Skip to content

feat(container-image): update binwiederhier/ntfy ( v2.24.0 → v2.26.3 ) - #1370

Open
robottoms-up[bot] wants to merge 1 commit into
masterfrom
renovate/binwiederhier-ntfy-2.x
Open

feat(container-image): update binwiederhier/ntfy ( v2.24.0 → v2.26.3 )#1370
robottoms-up[bot] wants to merge 1 commit into
masterfrom
renovate/binwiederhier-ntfy-2.x

Conversation

@robottoms-up

@robottoms-up robottoms-up Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
binwiederhier/ntfy (source) minor v2.24.0v2.26.3

Release Notes

binwiederhier/ntfy (binwiederhier/ntfy)

v2.26.3

Compare Source

This is a hotfix release, useful pretty much only for ntfy.sh. It was adds the ability to track abusive IPs mor efficiently, reducing the load on the IP banning services and preventing them from falling behind and leaving abusers unbanned for too long. It works by tracking HTTP errors, and writing out a ban file that fail2ban can read and ban offenders instantly. See ban-feed for details.

Features:

  • Add an abuse ban-feed: when enabled via ban-file, ntfy tracks a weighted strike budget per visitor and appends abusive IPs to a file that fail2ban can tail and ban on sight (ban-file, ban-window, ban-threshold, ban-weights; see ban-feed)

v2.26.0

Compare Source

This release hardens message templates, which are now executed with a hard-capped execution timeout. This closes
a denial-of-service hole.

On the web app side, it adds configurable date and time formats, a smoother loading and page-transition experience,
and a fix that strips unsafe URL protocols from rendered Markdown.

Security:

  • Prevent a CPU denial of service via message templates (Template: yes), #​1826, thanks to @​alanturing881 for reporting)

Features:

  • Web app: Add "Date format" and "Time format" settings (Settings -> Appearance), with ISO 8601, day/month/year (slash or dot) and month/day/year date options and a 12-/24-hour clock option, and base the default format on your browser/system locale rather than the selected display language. When logged in, both settings sync across devices via your account (#​1647, thanks to @​wsw70 for reporting)

Bug fixes + maintenance:

  • Web app: Smooth transitions and loading animation, remove flickering
  • Web app: GET /account now reads from the primary database instead of a read replica, so the account view no longer shows stale data right after a change when replicas lag behind
  • Docs: Document the third-party HelmForge Helm chart as a Kubernetes installation option (#​1727, thanks to @​mberlofa)
  • Web app: Strip unsafe URL protocols (javascript:, data:, ...) from links and images in Markdown-rendered messages, so they no longer trigger an uncaught "React has blocked a javascript: URL" error (thanks to @​jvoisin for reporting)

v2.25.0

Compare Source

This release adds password reset via email, and reworks email verification to use durable, link-based magic links (replacing the old in-memory 6-digit codes). Email stays optional at signup; a user can reset their password only once they have a verified "primary" (recovery)email.

All of this work is probably not useful for self-hosters, but it hopefully will be useful for me, since I do have to reset accounts on a regular basis.

Security issues:

  • Generate access tokens, IDs, and magic-link tokens with a cryptographically secure RNG (crypto/rand) instead of a clock-seeded PRNG

Features:

  • Add password reset via emailed magic link, with a "Forgot password" link on the login page and a ntfy user reset-pass CLI command for admins
  • Rework email verification to use durable, single-use, expiring magic links instead of in-memory 6-digit codes, and add a "primary" email (used for account recovery and as the X-Email: yes target) with verified/unverified state in the account UI
  • You can now clear/read messages and delete messages with a GET request (#​1771, thanks to @​lemmi for reporting and to @​wunter8 for implementing)
  • Add a reload button to the web app's action bar when running as an installed PWA, which clears the service worker caches and hard-refreshes the app
  • Add a "Back to app" link to the web app's login, signup, and password-reset pages (alongside the existing links), which previously had no way back to the app

Bug fixes + maintenance:

  • X-Email: yes (also true/1) now sends to your primary verified email regardless of the smtp-sender-verify setting (previously it was rejected unless verification was enabled); it requires being logged in with a verified address
  • Grant users full access to their own sync topic (st_...) so cross-device subscription sync works under auth-default-access: deny-all (#​733, #​1795, thanks to @​lmorchard for the contribution)
  • Support HTTP (non-TLS) S3-compatible endpoints by preserving the endpoint scheme, e.g. for a local MinIO instance (#​1794, #​1734, thanks to @​sskender for the contribution, and @​Kernald for reporting)
  • Stop silently stripping spaces from passwords while typing in the web app's login, signup, and password-reset forms (#​1246, thanks to @​aldem for reporting)
  • Update web app dependencies, including major-version upgrades to Vite (6 -> 8, now Rolldown-based), Material UI (5 -> 9), and Dexie (3 -> 4) (#​1800, #​1764, #​1767, #​1762, #​1766, #​1765, thanks Dependabot)
  • Play notification sounds in the web app even when the Notification API is unavailable, e.g. over plain HTTP or in browsers without notification support (#​1772, thanks to @​mitya12342 for the contribution)
  • Stop escaping <, >, and & as \u003c/\u003e/\u0026 in JSON responses (#​1511, #​1512, thanks to @​wunter8 for the contribution)
  • Fix the web app navbar not reflecting a topic reservation (lock icon, and "Reserve topic" -> "Change reservation"/"Remove reservation" menu) until a page reload, by persisting reservation and display-name changes onto already-subscribed topics during account sync
  • Reduce the web app's initial bundle size by ~300 KB (~50 KB gzipped) by lazy-loading the emoji picker dataset and the Markdown renderer, and by importing Material UI icons individually

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@robottoms-up

robottoms-up Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor Author
Kustomization diff
@@ spec.values.controllers.ntfy.containers.app.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/observability/ntfy
! ± value change
- v2.24.0@sha256:f8a9b104313b87cc24ae4f775f39e6328205b57dff6ede3eaf098a91e5d79f59
+ v2.26.3@sha256:081b53dbb20674fcfe05fdb4eb8af9036a2645ef979543d16f7f80803af467b1

HelmRelease diff
@@ spec.template.spec.containers.app.image @@
# apps/v1/Deployment/observability/ntfy
! ± value change
- binwiederhier/ntfy:v2.24.0@sha256:f8a9b104313b87cc24ae4f775f39e6328205b57dff6ede3eaf098a91e5d79f59
+ binwiederhier/ntfy:v2.26.3@sha256:081b53dbb20674fcfe05fdb4eb8af9036a2645ef979543d16f7f80803af467b1

Diff created by flateWorkflow run

@robottoms-up
robottoms-up Bot force-pushed the renovate/binwiederhier-ntfy-2.x branch from 85ca4b4 to 4b9bc35 Compare July 9, 2026 19:02
@robottoms-up robottoms-up Bot changed the title feat(container-image): update binwiederhier/ntfy ( v2.24.0 → v2.25.0 ) feat(container-image): update binwiederhier/ntfy ( v2.24.0 → v2.26.0 ) Jul 9, 2026
@robottoms-up
robottoms-up Bot force-pushed the renovate/binwiederhier-ntfy-2.x branch from 4b9bc35 to 3522773 Compare July 20, 2026 22:03
@robottoms-up robottoms-up Bot changed the title feat(container-image): update binwiederhier/ntfy ( v2.24.0 → v2.26.0 ) feat(container-image): update binwiederhier/ntfy ( v2.24.0 → v2.26.3 ) Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants