User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
Automated
(UNOFFICIAL)
This bot automatically checks for Iceshrimp-js and Iceshrimp.NET releases and posts them.

Sources:
iceshrimp.dev/iceshrimp/iceshrimp/releases
iceshrimp.dev/iceshrimp/Iceshrimp.NET/releases

Iceshrimp dev chat:
chat.iceshrimp.dev
Iceshrimp documentation:
iceshrimp.net/help
Iceshrimp issues board:
issues.iceshrimp.dev
Author @pancakes
Source Code https://codeberg.org/pancakes/fedifeeds
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1w
Iceshrimp.NET v2026.1-beta
This is a
beta release, containing lots of new features & bug fixes. Upgrading is recommended for all server operators.

Note: We've simplified our versioning scheme to reduce both confusion and the slightly absurd length of our releases - we're now following
v<yyyy>.<major>[.<patch>][-beta].

Highlights:

- Local and remote user/note reports are now fully supported
- Emoji management is massively improved with better handling of remote emojis and bulk emoji editing
- Users can now mute, block, unmute and unblock other users in any client
- Users can now import or export their following, muted, and blocked users list
- The note composer is much more powerful with support for polls, pasting attachments/quotes, user mention searching
- Instances can now customize their favicon, banner, and theme color
- MFM nodes for emojis,
fg, bg, border, font, and ruby have been improved
- Users can now manage account migrations from the frontend
- The Iceshrimp.NET API now has lots of human readable documentation which can be access through the Scalar or Swagger UI
- Atom, JSONFeed, and RSS are now supported. Profile pages now have links to the feeds and feed readers should be able to automatically find the feeds from a user's profile URL. Feeds only display notes that have a public visibility and are unavailable for private/locked users
- Moderators can now create instance announcements
- Mastodon users can now quote notes from Iceshrimp.NET users
- Users can now view, pin and unpin notes from any client
- Static pages are now visually consistent with the frontend
- Light theme is now supported for static pages and the frontend
- Updated from .NET 9 to .NET 10
- Added support for instance admins to use OpenTelemetry to better monitor instance performance and other metrics
- Private memos (notes you can create about other users) are supported in all clients
- Federated bite controls are now supported and bites are now opt-in

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
3w
Iceshrimp v2026.4.1
This release contains multiple new features and bug fixes. Due to this release including database migrations, you will not be able to migrate from this version to Iceshrimp.NET until their migration script is updated.

Some release highlights:

- Biting has been added
+ You can bite users, notes, and bites
+ You can control who is allowed to bite you
- Pronouns now have a dedicated field (only compatible with Iceshrimp.NET)
- Quotes now are compatible with Mastodon (FEP-044f)
+ Users on Mastodon can quote your post and it will show up properly on their side
+ You can quote users on Mastodon and it will show up properly on their side
- Unicode emojis up to version 16 are now supported

You can read the full changelog here:
https://iceshrimp.dev/iceshrimp/iceshrimp/src/branch/dev/CHANGELOG.md#v2026-4-1
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
4mo
Iceshrimp.NET v2025.1-beta5.patch3.security4
This is a
beta security hotfix release. It's identical to v2025.1-beta5.patch3.security3, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators.

- Note visibility is now checked when requesting the hashtag timeline

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
5mo
Iceshrimp.NET v2025.1-beta5.patch3.security3
This is a
beta security hotfix release. It's identical to v2025.1-beta5.patch3.security2, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators.

- Note visibility is now checked when listing likes or bookmarks

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
9mo
Iceshrimp.NET v2025.1-beta5.patch3.security2
This is a
beta hotfix release. It's identical to v2025.1-beta5.patch2.security2, except for a bunch of bug fixes. Upgrading is strongly recommended for all server operators.

This release resolves a regression where users with multiple authenticated sessions running .NET 9.0.7 / SDK 9.0.302 or above were unable to use the default frontend.

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp.NET v2025.1-beta5.patch2.security2
This is a
beta security hotfix release. It's identical to v2025.1-beta5.patch2.security1, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators.

- Profile fields are now rendered as HTML for federation

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp v2023.12.14
This is a
stable release containing a critical security fix, as well as several lower severity security fixes.

Upgrading is strongly recommended for all server operators.

Highlights:

- A XSS vulnerability related to parsing of relative URLs has been fixed
- Media URLs are now always proxied, no matter the protocol in use
- AiScript endpoints are now validated more strictly
- Negative values for MFM scale nodes are now clamped
- Profile fields are now rendered as HTML for federation
- Summaly has been updated, resolving a SSRF vulnerability

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
From Iceshrimp's Zulip chat:
There'll be security patches released for Iceshrimp-JS (severity: critical) and Iceshrimp.NET (severity: low) between 19:00, 27 Apr 2025 UTC and 21:00, 27 Apr 2025 UTC (this should show in your local time zone on Iceshrimp, but in case it doesn't, that's 2025-04-27T19:00Z - 2025-04-27T21:00Z. Be ready and patch quickly, especially if you're on -js.
Please boost
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp.NET v2025.1-beta5.patch2.security1
This is a
beta security hotfix release. It's identical to v2025.1-beta5.patch2, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators.

- Updated SixLabors.ImageSharp to 3.1.7 (addressing
GHSA-2cmq-823j-5qj8)

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp v2023.12.13
This is a
stable release containing a critical security fix. It's identical to v2023.12.13, except that it correctly identifies its version as v2023.12.13, instead of v2023.12.11.

Upgrading is strongly recommended for all server operators.

Highlights:

- An unauthenticated SQL injection vulnerability inherited from calckey/firefish has been patched

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp v2023.12.12
This is a
stable release containing a critical security fix.

Upgrading is strongly recommended for all server operators.

Highlights:

- An unauthenticated SQL injection vulnerability inherited from calckey/firefish has been patched

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp.NET v2025.1-beta5.patch2
This is a
beta hotfix release. It's identical to v2025.1-beta5.patch1, except for a bunch of bugfixes. Upgrading is strongly recommended for all server operators running v2025.1-beta5 or v2025.1-beta5.patch1.

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp.NET v2025.1-beta5.patch1
This is a
beta hotfix release. It's identical to v2025.1-beta5, except for a bunch of bugfixes. Upgrading is strongly recommended for all server operators running v2025.1-beta5.

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
A fix for the beta5 builds is being worked on
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp.NET v2025.1-beta5
This is a
beta release, containing lots of new features & bug fixes. Upgrading is recommended for all server operators.

This release contains a
breaking change - we now require PostgreSQL version 15 or higher. If you need assistance upgrading, please reach out to the support chat.

Highlights:

- The MFM parser has been completely rewritten, improving frontend performance by several orders of magnitude, as well as fixing countless bugs, slowdowns & edge cases.
- TOTP 2FA is now supported and can be configured in the user settings
- Instance rules can now be configured and displayed
- Links in user profile fields are now verified
- Full drive file management has been added
- Federated user pronouns have been added
- Remote media is now proxied by default
- The project and all in-house libraries now target .NET 9.0

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
An update from the developers, from the project README:
We're currently in winter holiday break - unless security issues or other catastrophic bugs are discovered, no releases will be made, and no issues will be responded to until the first week of january. Support is limited to community support until then.

Happy holidays!
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp.NET v2024.1-beta4.security2
This is a
beta security hotfix release. It's identical to v2024.1-beta4.security1, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators.

Mitigations:

- Several DoS & stack overflow vulnerabilities in the MFM parser were resolved

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
The previous two notes are there for both historical and testing reasons. Don't worry about them unless you're actually not up to date.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp.NET v2024.1-beta4.security1
This is a
beta security hotfix release. It's identical to v2024.1-beta4, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators.

Mitigations:

- ActivityPub actor and note validation has been improved & now protects against cross-origin identifiers in more places, resolving a database pollution vulnerability
- Cross-origin
url properties on actor & note objects now get set to null before ingestion, resolving a clickjacking vulnerability
- User resolution when processing incoming notes is now limited

Check out the
full changelog for more information on this release.
User avatar
Iceshrimp Updates Bot @iceshrimp_updates@meow.company
1y
Iceshrimp v2023.12.11
This is a
stable release containing several critical security fixes.

Upgrading is strongly recommended for all server operators.

Highlights:

- Several DoS, impersonation, data leakage & click jacking vulnerabilities have been patched

Check out the
full changelog for more information on this release.