Here's a bugfix release! v0.22.2 Shrubbiest Sloth 🌿🌿🌿!
If you're updating to this version from v0.22.x, it's a very easy update with no db migrations.
If you're updating to this version from a version before v0.22.0, please follow the update instructions from v0.22.0, but replace 0.22.0 with 0.22.2 throughout. Be aware that the update to 0.22.x contains some serious database migrations. Please do read the notes carefully!
If you're on current main/snapshot, stay there. You already have bugfixes from here, and going backwards won't work.
Release highlights
Update dependencies to allow building on Go v1.27.
Tighten some auth functions to fix a two-factor authentication (2FA) security bug whereby an attacker who already knows a victim's email address + password, ie., the first factor authentication, could bypass having to input a code from an authenticator app, ie., the second factor of authentication, and obtain an OAuth token for that account. This bug only affects 2FA, and again, only in cases where an attacker already knows their victim's email address + password.
Migration notes
Upgrading
To upgrade to v0.22.2 from a previous release:
Binary/tar
Stop GoToSocial.
Back up your database! If you're running on SQLite, this is as simple as copying your sqlite.db file, eg., cp sqlite.db sqlite.db.backup. On Postgres you can do this with pg_dump.
Download and untar the new release, including the web assets and html templates, not just the binary.
Edit your config.yaml file if necessary (see below).
Start GoToSocial.
Wait patiently for any migrations to run, do not interrupt migrations or you could leave your db in a broken state and will have to restore from backup!
Enjoy your updated instance.
Docker
Stop GoToSocial.
Back up your database! If you're running on SQLite, this is as simple as copying your sqlite.db file, eg., cp sqlite.db sqlite.db.backup. On Postgres you can do this with pg_dump.
Pull the new docker container with docker pull docker.io/superseriousbusiness/gotosocial:0.22.2 or docker pull docker.io/superseriousbusiness/gotosocial:latest if this is a stable release and not a release candidate.
Edit your config.yaml file or environment variables if necessary (see below).
Start GoToSocial.
Wait patiently for any migrations to run, do not interrupt migrations or you could leave your db in a broken state and will have to restore from backup!
Enjoy your updated instance.
config.yaml
No changes since v0.22.x.
Database Migrations
No migrations since v0.22.x.
Which release archive/container should I use?
GoToSocial releases binary builds for 64-bit Linux, FreeBSD, and NetBSD operating systems. We also release Docker builds for 64-bit Linux.
For your convenience, we also provide UNSUPPORTED, EXPERIMENTAL BUILDS, created using the nowasm tag, in the downloads list below. There is no Docker build for nowasm.
GoToSocial releases built with nowasm use the Go-native, modernc version of SQLite instead of the WASM one, and will use on-system ffmpeg and ffprobe binaries for media processing.
Using a nowasm build is currently the only way to run GoToSocial on a 32-bit system.
For more information on running a nowasm build, see the nowasm documentation page.
Changelog
Bug fixes
fb2bf13 [bugfix] tighten auth requirements for mustUserFromSession
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [superseriousbusiness/gotosocial](https://docs.gotosocial.org) ([source](https://codeberg.org/superseriousbusiness/gotosocial)) | patch | `0.22.1` -> `0.22.2` |
---
### Release Notes
<details>
<summary>superseriousbusiness/gotosocial (superseriousbusiness/gotosocial)</summary>
### [`v0.22.2`](https://codeberg.org/superseriousbusiness/gotosocial/releases/tag/v0.22.2): Shrubbiest Sloth 🌿🌿🌿
[Compare Source](https://codeberg.org/superseriousbusiness/gotosocial/compare/v0.22.1...v0.22.2)
Here's a bugfix release! v0.22.2 Shrubbiest Sloth 🌿🌿🌿!
**If you're updating to this version from v0.22.x**, it's a very easy update with no db migrations.
**If you're updating to this version from a version before v0.22.0**, please follow the [update instructions from v0.22.0](https://codeberg.org/superseriousbusiness/gotosocial/releases/tag/v0.22.0), but replace `0.22.0` with `0.22.2` throughout. Be aware that the update to 0.22.x contains some serious database migrations. Please do read the notes carefully!
**If you're on current main/snapshot**, stay there. You already have bugfixes from here, and going backwards won't work.
#### Release highlights
- Update dependencies to allow building on Go v1.27.
- Tighten some auth functions to fix a two-factor authentication (2FA) security bug whereby an attacker who already knows a victim's email address + password, ie., the first factor authentication, could bypass having to input a code from an authenticator app, ie., the second factor of authentication, and obtain an OAuth token for that account. This bug only affects 2FA, and again, *only in cases where an attacker already knows their victim's email address + password*.
#### Migration notes
##### Upgrading
To upgrade to v0.22.2 from a previous release:
##### Binary/tar
1. Stop GoToSocial.
2. **Back up your database!** If you're running on SQLite, this is as simple as copying your `sqlite.db` file, eg., `cp sqlite.db sqlite.db.backup`. On Postgres you can do this with [pg\_dump](https://www.postgresql.org/docs/current/backup-dump.html).
3. Download and untar the new release, **including the web assets and html templates**, not just the binary.
4. Edit your config.yaml file if necessary (see below).
5. Start GoToSocial.
6. Wait patiently for any migrations to run, **do not interrupt migrations or you could leave your db in a broken state and will have to restore from backup**!
7. Enjoy your updated instance.
##### Docker
1. Stop GoToSocial.
2. **Back up your database!** If you're running on SQLite, this is as simple as copying your `sqlite.db` file, eg., `cp sqlite.db sqlite.db.backup`. On Postgres you can do this with [pg\_dump](https://www.postgresql.org/docs/current/backup-dump.html).
3. Pull the new docker container with `docker pull docker.io/superseriousbusiness/gotosocial:0.22.2` or `docker pull docker.io/superseriousbusiness/gotosocial:latest` if this is a stable release and not a release candidate.
4. Edit your config.yaml file or environment variables if necessary (see below).
5. Start GoToSocial.
6. Wait patiently for any migrations to run, **do not interrupt migrations or you could leave your db in a broken state and will have to restore from backup**!
7. Enjoy your updated instance.
##### config.yaml
No changes since v0.22.x.
##### Database Migrations
No migrations since v0.22.x.
##### Which release archive/container should I use?
GoToSocial releases binary builds for 64-bit Linux, FreeBSD, and NetBSD operating systems. We also release Docker builds for 64-bit Linux.
| OS | Architecture | Support level | Binary archive | Docker |
| ------- | --------------------- | ------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------- |
| Linux | x86-64/AMD64 (64-bit) | 🟢 Full | [linux\_amd64.tar.gz](https://codeberg.org/superseriousbusiness/gotosocial/releases/download/v0.22.2/gotosocial_0.22.2_linux_amd64.tar.gz) | `docker.io/superseriousbusiness/gotosocial:0.22.2` |
| Linux | Armv8/ARM64 (64-bit) | 🟢 Full | [linux\_arm64.tar.gz](https://codeberg.org/superseriousbusiness/gotosocial/releases/download/v0.22.2/gotosocial_0.22.2_linux_arm64.tar.gz) | `docker.io/superseriousbusiness/gotosocial:0.22.2` |
| FreeBSD | x86-64/AMD64 (64-bit) | 🟢 Full | [freebsd\_amd64.tar.gz](https://codeberg.org/superseriousbusiness/gotosocial/releases/download/v0.22.2/gotosocial_0.22.2_freebsd_amd64.tar.gz) | Not provided |
| FreeBSD | Armv8/ARM64 (64-bit) | 🟢 Full | [freebsd\_arm64.tar.gz](https://codeberg.org/superseriousbusiness/gotosocial/releases/download/v0.22.2/gotosocial_0.22.2_freebsd_arm64.tar.gz) | Not provided |
| NetBSD | x86-64/AMD64 (64-bit) | 🟢 Full | [netbsd\_amd64.tar.gz](https://codeberg.org/superseriousbusiness/gotosocial/releases/download/v0.22.2/gotosocial_0.22.2_netbsd_amd64.tar.gz) | Not provided |
| NetBSD | Armv8/ARM64 (64-bit) | 🟢 Full | [netbsd\_arm64.tar.gz](https://codeberg.org/superseriousbusiness/gotosocial/releases/download/v0.22.2/gotosocial_0.22.2_netbsd_arm64.tar.gz) | Not provided |
##### `nowasm`
For your convenience, we also provide **UNSUPPORTED, EXPERIMENTAL BUILDS**, created using the `nowasm` tag, in the downloads list below. There is no Docker build for `nowasm`.
GoToSocial releases built with `nowasm` use the Go-native, modernc version of SQLite instead of the WASM one, and will use *on-system ffmpeg and ffprobe binaries* for media processing.
Using a `nowasm` build is currently the only way to run GoToSocial on a 32-bit system.
For more information on running a `nowasm` build, see the [nowasm](https://docs.gotosocial.org/en/latest/advanced/builds/nowasm/) documentation page.
#### Changelog
##### Bug fixes
- [`fb2bf13`](https://github.com/superseriousbusiness/gotosocial/commit/fb2bf1330c355f19c6f3614d7434c56f8d55aeaf) \[bugfix] tighten auth requirements for `mustUserFromSession`
##### Other
- [`b16281e`](https://github.com/superseriousbusiness/gotosocial/commit/b16281e3dc1a7f71c8405103af07ec6c14aef550) fix build for go1.27
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
0.22.1->0.22.2Release Notes
superseriousbusiness/gotosocial (superseriousbusiness/gotosocial)
v0.22.2: Shrubbiest Sloth 🌿🌿🌿Compare Source
Here's a bugfix release! v0.22.2 Shrubbiest Sloth 🌿🌿🌿!
If you're updating to this version from v0.22.x, it's a very easy update with no db migrations.
If you're updating to this version from a version before v0.22.0, please follow the update instructions from v0.22.0, but replace
0.22.0with0.22.2throughout. Be aware that the update to 0.22.x contains some serious database migrations. Please do read the notes carefully!If you're on current main/snapshot, stay there. You already have bugfixes from here, and going backwards won't work.
Release highlights
Migration notes
Upgrading
To upgrade to v0.22.2 from a previous release:
Binary/tar
sqlite.dbfile, eg.,cp sqlite.db sqlite.db.backup. On Postgres you can do this with pg_dump.Docker
sqlite.dbfile, eg.,cp sqlite.db sqlite.db.backup. On Postgres you can do this with pg_dump.docker pull docker.io/superseriousbusiness/gotosocial:0.22.2ordocker pull docker.io/superseriousbusiness/gotosocial:latestif this is a stable release and not a release candidate.config.yaml
No changes since v0.22.x.
Database Migrations
No migrations since v0.22.x.
Which release archive/container should I use?
GoToSocial releases binary builds for 64-bit Linux, FreeBSD, and NetBSD operating systems. We also release Docker builds for 64-bit Linux.
docker.io/superseriousbusiness/gotosocial:0.22.2docker.io/superseriousbusiness/gotosocial:0.22.2nowasmFor your convenience, we also provide UNSUPPORTED, EXPERIMENTAL BUILDS, created using the
nowasmtag, in the downloads list below. There is no Docker build fornowasm.GoToSocial releases built with
nowasmuse the Go-native, modernc version of SQLite instead of the WASM one, and will use on-system ffmpeg and ffprobe binaries for media processing.Using a
nowasmbuild is currently the only way to run GoToSocial on a 32-bit system.For more information on running a
nowasmbuild, see the nowasm documentation page.Changelog
Bug fixes
fb2bf13[bugfix] tighten auth requirements formustUserFromSessionOther
b16281efix build for go1.27Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.