Gitea 28.0.0 : nouvelle option Redis, casses de compatibilité, sécurité sur les branches
ven, 02/10/2026 - 15:07
Gitea est une plateforme de gestion de référentiels de code basée sur Git. La version 28 est sortie le 30 septembre. Cette version propose de nombreuses améliorations :
- retrait du préfixe 1 dans les numéros de version d'où le 28.0.0 et non le 1.12.0
- cette version contient des corrections de sécurité
- casses de compatibilité : retrait du preset external, le mode strict ipose les ports 80 et 443 uniquement
- les Actions terminées sont supprimées après 400 jours incluant les jobs, les logs et les artefacts
- Git 2.25 minimum est nécessaire
- un meilleur contrôle des flux Actions
- Les administrateurs peuvent désormais se connecter à Gitea via l'interface utilisateur, ce qui permet de reproduire les problèmes d'accès sans avoir à saisir le mot de passe. Une bannière signale la session et renvoie vers le compte administrateur. Toutes les actions effectuées dans la session sont réalisées par l'utilisateur dont l'identité est usurpée, et grâce à l'enregistrement des événements, les événements sont consignés pour les deux comptes.
- nouvelle section Redis dans CONN_STR
- les notivations live migrent utilisent maintnenat des websockets
- nouvelle règle de protection des branches bloque une fusion jusqu'à ce que chaque règle CODEOWNERS soit approuvée
- on peut maintenant voir le build d'artefacts en prévisualisation sur le navigateur
Changelog complet
BREAKING
SECURITY
- Fix(git): reject invalid and duplicate Git objects on push (#39472)
- Fix(git)!: route Git network operations through an internal proxy and update egress settings (#39426)
- Fix(ssh): identify presented public keys by fingerprint (#39423)
- Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate (#39399)
- Fix(deps): update golang.org/x/crypto SSH to address denial of service (#39219)
- Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking (#39063)
FEATURES
- Feat(actions): update actionslib, support
self:, misc fixes (#39358) - Feat(api): list all packages for site administrators (#38968)
- Feat: manage bot accounts from the admin UI, API and CLI (#38966)
- Feat(user): Personal access tokens can be regenerated (#38907)
- Feat(actions): support
$/prefix in reusable workflowuses:(#38822) - Feat(actions): add force-cancel workflow run API (#38756)
- Feat(licenses): support REUSE specification in licenses (#38720)
- Feat(api): add project APIs (#38691)
- Feat(webhook): fire repository event on repo rename (#38641)
- Feat: admin impersonates a user (#38614)
- Feat(actions): add build queue view (#38585)
- Feat(setting): add shared [redis] section as default for redis-backed subsystems (#38550)
- Feat(repo): prioritize well-known READMEs and optimize discovery (#38532)
- Feat(actions): implement adaptive auto-refresh for workflow runs list (#38329)
- Feat(auth): add
disable-2facommand (#38275) - Feat: Add audit logging (#38189)
- Feat(repo): add quick repository switcher to repo header (#38188)
- Feat(repo): support file exclusion logic in .gitea/template in template generation (#38064)
- Feat(web): Add org removal functionality to admin user details page (#38013)
- Feat: add watch options (#37571)
- Feat: add deploy tokens (#37306)
- Feat(diff): Add search and extension filter to diff sidebar (#37068)
- Feat: Replace SSE with WebSocket for UI notifications (#36965)
- Feat(actions): Add artifact preview in Actions run view (#36754)
- Feat(packages): add support for uploading helm provenance files (#36695)
- Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows (#36564)
- Feat: Add max-parallel Support for Gitea Actions (#36357)
- Feat(actions): Add Actions API endpoints for workflow run management and logs (#35382)
- Feat: Add block on pending codeowner reviews branch protection (#34995)
- Feat(actions): update actionslib, support
ENHANCEMENTS
- Enhance: allow auto-closing PRs from PRs (#39393)
- Enhance(actions): add pending job status and align job statuses with GitHub (#39376)
- Enhance(acme): add configurable ACME profile (#39375)
- Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data (#39363)
- Enhance: improve issue-pattern capture groups and support both internal&external trackers enabled (#39354)
- Enhance: update mermaid to v12 (#39331)
- Enhance(notifications): mark current notification page as read (#39294)
- Enhance: support
ETagon streamed repository archives, supportIf-None-Match: *(#39289) - Enhance: truncate but show long lines in diffs (#39279)
- Enhance(packages): implement npm single-version API and add per-version repository (#39267)
- Enhance: move window.config to JSON, improve CSP format (#39236)
- Enhance: improve commit page header (#39229)
- Enhance: Improve validation errors for secrets/variables (#39221)
- Enhance(repo): check full repo name for dangerous operations (#39213)
- Enhance(web): hide attachment dropzone on preview tab in combo editor (#39204)
- Enhance(web): show attachment URL and UUID in dropzone preview (#39203)
- Enhance(actions): make workflow dispatch choice dropdown support search (#39154)
- Enhance(repo): unify diff stats on commit pages, misc diff tweaks (#39134)
- Enhance: use browser’s locale to detect week’s first day for the contribution map (#38995)
- Enhance(ui): forced colors mode enhancements (#38991)
- Enhance: user-friendly packages setup manual (#38946)
- Enhance: inherit team access for all units (#38938)
- Enhance(admin): show impersonation banner and keep password change with the user (#38924)
- Enhance(ui): tint toast backgrounds by level (#38919)
- Enhance(repo): add default object format setting (#38877)
- Enhance(actions): set ref_protected in context (#38852)
- Enhance(ui): restyle toasts (#38842)
- Enhance: refine repo watching (#38835)
- Enhance: fall back to DEFAULT_TEMPLATE.md when style-specific template is missing (#38803)
- Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint (#38770)
- Enhance(api): expose file mode in contents API response (#38713)
- Enhance(tls): use go’s tls defaults (#38687)
- Enhance(ui): improve luminance calculations (#38682)
- Enhance(api): add
tag_filterquery parameter to release list API (#38681) - Enhance(actions): replace
ansi_upwith first-party code (#38619) - Enhance: keep status check list scrolled on merge box reload (#38597)
- Enhance(actions): action view enhancements (#38594)
- Enhance(ui): tweak tooltip style and misc fixes (#38524)
- Enhance: improve e-mail templates (#38396)
- Enhance(webhook): add reviewer name to MS Teams review request notifications (#38289)
- Enhance: extend
<video>tag allowed attributes (#38279) - Enhance(packages/npm): expand version metadata and support npm deprecate (#37890)
PERFORMANCE
BUGFIXES
- Fix(actions): preserve admitted jobs and runs in their concurrency group (#39461)
- Fix(api): commit tree SHA is the commit ID (#39449)
- Fix: PR merge (#39442)
- Fix(actions): evaluate job-level
if:before concurrency check (#39437) - Fix(api): allow pending-inline-comment-only reviews (#39433)
- Fix: sanitize external render command line arguments (#39417)
- Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data (#39406)
- Fix(indexer): index full file paths and real offsets in bleve (#39405)
- Fix(git): keep leading dashes in git grep search patterns (#39404)
- Fix: use clearer message for ldap auth failure (#39392)
- Fix(repo): commit page fails to render unsigned commits with a different committer (#39381)
- Fix: focus confirm button and use red for delete confirmations (#39350)
- Fix(migrations): preserve SHA-256 pull request commit IDs (#39343)
- Fix(ui): misc ui fixes (#39336)
- Fix(actions): use gitea’s clock for actions durations (#39323)
- Fix(actions): never show negative running durations (#39322)
- Fix: package registry keypair creation race (#39319)
- Fix: add default timeout and handle errors for HaveIBeenPwned API (#39316)
- Fix(user): unify email validation for registration and settings (#39304)
- Fix(ui): use button elements for branch and tag dropdown tabs (#39285)
- Fix(auth): fix ssh and gpg key verification on windows (#39283)
- Fix(feed): use meaningful lines as comment excerpt (#39276)
- Fix(projects): allow max columns to the limit (#39272)
- Fix: pass merge commit messages to git via stdin (#39269)
- Fix(repo): surface unrelated histories on Sync Fork (#39258)
- Fix: avoid nil panic and refactor some trivial problems (#39251)
- Fix: restore missing blob file when re-publishing a package (#39239)
- Fix(automerge): validate head commit before merge (#39235)
- Fix(httplib): prevent leaking localhost:3000 in public links (#39217)
- Fix(setting): honor bare -1 for timeout settings (#39181)
- Fix: correct repo/attatchment absolute url and release layout (#39178)
- Fix(web): populate the reason for “cannot commit to branch” in web editor commit form (#39155)
- Fix(process): reap entire process group on cmd.Cancel (#39143)
- Fix: recognize linguist language aliases (#39135)
- Fix(repo): preserve transfer recipient collaboration (#39042)
- Fix(db): make paginated database reads always require “order” option (#39017)
- Fix: make local queue PopItem can be notified (#39011)
- Fix: classify git failures on stderr, restrict migration failure detail (#39010)
- Fix: allow re-requesting uncounted review approvals (#38988)
- Fix(actions): allow larger scheduled workflows (#38985)
- Fix: resolve actions commit status permission per repository (#38977)
- Fix(deps): update module golang.org/x/image to v0.45.0 [security] (#38930)
- Fix(deps): update module golang.org/x/mod to v0.40.0 [security] (#38914)
- Fix: dedupe issue cross-reference timeline entries (#38881)
- Fix(server): set
ReadHeaderTimeouton HTTP servers (#38878) - Fix(repo): avoid a repo-sized temp file for every bundle download (#38863)
- Fix(lfs): ensure lock listing paginates with a total order (#38850)
- Fix(avatar): use sha256 and inline the federated avatar lookup (#38843)
- Fix(gitdiff): render exact-limit diffs and zero-limit comments (#38838)
- Fix(deps): update dependency mermaid to v11.16.1 [security] (#38813)
- Fix: misc fixes in pub/gpg/tests (#38809)
- Fix: git diff blob excerpt (#38808)
- Fix(packages): show error for duplicate cleanup rules #37820 (#38786)
- Fix(actions): fix runner docs link (#38783)
- Fix: git cache (#38763)
- Fix(actions): evaluate each
${{ }}part on its own (#38754) - Fix: don’t report failed network requests as JavaScript errors (#38732)
- Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker (#38728)
- Fix(api): document X-Total-Count instead of non-existent X-Total header (#38717)
- Fix(actions): dynamic matrix expansion correctness fixes (#38690)
- Fix(auth): record last sign-in on reverse proxy login (#38672)
- Fix(api): accept fully-qualified refs in contents API (#38650)
- Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 [security] (#38623)
- Fix(deps): update dependency js-yaml to v5.2.2 [security] (#38622)
- Fix: abort superseded issue suggestion requests (#38620)
- Fix(issue): display error toast on batch action failures instead of reloading page (#38593)
- Fix(deps): update module google.golang.org/grpc to v1.82.1 [security] (#38567)
- Fix(deps): update module github.com/google/go-github/v88 to v89 (#38433)
- Fix(deps): update go dependencies (#38429)
- Fix(deps): update go dependencies (#38346)
- Fix(deps): update npm dependencies (#38342)
- Fix(base): correct natural sort of numbers with leading zeros (#38163)
- Fix(ui): avoid layout shifts in
overflow-menuand repo filter (#37818) - Fix: make auth source group sync correctly handle team removal (#37161)
- Fix(release): separate publication time from the release date (#36761)
TESTING
- Test: stop tests from writing into
~/.ssh(#39348) - Test(e2e): log out to switch users in pr-review test (#39328)
- Test: release fixtures loader lock before database work (#39263)
- Test: speed up tests, fix transaction bug (#39030)
- Test: run frontend unit tests in browsers (#38860)
- Test(pubsub): stop racing the Redis SUBSCRIBE ack (#38661)
- Test(e2e): add pull request merge box test, update AGENTS.md (#38576)
- Test(e2e): deterministically wait for event stream in logout propagation test (#38535)
- Test: stop tests from writing into
BUILD
- Refactor: fix
go veterrors related to composite literals (#39341) - Build(gogit): disable gogit builds for stable releases (#39324)
- Refactor: replace jquery.are-you-sure with first-party code (#39233)
- Refactor: http request binding (#38971)
- Refactor: clean up git repo and model migration packages (#38564)
- Refactor: prepare to decouple the “model migration” package and “models” package (#38533)
- Build: fix snapcraft release (#38260)
- Build(release): use native golang toolchain for official release builds (#37828)
- Refactor: fix
DOCS
- Docs(webhook): review.type comment lists values the webhook never sends (#39451)
- Docs(api): document verification and files on the compare endpoint (#39440)
- Docs(api): name the unadopted-repository search parameter query (#39370)
- Docs: remove unused COOKIE_USERNAME from app.example.ini (#39365)
- Docs: document NOTICE_ON_SUCCESS for every cron task (#39352)
- Docs: correct ALLOW_LOCALNETWORKS description in app.example.ini (#39240)
- Docs: fix typo in README about app.ini restart (#39223)
- Docs: fix dead localization doc link in the READMEs (#39211)
- Docs: Update CHANGELOG for release 1.27.3 (#39170)
- Docs: Update CHANGELOG for version 1.27.2 (#38923)
- Docs: Update PGP key expiration date to July 23, 2027 (#38747)
- Docs(api): document 401/403 responses for user key endpoints (#38711)
- Docs: Update Changelog for release v1.27.1 (#38670)
- Docs: Update Changelog for 1.27 (#38440)
- Docs: Update Security docs (#38422)
MISC
- Refactor: make git http respond error message (#39390)
- Refactor(api): convert bot accounts through the admin user edit endpoint (#39355)
- Refactor: replace AWS SDK with a REST client for CodeCommit migration (#39330)
- Refactor: replace Azure Blob SDK with a REST client (#39315)
- Refactor: npm route handlers (#39275)
- Refactor: GetDiffShortStat and fix panic caused by inconsistent “changed file number” (#39248)
- Refactor(templates): update djlint to 1.46.0 and resolve its new findings (#39231)
- Refactor: pagination/pager (#39162)
- Refactor: share package registry error status classification (#39133)
- Refactor: drop two unmaintained dependencies, rename the byte size helpers (#39083)
- Refactor(automerge): fix error handling, populate recent automerge tasks on restart (#39001)
- Refactor: deploy key and private route handlers (#38999)
- Refactor: wiki edit form (#38918)
- Refactor: clean up form binding & validation (#38873)
- Refactor: markup render (#38864)
- Refactor: api token scope check (#38862)
- Refactor: replace
gliderlabs/sshwithgolang.org/x/crypto/ssh(#38837) - Refactor: form binding validation (#38832)
- Refactor: prepare vue components for vapor mode (#38798)
- Refactor: use the shared workflow model from actionslib (#38768)
- Refactor(modelmigration): thread context through migration functions (#38758)
- Refactor: migrate remaining Vue components to
<script setup>(#38752) - Refactor: introduce trString for frontend (#38741)
- Refactor(diff): drive diff DOM init from the global selector observer (#38740)
- Refactor(git): clarify GetBranch behavior to make it only gets an existing branch (#38662)
- Refactor: replace debounce/throttle deps with first-party code (#38610)
- Refactor: hide git repo path details from more packages (#38601)
- Refactor: retry file remove/rename when a file is busy and clean up os detection (#38588)
- Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie (#38573)
- Refactor: implement mcaptcha client and add comments/tests (#38561)
- Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations (#38555)
- Refactor: remove Path field from git.Repository (#38552)
- Refactor: make git package handle all git operations (#38543)
- Refactor: remove unnecessary git command wrapper functions (#38531)
- Refactor: git repo and relative path handling (#38522)
- Refactor: clean up fragile diff render templates, use backend typed structs (#38517)
- Refactor: correct git repo design and fix some legacy problems (#38512)
- Refactor: fix legacy problems in cmd/serv.go (#38505)
- Refactor: remove Ctx field from git.Repository (#38500)
- Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree (#38464)
- Refactor: introduce ActivePageTimer to help to do partial page refresh (#38372)

