G

Gitea

G
Gitea Self-hosted v1.27.1

v1.27.1

SECURITY fix(oauth2): enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints (#38591) (#38606) API fix(api): align Swagger schemas for UserSettings and TopicListResponse (#38590) (#38592) ENHANCEMENTS enhance: improve diff contrast in light and dark themes (#37477) (#38574) BUGFIXES fix: skip OIDC end-session after password login for OAuth2 users (#38439) (#38666) fix: make Actions log p…

G
Gitea Self-hosted v1.27.0

v1.27.0

BREAKING Feat(actions)!: improve support for reusable workflows (#37478) Use Content-Security-Policy: script nonce (#37232) SECURITY Fix: various security fixes (#38406) (#38426) Fix(security): harden access checks and migration validation (#38324) (#38400) Fix: enforce public-only token scope and harden push options / locale parsing (#38323) (#38399) Fix(pull): re-evaluate review official flag on…

G
Gitea Self-hosted v1.27.0-rc0

v1.27.0-rc0

BREAKING Feat(actions)!: improve support for reusable workflows (#37478) Use Content-Security-Policy: script nonce (#37232) SECURITY Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#37786) Fix(oauth): restrict introspection to the token's client (#38042) Fix(api): don't expose private org membership via public_members (#38145) Fix(actions): deny fork-PR cross-repo acces…

G
Gitea Self-hosted v1.28.0-dev

v1.28.0-dev

fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2…

G
Gitea Self-hosted v1.26.4

v1.26.4

SECURITY fix(auth): do not auto-reactivate disabled users on OAuth2 callback (#38009) (#38183) BUGFIXES fix: walk git log context error handling (#38182) (#38185) Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

G
Gitea Self-hosted v1.26.3

v1.26.3

WarningPlease upgrade to 1.26.4 directly. A regression in this release can cause "context deadline exceeded" errors when opening any repository's code pages (#38177). Please hold off on upgrading until a fix is released. BREAKING fix(actions)!: require merged PR to bypass fork PR approval gate (#38010) (#38041) SECURITY fix(hostmatcher): patch incorrect private list (#38170) (#38173) fix: Various…

G
Gitea Self-hosted v1.26.2

v1.26.2

SECURITY fix(permissions): Fix reading permission (#37769) fix(actions): make artifact signature payloads unambiguous (#37707) fix: Unify public-only token filtering in API queries and repo access checks (#37118) fix: Add missed token scope checking (#37735) fix(oauth): bind token exchanges to the original client request (#37704) fix(oauth): strengthen PKCE validation and refresh token replay prot…

G
Gitea Self-hosted v1.26.1

v1.26.1

BUGFIXES Add event.schedule context for schedule actions task (#37320) (#37348) Fix an issue where changing an organization's visibility caused problems when users had forked its repositories. (#37324) (#37344) Use modern "git update-index --cacheinfo" syntax to support more file names (#37338) (#37343) Fix URL related escaping for oauth2 (#37334) (#37340) When the requested arch rpm is missing fa…

G
Gitea Self-hosted v1.26.0

v1.26.0

BREAKING Correct swagger annotations for enums, status codes, and notification state (#37030) Remove GET API registration-token (#36801) Support Actions concurrency syntax (#32751) Make PUBLIC_URL_DETECTION default to "auto" (#36955) SECURITY Bound PageSize in ListUnadoptedRepositories (#36884) FEATURES Support Actions concurrency syntax (#32751) Add terraform state registry (#36710) Instance-wide…

G
Gitea Self-hosted v1.26.0-rc0

v1.26.0-rc0

BREAKING Correct swagger annotations for enums, status codes, and notification state (#37030) Remove GET API registration-token (#36801) Support Actions concurrency syntax (#32751) Make PUBLIC_URL_DETECTION default to "auto" (#36955) SECURITY Bound PageSize in ListUnadoptedRepositories (#36884) FEATURES Support Actions concurrency syntax (#32751) Add terraform state registry (#36710) Instance-wide…

G
Gitea Self-hosted v1.27.0-dev

v1.27.0-dev: Fix various problems (#37129)

Fix #37128 Manually tested with various cases (issue, pr) X (close, reopen) Fix #36792 Fix the comment Fix #36755 Add a "sleep 3" Follow up #36697 Clarify the "attachment uploading" problem and function call Signed-off-by: wxiaoguang wxiaoguang@gmail.com Co-authored-by: TheFox0x7 thefox0x7@gmail.com

G
Gitea Self-hosted v1.25.5

v1.25.5

SECURITY Toolchain Update to Go 1.25.6 (#36480) (#36487) Adjust the toolchain version (#36537) (#36542) Update toolchain to 1.25.8 for v1.25 (#36888) Prevent redirect bypasses via backslash-encoded paths (#36660) (#36716) Fix get release draft permission check (#36659) (#36715) Fix a bug user could change another user's primary email (#36586) (#36607) Fix OAuth2 authorization code expiry and reuse…