Pangram verdict · v3.3
We believe this text is mainly human-written, with some AI and AI-assisted content.
AI likelihood · overall
HumanArticle text · 851 words · 6 segments analyzed
We are thrilled to announce the latest release of Gitea v28.0.0. Gitea drops the historical 1. prefix from its version numbers, so this release is 28.0.0 rather than 1.28.0. Highlights include audit logging, bot accounts, HTTPS deploy tokens, user impersonation for administrators, code-owner approval rules, diff file filters, and an Actions queue view. See the changelog for everything else. We are very thankful for the many people who have contributed to the project by sending code patches, reporting issues, translating, and supporting us in many other ways. This release contains security fixes. To give everyone time to upgrade, details will be added to this post in about a week. You can download Gitea from our downloads page. Please read our installation guide for more information. Before upgrading, read the breaking changes. Then back up your data, replace the binary or Docker container, and restart. Release binaries no longer include 32-bit x86 or gogit builds, and the Snap is no longer built for armhf. Download file names also no longer carry an OS version suffix, for example gitea-28.0.0-windows-amd64.exe, so update any download scripts. We would like to thank all of our supporters on Open Collective who are helping to sustain the project financially. Major Breaking ChangesSection titled “Major Breaking Changes” ⚠ Git network operations use an internal proxy and new egress rules (#39426)Section titled “⚠ Git network operations use an internal proxy and new egress rules (#39426)” Migrations, mirrors, and other Git network operations now go through an internal proxy that applies the egress settings to direct connections. Review your allow and block lists before upgrading: The external preset is removed. For a deny-by-default policy, set EGRESS_MODE = strict and list the allowed hosts. [migrations] EGRESS_MODE covers migrations and mirrors, and [security] EGRESS_MODE covers webhooks and OAuth2. In strict mode, entries without a port only allow ports 80 and 443. In the default lax mode, [security] ALLOWED_HOST_LIST no longer restricts public hosts. Set [security] EGRESS_MODE = strict to keep it as an exclusive allowlist. Gitea logs a startup warning when the list is set without an explicit EGRESS_MODE. IP address entries no longer accept wildcards, and * is no longer a valid entry. Domain entries follow curl syntax: example.com matches the domain and all subdomains, *.example.com matches only subdomains, and example.* is invalid. Invalid [migrations] BLOCKED_HOST_LIST entries now stop Gitea from starting. [migrations] ALLOWED_DOMAINS, BLOCKED_DOMAINS, and ALLOW_LOCALNETWORKS are deprecated in favor of [migrations] ALLOWED_HOST_LIST and BLOCKED_HOST_LIST. Thank you to @TheFox0x7 for contributing this change. Completed Actions runs are now deleted after 400 days by default, together with their jobs, logs, and artifacts. The new cleanup_action_runs cron task deletes them, by default at midnight. To keep all runs, set the following before upgrading: [actions]RUN_RETENTION_DAYS = 0 0 now means “keep forever” for RUN_RETENTION_DAYS, LOG_RETENTION_DAYS, and ARTIFACT_RETENTION_DAYS. Logs and artifacts are always deleted along with their run. Thank you to @facorazza for contributing this change. Gitea now refuses to start with a Git version older than 2.25.0. If you install Git yourself, check git --version before upgrading. Thank you to @silverwind for contributing this change. ⚠ Self-registration is off by default and [server] DOMAIN is ignored (#39400)Section titled “⚠ Self-registration is off by default and [server] DOMAIN is ignored (#39400)” Self-registration is now disabled unless [service] DISABLE_REGISTRATION = false is set explicitly. Gitea no longer reads [server] DOMAIN. The instance domain, including the default SSH domain, now comes from ROOT_URL, so set ROOT_URL if you relied on DOMAIN. Thank you to @wxiaoguang for contributing this change. Job-level if: is now evaluated before the matrix is expanded and may only use the github, gitea, needs, vars, and inputs contexts.
Move matrix conditions to strategy.matrix.include/exclude or to step-level if:. Matrix fail-fast is now enforced, so a failing job can cancel the remaining combinations. Set strategy.fail-fast: false to let all of them finish.
Workflows in public repositories can no longer call reusable workflows from private repositories, and nested workflows can no longer exceed the caller’s token permissions. Thank you to @silverwind for contributing these changes.
Major Highlights (Administration)Section titled “Major Highlights (Administration)” Administrators can now impersonate a user to see Gitea as that user does, which helps reproduce access problems without asking for the user’s password. A banner marks the session and links back to the administrator account. Everything done in the session is performed as the impersonated user, and with audit logging enabled, events record both accounts.
Thank you to @wxiaoguang and @bircni for contributing these improvements. Gitea can now record security-relevant events and show them in the admin, organization, repository, and user settings. Events can be filtered by actor, action, and origin, and administrators can export them as JSONL. Audit logging is off by default. Enable it with: [audit]RECORD_OUTPUT = database Events are kept for 30 days by default. Change this with [audit] RETENTION_DAYS, where 0 keeps them forever. Thank you to @bircni for contributing this feature.
A new [redis] section sets one CONN_STR as the default for cache, session, queue, global lock, and WebSocket pub/sub. It applies to subsystems that are already configured to use Redis but do not set their own connection string.