#hollo — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #hollo, aggregated by home.social.
-
-
Bon petit constat :
- Iceshrimp : trop lourd niveau RAM (3,50go et il en faut au moins 4 pour installer/mettre à jour), trop chiant à maintenir (toujours impossible de maj mon instance ...), la réécriture n'est "toujours" pas prête, pas de scrap pour aller chercher les réponses aux posts des autres instances, pareil pour les profils. Le drive c'est cool le gain de place surtout si comme moi on aime les GIF et ça n'existe nul par ailleurs (outre Misskey et donc ses forks). Déménager semble complètement "péter", fonctionne qu'a moitier ... joie
- Hollo : trop lourd aussi en RAM (2,50go et pour le moment il faut au minimum 3go pour mettre à jour la chose), et toujours pas de client web avec support des réactions (coucou phanpy, réactions uniquement en lecture) ... pourtant ça récupère les info des instances distante sur les post et les profils.
- Mitra : ultra léger, paquet debian, bon j'aime pas trop le coté cryptomonaie mais why not vu que tu peux faire payer pour du contenu (pour celles et ceux que ça interesse), mais pas de scrap pour aller chercher les réponses aux posts des autres instances, pareil pour les profils. Client web de base sympa mais très loins de Phanpy mais qui ne supporte toujours pas les réactions (réactions uniquement en lecture), a priori y aurait du déménagement de compte mais forcément faut que l'instance vers laquelle on déménage support donc ... bah wala quoi
Du coup revenir sur à la base sur Misskey ? je ne sais pas comment ça à évoluer (compatibilité avec les reste du fediverse) depuis mais y avait plus trop d'européen•nes dessus après la tétrachier de fork qui a vu le jour.
Non je ne remettrais pas les pied sur Mastodon pour plein de raison. Go To Social hmm bof bof.
#Hollo #Mitra #Iceshrimp #Fediverse -
Bon petit constat :
- Iceshrimp : trop lourd niveau RAM (3,50go et il en faut au moins 4 pour installer/mettre à jour), trop chiant à maintenir (toujours impossible de maj mon instance ...), la réécriture n'est "toujours" pas prête, pas de scrap pour aller chercher les réponses aux posts des autres instances, pareil pour les profils. Le drive c'est cool le gain de place surtout si comme moi on aime les GIF et ça n'existe nul par ailleurs (outre Misskey et donc ses forks). Déménager semble complètement "péter", fonctionne qu'a moitier ... joie
- Hollo : trop lourd aussi en RAM (2,50go et pour le moment il faut au minimum 3go pour mettre à jour la chose), et toujours pas de client web avec support des réactions (coucou phanpy, réactions uniquement en lecture) ... pourtant ça récupère les info des instances distante sur les post et les profils.
- Mitra : ultra léger, paquet debian, bon j'aime pas trop le coté cryptomonaie mais why not vu que tu peux faire payer pour du contenu (pour celles et ceux que ça interesse), mais pas de scrap pour aller chercher les réponses aux posts des autres instances, pareil pour les profils. Client web de base sympa mais très loins de Phanpy mais qui ne supporte toujours pas les réactions (réactions uniquement en lecture), a priori y aurait du déménagement de compte mais forcément faut que l'instance vers laquelle on déménage support donc ... bah wala quoi
Du coup revenir sur à la base sur Misskey ? je ne sais pas comment ça à évoluer (compatibilité avec les reste du fediverse) depuis mais y avait plus trop d'européen•nes dessus après la tétrachier de fork qui a vu le jour.
Non je ne remettrais pas les pied sur Mastodon pour plein de raison. Go To Social hmm bof bof.
#Hollo #Mitra #Iceshrimp #Fediverse -
Been thinking more about the #indieweb flex of hosting a blog and fediverse instance on the same domain. No split domain.
I could just run #Hollo on the domain and place my blog on top of it. When I build and deploy the site, it will also publish new posts to Hollo.
Similar to the #ActivityPub plugin for Wordpress but without Wordpress.
-
Been thinking more about the #indieweb flex of hosting a blog and fediverse instance on the same domain. No split domain.
I could just run #Hollo on the domain and place my blog on top of it. When I build and deploy the site, it will also publish new posts to Hollo.
Similar to the #ActivityPub plugin for Wordpress but without Wordpress.
-
Hollo announces: Hollo 0.9.0 is out. https://hollo.social/@hollo/019e451e-f368-70e2-b993-77d01a14a677 #hollo #fediverse #ActivityPub
-
Hollo announces: Hollo 0.9.0 is out. https://hollo.social/@hollo/019e451e-f368-70e2-b993-77d01a14a677 #hollo #fediverse #ActivityPub
-
My Hollo instance has been updated to 0.9.1 if you wanna take a peek. It's shaking off the early UI look and feel for something more professional.
A lot of extra configurations that I didn't have time to review or enable, but some of it looks interesting, like more efficient handling of remote media.
-
My Hollo instance has been updated to 0.9.1 if you wanna take a peek. It's shaking off the early UI look and feel for something more professional.
A lot of extra configurations that I didn't have time to review or enable, but some of it looks interesting, like more efficient handling of remote media.
-
Hollo 0.9.0 is out. https://github.com/fedify-dev/hollo/discussions/496
The biggest change this release is a complete redesign of every server-rendered page. Pico CSS is replaced by a new design system built on UnoCSS, and your chosen theme color now tints your profile and dashboard pages throughout.
Other highlights:
- Passkey (WebAuthn) authentication: sign in with a biometric or PIN gesture, which counts as MFA so there's no separate TOTP step
- Full FEP-044f quote authorization:
QuoteRequest/Accept/Rejectfederation, quote policy enforcement, and dereferenceableQuoteAuthorizationobjects - A configurable media proxy (
MEDIA_PROXY=proxyorcache) that re-serves remote avatars, attachments, and preview images from Hollo's own origin - Optional split-domain WebFinger via
HANDLE_HOST+WEB_ORIGIN - Public followers/following pages and per-post reaction list pages (likes, boosts, emoji reactions, quotes)
There were also several serious database performance fixes: profile page queries that were taking hundreds of seconds on cold caches, a NodeInfo endpoint doing a full table scan on every request, and a handful of timeline pagination bugs.
-
Hollo 0.9.0 is out. https://github.com/fedify-dev/hollo/discussions/496
The biggest change this release is a complete redesign of every server-rendered page. Pico CSS is replaced by a new design system built on UnoCSS, and your chosen theme color now tints your profile and dashboard pages throughout.
Other highlights:
- Passkey (WebAuthn) authentication: sign in with a biometric or PIN gesture, which counts as MFA so there's no separate TOTP step
- Full FEP-044f quote authorization:
QuoteRequest/Accept/Rejectfederation, quote policy enforcement, and dereferenceableQuoteAuthorizationobjects - A configurable media proxy (
MEDIA_PROXY=proxyorcache) that re-serves remote avatars, attachments, and preview images from Hollo's own origin - Optional split-domain WebFinger via
HANDLE_HOST+WEB_ORIGIN - Public followers/following pages and per-post reaction list pages (likes, boosts, emoji reactions, quotes)
There were also several serious database performance fixes: profile page queries that were taking hundreds of seconds on cold caches, a NodeInfo endpoint doing a full table scan on every request, and a handful of timeline pagination bugs.
-
Bon aller avec la v0.8.0 de #Hollo on peut enfin vider le cache ... 40go a vider, il me reste encore la moitié à faire, j'ai vider l'autre moitié hier soir pour tester la feature et ça vide bien :nko_okay:
-
Fedify & Futures: Building the Fediverse's Backbone - Hong Minhee - Fedify, Hollo, Botkit - E83
-
Fedify & Futures: Building the Fediverse's Backbone - Hong Minhee - Fedify, Hollo, Botkit - E83
-
CW: 关于联邦软件——hollo的消极吐槽(梦话)——很一般、很普通
hollo......如果用过botkit,那差不多就相当于用过hollo了 (
虽然也是和 #gotosocial 一样的“单”用户实例;
但是gotosocial,只是推荐单用户;
而hollo,应该是一个管理员,可以创建多个账户,比如这个@[email protected] ,还可以创建 @[email protected] ;
创建多账户上这一点要比botkit更好?botkit是一域名一机器人的,就像 @mybot 和 @drawbot
Gotosocial还是要比Hollo完善许多,Gotosocial在功能上不比mastodon差多少,hollo就算了
总的来说吧,单用户不推荐自托管fedify-dev/hollo,如果想搭建机器人,可以用fedify-dev/botkit介绍 #Hollo。Hollo 是一款支持 #ActivityPub 的单用户微型博客软件。虽然它只针对单一用户,但它也支持为不同主题创建和运行多个账户。
它是无头的,意味着你可以使用现有的 #Mastodon 客户端应用,配合其兼容 Mastodon 的 API。它与猛犸象在特征上几乎相当。Mastodon 的两个大区别是你可以在帖子内容中使用 #Markdown,并且可以引用其他帖子。
哦,Hollo 是用 #Bun 和 #Fedify 构建的。
https://github.com/dahlia/hollo
#fedidev这里也确实提到了“虽然它只针对单一用户,但它也支持为不同主题创建和运行多个账户”
hollo最近发了一个投票:Hollo 一直都是无头的——没有内置前端,只有一个兼容 Mastodon 的 API。你自己选客户。这正是重点。
但我们一直在想:如果 Hollo 发布自己的网页前端会怎样?Mastodon 兼容的 API 会保留,所以你当前的客户端设置不会改变。这只是多了一个选择。
你会用吗?你要我怎么夸你呢?占用1.4GB内存......还是“创建fediverse账户变得非常简单低成本吗?”
Links:
https://hollo.social/@hollo
https://github.com/fedify-dev/botkit
https://github.com/fedify-dev/hollo
https://fedihollo.org/@adminRE: https://fedihollo.org/@admin/019d3008-b3ec-7869-9a15-71eb70de9ffd
-
Hello Hollo! Voice From fedihollo.org ! :linux: :fediverse:
-
Looks like Hollo's media folder is overflowing and I'm out of disk space.
Unfortunately, it seems impossible to clear the cache at the moment?
So, I'm going to have to shut down the instance until there's a solution.
Edit :
Here's the disk space usage for the assets folder :pikasob: Hollo seriously needs an option to clear the media cache or just a straight-up remote media option.$ du -hs /home/hollo/hollo/assets/ 38G /home/hollo/hollo/assets/
#Hollo -
Hmm : 330 / 330 items processed (132 successful, 198 failed) :pikathinknothappy:
-
Hmm : 330 / 330 items processed (132 successful, 198 failed) :pikathinknothappy:
-
I'm testing the import into Hollo again and it seems to be working
-
I'm testing the import into Hollo again and it seems to be working
-
So Hollo gets stuck after 10 minutes and this is all I have left all I have left in the logs:
mars 04 23:48:19 hollo pnpm[3640]: 22:48:19.853 INF fedify·federation·http: 'OPTIONS' '/api/v1/timelines/home?limit=20': 204 mars 04 23:48:35 hollo pnpm[3640]: 22:48:35.110 INF fedify·federation·http: 'OPTIONS' '/api/v1/timelines/home?limit=20': 204 mars 04 23:48:50 hollo pnpm[3640]: 22:48:50.251 INF fedify·federation·http: 'OPTIONS' '/api/v1/timelines/home?limit=20': 204 mars 04 23:49:05 hollo pnpm[3640]: 22:49:05.584 INF fedify·federation·http: 'OPTIONS' '/api/v1/timelines/home?limit=20': 204 mars 04 23:49:19 hollo pnpm[3640]: 22:49:19.747 INF fedify·federation·http: 'OPTIONS' '/api/v1/timelines/home?limit=20': 204 mars 04 23:49:34 hollo pnpm[3640]: 22:49:34.867 INF fedify·federation·http: 'OPTIONS' '/api/v1/timelines/home?limit=20': 204 mars 04 23:52:40 hollo pnpm[3640]: 22:52:40.282 INF fedify·federation·http: 'OPTIONS' '/api/v1/timelines/home?limit=20': 204
#Hollo -
Hmm, Hollo's frozen again. The server's still running, but it's impossible to reach it.
I should take the time to go check the logs, but I think I saw a message saying it failed because it ran out of RAM :pikaomo:
#Hollo -
A couple days ago, I got a DM from a #Bonfire user. I happily replied and sent a follow request—but the
Acceptnever came back, even though they hadn't enabledmanuallyApprovesFollowers. My DM reply probably never arrived either. Classic interop bug.I checked out the Bonfire source and dug in. Turns out Bonfire hasn't implemented RFC 9421 yet, so it was silently discarding any activity signed with it. That alone would be workable, except for one more issue: Bonfire was responding
200 OKeven when signature verification failed, instead of401 Unauthorized.This matters because Fedify implements a double-knocking mechanism—if a request signed with RFC 9421 fails, it retries with the older draft cavage signature. But since Bonfire returned
200 OKon the failed first knock, #Fedify had no reason to send a second one.I filed two issues on the Bonfire #ActivityPub repo—one requesting RFC 9421 support, and one about returning
401on invalid signatures. For the latter, I also sent a PR, which got merged pretty quickly: bonfire-networks/activity_pub#9.That said, individual Bonfire instances won't pick up the fix until they actually deploy it. So in the meantime, I patched Hollo and Hackers' Pub to use
draft-cavage-http-signatures-12as thefirstKnock, so Bonfire instances can at least understand the first request.One last thing: Fedify caches whether a given server supports RFC 9421, and the Bonfire servers I'd already talked to were cached as “supports RFC 9421”—because they'd been returning
200 OK. I had to manually clear that cache on both hollo.social and hackers.pub before everything finally worked.After all that, the mutual follow went through and my DM reply landed. Worth it.
-
A couple days ago, I got a DM from a #Bonfire user. I happily replied and sent a follow request—but the
Acceptnever came back, even though they hadn't enabledmanuallyApprovesFollowers. My DM reply probably never arrived either. Classic interop bug.I checked out the Bonfire source and dug in. Turns out Bonfire hasn't implemented RFC 9421 yet, so it was silently discarding any activity signed with it. That alone would be workable, except for one more issue: Bonfire was responding
200 OKeven when signature verification failed, instead of401 Unauthorized.This matters because Fedify implements a double-knocking mechanism—if a request signed with RFC 9421 fails, it retries with the older draft cavage signature. But since Bonfire returned
200 OKon the failed first knock, #Fedify had no reason to send a second one.I filed two issues on the Bonfire #ActivityPub repo—one requesting RFC 9421 support, and one about returning
401on invalid signatures. For the latter, I also sent a PR, which got merged pretty quickly: bonfire-networks/activity_pub#9.That said, individual Bonfire instances won't pick up the fix until they actually deploy it. So in the meantime, I patched Hollo and Hackers' Pub to use
draft-cavage-http-signatures-12as thefirstKnock, so Bonfire instances can at least understand the first request.One last thing: Fedify caches whether a given server supports RFC 9421, and the Bonfire servers I'd already talked to were cached as “supports RFC 9421”—because they'd been returning
200 OK. I had to manually clear that cache on both hollo.social and hackers.pub before everything finally worked.After all that, the mutual follow went through and my DM reply landed. Worth it.
-
Hi #fediverse and #ActivityPub developers!
I'm currently working on interoperability testing for #Hollo and #Fedify, and I need a #Bonfire account to test federation with their implementation.
Since there aren't many open public Bonfire instances available, I was wondering if any Bonfire instance admins out there would be willing to grant me a test account? It would be a huge help for improving interop! Let me know if you can help. Thanks!
-
Hi #fediverse and #ActivityPub developers!
I'm currently working on interoperability testing for #Hollo and #Fedify, and I need a #Bonfire account to test federation with their implementation.
Since there aren't many open public Bonfire instances available, I was wondering if any Bonfire instance admins out there would be willing to grant me a test account? It would be a huge help for improving interop! Let me know if you can help. Thanks!
-
Did you know there's a community space for #Fedify, #Hollo, #BotKit, and other Fedify ecosystem projects?
Whether you have questions, want to share what you're building, or just want to hang out with fellow fediverse developers—come join us!
- Matrix: #fedify:matrix.org
- Discord
-
Did you know there's a community space for #Fedify, #Hollo, #BotKit, and other Fedify ecosystem projects?
Whether you have questions, want to share what you're building, or just want to hang out with fellow fediverse developers—come join us!
- Matrix: #fedify:matrix.org
- Discord
-
-
-
セキュリティアップデート: Hollo 0.6.19 リリース
FedifyのHTMLパースコードにおけるセキュリティ脆弱性に対応したHollo 0.6.19をリリースしました。
この脆弱性 (CVE-2025-68475) は ReDoS (正規表現によるサービス拒否) の問題であり、攻撃者がフェデレーション操作中に特別に細工されたHTMLレスポンスを送信することで、サービス停止を引き起こす可能性があります。悪意のあるペイロードは小さい (約170バイト) ですが、Node.jsのイベントループを長時間ブロックする可能性があります。
すべてのHollo運営者の皆様には、直ちにバージョン 0.6.19 へのアップグレードを強くお勧めします。
項目 詳細 CVE CVE-2025-68475 深刻度 高 (CVSS 7.5) 対応 Hollo 0.6.19 にアップグレード -
セキュリティアップデート: Hollo 0.6.19 リリース
FedifyのHTMLパースコードにおけるセキュリティ脆弱性に対応したHollo 0.6.19をリリースしました。
この脆弱性 (CVE-2025-68475) は ReDoS (正規表現によるサービス拒否) の問題であり、攻撃者がフェデレーション操作中に特別に細工されたHTMLレスポンスを送信することで、サービス停止を引き起こす可能性があります。悪意のあるペイロードは小さい (約170バイト) ですが、Node.jsのイベントループを長時間ブロックする可能性があります。
すべてのHollo運営者の皆様には、直ちにバージョン 0.6.19 へのアップグレードを強くお勧めします。
項目 詳細 CVE CVE-2025-68475 深刻度 高 (CVSS 7.5) 対応 Hollo 0.6.19 にアップグレード -
보안 업데이트: Hollo 0.6.19 릴리스
Fedify의 HTML 파싱 코드에서 발견된 보안 취약점을 수정한 Hollo 0.6.19를 릴리스했습니다.
이 취약점(CVE-2025-68475)은 ReDoS(정규 표현식 서비스 거부) 문제로, 공격자가 연합 작업 중 특수하게 조작된 HTML 응답을 보내 서비스 장애를 유발할 수 있습니다. 악성 페이로드는 작지만(약 170바이트), Node.js 이벤트 루프를 장시간 차단할 수 있습니다.
모든 Hollo 운영자분들께 즉시 버전 0.6.19로 업그레이드하실 것을 강력히 권고드립니다.
항목 상세 CVE CVE-2025-68475 심각도 높음 (CVSS 7.5) 조치 Hollo 0.6.19로 업그레이드 -
보안 업데이트: Hollo 0.6.19 릴리스
Fedify의 HTML 파싱 코드에서 발견된 보안 취약점을 수정한 Hollo 0.6.19를 릴리스했습니다.
이 취약점(CVE-2025-68475)은 ReDoS(정규 표현식 서비스 거부) 문제로, 공격자가 연합 작업 중 특수하게 조작된 HTML 응답을 보내 서비스 장애를 유발할 수 있습니다. 악성 페이로드는 작지만(약 170바이트), Node.js 이벤트 루프를 장시간 차단할 수 있습니다.
모든 Hollo 운영자분들께 즉시 버전 0.6.19로 업그레이드하실 것을 강력히 권고드립니다.
항목 상세 CVE CVE-2025-68475 심각도 높음 (CVSS 7.5) 조치 Hollo 0.6.19로 업그레이드 -
Security Update: Hollo 0.6.19 Released
We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.
This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.
We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.
Field Details CVE CVE-2025-68475 Severity High (CVSS 7.5) Action Upgrade to Hollo 0.6.19 -
Security Update: Hollo 0.6.19 Released
We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.
This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.
We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.
Field Details CVE CVE-2025-68475 Severity High (CVSS 7.5) Action Upgrade to Hollo 0.6.19 -
早晩間(조만간) 몇 個月(개월)만의 새 #Hollo 마이너 릴리스(v0.7.0)이 나올 것 같다.
-
早晩間(조만간) 몇 個月(개월)만의 새 #Hollo 마이너 릴리스(v0.7.0)이 나올 것 같다.
-
It looks like a new minor release of #Hollo (v0.7.0) will be out soon, the first in several months.
-
It looks like a new minor release of #Hollo (v0.7.0) will be out soon, the first in several months.
-
#Hollo 0.7 brings a redesigned #notification system with much better performance. We've moved from generating #notifications on-demand to storing them as they happen, which makes the notifications endpoint about 60% faster. We've also added response compression (though if you're using a reverse proxy, you probably had this already).
More notably, Hollo 0.7 implements Mastodon's v2 grouped notifications API. Notifications like favorites, follows, and reblogs targeting the same post or account are now grouped together server-side, reducing clutter. Clients that support the new API (introduced in #Mastodon 4.3) will show cleaner, more organized notifications automatically.
Hollo 0.7 is still in development, but we're excited to share it with you when it's ready!
-
Holloをお使いの方は、できるだけ早く0.6.12バージョンにアップデートしてください。DMが公開投稿ページで露出する深刻なセキュリティ脆弱性が修正されました。
https://hollo.social/@hollo/0199aaaf-7979-7da3-9509-73c9e487de05
-
#Hollo 쓰시는 분들은 可能(가능)한 限(한) 빨리 0.6.12 버전으로 올리시기 바랍니다. DM이 公開(공개) 揭示物(게시물) 페이지에서 露出(노출)되는 深刻(심각)한 保安(보안) 脆弱點(취약점)이 패치되었습니다.
https://hollo.social/@hollo/0199aaaf-7979-7da3-9509-73c9e487de05
-
If you're running #Hollo, please update to version 0.6.12 as soon as possible. A critical #security #vulnerability has been fixed where direct messages were being exposed on public post pages.
https://hollo.social/@hollo/0199aaaf-7979-7da3-9509-73c9e487de05
-
Security update: Hollo 0.6.12 is now available
We've released #Hollo 0.6.12 to fix a critical privacy #vulnerability where direct messages were being exposed in the replies section of public posts. Please update your instances immediately to ensure your private conversations remain private.
-
New compatibility table at funfedi.dev: JSON-LD @context
https://funfedi.dev/support_tables/generated/context/
6 out of 9 implementations accept any
@contextvalue. But Mastodon, Hollo and Friendica reject activity entirely ifhttps://www.w3.org/ns/activitystreamsis not included in@context. Mastodon probably does this for no reason, but what about #Friendica and #Hollo?#ActivityPub specification, section 3. Objects:
Implementers SHOULD include the ActivityPub context in their object definitions. Implementers MAY include additional context as appropriate.
ActivityPub context is recommended, but not required.
-
为了解决底层 Fedify 框架的安全漏洞,我们发布了 Hollo 安全更新。(0.4.12、0.5.7 和 0.6.6)这些更新包含了修复 CVE-2025-54888 的最新 Fedify 安全补丁。
我们强烈建议所有 Hollo 实例管理员尽快更新到相应发布分支的最新版本。
更新方法:
- Railway 用户:进入项目仪表板,选择您的 Hollo 服务,点击部署中的三点菜单,然后选择"Redeploy"
- Docker 用户:使用
docker pull ghcr.io/fedify-dev/hollo:latest拉取最新镜像并重启容器 - 手动安装用户:运行
git pull获取最新代码,然后执行pnpm install并重启服务