tag:github.com,2008:https://github.com/binwiederhier/ntfy/releases Release notes from ntfy 2026-08-27T20:16:48Z tag:github.com,2008:Repository/420503947/v2.28.0 2026-08-27T20:38:30Z v2.28.0 <p>This is a hardening release. A single topic on ntfy.sh was polled continuously with <code>poll=1</code> and no <code>since</code> cursor, which replays a topic's entire cache on every request. The changes below bound what one replay can cost, close two fields that had no size limit at all, and fix an ordering bug found while digging into it.</p> <p><strong>Bug fixes + maintenance:</strong></p> <ul> <li>Fix messages being returned out of publish order when polling or replaying <strong>several topics at once</strong> (<code>/topic1,topic2/json?poll=1</code>, <a href="https://github.com/binwiederhier/ntfy/issues/1297" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1297/hovercard">#1297</a>)</li> <li>Limit the message title to 1 KB and all tags combined to 512 bytes, rejecting larger requests with HTTP 400 (error codes <code>40057</code> and <code>40058</code>). Neither field had a size limit before, unlike the message body; on ntfy.sh the 99.9th percentile is 212 bytes for titles and 244 for tags</li> <li>Cap a single cache replay at 10 MB of messages per topic. A poll without a <code>since</code> cursor returns a topic's entire cache, which was previously unbounded and could reach tens of megabytes on a busy topic, so one request could allocate that much on the server. The newest messages that fit are kept and a truncated response carries an <code>X-Messages-Truncated: 1</code> header</li> <li><code>visitor-attachment-daily-bandwidth-limit</code> now also covers messages replayed from the message cache by poll requests, not just attachment traffic. A poll without a <code>since</code> cursor returns a topic's entire cache, so a topic that is cheap to fill can be re-read for many times its own size; polls beyond the budget are rejected with HTTP 429 (error code 42905) before anything is written. <strong>Note that heavy pollers now consume the same budget as attachment downloads</strong>, so operators serving both may want to raise the limit</li> </ul> github-actions[bot] tag:github.com,2008:Repository/420503947/v2.27.0 2026-08-04T05:42:48Z v2.27.0 <p>This release lets you sign in with your verified email address instead of your username, which should help if you ever signed up with an email and then forgot which username you picked. It also hardens the message templating engine against a few ways a small template could eat a lot of memory, and it drops the "experimental" label from PostgreSQL support, which has been running ntfy.sh for a while now.</p> <p>I also did a bunch of refactoring in, mostly in preparation for being able to cluster ntfy nodes and scale the service horizontally. It'll be a while until then, ... baby steps.</p> <p><strong>Security:</strong></p> <ul> <li>Limit message templates (<code>Template: yes</code>) to 32 KB, limit <code>printf</code> widths and precisions to below 1000, and limit <code>indent</code>/<code>nindent</code> to 100 spaces, preventing excessive memory use from a single small template</li> <li>Exclude secrets from the config hash served to the web app, preventing a rather theoretical information leak</li> </ul> <p><strong>Features:</strong></p> <ul> <li>Allow logging in with your verified primary email address (in addition to your username), so a password reset no longer leaves you unable to sign in when you only remember the email you signed up with</li> </ul> <p><strong>Bug fixes + maintenance:</strong></p> <ul> <li>Fix Twilio phone calls and phone number verifications failing silently when Twilio rejected the request, and move the Twilio integration into its own <code>twilio</code> package</li> <li>Move the Prometheus metrics into a dedicated <code>metrics</code> package</li> <li>Message cache databases from ntfy older than v1.10.0 (November 2021) can no longer be migrated; upgrade via an older ntfy version first, or delete the cache database</li> <li>Fix <code>user_phone</code> table in the SQLite user database referencing a dropped table after the v2.14 schema migration; repaired automatically by a new migration</li> </ul> github-actions[bot] tag:github.com,2008:Repository/420503947/v2.26.3 2026-07-20T21:39:40Z v2.26.3 <p>This is a hotfix release, useful pretty much only for ntfy.sh. It was adds the ability to track abusive IPs mor efficiently, reducing the load on the IP banning services and preventing them from falling behind and leaving abusers unbanned for too long. It works by tracking HTTP errors, and writing out a ban file that fail2ban can read and ban offenders instantly. See <a href="https://docs.ntfy.sh/config/#ban-feed" rel="nofollow">ban-feed</a> for details.</p> <p><strong>Features:</strong></p> <ul> <li>Add an abuse ban-feed: when enabled via <code>ban-file</code>, ntfy tracks a weighted strike budget per visitor and appends abusive IPs to a file that fail2ban can tail and ban on sight (<code>ban-file</code>, <code>ban-window</code>, <code>ban-threshold</code>, <code>ban-weights</code>; see <a href="https://docs.ntfy.sh/config/#ban-feed" rel="nofollow">ban-feed</a>)</li> </ul> github-actions[bot] tag:github.com,2008:Repository/420503947/v2.26.2 2026-07-20T19:34:47Z v2.26.2 <p>Redo the banning logic, ban.Service</p> binwiederhier tag:github.com,2008:Repository/420503947/v2.26.1 2026-07-18T06:41:25Z v2.26.1 <p>Hotfix: Add ban-file/ban-threshold/ban-weights as a more lightweight …</p> binwiederhier tag:github.com,2008:Repository/420503947/v2.26.0 2026-07-09T19:18:45Z v2.26.0 <p>This release hardens <strong>message templates</strong>, which are now executed with a hard-capped execution timeout. This closes<br> a denial-of-service hole.</p> <p>On the web app side, it adds configurable <strong>date and time formats</strong>, a smoother loading and page-transition experience,<br> and a fix that strips unsafe URL protocols from rendered Markdown.</p> <p><strong>Security:</strong></p> <ul> <li>Prevent a CPU denial of service via message templates (<code>Template: yes</code>), <a href="https://github.com/binwiederhier/ntfy/pull/1826" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1826/hovercard">#1826</a>, thanks to @alanturing881 for reporting)</li> </ul> <p><strong>Features:</strong></p> <ul> <li>Web app: Add "Date format" and "Time format" settings (Settings -&gt; Appearance), with ISO 8601, day/month/year (slash or dot) and month/day/year date options and a 12-/24-hour clock option, and base the default format on your browser/system locale rather than the selected display language. When logged in, both settings sync across devices via your account (<a href="https://github.com/binwiederhier/ntfy/issues/1647" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1647/hovercard">#1647</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wsw70/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wsw70">@wsw70</a> for reporting)</li> </ul> <p><strong>Bug fixes + maintenance:</strong></p> <ul> <li>Web app: Smooth transitions and loading animation, remove flickering</li> <li>Web app: <code>GET /account</code> now reads from the primary database instead of a read replica, so the account view no longer shows stale data right after a change when replicas lag behind</li> <li>Docs: Document the third-party HelmForge Helm chart as a Kubernetes installation option (<a href="https://github.com/binwiederhier/ntfy/issues/1727" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1727/hovercard">#1727</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mberlofa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mberlofa">@mberlofa</a>)</li> <li>Web app: Strip unsafe URL protocols (<code>javascript:</code>, <code>data:</code>, ...) from links and images in Markdown-rendered messages, so they no longer trigger an uncaught "React has blocked a javascript: URL" error (thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jvoisin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jvoisin">@jvoisin</a> for reporting)</li> </ul> github-actions[bot] tag:github.com,2008:Repository/420503947/v2.25.0 2026-06-24T23:31:54Z v2.25.0 <p>This release adds <strong>password reset</strong> via email, and reworks email verification to use durable, link-based magic links (replacing the old in-memory 6-digit codes). Email stays optional at signup; a user can reset their password only once they have a verified "primary" (recovery)email.</p> <p>All of this work is probably not useful for self-hosters, but it hopefully will be useful for me, since I do have to reset accounts on a regular basis.</p> <p><strong>Security issues:</strong></p> <ul> <li>Generate access tokens, IDs, and magic-link tokens with a cryptographically secure RNG (<code>crypto/rand</code>) instead of a clock-seeded PRNG</li> </ul> <p><strong>Features:</strong></p> <ul> <li>Add password reset via emailed magic link, with a "Forgot password" link on the login page and a <code>ntfy user reset-pass</code> CLI command for admins</li> <li>Rework email verification to use durable, single-use, expiring magic links instead of in-memory 6-digit codes, and add a "primary" email (used for account recovery and as the <code>X-Email: yes</code> target) with verified/unverified state in the account UI</li> <li>You can now clear/read messages and delete messages with a GET request (<a href="https://github.com/binwiederhier/ntfy/issues/1771" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1771/hovercard">#1771</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lemmi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lemmi">@lemmi</a> for reporting and to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wunter8/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wunter8">@wunter8</a> for implementing)</li> <li>Add a reload button to the web app's action bar when running as an installed PWA, which clears the service worker caches and hard-refreshes the app</li> <li>Add a "Back to app" link to the web app's login, signup, and password-reset pages (alongside the existing links), which previously had no way back to the app</li> </ul> <p><strong>Bug fixes + maintenance:</strong></p> <ul> <li><code>X-Email: yes</code> (also <code>true</code>/<code>1</code>) now sends to your primary verified email regardless of the <code>smtp-sender-verify</code> setting (previously it was rejected unless verification was enabled); it requires being logged in with a verified address</li> <li>Grant users full access to their own sync topic (<code>st_...</code>) so cross-device subscription sync works under <code>auth-default-access: deny-all</code> (<a href="https://github.com/binwiederhier/ntfy/issues/733" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/733/hovercard">#733</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1795" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1795/hovercard">#1795</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lmorchard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lmorchard">@lmorchard</a> for the contribution)</li> <li>Support HTTP (non-TLS) S3-compatible endpoints by preserving the endpoint scheme, e.g. for a local MinIO instance (<a href="https://github.com/binwiederhier/ntfy/pull/1794" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1794/hovercard">#1794</a>, <a href="https://github.com/binwiederhier/ntfy/issues/1734" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1734/hovercard">#1734</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sskender/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sskender">@sskender</a> for the contribution, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kernald/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kernald">@Kernald</a> for reporting)</li> <li>Stop silently stripping spaces from passwords while typing in the web app's login, signup, and password-reset forms (<a href="https://github.com/binwiederhier/ntfy/issues/1246" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1246/hovercard">#1246</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aldem/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aldem">@aldem</a> for reporting)</li> <li>Update web app dependencies, including major-version upgrades to Vite (6 -&gt; 8, now Rolldown-based), Material UI (5 -&gt; 9), and Dexie (3 -&gt; 4) (<a href="https://github.com/binwiederhier/ntfy/pull/1800" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1800/hovercard">#1800</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1764" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1764/hovercard">#1764</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1767" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1767/hovercard">#1767</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1762" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1762/hovercard">#1762</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1766" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1766/hovercard">#1766</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1765" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1765/hovercard">#1765</a>, thanks Dependabot)</li> <li>Play notification sounds in the web app even when the Notification API is unavailable, e.g. over plain HTTP or in browsers without notification support (<a href="https://github.com/binwiederhier/ntfy/pull/1772" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1772/hovercard">#1772</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mitya12342/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mitya12342">@mitya12342</a> for the contribution)</li> <li>Stop escaping <code>&lt;</code>, <code>&gt;</code>, and <code>&amp;</code> as <code>\u003c</code>/<code>\u003e</code>/<code>\u0026</code> in JSON responses (<a href="https://github.com/binwiederhier/ntfy/issues/1511" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1511/hovercard">#1511</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1512" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1512/hovercard">#1512</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wunter8/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wunter8">@wunter8</a> for the contribution)</li> <li>Fix the web app navbar not reflecting a topic reservation (lock icon, and "Reserve topic" -&gt; "Change reservation"/"Remove reservation" menu) until a page reload, by persisting reservation and display-name changes onto already-subscribed topics during account sync</li> <li>Reduce the web app's initial bundle size by ~300 KB (~50 KB gzipped) by lazy-loading the emoji picker dataset and the Markdown renderer, and by importing Material UI icons individually</li> </ul> github-actions[bot] tag:github.com,2008:Repository/420503947/v2.24.0 2026-06-05T00:40:31Z v2.24.0 <p>The main feature for this release is an in-memory ACL cache (<code>auth-access-cache</code>) that can help bring down the read load on the production database. The topic authorization queries are consistently the highest ranking queries on the database, so this will help quite a bit. The current database load is quite low, but I'm expecting it to increase as more users join and use ntfy.</p> <p><strong>Security issues:</strong></p> <ul> <li>Fix case-insensitive ACL topic matching on SQLite: an access control rule for <code>secret</code> no longer also matches a request for <code>SECRET</code>. SQLite's <code>LIKE</code> is case-insensitive for ASCII by default. PostgreSQL was unaffected. It's honestly incredible that this issue remained undetected for so long, especially while ntfy.sh was running on SQLite (it now runs on PostgreSQL).</li> </ul> <p><strong>Features:</strong></p> <ul> <li>Add opt-in in-memory ACL cache (<code>auth-access-cache</code>) that serves topic authorization without a database round-trip; off by default, intended for high-volume servers</li> <li>Add <code>ntfy --version</code> flag to the CLI (<a href="https://github.com/binwiederhier/ntfy/issues/1722" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1722/hovercard">#1722</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1748" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1748/hovercard">#1748</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sskender/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sskender">@sskender</a> for the contribution, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saucy9607/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saucy9607">@Saucy9607</a> for reporting)</li> </ul> <p><strong>Bug fixes + maintenance:</strong></p> <ul> <li>Extend account token automatically from the PWA service worker, so installed PWAs don't get logged out (<a href="https://github.com/binwiederhier/ntfy/pull/1669" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1669/hovercard">#1669</a>, <a href="https://github.com/binwiederhier/ntfy/issues/1203" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1203/hovercard">#1203</a>, <a href="https://github.com/binwiederhier/ntfy/issues/1533" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1533/hovercard">#1533</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nihalgonsalves/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nihalgonsalves">@nihalgonsalves</a> for the contribution)</li> <li>Fix <code>rel</code> attribute on auto-linked notification URLs so <code>noreferrer</code>/<code>noopener</code> are actually applied (<a href="https://github.com/binwiederhier/ntfy/pull/1720" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1720/hovercard">#1720</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmitrylyzo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmitrylyzo">@dmitrylyzo</a> for the contribution)</li> <li>Add systemd sandboxing/hardening to the <code>ntfy.service</code> unit (<a href="https://github.com/binwiederhier/ntfy/pull/1467" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1467/hovercard">#1467</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Velocifyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Velocifyer">@Velocifyer</a> for the contribution)</li> <li>Fix <code>cmd</code> package build on macOS (darwin) so the server compiles from source (<a href="https://github.com/binwiederhier/ntfy/issues/1631" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1631/hovercard">#1631</a>, <a href="https://github.com/binwiederhier/ntfy/pull/1696" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1696/hovercard">#1696</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ShipItAndPray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ShipItAndPray">@ShipItAndPray</a> for the contribution, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XYenon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XYenon">@XYenon</a> for reporting)</li> </ul> github-actions[bot] tag:github.com,2008:Repository/420503947/v2.23.0 2026-05-18T01:28:55Z v2.23.0 <p><strong>Features:</strong></p> <ul> <li>Add per-visitor rate limit on new topic creations (<code>visitor-topic-creation-limit-burst</code> / <code>visitor-topic-creation-limit-replenish</code>, defaults 100 burst / 1m replenish) to mitigate topic-enumeration / squatting attacks that inflate the in-memory topic map</li> </ul> <p><strong>Bug fixes + maintenance:</strong></p> <ul> <li>Remove <code>stacktrace-js</code>, <code>stacktrace-gps</code>, <code>humanize-duration</code>, and <code>js-base64</code> from the web app to reduce dependency and security footprint</li> <li>Restrict the publish dialog's local file preview to safe image types (png/jpg/gif/webp) to prevent same-origin script execution from blob URLs when previewing a crafted SVG (<a href="https://github.com/binwiederhier/ntfy/security/advisories/GHSA-j8hr-p342-xrmh">GHSA-j8hr-p342-xrmh</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Venukamatchi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Venukamatchi">@Venukamatchi</a> for reporting)</li> </ul> github-actions[bot] tag:github.com,2008:Repository/420503947/v2.22.0 2026-04-21T15:17:51Z v2.22.0 <p><strong>Bug fixes + maintenance:</strong></p> <ul> <li>Tighten web push endpoint allow-list regex to prevent SSRF via unanchored pattern matching (<a href="https://github.com/binwiederhier/ntfy/security/advisories/GHSA-w9hq-5jg7-q4j7">GHSA-w9hq-5jg7-q4j7</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MightyNawaf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MightyNawaf">@MightyNawaf</a> for reporting)</li> <li>Fix web app not allowing access tokens to be changed to never expire (<a href="https://github.com/binwiederhier/ntfy/issues/1693" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1693/hovercard">#1693</a>/<a href="https://github.com/binwiederhier/ntfy/pull/1694" data-hovercard-type="pull_request" data-hovercard-url="/binwiederhier/ntfy/pull/1694/hovercard">#1694</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lastsamurai26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lastsamurai26">@lastsamurai26</a> for reporting and to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ShipItAndPray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ShipItAndPray">@ShipItAndPray</a> for fixing)</li> <li>Fix web app crashing on account page for tokens without a last access time (<a href="https://github.com/binwiederhier/ntfy/issues/1651" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1651/hovercard">#1651</a>, <a href="https://github.com/binwiederhier/ntfy/issues/1684" data-hovercard-type="issue" data-hovercard-url="/binwiederhier/ntfy/issues/1684/hovercard">#1684</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pulsar7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pulsar7">@Pulsar7</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rzhli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rzhli">@rzhli</a> for reporting)</li> </ul> github-actions[bot]