Home | Notifications | New Note | Local | Federated | Search | Logout

Federated Timeline


fedicat@fedicat@pc.cafe boosted: @Pixelix@mastodon.social (2026-07-19 03:27:07) Pixelix version 5.0.0 with Vernissage support is now available.

This is one of the largest updates we have ever shipped. We refactored a large portion of Pixelix's architecture to support multiple platforms with different feature sets.

Additionally many UI components got a design overhaul.

The APK is available on GitHub.
Play Store, App Store and F-Droid are following soon.

Check it out, and let us know what you think.

https://github.com/ghostbyte-dev/pixelix/releases/tag/v5.0.0

#Pixelix #Vernissage #Update

Pixelix@Pixelix@mastodon.social (2026-07-19 03:27:07) Pixelix version 5.0.0 with Vernissage support is now available.

This is one of the largest updates we have ever shipped. We refactored a large portion of Pixelix's architecture to support multiple platforms with different feature sets.

Additionally many UI components got a design overhaul.

The APK is available on GitHub.
Play Store, App Store and F-Droid are following soon.

Check it out, and let us know what you think.

https://github.com/ghostbyte-dev/pixelix/releases/tag/v5.0.0

#Pixelix #Vernissage #Update

fedicat@fedicat@pc.cafe boosted: @writefreely@writing.exchange (2026-07-19 03:19:34) There's a pull request open now for mass user moderation via the command-line (listing, silencing and deleting).

If there's anything else you think is missing or needed, please leave a comment there!

https://github.com/writefreely/writefreely/pull/1705

#WriteFreely #WriteFreelyDev

Reply to @writefreely@writing.exchange WriteFreely@writefreely@writing.exchange (2026-07-19 03:19:34) There's a pull request open now for mass user moderation via the command-line (listing, silencing and deleting).

If there's anything else you think is missing or needed, please leave a comment there!

https://github.com/writefreely/writefreely/pull/1705

#WriteFreely #WriteFreelyDev

Reply to @cwebber@social.coop Christine Lemmer-Webber@cwebber@social.coop (2026-07-19 02:57:44) Hack & Craft starting now! https://fossandcrafts.org/hack-and-craft/

fedicat@fedicat@pc.cafe boosted: @hollo@hollo.social (2026-07-19 02:37:26) Hollo security updates: 0.8.9 and 0.9.9
If you run Hollo, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client, which Hollo uses to identify the software running on remote ActivityPub servers.

A NodeInfo lookup starts by fetching a remote server's /.well-known/nodeinfo document, then follows the NodeInfo document URL advertised in that response. The vulnerable getNodeInfo() path fetched both URLs without validating that they resolved to public network destinations. Because the second URL comes directly from a response controlled by the remote server, it could point to a loopback address, a link-local cloud metadata endpoint, an RFC 1918 private address, or even a data: URL.

An attacker who controls a remote server that Hollo discovers could therefore make the Hollo instance initiate requests to non-public network destinations, depending on the deployment environment and network routing.

The fix applies Fedify's public-address validation to both NodeInfo requests and every redirect hop. It also caps redirects, refuses cross-protocol redirects, and rejects non-HTTP(S) URLs. As a result, NodeInfo lookups for private or intranet addresses are now refused.

For full technical details of the underlying vulnerability, see the Fedify security advisory and the Fedify security announcement.

All Hollo versions in the supported 0.8.x and 0.9.x release lines up to and including 0.8.8 and 0.9.8 are affected. Patched releases are 0.8.9 for the 0.8.x series and 0.9.9 for the 0.9.x series.

Hollo 0.7.x is also affected. It and earlier release lines are no longer supported under the Hollo security policy. Upgrade to a supported release series rather than remaining on an older version.

For 0.8.x deployments, update to 0.8.9:


docker pull ghcr.io/fedify-dev/hollo:0.8.9
For 0.9.x deployments, update to 0.9.9:


docker pull ghcr.io/fedify-dev/hollo:0.9.9
After pulling the new image, restart your Hollo container. If you deploy from source, pull t

Hollo :hollo:@hollo@hollo.social (2026-07-19 02:37:26) Hollo security updates: 0.8.9 and 0.9.9
If you run Hollo, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client, which Hollo uses to identify the software running on remote ActivityPub servers.

A NodeInfo lookup starts by fetching a remote server's /.well-known/nodeinfo document, then follows the NodeInfo document URL advertised in that response. The vulnerable getNodeInfo() path fetched both URLs without validating that they resolved to public network destinations. Because the second URL comes directly from a response controlled by the remote server, it could point to a loopback address, a link-local cloud metadata endpoint, an RFC 1918 private address, or even a data: URL.

An attacker who controls a remote server that Hollo discovers could therefore make the Hollo instance initiate requests to non-public network destinations, depending on the deployment environment and network routing.

The fix applies Fedify's public-address validation to both NodeInfo requests and every redirect hop. It also caps redirects, refuses cross-protocol redirects, and rejects non-HTTP(S) URLs. As a result, NodeInfo lookups for private or intranet addresses are now refused.

For full technical details of the underlying vulnerability, see the Fedify security advisory and the Fedify security announcement.

All Hollo versions in the supported 0.8.x and 0.9.x release lines up to and including 0.8.8 and 0.9.8 are affected. Patched releases are 0.8.9 for the 0.8.x series and 0.9.9 for the 0.9.x series.

Hollo 0.7.x is also affected. It and earlier release lines are no longer supported under the Hollo security policy. Upgrade to a supported release series rather than remaining on an older version.

For 0.8.x deployments, update to 0.8.9:


docker pull ghcr.io/fedify-dev/hollo:0.8.9
For 0.9.x deployments, update to 0.9.9:


docker pull ghcr.io/fedify-dev/hollo:0.9.9
After pulling the new image, restart your Hollo container. If you deploy from source, pull t

dave@dthompson@toot.cat boosted: @TodePond@mas.to (2026-07-15 00:08:38) can't make this shit up ---Attachments--- image: https://media.mas.to/media_attachments/files/116/918/957/280/036/417/original/3e9d9eebf2578188.jpg

fedicat@fedicat@pc.cafe boosted: @HolosSocial@mastodon.social (2026-07-19 02:25:48) #HolosSocial 1.15.0 is available.
This release brings moderation tools for the relay staff, and an account standing page where everyone can see if they have strikes from a relay, with the possibility to appeal. A post preview is now shown in grouped notifications.
It also brings several fixes, including boosts not reaching all followers servers, blocked accounts in hashtag tracking, and a stuck sync notification draining the battery.

Release notes: https://codeberg.org/tom79/Holos-App/releases/tag/1.15.0

Holos Social@HolosSocial@mastodon.social (2026-07-19 02:25:48) #HolosSocial 1.15.0 is available.
This release brings moderation tools for the relay staff, and an account standing page where everyone can see if they have strikes from a relay, with the possibility to appeal. A post preview is now shown in grouped notifications.
It also brings several fixes, including boosts not reaching all followers servers, blocked accounts in hashtag tracking, and a stuck sync notification draining the battery.

Release notes: https://codeberg.org/tom79/Holos-App/releases/tag/1.15.0

never obsolete@256@mastodon.social (2026-07-19 02:02:12) Lenovo ThinkPad X60 Tablet (2006)
(photo source: ebay) ---Attachments--- image: https://files.mastodon.social/media_attachments/files/116/942/051/329/175/724/original/ebe33df981efaebf.jpg

fedicat@fedicat@pc.cafe boosted: @michael@social.chrisco.me (2026-07-18 16:29:14) https://canvas.fediverse.events/ is happening right now!

#fediverse

Reply to @Yohei_Zuho@mstdn.y-zu.org たかし@tak4@mstdn.y-zu.org (2026-07-19 01:33:03) @Yohei_Zuho ハッチポッチステーション

Christine Lemmer-Webber@cwebber@social.coop (2026-07-19 01:31:17) Hack & Craft! From 2pm-4pm ET (that's in 1.5 hours from the time of me posting this)! https://fossandcrafts.org/hack-and-craft/

Come bring a coding project, an art project, your sewing project, etc!

fedicat@fedicat@pc.cafe boosted: @dansup@mastodon.social (2026-07-18 22:07:23) RE: https://macaw.social/@andypiper/116941037974688000

What an absolute legend, after moving on from @Mastodon, he still spreads awareness and donates stickers!

@andypiper you may have moved on to another role, but your kindness and impact will always be remembered here on the fediverse ❤️

fedicat@fedicat@pc.cafe boosted: @writefreely@writing.exchange (2026-07-19 00:22:00) After yesterday's critical 0.17 release, there was a bug with the Export page not rendering that came up (https://github.com/writefreely/writefreely/issues/1702). I'm fixing that now.

I'm also building a way to quickly clear out spam accounts that might've been created while the account-creation vulnerability was out there.

fedicat@fedicat@pc.cafe boosted: @grunfink@comam.es (2026-07-19 01:15:03) Hi. After some incorrect user / password tries from a given IP, #snac bans it for a (configurable) amount of time. This is probably what has happened to you on your mobile.

Christine Lemmer-Webber@cwebber@social.coop (2026-07-19 01:20:06) New https://worm-blossom.org update where @gwil writes:

> Sneakerweb was very much at the heart of worm-blossom’s presence at DWeb camp this year. We had a table at the ‘demo night market’, in which we had to beckon passers-by with nothing but our charms. The only problem: our neighbour was the inimitable Christine Lemmer-Webber of the Spritely Institute, who not only had prepared an incredible multi-screen, multimedia experience, but also has the overpowering voice of a lady who sells onions at the market.

Sorrryyyyyyyyyyy

It was pretty dope tho https://mastodon.social/@kirschner/116891637708028942

Reply to @gmc@snac.chasmcity.net The Real Grunfink@grunfink@comam.es (2026-07-19 01:15:03) Hi. After some incorrect user / password tries from a given IP, #snac bans it for a (configurable) amount of time. This is probably what has happened to you on your mobile.

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-19 01:10:28) 毛根

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-19 01:00:05) 歩きスマホは最高っすねぇ~~~~!!!!!!(時速100キロおいどけクソスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホスマホぐわーーーーーーーー俺がスマホになってしまった(超常現象

もちもちずきん🍆@Yohei_Zuho@mstdn.y-zu.org (2026-07-19 00:59:40) ワークステーション
ホビーステーション
レストステーション

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-19 00:56:37) ray (超かぐや姫! Version) - かぐや(cv.夏吉ゆうこ) & 月見ヤチヨ(cv.早見沙織) #NowPlaying #なうぷれ
検索

コシヌケ1040@ksnk@pawoo.net boosted: @shapoco@misskey.io (2026-07-18 22:37:15) 人にはウインナーで白飯を食いまくりたい時がある #shapoart ---Attachments--- image: https://media.misskeyusercontent.com/io/a23cd342-272f-4f4b-b08d-434fe22532fc.png

猫川/네코가와🇯🇵🇰🇷🇹🇭🇧🇷🇨🇦❤@nounashi7298@social.nekokawa.net (2026-07-19 00:39:46) 国よりも自分に不満がある

猫川/네코가와🇯🇵🇰🇷🇹🇭🇧🇷🇨🇦❤@nounashi7298@social.nekokawa.net (2026-07-19 00:37:46) この世のいろんなニュース、割とどうでもいいで結論ついちゃう

Reply to @octo@blackqueer.life legally distinct octo@octo@blackqueer.life (2026-07-19 00:24:26) @mutualaid :boostRequest: could you please give me a boost? :boostRequest: 🥺

goal: 153/900

I still am 47 or so USD short from covering my cat expenses and I haven't really got anything on the last few days. I really need any help i can get!

I've been reaally trying my best cut as much as I can of my expenses as I can as I am unable to crowdfund this year.

Any and every bit of help is much appreciated! Any amount and boosts goes a long way!

thanks for the support!!!

links:
ko-fi - accepts paypal and stripe.
stripe (USD) - (for those that prefer not using paypal)
hashtags
@mutualaid

#mutualAid #transCrowdfund #mutualAidRequest #blackMutualAid #boostPlease #transMutualAid

WriteFreely@writefreely@writing.exchange (2026-07-19 00:22:00) After yesterday's critical 0.17 release, there was a bug with the Export page not rendering that came up (https://github.com/writefreely/writefreely/issues/1702). I'm fixing that now.

I'm also building a way to quickly clear out spam accounts that might've been created while the account-creation vulnerability was out there.

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-19 00:10:25) 最近街中でパンケーキに脳内が過剰反応してしまいかぐやの声が流れてくるので終わり

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-19 00:08:41) パンケーキ!?
Older Notes