The latest iPhone, Apple Watch, and AirPods lineups arrive in stores worldwide


Thank you for your donations:
One-time
Monthly
This release fixes six vulnerabilities reported by Jan Kahmen (turingpoint). Please update.
cid: references were rewritten to blob: URLs that kept the sender's Content-Type, and the reverse proxy skipped every security header β CSP included β on app paths whose last segment contains a dot, although the signed-in mail, calendar, contacts and files routes render there. Blob URLs are now retyped as inert, link clicks from the message frame are gated by scheme, and the proxy only skips headers for an explicit static-asset allowlist (GHSA-xvjh-v9c6-qcvc, thanks @kah-ja)POST /api/auth/session and POST /api/auth/stalwart-context minted identity cookies without checking the supplied credentials against the JMAP server, so anyone could obtain a cookie for an arbitrary username and read that user's server-side settings. Credentials are now verified upstream before a cookie is issued: Basic credentials are bound to the account they authenticate, Bearer tokens to the session's username and identity. Deployments whose webmail container cannot reach the JMAP server no longer receive identity cookies, so cross-device settings sync stops working there (GHSA-wxcm-j4jc-9fxq, thanks @kah-ja)/plugin-sandbox runtime trusted whichever window posted the first message, so a foreign site could window.open() it, post its own init, and run code under the route's unsafe-eval CSP in the app origin β with or without plugins enabled. The sandbox now only accepts its framing window, and the proxy refuses to serve the route outside an iframe or when plugins are disabled (GHSA-96cx-gx36-3g79, thanks @kah-ja)jmap_stalwart_ctx session cookie (GHSA-cqqx-mjcf-mh55, thanks @kah-ja)/api/auth/*. A malicious page could POST the victim's browser into an attacker-controlled account (session fixation) (GHSA-qvr9-m8cq-7wvg, thanks @kah-ja)Principal/getAvailabilityCalendarEventNotification, and invitations are organized as the default ParticipantIdentitymail:share; share notifications appear as toastsSearchSnippet/getEmail/changes and Mailbox/changes deltas instead of refetching the listprompt=select_account is sent to the identity provider when adding another account (#979, thanks @Almost-Senseless-Coder)ui.openDialog and a plugin-dialog slot for large, clickable custom UI (#975, thanks @bartfaizoli76)attachment-actions and composer-attachment-source slots (#974, thanks @bartfaizoli76)fileinto "INBOX" (#1027).eml file names collided (#1039)cid: parts declared as application/octet-stream from the attachment list (#1005, thanks @dealerweb).eml preview views (#663, thanks @shukiv)Email/set failures on delete and move (#956)x shortcut to thread expansion (#683)progressUpdated from the task completion payload (#958, thanks @sanitz)name.full on all write paths so vCards carry the mandatory FN (#430)JMAP_SERVER_URL refreshes (#971, thanks @thejdubb02)max_age=0 from OIDC re-authentication requests (#938)<select> option lists in dark themes (#999)basePath when normalizing a Chinese Accept-Language
release: v2.0.7
New uNmINeD development snapshot is available for download!
Changes:
Sunlight shadows in isometric mode:

Donations are appreciated. There is now a PayPal option.
Updates:
Changes/additions:
Fixes:
Full list of all changes since start of this project.
Subtitle downloads from OpenSubtitles may fail depending on time of day. This is due to our daily download quota being exceeded. Current amount of donations is barely enough to pay for the existing quota. So it is unlikely that quota can be increased and situation will get worse over time.
If you create an OpenSubtitles account and configure it in MPC-HC settings then you may be able to bypass the quota.
Options > Subtitles > Misc > Right-click on OpenSubtitles.com > Setup > Fill in username/password
A lot of people seem to be unaware of some of the awesome features that have been added to MPC-HC in the past years. Here is a list of useful options and features that everyone should know about:
1 (restore normal view with 3).
![]()
![]()
Script to find new contributors from bug list
![]()
![]()
![]()
![]()
![]()
We are excited that the 1.61 update for Euro Truck Simulator 2 is now officially released and available on Steam! We hope you will enjoy all the new features, which you can read about in more detail below.
Vehicles
Visual
The Asterisk Development Team would like to announce
release candidate 1 of asterisk-24.0.0.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/24.0.0-rc1
and
https://downloads.asterisk.org/pub/telephony/asterisk
Repository: https://github.com/asterisk/asterisk
Tag: 24.0.0-rc1
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
The Asterisk Development Team would like to announce
release candidate 1 of asterisk-22.12.0.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/22.12.0-rc1
and
https://downloads.asterisk.org/pub/telephony/asterisk
Repository: https://github.com/asterisk/asterisk
Tag: 22.12.0-rc1
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
The Asterisk Development Team would like to announce
release candidate 1 of asterisk-23.6.0.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/23.6.0-rc1
and
https://downloads.asterisk.org/pub/telephony/asterisk
Repository: https://github.com/asterisk/asterisk
Tag: 23.6.0-rc1
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
The Asterisk Development Team would like to announce
release candidate 1 of asterisk-20.22.0.
The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/20.22.0-rc1
and
https://downloads.asterisk.org/pub/telephony/asterisk
Repository: https://github.com/asterisk/asterisk
Tag: 20.22.0-rc1
This release resolves issues reported by the community
and would have not been possible without your participation.
Thank You!
release: v2.0.6
This PR bumps the version of the HTML extension to v0.3.2.
Release Notes:
Co-authored-by: zed-zippy[bot] <234243425+zed-zippy[bot]@users.noreply.github.com>
Co-authored-by: Finn Evers finn@zed.dev
This PR bumps the version of the GLSL extension to v0.2.5.
Release Notes:
Co-authored-by: zed-zippy[bot] <234243425+zed-zippy[bot]@users.noreply.github.com>
Co-authored-by: Finn Evers finn@zed.dev
This PR bumps the version of the Proto extension to v0.3.4.
Release Notes:
Co-authored-by: zed-zippy[bot] <234243425+zed-zippy[bot]@users.noreply.github.com>
Co-authored-by: Finn Evers finn@zed.dev
Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:
xattr -cr /Applications/marktext.app
All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:
sha256sum -c SHA256SUMS.txt --ignore-missing
Full Changelog: v0.20.0-rc.3...v0.20.0-rc.4
The Stable channel has been updated to 154.0.8037.44/.45 for Windows. as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.
You can find more details about early Stable releases here.
Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Srinivas Sista
Google Chrome
Migrations finished. New migration version schema: 1125 in PeerTube startup logs):
cd /var/www/peertube/peertube-latest && sudo -u peertube NODE_CONFIG_DIR=/var/www/peertube/config NODE_ENV=production node dist/scripts/migrations/peertube-8.3.jscd /var/www/peertube-docker && docker compose exec -u peertube peertube node dist/scripts/migrations/peertube-8.3.jsGET /api/v1/videos/{id}/comment-threads/{threadId} no longer returns the full comment tree
totalChildren field: compare it against children.length to know if replies were cut offGET /api/v1/videos/{id}/comments/{commentId}/repliesfilter:api.video-thread-comments.list.result now sees only the truncated tree. Two new hooks, filter:api.video-comment-replies.list.params / .result, cover the new replies endpointcd /var/www/peertube/peertube-latest && sudo -H -u peertube curl -fsSL -o dist/scripts/upgrade.sh https://raw.githubusercontent.com/Chocobozzz/PeerTube/13c16ec0e80a16f3d98b6d0e2c2942c1c22513dc/server/scripts/upgrade.sh and then run the upgrade script as usualnosniff X-Content-Type-Options HTTP response headerContent-Disposition header to prevent XSS injectionsconfig/config-schema.jsonThis section is not exhaustive
redis.socket to provide the redis socket pathuser.allow_cross_provider_auth configuration to support multiple auth plugins for the same PeerTube user #7655log.tag_requestsfilter:api.video-comment-replies.list.params and filter:api.video-comment-replies.list.result for the new /api/v1/videos/{id}/comments/{commentId}/replies comment endpointfilter:api.video-watch.video-comment-replies.list.params and filter:api.video-watch.video-comment-replies.list.result when loading more replies of a commentpeertubeHelpers.email.createJob({ ... }) to send an emailpeertubeHelpers.videos.updateVideo({ ... }) to update video metadatapeertubeHelpers.videos.withFile({ ... }) to fetch a video fileregisterCommentAutoTagger: (options: RegisterCommentAutoTaggerOptions) => voidregisterVideoAutoTagger: (options: RegisterVideoAutoTaggerOptions) => voidunregisterCommentAutoTagger: (options: RegisterCommentAutoTaggerOptions) => voidunregisterVideoAutoTagger: (options: RegisterVideoAutoTaggerOptions) => voidexternalId when returning the user from an auth plugin, so it no longer needs to rely on the user's email to map the auth provider user to a PeerTube userlanguage when returning the user from an auth pluginreq.cookies in the onLogout hook of the registerExternalAuth plugin helperblocklist.public_log.enabled configuration) so other admins can subscribe to itlastmod field in sitemap entries #7738host-meta well-known endpoint for remote subscriptions... suffix to actions that lead to another step502 HTTP statusoriginallyPublishedAt for videos
Migrations finished. New migration version schema: 1125 in PeerTube startup logs):
cd /var/www/peertube/peertube-latest && sudo -u peertube NODE_CONFIG_DIR=/var/www/peertube/config NODE_ENV=production node dist/scripts/migrations/peertube-8.3.jscd /var/www/peertube-docker && docker compose exec -u peertube peertube node dist/scripts/migrations/peertube-8.3.jsGET /api/v1/videos/{id}/comment-threads/{threadId} no longer returns the full comment tree
totalChildren field: compare it against children.length to know if replies were cut offGET /api/v1/videos/{id}/comments/{commentId}/repliesfilter:api.video-thread-comments.list.result now sees only the truncated tree. Two new hooks, filter:api.video-comment-replies.list.params / .result, cover the new replies endpointnosniff X-Content-Type-Options HTTP response headerContent-Disposition header to prevent XSS injectionsconfig/config-schema.jsonThis section is not exhaustive
redis.socket to provide the redis socket pathuser.allow_cross_provider_auth configuration to support multiple auth plugins for the same PeerTube user #7655log.tag_requestsfilter:api.video-comment-replies.list.params and filter:api.video-comment-replies.list.result for the new /api/v1/videos/{id}/comments/{commentId}/replies comment endpointfilter:api.video-watch.video-comment-replies.list.params and filter:api.video-watch.video-comment-replies.list.result when loading more replies of a commentpeertubeHelpers.email.createJob({ ... }) to send an emailpeertubeHelpers.videos.updateVideo({ ... }) to update video metadatapeertubeHelpers.videos.withFile({ ... }) to fetch a video fileregisterCommentAutoTagger: (options: RegisterCommentAutoTaggerOptions) => voidregisterVideoAutoTagger: (options: RegisterVideoAutoTaggerOptions) => voidunregisterCommentAutoTagger: (options: RegisterCommentAutoTaggerOptions) => voidunregisterVideoAutoTagger: (options: RegisterVideoAutoTaggerOptions) => voidexternalId when returning the user from an auth plugin, so it no longer needs to rely on the user's email to map the auth provider user to a PeerTube userlanguage when returning the user from an auth pluginreq.cookies in the onLogout hook of the registerExternalAuth plugin helperblocklist.public_log.enabled configuration) so other admins can subscribe to itlastmod field in sitemap entries #7738host-meta well-known endpoint for remote subscriptions... suffix to actions that lead to another step502 HTTP statusoriginallyPublishedAt for videos