Email or username:

Password:

Forgot your password?
dansup

Pixelfed has shipped a fix to validate timestamps from remote activities, rejecting any dates outside the range (-10 years and +1 day)

github.com/pixelfed/pixelfed/p

3 comments
infinite love ⴳ

@dansup wait, why -10 years? not every object is freshly authored activitystreams... some objects might be historical, converted from a cms, or even just fetched 10+ years later without the activity.

Go Up