Sign in

Fedify: ActivityPub server framework

@fedify.hollo.social.ap.brid.gy
49 followers 0 following 134 posts

:fedify: Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards, so-called fediverse. It aims to eliminate the […] 🌉 bridged from ⁂ hollo.social/@fedify, follow @ap.brid.gy to interact

PostsRepliesMedia
Reposted by Fedify: ActivityPub server framework
Jiwon @z9mb1.hackers.pub.ap.brid.gy · 4h
First big release after I joined as a maintainer probably. Patch releases, feature implementations, bug fixes, and lots of code reviews. Thanks, every contributors!! RE: hackers.pub/@fedify/2026/fedify-2-4
hackers.pub
034
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 8h
A Chinese developer, @21018365486, wrote about adding ActivityPub to her blog using Fedify. Thank you for using Fedify! blog.yunyi.beiyan.us/posts/migrateT…
blog.yunyi.beiyan.us
002
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 27/09/2026
hackers.pub
Fedify security updates: 2.0.28, 2.1.24, 2.2.13, and 2.3.8
If you use an affected Fedify release, update now. Three vulnerabilities have been fixed: CVE-2026-96625, a critical actor impersonation vulnerability; CVE-2026-96623, a high-severity denial-of-service vulnerability in remote document parsing; and CVE-2026-96624, a medium-severity server-side request forgery vulnerability in outbound activity delivery. Treat the actor impersonation issue as an immediate upgrade: anyone on the internet could have an activity accepted by your inbox as coming from any actor. The patched releases are 2.0.28, 2.1.24, 2.2.13, and 2.3.8. All three vulnerabilities affect the preceding releases on those lines: 2.0.27, 2.1.23, 2.2.12, and 2.3.7, respectively. If you still use Fedify 1.x, change your dependency to a patched 2.x release because package-manager update commands do not cross the declared major-version range. ## Actor impersonation (CVE-2026-96625, critical, CVSS 9.1) CVE-2026-96625 has been present since Fedify's first public release, 0.1.0. Fedify verified the signature on an incoming activity, but trusted the signing key document's own claim about whom the key belonged to. An attacker with an ordinary HTTP server could serve a key document naming any actor as its owner and have activities accepted under that actor's identity, even if the actor did not exist. No account on the receiving server was required. HTTP Signatures, Linked Data Signatures, and Object Integrity Proofs were all affected; the latter two did not require an HTTP signature on the request. The same vulnerability affected `getKeyOwner()` and `Context.getSignedKeyOwner()`. A forged key document could pass ownership checks under another actor's identity, allowing an attacker to read resources that an application's authorized fetch access control reserved for that actor. The fix resolves the claimed owner's actor document and requires it to link back to the key. It also validates the origin of fetched actor documents, so a host serving a key cannot speak for an actor on another origin. A key without an explicit owner is attributed to the actor whose document carried it. Public keys cached before this release recorded ownership that had not been verified. Fedify's built-in key cache automatically stops reading those entries. If you pass a custom `KeyCache` implementation to `verifyRequest()`, `verifyJsonLd()`, or `verifyObject()`, discard its contents when you upgrade. A patched process reading a stale entry from a custom cache would still trust the unverified owner in it. ## Unbounded document parsing (CVE-2026-96623, high, CVSS 7.5) CVE-2026-96623 affects deployments that accept inbox requests or fetch remote documents. Fedify parsed JSON bodies without a byte limit, including inbox bodies and responses fetched for keys, actors, objects, JSON-LD contexts, WebFinger descriptors, and NodeInfo documents. An attacker who caused Fedify to fetch a URL they controlled could exhaust memory and CPU with a large response. A small compressed response could expand substantially before parsing, so an inbound body limit at a reverse proxy did not protect the outbound fetch paths. The fix limits JSON bodies to 16 MiB after decompression. HTML alternate-link discovery retains its existing 1 MiB limit. Oversized inbox requests receive HTTP 413, and oversized WebFinger descriptors resolve to `null`. The JSON limit is fixed in these patch releases; applications that exchange legitimate JSON-LD documents larger than 16 MiB will now have those documents rejected. The parsing fixes also ship in `@fedify/vocab-runtime` and `@fedify/webfinger`. If you depend on either package directly, update it too. They use the same patched version numbers listed above. ## Outbound delivery SSRF (CVE-2026-96624, medium, CVSS 5.8) CVE-2026-96624 affects applications that deliver activities to inbox URLs learned from remote actors. The delivery path validated neither the advertised inbox URL nor redirect destinations. A remote actor could point its inbox at a loopback address, a link-local metadata service, or a private network host, or redirect delivery there. On the RSA delivery path, the redirected request remained a POST carrying the activity body and was re-signed for the internal host. The vulnerable delivery path dates back to JSR release 0.1.0 and npm release 0.5.0. The fix validates the initial destination and every redirect target before sending a request. The authenticated document-loader fix in CVE-2026-77632 covered a separate fetch path and did not protect outbound activity delivery. If you deliberately deliver to private addresses for local testing or a closed federation, these releases will refuse those deliveries unless you pass `allowPrivateAddress: true` to `createFederation()`. That option permits both private inbox URLs and private redirect targets, restoring the exposure described here. Keep it to environments where you control the actors you federate with. ## Updating Update `@fedify/fedify`: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify Check that your resolved dependency versions are at least 2.0.28, 2.1.24, 2.2.13, or 2.3.8 on the corresponding release line. Update any direct dependencies on `@fedify/vocab-runtime` and `@fedify/webfinger` as well, and clear any custom key cache as described above. After updating, redeploy. If you run other Fedify-based servers, update those too. The full GitHub Security Advisories are CVE-2026-96625, CVE-2026-96623, and CVE-2026-96624. Thanks to @kaimandalic and @moreal for independently reporting the actor impersonation issue. Thanks also to @kaimandalic for the unbounded document parsing report and @euriconicacio for the outbound delivery SSRF report, and to all three for responsible disclosure. If anything is unclear, ask below.
000
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 04/09/2026
今週(금주) 日曜日(일요일)(6日(일))에 瑞草驛(서초역) 近處(근처)에 位置(위치)한 오픈업 센터(네이버地圖, 카카오맵)에서 @fedify 寄與(기여)를 爲(위)한 모임이 열립니다. 午前(오전) 10時(시)에서 午後(오후) 6時(시)까지 進行(진행)되니, 關心(관심) 있는 분들은 自由(자유)롭게 오셔서 參與(참여) 바랍니다! (10時(시)에서 18時(시) 사이에 아무 때나 오셔서 아무 때나 가셔도 됩니다!)
map.naver.com
013
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 28/08/2026
日本語で書かれたFedifyの紹介記事が掲載されたんですね。ありがとうございます。 easegis.jp/blog/fedify
easegis.jp
ActivityPubの仕様書を読まなくても、FedifyでMastodon連携ができる
HTTP署名やWebFingerなどActivityPub実装の面倒な部分を肩代わりしてくれるTypeScript製フェデレーションフレームワーク、Fedifyの特徴からインストール、実践的な使い方までを解説します。
022
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 26/08/2026
hackers.pub
Fedify security updates: 2.0.26, 2.1.22, 2.2.11, and 2.3.6
If you use an affected Fedify release, update now. Two vulnerabilities have been fixed in `@fedify/fedify`: CVE-2026-77632, a high-severity server-side request forgery vulnerability in the authenticated document loader, and CVE-2026-69132, a medium-severity denial-of-service vulnerability in the outbound delivery circuit breaker. CVE-2026-77632 affects versions 1.6.1 through 2.3.4. Fedify uses an authenticated document loader when it fetches remote documents such as actors and public keys with a signed HTTP request. Affected versions checked that the initial URL was public, but did not apply the same check when that URL returned an HTTP redirect. An attacker who controlled the public URL could redirect the signed request to a loopback address, a link-local metadata service, or an RFC 1918 host. In the ordinary inbox path, Fedify may fetch a signature's `keyId` before it can verify the signature, so a bogus signature is enough to reach this path. The demonstrated attack is blind SSRF: the internal response is consumed while resolving the remote document and is not automatically returned to the attacker. The fix validates every redirect target before it is fetched. The existing `allowPrivateAddress` option still permits private destinations when an application explicitly opts in, such as for a closed federation or test environment. CVE-2026-69132 affects versions 2.3.0 through 2.3.4. Fedify 2.3 introduced an outbound delivery circuit breaker that records failures in the configured key–value store, using the remote inbox's `host:port` as part of the key. An attacker could send signed `Follow` activities from actors whose inbox URLs pointed to distinct ports where delivery would fail. Each failure created a separate record, allowing the attacker to grow circuit-breaker state until storage or memory was exhausted. Versions 2.3.0 and 2.3.1 were vulnerable with every circuit-breaker configuration. In versions 2.3.2 through 2.3.4, the vulnerable configuration was a custom `failure` policy without an explicit `stateTtl`. The fix gives custom failure policies a bounded default `stateTtl`, equal to `recoveryDelay` plus `heldActivityTtl` (7 days 30 minutes with the default values). On stores that support compare-and-set operations, Fedify also sweeps circuit-breaker state left by affected releases and stamps it with a TTL. Applications that need a different retention period for a custom failure policy can continue to set `stateTtl` explicitly. The SSRF fix first appeared in 2.0.25, 2.1.21, 2.2.10, and 2.3.5; the circuit-breaker fix first appeared in 2.3.5. The current releases on those lines are 2.0.26, 2.1.22, 2.2.11, and 2.3.6, and those are the versions we recommend installing. The circuit-breaker issue only affects the 2.3 line; the authenticated document-loader issue affects every Fedify release from 1.6.1 through 2.3.4. If you still use Fedify 1.x, change your dependency to a current 2.x release because package-manager update commands do not cross the declared major-version range. The GitHub Security Advisories are GHSA-cxc3-7q96-6cpx and GHSA-fx98-wc5v-jrg5. Update `@fedify/fedify`: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify After updating, redeploy. If you run other Fedify-based servers, update those too. Thanks to Jace and @nyanrus for the reports and responsible disclosure. If anything is unclear, ask below.
000
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 18/07/2026
hackers.pub
Fedify security updates: 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2
If you use Fedify, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client. An attacker who runs any instance your server looks up could cause that server to fetch non-public network destinations and return their contents to your application, depending on the deployment environment and network routing. Fedify can look up a remote instance's NodeInfo document to learn what software it runs. The lookup happens in two steps: it fetches the instance's `/.well-known/nodeinfo` document, then follows the NodeInfo document URL that response advertises. The vulnerable path is `getNodeInfo()`, along with the `Context.lookupNodeInfo()` method that wraps it: affected versions sent both requests without validating the destination against public-network expectations. Because that second URL comes straight out of the remote server's response body, the instance being looked up fully controls it, and could point it at a loopback address, a link-local metadata endpoint, an RFC 1918 host, or a `data:` URL. Servers are exposed only if they look up NodeInfo, but that lookup is routine for peer discovery and instance metadata. The fix routes both requests through the same public-address validation Fedify already applied to WebFinger lookups and remote document loading. Every request is now checked before it is sent, including each redirect hop, so a public URL cannot bounce a request to an internal address. Redirects are followed with a cap and are refused if they cross protocols, and non-HTTP(S) URLs such as `data:` are rejected outright. These are patch releases, so they tighten behavior without adding new API. If you deliberately look up NodeInfo on a private or intranet address, such as in a closed federation or a test environment, these releases will now refuse it. An `allowPrivateAddress` opt-out is coming in 2.4.0. Current patched releases are 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2. The GitHub Security Advisory is GHSA-hqph-j65v-8cq5, and the CVE ID is CVE-2026-62857. Update `@fedify/fedify`: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify After updating, redeploy. If you run other Fedify-based servers, update those too. Thanks to @rvzsec and @manus-use for the report and responsible disclosure. If anything is unclear, ask below.
000
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 01/07/2026
The official account for the Fedify project is moving to @fedify. This account will be replaced by the new one. Followers should automatically follow the new account unless any issues occur.
022
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 29/06/2026
OSSCA 2026 has started, and Fedify is joining for the second year. 24 mentees will work on Fedify, Hollo, BotKit, DrFed, and Feder over the next four months, with some of that work likely to continue after the program ends. OSSCA, the Open Source Software Contribution Academy, is a South Korean […]
hollo.social
Original post on hollo.social
003
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 26/06/2026
### Two new maintainers join Fedify: Chanhaeng Lee and Jiwon Kwon Chanhaeng Lee (@2chanhaeng) and Jiwon Kwon (@z9mb1) are now co-maintainers of Fedify. They have already been doing maintainer-shaped work for much of the past year, so this is mostly making the repository match reality […]
hollo.social
Original post on hollo.social
105
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 24/06/2026
Fedify 2.3.0 is out! This release is largely about production observability: OpenTelemetry metrics now cover every major federation path, and a monitoring guide and runnable example stack ship alongside them. Also new: a delivery circuit breaker that holds queued activities for unreachable […]
hollo.social
Original post on hollo.social
013
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 17/06/2026
DrFed is our sister project, built alongside #Fedify to tackle the debugging side of #ActivityPub development. It just received @nlnet funding and now has its own account here: @drfed. #DrFed #fedidev #fediverse #NLnet RE: hackers.pub/@drfed/019ed3c9-7e8c-78…
hackers.pub
003
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 08/06/2026
### Fedify security updates: 1.9.12, 1.10.11, 2.0.20, 2.1.16, and 2.2.5 If you use Fedify, update to a patched release now. CVE-2026-50131 affects Fedify's public URL validation for remote document and media loading. An attacker could use special-use IP address ranges to bypass Fedify's SSRF […]
hollo.social
Original post on hollo.social
002
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 06/06/2026
There's a Matrix room for #Fedify contributors, open to anyone curious about how development happens. Feel free to drop in or lurk; small questions are fine too. #fedify-contributors:matrix.org
002
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 20/05/2026
### Fedify security updates: 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3 If you use Fedify, update to a patched release now. CVE-2026-42462 affects Fedify's Linked Data Signature handling. An attacker could use JSON-LD graph-restructuring features to change how a signed activity is interpreted […]
hollo.social
Original post on hollo.social
027
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 19/05/2026
日本で世界初のFedifyの書籍「実践Fedify——ActivityPubマイクロブログ開発入門」が出版されました。この本は私にとって初めての著書でもありますが、最初の本が母語の韓国語ではなく日本語だというのは、なんだかとても不思議な気分ですね。本書は、英語で書かれたFedifyの公式チュートリアル「Creating your own federated microblog」をベースに、様々な加筆を行ったものです。Fedifyのマスコットの恐竜と、Misskeyのマスコットである三須木みすき 藍あい、Mastodon […] [Original post on hollo.social]
インプレス NextPublishing刊、洪 民憙(ホン・ミンヒ)著「実践Fedify——ActivityPubマイクロブログ開発入門」の表紙。セーラー服を着たMisskeyの猫耳マスコット・藍ちゃんが、Fedifyの青い恐竜マスコットとMastodonの黄色い象マスコットの上でジャンプしながら指を差しており、周囲にはカラフルな星や幾何学模様が散りばめられている。
111
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 19/05/2026
The world's first Fedify book, Practical Fedify: Introduction to ActivityPub Microblog Development (実践Fedify——ActivityPubマイクロブログ開発入門), has been published in Japan. This is also the first book I have ever published, and it feels quite surreal that my first book […] [Original post on hollo.social]
Cover of Practical Fedify: Introduction to ActivityPub Microblog Development (実践Fedify——ActivityPubマイクロブログ開発入門) by Hong Minhee (洪 民憙), published by Impress NextPublishing. Ai-chan, Misskey's cat-eared mascot in a sailor uniform, jumps and points upward above Fedify's blue dinosaur mascot and Mastodon's small golden mascot, with colorful stars and geometric shapes scattered around.
328
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 10/05/2026
### Fedify security updates: 1.9.10, 1.10.9, 2.0.16, 2.1.12, and 2.2.1 If you use Fedify, update to a patched release now. A private network protection bypass affects Fedify's remote document loading code. URLs with private IPv4 addresses encoded as IPv4-mapped IPv6 literals, such as `http://[ […]
hollo.social
Original post on hollo.social
011
Reposted by Fedify: ActivityPub server framework
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 28/04/2026
Fedify 2.2.0 is out! This release finally adds client-to-server (C2S) outbox listener support, proper HTTP `410 Gone` responses for deleted actors via `Tombstone`, new integrations for SolidStart and Nuxt, and interoperability fixes for Lemmy and Pixelfed. Three new end-to-end tutorials also […]
hollo.social
Original post on hollo.social
008
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 28/04/2026
Fedify 2.2.0 is out! This release finally adds client-to-server (C2S) outbox listener support, proper HTTP `410 Gone` responses for deleted actors via `Tombstone`, new integrations for SolidStart and Nuxt, and interoperability fixes for Lemmy and Pixelfed. Three new end-to-end tutorials also […]
hollo.social
Original post on hollo.social
008
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 27/04/2026
Unless something comes up, #Fedify 2.2.0 will be released today.
021
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 23/04/2026
If you'd like to preview the #tutorial I'm writing on building a small #threadiverse software with #Fedify, here it is: pr-710.fedify.pages.dev/tutorial/th… If you'd like to give feedback after reading it, please leave a comment on the following PR […]
hollo.social
Original post on hollo.social
003
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 20/04/2026
The official Awesome Fedify site is now live: awesome.fedify.dev It brings together real-world Fedify projects, packages, examples, tutorials, and talks in one place. If you know a good resource we should list, contributions are welcome: github.com/fedify-dev/awesome-fedify
awesome.fedify.dev
Awesome Fedify
A curated directory of Fedify projects, packages, examples, tutorials, and talks.
022
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 19/04/2026
We're working on a new #tutorial for #Fedify: _Building a Federated Blog with Astro_! It walks you through creating a hybrid blog—static Markdown posts powered by #Astro content collections, with #ActivityPub federation layered on top. By the end, your blog will be followable from Mastodon […]
hollo.social
Original post on hollo.social
0110
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 19/04/2026
Naru, the Korean version of #Neocities, reportedly added an #ActivityPub implementation in just an hour using #Fedify. If you also want to implement ActivityPub quickly, give Fedify a try! hackers.pub/@jihyeok/019da3d9-45b8-…
hackers.pub
2417
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 08/04/2026
Significant performance improvements are expected in today's latest Fedify patch releases (v1.9.9, v1.10.8, v2.0.12, and v2.1.5).
012
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 04/04/2026
### Fedify security updates: 1.9.7, 1.10.6, 2.0.10, and 2.1.3 If you use Fedify, update to a patched release now. A high-severity denial-of-service vulnerability (CVE-2026-34148) affects Fedify's remote document loader and authenticated document loader. Both follow HTTP redirects without a […]
hollo.social
Original post on hollo.social
036
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 24/03/2026
Fedify 2.1.0 is out! The highlight of this release is `onUnverifiedActivity()`, a long-requested hook that lets you intercept inbound activities whose signatures couldn't be verified, instead of silently returning 401 and letting remote servers retry forever. Great for handling `Delete` […]
hollo.social
Original post on hollo.social
017
Reposted by Fedify: ActivityPub server framework
Julian Fietkau @fietkau.me · 10/03/2026
Seems as good a day as any to thank @hongminhee and team for the exemplary work on @fedify. Following Fedify's big 2.0 release, my two largest interoperability pain points in @encyclia can be fixed. 🙂 github.com/fedify-dev/fedify/issues… means that people using @gotosocial will […]
fietkau.social
Original post on fietkau.social
005
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 27/02/2026
Jiwon (@z9mb1), one of our core contributors, drew a Fedify dino! How cute! oeee.cafe/@z9mb1/2b5b0baf-466b-4c65…
oeee.cafe
023
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 27/02/2026
Started laying out a rough plan for implementing FEP-ef61: Portable Objects in #Fedify—server-independent #ActivityPub identities backed by #DIDs, multi-server replication, and client-side signing. It's going to be a long road (13 tasks across 5 phases, with a few open questions that need […]
hollo.social
Original post on hollo.social
2212
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 22/02/2026
Hi #fediverse and #ActivityPub developers! I'm currently working on interoperability testing for #Hollo and #Fedify, and I need a #Bonfire account to test federation with their implementation. Since there aren't many open public Bonfire instances available, I was wondering if any Bonfire […]
hollo.social
Original post on hollo.social
0317
Reposted by Fedify: ActivityPub server framework
Julian Fietkau @fietkau.me · 22/02/2026
@fedify That is one juicy changelog! 🤩 Makes me want to jump into upgrading @encyclia, especially after we postponed the Fresh 2.x integration. But it sounds like that's going to be a bit of an adventure, so I'll wait until I can set an afternoon aside for it.
012
Reposted by Fedify: ActivityPub server framework
Emelia @thisismissem.social · 22/02/2026
The really cool thing about this new architecture is that it can enable Client to Server architecture for AP with fedify (maybe vocab packages could be used in the browser too!)
195
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 22/02/2026
**Fedify 2.0.0 is here!** This is the biggest release in Fedify's history. Here are the highlights: * **Modular architecture** — The monolithic `@fedify/fedify` package has been broken up into focused, independent packages: `@fedify/vocab`, `@fedify/vocab-runtime`, `@fedify/vocab-tools` […]
hollo.social
Original post on hollo.social
3629
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 19/02/2026
We're gradually moving our community from Discord to Matrix. The maintainers and contributors are already there, so you'll get faster responses on Matrix going forward. Discord will stay up for a while, but Matrix is now our primary home. For the full details and the list of Matrix rooms, see […]
hollo.social
Original post on hollo.social
258
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 14/02/2026
We have only 4 issues left until the Fedify 2.0 milestone!
The Fedify 2.0 milestone which consists of 4 issues left.
126
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 12/02/2026
Fedify 2.0 will probably be out by the end of February. No, it has to be.
011
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 11/02/2026
Sneak peak.
Traces list page of the debug dashboardTrace detail page showing activities and logs
002
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 11/02/2026
Working on `@fedify/debugger`, an embedded ActivityPub debug dashboard for Fedify applications. It will be shipped with Fedify 2.0. github.com/fedify-dev/fedify/pull/5…
github.com
`@fedify/debugger`: Embedded ActivityPub debug dashboard by dahlia · Pull Request #564 · fedify-dev/fedify
Summary Closes #561 Adds a new @fedify/debugger package that provides an embedded real-time ActivityPub debug dashboard. It works as a proxy implementing the Federation interface, wrapping the orig...
102
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 10/02/2026
Just created a Matrix room for Fedify contributors: #fedify-contributors:matrix.org. If you'd like to contribute to Fedify or wonder how Fedify internals are going on please join there!
011
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 09/02/2026
Did you know there's a community space for #Fedify, #Hollo, #BotKit, and other Fedify ecosystem projects? Whether you have questions, want to share what you're building, or just want to hang out with fellow fediverse developers—come join us! * Matrix: #fedify:matrix.org * Discord
104
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 07/02/2026
Recently, @moreal built _ap-thread-reader_ , a tool that displays threaded posts on a single page. Works with any ActivityPub platform, not just Mastodon. Try it at ap-thread-reader.fly.dev. Built with Fedify and released as open source: github.com/moreal/ap-thread-reader […]
hollo.social
Original post on hollo.social
002
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 03/02/2026
It was great to see fantastic people at @offline today, and thank you for listening my talk! If you'd like to get my deck, here it is: _Fedify: Building ActivityPub servers without the pain_. Huge thanks @liaizon for organizing this event!
128
Reposted by Fedify: ActivityPub server framework
wakest ⁂ @fedi.wake.st · 31/01/2026
@fedify abstracts away complexity in building for the fediverse
115
Reposted by Fedify: ActivityPub server framework
wakest ⁂ @fedi.wake.st · 31/01/2026
Now we have @hongminhee presenting @fedify!
124
Reposted by Fedify: ActivityPub server framework
@reiver ⊼ (Charles) :batman: @reiver.mastodon.social.ap.brid.gy · 31/01/2026
Slides from @hongminhee talking about @fedify #Fediverse #FOSDEM #FOSDEM2026 #SocialWeb #SocialWebFOSDEM #SocialWebFOSDEM2026
003
Reposted by Fedify: ActivityPub server framework
@reiver ⊼ (Charles) :batman: @reiver.mastodon.social.ap.brid.gy · 31/01/2026
Up next is @hongminhee talking about Fedify #Fediverse #FOSDEM #FOSDEM2026 #SocialWeb #SocialWebFOSDEM #SocialWebFOSDEM2026
115
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 24/01/2026
We've published an AI usage policy for the Fedify project, inspired by Ghostty's approach. TL;DR: AI tools are welcome, but contributions must disclose AI usage, be tied to accepted issues, and be human-verified. Maintainers are exempt. github.com/fedify-dev/fedify/blob/m…
github.com
fedify/AI_POLICY.md at main · fedify-dev/fedify
ActivityPub server framework in TypeScript. Contribute to fedify-dev/fedify development by creating an account on GitHub.
002