Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Offical apps | Community apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Fider
  3. Fider - Package Updates

Fider - Package Updates

Scheduled Pinned Locked Moved Fider
18 Posts 2 Posters 4.0k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Package UpdatesP
    Package UpdatesP
    Package Updates
    wrote on last edited by
    #7

    [1.3.0]

    • Update fider to 0.30.0
    • Full Changelog
    • OAuth Provider Management: Tenant-level enable/disable controls for built-in OAuth providers (#​1377)
    • Enhanced Search: Improved full-text search with language detection support and better handling of non-Latin languages (#​1375)
    • Link Insertion in Editor: New insert link button and keyboard shortcut (Cmd/Ctrl+K) in comment editor (#​1371)
    • Fixed search functionality for queries with multiple words and special characters
    • Fixed link rendering in comment editor (#​1370)
    • Proper i18n for post status labels (#​1380)
    • Fixed long post titles breaking layout with proper word wrapping (#​1368)
    1 Reply Last reply
    0
    • Package UpdatesP
      Package UpdatesP
      Package Updates
      wrote on last edited by
      #8

      [1.4.0]

      • Update fider to 0.31.0
      • Full Changelog
      • Allow setting listen addr with HOST and METRICS_HOST by @dani in #1384
      • Allow resending signup verification email for pending tenants by @Copilot in #1378
      • Replace loose equality with strict equality in SignInControl by @Copilot in #1392
      • Email sign-in changed to use sign-in codes. by @mattwoberts in #1389
      • Better email formatting. by @mattwoberts in #1400
      1 Reply Last reply
      0
      • Package UpdatesP
        Package UpdatesP
        Package Updates
        wrote on last edited by
        #9

        [1.5.0]

        • Update fider to 0.32.0
        • Full Changelog
        • There were some issues with the "raw markdown mode" editor where markdown formatting wasn't always persisting properly between HTML and raw view. Switching to use a textarea for the raw markdown mode fixed these issues, and meant that the code was simpler since we had less kludging to do. That fixes many little issues, including #1401
        • Also sorted #1402, and implemented some security improvements too (CWE-22 Path Traversal vulnerability).
        1 Reply Last reply
        0
        • Package UpdatesP
          Package UpdatesP
          Package Updates
          wrote on last edited by
          #10

          [2.0.0]

          • Update fider to 0.33.0
          • Full Changelog
          • Please note new license changes
          • Open Core Licensing: Some features (content moderation, search indexing) are now gated as pro features, with a new commercial licensing system using separate private/public key environment variables.
          • Content Moderation (Pro): Admins can now moderate posts and comments before they go public, trust or block individual users, and manage pending content from a dedicated admin page. Content moderation is available as a pro feature.
          • Revamped UI: The home page and post detail view have been refreshed with a cleaner design, better dark mode support, improved mobile layouts, and post details now open in a modal without a full page reload.
          • Security: Sign-in email links now use a strong 64-character key (manual entry still uses a 6-digit code for convenience).
          • Fixed search with hyphenated words
          • Option to keep failing webhooks enabled rather than auto-disabling them
          • Fixed issue adding links via the toolbar button
          • Fixed filter/sort state persisting when navigating back from a post
          • Fixed vote listing issues
          • Post tags now update live in the listing without a page reload
          1 Reply Last reply
          0
          • Package UpdatesP Package Updates locked this topic on
          • Package UpdatesP
            Package UpdatesP
            Package Updates
            wrote on last edited by
            #11

            [2.1.0]

            • Update fider to 0.34.0
            • Full Changelog
            • Batch safe dependency updates by @mattwoberts in #1479
            • Show voted indicator on homepage post list + complete Polish translations by @lol2x in #1482
            • Fix authenticated arbitrary blob overwrite vulnerability by @mattwoberts in #1497
            • fix: prevent XSS in markdown rendering and ATOM feed by @mattwoberts in #1495
            • Fix SSRF vulnerability in webhook URLs by @mattwoberts in #1494
            • Added import and export for tags by @JimKnoxx in #1480
            • Bump Go to 1.25 and update dependencies by @mattwoberts in #1498
            • Fix DoS via unbounded HTTP response body read by @mattwoberts in #1499
            • Remove open core licensing model by @mattwoberts in #1483
            • Added an optional OAUTH_ALLOWED_ROLES environment variable by @JimKnoxx in #1463
            • Add Traditional Chinese (zh-TW) language support by @HansHans135 in #1488
            1 Reply Last reply
            0
            • Package UpdatesP
              Package UpdatesP
              Package Updates
              wrote on last edited by
              #12

              [3.0.0]

              • Remove built-in OIDC integration. The OIDC integration is meant to be used like external provider login. Set this up manually if required
              1 Reply Last reply
              0
              • Package UpdatesP
                Package UpdatesP
                Package Updates
                wrote on last edited by
                #13

                [3.1.0]

                • Update fider to 0.35.0
                • Full Changelog
                • Support for an annual plan too. by @mattwoberts in #1516
                • Fix mass assignment auth bypass in sign-in verification by @mattwoberts in #1517
                • Add rate limiting to sign-in verification code by @mattwoberts in #1524
                • fix(email): unescape HTML entities in rendered subject by @americodias in #1513
                • Harden post filter against edge cases by @lol2x in #1515
                1 Reply Last reply
                0
                • Package UpdatesP
                  Package UpdatesP
                  Package Updates
                  wrote on last edited by
                  #14

                  [3.2.0]

                  • Update fider to 0.36.0
                  • Full Changelog
                  • This release includes several security fixes upgrading is recommended.
                  • SSRF hardening block server-side request forgery via custom OAuth provider Token/Profile URLs.
                  • XSS fix prevent potential malicious script execution in rendered content (plus a DOMPurify update).
                  • Invite scoping invite-token verification is now scoped to the tenant.
                  • Roadmap a new public roadmap view (pro-only on the cloud instance)
                  • Self-service board deletion owners on multi-site instances can schedule deletion of their own board, with a grace period, a cancel link, and a confirmation email.
                  • SMTP implicit TLS (SMTPS) optional implicit-TLS / port-465 support for outbound email.
                  • Show images placed at the very beginning of post content.
                  • Append attachments supplied via POST /api/v1/posts to the end of the post description.
                  • New navigation header: stop notification icons wrapping onto a second row.
                  1 Reply Last reply
                  0
                  • Package UpdatesP
                    Package UpdatesP
                    Package Updates
                    wrote on last edited by
                    #15

                    [3.2.1]

                    • Update fider to 0.36.1
                    • Full Changelog
                    • feat(webhooks): ALLOW_PRIVATE_NETWORK_TARGETS env to allow internal targets by @hodyhq in #1579
                    • Fix missing email strings by @mattwoberts in #1598
                    • Respond copy by @mattwoberts in #1601
                    1 Reply Last reply
                    0
                    • Package UpdatesP
                      Package UpdatesP
                      Package Updates
                      wrote last edited by
                      #16

                      [3.3.0]

                      • Update fider to 0.37.0
                      • Full Changelog
                      • Stop retrying Let's Encrypt for hosts that just failed by @mattwoberts in #1616
                      • Improvements to tiptap editor by @mattwoberts in #1604
                      • Plural vote translations by @mattwoberts in #1605
                      • Issues with the share feedback page by @mattwoberts in #1617
                      • fix(locale): register and polish Korean (ko) translations by @Cynn in #1619
                      • Fix cross-tenant auth takeover via tenant-unbound user lookup by @mattwoberts in #1623
                      • Update Italian translation by @albanobattistella in #1592
                      • Bind OAuth sign-in to the tenant's canonical origin by @mattwoberts in #1626
                      • Support for deleting accounts from support tools by @mattwoberts in #1671
                      • Sanitize backend markdown output and filter URL schemes by @mattwoberts in #1673
                      1 Reply Last reply
                      0
                      • Package UpdatesP
                        Package UpdatesP
                        Package Updates
                        wrote last edited by
                        #17

                        [3.4.0]

                        • Update fider to 0.38.0
                        • Full Changelog
                        • GHSA-whx4-hxwq-qgjh: SSRF protection bypass via DNS rebinding (#1678)
                        • GHSA-p8j9-wxg9-qp34: SSRF protection bypass via IPv6 transition addresses (#1678)
                        • GHSA-xjr8-w967-4xjq: CSRF bypass via the Accept header (#1676)
                        • GHSA-7cw3-7xh9-529r: Denial of service via image decompression bomb (#1677)
                        • Enforce the SSRF guard at connect time and block IPv6 transition addresses by @mattwoberts in #1678
                        • Require a preflight-forcing signal for write requests (CSRF hardening) by @mattwoberts in #1676
                        • Bound image decode memory before resizing (decompression bomb DoS) by @mattwoberts in #1677
                        1 Reply Last reply
                        0
                        • Package UpdatesP
                          Package UpdatesP
                          Package Updates
                          wrote last edited by
                          #18

                          [3.4.1]

                          • Update fider to 0.38.1
                          • Full Changelog
                          • Fixed a stored XSS in post previews on the home page and in the moderation queue (#1687). Advisory to follow.
                          • Security updates for dependencies, including gomarkdown, DOMPurify, golang.org/x/crypto and golang.org/x/net (#1682).
                          • Now built with Go 1.27, because Go 1.25 no longer gets security fixes (#1686).
                          • Editor upgraded to tiptap v3, with a single markdown engine for editing and display. Tables and task lists are now kept when editing (#1644).
                          • Search engines now get fully rendered pages; previously, pages showing vote counts failed to render for them (#1685).
                          • Design System page fix (#1654, thanks @dhinesh20022806).
                          1 Reply Last reply
                          0

                          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                          With your input, this post could be even better 💗

                          Register Login
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Don't have an account? Register

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • Bookmarks
                          • Search