検索

Misskey 2026.3.1 及 Sharkey 2025.4.6 已发布。 此版本包含严重漏洞修复,请尽快升级至本版本或最新版 CVE: CVE-2026-28431 (Misskey) CVSS: 9.2/10 https://github.com/misskey-dev/misskey/releases/tag/2026.3.1 https://activitypub.software/TransFem-org/Sharkey/-/releases/2025.4.6 #Sharkey #Misskey
The stable release for 2025.4.6 has been made, with the security patches applied. Develop has merge conflicts that are actively being resolved.
This is your official notice that we'll be making a major security release for Sharkey tomorrow (between and ) in coordination with Misskey. Please be ready to patch your instances soon as humanly possible, as the vulnerabilities at play are _extremely_ severe. Note that IceShrimp and Firefish derivatives are not affected, only direct forks of Misskey.
返信 0 · Renote 2
返信 0 · Renote 2
返信 0 · Renote 1
PSA for Misskey/fork admins: Misskey relies on Redis for long-term data storage. It is *not* just a caching solution, and wiping redis will result in permanent data loss. This is contrary to most guides and documentation regarding redis, because *Misskey is actually using it wrong.* But unfortunately, lots of data is only stored in Redis with no way to re-create it from Postgres: - All notifications - Most timelines, if Fanout Timelines is enabled - Charts and graphs - Federation jobs, including delayed / scheduled jobs - Antennas (they "reset" and lose all posts) - User lists (they "reset" and lose all posts) - Trending hashtags / notes - Reversi games - WebAuthn - User profiles (specifically the list of posts) If you ever lose or rollback your Redis cluster, then all of the above will be impacted. So please take regular backups! #FediAdmin #Misskey #MisskeyAdmins #Sharkey #SharkeyAdmins #PSA
返信 0 · Renote 2
Hi friends! :senko_happy_3:

I want to tell you all about a new thing I'm trying, where I'll accept bounties to work on specific features or bug fixes for Sharkey. If there's something you really want implemented, then you can make a donation and I'll prioritize that work over whatever other ticket I was going to work on.

To be clear, this is an agreement to *work on* a particular project, not a promise to finish it! I'll dedicate a certain amount of time to the work based on the size of the donation, and if I finish the work - then great! If not, I'll upload my progress to branch to either finish later or hand off to another interested party. I may choose to complete the work anyway if it's something that I also want, but that's not a gaurantee! Pricing is in lose terms because tracking my hours or comtting to deadlines will take all the fun out of everything. Sorry if that's an issue, but I'm not willing to negotiate on this. I *will* make sure not to "count it" if I don't actually get much work done, so don't worry about picking a bad week and wasting your money. If I don't manage enough work when I initally plan to, then I'll just save my progress and resume when I have more time. Time slots are broken down like this: • $20 - I work on my lunch break. This is usually about an hour, so I probably won't complete a whole ticket unless it's something small. • $30 - I dedicate an evening or two. The exact number of hours varies, but it's usually 2-4 per evening. I'll aim for at least 3 hours in total. • $50 - It's my weekend project. Again, my availability varies - but sometimes I spend 12+ hours between Saturday and Sunday. • $100 - This is my focus for the week. I won't devote any more Sharkey time than I would normally, but all of that time is devoted to this work item. If this sounds like something you'd like, then please reply or send a DM! For this first trial phase, I've picked a curated list of tickets that I'm willing to work on. Assuming everything goes well, I'll add more options and open up the possibility of working on brand new ideas too. I hope this can be a good deal for everyone! --- Ticket options: • #499 - enhancement: Context menu button for muting the instance of a post • #548 - enhancement: Admin feature: Ability to safely reset MFA for end users • #675 - enhancement: API Endpoint for validating scoped tokens, returning a list of assigned scopes • #746 - bug: When editing a quote, the "quote" indicator and button are not aligned • #836 - enhancement: Log IP Address of Registrants • #910 - enhancement: Allow moderators to set a content warning on any post • #943 - enhancement: Allow moderators to force a content warning for all posts by an instance • #953 - enhancement: Investigate a better on-disk structure for drive files • #997 - enhancement: Increase options for number of poll options • #1001 - enhancement: Add option to delete all users from remote instance • #1002 - bug: "Force Content Warning" does not apply to boosts • #1008 - bug: Search menu does not lookup url containing emoji • #1034 - enhancement: Multi select for adding notes to clips • #1039 - enhancement: Add change UI language when logged out • #1040 - enhancement: Hide alt-text • #1065 - enhancement: Option to hide note that are replies to a reply of a note • #1069 - bug: Send abuse reports to contact email • #1070 - enhancement: Translate Content Warning • #1071 - enhancement: Translate Alt Text • #1072 - enhancement: Allow user to specify the source language for translation • #1076 - enhancement: Support multiple hosts for email delivery • #1106 - bug: Dont mark post as long for just including certain mfm • #1110 - enhancement: Allow admins to change bio length limit

---

Clarifications and Disclaimers:

1. As stated above, this is not a promise to complete any work item! I'll put effort in - that's the only gaurantee. 2. This is not a contract of employment or payment for services. 3. If something "important" comes up, then I may pause your work item to focus on that. Think urgent bugs, security issues, or project management responsibilities. This won't count against the promised effort. 4. If multiple donations are made around the same time, then I'll complete them in order of submission. 5. If a work item is completed before I get to your request, then I'll offer the chance to select another ticket instead. 6. You're welcome to ask how long I expect a particular item to take! I may not answer in hours, but I can give a relative estimate of complexity. #Sharkey #FediDevs #FediDev #SoftwareDev
返信 0 · Renote 0
https://00m.in/GTIBa FirefishからSharkeyへの移行はこちらの手順とSharkey公式ドキュメントをあわせて確認すると良いと思いますが(手順にないデータベースの書き換えが公式ドキュメントにあるので注意)、この方法だけだと、ユーザーのアバターやカスタム絵文字他が表示されなくなってしまいます。
アバターについては再アップロードすればよいですが、カスタム絵文字についてはインポート・エクスポートではどうしようもなさそうです。
要検証ではありますが、エラーメッセージを読む限り、 (Firefishのディレクトリ)/files の中身を (Sharkeyのディレクトリ)/files に移さないといけないかもしれません。 近々Zennあたりに投稿しようかと。 #Sharkey #Firefish
返信 0 · Renote 1
Tip for #singleuser or small instance users: The biggest disadvantage of small instances is the dead federated timeline. Instance admins can subscribe to the classic #relays, but this comes at a high price such as high resource usage and too much noise, depending on the relay. It's either all or nothing. Instead you can populate your federated timeline by following the #FediBuzz relays. They can be followed as normal users and boost posts based on the hashtag, instance or even language. Here are a few examples: @tag-fediverse@relay.fedi.buzz (boosts the #fediverse hashtag from all instances) @instance-jasdemi.com@relay.fedi.buzz (boosts everything from my instance, jasdemi.com) @language-it@relay.fedi.buzz (boosts only posts in Italian language from all instances) Now before you follow any relays, I suggest creating an alt account as this will make you home timeline very noisy. With your main account you can now check out the federated timeline or follow hashtags. More info here: https://relay.fedi.buzz/ #fediadmin #gotosocial #sharkey #mastodon #feditip #selfhosted
返信 1 · Renote 0