|
@@ -3,7 +3,7 @@ Changelog
|
|
|
|
|
|
All notable changes to this project will be documented in this file.
|
|
|
|
|
|
-## [Unreleased]
|
|
|
+## [4.0.0] - 2022-11-14
|
|
|
|
|
|
Some of the features in this release have been funded through the [NGI0 Discovery](https://nlnet.nl/discovery) Fund, a fund established by [NLnet](https://nlnet.nl/) with financial support from the European Commission's [Next Generation Internet](https://ngi.eu/) programme, under the aegis of DG Communications Networks, Content and Technology under grant agreement No 825322.
|
|
|
|
|
@@ -196,6 +196,10 @@ Some of the features in this release have been funded through the [NGI0 Discover
|
|
|
### Security
|
|
|
|
|
|
- Fix being able to spoof link verification ([Gargron](https://github.com/mastodon/mastodon/pull/20217))
|
|
|
+- Fix emoji substitution not applying only to text nodes in backend code ([ClearlyClaire](https://github.com/mastodon/mastodon/pull/20641))
|
|
|
+- Fix emoji substitution not applying only to text nodes in web UI ([ClearlyClaire](https://github.com/mastodon/mastodon/pull/20640))
|
|
|
+- Fix rate limiting for paths with formats ([Gargron](https://github.com/mastodon/mastodon/pull/20675))
|
|
|
+- Fix out-of-bound reads in blurhash transcoder ([delroth](https://github.com/mastodon/mastodon/pull/20388))
|
|
|
|
|
|
## [3.5.3] - 2022-05-26
|
|
|
### Added
|