We are thrilled to announce the latest release of Gitea v28.0.0.
Gitea drops the historical 1. prefix from its version numbers, so this release is 28.0.0 rather than 1.28.0.
Highlights include audit logging, bot accounts, HTTPS deploy tokens, user impersonation for administrators, code-owner approval rules, diff file filters, and an Actions queue view. See the changelog for everything else.
We are very thankful for the many people who have contributed to the project by sending code patches, reporting issues, translating, and supporting us in many other ways.
Security
Section titled “Security” This release contains security fixes. To give everyone time to upgrade, details will be added to this post in about a week.
How to Update
Section titled “How to Update” You can download Gitea from our downloads page. Please read our installation guide for more information. Before upgrading, read the breaking changes. Then back up your data, replace the binary or Docker container, and restart.
Release binaries no longer include 32-bit x86 or gogit builds, and the Snap is no longer built for armhf. Download file names also no longer carry an OS version suffix, for example gitea-28.0.0-windows-amd64.exe, so update any download scripts.
Special Thanks
Section titled “Special Thanks” We would like to thank all of our supporters on Open Collective who are helping to sustain the project financially.
Major Breaking Changes
Section titled “Major Breaking Changes”
⚠️ Git network operations use an internal proxy and new egress rules (#39426)
Section titled “⚠️ Git network operations use an internal proxy and new egress rules (#39426)” Migrations, mirrors, and other Git network operations now go through an internal proxy that applies the egress settings to direct connections. Review your allow and block lists before upgrading:
- The
externalpreset is removed. For a deny-by-default policy, setEGRESS_MODE = strictand list the allowed hosts.[migrations] EGRESS_MODEcovers migrations and mirrors, and[security] EGRESS_MODEcovers webhooks and OAuth2. - In strict mode, entries without a port only allow ports 80 and 443.
- In the default
laxmode,[security] ALLOWED_HOST_LISTno longer restricts public hosts. Set[security] EGRESS_MODE = strictto keep it as an exclusive allowlist. Gitea logs a startup warning when the list is set without an explicitEGRESS_MODE. - IP address entries no longer accept wildcards, and
*is no longer a valid entry. - Domain entries follow curl syntax:
example.commatches the domain and all subdomains,*.example.commatches only subdomains, andexample.*is invalid. - Invalid
[migrations] BLOCKED_HOST_LISTentries now stop Gitea from starting. [migrations] ALLOWED_DOMAINS,BLOCKED_DOMAINS, andALLOW_LOCALNETWORKSare deprecated in favor of[migrations] ALLOWED_HOST_LISTandBLOCKED_HOST_LIST.
Thank you to @TheFox0x7 for contributing this change.
⚠️ Actions run history now expires (#38855)
Section titled “⚠️ Actions run history now expires (#38855)”
Completed Actions runs are now deleted after 400 days by default, together with their jobs, logs, and artifacts. The new cleanup_action_runs cron task deletes them, by default at midnight. To keep all runs, set the following before upgrading:
0 now means “keep forever” for RUN_RETENTION_DAYS, LOG_RETENTION_DAYS, and ARTIFACT_RETENTION_DAYS. Logs and artifacts are always deleted along with their run.
Thank you to @facorazza for contributing this change.
⚠️ Git 2.25 or newer is required (#39131)
Section titled “⚠️ Git 2.25 or newer is required (#39131)”
Gitea now refuses to start with a Git version older than 2.25.0. If you install Git yourself, check git --version before upgrading.
Thank you to @silverwind for contributing this change.
⚠️ Self-registration is off by default and [server] DOMAIN is ignored (#39400)
Section titled “⚠️ Self-registration is off by default and [server] DOMAIN is ignored (#39400)”
- Self-registration is now disabled unless
[service] DISABLE_REGISTRATION = falseis set explicitly. - Gitea no longer reads
[server] DOMAIN. The instance domain, including the default SSH domain, now comes fromROOT_URL, so setROOT_URLif you relied onDOMAIN.
Thank you to @wxiaoguang for contributing this change.
⚠️ Actions workflows are evaluated more strictly (#39358)
Section titled “⚠️ Actions workflows are evaluated more strictly (#39358)”
- Job-level
if:is now evaluated before the matrix is expanded and may only use thegithub,gitea,needs,vars, andinputscontexts. Movematrixconditions tostrategy.matrix.include/excludeor to step-levelif:. - Matrix
fail-fastis now enforced, so a failing job can cancel the remaining combinations. Setstrategy.fail-fast: falseto let all of them finish. - Workflows in public repositories can no longer call reusable workflows from private repositories, and nested workflows can no longer exceed the caller’s token permissions.
Thank you to @silverwind for contributing these changes.
Major Highlights (Administration)
Section titled “Major Highlights (Administration)”
🚀 View the instance as a specific user (#38614) (#38924)
Section titled “🚀 View the instance as a specific user (#38614) (#38924)” Administrators can now impersonate a user to see Gitea as that user does, which helps reproduce access problems without asking for the user’s password. A banner marks the session and links back to the administrator account. Everything done in the session is performed as the impersonated user, and with audit logging enabled, events record both accounts.
Thank you to @wxiaoguang and @bircni for contributing these improvements.
🚀 Audit logging (#38189)
Section titled “🚀 Audit logging (#38189)” Gitea can now record security-relevant events and show them in the admin, organization, repository, and user settings. Events can be filtered by actor, action, and origin, and administrators can export them as JSONL.
Audit logging is off by default. Enable it with:
Events are kept for 30 days by default. Change this with [audit] RETENTION_DAYS, where 0 keeps them forever.
Thank you to @bircni for contributing this feature.
🚀 Shared Redis configuration (#38550)
Section titled “🚀 Shared Redis configuration (#38550)”
A new [redis] section sets one CONN_STR as the default for cache, session, queue, global lock, and WebSocket pub/sub. It applies to subsystems that are already configured to use Redis but do not set their own connection string.
Thank you to @mohammad-rj and @wxiaoguang for contributing this feature.
🚀 Dedicated bot accounts (#38966)
Section titled “🚀 Dedicated bot accounts (#38966)” Bot accounts are meant for automation. They authenticate with access tokens, cannot sign in interactively, and receive no notifications or emails. Administrators can create bots, manage their tokens, and convert eligible local accounts between users and bots from the admin UI, API, or CLI.
Thank you to @joestump and @bircni for contributing this feature.
🚀 Live notifications move to WebSockets (#36965)
Section titled “🚀 Live notifications move to WebSockets (#36965)”
Notification counts, stopwatch updates, and logout events now use a WebSocket at /-/ws instead of server-sent events at /user/events. Reverse proxies must forward WebSocket upgrade headers, otherwise notification counts and stopwatch updates fall back to polling. Deployments with multiple Gitea processes need [websocket] PUBSUB_TYPE = redis and a Redis connection. The [ui.notification] EVENT_SOURCE_UPDATE_TIME setting is removed.
Thank you to @mohammad-rj for contributing this change.
Major Highlights (Code & Collaboration)
Section titled “Major Highlights (Code & Collaboration)”
🚀 Repository-scoped HTTPS deploy tokens (#37306)
Section titled “🚀 Repository-scoped HTTPS deploy tokens (#37306)” Deploy tokens are the HTTPS counterpart to SSH deploy keys. Each token is scoped to one repository with read or read-write access and serves as the password for Git and LFS over HTTPS. Both deploy tokens and personal access tokens (#38907) can be regenerated in place.
Thank you to @ToastyTheBot and @gomitrah for contributing these features.
🚀 Search and filter files in pull request diffs (#37068)
Section titled “🚀 Search and filter files in pull request diffs (#37068)” The diff file tree gains a search box and a file-extension filter. Both narrow the file tree and the diff, and the extension filter is kept in the URL, so a filtered view can be shared.
Thank you to @McMichalK, @silverwind, and @wxiaoguang for contributing this feature.
🚀 Require code-owner reviews before merging (#34995)
Section titled “🚀 Require code-owner reviews before merging (#34995)”
A new branch protection option blocks merging until every matching CODEOWNERS rule is approved by one of its code owners or a member of a listed team.
Thank you to @Naxdy, @bircni, and @wxiaoguang for contributing this feature.
🚀 Choose which repository notifications to receive (#37571)
Section titled “🚀 Choose which repository notifications to receive (#37571)” The watch button is now a menu with Participating and mentions, All activity, Ignore, and Custom. Custom adds notifications for any of issues, pull requests, and releases. These choices apply to both UI and email notifications.
Thank you to @schonwetter for contributing this feature.
🚀 Switch repositories from the repository header (#38188)
Section titled “🚀 Switch repositories from the repository header (#38188)” A dropdown next to the repository name lets you search and switch between repositories of the same owner.
Thank you to @bircni for contributing this feature.
🚀 Exclude files from generated repositories (#38064)
Section titled “🚀 Exclude files from generated repositories (#38064)”
Template repositories can list files and directories in an [exclude] section of .gitea/template to leave them out of generated repositories.
Thank you to @paarth-k2002 for contributing this feature.
🚀 Close pull requests through closing references (#39393)
Section titled “🚀 Close pull requests through closing references (#39393)”
Closing references such as Fixes: #123 can now close pull requests, not only issues.
Thank you to @silverwind for contributing this improvement.
🚀 Use internal and external issue trackers together (#39354)
Section titled “🚀 Use internal and external issue trackers together (#39354)”
Repositories can now use Gitea’s built-in issues together with an external tracker whose references use an alphanumeric or regular-expression format, such as JIRA-123. Leave the external tracker URL empty, otherwise the Issues tab still redirects to the external tracker.
Thank you to @breken-ai for contributing this improvement.
🚀 REUSE license detection and multiple-license display (#38720)
Section titled “🚀 REUSE license detection and multiple-license display (#38720)” Gitea now detects REUSE-style license files named by their SPDX identifier and shows every detected license with a link to its file.
Thank you to @TheFox0x7 for contributing this feature.
Major Highlights (Actions)
Section titled “Major Highlights (Actions)”
🚀 See what is running and waiting in the build queue (#38585)
Section titled “🚀 See what is running and waiting in the build queue (#38585)” The new queue view lists running jobs first, then waiting jobs in the order runners pick them up. Administrators get an instance-wide view with owner, repository, and status filters, and each repository has its own queue in the Actions tab. Both views refresh in place.
Thank you to @bircni for contributing this feature.
🚀 Workflow run lists refresh automatically (#38329)
Section titled “🚀 Workflow run lists refresh automatically (#38329)” The Actions run list now refreshes automatically, except while the browser tab is in the background.
Thank you to @SudhanshuMatrix for contributing this feature.
🚀 Preview build artifacts in the browser (#36754)
Section titled “🚀 Preview build artifacts in the browser (#36754)” The Actions run view can now browse artifacts and preview text, images, PDFs, and generated HTML such as test reports. Previews require sign-in and read access to the run. HTML previews run in a sandboxed frame. ZIP downloads remain available.
[actions] ARTIFACT_PREVIEW_MAX_SIZE limits previews to artifacts of up to 10 MiB by default. 0 disables previews and -1 removes the limit. Individual files are also subject to [ui] MAX_DISPLAY_FILE_SIZE.
Thank you to @bircni for contributing this feature.
🚀 Dynamic matrices, max-parallel, and more workflow syntax (#36564) (#36357) (#39358)
Section titled “🚀 Dynamic matrices, max-parallel, and more workflow syntax (#36564) (#36357) (#39358)”
A job matrix can now be built from the outputs of earlier jobs, and strategy.max-parallel limits how many matrix jobs run at once. Properties such as runs-on can depend on needs and are resolved once those jobs finish. uses: accepts self: to reference actions and workflows on the same instance, and reusable workflow calls accept $/ for the same repository (#38822). Pushing an invalid workflow file now creates a failed run that shows the error.
Thank you to @ZPascal and @silverwind for contributing these improvements.
Major Highlights (API & Packages)
Section titled “Major Highlights (API & Packages)”
🚀 Project board APIs (#38691)
Section titled “🚀 Project board APIs (#38691)” New REST endpoints manage project boards at repository, organization, and user level.
Thank you to @silverwind for contributing this feature.
🚀 More workflow run management APIs (#35382) (#38756)
Section titled “🚀 More workflow run management APIs (#35382) (#38756)” New Actions endpoints manage workflow runs, fetch their logs, and force-cancel them.
Thank you to @rossigee and @Zettat123 for contributing these improvements.
🚀 Package registry improvements (#37890) (#39267) (#36695) (#38968)
Section titled “🚀 Package registry improvements (#37890) (#39267) (#36695) (#38968)”
The npm registry supports npm deprecate, richer version metadata, and the single-version API. Helm charts can be uploaded with provenance files, and site administrators can list all packages through a new API.
Thank you to @philip-x-rutkowski-intel-com, @silverwind, @TheFox0x7, and @lunny for contributing these improvements.
Changelog
Section titled “Changelog”
BREAKING
SECURITY
- Fix(git): reject invalid and duplicate Git objects on push (#39472)
- Fix(git)!: route Git network operations through an internal proxy and update egress settings (#39426)
- Fix(ssh): identify presented public keys by fingerprint (#39423)
- Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate (#39399)
- Fix(deps): update golang.org/x/crypto SSH to address denial of service (#39219)
- Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking (#39063)
FEATURES
- Feat(actions): update actionslib, support
self:, misc fixes (#39358) - Feat(api): list all packages for site administrators (#38968)
- Feat: manage bot accounts from the admin UI, API and CLI (#38966)
- Feat(user): Personal access tokens can be regenerated (#38907)
- Feat(actions): support
$/prefix in reusable workflowuses:(#38822) - Feat(actions): add force-cancel workflow run API (#38756)
- Feat(licenses): support REUSE specification in licenses (#38720)
- Feat(api): add project APIs (#38691)
- Feat(webhook): fire repository event on repo rename (#38641)
- Feat: admin impersonates a user (#38614)
- Feat(actions): add build queue view (#38585)
- Feat(setting): add shared [redis] section as default for redis-backed subsystems (#38550)
- Feat(repo): prioritize well-known READMEs and optimize discovery (#38532)
- Feat(actions): implement adaptive auto-refresh for workflow runs list (#38329)
- Feat(auth): add
disable-2facommand (#38275) - Feat: Add audit logging (#38189)
- Feat(repo): add quick repository switcher to repo header (#38188)
- Feat(repo): support file exclusion logic in .gitea/template in template generation (#38064)
- Feat(web): Add org removal functionality to admin user details page (#38013)
- Feat: add watch options (#37571)
- Feat: add deploy tokens (#37306)
- Feat(diff): Add search and extension filter to diff sidebar (#37068)
- Feat: Replace SSE with WebSocket for UI notifications (#36965)
- Feat(actions): Add artifact preview in Actions run view (#36754)
- Feat(packages): add support for uploading helm provenance files (#36695)
- Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows (#36564)
- Feat: Add max-parallel Support for Gitea Actions (#36357)
- Feat(actions): Add Actions API endpoints for workflow run management and logs (#35382)
- Feat: Add block on pending codeowner reviews branch protection (#34995)
- Feat(actions): update actionslib, support
ENHANCEMENTS
- Enhance: allow auto-closing PRs from PRs (#39393)
- Enhance(actions): add pending job status and align job statuses with GitHub (#39376)
- Enhance(acme): add configurable ACME profile (#39375)
- Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data (#39363)
- Enhance: improve issue-pattern capture groups and support both internal&external trackers enabled (#39354)
- Enhance: update mermaid to v12 (#39331)
- Enhance(notifications): mark current notification page as read (#39294)
- Enhance: support
ETagon streamed repository archives, supportIf-None-Match: *(#39289) - Enhance: truncate but show long lines in diffs (#39279)
- Enhance(packages): implement npm single-version API and add per-version repository (#39267)
- Enhance: move window.config to JSON, improve CSP format (#39236)
- Enhance: improve commit page header (#39229)
- Enhance: Improve validation errors for secrets/variables (#39221)
- Enhance(repo): check full repo name for dangerous operations (#39213)
- Enhance(web): hide attachment dropzone on preview tab in combo editor (#39204)
- Enhance(web): show attachment URL and UUID in dropzone preview (#39203)
- Enhance(actions): make workflow dispatch choice dropdown support search (#39154)
- Enhance(repo): unify diff stats on commit pages, misc diff tweaks (#39134)
- Enhance: use browser’s locale to detect week’s first day for the contribution map (#38995)
- Enhance(ui): forced colors mode enhancements (#38991)
- Enhance: user-friendly packages setup manual (#38946)
- Enhance: inherit team access for all units (#38938)
- Enhance(admin): show impersonation banner and keep password change with the user (#38924)
- Enhance(ui): tint toast backgrounds by level (#38919)
- Enhance(repo): add default object format setting (#38877)
- Enhance(actions): set ref_protected in context (#38852)
- Enhance(ui): restyle toasts (#38842)
- Enhance: refine repo watching (#38835)
- Enhance: fall back to DEFAULT_TEMPLATE.md when style-specific template is missing (#38803)
- Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint (#38770)
- Enhance(api): expose file mode in contents API response (#38713)
- Enhance(tls): use go’s tls defaults (#38687)
- Enhance(ui): improve luminance calculations (#38682)
- Enhance(api): add
tag_filterquery parameter to release list API (#38681) - Enhance(actions): replace
ansi_upwith first-party code (#38619) - Enhance: keep status check list scrolled on merge box reload (#38597)
- Enhance(actions): action view enhancements (#38594)
- Enhance(ui): tweak tooltip style and misc fixes (#38524)
- Enhance: improve e-mail templates (#38396)
- Enhance(webhook): add reviewer name to MS Teams review request notifications (#38289)
- Enhance: extend
<video>tag allowed attributes (#38279) - Enhance(packages/npm): expand version metadata and support npm deprecate (#37890)
PERFORMANCE
BUGFIXES
- Fix(actions): preserve admitted jobs and runs in their concurrency group (#39461)
- Fix(api): commit tree SHA is the commit ID (#39449)
- Fix: PR merge (#39442)
- Fix(actions): evaluate job-level
if:before concurrency check (#39437) - Fix(api): allow pending-inline-comment-only reviews (#39433)
- Fix: sanitize external render command line arguments (#39417)
- Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data (#39406)
- Fix(indexer): index full file paths and real offsets in bleve (#39405)
- Fix(git): keep leading dashes in git grep search patterns (#39404)
- Fix: use clearer message for ldap auth failure (#39392)
- Fix(repo): commit page fails to render unsigned commits with a different committer (#39381)
- Fix: focus confirm button and use red for delete confirmations (#39350)
- Fix(migrations): preserve SHA-256 pull request commit IDs (#39343)
- Fix(ui): misc ui fixes (#39336)
- Fix(actions): use gitea’s clock for actions durations (#39323)
- Fix(actions): never show negative running durations (#39322)
- Fix: package registry keypair creation race (#39319)
- Fix: add default timeout and handle errors for HaveIBeenPwned API (#39316)
- Fix(user): unify email validation for registration and settings (#39304)
- Fix(ui): use button elements for branch and tag dropdown tabs (#39285)
- Fix(auth): fix ssh and gpg key verification on windows (#39283)
- Fix(feed): use meaningful lines as comment excerpt (#39276)
- Fix(projects): allow max columns to the limit (#39272)
- Fix: pass merge commit messages to git via stdin (#39269)
- Fix(repo): surface unrelated histories on Sync Fork (#39258)
- Fix: avoid nil panic and refactor some trivial problems (#39251)
- Fix: restore missing blob file when re-publishing a package (#39239)
- Fix(automerge): validate head commit before merge (#39235)
- Fix(httplib): prevent leaking localhost:3000 in public links (#39217)
- Fix(setting): honor bare -1 for timeout settings (#39181)
- Fix: correct repo/attatchment absolute url and release layout (#39178)
- Fix(web): populate the reason for “cannot commit to branch” in web editor commit form (#39155)
- Fix(process): reap entire process group on cmd.Cancel (#39143)
- Fix: recognize linguist language aliases (#39135)
- Fix(repo): preserve transfer recipient collaboration (#39042)
- Fix(db): make paginated database reads always require “order” option (#39017)
- Fix: make local queue PopItem can be notified (#39011)
- Fix: classify git failures on stderr, restrict migration failure detail (#39010)
- Fix: allow re-requesting uncounted review approvals (#38988)
- Fix(actions): allow larger scheduled workflows (#38985)
- Fix: resolve actions commit status permission per repository (#38977)
- Fix(deps): update module golang.org/x/image to v0.45.0 [security] (#38930)
- Fix(deps): update module golang.org/x/mod to v0.40.0 [security] (#38914)
- Fix: dedupe issue cross-reference timeline entries (#38881)
- Fix(server): set
ReadHeaderTimeouton HTTP servers (#38878) - Fix(repo): avoid a repo-sized temp file for every bundle download (#38863)
- Fix(lfs): ensure lock listing paginates with a total order (#38850)
- Fix(avatar): use sha256 and inline the federated avatar lookup (#38843)
- Fix(gitdiff): render exact-limit diffs and zero-limit comments (#38838)
- Fix(deps): update dependency mermaid to v11.16.1 [security] (#38813)
- Fix: misc fixes in pub/gpg/tests (#38809)
- Fix: git diff blob excerpt (#38808)
- Fix(packages): show error for duplicate cleanup rules #37820 (#38786)
- Fix(actions): fix runner docs link (#38783)
- Fix: git cache (#38763)
- Fix(actions): evaluate each
${{ }}part on its own (#38754) - Fix: don’t report failed network requests as JavaScript errors (#38732)
- Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker (#38728)
- Fix(api): document X-Total-Count instead of non-existent X-Total header (#38717)
- Fix(actions): dynamic matrix expansion correctness fixes (#38690)
- Fix(auth): record last sign-in on reverse proxy login (#38672)
- Fix(api): accept fully-qualified refs in contents API (#38650)
- Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 [security] (#38623)
- Fix(deps): update dependency js-yaml to v5.2.2 [security] (#38622)
- Fix: abort superseded issue suggestion requests (#38620)
- Fix(issue): display error toast on batch action failures instead of reloading page (#38593)
- Fix(deps): update module google.golang.org/grpc to v1.82.1 [security] (#38567)
- Fix(deps): update module github.com/google/go-github/v88 to v89 (#38433)
- Fix(deps): update go dependencies (#38429)
- Fix(deps): update go dependencies (#38346)
- Fix(deps): update npm dependencies (#38342)
- Fix(base): correct natural sort of numbers with leading zeros (#38163)
- Fix(ui): avoid layout shifts in
overflow-menuand repo filter (#37818) - Fix: make auth source group sync correctly handle team removal (#37161)
- Fix(release): separate publication time from the release date (#36761)
TESTING
- Test: stop tests from writing into
~/.ssh(#39348) - Test(e2e): log out to switch users in pr-review test (#39328)
- Test: release fixtures loader lock before database work (#39263)
- Test: speed up tests, fix transaction bug (#39030)
- Test: run frontend unit tests in browsers (#38860)
- Test(pubsub): stop racing the Redis SUBSCRIBE ack (#38661)
- Test(e2e): add pull request merge box test, update AGENTS.md (#38576)
- Test(e2e): deterministically wait for event stream in logout propagation test (#38535)
- Test: stop tests from writing into
BUILD
- Refactor: fix
go veterrors related to composite literals (#39341) - Build(gogit): disable gogit builds for stable releases (#39324)
- Refactor: replace jquery.are-you-sure with first-party code (#39233)
- Refactor: http request binding (#38971)
- Refactor: clean up git repo and model migration packages (#38564)
- Refactor: prepare to decouple the “model migration” package and “models” package (#38533)
- Build: fix snapcraft release (#38260)
- Build(release): use native golang toolchain for official release builds (#37828)
- Refactor: fix
DOCS
- Docs(webhook): review.type comment lists values the webhook never sends (#39451)
- Docs(api): document verification and files on the compare endpoint (#39440)
- Docs(api): name the unadopted-repository search parameter query (#39370)
- Docs: remove unused COOKIE_USERNAME from app.example.ini (#39365)
- Docs: document NOTICE_ON_SUCCESS for every cron task (#39352)
- Docs: correct ALLOW_LOCALNETWORKS description in app.example.ini (#39240)
- Docs: fix typo in README about app.ini restart (#39223)
- Docs: fix dead localization doc link in the READMEs (#39211)
- Docs: Update CHANGELOG for release 1.27.3 (#39170)
- Docs: Update CHANGELOG for version 1.27.2 (#38923)
- Docs: Update PGP key expiration date to July 23, 2027 (#38747)
- Docs(api): document 401/403 responses for user key endpoints (#38711)
- Docs: Update Changelog for release v1.27.1 (#38670)
- Docs: Update Changelog for 1.27 (#38440)
- Docs: Update Security docs (#38422)
MISC
- Refactor: make git http respond error message (#39390)
- Refactor(api): convert bot accounts through the admin user edit endpoint (#39355)
- Refactor: replace AWS SDK with a REST client for CodeCommit migration (#39330)
- Refactor: replace Azure Blob SDK with a REST client (#39315)
- Refactor: npm route handlers (#39275)
- Refactor: GetDiffShortStat and fix panic caused by inconsistent “changed file number” (#39248)
- Refactor(templates): update djlint to 1.46.0 and resolve its new findings (#39231)
- Refactor: pagination/pager (#39162)
- Refactor: share package registry error status classification (#39133)
- Refactor: drop two unmaintained dependencies, rename the byte size helpers (#39083)
- Refactor(automerge): fix error handling, populate recent automerge tasks on restart (#39001)
- Refactor: deploy key and private route handlers (#38999)
- Refactor: wiki edit form (#38918)
- Refactor: clean up form binding & validation (#38873)
- Refactor: markup render (#38864)
- Refactor: api token scope check (#38862)
- Refactor: replace
gliderlabs/sshwithgolang.org/x/crypto/ssh(#38837) - Refactor: form binding validation (#38832)
- Refactor: prepare vue components for vapor mode (#38798)
- Refactor: use the shared workflow model from actionslib (#38768)
- Refactor(modelmigration): thread context through migration functions (#38758)
- Refactor: migrate remaining Vue components to
<script setup>(#38752) - Refactor: introduce trString for frontend (#38741)
- Refactor(diff): drive diff DOM init from the global selector observer (#38740)
- Refactor(git): clarify GetBranch behavior to make it only gets an existing branch (#38662)
- Refactor: replace debounce/throttle deps with first-party code (#38610)
- Refactor: hide git repo path details from more packages (#38601)
- Refactor: retry file remove/rename when a file is busy and clean up os detection (#38588)
- Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie (#38573)
- Refactor: implement mcaptcha client and add comments/tests (#38561)
- Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations (#38555)
- Refactor: remove Path field from git.Repository (#38552)
- Refactor: make git package handle all git operations (#38543)
- Refactor: remove unnecessary git command wrapper functions (#38531)
- Refactor: git repo and relative path handling (#38522)
- Refactor: clean up fragile diff render templates, use backend typed structs (#38517)
- Refactor: correct git repo design and fix some legacy problems (#38512)
- Refactor: fix legacy problems in cmd/serv.go (#38505)
- Refactor: remove Ctx field from git.Repository (#38500)
- Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree (#38464)
- Refactor: introduce ActivePageTimer to help to do partial page refresh (#38372)
Contributors for this release
Section titled “Contributors for this release” We thank all contributors who helped make this release possible!