Tech:Noticeboard

{{ {{/header}} }}

{{ {{Autoarchive/config
|archive = Tech:Noticeboard/Archive %(counter)d
|algo = old(31d)
|counter = 1
|maxarchivesize = 150K
|archiveheader = {{Archive}} |minthreadstoarchive = 1
}} }}

{{ {{Navigation Miraheze}} }}

New request for feedback on changes to Miraheze’s default MediaWiki configuration

Please go to Tech:Noticeboard/Request for feedback: changes to default MediaWiki settings to view the proposals and voice your opinions. PetraMagna (talk) 00:47, 24 April 2026 (UTC)

You got it. DarkMatterMan4500 (talk) (contribs) 17:02, 16 May 2026 (UTC)

Maps has been globally disabled

Hello,

Following credible reports of a security vulnerability in the Maps extension, we have decided to disable the extension on all wikis until the security of it can be ensured. There are no signs of the vulnerability being used on Miraheze and we remain uncompromised.

We will be notifying you again once the extension is re-enabled. We apologize for the inconvenience and are happy to answer any questions regarding the matter.

Skye (Miraheze) (talk)
MediaWiki Specialist
02:33, 27 May 2026 (UTC)

Cargo extension’s default map feature is unfortunately not very user-friendly for our use case. We previously relied on the Maps extension to use Leaflet-based interactive maps together with Cargo queries. Is there any recommended alternative for interactive mapping after the removal of Maps? Kijo Sora (talk) 05:06, 27 May 2026 (UTC) I think this might be (related to) issue #898 on ProfessionalWiki/Maps@Github (Maps 12.1.2 vs. SMW 7.0.0); correct me otherwise. –Routhwick (talk) 08:21, 27 May 2026 (UTC) On the other hand… –Routhwick (talk) 08:12, 29 May 2026 (UTC) CVSS 8.6. Yes, the extension has to remain offline until that’s fixed. –Robkelk (talk) 12:54, 29 May 2026 (UTC) Furthermore, it wasn’t functioning fully anymore. Wazzimagiygg (talk) 18:45, 27 May 2026 (UTC) If you’re talking about the issue where some map tiles don’t load, perhaps phab:T15102 might address the matter. –Robkelk (talk) 18:58, 27 May 2026 (UTC) I’d like to kindly ask if there’s any news yet regarding this extension? Without maps (GeoJSON), my wiki isn’t very useful, and almost every wiki page displays a map in an infobox. Weltbibliographie (talk) 18:11, 31 July 2026 (UTC) Another vulnerability was found: https://github.com/ProfessionalWiki/Maps/security/advisories/GHSA-rg4f-xvhj-mw22 Considering this was found using Claude Code, the same tool that the maintainer uses, we have serious doubts that the maintainer has even considered security at all. TheWWRNerdGuy (talk) 18:14, 31 July 2026 (UTC)

Hoping you can sort out the issue, maps are an important element for my wikis. Bertie (talk) 06:18, 27 May 2026 (UTC)

I’m having trouble finding a CVE for this vulnerability (although I admit it’s been nearly a decade since I was involved in IT security, so maybe I’m looking in the wrong place). What’s the CVSS score for this vuln, and has the extension’s maintainers provided a timeline on mitigation and resolution of the issue? In the meantime, what’s available as a replacement? –Robkelk (talk) 12:01, 27 May 2026 (UTC)

Not all vulnerabilities end up getting a CVE, and even then it wouldn’t be public yet. Unfortunately there is no direct drop-in replacement but you may have some success with Kartographer. We’ve also determined the need to perform a review of the extension for more issues. We don’t have an exact timeline for this, but we aim to minimize its inavailability due to high usage and lack of replacement. Skye (talk) 21:01, 27 May 2026 (UTC) Kartographer has its own share of bugs, as documented this month at phab:T15384. –Routhwick (talk) 21:17, 27 May 2026 (UTC) Yeah, that makes sense. DarkMatterMan4500 (talk) (contribs) 16:49, 21 June 2026 (UTC)

It’s been a month and a half since the last update on this. Could we get a status update, please, even if it’s “no change since the end of July”? – Robkelk (talk) 00:25, 20 September 2026 (UTC)

Changes to Miraheze’s default MediaWiki configuration

Following a successful Request for Feedback, the Technology Team is making several changes to Miraheze’s default MediaWiki configurations. We believe they are a net positive for most wikis. If they do not work well for your wiki, you can change the setting back on ManageWiki. The configuration changes are as follows:

  • wgNativeImageLazyLoading is enabled.
  • wgRestrictDisplayTitle is disabled.
  • wgArticleCountMethod is changed from link to any.
  • wgTabberNeueEnableAnimation is disabled.
  • wgVectorResponsive is set to true for all new wikis. Existing wikis are unaffected. Please note that if you have changed the setting manually on ManageWiki before, it will not be changed by us. PetraMagna (talk) 11:58, 15 June 2026 (UTC)

Extension removal for the MediaWiki 1.46 update

As the MediaWiki 1.46 update draws near, the technology team is planning to remove several MediaWiki extensions due to both technical issues and perceived lack of usefulness/community interest.

The list of extensions is on Tech:Noticeboard/Removing extensions for the MediaWiki 1.46 upgrade. If your wiki is affected and you want to keep a particular extension, please join the discussion and explain why the extension is important to your wiki. Administrators and bureaucrats on affected wikis will also receive a Echo notification shortly. PetraMagna (talk) 01:22, 19 July 2026 (UTC)

New Request for Feedback: RequestWiki redesign

Please provide your comments on Request for Feedback: RequestWiki redesign if you have any opinions there.

Thank you,

Universal Omega (Miraheze) (talk) 20:09, 12 September 2026 (UTC)


Go to Source →