Sign in

Fedify: ActivityPub server framework

@fedify.hollo.social.ap.brid.gy
50 followers 0 following 135 posts

:fedify: Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards, so-called fediverse. It aims to eliminate the […] 🌉 bridged from ⁂ hollo.social/@fedify, follow @ap.brid.gy to interact

PostsRepliesMedia
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 04/10/2026
hackers.pub
Fedify security updates: 2.0.30, 2.1.26, 2.2.15, 2.3.10, and 2.4.0
Two vulnerabilities have been fixed: GHSA-97w4-f4rq-mgqm, unbounded alternate-document fetch chains vulnerability and GHSA-39gj-rchc-q5m3, unverified activity routed after dereference verification vulnerability. The patched releases are 2.0.30, 2.1.26, 2.2.15, 2.3.10, and 2.4.0. Both vulnerabilities affect the preceding releases on those lines: 2.0.28 and 2.0.29, 2.1.24 and 2.1.25, 2.2.13 and 2.2.14, 2.3.8 and 2.3.9. If you still use Fedify 1.x, change your dependency to patched 2.x release because package-manager update commands do not cross the declared major-version range. ## Unbounded alternate-document fetch chains (GHSA-97w4-f4rq-mgqm, high, CVSS 7.5) GHSA-97w4-f4rq-mgqm affects Fedify's document loaders when fetching remote keys and ActivityPub documents. Fedify follows alternate-document links supplied through HTTP `Link` headers and HTML, but following an alternate document reset the redirect counter and visited-URL history. An attacker could therefore make two URLs refer to each other as alternate documents and cause Fedify to fetch them indefinitely. Following an alternate link also dropped the caller's cancellation signal, so aborting the original operation did not stop the fetch chain. An unauthenticated inbox request could exploit this by referencing an attacker-controlled signing-key URL. Resolving the key could then enter an unbounded alternate-document chain, continuously issuing HTTP requests and DNS lookups and eventually exhausting server resources. Both `getDocumentLoader()` and `getAuthenticatedDocumentLoader()` were affected, including their use in `@fedify/vocab-runtime` and `@fedify/fedify`. The fix makes alternate-document links and ordinary HTTP redirects share the same 20-hop limit and visited-URL history. It also preserves the caller's cancellation signal throughout the entire fetch chain. This closes a gap left by the earlier redirect-loop fix for CVE-2026-34148. ## Unverified activity routed after dereference verification (GHSA-39gj-rchc-q5m3, medium, CVSS 6.5) GHSA-39gj-rchc-q5m3 has been present since `Context.routeActivity()` was introduced in Fedify 1.3.0. `Context.routeActivity()` verifies an activity before passing it to inbox listeners. When an activity has no verifiable Object Integrity Proof, Fedify dereferences its `id` and verifies the fetched copy. However, only the Activity object was replaced with the verified copy; the original, unverified JSON-LD document supplied by the caller was retained. With an inbox queue configured, that unverified document was enqueued and later delivered to inbox listeners without being verified again. An attacker who knew the ID of any dereferenceable activity could therefore submit a document with the same ID but an actor, object, and addressing of their choice, causing the application to process attacker-controlled data as authenticated. Without a queue, listeners received the verified Activity object, but their `InboxContext` still contained the unverified document, which `InboxContext.forwardActivity()` could forward to other servers. Applications that never call `Context.routeActivity()` are not affected. Activities successfully authenticated using an Object Integrity Proof are also unaffected, as is the HTTP inbox, which does not use this routing path. The fix replaces both the Activity object and its JSON-LD document with the verified copy when `Context.routeActivity()` falls back to dereferencing. Inbox queues, `InboxContext`, and forwarding therefore all operate on the same document that was actually authenticated. ## Updating Update `@fedify/fedify`: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify Check if your resolved dependency versions are at least 2.0.30, 2.1.26, 2.2.15, 2.3.10, or 2.4.0 on the corresponding release line. Please redeploy every Fedify-based servers, after updating. The full Github Security Advisories are GHSA-97w4-f4rq-mgqmand GHSA-39gj-rchc-q5m3. Thanks to @adelzaitri for reporting unverified activity is routed after dereference verification issue. Ask below if anything is unclear.
000
Reposted by Fedify: ActivityPub server framework
Jiwon @z9mb1.hackers.pub.ap.brid.gy · 01/10/2026
First big release after I joined as a maintainer probably. Patch releases, feature implementations, bug fixes, and lots of code reviews. Thanks, every contributors!! RE: hackers.pub/@fedify/2026/fedify-2-4
hackers.pub
034
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 01/10/2026
A Chinese developer, @21018365486, wrote about adding ActivityPub to her blog using Fedify. Thank you for using Fedify! blog.yunyi.beiyan.us/posts/migrateT…
blog.yunyi.beiyan.us
004
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 27/09/2026
hackers.pub
Fedify security updates: 2.0.28, 2.1.24, 2.2.13, and 2.3.8
If you use an affected Fedify release, update now. Three vulnerabilities have been fixed: CVE-2026-96625, a critical actor impersonation vulnerability; CVE-2026-96623, a high-severity denial-of-service vulnerability in remote document parsing; and CVE-2026-96624, a medium-severity server-side request forgery vulnerability in outbound activity delivery. Treat the actor impersonation issue as an immediate upgrade: anyone on the internet could have an activity accepted by your inbox as coming from any actor. The patched releases are 2.0.28, 2.1.24, 2.2.13, and 2.3.8. All three vulnerabilities affect the preceding releases on those lines: 2.0.27, 2.1.23, 2.2.12, and 2.3.7, respectively. If you still use Fedify 1.x, change your dependency to a patched 2.x release because package-manager update commands do not cross the declared major-version range. ## Actor impersonation (CVE-2026-96625, critical, CVSS 9.1) CVE-2026-96625 has been present since Fedify's first public release, 0.1.0. Fedify verified the signature on an incoming activity, but trusted the signing key document's own claim about whom the key belonged to. An attacker with an ordinary HTTP server could serve a key document naming any actor as its owner and have activities accepted under that actor's identity, even if the actor did not exist. No account on the receiving server was required. HTTP Signatures, Linked Data Signatures, and Object Integrity Proofs were all affected; the latter two did not require an HTTP signature on the request. The same vulnerability affected `getKeyOwner()` and `Context.getSignedKeyOwner()`. A forged key document could pass ownership checks under another actor's identity, allowing an attacker to read resources that an application's authorized fetch access control reserved for that actor. The fix resolves the claimed owner's actor document and requires it to link back to the key. It also validates the origin of fetched actor documents, so a host serving a key cannot speak for an actor on another origin. A key without an explicit owner is attributed to the actor whose document carried it. Public keys cached before this release recorded ownership that had not been verified. Fedify's built-in key cache automatically stops reading those entries. If you pass a custom `KeyCache` implementation to `verifyRequest()`, `verifyJsonLd()`, or `verifyObject()`, discard its contents when you upgrade. A patched process reading a stale entry from a custom cache would still trust the unverified owner in it. ## Unbounded document parsing (CVE-2026-96623, high, CVSS 7.5) CVE-2026-96623 affects deployments that accept inbox requests or fetch remote documents. Fedify parsed JSON bodies without a byte limit, including inbox bodies and responses fetched for keys, actors, objects, JSON-LD contexts, WebFinger descriptors, and NodeInfo documents. An attacker who caused Fedify to fetch a URL they controlled could exhaust memory and CPU with a large response. A small compressed response could expand substantially before parsing, so an inbound body limit at a reverse proxy did not protect the outbound fetch paths. The fix limits JSON bodies to 16 MiB after decompression. HTML alternate-link discovery retains its existing 1 MiB limit. Oversized inbox requests receive HTTP 413, and oversized WebFinger descriptors resolve to `null`. The JSON limit is fixed in these patch releases; applications that exchange legitimate JSON-LD documents larger than 16 MiB will now have those documents rejected. The parsing fixes also ship in `@fedify/vocab-runtime` and `@fedify/webfinger`. If you depend on either package directly, update it too. They use the same patched version numbers listed above. ## Outbound delivery SSRF (CVE-2026-96624, medium, CVSS 5.8) CVE-2026-96624 affects applications that deliver activities to inbox URLs learned from remote actors. The delivery path validated neither the advertised inbox URL nor redirect destinations. A remote actor could point its inbox at a loopback address, a link-local metadata service, or a private network host, or redirect delivery there. On the RSA delivery path, the redirected request remained a POST carrying the activity body and was re-signed for the internal host. The vulnerable delivery path dates back to JSR release 0.1.0 and npm release 0.5.0. The fix validates the initial destination and every redirect target before sending a request. The authenticated document-loader fix in CVE-2026-77632 covered a separate fetch path and did not protect outbound activity delivery. If you deliberately deliver to private addresses for local testing or a closed federation, these releases will refuse those deliveries unless you pass `allowPrivateAddress: true` to `createFederation()`. That option permits both private inbox URLs and private redirect targets, restoring the exposure described here. Keep it to environments where you control the actors you federate with. ## Updating Update `@fedify/fedify`: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify Check that your resolved dependency versions are at least 2.0.28, 2.1.24, 2.2.13, or 2.3.8 on the corresponding release line. Update any direct dependencies on `@fedify/vocab-runtime` and `@fedify/webfinger` as well, and clear any custom key cache as described above. After updating, redeploy. If you run other Fedify-based servers, update those too. The full GitHub Security Advisories are CVE-2026-96625, CVE-2026-96623, and CVE-2026-96624. Thanks to @kaimandalic and @moreal for independently reporting the actor impersonation issue. Thanks also to @kaimandalic for the unbounded document parsing report and @euriconicacio for the outbound delivery SSRF report, and to all three for responsible disclosure. If anything is unclear, ask below.
000
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 04/09/2026
今週(금주) 日曜日(일요일)(6日(일))에 瑞草驛(서초역) 近處(근처)에 位置(위치)한 오픈업 센터(네이버地圖, 카카오맵)에서 @fedify 寄與(기여)를 爲(위)한 모임이 열립니다. 午前(오전) 10時(시)에서 午後(오후) 6時(시)까지 進行(진행)되니, 關心(관심) 있는 분들은 自由(자유)롭게 오셔서 參與(참여) 바랍니다! (10時(시)에서 18時(시) 사이에 아무 때나 오셔서 아무 때나 가셔도 됩니다!)
map.naver.com
013
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 28/08/2026
日本語で書かれたFedifyの紹介記事が掲載されたんですね。ありがとうございます。 easegis.jp/blog/fedify
easegis.jp
ActivityPubの仕様書を読まなくても、FedifyでMastodon連携ができる
HTTP署名やWebFingerなどActivityPub実装の面倒な部分を肩代わりしてくれるTypeScript製フェデレーションフレームワーク、Fedifyの特徴からインストール、実践的な使い方までを解説します。
022
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 26/08/2026
hackers.pub
Fedify security updates: 2.0.26, 2.1.22, 2.2.11, and 2.3.6
If you use an affected Fedify release, update now. Two vulnerabilities have been fixed in `@fedify/fedify`: CVE-2026-77632, a high-severity server-side request forgery vulnerability in the authenticated document loader, and CVE-2026-69132, a medium-severity denial-of-service vulnerability in the outbound delivery circuit breaker. CVE-2026-77632 affects versions 1.6.1 through 2.3.4. Fedify uses an authenticated document loader when it fetches remote documents such as actors and public keys with a signed HTTP request. Affected versions checked that the initial URL was public, but did not apply the same check when that URL returned an HTTP redirect. An attacker who controlled the public URL could redirect the signed request to a loopback address, a link-local metadata service, or an RFC 1918 host. In the ordinary inbox path, Fedify may fetch a signature's `keyId` before it can verify the signature, so a bogus signature is enough to reach this path. The demonstrated attack is blind SSRF: the internal response is consumed while resolving the remote document and is not automatically returned to the attacker. The fix validates every redirect target before it is fetched. The existing `allowPrivateAddress` option still permits private destinations when an application explicitly opts in, such as for a closed federation or test environment. CVE-2026-69132 affects versions 2.3.0 through 2.3.4. Fedify 2.3 introduced an outbound delivery circuit breaker that records failures in the configured key–value store, using the remote inbox's `host:port` as part of the key. An attacker could send signed `Follow` activities from actors whose inbox URLs pointed to distinct ports where delivery would fail. Each failure created a separate record, allowing the attacker to grow circuit-breaker state until storage or memory was exhausted. Versions 2.3.0 and 2.3.1 were vulnerable with every circuit-breaker configuration. In versions 2.3.2 through 2.3.4, the vulnerable configuration was a custom `failure` policy without an explicit `stateTtl`. The fix gives custom failure policies a bounded default `stateTtl`, equal to `recoveryDelay` plus `heldActivityTtl` (7 days 30 minutes with the default values). On stores that support compare-and-set operations, Fedify also sweeps circuit-breaker state left by affected releases and stamps it with a TTL. Applications that need a different retention period for a custom failure policy can continue to set `stateTtl` explicitly. The SSRF fix first appeared in 2.0.25, 2.1.21, 2.2.10, and 2.3.5; the circuit-breaker fix first appeared in 2.3.5. The current releases on those lines are 2.0.26, 2.1.22, 2.2.11, and 2.3.6, and those are the versions we recommend installing. The circuit-breaker issue only affects the 2.3 line; the authenticated document-loader issue affects every Fedify release from 1.6.1 through 2.3.4. If you still use Fedify 1.x, change your dependency to a current 2.x release because package-manager update commands do not cross the declared major-version range. The GitHub Security Advisories are GHSA-cxc3-7q96-6cpx and GHSA-fx98-wc5v-jrg5. Update `@fedify/fedify`: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify After updating, redeploy. If you run other Fedify-based servers, update those too. Thanks to Jace and @nyanrus for the reports and responsible disclosure. If anything is unclear, ask below.
000
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 18/07/2026
hackers.pub
Fedify security updates: 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2
If you use Fedify, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client. An attacker who runs any instance your server looks up could cause that server to fetch non-public network destinations and return their contents to your application, depending on the deployment environment and network routing. Fedify can look up a remote instance's NodeInfo document to learn what software it runs. The lookup happens in two steps: it fetches the instance's `/.well-known/nodeinfo` document, then follows the NodeInfo document URL that response advertises. The vulnerable path is `getNodeInfo()`, along with the `Context.lookupNodeInfo()` method that wraps it: affected versions sent both requests without validating the destination against public-network expectations. Because that second URL comes straight out of the remote server's response body, the instance being looked up fully controls it, and could point it at a loopback address, a link-local metadata endpoint, an RFC 1918 host, or a `data:` URL. Servers are exposed only if they look up NodeInfo, but that lookup is routine for peer discovery and instance metadata. The fix routes both requests through the same public-address validation Fedify already applied to WebFinger lookups and remote document loading. Every request is now checked before it is sent, including each redirect hop, so a public URL cannot bounce a request to an internal address. Redirects are followed with a cap and are refused if they cross protocols, and non-HTTP(S) URLs such as `data:` are rejected outright. These are patch releases, so they tighten behavior without adding new API. If you deliberately look up NodeInfo on a private or intranet address, such as in a closed federation or a test environment, these releases will now refuse it. An `allowPrivateAddress` opt-out is coming in 2.4.0. Current patched releases are 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2. The GitHub Security Advisory is GHSA-hqph-j65v-8cq5, and the CVE ID is CVE-2026-62857. Update `@fedify/fedify`: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify After updating, redeploy. If you run other Fedify-based servers, update those too. Thanks to @rvzsec and @manus-use for the report and responsible disclosure. If anything is unclear, ask below.
000
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 01/07/2026
The official account for the Fedify project is moving to @fedify. This account will be replaced by the new one. Followers should automatically follow the new account unless any issues occur.
022
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 29/06/2026
OSSCA 2026 has started, and Fedify is joining for the second year. 24 mentees will work on Fedify, Hollo, BotKit, DrFed, and Feder over the next four months, with some of that work likely to continue after the program ends. OSSCA, the Open Source Software Contribution Academy, is a South Korean […]
hollo.social
Original post on hollo.social
003
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 26/06/2026
### Two new maintainers join Fedify: Chanhaeng Lee and Jiwon Kwon Chanhaeng Lee (@2chanhaeng) and Jiwon Kwon (@z9mb1) are now co-maintainers of Fedify. They have already been doing maintainer-shaped work for much of the past year, so this is mostly making the repository match reality […]
hollo.social
Original post on hollo.social
105
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 24/06/2026
Fedify 2.3.0 is out! This release is largely about production observability: OpenTelemetry metrics now cover every major federation path, and a monitoring guide and runnable example stack ship alongside them. Also new: a delivery circuit breaker that holds queued activities for unreachable […]
hollo.social
Original post on hollo.social
013
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 17/06/2026
DrFed is our sister project, built alongside #Fedify to tackle the debugging side of #ActivityPub development. It just received @nlnet funding and now has its own account here: @drfed. #DrFed #fedidev #fediverse #NLnet RE: hackers.pub/@drfed/019ed3c9-7e8c-78…
hackers.pub
003
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 08/06/2026
### Fedify security updates: 1.9.12, 1.10.11, 2.0.20, 2.1.16, and 2.2.5 If you use Fedify, update to a patched release now. CVE-2026-50131 affects Fedify's public URL validation for remote document and media loading. An attacker could use special-use IP address ranges to bypass Fedify's SSRF […]
hollo.social
Original post on hollo.social
002
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 06/06/2026
There's a Matrix room for #Fedify contributors, open to anyone curious about how development happens. Feel free to drop in or lurk; small questions are fine too. #fedify-contributors:matrix.org
002
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 20/05/2026
### Fedify security updates: 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3 If you use Fedify, update to a patched release now. CVE-2026-42462 affects Fedify's Linked Data Signature handling. An attacker could use JSON-LD graph-restructuring features to change how a signed activity is interpreted […]
hollo.social
Original post on hollo.social
027
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 19/05/2026
日本で世界初のFedifyの書籍「実践Fedify——ActivityPubマイクロブログ開発入門」が出版されました。この本は私にとって初めての著書でもありますが、最初の本が母語の韓国語ではなく日本語だというのは、なんだかとても不思議な気分ですね。本書は、英語で書かれたFedifyの公式チュートリアル「Creating your own federated microblog」をベースに、様々な加筆を行ったものです。Fedifyのマスコットの恐竜と、Misskeyのマスコットである三須木みすき 藍あい、Mastodon […] [Original post on hollo.social]
インプレス NextPublishing刊、洪 民憙(ホン・ミンヒ)著「実践Fedify——ActivityPubマイクロブログ開発入門」の表紙。セーラー服を着たMisskeyの猫耳マスコット・藍ちゃんが、Fedifyの青い恐竜マスコットとMastodonの黄色い象マスコットの上でジャンプしながら指を差しており、周囲にはカラフルな星や幾何学模様が散りばめられている。
111
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 19/05/2026
The world's first Fedify book, Practical Fedify: Introduction to ActivityPub Microblog Development (実践Fedify——ActivityPubマイクロブログ開発入門), has been published in Japan. This is also the first book I have ever published, and it feels quite surreal that my first book […] [Original post on hollo.social]
Cover of Practical Fedify: Introduction to ActivityPub Microblog Development (実践Fedify——ActivityPubマイクロブログ開発入門) by Hong Minhee (洪 民憙), published by Impress NextPublishing. Ai-chan, Misskey's cat-eared mascot in a sailor uniform, jumps and points upward above Fedify's blue dinosaur mascot and Mastodon's small golden mascot, with colorful stars and geometric shapes scattered around.
328
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 10/05/2026
### Fedify security updates: 1.9.10, 1.10.9, 2.0.16, 2.1.12, and 2.2.1 If you use Fedify, update to a patched release now. A private network protection bypass affects Fedify's remote document loading code. URLs with private IPv4 addresses encoded as IPv4-mapped IPv6 literals, such as `http://[ […]
hollo.social
Original post on hollo.social
011
Reposted by Fedify: ActivityPub server framework
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 28/04/2026
Fedify 2.2.0 is out! This release finally adds client-to-server (C2S) outbox listener support, proper HTTP `410 Gone` responses for deleted actors via `Tombstone`, new integrations for SolidStart and Nuxt, and interoperability fixes for Lemmy and Pixelfed. Three new end-to-end tutorials also […]
hollo.social
Original post on hollo.social
008
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 28/04/2026
Fedify 2.2.0 is out! This release finally adds client-to-server (C2S) outbox listener support, proper HTTP `410 Gone` responses for deleted actors via `Tombstone`, new integrations for SolidStart and Nuxt, and interoperability fixes for Lemmy and Pixelfed. Three new end-to-end tutorials also […]
hollo.social
Original post on hollo.social
008
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 27/04/2026
Unless something comes up, #Fedify 2.2.0 will be released today.
021
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 23/04/2026
If you'd like to preview the #tutorial I'm writing on building a small #threadiverse software with #Fedify, here it is: pr-710.fedify.pages.dev/tutorial/th… If you'd like to give feedback after reading it, please leave a comment on the following PR […]
hollo.social
Original post on hollo.social
003
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 20/04/2026
The official Awesome Fedify site is now live: awesome.fedify.dev It brings together real-world Fedify projects, packages, examples, tutorials, and talks in one place. If you know a good resource we should list, contributions are welcome: github.com/fedify-dev/awesome-fedify
awesome.fedify.dev
Awesome Fedify
A curated directory of Fedify projects, packages, examples, tutorials, and talks.
022
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 19/04/2026
We're working on a new #tutorial for #Fedify: _Building a Federated Blog with Astro_! It walks you through creating a hybrid blog—static Markdown posts powered by #Astro content collections, with #ActivityPub federation layered on top. By the end, your blog will be followable from Mastodon […]
hollo.social
Original post on hollo.social
0110
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 19/04/2026
Naru, the Korean version of #Neocities, reportedly added an #ActivityPub implementation in just an hour using #Fedify. If you also want to implement ActivityPub quickly, give Fedify a try! hackers.pub/@jihyeok/019da3d9-45b8-…
hackers.pub
2417
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 08/04/2026
Significant performance improvements are expected in today's latest Fedify patch releases (v1.9.9, v1.10.8, v2.0.12, and v2.1.5).
012
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 04/04/2026
### Fedify security updates: 1.9.7, 1.10.6, 2.0.10, and 2.1.3 If you use Fedify, update to a patched release now. A high-severity denial-of-service vulnerability (CVE-2026-34148) affects Fedify's remote document loader and authenticated document loader. Both follow HTTP redirects without a […]
hollo.social
Original post on hollo.social
036
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 24/03/2026
Fedify 2.1.0 is out! The highlight of this release is `onUnverifiedActivity()`, a long-requested hook that lets you intercept inbound activities whose signatures couldn't be verified, instead of silently returning 401 and letting remote servers retry forever. Great for handling `Delete` […]
hollo.social
Original post on hollo.social
017
Reposted by Fedify: ActivityPub server framework
Julian Fietkau @fietkau.me · 10/03/2026
Seems as good a day as any to thank @hongminhee and team for the exemplary work on @fedify. Following Fedify's big 2.0 release, my two largest interoperability pain points in @encyclia can be fixed. 🙂 github.com/fedify-dev/fedify/issues… means that people using @gotosocial will […]
fietkau.social
Original post on fietkau.social
005
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 27/02/2026
Jiwon (@z9mb1), one of our core contributors, drew a Fedify dino! How cute! oeee.cafe/@z9mb1/2b5b0baf-466b-4c65…
oeee.cafe
023
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 27/02/2026
Started laying out a rough plan for implementing FEP-ef61: Portable Objects in #Fedify—server-independent #ActivityPub identities backed by #DIDs, multi-server replication, and client-side signing. It's going to be a long road (13 tasks across 5 phases, with a few open questions that need […]
hollo.social
Original post on hollo.social
2212
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 22/02/2026
Hi #fediverse and #ActivityPub developers! I'm currently working on interoperability testing for #Hollo and #Fedify, and I need a #Bonfire account to test federation with their implementation. Since there aren't many open public Bonfire instances available, I was wondering if any Bonfire […]
hollo.social
Original post on hollo.social
0317
Reposted by Fedify: ActivityPub server framework
Julian Fietkau @fietkau.me · 22/02/2026
@fedify That is one juicy changelog! 🤩 Makes me want to jump into upgrading @encyclia, especially after we postponed the Fresh 2.x integration. But it sounds like that's going to be a bit of an adventure, so I'll wait until I can set an afternoon aside for it.
012
Reposted by Fedify: ActivityPub server framework
Emelia @thisismissem.social · 22/02/2026
The really cool thing about this new architecture is that it can enable Client to Server architecture for AP with fedify (maybe vocab packages could be used in the browser too!)
195
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 22/02/2026
**Fedify 2.0.0をリリースしました!** Fedify史上最大のリリースです。主な変更点をご紹介します: * **モジュラーアーキテクチャ** — これまでのモノリシックな`@fedify/fedify`パッケージを、`@fedify/vocab`、`@fedify/vocab-runtime`、`@fedify/vocab-tools`、`@fedify/webfinger`など、独立したパッケージに分割しました。バンドルサイズの削減、インポートの整理に加え、カスタム語彙型によるActivityPubの拡張も可能になりました。 * **リアルタイムデバッグダッ […]
hollo.social
Original post on hollo.social
013
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 22/02/2026
**Fedify 2.0.0을 릴리스했습니다!** Fedify 역사상 가장 큰 릴리스입니다. 주요 변경 사항을 소개합니다: * **모듈형 아키텍처** — 기존의 단일 `@fedify/fedify` 패키지를 `@fedify/vocab`, `@fedify/vocab-runtime`, `@fedify/vocab-tools`, `@fedify/webfinger` 등 독립적인 패키지들로 분리했습니다. 번들 크기가 줄어들고, 임포트가 깔끔해지며, 커스텀 어휘 타입으로 ActivityPub을 확장할 수도 있습니다. * **실시간 […]
hollo.social
Original post on hollo.social
116
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 22/02/2026
**Fedify 2.0.0 is here!** This is the biggest release in Fedify's history. Here are the highlights: * **Modular architecture** — The monolithic `@fedify/fedify` package has been broken up into focused, independent packages: `@fedify/vocab`, `@fedify/vocab-runtime`, `@fedify/vocab-tools` […]
hollo.social
Original post on hollo.social
3629
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 19/02/2026
コミュニティをDiscordからMatrixへ段階的に移行しています。メンテナーとコントリビューターはすでにMatrixに移っているため、今後はMatrixのほうが返答が早くなります。Discordはしばらく継続しますが、Matrixがメインの場となりました。 詳細とMatrixルームの一覧はこちら:https://github.com/fedify-dev/fedify/discussions/573(英文)
github.com
We're moving our community to Matrix · fedify-dev fedify · Discussion #573
Discord recently announced that it will be introducing mandatory age verification for all users. As the EFF has noted, this raises serious privacy concerns, especially given a recent data breach—th...
032
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 19/02/2026
저희 커뮤니티를 Discord에서 Matrix로 조금씩 이전하고 있습니다. 메인테이너와 기여자들은 이미 Matrix로 옮긴 상태라, 앞으로는 Matrix 쪽이 응답이 더 빠를 거예요. Discord는 당분간 유지되지만, Matrix가 이제 메인 거점입니다. 자세한 내용과 Matrix 룸 목록은 여기서 확인하세요: github.com/fedify-dev/fedify/discus….
github.com
We're moving our community to Matrix · fedify-dev fedify · Discussion #573
Discord recently announced that it will be introducing mandatory age verification for all users. As the EFF has noted, this raises serious privacy concerns, especially given a recent data breach—th...
101
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 19/02/2026
We're gradually moving our community from Discord to Matrix. The maintainers and contributors are already there, so you'll get faster responses on Matrix going forward. Discord will stay up for a while, but Matrix is now our primary home. For the full details and the list of Matrix rooms, see […]
hollo.social
Original post on hollo.social
258
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 14/02/2026
We have only 4 issues left until the Fedify 2.0 milestone!
The Fedify 2.0 milestone which consists of 4 issues left.
126
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 12/02/2026
Fedify 2.0 will probably be out by the end of February. No, it has to be.
011
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 11/02/2026
Sneak peak.
Traces list page of the debug dashboardTrace detail page showing activities and logs
002
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 11/02/2026
Working on `@fedify/debugger`, an embedded ActivityPub debug dashboard for Fedify applications. It will be shipped with Fedify 2.0. github.com/fedify-dev/fedify/pull/5…
github.com
`@fedify/debugger`: Embedded ActivityPub debug dashboard by dahlia · Pull Request #564 · fedify-dev/fedify
Summary Closes #561 Adds a new @fedify/debugger package that provides an embedded real-time ActivityPub debug dashboard. It works as a proxy implementing the Federation interface, wrapping the orig...
102
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 10/02/2026
Just created a Matrix room for Fedify contributors: #fedify-contributors:matrix.org. If you'd like to contribute to Fedify or wonder how Fedify internals are going on please join there!
011
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 09/02/2026
Did you know there's a community space for #Fedify, #Hollo, #BotKit, and other Fedify ecosystem projects? Whether you have questions, want to share what you're building, or just want to hang out with fellow fediverse developers—come join us! * Matrix: #fedify:matrix.org * Discord
104
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 07/02/2026
Recently, @moreal built _ap-thread-reader_ , a tool that displays threaded posts on a single page. Works with any ActivityPub platform, not just Mastodon. Try it at ap-thread-reader.fly.dev. Built with Fedify and released as open source: github.com/moreal/ap-thread-reader […]
hollo.social
Original post on hollo.social
002
Reposted by Fedify: ActivityPub server framework
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 03/02/2026
It was great to see fantastic people at @offline today, and thank you for listening my talk! If you'd like to get my deck, here it is: _Fedify: Building ActivityPub servers without the pain_. Huge thanks @liaizon for organizing this event!
128