Zum Inhalt springen

Gitea Release Notes

6 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Gitea

Gitea 28.1.0: Bessere npm-Kompatibilität und viele Fehlerbehebungen

Gitea 28.1.0 verbessert die npm-Client-Kompatibilität der Paketregistry und behebt zahlreiche Fehler, darunter in Actions, MathML-Darstellung, Git-Handling, OAuth2-Scope-Freigaben, Captcha mit CSP sowie Transaktionen auf MySQL, MariaDB und MSSQL.

[28.1.0] - 2026-10-06

Enhancements

  • (packages/npm) Improve npm client compatibility (#39434) (#39522)

Bug Fixes

  • (actions) Keep runs order after auto refresh (#39479) (#39481)
  • Npm route (#39488) (#39490)
  • Copy new access token to clipboard (#39496) (#39499)
  • (markup) Skip post-processing inside MathML (#39497) (#39502)
  • (markup) Don't escape ambiguous characters in MathML (#39493) (#39505)
  • Add missing checks to several API and web handlers (#39501) (#39507)
  • Handle git branch name with special chars correctly (#39483) (#39515)
  • Trace git command correctly (#39520) (#39524)
  • (git) Reindex go-git storage when a concurrent repack removes packs (#39510) (#39534)
  • (oauth2) Allow users to approve scope changes (#38942) (#39521)
  • (api) Add index tiebreaker to commit status ordering (#39508) (#39525)
  • (git) Avoid unnecessary timers during language stats (#39531) (#39535)
  • Use READ COMMITTED transactions on MySQL and MariaDB (#39506) (#39537)
  • (markup) Use installed math fonts for MathML in Chromium (#39491) (#39547)
  • (git) Tolerate concurrent repacks in go-git storage (#39536) (#39556)
  • Make image captcha work with csp (#39555)
  • Use READ_COMMITTED_SNAPSHOT on MSSQL (#39512) (#39558)
  • Make navbar stopwatch button can show popup (#39562)
  • (actions) Restore pushes to protected branches (#39564) (#39567)
  • (api) Allow bots with pending password changes (#39551) (#39566) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Gitea

Gitea 28.0.0: Interner Git-Proxy, RUN_RETENTION_DAYS und Sicherheitskorrekturen

Gitea 28.0.0 leitet Git-Netzwerkoperationen über einen internen Proxy, führt mit RUN_RETENTION_DAYS das Löschen alter Action-Runs ein und enthält mehrere Sicherheitskorrekturen, etwa für Git-Objekte beim Push, SSH-Schlüssel und Fork-PR-Freigaben.

  • BREAKING

    • Fix(git)!: route Git network operations through an internal proxy and update egress settings (#39426)
    • Feat(actions)!: add RUN_RETENTION_DAYS to delete old action runs (#38855)
  • SECURITY

    • Fix(git): reject invalid and duplicate Git objects on push (#39472)
    • Fix(git)!: route Git network operations through an internal proxy and update egress settings (#39426)
    • Fix(ssh): identify presented public keys by fingerprint (#39423)
    • Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate (#39399)
    • Fix(deps): update golang.org/x/crypto SSH to address denial of service (#39219)
    • Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking (#39063)
  • FEATURES

    • Feat(actions): update actionslib, support self:, misc fixes (#39358)
    • Feat(api): list all packages for site administrators (#38968) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Gitea

Gitea 1.27.3: Zahlreiche Sicherheitslücken geschlossen, PR-Review-Permalinks

Gitea 1.27.3 schließt zahlreiche Sicherheitslücken, unter anderem bei Paketen, Anhängen, Actions-Fork-Pull-Requests, API-Zugriffen und Migrationen, und ergänzt Permalinks für Pull-Request-Reviews.

  • SECURITY
    • fix(packages): restrict/limited/token-scope access (#39041, #39043, #39044, #39047, #39046) (#39058)
    • fix(attachments): enforce owning repository path (#39048) (#39077)
    • fix(markup): enforce same-repository issue access (#39045) (#39054)
    • fix(actions): verify raw artifact signatures first (#39049) (#39053)
    • fix(api): hide limited users from restricted viewers (#39004) (#39039)
    • fix(repo): limit gitignore template selections (#39027) (#39040)
    • fix(migrations): cancel GitLab version probes (#39023) (#39035)
    • fix(packages): limit Swift package manifests (#39025) (#39032)
    • fix(migrations): bound OneDev version responses (#39024) (#39033)
    • fix(packages): limit Maven checksum uploads (#39028) (#39031)
    • fix(packages): bound Alpine metadata entries (#39026) (#39029)
    • fix(actions): enforce fork pull request trust boundaries (#39005) (#39018)
    • fix(git): restrict hook permissions (#39008) (#39016)
    • fix(api): enforce repository creation token authorization (#39007) (#39014)
    • fix(api): enforce public-only scope for compare heads (#39006) (#39013)
    • fix(repo): hide repositories of hidden owners (#39009) (#39012)
    • fix: avoid enumerating every public repository in issue search (#38992) (#39000)
    • refactor: private endpoints (#38964) (#38965)
  • ENHANCEMENTS
    • enhance: add permalinks to pull request reviews (#38849) (#39036)
  • BUGFIXES …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Gitea

Gitea 1.27.2: Sicherheitskorrekturen und Fehlerbehebungen

Gitea 1.27.2 enthält Sicherheitskorrekturen unter anderem zu Collaborator-Zugriff, externem Rendering, WebAuthn und mermaid, ergänzt npm-Paketmetadaten und behebt Fehler in Actions, LFS, Paketen und Azure-Blob-Storage.

  • SECURITY

    • Fix: update collaborator access mode and httpsign (#38894, #38862) (#38895)
    • Refactor: external render (#38885) (#38898)
    • Fix(actions): resolve pull_request_target reusable workflows at the base commit (#38886) (#38897)
    • Refactor: markup render (#38864) (#38869)
    • Fix(deps): update dependency mermaid to v11.16.1 (#38816)
    • Fix(auth): set WebAuthn user verification per request (#38805) (#38810)
    • Fix: render highlight language (#38793) (#38795)
  • ENHANCEMENTS

    • enhance: add missing npm package metadata properties (#38826) (#38831)
  • BUGFIXES

    • fix(actions): keep github.event.inputs as strings for workflow_dispatch (#38899) (#38908)
    • fix(actions): let a rerun of selected jobs read the previous attempt's artifacts (#38857) (#38901)
    • fix(lfs): accept successful transfer responses (#38866) (#38875)
    • fix(packages): ignore nested Package.swift (#38788) (#38836)
    • fix: drop newline-bearing member names in arch ParsePackage (#38102) (#38830)
    • fix(storage): fix Azure Blob dump failing with file does not exist (#38814) (#38828)
    • fix(migration): migration deletion returned json redirection (#38796) (#38825)
    • fix(ui): change underlines to default browser style (#38819) (#38823)
    • fix(actions): allow cancelling runs without running jobs (#35842) (#38812)
    • fix(actions): evaluate each ${{ }} part on its own (#38754) (#38797) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Gitea

Gitea 1.27.1: Sicherheitskorrekturen und bessere Diff-Kontraste

Gitea 1.27.1 behebt Sicherheitsprobleme beim Orgmode-Rendering und beim Anwenden von Git-Patches, verbessert den Diff-Kontrast und korrigiert viele Fehler, vor allem in Actions, OIDC-Abmeldung, Webhooks und beim Löschen von Repositories.

  • SECURITY
    • Fix: orgmode render include path (#38642) (#38645)
    • Fix: git patch apply (#38637) (#38638)
  • API

    • fix(api): align Swagger schemas for UserSettings and TopicListResponse (#38590) (#38592)
  • ENHANCEMENTS

    • enhance: improve diff contrast in light and dark themes (#37477) (#38574)
  • BUGFIXES

    • fix: skip OIDC end-session after password login for OAuth2 users (#38439) (#38666)
    • fix: make Actions log parser support multiple line message encoding (#38659) (#38664)
    • fix(actions): use base branch ref for pull_request_target context (#38636) (#38657)
    • fix(actions): skip already-approved runs in ApproveRuns (#38653) (#38654)
    • fix: orgmode render include path (#38642) (#38645)
    • fix(actions): cancel tasks immediately when the runner stopped reporting (#38616) (#38644)
    • fix(issues): fix label bulk-load key and reduce log noise in LoadLabel (#38632) (#38643)
    • fix(actions): improve runner list status sorting, labels and task job links (#38586) (#38633)
    • fix(actions): correctness and hardening fixes (#38518) (#38631)
    • fix(repo): prevent double-write redirect collisions on dependency errors, fix ui (#38627) (#38628)
    • fix: delete repo-scoped rows of seven more tables when deleting a repository (#38534) (#38618)
    • fix(webhook): remove slack channel name check (#38608) (#38612)
    • fix: download dropdown menu clipped on the branches page (#38604) (#38609) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Gitea

Gitea 1.27.0: Breaking Changes, CSP mit Script-Nonce und Sicherheitskorrekturen

Gitea 1.27.0 bringt Breaking Changes durch besseren Support für wiederverwendbare Workflows und Content-Security-Policy mit Script-Nonce, zahlreiche Sicherheitskorrekturen sowie ein Modal für Workflow-Status-Badges.

  • BREAKING

    • Feat(actions)!: improve support for reusable workflows (#37478)
    • Use Content-Security-Policy: script nonce (#37232)
  • SECURITY

    • Fix: various security fixes (#38406) (#38426)
    • Fix(security): harden access checks and migration validation (#38324) (#38400)
    • Fix: enforce public-only token scope and harden push options / locale parsing (#38323) (#38399)
    • Fix(pull): re-evaluate review official flag on target branch change (#38319) (#38402)
    • Fix(api): stop leaking private repo metadata after access revocation (#38321) (#38390)
    • Fix(lfs): require proof of possession for cross-repo objects (#38322) (#38389)
    • Fix(mirror): disable HTTP redirects on pull mirror sync (#38320) (#38367)
    • Fix: golang html template url escaping (#38363) (#38369)
    • Fix(release): validate web attachment renames against allowed types (#38314) (#38328)
    • Fix(release): gate draft release attachments on web download endpoints (#38318) (#38325)
    • Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#37786)
    • Fix(oauth): restrict introspection to the token's client (#38042)
    • Fix(api): don't expose private org membership via public_members (#38145)
    • Fix(actions): deny fork-PR cross-repo access via collaborative owner (#38214)
    • Fix(migrations): prevent path traversal in repository restore (#38215)
  • FEATURES

    • Feat(actions): add workflow status badge modal (#38196) …

Originalquelle(öffnet in neuem Tab)Problem melden