Email or username:

Password:

Forgot your password?
Mastodon

⚠️ We have just released important security fixes for the #Mastodon server software. Versions 4.1.3, 4.0.5, 3.5.9, as well as a new nightly are available now to make upgrading quick and painless. Please upgrade as soon as possible!

51 comments
DELETED

@Mastodon three servers all upgraded.

Seamless on all of them! Thanks.

Olaf Kolkman

@Mastodon

this may be useful for some here:
If during the build phase on docker you encounter
```
Bundler::HTTPError Could not fetch specs from rubygems.org/ due to underlying error <Net::OpenTimeout: execution expired (rubygems.org/specs.4.8.gz)>
```
Then an unsatisfactory workaround is to temporarily disable IPv6 on your docker daemon.

Nhan Dang

@koakuma @Mastodon @dean guess he's busy sleeping rn, he shoulda setup watchtower from the first place.

DELETED

@Mastodon May I suggest you include the hashtag #MastoAdmin in that post since many admins follow that

Filibert

@Mastodon com podem saber la versió que tenim i, per tant, si estem actualitzats?

fuomag9

@Mastodon Please improve the docker container building process though! It should not take 2h to get it build and pushed!

Eph Levi

@Mastodon am new here and it's impossible to use android version . Can you fix it ?

DeManiak 🇿🇦 🐧

@Mastodon thank ye kindly.

base image available on docker hub for 4.1.3 yet?

wasn't earlier today.

Zoe

Dear readers of social.animeprincess.net: I will upgrade my website to fix this this weekend. You have until then to hax me. GLHF.

Matt 💩

@Mastodon the docker build process really needs to be looked at, over 2 hours to build after release is a bit much.

Stilic

@Mastodon I got an error related to puma with `mastodon-web`.
What I did to fix this issue was to stop Mastodon, run `bundle install`, and restart it.

GunChleoc

@Mastodon Thanks for the new version!

The upgrade instructions still need some TLC though mastodon.scot/@gunchleoc/11066

Bouncing1981

@Mastodon What does this mean for a common user? Is the user vulnerable if some instances aren't patched and how would I know if I'm part of a server that's not patched?

Kaz24

@Mastodon just want to say thank you to all those behind the scenes that make this place possible. You’re awesome 😊

Felix Urbasik

@Mastodon For the lazy:
```
su - mastodon
cd live
git fetch && git checkout v4.1.3
bundle install
yarn install
sudo systemctl stop mastodon-web mastodon-streaming mastodon-sidekiq
sudo systemctl start mastodon-web mastodon-streaming mastodon-sidekiq
```

Axel Morgner

@Mastodon Thanks for providing the update. I just upgraded our instance to v4.1.3.

kaitou

@Mastodon Your upgrade process is lacking. The upgrade page says "check the release notes on the git page" but doesn't say where to find them. Adding the link with a <fill in the version here> would help. Also, mine didn't start because the ruby gems needed upgrading (no mention of that); adding a "bundle install" command in the generic upgrade instructions wouldn't hurt. (I had to run the sidekiq command by hand to find this out.)

Сандер (прошу, поправляйте мя)

@Mastodon трумбета буде кус офлайн тота вечер жебы мушу робити апдейт.

AstroHyde

@Mastodon I’ve upgraded but still finding it very slow to load posts (I’m on iPhone), any ideas for speed fixes?

Mikaela Caron 🦄

@Mastodon I have absolutely no idea how to update my server 😅

I built it kinda for fun, if anyone has any guides I’d love to see them thanks!
I pretty much followed this guide to set mine up (this was before there was the 1 click install)

linode.com/docs/guides/install

Daniele Pantaleo 🦥:verified:

@Mastodon

» released patch two hours ago
» server is patched already! <3

Jeroen Habets

@Mastodon updated mastodon.habets.dev/ to 4.1.3.

As always: upgrade went smooth as a whistle! Thanks!

Phil Rudland

@Mastodon
Hi,
As this is for server software, do we normal user have to do anything?

Beefy Goblin

@Mastodon what's the advantage of using an app over the website?

Dr. Couts

@Mastodon I hope it’s easier to report cyberbulling, and cyber libel here than on Twitter. I hope you will never allow and promote violence like Twitter does, especially, against women.

Chewie

@Mastodon Thank you, non-docker upgrade went smoothly

Steve Hill 🏴󠁧󠁢󠁷󠁬󠁳󠁿🇪🇺

@Mastodon getting "Module parse failed: Unexpected token" when running assets:precompile :(

Littlekitten13

@Mastodon hope this gets rid of the pedos posting irl loli and links hate the stuff makes this site suck

Dennis1212

@Mastodon I don’t understand what I should/how I should update my Mastodon.

☆⁠ Tყα 2️⃣ Ⓣⓨⓐ :welp:

@Mastodon I came back to this space using a new account. Everything here has been improved. What a nice comeback surprise♡ :patcat:

Tom O

@Mastodon why is there nothing new under Posts for the last day? Seems like your security patch might have broken things.

Jeroen Habets

@Mastodon I just noticed 4.1.4 on github and upgraded (smooth as a whistle)

No post though...or did I miss it?

"This release addresses a few issues that were missed in the last security update and includes changelogs for both updates.

⚠️ It is a follow-up to the important 4.1.3 security release fixing multiple critical security issues (CVE-2023-36460, CVE-2023-36459)."

github.com/mastodon/mastodon/r

Go Up