Sign in

Hollo :hollo:

@hollo.hollo.social.ap.brid.gy
16 followers 0 following 76 posts

:hollo: A federated single-user microblogging software. [bridged from hollo.social/@hollo on the fediverse by fed.brid.gy ]

PostsRepliesMedia
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 27/09/2026
### Hollo security updates: 0.8.12 and 0.9.19 If you run Hollo, update to a patched release now. Fedify has disclosed three vulnerabilities that affect Hollo: CVE-2026-96625, a critical actor impersonation vulnerability; CVE-2026-96623, a high-severity denial-of-service vulnerability in remote […]
hollo.social
Original post on hollo.social
005
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 26/08/2026
### Hollo security updates: 0.8.11 and 0.9.14 If you run Hollo, update to a current patched release now. Fedify has disclosed two vulnerabilities, one of which affects Hollo: CVE-2026-77632, a high-severity server-side request forgery vulnerability in Fedify's authenticated document loader […]
hollo.social
Original post on hollo.social
002
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 18/07/2026
### Hollo security updates: 0.8.9 and 0.9.9 If you run Hollo, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client, which Hollo uses to identify the software running on remote ActivityPub servers. A NodeInfo lookup starts by fetching a remote server's `/ […]
hollo.social
Original post on hollo.social
003
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 08/06/2026
### Hollo security updates: 0.7.18, 0.8.7, and 0.9.4 If you run Hollo, update to a patched release now. CVE-2026-50131 affects Fedify's SSRF protection, and Hollo depends on Fedify for ActivityPub federation. Fedify guards against SSRF (Server-Side Request Forgery) when fetching remote […]
hollo.social
Original post on hollo.social
002
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 20/05/2026
### Hollo security updates: 0.7.17, 0.8.6, and 0.9.1 If you run Hollo, update to a patched release now. CVE-2026-42462 affects Fedify's Linked Data Signature handling, and Hollo depends on Fedify for ActivityPub federation. Fedify verifies incoming ActivityPub activities with several […]
hollo.social
Original post on hollo.social
001
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 20/05/2026
Hollo 0.9.0 is out. github.com/fedify-dev/hollo/discuss… The biggest change this release is a complete redesign of every server-rendered page. Pico CSS is replaced by a new design system built on UnoCSS, and your chosen theme color now tints your […] [Original post on hollo.social]
Public profile for 洪 民憙 (Hong Minhee) with a bookstore header image, circular avatar, follower and following counts, bio, custom fields including website and GitHub links, and a pinned post card belowThe “Edit @hongminhee” admin page showing the new Hollo design: profile image upload areas for avatar and header, identity fields for display name and bio, custom fields table with label-value pairs, privacy checkboxes, a 20-swatch theme color picker with orange selected, and a “Save changes” button
0110
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 19/05/2026
### Hollo security updates: 0.7.16 and 0.8.5 If you run Hollo, update to a patched release now. Hollo 0.7.16 and 0.8.5 fix several security issues in ActivityPub federation, the web admin UI, OAuth, and the transitive `fast-xml-parser` dependency. On the federation side, three inbox handlers […]
hollo.social
Original post on hollo.social
005
Reposted by Hollo :hollo:
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 15/05/2026
Hollo 0.8.0 shipped less than a month ago, and 0.9.0 is already shaping up to be a bigger release than I expected. New frontend design, Passkey support, WebFinger domain separation, a media proxy, full FEP-044f (Mastodon-style quote posts) compliance, and Traditional Chinese docs. More details […]
hollo.social
Original post on hollo.social
106
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 10/05/2026
### Hollo security updates: 0.7.15 and 0.8.3 If you run Hollo, update to a patched release now. A private network protection bypass in Fedify, the ActivityPub framework Hollo depends on, affects remote document loading. URLs with private IPv4 addresses encoded as IPv4-mapped IPv6 literals, such […]
hollo.social
Original post on hollo.social
006
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 26/04/2026
Hollo 0.8.0 is out. The main additions: you can now run web and worker processes separately via `NODE_TYPE`, which helps on instances with large follower counts where federation load was slowing down API responses. Mastodon clients that support the 4.5 quote post API will now work with Hollo […]
hollo.social
Original post on hollo.social
014
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 21/04/2026
Hollo 0.7.11 is now available and includes an important security update. If you are running an older version, please upgrade to 0.7.11 as soon as possible.
003
Reposted by Hollo :hollo:
NTSK @hl.n.oyasumi.dev · 12/03/2026
なるほどHollo、他人to他人の絵文字リアクションが出るようになったんだ
012
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 24/02/2026
The recent Hollo 0.7.3 and 0.7.4 updates have improved interoperability with #Bonfire. The issue where sending/receiving DMs or mutual following with Bonfire wasn't working properly has been resolved.
github.com
Release Hollo 0.7.3 · fedify-dev/hollo
Released on February 23, 2026. Temporarily changed Fedify's firstKnock setting to draft-cavage-http-signatures-12 for outbound inbox deliveries as a compatibility workaround for Bonfire's current ...
001
Reposted by Hollo :hollo:
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 22/02/2026
Hi #fediverse and #ActivityPub developers! I'm currently working on interoperability testing for #Hollo and #Fedify, and I need a #Bonfire account to test federation with their implementation. Since there aren't many open public Bonfire instances available, I was wondering if any Bonfire […]
hollo.social
Original post on hollo.social
0317
Reposted by Hollo :hollo:
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 09/02/2026
Did you know there's a community space for #Fedify, #Hollo, #BotKit, and other Fedify ecosystem projects? Whether you have questions, want to share what you're building, or just want to hang out with fellow fediverse developers—come join us! * Matrix: #fedify:matrix.org * Discord
104
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 24/01/2026
# Hollo 0.7.0: Advanced search, faster notifications, and improved client compatibility It's been a while since our last release, and we're excited to finally share Hollo 0.7.0 with you. This release brings a lot of improvements that we've been working on over the past months—from powerful new […]
hollo.social
Original post on hollo.social
008
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 23/01/2026
Hollo 0.7.0 will introduce advanced search operators! You'll be able to filter posts using operators like `has:media`, `is:sensitive`, `language:en`, `from:username`, date ranges with `before:` and `after:`, and combine them with `OR` and negation (`-`). For example: `cat has:media -is […]
hollo.social
Original post on hollo.social
014
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 20/12/2025
### Security Update: Hollo 0.6.19 Released We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code. This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability […]
hollo.social
Original post on hollo.social
105
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 15/11/2025
#Hollo 0.7 brings a redesigned #notification system with much better performance. We've moved from generating #notifications on-demand to storing them as they happen, which makes the notifications endpoint about 60% faster. We've also added response compression (though if you're using a reverse […]
hollo.social
Original post on hollo.social
007
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 03/10/2025
### Security update: Hollo 0.6.12 is now available We've released #Hollo 0.6.12 to fix a critical privacy #vulnerability where direct messages were being exposed in the replies section of public posts. Please update your instances immediately to ensure your private conversations remain private […]
hollo.social
Original post on hollo.social
006
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 17/09/2025
Hollo 0.6.11 significantly improves Bluesky interoperability via BridgyFed! Fixed AT Protocol URI parsing issues that were affecting various cross-platform interactions—not just likes, but overall federation with Bluesky users. 🌉
github.com
Like activity not receive from brid.gy · Issue #217 · fedify-dev/hollo
version : Hollo 0.6.10 reproduction procedure Post something on Hollo Once the post is bridged to the bluesky side, add it to your favorites Not receiving like notification on Hollo remarks On Mast...
025
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 08/08/2025
We've released #security updates for #Hollo (0.4.12, 0.5.7, and 0.6.6) to address a #vulnerability in the underlying #Fedify framework. These updates incorporate the latest Fedify security patches that fix CVE-2025-54888. We strongly recommend all Hollo instance administrators update to the […]
hollo.social
Original post on hollo.social
103
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 17/07/2025
🚨 **Security Update:Hollo 0.6.5 Released** We've released #Hollo 0.6.5 with a critical #security fix for CVE-2025-53941, addressing an HTML injection vulnerability in federated posts. **Please#update immediately** to protect your instance from potential phishing and XSS attacks. **How to […]
hollo.social
Original post on hollo.social
105
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 07/07/2025
Just dropped Hollo 0.6.4 with a minor bug fix.
github.com
Release Hollo 0.6.4 · fedify-dev/hollo
Released on July 7, 2025. Fixed a regression bug where follower-only posts were returning 404 Not Found errors when accessed through conversation threads. This was caused by improper OAuth scope ...
012
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 07/06/2025
🚨 **Known Issue** : Elk (@elk) login may fail on Hollo instances upgraded from 0.5.x to 0.6.x with `401 Unauthorized` errors. Fresh 0.6.x installs work fine. Other clients (Phanpy, Moshidon) are unaffected. We're investigating: github.com/fedify-dev/hollo/issues/… Workaround: Use […]
hollo.social
Original post on hollo.social
103
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 05/06/2025
We're excited to announce Hollo 0.6.0, a significant release that brings enhanced security, better user experience, and important infrastructure improvements to your single-user microblogging setup. ## Enhanced OAuth Security with Modern Standards This release prioritizes security with […]
hollo.social
Original post on hollo.social
1013
Reposted by Hollo :hollo:
Emelia 👸🏻 @thisismissem.hachyderm.io.ap.brid.gy · 05/06/2025
@hongminhee something else I'm bringing to @hollo is my experience building with Node.js (which is something like 16 years at this point), but I also get to cross-pollinate ideas between the various projects I work on (e.g., bringing S3 storage to Hollo via the same storage adapter model as […]
hachyderm.io
Original post on hachyderm.io
002
Reposted by Hollo :hollo:
Emelia 👸🏻 @thisismissem.hachyderm.io.ap.brid.gy · 05/06/2025
Oh yeah, this quietly happened the other day: hollo.social/@hollo/01973e37-2969-7…
hollo.social
Exciting news for the #Hollo project! We're thrilled to announce that **Emelia Smith** (@thisismissem) has joined as a co-maintainer alongside Hong Minhee (@hongminhee). Emelia brings extensive experience in the #fediverse ecosystem, having been a long-time contributor to Mastodon and a leading expert in trust & safety tooling for decentralized social networks. She's dedicated years to improving moderation systems and security across #ActivityPub platforms. Her recent contributions to Hollo have been substantial—implementing the reporting/flagging system and making significant improvements to OAuth and security features. These valuable contributions naturally led to her joining as a co-maintainer. This collaboration marks an important milestone for Hollo as we continue building better single-user microblogging software for the fediverse. Welcome aboard, Emelia! 🚀
026
Reposted by Hollo :hollo:
Emelia 👸🏻 @thisismissem.hachyderm.io.ap.brid.gy · 05/06/2025
@hollo @hongminhee happy to be involved! I think I'm probably most pleased with getting the OAuth functionality pretty much 100% covered by tests. At some point, we'll definitely want to integrate test coverage into PR workflows
002
Reposted by Hollo :hollo:
Anuj Ahooja @quillmatiq.mastodon.social.ap.brid.gy · 05/06/2025
@hollo Amazing news 👏🏼 congrats @thisismissem @hongminhee !!
000
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 05/06/2025
Exciting news for the #Hollo project! We're thrilled to announce that **Emelia Smith** (@thisismissem) has joined as a co-maintainer alongside Hong Minhee (@hongminhee). Emelia brings extensive experience in the #fediverse ecosystem, having been a long-time contributor to Mastodon and a leading […]
hollo.social
Original post on hollo.social
3112
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 03/06/2025
#Hollo 0.6.0 is coming soon! We're putting the finishing touches on our biggest security and feature update yet. Here's what's coming: ### Enhanced #OAuth #security * RFC 8414 (OAuth metadata discovery) * RFC 7636 (#PKCE support) * Improved authorization flows following RFC 9700 best […]
hollo.social
Original post on hollo.social
005
Reposted by Hollo :hollo:
Emelia 👸🏻 @thisismissem.hachyderm.io.ap.brid.gy · 26/05/2025
Following on from today's earlier PR to @hollo, I've gone ahead and implemented PKCE for OAuth in Hollo So now they too can have more security for OAuth authorization code grant flows. (Also added a tonne of extra test coverage) github.com/fedify-dev/hollo/pull/155
github.com
Implement OAuth PKCE by ThisIsMissEm · Pull Request #155 · fedify-dev/hollo
This implements OAuth PKCE for the code challenge method S256 (we don't support plain because it's simply insecure). Additionally, I've added test coverage for GET /oauth/authorize usin...
112
Reposted by Hollo :hollo:
Emelia 👸🏻 @thisismissem.hachyderm.io.ap.brid.gy · 25/05/2025
So I was getting really misleading code coverage results from c8 / tsx in the tests for @hollo, so after some discussion, we decided to migrate to vitest, and now we have accurate code coverage output! But my gosh that was a sizeable chunk of work! github.com/fedify-dev/hollo/pull/154
github.com
Migrate to vitest to improve coverage reporting by ThisIsMissEm · Pull Request #154 · fedify-dev/hollo
c8 was giving misleading coverage reports for files containing jsx, which made assessing where we were at with test coverage difficult. I also tried using nyc, one-double-zero and borp, but all the...
102
Reposted by Hollo :hollo:
Emelia 👸🏻 @thisismissem.hachyderm.io.ap.brid.gy · 24/05/2025
Just ended up implementing much greater test coverage for @hollo as well as access token revocation: github.com/fedify-dev/hollo/pull/147 Sometimes I end up doing more than expected in pull requests 🙃
github.com
Add support for more client authentication methods by ThisIsMissEm · Pull Request #147 · fedify-dev/hollo
This adds support for client authentication using: client_secret_basic client_secret_post none (public clients, though it's not possible to create a public client yet) This also adds the noti...
023
Reposted by Hollo :hollo:
Emelia 👸🏻 @thisismissem.hachyderm.io.ap.brid.gy · 11/05/2025
If you're wondering why I'm doing tonnes of OAuth implementation work in @hollo, it's because it allows me to more quickly ship prototypes of things like: - Client ID Metadata Documents - Expiring Access Tokens & Refresh Tokens - Public Clients Both of those are planned for Mastodon, but I'm […]
hachyderm.io
Original post on hachyderm.io
000
Reposted by Hollo :hollo:
Emelia 👸🏻 @thisismissem.hachyderm.io.ap.brid.gy · 11/05/2025
In between working on FIRES yesterday, I also finished up a rather substantial contribution to @hollo that I'd been working on. github.com/fedify-dev/hollo/pull/130 It's an OAuth thing, which to end users shouldn't really change anything, but internally it helps pave the way for […]
hachyderm.io
Original post on hachyderm.io
102
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 30/04/2025
We're pleased to announce that #Hollo has been included in the Nivenly Fediverse Security Fund program! The @nivenly Foundation has launched a security bounty fund to support contributors who identify and help fix #security vulnerabilities in popular #fediverse software. Both Hollo and @fedify […]
hollo.social
Original post on hollo.social
035
Reposted by Hollo :hollo:
🕊️ キツネパレード @rns-8i8.calc.rettuce.page.ap.brid.gy · 27/04/2025
おひとり様サーバーで見るHolloとMitra :: rettuce rettuce.page/posts/fediverse-hollo-and-mitra/ 3ヶ月くらいあたためていた日記を書きました
rettuce.page
おひとり様サーバーで見るHolloとMitra
前提条件 2025/04末時点 Google Cloud Engine の e2-micro インスタンスで動作させる Docker は未使用 おひとり様想定 (利用者が自分1人) また、単純に当方が機能の全容を把握していないため、誤った情報を含む可能性があることにご留意ください。
244
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 28/04/2025
We just released Hollo 0.5.6, a patch release after a month, which fixes a minor bug and updates Fedify.
github.com
Release Hollo 0.5.6 · fedify-dev/hollo
Released on April 29, 2025. Fixed a bug where voting to a poll which had been shared (boosted) had not been sent to the correct recipient. [#142] Upgrade Fedify to 1.4.10.
014
Reposted by Hollo :hollo:
네이티브 @native.pointless.chat.ap.brid.gy · 02/04/2025
포인트리스 연합우주 소프트웨어 호스팅 서비스 - 완전 관리형: 구독기간 중 업그레이드를 포함한 서버 유지보수가 무료입니다. - 데이터베이스와 웹서버를 분리한 구조로 성능이 높습니다. - 마스토돈, 미스키, Hollo 를 지원합니다. - 방화벽: Cloudflare Zero Trust 를 구성해드립니다. 수익금은 포인트리스 서버비로 사용됩니다.
003
Reposted by Hollo :hollo:
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 23/03/2025
### Security Update: Hollo v0.3.10, v0.4.11, v0.5.5 Released We've released security patches for Hollo in versions v0.3.10, v0.4.11, and v0.5.5. These updates address important security vulnerabilities, and we strongly recommend all users update immediately. Docker users can update with […]
hollo.social
Original post on hollo.social
017
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 23/03/2025
### Security Update: Hollo v0.3.10, v0.4.11, v0.5.5 Released We've released security patches for Hollo in versions v0.3.10, v0.4.11, and v0.5.5. These updates address important security vulnerabilities, and we strongly recommend all users update immediately. Docker users can update with […]
hollo.social
Original post on hollo.social
017
Reposted by Hollo :hollo:
wakest ⁂ @fedi.wake.st · 22/03/2025
Theres a new interview with @hongminhee (of @fedify, @hollo, and now #Ghost fame). It's in Japanese (with Korean subtitles) but quite readable with YouTube's autogenerated English subs. www.youtube.com/watch?v=sqxR8zscSDo […]
social.wake.st
Original post on social.wake.st
000
Reposted by Hollo :hollo:
우주스타 아이도루 랭호 🌠 @fedi.rangho.moe · 11/03/2025
Hollo 전용 앱 깎아주세요 심플 이즈 베스트자나
104
Reposted by Hollo :hollo:
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 03/03/2025
@xenon, a new fediverse client app for iOS by @tkgka, is now in public beta! If you use iPhone give it a try! Note that it also works well with @hollo. xenon.social/@xenon/01955c88-10fa-7…
A home timeline on Xenon, a new fediverse client app for iOS
000
Reposted by Hollo :hollo:
Fedify: ActivityPub server framework @fedify.hollo.social.ap.brid.gy · 25/02/2025
We'd like to introduce the #Fedify project family—a set of related tools that make building #ActivityPub applications more accessible: ### Fedify :fedify: Fedify (@fedify) is a #TypeScript library for building federated server applications powered by ActivityPub and other #fediverse standards […]
hollo.social
Original post on hollo.social
0521
Hollo :hollo: @hollo.hollo.social.ap.brid.gy · 25/02/2025
Just released #Hollo 0.5.4 (`ghcr.io/fedify-dev/hollo:0.5.4`), 0.4.10 (`ghcr.io/fedify-dev/hollo:0.4.10`), and 0.3.9 (`ghcr.io/fedify-dev/hollo:0.3.9`), which fix interoperability issues with some software including @mitra. (Thanks for @silverpill's bug report.)
github.com
Release Hollo 0.5.4 · fedify-dev/hollo
Released on February 26, 2025. Fixed a bug where custom emojis in the display name and bio had not been rendered correctly from other software including Mitra. Upgrade Fedify to 1.4.4.
002
Reposted by Hollo :hollo:
洪 民憙 (Hong Minhee) :nonbinary: @hongminhee.hollo.social.ap.brid.gy · 24/02/2025
I have great respect for @thisismissem's tremendous work on @hollo.😲 hachyderm.io/@thisismissem/11405633…
hachyderm.io
002