Search

Items tagged with: fediverse


Week in Fediverse 2026-09-11


Servers

- Hubzilla v11.4.1
- Bookwyrm v0.9.3
- Cookifed v0.1.0
- Ktistec v3.12.1
- Misskey v2026.9.0
- gathio v1.6.7
- NeoDB v0.18.2
- Appy v0.7.0
- PieFed v1.7.15
- Wafrn v2026.09.01

Clients

- Voyager v2.49.0
- Miria v4.0.1
- Aria v1.5.13

Tools and Plugins

- Enable Mastodon Apps v1.6.4 (WordPress plugin)

Articles

- Static ActivityPub Publishing

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/01a06eb0-…


Nach mehreren Tagen Messung möchte ich unsere Untersuchung zum ungewöhnlich
anwachsenden PHP-FPM-Pool abschließen.

Der wichtigste Befund ist inzwischen recht eindeutig:
Von 196.466 ausgewerteten Slowlog-Ereignissen enthielten 195.069 einen
curl_exec()-Aufruf, also rund 99,3 Prozent.

Zusätzlich konnten wir einen betroffenen PHP-FPM-Prozess während eines realen
Ereignisses mit ss und strace beobachten. Dabei wartete der Prozess über viele Sekunden wiederholt in poll() auf Daten eines externen HTTPS-Sockets. Über ss ließsich derselbe File-Descriptor derselben PID eindeutig einer externen Verbindung zuordnen. Gleichzeitig bestanden mehrere weitere PHP-FPM-Verbindungen zu denselben wenigen Gegenstellen.

MariaDB und Redis antworteten im selben Zeitraum dagegen sehr schnell. Der Engpass
lag also nicht primär im lokalen System, sondern im Warten auf externe HTTP-
Kommunikation.

Nach der schrittweisen Anpassung der Wartezeiten und der FPM-Reserve hat sich das
Verhalten deutlich beruhigt. Auch der Load Average ist wieder auf ein normales Niveau
zurückgegangen. Die Zahl der Slowlog-Ereignisse fiel ab dem 4. September massiv ab.

Der Slowlog ist deshalb inzwischen wieder deaktiviert.

Mein persönliches Fazit aus der Untersuchung geht inzwischen über die konkrete
Friendica-Instanz hinaus:

Eine föderierte Instanz muss nicht nur selbst stabil laufen. Sie muss auch so mit
langsamen, fehlerhaften oder zeitweise unerreichbaren Gegenstellen umgehen können,
dass deren Zustand die eigene Funktionsfähigkeit möglichst wenig beeinflusst.

Ich habe die Ergebnisse deshalb noch einmal ausführlicher in einem Fachartikel
zusammengefasst:

Föderation braucht Fehlertoleranz an den Instanzgrenzen

Hier der vollständige Artikel

Dabei verzichte ich bewusst auf konkrete Grenzwerte oder eine allgemeine „Best-Practice-
Konfiguration“. Die Werte hängen zu stark von Instanzgröße, Nutzung, Federation-
Volumen und Systemumgebung ab. Entscheidend ist aus meiner Sicht nicht das Kopieren
einzelner Parameter, sondern das Verständnis der Zusammenhänge und die Messung auf
der eigenen Instanz.

#Friendica #Fediverse #Sysadmin #ActivityPub #Federation


Week in Fediverse 2026-09-04


Servers

- Ktistec v3.12.0
- Mastodon v4.7.1
- Vernissage v1.43.0
- snac v2.95
- ActivityPub for WordPress v9.3.0
- Owncast v0.3.0
- gathio v1.6.6
- NodeBB v4.15.2
- tootik v0.25.2
- NeoDB v0.18.0
- Bonfire v1.0.7

Clients

- PleromaFE v2.11.4
- Fedilab v3.43.3
- Tuba v0.11.1
- Pixelix v5.2.0
- Summit v1.85.0
- Shoot Web App v1.3.0

Tools and Plugins

- FediFetcher v8.2.0
- Poduptime v6.3.2
- Enable Mastodon Apps v1.6.3 (WordPress plugin)

For developers

- APx v0.27.0
- Library progress report - September 2026 (GoActivityPub)

Articles

- A reasonably practical guide to validating RFC 9421 HTTP Signatures for ActivityPub in PHP

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/01a04a26-…


I've just published version 2.95 of #snac, the simple, minimalistic #ActivityPub instance server written in C. This is an important release, as it fixes an issue that can lead to denial of service attacks, so please update as soon as possible. It also includes the following changes:

Fixed a bug in the notification page that made snac hang forever while trying to read abnormally big files.

Improved support for text-only web browsers: it's now possible to configure a set of web browser user-agent strings that will receive simpler HTML in the private timeline web UI. Basically, it consists in avoiding details / summary HTML tags as much as possible.

Added some fixes to media proxy code.

Fixed EmojiReact code to allow any emoticon defined in emojis.json, not only those with colon-wrapped identifiers.

Fixed a bug in notification filtering (paging was sometimes incorrect).

Added a notification filter for Webmentions.

Mastodon API: Don't return reactions count as string (contributed by mkljczk), implemented GET /v1/media (contributed by clairemont).

Fixed bug in documentation examples (contributed by Sprite_tm).

Updated Ukrainian and Russian translations (contributed by wincentbalin and koru).

comam.es/what-is-snac

If you find #snac useful, please consider buying grunfink a coffee or contributing via LiberaPay.

#snacAnnounces #FrugalFediverse



#Fread 1.10.0 版本已经发布,以下是更新日志:

- 新增 AI 翻译
- Feeds 流支持加载缩略图
- 优化沉浸式浏览体验
- 优化 AI 设置
- 修复一些已知问题

#Mastodon #fediverse #Opensource
#RSS #FOSS #Freesoftware

github.com/0xZhangKe/Fread/rel…


The media in this post is not displayed to visitors. To view it, please go to the original post.

A video I tried to archive after the freedom of form foundation tried to erase some of the work from Atha (who was a compliance officer and was essentially given a unreasonable situation and was essentially kicked out) years ago got copyright striked by the fff recently

Any peer tube instances I can reupload this to
There's been more and more members leaving the fff recently as well as the fff leaves it's original purpose and enshitifies and becomes more corporate

Also boosting is appreciated

#fediverse #censorship #peertube #askfedi #vulpinelabs #freedomofform #transrights #science #preservation


9.3.0 — Modern Signatures and a Summer of Security Reports


The media in this post is not displayed to visitors. To view it, please go to the original post.

It has been almost three months since 9.0.0, and eight releases: 9.0.1, 9.0.2, 9.1.0, 9.2.0, 9.2.1, 9.2.2, 9.3.0, and now 9.3.1. Together they added seven new things, closed ten security issues, and fixed close to fifty bugs, which is a very different balance than usual.

This post covers the new things first, and then explains where the rest of the summer went.

Modern Signatures, On by Default


Every message your site sends to the Fediverse carries a signature, the digital equivalent of a wax seal on an envelope. In July 2025 we wrote about the move from the old draft format to RFC 9421, the official standard. Back then, sending with the new format was a setting for early adopters, and we promised to turn it on for everyone once the rest of the Fediverse was ready.

With 9.3.0 it is on by default. Your site now signs outgoing requests with RFC 9421, and falls back to the old format when the server on the other side does not understand it yet. For almost everyone this changes nothing you can see. Your posts keep arriving, your follows keep working.

A small number of servers advertise support for the new format but handle it differently in practice. If your posts suddenly stop arriving on one particular server after this update, you can switch back. Open the ActivityPub settings, click Screen Options in the top right, enable Advanced Settings, and turn off the modern signature format in the Advanced tab. Please let us know in the support forum which server it was, so we can look into it.

Your Podcast Travels With Its Audio


If you publish podcast episodes with Jetpack, your episodes now federate as episodes. The audio file and the cover art travel with the post, so your followers get a playable player in their Fediverse app instead of a link they have to click through.
A screenshot of a WordPress hosted Podcast Episode on Mastodon.
Version 9.1.0 did the same for Podlove Podcast Publisher, where the episode summary now goes out with the post rather than being dropped.

A Quieter Inbox


Likes, reposts, and quotes are lovely until there are two hundred of them and your email inbox has two hundred entries. Until now, switching those off meant switching off notifications for real comments and replies too.
Screenshot of the E-Mail Notification settings in WP-Admin.
9.3.0 separates them. There is a new notification setting that turns off emails about likes, reposts, and quotes, while comments and replies from the Fediverse keep reaching you. Reactions still show up on your post, you just stop hearing about each one individually.

Smaller Things You Might Notice


  • Fediverse and ActivityPub logos in the editor. On WordPress 7.1 and newer, both logos are part of the block editor’s icon library, so you can use them in a Social Icons block or anywhere else an icon fits.
  • The follow, reply, and reaction dialogs speak up. Screen readers now announce errors in those dialogs instead of leaving people guessing why nothing happened.
  • Scheduled posts show the right preview. Since 9.1.0, a scheduled post shows the Fediverse Preview, so you can see what your followers will get before it goes out.
  • Avatars that actually update. The scheduled refresh of remote profiles was not refreshing anything. Commenters kept the avatar and bio they had when they first showed up. Fixed in 9.1.0.
  • Two new FAQ guides, added in 9.0.1, for the two questions we get most often: follow requests stuck on “pending”, and comments from the Fediverse not appearing on your posts.


For People Building on the Plugin


9.1.0 added an actor autocomplete endpoint, so a Fediverse app connected to your site can offer typeahead search when you are mentioning someone. There is also a new filter for sites that need to federate inside a private or internal network, which mostly matters for intranets and staging setups.

In 9.3.0, apps connected through the ActivityPub API now use the standard permission names from the specification, and fetching remote content through your site counts as reading rather than posting. Apps also see the real error when a post is missing, instead of a generic failure that told them nothing.

Where the Summer Went


Seven new things in three months is not much. Here is the reason.

Since June we have had a steady stream of security reports. Ten of them became entries in the changelogs of 9.1.0 and 9.3.0, and a few more landed quietly as fixes. Every report has to be read, reproduced, judged, fixed, tested, and shipped, and the fix has to be written so it does not break the sites that already work. For a team our size that is most of a week each time, sometimes more.

This is not a complaint, and a real thank you to everyone who sent a report and then waited while we worked through the queue. Nearly all of the reports were real, and every one of them made the plugin safer for the people running it. This is responsible disclosure working the way it should. It just means the roadmap moves slower than it looks on paper, and features that were planned for July are still open.

We are not alone in this. WordPress core is seeing the same wave, and for the same reason: AI models have become good enough at reading code that finding a plausible vulnerability is now cheap. The security team wrote about it in The Core Security Initiative, and the project started Protect The Shire to review the code in the plugin and theme directories at a scale that was not possible before. The same tools that raise the number of reports also help everyone work through them. On balance, we think this is good for the ecosystem, even on the weeks where it does not feel like it.

In general terms, the security work in these releases covers four areas:

  • Content from other servers is cleaned before it is stored, and again before it is displayed, so what another server sends cannot influence how your site behaves.
  • Data that belongs to you stays yours. Your followers, the profiles your site has cached, and your reader posts are not readable by logged-out visitors, and the setting that hides your follower list is respected everywhere.
  • Activities are checked more strictly against the account they claim to come from, so a server cannot act on behalf of someone else.
  • Apps you connect can only do what you allowed them to do, and nothing wider.

We are keeping this vague on purpose. The details are in the reports, and we would rather not hand a recipe to anyone whose site has not updated yet. If you run the plugin, please update.

What the Fixes Cover


The fifty or so fixes across these releases are not one story, but they fall into a few groups:

  • Finding each other. Profiles and posts were not always found when an address contained unusual characters, or was written with different capitalisation, or when the other server answered in an unexpected shape. Several fixes make lookups work in all of those cases.
  • Reactions arriving once. Likes and boosts could be recorded as duplicate comments, or come back after you marked them as spam. A deletion on Mastodon did not always remove the matching comment on your site. Both are fixed.
  • Caching. ActivityPub responses were sometimes stored by page caches meant for regular web pages. Since 9.2.0, those responses are served only to clients that ask for ActivityPub data and nothing else, which keeps them out of caches like LiteSpeed and Surge. Support for the WP REST Cache plugin was removed as part of this.
  • Publishing edge cases. Posts scheduled for a future date were removed from the Fediverse when edited. Hidden page elements, like the text inside a closed dialog, ended up in the content sent to your followers. Backslashes vanished from imported titles. Small things, annoying every time.
  • Living with other plugins. Fixes for sites running Polylang, Jetpack, Surge, and the Mastodon importer, which was creating duplicate posts when an archive was imported twice.
  • Admin screens and the editor. Styles that failed to load on the Fediverse screens and in the Followers and Following blocks, an editor warning about unsaved changes that appeared right after saving, and a handful of errors that filled up log files without breaking anything visible.

The full, item-by-item changelog for every release is in the plugin’s changelog if you want to read it in detail.

Get It


Download from WordPress.org or grab it on GitHub. If your site updates automatically, you already have it.

Thanks to everyone who filed a bug report with steps we could follow. Those are the ones that get fixed fastest.

Now that signatures are modern by default: does anything still deliver differently for you? And what would you like to see us build once the queue is shorter?


Hello !Friendica Support

Does anyone know what exactly happens when changing an existing Friendica instance from "Single user instance" to "Multi user instance"?

Is this basically just enabling registration/additional local accounts, or are there any other behavioural changes or side effects I should be aware of?

The instance has been running as a single-user instance for quite some time, so I'm particularly interested in whether switching an existing installation is completely safe and reversible.

#Friendica #Fediverse #SelfHosting


Week in Fediverse 2026-08-28


Servers

- Hollo v0.9.13
- gush! v0.0.41
- tootik v0.25.0
- Mitra v5.10.0
- Pixelfed v0.12.9
- Hollo v0.9.15
- Funkwhale v2.0.10
- PieFed v1.7.13
- tootik v0.25.1
- NeoDB v0.17.8

Clients

- Pachli v3.8.1
- Fedilab v3.43.2
- RaccoonForFriendica v1.1.0

For developers

- Fedify v2.3.6

Protocol

- FEP-49eb: Batched Inbox Delivery

Articles

- A crawler wanted to know who talks to whom on our server
- The Problems and Successes of Fediverse Comments on my blog
- The Fediverse is Throwing a Music Festival

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/01a0269e-…


#Mastodon is the powerful war rig in the #Fediverse army against the axis of biased social networks; #snac is the little buffoon back there in the rearguard, playing their old-fashioned lute and making silly jokes.

#CrazyFediverseAnalogies


Week in Fediverse 2026-08-21


Servers

- Funkwhale v2.0.8
- PieFed v1.7.11
- TinyAP v0.1.13
- Wafrn v2026.08.04
- Mastodon v4.7.0
- gathio v1.6.5
- NeoDB v0.17.7
- NodeBB v4.15.1
- Flox v2.7.0
- 5.0: Laying the foundation (Mastodon)

Clients

- PleromaFE v2.11.3
- chan-fe v0.3.0
- Tuba v0.11.0
- Mangane v1.24.3
- Mastodon for iOS v2026.07
- Miria v4.0.0+125
- Summit v1.84.0
- Voyager v2.48.5
- Pixelix v5.1.1

Tools and Plugins

- Pluraldawn: Decodes indicator emoji information from account avatars to provide a PluralKit-esque experience inside of various fediverse webapps

Protocol

- ActivityPub Miscellaneous Terms

Articles

- Implementing Pagination for ActivityPub Collections
- Owncast Newsletter August 2026

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/01a001c8-…


!Friendica Admins
📢 Einladung zum 6. Friendica-Admin-Treffen

📅 Montag, 24.08.2026
🕢 19:30 Uhr (MESZ)

Hallo zusammen,

am kommenden Montag ist es wieder soweit: Wir laden herzlich zum 6. Friendica-Admin-Treffen ein.

Eingeladen sind alle Friendica-Admins, Instanzbetreiber, Entwickler:innen sowie alle, die sich für den Betrieb und die Weiterentwicklung von Friendica interessieren.

🔹 Ein mögliches Thema für den Abend:
Mit Friendica 2026.08-rc ist der Release Candidate der kommenden Version veröffentlicht worden. Eine gute Gelegenheit, gemeinsam einen Blick darauf zu werfen:

Was gibt es Neues? Gibt es bereits erste Erfahrungen mit dem RC? Welche Änderungen sind besonders für Administratoren interessant? Und vielleicht können wir auch einen vorsichtigen Blick darauf werfen, wie der weitere Weg bis zur nächsten stabilen Friendica-Version aussieht.

Dabei geht es natürlich nicht darum, einen Veröffentlichungstermin einzufordern – schließlich gilt auch bei Friendica: Es ist fertig, wenn es fertig ist. 😉

💬 Weitere Themen und Fragen sind ausdrücklich willkommen!

Bringt gerne eure Erfahrungen, Ideen, Fragen oder aktuelle Herausforderungen aus dem Alltag als Friendica-Admin mit. Oft entstehen gerade aus dem offenen Austausch die interessantesten Gespräche.

Wir freuen uns auf einen informativen und gemütlichen Abend mit euch und auf einen regen Austausch rund um Friendica. 🌐

💻 Online-Konferenzraum

Gerne weitersagen und auch andere Friendica-Admins und Entwickler:innen auf das Treffen aufmerksam machen.

#Friendica #Fediverse #FriendicaAdmin #AdminTreffen #OpenSource


The media in this post is not displayed to visitors. To view it, please go to the original post.

Frage | Friendica: Wie gut funktioniert das mit der Federation?


Guten Morgen Zusammen :-) Ich habe mal eine Frage betreffs Federation. Und zwar habe ich gesehen das ich in Sachen Beiträge vor allen via Lemmy Feedback bekomme, aber in den allermeisten Fällen kaum aus dem Rest des Fediverse. Dabei ist mir klar das ich wenn ich in eine Lemmy Community poste, ich recht viele Leute erreiche. Aber das erklärt eben nicht warum aus dem Rest des Fediverse wo ich sehr viel mehr Kontakte habe die mir folgen so wenig zurück bekomme.

Ist Euch ähnliches aufgefallen?

#Frage #Friendica #Federation #Feedback #Fediverse #Lemmy !Friendica Support


The media in this post is not displayed to visitors. To view it, please go to the original post.

I’ve updated the Dystronix Pixelfed icon.

The new gradient icon helps distinguish Dystronix on Pixelfed from dystronix.com. #fediverse #photography #streetphotography


Week in Fediverse 2026-08-14


Servers

- Akkoma v2026.08
- WriteFreely v0.17.2
- Wafrn v2026.08.03
- Mitra v5.9.0
- Ktistec v3.11.0
- Hollo v0.9.11
- Mastodon v4.6.6
- Forte v26.8.11
- gathio v1.6.4
- ActivityPub for WordPress v9.2.2
- NeoDB v0.17.6
- NodeBB v4.15.0
- Trunk & Tidbits, July 2026 (Mastodon)

Clients

- Aria v1.5.11
- Snowdrop: Multiplatform client for Mastodon API compatable Fediverse software

Tools and Plugins

- FediFetcher v9.1.1

For developers

- Fedipub v0.9.0
- Library progress report - August 2026 (GoActivityPub)

Protocol

- FEP-e4de: Closing Registration on Unattended Servers
- FEP-633c: Guardians

Articles

- Deploying your own Vernissage instance

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/019fde3b-…


The media in this post is not displayed to visitors. To view it, please go to the original post.

For: Linux distro developers
Subject: Switched my Linux distro to XLibre

This is a copy of a post that I made just now in the Github issues section for XLibre. Link to the original post:
github.com/orgs/X11Libre/discu…

I've been developing a Linux distro, #Laclin, for 30 years. In the past 24 hours, I've switched, for now, from the old #Xorg framework to #XLibre. This includes, so far, xserver and some of the video drivers. I'll comment below on the rest.

This is my desktop running on XLibre:
260813-laclin-desktop

The desktop is original. The parts add up to only a few MB. I like light and stable. I'm not a fan of sumo-wrestler size layers that gobble up GB of RAM and drag performance down to Windows level.

I'm also the type that holds up a cross and recites "Get thee behind me, Satan" when I see systemd and Wayland. No offense to fans of systemd and Wayland is intended. But I don't plan to switch to either. So, XLibre is a positive development.

I've had no "build" or runtime issues with XLibre xserver so far. I needed to switch some of the video drivers to the XLibre forks in order to get them to build. I'd switch other components as well, but here's the thing:

Did I mention that I have 30 years of work invested in the distro? I don't want to break 2,000 packages.

The distro includes legacy packages, some of which no other distro has. The code goes back as far as the 1990s. [The 1970s to 1980s, in a few cases.] If XLibre drops ".pc" or ".la" files [as I gather it did in one case] the packages won't build. [Yes, I understand that that change was reverted.]

So, I have four requests:

  1. Keep up the good work. The fork needs to continue or the distros that are switching will be between a rock and a hard place.
  2. Prioritize backwards compatibility to the extent that old packages can be built in the new framework.
  3. Use of systemd should be optional.
  4. Set up a #Fediverse account and post there. LibreOffice, The GIMP, G'MIC, Project Gutenberg, Internet Archive, Dillo, LibreWolf, and many other projects do. It's a FOSS friendly environment.

The desktop in the screenshot is based on jwm with features added using lightweight scripts. It's got Start button, Boss button, taskbar, workspaces, systray, launch buttons, and dockapps. Plus Alt-Tab and single-instance support. I figure that that is most of what is needed.

It runs fine so far in XLibre. I'm not going to port 30 years of work to a new framework [Wayland] that intentionally breaks things and that isn't going to support old software or hardware.


I’ve been thinking about how the internet shapes polarization.After gathering on massive social platforms, many people now seem to be looking for smaller places that feel like their own.A huge public square where opposing views constantly collide can easily create conflict.Maybe the Fediverse is still underestimated—not just because it’s decentralized, but because it lets us stay connected while keeping some distance.We don’t all have to live in the same square to share the same world
#fediverse



Only 2 days left to share your voice in our annual #Fediverse survey!

If you run, manage, or moderate a #SocialWeb service, your anonymised and aggregated feedback goes directly to lawmakers and regulators around the world.

If they don’t know our concerns, they can’t write laws that protect our mission.

Help shape the policies that impact us. Take 5 minutes to share your experience:

➡️ tally.so/r/81MW6k


Hello World


Coucou! This is just a first post announcing Nuages to the world.

Nuages is an ActivityPub app, connecting to your favourite servers that support the Client to Server API.

Follow us to get our latest updates, we’ll be officially launching the app in the coming weeks 😉

#ActivityPub #c2s #ActivityPubAPI #Fediverse


Opengraph image different from Avatar?

!Friendica Support

Hi,

is there a way to configure per account a different opengraph image than the avatar image?

Reason I am asking is, when I am sharing single posts (no urls to articles) on other networks I would love to use a different standard image, where e.g. I can advertise the #fediverse in words and logo.

So sharing would meet 3 situations

  1. Sharing a post with my profile URL = my avatar
  2. Sharing a post - no URL provided = my fediverse logo / fallback (if not defined) my avatar
  3. Sharing a post with an article url = the article opengraph image

What do you think? And would it be possible?


📋 Rückblick auf das Friendica-Admin-Treffen vom 27.07.2026

Am Montag fand wieder unser monatliches Friendica-Admin-Treffen statt. Erfreulicherweise waren zahlreiche Administratoren und auch mehrere Entwickler dabei – genau so wünschen wir uns den gemeinsamen Austausch. 😊

Ein Thema war der Umgang mit Meldungen (Reports) im Administrationsbereich. Wir haben besprochen, wie Administratoren und Moderatoren mit gemeldeten Inhalten umgehen können, welche Schwierigkeiten es derzeit gibt und welche Verbesserungen wünschenswert wären. Die Entwickler haben die Anregungen aufgenommen und möchten sich die Vorschläge genauer ansehen.

Außerdem ging es um die Änderungen beim Start von Daemon und Worker. Für Administratoren hat sich der Aufruf über die Kommandozeile etwas ändern. Die neue Methode kann bereits genutzt werden und sollte rechtzeitig eingerichtet werden.

Ebenfalls vorgestellt wurde die neue Technik für schnellere Seitenaktualisierungen. Statt künftig bei jeder Aktion die komplette Seite neu zu laden, werden nur noch die geänderten Bereiche aktualisiert. Dieses Prinzip nennt sich SPA (Single Page Application). Dadurch wirkt Friendica deutlich flüssiger und reaktionsschneller. Die Funktion befindet sich derzeit noch in der Entwicklerversion und könnte bereits mit einer der nächsten stabilen Friendica-Versionen verfügbar werden.

Kurz gesprochen wurde auch über das Übersetzer-Addon. Oldkid stellte den aktuellen Stand seiner Arbeiten vor und gab einen Einblick in die Funktionsweise des Addons.

Wie immer blieb genügend Zeit für Fragen, Ideen und den direkten Austausch. Genau das macht diese Treffen so wertvoll: Entwickler und Administratoren kommen miteinander ins Gespräch, diskutieren ausführlich über aktuelle Themen und entwickeln gemeinsam neue Ideen.

💬 Für den Austausch zwischen den Treffen gibt es außerdem eine XMPP-Gruppe für Friendica-Administratoren und Entwickler, die von tuxi bereitgestellt wird. Wer daran teilnehmen möchte, kann sich für eine Einladung einfach bei @Tuxi ⁂ , @OldKid ⁂ oder @Jools melden.

Vielen Dank an alle Teilnehmenden für den offenen und informativen Abend!

📅 Das nächste Friendica-Admin-Treffen findet am Montag, 24.08.2026, um 19:30 Uhr statt. Interessierte Administratoren und Entwickler sind herzlich willkommen.

#Friendica #Fediverse #OpenSource #Community #Systemadministration @Friendica Admins


There is too much tech/features talk and too little UI/UX or just “beauty” talk in the Fediverse.

Let’s please take some time to appreciate how gorgeous @Bonfire’s interface and the design choices are.

The article sharing the Jacobin case study is so cool!

#UI #UX #beauty #Fediverse #interface #design #graphicDesign


The Blog Option in littleFedi


littleFedi, like many social platforms, had both a strength and a limit. Posts, by their nature, are ephemeral. They get published, federated (unless local-only, which littleFedi handles) and then, over time, lost. Partly through self-deletion, partly through their normal blending in with the thousands of other posts that pile up over time. Sometimes, though, we want something to stay. And not just stay as a social post, but as an actual blog. A bit like with BSSG, I had thought it would be convenient to have a minimal system. Not to compete with WordPress or other solutions, but to have a small blog, integrated into littleFedi, that would produce and serve a blog updated every now and then, whenever the person writing felt like doing it.

And that's why the blog option was born.

The idea is simple: when you write a post, from the web UI or from the CLI, there's a checkbox, "blog post". If you check it, that post stops being just a status that will scroll past and disappear. littleFedi renders it into a real static site. No JavaScript, just HTML and CSS, an Atom feed, tag pages, a chronological archive. Nothing exotic, nothing that needs maintenance five years from now.

The blog isn't a parallel system you have to feed separately. It's not an export, not an import, not a bridge to some other CMS. The post you wrote is the blog post. Same database, same act of writing, still boostable, still repliable, still part of the conversation on the fediverse side. The blog is just a second representation of the same content, generated automatically. Every time you create, edit, or delete a blog post, the whole static site for your account gets rebuilt from scratch, and the new version replaces the old one atomically, so nobody ever lands on a half-built page. If the build fails, the previous version stays in place. Simple, but it has to work reliably, or the whole idea is pointless.

That's the core of it: two representations of the same post. As a status, it lives in the fediverse, interactive, part of the conversation, subject to replies and boosts like anything else. As a static page, it lives on the web, durable, indexable, with a permalink, something an RSS reader can hold onto. You don't have to decide in advance which posts deserve to last. You write normally, and if something turns out to be worth keeping, you flag it, and it gets its own page.

One detail I cared about while thinking this through: the generated site has to be self-contained. When littleFedi builds it, media gets copied or hard-linked into the generated directory - images, audio, video. If it's stored on S3, it keeps its public URL directly. Either way, the point is that the site on disk doesn't depend on the instance staying up. If the server goes down tomorrow, the blog files are still a complete, working website. That wasn't an afterthought, it was one of the requirements from the start.

Not every account gets a blog, and that's intentional. The instance admin has to enable the feature globally ([blog] enabled = true), and then grant it per account. It's not meant to be a CMS, and I didn't want it to become one. Blog posts can't be replies, can't be boosts, have to be public and top-level. These are constraints, not missing features: the blog is for your own writing, not for threads or reshared content.

There's no JavaScript anywhere in the generated site. That was deliberate too. It loads fast, it works offline if you cache it, and it will still render correctly in ten years without anyone having to update a dependency.

In the end, the blog option doesn't ask you to choose between writing socially and writing something permanent. You keep writing the way you always do, on littleFedi, and if a post is worth keeping, you check a box. No separate platform, no migration, no vendor lock-in. Just your own posts, some of them rendered into a small static site you can host anywhere, built out of something that already existed on the open web.

Remember: all this is being currently served by a Raspberry PI Zero W powered by NetBSD

Here's the result: rpi0w.stefanomarinelli.it/@ste…

#littleFedi #SSG #BSSG #OwnYourData #Blogging #Fediverse #NetBSD


🔔 Erinnerung: Friendica-Admin-Treffen

Am Montag ist es wieder soweit!

📅 Montag, 27.07.2026
🕢 19:30 Uhr

Gemeinsam werfen wir einen Blick auf aktuelle Entwicklungen rund um Friendica. Geplant sind unter anderem:

🔹 Änderungen beim Start von Daemon und Worker
🔹 Die neue Technik für schnellere Seitenaktualisierungen

Wie immer gilt: Bringt gern eure Fragen, Erfahrungen und Themen mit. Der Austausch untereinander ist mindestens genauso wertvoll wie die vorbereiteten Themen.

📣 Gebt die Einladung gern auch an andere Friendica-Admins und Entwickler weiter. Je mehr teilnehmen, desto vielfältiger werden Erfahrungen, Ideen und Lösungsansätze.

Wir freuen uns auf einen informativen und gemütlichen Abend mit euch! 😊

#Friendica #Fediverse #OpenSource #Community #Systemadministration

@Friendica Admins


Week in Fediverse 2026-07-24


Servers

- WriteFreely v0.17.0
- Ktistec v3.9.0
- Vernissage Server v1.41.0
- GoToSocial v0.22.1
- Bookwyrm v0.9.1
- PeerTube v8.2.3
- Lemmy v0.19.20
- ties v0.3
- ActivityPub for WordPress v9.1.0
- NeoDB v0.17.2
- NodeBB v4.14.2
- PieFed v1.7.7
- FitPub v1.2.1
- ActivityForge: ForgeFed implementation in Rust

Clients

- PleromaFE v2.11.1
- Aria v1.5.9
- Pixelix v5.0.0
- Summit v1.83.0
- Jerboa v0.0.88
- Holos v1.15.0
- Rocinante v1.1.8

Tools and Plugins

- Superblock v3.1 (Hubzilla addon)
- Polls for ActivityPub v1.0.10 (WordPress plugin)

Protocol

- FEP-de8d: Emoji Catalogs

Articles

- I added ActivityPub to this blog

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/019f71c0-…


Week in Fediverse 2026-07-17


Servers

- flohmarkt v0.20.0
- Vernissage Server v1.40.0
- FitPub v1.2.0
- Wafrn v2026.07.02
- TinyAP v0.1.11
- NeoDB v0.16.5.0
- PieFed v1.7.6
- Catodon v26.7.0
- Trunk & Tidbits, June 2026 (Mastodon)
- matrix-appservice-activitypub: Turns your Matrix server into a fully functioning ActivityPub server
- Discord–Fediverse Bridge: A self-hosted bridge between Discord forum channels and ActivityPub community actors
- ~petersanchez/honk: Fork of honk

Clients

- PeerTube Mobile v2.2.0
- Photon v2.4.0
- Tesseract v1.5.5
- Aria v1.5.8
- Mitra Mini v0.5.0

Tools and Plugins

- Enable Mastodon Apps v1.6.1 (WordPress plugin)
- Polls for ActivityPub v1.0.9 (WordPress plugin)
- Telegram ↔️ Mastodon Bridge Bot: A Python bot that forwards text messages, photos, and albums from a Telegram chat to your Mastodon account

For developers

- @shootpub/activitypub-types: ActivityPub types package with support for FEP-2277 Activitypub core types (duck typing)

Articles

- The Long Tail of Work Left Until ActivityPub Has E2EE

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/019f4de5-…


Threads 連上聯邦宇宙真的只做半套,比bluesky 橋接到聯邦宇宙遇到的問題還多。

#fediverse #threads #bluesky


【研究】你看到的動態消息,不是巧合:社群平台為什麼容易往右靠

這幾年你可能也感覺到了:社群平台上看到的內容好像變得更兩極、更容易吵起來。這不完全是錯覺,也不是巧合——這跟演算法的設計邏輯有關,也跟這些平台最近幾年一次次鬆綁內容審核政策有關。對跨性別者等邊緣族群來說,這不只是「討厭」而已,而是攸關能不能安全地待在網路上發言、生活。

閱讀全文: ethome.cc/algorithm-mastodon-d…

---
ETHome | 資訊安全自媒體
給每個人的資安,也給最需要的人
#Fediverse #Mastodon #演算法 #社群平台 #資料自主權 #跨性別


Week in Fediverse 2026-07-10


Servers

- Betula v1.8.1
- Stegodon v1.8.6
- Ktistec v3.8.0
- Mitra v5.7.0
- Ibis v0.3.3
- Gathio v1.6.3
- NodeBB v4.14.0
- Wanderer v0.20.0
- Wafrn v2026.07.01
- Gush! v0.0.40
- PieFed v1.7.5
- Harmony v1.4.0

Clients

- Mastodon for iOS v2026.05
- tooi v0.27.0
- Voyager v2.47.4
- Aria v1.5.7
- Holos v1.14.0
- Rocinante v1.1.0
- chan-fe: Imageboard-style frontend for Mitra and Mastodon-compatible fediverse APIs

Tools and Plugins

- tag-federation.online: How Widely Do Hashtags Federate?
- Fedigraph: A dashboard for exploring the fediverse

For developers

- BotKit v0.5.0

Protocol

- FEP-4772: Representing bookmarks
- FEP-521b: Switch the default in FEP-521a to be 76171% cooler

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/019f29a4-…


#Mitra v5.7.0

codeberg.org/silverpill/mitra/…
codeberg.org/silverpill/mitra-…

- Improvements related to groups: adding group description, editing and deleting groups, better navigation.
- Showing total number of voters in polls.
- The "Posts and replies" tab was removed from the profile page, replaced with filters (show reposts / show replies).




Friendica Plausch


The media in this post is not displayed to visitors. To view it, please go to the original post.

Friendica Plausch
Starts: Saturday, July 11, 2026 at 12:00:00 PM UTC
Finishes: Saturday, July 11, 2026 at 12:45:00 PM UTC

Statt FAQ zu lesen oder sich Videos anzusehen, könnte man einfach ins Gespräch kommen.

Der Termin richtet sich an alle Menschen, die von LinkedIn, Facebook, 𝕏 oder einer anderen unfreien Plattform weg wollen. Die sich für Friendica interessieren, beim Start noch etwas Hilfe benötigen oder konkrete Fragen zur Anwendung haben.

Der Rahmen:


  • Jeden Samstag 14 Uhr
  • 45 Minuten Plausch
  • Deine Fragen zur Anwendung
  • Realisiert über meet.jit.si/FriendicaPlausch
  • ohne Cam aber mit Mikrofon


Komm einfach vorbei. Wir lassen uns von den Themen tragen.

#Friendica #Fediverse #DIDit #DUTgemacht #DIDAY

Location: meet.jit.si/FriendicaPlausch


Ich habe heute baraag.net komplett blockiert.

Nachdem ich in den letzten Tagen bereits 17 Accounts von diesem Server einzeln sperren musste, weil sie sexualisierte Darstellungen offensichtlich minderjähriger Figuren in Form von #Cartoons, #Manga oder #Anime, verbreiteten oder teilten, ist für mich die Grenze erreicht.

Wer solche Inhalte nicht im #Fediverse sehen möchte, sollte überlegen, den gesamten Server zu blockieren.

Je nach Ausgestaltung können solche Darstellungen in mehreren Ländern in #Europa strafrechtlich relevant sein, insbesondere in der #Schweiz sowie, abhängig von den konkreten Umständen, auch in #Deutschland und weiteren EU-Staaten. Allein deshalb ist das kein Thema, bei dem ich Kompromisse eingehe.

#Friendica #Mastodon #Moderation #Kinderschutz


Week in Fediverse 2026-07-03


Servers

- TinyAP v0.1.10
- GoToSocial v0.22.0
- Mobilizon v5.2.4
- Bonfire v1.0.5
- PeerTube v8.2.2
- Ktistec v3.7.0
- PieFed v1.7.0
- Mastodon v4.6.3
- Hollo v0.9.6
- ActivityPub for WordPress v9.0.2
- NeoDB v0.16.3
- Wanderer v0.19.3
- Trunk & Tidbits, May 2026 (Mastodon)
- Lemmy Development Update June 2026 and 1.0.0-beta.1

Clients

- Fedilab v3.42.1
- Pachli v3.7.1
- Aria v1.5.5
- Rocinante v1.0.9
- Holos v1.12.0
- Mitra Mini v0.4.2

Tools and Plugins

- FediFetcher v7.1.21
- owncast-emojiwall v2.1.0
- Polls For ActivityPub (WordPress plugin)

For developers

- Why implementing ActivityPub is hard, and why it doesn't have to be (Fedify)

Protocol

- FEP-8c13: Context-Authority Routing with Object Integrity Proofs for Restricted Threads
- FEP-f228: Backfilling conversations (Final comments)
- FEP-7628: Move actor (Final comments)

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/019f058a-…


Why implementing ActivityPub is hard, and why it doesn't have to be


A quiet failure


Picture the moment your server sends its first Follow activity to Mastodon. You read the spec, built the JSON, signed the HTTP request, and POSTed it with care. What comes back is a single line: 401 Unauthorized. No body. No explanation.

What went wrong? Maybe the clock behind your Date header drifted a few minutes. Maybe the hash in your Digest header is off. Maybe you uppercased the (request-target) pseudo-header while building the signing string, or published your public key as PEM where the other side wanted multibase. The remote server won't tell you. So you start reading someone else's server code to debug your own.

I know, because I've been there. Fedify began as a casualty of another project. I set out to build a single-user microblogging server, the one that would later become Hollo, and started implementing ActivityPub from scratch. Somewhere between the signature specs and the JSON-LD, the protocol work swallowed the product, and I put the whole thing down. What I picked back up wasn't the app. It was the framework the app should have had. Fedify shipped first; only then could Hollo exist, built on top of it. (I've told this story at more length in A year with the fediverse.)

ActivityPub development gets hard in a few very specific places. In this post I want to walk through five of them, then show what each one looks like with Fedify. If you've spent time in the fediverse, you'll probably nod along. If you haven't, you may wonder why anyone would do all of this by hand. Either way, the conclusion is the same: nobody has to anymore.

Five scenes

Scene 1: there is more than one standard


ActivityPub servers authenticate each other with HTTP signatures. Except there isn't one signature spec. Most of the fediverse runs on draft-cavage-http-signatures-12, an expired draft that never became a standard. The actual standard exists too: RFC 9421, HTTP Message Signatures. The problem is that you can't know which one a given server accepts until you try.

A real-world implementation therefore has to sign with one spec, see whether it gets rejected, re-sign with the other, and remember per server which one worked so it can skip the dance next time. The fediverse calls this double-knocking. Yes, you get to implement it yourself.

That's still not the end. HTTP signatures only prove who sent a request. For situations like inbox forwarding, where you relay an activity you received to a third party, you need signatures that live on the document itself: Linked Data Signatures and Object Integrity Proofs. Four signature mechanisms in total, and two kinds of keys to manage: RSA and Ed25519.

Scene 2: one document, many shapes


ActivityPub's wire format is JSON-LD, and in JSON-LD the same document can take many shapes. This is easier to show than to explain. Here is a Create activity one server might send:

{
  "@context": "https://www.w3.org/ns/activitystreams",
  "type": "Create",
  "actor": "https://example.com/users/alice",
  "to": "https://www.w3.org/ns/activitystreams#Public",
  "object": {
    "type": "Note",
    "id": "https://example.com/notes/123",
    "content": "Hello, fediverse!"
  }
}

And here is a semantically identical activity from another server:
{
  "@context": ["https://www.w3.org/ns/activitystreams"],
  "type": "Create",
  "actor": {
    "type": "Person",
    "id": "https://example.com/users/alice",
    "preferredUsername": "alice"
  },
  "to": ["as:Public"],
  "object": "https://example.com/notes/123"
}

actor turned from a URI string into an inline object. to turned from a string into an array. object went the other way, from an inline object to a URI. Even the address that means “public” has three valid spellings: https://www.w3.org/ns/activitystreams#Public, as:Public, and plain Public. Your parser has to accept every combination, and which one arrives depends on the sender's implementation.

The spec-compliant answer is to normalize every document with a JSON-LD processor, expansion followed by compaction. In practice many implementations treat it all as “just JSON” and quietly break on whatever shape some server happens to emit. Either way, you end up with defensive code smeared across the whole codebase: is this a string? An array? An object? A URI I have to fetch?

Scene 3: the zombie post


A user publishes a post, spots a typo, and deletes it right away. Your server sends a Create, then a Delete. Thanks to network weather, some receiving server gets the Delete first and the Create second. It ignores the deletion of a post that doesn't exist yet, then dutifully processes the creation of a post that was already deleted. That post now lives on that server forever, while its author believes it's gone.

Then there's scale. With five thousand followers, one post means thousands of HTTP deliveries. Do that inline in the request handler and your publish button takes half a minute to respond, or the server falls over. Fine, use a queue. Deliveries fail, so retry them. On what schedule? Exponential backoff. How many times? And is a 500 Internal Server Error the same kind of failure as a 410 Gone? When do you clean up three thousand followers on a server that no longer exists? Should you keep hammering a host that has been down for days?

At some point it dawns on you that this is no longer protocol implementation. It's distributed systems engineering.

Scene 4: it's not a spec, it's an ecosystem


Even perfect spec compliance doesn't buy you interoperability. A few examples from the field:

  • Mastodon's secure mode requires HTTP signatures on GET requests too (so-called authorized fetch). Now suppose both servers run in that mode. To fetch the other side's public key you must sign your request; to verify your signature, the other side must first fetch your key. Deadlock. The community's workaround is to sign with an “instance actor” that represents the server itself. You won't find that in the spec.
  • Threads can't parse activities whose actor is embedded as an inline object. When sending to Threads, the actor has to be a URI.
  • Lemmy silently rejects Group actors that lack fields Mastodon never asks for, such as a moderators collection linked via attributedTo and a featured collection.
  • Misskey carries vocabulary extensions of its own; quote posts alone go by three different property names across implementations.

The list keeps growing. Interoperability here is not something you finish once and stop thinking about. It's maintenance, forever.

Scene 5: insecure by default


Build it from scratch, and you start out wide open. Skip signature verification on incoming activities and anyone can inject a forged Follow or Delete. Leave the document loader unrestricted and a malicious activity can point it at http://169.254.169.254/ or your internal network, turning your server into an SSRF proxy. Skip origin checks on embedded objects and any server can hand out a document claiming “here's what the Mastodon lead developer said.”

What these traps share is that nothing happens when you fall into them. Everything appears to work. Until someone exploits it.

Ghost ran into this too


If you're thinking “surely our team would manage,” consider Ghost: a leading open-source publishing platform used by thousands of journalists and creators, and a team that set out to build its own ActivityPub support.

We can definitely attest to the problems that Fedify is working hard to solve, because even in just a few weeks of early prototyping we were running into the issues described above right away.

From Alright, let's Fedify


Ghost ended up building its ActivityPub layer on Fedify.

So I put all of it in a framework


Fedify is a TypeScript library for building federated server apps on ActivityPub and the standards around it. It runs on Deno, Node.js, and Bun, and supports edge runtimes like Cloudflare Workers. The design goal hasn't changed since the beginning: keep everything in those five scenes out of application code.

Here are the same five scenes again, this time with Fedify.

Scene 1, revisited: the signature war is the framework's job


Here is everything it takes to put one actor on the fediverse:

import { createFederation, generateCryptoKeyPair, MemoryKvStore } from "@fedify/fedify";
import { Endpoints, Person } from "@fedify/vocab";

const federation = createFederation<void>({
  kv: new MemoryKvStore(),  // Swap for Redis, PostgreSQL, etc. in production
});

federation
  .setActorDispatcher("/users/{identifier}", async (ctx, identifier) => {
    if (identifier !== "alice") return null;
    const keyPairs = await ctx.getActorKeyPairs(identifier);
    return new Person({
      id: ctx.getActorUri(identifier),
      preferredUsername: identifier,
      name: "Alice",
      inbox: ctx.getInboxUri(identifier),
      endpoints: new Endpoints({ sharedInbox: ctx.getInboxUri() }),
      publicKey: keyPairs[0].cryptographicKey,
      assertionMethods: keyPairs.map((keyPair) => keyPair.multikey),
    });
  })
  .setKeyPairsDispatcher(async (ctx, identifier) => {
    // In real code you'd persist these in a database; this shows the gist
    return [await generateCryptoKeyPair()];
  });

The moment this code runs:
  • Every outgoing request gets signed. With an RSA key, Fedify emits HTTP Signatures and Linked Data Signatures; add an Ed25519 key and it attaches Object Integrity Proofs as well. All four mechanisms coexist on a single activity, and each receiver verifies with the strongest one it understands.
  • Fedify does the double-knocking for you: first contact goes out as RFC 9421, a rejection triggers a draft-cavage retry, and the winning spec is cached per server. If the rejection carries an [Accept-Signature challenge] (RFC 9421 §5), Fedify reads it and re-signs with exactly the components the server asked for.
  • Incoming signatures are verified before your code sees anything. An activity that fails verification never reaches your listeners.
  • One bonus. Because you registered an actor dispatcher, you now have a WebFinger (RFC 7033) server, for free. Type @alice@example.com into Mastodon's search box and your actor comes up. You never wrote a line of WebFinger code.


Scene 2, revisited: types instead of JSON-LD


Fedify ships about eighty classes covering the whole Activity Vocabulary plus the major vendor extensions. The classes are typed and immutable, and their accessors absorb the shape differences that JSON-LD allows.

const actor = await ctx.lookupObject("@hongminhee@hollo.social");
if (actor instanceof Person) {
  console.log(actor.name);           // Safe whether it's a string or langString
  const followers = await actor.getFollowers();  // Fetches a URI, unwraps an object
}

[lookupObject()] takes a handle and runs the whole chain for you, WebFinger discovery included. Accessors like getFollowers() behave the same way whether the value is a URI reference or an inline object, and fetched values are cached.

Vendor fragmentation gets stitched up here too. The three competing quote properties (quoteUri, _misskey_quote, quoteUrl) are unified behind one API, next to the emerging FEP-044f quote. Misskey's isCat property exists as a type, so your server can determine cat-ness with full type safety. It sounds like a joke, but a few dozen details of exactly this kind are what interoperability is actually made of.

Scene 3, revisited: the zombie post dies in one line


Delivery infrastructure first. Plug a message queue into createFederation() and delivery moves to the background, with automatic retries under exponential backoff (up to ten attempts by default). When a post goes to thousands of followers, two-stage fan-out kicks in: a single consolidated message enters the queue, and a background worker splits it into per-server delivery tasks. The publish button responds immediately.

Retries create a problem of their own: the same activity can arrive twice. Fedify keeps a 24-hour idempotence cache of processed activities, so duplicates get detected and skipped before they reach your handlers.

As for the zombie post, the fix is one option:

await ctx.sendActivity(
  { identifier: "alice" },
  "followers",           // Collects recipients from your followers collection
  deleteActivity,
  { orderingKey: post.id },  // Same key = in-order delivery per server
);

[Activities that share an orderingKey] are delivered to each receiving server in the order they were sent. A Delete can no longer overtake its Create. Activities with different keys still go out in parallel, so throughput survives.

Fedify also handles dead servers. On a 404 Not Found or 410 Gone, it stops retrying and calls a handler you register. If the delivery went to a shared inbox, you also get the list of followers behind it, so you can prune vanished accounts on the spot. Hosts that fail repeatedly trip a per-host circuit breaker that holds deliveries and probes periodically until the host recovers. It's on by default; there's nothing to configure.

Scene 4, revisited: we track the quirks so you don't


Here is how Fedify disarms the traps from scene 4:

  • Authorized fetch: chain [.authorize()] onto a dispatcher and the verified identity of the requester lands in your callback. Blocklists, private collections, whatever your app needs is plain application logic. The instance-actor deadlock has a supported pattern as well.
  • Threads and inline actors: an activity transformer, enabled by default, rewrites inline actors into URIs on the way out. You don't need to know Threads has this problem.
  • Lemmy's requirements: the custom collection API exposes a moderators collection in a few lines, and Lemmy's JSON-LD context ships preloaded.

When a new quirk surfaces in the wild, the fix lands in Fedify, not in every application separately. Each interoperability lesson gets learned once.

Scene 5, revisited: becoming unsafe takes effort


Fedify's defaults point the other way.

  • Signature verification is something you turn off (for tests), not something you remember to turn on.
  • The document loader refuses private address ranges and loopback out of the box, with DNS rebinding accounted for. To open yourself up to SSRF you have to flip an option whose very name announces it's for testing.
  • When an embedded object's origin differs from its parent document's, the accessor refuses to trust it and re-fetches from the source (based on FEP-fe34). Content spoofing is stopped at the property access level.

In a from-scratch implementation, you have to keep remembering to do things safely. In Fedify, the unsafe path is the one that takes deliberate effort. For a federated server, with its tangle of trust boundaries, that's the right way around.

Your stack stays your stack


“Fine, but what if it doesn't fit our stack?” Fedify was built to fit the stack you already have. There are thirteen web framework integrations: servers like Express, Hono, Fastify, Koa, NestJS, and Elysia, and meta-frameworks like Next.js, Nuxt, SvelteKit, Astro, SolidStart, and Fresh. Middleware handles content negotiation, so the same URL in your existing app serves HTML to browsers and JSON-LD to the fediverse.

Fedify doesn't dictate your database either. For its own storage it asks for one key–value interface, with seven adapters available (Redis, PostgreSQL, MySQL/MariaDB, SQLite, Deno KV, Cloudflare Workers KV, in-memory). Message queues come in eight flavors (PostgreSQL, Redis, AMQP/RabbitMQ, and so on), and you can implement the interface yourself if none fits. Your domain data stays in whatever database and ORM you already use.

Already running federation on another library? There are migration guides with data migration scripts for moving from activitypub-express and friends without losing your existing followers.

The core isn't the ceiling, either. Higher-level packages build on it: [@fedify/relay] gives you a complete ActivityPub relay server in a single function call, and [@fedify/backfill] reconstructs incomplete conversation threads by walking the rest of the fediverse for you.

Tools for the whole development loop


A quieter misery of federated development has always been the missing tooling. Fedify comes with tools for every stage of the loop.

[fedify init] scaffolds a project in one line, and fedify tunnel exposes your local server over HTTPS so you can test against real Mastodon. Activities your server sends can be received by fedify inbox, a disposable inbox server spun up on the spot; whatever other servers publish, you can inspect with fedify lookup. My personal favorite is fedify lookup --authorized-fetch, which generates a one-off key pair and stands up a temporary ActivityPub server just to make a signed request for an object behind secure mode. The CLI is also useful to ActivityPub developers who don't use Fedify at all.

While you write code, an ActivityPub-specific linter (@fedify/lint) catches twenty kinds of interoperability bugs, like an actor missing its inbox. Tests run without the network using mocks from [@fedify/testing]. Once the server is up, attach the debug dashboard (@fedify/debugger) with one line and watch activities and signature verification results in your browser, live. In production there's built-in OpenTelemetry instrumentation (28 span types, 37 metrics) plus a monitoring guide, and when performance matters, [fedify bench], a load-testing tool built for ActivityPub, catches regressions in CI.

As far as I know, no other ActivityPub framework ships even one of the tools in this section.

The documentation is part of the tooling. The official docs run to a thirty-chapter manual and five tutorials, and they go well past API listings. There's an operations chapter with ready-made PromQL queries and alerting rules for watching your queue backlog, and a field-guide chapter that documents de facto conventions, like which property makes your avatar show up in Mastodon, with screenshots. At two in the morning, when federation is broken and you don't know why, this is the difference between a bad night and a short one.

It's already running


Fedify is not a thought experiment. Ghost's ActivityPub service, mentioned above, is built on it. So are Encyclia, which bridges ORCID researcher records into the fediverse; SiliconBeest, running serverless on Cloudflare Workers; Typo Blue, a Korean blogging platform; Hollo, my own single-user microblogging platform; and Hackers' Pub, run by its community. Hollo, by the way, is the app from the beginning of this post: the project I once had to shelve, finished at last on the framework it forced into existence.

The tutorials give a concrete sense of scale. They walk you from a single-file server, a few dozen lines, that Mastodon can follow, through an image sharing service in roughly 750 lines that fully interoperates with Pixelfed (follows, likes, comments), up to a community platform federating both ways with the real lemmy.ml.

The fediverse needs more apps


I didn't build Fedify to mint more ActivityPub experts. Rather the opposite. I believe the fediverse will only grow beyond microblogging when developers can build federated apps without knowing ActivityPub's fine print. Signature spec transitions and JSON-LD compaction are problems that belong inside a framework, not barriers in front of someone with a new idea.

Starting takes one line:

npm init @fedify

Follow the first tutorial and by the end, Mastodon can find your server. If you get stuck, come find us in the Matrix room or GitHub Discussions. See you in the fediverse.


Where in the Fediverse are you reading this ?
Asking for a friend.
#poll #fediverse #socialmedia

  • Mastodon (90%, 73 votes)
  • GoToSocial (2%, 2 votes)
  • Akkoma (2%, 2 votes)
  • Friendica (0%, 0 votes)
  • Lemmy (0%, 0 votes)
  • PieFed (0%, 0 votes)
  • Mbin (0%, 0 votes)
  • snac2 (1%, 1 vote)
  • Pixelfed (0%, 0 votes)
  • Other (comment) (3%, 3 votes)
81 voters. Poll end: Monday, July 6, 2026, 9:32 PM


Week in Fediverse 2026-06-26


Servers

- Vernissage Server v1.39.0
- Bookwyrm v0.9.0
- Mastodon v4.6.1
- GoToSocial v0.21.3
- Ktistec v3.6.0
- snac v2.93
- Mitra v5.6.0
- Misskey v2026.6.0
- NeoDB v0.16.2.1

Clients

- Fedilab v3.42.0
- Mastodon for Android v2.13.0
- Voyager 2.47.3
- Tesseract v1.5.4
- Holos v1.10.2
- Phanpy changelog
- Rocinante: A modern, open-source Android client for BookWyrm

For developers

- Fedify v2.3.0
- Masto.js v7.12.0

Articles

- FR#168 – LLMs Join The Fediverse

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/019ee1be-…


Fediverse & Social Web track at COSCUP 2026


The Fediverse & Social Web track runs on Sunday, August 9 (day 2 of
COSCUP 2026) in room TR411 at National Taiwan University of Science and
Technology (NTUST), Taipei.

Eleven sessions across the day, covering ActivityPub implementations,
governance and community building in East Asia, internationalization, and
non-Latin script support on the fediverse.

TimeSessionSpeaker
9:30 AMFederation Is Not Enough: Governance Patterns for the Open Social Web in East AsiaRoro Park
10:00 AMDecentralized by Design, Connected by Culture: Japan's Fediverse and OSS Ecosystem Through FediLUGYuki Onobuchi (@Yohei_Zuho@mstdn.y-zu.org)
10:35 AMBuilding a Fediverse on the CloudFlare Edge: SiliconBeestSAE JIN KIM (@siliconsjang@siliconbeest.sjang.dev)
11:05 AMFrom 0 to FediverseJihyeok Seo (@jihyeok@hackers.pub)
11:35 AMFeder: One ActivityPub Core, Many RuntimesJiwon Kwon (@z9mb1@hackers.pub)
1:30 PMFrom One Codebase to Many Clients: How We Turn Mastodon Instances into No-Code Mobile Apps and Help Grow the FediverseAung Kyaw Phyo, Ye Myat Thu
2:00 PMActivityPlug: a unified API layer for ActivityPub server softwareHaze (@nebuleto@hackers.pub)
2:30 PMI just wanted ruby annotations: writing in dead scripts on the living fediverseHong Minhee (洪 民憙) (@hongminhee@hollo.social)
3:00 PMVertical writing for the Mongolian script on MastodonItoh Shimon (@shimon1024@mastodon.social)
3:30 PM@小明@範例.測試, or, Fediverse handles in every languageJim DeLaHunt (@jdlh@mstdn.ca)
4:00 PMFrom CMS to Fediverse: Drupal's ActivityPub moduleJiajun Xu (@foolfitz@social.slat.org)

@COSCUP@floss.social 2026 takes place August 8–9 at NTUST, Taipei. The full schedule is at
pretalx.coscup.org/coscup-2026/schedule/.


好耶😀👍

@matt_birchler Frok 了 @nileane 的 Tangerine UI 并进行了一些更新,使其支持 Mastodon 4.6,并添加了新主题,增强了高对比度模式。@matt_birchler 表示他无法保证对 Tangerine UI 的长期维护。

#联邦宇宙 #长毛象安利大会 #社交媒体 #新闻 #Fediverse #Mastodon #News #BreakingNews


No promises long term, but I've forked @nileane's outstanding Tangerine UI and have made a few updates.

🦣 Mastodon 4.6 support
🪨 New Granite theme
🌓 Better support for high contrast mode

Read the full details below!

birchtree.me/blog/tangerine-ne…




Week in Fediverse 2026-06-19


Servers

- Gush! v0.0.39
- Hollo v0.9.5
- FitPub v1.1.0
- Mbin v1.10.0
- PeerTube v8.2.1
- Mastodon v4.6.0
- Wafrn v2026.06.02
- Ktistec v3.5.0
- ActivityPub for WordPress v9.0.1
- NeoDB v0.16.2
- NodeBB v4.13.2

Clients

- Nicolium v1.0.0
- Mastodon Bird UI v4.0.0
- Loops for Android v1.0.2.4
- Voyager v2.47.1
- Aria v1.5.4
- Loops is now on Google Play

Tools and Plugins

- PeerTube livechat plugin v14.0.3
- Canvas: A collaborative pixel canvas built for the Fediverse

Articles

- We've been hacked

-----

#WeekInFediverse #Fediverse #ActivityPub

Previous edition: mitra.social/objects/019ebd9e-…