0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-04 10:39:43 +08:00
A platform for community discussion. Free, open, simple. https://www.discourse.org
  • Ruby 58.5%
  • JavaScript 35.5%
  • HTML 3.1%
  • SCSS 2.8%
Find a file
Alan Guo Xiang Tan 719286df21
SECURITY: Limit topic OG asset dimensions
SVG and compressed raster assets can declare dimensions that require excessive memory before the renderer produces the fixed-size topic OG canvas.

This commit applies the former ImageMagick 64K dimension ceiling and the configured image megapixel ceiling before libvips decodes an OG asset.
2026-08-04 06:21:39 +08:00
.agents
.claude
.cursor/rules
.devcontainer DEV: Bump dev container image to 20260803-0122 (#42256) 2026-08-03 14:28:00 +08:00
.github
.skills FEATURE: Allow selection of multiple content languages when viewing topics and posts (#42128) 2026-07-30 12:19:44 +08:00
.vscode
.zed
app FEATURE: Use libvips for low-risk image operations 2026-08-04 06:19:27 +08:00
bin
config FIX: Prevent read-only keys being created without scopes (#42280) 2026-08-03 15:45:48 -05:00
db FIX: Prevent read-only keys being created without scopes (#42280) 2026-08-03 15:45:48 -05:00
docs FEATURE: Use libvips for low-risk image operations 2026-08-04 06:19:27 +08:00
frontend DEV: simplify and use reuable components in invite modal, fix bug, (#42273) 2026-08-03 15:31:55 -04:00
images
lib SECURITY: Limit topic OG asset dimensions 2026-08-04 06:21:39 +08:00
log
migrations MT: Sync migrations schema config with recent core schema changes (#42202) 2026-07-31 16:26:05 +02:00
patches
plugins UX: hide chat header buttons for collapsed drawer chat, change minimize icon (#42279) 2026-08-03 15:35:17 -04:00
public
script DEV: Add image-processing regression coverage (#42117) 2026-07-30 15:28:07 +08:00
spec SECURITY: Limit topic OG asset dimensions 2026-08-04 06:21:39 +08:00
stylelint-rules
test
themes I18N: Update translations (#42261) 2026-08-03 10:55:52 +02:00
vendor
.annotaterb.yml
.editorconfig
.git-blame-ignore-revs
.gitattributes
.gitignore
.ignore
.jsdoc
.licensed.yml
.licensee.json
.npmrc
.pnpmfile.cjs
.prettierignore
.prettierrc.cjs
.rspec
.rspec_parallel
.rubocop.yml
.ruby-gemset.sample
.streerc
AGENTS.md
AI-AGENTS.md
Brewfile
CLAUDE.md
CODEOWNERS
config.ru
CONTRIBUTING.md
COPYRIGHT.md
d
discourse.sublime-project
eslint.config.mjs
Gemfile
Gemfile.lock MT: Adopt markbridge 0.4.0, where [code] is always a block 2026-07-31 16:17:14 +02:00
GEMINI.md
lefthook.yml
LICENSE.txt
package.json
pnpm-lock.yaml
pnpm-workspace.yaml
Rakefile
README.md
stylelint.config.mjs
translator.yml
tsconfig-base.json
tsconfig.json
versions.json

The online home for your community.

github-readme

You can self-host Discourse on your own infrastructure. But if you'd rather skip the setup, maintenance, and server management, we offer official Discourse hosting.

👉 Learn more about Discourse hosting

Discourse is a 100% open-source community platform for those who want complete control over how and where their site is run.

Our platform has been battle-tested for over a decade and continues to evolve to meet users needs for a powerful community platform.

With Discourse, you can:

  • 💬 Create discussion topics to foster meaningful conversations.

  • Connect in real-time with built-in chat.

  • 🎨 Customize your experience with an ever-growing selection of official and community themes.

  • 🤖 Enhance your community with plugins, from chatbots powered by Discourse AI to advanced tools like SQL analysis with the Data Explorer plugin.

To learn more, visit discourse.org and join our support community at meta.discourse.org.

Here are just a few of the incredible communities using Discourse:

discourse-communities

👉 Discover more communities using Discourse

Development

To get your environment set up, follow one of the setup guides:

Before you get started, ensure you have the following minimum versions: Ruby 3.4+, PostgreSQL 15, Redis 7.

For more information, check out the Developer Documentation.

Setting up Discourse

If you want to set up a Discourse forum for production use, see our Discourse Install Guide.

If you're looking for official hosting, see discourse.org/pricing.

Requirements

Discourse supports the latest, stable releases of all major browsers and platforms:

Browsers Tablets Phones
Apple Safari iPadOS iOS
Google Chrome Android Android
Microsoft Edge
Mozilla Firefox

Additionally, we aim to support Safari on iOS 16.4+.

Built With

  • Ruby on Rails — Our back end API is a Rails app. It responds to requests RESTfully in JSON.
  • Ember.js — Our front end is an Ember.js app that communicates with the Rails API.
  • PostgreSQL — Our main data store is in Postgres.
  • Redis — We use Redis as a cache and for transient data.
  • BrowserStack — We use BrowserStack to test on real devices and browsers.

Plus lots of Ruby Gems, a complete list of which is at /main/Gemfile.

Contributing

Build Status

Discourse is 100% free and open source. We encourage and support an active, healthy community that accepts contributions from the public including you!

Before contributing to Discourse:

  1. Please read the complete mission statements on discourse.org. Yes we actually believe this stuff; you should too.
  2. Read and sign the Electronic Discourse Forums Contribution License Agreement.
  3. Dig into CONTRIBUTING.MD, which covers submitting bugs, requesting new features, preparing your code for a pull request, etc.
  4. Always strive to collaborate with mutual respect.
  5. Not sure what to work on? We've got some ideas.

We look forward to seeing your pull requests!

Security

We take security very seriously at Discourse; all our code is 100% open source and peer reviewed. Please read our security guide for an overview of security measures in Discourse, or if you wish to report a security issue.

Security fixes are listed in the release notes for each version.

The Discourse Team

The original Discourse code contributors can be found in AUTHORS.MD. For a complete list of the many individuals that contributed to the design and implementation of Discourse, please refer to the official Discourse blog and GitHub's list of contributors.

Copyright 2014 - 2026 Civilized Discourse Construction Kit, Inc.

Licensed under the GNU General Public License Version 2.0 (or later); you may not use this work except in compliance with the License. You may obtain a copy of the License in the LICENSE file, or at:

https://www.gnu.org/licenses/old-licenses/gpl-2.0.txt

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Discourse logo and “Discourse Forum” ®, Civilized Discourse Construction Kit, Inc.

Accessibility

To guide our ongoing effort to build accessible software we follow the W3Cs Web Content Accessibility Guidelines (WCAG). If you'd like to report an accessibility issue that makes it difficult for you to use Discourse, email accessibility@discourse.org. For more information visit discourse.org/accessibility.

Dedication

Discourse is built with love, Internet style.

For over a decade, our amazing community has helped shape Discourse into what it is today. Your support, feedback, and contributions have been invaluable in making Discourse a powerful and versatile platform.

Were deeply grateful for every feature request, bug report, and discussion that has driven Discourse forward. Thank you for being a part of this journey—we couldnt have done it without you!