Social Media Platforms Release Notes

Release notes for popular social media platforms

Get this feed:

Products (7)

Latest Social Media Platforms Updates

  • Sep 3, 2026
    • Date parsed from source:
      Sep 3, 2026
    • First seen by Releasebot:
      Sep 3, 2026
    TikTok logo

    TikTok

    Say More in the Comments: Introducing Voice, Polls, and Carousels on TikTok

    TikTok adds Voice Comments, Comment Polls, and richer photo comments with carousels and Live Photos, giving users new ways to react and keep conversations going in the comment section.

    On TikTok, the comment section isn't just a place to react — It's where a video's story keeps going: where jokes get funnier, reactions get bigger, and total strangers connect in real time.

    Features like text, photo, and video sticker comments give people new ways to say more than words ever could, turning the comment section into an experience of its own. Every day, that adds up to more than 1.7 billion comments shared across the platform. Today, we're building on that innovation with a series of new updates:

    React out loud with Voice Comments

    Sound and music have shaped TikTok from the very beginning, turning songs into trends and audio clips into jokes shared across the app. Now, we're bringing that same energy to the comment section with Voice Comments, a new way to post and listen to audio messages directly under any video.

    To leave a voice comment, just tap the microphone icon in the comment box and record a message up to 60 seconds long. Once posted, anyone can tap to listen, turning the comment section into a place people can hear as much as read. Whether you’re laughing at a meme, singing with a creator, or reacting to a sudden plot twist, Voice Comments make it easy to say what you’re feeling — no typing required. Voice Comments are rolling out globally over the next month to accounts 18 and older.

    Let viewers vote directly in the comments with Comment Polls

    Creators have always found creative ways to turn the comment section into a conversation with their audience. To make that easier, we're announcing Comment Polls, a new way for creators to put decisions directly in their followers' hands. Whether it's picking an outfit, deciding what to cook, or voting on the next video idea.

    To create a Comment Poll, creators can add a poll when commenting on their own video. Just tap the poll icon in the comment box, choose up to 5 options for followers to vote on, and set a timeframe for how long voting will last. As votes come in, creators can track results directly in the comment section, making it easy to see how the conversation is trending in real time. Comment Polls are now available globally.

    Take photo comments to the next level with Photo Carousel and Live Photo Comments

    Photo comments have become one of the most loved ways people express themselves on TikTok. And we're making the feature even more useful with two updates: Photo Carousel Comments and Live Photo Comments.

    With Photo Carousel Comments, people can now add up to 9 photos in a single comment, making it easy to share a full moment instead of just one frame. For instance, if someone wants to react to a travel video with their own vacation photos, they no longer have to pick just one, they can drop the whole album in a single comment.

    Live Photos capture more than a static image, they capture a moment. With Live Photo Comments, people can upload Live Photos directly from their camera roll, giving the photo comment a brief burst of motion so others get a quick preview of the moment before diving into the full image. Live Photo Comments are now available globally, and Photo Carousel Comments are rolling out globally over the next month.

    We’re excited to see how creators and fans take reactions to the next level with these updates.

    Original source
  • Sep 3, 2026
    • Date parsed from source:
      Sep 3, 2026
    • First seen by Releasebot:
      Sep 3, 2026
    Reddit logo

    Reddit

    Performance unlocked: Reddit Max campaigns are now available to all advertisers

    Reddit expands Max campaigns to all advertisers and adds API support, Smartly integration, and new asset groups for organizing creative and reporting performance within a single campaign.

    With more than 26 billion conversations on our platform, Reddit provides advertisers with a uniquely powerful source of real-time human insight and has become a proven performance driver for advertisers. Reddit delivers 2.1x higher incremental ROAS than the digital media average.

    Max campaigns, in particular, have unlocked performance for advertisers of all sizes. Launched earlier this year in beta, Max campaigns automate targeting, creative selection and rotation, placements and budget allocation, while still providing advertisers with the right amount of control to apply their own strategic expertise. The results from early testing: advertisers see 17% lower costs/CPA and over 27% more conversions with Max campaigns.

    What’s new with Max campaigns

    Today, we are making Max campaigns available to all advertisers on Reddit and announcing three major updates to ensure they get even more value out of Max campaigns:

    • Advertising API Availability: Reddit’s Advertising API now supports Max campaigns, enabling advertisers to create and manage them through supported third-party tools and workflows.
    • Smartly integration: Smartly is the first third-party partner to support Max campaigns, allowing advertisers to create, scale, and manage them directly through Smartly.
    • Asset groups: We are introducing asset groups, which allow advertisers to organize multiple sets of creative within a single Max campaign. Each asset group can represent a different product line or use case (ie: running shoes, training apparel, fitness accessories), and include its own headlines, media, and destination URL. Advertisers can also report on each group separately to understand which products and messages are driving performance.

    “Advertisers need confidence that their budgets are driving the outcomes that matter most to their business,” said Jyoti Vaidee, VP of Ads Product, Reddit. “Our goal is to give them the intelligence and automation to work more efficiently while keeping them in control, so they can move faster, make smarter decisions, and get more value from their investment.”

    How advertisers are putting Max campaigns to work

    Advertisers are already using Max campaigns to turn automation into measurable momentum. Musical instrument manufacturer Fender leaned into Max campaigns during Black Friday shopping to reach new customers and drive efficient traffic to its site. Working with Gupta Media, Fender used a mix of banners, artist imagery, product shots, and video, while Max campaign’s AI helped match creative formats and messaging with relevant communities. The campaign delivered 148% ROAS, with CTR 126% higher than benchmark and CPC 46% more efficient than a standard campaign.

    LensDirect used Max campaigns as part of an evergreen strategy to expand its reach, connect with new communities, and improve campaign efficiency. The contact lens retailer combined automatic targeting and retargeting with Max campaign’s ability to rotate headlines, images, and CTAs, allowing the campaign to serve the creative combination predicted to have the greatest impact without manual setup. LensDirect reported 5.5x overall ROAS and planned to continue scaling its presence on Reddit.

    Powered by AI that predicts the value of every impression, Max campaigns drive better traffic, conversions, and app results with less effort. We’ll continue innovating our Max campaign offering to better meet the evolving needs of our advertisers. Interested in learning more about it? Talk to your Reddit rep to review your current setup with your team and ensure you’re getting the most value possible out of your campaigns.

    1. TransUnion (formerly Neustar), 2025 MTA findings across 24 brands and 112 outcome metrics.
    2. Based on 17 split tests conducted between June and August 2025. Each test compared Max campaigns to standard campaigns over a 21-day period.
    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from TikTok and hundreds of other software products.

    Create account
  • Sep 1, 2026
    • Date parsed from source:
      Sep 1, 2026
    • First seen by Releasebot:
      Sep 2, 2026
    Mastodon logo

    Mastodon

    v4.7.1

    Mastodon releases a security-focused update with fixes for password authentication bypasses, a JSON-LD denial of service issue, and disabled staff account admin API access, plus several bugs affecting invites, email blocks, Docker, migrations, and setup.

    Changelog

    Security

    Fix password authentication bypass in 2FA auth for LDAP/PAM/SSO accounts (GHSA-vx32-x96w-qq65)

    Fix Denial of Service when processing pathological JSON-LD activities (GHSA-vgm8-frgh-rh2v)

    Fix disabled staff accounts still having access to admin API (GHSA-62j4-hvj7-px3f)

    Fixes

    Fix invited-without-approval-bypass not being asked for a textual reason (#40332 by @ClearlyClaire)

    Fix email blocks domain filter not being kept through pagination (#40254 by @ClearlyClaire)

    Fix config/ directory missing from Bootsnap precompilation options in Dockerfile (#40255 by @ClearlyClaire)

    Fix some of 4.7 migrations not re-running cleanly when interrupted (#40264 by @ClearlyClaire)

    Fix account creation failing on ActiveRecord::Encryption configuration in mastodon:setup rake task (#40275 by @ClearlyClaire)

    Upgrade notes

    To get the code for v4.7.1, use git fetch && git checkout v4.7.1.

    Note

    As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

    Dependencies

    External dependencies have not changed since v4.6.0.

    Ruby: 3.3 or newer

    PostgreSQL: 14 or newer

    Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work)

    LibreTranslate (optional, for translations): 1.3.3 or newer

    Redis: 7.0 or newer

    Node: 22 or newer

    libvips: 8.13 or newer

    FFMpeg: 5.1 or newer

    Update steps

    The following instructions are for updating from 4.7.0.

    If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations. In particular, it is very important to read the 4.7.0 release notes.

    Non-Docker

    Tip

    The charlock_holmes gem may fail to build on some systems with recent versions of gcc.

    If you run into this issue, try BUNDLE_BUILD__CHARLOCK_HOLMES="--with-cxxflags=-std=c++17" bundle install.

    Install dependencies with bundle install

    Restart all Mastodon processes.

    When using Docker

    Restart all Mastodon processes.

    Original source
  • Sep 1, 2026
    • Date parsed from source:
      Sep 1, 2026
    • First seen by Releasebot:
      Sep 2, 2026
    Mastodon logo

    Mastodon

    v4.6.7

    Mastodon ships a maintenance release with important security fixes, including LDAP, PAM, SSO, JSON-LD, and admin API issues, plus bug fixes for Docker assets, autosuggestions, remote actor handling, and statistics ranges.

    Upgrade overview

    This release contains upgrade notes that deviate from the norm:

    ℹ️ Requires assets recompilation

    For more information, view the complete release notes and scroll down to the upgrade instructions section.

    Changelog

    Security

    Update dependencies

    Fix password authentication bypass in 2FA auth for LDAP/PAM/SSO accounts (GHSA-vx32-x96w-qq65)

    Fix Denial of Service when processing pathological JSON-LD activities (GHSA-vgm8-frgh-rh2v)

    Fix disabled staff accounts still having access to admin API (GHSA-62j4-hvj7-px3f)

    Fixes

    Fix config/ directory missing from Bootsnap precompilation options in Dockerfile (#40255 by @ClearlyClaire)

    Fix autosuggestions overstaying their welcome in languages that don't use spaces (#40217 by @Gargron)

    Fix error when processing remote actors with null public keys (#40194 by @ClearlyClaire)

    Fix various off-by-one errors in statistics time ranges (#40193 by @ClearlyClaire)

    Upgrade notes

    To get the code for v4.6.7, use git fetch && git checkout v4.6.7.

    Note

    As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

    Dependencies

    External dependencies have not changed since v4.6.0.

    Ruby: 3.3 or newer

    PostgreSQL: 14 or newer

    Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work)

    LibreTranslate (optional, for translations): 1.3.3 or newer

    Redis: 7.0 or newer

    Node: 22 or newer

    libvips: 8.13 or newer

    FFMpeg: 5.1 or newer

    Update steps

    The following instructions are for updating from 4.6.6.

    If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations. In particular, it is very important to read the 4.6.0 release notes.

    Non-Docker

    Tip

    The charlock_holmes gem may fail to build on some systems with recent versions of gcc.

    If you run into this issue, try BUNDLE_BUILD__CHARLOCK_HOLMES="--with-cxxflags=-std=c++17" bundle install.

    Install dependencies with bundle install

    Precompile the assets: RAILS_ENV=production bundle exec rails assets:precompile

    Restart all Mastodon processes.

    When using Docker

    Restart all Mastodon processes.

    Original source
  • Sep 1, 2026
    • Date parsed from source:
      Sep 1, 2026
    • First seen by Releasebot:
      Sep 2, 2026
    Mastodon logo

    Mastodon

    v4.5.17

    Mastodon ships a security update with fixes for password authentication bypass in 2FA for LDAP, PAM and SSO accounts, a denial of service issue in JSON-LD processing, and disabled staff accounts retaining admin API access, plus Docker and statistics fixes.

    Changelog

    Security

    Update dependencies

    Fix password authentication bypass in 2FA auth for LDAP/PAM/SSO accounts (GHSA-vx32-x96w-qq65)

    Fix Denial of Service when processing pathological JSON-LD activities (GHSA-vgm8-frgh-rh2v)

    Fix disabled staff accounts still having access to admin API (GHSA-62j4-hvj7-px3f)

    Fixes

    Fix config/ directory missing from Bootsnap precompilation options in Dockerfile (#40255 by @ClearlyClaire)

    Fix various off-by-one errors in statistics time ranges (#40193 by @ClearlyClaire)

    Upgrade notes

    To get the code for v4.5.17, use git fetch && git checkout v4.5.17.

    Note

    As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

    Dependencies

    External dependencies have not changed since v4.5.0.

    Ruby: 3.2 or newer

    PostgreSQL: 14 or newer

    Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work)

    LibreTranslate (optional, for translations): 1.3.3 or newer

    Redis: 7.0 or newer

    Node: 20.19 or newer

    libvips (optional, instead of ImageMagick): 8.13 or newer

    ImageMagick (optional if using libvips): 6.9.7-7 or newer

    Update steps

    The following instructions are for updating from 4.5.16.

    If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations. In particular, it is very important to read the 4.5.0 release notes.

    Non-Docker

    Tip

    The charlock_holmes gem may fail to build on some systems with recent versions of gcc.

    If you run into this issue, try BUNDLE_BUILD__CHARLOCK_HOLMES="--with-cxxflags=-std=c++17" bundle install.

    Install dependencies with bundle install

    Restart all Mastodon processes.

    When using Docker

    Restart all Mastodon processes.

    Original source
  • Sep 1, 2026
    • Date parsed from source:
      Sep 1, 2026
    • First seen by Releasebot:
      Sep 2, 2026
    Mastodon logo

    Mastodon

    v4.4.24

    Mastodon releases 4.4.24 with security fixes for 2FA LDAP/PAM/SSO password bypass, JSON-LD denial of service, and disabled staff admin API access, plus Docker and statistics fixes. It also notes Mastodon 4.6 is available with new features, changes and fixes.

    Note

    While we continue to support Mastodon 4.4 and release patches for it, please note that Mastodon 4.6 is available with new features, changes and fixes. We encourage administrators to update to the latest 4.6 version when they can.

    Changelog

    Security

    Update dependencies

    Fix password authentication bypass in 2FA auth for LDAP/PAM/SSO accounts (GHSA-vx32-x96w-qq65)

    Fix Denial of Service when processing pathological JSON-LD activities (GHSA-vgm8-frgh-rh2v)

    Fix disabled staff accounts still having access to admin API (GHSA-62j4-hvj7-px3f)

    Fixes

    Fix config/ directory missing from Bootsnap precompilation options in Dockerfile (#40255 by @ClearlyClaire)

    Fix various off-by-one errors in statistics time ranges (#40193 by @ClearlyClaire)

    Upgrade notes

    To get the code for v4.4.24, use git fetch && git checkout v4.4.24.

    Note

    As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

    Dependencies

    External dependencies have not changed since v4.4.1:

    • Ruby: 3.2 or newer
    • PostgreSQL: 13 or newer
    • Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work)
    • LibreTranslate (optional, for translations): 1.3.3 or newer
    • Redis: 6.2 or newer
    • Node: 20 or newer
    • libvips (optional, instead of ImageMagick): 8.13 or newer
    • ImageMagick (optional if using libvips): 6.9.7-7 or newer

    Update steps

    The following instructions are for updating from 4.4.23.

    If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations. In particular, it is very important to read the 4.4.0 release notes.

    Non-Docker

    Tip

    The charlock_holmes gem may fail to build on some systems with recent versions of gcc.

    If you run into this issue, try BUNDLE_BUILD__CHARLOCK_HOLMES="--with-cxxflags=-std=c++17" bundle install.

    Install dependencies with bundle install

    Restart all Mastodon processes.

    When using Docker

    Restart all Mastodon processes.

    Original source
  • August 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Aug 20, 2026
    Mastodon logo

    Mastodon

    Mastodon 4.7 Release

    Mastodon releases a technical update focused on better fediverse compatibility, improved performance, and bug fixes. It adds encrypted private keys, stronger ActivityPub signature support, better remote handle handling, and support for FEP-8967 link previews.

    This release of Mastodon focuses entirely on technical improvements that are not necessarily visible on the user side, ahead of the ambitiously user-focused Mastodon 5.0 release later this year. Our goal is to improve compatibility with other fediverse platforms, improve performance, and fix various bugs that we’ve found. So this post will be very technical. If you’re into that, read on.

    This release features multiple long-running database migrations, as we tackled several long-standing issues in our database structure that made some features difficult or even impossible to implement, and made some migrations unnecessarily complicated. Zero-downtime migration from Mastodon 4.6 to 4.7 is supported, as will be zero-downtime migration from 4.7 to the next version. However, Mastodon 4.7 will be a required stop for zero-downtime migrations.

    Private keys of local users used for ActivityPub authentication are now encrypted in the database to reduce the risk of leaks, for example from backup files or external database providers. They are also stored in a way that will allow us to seamlessly use different signature algorithms and properly rotate keys in the future.

    We now have better support for account handle changes for accounts hosted elsewhere on the fediverse. You can’t change your Mastodon handle for now, but this is a necessary step towards being able to do so in the future.

    Mastodon 4.7 now also supports FEP-8967 to represent and process link previews, which in the future will allow us to let users chose which link they want to have a preview whenever they’re composing a post with multiple links in it. For now, Mastodon does not require other servers to use FEP-8967 and will fall back to scanning the post’s links when a remote server does not include a FEP-8967 link preview, but that may change in future versions.

    We have made several improvements to how we handle cryptographic signatures in ActivityPub, allowing the ecosystem to move past old specification drafts and make it easier to change signature algorithms in the future:

    • We now support RSA, Ed25519 and as a post-quantum algorithm, ML-DSA-44 public keys represented using FEP-521a.
    • We now emit RFC 9421 signatures when requests fail using the previous draft specification, allowing compatibility between Mastodon 4.7 and servers that only implement the final RFC 9421 specification, while retaining compatibility with servers that only implement the previous draft specification (most current implementations), and have added support for verification of RFC 9421 signatures made with Ed25519 keys.
    • We now support verifying FEP-8b32 Object Integrity Proofs using either eddsa-jcs-2022 or mldsa44-jcs-2024.

    If none of this makes sense to you, don’t worry. There is absolutely no need to understand any of this to enjoy using Mastodon. This is only relevant to you if you are developing or running your own fediverse platform. Our next big release, Mastodon 5.0, will be a lot more interesting for everyone!

    In conclusion

    Mastodon is the result of the work of our engineering team and community contributors who submit patches, file bug reports, and translate Mastodon into their native languages. From our heart: Thank you to everyone who contributed to this release, either through code, feedback, or by funding our mission.

    Delivering handcrafted code that runs on tens of thousands of servers and serves hundreds of thousands of users is not an easy task. We don’t take venture capital, we don’t use AI, we don’t sell ads, and we don’t sell your data—unlike many other platforms out there. Please support our mission, so that we can continue to make Mastodon better, and work towards an internet that is diverse, fun, and free from corporate control.

    Thank you for supporting Mastodon

    We develop and maintain the free and open source software that powers the social web. There is no capital behind this — we rely entirely on your support.

    Original source
  • Aug 14, 2026
    • Date parsed from source:
      Aug 14, 2026
    • First seen by Releasebot:
      Aug 11, 2026
    • Modified by Releasebot:
      Sep 2, 2026
    Mastodon logo

    Mastodon

    v4.7.0-rc.1

    Mastodon releases a pre-release that reworks core internals for stronger security, new protocol support, and future features, while also adding admin tools, better account handling, and a batch of Web UI and moderation fixes.

    Warning

    This is a pre-release! This has not been as widely tested as regular releases, although it is still tested on mastodon.social and some other servers. If you update to this release, you will not be able to safely downgrade to the existing stable releases. You will, however, be able to upgrade to later nightly releases or pre-releases, as well as the upcoming 4.7.0 stable release.

    This version introduces very few user-facing changes but substantially reworks Mastodon's internals to increase security, support new protocols, and pave the way for new features. Updating to this version will be required for zero-downtime migration to the upcoming Mastodon 5.0.

    Upgrade overview

    This release contains upgrade notes that deviate from the norm:

    • ℹ️ Requires assets recompilation
    • ℹ️ Requires streaming server restart
    • ℹ️ Requires database migrations

    For more information, view the complete release notes and scroll down to the upgrade instructions section.

    Changelog (v4.7.0-rc.1)

    Changed

    Change mastodon:setup task warning about trademark to match masto but ignore subdomains (#40143 by @ClearlyClaire)

    Fixed

    Fix redundant index index_keypairs_on_account_id (#40138 by @ClearlyClaire)

    Fix connection errors when processing fediverse:creator preventing creation of preview cards (#40135 by @ClearlyClaire)

    Fix Web UI being inaccessible with URLs ending with .zip (#40134 by @ClearlyClaire)

    Fix semitransparent background of picture-in-picture video player (#40132 by @diondiondion)

    Fix title tooltip appearing for fullscreen videos (#40127 by @diondiondion)

    Fix image preview too dark in alt text editor dialog (#40126 by @diondiondion)

    Fix domain block impact queries being rejected (#40122 by @ClearlyClaire)

    Fix mobile navigation scrolling to top while opening (#40042 by @sharlayan)

    Fix selected account being lost when creating a collection (#39897 and #40133 by @diondiondion and @sharlayan)

    Fix error in tootctl media refresh when cleaning some incompletely processed files (#40056 by @shleeable)

    Fix plain-text formatter not treating <BR> as newline (#40079 by @shleeable)

    Changelog (v4.7.0-beta.1)

    Added

    Add audit logs for Hashtags (#39473, #39337 and #39670 by @arte7)

    Add search field to admin ip blocks (#39404 by @arte7)

    Add notifications for out-of-support versions of Mastodon (#39732 and #39734 by @ClearlyClaire)

    Add Elasticsearch request timeout of 10s (can be overridden through ES_QUERY_TIMEOUT) (#40064 by @ClearlyClaire)

    Add ActivityPub attributes to current span when processing Activities (#40041 by @jhbabon)

    Add OTel span attribute to deprecated endpoints (#40030 by @jhbabon)

    Add default permission check to admin area (#39974 by @oneiros)

    Add uniqueness constraint on Account uri (#39882, #39999 and #39861 by @ClearlyClaire)

    Add new theme tokens bg-blend, bg-highlight, and border-strong (#39786 by @diondiondion)

    Add support for Link objects in attachment (FEP-8967) (#36104, #39977 and #39983 by @Gargron, @TheEssem and @shleeable)

    Mastodon will use the first Link attachment, if any, as preview card.

    If there is no Link attachment, Mastodon will still scan the message content's to populate one. This may change in a later release.

    Mastodon sets a Link attachment for outgoing posts with a preview card.

    Add support for remote accounts changing handles (#39785, #39850, #39865 and #40045 by @ClearlyClaire)

    ActivityPub actor id is now used as the primary identifier, instead of webfinger handle.

    Remote actors that change handles are now renamed instead of a duplicate account being created then the two merged.

    Mastodon does not offer its users to change handles yet.

    The concept of “invalid handles” has been added to handle some edge cases. An account with an invalid handle
    is an account for which the handle cannot be currently verified, but is otherwise valid.

    In the REST API, they have their username and domain attribute overridden and this is made explicit through the invalid_handle attribute.

    Add outgoing RFC9421 HTTP Message Signatures as fallback to earlier draft (#39756 by @ClearlyClaire)

    Change how local users' keypairs are stored (#39658, #39668, #39662, #39684, #39686 and #39690 by @ClearlyClaire)

    This moves local users' keypairs to the dedicated table that was created in 4.6.

    Private keys are now encrypted at rest, and the new infrastructure will allow for key rotation in the future.

    Add support for expires in Linked Data Signatures and Object Integrity Proofs (#39701 by @ClearlyClaire)

    Add verification of FEP-8b32 Object Integrity Proofs (#39530, #39728, #39754, #39760, #39522 and #39747 by @ClearlyClaire)

    Both eddsa-jcs-2022 and mldsa44-jcs-2024 are supported.

    mldsa44-jcs-2024 verification requires OpenSSL >= 3.5 to be verified.

    Add support for Ed25519 signatures in HTTP Message Signatures (#39518 by @ClearlyClaire)

    Add inbound support for FEP-521a (#39497, #39618, and #39725 by @ClearlyClaire and @shleeable)

    Fixed

    Fix performance of listing follow requests by adding appropriate index (#40033 by @ClearlyClaire)

    Fix missing on_delete: :cascade on GeneratedAnnualReport foreign key (#40063 by @ClearlyClaire)

    Fix DeleteAccountService#purge_favourites! only invalidating deprecated cache keys (#40048 by @shleeable)

    Fix spam-filtered scheduled posts raising an error rather than being silently ignored (#40051 by @shleeable)

    Fix error when processing backups for deleted accounts (#40053 by @shleeable)

    Fix notification filter selection after settings change (#39872 by @sharlayan)

    Fix timeline unable to load more when the last item is a inline-follow-suggestions (#39773 by @sharlayan)

    Fix embedded videos restarting when interacting with post (or other posts in the same feed) (#39746 by @diondiondion)

    Fix N+1 queries when rendering accounts on the admin collection page (#39738 by @rubys)

    Fix authored posts not immediately appearing in timelines (#39733 by @ChaosExAnima)

    Fix newletter button display on some e-mail clients (#39634 by @diondiondion)

    Fix handling of rdf:langString in media summary and name (#39590 by @ClearlyClaire)

    Fix error when rejecting appeal of already-deleted user (#39490 by @shleeable)

    Fix navigation switching to user “Account” category when viewing appeal for moderation interface (#39476, #39619 and #40026 by @ClearlyClaire and @shleeable)

    Changed

    Change follow recommendation materialized views to manually-maintained tables (#40039 by @ClearlyClaire)

    Change database schema to distinguish deleted-but-not-suspended accounts (#23617, #40027, #40029, #40034, #40083 and #40078 by @ClearlyClaire and @shleeable)

    Change reblogs to be deduplicated within the last 80 posts instead of the last 40 (#39784 by @ClearlyClaire)

    Change AttachmentBatch to reset retry attempt counter for each S3 batch (#39979 by @shleeable)

    Change featured tag recommendation criteria (#39567 by @renchap)

    Removed

    Remove inbox processing of collections of activities (#39932 by @ClearlyClaire)

    Remove support for Reject and Accept of QuoteRequest that cannot be found by id (#39833 by @ClearlyClaire)

    Remove deprecated bin/update script (#39443 by @mjankowski)

    Remove support for pre-Mastodon 4.3.0 cookies (#38918 by @ClearlyClaire)

    Upgrade notes

    To get the code for v4.7.0-rc.1, use git fetch && git checkout v4.7.0-rc.1.

    Note

    As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

    Dependencies

    External dependencies have not changed since v4.6.0.

    Ruby: 3.3 or newer

    PostgreSQL: 14 or newer

    Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work)

    LibreTranslate (optional, for translations): 1.3.3 or newer

    Redis: 7.0 or newer

    Node: 22 or newer

    libvips: 8.13 or newer

    FFMpeg: 5.1 or newer

    Cookies from pre-4.3.0 Mastodon

    This version drops compatibility with cookies issued by Mastodon v4.2 and earlier. This means that any user who has not visited your server after you updated to Mastodon 4.3 or newer will be logged out.

    Lengthy database migrations

    This version includes very substantial database migrations. They do not require unusual update steps, but they can take a long time. Expect up to a couple hours for very large servers.

    Update steps

    The following instructions are for updating from 4.6.5 or 4.6.7-beta.1.

    If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations. In particular, it is very important to read the 4.6.0 release notes.

    Non-Docker

    Tip

    The charlock_holmes gem may fail to build on some systems with recent versions of gcc.

    If you run into this issue, try BUNDLE_BUILD__CHARLOCK_HOLMES="--with-cxxflags=-std=c++17" bundle install.

    If you are using rbenv, update the list of available versions and install the proper Ruby version by doing RUBY_CONFIGURE_OPTS=--with-jemalloc rbenv install in the Mastodon install directory (e.g. /home/mastodon/live)

    Install dependencies with bundle install and yarn install --immutable

    Precompile the assets: RAILS_ENV=production bundle exec rails assets:precompile

    Run the pre-deployment database migrations by specifying the SKIP_POST_DEPLOYMENT_MIGRATIONS=true environment variable: SKIP_POST_DEPLOYMENT_MIGRATIONS=true RAILS_ENV=production bundle exec rails db:migrate

    Restart all Mastodon processes.

    Run the post-deployment database migrations: RAILS_ENV=production bundle exec rails db:migrate

    When using Docker

    Run the pre-deployment database migrations by specifying the SKIP_POST_DEPLOYMENT_MIGRATIONS=true environment variable: docker-compose run --rm -e SKIP_POST_DEPLOYMENT_MIGRATIONS=true web bundle exec rails db:migrate

    Restart all Mastodon processes.

    Run the post-deployment database migrations: docker-compose run --rm web bundle exec rails db:migrate

    Original source
  • Aug 13, 2026
    • Date parsed from source:
      Aug 13, 2026
    • First seen by Releasebot:
      Aug 13, 2026
    Mastodon logo

    Mastodon

    v4.6.6

    Mastodon ships v4.6.6 with a batch of fixes for Web UI access, preview cards, video playback, alt text editing, domain block queries, mobile navigation, and collection creation, plus an updated setup warning and an upgrade note requiring asset recompilation.

    Upgrade overview

    This release contains upgrade notes that deviate from the norm:

    ℹ️ Requires assets recompilation

    For more information, view the complete release notes and scroll down to the upgrade instructions section.

    Changelog

    Changed

    Change mastodon:setup task warning about trademark to match masto but ignore subdomains (#40143 by @ClearlyClaire)

    Fixed

    Fix connection errors when processing fediverse:creator preventing creation of preview cards (#40135 by @ClearlyClaire)

    Fix Web UI being inaccessible with URLs ending with .zip (#40134 by @ClearlyClaire)

    Fix semitransparent background of picture-in-picture video player (#40132 by @diondiondion)

    Fix title tooltip appearing for fullscreen videos (#40127 by @diondiondion)

    Fix image preview too dark in alt text editor dialog (#40126 by @diondiondion)

    Fix domain block impact queries being rejected (#40122 by @ClearlyClaire)

    Fix mobile navigation scrolling to top while opening (#40042 by @sharlayan)

    Fix selected account being lost when creating a collection (#39897 and #40133 by @diondiondion and @sharlayan)

    Upgrade notes

    To get the code for v4.6.6, use git fetch && git checkout v4.6.6.

    Note

    As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

    Dependencies

    External dependencies have not changed since v4.6.0.

    Ruby: 3.3 or newer

    PostgreSQL: 14 or newer

    Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work)

    LibreTranslate (optional, for translations): 1.3.3 or newer

    Redis: 7.0 or newer

    Node: 22 or newer

    libvips: 8.13 or newer

    FFMpeg: 5.1 or newer

    Update steps

    The following instructions are for updating from 4.6.5.

    If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations. In particular, it is very important to read the 4.6.0 release notes.

    Non-Docker

    Precompile the assets: RAILS_ENV=production bundle exec rails assets:precompile

    Restart all Mastodon processes.

    When using Docker

    Restart all Mastodon processes.

    Original source
  • Aug 13, 2026
    • Date parsed from source:
      Aug 13, 2026
    • First seen by Releasebot:
      Aug 13, 2026
    Mastodon logo

    Mastodon

    v4.5.16

    Mastodon fixes connection errors in preview card processing, restores Web UI access for URLs ending in .zip, improves domain block impact queries, and updates the mastodon:setup trademark warning for better matching.

    Changelog

    Changed

    Change mastodon:setup task warning about trademark to match masto but ignore subdomains (#40143 by @ClearlyClaire)

    Fixed

    Fix connection errors when processing fediverse:creator preventing creation of preview cards (#40135 by @ClearlyClaire)

    Fix Web UI being inaccessible with URLs ending with .zip (#40134 by @ClearlyClaire)

    Fix domain block impact queries being rejected (#40122 by @ClearlyClaire)

    Upgrade notes

    To get the code for v4.5.16, use git fetch && git checkout v4.5.16.

    Note

    As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump

    Dependencies

    External dependencies have not changed since v4.5.0.

    Ruby: 3.2 or newer

    PostgreSQL: 14 or newer

    Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work)

    LibreTranslate (optional, for translations): 1.3.3 or newer

    Redis: 7.0 or newer

    Node: 20.19 or newer

    libvips (optional, instead of ImageMagick): 8.13 or newer

    ImageMagick (optional if using libvips): 6.9.7-7 or newer

    Update steps

    The following instructions are for updating from 4.5.15.

    If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations. In particular, it is very important to read the 4.5.0 release notes.

    Restart all Mastodon processes.

    Original source