fedify 2.3.2 - #293251
Merged
Merged
Conversation
daeho-ro
approved these changes
Jul 15, 2026
Contributor
|
馃 An automated task has requested bottles to be published to this PR. Caution Please do not push to this PR branch before the bottle commits have been pushed, as this results in a state that is difficult to recover from. If you need to resolve a merge conflict, please use a merge commit. Do not force-push to this PR branch. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Created by
brew bumpCreated with
brew bump-formula-pr.release notes
Fixed a server-side request forgery (SSRF) vulnerability in the
getNodeInfo()function and theContext.lookupNodeInfo()method, where the NodeInfo document URL advertised in a remote server's/.well-known/nodeinforesponse was fetched without checking that it points to a public address. A malicious server could direct the link to a loopback, link-local, or private address鈥攐r to adata:URL鈥攃ausing Fedify to fetch internal resources and return their contents to the caller. Both requests, including any redirect hops, are now validated against private and non-public addresses, consistent with the protections already applied to WebFinger lookups and the built-in document loader. [CVE-2026-62857]Fixed custom collection dispatchers registered through
FederationBuilder.setCollectionDispatcher()andsetOrderedCollectionDispatcher()returning404 Not Foundafterbuild().build()now copies the collection callbacks and item types onto the built federation, so the registered routes dispatch their collections instead of being treated as unknown routes. [#849, #851 by ChanHaeng Lee]Fixed the outbound delivery circuit breaker retaining per-host state in the configured key鈥搗alue store forever when a remote host never recovered. Circuit breaker state now receives a TTL on writes made with the default failure policy, custom failure policies can opt in with the new
stateTtloption, and stale state written by earlier 2.3 releases is cleared automatically on CAS-backed stores after upgrade, with another sweep after a grace window to cover rolling deployments. [#916, #917]Fixed split-origin WebFinger responses for
acct:aliases on the web origin host. When a local actor is queried through the server-originacct:alias, Fedify now returns the canonical handle-hostacct:URI as the JRDsubjectand keeps the queriedacct:URI inaliases. [#920, #921]Fixed the npm package published by CI/CD so it includes the Fedify agent skill at skills/fedify/SKILL.md. The package metadata already advertised the skill, and local
pnpm packbuilds included it, but the automated npm publish artifact skipped theprepackstep that materializes the symlinked skill directory before packing.@fedify/vocab
RangeError. Fedify now ignores only the malformed language-tagged value and continues parsing the rest of the object. [#847, #848]@fedify/cli
fedify nodeinfochoosing SVG favicons whose filenames use uppercase.SVGextensions or include query strings or fragments. The command now ignores those SVG favicon links and falls back to/favicon.icobefore rendering terminal art. [#891, #918 by Junghoon Ban]View the full release notes at https://github.com/fedify-dev/fedify/releases/tag/2.3.2.