Hollo There
3-Armed Mutant Santa
3-Armed Mutant Santa
Trying out pl-fe with @hollo and I'm pretty happy with it. It seems to customize per platform and show features specific to each.
I keep forgetting that Hollo supports emoji reacts and markdown .
Hmm Mona doesn’t post from Hollo accounts
For anyone finding this message, I wish you moments of peace and contentment, and a long moment or two filled with things that make you happy, in whatever that may be.
☮️ 😌 ☮️

We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.
This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.
We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.
| Field | Details |
|---|---|
| CVE | CVE-2025-68475 |
| Severity | High (CVSS 7.5) |
| Action | Upgrade to Hollo 0.6.19 |
@[email protected] · Reply to wolf aliceif's post
@aliceif Was the install easy? Or did you move on already? Would really like a web client that has emoji reacts!
Late night cheese snacks 🧀
| Option | Voters |
|---|---|
| Great idea! | 2 (33%) |
| You're gonna regret this later.... | 4 (67%) |

We've released #security updates for #Hollo (0.4.12, 0.5.7, and 0.6.6) to address a #vulnerability in the underlying #Fedify framework. These updates incorporate the latest Fedify security patches that fix CVE-2025-54888.
We strongly recommend all Hollo instance administrators update to the latest version for their respective release branch as soon as possible.
Update Instructions:
docker pull ghcr.io/fedify-dev/hollo:latest and restart your containersgit pull to get the latest code, then pnpm install and restart your service
🚨 Security Update: Hollo 0.6.5 Released
We've released #Hollo 0.6.5 with a critical #security fix for CVE-2025-53941, addressing an HTML injection vulnerability in federated posts.
Please #update immediately to protect your instance from potential phishing and XSS attacks.
How to update:
docker pull ghcr.io/fedify-dev/hollo:latest and restartgit pull origin stable && pnpm install and restart serverI’m phone flashlight constantly turning on in my pocket years old.
Is anyone out there?
| Option | Voters |
|---|---|
| Yes | 1 (100%) |
| No | 0 (0%) |
| I don't want to answer. | 0 (0%) |

What client apps do you use with #Hollo?
| Option | Voters |
|---|---|
| Elk | 1 (50%) |
| Phanpy | 1 (50%) |
| Moshidon | 0 (0%) |
| Subway Tooter | 0 (0%) |
| Mona | 0 (0%) |
| Nightfox DAWN | 0 (0%) |
| Tusker | 0 (0%) |
| Woolly | 0 (0%) |
Was getting super into solving a problem with bulk data imports, only to realize 3 hours later I have to scrap it all because of how the vendor charges for API usage.
Like, hard times all around, man. Solving mysteries doesn’t pay the bills.
Current mood.
@[email protected] · Reply to wolf aliceif's post
@aliceif Yeah I was trying to use a new app that cross posts - there was no crossing of post content - just a post. Here's the photos from my walk today!
Oh! Also had another API added to Mastodon today: currently when you attach media there's no way to immediately get it deleted, this changes that by allowing clients to delete media not yet attached to any status: https://github.com/mastodon/mastodon/pull/33991
This came about because I was looking at the media upload handling in @hollo the other weekend
This is a test. Please reblog to trying to stress this instance and the worms that live within it
It's time to sleep. Yet my brain says no.
You'll regret this at 7 AM
I have great respect for @thisismissem's tremendous work on @hollo.😲
Extended my previous contribution to @hollo tonight with some tests for the `GET /api/v1/accounts/verify_credentials` route:
There's some magic going on here, but I'm pretty happy with the results.
Though, node.js's test runner seems really slow at times and I've no idea why, like some of these are taking 1-4 seconds, whereas other tests are 54ms. I've tried instrumenting the code to find slownesses and I can't, everything's taking only milliseconds.
Have been working on a few things for @hollo today, one of the public things is setting up testing for the codebase: https://github.com/fedify-dev/hollo/pull/114
There's still some work to do, but it's a start.

#Hollo v0.6.0, the next minor release, will have theme colors on your profile pages. Powered by Pico CSS, see the list of all available colors in the Colors section from their docs.
Want to give it a try in advance? Try v0.6.0-dev.397, an unstable release, at your own risk.

Just released #Hollo 0.5.2 (ghcr.io/fedify-dev/hollo:0.5.2) and 0.4.8 (ghcr.io/fedify-dev/hollo:0.4.8), which fix several minor bugs! (Thanks for @ntek's bug reports.)
@[email protected] · Reply to Hollo :hollo:'s post
@hollo Have you considered creating or requesting creation of installation packages for Yunohost, FreedomBox, CoOpCloud platforms? Heck even Synology!
Coming soon™℠®© to @hollo as PR
Hmm.. WAV files aren't supported. What about MP4?