Discussion
Loading...

Discussion

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
David - Forking Mad
@daj@gofer.social  ·  activity timestamp 2 months ago
@thisismissem One of the biggest problems, in my humble opinion, is the over promise under deliver. We constantly see toots telling us what is coming, or giving dates, and it doesn't appear. I have lost count of the number of these toots that are then deleted at a later date. I did keep a copy of a toot that was posed by Dan a few weeks ago in which he promised to stop over-promising. It was deleted about an hour later.

Dan the Dev is too thinly spread. He has great talent, but works on far too much. The result is that things suffer. Projects and promises lapse. People get frustrated. Tempers flare. Dan gets pissed off, understandably. Then come the churlish toots

One could argue that we have no right to dictate his workload. However, he's putting out a product (products maybe?) and it comes with responsibility and expectations from the 110k active users. And what about the people who gave up their hard earned cash to fund over $100k to his projects. What was the plan there? I've never seen any firm strategy. Where's the crowdfunding being used?

People want to help him. I have offered several times over the years. I have a list of crap UI issues. I've offered/suggested that he needs to test stuff before launch. If he has a test group, it's not working .... and it can't be your friends! Testing is a thorough and serious aspect of software dev. It's not happening here.

He's hinted at a new team. He has been asked to introduce this team. I'ts never happened that I have seen, and the messages go unacknowledged.

No one really wants to see Pixelfed fail (well there are probably some), but on the whole I think we all want this to work. It's the makings of a great product.

Important issues, like the one raised here in the original toot can't go unfixed and ignored. The point of the fedi is to be open (and supportive), trusting, and honest with user data.

  • Copy link
  • Flag this post
  • Block
Leonardo Ferreira Fontenelle
@lffontenelle@mastodon.social replied  ·  activity timestamp 2 months ago
@thisismissem broken URL?
  • Copy link
  • Flag this comment
  • Block
David - Forking Mad
@daj@gofer.social replied  ·  activity timestamp 2 months ago
@thisismissem One of the biggest problems, in my humble opinion, is the over promise under deliver. We constantly see toots telling us what is coming, or giving dates, and it doesn't appear. I have lost count of the number of these toots that are then deleted at a later date. I did keep a copy of a toot that was posed by Dan a few weeks ago in which he promised to stop over-promising. It was deleted about an hour later.

Dan the Dev is too thinly spread. He has great talent, but works on far too much. The result is that things suffer. Projects and promises lapse. People get frustrated. Tempers flare. Dan gets pissed off, understandably. Then come the churlish toots

One could argue that we have no right to dictate his workload. However, he's putting out a product (products maybe?) and it comes with responsibility and expectations from the 110k active users. And what about the people who gave up their hard earned cash to fund over $100k to his projects. What was the plan there? I've never seen any firm strategy. Where's the crowdfunding being used?

People want to help him. I have offered several times over the years. I have a list of crap UI issues. I've offered/suggested that he needs to test stuff before launch. If he has a test group, it's not working .... and it can't be your friends! Testing is a thorough and serious aspect of software dev. It's not happening here.

He's hinted at a new team. He has been asked to introduce this team. I'ts never happened that I have seen, and the messages go unacknowledged.

No one really wants to see Pixelfed fail (well there are probably some), but on the whole I think we all want this to work. It's the makings of a great product.

Important issues, like the one raised here in the original toot can't go unfixed and ignored. The point of the fedi is to be open (and supportive), trusting, and honest with user data.

  • Copy link
  • Flag this comment
  • Block
just small circles 🕊
@smallcircles@social.coop replied  ·  activity timestamp 2 months ago
@daj @thisismissem

There's a general anti-pattern to many #FOSS projects, which I call the "One Man Army", where over time - as the popularity of a project steadily grows - just coding isn't enough and more and more additional aspects of the Free software development lifecycle, the #FSDL, must be addressed in order for the project to remain sustainable. Pixelfed at the time was my inspiration to coin the anti-pattern:

https://social.coop/@smallcircles/113874718620285261

  • Copy link
  • Flag this comment
  • Block
dansup
@dansup@mastodon.social replied  ·  activity timestamp 2 months ago
@thisismissem @pixelfed The fix was shipped and announced in March.

https://mastodon.social/@pixelfed/114215925957179498

I'm working on collection sync, but that is a Mastodon extension that isn't supported in most software keep in mind.

Maybe you could have reached out privately instead of publicly shaming an open source fediverse project into implementing a Mastodon-only fix.

We do accept PRs, and you could have contributed a fix to help ship sync quicker if you did really care (adonis is based on laravel, php is ez)

  • Copy link
  • Flag this comment
  • Block
julian
@julian@community.nodebb.org replied  ·  activity timestamp 2 months ago

Re: So @pixelfed still hasn't fully acknowledged nor fixed the security vulnerability from earlier this year, despite multiple people asking for updates over the past ~6 months.

@thisismissem@hachyderm.io what was this in reference to, the one where Pixelfed allows anyone on a server access to a followers only post if one person on that server is a follower?
  • Copy link
  • Flag this comment
  • Block
Sean Tilley
@deadsuperhero@social.wedistribute.org replied  ·  activity timestamp 2 months ago
@thisismissem Hey @dansup, you need to fix this, dude.
  • Copy link
  • Flag this comment
  • Block
dansup
@dansup@mastodon.social replied  ·  activity timestamp 2 months ago
@deadsuperhero @thisismissem the fix was shipped months ago, thanks for spreading misinformation!
  • Copy link
  • Flag this comment
  • Block
feld
@feld@friedcheese.us replied  ·  activity timestamp 2 months ago
@dansup@deadsuperhero @thisismissem so are Pixelfed servers not patching or what?

Or is this just another case of Mastodon finding ways to punch down other software in the ecosystem?
  • Copy link
  • Flag this comment
  • Block
peachfiend - they/them 🏳️‍⚧️
@peachfiend@mastodon.sdf.org replied  ·  activity timestamp 2 months ago
@thisismissem there are many #fediverse platforms using #ActivityPub, most of which allow media sharing, and i have never really understood what @pixelfed purports to bring to the party anyway.
  • Copy link
  • Flag this comment
  • Block
Samantha Xavia
@sam@bikersgo.social replied  ·  activity timestamp 2 months ago

@peachfiend@mastodon.sdf.org @thisismissem@hachyderm.io Tbh @pixelfed@pixelfed.social would probably be better put as an app using the Mastodon API instead as it would allow for people to login and post text based posts but still would allow you to have a Instagram look and layout when you want.

  • Copy link
  • Flag this comment
  • Block
Emelia 👸🏻
@thisismissem@hachyderm.io replied  ·  activity timestamp 2 months ago
@gelbphoenix @dansup@deadsuperhero here's what a published one looks like: https://nvd.nist.gov/vuln/detail/CVE-2025-54879

Notice how it links back to the published security vulnerability report on Mastodon? Notice how the vulnerability for Pixelfed doesn't?

Here's the same for the only published advisory for Pixelfed: https://nvd.nist.gov/vuln/detail/CVE-2024-25108

  • Copy link
  • Flag this comment
  • Block
Emelia 👸🏻
@thisismissem@hachyderm.io replied  ·  activity timestamp 2 months ago
@gelbphoenix @dansup@deadsuperhero

This was mostly empty last I looked, and the corresponding security advisory on GitHub's side wasn't published: https://github.com/pixelfed/pixelfed/security

  • Copy link
  • Flag this comment
  • Block
Phoenix Paulina Schmid
@gelbphoenix@social.gelbphoenix.de replied  ·  activity timestamp 2 months ago
@thisismissem @dansup@deadsuperhero A CVE was published: https://nvd.nist.gov/vuln/detail/CVE-2025-30741 (And I found that with a simple search for "pixelfed vulnerability")
  • Copy link
  • Flag this comment
  • Block
Chad - x :mstdn:
@chad@mstdn.ca replied  ·  activity timestamp 2 months ago
@thisismissem @dansup@deadsuperhero why are we pulling our forks and daggers out over this? Are we not together in building the fediverse?

I'm not sure why this needs to be put on blast in public.

You do amazing work. This is pretty aggressive considering the context.

  • Copy link
  • Flag this comment
  • Block
Emelia 👸🏻
@thisismissem@hachyderm.io replied  ·  activity timestamp 2 months ago
@hiphopheaven @pixelfed I'm not saying "don't use Pixelfed", no, in fact I want people to be safe using and federating with Pixelfed.

However, I am calling on Dan & the pixelfed team (?) to do the right thing and fully fix this vulnerability, and do the remediation work necessary, and adopt better security release practices.

Having this in a state of "kinda fixed" for 6 months or so isn't great.

  • Copy link
  • Flag this comment
  • Block
hiphopheaven
@hiphopheaven@mastodon.social replied  ·  activity timestamp 2 months ago
@thisismissem @pixelfed so what's the alternative?
  • Copy link
  • Flag this comment
  • Block
Crissy ⁂ Geco 🇨🇦🧨
@Crissy@tech.lgbt replied  ·  activity timestamp 2 months ago
@thisismissem hello Emelia. just read this all now and wondering if you recommend leaving pixelfed?

thank u for providing detail as to what the issue is about for this designer to understand what the major concerns are.

I don't know how he treats contributors but also haven't posted anything there for weeks so unsure if I shall keep my account alive knowing this now. Thank you in advance!

Would you also have other recommendations of other pixelfed-like solutions or is it simpler to just post pix directly on one's account here on Fedi from the server I am part of? Thanks again!

  • Copy link
  • Flag this comment
  • Block
Emelia 👸🏻
@thisismissem@hachyderm.io replied  ·  activity timestamp 2 months ago
@dansup@deadsuperhero no published vulnerability report for it either:
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this comment
  • Block
Emelia 👸🏻
@thisismissem@hachyderm.io replied  ·  activity timestamp 2 months ago
@dansup@deadsuperhero unless I'm missing something? https://github.com/search?q=repo%3Apixelfed%2Fpixelfed%20Collection-Synchronization&type=code
  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.13 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login