chore(deps): update docker.io/binwiederhier/ntfy docker tag to v2.27.0 #22
Open
renovate-bot
wants to merge 1 commit from
renovate/docker.io-binwiederhier-ntfy-2.x into main
pull from: renovate/docker.io-binwiederhier-ntfy-2.x
merge into: ops:main
ops:main
ops:renovate/ghcr.io-paperless-ngx-paperless-ngx-3.x
ops:renovate/ghcr.io-remsky-kokoro-fastapi-gpu-0.x
ops:renovate/ghcr.io-perfectra1n-kubesearch-mcp-1.x
ops:renovate/ghcr.io-atuinsh-atuin-18.x
ops:renovate/forgejo-1.x-lockfile
ops:renovate/registry.erwanleboucher.dev-eleboucher-charts-memini-0.x
ops:renovate/ghcr.io-siderolabs-installer-1.13.x
ops:renovate/ghcr.io-scanopy-scanopy-server-0.x
ops:renovate/crowci-0.x-lockfile
ops:renovate/quay.io-jetstack-charts-cert-manager-1.x
ops:renovate/loki-7.x
ops:renovate/gitlab-10.x
ops:renovate/ghcr.io-rommapp-romm-5.x
ops:renovate/quay.io-thanos-thanos-0.x
ops:renovate/plugin-barman-cloud-0.x
ops:renovate/cilium-1.x
ops:renovate/uv_build-0.x
ops:renovate/open-webui-15.x
ops:renovate/ghcr.io-siderolabs-charts-talos-cloud-controller-manager-0.x
ops:renovate/code.forgejo.org-forgejo-helm-forgejo-17.x
ops:renovate/ghcr.io-stacklok-toolhive-toolhive-operator-crds-0.x
ops:renovate/ghcr.io-stacklok-toolhive-toolhive-operator-0.x
ops:renovate/nvidia-gpu-exporter-2.x
ops:renovate/ghcr.io-diced-zipline-4.x
ops:renovate/sentry-33.x
ops:renovate/kube-prometheus-stack-87.x
ops:renovate/ghcr.io-mogenius-helm-charts-renovate-operator-5.x
ops:renovate/ghcr.io-controlplaneio-fluxcd-charts-flux-operator-0.x
ops:renovate/ghcr.io-home-operations-kromgo-0.x
ops:renovate/ghcr.io-home-operations-charts-echo-0.x
ops:renovate/ghcr.io-usememos-memos-0.x
ops:renovate/ghcr.io-helmforgedev-helm-kubernetes-mcp-server-1.x
ops:renovate/codefloe.com-crowci-crow-2.x
ops:renovate/altinity-clickhouse-operator-0.x
ops:renovate/ghcr.io-siderolabs-kubelet-1.x
ops:renovate/ghcr.io-siderolabs-kubelet-1.34.x
ops:renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x
ops:renovate/mail-5.x
ops:renovate/kubernetes.core-6.x
ops:renovate/ghcr.io-goauthentik-server-2026.x
ops:renovate/reloader-2.x
ops:renovate/metrics-server-3.x
ops:renovate/cert-manager-webhook-pdns-3.x
ops:renovate/bluesky-pds-0.x
ops:renovate/ghcr.io-sysadminsmedia-homebox-0.x
ops:renovate/promtail-6.x
ops:renovate/loki-6.x
ops:renovate/cloudnative-pg-0.x
ops:renovate/github.com-imusmanmalik-cert-manager-mixin-1.x
ops:renovate/gitlab-agent-2.x
ops:renovate/ghcr.io-spegel-org-helm-charts-spegel-0.x
ops:renovate/lock-file-maintenance
ops:renovate/bitwarden-secrets-1.x
ops:renovate/gitlab-19.x
ops:renovate/authentik-2026.x
ops:renovate/ruby-4.x
ops:renovate/docker.io-healthchecks-healthchecks-4.x
ops:renovate/plausible-analytics-3.x
ops:renovate/sops-1.x
ops:renovate/random-3.x
ops:renovate/registry.gitlab.com-fmd-foss-fmd-server-0.x
ops:renovate/plausible-analytics-2.x
ops:renovate/quay.io-oauth2-proxy-oauth2-proxy-7.x
ops:renovate/python-3.x
ops:renovate/johly-airtrail-3.x
ops:renovate/ghcr.io-gethomepage-homepage-1.x
ops:renovate/ingress-nginx-4.x
ops:renovate/gitlab-9.x
ops:renovate/ghcr.io-rommapp-romm-4.x
ops:renovate/ghcr.io-gotson-komga-1.x
ops:renovate/gabehf-koito-0.x
ops:renovate/willshersystems.sshd-0.x
ops:renovate/containers.podman-1.x
ops:renovate/ghcr.io-prometheus-community-charts-prometheus-operator-crds-30.x
No reviewers
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
ops/homelab!22
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/docker.io-binwiederhier-ntfy-2.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v2.17.0→v2.27.0Release Notes
binwiederhier/ntfy (docker.io/binwiederhier/ntfy)
v2.27.0Compare Source
This release lets you sign in with your verified email address instead of your username, which should help if you ever signed up with an email and then forgot which username you picked. It also hardens the message templating engine against a few ways a small template could eat a lot of memory, and it drops the "experimental" label from PostgreSQL support, which has been running ntfy.sh for a while now.
I also did a bunch of refactoring in, mostly in preparation for being able to cluster ntfy nodes and scale the service horizontally. It'll be a while until then, ... baby steps.
Security:
Template: yes) to 32 KB, limitprintfwidths and precisions to below 1000, and limitindent/nindentto 100 spaces, preventing excessive memory use from a single small templateFeatures:
Bug fixes + maintenance:
twiliopackagemetricspackageuser_phonetable in the SQLite user database referencing a dropped table after the v2.14 schema migration; repaired automatically by a new migrationv2.26.3Compare Source
This is a hotfix release, useful pretty much only for ntfy.sh. It was adds the ability to track abusive IPs mor efficiently, reducing the load on the IP banning services and preventing them from falling behind and leaving abusers unbanned for too long. It works by tracking HTTP errors, and writing out a ban file that fail2ban can read and ban offenders instantly. See ban-feed for details.
Features:
ban-file, ntfy tracks a weighted strike budget per visitor and appends abusive IPs to a file that fail2ban can tail and ban on sight (ban-file,ban-window,ban-threshold,ban-weights; see ban-feed)v2.26.0Compare Source
This release hardens message templates, which are now executed with a hard-capped execution timeout. This closes
a denial-of-service hole.
On the web app side, it adds configurable date and time formats, a smoother loading and page-transition experience,
and a fix that strips unsafe URL protocols from rendered Markdown.
Security:
Template: yes), #1826, thanks to @alanturing881 for reporting)Features:
Bug fixes + maintenance:
GET /accountnow reads from the primary database instead of a read replica, so the account view no longer shows stale data right after a change when replicas lag behindjavascript:,data:, ...) from links and images in Markdown-rendered messages, so they no longer trigger an uncaught "React has blocked a javascript: URL" error (thanks to @jvoisin for reporting)v2.25.0Compare Source
This release adds password reset via email, and reworks email verification to use durable, link-based magic links (replacing the old in-memory 6-digit codes). Email stays optional at signup; a user can reset their password only once they have a verified "primary" (recovery)email.
All of this work is probably not useful for self-hosters, but it hopefully will be useful for me, since I do have to reset accounts on a regular basis.
Security issues:
crypto/rand) instead of a clock-seeded PRNGFeatures:
ntfy user reset-passCLI command for adminsX-Email: yestarget) with verified/unverified state in the account UIBug fixes + maintenance:
X-Email: yes(alsotrue/1) now sends to your primary verified email regardless of thesmtp-sender-verifysetting (previously it was rejected unless verification was enabled); it requires being logged in with a verified addressst_...) so cross-device subscription sync works underauth-default-access: deny-all(#733, #1795, thanks to @lmorchard for the contribution)<,>, and&as\u003c/\u003e/\u0026in JSON responses (#1511, #1512, thanks to @wunter8 for the contribution)v2.24.0Compare Source
The main feature for this release is an in-memory ACL cache (
auth-access-cache) that can help bring down the read load on the production database. The topic authorization queries are consistently the highest ranking queries on the database, so this will help quite a bit. The current database load is quite low, but I'm expecting it to increase as more users join and use ntfy.Security issues:
secretno longer also matches a request forSECRET. SQLite'sLIKEis case-insensitive for ASCII by default. PostgreSQL was unaffected. It's honestly incredible that this issue remained undetected for so long, especially while ntfy.sh was running on SQLite (it now runs on PostgreSQL).Features:
auth-access-cache) that serves topic authorization without a database round-trip; off by default, intended for high-volume serversntfy --versionflag to the CLI (#1722, #1748, thanks to @sskender for the contribution, and @Saucy9607 for reporting)Bug fixes + maintenance:
relattribute on auto-linked notification URLs sonoreferrer/noopenerare actually applied (#1720, thanks to @dmitrylyzo for the contribution)ntfy.serviceunit (#1467, thanks to @Velocifyer for the contribution)cmdpackage build on macOS (darwin) so the server compiles from source (#1631, #1696, thanks to @ShipItAndPray for the contribution, and @XYenon for reporting)v2.23.0Compare Source
Features:
visitor-topic-creation-limit-burst/visitor-topic-creation-limit-replenish, defaults 100 burst / 1m replenish) to mitigate topic-enumeration / squatting attacks that inflate the in-memory topic mapBug fixes + maintenance:
stacktrace-js,stacktrace-gps,humanize-duration, andjs-base64from the web app to reduce dependency and security footprintv2.22.0Compare Source
Bug fixes + maintenance:
v2.21.0Compare Source
This release adds the ability to verify email addresses using the
smtp-sender-verifyflag. This is a change that is required because ntfy.sh was used to send unsolicited emails and the AWS SES account was suspended. Going forward, ntfy.sh won't be able to send emails unless the email address was verified ahead of time.Features:
smtp-sender-verifyconfig flag, allowing server admins to require emailaddress verification before sending email notifications (#1681)
v2.20.1Compare Source
This is a small bugfix release that only affects high volume S3 backends that struggle with HTTP/2.
Bug fixes + maintenance:
disable_http2=trueS3 URL option to work around HTTP/2 stream errors with DigitalOcean Spaces and other S3-compatible providers (#1678/#1679)v2.20.0Compare Source
This release is another step towards making it possible to help scale ntfy up and out 🔥! With this release, you can store attachments in an S3-compatible object store as an alterative to the directory. See attachment store for details.
Features:
attachment-cache-dirconfig option (#1656/#1672)Bug fixes + maintenance:
v2.19.2Compare Source
This is another small bugfix release for PostgreSQL, avoiding races between primary and read replica, as well as to further reduce primary load.
Bug fixes + maintenance:
v2.19.1Compare Source
This is a bugfix release to avoid PostgreSQL insert failures due to invalid UTF-8 messages. It also fixes
database-urlvalidation incorrectly rejectingpostgresql://connection strings.Bug fixes + maintenance:
database-urlvalidation rejectingpostgresql://connection strings (#1657/#1658)v2.19.0Compare Source
This is a fast-follow release that enables Postgres read replica support.
To offload read-heavy queries from the primary database, you can optionally configure one or more read replicas using the
database-replica-urlsoption. When configured, non-critical read-only queries (e.g. fetching messages, checking access permissions, etc) are distributed across the replicas using round-robin, while all writes and correctness-critical reads continue to go to the primary. If a replica becomes unhealthy, ntfy automatically falls back to the primary until the replica recovers.Features:
database-replica-urlsconfig option (#1648)Bug fixes + maintenance:
v2.18.0Compare Source
This is the biggest release I've ever done on the server. It's 14,997 added lines of code, and 10,202 lines removed, all from one pull request that adds PostgreSQL support.
The code was written by Cursor and Claude, but reviewed and heavily tested over 2-3 weeks by me. I created comparison documents, went through all queries multiple times and reviewed the logic over and over again. I also did load tests and manual regression tests, which took lots of evenings.
ntfy.sh was successfully upgraded to 2.18.0 (though not with Postgres backend yet, as per the rollout plan).
I'm kindly asking the community to test the Postgres support and report back to me if things are working (or not working). There is a one-off migration tool (entirely written by AI) that you can use to migrate.
Features:
database-urlconfig option (#1114/#1619, thanks to @brettinternet for reporting)Bug fixes + maintenance:
<br>line breaks in HTML-only emails received via SMTP (#690, #1620, thanks to @uzkikh for the fix and to @teastrainer for reporting)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
29342b4645to1ec7e0de29Update docker.io/binwiederhier/ntfy Docker tag to v2.25.0to Update docker.io/binwiederhier/ntfy Docker tag to v2.26.0Update docker.io/binwiederhier/ntfy Docker tag to v2.26.0to chore(deps): update docker.io/binwiederhier/ntfy docker tag to v2.26.01ec7e0de29to0e7bf27b63chore(deps): update docker.io/binwiederhier/ntfy docker tag to v2.26.0to chore(deps): update docker.io/binwiederhier/ntfy docker tag to v2.26.3chore(deps): update docker.io/binwiederhier/ntfy docker tag to v2.26.3to Update docker.io/binwiederhier/ntfy Docker tag to v2.26.3Update docker.io/binwiederhier/ntfy Docker tag to v2.26.3to chore(deps): update docker.io/binwiederhier/ntfy docker tag to v2.26.3chore(deps): update docker.io/binwiederhier/ntfy docker tag to v2.26.3to chore(deps): update docker.io/binwiederhier/ntfy docker tag to v2.27.0View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.