diff --git a/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch b/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch deleted file mode 100644 index 0f76f7313fde..000000000000 --- a/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 5592bfb58eb8d1c8a644e67c9bba795d1384a995 Mon Sep 17 00:00:00 2001 -From: Marc Lehmann -Date: Sat, 6 Sep 2025 11:31:36 +0200 -Subject: [PATCH 1/2] fix json_atof_scan1 overflows - -with fuzzed overlong numbers. CVE-2025-40928 -Really the comparisons were wrong. ---- - XS.xs | 8 ++++---- - 1 file changed, 4 insertions(+), 4 deletions(-) - -diff --git a/XS.xs b/XS.xs -index 9b1ce2b..94ab0d6 100755 ---- a/XS.xs -+++ b/XS.xs -@@ -710,16 +710,16 @@ json_atof_scan1 (const char *s, NV *accum, int *expo, int postdp, int maxdepth) - /* if we recurse too deep, skip all remaining digits */ - /* to avoid a stack overflow attack */ - if (UNLIKELY(--maxdepth <= 0)) -- while (((U8)*s - '0') < 10) -+ while ((U8)(*s - '0') < 10) - ++s; - - for (;;) - { -- U8 dig = (U8)*s - '0'; -+ U8 dig = (U8)(*s - '0'); - - if (UNLIKELY(dig >= 10)) - { -- if (dig == (U8)((U8)'.' - (U8)'0')) -+ if (dig == (U8)('.' - '0')) - { - ++s; - json_atof_scan1 (s, accum, expo, 1, maxdepth); -@@ -739,7 +739,7 @@ json_atof_scan1 (const char *s, NV *accum, int *expo, int postdp, int maxdepth) - else if (*s == '+') - ++s; - -- while ((dig = (U8)*s - '0') < 10) -+ while ((dig = (U8)(*s - '0')) < 10) - exp2 = exp2 * 10 + *s++ - '0'; - - *expo += neg ? -exp2 : exp2; --- -2.50.1 - diff --git a/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch b/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch deleted file mode 100644 index dd8492c60f21..000000000000 --- a/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch +++ /dev/null @@ -1,25 +0,0 @@ -From ca70a73bb147549e62e74751d924b1dbb59d1707 Mon Sep 17 00:00:00 2001 -From: Stig Palmquist -Date: Thu, 5 Jun 2025 03:45:50 +0200 -Subject: [PATCH] Fix CVE-2011-10007 - ---- - lib/File/Find/Rule.pm | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/lib/File/Find/Rule.pm b/lib/File/Find/Rule.pm -index feccc76..d4dc475 100644 ---- a/lib/File/Find/Rule.pm -+++ b/lib/File/Find/Rule.pm -@@ -420,7 +420,7 @@ sub grep { - - $self->exec( sub { - local *FILE; -- open FILE, $_ or return; -+ open FILE, '<', $_ or return; - local ($_, $.); - while () { - for my $p (@pattern) { --- -2.49.0 - diff --git a/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch b/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch deleted file mode 100644 index f1d258c12a3d..000000000000 --- a/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch +++ /dev/null @@ -1,31 +0,0 @@ ---- a/XS.xs 2025-09-06 08:34:51.376455632 -0300 -+++ b/XS.xs 2025-09-06 08:35:30.725873619 -0300 -@@ -253,16 +253,16 @@ - // if we recurse too deep, skip all remaining digits - // to avoid a stack overflow attack - if (expect_false (--maxdepth <= 0)) -- while (((U8)*s - '0') < 10) -+ while ((U8)(*s - '0') < 10) - ++s; - - for (;;) - { -- U8 dig = (U8)*s - '0'; -+ U8 dig = *s - '0'; - - if (expect_false (dig >= 10)) - { -- if (dig == (U8)((U8)'.' - (U8)'0')) -+ if (dig == (U8)('.' - '0')) - { - ++s; - json_atof_scan1 (s, accum, expo, 1, maxdepth); -@@ -282,7 +282,7 @@ - else if (*s == '+') - ++s; - -- while ((dig = (U8)*s - '0') < 10) -+ while ((dig = (U8)(*s - '0')) < 10) - exp2 = exp2 * 10 + *s++ - '0'; - - *expo += neg ? -exp2 : exp2; diff --git a/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch b/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch deleted file mode 100644 index 5433d3afd934..000000000000 --- a/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch +++ /dev/null @@ -1,242 +0,0 @@ -From bee8338fd1cbd7aad4bf60c2965833343b6ead6f Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Tue, 21 May 2024 15:17:30 +0200 -Subject: [PATCH 1/3] Fix test suite with libxml2 2.13.0 - ---- - t/02parse.t | 7 ++++++- - t/08findnodes.t | 8 +++++++- - t/19die_on_invalid_utf8_rt_58848.t | 2 +- - t/25relaxng.t | 4 ++-- - t/26schema.t | 4 ++-- - t/60error_prev_chain.t | 8 ++++---- - 6 files changed, 22 insertions(+), 11 deletions(-) - -diff --git a/t/02parse.t b/t/02parse.t -index b111507b..40aa5f13 100644 ---- a/t/02parse.t -+++ b/t/02parse.t -@@ -884,7 +884,12 @@ EOXML - eval { - $doc2 = $parser->parse_string( $xmldoc ); - }; -- isnt($@, '', "error parsing $xmldoc"); -+ # https://gitlab.gnome.org/GNOME/libxml2/-/commit/b717abdd -+ if (XML::LibXML::LIBXML_RUNTIME_VERSION() < 21300) { -+ isnt($@, '', "error parsing $xmldoc"); -+ } else { -+ is( $doc2->documentElement()->firstChild()->nodeName(), "foo" ); -+ } - - $parser->validation(1); - -diff --git a/t/08findnodes.t b/t/08findnodes.t -index 016c85a1..e9417bc5 100644 ---- a/t/08findnodes.t -+++ b/t/08findnodes.t -@@ -123,7 +123,13 @@ my $docstring = q{ - my @ns = $root->findnodes('namespace::*'); - # TEST - --is(scalar(@ns), 2, ' TODO : Add test name' ); -+# https://gitlab.gnome.org/GNOME/libxml2/-/commit/aca16fb3 -+# fixed xmlCopyNamespace with XML namespace. -+if (XML::LibXML::LIBXML_RUNTIME_VERSION() < 21300) { -+ is(scalar(@ns), 2, ' TODO : Add test name' ); -+} else { -+ is(scalar(@ns), 3, ' TODO : Add test name' ); -+} - - # bad xpaths - # TEST:$badxpath=4; -diff --git a/t/19die_on_invalid_utf8_rt_58848.t b/t/19die_on_invalid_utf8_rt_58848.t -index aa8ad105..4160cb27 100644 ---- a/t/19die_on_invalid_utf8_rt_58848.t -+++ b/t/19die_on_invalid_utf8_rt_58848.t -@@ -16,7 +16,7 @@ use XML::LibXML; - my $err = $@; - - # TEST -- like ("$err", qr{parser error : Input is not proper UTF-8}, -+ like ("$err", qr{not proper UTF-8|Invalid bytes in character encoding}, - 'Parser error.', - ); - } -diff --git a/t/25relaxng.t b/t/25relaxng.t -index 93e61883..71383b2a 100644 ---- a/t/25relaxng.t -+++ b/t/25relaxng.t -@@ -132,7 +132,7 @@ print "# 6 check that no_network => 1 works\n"; - { - my $rng = eval { XML::LibXML::RelaxNG->new( location => $netfile, no_network => 1 ) }; - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'RNG from file location with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'RNG from file location with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $rng, 'RNG from file location with external import and no_network => 1 is not loaded.' ); - } -@@ -152,7 +152,7 @@ print "# 6 check that no_network => 1 works\n"; - - EOF - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'RNG from buffer with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'RNG from buffer with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $rng, 'RNG from buffer with external import and no_network => 1 is not loaded.' ); - } -diff --git a/t/26schema.t b/t/26schema.t -index 17f641e4..c404cedd 100644 ---- a/t/26schema.t -+++ b/t/26schema.t -@@ -117,7 +117,7 @@ EOF - { - my $schema = eval { XML::LibXML::Schema->new( location => $netfile, no_network => 1 ) }; - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'Schema from file location with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'Schema from file location with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $schema, 'Schema from file location with external import and no_network => 1 is not loaded.' ); - } -@@ -129,7 +129,7 @@ EOF - - EOF - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'Schema from buffer with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'Schema from buffer with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $schema, 'Schema from buffer with external import and no_network => 1 is not loaded.' ); - } -diff --git a/t/60error_prev_chain.t b/t/60error_prev_chain.t -index e48215c4..55ac0b2e 100644 ---- a/t/60error_prev_chain.t -+++ b/t/60error_prev_chain.t -@@ -16,13 +16,11 @@ use XML::LibXML; - - { - my $parser = XML::LibXML->new(); -- $parser->validation(0); -- $parser->load_ext_dtd(0); - - eval - { - local $^W = 0; -- $parser->parse_file('example/JBR-ALLENtrees.htm'); -+ $parser->parse_string('“ ”'); - }; - - my $err = $@; -@@ -31,7 +29,7 @@ use XML::LibXML; - if( $err && !ref($err) ) { - plan skip_all => 'The local libxml library does not support errors as objects to $@'; - } -- plan tests => 1; -+ plan tests => 2; - - while (defined($err) && $count < 200) - { -@@ -44,6 +42,8 @@ use XML::LibXML; - - # TEST - ok ((!$err), "Reached the end of the chain."); -+ # TEST -+ is ($count, 3, "Correct number of errors reported") - } - - =head1 COPYRIGHT & LICENSE - -From c9f9c2fe51173b0a00969f01b577399f1098aa47 Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Thu, 13 Feb 2025 19:50:35 +0100 -Subject: [PATCH 2/3] Fix test suite with libxml2 2.14.0 - ---- - t/16docnodes.t | 7 ++++++- - t/49_load_html.t | 8 +++++++- - 2 files changed, 13 insertions(+), 2 deletions(-) - -diff --git a/t/16docnodes.t b/t/16docnodes.t -index db7bc1fc..0b0ae005 100644 ---- a/t/16docnodes.t -+++ b/t/16docnodes.t -@@ -60,7 +60,12 @@ for my $time (0 .. 2) { - $doc->setDocumentElement($node); - - # TEST -- is( $node->serialize(), '', 'Node serialise works.' ); -+ # libxml2 2.14 avoids unnecessary escaping of attribute values. -+ if (XML::LibXML::LIBXML_VERSION() >= 21400) { -+ is( $node->serialize(), "", 'Node serialise works.' ); -+ } else { -+ is( $node->serialize(), '', 'Node serialise works.' ); -+ } - - $doc->setEncoding('utf-8'); - # Second output -diff --git a/t/49_load_html.t b/t/49_load_html.t -index 70d26607..3861edf8 100644 ---- a/t/49_load_html.t -+++ b/t/49_load_html.t -@@ -52,7 +52,13 @@ use XML::LibXML; - - EOS - -- { -+ SKIP: { -+ # libxml2 2.14 tokenizes HTML according to HTML5 where -+ # this isn't an error, see "13.2.5.73 Named character -+ # reference state". -+ skip("libxml2 version >= 21400", 1) -+ if XML::LibXML::LIBXML_VERSION >= 21400; -+ - my $buf = ''; - open my $fh, '>', \$buf; - # redirect STDERR there - -From ecbebc2f33fecb66b3d5487c6e48bea353e374f9 Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Fri, 16 May 2025 19:11:12 +0200 -Subject: [PATCH 3/3] Remove tests that disable line numbers - -Line numbers are always enabled since libxml2 2.15.0. ---- - t/02parse.t | 13 ++----------- - 1 file changed, 2 insertions(+), 11 deletions(-) - -diff --git a/t/02parse.t b/t/02parse.t -index 40aa5f13..17419f8f 100644 ---- a/t/02parse.t -+++ b/t/02parse.t -@@ -14,7 +14,7 @@ use locale; - - POSIX::setlocale(LC_ALL, "C"); - --use Test::More tests => 533; -+use Test::More tests => 531; - use IO::File; - - use XML::LibXML::Common qw(:libxml); -@@ -25,7 +25,7 @@ use constant XML_DECL => "\n"; - - use Errno qw(ENOENT); - --# TEST*533 -+# TEST*531 - - ## - # test values -@@ -773,15 +773,6 @@ EOXML - - my $newkid = $root->appendChild( $doc->createElement( "bar" ) ); - is( $newkid->line_number(), 0, "line number is 0"); -- -- $parser->line_numbers(0); -- eval { $doc = $parser->parse_string( $goodxml ); }; -- -- $root = $doc->documentElement(); -- is( $root->line_number(), 0, "line number is 0"); -- -- @kids = $root->childNodes(); -- is( $kids[1]->line_number(), 0, "line number is 0"); - } - - SKIP: { diff --git a/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch b/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch index 06207a8b7334..31b21f5cb768 100644 --- a/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch +++ b/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch @@ -1,36 +1,19 @@ Send an ETag header, and honour the If-None-Match request header -diff -ru -x '*~' Catalyst-Plugin-Static-Simple-0.30-orig/lib/Catalyst/Plugin/Static/Simple.pm Catalyst-Plugin-Static-Simple-0.30/lib/Catalyst/Plugin/Static/Simple.pm ---- Catalyst-Plugin-Static-Simple-0.30-orig/lib/Catalyst/Plugin/Static/Simple.pm 2012-05-04 18:49:30.000000000 +0200 -+++ Catalyst-Plugin-Static-Simple-0.30/lib/Catalyst/Plugin/Static/Simple.pm 2013-02-25 22:57:18.667150181 +0100 -@@ -187,16 +187,27 @@ - my $type = $c->_ext_to_type( $full_path ); - my $stat = stat $full_path; +--- a/lib/Catalyst/Plugin/Static/Simple.pm ++++ b/lib/Catalyst/Plugin/Static/Simple.pm +@@ -223,6 +223,15 @@ -- $c->res->headers->content_type( $type ); -- $c->res->headers->content_length( $stat->size ); -- $c->res->headers->last_modified( $stat->mtime ); - # Tell Firefox & friends its OK to cache, even over SSL: -- $c->res->headers->header('Cache-control' => 'public'); -+ #$c->res->headers->header('Cache-control' => 'public'); -+ -+ $c->res->headers->last_modified( $stat->mtime ); - # Optionally, set a fixed expiry time: - if ($config->{expires}) { - $c->res->headers->expires(time() + $config->{expires}); - } + $c->res->headers->header('Cache-Control' => $cache_control); + if ($config->{send_etag}) { -+ my $etag = '"' . $stat->mtime . '-' . $stat->ino . '-'. $stat->size . '"'; ++ my $etag = '"' . $stat->mtime . '-' . $stat->ino . '-' . $stat->size . '"'; + $c->res->headers->header('ETag' => $etag); + if (($c->req->header('If-None-Match') // "") eq $etag) { + $c->res->status(304); + return 1; + } + } -+ -+ $c->res->headers->content_type( $type ); -+ $c->res->headers->content_length( $stat->size ); + my $fh = IO::File->new( $full_path, 'r' ); if ( defined $fh ) { diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 3ed61420168d..9ae74d3ab59d 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -116,11 +116,11 @@ with self; ack = buildPerlPackage rec { pname = "ack"; - version = "3.9.0"; + version = "3.10.0"; src = fetchurl { url = "mirror://cpan/authors/id/P/PE/PETDANCE/ack-v${version}.tar.gz"; - hash = "sha256-lO1Hfjs/lNEmzscynw6DmfHQzoLHxNiCqUrbFQ5//JA="; + hash = "sha256-Zeg8+zinH8pyXpoUqCAe6HHmKfxrECMeEwPdNQG6Vjo="; }; outputs = [ @@ -3352,18 +3352,11 @@ with self; CatalystAuthenticationCredentialHTTP = buildPerlModule { pname = "Catalyst-Authentication-Credential-HTTP"; - version = "1.018"; + version = "1.019"; src = fetchurl { - url = "mirror://cpan/authors/id/E/ET/ETHER/Catalyst-Authentication-Credential-HTTP-1.018.tar.gz"; - hash = "sha256-b6GBbe5kSw216gzBXF5xHcLO0gg2JavOcJZSHx1lpSk="; + url = "mirror://cpan/authors/id/A/AB/ABRAXXA/Catalyst-Authentication-Credential-HTTP-1.019.tar.gz"; + hash = "sha256-7IHpbCo/ZYbqQdCI6o6AGx80ABqxnMmmXe+KOMOaW9o="; }; - patches = [ - (fetchpatch { - name = "CVE-2025-40920.patch"; - url = "https://github.com/perl-catalyst/Catalyst-Authentication-Credential-HTTP/commit/ad2c03aad95406db4ce35dfb670664ebde004c18.patch"; - hash = "sha256-WI6JwvY6i3KkQO9HbbSvHPX8mgM8I2cF0UTjF1D14T4="; - }) - ]; buildInputs = [ ModuleBuildTiny TestException @@ -3374,7 +3367,6 @@ with self; CatalystPluginAuthentication ClassAccessor CryptSysRandom - DataUUID StringEscape ]; meta = { @@ -4116,12 +4108,19 @@ with self; CatalystPluginStaticSimple = buildPerlPackage { pname = "Catalyst-Plugin-Static-Simple"; - version = "0.37"; + version = "0.38"; src = fetchurl { - url = "mirror://cpan/authors/id/I/IL/ILMARI/Catalyst-Plugin-Static-Simple-0.37.tar.gz"; - hash = "sha256-Wk2Fo1iM1Og/GwAlgUEufXG31X9mBW5dh6Nvk9icnnw="; + url = "mirror://cpan/authors/id/E/ET/ETHER/Catalyst-Plugin-Static-Simple-0.38.tar.gz"; + hash = "sha256-BOtn69x4cyf3fvLHOXar7Pk/mu/KCnGFIv6YuMpSOLA="; }; - patches = [ ../development/perl-modules/catalyst-plugin-static-simple-etag.patch ]; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch"; + hash = "sha256-dNJOz7X7i03kisrf+lhqAaL6lYeTlt1NJZnJWNM7bgQ="; + }) + ../development/perl-modules/catalyst-plugin-static-simple-etag.patch + ]; + postPatch = "rm -f lib/Catalyst/Plugin/Static/Simple.pm.orig"; propagatedBuildInputs = [ CatalystRuntime MIMETypes @@ -4627,12 +4626,15 @@ with self; CGISession = buildPerlModule { pname = "CGI-Session"; - version = "4.48"; + version = "4.49"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MA/MARKSTOS/CGI-Session-4.48.tar.gz"; - hash = "sha256-RnVkYcJM52ZrgQjduW26thJpnfMBLIDvEQFmGf4VVPc="; + url = "mirror://cpan/authors/id/M/MA/MARKSTOS/CGI-Session-4.49.tar.gz"; + hash = "sha256-X9iKgwo19UUmeH8DauXkp9FLYcQUzSmthjG/RuaXEgc="; }; - propagatedBuildInputs = [ CGI ]; + propagatedBuildInputs = [ + CGI + CryptSysRandom + ]; meta = { description = "Persistent session data in CGI applications"; license = with lib.licenses; [ artistic1 ]; @@ -5092,6 +5094,22 @@ with self; }; }; + ClassErrorHandler = buildPerlPackage { + pname = "Class-ErrorHandler"; + version = "0.04"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TO/TOKUHIROM/Class-ErrorHandler-0.04.tar.gz"; + hash = "sha256-NC0tz8eXogvugXmxuWuFwK56W0iCc1lSPNjHTD5wRQI="; + }; + meta = { + description = "Base class for error handling"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ClassInspector = buildPerlPackage { pname = "Class-Inspector"; version = "1.36"; @@ -6045,10 +6063,10 @@ with self; ConfigIniFiles = buildPerlPackage { pname = "Config-IniFiles"; - version = "3.000003"; + version = "3.002000"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SH/SHLOMIF/Config-IniFiles-3.000003.tar.gz"; - hash = "sha256-PEV7ZdmOX/QL25z4FLDVmD6wxT+4aWvaO6A1rSrNaAI="; + url = "mirror://cpan/authors/id/S/SH/SHLOMIF/Config-IniFiles-3.002000.tar.gz"; + hash = "sha256-Bmke17QZl+hQxOfGs05cOWFF4M0FCvGUSiDQaMOlpAs="; }; propagatedBuildInputs = [ IOStringy ]; meta = { @@ -6397,6 +6415,29 @@ with self; }; }; + ConvertPEM = buildPerlPackage { + pname = "Convert-PEM"; + version = "0.13"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Convert-PEM-0.13.tar.gz"; + hash = "sha256-eZ+jLCcAgfTmKSsN31GAlScQqKS+Ey6Qe9oxdqe9HCM="; + }; + buildInputs = [ TestException ]; + propagatedBuildInputs = [ + ClassErrorHandler + ConvertASN1 + CryptDESEDE3 + CryptX + ]; + meta = { + description = "Read/write encrypted ASN.1 PEM files"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ConvertUU = buildPerlPackage { pname = "Convert-UU"; version = "0.5201"; @@ -6480,10 +6521,10 @@ with self; CookieBaker = buildPerlModule { pname = "Cookie-Baker"; - version = "0.11"; + version = "0.12"; src = fetchurl { - url = "mirror://cpan/authors/id/K/KA/KAZEBURO/Cookie-Baker-0.11.tar.gz"; - hash = "sha256-WSdfR04HwKo2EePmhLiU59uRMzPYIUQgvmPxLsGM16s="; + url = "mirror://cpan/authors/id/K/KA/KAZEBURO/Cookie-Baker-0.12.tar.gz"; + hash = "sha256-mwTfXUfc1FrEKZYmoQ7JkPtAyU7lpjAMOoi9+zV17Ck="; }; buildInputs = [ ModuleBuildTiny @@ -6691,12 +6732,11 @@ with self; CpanelJSONXS = buildPerlPackage { pname = "Cpanel-JSON-XS"; - version = "4.37"; + version = "4.42"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RURBAN/Cpanel-JSON-XS-4.37.tar.gz"; - hash = "sha256-wkFhWg4X/3Raqoa79Gam4pzSQFFeZfBqegUBe2GebUs="; + url = "mirror://cpan/authors/id/R/RU/RURBAN/Cpanel-JSON-XS-4.42.tar.gz"; + hash = "sha256-4awvqx46bS2ZjTRAxgAGc2W9x9vwyPKyBZy85LTIMXM="; }; - patches = [ ../development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch ]; meta = { description = "CPanel fork of JSON::XS, fast and correct serializing"; license = with lib.licenses; [ @@ -6890,13 +6930,15 @@ with self; CryptArgon2 = buildPerlModule { pname = "Crypt-Argon2"; - version = "0.019"; + version = "0.031"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/Crypt-Argon2-0.019.tar.gz"; - hash = "sha256-+Fm+6NL2tAf11EZFwiOu4hL+AFkd/YLlBlrhvnio5Dg="; + url = "mirror://cpan/authors/id/L/LE/LEONT/Crypt-Argon2-0.031.tar.gz"; + hash = "sha256-1l5RoZQ+6AglEkUNw1KuUpUQZswJI/u38uYK+l8WTi0="; }; nativeBuildInputs = [ pkgs.ld-is-cc-hook ]; + buildInputs = [ DistBuild ]; meta = { + changelog = "https://github.com/Leont/crypt-argon2/blob/v0.031/Changes"; description = "Perl interface to the Argon2 key derivation functions"; license = with lib.licenses; [ cc0 ]; }; @@ -6950,11 +6992,16 @@ with self; CryptCBC = buildPerlPackage { pname = "Crypt-CBC"; - version = "2.33"; + version = "3.07"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LD/LDS/Crypt-CBC-2.33.tar.gz"; - hash = "sha256-anDeIbbMfysQAGfo4Yjblm6agAG122+pdufLWylK5kU="; + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-CBC-3.07.tar.gz"; + hash = "sha256-9N37TdasUBPfg0G/pzTZye4PEOLnEhXsj+W/eAt8kSc="; }; + propagatedBuildInputs = [ + CryptPBKDF2 + CryptURandom + CryptX + ]; meta = { description = "Encrypt Data with Cipher Block Chaining Mode"; license = with lib.licenses; [ @@ -7017,6 +7064,23 @@ with self; }; }; + CryptDESEDE3 = buildPerlPackage { + pname = "Crypt-DES_EDE3"; + version = "0.03"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DES_EDE3-0.03.tar.gz"; + hash = "sha256-KFktt7njR0WqkfPhnl27uDqvRyop5we5eR0NArPiJ/U="; + }; + propagatedBuildInputs = [ CryptDES ]; + meta = { + description = "Triple-DES EDE encryption/decryption"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + CryptDH = buildPerlPackage { pname = "Crypt-DH"; version = "0.07"; @@ -7059,14 +7123,16 @@ with self; CryptDSA = buildPerlPackage { pname = "Crypt-DSA"; - version = "1.17"; + version = "1.24"; src = fetchurl { - url = "mirror://cpan/authors/id/A/AD/ADAMK/Crypt-DSA-1.17.tar.gz"; - hash = "sha256-0bhYX2v3RvduXcXaNkHTJe1la8Ll80S1RRS1XDEAmgM="; + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DSA-1.24.tar.gz"; + hash = "sha256-ChY4tvK07+ktbuL0kBzKAtenBWf2uw9Iapu19pvnZ2Y="; }; propagatedBuildInputs = [ + ConvertASN1 + ConvertPEM + CryptSysRandom DataBuffer - DigestSHA1 FileWhich ]; meta = { @@ -7260,11 +7326,12 @@ with self; CryptPasswdMD5 = buildPerlPackage { pname = "Crypt-PasswdMD5"; - version = "1.42"; + version = "1.43"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RS/RSAVAGE/Crypt-PasswdMD5-1.42.tgz"; - hash = "sha256-/Tlubn9E7rkj6TyZOUC49nqa7Vb8dKrK8Dj8QFPvO1k="; + url = "mirror://cpan/authors/id/R/RS/RSAVAGE/Crypt-PasswdMD5-1.43.tgz"; + hash = "sha256-Qr+Sk0UQlYXUlWkCVX7ONdBh7aQ454lPhucHV0EoB1k="; }; + propagatedBuildInputs = [ CryptURandom ]; meta = { description = "Provide interoperable MD5-based crypt() functions"; license = with lib.licenses; [ @@ -7495,14 +7562,32 @@ with self; }; }; + CryptURandomMonkeyPatch = buildPerlPackage { + pname = "Crypt-URandom-MonkeyPatch"; + version = "0.1.4"; + src = fetchurl { + url = "mirror://cpan/authors/id/R/RR/RRWO/Crypt-URandom-MonkeyPatch-v0.1.4.tar.gz"; + hash = "sha256-eydufcxL7TnZW/+dnTemlTkycVaPTarMrFBowLQcKsk="; + }; + buildInputs = [ TestOutput ]; + propagatedBuildInputs = [ CryptURandom ]; + meta = { + description = "Override core rand function to use system random sources"; + license = lib.licenses.artistic2; + }; + }; + CryptScryptKDF = buildPerlModule { pname = "Crypt-ScryptKDF"; - version = "0.010"; + version = "0.011"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MI/MIK/Crypt-ScryptKDF-0.010.tar.gz"; - hash = "sha256-fRbulczj61TBdGc6cpn0wIb7o6yF+EfQ4TT+7V93YBc="; + url = "mirror://cpan/authors/id/M/MI/MIK/Crypt-ScryptKDF-0.011.tar.gz"; + hash = "sha256-IZLJ8E8rX/cHN/XNrz9PZ6VXE8MeoIVAOMvzXjttFrQ="; }; - propagatedBuildInputs = [ CryptOpenSSLRandom ]; + propagatedBuildInputs = [ + CryptOpenSSLRandom + CryptX + ]; meta = { description = "Scrypt password based key derivation function"; homepage = "https://github.com/DCIT/perl-Crypt-ScryptKDF"; @@ -7748,15 +7833,19 @@ with self; }; }; - CryptPBKDF2 = buildPerlPackage { + CryptPBKDF2 = buildPerlModule { pname = "Crypt-PBKDF2"; - version = "0.161520"; + version = "0.261630"; src = fetchurl { - url = "mirror://cpan/authors/id/A/AR/ARODLAND/Crypt-PBKDF2-0.161520.tar.gz"; - hash = "sha256-l9+nmjCaCG4YSk5hBH+KEP+z2wUQJefSIqJfGRMLpBc="; + url = "mirror://cpan/authors/id/A/AR/ARODLAND/Crypt-PBKDF2-0.261630.tar.gz"; + hash = "sha256-GHVxiWOJMrMJs0xFu4EKo+SFbj7VgBAAF9reZXk/RsA="; }; - buildInputs = [ TestFatal ]; + buildInputs = [ + ModuleBuildTiny + TestFatal + ]; propagatedBuildInputs = [ + CryptURandom DigestHMAC DigestSHA3 Moo @@ -7896,10 +7985,10 @@ with self; CSSMinifierXS = buildPerlPackage { pname = "CSS-Minifier-XS"; - version = "0.13"; + version = "0.15"; src = fetchurl { - url = "mirror://cpan/authors/id/G/GT/GTERMARS/CSS-Minifier-XS-0.13.tar.gz"; - hash = "sha256-xBnjCM3IKvHCXWuNB7L/JjR6Yit6Y+wghWq+jbQFH4I="; + url = "mirror://cpan/authors/id/G/GT/GTERMARS/CSS-Minifier-XS-0.15.tar.gz"; + hash = "sha256-iprSIxYtpGceP4EsSlXyl3OUg70xar2kH0wn6K3XhVM="; }; buildInputs = [ TestDiagINC ]; meta = { @@ -8157,16 +8246,16 @@ with self; DataEntropy = buildPerlPackage { pname = "Data-Entropy"; - version = "0.008"; + version = "0.010"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RR/RRWO/Data-Entropy-0.008.tar.gz"; - hash = "sha256-GKUrE4boLGuM2zhKOYYdYCIKRCp5DgdwEL5y3YU7Z7M="; + url = "mirror://cpan/authors/id/R/RR/RRWO/Data-Entropy-0.010.tar.gz"; + hash = "sha256-0M8s2wKCAuidw2K42Qtw00WFApOwGQDZoYgqDG8g+Dc="; }; propagatedBuildInputs = [ CryptRijndael CryptURandom DataFloat - HTTPLite + DevelDeprecate ParamsClassify ]; meta = { @@ -9604,6 +9693,24 @@ with self; }; }; + DevelDeprecate = buildPerlPackage { + pname = "Devel-Deprecate"; + version = "0.01"; + src = fetchurl { + url = "mirror://cpan/authors/id/O/OV/OVID/Devel-Deprecate-0.01.tar.gz"; + hash = "sha256-xQLEGoL+JU6XFRJ3ytOk8KQHrTydP2I9J3sDA6PhoS8="; + }; + buildInputs = [ SubOverride ]; + propagatedBuildInputs = [ DateTime ]; + meta = { + description = "Create deprecation schedules in your code"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + DevelDeprecationsEnvironmental = buildPerlPackage { pname = "Devel-Deprecations-Environmental"; version = "1.101"; @@ -10044,11 +10151,11 @@ with self; DBI = buildPerlPackage { pname = "DBI"; - version = "1.648"; + version = "1.653"; src = fetchurl { - url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.648.tgz"; - hash = "sha256-7yZqrWAQzi6rt+Rl69c8owILxYFQ9pib2Jwrj5usaoY="; + url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.653.tgz"; + hash = "sha256-qYwh/Tfu2PhBFyh10XXZcv6H8GPX0NKjt3ZZCLsl61g="; }; env = lib.optionalAttrs stdenv.cc.isGNU { @@ -11036,6 +11143,31 @@ with self; }; }; + DistBuild = buildPerlModule { + pname = "Dist-Build"; + version = "0.028"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/Dist-Build-0.028.tar.gz"; + hash = "sha256-JPFLFA4Tq3x1PU25bI0zbQnepcb1H+1IvA92Khyhgx8="; + }; + propagatedBuildInputs = [ + ExtUtilsBuilder + ExtUtilsBuilderCompiler + ExtUtilsConfig + ExtUtilsHelpers + ExtUtilsInstallPaths + ]; + meta = { + changelog = "https://github.com/Leont/dist-build/blob/v0.028/Changes"; + description = "Modern module builder, author tools not included"; + homepage = "https://github.com/Leont/dist-build"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + DistributionMetadata = buildPerlModule { pname = "Distribution-Metadata"; version = "0.10"; @@ -12584,6 +12716,48 @@ with self; }; }; + ExtUtilsBuilder = buildPerlPackage { + pname = "ExtUtils-Builder"; + version = "0.020"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Builder-0.020.tar.gz"; + hash = "sha256-UtZR46oDJyUOR5h9Rf9I6cyQtbe9L7D/P3h4PlMq/8w="; + }; + propagatedBuildInputs = [ + ExtUtilsConfig + ExtUtilsHelpers + ]; + meta = { + description = "Abstract representation of build processes"; + homepage = "https://github.com/Leont/extutils-builder-plan"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + + ExtUtilsBuilderCompiler = buildPerlPackage { + pname = "ExtUtils-Builder-Compiler"; + version = "0.037"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Builder-Compiler-0.037.tar.gz"; + hash = "sha256-s5VNaI45gDkoUnkWfG6+7nVX8Q6VYBzj/baBkyY2h7g="; + }; + propagatedBuildInputs = [ + ExtUtilsBuilder + ExtUtilsConfig + ]; + meta = { + description = "Interface around different compilers"; + homepage = "https://github.com/Leont/extutils-builder-compiler"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ExtUtilsCChecker = buildPerlModule { pname = "ExtUtils-CChecker"; version = "0.11"; @@ -12603,10 +12777,10 @@ with self; ExtUtilsConfig = buildPerlPackage { pname = "ExtUtils-Config"; - version = "0.008"; + version = "0.010"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Config-0.008.tar.gz"; - hash = "sha256-rlEE9jRlDc6KebftE/tZ1no5whOmd2z9qj7nSeYvGow="; + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Config-0.010.tar.gz"; + hash = "sha256-gufk6Qy+OA4VL13m4+QDdGmC1QLdMBl6EjZS5GYQxm0="; }; meta = { description = "Wrapper for perl's configuration"; @@ -12694,10 +12868,10 @@ with self; ExtUtilsHelpers = buildPerlPackage { pname = "ExtUtils-Helpers"; - version = "0.026"; + version = "0.028"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Helpers-0.026.tar.gz"; - hash = "sha256-3pAbZ5CkVXz07JCBSeA1eDsSW/EV65ZA/rG8HCTDNBY="; + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Helpers-0.028.tar.gz"; + hash = "sha256-yFdIdczgc+fcU0WnsG1QLlIETWiJT5FgID/KqzeVFP4="; }; meta = { description = "Various portability utilities for module builders"; @@ -13478,14 +13652,11 @@ with self; FileFindRule = buildPerlPackage { pname = "File-Find-Rule"; - version = "0.34"; + version = "0.35"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RC/RCLAMP/File-Find-Rule-0.34.tar.gz"; - hash = "sha256-fm8WzDPrHyn/Jb7lHVE/S4qElHu/oY7bLTzECi1kyv4="; + url = "mirror://cpan/authors/id/R/RC/RCLAMP/File-Find-Rule-0.35.tar.gz"; + hash = "sha256-K9VWKJptRK0u50gDJYuwsAUNJG8egcqrCyY8MDrPDII="; }; - patches = [ - ../development/perl-modules/FileFindRule-CVE-2011-10007.patch - ]; propagatedBuildInputs = [ NumberCompare TextGlob @@ -14667,10 +14838,10 @@ with self; GD = buildPerlPackage { pname = "GD"; - version = "2.78"; + version = "2.86"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RURBAN/GD-2.78.tar.gz"; - hash = "sha256-aDEFS/VCS09cI9NifT0UhEgPb5wsZmMiIpFfKFG+buQ="; + url = "mirror://cpan/authors/id/R/RU/RURBAN/GD-2.86.tar.gz"; + hash = "sha256-bWTTvhQpzB606IqPICL+yRDqPgeS2k/ljT7fdpXEbKI="; }; nativeBuildInputs = [ @@ -14685,6 +14856,7 @@ with self; pkgs.fontconfig pkgs.libxpm ExtUtilsPkgConfig + FileWhich TestFork TestNoWarnings ]; @@ -14739,7 +14911,16 @@ with self; url = "mirror://cpan/authors/id/B/BU/BURAK/GD-SecurityImage-1.75.tar.gz"; hash = "sha256-Pd4k2ay6lRzd5bVp0eQsrZRs/bUSgORGnzNv1f4MjqY="; }; - propagatedBuildInputs = [ GD ]; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/G/GD-SecurityImage/1.75/CVE-2026-13082-r1.patch"; + hash = "sha256-xIMPQD2JYuHdsYnW1ojqG3xgV7VWEKyJ6sEqNRUdNdQ="; + }) + ]; + propagatedBuildInputs = [ + CryptURandomMonkeyPatch + GD + ]; meta = { description = "Security image (captcha) generator"; license = with lib.licenses; [ @@ -16139,6 +16320,12 @@ with self; url = "mirror://cpan/authors/id/C/CF/CFRANKS/HTML-FormFu-2.07.tar.gz"; hash = "sha256-Ty8Bf3qHVPu26RIGyI7RPHVqFOO+oXgYjDuXdGNm6zI="; }; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/H/HTML-FormFu/2.08/CVE-2026-19873-r1.patch"; + hash = "sha256-1QquxDl/NuNJe6MFbeEH49hYA8agXXeWm1Q23fOM+Nc="; + }) + ]; buildInputs = [ CGI FileShareDirInstall @@ -16200,19 +16387,18 @@ with self; HTMLFormHandler = buildPerlPackage { pname = "HTML-FormHandler"; - version = "0.40068"; + version = "0.410002"; src = fetchurl { - url = "mirror://cpan/authors/id/G/GS/GSHANK/HTML-FormHandler-0.40068.tar.gz"; - hash = "sha256-63t43aMSV1LMi8wDltOXf70o2jPS1ExQQq1tNdbN6Cc="; + url = "mirror://cpan/authors/id/A/AB/ABRAXXA/HTML-FormHandler-0.410002.tar.gz"; + hash = "sha256-wT3n5PLDmV5QR1xilSm2VM+eLGJ73WLifqSMfG1jqeU="; }; - # a single test is failing on perl 5.20 - doCheck = false; buildInputs = [ FileShareDirInstall PadWalker TestDifferences TestException TestMemoryCycle + TestNeeds TestWarn ]; propagatedBuildInputs = [ @@ -16239,10 +16425,10 @@ with self; HTMLGumbo = buildPerlModule { pname = "HTML-Gumbo"; - version = "0.18"; + version = "0.20"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RUZ/HTML-Gumbo-0.18.tar.gz"; - hash = "sha256-v1C2HCRlbMP8lYYC2AqcfQFyR6842Nv6Dp3sW3VCXV8="; + url = "mirror://cpan/authors/id/B/BP/BPS/HTML-Gumbo-0.20.tar.gz"; + hash = "sha256-ImEK+8bIfgZ92E9/EZo9J4Ie1kEwNFU8Ga694iEdiDU="; }; propagatedBuildInputs = [ AlienLibGumbo ]; meta = { @@ -16303,10 +16489,10 @@ with self; HTMLParser = buildPerlPackage { pname = "HTML-Parser"; - version = "3.81"; + version = "3.85"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTML-Parser-3.81.tar.gz"; - hash = "sha256-wJEKXI+S+IF+3QbM/SJLocLr6MEPVR8DJYeh/IPWL/I="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTML-Parser-3.85.tar.gz"; + hash = "sha256-/UK6ar4HJBzwrVe+JGw5gAZfaD5EZeWbRq+e/ryODHE="; }; propagatedBuildInputs = [ HTMLTagset @@ -16771,10 +16957,10 @@ with self; HTTPDate = buildPerlPackage { pname = "HTTP-Date"; - version = "6.06"; + version = "6.08"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Date-6.06.tar.gz"; - hash = "sha256-e2hRkcasw+dz0fwCyV7h+frpT3d4MXX154wYHMktK1I="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Date-6.08.tar.gz"; + hash = "sha256-tX2Aym2CHGlJykiydGfUWrp6nHc0ZWIwb6zKeBoAPkQ="; }; propagatedBuildInputs = [ TimeDate ]; meta = { @@ -16901,10 +17087,10 @@ with self; HTTPMessage = buildPerlPackage { pname = "HTTP-Message"; - version = "6.45"; + version = "7.02"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Message-6.45.tar.gz"; - hash = "sha256-AcuEBmEqP3OIQtHpcxOuTYdIcNG41tZjMfFgAJQ9TL4="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Message-7.02.tar.gz"; + hash = "sha256-eKvvHYMxRrSNF9shmxsD1Ty743oozNrQ79zFgzylxgw="; }; buildInputs = [ TestNeeds @@ -16912,8 +17098,11 @@ with self; ]; propagatedBuildInputs = [ Clone + CompressRawBzip2 + CompressRawZlib EncodeLocale HTTPDate + IOCompress IOHTML LWPMediaTypes URI @@ -17198,26 +17387,11 @@ with self; Imager = buildPerlPackage rec { pname = "Imager"; - version = "1.034"; + version = "1.035"; src = fetchurl { url = "mirror://cpan/authors/id/T/TO/TONYC/Imager-${version}.tar.gz"; - hash = "sha256-hrWizXGna4QJJJFSGl1WI4Qo8sN1AYMsmVxaMxJg+AM="; + hash = "sha256-W6BYrMmLtb+QK6/XTNKwepS7GVrmYWxEC1RwFIBv6xc="; }; - # Remove when updating to the first release containing both fixes. - patches = [ - (fetchpatch2 { - name = "fix-32-bit-exif-ifd-offset-checks.patch"; - url = "https://github.com/tonycoz/imager/commit/48ba8ac0749f89466b6e6681fb88cbdb51086ebd.patch?full_index=1"; - includes = [ "imexif.c" ]; - hash = "sha256-rpUeTsgSkCdzJsy3Ny0rU+KNL6xkSosfkDqzFb813Wo="; - }) - (fetchpatch2 { - name = "fix-32-bit-exif-limit-checks.patch"; - url = "https://github.com/tonycoz/imager/commit/6f1fd003a8e48c7e6e58b7019a04cc71bbfec2c3.patch?full_index=1"; - includes = [ "imexif.c" ]; - hash = "sha256-Ct7T/JHuxAIAjjuzoUhdAPlp0qPYKRQQqejsrcGXPko="; - }) - ]; buildInputs = [ pkgs.freetype pkgs.fontconfig @@ -17579,10 +17753,10 @@ with self; IOCompress = buildPerlPackage { pname = "IO-Compress"; - version = "2.220"; + version = "2.221"; src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz"; - hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic="; + url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.221.tar.gz"; + hash = "sha256-r0LJyRBK3313LSVcDZpASjRi6kXnvELQbaCgtR3j0K4="; }; propagatedBuildInputs = [ CompressRawBzip2 @@ -18504,12 +18678,11 @@ with self; JSONXS = buildPerlPackage { pname = "JSON-XS"; - version = "4.03"; + version = "4.04"; src = fetchurl { - url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.03.tar.gz"; - hash = "sha256-UVU29F8voafojIgkUzdY0BIdJnq5y0U6G1iHyKVrkGg="; + url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.04.tar.gz"; + hash = "sha256-jv8enzBMViW1mre0IlhBX20+NoHB3atrclUYoBin9eA="; }; - patches = [ ../development/perl-modules/JSON-XS-CVE-2025-40928.patch ]; propagatedBuildInputs = [ TypesSerialiser ]; buildInputs = [ CanaryStability ]; meta = { @@ -18817,10 +18990,10 @@ with self; libwwwperl = buildPerlPackage { pname = "libwww-perl"; - version = "6.72"; + version = "6.83"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.72.tar.gz"; - hash = "sha256-6bg1T9XiC+IHr+I93VhPzVm/gpmNwHfez2hLodrloF0="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.83.tar.gz"; + hash = "sha256-518PqdPG8Nr1pacvqfixycDSPjqEqFIsy0+DUjK5VQU="; }; buildInputs = [ HTTPDaemon @@ -20074,10 +20247,10 @@ with self; LWP = buildPerlPackage { pname = "libwww-perl"; - version = "6.72"; + version = "6.83"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.72.tar.gz"; - hash = "sha256-6bg1T9XiC+IHr+I93VhPzVm/gpmNwHfez2hLodrloF0="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.83.tar.gz"; + hash = "sha256-518PqdPG8Nr1pacvqfixycDSPjqEqFIsy0+DUjK5VQU="; }; propagatedBuildInputs = [ FileListing @@ -22705,10 +22878,10 @@ with self; Mojolicious = buildPerlPackage { pname = "Mojolicious"; - version = "9.39"; + version = "9.48"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.39.tar.gz"; - hash = "sha256-EwpJDXfXYTn3NM4biU1Fm64DgF+x89/dWPxE/oKvPP0="; + url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.48.tar.gz"; + hash = "sha256-Jv8EFSgR/VsaNrR9mewhnFiZW6jnsVugKzPQdwpe7pg="; }; meta = { description = "Real-time web framework"; @@ -23070,13 +23243,16 @@ with self; MojoJWT = buildPerlModule { pname = "Mojo-JWT"; - version = "0.09"; + version = "1.02"; src = fetchurl { - url = "mirror://cpan/authors/id/J/JB/JBERGER/Mojo-JWT-0.09.tar.gz"; - hash = "sha256-wE4DmD4MbyvORdCOoucph5yWee+mNLDmjLa4t7SoWIY="; + url = "mirror://cpan/authors/id/J/JB/JBERGER/Mojo-JWT-1.02.tar.gz"; + hash = "sha256-yBHXkoWMJBFQNyDxJDbjNDZ0k2dUO/vCqV1PgDzmCHQ="; }; buildInputs = [ ModuleBuildTiny ]; - propagatedBuildInputs = [ Mojolicious ]; + propagatedBuildInputs = [ + CryptX + Mojolicious + ]; meta = { description = "JSON Web Token the Mojo way"; homepage = "https://github.com/jberger/Mojo-JWT"; @@ -25529,10 +25705,10 @@ with self; NetDNS = buildPerlPackage { pname = "Net-DNS"; - version = "1.56"; + version = "1.57"; src = fetchurl { - url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.56.tar.gz"; - hash = "sha256-WTDjn3aJWzgMfKEfwINS0VrXHEH+hMEt+2oyLRf2aUY="; + url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.57.tar.gz"; + hash = "sha256-fJjeMpy11qmau7A6qtKGbLBBCS7Zk2pyRpCOFwAFsFg="; }; propagatedBuildInputs = [ DigestHMAC ]; makeMakerFlags = [ "--noonline-tests" ]; @@ -26404,10 +26580,10 @@ with self; NetStatsd = buildPerlPackage { pname = "Net-Statsd"; - version = "0.12"; + version = "0.13"; src = fetchurl { - url = "mirror://cpan/authors/id/C/CO/COSIMO/Net-Statsd-0.12.tar.gz"; - hash = "sha256-Y+RTYD2hZbxtHEygtV7aPSIE8EDFkwSkd4LFqniGVlw="; + url = "mirror://cpan/authors/id/C/CO/COSIMO/Net-Statsd-0.13.tar.gz"; + hash = "sha256-xKYP9dP002ompqR3YxGI7HnNzp4wUMZ6NOm1rikgoQA="; }; meta = { description = "Perl client for Etsy's statsd daemon"; @@ -28577,12 +28753,13 @@ with self; PlackMiddlewareSession = buildPerlModule { pname = "Plack-Middleware-Session"; - version = "0.33"; + version = "0.36"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MI/MIYAGAWA/Plack-Middleware-Session-0.33.tar.gz"; - hash = "sha256-T/miydGK2ASbRd/ze5vdQSIeLC8eFrr7gb/tyIxRpO4="; + url = "mirror://cpan/authors/id/M/MI/MIYAGAWA/Plack-Middleware-Session-0.36.tar.gz"; + hash = "sha256-kqWDFliBDSNzLm47rnpEofpafYpqbm3NdbkcapwktGY="; }; propagatedBuildInputs = [ + CryptSysRandom DigestHMAC Plack ]; @@ -29137,10 +29314,10 @@ with self; ProtocolHTTP2 = buildPerlModule { pname = "Protocol-HTTP2"; - version = "1.11"; + version = "1.14"; src = fetchurl { - url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.11.tar.gz"; - hash = "sha256-Vp8Fsavpl7UHyCUVMMyB0e6WvZMsxoJTS2zkhlNQCRM="; + url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.14.tar.gz"; + hash = "sha256-pT8n6i+6wVakzUmB2O90nBvvNmwpCRNLTTHaIWRLSW4="; }; buildInputs = [ AnyEvent @@ -30581,10 +30758,10 @@ with self; SerealDecoder = buildPerlPackage { pname = "Sereal-Decoder"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Decoder-5.004.tar.gz"; - hash = "sha256-aO8DFNh9Gm5guw9m/PQ+ssrN6xdUQy9eJeeE450+Z4Q="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Decoder-5.006.tar.gz"; + hash = "sha256-eZGFXpGBo3nJsBIv6PwvaONEnJFhaow1eSbxFh9oR2g="; }; buildInputs = [ TestDeep @@ -30606,10 +30783,10 @@ with self; SerealEncoder = buildPerlPackage { pname = "Sereal-Encoder"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Encoder-5.004.tar.gz"; - hash = "sha256-XlqGzNMtrjTtgJMuy+XGjil1K13g6bCnk6t+sspVyxs="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Encoder-5.006.tar.gz"; + hash = "sha256-kLQsyHdZgq4MdJno9ZLOeu+ug0M1g+EKWtVxKBHRcK0="; }; buildInputs = [ SerealDecoder @@ -30631,10 +30808,10 @@ with self; Sereal = buildPerlPackage { pname = "Sereal"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-5.004.tar.gz"; - hash = "sha256-nCW7euS9c20ksa0dk9dzlbDGXKh0HiZr/Ay+VCJh128="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-5.006.tar.gz"; + hash = "sha256-uwXnY+1ry+pEx5IX/vCy05GKwVRxlHIwOMbER+5vWd4="; }; buildInputs = [ TestDeep @@ -31408,10 +31585,10 @@ with self; Starlet = buildPerlPackage { pname = "Starlet"; - version = "0.31"; + version = "0.32"; src = fetchurl { - url = "mirror://cpan/authors/id/K/KA/KAZUHO/Starlet-0.31.tar.gz"; - hash = "sha256-uWA7jmKIDLRYL2p5Oer+xl5u/T2QDyx900Ll9MaNYtg="; + url = "mirror://cpan/authors/id/K/KA/KAZUHO/Starlet-0.32.tar.gz"; + hash = "sha256-gZI9OmCX3YHH4Og9SBvuof89ZejgHY0f59yziFV1vY8="; }; buildInputs = [ LWP @@ -32032,14 +32209,13 @@ with self; }; }; - StringUtil = buildPerlModule { + StringUtil = buildPerlPackage { pname = "String-Util"; - version = "1.34"; + version = "1.36"; src = fetchurl { - url = "mirror://cpan/authors/id/B/BA/BAKERSCOT/String-Util-1.34.tar.gz"; - hash = "sha256-MZzozWZTQeVlIfoVXZYqGTKOkNn3A2dlklzN4mclxGk="; + url = "mirror://cpan/authors/id/B/BA/BAKERSCOT/String-Util-1.36.tar.gz"; + hash = "sha256-UXsasyVm/U1ei+I9mTOc47/+4pEsX/KfXclYcP9Pyw4="; }; - buildInputs = [ ModuleBuildTiny ]; meta = { description = "String processing utility functions"; homepage = "https://github.com/scottchiefbaker/String-Util"; @@ -38792,10 +38968,10 @@ with self; XMLLibXML = buildPerlPackage { pname = "XML-LibXML"; - version = "2.0210"; + version = "2.0213"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SH/SHLOMIF/XML-LibXML-2.0210.tar.gz"; - hash = "sha256-opvz8Aq5ye4EIYFU4K/I95m/I2dOuZwantTeH0BZpI0="; + url = "mirror://cpan/authors/id/T/TO/TODDR/XML-LibXML-2.0213.tar.gz"; + hash = "sha256-KvIcXWGsNOompfq/FbpaWEHmSPcYnbPjO28otUiYAqs="; }; env.SKIP_SAX_INSTALL = 1; buildInputs = [ @@ -38809,10 +38985,6 @@ with self; zlib ] ); - patches = [ - # https://github.com/shlomif/perl-XML-LibXML/pull/87 - ../development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch - ]; propagatedBuildInputs = [ XMLSAX ]; meta = { description = "Perl Binding for libxml2"; @@ -39407,11 +39579,12 @@ with self; YAMLLibYAML = buildPerlPackage { pname = "YAML-LibYAML"; - version = "0.89"; + version = "0.907.0"; src = fetchurl { - url = "mirror://cpan/authors/id/T/TI/TINITA/YAML-LibYAML-0.89.tar.gz"; - hash = "sha256-FVq4NnU0XFCt0DMRrPndkVlVcH+Qmiq9ixfXeShZsuw="; + url = "mirror://cpan/authors/id/T/TI/TINITA/YAML-LibYAML-v0.907.0.tar.gz"; + hash = "sha256-a6CHIkkROJ52+hmLFJzsg/BlsKx13cUmGPNJCULNlQY="; }; + buildInputs = [ TestWarnings ]; meta = { description = "Perl YAML Serialization using XS and libyaml"; license = with lib.licenses; [ @@ -39457,6 +39630,11 @@ with self; MojoliciousPluginOpenAPI RoleTiny ]; + # Mojolicious 9.48 enforces CSRF token validation (CVE-2026-15747); these + # tests drive forms without a token and fail with 400 "CSRF token failure". + preCheck = '' + rm t/plugin/auth/github.t t/plugin/form/bootstrap4.t + ''; meta = { homepage = "http://preaction.me/yancy/"; description = "Best Web Framework Deserves the Best CMS";