:sparkles_pink: Navi :sparkles_pink:'s avatar

:sparkles_pink: Navi :sparkles_pink:

@navi@hey.pomnavi.net

150 following26 followers

:opmugiwara: anime nerd extraordinaire. ♀️

Current Obsessions:

  • 🃏Lord of Mysteries
  • 👁️‍🗨️ Omniscient Reader's Viewpoint
  • 🧛VampDies/吸死
  • 🍀The Apothecary Diaries
  • 🎃Pumpkin ✂️ Scissors
  • 📖 Bookworm/本好き

日本語勉強中。アニメと漫画が大好きです。

This is my self-hosted fediverse account using !

I also have alt accounts for blogging (@naviblogs), collecting (@treasures), and eating (@mmm).

I'm followers-locked on @yume but I do liveblogs there as well

Also on sakurajima.moe @navi

Tags used: #Art #LinkBlog #WebDev

@navi@hey.pomnavi.net

please please please read Magic Doctor Rex's Perverted Medical Record, I promise you it's absolutely hilarious and the doctor is NOT the perverted one in this series lmaoooo

It's the first manga series I've seen that's had such an honest, frank viewpoint towards sex and sexuality.

manga panel 1: a girl is admitting to use a slime to masturbate. Doctor Rex exclaims "What the hell were you thinking!!?"
ALT text

manga panel 1: a girl is admitting to use a slime to masturbate. Doctor Rex exclaims "What the hell were you thinking!!?"

manga panel 2: a large orc and a small petit elf woman are consulting Dr. Rex about their inability to have intercourse due to their size difference.
ALT text

manga panel 2: a large orc and a small petit elf woman are consulting Dr. Rex about their inability to have intercourse due to their size difference.

manga panel 3: three idiots in an adventurer's party got their dicks severed by a man-eating plant, and are lying on the floor in the medical office. The 4th party member (their leader) is explaining the situation to Dr. Rex
ALT text

manga panel 3: three idiots in an adventurer's party got their dicks severed by a man-eating plant, and are lying on the floor in the medical office. The 4th party member (their leader) is explaining the situation to Dr. Rex

manga panel 4: Velma (a male incubus in female human form) is boasting about her ability to do "counseling for women with low sensitivity, advice on how to cum like a pro, and erotic massages!". 

Dr. Rex is grumbling that he meant "medical work".
ALT text

manga panel 4: Velma (a male incubus in female human form) is boasting about her ability to do "counseling for women with low sensitivity, advice on how to cum like a pro, and erotic massages!". Dr. Rex is grumbling that he meant "medical work".

@navi@hey.pomnavi.net

Mist Vol. 1 (Haitang Books) is available for preorder from Kinokuniya but I'm honestly a little worried about the translation quality after the whole debacle over their earlier releases.

I really want it though...

@yenpress@tippy.rabbithouse.garden
🎥 When Hinata and Kaoru are strictly warned to stay off the forbidden mountain, they naturally do the exact opposite.

With the anime airing, check out Dara-san of Reiwa, Vol. 1: buff.ly/Pd70XzP
@geraineon@sakurajima.social
@rinmari68k@sakurajima.social

While you are well within your right to Yell about the video game industry especially in the year of AI slop and union-busting and layoff hell 2026, it's important to also uplift games you do love.

Tell people about games you like! Make a public
🌏 post saying "Please buy this game" or something along those lines.

@arimamary@sakurajima.moe

Art archive is complete! I settled on sharing fanart only and add OC art someplace else.

Link: art.arimamary.net/

Original template: nomnomnami.com/templates/pasti

Screenshot of a Tumblr-style feed on a pink color scheme. There's a side bar and a main section. The side bar has a profile picture, a username, pronouns, a link to the personal website. There's also a section with external links and some button. The main section has two dropdowns, one with notes on things to fix and another a set of filters. Below, there's one quote art featuring an OC from a friend.
ALT text

Screenshot of a Tumblr-style feed on a pink color scheme. There's a side bar and a main section. The side bar has a profile picture, a username, pronouns, a link to the personal website. There's also a section with external links and some button. The main section has two dropdowns, one with notes on things to fix and another a set of filters. Below, there's one quote art featuring an OC from a friend.

@arimamary@sakurajima.moe

🌐 These past couple of weeks I've been busy transferring my website to 11ty. Happy to announce that the site is in pretty decent shape! :meowpuffyheadphones:

New features:

✅ Brand new navs for both desktop and mobile.
✅ Three new sections with subsections: Writing, For You and For Me.
✅ Revamped fic archive: mobile-friendly, no JS, and various filters.

Screenshot of fic archive in light mode (black text over whites and grey highlights). On top there's a header. Below, there are a couple of paragraphs introducing the page. Then, the page is divided into two. On one side there's an AO3 style cards with the name of the fic, the rating, pairing types, a summary, tropes, and characters. On the right there's filtering options such as fics wtih warnings and filter by fandom.
ALT text

Screenshot of fic archive in light mode (black text over whites and grey highlights). On top there's a header. Below, there are a couple of paragraphs introducing the page. Then, the page is divided into two. On one side there's an AO3 style cards with the name of the fic, the rating, pairing types, a summary, tropes, and characters. On the right there's filtering options such as fics wtih warnings and filter by fandom.

Screenshot of my site's homepage. It has a header nav and three sidebars. The nav has some dropdowns. The side has a pink color scheme.
ALT text

Screenshot of my site's homepage. It has a header nav and three sidebars. The nav has some dropdowns. The side has a pink color scheme.

@navi@hey.pomnavi.net

I'll need to check out more manga from Harta magazine, since these all look quite interesting (obvs I've read Dungeon Meshi already lol)

https://yenpress.com/news/let-your-heart-soar-with-our-harta-selection

@yenpress https://tippy.rabbithouse.garden/notes/ap5oa06hyaqmq53a

tippy.rabbithouse.garden

Yen Press (Unofficial) (@yenpress)

From Delicious in Dungeon to My Oh My, Atami, Harta Magazine has produced countless manga that continue to dazzle and delight! Hungry for a new read? Check out our latest blog post for a list that's sure to satisfy!: buff.ly/CpzCTU5 (1 attachments)

@yenpress@tippy.rabbithouse.garden
From Delicious in Dungeon to My Oh My, Atami, Harta Magazine has produced countless manga that continue to dazzle and delight!

Hungry for a new read? Check out our latest blog post for a list that's sure to satisfy!: buff.ly/CpzCTU5

【予告】
10月17日~30日
原宿、竹下通りにあるPINK TOKYO JAPANさん(
https://www.instagram.com/pinktokyo_official?igsh=enBveTJpdzhmZ2Fq)にてスマホケース屋さん兼ポップアップストアをやります!

好きな画像をスマホケースにその場で印刷してくれるサービスです
それの新規イラストを担当します!
ストアでのグッズ販売も予定しています!

@navi@hey.pomnavi.net

I'm not surprised that Onyx Boox is trying to make a competitor to XTEINK but I'm curious about the price point and software.

I got my X4 for 55 USD, hard to beat that price. But if it has a better software experience I might pass this one on.

https://goodereader.com/blog/onyx-boox/new-onyx-boox-picco-wants-to-compete-against-xteink

goodereader.com

New Onyx Boox Picco wants to compete against XTEINK

The BOOX Picco is a pocket-sized eReader that Onyx Boox teased as

@navi@hey.pomnavi.net · Reply to geraineon

@geraineon @morgana_catbus i think I used this one when I was starting out: https://farfromdaylight.tumblr.com/post/180786211798/how-to-dreamwidth-a-primer

Tags can be nested several times deep, but you need to tag every level if you want it to be usable for each level.

For example, if I had a tag like animals: cats, I would need to tag "animals, animals: cats" so I could see both "animals" and "cats". If I don't tag "animals" by itself, then the post will only show up under animals: cats.

I hope that makes sense lol.

farfromdaylight.tumblr.com

How To Dreamwidth: A Primer

the more friends ask me about dreamwidth, the more i realize i know a lot about this site that isn’t super obvious at first glance. so here is a primer for those of you thinking about making a...

@davidrevoy@framapiaf.org
Panel 1. Pepper fans herself: she's flushed and sweating. Her bedroom is hot, with the shutter drawn. Carrot is sleeping on the bed in the background, but she's too busy with items on her desk to notice.  
> Pepper: "So much to do! I need to reorganize my spells, brew new potions, get some writing done!"
ALT text

Panel 1. Pepper fans herself: she's flushed and sweating. Her bedroom is hot, with the shutter drawn. Carrot is sleeping on the bed in the background, but she's too busy with items on her desk to notice. > Pepper: "So much to do! I need to reorganize my spells, brew new potions, get some writing done!"

Panel 2. Pepper spins around and spots Carrot napping.  
> Carrot: "Zzz"  
> Pepper: "How can you just take a nap in this heat?"
ALT text

Panel 2. Pepper spins around and spots Carrot napping. > Carrot: "Zzz" > Pepper: "How can you just take a nap in this heat?"

Panel 3. Pepper pauses and thinks for a moment.
ALT text

Panel 3. Pepper pauses and thinks for a moment.

Panel 4. Pepper stretches out next to Carrot, closes her eyes, and finally relaxes.  
> Pepper: "Actually, you're right. This heat? Yeah, there's nothing smarter to do than this."
ALT text

Panel 4. Pepper stretches out next to Carrot, closes her eyes, and finally relaxes. > Pepper: "Actually, you're right. This heat? Yeah, there's nothing smarter to do than this."

@hongminhee@writings.hongminhee.org
I built this blog with Jikji, a static site generator I wrote myself, almost five years ago. Back then I barely knew TypeScript or modern web tooling, and I'd…

I added ActivityPub to this blog

I built this blog with Jikji, a static site generator I wrote myself, almost five years ago. Back then I barely knew TypeScript or modern web tooling, and I'd never implemented ActivityPub. TypeScript and modern web tooling are second nature to me now, and ActivityPub has become central to my work. I maintain Fedify, for whatever that's worth, and it bothered me that my own blog wasn't federated. So I fixed that.

The old stack: Jikji and PHP

This blog used to run on Jikji, a static site generator I wrote myself in Deno. Calling it a static site generator is a bit of a stretch, though. Like old Movable Type installations, it didn't just produce HTML; it generated a bit of PHP too. That PHP existed almost entirely for HTTP content negotiation: it read the browser's Accept-Language header and chose among Korean mixed script, hangul-only Korean, English, and Japanese. That's all it did.

I first considered adding a thin ActivityPub implementation directly in PHP, since I was already using it. But I wasn't really writing that PHP by hand; Jikji generated it for me, and I had no interest in hand-coding PHP myself. Federating meant delivering a Create(Article) activity to followers whenever a new post went up, which meant I'd need something like a message queue. Bolting a message queue onto Jikji's generated PHP felt, to me at least, like more complexity than it was worth maintaining. And honestly, with Fedify already around, I had no desire to implement ActivityPub from scratch again.

So I ripped out PHP entirely and decided to bring in Fedify instead.

The new stack: Astro and Netlify

The first decision was to drop Jikji and PHP for Astro, a JavaScript framework built for static-content-heavy sites. I chose Astro largely because it already had a @fedify/astro integration.

I reused as much of the existing CSS and HTML as I could. I'm happy with the current design, and redoing it alongside everything else felt like scope creep waiting to happen. Permalinks stayed exactly as they were. I wanted to replace the stack underneath without visitors noticing anything had changed at all.

For hosting, I went back and forth between Cloudflare Workers and Netlify, and settled on Netlify partly because Fedify had never run there before, and this seemed like a good excuse to add that support. I've hosted static sites on Netlify plenty of times, but this was my first time pairing it with edge functions. The idea of a mostly static site with a few dynamic slices reminded me of the late-nineties web, when a site was static HTML except for whatever lived in /cgi-bin/.

Publishing used to mean committing a Markdown file to Git, pushing, letting GitHub Actions build the static site, and deploying it over SFTP. Now GitHub Actions is out of the build pipeline entirely, since Netlify builds the site itself. It ended up simpler overall.

I'm happy with Astro, and the migration went smoothly. It beats Jikji, which I'd barely touched since building it five years ago. Jikji is now archived; there's no reason left for me to keep maintaining it.

Fitting Fedify into Astro

Updating @fedify/astro

Once I actually tried to add Fedify to Astro, I ran into a problem: @fedify/astro didn't support Astro 7, the current version. The Astro APIs it relied on hadn't changed much internally, but the package's declared compatibility range, and its tests, only went up to Astro 5. So before I could federate the blog, I had to fix @fedify/astro first.

That meant more than widening a version range. The existing tests built a fake Astro context and called the middleware directly, which couldn't catch problems with Vite's SSR configuration, compatibility across adapters, or request routing on a built server. So I wrote new compatibility tests that pack @fedify/astro for real, install it into a small Astro app, build and start the app, and send real HTTP requests to it.

Those tests check, across Astro 5, 6, and 7, that HTML requests reach Astro's pages, that ActivityPub and WebFinger requests are handled by Fedify, and that Astro's 404 Not Found still applies to everything else. For Astro 7 specifically, I also run the tests against Deno and Bun, not just the Node.js adapter.

That work has already been merged upstream and will ship in Fedify 2.4.0.

Static pages, dynamic endpoints

The Astro project as a whole builds with server output, but the existing blog pages are still prerendered, same as before. WebFinger, the actor, the inbox and outbox, the followers collection, and ActivityPub objects are the exceptions: Fedify handles those dynamically, per request. The middleware @fedify/astro provides looks at a request's URL and Accept header and only intercepts what Fedify is meant to handle. The same URL can return the existing Astro page for an HTML request and a Fedify-built object for an ActivityPub one.

What visitors see is still, for all practical purposes, a static site. Nearly all the new dynamic surface lives somewhere only other fediverse servers ever touch. That's the CGI comparison again.

Person and Article

Adding ActivityPub also meant deciding what counts as an actor here, and what counts as an object. I gave the blog's actor a Person type. Publishing itself is automated, but the actor represents me, the person writing these posts, not a piece of software or a service. So the handle is @hongminhee@writings.hongminhee.org, and the actor's web URL points at the blog.

Each post gets an Article. It has a title and a body, and it lives at its own permalink as a long-form document, which fits Article better than Note. Most major ActivityPub implementations support Article these days, Mastodon included. Human-facing permalinks stayed put; ActivityPub objects got their own URIs instead, shaped like /ap/articles/{year}/{month}/{slug}. Article's url points back at the original permalink, so the object's identity and the web page people actually read stay separate.

Multiple languages took more thought. Representing each language as its own Article would scatter likes and shares for the same post across several objects. So I merged the Korean mixed script, hangul-only Korean, English, and Japanese versions under a single Article, all sharing one permalink. Title, summary, and body each carry language-tagged values for every version, which serialize to JSON-LD as nameMap, summaryMap, and contentMap. For implementations that don't handle per-language values, name, summary, and content also carry a default: English if there's an English version, Korean mixed script otherwise. Each language's HTML page also gets a Link on Article's url, tagged with hreflang.

That way, a receiving server that understands multiple languages can pick a title and body matching the reader's language, and one that doesn't can still fall back to the default. In practice, though, I know of hardly any ActivityPub implementation that renders these multilingual values properly yet. There's an open issue for it on Mastodon's tracker, and a similar proposal on Hackers' Pub's, but neither has a timeline. Some of that is probably a UI design problem as much as anything else.

Running Fedify on Netlify

Unlike serving plain static files, an ActivityPub server needs some state that outlives any single deploy. The actor's signing key can't rotate on every deploy. The followers list can't disappear on the next one either. Both live in Netlify Database.

Incoming and outgoing activities go through a message queue built on Async Workloads. Delivery can be slow or fail outright depending on the receiving server, so it can't all happen inside the function handling the HTTP request. Queuing it separates accepting a request from actually delivering it, and failed deliveries can be retried later. Fedify already abstracts this, with pluggable backend adapters, but there wasn't yet an adapter for Netlify's Async Workloads. So I wrote the @fedify/netlify package, which uses Async Workloads as the queue and keeps delivery-order state in Netlify Database.

Announcing new posts to the fediverse turned out to be a separate problem. A static site finishing its build doesn't tell a running ActivityPub server anything about which posts changed. So on every successful production deploy, I diff the current post list against the previous deploy's. New posts get a Create(Article); edited ones, whether the content or just the timestamp changed, get an Update(Article); removed ones get a Delete(Article). All of it goes out to followers. Retries reuse the same activity ID for the same change, and deploy ordering is checked so that an older deploy syncing late can't undo a newer one.

Netlify's deploy previews and branch deploys have federation turned off entirely. Otherwise every preview would spin up an actor claiming to be this same blog, and a test deploy could end up sending activities to real followers. Locally, I develop against an in-memory store and queue; production is the only place using the persistent database and queue.

Fedify now runs on Netlify Functions, alongside Deno Deploy and Cloudflare Workers, on top of its usual support for Node.js, Deno, and Bun.

Wrapping up

None of this gives the blog a timeline, a reply box, or any other social feature. Writing and reading still work the way they always did, and the permalinks and design are basically untouched. What changed is that the blog, and every post on it, now has a name and address the fediverse understands. Follow @hongminhee@writings.hongminhee.org to get new posts, or look up a post's ActivityPub object URI to find the original.

I've maintained Fedify long enough to show other developers how to implement ActivityPub, and I dogfooded it plenty while building Hollo and Hackers' Pub. But this was the first time I'd added it to a site that was already live, and static at that. Along the way I got a compatibility test suite for the Astro integration, Netlify support, and a handful of deployment and operational problems that no amount of reading docs or unit tests would have surfaced. It turns out Fedify isn't just for building new social networks from scratch; it works just as well for bringing an existing site into the fediverse without changing how it looks.

hackers.pub

Hackers' Pub: Local timeline

@hollo@hollo.social

Hollo security updates: 0.8.9 and 0.9.9

If you run Hollo, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client, which Hollo uses to identify the software running on remote ActivityPub servers.

A NodeInfo lookup starts by fetching a remote server's /.well-known/nodeinfo document, then follows the NodeInfo document URL advertised in that response. The vulnerable getNodeInfo() path fetched both URLs without validating that they resolved to public network destinations. Because the second URL comes directly from a response controlled by the remote server, it could point to a loopback address, a link-local cloud metadata endpoint, an RFC 1918 private address, or even a data: URL.

An attacker who controls a remote server that Hollo discovers could therefore make the Hollo instance initiate requests to non-public network destinations, depending on the deployment environment and network routing.

The fix applies Fedify's public-address validation to both NodeInfo requests and every redirect hop. It also caps redirects, refuses cross-protocol redirects, and rejects non-HTTP(S) URLs. As a result, NodeInfo lookups for private or intranet addresses are now refused.

For full technical details of the underlying vulnerability, see the Fedify security advisory and the Fedify security announcement.

All Hollo versions in the supported 0.8.x and 0.9.x release lines up to and including 0.8.8 and 0.9.8 are affected. Patched releases are 0.8.9 for the 0.8.x series and 0.9.9 for the 0.9.x series.

Hollo 0.7.x is also affected. It and earlier release lines are no longer supported under the Hollo security policy. Upgrade to a supported release series rather than remaining on an older version.

For 0.8.x deployments, update to 0.8.9:

docker pull ghcr.io/fedify-dev/hollo:0.8.9

For 0.9.x deployments, update to 0.9.9:

docker pull ghcr.io/fedify-dev/hollo:0.9.9

After pulling the new image, restart your Hollo container. If you deploy from source, pull the corresponding release tag and restart.

Thanks to @rvzsec and @manus-use for the report and responsible disclosure to the Fedify project.

If anything is unclear, ask below.

github.com

manus-use - Overview

Cybersecurity Researcher | Sharing practical InfoSec knowledge - manus-use

@cuppabakedbeans@pixelfed.social
hello i would like more validation. here is my art. here are the four arguably most emo megas from ZA. scrafty was challenging getting the fabric texture, since that's new to me. chandelure i'm so surprised came out looking good even though it has 12 arms.

#pixelart #aseprite #pokemon #legendsza #megaevolution #scrafty #darkrai #floette #chandelure
pixel art of mega scrafty in DS style
ALT text

pixel art of mega scrafty in DS style

pixel art of mega darkrai in DS style
ALT text

pixel art of mega darkrai in DS style

pixel art of mega chandelure in DS style
ALT text

pixel art of mega chandelure in DS style

pixel art of mega floette in DS style
ALT text

pixel art of mega floette in DS style

@navi@hey.pomnavi.net

I started watching The Forsaken Saintess and Her Foodie Roadtrip in Another World (it wasn't on my list before) because someone described it as Campfire Cooking + The Saint's Magic Power is Omnipotent

It's so cute and comfy and there's the start of a little romance too!

It's like if Mukouda actually decided to start working with Iron Will or another party, or if Fel, Sui, and Dora were ikemen/bishoujo 😂

anilist.co

AniList

@doodlemancy@kind.social

new in my etsy shop: these silly little pillboxes. 💊 choose your label and color combo. i made these to carry backup medication, but they have lots of potential! 😎 etsy.com/listing/4539121432/

four small slide tins, a couple of them showing off pills inside.
label 1: oh shit
label 2: i forgor 💀
label 3: just in case (with an anxious kitty)
label 4: a doodly cartoon cat, face-down on the floor in utter despair
ALT text

four small slide tins, a couple of them showing off pills inside. label 1: oh shit label 2: i forgor 💀 label 3: just in case (with an anxious kitty) label 4: a doodly cartoon cat, face-down on the floor in utter despair

examples of other things you could fit in them:
-house key
-bus money
-bandaids? (which i did have to fold)
-hair ties
ALT text

examples of other things you could fit in them: -house key -bus money -bandaids? (which i did have to fold) -hair ties

examples of all the labels (the "just in case" kitty has both a red and blue version) and all the tin colors (white, purple, pink, and mint)
ALT text

examples of all the labels (the "just in case" kitty has both a red and blue version) and all the tin colors (white, purple, pink, and mint)