diaspora
Distributed open-source social network
The original federated social network now ships roughly once every two years.
◆Recent moves
- 3mo ago
diaspora* 0.9.1.0 patches an SSRF hole in its OIDC implementation
The first release in nearly two years, and the project describes it as a security update podmins should apply promptly. The headline fix closes a vulnerability where malicious client registrations against the OpenID Connect API could trigger HTTP requests inside a pod's private network — a real exposure for anyone running a pod alongside other internal services.
View source ↗ - 2y ago
diaspora* 0.9.0.0 opens a supported API and moves config to TOML
⚡ SPARKThe one release in this window that changes what the project is capable of: a supported public API for third-party applications, and a configuration format migration to TOML with YAML support scheduled to end at 1.0. Everything after this is maintenance, which makes 0.9.0.0 the last point where the roadmap moved.
View source ↗ - 3y ago
diaspora* 0.7.18.2 hardens user image processing
A targeted security release addressing image-processing risks in user uploads, adapted from Mastodon's fix for the same class of issue. The project notes its own attack surface is smaller and some systems already ship restrictive ImageMagick policies, but shipped the fix to cover every configuration.
View source ↗ - 3y ago
diaspora* 0.7.18.1 fixes startup with multiple bundler versions
A single-fix release updating binstubs so a pod can start when more than one bundler version is installed. It affects installation only and changes nothing users can see.
View source ↗ - 4y ago
diaspora* 0.7.18.0 upgrades to Rails 6.1
Entirely internal work: the Rails 6.1 upgrade, removal of unmaintained dependencies including compass-rails and entypo-rails, a switch to sassc-rails for faster asset compilation, and Sidekiq 7 deprecation warnings cleared. Podmins get a faster precompile and a suggested Ruby version bump to 2.7; users see nothing.
View source ↗ - 4y ago
diaspora* 0.7.17.0 blocks mass assignment of password and 2FA settings
Two security fixes: a Rails bump to 5.2.7 covering two CVEs, and a change preventing users from mass-assigning their own password and two-factor settings alongside other parameters. The second was externally reported, and it is the more consequential of the pair for account safety.
View source ↗