Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Vikunja (/vɪˈkuːnjə/)

@vikunja@social.linux.pizza
mastodon 4.7.3
  • Open on social.linux.pizza

The open source to-do app to simplify your life. Built by @kolaente@mastodon.social

969 Followers
1 Following
22 Posts
Joined October 28, 2022
Website:
https://vikunja.io
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 1mo ago

🚀 Vikunja 2.6.0 is out! 380 commits, 18 of which are security fixes. 🔒

Also new: import from Planka 📥, image/audio/video previews for attachments 🖼️, and an email change flow that no longer locks you out on a typo. ✉️

https://vikunja.io/changelog/vikunja-2.6.0-was-released/

vikunja.io
6
0
5
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 2mo ago

🚀 Vikunja 2.5.0 is out! Small release, 203 commits of cleanup.

🔒 One security fix: a share link could act as another user. Please update.

⚡ Pasting a list into quick add magic now creates every task in one request, in the order you wrote them.

Plus a bunch of CalDAV, notification and import fixes 🦙

https://vikunja.io/changelog/vikunja-2.5.0-was-released/

vikunja.io
10
0
5
1
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 5mo ago

Cal.com announced they're going closed source. The stated reason: AI has made it too easy for attackers to find bugs in public code.

I've been thinking about this for a bit. It's security-through-obscurity with a 2026 paint job, and I don't buy it.

Kerckhoffs's principle is over a century old: a system should remain secure even when everything about it except the key is public.

LLMs don't change the direction, only the speed. AI scans closed code just fine (fuzzing, binaries, APIs). Hiding the source doesn't remove bugs. It just means whoever finds them has no obligation to tell you first.

From Vikunja's own release notes: CVE-2026-28268, fixed in 2.1.0. Password reset tokens weren't being invalidated after use. The bug had been sitting in the codebase since v0.18.0 in September 2021.

A researcher found it (probably with the help of AI), reported it responsibly, and it got fixed. If the source had been closed, nobody external would have been in a position to catch it.

Every founder who eventually closed their source once said "I promise we won't." I believe they meant it at the time. Circumstances change.

So the better question is: what would have to happen for Vikunja to close? Four structural facts: AGPL-3 license, no CLA, no investors, and anyone can fork today's code.

Transparency trades "bugs found later by the wrong people" for "bugs found earlier by the right ones."

That's the actual tradeoff. Closing the source flips the sign on every term.

https://vikunja.io/changelog/vikunja-stays-open/

vikunja.io
57
2
46
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 2mo ago

🦙 Vikunja 2.4.0 is out! Ten security fixes (please update soon), the first Vikunja Pro features, and a brand-new v2 API. Full rundown: https://vikunja.io/changelog/vikunja-2.4.0-pro-and-a-new-api

vikunja.io
11
0
8
1
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 4mo ago

In 2020 the EU's open-source strategy was an internal memo about the Commission's own code. Today's wants Europe to build open alternatives to US proprietary software, and treat them as industrial policy.

Good, and long overdue. But it's non-binding, and ~€2B over 7 years is a rounding error next to the ~€264B Europe spends on proprietary software every year.

The lever it keeps ignoring is its own procurement budget.

https://vikunja.io/changelog/eu-open-source-budget-is-the-policy/

For EU Open Source, the Budget Is the Policy
vikunja.io

For EU Open Source, the Budget Is the Policy

The EU

21
0
12
1
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 6mo ago

🦙 Vikunja 2.3.0 is out! 11 security fixes, a new plugin system, quick-entry window for the desktop app, Vikunja as an OAuth 2.0 provider, WeKan + CSV imports, and more across 277 commits. Updating soon is highly reccomended!

https://vikunja.io/changelog/whats-new-in-vikunja-2.3.0

vikunja.io
12
6
6
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 5mo ago

cal.com closed their source this week, citing AI bug-hunters as the reason.

Every time a project does this, someone asks if Vikunja could too.

Not easily. AGPL-3, no CLA, no investors, and anyone can fork today's code.

More on why: https://vikunja.io/changelog/vikunja-stays-open/

vikunja.io
11
0
7
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 7mo ago
🎉 Just two days after the last release, Vikunja 2.1.0 is now released! 🔒 Fixes a security issue with password reset tokens and adds a nice touch: checklist indicators now turn green when all items are done! Check out the full release post on the website: https://vikunja.io/changelog/vikunja-v2.1.0-was-released/
Vikunja 2.1.0: One security fix and some improvements
vikunja.io

Vikunja 2.1.0: One security fix and some improvements

Vikunja 2.1.0 fixes a security issue where password reset tokens were not cleaned up after use (CVE-2026-28268) and includes quality of life improvements like a green checklist indicator when all items are done.

12
0
7
1
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 6mo ago

🔒 Vikunja 2.2.2 is out: nine security fixes including a critical chain that could expose instance-wide data. Also adds centralized SSRF protection and a few nice bug fixes. Please update soon!

(2.2.1 has been released as well but did not fix the issues fully, therefore I went and pushed 2.2.2 right after)

https://vikunja.io/changelog/vikunja-v2.2.2-was-released

vikunja.io
9
1
2
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 7mo ago

📣 Vikunja now (finally) has help docs for end users! Check it out at the website and tell me what you think: https://vikunja.io/help

vikunja.io
10
0
4
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 6mo ago
PSA: The next Vikunja release will fix 10 (!) CVEs. If all goes well, later today or tomorrow.
9
0
5
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 6mo ago

PSA: there will be a release tomorrow (April 8th) or the day after that with a bunch of security fixes

7
0
2
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 6mo ago

🔒 Vikunja 2.2.0 is out! 10 security fixes (update now!), plus task duplication, an improved Gantt chart with subtask hierarchy & dependency arrows, and user-level webhooks. 237 commits of goodness 🚀

https://vikunja.io/changelog/vikunja-v2.2.0-was-released

vikunja.io
8
0
7
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 6mo ago

PSA: Because of the great recent success, there will be ANOTHER release later today or tomorrow fixing 9 more security vulnerabilities.

6
1
3
1
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 7mo ago
PSA: Vikunja 1.2.0 will be released tomorrow or the day after. It will fix four (!) critical security vulnerabilities.
7
0
5
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 7mo ago
Replying to
The post is now updated with details about the vulnerability!
7
3
0
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 5mo ago
Replying to
@badnetmask@hachyderm.io @homelab@fedigroups.social happy to be here!
1
1
0
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 6mo ago
Replying to on mastodon.social
@pojntfx@mastodon.social @jonasfranz@gruene.social We have CalDAV support 👀 https://vikunja.io/help/caldav/
CalDAV
vikunja.io

CalDAV

Sync tasks with external apps using CalDAV. Covers supported properties, URLs, and client compatibility.

1
0
0
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 7mo ago
Replying to
@LilithElina@norden.social @mailbox_org@social.mailbox.org das sollte mit Vikunja ganz gut funktionieren. Für Push-Nachrichten kann ich entweder die Vikunja-App oder die Synchronisation mit Tasks.org empfehlen
1
4
0
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 7mo ago
Replying to
@LilithElina@norden.social caldav funktioniert, aber eher rudimentär. Geteilte Projekte sind darüber abrufbar und je nach Einstellung auch abrufbar, nur die Berechtigungen lassen sich über caldav direkt nicht einstellen. Was ist denn euer use-case bzw pain point?
1
2
0
0
Open post
Vikunja (/vɪˈkuːnjə/) @vikunja@social.linux.pizza
· 7mo ago
Replying to
@davidbaakman@mastodon.nl ah yes, sorry! I've corrected it in the advisory.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:58:54 UTC