From 3987b9fd624010eeeaeb7cad96606b05aa813f6a Mon Sep 17 00:00:00 2001 From: Claire Date: Tue, 15 Sep 2026 14:05:45 +0200 Subject: [PATCH] Bump version to v4.7.2 --- CHANGELOG.md | 18 +++++++++++++++++- config/initializers/vips.rb | 1 - docker-compose.yml | 6 +++--- lib/mastodon/version.rb | 2 +- 4 files changed, 21 insertions(+), 6 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3817ebd5c0c..3ae4659e7b9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,9 +2,25 @@ All notable changes to this project will be documented in this file. +## [4.7.2] - 2026-09-15 + +### Security + +- Temporarily disable HEIF support + +### Fixes + +- Fix relative privacy policy links in subscription emails (#40486 by @crafkaz) +- Fix canonical email blocks interfering with freezing or approving users (#40463 by @ClearlyClaire) +- Fix 500 error when trying to upload a non-custom-filter JSON import (#40449 and #40451 by @ClearlyClaire) +- Fix 500 error when submitting a status twice (#40439 by @ClearlyClaire) +- Fix self-deleted accounts not being un-deleted when using `tootctl accounts create --reattach` (#40430 by @mjankowski) +- Fix account deletion not deleting generated annual reports (#40394 by @ClearlyClaire) +- Fix notifications not being cleaned up when notification requests are deleted in bulk (#40393 by @ClearlyClaire) + ## [4.7.1] - 2026-09-01 -## Security +### Security - Fix password authentication bypass in 2FA auth for LDAP/PAM/SSO accounts ([GHSA-vx32-x96w-qq65](https://github.com/mastodon/mastodon/security/advisories/GHSA-vx32-x96w-qq65)) - Fix Denial of Service when processing pathological JSON-LD activities ([GHSA-vgm8-frgh-rh2v](https://github.com/mastodon/mastodon/security/advisories/GHSA-vgm8-frgh-rh2v)) diff --git a/config/initializers/vips.rb b/config/initializers/vips.rb index cd8d2410b92..4d68e9023ab 100644 --- a/config/initializers/vips.rb +++ b/config/initializers/vips.rb @@ -17,7 +17,6 @@ Vips.block('VipsForeign', true) VipsForeignLoadJpeg VipsForeignLoadPng VipsForeignLoadWebp - VipsForeignLoadHeif VipsForeignSavePng VipsForeignSaveSpng VipsForeignSaveJpeg diff --git a/docker-compose.yml b/docker-compose.yml index 1e690292603..485a687b33a 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -59,7 +59,7 @@ services: web: # You can uncomment the following line if you want to not use the prebuilt image, for example if you have local code changes # build: . - image: ghcr.io/mastodon/mastodon:v4.7.1 + image: ghcr.io/mastodon/mastodon:v4.7.2 restart: always env_file: .env.production command: bundle exec puma -C config/puma.rb @@ -83,7 +83,7 @@ services: # build: # dockerfile: ./streaming/Dockerfile # context: . - image: ghcr.io/mastodon/mastodon-streaming:v4.7.1 + image: ghcr.io/mastodon/mastodon-streaming:v4.7.2 restart: always env_file: .env.production command: node ./streaming/index.js @@ -102,7 +102,7 @@ services: sidekiq: # You can uncomment the following line if you want to not use the prebuilt image, for example if you have local code changes # build: . - image: ghcr.io/mastodon/mastodon:v4.7.1 + image: ghcr.io/mastodon/mastodon:v4.7.2 restart: always env_file: .env.production command: bundle exec sidekiq diff --git a/lib/mastodon/version.rb b/lib/mastodon/version.rb index 8abdcc8376a..f790da2cdcb 100644 --- a/lib/mastodon/version.rb +++ b/lib/mastodon/version.rb @@ -13,7 +13,7 @@ module Mastodon end def patch - 1 + 2 end def default_prerelease