Attention Mastodon server owners: Security patch release v2.4.4 is out. It's a quick upgrade.
If you are deploying Mastodon from the master branch, update to at least commit 802cf6a.
@Mastodon mastodon.social is running latest master already.
@Granddad will give this a try tonight. thx for the heads-up my co-admin 🙏
I gotcha fam
@Mastodon Is relay federation part of this update?
@Mastodon This is somewhat scary.
Mistakes happen and it is good that they are transparent about it, good first impressions so far.
@Mastodon fuck yeah security patches for days bitch
@Mastodon FWIW I successfully upgraded 3 instances from 2.3.3 to 2.4.3 by cherry-picking these commits onto 2.4.3: https://github.com/tootsuite/mastodon/issues/8007#issuecomment-413388963 No need to migrate to 2.4.1 first (although perhaps that is safer).
@Mastodon easy peasy! thanks for the fix!
Follow friends and discover new ones. Publish anything you want: links, pictures, text, video. This server is run by the main developers of the Mastodon project. Everyone is welcome as long as you follow our code of conduct!