Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Fedify: ActivityPub server framework

@fedify@hollo.social
hollo 0.10.0-dev.658
  • Open on hollo.social

:fedify: Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards, so-called fediverse. It aims to eliminate the complexity and redundant boilerplate code when building a federated server app, so that you can focus on your business logic and user experience.

249 Followers
0 Following
20 Posts
Joined June 28, 2024
Website:

https://fedify.dev/

GitHub:

https://github.com/fedify-dev/fedify

JSR:

https://jsr.io/@fedify/fedify

npm:

https://www.npmjs.com/package/@fedify/fedify

Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 5mo ago

Naru, the Korean version of #Neocities, reportedly added an #ActivityPub implementation in just an hour using #Fedify. If you also want to implement ActivityPub quickly, give Fedify a try!

@jihyeok@hackers.pub

naru.pub
36
2
33
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 3mo ago
Boosted by @fedicat@pc.cafe
Two new maintainers join Fedify: Chanhaeng Lee and Jiwon Kwon Chanhaeng Lee (@2chanhaeng@hackers.pub) and Jiwon Kwon (@z9mb1@hackers.pub) are now co-maintainers of Fedify. They have already been doing maintainer-shaped work for much of the past year, so this is mostly making the repository match reality. Chanhaeng has done a lot of the package-boundary work in Fedify. The most visible piece was splitting the old @fedify/fedify/x/* modules into standalone packages: @fedify/cfworkers, @fedify/denokv, @fedify/hono, and @fedify/sveltekit. They then separated the Activity Vocabulary layer itself into @fedify/vocab, @fedify/vocab-runtime, and @fedify/vocab-tools, making it possible to build custom vocabulary extensions without touching the federation core. They built @fedify/next and @fedify/nuxt from scratch, contributed to @fedify/solidstart, and added Nuxt support to fedify init. @fedify/sqlite gained SqliteMessageQueue: a queue backend that only needs SQLite, handy for single-node deployments and local development. Chanhaeng also implemented the fedify webfinger CLI command, fediverse handle utilities (parseFediverseHandle(), isFediverseHandle(), toAcctUrl()), and the @fedify/webfinger and @fedify/lint packages. They are currently working on a custom background task API built around defineTask(). Jiwon has spent much of the past year making the CLI and relay tooling more useful for real ActivityPub debugging. fedify relay, backed by @fedify/relay, spins up a local ephemeral ActivityPub relay server with Mastodon and LitePub support. They extended fedify lookup with multi-URL traversal and inline image rendering for compatible terminal emulators (Kitty, WezTerm, iTerm, and others), and added configuration file support so options can live in ~/.config/fedify/config.toml or a project-local .fedify.toml rather than being passed on every invocation. They also fixed a race condition in RedisMessageQueue, corrected ActivityPub object handling for relative URLs, extended TypeScript types for RFC 6570 URI Template expressions in dispatcher paths, and implemented the FEP-5711 inverse collection properties, including likesOf, repliesOf, and followersOf. Chanhaeng and Jiwon both came to Fedify through OSSCA 2025, Korea's Open Source Contribution Academy. I'm grateful that the program led to long-term maintainers, not just a few merged patches, and I'm looking forward to working with them in this new role.
13
1
14
2
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 5mo ago

We're working on a new #tutorial for #Fedify: Building a Federated Blog with Astro!

It walks you through creating a hybrid blog—static Markdown posts powered by #Astro content collections, with #ActivityPub federation layered on top. By the end, your blog will be followable from Mastodon, send Create/Update/Delete activities when you publish or edit posts, and display #fediverse replies as comments.

Preview the draft here: https://d180af62.fedify.pages.dev/tutorial/astro-blog.

We'd love your feedback—especially if you spot anything incorrect, unclear, or missing. Please leave comments on the GitHub PR #695 or issue #691.

#fedidev

hollo.social
22
0
28
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 3mo ago
Boosted by @fedicat@pc.cafe
Fedify 2.3.0 is out! This release is largely about production observability: OpenTelemetry metrics now cover every major federation path, and a monitoring guide and runnable example stack ship alongside them. Also new: a delivery circuit breaker that holds queued activities for unreachable servers rather than retrying indefinitely; @fedify/backfill, a new package for reconstructing conversations via FEP-f228; and fedify bench, an ActivityPub-aware load testing command. Release notes: https://github.com/fedify-dev/fedify/discussions/821 Thanks to @2chanhaeng@hackers.pub (@fedify/uri-template), @z9mb1@hackers.pub (@fedify/backfill), @sabrinkmann@hachyderm.io (FEP-0837 vocabulary), @nyanrus@sukhi.f3liz.casa (@fedify/lint/oxlint), and @fruitsssdev@hackers.pub (--skip-install) for their contributions to this release.
GitHub

Fedify 2.3.0: OpenTelemetry metrics, delivery circuit breaker, `@fedify/backfill`, and `fedify bench` · fedify-dev/fedify · Discussion #821

Fedify is a TypeScript framework for building ActivityPub servers. It implements federation details such as HTTP Signatures, JSON-LD processing, WebFinger, inbox and outbox routing, and activity de...

8
0
8
1
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 3mo ago
Boosted by @fedicat@pc.cafe
DrFed is our sister project, built alongside #Fedify to tackle the debugging side of #ActivityPub development. It just received @nlnet@social.nlnet.nl funding and now has its own account here: @drfed@hackers.pub. #DrFed #fedidev #fediverse #NLnet RE: https://hackers.pub/@drfed/019ed3c9-7e8c-782f-a512-5fbc75a4610b
Open quoted post
Quoting
DrFed
@drfed@hackers.pub
Some of you have already heard of us as #Fedify Studio. We now have a proper name: DrFed, short for “Doctor Fed.” We've also just received funding from @nlnet@social.nlnet.nl, through the NGI0 Commons Fund. #DrFed is a web app for debugging #ActivityPub interoperability failures. When two implementations don't federate, the slow part is usually figuring out where the exchange broke: signing, JSON-LD processing, WebFinger, or something less obvious. DrFed's first job is to show where it failed. We're the team behind @fedify@hollo.social: @2chanhaeng@hackers.pub, @gaebalgom@hackers.pub, @hongminhee@hollo.social, and @z9mb1@hackers.pub. We'll post updates when there's something to try. #fedidev #fediverse
Open quoted post
hackers.pub

Some of you have already heard of us as #Fedify Studio. We now have a proper na…

Some of you have already heard of us as #Fedify Studio. We now have a proper name: DrFed, short for “Doctor Fed.” We

9
1
10
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 5mo ago
Fedify security updates: 1.9.10, 1.10.9, 2.0.16, 2.1.12, and 2.2.1

If you use Fedify, update to a patched release now. A private network protection bypass affects Fedify's remote document loading code. URLs with private IPv4 addresses encoded as IPv4-mapped IPv6 literals, such as http://[::ffff:7f00:1]/, could pass validatePublicUrl() even though they refer to private or loopback addresses.

Fedify uses validatePublicUrl() when fetching remote ActivityPub documents and related resources. An attacker who can make a Fedify server fetch an attacker-controlled URL may be able to bypass the private address checks that are intended to reduce SSRF risk.

All versions up to and including 2.2.0 are affected. Patched releases are 1.9.10, 1.10.9, 2.0.16, 2.1.12, and 2.2.1.

For Fedify 1.x, update @fedify/fedify:

npm update @fedify/fedify
yarn upgrade @fedify/fedify
pnpm update @fedify/fedify
bun update @fedify/fedify
deno update @fedify/fedify

For Fedify 2.x, update both @fedify/fedify and @fedify/vocab-runtime:

npm update @fedify/fedify @fedify/vocab-runtime
yarn upgrade @fedify/fedify @fedify/vocab-runtime
pnpm update @fedify/fedify @fedify/vocab-runtime
bun update @fedify/fedify @fedify/vocab-runtime
deno update @fedify/fedify @fedify/vocab-runtime

After updating, redeploy. If you run other Fedify-based servers, update those too.

Thanks to Changkyun Kim (@me) for the report and responsible disclosure.

If anything is unclear, ask below.

GitHub

Release Fedify 1.9.10 · fedify-dev/fedify

Released on May 10, 2026. @fedify/fedify Fixed validatePublicUrl() allowing private IPv4 addresses encoded as IPv4-mapped IPv6 URL literals, such as http://[::ffff:7f00:1]/, which could bypass pri...

11
0
17
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 5mo ago

Fedify 2.2.0 is out! This release finally adds client-to-server (C2S) outbox listener support, proper HTTP 410 Gone responses for deleted actors via Tombstone, new integrations for SolidStart and Nuxt, and interoperability fixes for Lemmy and Pixelfed. Three new end-to-end tutorials also landed alongside a custom collections cookbook.

https://github.com/fedify-dev/fedify/discussions/733

GitHub

Fedify 2.2.0: C2S outbox listeners, `Tombstone` support, SolidStart and Nuxt integrations, and three new tutorials · fedify-dev/fedify · Discussion #733

Fedify is a TypeScript framework for building ActivityPub servers. It implements federation details such as HTTP Signatures, JSON-LD processing, WebFinger, inbox and outbox routing, and activity de...

10
0
18
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 3mo ago
Boosted by @fedicat@pc.cafe
The official account for the Fedify project is moving to @fedify@hackers.pub. This account will be replaced by the new one. Followers should automatically follow the new account unless any issues occur.
4
0
7
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 3mo ago
OSSCA 2026 has started, and Fedify is joining for the second year. 24 mentees will work on Fedify, Hollo, BotKit, DrFed, and Feder over the next four months, with some of that work likely to continue after the program ends. OSSCA, the Open Source Software Contribution Academy, is a South Korean mentorship program that connects developers with active open source projects. @2chanhaeng@hackers.pub and @z9mb1@hackers.pub, both Fedify co-maintainers who first came to the project through OSSCA 2025, are mentoring this year's cohort. Welcome, everyone.
3
0
6
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 4mo ago
Boosted by @fedicat@pc.cafe
Fedify security updates: 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3 If you use Fedify, update to a patched release now. CVE-2026-42462 affects Fedify's Linked Data Signature handling. An attacker could use JSON-LD graph-restructuring features to change how a signed activity is interpreted without invalidating its Linked Data Signature. Fedify verifies incoming ActivityPub activities with several mechanisms, including HTTP Signatures, Object Integrity Proofs, and Linked Data Signatures. The vulnerable path is Linked Data Signatures: the signature is checked over the canonical RDF graph, but JSON-LD can represent the same graph in more than one JSON shape. In affected versions, that gap could let a signed activity be reshaped so that Fedify reads a different ActivityPub object shape than intended. The fix makes Fedify normalize Linked Data Signature-verified activities against Fedify's local JSON-LD context before interpreting them, and rejects JSON-LD constructs that can preserve the signed RDF graph while changing the ActivityPub object shape consumed by Fedify. Patched releases are 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3. The GitHub Security Advisory is GHSA-9rfg-v8g9-9367, and the CVE ID is CVE-2026-42462. Update @fedify/fedify: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify After updating, redeploy. If you run other Fedify-based servers, update those too. Thanks to @Claire@social.sitedethib.com for the report and responsible disclosure. If anything is unclear, ask below.
5
0
22
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 6mo ago
Fedify security updates: 1.9.7, 1.10.6, 2.0.10, and 2.1.3

If you use Fedify, update to a patched release now. A high-severity denial-of-service vulnerability (CVE-2026-34148) affects Fedify's remote document loader and authenticated document loader. Both follow HTTP redirects without a redirect limit or loop detection. An attacker-controlled server can return a redirect loop for a keyId or actor URL fetch, causing a single inbound ActivityPub request to keep issuing outbound requests until the fetch times out.

All versions up to and including 2.1.0 are affected. Patched releases are 1.9.7, 1.10.6, 2.0.10, and 2.1.3. Update with your package manager:

npm update @fedify/fedify
yarn upgrade @fedify/fedify
pnpm update @fedify/fedify
bun update @fedify/fedify
deno update @fedify/fedify

After updating, redeploy. If you run other Fedify-based servers, update those too.

Thanks to Abhinav Jaswal for the report and responsible disclosure. Disclosure was coordinated with Ghost so they had time to ship their update.

If anything is unclear, ask below.

GitHub

Resource exhaustion caused by unbounded redirect following during remote key/document resolution

### Summary `@fedify/fedify` follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop det...

5
0
10
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 5mo ago

The official Awesome Fedify site is now live:

http://awesome.fedify.dev/

It brings together real-world Fedify projects, packages, examples, tutorials, and talks in one place.

If you know a good resource we should list, contributions are welcome:

https://github.com/fedify-dev/awesome-fedify

Awesome Fedify
Awesome Fedify

Awesome Fedify

A curated directory of Fedify projects, packages, examples, tutorials, and talks.

4
0
4
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 4mo ago
Boosted by @fedicat@pc.cafe
There's a Matrix room for #Fedify contributors, open to anyone curious about how development happens. Feel free to drop in or lurk; small questions are fine too. #fedify-contributors:matrix.org
2
0
5
1
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 6mo ago

Fedify 2.1.0 is out!

The highlight of this release is onUnverifiedActivity(), a long-requested hook that lets you intercept inbound activities whose signatures couldn't be verified, instead of silently returning 401 and letting remote servers retry forever. Great for handling Delete activities from permanently gone actors.

Also new: full RFC 9421 Accept-Signature negotiation on both outbound and inbound paths, GoToSocial interoperability fixes, @fedify/mysql for MySQL/MariaDB backends, @fedify/astro for Astro integration, and fedify lookup --recurse for following reply chains.

Release notes: https://github.com/fedify-dev/fedify/discussions/642

GitHub

Fedify 2.1.0: Unverified activity hooks, RFC 9421 negotiation, MySQL support, and Astro integration · fedify-dev/fedify · Discussion #642

Fedify is a TypeScript framework for building ActivityPub servers that participate in the fediverse. It handles the heavy lifting of federation—HTTP Signatures, JSON-LD processing, WebFinger, and m...

4
0
15
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 7mo ago

Jiwon (@z9mb1@hackers.pub), one of our core contributors, drew a Fedify dino! How cute!

@z9mb1@oeee.cafe

oeee.cafe
3
0
9
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 7mo ago
Replying to
コミュニティをDiscordからMatrixへ段階的に移行しています。メンテナーとコントリビューターはすでにMatrixに移っているため、今後はMatrixのほうが返答が早くなります。Discordはしばらく継続しますが、Matrixがメインの場となりました。 詳細とMatrixルームの一覧はこちら:https://github.com/fedify-dev/fedify/discussions/573(英文)
github.com
3
0
4
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 7mo ago
Replying to
Fedify 2.0.0をリリースしました! Fedify史上最大のリリースです。主な変更点をご紹介します: モジュラーアーキテクチャ — これまでのモノリシックな@fedify/fedifyパッケージを、@fedify/vocab、@fedify/vocab-runtime、@fedify/vocab-tools、@fedify/webfingerなど、独立したパッケージに分割しました。バンドルサイズの削減、インポートの整理に加え、カスタム語彙型によるActivityPubの拡張も可能になりました。リアルタイムデバッグダッシュボード — 新しい@fedify/debuggerパッケージにより、/__debug__/パスにライブダッシュボードを表示できます。連合トラフィックのトレース、アクティビティの詳細、署名検証、ログまで一目で確認できます。既存のFederationオブジェクトをラップするだけで使えます。ActivityPubリレーサポート — @fedify/relayパッケージとfedify relayCLIコマンドで、リレーサーバーをすぐに立ち上げることができます。Mastodon方式とLitePub方式の両方に対応しています(FEP-ae0c)。順序保証メッセージ配信 — 新しいorderingKeyオプションにより、「ゾンビ投稿」問題を解決しました。DeleteがCreateより先に到着してしまう問題がなくなります。同じキーを共有するアクティビティはFIFO順序が保証されます。永続的な配信失敗の処理 — setOutboxPermanentFailureHandler()で、リモートのインボックスが404や410を返した際に対応できるようになりました。到達不能なフォロワーの整理などが可能です。 その他にも、ミドルウェアレベルでのコンテンツネゴシエーション、@fedify/lint、@fedify/create、CLI設定ファイル、ネイティブNode.js/Bun CLIサポート、多数のバグ修正などが含まれています。 今回のリリースには、韓国のOSSCA(オープンソースコントリビューションアカデミー)参加者の皆さんからの多大な貢献が含まれています。ご協力いただいた全ての方に感謝いたします! 破壊的変更を含むメジャーリリースです。アップグレード前にマイグレーションガイドを必ずご確認ください。 リリースノート全文: https://github.com/fedify-dev/fedify/discussions/580 #Fedify #ActivityPub #fediverse #fedidev #TypeScript
GitHub

Fedify 2.0.0: Modular architecture, debug dashboard, and relay support · fedify-dev/fedify · Discussion #580

Fedify is a TypeScript framework for building ActivityPub servers that participate in the fediverse. It reduces the complexity and boilerplate typically required for ActivityPub implementation whil...

2
0
9
0
Open post
Fedify: ActivityPub server framework @fedify@hollo.social
· 22mo ago
Replying to
돌아왔습니다. 集會에서는 인터넷이 잘 안 되어서 업데이트를 하나도 못했네요…
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:56:46 UTC