検索

💬 Commented on "Docker を使用している場合に 2026.5.2 の起動に失敗する": kakkokari-gtyih "> verifyDepsBeforeRunが有効になったのは良くてそれがなぜ通らなくなったかはworkaround applyした後に確認するべきかもしれない?

多分 pnpm v11 の breaking change を踏んだ

> ### Security & build defaults
>
> Several defaults have flipped to safer values:
>
> | Setting | New default |
> | --- | --- |
> | `minimumReleaseAge` | `1440` (1 day) |
> | `minimumReleaseAgeStrict` | `false` |
> | `blockExoticSubdeps` | `true` |
> | `strictDepBuilds` | `true` |
> | `optimisticRepeatInstall` | `true` |
> | **`verifyDepsBeforeRun`** | **`install`** |
>
> https://pnpm.io/blog/releases/11.0#security--build-defaults" https://github.com/misskey-dev/misskey/issues/17424#issuecomment-4473296859
返信 0 · Renote 0
We're pleased to announce that #Fedify has been included in the Nivenly Fediverse Security Fund program! The @[email protected] Foundation has launched a security bounty fund to support contributors who identify and help fix #security vulnerabilities in popular #fediverse software. Both Fedify and @[email protected] are among the selected projects that meet their responsible security disclosure requirements.

This program will run from April–September 2025, with bounties of $250–$500 USD for high and critical security vulnerabilities.

We're honored to be recognized alongside other established fediverse projects like Mastodon, Misskey, and Lemmy. This further encourages our commitment to maintaining strong security practices.

If you're interested in contributing to Fedify's security, please follow our responsible disclosure process outlined in our SECURITY.md file. Learn more about the program: https://nivenly.org/blog/2025/04/01/nivenly-fediverse-security-fund/
返信 0 · Renote 1
In related news, #Hollo has also released #security updates: 0.3.6 & 0.4.4. Update now! https://hollo.social/@fedify/01948487-87b2-709d-953f-8799b78433ed
We have released #security updates (1.0.14, 1.1.11, 1.2.11, 1.3.4) to address CVE-2025-23221, a #vulnerability in #Fedify's #WebFinger implementation. We recommend all users update to the latest version of their respective release series immediately.


The Vulnerability


A security researcher identified multiple security issues in Fedify's lookupWebFinger() function that could be exploited to: Perform denial of service attacks through infinite redirect loops Execute server-side request forgery (#SSRF) attacks via redirects to private network addresses Access unintended URL schemes through redirect manipulation Fixed Versions 1.3.x series: Update to 1.3.4 1.2.x series: Update to 1.2.11 1.1.x series: Update to 1.1.11 1.0.x series: Update to 1.0.14



Changes


The security updates implement the following fixes:


Added a maximum redirect limit (5) to prevent infinite redirect loops

Restricted redirects to only follow the same scheme as the original request (HTTP/HTTPS)

Blocked redirects to private network addresses to prevent SSRF attacks



How to Update


To update to the latest secure version:


# For npm users
npm update @fedify/fedify

# For Deno users
deno add jsr:@fedify/fedify

We thank the security researcher who responsibly disclosed this vulnerability, allowing us to address these issues promptly. For more details about this vulnerability, please refer to our security advisory. If you have any questions or concerns, please don't hesitate to reach out through our GitHub Discussions, join our Matrix chat space, or our Discord server.
返信 1 · Renote 1
返信 1 · Renote 0
We have released #security updates (1.0.14, 1.1.11, 1.2.11, 1.3.4) to address CVE-2025-23221, a #vulnerability in #Fedify's #WebFinger implementation. We recommend all users update to the latest version of their respective release series immediately.


The Vulnerability


A security researcher identified multiple security issues in Fedify's lookupWebFinger() function that could be exploited to: Perform denial of service attacks through infinite redirect loops Execute server-side request forgery (#SSRF) attacks via redirects to private network addresses Access unintended URL schemes through redirect manipulation Fixed Versions 1.3.x series: Update to 1.3.4 1.2.x series: Update to 1.2.11 1.1.x series: Update to 1.1.11 1.0.x series: Update to 1.0.14



Changes


The security updates implement the following fixes:


Added a maximum redirect limit (5) to prevent infinite redirect loops

Restricted redirects to only follow the same scheme as the original request (HTTP/HTTPS)

Blocked redirects to private network addresses to prevent SSRF attacks



How to Update


To update to the latest secure version:


# For npm users
npm update @fedify/fedify

# For Deno users
deno add jsr:@fedify/fedify

We thank the security researcher who responsibly disclosed this vulnerability, allowing us to address these issues promptly. For more details about this vulnerability, please refer to our security advisory. If you have any questions or concerns, please don't hesitate to reach out through our GitHub Discussions, join our Matrix chat space, or our Discord server.
返信 1 · Renote 1
How many of you think that Linux is more secure than other major operating systems from malware and cyberattacks? Why do you think so? Let me know. #Linux #Security #CyberSecurity #Malware #SysAdmin

投票

  • Linux is an impenetrable fortress: 0票
  • Some vulnerabilities exist but it's mostly safe: 0票
  • Has some security features but is mostly exposed: 0票
  • Is more exposed than a tortoise without its shell: 0票
返信 0 · Renote 1
Tooting into space here, hello 👋 I'm 30 year old programmer from the Netherlands. I fiddle with hardware, mostly keyboards and I'm finding my way back into #security. Besides this I'm pretty active by doing swimming, bouldering and playing padel. Interested in going to #concerts and #music. Never really got into Twitter but Mastodon seems more like my thing, don't be shy to connect and I will do the same #introduction
返信 0 · Renote 0
ALL CLEAR for Fedora Rawhide and Fedora 40 Beta builds regarding the xz exploit. 👍 Things had stabilized soon after the initial security advisory, but we're now confirming that you can use Rawhide and Fedora 40 Beta safely as long as you have the latest updates or reinstall (which is not a bad idea to be safe). Fedora 38 and 39 were never affected. Learn more: https://fedoramagazine.org/cve-2024-3094-all-clear/ #Fedora #Security #Privacy #InfoSec #Linux #OpenSource
返信 0 · Renote 1