github go-gitea/gitea v28.0.0

2 hours ago
  • BREAKING

    • Fix(git)!: route Git network operations through an internal proxy and update egress settings (#39426)
    • Feat(actions)!: add RUN_RETENTION_DAYS to delete old action runs (#38855)
  • SECURITY

    • Fix(git): reject invalid and duplicate Git objects on push (#39472)
    • Fix(git)!: route Git network operations through an internal proxy and update egress settings (#39426)
    • Fix(ssh): identify presented public keys by fingerprint (#39423)
    • Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate (#39399)
    • Fix(deps): update golang.org/x/crypto SSH to address denial of service (#39219)
    • Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking (#39063)
  • FEATURES

    • Feat(actions): update actionslib, support self:, misc fixes (#39358)
    • Feat(api): list all packages for site administrators (#38968)
    • Feat: manage bot accounts from the admin UI, API and CLI (#38966)
    • Feat(user): Personal access tokens can be regenerated (#38907)
    • Feat(actions): support $/ prefix in reusable workflow uses: (#38822)
    • Feat(actions): add force-cancel workflow run API (#38756)
    • Feat(licenses): support REUSE specification in licenses (#38720)
    • Feat(api): add project APIs (#38691)
    • Feat(webhook): fire repository event on repo rename (#38641)
    • Feat: admin impersonates a user (#38614)
    • Feat(actions): add build queue view (#38585)
    • Feat(setting): add shared [redis] section as default for redis-backed subsystems (#38550)
    • Feat(repo): prioritize well-known READMEs and optimize discovery (#38532)
    • Feat(actions): implement adaptive auto-refresh for workflow runs list (#38329)
    • Feat(auth): add disable-2fa command (#38275)
    • Feat: Add audit logging (#38189)
    • Feat(repo): add quick repository switcher to repo header (#38188)
    • Feat(repo): support file exclusion logic in .gitea/template in template generation (#38064)
    • Feat(web): Add org removal functionality to admin user details page (#38013)
    • Feat: add watch options (#37571)
    • Feat: add deploy tokens (#37306)
    • Feat(diff): Add search and extension filter to diff sidebar (#37068)
    • Feat: Replace SSE with WebSocket for UI notifications (#36965)
    • Feat(actions): Add artifact preview in Actions run view (#36754)
    • Feat(packages): add support for uploading helm provenance files (#36695)
    • Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows (#36564)
    • Feat: Add max-parallel Support for Gitea Actions (#36357)
    • Feat(actions): Add Actions API endpoints for workflow run management and logs (#35382)
    • Feat: Add block on pending codeowner reviews branch protection (#34995)
  • ENHANCEMENTS

    • Enhance: allow auto-closing PRs from PRs (#39393)
    • Enhance(actions): add pending job status and align job statuses with GitHub (#39376)
    • Enhance(acme): add configurable ACME profile (#39375)
    • Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data (#39363)
    • Enhance: improve issue-pattern capture groups and support both internal&external trackers enabled (#39354)
    • Enhance: update mermaid to v12 (#39331)
    • Enhance(notifications): mark current notification page as read (#39294)
    • Enhance: support ETag on streamed repository archives, support If-None-Match: * (#39289)
    • Enhance: truncate but show long lines in diffs (#39279)
    • Enhance(packages): implement npm single-version API and add per-version repository (#39267)
    • Enhance: move window.config to JSON, improve CSP format (#39236)
    • Enhance: improve commit page header (#39229)
    • Enhance: Improve validation errors for secrets/variables (#39221)
    • Enhance(repo): check full repo name for dangerous operations (#39213)
    • Enhance(web): hide attachment dropzone on preview tab in combo editor (#39204)
    • Enhance(web): show attachment URL and UUID in dropzone preview (#39203)
    • Enhance(actions): make workflow dispatch choice dropdown support search (#39154)
    • Enhance(repo): unify diff stats on commit pages, misc diff tweaks (#39134)
    • Enhance: use browser's locale to detect week's first day for the contribution map (#38995)
    • Enhance(ui): forced colors mode enhancements (#38991)
    • Enhance: user-friendly packages setup manual (#38946)
    • Enhance: inherit team access for all units (#38938)
    • Enhance(admin): show impersonation banner and keep password change with the user (#38924)
    • Enhance(ui): tint toast backgrounds by level (#38919)
    • Enhance(repo): add default object format setting (#38877)
    • Enhance(actions): set ref_protected in context (#38852)
    • Enhance(ui): restyle toasts (#38842)
    • Enhance: refine repo watching (#38835)
    • Enhance: fall back to DEFAULT_TEMPLATE.md when style-specific template is missing (#38803)
    • Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint (#38770)
    • Enhance(api): expose file mode in contents API response (#38713)
    • Enhance(tls): use go's tls defaults (#38687)
    • Enhance(ui): improve luminance calculations (#38682)
    • Enhance(api): add tag_filter query parameter to release list API (#38681)
    • Enhance(actions): replace ansi_up with first-party code (#38619)
    • Enhance: keep status check list scrolled on merge box reload (#38597)
    • Enhance(actions): action view enhancements (#38594)
    • Enhance(ui): tweak tooltip style and misc fixes (#38524)
    • Enhance: improve e-mail templates (#38396)
    • Enhance(webhook): add reviewer name to MS Teams review request notifications (#38289)
    • Enhance: extend
    • Enhance(packages/npm): expand version metadata and support npm deprecate (#37890)
  • PERFORMANCE

    • Perf(references): scan only the keyword window before a reference (#39396)
    • Perf(frontend): enable vite module preload (#39332)
    • Perf(gitdiff): optimize inline diff highlighting using cache (#38706)
  • BUGFIXES

    • Fix(actions): preserve admitted jobs and runs in their concurrency group (#39461)
    • Fix(api): commit tree SHA is the commit ID (#39449)
    • Fix: PR merge (#39442)
    • Fix(actions): evaluate job-level if: before concurrency check (#39437)
    • Fix(api): allow pending-inline-comment-only reviews (#39433)
    • Fix: sanitize external render command line arguments (#39417)
    • Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data (#39406)
    • Fix(indexer): index full file paths and real offsets in bleve (#39405)
    • Fix(git): keep leading dashes in git grep search patterns (#39404)
    • Fix: use clearer message for ldap auth failure (#39392)
    • Fix(repo): commit page fails to render unsigned commits with a different committer (#39381)
    • Fix: focus confirm button and use red for delete confirmations (#39350)
    • Fix(migrations): preserve SHA-256 pull request commit IDs (#39343)
    • Fix(ui): misc ui fixes (#39336)
    • Fix(actions): use gitea's clock for actions durations (#39323)
    • Fix(actions): never show negative running durations (#39322)
    • Fix: package registry keypair creation race (#39319)
    • Fix: add default timeout and handle errors for HaveIBeenPwned API (#39316)
    • Fix(user): unify email validation for registration and settings (#39304)
    • Fix(ui): use button elements for branch and tag dropdown tabs (#39285)
    • Fix(auth): fix ssh and gpg key verification on windows (#39283)
    • Fix(feed): use meaningful lines as comment excerpt (#39276)
    • Fix(projects): allow max columns to the limit (#39272)
    • Fix: pass merge commit messages to git via stdin (#39269)
    • Fix(repo): surface unrelated histories on Sync Fork (#39258)
    • Fix: avoid nil panic and refactor some trivial problems (#39251)
    • Fix: restore missing blob file when re-publishing a package (#39239)
    • Fix(automerge): validate head commit before merge (#39235)
    • Fix(httplib): prevent leaking localhost:3000 in public links (#39217)
    • Fix(setting): honor bare -1 for timeout settings (#39181)
    • Fix: correct repo/attatchment absolute url and release layout (#39178)
    • Fix(web): populate the reason for "cannot commit to branch" in web editor commit form (#39155)
    • Fix(process): reap entire process group on cmd.Cancel (#39143)
    • Fix: recognize linguist language aliases (#39135)
    • Fix(repo): preserve transfer recipient collaboration (#39042)
    • Fix(db): make paginated database reads always require "order" option (#39017)
    • Fix: make local queue PopItem can be notified (#39011)
    • Fix: classify git failures on stderr, restrict migration failure detail (#39010)
    • Fix: allow re-requesting uncounted review approvals (#38988)
    • Fix(actions): allow larger scheduled workflows (#38985)
    • Fix: resolve actions commit status permission per repository (#38977)
    • Fix(deps): update module golang.org/x/image to v0.45.0 [security] (#38930)
    • Fix(deps): update module golang.org/x/mod to v0.40.0 [security] (#38914)
    • Fix: dedupe issue cross-reference timeline entries (#38881)
    • Fix(server): set ReadHeaderTimeout on HTTP servers (#38878)
    • Fix(repo): avoid a repo-sized temp file for every bundle download (#38863)
    • Fix(lfs): ensure lock listing paginates with a total order (#38850)
    • Fix(avatar): use sha256 and inline the federated avatar lookup (#38843)
    • Fix(gitdiff): render exact-limit diffs and zero-limit comments (#38838)
    • Fix(deps): update dependency mermaid to v11.16.1 [security] (#38813)
    • Fix: misc fixes in pub/gpg/tests (#38809)
    • Fix: git diff blob excerpt (#38808)
    • Fix(packages): show error for duplicate cleanup rules #37820 (#38786)
    • Fix(actions): fix runner docs link (#38783)
    • Fix: git cache (#38763)
    • Fix(actions): evaluate each ${{ }} part on its own (#38754)
    • Fix: don't report failed network requests as JavaScript errors (#38732)
    • Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker (#38728)
    • Fix(api): document X-Total-Count instead of non-existent X-Total header (#38717)
    • Fix(actions): dynamic matrix expansion correctness fixes (#38690)
    • Fix(auth): record last sign-in on reverse proxy login (#38672)
    • Fix(api): accept fully-qualified refs in contents API (#38650)
    • Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 [security] (#38623)
    • Fix(deps): update dependency js-yaml to v5.2.2 [security] (#38622)
    • Fix: abort superseded issue suggestion requests (#38620)
    • Fix(issue): display error toast on batch action failures instead of reloading page (#38593)
    • Fix(deps): update module google.golang.org/grpc to v1.82.1 [security] (#38567)
    • Fix(deps): update module github.com/google/go-github/v88 to v89 (#38433)
    • Fix(deps): update go dependencies (#38429)
    • Fix(deps): update go dependencies (#38346)
    • Fix(deps): update npm dependencies (#38342)
    • Fix(base): correct natural sort of numbers with leading zeros (#38163)
    • Fix(ui): avoid layout shifts in overflow-menu and repo filter (#37818)
    • Fix: make auth source group sync correctly handle team removal (#37161)
    • Fix(release): separate publication time from the release date (#36761)
  • TESTING

    • Test: stop tests from writing into ~/.ssh (#39348)
    • Test(e2e): log out to switch users in pr-review test (#39328)
    • Test: release fixtures loader lock before database work (#39263)
    • Test: speed up tests, fix transaction bug (#39030)
    • Test: run frontend unit tests in browsers (#38860)
    • Test(pubsub): stop racing the Redis SUBSCRIBE ack (#38661)
    • Test(e2e): add pull request merge box test, update AGENTS.md (#38576)
    • Test(e2e): deterministically wait for event stream in logout propagation test (#38535)
  • BUILD

    • Refactor: fix go vet errors related to composite literals (#39341)
    • Build(gogit): disable gogit builds for stable releases (#39324)
    • Refactor: replace jquery.are-you-sure with first-party code (#39233)
    • Refactor: http request binding (#38971)
    • Refactor: clean up git repo and model migration packages (#38564)
    • Refactor: prepare to decouple the "model migration" package and "models" package (#38533)
    • Build: fix snapcraft release (#38260)
    • Build(release): use native golang toolchain for official release builds (#37828)
  • DOCS

    • Docs(webhook): review.type comment lists values the webhook never sends (#39451)
    • Docs(api): document verification and files on the compare endpoint (#39440)
    • Docs(api): name the unadopted-repository search parameter query (#39370)
    • Docs: remove unused COOKIE_USERNAME from app.example.ini (#39365)
    • Docs: document NOTICE_ON_SUCCESS for every cron task (#39352)
    • Docs: correct ALLOW_LOCALNETWORKS description in app.example.ini (#39240)
    • Docs: fix typo in README about app.ini restart (#39223)
    • Docs: fix dead localization doc link in the READMEs (#39211)
    • Docs: Update CHANGELOG for release 1.27.3 (#39170)
    • Docs: Update CHANGELOG for version 1.27.2 (#38923)
    • Docs: Update PGP key expiration date to July 23, 2027 (#38747)
    • Docs(api): document 401/403 responses for user key endpoints (#38711)
    • Docs: Update Changelog for release v1.27.1 (#38670)
    • Docs: Update Changelog for 1.27 (#38440)
    • Docs: Update Security docs (#38422)
  • MISC

    • Refactor: make git http respond error message (#39390)
    • Refactor(api): convert bot accounts through the admin user edit endpoint (#39355)
    • Refactor: replace AWS SDK with a REST client for CodeCommit migration (#39330)
    • Refactor: replace Azure Blob SDK with a REST client (#39315)
    • Refactor: npm route handlers (#39275)
    • Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" (#39248)
    • Refactor(templates): update djlint to 1.46.0 and resolve its new findings (#39231)
    • Refactor: pagination/pager (#39162)
    • Refactor: share package registry error status classification (#39133)
    • Refactor: drop two unmaintained dependencies, rename the byte size helpers (#39083)
    • Refactor(automerge): fix error handling, populate recent automerge tasks on restart (#39001)
    • Refactor: deploy key and private route handlers (#38999)
    • Refactor: wiki edit form (#38918)
    • Refactor: clean up form binding & validation (#38873)
    • Refactor: markup render (#38864)
    • Refactor: api token scope check (#38862)
    • Refactor: replace gliderlabs/ssh with golang.org/x/crypto/ssh (#38837)
    • Refactor: form binding validation (#38832)
    • Refactor: prepare vue components for vapor mode (#38798)
    • Refactor: use the shared workflow model from actionslib (#38768)
    • Refactor(modelmigration): thread context through migration functions (#38758)
    • Refactor: migrate remaining Vue components to <script setup> (#38752)
    • Refactor: introduce trString for frontend (#38741)
    • Refactor(diff): drive diff DOM init from the global selector observer (#38740)
    • Refactor(git): clarify GetBranch behavior to make it only gets an existing branch (#38662)
    • Refactor: replace debounce/throttle deps with first-party code (#38610)
    • Refactor: hide git repo path details from more packages (#38601)
    • Refactor: retry file remove/rename when a file is busy and clean up os detection (#38588)
    • Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie (#38573)
    • Refactor: implement mcaptcha client and add comments/tests (#38561)
    • Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations (#38555)
    • Refactor: remove Path field from git.Repository (#38552)
    • Refactor: make git package handle all git operations (#38543)
    • Refactor: remove unnecessary git command wrapper functions (#38531)
    • Refactor: git repo and relative path handling (#38522)
    • Refactor: clean up fragile diff render templates, use backend typed structs (#38517)
    • Refactor: correct git repo design and fix some legacy problems (#38512)
    • Refactor: fix legacy problems in cmd/serv.go (#38505)
    • Refactor: remove Ctx field from git.Repository (#38500)
    • Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree (#38464)
    • Refactor: introduce ActivePageTimer to help to do partial page refresh (#38372)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

Don't miss a new gitea release

NewReleases is sending notifications on new releases.