Skip to content

Release history

ktistec releases

ActivityPub (https://www.w3.org/TR/activitypub/) server for individual users and small groups.

All releases

20 shown

No immediate action
v3.9.0 Breaking risk

`deliver_to` removal

No immediate action
v3.8.0 Bug fix

MIME multipart & bad request mapping

No immediate action
v3.7.0 New feature

Webfinger + Update activity support

Review required
v3.6.0 Breaking risk
Dependencies

Removed idx_relationships_type index

No immediate action
v3.5.0 Breaking risk

Dependency removals

No immediate action
v3.4.1 Breaking risk

Tag counts removal

No immediate action
v3.4.0 Breaking risk

Removed paginated queries

Review required
v3.3.9 Security relevant
Auth

DNS rebinding + HTTP body limits

Review required
v3.3.8 New feature
Auth RBAC

String safety + Slang engine

v3.3.7 New feature
Security fixes
  • Prevent pinning of private objects and auto-unpin them
  • Remove `href` attributes with unsafe schemes from sanitized HTML
  • Escape interpolated values in view helpers and actor icon refresh
Notable features
  • Sliding token expiration for OAuth2 access tokens
  • Mastodon-compatible API endpoint `/api/v1/accounts/update_credentials`
Full changelog

Added

  • Sliding token expiration for OAuth2 access tokens.
  • Mastodon-compatible API: /api/v1/accounts/update_credentials endpoint.

Fixed

  • Prevent pinning of (and auto-unpin) private objects.
  • Don't save a quote if the quoted actor cannot be dereferenced.
  • Fix rendering of federated actor profile attachment values.
  • Remove href attributes with unsafe schemes from sanitized HTML.
  • Escape interpolated values in view helpers and the actor icon streaming refresh.
  • Restrict upload extensions and serve uploads with X-Content-Type-Options: nosniff.
  • Escape publicKey and scrub Tag.href.
  • Sanitizer no longer permits single-quote attribute injection.
  • Ensure bearer-token sessions cannot reach the web UI.
  • Require client authentication on the OAuth token endpoint.
v3.3.6 Security
Security fixes
  • Prevented SSRF when dereferencing externally supplied IRIs
Notable features
  • Deferred downloading of script files
  • Deferred loading of image, video, and audio attachments
Full changelog

Fixed

  • Prevent SSRF when dereferencing externally supplied IRIs.
  • Timeline entry no longer becomes stale when an announce is undone.
  • Correctly represent boosted posts on the home timeline in API clients.

Changed

  • Defer downloading of script files.
  • Defer loading of image, video, and audio attachments.
  • Move poll vote notification for voters into the outbox processor.
v3.3.5 New feature
Breaking changes
  • with_mastodon_api compiler flag removed, API always enabled
Security fixes
  • Correctly resolve keyId from Signature header
Notable features
  • Mastodon-compatible API endpoints
  • Cursor-based pagination
  • Account and status APIs
v3.3.4 New feature
Security fixes
  • Fixed autosave focus handling
Notable features
  • Status posting endpoint
  • Public timeline endpoint
v3.3.1 New feature
Breaking changes
  • NodeInfo siteName renamed to nodeName
Notable features
  • Federation documentation
  • Quote post notifications
  • MCP integration
v3.3.0 New feature
Breaking changes
  • next_attempt_at in tasks nil means not scheduled
Notable features
  • FEP-044f quote post support
v3.2.8 New feature
Notable features
  • Poll creation frontend
  • Poll expiry notifications
  • Metadata editor options
v3.2.7 New feature
Notable features
  • Backend poll support
  • Advanced theming
  • Admin task monitoring

Beta — feedback welcome: [email protected]