-
BREAKING
-
SECURITY
- Fix(git): reject invalid and duplicate Git objects on push (#39472)
- Fix(git)!: route Git network operations through an internal proxy and update egress settings (#39426)
- Fix(ssh): identify presented public keys by fingerprint (#39423)
- Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate (#39399)
- Fix(deps): update golang.org/x/crypto SSH to address denial of service (#39219)
- Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking (#39063)
-
FEATURES
- Feat(actions): update actionslib, support
self:, misc fixes (#39358) - Feat(api): list all packages for site administrators (#38968)
- Feat: manage bot accounts from the admin UI, API and CLI (#38966)
- Feat(user): Personal access tokens can be regenerated (#38907)
- Feat(actions): support
$/prefix in reusable workflowuses:(#38822) - Feat(actions): add force-cancel workflow run API (#38756)
- Feat(licenses): support REUSE specification in licenses (#38720)
- Feat(api): add project APIs (#38691)
- Feat(webhook): fire repository event on repo rename (#38641)
- Feat: admin impersonates a user (#38614)
- Feat(actions): add build queue view (#38585)
- Feat(setting): add shared [redis] section as default for redis-backed subsystems (#38550)
- Feat(repo): prioritize well-known READMEs and optimize discovery (#38532)
- Feat(actions): implement adaptive auto-refresh for workflow runs list (#38329)
- Feat(auth): add
disable-2facommand (#38275) - Feat: Add audit logging (#38189)
- Feat(repo): add quick repository switcher to repo header (#38188)
- Feat(repo): support file exclusion logic in .gitea/template in template generation (#38064)
- Feat(web): Add org removal functionality to admin user details page (#38013)
- Feat: add watch options (#37571)
- Feat: add deploy tokens (#37306)
- Feat(diff): Add search and extension filter to diff sidebar (#37068)
- Feat: Replace SSE with WebSocket for UI notifications (#36965)
- Feat(actions): Add artifact preview in Actions run view (#36754)
- Feat(packages): add support for uploading helm provenance files (#36695)
- Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows (#36564)
- Feat: Add max-parallel Support for Gitea Actions (#36357)
- Feat(actions): Add Actions API endpoints for workflow run management and logs (#35382)
- Feat: Add block on pending codeowner reviews branch protection (#34995)
- Feat(actions): update actionslib, support
-
ENHANCEMENTS
- Enhance: allow auto-closing PRs from PRs (#39393)
- Enhance(actions): add pending job status and align job statuses with GitHub (#39376)
- Enhance(acme): add configurable ACME profile (#39375)
- Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data (#39363)
- Enhance: improve issue-pattern capture groups and support both internal&external trackers enabled (#39354)
- Enhance: update mermaid to v12 (#39331)
- Enhance(notifications): mark current notification page as read (#39294)
- Enhance: support
ETagon streamed repository archives, supportIf-None-Match: *(#39289) - Enhance: truncate but show long lines in diffs (#39279)
- Enhance(packages): implement npm single-version API and add per-version repository (#39267)
- Enhance: move window.config to JSON, improve CSP format (#39236)
- Enhance: improve commit page header (#39229)
- Enhance: Improve validation errors for secrets/variables (#39221)
- Enhance(repo): check full repo name for dangerous operations (#39213)
- Enhance(web): hide attachment dropzone on preview tab in combo editor (#39204)
- Enhance(web): show attachment URL and UUID in dropzone preview (#39203)
- Enhance(actions): make workflow dispatch choice dropdown support search (#39154)
- Enhance(repo): unify diff stats on commit pages, misc diff tweaks (#39134)
- Enhance: use browser's locale to detect week's first day for the contribution map (#38995)
- Enhance(ui): forced colors mode enhancements (#38991)
- Enhance: user-friendly packages setup manual (#38946)
- Enhance: inherit team access for all units (#38938)
- Enhance(admin): show impersonation banner and keep password change with the user (#38924)
- Enhance(ui): tint toast backgrounds by level (#38919)
- Enhance(repo): add default object format setting (#38877)
- Enhance(actions): set ref_protected in context (#38852)
- Enhance(ui): restyle toasts (#38842)
- Enhance: refine repo watching (#38835)
- Enhance: fall back to DEFAULT_TEMPLATE.md when style-specific template is missing (#38803)
- Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint (#38770)
- Enhance(api): expose file mode in contents API response (#38713)
- Enhance(tls): use go's tls defaults (#38687)
- Enhance(ui): improve luminance calculations (#38682)
- Enhance(api): add
tag_filterquery parameter to release list API (#38681) - Enhance(actions): replace
ansi_upwith first-party code (#38619) - Enhance: keep status check list scrolled on merge box reload (#38597)
- Enhance(actions): action view enhancements (#38594)
- Enhance(ui): tweak tooltip style and misc fixes (#38524)
- Enhance: improve e-mail templates (#38396)
- Enhance(webhook): add reviewer name to MS Teams review request notifications (#38289)
- Enhance: extend
- Enhance(packages/npm): expand version metadata and support npm deprecate (#37890)
-
PERFORMANCE
-
BUGFIXES
- Fix(actions): preserve admitted jobs and runs in their concurrency group (#39461)
- Fix(api): commit tree SHA is the commit ID (#39449)
- Fix: PR merge (#39442)
- Fix(actions): evaluate job-level
if:before concurrency check (#39437) - Fix(api): allow pending-inline-comment-only reviews (#39433)
- Fix: sanitize external render command line arguments (#39417)
- Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data (#39406)
- Fix(indexer): index full file paths and real offsets in bleve (#39405)
- Fix(git): keep leading dashes in git grep search patterns (#39404)
- Fix: use clearer message for ldap auth failure (#39392)
- Fix(repo): commit page fails to render unsigned commits with a different committer (#39381)
- Fix: focus confirm button and use red for delete confirmations (#39350)
- Fix(migrations): preserve SHA-256 pull request commit IDs (#39343)
- Fix(ui): misc ui fixes (#39336)
- Fix(actions): use gitea's clock for actions durations (#39323)
- Fix(actions): never show negative running durations (#39322)
- Fix: package registry keypair creation race (#39319)
- Fix: add default timeout and handle errors for HaveIBeenPwned API (#39316)
- Fix(user): unify email validation for registration and settings (#39304)
- Fix(ui): use button elements for branch and tag dropdown tabs (#39285)
- Fix(auth): fix ssh and gpg key verification on windows (#39283)
- Fix(feed): use meaningful lines as comment excerpt (#39276)
- Fix(projects): allow max columns to the limit (#39272)
- Fix: pass merge commit messages to git via stdin (#39269)
- Fix(repo): surface unrelated histories on Sync Fork (#39258)
- Fix: avoid nil panic and refactor some trivial problems (#39251)
- Fix: restore missing blob file when re-publishing a package (#39239)
- Fix(automerge): validate head commit before merge (#39235)
- Fix(httplib): prevent leaking localhost:3000 in public links (#39217)
- Fix(setting): honor bare -1 for timeout settings (#39181)
- Fix: correct repo/attatchment absolute url and release layout (#39178)
- Fix(web): populate the reason for "cannot commit to branch" in web editor commit form (#39155)
- Fix(process): reap entire process group on cmd.Cancel (#39143)
- Fix: recognize linguist language aliases (#39135)
- Fix(repo): preserve transfer recipient collaboration (#39042)
- Fix(db): make paginated database reads always require "order" option (#39017)
- Fix: make local queue PopItem can be notified (#39011)
- Fix: classify git failures on stderr, restrict migration failure detail (#39010)
- Fix: allow re-requesting uncounted review approvals (#38988)
- Fix(actions): allow larger scheduled workflows (#38985)
- Fix: resolve actions commit status permission per repository (#38977)
- Fix(deps): update module golang.org/x/image to v0.45.0 [security] (#38930)
- Fix(deps): update module golang.org/x/mod to v0.40.0 [security] (#38914)
- Fix: dedupe issue cross-reference timeline entries (#38881)
- Fix(server): set
ReadHeaderTimeouton HTTP servers (#38878) - Fix(repo): avoid a repo-sized temp file for every bundle download (#38863)
- Fix(lfs): ensure lock listing paginates with a total order (#38850)
- Fix(avatar): use sha256 and inline the federated avatar lookup (#38843)
- Fix(gitdiff): render exact-limit diffs and zero-limit comments (#38838)
- Fix(deps): update dependency mermaid to v11.16.1 [security] (#38813)
- Fix: misc fixes in pub/gpg/tests (#38809)
- Fix: git diff blob excerpt (#38808)
- Fix(packages): show error for duplicate cleanup rules #37820 (#38786)
- Fix(actions): fix runner docs link (#38783)
- Fix: git cache (#38763)
- Fix(actions): evaluate each
${{ }}part on its own (#38754) - Fix: don't report failed network requests as JavaScript errors (#38732)
- Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker (#38728)
- Fix(api): document X-Total-Count instead of non-existent X-Total header (#38717)
- Fix(actions): dynamic matrix expansion correctness fixes (#38690)
- Fix(auth): record last sign-in on reverse proxy login (#38672)
- Fix(api): accept fully-qualified refs in contents API (#38650)
- Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 [security] (#38623)
- Fix(deps): update dependency js-yaml to v5.2.2 [security] (#38622)
- Fix: abort superseded issue suggestion requests (#38620)
- Fix(issue): display error toast on batch action failures instead of reloading page (#38593)
- Fix(deps): update module google.golang.org/grpc to v1.82.1 [security] (#38567)
- Fix(deps): update module github.com/google/go-github/v88 to v89 (#38433)
- Fix(deps): update go dependencies (#38429)
- Fix(deps): update go dependencies (#38346)
- Fix(deps): update npm dependencies (#38342)
- Fix(base): correct natural sort of numbers with leading zeros (#38163)
- Fix(ui): avoid layout shifts in
overflow-menuand repo filter (#37818) - Fix: make auth source group sync correctly handle team removal (#37161)
- Fix(release): separate publication time from the release date (#36761)
-
TESTING
- Test: stop tests from writing into
~/.ssh(#39348) - Test(e2e): log out to switch users in pr-review test (#39328)
- Test: release fixtures loader lock before database work (#39263)
- Test: speed up tests, fix transaction bug (#39030)
- Test: run frontend unit tests in browsers (#38860)
- Test(pubsub): stop racing the Redis SUBSCRIBE ack (#38661)
- Test(e2e): add pull request merge box test, update AGENTS.md (#38576)
- Test(e2e): deterministically wait for event stream in logout propagation test (#38535)
- Test: stop tests from writing into
-
BUILD
- Refactor: fix
go veterrors related to composite literals (#39341) - Build(gogit): disable gogit builds for stable releases (#39324)
- Refactor: replace jquery.are-you-sure with first-party code (#39233)
- Refactor: http request binding (#38971)
- Refactor: clean up git repo and model migration packages (#38564)
- Refactor: prepare to decouple the "model migration" package and "models" package (#38533)
- Build: fix snapcraft release (#38260)
- Build(release): use native golang toolchain for official release builds (#37828)
- Refactor: fix
-
DOCS
- Docs(webhook): review.type comment lists values the webhook never sends (#39451)
- Docs(api): document verification and files on the compare endpoint (#39440)
- Docs(api): name the unadopted-repository search parameter query (#39370)
- Docs: remove unused COOKIE_USERNAME from app.example.ini (#39365)
- Docs: document NOTICE_ON_SUCCESS for every cron task (#39352)
- Docs: correct ALLOW_LOCALNETWORKS description in app.example.ini (#39240)
- Docs: fix typo in README about app.ini restart (#39223)
- Docs: fix dead localization doc link in the READMEs (#39211)
- Docs: Update CHANGELOG for release 1.27.3 (#39170)
- Docs: Update CHANGELOG for version 1.27.2 (#38923)
- Docs: Update PGP key expiration date to July 23, 2027 (#38747)
- Docs(api): document 401/403 responses for user key endpoints (#38711)
- Docs: Update Changelog for release v1.27.1 (#38670)
- Docs: Update Changelog for 1.27 (#38440)
- Docs: Update Security docs (#38422)
-
MISC
- Refactor: make git http respond error message (#39390)
- Refactor(api): convert bot accounts through the admin user edit endpoint (#39355)
- Refactor: replace AWS SDK with a REST client for CodeCommit migration (#39330)
- Refactor: replace Azure Blob SDK with a REST client (#39315)
- Refactor: npm route handlers (#39275)
- Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" (#39248)
- Refactor(templates): update djlint to 1.46.0 and resolve its new findings (#39231)
- Refactor: pagination/pager (#39162)
- Refactor: share package registry error status classification (#39133)
- Refactor: drop two unmaintained dependencies, rename the byte size helpers (#39083)
- Refactor(automerge): fix error handling, populate recent automerge tasks on restart (#39001)
- Refactor: deploy key and private route handlers (#38999)
- Refactor: wiki edit form (#38918)
- Refactor: clean up form binding & validation (#38873)
- Refactor: markup render (#38864)
- Refactor: api token scope check (#38862)
- Refactor: replace
gliderlabs/sshwithgolang.org/x/crypto/ssh(#38837) - Refactor: form binding validation (#38832)
- Refactor: prepare vue components for vapor mode (#38798)
- Refactor: use the shared workflow model from actionslib (#38768)
- Refactor(modelmigration): thread context through migration functions (#38758)
- Refactor: migrate remaining Vue components to
<script setup>(#38752) - Refactor: introduce trString for frontend (#38741)
- Refactor(diff): drive diff DOM init from the global selector observer (#38740)
- Refactor(git): clarify GetBranch behavior to make it only gets an existing branch (#38662)
- Refactor: replace debounce/throttle deps with first-party code (#38610)
- Refactor: hide git repo path details from more packages (#38601)
- Refactor: retry file remove/rename when a file is busy and clean up os detection (#38588)
- Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie (#38573)
- Refactor: implement mcaptcha client and add comments/tests (#38561)
- Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations (#38555)
- Refactor: remove Path field from git.Repository (#38552)
- Refactor: make git package handle all git operations (#38543)
- Refactor: remove unnecessary git command wrapper functions (#38531)
- Refactor: git repo and relative path handling (#38522)
- Refactor: clean up fragile diff render templates, use backend typed structs (#38517)
- Refactor: correct git repo design and fix some legacy problems (#38512)
- Refactor: fix legacy problems in cmd/serv.go (#38505)
- Refactor: remove Ctx field from git.Repository (#38500)
- Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree (#38464)
- Refactor: introduce ActivePageTimer to help to do partial page refresh (#38372)
Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.