diff --git a/CHANGELOG b/CHANGELOG index ad46f37..ae22353 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -150,3 +150,14 @@ * Update Mastodon to 3.4.5 * [Full changelog](https://github.com/mastodon/mastodon/releases/tag/v3.4.5) +[1.7.5] +* Update Mastodon to 3.4.6 +* [Full changelog](https://github.com/mastodon/mastodon/releases/tag/v3.4.6) +* Fix mastodon:webpush:generate_vapid_key task requiring a functional environment (ClearlyClaire) +* Fix spurious errors when receiving an Add activity for a private post (ClearlyClaire) +* Fix error-prone SQL queries (ClearlyClaire) +* Fix not compacting incoming signed JSON-LD activities (puckipedia, ClearlyClaire) (CVE-2022-24307) +* Fix insufficient sanitization of report comments (ClearlyClaire) +* Fix stop condition of a Common Table Expression (ClearlyClaire) +* Disable legacy XSS filtering (Wonderfall) + diff --git a/CloudronManifest.json b/CloudronManifest.json index a58e85b..255279a 100644 --- a/CloudronManifest.json +++ b/CloudronManifest.json @@ -5,7 +5,7 @@ "description": "file://DESCRIPTION.md", "changelog": "file://CHANGELOG", "tagline": "Federated social network", - "version": "1.7.4", + "version": "1.7.5", "healthCheckPath": "/about", "httpPort": 8000, "memoryLimit": 1610612736, diff --git a/DESCRIPTION.md b/DESCRIPTION.md index 22ccffb..ee890de 100644 --- a/DESCRIPTION.md +++ b/DESCRIPTION.md @@ -1,4 +1,4 @@ -This app packages Mastodon 3.4.5. +This app packages Mastodon 3.4.6. ## About diff --git a/Dockerfile b/Dockerfile index 3c9e784..62456d4 100644 --- a/Dockerfile +++ b/Dockerfile @@ -17,7 +17,7 @@ RUN gem install --no-document bundler ENV RAILS_ENV production ENV NODE_ENV production -ARG VERSION=3.4.5 +ARG VERSION=3.4.6 RUN curl -L https://github.com/tootsuite/mastodon/archive/v${VERSION}.tar.gz | tar -xz --strip-components 1 -f - && \ bundle config --local set deployment 'true' && \