This release contains fixes for minor bugs and issues reported by Ghost users.
View the changelog for full details: v5.90.0...v5.90.1
Tag Name: v5.90.1
Release Date: 8/26/2024
GhostOpen-source publishing platform specifically designed for professional bloggers and publications. Focuses on clean, minimalist writing and publishing experience.
This minor release adds a honeypot field to the Ghost Portal signup form to help mitigate bot signup activity. The honeypot field is hidden from regular users but can be filled out by bots, allowing Ghost to identify and log potential automated signups. This release focuses on properly implementing this anti-spam measure while ensuring it works consistently across page changes within Portal.
No migration steps are required for this release. The honeypot field implementation is handled automatically and doesn't require any configuration changes from administrators or developers.
This release is recommended for all Ghost users, especially those experiencing issues with bot signups or spam accounts. The upgrade process is straightforward with no breaking changes:
The honeypot field will be automatically implemented in your Portal signup forms after the update.
Ghost Portal now includes a honeypot field in the signup form to help identify and mitigate bot signup activity. This field:
This implementation is currently in data collection mode, logging suspicious activity while Ghost evaluates the effectiveness of this approach.
While not a security fix for a specific vulnerability, this release enhances Ghost's security posture by:
This is part of Ghost's ongoing efforts to protect sites from spam and automated abuse.
No specific performance improvements were mentioned in this release. The primary focus was on security enhancement through the implementation of the honeypot field in Portal.
This release introduces a non-intrusive security enhancement to Ghost's Portal signup process through the implementation of a honeypot field. This helps site administrators identify and potentially block bot signups without affecting legitimate users. The implementation is currently in a data collection phase, logging suspicious activity to help Ghost evaluate and refine this approach.
The changes are focused on the Portal component, ensuring that the honeypot field works properly and maintains its state across page changes. This provides a foundation for future anti-spam measures while immediately beginning to collect data on bot activity.
For site administrators, this release offers improved protection against automated signups with no configuration required. For end users, the experience remains unchanged as the honeypot field is invisible to human visitors.
This release contains fixes for minor bugs and issues reported by Ghost users.
View the changelog for full details: v5.90.0...v5.90.1