This is the full release of version 1.11.
It includes new features for users and admins, bug fixes, performance and security fixes.
Comparison to previous stable version v1.10.1:
| DB migrations | New ENV vars | Renamed ENV vars | Admin guide changes | Suggest cache clearing | New dependencies |
|---|---|---|---|---|---|
| ☑️ | ❌ | ❌ | ☑️ | ☑️ | ☑️ |
We have 3 different summaries below. One for end-users, one for server admins, and finally a summary for developers.
Summary for Users
- Show who boosted content in the feed (Combined view + subscribed + newest)
- Add ability to block instances. Content from blocked instances will not show up in the feed and search anymore.
- Fix emoji autocomplete inserts 'null'
- Show a placeholder when an image embed could not be loaded
- Improve design of posts and comments in some areas of the site
- Fix endless loop when compressing uploaded images
- Fix layout when a comment contains a very wide table
- Bugfixes for some federation issues (handling of Mastodon posts with multiple images, embedded video formats, buggy mentions, etc.)
- Change layout of list of cross posts
- Fix the issue of browsers wanting to download a file when unsupported media files are used in an embed
- Add translation for Swedish (by Jonatan Nyberg)
Summary for Server Admins
- Minimum software requirements updated to PHP 8.5, Node 24 and Ubuntu 24.04 recommended
- Upgraded most of our dependencies. For more details see #2162
- Add ability to block instances globally. Instances blocked this way will be blocked for all current and new users. Users can unblock them manually afterward; thus allowing a "soft" way to moderate the content shown by default for your users. For more details see #2155
- Added the new queue
async_slowfor long-running tasks. If yourasyncqueue have gotten full often in the past, consider creating a separate messenger forasync_slow. - The sessions are now stored in Redis instead of Postgres. You need to enable persistence in your Redis server, if you want to keep open sessions on restarts of Redis.
- Fixed a couple of security vulnerabilities
- PostgreSQL autovacuum is tuned for high-churn tables
Summary for developers
Mbin:
- Minimum software requirements updated to PHP 8.5 and Node 24
- Upgraded most of our dependencies. For more details, including possible breaking package changes, see #2162
Fediverse:
- Fix issue that
tovalue might be an object instead of array in some edge-cases
Upgrade Instructions
There are significant changes in the DB. It is advised to create a DB backup before upgrading.
After the post-upgrade script has run, you should not clear Redis / Valkey.
For Docker
- Get the official image or checkout the code and build it locally
- Stop all containers
docker compose down - Start all containers
docker compose up -d
For Bare Metal
- Ensure you have PHP 8.5 and Node 24 installed. Remember to also update PHP related software, like composer.
- Login as the mbin/kbin user:
su mbin - Go to your repo
cd /var/www/mbin - Get the new release:
git fetch && git checkout v1.11.0 - Run the update script:
bash bin/post-upgrade. - Run
exitso we are back at the root user (or put a sudo in front of every command) - clear your opcache by reloading php fpm
systemctl restart php8.5-fpm - Restart the messengers:
supervisorctl restart messenger:*
What's Changed
- Bump ghcr.io/devcontainers/features/node from 1.7.1 to 2.1.0 by @dependabot[bot] in #2159
- Fix devcontainer build errors by @garrettw in #2160
- upgrade PHP in CI Docker image by @blued-gear in #2163
- Fix Node version and missing PHP extension in CI image by @blued-gear in #2164
- fix CI image by @blued-gear in #2166
- optimize some queries by @blued-gear in #2165
- call gc_collect_cycles() for every message by @blued-gear in #2168
- use more EXTRA_LAZY collections in entities by @blued-gear in #2170
- npm audit fix by @garrettw in #2169
- update docker build by @blued-gear in #2167
- fix search filter when no type is set in SearchRetrieveApi request by @blued-gear in #2175
- Bump guzzlehttp/guzzle from 7.13.1 to 7.15.1 by @dependabot[bot] in #2173
- Fix: video embed with unsupported media by @garrettw in #2172
- fix parsing of actorUrl for magazine by @blued-gear in #2174
- Make query of AP user case-sensitive by @blued-gear in #2177
- Order content by boost date in Combined if boosted content should be included by @blued-gear in #2147
- Another npm audit fix by @garrettw in #2176
- docs(contributor): contributors readme action update by @github-actions[bot] in #2178
- Add ability for users to block whole instances by @blued-gear in #2155
- Add a session handler to migrate from pdo to redis, add managed gc times by @BentiGorlich in #2127
- fix creation of temporary images in tests by @blued-gear in #2181
- remove accidentally commited debug logging by @blued-gear in #2183
- fix and speed up migration of 'last_boosted_at' column by @blued-gear in #2184
- Translations update from Hosted Weblate by @weblate in #2186
- a couple of smaller fixes by @blued-gear in #2187
- Fix unverified users having access to the api by @BentiGorlich in #2194
- Bump version to 1.10.1 by @BentiGorlich in #2195
- Bump guzzlehttp/guzzle from 7.15.1 to 7.15.2 by @dependabot[bot] in #2196
- docs: update PHP instructions to 8.5 + Ubuntu to 24.04 by @melroy89 in #2198
- fix: update commonmark security release by @melroy89 in #2203
- Fix tag API ordering test sort parameter by @melroy89 in #2204
- fix: emoji autocomplete inserts 'null' after colon + newline (Fixes #2151) by @waterWang in #2197
- docs(contributor): contributors readme action update by @github-actions[bot] in #2205
- fix empty image embed link text by @blued-gear in #2207
- fix ImageManager::compressUntilSize() by @blued-gear in #2200
- Update league/commonmark for security fixes by @melroy89 in #2215
- Fix abandoned magazine ordering test flake by @melroy89 in #2216
- Update Docker login action to v4 by @melroy89 in #2217
- fix overflow handling when a post or comment contains an overly wide table by @blued-gear in #2212
- fix some AP stuff by @blued-gear in #2201
- fix css of crosspost list by @blued-gear in #2220
- Tune autovacuum thresholds for high-churn tables by @melroy89 in #2219
- docs(contributor): contributors readme action update by @github-actions[bot] in #2221
- docs: align README with PHP 8.5 requirements by @melroy89 in #2222
- Fix CI failure when main advances during tests by @melroy89 in #2223
- Reject unsupported media URLs in iframe previews by @melroy89 in #2224
- Restore Redis DSN support for session storage by @melroy89 in #2218
- show who boosted content in feed by @blued-gear in #2210
- Block private network access in embed fetches by @melroy89 in #2225
- Tighten ActivityPub signature validation by @melroy89 in #2227
- show a summary of the entry / post a comment is from when displaying it in Combined or Microblog by @blued-gear in #2206
- Fix null error on initialization by @BentiGorlich in #2229
- prevent HTTP request to internal networks by user content by @blued-gear in #2228
- Fix the "to" array being a json dictionary by @BentiGorlich in #2232
- intoduce new async_slow queue for image deletion by @blued-gear in #2199
- Translations update from Hosted Weblate by @weblate in #2235
- Pin generated URLs to the configured domain by @melroy89 in #2226
- Fix date-filtered general statistics with DBAL 4 by @melroy89 in #2240
- Upgrade dependencies by @blued-gear in #2162
- Bump version to 1.11.0 by @melroy89 in #2241
- docs: refresh project overview for current source layout by @melroy89 in #2242
- enable migrating session handler by @blued-gear in #2245
New Contributors
- @waterWang made their first contribution in #2197
Full Changelog: v1.10.1...v1.11.0