Added admin api for managing tags (#26872)
Fix #26849 by adding the domain of the current SSO provider to the form-action CSP (#26857)
Change `GET /api/v1/directory` to use database replica rather than primary (#26856)
Downgrade signature verification debug logging from `warn` to `debug` (#26812)
Improve interaction modal error handling (#26795)
Add admin notifications for new Mastodon versions (#26582)
Add `authorized_fetch` server setting in addition to env var (#25798)
Fix `/api/v1/timelines/tag/:hashtag` allowing for unauthenticated access when public preview is disabled (#26237)
Add debug logging on signature verification failure (#26637)
Improve error messages when DeepL quota is exceeded (#26704)
Refactor `Api::V1::ProfilesController` into two separate controllers (#26573)
Change “privacy and reach” settings so that unchecking boxes always increase privacy and checking them always increase reach (#26508)
Fix blocking subdomains of an already-blocked domain (#26392)
Fix Content Security Policy sometimes unnecessarily allowing hCaptcha scripts (#26388)
Add direct link to the Single-Sign On provider if there is only one sign up method available (#26083)
Refactor: replace whitelist_mode mentions with limited_federation_mode (#26252)