Folk Zone Release Notes
3 release notes curated from 4 sources by the Releasebot Team. Last updated: Sep 1, 2026
- Aug 9, 2026
- Date parsed from source:Aug 9, 2026
- First seen by Releasebot:Sep 1, 2026
Security Audit: Hardening folk.zone After Spam Attack
Folk Zone strengthens its infrastructure with security hardening after a spam and attack audit, plus new and restored services including webmention.folk.zone for IndieWeb conversations and a stable, operational Lemmy instance at lemmy.folk.zone.
Hello, first off my apologies for not updating this project sooner. I have been busy with my writing and other initatives, but that is no excuse. I will try to ensure these updates are more regular moving forward.
On August 10, 2026, I conducted a security audit of the folk.zone infrastructure. This audit revealed some issues that required immediate attention, particularly with the WriteFreely instance.
What I Found
WriteFreely Compromised
The most serious finding was that the WriteFreely instance at write.folk.zone had been overrun by spam bots. With open registration enabled, automated bots created 569 fake users and published 526 spam posts in Thai language promoting online gambling and casinos.
The spam accounts followed clear patterns:
- Generic usernames with random numbers (e.g., "nora25724176", "jade16631554")
- Pattern-based usernames (e.g., "cybersky89", "skyember4902")
- Mass account creation throughout July 2026
Other Issues
Forgejo (git.folk.zone): Multiple SSH brute force attacks from various IP addresses attempting to access the Git service using invalid usernames.
URL Shortener (go.folk.zone): Path traversal attacks attempting to access sensitive system files through URL encoding bypass attempts.
BookWyrm (books.folk.zone): Automated vulnerability scanning attempting to discover sensitive configuration files (all attempts blocked).
Countermeasures Taken
WriteFreely Cleanup
I took action to clean up the WriteFreely instance:
- Disabled open registration to prevent future spam account creation
- Removed spam users and posts from the database
- Restarted the service with new security settings
During this cleanup, I was too aggressive in removing accounts and may have deleted some legitimate early users who signed up before the spam wave began. I should have used a more conservative approach, such as only removing accounts created after a certain date or those with obvious spam patterns. I sincerely apologize for this error and will be much more careful with user data in the future.
Forgejo Security Hardening
- Enabled rate limiting in Forgejo configuration
- Set rate limiting recovery time to 60 seconds
- Set memory duration to 30 minutes
- Restarted the service
Other Services
- Reviewed all service logs for suspicious activity
- Confirmed no successful breaches
- Verified security headers are configured across all services
Lessons Learned
This audit taught me a few lessons:
- Rate Limiting: Rate limiting should be enabled on all authentication endpoints by default
- Monitoring: Automated security monitoring and alerting is essential
- Conservative Cleanup: When dealing with user data, use conservative approaches and always ask before destructive actions
Moving Forward
The homelab is now more secure with proper rate limiting, disabled open registration on vulnerable services, and enhanced monitoring. I've implemented a regular security audit schedule and will be more vigilant about monitoring for suspicious activity.
The security of folk.zone and the privacy of its users remain my top priorities.
New Service: Webmention
I'm pleased to announce that webmention.folk.zone has been added to the folk.zone infrastructure. This service provides webmention support for the IndieWeb, allowing sites to send and receive webmentions for better cross-site conversation and interaction.
Lemmy Status Update
The Lemmy instance at lemmy.folk.zone is now operational and ready for use. After some initial setup and configuration, the federated link aggregation and discussion platform is stable and accepting new communities.
If you have any concerns about your account or data, please reach out to me at p@[email protected].
Original source - Jun 20, 2026
- Date parsed from source:Jun 20, 2026
- First seen by Releasebot:Sep 1, 2026
New Services: BookWyrm, Etherpad, and a Few Things to Know
Folk Zone adds BookWyrm at books.folk.zone, opens Etherpad at pad.folk.zone, and brings a TownSquare widget to the homepage for real-time presence. It also notes a simpler single-machine setup and more services still on the way.
A few days ago I published the first post here and launched folk.zone with a modest set of services. Since then I've added two more that have been on the list, consolidated everything onto a single machine, and wanted to share a few things.
What's New
books.folk.zone: BookWyrm is now online. It's a federated reading tracker, part Goodreads, part social network for books. You can log what you're reading, write reviews, follow readers on other BookWyrm instances, and have those reviews federate out to Mastodon. It's invite-only for now as I set it up.
pad.folk.zone: Etherpad is open. Real-time collaborative documents with no account required. Create a pad, share the URL, write together. Great for drafting things with people who don't want to sign up for anything. Pads persist but I make no archival guarantees.
folk.zone: Finally, the homepage now has a TownSquare widget tucked below the footer. It's a small presence layer that shows visitors on the page in real time. You can move around, wave, and say a few words to whoever else happens to be there. No account needed. A small nod toward making the web feel inhabited again.
About Invites
A few people have reached out asking how to get access to folk.zone. I really appreciate the interest. One thing to know is these services are not interconnected the way omg.lol is. An invite to folk.zone is not an invite to everything. Each service has its own account system and its own waitlist.
When you reach out, please tell me which service you want access to, and ideally why. The services that currently require an invite or application are:
- social.folk.zone (Mastodon)
- books.folk.zone (BookWyrm)
Fully open services (no invite needed) include git, gist, irc, paste, pad, wiki, links, bridge, go, write, and rss. Just visit them and use them!
Find me at @[email protected] with your request.
The Stack
I originally described folk.zone as running across four separate machines. That was the plan, but in practice everything is now running on a single machine, nitro, a Core i5-12400F with 15 GB RAM. The other machines are still around but not currently serving folk.zone traffic.
This simplifies deployment and makes it easier to keep things reliable. It also means that if nitro goes down, everything goes down at once. I'm at peace with that trade-off for now.
What's Still Coming
pics.folk.zone (Pixelfed) is still on the list, among a few more.
If you have requests, the wiki is a good place to document ideas, or find me on IRC at irc.folk.zone.
Original source All of your release notes in one feed
Join Releasebot and get updates from Folk Zone and hundreds of other software products.
- Jun 18, 2026
- Date parsed from source:Jun 18, 2026
- First seen by Releasebot:Sep 1, 2026
folk.zone is Live: What's Online and What's Next
Folk Zone launches as an IndieWeb commons with a suite of self-hosted social, publishing, chat, code, reading, and utility services on real hardware in Calgary. It also adds a new status page, publishes the folk pledge, and moves the homepage to Eleventy for easier updates.
folk.zone is now live. This is what we've built so far, what's online, and what this project is about.
What folk.zone Is
folk.zone is an IndieWeb commons, a collection of free and open-source internet services running on real hardware in Calgary, Alberta. No company and no business model beyond "I think this is worth doing." It's infrastructure for the common folk, by one of them.
The name comes from folk music and folk art, community-made things that persist because people care about them, and the folk as in regular people, not institutions, not platforms, not corporations.
What's Online Right Now
Social & Community
social.folk.zone: A Mastodon instance running glitch-soc. Federated social media for the common folk. Invite-only at launch to build the community intentionally.
lemmy.folk.zone: A Lemmy instance for federated link aggregation and discussion. Communities for whatever you want to build together.
irc.folk.zone: An IRC server running Ergo with The Lounge web client. Real-time chat, old school but still excellent. Join #general and say hello.
Writing & Publishing
write.folk.zone: A WriteFreely instance for longform writing and blogging. Federated via ActivityPub, minimalist by design.
Code
git.folk.zone: A Forgejo instance for git hosting. Open registration, anonymous git clone permitted. Low risk, no federation, just code.
Reading & Research
rss.folk.zone: FreshRSS for self-hosted RSS reading. Invite-only accounts.
bridge.folk.zone: RSS Bridge for generating RSS feeds from sites that don't have them. Open, no accounts required.
links.folk.zone: Linkding for bookmark management. Private initially.
Utilities & Collaboration
paste.folk.zone: PrivateBin for encrypted, ephemeral pastes. Open, anonymous allowed. No account required.
wiki.folk.zone: DokuWiki for documentation and knowledge sharing. Open read, logged-in edit.
go.folk.zone: Kutt for URL shortening. Private initially, operator-curated links may open later.
Infrastructure
status.folk.zone: A custom status page built with Python and Flask. It monitors all the containers, shows real-time health, and displays system metrics. It's styled to match the folk.zone aesthetic and is fully open source.
The Hardware
Everything runs on four physical machines in Calgary:
- nitro: Intel Core i5-12400F, 15 GB RAM. Mastodon, Forgejo, Lemmy live here. Most CPU and storage.
- cafe: AMD FX-4130, 7 GB RAM. Caddy reverse proxy, homepage, paste, IRC, short links.
- click: Intel Core i5-5257U (MacBook Pro 2015), 8 GB RAM. FreshRSS, Etherpad, Umami, DokuWiki, RSS-Bridge.
- casa: Intel Core i5-7200U (ThinkPad X270), 7.3 GB RAM. WriteFreely. Future home of BookWyrm.
All of this runs in my living space on a residential internet connection. I make no SLA guarantees.
The Folk Pledge
We've published the folk pledge, a commitment to put marginalized communities first in all decisions about folk.zone. This isn't just words, it's a commitment to action.
The Homepage
The homepage has been migrated from handwritten static HTML to Eleventy, a static site generator. This makes it easier to maintain, allows for the blog you're reading now, and provides a foundation for future improvements. Service cards are now data-driven from a JSON file, making updates simpler.
What's Next
This is an experiment. I don't know if people will actually use this. I don't know if there will be cyberattacks or DDoS or quiet years of steady use. But I have to try anyway, because it's the next logical step for someone who cares about building the web, not just using it.
Registration is invite-only or application-based at launch. Find me at @[email protected] to get on the list. Read the about page for more details, or browse the wiki for documentation.
The IndieWeb can only survive if people contribute to the infrastructure and not just the conversation. folk.zone is my attempt to do that.
Original source Similar to Folk Zone with recent updates:
- Smokeball release notes144 release notes · Latest Sep 4, 2026
- Cosmolex release notes20 release notes · Latest Jul 30, 2025
- PracticePanther release notes36 release notes · Latest Aug 11, 2026
- Salesforce release notes71 release notes · Latest Sep 1, 2026
- Microsoft release notes820 release notes · Latest Sep 4, 2026
- Zoom release notes210 release notes · Latest Aug 31, 2026
This is the end. You've seen all the release notes in this feed!
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.