github mastodon/mastodon v3.5.19

latest releases: v4.1.16, v4.2.8
2 months ago

Mastodon

Caution

The 3.5.x branch will not receive any update—including security fixes—after this one.

Warning

This release is an important security release fixing a major security issue.

Corresponding security releases are available for the 4.2.x branch, the 4.1.x branch and the 4.0.x branch.

Note

If you are using nightly builds, do not use this release but update to nightly.2024-02-17-security or newer instead. If you are on the main branch, update to the latest commit.

End of life notice

The 3.5.x branch will not receive any further update after this one.

This means that no further security fix will be made available for this branch, and you will need to update to a more recent version (such as the 4.2.x branch) to receive security fixes.

Changelog

Fixed

Security

Upgrade notes

To get the code for v3.5.19, use git fetch && git checkout v3.5.19.

Note

As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

Dependencies

Warning

The minimum required Ruby version has been bumped to 3.0 in Mastodon v3.5.18.

External dependencies have not changed compared to v3.5.18, the compatible Ruby, PostgreSQL, Node, Elasticsearch and Redis versions are the same, that is:

  • Ruby: 3.0
  • PostgreSQL: 9.5 or newer
  • Elasticsearch (optional, for full-text search): 7.x
  • Redis: 4 or newer
  • Node: >= 12.22, < 18
  • ImageMagick: 6.9.7-7 or newer

Tip

If your uploaded images are broken after the upgrade, it means your installed ImageMagick version is older than the new minimum version (6.9.7-7), for example if you are running Ubuntu 18.04. If this happens, you can find more information and ways to fix it on this page.

Update steps

The following instructions are for updating from 3.5.18.

If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations.

Non-Docker only:

  1. Install dependencies: bundle install and yarn install --frozen-lockfile

Both Docker and non-Docker:

  1. Restart all Mastodon processes

Don't miss a new mastodon release

NewReleases is sending notifications on new releases.