Email or username:

Password:

Forgot your password?
Darius Kazemi

Hi admins! To keep us up to date with this morning's Mastodon security patches I have released Hometown v1.1.1+4.0.6:

github.com/hometown-fork/homet

(This is a second release in two days, containing further bugfixes released by the Mastodon team.)

I'll have a backport for people running the older Hometown version 1.0.8+3.5.5 later today when I'm not stuck on my phone at an airport. Thank you @jasmin and @misty for your help!!

16 comments
Mark

@darius Some of those CVEs are absolutely vicious. I thought log4j was bad!

Kostyn

@darius got the update running well on niagara.social. Really quite lost on how to actually find the nginx config file that to add those hardening lines to though (using proxyed external object storage). Any ideas ?

Darius Kazemi

Hello again admins -- there was a bug in Mastodon's security patch that caused issues in the admin panel when viewing remote accounts. They released a fix about 15 minutes ago and I am working to get a Hometown release with that fix very soon.

Nikoh :verified:

@darius hello, I wrote to you many time about but any answer.... 🙄

Darius Kazemi

@Nikoh Sorry, it is difficult for me to keep up with correspondence sometimes. How can I help?

Nikoh :verified:

@darius Nothing special, I have a mastodon istance ad I would want switch to hometown, I wrote to you just to know if you can help me if I need

Darius Kazemi

@Nikoh Oh, I'm sorry but I can't. I try my best to provide documentation but I don't have the time to help individual server operators (I wish I did)

Darius Kazemi

Okay, here is the v1.1.1 (Mastodon 4.0.6) release:

github.com/hometown-fork/homet

It should be pretty simple to patch your 4.0.5 installation if you did that yesterday! (I have updated my original post in this thread to point to the new release.)

maxine

@darius installed with no issues, tysm : )

Darius Kazemi

If you are on a Mastodon v3-compatible version of (v3.5.5+hometown-1.0.8 is the only one I support) here is the patched Hometown version, v3.5.10+hometown-1.0.8:

github.com/hometown-fork/homet

nilesh

@darius Hi Darius, can you point me to an example of a long-form <Article> object on any instance?

I filed an issue in @neet's masto.js for supporting <Article> so that this can eventually come to clients like @elk

github.com/neet/masto.js/issue

Darius Kazemi

@nilesh @neet @elk We don't write Article, we only read it. I would look at writefreely servers for examples of Article in the wild.

Go Up