Gitea

Developer Tools

A painless self-hosted Git service.

Latest v1.27.1 · by GiteaWebsitego-gitea/gitea

Release activity

Release activity — 10 releases across 10 days since Mar 13, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Mar 13, 2026. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 19, 2026No releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 20261 release on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026
MondayNo releases on Apr 20, 2026No releases on Apr 27, 2026No releases on May 4, 2026No releases on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 20261 release on Jul 13, 2026No releases on Jul 20, 20261 release on Jul 27, 2026No releases on Aug 3, 2026
TuesdayNo releases on Apr 21, 2026No releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 2026No releases on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 20261 release on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
WednesdayNo releases on Apr 22, 2026No releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 20261 release on May 20, 2026No releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Apr 23, 2026No releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
Friday1 release on Apr 24, 2026No releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on Apr 25, 2026No releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 20261 release on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026

10 releases since Mar 13, 2026

Changelog

v1.27.1

Changed 1
  • improve diff contrast in light and dark themes
Fixed 19
  • skip OIDC end-session after password login for OAuth2 users
  • make Actions log parser support multiple line message encoding
  • use base branch ref for pull_request_target context
  • skip already-approved runs in ApproveRuns
  • orgmode render include path
  • cancel tasks immediately when the runner stopped reporting
Security 1
  • enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints
  • SECURITY

    • fix(oauth2): enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints (#38591) (#38606)
  • API

    • fix(api): align Swagger schemas for UserSettings and TopicListResponse (#38590) (#38592)
  • ENHANCEMENTS

    • enhance: improve diff contrast in light and dark themes (#37477) (#38574)
  • BUGFIXES

    • fix: skip OIDC end-session after password login for OAuth2 users (#38439) (#38666)
    • fix: make Actions log parser support multiple line message encoding (#38659) (#38664)
    • fix(actions): use base branch ref for pull_request_target context (#38636) (#38657)
    • fix(actions): skip already-approved runs in ApproveRuns (#38653) (#38654)
    • fix: orgmode render include path (#38642) (#38645)
    • fix(actions): cancel tasks immediately when the runner stopped reporting (#38616) (#38644)
    • fix(issues): fix label bulk-load key and reduce log noise in LoadLabel (#38632) (#38643)
    • fix(actions): improve runner list status sorting, labels and task job links (#38586) (#38633)
    • fix(actions): correctness and hardening fixes (#38518) (#38631)
    • fix(repo): prevent double-write redirect collisions on dependency errors, fix ui (#38627) (#38628)
    • fix: delete repo-scoped rows of seven more tables when deleting a repository (#38534) (#38618)
    • fix(webhook): remove slack channel name check (#38608) (#38612)
    • fix: download dropdown menu clipped on the branches page (#38604) (#38609)
    • fix(project): prevent database mutations on invalid MoveIssues payload (#38600) (#38602)
    • fix(actions): make SingleWorkflow.Marshal round-trip multi-line run blocks (stop silent job stranding) (#38520) (#38599)
    • fix(file-tree): handle submodule links and missing view container (#38033) (#38589)
    • fix(actions): fail unexpandable reusable workflow callers and decouple the job emitter's cross-run processing (#38565) (#38587)
    • fix: keep serving valid ACME cert when renewal fails at startup (#38554) (#38583)
    • fix: branch protection user list (#38570) (#38584)
    • fix(pulls): respect diff.orderFile in diff file tree (#38566) (#38578)
    • fix(issue): make issue action (issue list batch operation) elements have correct attributes (#38575) (#38580)
    • fix(actions): support matrix when evaluating workflow if expression (#38474) (#38557)
    • fix(actions): align status icon span for Safari rendering (#38558) (#38562)
    • fix: revert git clone http redirection forbidden (#38530) (#38545)
    • fix: clean up orphaned user-keyed tables in deleteUser (#38511) (#38514)
    • fix(actions): coerce workflow_dispatch boolean inputs to native types (#38472) (#38521)
    • fix: make the merge box button red if some checks fail (#38508) (#38516)
    • fix(pull): sign the commit when updating a branch by merge (#38441) (#38499)
    • fix: make commit message merge correctly (#38490) (#38502)
    • fix(actions): explain why a blocked or waiting job has not started (#38476) (#38498)
    • fix(actions): make cancelled() work in job if evaluation (#38495) (#38497)
    • fix(actions): show retention info on hover for expired artifacts (#38477) (#38493)
    • fix(actions): group reusable-workflow matrix legs in the workflow graph (#38475) (#38492)
    • fix: full file highlighting for git diff with CR char (#38484) (#38491)
    • fix(packages): serve noarch Alpine index for any requested architecture (#38479) (#38486)
    • fix: 500 error when updating user visibility (#38480) (#38483)
    • fix(actions): make job list item fully clickable (#38462) (#38471)
    • fix: mail template for push event (#38467) (#38468)
    • fix: make "test push webhook" always work (#38425) (#38455)
    • fix(actions): prevent bulk actions from affecting all runners (#38453) (#38457)
    • fix(org): align follow button and wrap description (#38448) (#38454)
    • fix(actions): populate github.event for scheduled runs (#38446) (#38452)
  • MISC

    • refactor: git patch apply (#38637) (#38638)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

View originalPermalink
How v1.27.1 went

v1.27.0

Added 6
  • Add workflow status badge modal
  • Support owner-level and global scoped workflows
  • Support ref suffixes in compare API
  • Implement jobs.<job_id>.continue-on-error in actions
  • Show run status on browser tab favicon
  • Add token introspection and self-deletion endpoint
Changed 2
  • Improve support for reusable workflows
  • Use Content-Security-Policy script nonce
Security 14
  • Harden access checks and migration validation
  • Enforce public-only token scope and harden push options and locale parsing
  • Re-evaluate review official flag on target branch change
  • Stop leaking private repo metadata after access revocation
  • Require proof of possession for cross-repo LFS objects
  • Disable HTTP redirects on pull mirror sync
  • BREAKING

    • Feat(actions)!: improve support for reusable workflows (#37478)
    • Use Content-Security-Policy: script nonce (#37232)
  • SECURITY

    • Fix: various security fixes (#38406) (#38426)
    • Fix(security): harden access checks and migration validation (#38324) (#38400)
    • Fix: enforce public-only token scope and harden push options / locale parsing (#38323) (#38399)
    • Fix(pull): re-evaluate review official flag on target branch change (#38319) (#38402)
    • Fix(api): stop leaking private repo metadata after access revocation (#38321) (#38390)
    • Fix(lfs): require proof of possession for cross-repo objects (#38322) (#38389)
    • Fix(mirror): disable HTTP redirects on pull mirror sync (#38320) (#38367)
    • Fix: golang html template url escaping (#38363) (#38369)
    • Fix(release): validate web attachment renames against allowed types (#38314) (#38328)
    • Fix(release): gate draft release attachments on web download endpoints (#38318) (#38325)
    • Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#37786)
    • Fix(oauth): restrict introspection to the token's client (#38042)
    • Fix(api): don't expose private org membership via public_members (#38145)
    • Fix(actions): deny fork-PR cross-repo access via collaborative owner (#38214)
    • Fix(migrations): prevent path traversal in repository restore (#38215)
  • FEATURES

    • Feat(actions): add workflow status badge modal (#38196)
    • Feat(actions): support owner-level and global scoped workflows (#38154)
    • Feat(api): support ref suffixes in compare (#38148)
    • Feat(actions): implement jobs.<job_id>.continue-on-error (#38100)
    • Feat(actions): show run status on browser tab favicon (#38071)
    • Feat(api): add token introspection and self-deletion endpoint (#37995)
    • Feat(api): add q parameter to list branches API for server-side filtering (#37982)
    • Feat(repo): split repository creation limit into user and org scopes (#37872)
    • Feat(actions): bulk delete, disable and enable runners in admin UI (#37869)
    • Feat(actions): List workflows that were executed once but got removed from the default branch (#37835)
    • Feat(org): add team visibility so org members can discover teams (#37680)
    • Feat: add raw diff/patch endpoint for repository comparisons (#37632)
    • Feat: Add avatar stacks (#37594)
    • Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) (#37500)
    • Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support (#37433)
    • Support for Custom URI Schemes in OAuth2 Redirect URIs (#37356)
    • Feat(orgs): Add search bar for organization members tab page (#37347)
    • Feat(api): Add assignees APIs (#37330)
    • Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs (#37196)
    • Serve OpenAPI 3.0 spec at /openapi.v1.json (#37038)
    • Add project column picker to issue and pull request sidebar (#37037)
    • Allow multiple projects per issue and pull requests (#36784)
    • Feat(ui): add "follow rename" to file commit history list (#34994)
    • Feat(ssh): auto generate additional ssh keys (#33974)
  • ENHANCEMENTS

    • Enhance(actions): only create filtered-out workflow commit status for required contexts (#38371) (#38385)
    • Enhance: allow builtin default git config options to be overridden (#38172)
    • Enhance: allow MathML core elements (#38034)
    • Enhance(markup): improve issue title rendering (#37908)
    • Enhance(actions): set descriptive browser tab title on run view (#37870)
    • Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 (#37866)
    • Enhance(actions): show workflow name from YAML instead of filename (#37833)
    • Feat(actions): add before/after to PR synchronize event payload (#37827)
    • Enhance(actions): add branch filters to run list (#37826)
    • Enhance(actions): Make Summary UI more beautiful with more infos (#37824)
    • Feat: add copy button to action step header, improve other copy buttons (#37744)
    • Fix(icon): use repo-forked icon to display forks count (#37731)
    • Feat(api): add sort and order query parameters to job list endpoints (#37672)
    • Feat(api): add last_sync to repository API (#37566)
    • Enhance: Adjust Workflow Graph styling (#37497)
    • Improve code editor text selection and clean up lint enablement (#37474)
    • Add mirror auth updates to repo edit API and settings (#37468)
    • Replace olivere/elastic with REST API client, add OpenSearch support (#37411)
    • Feat: Add default PR branch update style setting (#37410)
    • Fix inconsistent disabled styling on logged-out repo header buttons (#37406)
    • Allow fast-forward-only merge when signed commits are required (#37335)
    • Enhance styling in actions page (#37323)
    • Fix: improve actions status icons and texts (#37206)
    • Make Markdown fenced code block work with more syntaxes (#37154)
    • Fix: Sort action run jobs by JobID and Name with matrix examples (#37046)
    • Add API endpoint to reply to pull request review comments (#36683)
  • PERFORMANCE

    • Perf(actions): debounce runner heartbeat writes and throttle task picks (#38281) (#38368)
    • Perf(web): sort the action_run query by a repo-scoped index when possible (#38155)
    • Perf: Various performance regression fixes (#38078)
    • Perf: extend action c_u index to include created_unix for faster dashboard feeds (#38076)
    • Batch-load related data in actions run, job, and task API endpoints (#37032)
  • BUGFIXES

    • Fix(util): reject invalid characters between time-estimate units (#38416) (#38423)
    • Fix: represent a deleted assignee team as a Ghost team (#38413) (#38419)
    • Fix(turnstile): route CAPTCHA verification through the configured proxy (#38412) (#38420)
    • Fix: refresh pull request merge box when the commit status is pending (#38410) (#38411)
    • Fix: actions task state concurrent update (#38405) (#38409)
    • Fix(actions): keep workflow run trailing on one row with long branch names (#38382) (#38403)
    • Fix(web): use locale-aware date formatting for contribution calendar tooltips (#38398) (#38401)
    • Fix: co-author detection (#38392) (#38397)
    • Fix: incorrect co-author detection on commit page (#38386) (#38387)
    • Fix(ui): restore commits table column widths (#38379) (#38383)
    • Fix: minio init check (#38355) (#38361)
    • Fix: org project view assignee list (#38357) (#38360)
    • Fix(actions): release claimed task if context is cancelled during FetchTask (#38343) (#38347)
    • Fix(actions): make runner list pagination order deterministic (#38313) (#38327)
    • Fix: Improve since/until when counting commits for X-Total-Count (#38243) (#38304)
    • Fix(actions): prevent chevron overlap with log text when timestamps are enabled (#38227) (#38307)
    • Fix(workflows): branch protection status checks fail when workflow uses on: paths filter (#38237) (#38302)
    • Fix(oauth2): persist linkAccountData during auto-link 2FA flow (#38274) (#38295)
    • Fix(actions): allow Actions bot to push to protected branches (#38284) (#38293)
    • Fix(actions): include all aggregable run statuses in status filter (#38280) (#38287)
    • Fix(archiver): use serializable repo-archive queue payload (#38273) (#38283)
    • Fix: update npm dependencies, fix misc issues (#38257)
    • Fix(api): respect since/until when counting commits for X-Total-Count (#38204)
    • Fix: codemirror regressions (#38248)
    • Fix(api): support HEAD requests on all API GET endpoints (#38245)
    • Fix(actions): Cleanup workflow status badge code (#38241)
    • Fix(web): Correctly align the "disabled" label on larger workflow names (#38240)
    • Fix(actions): don't swallow HTML entities into linkified URLs (#38239)
    • Fix(packages): accept npm "repository" and "bin" in string form (#38236)
    • Fix(actions): fix 500 error when canceling a canceling task (#38223)
    • Fix(deps): update module golang.org/x/image to v0.43.0 [security] (#38219)
    • Fix(mssql): convert legacy DATETIME columns to DATETIME2 (#38216)
    • Fix(api): deny private org member enumeration via /members (#38213)
    • Fix(actions): ensure all waiting jobs get runners in large workflows (#38200)
    • Fix(deps): update go dependencies (#38194)
    • Fix(deps): update npm dependencies (#38193)
    • Fix(cli): default must-change-password to false for bot users (#38175)
    • Fix(actions): show run index in run view and fix summary graph height (#38165)
    • Fix: csp (#38162)
    • Fix(deps): update npm dependencies (#38123)
    • Fix(mssql): expand legacy issue and comment long-text columns (#38120)
    • Fix(packages): validate debian distribution and component names (#38116)
    • Fix(packages): validate module version in goproxy ParsePackage (#38104)
    • Fix(deps): update dependency esbuild to v0.28.1 [security] (#38097)
    • Fix: git push hook post receive (#38089)
    • Fix(ui): prevent commit status popup overflowing its row (#38081)
    • Fix: validate gem name in rubygems parseMetadataFile (#38061)
    • Fix: commit display name (#38057)
    • Fix: csp regressions (#38047)
    • Fix: api error message (#38031)
    • Fix(deps): update npm dependencies (#38029)
    • Fix: pgsql lint (#38022)
    • Fix(indexer): fix assignee filters in issue search (#38021)
    • Fix: various dropdown problems (#38020)
    • Fix: refactor git error handling and make archive streaming handle non-existing commit id (#38007)
    • Fix: raise git required version to 2.13 (#37996)
    • Fix: remove "no-transfrom" from the cache-control header (#37985)
    • Fix(deps): update module github.com/google/go-github/v87 to v88 (#37971)
    • Fix: use committer time where ever possible as default (#37969)
    • Fix(deps): update npm dependencies, remove nolyfill (#37968)
    • Fix(deps): update go dependencies (#37967)
    • Fix(pull): preserve squash message trailers and additional commit messages (#37954)
    • Fix(deps): update module golang.org/x/image to v0.41.0 [security] (#37904)
    • Fix: support ##[command] log prefix in action run UI (#37882)
    • Fix(deps): update module github.com/google/go-github/v86 to v87 (#37845)
    • Fix(deps): update npm dependencies (#37844)
    • Fix(deps): update go dependencies (#37841)
    • Fix(frontend): resolve Vite assets by manifest source path (#37836)
    • Fix(locales): Replace hardcoded strings (#37788)
    • Fix(packages): render markdown links relative to linked repo (#37676)
    • Fix: persist mirror repository metadata (#37519)
    • Fix cmd tests by mocking builtin paths (#37369)
    • Add form-fetch-action to some forms, fix "fetch action" resp bug (#37305)
    • Feat: execute post run cleanup when workflow is cancelled (#37275)
    • Fix relative-time error and improve global error handler (#37241)
    • Refactor flash message and remove SanitizeHTML template func (#37179)
  • TESTING

    • Test(e2e): fix race in pdf file render test (#38380) (#38381)
    • Test: compare key file contents instead of FileInfo in TestInitKeys (#38330) (#38331)
    • Test: speed up two tests (#37905)
    • Test: Fix random failure test (#37887)
    • Test: fix flaky issue-comment close test (#37880)
    • Test: enable WAL for sqlite integration tests (#37861)
    • Test: fix flaky TestResourceIndex and reduce its runtime (#37847)
    • Test: run TestAPIRepoMigrate offline via a local clone source (#37817)
    • Ci: shard tests and reduce redundant work (#37618)
    • Test(e2e): run playwright via container (#37300)
    • Remove external service dependencies in migration tests (#36866)
  • BUILD

    • Fix(actions): authenticate snapcraft before nightly remote build (#38252)
    • Ci: cap Elasticsearch heap in db-tests (#37816)
    • Build(snap): publish nightly version to snapcraft via actions (#37814)
    • Ci: split pgsql shards into plain jobs, dedupe setup actions (#37802)
    • Ci: narrow files-changed frontend filter (#37749)
    • Ci: add zizmor to lint-actions (#37720)
    • Chore: clean up "contrib" dir (#37690)
    • Fix: snap build (main branch) (#37685)
    • Ci: Also lint json5 files (#37659)
    • Feat(editor): broaden language detection in web code editor (#37619)
    • Build: update pnpm to v11 (#37591)
    • Refactor(deps): migrate from nektos/act fork to gitea/runner (#37557)
    • Refactor: lint bare fill/stroke colors, add vars for git graph color series (#37543)
    • Update go js py dependencies (#37525)
    • Ci: lint PR titles with commitlint (#37498)
    • Chore: upgrade Go version in devcontainer image to 1.26 (#37374)
    • Update GitHub Actions to latest major versions (#37313)
    • Update go js dependencies (#37312)
    • Fail vite build on rolldown warnings via NODE_ENV=test (#37270)
    • Remove htmx (#37224)
    • Replace custom Go formatter with golangci-lint fmt (#37194)
    • Refactor htmx and fetch-action related code (#37186)
    • Integrate renovate bot for all dependency updates (#37050)
    • Build(sign): move to sigstore (#38250)
  • DOCS

    • Docs: update changelog for 1.26.3 & 1.26.4 (#38178)
    • Docs: fix duplicated word in foreachref doc comment (#38161)
    • Docs: Clarify criteria for becoming a merger (#38113)
    • Docs: Publish TOC Election Result 2026 (#38111)
    • Docs: mark openapi3 as autogenerated in attributes (#37963)
    • Docs: add development setup guide (#37960)
  • MISC

    • Revert(sign): restore gpg (#38251)
    • Refactor: replace legacy delete-button with link-action (#38143)
    • Refactor(actions): read runner capabilities from proto field (#38068)
    • Refactor(api): clarify APIError message usage and fix legacy lint error (#38012)
    • Refactor: Use db.Get[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record (#37977)
    • Fix(deps): update go dependencies (#37851)
    • Ci: Fix sync PR labels from the conventional-commit title (#37784) (#37825)
    • Ci: tweak files-changed, add free-disk-space (#37819)
    • Fix(deps): update module golang.org/x/crypto to v0.52.0 [security] (#37806)
    • Test(e2e): add comment, release, star, PR and fork tests (#37800)
    • Chore: simplify issue and pull request templates (#37799)
    • Chore: Update giteabot to fix failure when backport (#37789)
    • Fix(api): handle partial failures in push mirror synchronization gracefully (#37782)
    • Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 (#37771)
    • Ci: split giteabot workflow (#37770)
    • Fix(deps): update npm dependencies (#37768)
    • Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go (#37764)
    • Fix(deps): update module google.golang.org/grpc to v1.81.1 (#37762)
    • Ci: fix cache-related issues (#37761)
    • Chore: fix tests (#37760)
    • Fix(deps): update module github.com/google/go-github/v85 to v86 (#37754)
    • Fix(deps): update npm dependencies (#37753)
    • Fix(deps): update go dependencies (#37752)
    • Chore(deps): update action dependencies (#37751)
    • Fix(markup): wrap indented code blocks for the code-copy button (#37748)
    • Chore(db): introduce db.Session and db.EngineMigration interfaces (#37746)
    • Feat(web): also display PR counts in repo list (#37739)
    • Refactor(glob): use strings.Builder for regexp compilation (#37730)
    • Chore(doctor): remove four obsolete doctor check implementations (#37728)
    • Refactor(org): simplify owner-team org repo creation logic (#37727)
    • Refactor: move workflowpattern into modules/actions (#37717)
    • Chore: clean up tests (#37715)
    • Style: misc UI fixes (#37691)
    • Ci: add shellcheck linter (#37682)
    • Fix: catch and fix more lint problems (#37674)
    • Fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test (#37662)
    • Fix(deps): update npm dependencies (#37647)
    • Ci(renovate): update Go import paths on major bumps (#37641)
    • Fix(deps): update go dependencies (major) (#37639)
    • Chore(deps): update action dependencies (major) (#37638)
    • Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 (#37637)
    • Fix(deps): update npm dependencies (#37636)
    • Refactor(log): replace log.Critical with log.Error (#37624)
    • Build(deps): bump fast-uri from 3.1.0 to 3.1.2 (#37616)
    • Feat(oauth): Support AWS Cognito OAuth2 provider (#37607)
    • Chore(deps): update action dependencies (#37603)
    • Ci: allow chore type in PR title lint (#37575)
    • Refactor: only reset a database table when the table's data was changed (#37573)
    • Ci: increase renovate frequency and fix RENOVATE_ALLOWED_POST_UPGRADE_COMMANDS (#37565)
    • Refactor: use modernc sqlite driver as default (#37562)
    • Docs: fix 4 typos in CHANGELOG.md (#37549)
    • Fix(deps): update go dependencies (#37541)
    • Chore(deps): update action dependencies (#37540)
    • Refactor pull request view (6) (#37522)
    • Fix: redirect early CLI console logger to stderr (#37507)
    • Refactor "flex-list" to "flex-divided-list" (#37505)
    • Refactor compare diff/pull page (1) (#37481)
    • Refactor pull request view (4) (#37451)
    • Update 1.26.1 changelog in main (#37442)
    • Refactor: use named Permission field in Repository struct instead of anonymous embedding (#37441)
    • Refactor: serve site manifest via /assets/site-manifest.json endpoint (#37405)
    • Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites (#37364)
    • Update Block a user form (#37359)
    • Move review request functions to a standalone file (#37358)
    • Feat(security): set X-Content-Type-Options: nosniff by default (#37354)
    • Enable strict TypeScript, add errorMessage helper (#37292)
    • Refactor frontend tw-justify-between layouts to flex-left-right (#37291)
    • Update Nix flake (#37284)
    • Fix Repository transferring page (#37277)
    • Remove SubmitEvent polyfill (#37276)
    • Remove dead code identified by deadcode tool (#37271)
    • Upgrade go-git to v5.18.0 (#37268)
    • Don't add useless labels which will bother changelog generation (#37267)
    • Move heatmap to first-party code (#37262)
    • Tests/integration: simplify code (#37249)
    • Add pagination and search box to org teams list (#37245)
    • Remove error returns from crypto random helpers and callers (#37240)
    • Add ExternalIDClaim option for OAuth2 OIDC auth source (#37229)
    • Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries (#37210)
    • Refactor "htmx" to "fetch action" (#37208)
    • Update go js py dependencies (#37204)
    • Add comment for the design of "user activity time" (#37195)
    • Remove outdated RunUser logic (#37180)
    • Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files (#37150)
    • Update javascript dependencies (#37142)
    • Update go dependencies (#37141)
    • Frontport changelog of v1.26.0-rc0 (#37138)
    • Introduce ActionRunAttempt to represent each execution of a run (#37119)
    • Workflow Artifact Info Hover (#37100)
    • Extend issue context popup beyond markdown content (#36908)
    • Add bulk repository deletion for organizations (#36763)
    • Feat: Add bypass allowlist for branch protection (#36514)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

View originalPermalink
How v1.27.0 went

v1.27.0-rc0

Pre-release
Added 13
  • Add workflow status badge modal
  • Support owner-level and global scoped workflows
  • Support ref suffixes in compare API
  • Implement jobs.<job_id>.continue-on-error in actions
  • Show run status on browser tab favicon
  • Add token introspection and self-deletion endpoint
Changed 2
  • Improve support for reusable workflows
  • Use Content-Security-Policy with script nonce
Security 5
  • Update go-git/go-git/v5 to v5.19.1 for security fixes
  • Restrict OAuth introspection to the token's client
  • Do not expose private org membership via public_members API
  • Deny fork-PR cross-repo access via collaborative owner in actions
  • Prevent path traversal in repository restore migrations
  • BREAKING

    • Feat(actions)!: improve support for reusable workflows (#37478)
    • Use Content-Security-Policy: script nonce (#37232)
  • SECURITY

    • Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#37786)
    • Fix(oauth): restrict introspection to the token's client (#38042)
    • Fix(api): don't expose private org membership via public_members (#38145)
    • Fix(actions): deny fork-PR cross-repo access via collaborative owner (#38214)
    • Fix(migrations): prevent path traversal in repository restore (#38215)
  • FEATURES

    • Feat(actions): add workflow status badge modal (#38196)
    • Feat(actions): support owner-level and global scoped workflows (#38154)
    • Feat(api): support ref suffixes in compare (#38148)
    • Feat(actions): implement jobs.<job_id>.continue-on-error (#38100)
    • Feat(actions): show run status on browser tab favicon (#38071)
    • Feat(api): add token introspection and self-deletion endpoint (#37995)
    • Feat(api): add q parameter to list branches API for server-side filtering (#37982)
    • Feat(repo): split repository creation limit into user and org scopes (#37872)
    • Feat(actions): bulk delete, disable and enable runners in admin UI (#37869)
    • Feat(actions): List workflows that were executed once but got removed from the default branch (#37835)
    • Feat(org): add team visibility so org members can discover teams (#37680)
    • Feat: add raw diff/patch endpoint for repository comparisons (#37632)
    • Feat: Add avatar stacks (#37594)
    • Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) (#37500)
    • Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support (#37433)
    • Support for Custom URI Schemes in OAuth2 Redirect URIs (#37356)
    • Feat(orgs): Add search bar for organization members tab page (#37347)
    • Feat(api): Add assignees APIs (#37330)
    • Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs (#37196)
    • Serve OpenAPI 3.0 spec at /openapi.v1.json (#37038)
    • Add project column picker to issue and pull request sidebar (#37037)
    • Allow multiple projects per issue and pull requests (#36784)
    • Feat(ui): add "follow rename" to file commit history list (#34994)
    • Feat(ssh): auto generate additional ssh keys (#33974)
  • ENHANCEMENTS

    • Enhance: allow builtin default git config options to be overridden (#38172)
    • Enhance: allow MathML core elements (#38034)
    • Enhance(markup): improve issue title rendering (#37908)
    • Enhance(actions): set descriptive browser tab title on run view (#37870)
    • Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 (#37866)
    • Enhance(actions): show workflow name from YAML instead of filename (#37833)
    • Feat(actions): add before/after to PR synchronize event payload (#37827)
    • Enhance(actions): add branch filters to run list (#37826)
    • Enhance(actions): Make Summary UI more beautiful with more infos (#37824)
    • Feat: add copy button to action step header, improve other copy buttons (#37744)
    • Fix(icon): use repo-forked icon to display forks count (#37731)
    • Feat(api): add sort and order query parameters to job list endpoints (#37672)
    • Feat(api): add last_sync to repository API (#37566)
    • Enhance: Adjust Workflow Graph styling (#37497)
    • Improve code editor text selection and clean up lint enablement (#37474)
    • Add mirror auth updates to repo edit API and settings (#37468)
    • Replace olivere/elastic with REST API client, add OpenSearch support (#37411)
    • Feat: Add default PR branch update style setting (#37410)
    • Fix inconsistent disabled styling on logged-out repo header buttons (#37406)
    • Allow fast-forward-only merge when signed commits are required (#37335)
    • Enhance styling in actions page (#37323)
    • Fix: improve actions status icons and texts (#37206)
    • Make Markdown fenced code block work with more syntaxes (#37154)
    • Fix: Sort action run jobs by JobID and Name with matrix examples (#37046)
    • Add API endpoint to reply to pull request review comments (#36683)
  • PERFORMANCE

    • Perf(web): sort the action_run query by a repo-scoped index when possible (#38155)
    • Perf: Various performance regression fixes (#38078)
    • Perf: extend action c_u index to include created_unix for faster dashboard feeds (#38076)
    • Batch-load related data in actions run, job, and task API endpoints (#37032)
  • BUGFIXES

    • Fix: update npm dependencies, fix misc issues (#38257)
    • Fix(api): respect since/until when counting commits for X-Total-Count (#38204)
    • Fix: codemirror regressions (#38248)
    • Fix(api): support HEAD requests on all API GET endpoints (#38245)
    • Fix(actions): Cleanup workflow status badge code (#38241)
    • Fix(web): Correctly align the "disabled" label on larger workflow names (#38240)
    • Fix(actions): don't swallow HTML entities into linkified URLs (#38239)
    • Fix(packages): accept npm "repository" and "bin" in string form (#38236)
    • Fix(actions): fix 500 error when canceling a canceling task (#38223)
    • Fix(deps): update module golang.org/x/image to v0.43.0 [security] (#38219)
    • Fix(mssql): convert legacy DATETIME columns to DATETIME2 (#38216)
    • Fix(api): deny private org member enumeration via /members (#38213)
    • Fix(actions): ensure all waiting jobs get runners in large workflows (#38200)
    • Fix(deps): update go dependencies (#38194)
    • Fix(deps): update npm dependencies (#38193)
    • Fix(cli): default must-change-password to false for bot users (#38175)
    • Fix(actions): show run index in run view and fix summary graph height (#38165)
    • Fix: csp (#38162)
    • Fix(deps): update npm dependencies (#38123)
    • Fix(mssql): expand legacy issue and comment long-text columns (#38120)
    • Fix(packages): validate debian distribution and component names (#38116)
    • Fix(packages): validate module version in goproxy ParsePackage (#38104)
    • Fix(deps): update dependency esbuild to v0.28.1 [security] (#38097)
    • Fix: git push hook post receive (#38089)
    • Fix(ui): prevent commit status popup overflowing its row (#38081)
    • Fix: validate gem name in rubygems parseMetadataFile (#38061)
    • Fix: commit display name (#38057)
    • Fix: csp regressions (#38047)
    • Fix: api error message (#38031)
    • Fix(deps): update npm dependencies (#38029)
    • Fix: pgsql lint (#38022)
    • Fix(indexer): fix assignee filters in issue search (#38021)
    • Fix: various dropdown problems (#38020)
    • Fix: refactor git error handling and make archive streaming handle non-existing commit id (#38007)
    • Fix: raise git required version to 2.13 (#37996)
    • Fix: remove "no-transfrom" from the cache-control header (#37985)
    • Fix(deps): update module github.com/google/go-github/v87 to v88 (#37971)
    • Fix: use committer time where ever possible as default (#37969)
    • Fix(deps): update npm dependencies, remove nolyfill (#37968)
    • Fix(deps): update go dependencies (#37967)
    • Fix(pull): preserve squash message trailers and additional commit messages (#37954)
    • Fix(deps): update module golang.org/x/image to v0.41.0 [security] (#37904)
    • Fix: support ##[command] log prefix in action run UI (#37882)
    • Fix(deps): update module github.com/google/go-github/v86 to v87 (#37845)
    • Fix(deps): update npm dependencies (#37844)
    • Fix(deps): update go dependencies (#37841)
    • Fix(frontend): resolve Vite assets by manifest source path (#37836)
    • Fix(locales): Replace hardcoded strings (#37788)
    • Fix(packages): render markdown links relative to linked repo (#37676)
    • Fix: persist mirror repository metadata (#37519)
    • Fix cmd tests by mocking builtin paths (#37369)
    • Add form-fetch-action to some forms, fix "fetch action" resp bug (#37305)
    • Feat: execute post run cleanup when workflow is cancelled (#37275)
    • Fix relative-time error and improve global error handler (#37241)
    • Refactor flash message and remove SanitizeHTML template func (#37179)
  • TESTING

    • Test: speed up two tests (#37905)
    • Test: Fix random failure test (#37887)
    • Test: fix flaky issue-comment close test (#37880)
    • Test: enable WAL for sqlite integration tests (#37861)
    • Test: fix flaky TestResourceIndex and reduce its runtime (#37847)
    • Test: run TestAPIRepoMigrate offline via a local clone source (#37817)
    • Ci: shard tests and reduce redundant work (#37618)
    • Test(e2e): run playwright via container (#37300)
    • Remove external service dependencies in migration tests (#36866)
  • BUILD

    • Fix(actions): authenticate snapcraft before nightly remote build (#38252)
    • Ci: cap Elasticsearch heap in db-tests (#37816)
    • Build(snap): publish nightly version to snapcraft via actions (#37814)
    • Ci: split pgsql shards into plain jobs, dedupe setup actions (#37802)
    • Ci: narrow files-changed frontend filter (#37749)
    • Ci: add zizmor to lint-actions (#37720)
    • Chore: clean up "contrib" dir (#37690)
    • Fix: snap build (main branch) (#37685)
    • Ci: Also lint json5 files (#37659)
    • Feat(editor): broaden language detection in web code editor (#37619)
    • Build: update pnpm to v11 (#37591)
    • Refactor(deps): migrate from nektos/act fork to gitea/runner (#37557)
    • Refactor: lint bare fill/stroke colors, add vars for git graph color series (#37543)
    • Update go js py dependencies (#37525)
    • Ci: lint PR titles with commitlint (#37498)
    • Chore: upgrade Go version in devcontainer image to 1.26 (#37374)
    • Update GitHub Actions to latest major versions (#37313)
    • Update go js dependencies (#37312)
    • Fail vite build on rolldown warnings via NODE_ENV=test (#37270)
    • Remove htmx (#37224)
    • Replace custom Go formatter with golangci-lint fmt (#37194)
    • Refactor htmx and fetch-action related code (#37186)
    • Integrate renovate bot for all dependency updates (#37050)
    • Build(sign): move to sigstore (#38250)
  • DOCS

    • Docs: update changelog for 1.26.3 & 1.26.4 (#38178)
    • Docs: fix duplicated word in foreachref doc comment (#38161)
    • Docs: Clarify criteria for becoming a merger (#38113)
    • Docs: Publish TOC Election Result 2026 (#38111)
    • Docs: mark openapi3 as autogenerated in attributes (#37963)
    • Docs: add development setup guide (#37960)
  • MISC

    • Revert(sign): restore gpg (#38251)
    • Refactor: replace legacy delete-button with link-action (#38143)
    • Refactor(actions): read runner capabilities from proto field (#38068)
    • Refactor(api): clarify APIError message usage and fix legacy lint error (#38012)
    • Refactor: Use db.Get[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record (#37977)
    • Fix(deps): update go dependencies (#37851)
    • Ci: Fix sync PR labels from the conventional-commit title (#37784) (#37825)
    • Ci: tweak files-changed, add free-disk-space (#37819)
    • Fix(deps): update module golang.org/x/crypto to v0.52.0 [security] (#37806)
    • Test(e2e): add comment, release, star, PR and fork tests (#37800)
    • Chore: simplify issue and pull request templates (#37799)
    • Chore: Update giteabot to fix failure when backport (#37789)
    • Fix(api): handle partial failures in push mirror synchronization gracefully (#37782)
    • Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 (#37771)
    • Ci: split giteabot workflow (#37770)
    • Fix(deps): update npm dependencies (#37768)
    • Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go (#37764)
    • Fix(deps): update module google.golang.org/grpc to v1.81.1 (#37762)
    • Ci: fix cache-related issues (#37761)
    • Chore: fix tests (#37760)
    • Fix(deps): update module github.com/google/go-github/v85 to v86 (#37754)
    • Fix(deps): update npm dependencies (#37753)
    • Fix(deps): update go dependencies (#37752)
    • Chore(deps): update action dependencies (#37751)
    • Fix(markup): wrap indented code blocks for the code-copy button (#37748)
    • Chore(db): introduce db.Session and db.EngineMigration interfaces (#37746)
    • Feat(web): also display PR counts in repo list (#37739)
    • Refactor(glob): use strings.Builder for regexp compilation (#37730)
    • Chore(doctor): remove four obsolete doctor check implementations (#37728)
    • Refactor(org): simplify owner-team org repo creation logic (#37727)
    • Refactor: move workflowpattern into modules/actions (#37717)
    • Chore: clean up tests (#37715)
    • Style: misc UI fixes (#37691)
    • Ci: add shellcheck linter (#37682)
    • Fix: catch and fix more lint problems (#37674)
    • Fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test (#37662)
    • Fix(deps): update npm dependencies (#37647)
    • Ci(renovate): update Go import paths on major bumps (#37641)
    • Fix(deps): update go dependencies (major) (#37639)
    • Chore(deps): update action dependencies (major) (#37638)
    • Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 (#37637)
    • Fix(deps): update npm dependencies (#37636)
    • Refactor(log): replace log.Critical with log.Error (#37624)
    • Build(deps): bump fast-uri from 3.1.0 to 3.1.2 (#37616)
    • Feat(oauth): Support AWS Cognito OAuth2 provider (#37607)
    • Chore(deps): update action dependencies (#37603)
    • Ci: allow chore type in PR title lint (#37575)
    • Refactor: only reset a database table when the table's data was changed (#37573)
    • Ci: increase renovate frequency and fix RENOVATE_ALLOWED_POST_UPGRADE_COMMANDS (#37565)
    • Refactor: use modernc sqlite driver as default (#37562)
    • Docs: fix 4 typos in CHANGELOG.md (#37549)
    • Fix(deps): update go dependencies (#37541)
    • Chore(deps): update action dependencies (#37540)
    • Refactor pull request view (6) (#37522)
    • Fix: redirect early CLI console logger to stderr (#37507)
    • Refactor "flex-list" to "flex-divided-list" (#37505)
    • Refactor compare diff/pull page (1) (#37481)
    • Refactor pull request view (4) (#37451)
    • Update 1.26.1 changelog in main (#37442)
    • Refactor: use named Permission field in Repository struct instead of anonymous embedding (#37441)
    • Refactor: serve site manifest via /assets/site-manifest.json endpoint (#37405)
    • Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites (#37364)
    • Update Block a user form (#37359)
    • Move review request functions to a standalone file (#37358)
    • Feat(security): set X-Content-Type-Options: nosniff by default (#37354)
    • Enable strict TypeScript, add errorMessage helper (#37292)
    • Refactor frontend tw-justify-between layouts to flex-left-right (#37291)
    • Update Nix flake (#37284)
    • Fix Repository transferring page (#37277)
    • Remove SubmitEvent polyfill (#37276)
    • Remove dead code identified by deadcode tool (#37271)
    • Upgrade go-git to v5.18.0 (#37268)
    • Don't add useless labels which will bother changelog generation (#37267)
    • Move heatmap to first-party code (#37262)
    • Tests/integration: simplify code (#37249)
    • Add pagination and search box to org teams list (#37245)
    • Remove error returns from crypto random helpers and callers (#37240)
    • Add ExternalIDClaim option for OAuth2 OIDC auth source (#37229)
    • Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries (#37210)
    • Refactor "htmx" to "fetch action" (#37208)
    • Update go js py dependencies (#37204)
    • Add comment for the design of "user activity time" (#37195)
    • Remove outdated RunUser logic (#37180)
    • Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files (#37150)
    • Update javascript dependencies (#37142)
    • Update go dependencies (#37141)
    • Frontport changelog of v1.26.0-rc0 (#37138)
    • Introduce ActionRunAttempt to represent each execution of a run (#37119)
    • Workflow Artifact Info Hover (#37100)
    • Extend issue context popup beyond markdown content (#36908)
    • Add bulk repository deletion for organizations (#36763)
    • Feat: Add bypass allowlist for branch protection (#36514)
View originalPermalink
How v1.27.0-rc0 went

v1.26.4

Fixed 1
  • Walk git log context error handling
Security 1
  • Do not auto-reactivate disabled users on OAuth2 callback
  • SECURITY

    • fix(auth): do not auto-reactivate disabled users on OAuth2 callback (#38009) (#38183)
  • BUGFIXES

    • fix: walk git log context error handling (#38182) (#38185)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

View originalPermalink
How v1.26.4 went

v1.26.3

Added 1
  • Add Link header in ListForks API endpoint
Changed 1
  • Require merged PR to bypass fork PR approval gate in actions
Fixed 8
  • Fix panic when SSH remote LFS endpoint parsing fails
  • Fix nil pointer panic when filtering tracked times by a non-existent user
  • Keep literal false value displayed in workflow_dispatch choice dropdowns
  • Parse HEAD ref correctly
  • Generate notes for initial tag in releases
  • Return 404 when action job log blob is missing
  • Exclude workflow_call from workflow trigger detection in actions
  • Clear stale ReviewTypeRequest when submitting pending review on issues
Security 10
  • Patch incorrect private list in hostmatcher
  • Apply various security fixes
  • Allow git clone of private repositories with anonymous code access
  • Ignore stale OIDC external login links to organizations in authentication
  • Block reserved IP ranges from external and private filters in hostmatcher
  • Require Code-unit access for cross-repository LFS object reuse

[!WARNING] Please upgrade to 1.26.4 directly. A regression in this release can cause "context deadline exceeded" errors when opening any repository's code pages (#38177). Please hold off on upgrading until a fix is released.

  • BREAKING

    • fix(actions)!: require merged PR to bypass fork PR approval gate (#38010) (#38041)
  • SECURITY

    • fix(hostmatcher): patch incorrect private list (#38170) (#38173)
    • fix: Various security fixes (#38103) (#38151)
    • fix: Various sec fixes (#38108) (#38147)
    • fix: allow git clone of private repos with anonymous code access (#38074) (#38146)
    • fix(auth): ignore stale OIDC external login links to organizations (#37875) (#38141)
    • fix(hostmatcher): block reserved IP ranges from external/private filters (#38039) (#38059)
    • fix(lfs): require Code-unit access for cross-repo LFS object reuse (#38006) (#38050)
    • fix(lfs): reject unknown SSH LFS sub-verbs to prevent auth bypass (#38008) (#38015)
    • fix: bound CODEOWNERS regex match time (#38011) (#38025)
    • fix: bound debian ParseControlFile to a single control stanza (#38044) (#38055)
    • fix(deps): update module golang.org/x/net to v0.55.0 [security] (#37813) (#37829)
  • API

    • feat(api): add Link header in ListForks (#38052) (#38063)
  • BUGFIXES

    • fix: Fix the panic when ssh remote lfs endpoint parsing failure (#38026) (#38158)
    • fix(api): nil pointer panic when filtering tracked times by a non-existent user (#38112) (#38115)
    • fix: keep literal "false" value displayed in workflow_dispatch choice dropdowns (#38080) (#38096)
    • fix: parse HEAD ref (#38119)
    • fix: git cmd (#38084) (#38087)
    • fix(releases): generate notes for initial tag (#37697) (#37986)
    • fix(actions): return 404 when job log blob is missing (#38003) (#38004)
    • fix(actions): exclude workflow_call from workflow trigger detection (#37894) (#37899)
    • fix(actions): keep action run title clickable when commit subject is a URL (#37867) (#37898)
    • fix(actions): reject workflow_dispatch for workflows without that trigger (#37660) (#37895)
    • fix(actions): ack re-sent UpdateLog finalize idempotently (#37885) (#37892)
    • fix: http content file render (#37850) (#37856)
    • fix(issues): clear stale ReviewTypeRequest when submitting pending review (#37809) (#37815)
    • fix: Fix issue target branch selection for non-collaborators (#36916) (#38164)
  • BUILD

    • fix(deps): update @playwright/test to 1.60.0 (#38144)
    • ci: add tools/ci-tools.ts for the PR labeler workflow (#37831)
    • fix(build): swagger css import (#37801) (#37803)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

View originalPermalink
How v1.26.3 went

v1.26.2

Fixed 4
  • Handle empty pull request files view to allow reviews
  • Make RenderString never fail
  • Add natural sort to sortTreeViewNodes
  • Fix package creation unique conflict
Security 16
  • Fix reading permission
  • Make artifact signature payloads unambiguous
  • Unify public-only token filtering in API queries and repo access checks
  • Add missed token scope checking
  • Bind token exchanges to the original client request
  • Strengthen PKCE validation and refresh token replay protection
  • SECURITY

    • fix(permissions): Fix reading permission (#37769)
    • fix(actions): make artifact signature payloads unambiguous (#37707)
    • fix: Unify public-only token filtering in API queries and repo access checks (#37118)
    • fix: Add missed token scope checking (#37735)
    • fix(oauth): bind token exchanges to the original client request (#37704)
    • fix(oauth): strengthen PKCE validation and refresh token replay protection (#37706)
    • fix(web): enforce token scopes on raw, media, and attachment downloads (#37698)
    • fix(security): enforce wiki git writes and LFS token access at request time (#37695)
    • feat(api): encrypt AWS creds (#37679)
    • fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test
    • fix(packages): Add label for private and internal package and fix composor package source permission check (#37610)
    • fix(git): Fix smart http request scope bug (#37583)
    • Fix basic auth bug (#37503)
    • Fix allow maintainer edit permission check (#37479) (#37484)
    • Fix URL sanitization to handle schemeless credentials (#37440) (#37471)
    • Fix attachment Content-Security-Policy (#37455) (#37464)
    • chore(deps): bump go-git/go-git/v5 to 5.19.0 (#37608)
  • BUGFIXES

    • fix(pull): handle empty pull request files view to allow reviews (#37783)
    • fix(markup): make RenderString never fail (#37779)
    • fix: add natural sort to sortTreeViewNodes (#37772)
    • fix: package creation unique conflict (#37774)
    • fix!: add DEFAULT_TITLE_SOURCE setting for pull request title default behavior (#37465)
    • fix: Allow direct commits for unprotected files with push restrictions (#37657)
    • fix(actions): wrong assumption that run id always >= job id (#37737)
    • fix(auth): set User-Agent on avatar fetch and sync avatar on link-account register (#37564) (#37588)
    • fix(actions): deadlock between PrepareRunAndInsert and UpdateTaskByState (#37692)
    • fix(repo): /generate must sync the branch table for the new repo (#37693)
    • build: Fix snap build (1.26)
    • fix(actions): run TransferLogs on UpdateLog{Rows:[], NoMore:true} (#37631)
    • fix show correct mergebase
    • fix: make clone URL respect public URL detection setting (#37615)
    • fix: "run as root" check (#37622)
    • chore(deps): update dependency go to v1.26.3 (#37601)
    • Compare dropdown fails when selecting branch with no common merge-base (#37470)
    • fix: treat email addresses case-insensitively (#37600)
    • fix(actions): fix blank lines after ::endgroup:: (#37597)
    • fix(actions): report individual step status in workflow job API response (#37592)
    • fix: Invalid UTF-8 commit messages in JSON API responses (#37542)
    • fix: use consistent GetUser family functions (#37553)
    • fix(api): return 409 message instead of empty JSON for wrong commit id (#37572)
    • fix(actions): prevent panic when workflow contains null jobs (#37570)
    • Make ServeSetHeaders default to download attachment if filename exists (#37552) (#37555)
    • Fix(actions): validate workflow param to prevent 500 error (#37546) (#37554)
    • Don't unblock run-level-concurrency-blocked runs in the resolver (#37461) (#37538)
    • Fix(packages): use file names for generic web downloads (#37514) (#37520)
    • Fix merge autodetect can't close other PRs but only the last one when multiple PRs are pushed at once (#37512) (#37516)
    • Fix update branch protection order (#37508) (#37513)
    • Fix mCaptcha broken after Vite migration (#37492) (#37509)
    • Fix review submission from single-commit PR view (#37475) (#37485)
    • Fix scheduled action panic with null event payload (#37459) (#37466)
    • Make GetPossibleUserByID can handle deleted user (#37430) (#37431)
    • Remove excessive quote from terraform instructions (#37424) (#37426)
    • Fix color regressions, add priority color (#37417) (#37421)
  • MISC

    • Add CurrentURL template variable back (#37444) (#37449)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

View originalPermalink
How v1.26.2 went

v1.26.1

  • BUGFIXES
    • Add event.schedule context for schedule actions task (#37320) (#37348)
    • Fix an issue where changing an organization's visibility caused problems when users had forked its repositories. (#37324) (#37344)
    • Use modern "git update-index --cacheinfo" syntax to support more file names (#37338) (#37343)
    • Fix URL related escaping for oauth2 (#37334) (#37340)
    • When the requested arch rpm is missing fall back to noarch (#37236) (#37339)
    • Fix actions concurrency groups cross-branch leak (#37311) (#37331)
    • Fix bug when accessing user badges (#37321) (#37329)
    • Fix AppFullLink (#37325) (#37328)
    • Fix container auth for public instance (#37290) (#37294)
    • Enhance GetActionWorkflow to support fallback references (#37189) (#37283)
    • Fix vite manifest update masking build errors (#37279) (#37310)
    • Fix Mermaid diagrams failing when node labels contain line breaks (#37296) (#37299)
    • Use TriggerEvent instead of Event in workflow runs API response for scheduled runs (#37288) #37360
    • Add URL to Learn more about blocking a user. (#37355) #37367
    • Fix button layout shift when collapsing file tree in editor (#37363) #37375
    • Fix org team assignee/reviewer lookups for team member permissions (#37365) #37391
    • Fix repo init README EOL (#37388) #37399
    • Fix: dump with default zip type produces uncompressed zip (#37401)#37402

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

View originalPermalink
How v1.26.1 went

v1.26.0

  • BREAKING
    • Correct swagger annotations for enums, status codes, and notification state (#37030)
    • Remove GET API registration-token (#36801)
    • Support Actions concurrency syntax (#32751)
    • Make PUBLIC_URL_DETECTION default to "auto" (#36955)
  • SECURITY
    • Bound PageSize in ListUnadoptedRepositories (#36884)
  • FEATURES
    • Support Actions concurrency syntax (#32751)
    • Add terraform state registry (#36710)
    • Instance-wide (global) info banner and maintenance mode (#36571)
    • Support rendering OpenAPI spec (#36449)
    • Add keyboard shortcuts for repository file and code search (#36416)
    • Add support for archive-upload rpc (#36391)
    • Add ability to download subpath archive (#36371)
    • Add workflow dependencies visualization (#26062) (#36248) & Restyle Workflow Graph (#36912)
    • Automatic generation of release notes (#35977)
    • Add "Go to file", "Delete Directory" to repo file list page (#35911)
    • Introduce "config edit-ini" sub command to help maintaining INI config file (#35735)
    • Add button to re-run failed jobs in Actions (#36924)
    • Support actions and reusable workflows from private repos (#32562)
    • Add summary to action runs view (#36883)
    • Add user badges (#36752)
    • Add configurable permissions for Actions automatic tokens (#36173)
    • Add per-runner "Disable/Pause" (#36776)
    • Feature non-zipped actions artifacts (action v7 / nodejs / npm v6.2.0) (#36786)
  • PERFORMANCE
    • WorkflowDispatch API optionally return runid (#36706)
    • Add render cache for SVG icons (#36863)
    • Load mentionValues asynchronously (#36739)
    • Lazy-load some Vue components, fix heatmap chunk loading on every page (#36719)
    • Load heatmap data asynchronously (#36622)
    • Use prev/next pagination for user profile activities page to speed up (#36642)
    • Refactor cat-file batch operations and support --batch-command approach (#35775)
    • Use merge tree to detect conflicts when possible (#36400)
  • ENHANCEMENTS
    • Implement logout redirection for reverse proxy auth setups (#36085) (#37171)
    • Adds option to force update new branch in contents routes (#35592)
    • Add viewer controller for mermaid (zoom, drag) (#36557)
    • Add code editor setting dropdowns (#36534)
    • Add elk layout support to mermaid (#36486)
    • Add resolve/unresolve review comment API endpoints (#36441)
    • Allow configuring default PR base branch (fixes #36412) (#36425)
    • Add support for RPM Errata (updateinfo.xml) (#37125)
    • Require additional user confirmation for making repo private (#36959)
    • Add actions.WORKFLOW_DIRS setting (#36619)
    • Avoid opening new tab when downloading actions logs (#36740)
    • Implements OIDC RP-Initiated Logout (#36724)
    • Show workflow link (#37070)
    • Desaturate dark theme background colors (#37056)
    • Refactor "org teams" page and help new users to "add member" to an org (#37051)
    • Add webhook name field to improve webhook identification (#37025) (#37040)
    • Make task list checkboxes clickable in the preview tab (#37010)
    • Improve severity labels in Actions logs and tweak colors (#36993)
    • Linkify URLs in Actions workflow logs (#36986)
    • Allow text selection on checkbox labels (#36970)
    • Support dark/light theme images in markdown (#36922)
    • Enable native dark mode for swagger-ui (#36899)
    • Rework checkbox styling, remove input border hover effect (#36870)
    • Refactor storage content-type handling of ServeDirectURL (#36804)
    • Use "Enable Gravatar" but not "Disable" (#36771)
    • Use case-insensitive matching for Git error "Not a valid object name" (#36728)
    • Add "Copy Source" to markup comment menu (#36726)
    • Change image transparency grid to CSS (#36711)
    • Add "Run" prefix for unnamed action steps (#36624)
    • Persist actions log time display settings in localStorage (#36623)
    • Use first commit title for multi-commit PRs and fix auto-focus title field (#36606)
    • Improve BuildCaseInsensitiveLike with lowercase (#36598)
    • Improve diff highlighting (#36583)
    • Exclude cancelled runs from failure-only email notifications (#36569)
    • Use full-file highlighting for diff sections (#36561)
    • Color command/error logs in Actions log (#36538)
    • Add paging headers (#36521)
    • Improve timeline entries for WIP prefix changes in pull requests (#36518)
    • Add FOLDER_ICON_THEME configuration option (#36496)
    • Normalize guessed languages for code highlighting (#36450)
    • Add chunked transfer encoding support for LFS uploads (#36380)
    • Indicate when only optional checks failed (#36367)
    • Add 'allow_maintainer_edit' API option for creating a pull request (#36283)
    • Support closing keywords with URL references (#36221)
    • Improve diff file headers (#36215)
    • Fix and enhance comment editor monospace toggle (#36181)
    • Add git.DIFF_RENAME_SIMILARITY_THRESHOLD option (#36164)
    • Add matching pair insertion to markdown textarea (#36121)
    • Add sorting/filtering to admin user search API endpoint (#36112)
    • Allow action user have read permission in public repo like other user (#36095)
    • Disable matchBrackets in monaco (#36089)
    • Use GitHub-style commit message for squash merge (#35987)
    • Make composer registry support tar.gz and tar.bz2 and fix bugs (#35958)
    • Add GITEA_PR_INDEX env variable to githooks (#35938)
    • Add proper error message if session provider can not be created (#35520)
    • Add button to copy file name in PR files (#35509)
    • Move X_FRAME_OPTIONS setting from cors to security section (#30256)
    • Add placeholder content for empty content page (#37114)
    • Add DEFAULT_DELETE_BRANCH_AFTER_MERGE setting (#36917)
    • Redirect to the only OAuth2 provider when no other login methods and fix various problems (#36901)
    • Add admin badge to navbar avatar (#36790)
    • Add never option to PUBLIC_URL_DETECTION configuration (#36785)
    • Add background and run count to actions list page (#36707)
    • Add icon to buttons "Close with Comment", "Close Pull Request", "Close Issue" (#36654)
    • Add support for in_progress event in workflow_run webhook (#36979)
    • Report commit status for pull_request_review events (#36589)
    • Render merged pull request title as such in dashboard feed (#36479)
    • Feature to be able to filter project boards by milestones (#36321)
    • Use user id in noreply emails (#36550)
    • Enable pagination on GiteaDownloader.getIssueReactions() (#36549)
    • Remove striped tables in UI (#36509)
    • Improve control char rendering and escape button styling (#37094)
    • Support legacy run/job index-based URLs and refactor migration 326 (#37008)
    • Add date to "No Contributions" tooltip (#36190)
    • Show edit page confirmation dialog on tree view file change (#36130)
    • Mention proc-receive in text for dashboard.resync_all_hooks func (#35991)
    • Reuse selectable style for wiki (#35990)
    • Support blue yellow colorblind theme (#35910)
    • Support selecting theme on the footer (#35741)
    • Improve online runner check (#35722)
    • Add quick approve button on PR page (#35678)
    • Enable commenting on expanded lines in PR diffs (#35662)
    • Print PR-Title into tooltip for actions (#35579)
    • Use explicit, stronger defaults for newly generated repo signing keys for Debian (#36236)
    • Improve the compare page (#36261)
    • Unify repo names in system notices (#36491)
    • Move package settings to package instead of being tied to version (#37026)
    • Add Actions API rerun endpoints for runs and jobs (#36768)
    • Add branch_count to repository API (#35351) (#36743)
    • Add created_by filter to SearchIssues (#36670)
    • Allow admins to rename non-local users (#35970)
    • Support updating branch via API (#35951)
    • Add an option to automatically verify SSH keys from LDAP (#35927)
    • Make "update file" API can create a new file when SHA is not set (#35738)
    • Update issue.go with labels documentation (labels content, not ids) (#35522)
    • Expose content_version for optimistic locking on issue and PR edits (#37035)
    • Pass ServeHeaderOptions by value instead of pointer, fine tune httplib tests (#36982)
  • BUGFIXES
    • Frontend iframe renderer framework: 3D models, OpenAPI (#37233) (#37273)
    • Fix CODEOWNERS absolute path matching. (#37244) (#37264)
    • Swift registry metadata: preserve more JSON fields and accept empty metadata (#37254) (#37261)
    • Fix user ssh key exporting and tests (#37256) (#37258)
    • Fix team member avatar size and add tooltip (#37253)
    • Fix commit title rendering in action run and blame (#37243) (#37251)
    • Fix corrupted JSON caused by goccy library (#37214) (#37220)
    • Add test for "fetch redirect", add CSS value validation for external render (#37207) (#37216)
    • Fix incorrect concurrency check (#37205) (#37215)
    • Fix handle missing base branch in PR commits API (#37193) (#37203)
    • Fix encoding for Matrix Webhooks (#37190) (#37201)
    • Fix handle fork-only commits in compare API (#37185) (#37199)
    • Indicate form field readonly via background, fix RunUser config (#37175, #37180) (#37178)
    • Report structurally invalid workflows to users (#37116) (#37164)
    • Fix API not persisting pull request unit config when has_pull_requests is not set (#36718)
    • Rename CSS variables and improve colorblind themes (#36353)
    • Hide add-matcher and remove-matcher from actions job logs (#36520)
    • Prevent navigation keys from triggering actions during IME composition (#36540)
    • Fix vertical alignment of .commit-sign-badge children (#36570)
    • Fix duplicate startup warnings in admin panel (#36641)
    • Fix CODEOWNERS review request attribution using comment metadata (#36348)
    • Fix HTML tags appearing in wiki table of contents (#36284)
    • Fix various bugs (#37096)
    • Fix various legacy problems (#37092)
    • Fix RPM Registry 404 when package name contains 'package' (#37087)
    • Merge some standalone Vite entries into index.js (#37085)
    • Fix various problems (#37077)
    • Fix issue label deletion with Actions tokens (#37013)
    • Hide delete branch or tag buttons in mirror or archived repositories. (#37006)
    • Fix org contact email not clearable once set (#36975)
    • Fix a bug when forking a repository in an organization (#36950)
    • Preserve sort order of exclusive labels from template repo (#36931)
    • Make container registry support Apple Container (basic auth) (#36920)
    • Fix the wrong push commits in the pull request when force push (#36914)
    • Add class "list-header-filters" to the div for projects (#36889)
    • Fix dbfs error handling (#36844)
    • Fix incorrect viewed files counter if reverted change was viewed (#36819)
    • Refactor avatar package, support default avatar fallback (#36788)
    • Fix README symlink resolution in subdirectories like .github (#36775)
    • Fix CSS stacking context issue in actions log (#36749)
    • Add gpg signing for merge rebase and update by rebase (#36701)
    • Delete non-exist branch should return 404 (#36694)
    • Fix TestActionsCollaborativeOwner (#36657)
    • Fix multi-arch Docker build SIGILL by splitting frontend stage (#36646)
    • Fix linguist-detectable attribute being ignored for configuration files (#36640)
    • Fix state desync in ComboMarkdownEditor (#36625)
    • Unify DEFAULT_SHOW_FULL_NAME output in templates and dropdown (#36597)
    • Pull Request Pusher should be the author of the merge (#36581)
    • Fix various version parsing problems (#36553)
    • Fix highlight diff result (#36539)
    • Fix mirror sync parser and fix mirror messages (#36504)
    • Fix bug when list pull request commits (#36485)
    • Fix various bugs (#36446)
    • Fix issue filter menu layout (#36426)
    • Restrict branch naming when new change matches with protection rules (#36405)
    • Fix link/origin referrer and login redirect (#36279)
    • Generate IDs for HTML headings without id attribute (#36233)
    • Use a migration test instead of a wrong test which populated the meta test repositories and fix a migration bug (#36160)
    • Fix issue close timeline icon (#36138)
    • Fix diff blob excerpt expansion (#35922)
    • Fix external render (#35727)
    • Fix review request webhook bug (#35339) (#35723)
    • Fix shutdown waitgroup panic (#35676)
    • Cleanup ActionRun creation (#35624)
    • Fix possible bug when migrating issues/pull requests (#33487)
    • Various fixes (#36697)
    • Apply notify/register mail flags during install load (#37120)
    • Repair duration display for bad stopped timestamps (#37121)
    • Fix(upgrade.sh): use HTTPS for GPG key import and restore SELinux context after upgrade (#36930)
    • Fix various trivial problems (#36921)
    • Fix various trivial problems (#36953)
    • Fix NuGet package upload error handling (#37074)
    • Fix CodeQL code scanning alerts (#36858)
    • Refactor issue sidebar and fix various problems (#37045)
    • Fix various problems (#37029)
    • Fix relative-time RangeError (#37021)
    • Fix chroma lexer mapping (#36629)
    • Fix typos and grammar in English locale (#36751)
    • Fix milestone/project text overflow in issue sidebar (#36741)
    • Fix no-content message not rendering after comment edit (#36733)
    • Fix theme loading in development (#36605)
    • Fix workflow run jobs API returning null steps (#36603)
    • Fix timeline event layout overflow with long content (#36595)
    • Fix minor UI issues in runner edit page (#36590)
    • Fix incorrect vendored detections (#36508)
    • Fix editorconfig not respected in PR Conversation view (#36492)
    • Don't create self-references in merged PRs (#36490)
    • Fix potential incorrect runID in run status update (#36437)
    • Fix file-tree ui error when adding files to repo without commits (#36312)
    • Improve image captcha contrast for dark mode (#36265)
    • Fix panic in blame view when a file has only a single commit (#36230)
    • Fix spelling error in migrate-storage cmd utility (#36226)
    • Fix code highlighting on blame page (#36157)
    • Fix nilnil in onedev downloader (#36154)
    • Fix actions lint (#36029)
    • Fix oauth2 session gob register (#36017)
    • Fix Arch repo pacman.conf snippet (#35825)
    • Fix a number of strictNullChecks-related issues (#35795)
    • Fix URLJoin, markup render link reoslving, sign-in/up/linkaccount page common data (#36861)
    • Hide delete directory button for mirror or archive repository and disable the menu item if user have no permission (#36384)
    • Update message severity colors, fix navbar double border (#37019)
    • Inline and lazy-load EasyMDE CSS, fix border colors (#36714)
    • Closed milestones with no issues now show as 100% completed (#36220)
    • Add test for ExtendCommentTreePathLength migration and fix bugs (#35791)
    • Only turn links to current instance into hash links (#36237)
    • Fix typos in code comments: doesnt, dont, wont (#36890)
  • REFACTOR
    • Clean up and improve non-gitea js error filter (#37148) (#37155)
    • Always show owner/repo name in compare page dropdowns (#37172) (#37200)
    • Remove dead CSS rules (#37173) (#37177)
    • Replace Monaco with CodeMirror (#36764)
    • Replace CSRF cookie with CrossOriginProtection (#36183)
    • Replace index with id in actions routes (#36842)
    • Remove unnecessary function parameter (#35765)
    • Move jobparser from act repository to Gitea (#36699)
    • Refactor compare router param parse (#36105)
    • Optimize 'refreshAccesses' to perform update without removing then adding (#35702)
    • Clean up checkbox cursor styles (#37016)
    • Remove undocumented support of signing key in the repository git configuration file (#36143)
    • Switch cmd/ to use constructor functions. (#36962)
    • Use relative-time to render absolute dates (#36238)
    • Some refactors about GetMergeBase (#36186)
    • Some small refactors (#36163)
    • Use gitRepo as parameter instead of repopath when invoking sign functions (#36162)
    • Move blame to gitrepo (#36161)
    • Move some functions to gitrepo package to reduce RepoPath reference directly (#36126)
    • Use gitrepo's clone and push when possible (#36093)
    • Remove mermaid margin workaround (#35732)
    • Move some functions to gitrepo package (#35543)
    • Move GetDiverging functions to gitrepo (#35524)
    • Use global lock instead of status pool for cron lock (#35507)
    • Use explicit mux instead of DefaultServeMux (#36276)
    • Use gitrepo's push function (#36245)
    • Pass request context to generateAdditionalHeadersForIssue (#36274)
    • Move assign project when creating pull request to the same database transaction (#36244)
    • Move catfile batch to a sub package of git module (#36232)
    • Use gitrepo.Repository instead of wikipath (#35398)
    • Use experimental go json v2 library (#35392)
    • Refactor template render (#36438)
    • Refactor GetRepoRawDiffForFile to avoid unnecessary pipe or goroutine (#36434)
    • Refactor text utility classes to Tailwind CSS (#36703)
    • Refactor git command stdio pipe (#36422)
    • Refactor git command context & pipeline (#36406)
    • Refactor git command stdio pipe (#36393)
    • Remove unused functions (#36672)
    • Refactor Actions Token Access (#35688)
    • Move commit related functions to gitrepo package (#35600)
    • Move archive function to repo_model and gitrepo (#35514)
    • Move some functions to gitrepo package (#35503)
    • Use git model to detect whether branch exist instead of gitrepo method (#35459)
    • Some refactor for repo path (#36251)
    • Extract helper functions from SearchIssues (#36158)
    • Refactor merge conan and container auth preserve actions taskID (#36560)
    • Refactor Nuget Auth to reuse Basic Auth Token Validation (#36558)
    • Refactor ActionsTaskID (#36503)
    • Refactor auth middleware (#36848)
    • Refactor code render and render control chars (#37078)
    • Clean up AppURL, remove legacy origin-url webcomponent (#37090)
    • Remove util.URLJoin and replace all callers with direct path concatenation (#36867)
    • Replace legacy tw-flex utility classes with flex-text-block/inline (#36778)
    • Mark unused&immature activitypub as "not implemented" (#36789)
  • TESTING
    • Add e2e tests for server push events (#36879)
    • Rework e2e tests (#36634)
    • Add e2e reaction test, improve accessibility, enable parallel testing (#37081)
    • Increase e2e test timeouts on CI to fix flaky tests (#37053)
  • BUILD
    • Upgrade go-git to v5.18.0 (#37269)
    • Replace rollup-plugin-license with rolldown-license-plugin (#37130) (#37158)
    • Bump min go version to 1.26.2 (#37139) (#37143)
    • Convert locale files from ini to json format (#35489)
    • Bump golangci-lint to 2.7.2, enable modernize stringsbuilder (#36180)
    • Port away from flake-utils (#35675)
    • Remove nolint (#36252)
    • Update the Unlicense copy to latest version (#36636)
    • Update to go 1.26.0 and golangci-lint 2.9.0 (#36588)
    • Replace google/go-licenses with custom generation (#36575)
    • Update go dependencies (#36548)
    • Bump appleboy/git-push-action from 1.0.0 to 1.2.0 (#36306)
    • Remove fomantic form module (#36222)
    • Bump setup-node to v6, re-enable cache (#36207)
    • Bump crowdin/github-action from 1 to 2 (#36204)
    • Revert "Bump alpine to 3.23 (#36185)" (#36202)
    • Update chroma to v2.21.1 (#36201)
    • Bump astral-sh/setup-uv from 6 to 7 (#36198)
    • Bump docker/build-push-action from 5 to 6 (#36197)
    • Bump aws-actions/configure-aws-credentials from 4 to 5 (#36196)
    • Bump dev-hanz-ops/install-gh-cli-action from 0.1.0 to 0.2.1 (#36195)
    • Add JSON linting (#36192)
    • Enable dependabot for actions (#36191)
    • Bump alpine to 3.23 (#36185)
    • Update chroma to v2.21.0 (#36171)
    • Update JS deps and eslint enhancements (#36147)
    • Update JS deps (#36091)
    • update golangci-lint to v2.7.0 (#36079)
    • Update JS deps, fix deprecations (#36040)
    • Update JS deps (#35978)
    • Add toolchain directive to go.mod (#35901)
    • Move gitea-vet to use go tool (#35878)
    • Update to go 1.25.4 (#35877)
    • Enable TypeScript strictNullChecks (#35843)
    • Enable vue/require-typed-ref eslint rule (#35764)
    • Update JS dependencies (#35759)
    • Move codeformat folder to tools (#35758)
    • Update dependencies (#35733)
    • Bump happy-dom from 20.0.0 to 20.0.2 (#35677)
    • Bump setup-go to v6 (#35660)
    • Update JS deps, misc tweaks (#35643)
    • Bump happy-dom from 19.0.2 to 20.0.0 (#35625)
    • Use bundled version of spectral (#35573)
    • Update JS and PY deps (#35565)
    • Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 (#35557)
    • Migrate from webpack to vite (#37002)
    • Update JS dependencies and misc tweaks (#37064)
    • Update to eslint 10 (#36925)
    • Optimize Docker build with dependency layer caching (#36864)
    • Update JS deps (#36850)
    • Update tool dependencies and fix new lint issues (#36702)
    • Remove redundant linter rules (#36658)
    • Move Fomantic dropdown CSS to custom module (#36530)
    • Remove and forbid @ts-expect-error (#36513)
    • Refactor git command stderr handling (#36402)
    • Enable gocheckcompilerdirectives linter (#36156)
    • Replace lint-go-gopls with additional govet linters (#36028)
    • Update golangci-lint to v2.6.0 (#35801)
    • Misc tool tweaks (#35734)
    • Add cache to container build (#35697)
    • Upgrade vite (#37126)
    • Update setup-uv to v8.0.0 (#37101)
    • Upgrade go-git to v5.17.2 and related dependencies (#37060)
    • Raise minimum Node.js version to 22.18.0 (#37058)
    • Upgrade golang.org/x/image to v0.38.0 (#37054)
    • Update minimum go version to 1.26.1, golangci-lint to 2.11.2, fix test style (#36876)
    • Enable eslint concurrency (#36878)
    • Vendor relative-time-element as local web component (#36853)
    • Update material-icon-theme v5.32.0 (#36832)
    • Update Go dependencies (#36781)
    • Upgrade minimatch (#36760)
    • Remove i18n backport tool at the moment because of translation format changed (#36643)
    • Update emoji data for Unicode 16 (#36596)
    • Update JS dependencies, adjust webpack config, misc fixes (#36431)
    • Update material-icon-theme to v5.31.0 (#36427)
    • Update JS and PY deps (#36383)
    • Bump alpine to 3.23, add platforms to docker-dryrun (#36379)
    • Update JS deps (#36354)
    • Update goldmark to v1.7.16 (#36343)
    • Update chroma to v2.22.0 (#36342)
  • DOCS
    • Update AI Contribution Policy (#37022)
    • Update AGENTS.md with additional guidelines (#37018)
    • Add missing cron tasks to example ini (#37012)
    • Add AI Contribution Policy to CONTRIBUTING.md (#36651)
    • Minor punctuation improvement in CONTRIBUTING.md (#36291)
    • Add documentation for markdown anchor post-processing (#36443)
  • MISC
    • Correct spelling (#36783)
    • Update Nix flake (#37110)
    • Update Nix flake (#37024)
    • Add valid github scopes (#36977)
    • Update Nix flake (#36943)
    • Update Nix flake (#36902)
    • Update Nix flake (#36857)
    • Update Nix flake (#36787)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

View originalPermalink
How v1.26.0 went

v1.26.0-rc0

Pre-release
  • BREAKING
    • Correct swagger annotations for enums, status codes, and notification state (#37030)
    • Remove GET API registration-token (#36801)
    • Support Actions concurrency syntax (#32751)
    • Make PUBLIC_URL_DETECTION default to "auto" (#36955)
  • SECURITY
    • Bound PageSize in ListUnadoptedRepositories (#36884)
  • FEATURES
    • Support Actions concurrency syntax (#32751)
    • Add terraform state registry (#36710)
    • Instance-wide (global) info banner and maintenance mode (#36571)
    • Support rendering OpenAPI spec (#36449)
    • Add keyboard shortcuts for repository file and code search (#36416)
    • Add support for archive-upload rpc (#36391)
    • Add ability to download subpath archive (#36371)
    • Add workflow dependencies visualization (#26062) (#36248) & Restyle Workflow Graph (#36912)
    • Automatic generation of release notes (#35977)
    • Add "Go to file", "Delete Directory" to repo file list page (#35911)
    • Introduce "config edit-ini" sub command to help maintaining INI config file (#35735)
    • Add button to re-run failed jobs in Actions (#36924)
    • Support actions and reusable workflows from private repos (#32562)
    • Add summary to action runs view (#36883)
    • Add user badges (#36752)
    • Add configurable permissions for Actions automatic tokens (#36173)
    • Add per-runner “Disable/Pause” (#36776)
  • PERFORMANCE
    • WorkflowDispatch API optionally return runid (#36706)
    • Add render cache for SVG icons (#36863)
    • Load mentionValues asynchronously (#36739)
    • Lazy-load some Vue components, fix heatmap chunk loading on every page (#36719)
    • Load heatmap data asynchronously (#36622)
    • Use prev/next pagination for user profile activities page to speed up (#36642)
    • Refactor cat-file batch operations and support --batch-command approach (#35775)
    • Use merge tree to detect conflicts when possible (#36400)
  • ENHANCEMENTS
    • Adds option to force update new branch in contents routes (#35592)
    • Add viewer controller for mermaid (zoom, drag) (#36557)
    • Add code editor setting dropdowns (#36534)
    • Add elk layout support to mermaid (#36486)
    • Add resolve/unresolve review comment API endpoints (#36441)
    • Allow configuring default PR base branch (fixes #36412) (#36425)
    • Add support for RPM Errata (updateinfo.xml) (#37125)
    • Require additional user confirmation for making repo private (#36959)
    • Feature non-zipped actions artifacts (action v7 / nodejs / npm v6.2.0) (#36786)
    • Add actions.WORKFLOW_DIRS setting (#36619)
    • Avoid opening new tab when downloading actions logs (#36740)
    • Implements OIDC RP-Initiated Logout (#36724)
    • Show workflow link (#37070)
    • Desaturate dark theme background colors (#37056)
    • Refactor "org teams" page and help new users to "add member" to an org (#37051)
    • Add webhook name field to improve webhook identification (#37025) (#37040)
    • Make task list checkboxes clickable in the preview tab (#37010)
    • Improve severity labels in Actions logs and tweak colors (#36993)
    • Linkify URLs in Actions workflow logs (#36986)
    • Allow text selection on checkbox labels (#36970)
    • Support dark/light theme images in markdown (#36922)
    • Enable native dark mode for swagger-ui (#36899)
    • Rework checkbox styling, remove input border hover effect (#36870)
    • Refactor storage content-type handling of ServeDirectURL (#36804)
    • Use "Enable Gravatar" but not "Disable" (#36771)
    • Use case-insensitive matching for Git error "Not a valid object name" (#36728)
    • Add “Copy Source” to markup comment menu (#36726)
    • Change image transparency grid to CSS (#36711)
    • Add "Run" prefix for unnamed action steps (#36624)
    • Persist actions log time display settings in localStorage (#36623)
    • Use first commit title for multi-commit PRs and fix auto-focus title field (#36606)
    • Improve BuildCaseInsensitiveLike with lowercase (#36598)
    • Improve diff highlighting (#36583)
    • Exclude cancelled runs from failure-only email notifications (#36569)
    • Use full-file highlighting for diff sections (#36561)
    • Color command/error logs in Actions log (#36538)
    • Add paging headers (#36521)
    • Improve timeline entries for WIP prefix changes in pull requests (#36518)
    • Add FOLDER_ICON_THEME configuration option (#36496)
    • Normalize guessed languages for code highlighting (#36450)
    • Add chunked transfer encoding support for LFS uploads (#36380)
    • Indicate when only optional checks failed (#36367)
    • Add 'allow_maintainer_edit' API option for creating a pull request (#36283)
    • Support closing keywords with URL references (#36221)
    • Improve diff file headers (#36215)
    • Fix and enhance comment editor monospace toggle (#36181)
    • Add git.DIFF_RENAME_SIMILARITY_THRESHOLD option (#36164)
    • Add matching pair insertion to markdown textarea (#36121)
    • Add sorting/filtering to admin user search API endpoint (#36112)
    • Allow action user have read permission in public repo like other user (#36095)
    • Disable matchBrackets in monaco (#36089)
    • Use GitHub-style commit message for squash merge (#35987)
    • Make composer registry support tar.gz and tar.bz2 and fix bugs (#35958)
    • Add GITEA_PR_INDEX env variable to githooks (#35938)
    • Add proper error message if session provider can not be created (#35520)
    • Add button to copy file name in PR files (#35509)
    • Move X_FRAME_OPTIONS setting from cors to security section (#30256)
    • Add placeholder content for empty content page (#37114)
    • Add DEFAULT_DELETE_BRANCH_AFTER_MERGE setting (#36917)
    • Redirect to the only OAuth2 provider when no other login methods and fix various problems (#36901)
    • Add admin badge to navbar avatar (#36790)
    • Add never option to PUBLIC_URL_DETECTION configuration (#36785)
    • Add background and run count to actions list page (#36707)
    • Add icon to buttons "Close with Comment", "Close Pull Request", "Close Issue" (#36654)
    • Add support for in_progress event in workflow_run webhook (#36979)
    • Report commit status for pull_request_review events (#36589)
    • Render merged pull request title as such in dashboard feed (#36479)
    • Feature to be able to filter project boards by milestones (#36321)
    • Use user id in noreply emails (#36550)
    • Enable pagination on GiteaDownloader.getIssueReactions() (#36549)
    • Remove striped tables in UI (#36509)
    • Improve control char rendering and escape button styling (#37094)
    • Support legacy run/job index-based URLs and refactor migration 326 (#37008)
    • Add date to "No Contributions" tooltip (#36190)
    • Show edit page confirmation dialog on tree view file change (#36130)
    • Mention proc-receive in text for dashboard.resync_all_hooks func (#35991)
    • Reuse selectable style for wiki (#35990)
    • Support blue yellow colorblind theme (#35910)
    • Support selecting theme on the footer (#35741)
    • Improve online runner check (#35722)
    • Add quick approve button on PR page (#35678)
    • Enable commenting on expanded lines in PR diffs (#35662)
    • Print PR-Title into tooltip for actions (#35579)
    • Use explicit, stronger defaults for newly generated repo signing keys for Debian (#36236)
    • Improve the compare page (#36261)
    • Unify repo names in system notices (#36491)
    • Move package settings to package instead of being tied to version (#37026)
    • Add Actions API rerun endpoints for runs and jobs (#36768)
    • Add branch_count to repository API (#35351) (#36743)
    • Add created_by filter to SearchIssues (#36670)
    • Allow admins to rename non-local users (#35970)
    • Support updating branch via API (#35951)
    • Add an option to automatically verify SSH keys from LDAP (#35927)
    • Make "update file" API can create a new file when SHA is not set (#35738)
    • Update issue.go with labels documentation (labels content, not ids) (#35522)
    • Expose content_version for optimistic locking on issue and PR edits (#37035)
    • Pass ServeHeaderOptions by value instead of pointer, fine tune httplib tests (#36982)
  • BUGFIXES
    • Fix API not persisting pull request unit config when has_pull_requests is not set (#36718)
    • Rename CSS variables and improve colorblind themes (#36353)
    • Hide add-matcher and remove-matcher from actions job logs (#36520)
    • Prevent navigation keys from triggering actions during IME composition (#36540)
    • Fix vertical alignment of .commit-sign-badge children (#36570)
    • Fix duplicate startup warnings in admin panel (#36641)
    • Fix CODEOWNERS review request attribution using comment metadata (#36348)
    • Fix HTML tags appearing in wiki table of contents (#36284)
    • Fix various bugs (#37096)
    • Fix various legacy problems (#37092)
    • Fix RPM Registry 404 when package name contains 'package' (#37087)
    • Merge some standalone Vite entries into index.js (#37085)
    • Fix various problems (#37077)
    • Fix issue label deletion with Actions tokens (#37013)
    • Hide delete branch or tag buttons in mirror or archived repositories. (#37006)
    • Fix org contact email not clearable once set (#36975)
    • Fix a bug when forking a repository in an organization (#36950)
    • Preserve sort order of exclusive labels from template repo (#36931)
    • Make container registry support Apple Container (basic auth) (#36920)
    • Fix the wrong push commits in the pull request when force push (#36914)
    • Add class "list-header-filters" to the div for projects (#36889)
    • Fix dbfs error handling (#36844)
    • Fix incorrect viewed files counter if reverted change was viewed (#36819)
    • Refactor avatar package, support default avatar fallback (#36788)
    • Fix README symlink resolution in subdirectories like .github (#36775)
    • Fix CSS stacking context issue in actions log (#36749)
    • Add gpg signing for merge rebase and update by rebase (#36701)
    • Delete non-exist branch should return 404 (#36694)
    • Fix TestActionsCollaborativeOwner (#36657)
    • Fix multi-arch Docker build SIGILL by splitting frontend stage (#36646)
    • Fix linguist-detectable attribute being ignored for configuration files (#36640)
    • Fix state desync in ComboMarkdownEditor (#36625)
    • Unify DEFAULT_SHOW_FULL_NAME output in templates and dropdown (#36597)
    • Pull Request Pusher should be the author of the merge (#36581)
    • Fix various version parsing problems (#36553)
    • Fix highlight diff result (#36539)
    • Fix mirror sync parser and fix mirror messages (#36504)
    • Fix bug when list pull request commits (#36485)
    • Fix various bugs (#36446)
    • Fix issue filter menu layout (#36426)
    • Restrict branch naming when new change matches with protection rules (#36405)
    • Fix link/origin referrer and login redirect (#36279)
    • Generate IDs for HTML headings without id attribute (#36233)
    • Use a migration test instead of a wrong test which populated the meta test repositories and fix a migration bug (#36160)
    • Fix issue close timeline icon (#36138)
    • Fix diff blob excerpt expansion (#35922)
    • Fix external render (#35727)
    • Fix review request webhook bug (#35339) (#35723)
    • Fix shutdown waitgroup panic (#35676)
    • Cleanup ActionRun creation (#35624)
    • Fix possible bug when migrating issues/pull requests (#33487)
    • Various fixes (#36697)
    • Apply notify/register mail flags during install load (#37120)
    • Repair duration display for bad stopped timestamps (#37121)
    • Fix(upgrade.sh): use HTTPS for GPG key import and restore SELinux context after upgrade (#36930)
    • Fix various trivial problems (#36921)
    • Fix various trivial problems (#36953)
    • Fix NuGet package upload error handling (#37074)
    • Fix CodeQL code scanning alerts (#36858)
    • Refactor issue sidebar and fix various problems (#37045)
    • Fix various problems (#37029)
    • Fix relative-time RangeError (#37021)
    • Fix chroma lexer mapping (#36629)
    • Fix typos and grammar in English locale (#36751)
    • Fix milestone/project text overflow in issue sidebar (#36741)
    • Fix no-content message not rendering after comment edit (#36733)
    • Fix theme loading in development (#36605)
    • Fix workflow run jobs API returning null steps (#36603)
    • Fix timeline event layout overflow with long content (#36595)
    • Fix minor UI issues in runner edit page (#36590)
    • Fix incorrect vendored detections (#36508)
    • Fix editorconfig not respected in PR Conversation view (#36492)
    • Don't create self-references in merged PRs (#36490)
    • Fix potential incorrect runID in run status update (#36437)
    • Fix file-tree ui error when adding files to repo without commits (#36312)
    • Improve image captcha contrast for dark mode (#36265)
    • Fix panic in blame view when a file has only a single commit (#36230)
    • Fix spelling error in migrate-storage cmd utility (#36226)
    • Fix code highlighting on blame page (#36157)
    • Fix nilnil in onedev downloader (#36154)
    • Fix actions lint (#36029)
    • Fix oauth2 session gob register (#36017)
    • Fix Arch repo pacman.conf snippet (#35825)
    • Fix a number of strictNullChecks-related issues (#35795)
    • Fix URLJoin, markup render link reoslving, sign-in/up/linkaccount page common data (#36861)
    • Hide delete directory button for mirror or archive repository and disable the menu item if user have no permission (#36384)
    • Update message severity colors, fix navbar double border (#37019)
    • Inline and lazy-load EasyMDE CSS, fix border colors (#36714)
    • Closed milestones with no issues now show as 100% completed (#36220)
    • Add test for ExtendCommentTreePathLength migration and fix bugs (#35791)
    • Only turn links to current instance into hash links (#36237)
    • Fix typos in code comments: doesnt, dont, wont (#36890)
  • REFACTOR
    • Replace Monaco with CodeMirror (#36764)
    • Replace CSRF cookie with CrossOriginProtection (#36183)
    • Replace index with id in actions routes (#36842)
    • Remove unnecessary function parameter (#35765)
    • Move jobparser from act repository to Gitea (#36699)
    • Refactor compare router param parse (#36105)
    • Optimize 'refreshAccesses' to perform update without removing then adding (#35702)
    • Clean up checkbox cursor styles (#37016)
    • Remove undocumented support of signing key in the repository git configuration file (#36143)
    • Switch cmd/ to use constructor functions. (#36962)
    • Use relative-time to render absolute dates (#36238)
    • Some refactors about GetMergeBase (#36186)
    • Some small refactors (#36163)
    • Use gitRepo as parameter instead of repopath when invoking sign functions (#36162)
    • Move blame to gitrepo (#36161)
    • Move some functions to gitrepo package to reduce RepoPath reference directly (#36126)
    • Use gitrepo's clone and push when possible (#36093)
    • Remove mermaid margin workaround (#35732)
    • Move some functions to gitrepo package (#35543)
    • Move GetDiverging functions to gitrepo (#35524)
    • Use global lock instead of status pool for cron lock (#35507)
    • Use explicit mux instead of DefaultServeMux (#36276)
    • Use gitrepo's push function (#36245)
    • Pass request context to generateAdditionalHeadersForIssue (#36274)
    • Move assign project when creating pull request to the same database transaction (#36244)
    • Move catfile batch to a sub package of git module (#36232)
    • Use gitrepo.Repository instead of wikipath (#35398)
    • Use experimental go json v2 library (#35392)
    • Refactor template render (#36438)
    • Refactor GetRepoRawDiffForFile to avoid unnecessary pipe or goroutine (#36434)
    • Refactor text utility classes to Tailwind CSS (#36703)
    • Refactor git command stdio pipe (#36422)
    • Refactor git command context & pipeline (#36406)
    • Refactor git command stdio pipe (#36393)
    • Remove unused functions (#36672)
    • Refactor Actions Token Access (#35688)
    • Move commit related functions to gitrepo package (#35600)
    • Move archive function to repo_model and gitrepo (#35514)
    • Move some functions to gitrepo package (#35503)
    • Use git model to detect whether branch exist instead of gitrepo method (#35459)
    • Some refactor for repo path (#36251)
    • Extract helper functions from SearchIssues (#36158)
    • Refactor merge conan and container auth preserve actions taskID (#36560)
    • Refactor Nuget Auth to reuse Basic Auth Token Validation (#36558)
    • Refactor ActionsTaskID (#36503)
    • Refactor auth middleware (#36848)
    • Refactor code render and render control chars (#37078)
    • Clean up AppURL, remove legacy origin-url webcomponent (#37090)
    • Remove util.URLJoin and replace all callers with direct path concatenation (#36867)
    • Replace legacy tw-flex utility classes with flex-text-block/inline (#36778)
    • Mark unused&immature activitypub as "not implemented" (#36789)
  • TESTING
    • Add e2e tests for server push events (#36879)
    • Rework e2e tests (#36634)
    • Add e2e reaction test, improve accessibility, enable parallel testing (#37081)
    • Increase e2e test timeouts on CI to fix flaky tests (#37053)
  • BUILD
    • Convert locale files from ini to json format (#35489)
    • Bump golangci-lint to 2.7.2, enable modernize stringsbuilder (#36180)
    • Port away from flake-utils (#35675)
    • Remove nolint (#36252)
    • Update the Unlicense copy to latest version (#36636)
    • Update to go 1.26.0 and golangci-lint 2.9.0 (#36588)
    • Replace google/go-licenses with custom generation (#36575)
    • Update go dependencies (#36548)
    • Bump appleboy/git-push-action from 1.0.0 to 1.2.0 (#36306)
    • Remove fomantic form module (#36222)
    • Bump setup-node to v6, re-enable cache (#36207)
    • Bump crowdin/github-action from 1 to 2 (#36204)
    • Revert "Bump alpine to 3.23 (#36185)" (#36202)
    • Update chroma to v2.21.1 (#36201)
    • Bump astral-sh/setup-uv from 6 to 7 (#36198)
    • Bump docker/build-push-action from 5 to 6 (#36197)
    • Bump aws-actions/configure-aws-credentials from 4 to 5 (#36196)
    • Bump dev-hanz-ops/install-gh-cli-action from 0.1.0 to 0.2.1 (#36195)
    • Add JSON linting (#36192)
    • Enable dependabot for actions (#36191)
    • Bump alpine to 3.23 (#36185)
    • Update chroma to v2.21.0 (#36171)
    • Update JS deps and eslint enhancements (#36147)
    • Update JS deps (#36091)
    • update golangci-lint to v2.7.0 (#36079)
    • Update JS deps, fix deprecations (#36040)
    • Update JS deps (#35978)
    • Add toolchain directive to go.mod (#35901)
    • Move gitea-vet to use go tool (#35878)
    • Update to go 1.25.4 (#35877)
    • Enable TypeScript strictNullChecks (#35843)
    • Enable vue/require-typed-ref eslint rule (#35764)
    • Update JS dependencies (#35759)
    • Move codeformat folder to tools (#35758)
    • Update dependencies (#35733)
    • Bump happy-dom from 20.0.0 to 20.0.2 (#35677)
    • Bump setup-go to v6 (#35660)
    • Update JS deps, misc tweaks (#35643)
    • Bump happy-dom from 19.0.2 to 20.0.0 (#35625)
    • Use bundled version of spectral (#35573)
    • Update JS and PY deps (#35565)
    • Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 (#35557)
    • Migrate from webpack to vite (#37002)
    • Update JS dependencies and misc tweaks (#37064)
    • Update to eslint 10 (#36925)
    • Optimize Docker build with dependency layer caching (#36864)
    • Update JS deps (#36850)
    • Update tool dependencies and fix new lint issues (#36702)
    • Remove redundant linter rules (#36658)
    • Move Fomantic dropdown CSS to custom module (#36530)
    • Remove and forbid @ts-expect-error (#36513)
    • Refactor git command stderr handling (#36402)
    • Enable gocheckcompilerdirectives linter (#36156)
    • Replace lint-go-gopls with additional govet linters (#36028)
    • Update golangci-lint to v2.6.0 (#35801)
    • Misc tool tweaks (#35734)
    • Add cache to container build (#35697)
    • Upgrade vite (#37126)
    • Update setup-uv to v8.0.0 (#37101)
    • Upgrade go-git to v5.17.2 and related dependencies (#37060)
    • Raise minimum Node.js version to 22.18.0 (#37058)
    • Upgrade golang.org/x/image to v0.38.0 (#37054)
    • Update minimum go version to 1.26.1, golangci-lint to 2.11.2, fix test style (#36876)
    • Enable eslint concurrency (#36878)
    • Vendor relative-time-element as local web component (#36853)
    • Update material-icon-theme v5.32.0 (#36832)
    • Update Go dependencies (#36781)
    • Upgrade minimatch (#36760)
    • Remove i18n backport tool at the moment because of translation format changed (#36643)
    • Update emoji data for Unicode 16 (#36596)
    • Update JS dependencies, adjust webpack config, misc fixes (#36431)
    • Update material-icon-theme to v5.31.0 (#36427)
    • Update JS and PY deps (#36383)
    • Bump alpine to 3.23, add platforms to docker-dryrun (#36379)
    • Update JS deps (#36354)
    • Update goldmark to v1.7.16 (#36343)
    • Update chroma to v2.22.0 (#36342)
  • DOCS
    • Update AI Contribution Policy (#37022)
    • Update AGENTS.md with additional guidelines (#37018)
    • Add missing cron tasks to example ini (#37012)
    • Add AI Contribution Policy to CONTRIBUTING.md (#36651)
    • Minor punctuation improvement in CONTRIBUTING.md (#36291)
    • Add documentation for markdown anchor post-processing (#36443)
  • MISC
    • Correct spelling (#36783)
    • Update Nix flake (#37110)
    • Update Nix flake (#37024)
    • Add valid github scopes (#36977)
    • Update Nix flake (#36943)
    • Update Nix flake (#36902)
    • Update Nix flake (#36857)
    • Update Nix flake (#36787)
View originalPermalink
How v1.26.0-rc0 went

v1.25.5

  • SECURITY

    • Toolchain Update to Go 1.25.6 (#36480) (#36487)
    • Adjust the toolchain version (#36537) (#36542)
    • Update toolchain to 1.25.8 for v1.25 (#36888)
    • Prevent redirect bypasses via backslash-encoded paths (#36660) (#36716)
    • Fix get release draft permission check (#36659) (#36715)
    • Fix a bug user could change another user's primary email (#36586) (#36607)
    • Fix OAuth2 authorization code expiry and reuse handling (#36797) (#36851)
    • Add validation constraints for repository creation fields (#36671) (#36757)
    • Fix bug to check whether user can update pull request branch or rebase branch (#36465) (#36838)
    • Add migration http transport for push/sync mirror lfs (#36665) (#36691)
    • Fix track time list permission check (#36662) (#36744)
    • Fix track time issue id (#36664) (#36689)
    • Fix path resolving (#36734) (#36746)
    • Fix dump release asset bug (#36799) (#36839)
    • Fix org permission API visibility checks for hidden members and private orgs (#36798) (#36841)
    • Fix forwarded proto handling for public URL detection (#36810) (#36836)
    • Add a git grep search timeout (#36809) (#36835)
    • Fix oauth2 s256 (#36462) (#36477)
  • ENHANCEMENTS

    • Make security-check informational only (#36681) (#36852)
    • Upgrade to github.com/cloudflare/circl 1.6.3, svgo 4.0.1, markdownlint-cli 0.48.0 (#36840)
    • Add some validation on values provided to USER_DISABLED_FEATURES and EXTERNAL_USER_DISABLED_FEATURES (#36688) (#36692)
    • Upgrade gogit to 5.16.5 (#36687)
    • Add wrap to runner label list (#36565) (#36574)
    • Add dnf5 command for Fedora in RPM package instructions (#36527) (#36572)
    • Allow scroll propagation outside code editor (#36502) (#36510)
  • BUGFIXES

    • Fix non-admins unable to automerge PRs from forks (#36833) (#36843)
    • Fix bug when pushing mirror with wiki (#36795) (#36807)
    • Fix artifacts v4 backend upload problems (#36805) (#36834)
    • Fix CRAN package version validation to allow more than 4 version components (#36813) (#36821)
    • Fix force push time-line commit comments of pull request (#36653) (#36717)
    • Fix SVG height calculation in diff viewer (#36748) (#36750)
    • Fix push time bug (#36693) (#36713)
    • Fix bug the protected branch rule name is conflicted with renamed branch name (#36650) (#36661)
    • Fix bug when do LFS GC (#36500) (#36608)
    • Fix focus lost bugs in the Monaco editor (#36609)
    • Reprocess htmx content after loading more files (#36568) (#36577)
    • Fix assignee sidebar links and empty placeholder (#36559) (#36563)
    • Fix issues filter dropdown showing empty label scope section (#36535) (#36544)
    • Fix various mermaid bugs (#36547) (#36552)
    • Fix data race when uploading container blobs concurrently (#36524) (#36526)
    • Correct spacing between username and bot label (#36473) (#36484)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

View originalPermalink
How v1.25.5 went
View all

Discussion