) = a8c27d91d811e6090848b7d2861875e1d6a80094c8665c2b7cf2fabfefb07811
SHA512 (python-3.11.16-docs-html.tar.bz2) = 051061ea5dae0c15840e3a6751a347a3ea069ce7d34275d56531155c016ad1a06a40d9f56b311670f70690b3765e738f0a982dee1e839294305c0aee91b3272c
Size (python-3.11.16-docs-html.tar.bz2) = 8006278 bytes
@
1.16
log
@python311 py311-html-docs: updated to 3.11.15
Python 3.11.15
Security
gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).
gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
gh-143925: Reject control characters in data: URL media types.
gh-143919: Reject control characters in http.cookies.Morsel fields and values.
gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
gh-142145: Remove quadratic behavior in xml.minidom node ID cache clearing. In order to do this without breaking existing users, we also add the ownerDocument attribute to xml.dom.minidom elements and attributes created by directly instantiating the Element or Attr class. Note that this way of creating nodes is not supported; creator functions like xml.dom.Document.documentElement() should be used instead.
gh-137836: Add support of the “plaintext” element, RAWTEXT elements “xmp”, “iframe”, “noembed” and “noframes”, and optionally RAWTEXT element “noscript” in html.parser.HTMLParser.
gh-136063: email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.
gh-136065: Fix quadratic complexity in os.path.expandvars().
gh-119451: Fix a potential memory denial of service in the http.client module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
gh-119452: Fix a potential memory denial of service in the http.server module. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
gh-119342: Fix a potential memory denial of service in the plistlib module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
Library
gh-144833: Fixed a use-after-free in ssl when SSL_new() returns NULL in newPySSLSocket(). The error was reported via a dangling pointer after the object had already been freed.
gh-144363: Update bundled libexpat to 2.7.4
gh-90949: Add SetAllocTrackerActivationThreshold() and SetAllocTrackerMaximumAmplification() to xmlparser objects to prevent use of disproportional amounts of dynamic memory from within an Expat parser. Patch by Bénédikt Tran.
Core and Builtins
gh-120384: Fix an array out of bounds crash in list_ass_subscript, which could be invoked via some specificly tailored input: including concurrent modification of a list object, where one thread assigns a slice and another clears it.
gh-120298: Fix use-after free in list_richcompare_impl which can be invoked via some specificly tailored evil input.
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.15 2025/10/10 12:57:12 adam Exp $
d3 3
a5 3
BLAKE2s (python-3.11.15-docs-html.tar.bz2) = 9171b3c0e04670bc464ad22e2944c3485535b900e22bc75219caa402d8f3a555
SHA512 (python-3.11.15-docs-html.tar.bz2) = 6a8815e32e5535214782c7378eb0678571cba46c9d5eb817323a3485c732127490142bc78deb00d2f37c8d3a62ceee736c746a120ea1a0dba6b08423123bc97e
Size (python-3.11.15-docs-html.tar.bz2) = 7879534 bytes
@
1.15
log
@python311 py311-html-docs: updated to 3.11.14
Python 3.11.14
Security
gh-139700: Check consistency of the zip64 end of central directory record. Support records with “zip64 extensible data” if there are no bytes prepended to the ZIP file.
gh-139400: xml.parsers.expat: Make sure that parent Expat parsers are only garbage-collected once they are no longer referenced by subparsers created by ExternalEntityParserCreate(). Patch by Sebastian Pipping.
gh-135661: Fix parsing start and end tags in html.parser.HTMLParser according to the HTML5 standard.
Whitespaces no longer accepted between and the tag name. E.g. script> does not end the script section.
Vertical tabulation (\v) and non-ASCII whitespaces no longer recognized as whitespaces. The only whitespaces are \t\n\r\f and space.
Null character (U+0000) no longer ends the tag name.
Attributes and slashes after the tag name in end tags are now ignored, instead of terminating after the first > in quoted attribute value. E.g. "/>.
Multiple slashes and whitespaces between the last attribute and closing > are now ignored in both start and end tags. E.g. .
Multiple = between attribute name and value are no longer collapsed. E.g. produces attribute “foo” with value “=bar”.
gh-135661: Fix CDATA section parsing in html.parser.HTMLParser according to the HTML5 standard: ] ]> and ]] > no longer end the CDATA section. Add private method _set_support_cdata() which can be used to specify how to parse <[CDATA[ — as a CDATA section in foreign content (SVG or MathML) or as a bogus comment in the HTML namespace.
gh-102555: Fix comment parsing in html.parser.HTMLParser according to the HTML5 standard. --!> now ends the comment. -- > no longer ends the comment. Support abnormally ended empty comments <--> and <--->.
gh-135462: Fix quadratic complexity in processing specially crafted input in html.parser.HTMLParser. End-of-file errors are now handled according to the HTML5 specs – comments and declarations are automatically closed, tags are ignored.
gh-118350: Fix support of escapable raw text mode (elements “textarea” and “title”) in html.parser.HTMLParser.
gh-86155: html.parser.HTMLParser.close() no longer loses data when the