github pixelfed/pixelfed v0.12.10

4 hours ago

Changelog

  • Change the collation for the hashtags table (53e5692cf)
  • French translation of the site pages (ca273cff0)
  • New translations web.php (Chinese Simplified) [ci skip] (f88d0db45)
  • New translations web.php (Occitan) [ci skip] (52a0e4120)
  • New translations web.php (Occitan) [ci skip] (6aee03c9a)
  • fix: apply EXIF orientation before resizing portrait images (4f13ebfe3)
  • New translations web.php (Portuguese, Brazilian) (b7ff17d3d)
  • feat: Spanish translation (7afc700f6)
  • feat: Spanish translation (354afc79c)
  • Fix videos never reaching cloud storage by downscaling in Blurhash (ef56880a7)
  • Update Kernel.php (3800612fd)
  • Update allowed routes for restricted access middleware (f6f9d5368)
  • Create RestrictedAccessMiddlewareTest.php (508b57337)
  • Refactor admin notification logic in pipeline (ceba5af03)
  • Update CuratedOnboardingNotifyAdminNewApplicationPipeline.php (a8bbbcd0e)
  • Create CuratedOnboardingNotifyAdminTest.php (da0805c45)
  • Update auth.php (d9e55199f)
  • Replace jenssegers/agent with matomo/device-detector (651f0de74)
  • Fix PSR-4 autoload: rename Webfinger.php to WebFinger.php (47e280b90)
  • Apply Pint formatting to tests/ (de3375a9f)
  • Apply Pint formatting to resources/ (e8d6a48cd)
  • Apply Pint formatting to bootstrap/ (3b0fd708c)
  • Apply Pint formatting to public/ (de965d410)
  • Adopt short array syntax (4c7780944)
  • Convert string references to ::class (19880c2ff)
  • Create pint.json (3950ace9a)
  • Add linting scripts to composer.json (64eb52596)
  • Fix first follower/following record excluded from API responses (396cf2d86)
  • Show detailed upload error messages instead of generic error (5eda13081)
  • Fix OAuth scope bypass on remove_from_followers endpoint (822e9c98c)
  • Delete tests/Feature/Api/RemoveFollowerScopeTest.php (906e3514c)
  • Fix OAuth client secret not displayed after creation (655d71ba5)
  • Handle PAT creation gracefully when not configured (1ab677a52)
  • Prevent deletion of personal access OAuth client (53759e3ad)
  • Install Larastan for static analysis (9a9726af7)
  • Create php-larastan.yml (c840d6bd7)
  • polish (0ce89e9f9)
  • Delete app/Comment.php (f1ca0340e)
  • Use Mastodon username convention for OIDC (9d0b5949e)
  • Update Inbox, fixes #6784 (ce64d0961)
  • Fix validateUrl() (30085e870)
  • Add GitHub Actions workflow for Docker image build (f6baba9b1)
  • Add GitHub Actions workflow for Docker tagged release (8cecf38cf)
  • Update docker-push.yml (aa72592ac)
  • Add GitHub Actions workflow for PHP Pint linting (e8b18f669)
  • Add 'unstable' branch to workflow and update PHP version (699b8af2d)
  • Fix ApiV1Controller, ensure follow notifications have an account (e1235dfd7)
  • Lint (91645faee)
  • Update changelog (8a728fc0d)
  • Update Docker workflow to include unstable branch (e53917f04)
  • Enhance Docker workflow with concurrency and platforms (8e3a37553)
  • Create docker-ghcr-cleanup.yml (d4d74a96f)
  • Rename workflow for GHCR container image cleanup (7bf4e64d9)
  • Upgrade images to v4 (552a55c2d)
  • Update .gitignore (6798175a8)
  • Add IMAGE_DRIVER option to .env.example (ec2b758bc)
  • Update .env.docker.example (8b9d1c12a)
  • Update .env.testing (6eec737b7)
  • Apply pint formatting to resources/ (78b2bc323)
  • Update and rename laravel.yml to php-laravel-tests.yml (580042f36)
  • Update CHANGELOG.md (0d4269017)
  • Create SeedDevUsers.php (16b5ffff1)
  • Update compiled assets (6235594cf)
  • Update CHANGELOG.md (b7f70cae7)
  • Update Clients.vue (80271c900)
  • Add entry for fixing oauth client deletion (63d28a486)
  • Update compiled assets (004ce3225)
  • fix: add larastan/larastan to composer.lock to fix docker build (2dbee8599)
  • Update composer (e4033b05b)
  • Update AccountService (59f57b110)
  • Update CHANGELOG.md (e69910e2b)
  • Update ApiV1Controller, add show_atom support to update_credentials endpoint (4e2e49f84)
  • Update CHANGELOG.md (0a2b97fb9)
  • Update ApiV1Controller, add is_suggestable to update_credentials endpoint (7937d91c3)
  • refactor: replace deprecated CheckForMaintenanceMode with PreventRequestsDuringMaintenance (f363715ad)
  • Update changelog (bb33696cc)
  • refactor: rename $routeMiddleware to $middlewareAliases (d2bd73c27)
  • Fix typo (8f1e47540)
  • refactor: convert string-based routes to ::class array syntax (28927f6f6)
  • refactor: replace deprecated laravel/helpers with native alternatives (edb4368b0)
  • refactor: use ::class syntax in EventServiceProvider (741bc995c)
  • fix: resolve PDO::MYSQL_ATTR_SSL_CA deprecation on PHP 8.5 (5041e1805)
  • Update CHANGELOG.md (3bf3e1274)
  • refactor: replace deprecated laravel/helpers with native alternatives (1bb05fafa)
  • refactor: replace deprecated str_random() with Str::random() (98267eb26)
  • refactor: replace str_limit() with Str::limit() (faa216b32)
  • Update ContextMenu, restore Edit button (b761107c7)
  • fix: replace str_random/str_limit/str_slug in Blade templates and tests (30db57448)
  • fix: remove bootstrap/cache bind mount from docker-compose (f5d166a93)
  • refactor: migrate to modern bootstrap/app.php architecture (8e41f6fdf)
  • Update AccountService.php (443f29acc)
  • refactor: remove redundant aliases from config/app.php (5693b1581)
  • refactor: remove thin middleware wrappers, use framework classes directly (ee7d7124d)
  • Add view_oidc_callback_ensure_valid_username unit test (22ff6810b)
  • refactor: replace short facade aliases with fully-qualified imports (c807a8524)
  • Update Extractor.php (899e360b4)
  • Delete tests/database.sqlite (e8a13300e)
  • Delete tests/database.sqlite (e3279b428)
  • Update CHANGELOG.md (3170c82a7)
  • Update docker-tag.yml (de656d12d)
  • Update docker-push.yml (28a56d047)
  • Delete phpstan-baseline.neon (412ac5fd9)
  • Update phpstan.neon (afbbd9ea0)
  • refactor: update phpstan.neon with Larastan 3.x best practices (890dc5534)
  • fix: add missing FeedUnfollowPipeline import (58efefb87)
  • Update phpstan.neon (d8a122a9c)
  • Update CHANGELOG.md (eeda06cee)
  • fix: add missing property declarations (phpstan property.notFound) (43040a227)
  • fix: resolve undefined variable bugs (phpstan variable.undefined) (ccd75dd90)
  • fix: use query methods instead of collection methods (phpstan noUnnecessaryCollectionCall) (49b85e9f2)
  • fix: remove call to non-existent PollService::storyPoll() (7bde84b23)
  • fix: add missing use imports to resolve phpstan class.notFound errors (e7ba43e2e)
  • Update StoryService.php (942e15c65)
  • Update TimelineController.php (58a34056c)
  • Update StoryService.php (4bb9edcb2)
  • fix: replace backslash-prefixed facade calls with imported references (7c964f3b4)
  • fix: resolve undefined $status variable in GroupsPostController::deletePost (e7ef58969)
  • fix: add return type declarations to Eloquent relation methods (f2159197e)
  • fix: replace Auth facade with $request->user() in request-scoped classes (0939f495b)
  • Revert "Merge pull request #6851 from pixelfed/fix/phpstan-auth-request-scope-2" (161773490)
  • fix: replace Auth facade with $request->user() in request-scoped classes (458150e06)
  • fix: use request() helper for methods without Request parameter (88e0d92ac)
  • fix: convert OAuth routes from legacy array syntax to modern fluent syntax (76d187edd)
  • feat: add critical path test suite and fix auth/config issues (8a2649b3f)
  • fix: resolve str_ends_with TypeError in RegisterController (97929f087)
  • test: expect oauth endpoints to return 200 (will pass after route syntax fix merge) (ec8a39302)
  • feat: add framework integration tests for Laravel 12→13 upgrade readiness (4ce28d914)
  • chore: add TODO to replace custom FrameGuard with Laravel built-in security headers (18c288f88)
  • ci: refactor GitHub Actions with Redis service and best practices (c7473cd1a)
  • ci: fix action versions (checkout@v7, cache@v6) and add unstable branch (0ed3e6192)
  • Update php-larastan.yml (b2af98788)
  • Update php-laravel-tests.yml (2adbb6507)
  • Rename workflow to PHP - Pint (0f6ed0d91)
  • Update CHANGELOG.md (f6a3df88d)
  • Revise CHANGELOG.md for recent updates (df9943368)
  • test: add settings, mute/block, and follow tests (278 total) (891e28280)
  • test: add status, timeline, federation, and privacy tests (309 total) (e1f883a41)
  • test: add notification, search, compose, report, and collection tests (332 total) (0f3820e7b)
  • test: add admin access and API scope security tests (360 total) (579a581de)
  • fix: replace removed Passport scope middleware with current classes (7a96cd2e9)
  • fix: replace removed Passport scope middleware with current classes (0eae871e4)
  • test: un-skip Passport scope tests now that middleware is fixed (9f81a5b42)
  • test: add auth scope migration verification tests (390 total, all green) (918e49136)
  • test: add auth scope migration tests and update CI action versions (a486f509a)
  • revert: restore original GitHub Actions workflow names (47d98bfb5)
  • fix: replace Auth facade with $request->user() in request-scoped classes (ffcef3eb2)
  • Update AccountController.php (3c6280111)
  • fix: remove deprecated Passport::personalAccessClientId() and enableImplicitGrant() (5a364be58)
  • fix: remove dead RemoteFollowPipeline (references uninstalled HttpSignatures package) (7042ea536)
  • fix: remove dead publicApi/homeApi methods from TimelineController (8cf532156)
  • Revert "fix: remove dead publicApi/homeApi methods from TimelineController" (ea2d054a4)
  • comment dead code (f54e6280b)
  • Update DOCKER_COMPOSE_SETUP.md (e2c6162b3)
  • Fix duplicate command in Docker Compose setup (4086f0778)
  • polish (c891f34df)
  • refactor: replace $fillable with $guarded = [] across all models (570a30d03)
  • fix: replace deprecated starts_with() with str_starts_with() (26b8a0a6b)
  • feat: add throttle:api middleware to the api route group (ed90e619f)
  • Update AppServiceProvider.php (0837968fa)
  • fix: unpin symfony/http-foundation to allow patch updates (0c849ca4e)
  • chore: remove unused direct dependencies (1696dfaca)
  • fix: enable MySQL strict mode and remove defaultStringLength(191) (1b64c59be)
  • fix: replace deprecated $request->get() with $request->input() (4320231c1)
  • refactor: rename VerifyCsrfToken to PreventRequestForgery (9958b095d)
  • feat: add serializable_classes to cache config for Laravel 13 prep (ba90d1bd2)
  • Update database.php (2f466b02d)
  • Update database.php (323cfc9cf)
  • Change DB_STRICT environment variable to true (35cb9a9dc)
  • Set strict mode to true in database configuration (542434785)
  • Update model loading behavior in AppServiceProvider (c04fec21f)
  • Update AppServiceProvider.php (1ae0feb12)
  • Update AppServiceProvider.php (de8de9251)
  • Pint app/ (33dce75f2)
  • Pint config/ (42f361540)
  • Update AppServiceProvider.php (f13a891ff)
  • Pint database/ (db636ee08)
  • Improve test assertions and imports (412c29bb4)
  • Update app.php (2c704d9a7)
  • Move ValidateCsrfToken middleware to a new position (46393bd9f)
  • refactor: add return type declarations to controller methods (54cfdf3c2)
  • fix: resolve 6 Larastan errors in controller return types (17a5b5c3d)
  • refactor: replace Guzzle pool with Laravel HTTP client in StatusDelete (00dd5b3d9)
  • fix: improve NewStatusPipeline retry configuration (a0f721781)
  • polish (2b1c9c818)
  • polish (a142db87b)
  • refactor: move 52 legacy models from App\ to App\Models\ (c0cde2f68)
  • test: verify morph map resolves legacy model namespaces (4231ce993)
  • fix: resolve 3 remaining Larastan errors from model migration (aae7700bf)
  • refactor: split ActivityPub Inbox into focused traits with shared helpers (f4b6d03ae)
  • refactor: extract shared ActivityPub pool delivery into ActivityPubDeliveryService (9c9e2a5a2)
  • refactor: extract duplicate patterns into shared methods (e7b70c608)
  • fix: resolve larastan class.notFound errors (941c30510)
  • refactor: migrate LikePipeline to use NotificationService::firstOrCreateNotification (8b53f23e7)
  • Fix endsWith. Closes #6904 (e3a264070)
  • Update composer (1810caac2)
  • Fix cache error (44275154e)
  • refactor: consolidate username validation into PixelfedUsername rule (7c5d93e96)
  • Create DeduplicationChanges.md (d1ea7a5be)
  • refactor: rename PixelfedUsername rule to ValidUsername (302edf09d)
  • Rename DeduplicationChanges.md to notes/DeduplicationChanges.md (0b6f8e4ab)
  • Update DeduplicationChanges.md (101b529ac)
  • Remove duplicate boilerplate code in documentation (27c778f4b)
  • Update DeduplicationChanges.md (4982839c5)
  • Refactor boilerplate examples for deduplication (6cce21032)
  • Update DeduplicationChanges.md with service reference (78a48f0ef)
  • chore: remove unused import and fix spacing in cache config (3be6dbf54)
  • Fix ProfileMigrationStorageRequest, use signed requests for gts and other compat (81245ec46)
  • Fix AdminReports (5b63f5f22)
  • Update compiled assets (db37202e6)
  • fix: stop caching raw Eloquent models to prevent incomplete-object 500s (f0e951dcc)
  • Add user:status artisan command for account login/reset diagnostics (e39b0f1b5)
  • Update AdminReportController (0679216fa)
  • Add user:setpassword artisan command for CLI password reset (7148c5828)
  • Update UserAccountDelete command (51beaa30d)
  • Add user:checkpassword read-only command to diagnose rejected logins (2c7227a9c)
  • Fix CSRF token not found error on guest pages (login/register) (54f99334b)
  • Fix CSRF token not found error on guest pages (login/register) (32e391d26)
  • Add csrf-token meta to anon and app-guest layouts (ea1a629b1)
  • Expand user:status profile section with full column dump and derived metadata (93f813848)
  • Add profile:status command for local and remote profile diagnostics (92d09ffaa)
  • Fix unauthenticated SSRF in remote media/avatar fetch (variant of CVE-2026-71246) (3d82a8e8b)
  • Allow gif and webp mime types for custom emoji import (7482befd8)
  • Update SecureMediaFetchService.php (8123dcf93)
  • Add fix:followercount command to resync drifted follower/following counts (9fe1fe55a)
  • Add fix:profilecounts (total profile cache resync); remove redundant count commands (037f1ac0b)
  • Apply Pint formatting to SecureMediaFetchService (aadde946d)
  • Refactor profile count reconciliation into shared AccountStatService methods (a187ab663)
  • Schedule weekly profile-count reconcile and add reconciliation tests (698ba224e)
  • Rename to admin:fixProfileCounts, make --active its own mode, add --type (96f26405f)
  • Update stale command-name reference in comment to admin:fixProfileCounts (55e9201b1)
  • Fix VueIntersect single-element warning in notifications section (b3be61c47)
  • Require --scope (local/remote/both) for admin:fixProfileCounts --all (bcd5a5bd7)
  • Add post:status command for post/media diagnostics (4aa7b5728)
  • Add admin:MigrateLocalMediaURL; replace media:cloud-url-rewrite (04536a6e3)
  • Rename to admin:MigrateLocalS3MediaURL and drop --avatars (da9e73dd2)
  • Fix MigrateLocalS3MediaUrl tests failing in CI (34d6fb31f)
  • Update CHANGELOG.md (45918bbb1)
  • Add media storage migration commands (local<->cloud) with integrated GC (6ff9ffbbb)
  • Add admin:MediaMoveStorageCloudToCloud for cold S3->S3 migration (70b4a05b5)
  • polish (68366c7dd)
  • Fix duplicate-key violation when importing remote media attachments (0d01d5a96)
  • refactor: rename status debug commands to status: prefix (16c7c5d2e)
  • refactor: organize Artisan commands into subfolders (1eae4bbd4)
  • docs: add README for Artisan commands with listing and audit (c99b8068a)
  • Update README.md (cafec250f)
  • refactor: move resolved one-off migrations to Deprecated/ (cd353a830)
  • Update Profile component (32ff6d48c)
  • Update compiled assets (ba8b92105)
  • feat: add admin:fixPostCounts to resync post like/boost/comment counts (744e45360)
  • refactor: move admin:fix*Counts commands to Admin/ (73b8353da)
  • fix: display comments count as 0 instead of blank in admin:fixPostCounts (d50024a57)
  • fix: make admin:fixPostCounts summary report only changed metrics (de850836c)
  • test: add feature tests for admin:fixPostCounts (ec5be5241)
  • style: import DB facade in FixPostCounts test (pint) (078380723)
  • chore: add Psalm static analysis (plugin-laravel, baseline, CI) (1a234c392)
  • ci(psalm): report findings but never fail the job (2617211c1)
  • ci(psalm): align workflow with php-* conventions, test on PHP 8.5 (6945277e2)
  • ci(psalm): guarantee SARIF file exists and upgrade upload-sarif to v4 (5cecde670)
  • ci(psalm): skip SARIF upload when report is missing (aed7936e4)
  • ci(psalm): run analyzer on PHP 8.4 to avoid 8.5 crash (25494c491)
  • Update php-psalm.yml (3058d3f81)
  • Update php-psalm.yml (27f7127cc)
  • Add vimeo/psalm and composer scripts (4e0c567ec)
  • Update VideoThumbnail.php (186fa7c86)
  • Fix larastan errors in RemoteOidcTest: import Test attribute and RefreshDatabase, replace removed str_random helper (b7c15dc7c)
  • polish (d86fd28e3)
  • Accept compacted Note attachments (#6588)
  • Update 2025_07_31_164635_change_hashtags_collation.php (e53e82faf)
  • Create HashtagCollationTest.php (27768cd69)
  • Update php-larastan.yml (9dfb5c062)
  • Update php-laravel-tests.yml (338d4da42)
  • Update php-pint.yml (765e10ea6)
  • Revert hashtags collation migration from #6098 (405674766)
  • chore: add composer psalm:report script for a full local txt report (6eea565ba)
  • chore: target PHP 8.4 in psalm config (fb69275cd)
  • chore: resolve psalm issues in admin commands and auth (878775cab)
  • implement search by country (129778ef2)
  • fix: prevent remcache temp file leaks and add GC command (3232761a7)
  • refactor: rename RemcacheGarbageCollector to GCRemcache (57b3bf140)
  • refactor: use GarbageCollector prefix for GC console command classes (9704fd5a3)
  • feat: migrate local story media to cloud storage (9f110bb74)
  • feat: store custom emoji on cloud storage when enabled (fa76e1014)
  • feat: migrate all local emoji to cloud in one pass by default (979df6e39)
  • feat: add migration to move local emoji to cloud on deploy (a945efbf7)
  • fix: schedule StoryMoveStorageLocalToCloud command (842681b99)
  • fix: emoji admin URLs and cloud-migration guard (aa9bb868d)
  • revert: story cloud-migration work (9f55f7204)
  • fix: make emoji cloud migration disk-driven + add --debug (79eef56be)
  • fix: skip missing.png in emoji cloud migration (9e5fcb9a9)
  • perf: parallelise emoji cloud migration with worker processes (00564ac22)
  • feat: add uploads/sec throughput counter to emoji migration (f17a88e16)
  • perf: async S3 SDK upload path for emoji migration (a0a262f07)
  • Update EmojiMoveStorageLocalToCloud.php (948da00f0)
  • revert: remove emoji local-to-cloud storage changes (40b323bca)
  • chore: modernize service providers for Laravel 13 readiness (3c6ba88e6)
  • perf: fix N+1 queries; fix ComposeController lint and test namespace (b52c3d765)
  • chore: uplift framework skeleton toward Laravel 12 defaults (4e83eb086)
  • Update composer.json (54a0b3ee9)
  • Revert "Merge pull request #6981 from pixelfed/chore/laravel12-skeleton-uplift" (7aa1f8936)
  • chore: uplift framework skeleton toward Laravel 12 defaults (80214c5e7)
  • Update composer.json (b86e4f731)
  • refactor: rename MigrateLocalS3MediaURL class and move media move-storage commands to unstable (41c9b8830)
  • Update filesystems.php (d18e87133)
  • refactor: keep MediaMoveStorageLocalToCloud as a stable admin command (a81270770)
  • feat: storage:maintenance command + in-flow cleanup of emptied dirs (400f00c5e)
  • polish (8ca3ac4dc)
  • refactor: simplify storage:maintenance flags and make it quiet by default (fce75030e)
  • fix: delete superseded image/thumbnail files instead of orphaning them (b6d645a4d)
  • Add domain-mismatch metadata to Announce status fetch and stop noisy ERROR logs (0df4c7117)
  • Add structured metadata to MediaDeletePipeline skip/failure logs (d456b7b64)
  • Add admin:resyncemoji command to re-download remote emoji locally (9214e9680)
  • Fix remote status deletion leaking attached media, add status:media command (69869536a)
  • Add media:maintenance command with orphanedMedia scope (87dad44d0)
  • Add verbose output to media:maintenance (48a1fe5e5)
  • Add --status and --profile state filters to media:maintenance (4ad6e91ef)
  • Drop live from --status on media:maintenance (4dfb34de7)
  • Rename media:maintenance to media:filtercleanup (d62c58988)
  • Rename status:post to status:statuses (237ed61b5)
  • Add status:instance, status:avatar, status:emoji inspector commands (9888923a8)
  • Update AdminReportController.php (10ae3fa8c)
  • Add success message for profile update action (45e4de392)
  • Update ApiV1Controller.php (7c3644c3e)
  • Remove 'true' argument from usernameToId call (c623a7afb)
  • Add Sanctum support (584ce27f7)
  • Create 2019_12_14_000001_create_personal_access_tokens_table.php (8e7b368ea)
  • Lint (c19fd269b)
  • Update composer.json (8a0368ab0)
  • Update Report endpoint, add support for optional message (ccac8b31b)
  • Update ASF (5468eaeb5)
  • Fix reblog handling (a6117a240)
  • composer (595620e5b)
  • Update dependabot.yml (07b5c1fd3)
  • Drop the no-op pf_type assignment in the group topic feed (71cade540)
  • Update ApiV1Controller, fix napi in timelines (4c4a457fe)
  • chore(deps): bump postcss-selector-parser (e5bda87a1)

Truncated... view the changelog for the full list

Don't miss a new pixelfed release

NewReleases is sending notifications on new releases.