Zum Inhalt springen

Mastodon Release Notes

24 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mastodon

Mastodon 4.4.22: Korrekturen bei Zitaten, Account-Merging und Anhangslimit

Mastodon v4.4.22 behebt einen Tippfehler in der Behandlung eingebetteter Zitate, ein fehlerhaftes Zusammenführen von Appeal- und AccountWarning-Datensätzen beim Account-Merging sowie einen Off-by-one-Fehler, der bei aktualisierten Remote-Beiträgen bis zu 5 Anhänge erlaubte.

<h1><picture> <source media="(prefers-color-scheme: dark)" srcset="./lib/assets/wordmark.dark.png?raw=true"> <source media="(prefers-color-scheme: light)" srcset="./lib/assets/wordmark.light.png?raw=true"> <img alt="Mastodon" src="./lib/assets/wordmark.light.png?raw=true" height="34"> </picture></h1>

[!NOTE] While we continue to support Mastodon 4.4 and release patches for it, please note that Mastodon 4.6 is available with new features, changes and fixes. We encourage administrators to update to the latest 4.6 version when they can.

Changelog

Fixed

  • Fix typo in embedded quote handling code (#40049 by @shleeable)
  • Fix account merging worker incorrectly merging Appeal and AccountWarning records (#39982 by @shleeable)
  • Fix off-by-one in handling of updated remote posts allowing up to 5 attachments (#39978 by @shleeable)

Upgrade notes

To get the code for v4.4.22, use git fetch && git checkout v4.4.22.

[!NOTE] As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

Dependencies

External dependencies have not changed since v4.4.1:

  • Ruby: 3.2 or newer
  • PostgreSQL: 13 or newer
  • Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mastodon

Mastodon 4.6.4: Sicherheitslücken geschlossen und Fehler behoben

Mastodon v4.6.4 behebt Sicherheitslücken (fehlerhafte Rechteprüfung, SSRF-Schutzumgehung über IPv4-kompatible IPv6-Adressen), berücksichtigt bei Autovorschlägen im Web-UI jetzt das zweite Wort, behebt unter anderem die Stimmabgabe bei Umfragen ohne Ablaufdatum und erfordert eine Neukompilierung der Assets.

<h1><picture> <source media="(prefers-color-scheme: dark)" srcset="./lib/assets/wordmark.dark.png?raw=true"> <source media="(prefers-color-scheme: light)" srcset="./lib/assets/wordmark.light.png?raw=true"> <img alt="Mastodon" src="./lib/assets/wordmark.light.png?raw=true" height="34"> </picture></h1>

Upgrade overview

This release contains upgrade notes that deviate from the norm:

ℹ️ Requires assets recompilation

For more information, view the complete release notes and scroll down to the upgrade instructions section.

Changelog

Security

Changed

  • Change autosuggestions to include second word in web UI (#39622 and #39696 by @Gargron and @zunda)

Fixed

  • Fix being unable to vote in polls without an expiration date (#39949 by @ClearlyClaire)
  • Fix performance of user-focused queries in admin dashboard (#39929 by @ClearlyClaire)
  • Fix Web Push subscription deletion endpoint incorrectly expecting anti-CSRF tokens (#39918 by @ClearlyClaire) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mastodon

Mastodon 4.5.14: Sicherheitslücken geschlossen, Abhängigkeiten aktualisiert

Mastodon v4.5.14 schließt Sicherheitslücken (fehlerhafte Rechteprüfung, SSRF-Schutzumgehung über IPv4-kompatible IPv6-Adressen), aktualisiert Abhängigkeiten, behebt unter anderem die Stimmabgabe bei Umfragen ohne Ablaufdatum und erfordert eine Neukompilierung der Assets.

<h1><picture> <source media="(prefers-color-scheme: dark)" srcset="./lib/assets/wordmark.dark.png?raw=true"> <source media="(prefers-color-scheme: light)" srcset="./lib/assets/wordmark.light.png?raw=true"> <img alt="Mastodon" src="./lib/assets/wordmark.light.png?raw=true" height="34"> </picture></h1>

Upgrade overview

This release contains upgrade notes that deviate from the norm:

ℹ️ Requires assets recompilation

For more information, view the complete release notes and scroll down to the upgrade instructions section.

Changelog

Security

Fixed

  • Fix being unable to vote in polls without an expiration date (#39949 by @ClearlyClaire)
  • Fix performance of user-focused queries in admin dashboard (#39929 by @ClearlyClaire)
  • Fix Web Push subscription deletion endpoint incorrectly expecting anti-CSRF tokens (#39918 by @ClearlyClaire)
  • Fix ActivityPub::Activity::Create trying to re-create known statuses when author changes (#39916 by @ClearlyClaire)
  • Fix typo in quotes list error handling (#39904 by @shleeable)
  • Fix lax relevancy check in inbound activity processing (#39892 by @ClearlyClaire) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mastodon

Mastodon 4.4.21: Sicherheitslücken geschlossen und mehrere Fehler behoben

Mastodon v4.4.21 schließt Sicherheitslücken (fehlerhafte Rechteprüfung, SSRF-Schutzumgehung über IPv4-kompatible IPv6-Adressen), aktualisiert Abhängigkeiten und behebt mehrere Fehler, darunter die Performance von Abfragen im Admin-Dashboard und die fehlende Unterstützung von Quotes beim Account-Merging.

<h1><picture> <source media="(prefers-color-scheme: dark)" srcset="./lib/assets/wordmark.dark.png?raw=true"> <source media="(prefers-color-scheme: light)" srcset="./lib/assets/wordmark.light.png?raw=true"> <img alt="Mastodon" src="./lib/assets/wordmark.light.png?raw=true" height="34"> </picture></h1>

[!NOTE] While we continue to support Mastodon 4.4 and release patches for it, please note that Mastodon 4.6 is available with new features, changes and fixes. We encourage administrators to update to the latest 4.6 version when they can.

Changelog

Security

Fixed

  • Fix performance of user-focused queries in admin dashboard (#39929 by @ClearlyClaire)
  • Fix Web Push subscription deletion endpoint incorrectly expecting anti-CSRF tokens (#39918 by @ClearlyClaire)
  • Fix ActivityPub::Activity::Create trying to re-create known statuses when author changes (#39916 by @ClearlyClaire)
  • Fix lax relevancy check in inbound activity processing (#39892 by @ClearlyClaire)
  • Fix Account::Merging concern not supporting Quotes, refactor it (#39884 by @ClearlyClaire) …

Originalquelle(öffnet in neuem Tab)Problem melden