Skip to content
Compare
Choose a tag to compare

v3.4.6

@ClearlyClaire ClearlyClaire released this
· 3 commits to stable-3.4 since this release
93a6c14
Compare
Choose a tag to compare

Mastodon

⚠️ This release is an important security release fixing CVE-2022-24307, a critical security issue.

A corresponding security release is also available for the 3.3.x branch, if for some reason you do not want or cannot update to 3.4.6 yet.

Changelog

Fixed

  • Fix mastodon:webpush:generate_vapid_key task requiring a functional environment (ClearlyClaire)
  • Fix spurious errors when receiving an Add activity for a private post (ClearlyClaire)

Security

Upgrade notes

Because this is a backport, it is not available with git pull. Use git fetch && git checkout v3.4.6

As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

Dependencies

External dependencies have not changed compared to v3.4.5, the compatible Ruby, PostgreSQL, Node, Elasticsearch and Redis versions are the same, that is:

  • Ruby: 2.6 to 3.1
  • PostgreSQL: 9.5 or newer
  • Elasticsearch (optional, for full-text search): 5.x, 6.x or 7.x
  • Redis: 4 or newer
  • Node: 12 or higher

Update steps

The following instructions are for updating from 3.4.5.

If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations or dependency updates.

Non-Docker

If you are updating from a release earlier than 3.4.5, you will need to do bundle install between steps 1 and 2, and other additional steps are likely to apply, please carefully read the upgrade notes for the skipped releases.

  1. Pull the code: git fetch && git checkout v3.4.6
  2. Restart mastodon-web and mastodon-sidekiq:
    systemctl reload mastodon-web
    systemctl restart mastodon-sidekiq

Docker

The exact steps depend on your setup, but they are likely to match the following:

  1. Pull the code: git fetch && git checkout v3.4.6
  2. Pull the prebuilt images: docker-compose pull, or, alternatively, build them yourself: docker-compose build --pull
  3. Restart all Mastodon processes: docker-compose up -d