3.19.0 - 2026-10-07
❤️ Thanks to all contributors! ❤️
@6543, @ChrisJr404, @KR-Ravindra, @LaGrunge, @cacarico, @chiliec, @confusedsushi, @grisu48, @healdropper, @hsdfat, @jagerman, @joseph0531, @lafriks, @mattwilkinsonn, @qwerty287, @roian6, @sb123sb123, @somaz94, @spatterIight, @tehlordvortex, @thiagola92, @tunglambk, @usiegj00, @xoxys
🔒 Security
- Prevent injection of matrix env vars into default clone step [#7157]
✨ Features
📈 Enhancement
- CLI exec sanitize secrets too [#6877]
- Harmonize unit test patterns [#7229]
- Generalize log output groups [#7226]
- Include HTTP status in Bitbucket errors without a message [#7227]
- Add default user namespace support with configurable non-root override [#6943]
- Adopt Golang v1.27 [#7153]
- Store workflow/step dependencies in database and update API [#6130]
- Fix/docs deps and flaky test [#7204]
- Add AgentListWithOpts with pagination options [#7155]
- Use more unique sign to detect commands [#7122]
- Run swaggo in golangci-lint [#7121]
- feat(agent): add CI_AGENT_ID and CI_AGENT_LABELS runtime env vars [#7070]
🐛 Bug Fixes
- Fix step logs lost when pipeline ends with skipped workflows [#7240]
- Release agents waiting on long polls during server shutdown [#7189]
- Add version endpoint to API as per spec [#7232]
- Accept host:port registry addresses [#7235]
- Fix queue scheduler debug log spam [#7224]
- Fix infinite hook pagination loop on Bitbucket Cloud [#7210]
- Wait for informer cache sync before checking pod deletion [#7158]
- Fix race condition on concurrent pipeline config persist [#7192]
- Reload user from store before refreshing OAuth token [#7176]
- Ignore GitLab rejecting a commit status transition [#7217]
- Fix workspace volume mismatch when using CLI exec with the Kubernetes backend [#7150]
- Fix CLI shell completion [#7203]
- Fix url including when combined with ansi escapes [#7196]
- Fix nix dev env by disable static linking and make pnpm work again [#7193]
- Fix data race in SSE stream handlers when the client disconnects early [#7139]
- Disable
cmd.exeAutoRun commands for local pipelines on Windows [#7162] - Restart a pipeline that errored before its config was persisted [#7120]
- Ignore directories while fetching files [#7145]
- Skip short multi-line secret lines [#7144]
- Fix agent panic in local backend cleanup when a workflow is canceled before a step started [#7132]
- Report an in-setup pipeline status as pending on all forges [#7118]
- Update CLI command in CLI & API example [#7129]
- Fix crash rendering a pipeline with a stepless workflow [#7119]
📚 Documentation
- Harmonize secrets docs [#7236]
- Clarify secret precedence order [#7233]
- Fix docs link in systemd example unit [#7222]
- Update pnpm to v12.9.1 [#7219]
- Use CI to update latest version on mastodon profile [#7179]
- Update dependency @types/node to v25.9.9 [#7211]
- Update docs npm deps non-major [#7208]
- Update docs npm deps non-major [#7186]
- Add MASH to awesome list [#7191]
- docs: document manual Linux binary installation [#7160]
📦️ Dependency
- Update module gitlab.com/gitlab-org/api/client-go/v3 to v3.16.0 [#7234]
- Update dependency @vueuse/core to v15 [#7212]
- Update dependency dotenv to v18 [#7213]
- Update module github.com/google/go-github/v91 to v92 [#7200]
- Update module gitlab.com/gitlab-org/api/client-go/v2 to v3 [#7201]
- Update docker.io/woodpeckerci/plugin-codecov Docker tag to v2.3.3 [#7199]
- Update golangci/golangci-lint Docker tag to v2.13.1 [#7057]
- Update dependency mvdan/gofumpt to v0.12.0 [#7185]
- Update woodpeckerci/plugin-release Docker tag to v0.3.2 [#7184]
- Update docker.io/woodpeckerci/plugin-surge-preview Docker tag to v1.4.3 [#7182]
- Update docker.io/woodpeckerci/plugin-trivy Docker tag to v1.6.1 [#7183]
- Update docker.io/woodpeckerci/plugin-docker-buildx Docker tag to v6.1.2 [#7180]
- Update docker.io/woodpeckerci/plugin-editorconfig-checker Docker tag to v0.3.4 [#7181]
- Update dependency simple-icons to v16.31.0 [#7138]
- Update woodpeckerci/plugin-git Docker tag to v2.10.1 [#7135]
Misc
- Remove remainig gitpod artifacts [#7216]