Skip to content

ktistec

v3.8.0 Feature

This release adds 4 notable features for engineering teams evaluating rollout.

Published 17d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

activitypub crystal

Summary

AI summary

Fixed MIME multipart upload errors and mapped malformed body parses to Bad Request.

Changes in this release

Feature Medium

Add back-end support for user-defined algorithmic feeds.

Add back-end support for user-defined algorithmic feeds.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Low

Display activity status on actor cards.

Display activity status on actor cards.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Low

Apply community-relayed moderator deletes received as a Group's wrapped `Announce`.

Apply community-relayed moderator deletes received as a Group's wrapped `Announce`.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Low

Follow a web page's `rel="alternate"` link when searching.

Follow a web page's `rel="alternate"` link when searching.

Source: llm_adapter@2026-07-16

Confidence: high

Performance Medium

Avoid loading entire `has_many` collections when constructing child records.

Avoid loading entire `has_many` collections when constructing child records.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Evaluate the same-origin fetch gate against an embedded node's own identifier.

Evaluate the same-origin fetch gate against an embedded node's own identifier.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Accept a delete of an uncached object or actor without verification.

Accept a delete of an uncached object or actor without verification.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Catch `MIME::Multipart::Error` in local file-upload handling.

Catch `MIME::Multipart::Error` in local file-upload handling.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Map malformed request-body parse failures to `Bad Request`.

Map malformed request-body parse failures to `Bad Request`.

Source: llm_adapter@2026-07-16

Confidence: high

Full changelog

Added

  • Display activity status on actor cards.
  • Back-end support for user-defined algorithmic feeds.
  • Apply community-relayed moderator deletes received as a Group's wrapped Announce.
  • Follow a web page's rel="alternate" link when searching.

Fixed

  • Avoid loading entire has_many collections when constructing child records.
  • Evaluate the same-origin fetch gate against an embedded node's own identifier.
  • Accept a delete of an uncached object or actor without verification.
  • Catch MIME::Multipart::Error in local file-upload handling.
  • Map malformed request-body parse failures to Bad Request.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track ktistec

Get notified when new releases ship.

Sign up free

About ktistec

ActivityPub (https://www.w3.org/TR/activitypub/) server for individual users and small groups.

All releases →

Related context

Related tools

Earlier breaking changes

  • v3.9.0 Removes the `deliver_to` state and recipients fallback.
  • v3.9.0 Restricts theme overrides to color and reduces reliance on `!important`.
  • v3.4.1 Return 410 Gone instead of 404 Not Found for missing actors.

Beta — feedback welcome: [email protected]