Tags

Tags give the ability to mark specific points in history as being important
  • v28.0.0

    * BREAKING
      * Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#39426](https://github.com/go-gitea/gitea/pull/39426))
      * Feat(actions)!: add RUN_RETENTION_DAYS to delete old action runs ([#38855](https://github.com/go-gitea/gitea/pull/38855))
    
    * SECURITY
      * Fix(git): reject invalid and duplicate Git objects on push ([#39472](https://github.com/go-gitea/gitea/pull/39472))
      * Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#39426](https://github.com/go-gitea/gitea/pull/39426))
      * Fix(ssh): identify presented public keys by fingerprint ([#39423](https://github.com/go-gitea/gitea/pull/39423))
      * Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#39399](https://github.com/go-gitea/gitea/pull/39399))
      * Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#39219](https://github.com/go-gitea/gitea/pull/39219))
      * Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#39063](https://github.com/go-gitea/gitea/pull/39063))
    
    * FEATURES
      * Feat(actions): update actionslib, support `self:`, misc fixes ([#39358](https://github.com/go-gitea/gitea/pull/39358))
      * Feat(api): list all packages for site administrators ([#38968](https://github.com/go-gitea/gitea/pull/38968))
      * Feat: manage bot accounts from the admin UI, API and CLI ([#38966](https://github.com/go-gitea/gitea/pull/38966))
      * Feat(user): Personal access tokens can be regenerated ([#38907](https://github.com/go-gitea/gitea/pull/38907))
      * Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#38822](https://github.com/go-gitea/gitea/pull/38822))
      * Feat(actions): add force-cancel workflow run API ([#38756](https://github.com/go-gitea/gitea/pull/38756))
      * Feat(licenses): support REUSE specification in licenses ([#38720](https://github.com/go-gitea/gitea/pull/38720))
      * Feat(api): add project APIs ([#38691](https://github.com/go-gitea/gitea/pull/38691))
      * Feat(webhook): fire repository event on repo rename ([#38641](https://github.com/go-gitea/gitea/pull/38641))
      * Feat: admin impersonates a user ([#38614](https://github.com/go-gitea/gitea/pull/38614))
      * Feat(actions): add build queue view ([#38585](https://github.com/go-gitea/gitea/pull/38585))
      * Feat(setting): add shared [redis] section as default for redis-backed subsystems ([#38550](https://github.com/go-gitea/gitea/pull/38550))
      * Feat(repo): prioritize well-known READMEs and optimize discovery ([#38532](https://github.com/go-gitea/gitea/pull/38532))
      * Feat(actions): implement adaptive auto-refresh for workflow runs list ([#38329](https://github.com/go-gitea/gitea/pull/38329))
      * Feat(auth): add `disable-2fa` command ([#38275](https://github.com/go-gitea/gitea/pull/38275))
      * Feat: Add audit logging ([#38189](https://github.com/go-gitea/gitea/pull/38189))
      * Feat(repo): add quick repository switcher to repo header ([#38188](https://github.com/go-gitea/gitea/pull/38188))
      * Feat(repo): support file exclusion logic in .gitea/template in template generation ([#38064](https://github.com/go-gitea/gitea/pull/38064))
      * Feat(web): Add org removal functionality to admin user details page ([#38013](https://github.com/go-gitea/gitea/pull/38013))
      * Feat: add watch options ([#37571](https://github.com/go-gitea/gitea/pull/37571))
      * Feat: add deploy tokens ([#37306](https://github.com/go-gitea/gitea/pull/37306))
      * Feat(diff): Add search and extension filter to diff sidebar ([#37068](https://github.com/go-gitea/gitea/pull/37068))
      * Feat: Replace SSE with WebSocket for UI notifications ([#36965](https://github.com/go-gitea/gitea/pull/36965))
      * Feat(actions): Add artifact preview in Actions run view ([#36754](https://github.com/go-gitea/gitea/pull/36754))
      * Feat(packages): add support for uploading helm provenance files ([#36695](https://github.com/go-gitea/gitea/pull/36695))
      * Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#36564](https://github.com/go-gitea/gitea/pull/36564))
      * Feat: Add max-parallel Support for Gitea Actions ([#36357](https://github.com/go-gitea/gitea/pull/36357))
      * Feat(actions): Add Actions API endpoints for workflow run management and logs ([#35382](https://github.com/go-gitea/gitea/pull/35382))
      * Feat: Add block on pending codeowner reviews branch protection ([#34995](https://github.com/go-gitea/gitea/pull/34995))
    
    * ENHANCEMENTS
      * Enhance: allow auto-closing PRs from PRs ([#39393](https://github.com/go-gitea/gitea/pull/39393))
      * Enhance(actions): add pending job status and align job statuses with GitHub ([#39376](https://github.com/go-gitea/gitea/pull/39376))
      * Enhance(acme): add configurable ACME profile ([#39375](https://github.com/go-gitea/gitea/pull/39375))
      * Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#39363](https://github.com/go-gitea/gitea/pull/39363))
      * Enhance: improve issue-pattern capture groups and support both internal&external trackers enabled ([#39354](https://github.com/go-gitea/gitea/pull/39354))
      * Enhance: update mermaid to v12 ([#39331](https://github.com/go-gitea/gitea/pull/39331))
      * Enhance(notifications): mark current notification page as read ([#39294](https://github.com/go-gitea/gitea/pull/39294))
      * Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#39289](https://github.com/go-gitea/gitea/pull/39289))
      * Enhance: truncate but show long lines in diffs ([#39279](https://github.com/go-gitea/gitea/pull/39279))
      * Enhance(packages): implement npm single-version API and add per-version repository ([#39267](https://github.com/go-gitea/gitea/pull/39267))
      * Enhance: move window.config to JSON, improve CSP format ([#39236](https://github.com/go-gitea/gitea/pull/39236))
      * Enhance: improve commit page header ([#39229](https://github.com/go-gitea/gitea/pull/39229))
      * Enhance: Improve validation errors for secrets/variables ([#39221](https://github.com/go-gitea/gitea/pull/39221))
      * Enhance(repo): check full repo name for dangerous operations ([#39213](https://github.com/go-gitea/gitea/pull/39213))
      * Enhance(web): hide attachment dropzone on preview tab in combo editor ([#39204](https://github.com/go-gitea/gitea/pull/39204))
      * Enhance(web): show attachment URL and UUID in dropzone preview ([#39203](https://github.com/go-gitea/gitea/pull/39203))
      * Enhance(actions): make workflow dispatch choice dropdown support search ([#39154](https://github.com/go-gitea/gitea/pull/39154))
      * Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#39134](https://github.com/go-gitea/gitea/pull/39134))
      * Enhance: use browser's locale to detect week's first day for the contribution map ([#38995](https://github.com/go-gitea/gitea/pull/38995))
      * Enhance(ui): forced colors mode enhancements ([#38991](https://github.com/go-gitea/gitea/pull/38991))
      * Enhance: user-friendly packages setup manual ([#38946](https://github.com/go-gitea/gitea/pull/38946))
      * Enhance: inherit team access for all units ([#38938](https://github.com/go-gitea/gitea/pull/38938))
      * Enhance(admin): show impersonation banner and keep password change with the user ([#38924](https://github.com/go-gitea/gitea/pull/38924))
      * Enhance(ui): tint toast backgrounds by level ([#38919](https://github.com/go-gitea/gitea/pull/38919))
      * Enhance(repo): add default object format setting ([#38877](https://github.com/go-gitea/gitea/pull/38877))
      * Enhance(actions): set ref_protected in context ([#38852](https://github.com/go-gitea/gitea/pull/38852))
      * Enhance(ui): restyle toasts ([#38842](https://github.com/go-gitea/gitea/pull/38842))
      * Enhance: refine repo watching ([#38835](https://github.com/go-gitea/gitea/pull/38835))
      * Enhance: fall back to DEFAULT_TEMPLATE.md when style-specific template is missing ([#38803](https://github.com/go-gitea/gitea/pull/38803))
      * Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#38770](https://github.com/go-gitea/gitea/pull/38770))
      * Enhance(api): expose file mode in contents API response ([#38713](https://github.com/go-gitea/gitea/pull/38713))
      * Enhance(tls): use go's tls defaults ([#38687](https://github.com/go-gitea/gitea/pull/38687))
      * Enhance(ui): improve luminance calculations ([#38682](https://github.com/go-gitea/gitea/pull/38682))
      * Enhance(api): add `tag_filter` query parameter to release list API ([#38681](https://github.com/go-gitea/gitea/pull/38681))
      * Enhance(actions): replace `ansi_up` with first-party code ([#38619](https://github.com/go-gitea/gitea/pull/38619))
      * Enhance: keep status check list scrolled on merge box reload ([#38597](https://github.com/go-gitea/gitea/pull/38597))
      * Enhance(actions): action view enhancements ([#38594](https://github.com/go-gitea/gitea/pull/38594))
      * Enhance(ui): tweak tooltip style and misc fixes ([#38524](https://github.com/go-gitea/gitea/pull/38524))
      * Enhance: improve e-mail templates ([#38396](https://github.com/go-gitea/gitea/pull/38396))
      * Enhance(webhook): add reviewer name to MS Teams review request notifications ([#38289](https://github.com/go-gitea/gitea/pull/38289))
      * Enhance: extend <video> tag allowed attributes ([#38279](https://github.com/go-gitea/gitea/pull/38279))
      * Enhance(packages/npm): expand version metadata and support npm deprecate ([#37890](https://github.com/go-gitea/gitea/pull/37890))
    
    * PERFORMANCE
      * Perf(references): scan only the keyword window before a reference ([#39396](https://github.com/go-gitea/gitea/pull/39396))
      * Perf(frontend): enable vite module preload ([#39332](https://github.com/go-gitea/gitea/pull/39332))
      * Perf(gitdiff): optimize inline diff highlighting using cache ([#38706](https://github.com/go-gitea/gitea/pull/38706))
    
    * BUGFIXES
      * Fix(actions): preserve admitted jobs and runs in their concurrency group ([#39461](https://github.com/go-gitea/gitea/pull/39461))
      * Fix(api): commit tree SHA is the commit ID ([#39449](https://github.com/go-gitea/gitea/pull/39449))
      * Fix: PR merge ([#39442](https://github.com/go-gitea/gitea/pull/39442))
      * Fix(actions): evaluate job-level `if:` before concurrency check ([#39437](https://github.com/go-gitea/gitea/pull/39437))
      * Fix(api): allow pending-inline-comment-only reviews ([#39433](https://github.com/go-gitea/gitea/pull/39433))
      * Fix: sanitize external render command line arguments ([#39417](https://github.com/go-gitea/gitea/pull/39417))
      * Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#39406](https://github.com/go-gitea/gitea/pull/39406))
      * Fix(indexer): index full file paths and real offsets in bleve ([#39405](https://github.com/go-gitea/gitea/pull/39405))
      * Fix(git): keep leading dashes in git grep search patterns ([#39404](https://github.com/go-gitea/gitea/pull/39404))
      * Fix: use clearer message for ldap auth failure ([#39392](https://github.com/go-gitea/gitea/pull/39392))
      * Fix(repo): commit page fails to render unsigned commits with a different committer ([#39381](https://github.com/go-gitea/gitea/pull/39381))
      * Fix: focus confirm button and use red for delete confirmations ([#39350](https://github.com/go-gitea/gitea/pull/39350))
      * Fix(migrations): preserve SHA-256 pull request commit IDs ([#39343](https://github.com/go-gitea/gitea/pull/39343))
      * Fix(ui): misc ui fixes ([#39336](https://github.com/go-gitea/gitea/pull/39336))
      * Fix(actions): use gitea's clock for actions durations ([#39323](https://github.com/go-gitea/gitea/pull/39323))
      * Fix(actions): never show negative running durations ([#39322](https://github.com/go-gitea/gitea/pull/39322))
      * Fix: package registry keypair creation race ([#39319](https://github.com/go-gitea/gitea/pull/39319))
      * Fix: add default timeout and handle errors for HaveIBeenPwned API ([#39316](https://github.com/go-gitea/gitea/pull/39316))
      * Fix(user): unify email validation for registration and settings ([#39304](https://github.com/go-gitea/gitea/pull/39304))
      * Fix(ui): use button elements for branch and tag dropdown tabs ([#39285](https://github.com/go-gitea/gitea/pull/39285))
      * Fix(auth): fix ssh and gpg key verification on windows ([#39283](https://github.com/go-gitea/gitea/pull/39283))
      * Fix(feed): use meaningful lines as comment excerpt ([#39276](https://github.com/go-gitea/gitea/pull/39276))
      * Fix(projects): allow max columns to the limit ([#39272](https://github.com/go-gitea/gitea/pull/39272))
      * Fix: pass merge commit messages to git via stdin ([#39269](https://github.com/go-gitea/gitea/pull/39269))
      * Fix(repo): surface unrelated histories on Sync Fork ([#39258](https://github.com/go-gitea/gitea/pull/39258))
      * Fix: avoid nil panic and refactor some trivial problems ([#39251](https://github.com/go-gitea/gitea/pull/39251))
      * Fix: restore missing blob file when re-publishing a package ([#39239](https://github.com/go-gitea/gitea/pull/39239))
      * Fix(automerge): validate head commit before merge ([#39235](https://github.com/go-gitea/gitea/pull/39235))
      * Fix(httplib): prevent leaking localhost:3000 in public links ([#39217](https://github.com/go-gitea/gitea/pull/39217))
      * Fix(setting): honor bare -1 for timeout settings ([#39181](https://github.com/go-gitea/gitea/pull/39181))
      * Fix: correct repo/attatchment absolute url and release layout ([#39178](https://github.com/go-gitea/gitea/pull/39178))
      * Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#39155](https://github.com/go-gitea/gitea/pull/39155))
      * Fix(process): reap entire process group on cmd.Cancel ([#39143](https://github.com/go-gitea/gitea/pull/39143))
      * Fix: recognize linguist language aliases ([#39135](https://github.com/go-gitea/gitea/pull/39135))
      * Fix(repo): preserve transfer recipient collaboration ([#39042](https://github.com/go-gitea/gitea/pull/39042))
      * Fix(db): make paginated database reads always require "order" option ([#39017](https://github.com/go-gitea/gitea/pull/39017))
      * Fix: make local queue PopItem can be notified ([#39011](https://github.com/go-gitea/gitea/pull/39011))
      * Fix: classify git failures on stderr, restrict migration failure detail ([#39010](https://github.com/go-gitea/gitea/pull/39010))
      * Fix: allow re-requesting uncounted review approvals ([#38988](https://github.com/go-gitea/gitea/pull/38988))
      * Fix(actions): allow larger scheduled workflows ([#38985](https://github.com/go-gitea/gitea/pull/38985))
      * Fix: resolve actions commit status permission per repository ([#38977](https://github.com/go-gitea/gitea/pull/38977))
      * Fix(deps): update module golang.org/x/image to v0.45.0 [security] ([#38930](https://github.com/go-gitea/gitea/pull/38930))
      * Fix(deps): update module golang.org/x/mod to v0.40.0 [security] ([#38914](https://github.com/go-gitea/gitea/pull/38914))
      * Fix: dedupe issue cross-reference timeline entries ([#38881](https://github.com/go-gitea/gitea/pull/38881))
      * Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#38878](https://github.com/go-gitea/gitea/pull/38878))
      * Fix(repo): avoid a repo-sized temp file for every bundle download ([#38863](https://github.com/go-gitea/gitea/pull/38863))
      * Fix(lfs): ensure lock listing paginates with a total order ([#38850](https://github.com/go-gitea/gitea/pull/38850))
      * Fix(avatar): use sha256 and inline the federated avatar lookup ([#38843](https://github.com/go-gitea/gitea/pull/38843))
      * Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#38838](https://github.com/go-gitea/gitea/pull/38838))
      * Fix(deps): update dependency mermaid to v11.16.1 [security] ([#38813](https://github.com/go-gitea/gitea/pull/38813))
      * Fix: misc fixes in pub/gpg/tests ([#38809](https://github.com/go-gitea/gitea/pull/38809))
      * Fix: git diff blob excerpt ([#38808](https://github.com/go-gitea/gitea/pull/38808))
      * Fix(packages): show error for duplicate cleanup rules #37820 ([#38786](https://github.com/go-gitea/gitea/pull/38786))
      * Fix(actions): fix runner docs link ([#38783](https://github.com/go-gitea/gitea/pull/38783))
      * Fix: git cache ([#38763](https://github.com/go-gitea/gitea/pull/38763))
      * Fix(actions): evaluate each `${{ }}` part on its own ([#38754](https://github.com/go-gitea/gitea/pull/38754))
      * Fix: don't report failed network requests as JavaScript errors ([#38732](https://github.com/go-gitea/gitea/pull/38732))
      * Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#38728](https://github.com/go-gitea/gitea/pull/38728))
      * Fix(api): document X-Total-Count instead of non-existent X-Total header ([#38717](https://github.com/go-gitea/gitea/pull/38717))
      * Fix(actions): dynamic matrix expansion correctness fixes ([#38690](https://github.com/go-gitea/gitea/pull/38690))
      * Fix(auth): record last sign-in on reverse proxy login ([#38672](https://github.com/go-gitea/gitea/pull/38672))
      * Fix(api): accept fully-qualified refs in contents API ([#38650](https://github.com/go-gitea/gitea/pull/38650))
      * Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 [security] ([#38623](https://github.com/go-gitea/gitea/pull/38623))
      * Fix(deps): update dependency js-yaml to v5.2.2 [security] ([#38622](https://github.com/go-gitea/gitea/pull/38622))
      * Fix: abort superseded issue suggestion requests ([#38620](https://github.com/go-gitea/gitea/pull/38620))
      * Fix(issue): display error toast on batch action failures instead of reloading page ([#38593](https://github.com/go-gitea/gitea/pull/38593))
      * Fix(deps): update module google.golang.org/grpc to v1.82.1 [security] ([#38567](https://github.com/go-gitea/gitea/pull/38567))
      * Fix(deps): update module github.com/google/go-github/v88 to v89 ([#38433](https://github.com/go-gitea/gitea/pull/38433))
      * Fix(deps): update go dependencies ([#38429](https://github.com/go-gitea/gitea/pull/38429))
      * Fix(deps): update go dependencies ([#38346](https://github.com/go-gitea/gitea/pull/38346))
      * Fix(deps): update npm dependencies ([#38342](https://github.com/go-gitea/gitea/pull/38342))
      * Fix(base): correct natural sort of numbers with leading zeros ([#38163](https://github.com/go-gitea/gitea/pull/38163))
      * Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#37818](https://github.com/go-gitea/gitea/pull/37818))
      * Fix: make auth source group sync correctly handle team removal ([#37161](https://github.com/go-gitea/gitea/pull/37161))
      * Fix(release): separate publication time from the release date ([#36761](https://github.com/go-gitea/gitea/pull/36761))
    
    * TESTING
      * Test: stop tests from writing into `~/.ssh` ([#39348](https://github.com/go-gitea/gitea/pull/39348))
      * Test(e2e): log out to switch users in pr-review test ([#39328](https://github.com/go-gitea/gitea/pull/39328))
      * Test: release fixtures loader lock before database work ([#39263](https://github.com/go-gitea/gitea/pull/39263))
      * Test: speed up tests, fix transaction bug ([#39030](https://github.com/go-gitea/gitea/pull/39030))
      * Test: run frontend unit tests in browsers ([#38860](https://github.com/go-gitea/gitea/pull/38860))
      * Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#38661](https://github.com/go-gitea/gitea/pull/38661))
      * Test(e2e): add pull request merge box test, update AGENTS.md ([#38576](https://github.com/go-gitea/gitea/pull/38576))
      * Test(e2e): deterministically wait for event stream in logout propagation test ([#38535](https://github.com/go-gitea/gitea/pull/38535))
    
    * BUILD
      * Refactor: fix `go vet` errors related to composite literals ([#39341](https://github.com/go-gitea/gitea/pull/39341))
      * Build(gogit): disable gogit builds for stable releases ([#39324](https://github.com/go-gitea/gitea/pull/39324))
      * Refactor: replace jquery.are-you-sure with first-party code ([#39233](https://github.com/go-gitea/gitea/pull/39233))
      * Refactor: http request binding ([#38971](https://github.com/go-gitea/gitea/pull/38971))
      * Refactor: clean up git repo and model migration packages ([#38564](https://github.com/go-gitea/gitea/pull/38564))
      * Refactor: prepare to decouple the "model migration" package and "models" package ([#38533](https://github.com/go-gitea/gitea/pull/38533))
      * Build: fix snapcraft release ([#38260](https://github.com/go-gitea/gitea/pull/38260))
      * Build(release): use native golang toolchain for official release builds ([#37828](https://github.com/go-gitea/gitea/pull/37828))
    
    * DOCS
      * Docs(webhook): review.type comment lists values the webhook never sends ([#39451](https://github.com/go-gitea/gitea/pull/39451))
      * Docs(api): document verification and files on the compare endpoint ([#39440](https://github.com/go-gitea/gitea/pull/39440))
      * Docs(api): name the unadopted-repository search parameter query ([#39370](https://github.com/go-gitea/gitea/pull/39370))
      * Docs: remove unused COOKIE_USERNAME from app.example.ini ([#39365](https://github.com/go-gitea/gitea/pull/39365))
      * Docs: document NOTICE_ON_SUCCESS for every cron task ([#39352](https://github.com/go-gitea/gitea/pull/39352))
      * Docs: correct ALLOW_LOCALNETWORKS description in app.example.ini ([#39240](https://github.com/go-gitea/gitea/pull/39240))
      * Docs: fix typo in README about app.ini restart ([#39223](https://github.com/go-gitea/gitea/pull/39223))
      * Docs: fix dead localization doc link in the READMEs ([#39211](https://github.com/go-gitea/gitea/pull/39211))
      * Docs: Update CHANGELOG for release 1.27.3 ([#39170](https://github.com/go-gitea/gitea/pull/39170))
      * Docs: Update CHANGELOG for version 1.27.2 ([#38923](https://github.com/go-gitea/gitea/pull/38923))
      * Docs: Update PGP key expiration date to July 23, 2027 ([#38747](https://github.com/go-gitea/gitea/pull/38747))
      * Docs(api): document 401/403 responses for user key endpoints ([#38711](https://github.com/go-gitea/gitea/pull/38711))
      * Docs: Update Changelog for release v1.27.1 ([#38670](https://github.com/go-gitea/gitea/pull/38670))
      * Docs: Update Changelog for 1.27 ([#38440](https://github.com/go-gitea/gitea/pull/38440))
      * Docs: Update Security docs ([#38422](https://github.com/go-gitea/gitea/pull/38422))
    
    * MISC
      * Refactor: make git http respond error message ([#39390](https://github.com/go-gitea/gitea/pull/39390))
      * Refactor(api): convert bot accounts through the admin user edit endpoint ([#39355](https://github.com/go-gitea/gitea/pull/39355))
      * Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#39330](https://github.com/go-gitea/gitea/pull/39330))
      * Refactor: replace Azure Blob SDK with a REST client ([#39315](https://github.com/go-gitea/gitea/pull/39315))
      * Refactor: npm route handlers ([#39275](https://github.com/go-gitea/gitea/pull/39275))
      * Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#39248](https://github.com/go-gitea/gitea/pull/39248))
      * Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#39231](https://github.com/go-gitea/gitea/pull/39231))
      * Refactor: pagination/pager ([#39162](https://github.com/go-gitea/gitea/pull/39162))
      * Refactor: share package registry error status classification ([#39133](https://github.com/go-gitea/gitea/pull/39133))
      * Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#39083](https://github.com/go-gitea/gitea/pull/39083))
      * Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#39001](https://github.com/go-gitea/gitea/pull/39001))
      * Refactor: deploy key and private route handlers ([#38999](https://github.com/go-gitea/gitea/pull/38999))
      * Refactor: wiki edit form ([#38918](https://github.com/go-gitea/gitea/pull/38918))
      * Refactor: clean up form binding & validation ([#38873](https://github.com/go-gitea/gitea/pull/38873))
      * Refactor: markup render ([#38864](https://github.com/go-gitea/gitea/pull/38864))
      * Refactor: api token scope check ([#38862](https://github.com/go-gitea/gitea/pull/38862))
      * Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#38837](https://github.com/go-gitea/gitea/pull/38837))
      * Refactor: form binding validation ([#38832](https://github.com/go-gitea/gitea/pull/38832))
      * Refactor: prepare vue components for vapor mode ([#38798](https://github.com/go-gitea/gitea/pull/38798))
      * Refactor: use the shared workflow model from actionslib ([#38768](https://github.com/go-gitea/gitea/pull/38768))
      * Refactor(modelmigration): thread context through migration functions ([#38758](https://github.com/go-gitea/gitea/pull/38758))
      * Refactor: migrate remaining Vue components to `<script setup>` ([#38752](https://github.com/go-gitea/gitea/pull/38752))
      * Refactor: introduce trString for frontend ([#38741](https://github.com/go-gitea/gitea/pull/38741))
      * Refactor(diff): drive diff DOM init from the global selector observer ([#38740](https://github.com/go-gitea/gitea/pull/38740))
      * Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#38662](https://github.com/go-gitea/gitea/pull/38662))
      * Refactor: replace debounce/throttle deps with first-party code ([#38610](https://github.com/go-gitea/gitea/pull/38610))
      * Refactor: hide git repo path details from more packages ([#38601](https://github.com/go-gitea/gitea/pull/38601))
      * Refactor: retry file remove/rename when a file is busy and clean up os detection ([#38588](https://github.com/go-gitea/gitea/pull/38588))
      * Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#38573](https://github.com/go-gitea/gitea/pull/38573))
      * Refactor: implement mcaptcha client and add comments/tests ([#38561](https://github.com/go-gitea/gitea/pull/38561))
      * Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#38555](https://github.com/go-gitea/gitea/pull/38555))
      * Refactor: remove Path field from git.Repository ([#38552](https://github.com/go-gitea/gitea/pull/38552))
      * Refactor: make git package handle all git operations ([#38543](https://github.com/go-gitea/gitea/pull/38543))
      * Refactor: remove unnecessary git command wrapper functions ([#38531](https://github.com/go-gitea/gitea/pull/38531))
      * Refactor: git repo and relative path handling ([#38522](https://github.com/go-gitea/gitea/pull/38522))
      * Refactor: clean up fragile diff render templates, use backend typed structs ([#38517](https://github.com/go-gitea/gitea/pull/38517))
      * Refactor: correct git repo design and fix some legacy problems ([#38512](https://github.com/go-gitea/gitea/pull/38512))
      * Refactor: fix legacy problems in cmd/serv.go ([#38505](https://github.com/go-gitea/gitea/pull/38505))
      * Refactor: remove Ctx field from git.Repository ([#38500](https://github.com/go-gitea/gitea/pull/38500))
      * Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#38464](https://github.com/go-gitea/gitea/pull/38464))
      * Refactor: introduce ActivePageTimer to help to do partial page refresh ([#38372](https://github.com/go-gitea/gitea/pull/38372))
    
    
  • v1.27.3

    * SECURITY
      * fix(packages): restrict/limited/token-scope access (#39041, #39043, #39044, #39047, #39046) (#39058)
      * fix(attachments): enforce owning repository path (#39048) (#39077)
      * fix(markup): enforce same-repository issue access (#39045) (#39054)
      * fix(actions): verify raw artifact signatures first (#39049) (#39053)
      * fix(api): hide limited users from restricted viewers (#39004) (#39039)
      * fix(repo): limit gitignore template selections (#39027) (#39040)
      * fix(migrations): cancel GitLab version probes (#39023) (#39035)
      * fix(packages): limit Swift package manifests (#39025) (#39032)
      * fix(migrations): bound OneDev version responses (#39024) (#39033)
      * fix(packages): limit Maven checksum uploads (#39028) (#39031)
      * fix(packages): bound Alpine metadata entries (#39026) (#39029)
      * fix(actions): enforce fork pull request trust boundaries (#39005) (#39018)
      * fix(git): restrict hook permissions (#39008) (#39016)
      * fix(api): enforce repository creation token authorization (#39007) (#39014)
      * fix(api): enforce public-only scope for compare heads (#39006) (#39013)
      * fix(repo): hide repositories of hidden owners (#39009) (#39012)
      * fix: avoid enumerating every public repository in issue search (#38992) (#39000)
      * refactor: private endpoints (#38964) (#38965)
    * ENHANCEMENTS
      * enhance: add permalinks to pull request reviews (#38849) (#39036)
    * BUGFIXES
      * fix: add missing query parameters on runner list page (#39163)
      * fix(actions): keep step-level continue-on-error expressions unevaluated (#39141) (#39148)
      * fix(packages): preserve SemVer prerelease identifiers in Swift Registry (#39156) (#39158)
      * fix(repo): prevent MarkAsBrokenEmpty when repository is being migrated (#39091) (#39092)
      * fix(asymkey): do not verify OpenPGP signatures with an SSH instance key (#39073) (#39086)
      * fix(pull): keep the merged state in sync with git (#39062) (#39118)
      * fix(pull): name the head repository in default compare links (#39075) (#39079)
      * fix(git): parse co-author trailers that are not RFC 5322 addresses (#39076) (#39081)
      * fix(actions): show "Complete job" logs when the last step is skipped (#38939) (#39003)
      * fix(actions): Fix how jobs in matrixes are grouped (#38980) (#38998)
      * fix: resolve YAML anchors and aliases in Actions workflows (#38984) (#38996)
      * fix: honor environment variables during install (#38974) (#38976)
      * fix: grant limited-org unit read access to authenticated non-members (#38871) (#38963)
      * fix: allow anonymous theme switching when REQUIRE_SIGNIN_VIEW is set (#38956) (#38961)
      * fix(actions): drop wrapper span around the action status icon (#38957) (#38959)
      * fix(issues): sort scoped labels by exclusive order in dropdowns (#38893) (#38954)
      * fix(indexer): correct bleve indexer token filters (#38853) (#38951)
      * fix: make "login_name" field optional for API edit user (#38917) (#38945)
      * fix(actions): reject non-mapping matrix include/exclude (#38933)
      * fix(ui): respect FEED_PAGING_NUM on the dashboard feed (#38935) (#38936)
    * MISC
      * chore: repo compare link (#39088) (#39119)
      * ci: remove AWS S3 uploads from release workflows (#38928) (#38929)
      * chore: Pre-register a builtin OAuth2 application for the official Gitea mobile app (#38880) (#38922)
    
  • v1.27.2

    * SECURITY
      * Fix: update collaborator access mode and httpsign (#38894, #38862) (#38895)
      * Refactor: external render (#38885) (#38898)
      * Fix(actions): resolve pull_request_target reusable workflows at the base commit (#38886) (#38897)
      * Refactor: markup render (#38864) (#38869)
      * Fix(deps): update dependency mermaid to v11.16.1 (#38816)
      * Fix(auth): set WebAuthn user verification per request (#38805) (#38810)
      * Fix: render highlight language (#38793) (#38795)
    
    * ENHANCEMENTS
      * enhance: add missing npm package metadata properties (#38826) (#38831)
    
    * BUGFIXES
      * fix(actions): keep github.event.inputs as strings for workflow_dispatch (#38899) (#38908)
      * fix(actions): let a rerun of selected jobs read the previous attempt's artifacts (#38857) (#38901)
      * fix(lfs): accept successful transfer responses (#38866) (#38875)
      * fix(packages): ignore nested Package.swift (#38788) (#38836)
      * fix: drop newline-bearing member names in arch ParsePackage (#38102) (#38830)
      * fix(storage): fix Azure Blob dump failing with file does not exist (#38814) (#38828)
      * fix(migration): migration deletion returned json redirection (#38796) (#38825)
      * fix(ui): change underlines to default browser style (#38819) (#38823)
      * fix(actions): allow cancelling runs without running jobs (#35842) (#38812)
      * fix(actions): evaluate each `${{ }}` part on its own (#38754) (#38797)
      * fix(actions): write an action task report in one transaction (#38792) (#38794)
      * fix: markup link (#38764) (#38765)
      * fix: set a minio part size when the content size is unknown (#38753) (#38755)
      * fix: bad path escape in subpath archive download (#38749) (#38750)
      * fix: remove the pull merge box from UI when the refreshed page doesn't contain it (#38742) (#38744)
      * fix(markdown): fix double strikethough on code (#38707) (#38729)
      * fix(lfs): failed upload deletes a concurrent upload's meta object (#38693) (#38722)
      * fix: correct full url when using sub-path (#38712) (#38716)
      * fix: avoid markup render panic (#38698) (#38703)
      * fix(ui): too many participants shown in commit avatar stacks (#38689) (#38700)
      * fix: support HEAD requests on Alpine registry APKINDEX.tar.gz (#38686) (#38688)
      * fix(migrations): use all configured GitHub tokens (#38841) (#38846)
    
  • v1.27.1

    * SECURITY
      * fix(oauth2): enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints (#38591) (#38606)
    
    * API
      * fix(api): align Swagger schemas for UserSettings and TopicListResponse (#38590) (#38592)
    
    * ENHANCEMENTS
      * enhance: improve diff contrast in light and dark themes (#37477) (#38574)
    
    * BUGFIXES
      * fix: skip OIDC end-session after password login for OAuth2 users (#38439) (#38666)
      * fix: make Actions log parser support multiple line message encoding (#38659) (#38664)
      * fix(actions): use base branch ref for pull_request_target context (#38636) (#38657)
      * fix(actions): skip already-approved runs in `ApproveRuns` (#38653) (#38654)
      * fix: orgmode render include path (#38642) (#38645)
      * fix(actions): cancel tasks immediately when the runner stopped reporting (#38616) (#38644)
      * fix(issues): fix label bulk-load key and reduce log noise in LoadLabel (#38632) (#38643)
      * fix(actions): improve runner list status sorting, labels and task job links (#38586) (#38633)
      * fix(actions): correctness and hardening fixes (#38518) (#38631)
      * fix(repo): prevent double-write redirect collisions on dependency errors, fix ui (#38627) (#38628)
      * fix: delete repo-scoped rows of seven more tables when deleting a repository (#38534) (#38618)
      * fix(webhook): remove slack channel name check (#38608) (#38612)
      * fix: download dropdown menu clipped on the branches page (#38604) (#38609)
      * fix(project): prevent database mutations on invalid MoveIssues payload (#38600) (#38602)
      * fix(actions): make SingleWorkflow.Marshal round-trip multi-line run blocks (stop silent job stranding) (#38520) (#38599)
      * fix(file-tree): handle submodule links and missing view container (#38033) (#38589)
      * fix(actions): fail unexpandable reusable workflow callers and decouple the job emitter's cross-run processing (#38565) (#38587)
      * fix: keep serving valid ACME cert when renewal fails at startup (#38554) (#38583)
      * fix: branch protection user list (#38570) (#38584)
      * fix(pulls): respect diff.orderFile in diff file tree (#38566) (#38578)
      * fix(issue): make issue action (issue list batch operation) elements have correct attributes (#38575) (#38580)
      * fix(actions): support `matrix` when evaluating workflow `if` expression (#38474) (#38557)
      * fix(actions): align status icon span for Safari rendering (#38558) (#38562)
      * fix: revert git clone http redirection forbidden (#38530) (#38545)
      * fix: clean up orphaned user-keyed tables in deleteUser (#38511) (#38514)
      * fix(actions): coerce workflow_dispatch boolean inputs to native types (#38472) (#38521)
      * fix: make the merge box button red if some checks fail (#38508) (#38516)
      * fix(pull): sign the commit when updating a branch by merge (#38441) (#38499)
      * fix: make commit message merge correctly (#38490) (#38502)
      * fix(actions): explain why a blocked or waiting job has not started (#38476) (#38498)
      * fix(actions): make `cancelled()` work in job `if` evaluation (#38495) (#38497)
      * fix(actions): show retention info on hover for expired artifacts (#38477) (#38493)
      * fix(actions): group reusable-workflow matrix legs in the workflow graph (#38475) (#38492)
      * fix: full file highlighting for git diff with CR char (#38484) (#38491)
      * fix(packages): serve noarch Alpine index for any requested architecture (#38479) (#38486)
      * fix: 500 error when updating user visibility (#38480) (#38483)
      * fix(actions): make job list item fully clickable (#38462) (#38471)
      * fix: mail template for push event (#38467) (#38468)
      * fix: make "test push webhook" always work (#38425) (#38455)
      * fix(actions): prevent bulk actions from affecting all runners (#38453) (#38457)
      * fix(org): align follow button and wrap description (#38448) (#38454)
      * fix(actions): populate `github.event` for scheduled runs (#38446) (#38452)
    
    * MISC
      * refactor: git patch apply (#38637) (#38638)
    
  • v1.27.0

    * BREAKING
      * Feat(actions)!: improve support for reusable workflows (#37478)
      * Use Content-Security-Policy: script nonce (#37232)
    
    * SECURITY
      * Fix: various security fixes (#38406) (#38426)
      * Fix(security): harden access checks and migration validation (#38324) (#38400)
      * Fix: enforce public-only token scope and harden push options / locale parsing (#38323) (#38399)
      * Fix(pull): re-evaluate review official flag on target branch change (#38319) (#38402)
      * Fix(api): stop leaking private repo metadata after access revocation (#38321) (#38390)
      * Fix(lfs): require proof of possession for cross-repo objects (#38322) (#38389)
      * Fix(mirror): disable HTTP redirects on pull mirror sync (#38320) (#38367)
      * Fix: golang html template url escaping (#38363) (#38369)
      * Fix(release): validate web attachment renames against allowed types (#38314) (#38328)
      * Fix(release): gate draft release attachments on web download endpoints (#38318) (#38325)
      * Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#37786)
      * Fix(oauth): restrict introspection to the token's client (#38042)
      * Fix(api): don't expose private org membership via public_members (#38145)
      * Fix(actions): deny fork-PR cross-repo access via collaborative owner (#38214)
      * Fix(migrations): prevent path traversal in repository restore (#38215)
    
    * FEATURES
      * Feat(actions): add workflow status badge modal (#38196)
      * Feat(actions): support owner-level and global scoped workflows (#38154)
      * Feat(api): support ref suffixes in compare (#38148)
      * Feat(actions): implement `jobs.<job_id>.continue-on-error` (#38100)
      * Feat(actions): show run status on browser tab favicon (#38071)
      * Feat(api): add token introspection and self-deletion endpoint (#37995)
      * Feat(api): add q parameter to list branches API for server-side filtering (#37982)
      * Feat(repo): split repository creation limit into user and org scopes (#37872)
      * Feat(actions): bulk delete, disable and enable runners in admin UI (#37869)
      * Feat(actions): List workflows that were executed once but got removed from the default branch (#37835)
      * Feat(org): add team visibility so org members can discover teams (#37680)
      * Feat: add raw diff/patch endpoint for repository comparisons (#37632)
      * Feat: Add avatar stacks (#37594)
      * Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) (#37500)
      * Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support (#37433)
      * Support for Custom URI Schemes in OAuth2 Redirect URIs (#37356)
      * Feat(orgs): Add search bar for organization members tab page (#37347)
      * Feat(api): Add assignees APIs (#37330)
      * Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs (#37196)
      * Serve OpenAPI 3.0 spec at /openapi.v1.json (#37038)
      * Add project column picker to issue and pull request sidebar (#37037)
      * Allow multiple projects per issue and pull requests (#36784)
      * Feat(ui): add "follow rename" to file commit history list (#34994)
      * Feat(ssh): auto generate additional ssh keys (#33974)
    
    * ENHANCEMENTS
      * Enhance(actions): only create filtered-out workflow commit status for required contexts (#38371) (#38385)
      * Enhance: allow builtin default git config options to be overridden (#38172)
      * Enhance: allow MathML core elements (#38034)
      * Enhance(markup): improve issue title rendering (#37908)
      * Enhance(actions): set descriptive browser tab title on run view (#37870)
      * Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 (#37866)
      * Enhance(actions): show workflow name from YAML instead of filename (#37833)
      * Feat(actions): add before/after to PR synchronize event payload (#37827)
      * Enhance(actions): add branch filters to run list (#37826)
      * Enhance(actions): Make Summary UI more beautiful with more infos (#37824)
      * Feat: add copy button to action step header, improve other copy buttons (#37744)
      * Fix(icon): use repo-forked icon to display forks count (#37731)
      * Feat(api): add sort and order query parameters to job list endpoints (#37672)
      * Feat(api): add last_sync to repository API (#37566)
      * Enhance: Adjust Workflow Graph styling (#37497)
      * Improve code editor text selection and clean up lint enablement (#37474)
      * Add mirror auth updates to repo edit API and settings (#37468)
      * Replace `olivere/elastic` with REST API client, add OpenSearch support (#37411)
      * Feat: Add default PR branch update style setting (#37410)
      * Fix inconsistent disabled styling on logged-out repo header buttons (#37406)
      * Allow fast-forward-only merge when signed commits are required (#37335)
      * Enhance styling in actions page (#37323)
      * Fix: improve actions status icons and texts (#37206)
      * Make Markdown fenced code block work with more syntaxes (#37154)
      * Fix: Sort action run jobs by JobID and Name with matrix examples (#37046)
      * Add API endpoint to reply to pull request review comments (#36683)
    
    * PERFORMANCE
      * Perf(actions): debounce runner heartbeat writes and throttle task picks (#38281) (#38368)
      * Perf(web): sort the action_run query by a repo-scoped index when possible (#38155)
      * Perf: Various performance regression fixes (#38078)
      * Perf: extend action `c_u` index to include `created_unix` for faster dashboard feeds (#38076)
      * Batch-load related data in actions run, job, and task API endpoints (#37032)
    
    * BUGFIXES
      * Fix(util): reject invalid characters between time-estimate units (#38416) (#38423)
      * Fix: represent a deleted assignee team as a Ghost team (#38413) (#38419)
      * Fix(turnstile): route CAPTCHA verification through the configured proxy (#38412) (#38420)
      * Fix: refresh pull request merge box when the commit status is pending (#38410) (#38411)
      * Fix: actions task state concurrent update (#38405) (#38409)
      * Fix(actions): keep workflow run trailing on one row with long branch names (#38382) (#38403)
      * Fix(web): use locale-aware date formatting for contribution calendar tooltips (#38398) (#38401)
      * Fix: co-author detection (#38392) (#38397)
      * Fix: incorrect co-author detection on commit page (#38386) (#38387)
      * Fix(ui): restore commits table column widths (#38379) (#38383)
      * Fix: minio init check (#38355) (#38361)
      * Fix: org project view assignee list (#38357) (#38360)
      * Fix(actions): release claimed task if context is cancelled during `FetchTask` (#38343) (#38347)
      * Fix(actions): make runner list pagination order deterministic (#38313) (#38327)
      * Fix: Improve since/until when counting commits for X-Total-Count (#38243) (#38304)
      * Fix(actions): prevent chevron overlap with log text when timestamps are enabled (#38227) (#38307)
      * Fix(workflows): branch protection status checks fail when workflow uses on: paths filter (#38237) (#38302)
      * Fix(oauth2): persist linkAccountData during auto-link 2FA flow (#38274) (#38295)
      * Fix(actions): allow Actions bot to push to protected branches (#38284) (#38293)
      * Fix(actions): include all aggregable run statuses in status filter (#38280) (#38287)
      * Fix(archiver): use serializable repo-archive queue payload (#38273) (#38283)
      * Fix: update npm dependencies, fix misc issues (#38257)
      * Fix(api): respect since/until when counting commits for X-Total-Count (#38204)
      * Fix: codemirror regressions (#38248)
      * Fix(api): support HEAD requests on all API GET endpoints (#38245)
      * Fix(actions): Cleanup workflow status badge code (#38241)
      * Fix(web): Correctly align the "disabled" label on larger workflow names (#38240)
      * Fix(actions): don't swallow HTML entities into linkified URLs (#38239)
      * Fix(packages): accept npm "repository" and "bin" in string form (#38236)
      * Fix(actions): fix 500 error when canceling a canceling task (#38223)
      * Fix(deps): update module golang.org/x/image to v0.43.0 [security] (#38219)
      * Fix(mssql): convert legacy DATETIME columns to DATETIME2 (#38216)
      * Fix(api): deny private org member enumeration via /members (#38213)
      * Fix(actions): ensure all waiting jobs get runners in large workflows (#38200)
      * Fix(deps): update go dependencies (#38194)
      * Fix(deps): update npm dependencies (#38193)
      * Fix(cli): default must-change-password to false for bot users (#38175)
      * Fix(actions): show run index in run view and fix summary graph height (#38165)
      * Fix: csp (#38162)
      * Fix(deps): update npm dependencies (#38123)
      * Fix(mssql): expand legacy issue and comment long-text columns (#38120)
      * Fix(packages): validate debian distribution and component names (#38116)
      * Fix(packages): validate module version in goproxy ParsePackage (#38104)
      * Fix(deps): update dependency esbuild to v0.28.1 [security] (#38097)
      * Fix: git push hook post receive (#38089)
      * Fix(ui): prevent commit status popup overflowing its row (#38081)
      * Fix: validate gem name in rubygems parseMetadataFile (#38061)
      * Fix: commit display name (#38057)
      * Fix: csp regressions (#38047)
      * Fix: api error message (#38031)
      * Fix(deps): update npm dependencies (#38029)
      * Fix: pgsql lint (#38022)
      * Fix(indexer): fix assignee filters in issue search (#38021)
      * Fix: various dropdown problems (#38020)
      * Fix: refactor git error handling and make archive streaming handle non-existing commit id (#38007)
      * Fix: raise git required version to 2.13 (#37996)
      * Fix: remove "no-transfrom" from the cache-control header (#37985)
      * Fix(deps): update module github.com/google/go-github/v87 to v88 (#37971)
      * Fix: use committer time where ever possible as default (#37969)
      * Fix(deps): update npm dependencies, remove nolyfill (#37968)
      * Fix(deps): update go dependencies (#37967)
      * Fix(pull): preserve squash message trailers and additional commit messages (#37954)
      * Fix(deps): update module golang.org/x/image to v0.41.0 [security] (#37904)
      * Fix: support ##[command] log prefix in action run UI (#37882)
      * Fix(deps): update module github.com/google/go-github/v86 to v87 (#37845)
      * Fix(deps): update npm dependencies (#37844)
      * Fix(deps): update go dependencies (#37841)
      * Fix(frontend): resolve Vite assets by manifest source path (#37836)
      * Fix(locales): Replace hardcoded strings (#37788)
      * Fix(packages): render markdown links relative to linked repo (#37676)
      * Fix: persist mirror repository metadata (#37519)
      * Fix cmd tests by mocking builtin paths (#37369)
      * Add `form-fetch-action` to some forms, fix "fetch action" resp bug (#37305)
      * Feat: execute post run cleanup when workflow is cancelled (#37275)
      * Fix `relative-time` error and improve global error handler (#37241)
      * Refactor flash message and remove SanitizeHTML template func (#37179)
    
    * TESTING
      * Test(e2e): fix race in pdf file render test (#38380) (#38381)
      * Test: compare key file contents instead of `FileInfo` in `TestInitKeys` (#38330) (#38331)
      * Test: speed up two tests (#37905)
      * Test: Fix random failure test (#37887)
      * Test: fix flaky `issue-comment` close test (#37880)
      * Test: enable WAL for sqlite integration tests (#37861)
      * Test: fix flaky `TestResourceIndex` and reduce its runtime (#37847)
      * Test: run `TestAPIRepoMigrate` offline via a local clone source (#37817)
      * Ci: shard tests and reduce redundant work (#37618)
      * Test(e2e): run playwright via container (#37300)
      * Remove external service dependencies in migration tests (#36866)
    
    * BUILD
      * Fix(actions): authenticate snapcraft before nightly remote build (#38252)
      * Ci: cap Elasticsearch heap in db-tests (#37816)
      * Build(snap): publish nightly version to snapcraft via actions (#37814)
      * Ci: split pgsql shards into plain jobs, dedupe setup actions (#37802)
      * Ci: narrow files-changed frontend filter (#37749)
      * Ci: add `zizmor` to `lint-actions` (#37720)
      * Chore: clean up "contrib" dir (#37690)
      * Fix: snap build (main branch) (#37685)
      * Ci: Also lint json5 files (#37659)
      * Feat(editor): broaden language detection in web code editor (#37619)
      * Build: update pnpm to v11 (#37591)
      * Refactor(deps): migrate from `nektos/act` fork to `gitea/runner` (#37557)
      * Refactor: lint bare `fill`/`stroke` colors, add vars for git graph color series (#37543)
      * Update go js py dependencies (#37525)
      * Ci: lint PR titles with commitlint (#37498)
      * Chore: upgrade Go version in devcontainer image to 1.26 (#37374)
      * Update GitHub Actions to latest major versions (#37313)
      * Update go js dependencies (#37312)
      * Fail vite build on rolldown warnings via NODE_ENV=test (#37270)
      * Remove htmx (#37224)
      * Replace custom Go formatter with `golangci-lint fmt` (#37194)
      * Refactor htmx and fetch-action related code (#37186)
      * Integrate renovate bot for all dependency updates (#37050)
      * Build(sign): move to sigstore (#38250)
    
    * DOCS
      * Docs: update changelog for 1.26.3 & 1.26.4 (#38178)
      * Docs: fix duplicated word in foreachref doc comment (#38161)
      * Docs: Clarify criteria for becoming a merger (#38113)
      * Docs: Publish TOC Election Result 2026 (#38111)
      * Docs: mark openapi3 as autogenerated in attributes (#37963)
      * Docs: add development setup guide (#37960)
    
    * MISC
      * Revert(sign): restore gpg (#38251)
      * Refactor: replace legacy `delete-button` with `link-action` (#38143)
      * Refactor(actions): read runner capabilities from proto field (#38068)
      * Refactor(api): clarify APIError message usage and fix legacy lint error (#38012)
      * Refactor: Use db.Get[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record (#37977)
      * Fix(deps): update go dependencies (#37851)
      * Ci: Fix sync PR labels from the conventional-commit title (#37784) (#37825)
      * Ci: tweak `files-changed`, add `free-disk-space` (#37819)
      * Fix(deps): update module golang.org/x/crypto to v0.52.0 [security] (#37806)
      * Test(e2e): add comment, release, star, PR and fork tests (#37800)
      * Chore: simplify issue and pull request templates (#37799)
      * Chore: Update giteabot to fix failure when backport (#37789)
      * Fix(api): handle partial failures in push mirror synchronization gracefully (#37782)
      * Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 (#37771)
      * Ci: split giteabot workflow (#37770)
      * Fix(deps): update npm dependencies (#37768)
      * Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go (#37764)
      * Fix(deps): update module google.golang.org/grpc to v1.81.1 (#37762)
      * Ci: fix cache-related issues (#37761)
      * Chore: fix tests (#37760)
      * Fix(deps): update module github.com/google/go-github/v85 to v86 (#37754)
      * Fix(deps): update npm dependencies (#37753)
      * Fix(deps): update go dependencies (#37752)
      * Chore(deps): update action dependencies (#37751)
      * Fix(markup): wrap indented code blocks for the code-copy button (#37748)
      * Chore(db): introduce db.Session and db.EngineMigration interfaces (#37746)
      * Feat(web): also display PR counts in repo list (#37739)
      * Refactor(glob): use strings.Builder for regexp compilation (#37730)
      * Chore(doctor): remove four obsolete doctor check implementations (#37728)
      * Refactor(org): simplify owner-team org repo creation logic (#37727)
      * Refactor: move `workflowpattern` into `modules/actions` (#37717)
      * Chore: clean up tests (#37715)
      * Style: misc UI fixes (#37691)
      * Ci: add shellcheck linter (#37682)
      * Fix: catch and fix more lint problems (#37674)
      * Fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test (#37662)
      * Fix(deps): update npm dependencies (#37647)
      * Ci(renovate): update Go import paths on major bumps (#37641)
      * Fix(deps): update go dependencies (major) (#37639)
      * Chore(deps): update action dependencies (major) (#37638)
      * Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 (#37637)
      * Fix(deps): update npm dependencies (#37636)
      * Refactor(log): replace log.Critical with log.Error (#37624)
      * Build(deps): bump fast-uri from 3.1.0 to 3.1.2 (#37616)
      * Feat(oauth): Support AWS Cognito OAuth2 provider (#37607)
      * Chore(deps): update action dependencies (#37603)
      * Ci: allow `chore` type in PR title lint (#37575)
      * Refactor: only reset a database table when the table's data was changed (#37573)
      * Ci: increase renovate frequency and fix RENOVATE_ALLOWED_POST_UPGRADE_COMMANDS (#37565)
      * Refactor: use modernc sqlite driver as default (#37562)
      * Docs: fix 4 typos in CHANGELOG.md (#37549)
      * Fix(deps): update go dependencies (#37541)
      * Chore(deps): update action dependencies (#37540)
      * Refactor pull request view (6) (#37522)
      * Fix: redirect early CLI console logger to stderr (#37507)
      * Refactor "flex-list" to "flex-divided-list" (#37505)
      * Refactor compare diff/pull page (1) (#37481)
      * Refactor pull request view (4) (#37451)
      * Update 1.26.1 changelog in main (#37442)
      * Refactor: use named `Permission` field in `Repository` struct instead of anonymous embedding (#37441)
      * Refactor: serve site manifest via `/assets/site-manifest.json` endpoint (#37405)
      * Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites (#37364)
      * Update `Block a user` form (#37359)
      * Move review request functions to a standalone file (#37358)
      * Feat(security): set X-Content-Type-Options: nosniff by default (#37354)
      * Enable strict TypeScript, add `errorMessage` helper (#37292)
      * Refactor frontend `tw-justify-between` layouts to `flex-left-right` (#37291)
      * Update Nix flake (#37284)
      * Fix Repository transferring page (#37277)
      * Remove `SubmitEvent` polyfill (#37276)
      * Remove dead code identified by `deadcode` tool (#37271)
      * Upgrade go-git to v5.18.0 (#37268)
      * Don't add useless labels which will bother changelog generation (#37267)
      * Move heatmap to first-party code (#37262)
      * Tests/integration: simplify code (#37249)
      * Add pagination and search box to org teams list (#37245)
      * Remove error returns from crypto random helpers and callers (#37240)
      * Add `ExternalIDClaim` option for OAuth2 OIDC auth source (#37229)
      * Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries (#37210)
      * Refactor "htmx" to "fetch action" (#37208)
      * Update go js py dependencies (#37204)
      * Add comment for the design of "user activity time" (#37195)
      * Remove outdated RunUser logic (#37180)
      * Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files (#37150)
      * Update javascript dependencies (#37142)
      * Update go dependencies (#37141)
      * Frontport changelog of v1.26.0-rc0 (#37138)
      * Introduce `ActionRunAttempt` to represent each execution of a run (#37119)
      * Workflow Artifact Info Hover (#37100)
      * Extend issue context popup beyond markdown content (#36908)
      * Add bulk repository deletion for organizations (#36763)
      * Feat: Add bypass allowlist for branch protection (#36514)
    
    
  • v1.27.0-rc0

    * BREAKING
      * Feat(actions)!: improve support for reusable workflows (#37478)
      * Use Content-Security-Policy: script nonce (#37232)
    
    * SECURITY
      * Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#37786)
      * Fix(oauth): restrict introspection to the token's client (#38042)
      * Fix(api): don't expose private org membership via public_members (#38145)
      * Fix(actions): deny fork-PR cross-repo access via collaborative owner (#38214)
      * Fix(migrations): prevent path traversal in repository restore (#38215)
    
    * FEATURES
      * Feat(actions): add workflow status badge modal (#38196)
      * Feat(actions): support owner-level and global scoped workflows (#38154)
      * Feat(api): support ref suffixes in compare (#38148)
      * Feat(actions): implement `jobs.<job_id>.continue-on-error` (#38100)
      * Feat(actions): show run status on browser tab favicon (#38071)
      * Feat(api): add token introspection and self-deletion endpoint (#37995)
      * Feat(api): add q parameter to list branches API for server-side filtering (#37982)
      * Feat(repo): split repository creation limit into user and org scopes (#37872)
      * Feat(actions): bulk delete, disable and enable runners in admin UI (#37869)
      * Feat(actions): List workflows that were executed once but got removed from the default branch (#37835)
      * Feat(org): add team visibility so org members can discover teams (#37680)
      * Feat: add raw diff/patch endpoint for repository comparisons (#37632)
      * Feat: Add avatar stacks (#37594)
      * Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) (#37500)
      * Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support (#37433)
      * Support for Custom URI Schemes in OAuth2 Redirect URIs (#37356)
      * Feat(orgs): Add search bar for organization members tab page (#37347)
      * Feat(api): Add assignees APIs (#37330)
      * Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs (#37196)
      * Serve OpenAPI 3.0 spec at /openapi.v1.json (#37038)
      * Add project column picker to issue and pull request sidebar (#37037)
      * Allow multiple projects per issue and pull requests (#36784)
      * Feat(ui): add "follow rename" to file commit history list (#34994)
      * Feat(ssh): auto generate additional ssh keys (#33974)
    
    * ENHANCEMENTS
      * Enhance: allow builtin default git config options to be overridden (#38172)
      * Enhance: allow MathML core elements (#38034)
      * Enhance(markup): improve issue title rendering (#37908)
      * Enhance(actions): set descriptive browser tab title on run view (#37870)
      * Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 (#37866)
      * Enhance(actions): show workflow name from YAML instead of filename (#37833)
      * Feat(actions): add before/after to PR synchronize event payload (#37827)
      * Enhance(actions): add branch filters to run list (#37826)
      * Enhance(actions): Make Summary UI more beautiful with more infos (#37824)
      * Feat: add copy button to action step header, improve other copy buttons (#37744)
      * Fix(icon): use repo-forked icon to display forks count (#37731)
      * Feat(api): add sort and order query parameters to job list endpoints (#37672)
      * Feat(api): add last_sync to repository API (#37566)
      * Enhance: Adjust Workflow Graph styling (#37497)
      * Improve code editor text selection and clean up lint enablement (#37474)
      * Add mirror auth updates to repo edit API and settings (#37468)
      * Replace `olivere/elastic` with REST API client, add OpenSearch support (#37411)
      * Feat: Add default PR branch update style setting (#37410)
      * Fix inconsistent disabled styling on logged-out repo header buttons (#37406)
      * Allow fast-forward-only merge when signed commits are required (#37335)
      * Enhance styling in actions page (#37323)
      * Fix: improve actions status icons and texts (#37206)
      * Make Markdown fenced code block work with more syntaxes (#37154)
      * Fix: Sort action run jobs by JobID and Name with matrix examples (#37046)
      * Add API endpoint to reply to pull request review comments (#36683)
    
    * PERFORMANCE
      * Perf(web): sort the action_run query by a repo-scoped index when possible (#38155)
      * Perf: Various performance regression fixes (#38078)
      * Perf: extend action `c_u` index to include `created_unix` for faster dashboard feeds (#38076)
      * Batch-load related data in actions run, job, and task API endpoints (#37032)
    
    * BUGFIXES
      * Fix: update npm dependencies, fix misc issues (#38257)
      * Fix(api): respect since/until when counting commits for X-Total-Count (#38204)
      * Fix: codemirror regressions (#38248)
      * Fix(api): support HEAD requests on all API GET endpoints (#38245)
      * Fix(actions): Cleanup workflow status badge code (#38241)
      * Fix(web): Correctly align the "disabled" label on larger workflow names (#38240)
      * Fix(actions): don't swallow HTML entities into linkified URLs (#38239)
      * Fix(packages): accept npm "repository" and "bin" in string form (#38236)
      * Fix(actions): fix 500 error when canceling a canceling task (#38223)
      * Fix(deps): update module golang.org/x/image to v0.43.0 [security] (#38219)
      * Fix(mssql): convert legacy DATETIME columns to DATETIME2 (#38216)
      * Fix(api): deny private org member enumeration via /members (#38213)
      * Fix(actions): ensure all waiting jobs get runners in large workflows (#38200)
      * Fix(deps): update go dependencies (#38194)
      * Fix(deps): update npm dependencies (#38193)
      * Fix(cli): default must-change-password to false for bot users (#38175)
      * Fix(actions): show run index in run view and fix summary graph height (#38165)
      * Fix: csp (#38162)
      * Fix(deps): update npm dependencies (#38123)
      * Fix(mssql): expand legacy issue and comment long-text columns (#38120)
      * Fix(packages): validate debian distribution and component names (#38116)
      * Fix(packages): validate module version in goproxy ParsePackage (#38104)
      * Fix(deps): update dependency esbuild to v0.28.1 [security] (#38097)
      * Fix: git push hook post receive (#38089)
      * Fix(ui): prevent commit status popup overflowing its row (#38081)
      * Fix: validate gem name in rubygems parseMetadataFile (#38061)
      * Fix: commit display name (#38057)
      * Fix: csp regressions (#38047)
      * Fix: api error message (#38031)
      * Fix(deps): update npm dependencies (#38029)
      * Fix: pgsql lint (#38022)
      * Fix(indexer): fix assignee filters in issue search (#38021)
      * Fix: various dropdown problems (#38020)
      * Fix: refactor git error handling and make archive streaming handle non-existing commit id (#38007)
      * Fix: raise git required version to 2.13 (#37996)
      * Fix: remove "no-transfrom" from the cache-control header (#37985)
      * Fix(deps): update module github.com/google/go-github/v87 to v88 (#37971)
      * Fix: use committer time where ever possible as default (#37969)
      * Fix(deps): update npm dependencies, remove nolyfill (#37968)
      * Fix(deps): update go dependencies (#37967)
      * Fix(pull): preserve squash message trailers and additional commit messages (#37954)
      * Fix(deps): update module golang.org/x/image to v0.41.0 [security] (#37904)
      * Fix: support ##[command] log prefix in action run UI (#37882)
      * Fix(deps): update module github.com/google/go-github/v86 to v87 (#37845)
      * Fix(deps): update npm dependencies (#37844)
      * Fix(deps): update go dependencies (#37841)
      * Fix(frontend): resolve Vite assets by manifest source path (#37836)
      * Fix(locales): Replace hardcoded strings (#37788)
      * Fix(packages): render markdown links relative to linked repo (#37676)
      * Fix: persist mirror repository metadata (#37519)
      * Fix cmd tests by mocking builtin paths (#37369)
      * Add `form-fetch-action` to some forms, fix "fetch action" resp bug (#37305)
      * Feat: execute post run cleanup when workflow is cancelled (#37275)
      * Fix `relative-time` error and improve global error handler (#37241)
      * Refactor flash message and remove SanitizeHTML template func (#37179)
    
    * TESTING
      * Test: speed up two tests (#37905)
      * Test: Fix random failure test (#37887)
      * Test: fix flaky `issue-comment` close test (#37880)
      * Test: enable WAL for sqlite integration tests (#37861)
      * Test: fix flaky `TestResourceIndex` and reduce its runtime (#37847)
      * Test: run `TestAPIRepoMigrate` offline via a local clone source (#37817)
      * Ci: shard tests and reduce redundant work (#37618)
      * Test(e2e): run playwright via container (#37300)
      * Remove external service dependencies in migration tests (#36866)
    
    * BUILD
      * Fix(actions): authenticate snapcraft before nightly remote build (#38252)
      * Ci: cap Elasticsearch heap in db-tests (#37816)
      * Build(snap): publish nightly version to snapcraft via actions (#37814)
      * Ci: split pgsql shards into plain jobs, dedupe setup actions (#37802)
      * Ci: narrow files-changed frontend filter (#37749)
      * Ci: add `zizmor` to `lint-actions` (#37720)
      * Chore: clean up "contrib" dir (#37690)
      * Fix: snap build (main branch) (#37685)
      * Ci: Also lint json5 files (#37659)
      * Feat(editor): broaden language detection in web code editor (#37619)
      * Build: update pnpm to v11 (#37591)
      * Refactor(deps): migrate from `nektos/act` fork to `gitea/runner` (#37557)
      * Refactor: lint bare `fill`/`stroke` colors, add vars for git graph color series (#37543)
      * Update go js py dependencies (#37525)
      * Ci: lint PR titles with commitlint (#37498)
      * Chore: upgrade Go version in devcontainer image to 1.26 (#37374)
      * Update GitHub Actions to latest major versions (#37313)
      * Update go js dependencies (#37312)
      * Fail vite build on rolldown warnings via NODE_ENV=test (#37270)
      * Remove htmx (#37224)
      * Replace custom Go formatter with `golangci-lint fmt` (#37194)
      * Refactor htmx and fetch-action related code (#37186)
      * Integrate renovate bot for all dependency updates (#37050)
      * Build(sign): move to sigstore (#38250)
    
    * DOCS
      * Docs: update changelog for 1.26.3 & 1.26.4 (#38178)
      * Docs: fix duplicated word in foreachref doc comment (#38161)
      * Docs: Clarify criteria for becoming a merger (#38113)
      * Docs: Publish TOC Election Result 2026 (#38111)
      * Docs: mark openapi3 as autogenerated in attributes (#37963)
      * Docs: add development setup guide (#37960)
    
    * MISC
      * Revert(sign): restore gpg (#38251)
      * Refactor: replace legacy `delete-button` with `link-action` (#38143)
      * Refactor(actions): read runner capabilities from proto field (#38068)
      * Refactor(api): clarify APIError message usage and fix legacy lint error (#38012)
      * Refactor: Use db.Get[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record (#37977)
      * Fix(deps): update go dependencies (#37851)
      * Ci: Fix sync PR labels from the conventional-commit title (#37784) (#37825)
      * Ci: tweak `files-changed`, add `free-disk-space` (#37819)
      * Fix(deps): update module golang.org/x/crypto to v0.52.0 [security] (#37806)
      * Test(e2e): add comment, release, star, PR and fork tests (#37800)
      * Chore: simplify issue and pull request templates (#37799)
      * Chore: Update giteabot to fix failure when backport (#37789)
      * Fix(api): handle partial failures in push mirror synchronization gracefully (#37782)
      * Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 (#37771)
      * Ci: split giteabot workflow (#37770)
      * Fix(deps): update npm dependencies (#37768)
      * Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go (#37764)
      * Fix(deps): update module google.golang.org/grpc to v1.81.1 (#37762)
      * Ci: fix cache-related issues (#37761)
      * Chore: fix tests (#37760)
      * Fix(deps): update module github.com/google/go-github/v85 to v86 (#37754)
      * Fix(deps): update npm dependencies (#37753)
      * Fix(deps): update go dependencies (#37752)
      * Chore(deps): update action dependencies (#37751)
      * Fix(markup): wrap indented code blocks for the code-copy button (#37748)
      * Chore(db): introduce db.Session and db.EngineMigration interfaces (#37746)
      * Feat(web): also display PR counts in repo list (#37739)
      * Refactor(glob): use strings.Builder for regexp compilation (#37730)
      * Chore(doctor): remove four obsolete doctor check implementations (#37728)
      * Refactor(org): simplify owner-team org repo creation logic (#37727)
      * Refactor: move `workflowpattern` into `modules/actions` (#37717)
      * Chore: clean up tests (#37715)
      * Style: misc UI fixes (#37691)
      * Ci: add shellcheck linter (#37682)
      * Fix: catch and fix more lint problems (#37674)
      * Fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test (#37662)
      * Fix(deps): update npm dependencies (#37647)
      * Ci(renovate): update Go import paths on major bumps (#37641)
      * Fix(deps): update go dependencies (major) (#37639)
      * Chore(deps): update action dependencies (major) (#37638)
      * Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 (#37637)
      * Fix(deps): update npm dependencies (#37636)
      * Refactor(log): replace log.Critical with log.Error (#37624)
      * Build(deps): bump fast-uri from 3.1.0 to 3.1.2 (#37616)
      * Feat(oauth): Support AWS Cognito OAuth2 provider (#37607)
      * Chore(deps): update action dependencies (#37603)
      * Ci: allow `chore` type in PR title lint (#37575)
      * Refactor: only reset a database table when the table's data was changed (#37573)
      * Ci: increase renovate frequency and fix RENOVATE_ALLOWED_POST_UPGRADE_COMMANDS (#37565)
      * Refactor: use modernc sqlite driver as default (#37562)
      * Docs: fix 4 typos in CHANGELOG.md (#37549)
      * Fix(deps): update go dependencies (#37541)
      * Chore(deps): update action dependencies (#37540)
      * Refactor pull request view (6) (#37522)
      * Fix: redirect early CLI console logger to stderr (#37507)
      * Refactor "flex-list" to "flex-divided-list" (#37505)
      * Refactor compare diff/pull page (1) (#37481)
      * Refactor pull request view (4) (#37451)
      * Update 1.26.1 changelog in main (#37442)
      * Refactor: use named `Permission` field in `Repository` struct instead of anonymous embedding (#37441)
      * Refactor: serve site manifest via `/assets/site-manifest.json` endpoint (#37405)
      * Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites (#37364)
      * Update `Block a user` form (#37359)
      * Move review request functions to a standalone file (#37358)
      * Feat(security): set X-Content-Type-Options: nosniff by default (#37354)
      * Enable strict TypeScript, add `errorMessage` helper (#37292)
      * Refactor frontend `tw-justify-between` layouts to `flex-left-right` (#37291)
      * Update Nix flake (#37284)
      * Fix Repository transferring page (#37277)
      * Remove `SubmitEvent` polyfill (#37276)
      * Remove dead code identified by `deadcode` tool (#37271)
      * Upgrade go-git to v5.18.0 (#37268)
      * Don't add useless labels which will bother changelog generation (#37267)
      * Move heatmap to first-party code (#37262)
      * Tests/integration: simplify code (#37249)
      * Add pagination and search box to org teams list (#37245)
      * Remove error returns from crypto random helpers and callers (#37240)
      * Add `ExternalIDClaim` option for OAuth2 OIDC auth source (#37229)
      * Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries (#37210)
      * Refactor "htmx" to "fetch action" (#37208)
      * Update go js py dependencies (#37204)
      * Add comment for the design of "user activity time" (#37195)
      * Remove outdated RunUser logic (#37180)
      * Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files (#37150)
      * Update javascript dependencies (#37142)
      * Update go dependencies (#37141)
      * Frontport changelog of v1.26.0-rc0 (#37138)
      * Introduce `ActionRunAttempt` to represent each execution of a run (#37119)
      * Workflow Artifact Info Hover (#37100)
      * Extend issue context popup beyond markdown content (#36908)
      * Add bulk repository deletion for organizations (#36763)
      * Feat: Add bypass allowlist for branch protection (#36514)
    
    
  • v1.26.4

    * SECURITY
      * fix(auth): do not auto-reactivate disabled users on OAuth2 callback (#38009) (#38183)
    
    * BUGFIXES
      * fix: walk git log context error handling (#38182) (#38185)
    
  • v1.26.3

    * BREAKING
      * fix(actions)!: require merged PR to bypass fork PR approval gate (#38010) (#38041)
    
    * SECURITY
      * fix(hostmatcher): patch incorrect private list (#38170) (#38173)
      * fix: Various security fixes (#38103) (#38151)
      * fix: Various sec fixes (#38108) (#38147)
      * fix: allow git clone of private repos with anonymous code access (#38074) (#38146)
      * fix(auth): ignore stale OIDC external login links to organizations (#37875) (#38141)
      * fix(hostmatcher): block reserved IP ranges from external/private filters (#38039) (#38059)
      * fix(lfs): require Code-unit access for cross-repo LFS object reuse (#38006) (#38050)
      * fix(lfs): reject unknown SSH LFS sub-verbs to prevent auth bypass (#38008) (#38015)
      * fix: bound CODEOWNERS regex match time (#38011) (#38025)
      * fix: bound debian ParseControlFile to a single control stanza (#38044) (#38055)
      * fix(deps): update module golang.org/x/net to v0.55.0 [security] (#37813) (#37829)
    
    * API
      * feat(api): add Link header in ListForks (#38052) (#38063)
    
    * BUGFIXES
      * fix: Fix the panic when ssh remote lfs endpoint parsing failure (#38026) (#38158)
      * fix(api): nil pointer panic when filtering tracked times by a non-existent user (#38112) (#38115)
      * fix: keep literal "false" value displayed in workflow_dispatch choice dropdowns (#38080) (#38096)
      * fix: parse HEAD ref (#38119)
      * fix: git cmd (#38084) (#38087)
      * fix(releases): generate notes for initial tag (#37697) (#37986)
      * fix(actions): return 404 when job log blob is missing (#38003) (#38004)
      * fix(actions): exclude `workflow_call` from workflow trigger detection (#37894) (#37899)
      * fix(actions): keep action run title clickable when commit subject is a URL (#37867) (#37898)
      * fix(actions): reject workflow_dispatch for workflows without that trigger (#37660) (#37895)
      * fix(actions): ack re-sent `UpdateLog` finalize idempotently (#37885) (#37892)
      * fix: http content file render (#37850) (#37856)
      * fix(issues): clear stale ReviewTypeRequest when submitting pending review (#37809) (#37815)
      * fix: Fix issue target branch selection for non-collaborators (#36916) (#38164)
    
    * BUILD
      * fix(deps): update `@playwright/test` to 1.60.0 (#38144)
      * ci: add `tools/ci-tools.ts` for the PR labeler workflow (#37831)
      * fix(build): swagger css import (#37801) (#37803)
    
  • v1.26.2

    * SECURITY
      * fix(permissions): Fix reading permission (#37769)
      * fix(actions): make artifact signature payloads unambiguous (#37707)
      * fix: Unify public-only token filtering in API queries and repo access checks (#37118)
      * fix: Add missed token scope checking (#37735)
      * fix(oauth): bind token exchanges to the original client request (#37704)
      * fix(oauth): strengthen PKCE validation and refresh token replay protection (#37706)
      * fix(web): enforce token scopes on raw, media, and attachment downloads (#37698)
      * fix(security): enforce wiki git writes and LFS token access at request time (#37695)
      * feat(api): encrypt AWS creds (#37679)
      * fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test
      * fix(packages): Add label for private and internal package and fix composor package source permission check (#37610)
      * fix(git): Fix smart http request scope bug (#37583)
      * Fix basic auth bug (#37503)
      * Fix allow maintainer edit permission check (#37479) (#37484)
      * Fix URL sanitization to handle schemeless credentials (#37440) (#37471)
      * Fix attachment Content-Security-Policy (#37455) (#37464)
      * chore(deps): bump go-git/go-git/v5 to 5.19.0 (#37608)
    
    * BUGFIXES
      * fix(pull): handle empty pull request files view to allow reviews (#37783)
      * fix(markup): make RenderString never fail (#37779)
      * fix: add natural sort to sortTreeViewNodes (#37772)
      * fix: package creation unique conflict (#37774)
      * fix!: add DEFAULT_TITLE_SOURCE setting for pull request title default behavior (#37465)
      * fix: Allow direct commits for unprotected files with push restrictions (#37657)
      * fix(actions): wrong assumption that run id always >= job id (#37737)
      * fix(auth): set User-Agent on avatar fetch and sync avatar on link-account register (#37564) (#37588)
      * fix(actions): deadlock between PrepareRunAndInsert and UpdateTaskByState (#37692)
      * fix(repo): /generate must sync the branch table for the new repo (#37693)
      * build: Fix snap build (1.26)
      * fix(actions): run TransferLogs on UpdateLog{Rows:[], NoMore:true} (#37631)
      * fix show correct mergebase
      * fix: make clone URL respect public URL detection setting (#37615)
      * fix: "run as root" check (#37622)
      * chore(deps): update dependency go to v1.26.3 (#37601)
      * Compare dropdown fails when selecting branch with no common merge-base (#37470)
      * fix: treat email addresses case-insensitively (#37600)
      * fix(actions): fix blank lines after ::endgroup:: (#37597)
      * fix(actions): report individual step status in workflow job API response (#37592)
      * fix: Invalid UTF-8 commit messages in JSON API responses (#37542)
      * fix: use consistent GetUser family functions (#37553)
      * fix(api): return 409 message instead of empty JSON for wrong commit id (#37572)
      * fix(actions): prevent panic when workflow contains null jobs (#37570)
      * Make ServeSetHeaders default to download attachment if filename exists (#37552) (#37555)
      * Fix(actions): validate workflow param to prevent 500 error (#37546) (#37554)
      * Don't unblock run-level-concurrency-blocked runs in the resolver (#37461) (#37538)
      * Fix(packages): use file names for generic web downloads (#37514) (#37520)
      * Fix merge autodetect can't close other PRs but only the last one when multiple PRs are pushed at once (#37512) (#37516)
      * Fix update branch protection order (#37508) (#37513)
      * Fix mCaptcha broken after Vite migration (#37492) (#37509)
      * Fix review submission from single-commit PR view (#37475) (#37485)
      * Fix scheduled action panic with null event payload (#37459) (#37466)
      * Make GetPossibleUserByID can handle deleted user (#37430) (#37431)
      * Remove excessive quote from terraform instructions (#37424) (#37426)
      * Fix color regressions, add `priority` color (#37417) (#37421)
    
    * MISC
      * Add CurrentURL template variable back (#37444) (#37449)
    
  • v1.26.1

    * BUGFIXES
      * Add event.schedule context for schedule actions task (#37320) (#37348)
      * Fix an issue where changing an organization's visibility caused problems when users had forked its repositories. (#37324) (#37344)
      * Use modern "git update-index --cacheinfo" syntax to support more file names (#37338) (#37343)
      * Fix URL related escaping for oauth2 (#37334) (#37340)
      * When the requested arch rpm is missing fall back to noarch (#37236) (#37339)
      * Fix actions concurrency groups cross-branch leak (#37311) (#37331)
      * Fix bug when accessing user badges (#37321) (#37329)
      * Fix AppFullLink (#37325) (#37328)
      * Fix container auth for public instance (#37290) (#37294)
      * Enhance GetActionWorkflow to support fallback references (#37189) (#37283)
      * Fix vite manifest update masking build errors (#37279) (#37310)
      * Fix Mermaid diagrams failing when node labels contain line breaks (#37296) (#37299)
      * Use TriggerEvent instead of Event in workflow runs API response for scheduled runs (#37288) #37360
      * Add URL to Learn more about blocking a user. (#37355) #37367
      * Fix button layout shift when collapsing file tree in editor (#37363) #37375
      * Fix org team assignee/reviewer lookups for team member permissions (#37365) #37391
      * Fix repo init README EOL (#37388) #37399
      * Fix: dump with default zip type produces uncompressed zip (#37401)#37402
    
  • v1.26.0

    * BREAKING
      * Correct swagger annotations for enums, status codes, and notification state (#37030)
      * Remove GET API registration-token (#36801)
      * Support Actions `concurrency` syntax (#32751)
      * Make PUBLIC_URL_DETECTION default to "auto" (#36955)
    * SECURITY
      * Bound PageSize in `ListUnadoptedRepositories` (#36884)
    * FEATURES
      * Support Actions `concurrency` syntax (#32751)
      * Add terraform state registry (#36710)
      * Instance-wide (global) info banner and maintenance mode (#36571)
      * Support rendering OpenAPI spec (#36449)
      * Add keyboard shortcuts for repository file and code search (#36416)
      * Add support for archive-upload rpc (#36391)
      * Add ability to download subpath archive (#36371)
      * Add workflow dependencies visualization (#26062) (#36248) & Restyle Workflow Graph (#36912)
      * Automatic generation of release notes (#35977)
      * Add "Go to file", "Delete Directory" to repo file list page (#35911)
      * Introduce "config edit-ini" sub command to help maintaining INI config file (#35735)
      * Add button to re-run failed jobs in Actions (#36924)
      * Support actions and reusable workflows from private repos (#32562)
      * Add summary to action runs view (#36883)
      * Add user badges (#36752)
      * Add configurable permissions for Actions automatic tokens (#36173)
      * Add per-runner "Disable/Pause"  (#36776)
      * Feature non-zipped actions artifacts (action v7 / nodejs / npm v6.2.0) (#36786)
    * PERFORMANCE
      * WorkflowDispatch API optionally return runid (#36706)
      * Add render cache for SVG icons (#36863)
      * Load `mentionValues` asynchronously (#36739)
      * Lazy-load some Vue components, fix heatmap chunk loading on every page (#36719)
      * Load heatmap data asynchronously (#36622)
      * Use prev/next pagination for user profile activities page to speed up (#36642)
      * Refactor cat-file batch operations and support `--batch-command` approach (#35775)
      * Use merge tree to detect conflicts when possible (#36400)
    * ENHANCEMENTS
      * Implement logout redirection for reverse proxy auth setups (#36085) (#37171)
      * Adds option to force update new branch in contents routes (#35592)
      * Add viewer controller for mermaid (zoom, drag) (#36557)
      * Add code editor setting dropdowns (#36534)
      * Add `elk` layout support to mermaid (#36486)
      * Add resolve/unresolve review comment API endpoints (#36441)
      * Allow configuring default PR base branch (fixes #36412) (#36425)
      * Add support for RPM Errata (updateinfo.xml) (#37125)
      * Require additional user confirmation for making repo private (#36959)
      * Add `actions.WORKFLOW_DIRS` setting (#36619)
      * Avoid opening new tab when downloading actions logs (#36740)
      * Implements OIDC RP-Initiated Logout (#36724)
      * Show workflow link (#37070)
      * Desaturate dark theme background colors (#37056)
      * Refactor "org teams" page and help new users to "add member" to an org (#37051)
      * Add webhook name field to improve webhook identification (#37025) (#37040)
      * Make task list checkboxes clickable in the preview tab (#37010)
      * Improve severity labels in Actions logs and tweak colors (#36993)
      * Linkify URLs in Actions workflow logs (#36986)
      * Allow text selection on checkbox labels (#36970)
      * Support dark/light theme images in markdown (#36922)
      * Enable native dark mode for swagger-ui (#36899)
      * Rework checkbox styling, remove `input` border hover effect (#36870)
      * Refactor storage content-type handling of ServeDirectURL (#36804)
      * Use "Enable Gravatar" but not "Disable" (#36771)
      * Use case-insensitive matching for Git error "Not a valid object name" (#36728)
      * Add "Copy Source" to markup comment menu (#36726)
      * Change image transparency grid to CSS (#36711)
      * Add "Run" prefix for unnamed action steps (#36624)
      * Persist actions log time display settings in `localStorage` (#36623)
      * Use first commit title for multi-commit PRs and fix auto-focus title field (#36606)
      * Improve BuildCaseInsensitiveLike with lowercase (#36598)
      * Improve diff highlighting (#36583)
      * Exclude cancelled runs from failure-only email notifications (#36569)
      * Use full-file highlighting for diff sections (#36561)
      * Color command/error logs in Actions log (#36538)
      * Add paging headers (#36521)
      * Improve timeline entries for WIP prefix changes in pull requests (#36518)
      * Add FOLDER_ICON_THEME configuration option (#36496)
      * Normalize guessed languages for code highlighting (#36450)
      * Add chunked transfer encoding support for LFS uploads (#36380)
      * Indicate when only optional checks failed (#36367)
      * Add 'allow_maintainer_edit' API option for creating a pull request (#36283)
      * Support closing keywords with URL references (#36221)
      * Improve diff file headers (#36215)
      * Fix and enhance comment editor monospace toggle (#36181)
      * Add git.DIFF_RENAME_SIMILARITY_THRESHOLD option (#36164)
      * Add matching pair insertion to markdown textarea (#36121)
      * Add sorting/filtering to admin user search API endpoint (#36112)
      * Allow action user have read permission in public repo like other user (#36095)
      * Disable matchBrackets in monaco (#36089)
      * Use GitHub-style commit message for squash merge (#35987)
      * Make composer registry support tar.gz and tar.bz2 and fix bugs (#35958)
      * Add GITEA_PR_INDEX env variable to githooks (#35938)
      * Add proper error message if session provider can not be created (#35520)
      * Add button to copy file name in PR files (#35509)
      * Move `X_FRAME_OPTIONS` setting from `cors` to `security` section (#30256)
      * Add placeholder content for empty content page (#37114)
      * Add `DEFAULT_DELETE_BRANCH_AFTER_MERGE` setting (#36917)
      * Redirect to the only OAuth2 provider when no other login methods and fix various problems (#36901)
      * Add admin badge to navbar avatar (#36790)
      * Add `never` option to `PUBLIC_URL_DETECTION` configuration (#36785)
      * Add background and run count to actions list page (#36707)
      * Add icon to buttons "Close with Comment", "Close Pull Request", "Close Issue" (#36654)
      * Add support for in_progress event in workflow_run webhook (#36979)
      * Report commit status for pull_request_review events (#36589)
      * Render merged pull request title as such in dashboard feed (#36479)
      * Feature to be able to filter project boards by milestones (#36321)
      * Use user id in noreply emails (#36550)
      * Enable pagination on GiteaDownloader.getIssueReactions() (#36549)
      * Remove striped tables in UI (#36509)
      * Improve control char rendering and escape button styling (#37094)
      * Support legacy run/job index-based URLs and refactor migration 326 (#37008)
      * Add date to "No Contributions" tooltip (#36190)
      * Show edit page confirmation dialog on tree view file change (#36130)
      * Mention proc-receive in text for dashboard.resync_all_hooks func (#35991)
      * Reuse selectable style for wiki (#35990)
      * Support blue yellow colorblind theme (#35910)
      * Support selecting theme on the footer (#35741)
      * Improve online runner check (#35722)
      * Add quick approve button on PR page (#35678)
      * Enable commenting on expanded lines in PR diffs (#35662)
      * Print PR-Title into tooltip for actions (#35579)
      * Use explicit, stronger defaults for newly generated repo signing keys for Debian (#36236)
      * Improve the compare page (#36261)
      * Unify repo names in system notices (#36491)
      * Move package settings to package instead of being tied to version (#37026)
      * Add Actions API rerun endpoints for runs and jobs (#36768)
      * Add branch_count to repository API (#35351) (#36743)
      * Add created_by filter to SearchIssues (#36670)
      * Allow admins to rename non-local users (#35970)
      * Support updating branch via API (#35951)
      * Add an option to automatically verify SSH keys from LDAP (#35927)
      * Make "update file" API can create a new file when SHA is not set (#35738)
      * Update issue.go with labels documentation (labels content, not ids) (#35522)
      * Expose content_version for optimistic locking on issue and PR edits (#37035)
      * Pass ServeHeaderOptions by value instead of pointer, fine tune httplib tests (#36982)
    * BUGFIXES
      * Frontend iframe renderer framework: 3D models, OpenAPI (#37233) (#37273)
      * Fix CODEOWNERS absolute path matching. (#37244) (#37264)
      * Swift registry metadata: preserve more JSON fields and accept empty metadata (#37254) (#37261)
      * Fix user ssh key exporting and tests (#37256) (#37258)
      * Fix team member avatar size and add tooltip (#37253)
      * Fix commit title rendering in action run and blame (#37243) (#37251)
      * Fix corrupted JSON caused by goccy library (#37214) (#37220)
      * Add test for "fetch redirect", add CSS value validation for external render (#37207) (#37216)
      * Fix incorrect concurrency check (#37205) (#37215)
      * Fix handle missing base branch in PR commits API (#37193) (#37203)
      * Fix encoding for Matrix Webhooks (#37190) (#37201)
      * Fix handle fork-only commits in compare API (#37185) (#37199)
      * Indicate form field readonly via background, fix RunUser config (#37175, #37180) (#37178)
      * Report structurally invalid workflows to users (#37116) (#37164)
      * Fix API not persisting pull request unit config when has_pull_requests is not set (#36718)
      * Rename CSS variables and improve colorblind themes (#36353)
      * Hide `add-matcher` and `remove-matcher` from actions job logs (#36520)
      * Prevent navigation keys from triggering actions during IME composition (#36540)
      * Fix vertical alignment of `.commit-sign-badge` children (#36570)
      * Fix duplicate startup warnings in admin panel (#36641)
      * Fix CODEOWNERS review request attribution using comment metadata (#36348)
      * Fix HTML tags appearing in wiki table of contents (#36284)
      * Fix various bugs (#37096)
      * Fix various legacy problems (#37092)
      * Fix RPM Registry 404 when package name contains 'package' (#37087)
      * Merge some standalone Vite entries into index.js (#37085)
      * Fix various problems (#37077)
      * Fix issue label deletion with Actions tokens (#37013)
      * Hide delete branch or tag buttons in mirror or archived repositories. (#37006)
      * Fix org contact email not clearable once set (#36975)
      * Fix a bug when forking a repository in an organization (#36950)
      * Preserve sort order of exclusive labels from template repo (#36931)
      * Make container registry support Apple Container (basic auth) (#36920)
      * Fix the wrong push commits in the pull request when force push (#36914)
      * Add class "list-header-filters" to the div for projects (#36889)
      * Fix dbfs error handling (#36844)
      * Fix incorrect viewed files counter if reverted change was viewed (#36819)
      * Refactor avatar package, support default avatar fallback (#36788)
      * Fix README symlink resolution in subdirectories like .github (#36775)
      * Fix CSS stacking context issue in actions log (#36749)
      * Add gpg signing for merge rebase and update by rebase (#36701)
      * Delete non-exist branch should return 404 (#36694)
      * Fix `TestActionsCollaborativeOwner` (#36657)
      * Fix multi-arch Docker build SIGILL by splitting frontend stage (#36646)
      * Fix linguist-detectable attribute being ignored for configuration files (#36640)
      * Fix state desync in ComboMarkdownEditor (#36625)
      * Unify DEFAULT_SHOW_FULL_NAME output in templates and dropdown (#36597)
      * Pull Request Pusher should be the author of the merge (#36581)
      * Fix various version parsing problems (#36553)
      * Fix highlight diff result (#36539)
      * Fix mirror sync parser and fix mirror messages (#36504)
      * Fix bug when list pull request commits (#36485)
      * Fix various bugs (#36446)
      * Fix issue filter menu layout (#36426)
      * Restrict branch naming when new change matches with protection rules (#36405)
      * Fix link/origin referrer and login redirect (#36279)
      * Generate IDs for HTML headings without id attribute (#36233)
      * Use a migration test instead of a wrong test which populated the meta test repositories and fix a migration bug (#36160)
      * Fix issue close timeline icon (#36138)
      * Fix diff blob excerpt expansion (#35922)
      * Fix external render (#35727)
      * Fix review request webhook bug (#35339) (#35723)
      * Fix shutdown waitgroup panic (#35676)
      * Cleanup ActionRun creation (#35624)
      * Fix possible bug when migrating issues/pull requests (#33487)
      * Various fixes (#36697)
      * Apply notify/register mail flags during install load (#37120)
      * Repair duration display for bad stopped timestamps (#37121)
      * Fix(upgrade.sh): use HTTPS for GPG key import and restore SELinux context after upgrade (#36930)
      * Fix various trivial problems (#36921)
      * Fix various trivial problems (#36953)
      * Fix NuGet package upload error handling (#37074)
      * Fix CodeQL code scanning alerts (#36858)
      * Refactor issue sidebar and fix various problems (#37045)
      * Fix various problems (#37029)
      * Fix relative-time RangeError (#37021)
      * Fix chroma lexer mapping (#36629)
      * Fix typos and grammar in English locale (#36751)
      * Fix milestone/project text overflow in issue sidebar (#36741)
      * Fix `no-content` message not rendering after comment edit (#36733)
      * Fix theme loading in development (#36605)
      * Fix workflow run jobs API returning null steps (#36603)
      * Fix timeline event layout overflow with long content (#36595)
      * Fix minor UI issues in runner edit page (#36590)
      * Fix incorrect vendored detections (#36508)
      * Fix editorconfig not respected in PR Conversation view (#36492)
      * Don't create self-references in merged PRs (#36490)
      * Fix potential incorrect runID in run status update (#36437)
      * Fix file-tree ui error when adding files to repo without commits (#36312)
      * Improve image captcha contrast for dark mode (#36265)
      * Fix panic in blame view when a file has only a single commit (#36230)
      * Fix spelling error in migrate-storage cmd utility (#36226)
      * Fix code highlighting on blame page (#36157)
      * Fix nilnil in onedev downloader (#36154)
      * Fix actions lint (#36029)
      * Fix oauth2 session gob register (#36017)
      * Fix Arch repo pacman.conf snippet (#35825)
      * Fix a number of `strictNullChecks`-related issues (#35795)
      * Fix URLJoin, markup render link reoslving, sign-in/up/linkaccount page common data (#36861)
      * Hide delete directory button for mirror or archive repository and disable the menu item if user have no permission (#36384)
      * Update message severity colors, fix navbar double border (#37019)
      * Inline and lazy-load EasyMDE CSS, fix border colors (#36714)
      * Closed milestones with no issues now show as 100% completed (#36220)
      * Add test for ExtendCommentTreePathLength migration and fix bugs (#35791)
      * Only turn links to current instance into hash links (#36237)
      * Fix typos in code comments: doesnt, dont, wont (#36890)
    * REFACTOR
      * Clean up and improve non-gitea js error filter (#37148) (#37155)
      * Always show owner/repo name in compare page dropdowns (#37172) (#37200)
      * Remove dead CSS rules (#37173) (#37177)
      * Replace Monaco with CodeMirror (#36764)
      * Replace CSRF cookie with `CrossOriginProtection` (#36183)
      * Replace index with id in actions routes (#36842)
      * Remove unnecessary function parameter (#35765)
      * Move jobparser from act repository to Gitea (#36699)
      * Refactor compare router param parse (#36105)
      * Optimize 'refreshAccesses' to perform update without removing then adding (#35702)
      * Clean up checkbox cursor styles (#37016)
      * Remove undocumented support of signing key in the repository git configuration file (#36143)
      * Switch `cmd/` to use constructor functions. (#36962)
      * Use `relative-time` to render absolute dates (#36238)
      * Some refactors about GetMergeBase (#36186)
      * Some small refactors (#36163)
      * Use gitRepo as parameter instead of repopath when invoking sign functions (#36162)
      * Move blame to gitrepo (#36161)
      * Move some functions to gitrepo package to reduce RepoPath reference directly (#36126)
      * Use gitrepo's clone and push when possible (#36093)
      * Remove mermaid margin workaround (#35732)
      * Move some functions to gitrepo package (#35543)
      * Move GetDiverging functions to gitrepo (#35524)
      * Use global lock instead of status pool for cron lock (#35507)
      * Use explicit mux instead of DefaultServeMux (#36276)
      * Use gitrepo's push function (#36245)
      * Pass request context to generateAdditionalHeadersForIssue (#36274)
      * Move assign project when creating pull request to the same database transaction (#36244)
      * Move catfile batch to a sub package of git module (#36232)
      * Use gitrepo.Repository instead of wikipath (#35398)
      * Use experimental go json v2 library (#35392)
      * Refactor template render (#36438)
      * Refactor GetRepoRawDiffForFile to avoid unnecessary pipe or goroutine (#36434)
      * Refactor text utility classes to Tailwind CSS (#36703)
      * Refactor git command stdio pipe (#36422)
      * Refactor git command context & pipeline (#36406)
      * Refactor git command stdio pipe (#36393)
      * Remove unused functions (#36672)
      * Refactor Actions Token Access (#35688)
      * Move commit related functions to gitrepo package (#35600)
      * Move archive function to repo_model and gitrepo (#35514)
      * Move some functions to gitrepo package (#35503)
      * Use git model to detect whether branch exist instead of gitrepo method (#35459)
      * Some refactor for repo path (#36251)
      * Extract helper functions from SearchIssues (#36158)
      * Refactor merge conan and container auth preserve actions taskID (#36560)
      * Refactor Nuget Auth to reuse Basic Auth Token Validation (#36558)
      * Refactor ActionsTaskID (#36503)
      * Refactor auth middleware (#36848)
      * Refactor code render and render control chars (#37078)
      * Clean up AppURL, remove legacy origin-url webcomponent (#37090)
      * Remove `util.URLJoin` and replace all callers with direct path concatenation (#36867)
      * Replace legacy tw-flex utility classes with flex-text-block/inline (#36778)
      * Mark unused&immature activitypub as "not implemented" (#36789)
    * TESTING
      * Add e2e tests for server push events (#36879)
      * Rework e2e tests (#36634)
      * Add e2e reaction test, improve accessibility, enable parallel testing (#37081)
      * Increase e2e test timeouts on CI to fix flaky tests (#37053)
    * BUILD
      * Upgrade go-git to v5.18.0 (#37269)
      * Replace rollup-plugin-license with rolldown-license-plugin (#37130) (#37158)
      * Bump min go version to 1.26.2 (#37139) (#37143)
      * Convert locale files from ini to json format (#35489)
      * Bump golangci-lint to 2.7.2, enable modernize stringsbuilder (#36180)
      * Port away from `flake-utils` (#35675)
      * Remove nolint (#36252)
      * Update the Unlicense copy to latest version (#36636)
      * Update to go 1.26.0 and golangci-lint 2.9.0 (#36588)
      * Replace `google/go-licenses` with custom generation (#36575)
      * Update go dependencies (#36548)
      * Bump appleboy/git-push-action from 1.0.0 to 1.2.0 (#36306)
      * Remove fomantic form module (#36222)
      * Bump setup-node to v6, re-enable cache (#36207)
      * Bump crowdin/github-action from 1 to 2 (#36204)
      * Revert "Bump alpine to 3.23 (#36185)" (#36202)
      * Update chroma to v2.21.1 (#36201)
      * Bump astral-sh/setup-uv from 6 to 7 (#36198)
      * Bump docker/build-push-action from 5 to 6 (#36197)
      * Bump aws-actions/configure-aws-credentials from 4 to 5 (#36196)
      * Bump dev-hanz-ops/install-gh-cli-action from 0.1.0 to 0.2.1 (#36195)
      * Add JSON linting (#36192)
      * Enable dependabot for actions (#36191)
      * Bump alpine to 3.23 (#36185)
      * Update chroma to v2.21.0 (#36171)
      * Update JS deps and eslint enhancements (#36147)
      * Update JS deps (#36091)
      * update golangci-lint to v2.7.0 (#36079)
      * Update JS deps, fix deprecations (#36040)
      * Update JS deps (#35978)
      * Add toolchain directive to go.mod (#35901)
      * Move `gitea-vet` to use `go tool` (#35878)
      * Update to go 1.25.4 (#35877)
      * Enable TypeScript `strictNullChecks` (#35843)
      * Enable `vue/require-typed-ref` eslint rule (#35764)
      * Update JS dependencies (#35759)
      * Move `codeformat` folder to tools (#35758)
      * Update dependencies (#35733)
      * Bump happy-dom from 20.0.0 to 20.0.2 (#35677)
      * Bump setup-go to v6 (#35660)
      * Update JS deps, misc tweaks (#35643)
      * Bump happy-dom from 19.0.2 to 20.0.0 (#35625)
      * Use bundled version of spectral (#35573)
      * Update JS and PY deps (#35565)
      * Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 (#35557)
      * Migrate from webpack to vite (#37002)
      * Update JS dependencies and misc tweaks (#37064)
      * Update to eslint 10 (#36925)
      * Optimize Docker build with dependency layer caching (#36864)
      * Update JS deps (#36850)
      * Update tool dependencies and fix new lint issues (#36702)
      * Remove redundant linter rules (#36658)
      * Move Fomantic dropdown CSS to custom module (#36530)
      * Remove and forbid `@ts-expect-error` (#36513)
      * Refactor git command stderr handling (#36402)
      * Enable gocheckcompilerdirectives linter (#36156)
      * Replace `lint-go-gopls` with additional `govet` linters (#36028)
      * Update golangci-lint to v2.6.0 (#35801)
      * Misc tool tweaks (#35734)
      * Add cache to container build (#35697)
      * Upgrade vite (#37126)
      * Update `setup-uv` to v8.0.0 (#37101)
      * Upgrade `go-git` to v5.17.2 and related dependencies (#37060)
      * Raise minimum Node.js version to 22.18.0 (#37058)
      * Upgrade `golang.org/x/image` to v0.38.0 (#37054)
      * Update minimum go version to 1.26.1, golangci-lint to 2.11.2, fix test style (#36876)
      * Enable eslint concurrency (#36878)
      * Vendor relative-time-element as local web component (#36853)
      * Update material-icon-theme v5.32.0 (#36832)
      * Update Go dependencies (#36781)
      * Upgrade minimatch (#36760)
      * Remove i18n backport tool at the moment because of translation format changed (#36643)
      * Update emoji data for Unicode 16 (#36596)
      * Update JS dependencies, adjust webpack config, misc fixes (#36431)
      * Update material-icon-theme to v5.31.0 (#36427)
      * Update JS and PY deps (#36383)
      * Bump alpine to 3.23, add platforms to `docker-dryrun` (#36379)
      * Update JS deps (#36354)
      * Update goldmark to v1.7.16 (#36343)
      * Update chroma to v2.22.0 (#36342)
    * DOCS
      * Update AI Contribution Policy (#37022)
      * Update AGENTS.md with additional guidelines (#37018)
      * Add missing cron tasks to example ini (#37012)
      * Add AI Contribution Policy to CONTRIBUTING.md (#36651)
      * Minor punctuation improvement in CONTRIBUTING.md (#36291)
      * Add documentation for markdown anchor post-processing (#36443)
    * MISC
      * Correct spelling (#36783)
      * Update Nix flake (#37110)
      * Update Nix flake (#37024)
      * Add valid github scopes (#36977)
      * Update Nix flake (#36943)
      * Update Nix flake (#36902)
      * Update Nix flake (#36857)
      * Update Nix flake (#36787)
    
    
  • v1.26.0-rc0

    * BREAKING
      * Correct swagger annotations for enums, status codes, and notification state (#37030)
      * Remove GET API registration-token (#36801)
      * Support Actions `concurrency` syntax (#32751)
      * Make PUBLIC_URL_DETECTION default to "auto" (#36955)
    * SECURITY
      * Bound PageSize in `ListUnadoptedRepositories` (#36884)
    * FEATURES
      * Support Actions `concurrency` syntax (#32751)
      * Add terraform state registry (#36710)
      * Instance-wide (global) info banner and maintenance mode (#36571)
      * Support rendering OpenAPI spec (#36449)
      * Add keyboard shortcuts for repository file and code search (#36416)
      * Add support for archive-upload rpc (#36391)
      * Add ability to download subpath archive (#36371)
      * Add workflow dependencies visualization (#26062) (#36248) & Restyle Workflow Graph (#36912)
      * Automatic generation of release notes (#35977)
      * Add "Go to file", "Delete Directory" to repo file list page (#35911)
      * Introduce "config edit-ini" sub command to help maintaining INI config file (#35735)
      * Add button to re-run failed jobs in Actions (#36924)
      * Support actions and reusable workflows from private repos (#32562)
      * Add summary to action runs view (#36883)
      * Add user badges (#36752)
      * Add configurable permissions for Actions automatic tokens (#36173)
      * Add per-runner “Disable/Pause”  (#36776)
    * PERFORMANCE
      * WorkflowDispatch API optionally return runid (#36706)
      * Add render cache for SVG icons (#36863)
      * Load `mentionValues` asynchronously (#36739)
      * Lazy-load some Vue components, fix heatmap chunk loading on every page (#36719)
      * Load heatmap data asynchronously (#36622)
      * Use prev/next pagination for user profile activities page to speed up (#36642)
      * Refactor cat-file batch operations and support `--batch-command` approach (#35775)
      * Use merge tree to detect conflicts when possible (#36400)
    * ENHANCEMENTS
      * Adds option to force update new branch in contents routes (#35592)
      * Add viewer controller for mermaid (zoom, drag) (#36557)
      * Add code editor setting dropdowns (#36534)
      * Add `elk` layout support to mermaid (#36486)
      * Add resolve/unresolve review comment API endpoints (#36441)
      * Allow configuring default PR base branch (fixes #36412) (#36425)
      * Add support for RPM Errata (updateinfo.xml) (#37125)
      * Require additional user confirmation for making repo private (#36959)
      * Feature non-zipped actions artifacts (action v7 / nodejs / npm v6.2.0) (#36786)
      * Add `actions.WORKFLOW_DIRS` setting (#36619)
      * Avoid opening new tab when downloading actions logs (#36740)
      * Implements OIDC RP-Initiated Logout (#36724)
      * Show workflow link (#37070)
      * Desaturate dark theme background colors (#37056)
      * Refactor "org teams" page and help new users to "add member" to an org (#37051)
      * Add webhook name field to improve webhook identification (#37025) (#37040)
      * Make task list checkboxes clickable in the preview tab (#37010)
      * Improve severity labels in Actions logs and tweak colors (#36993)
      * Linkify URLs in Actions workflow logs (#36986)
      * Allow text selection on checkbox labels (#36970)
      * Support dark/light theme images in markdown (#36922)
      * Enable native dark mode for swagger-ui (#36899)
      * Rework checkbox styling, remove `input` border hover effect (#36870)
      * Refactor storage content-type handling of ServeDirectURL (#36804)
      * Use "Enable Gravatar" but not "Disable" (#36771)
      * Use case-insensitive matching for Git error "Not a valid object name" (#36728)
      * Add “Copy Source” to markup comment menu (#36726)
      * Change image transparency grid to CSS (#36711)
      * Add "Run" prefix for unnamed action steps (#36624)
      * Persist actions log time display settings in `localStorage` (#36623)
      * Use first commit title for multi-commit PRs and fix auto-focus title field (#36606)
      * Improve BuildCaseInsensitiveLike with lowercase (#36598)
      * Improve diff highlighting (#36583)
      * Exclude cancelled runs from failure-only email notifications (#36569)
      * Use full-file highlighting for diff sections (#36561)
      * Color command/error logs in Actions log (#36538)
      * Add paging headers (#36521)
      * Improve timeline entries for WIP prefix changes in pull requests (#36518)
      * Add FOLDER_ICON_THEME configuration option (#36496)
      * Normalize guessed languages for code highlighting (#36450)
      * Add chunked transfer encoding support for LFS uploads (#36380)
      * Indicate when only optional checks failed (#36367)
      * Add 'allow_maintainer_edit' API option for creating a pull request (#36283)
      * Support closing keywords with URL references (#36221)
      * Improve diff file headers (#36215)
      * Fix and enhance comment editor monospace toggle (#36181)
      * Add git.DIFF_RENAME_SIMILARITY_THRESHOLD option (#36164)
      * Add matching pair insertion to markdown textarea (#36121)
      * Add sorting/filtering to admin user search API endpoint (#36112)
      * Allow action user have read permission in public repo like other user (#36095)
      * Disable matchBrackets in monaco (#36089)
      * Use GitHub-style commit message for squash merge (#35987)
      * Make composer registry support tar.gz and tar.bz2 and fix bugs (#35958)
      * Add GITEA_PR_INDEX env variable to githooks (#35938)
      * Add proper error message if session provider can not be created (#35520)
      * Add button to copy file name in PR files (#35509)
      * Move `X_FRAME_OPTIONS` setting from `cors` to `security` section (#30256)
      * Add placeholder content for empty content page (#37114)
      * Add `DEFAULT_DELETE_BRANCH_AFTER_MERGE` setting (#36917)
      * Redirect to the only OAuth2 provider when no other login methods and fix various problems (#36901)
      * Add admin badge to navbar avatar (#36790)
      * Add `never` option to `PUBLIC_URL_DETECTION` configuration (#36785)
      * Add background and run count to actions list page (#36707)
      * Add icon to buttons "Close with Comment", "Close Pull Request", "Close Issue" (#36654)
      * Add support for in_progress event in workflow_run webhook (#36979)
      * Report commit status for pull_request_review events (#36589)
      * Render merged pull request title as such in dashboard feed (#36479)
      * Feature to be able to filter project boards by milestones (#36321)
      * Use user id in noreply emails (#36550)
      * Enable pagination on GiteaDownloader.getIssueReactions() (#36549)
      * Remove striped tables in UI (#36509)
      * Improve control char rendering and escape button styling (#37094)
      * Support legacy run/job index-based URLs and refactor migration 326 (#37008)
      * Add date to "No Contributions" tooltip (#36190)
      * Show edit page confirmation dialog on tree view file change (#36130)
      * Mention proc-receive in text for dashboard.resync_all_hooks func (#35991)
      * Reuse selectable style for wiki (#35990)
      * Support blue yellow colorblind theme (#35910)
      * Support selecting theme on the footer (#35741)
      * Improve online runner check (#35722)
      * Add quick approve button on PR page (#35678)
      * Enable commenting on expanded lines in PR diffs (#35662)
      * Print PR-Title into tooltip for actions (#35579)
      * Use explicit, stronger defaults for newly generated repo signing keys for Debian (#36236)
      * Improve the compare page (#36261)
      * Unify repo names in system notices (#36491)
      * Move package settings to package instead of being tied to version (#37026)
      * Add Actions API rerun endpoints for runs and jobs (#36768)
      * Add branch_count to repository API (#35351) (#36743)
      * Add created_by filter to SearchIssues (#36670)
      * Allow admins to rename non-local users (#35970)
      * Support updating branch via API (#35951)
      * Add an option to automatically verify SSH keys from LDAP (#35927)
      * Make "update file" API can create a new file when SHA is not set (#35738)
      * Update issue.go with labels documentation (labels content, not ids) (#35522)
      * Expose content_version for optimistic locking on issue and PR edits (#37035)
      * Pass ServeHeaderOptions by value instead of pointer, fine tune httplib tests (#36982)
    * BUGFIXES
      * Fix API not persisting pull request unit config when has_pull_requests is not set (#36718)
      * Rename CSS variables and improve colorblind themes (#36353)
      * Hide `add-matcher` and `remove-matcher` from actions job logs (#36520)
      * Prevent navigation keys from triggering actions during IME composition (#36540)
      * Fix vertical alignment of `.commit-sign-badge` children (#36570)
      * Fix duplicate startup warnings in admin panel (#36641)
      * Fix CODEOWNERS review request attribution using comment metadata (#36348)
      * Fix HTML tags appearing in wiki table of contents (#36284)
      * Fix various bugs (#37096)
      * Fix various legacy problems (#37092)
      * Fix RPM Registry 404 when package name contains 'package' (#37087)
      * Merge some standalone Vite entries into index.js (#37085)
      * Fix various problems (#37077)
      * Fix issue label deletion with Actions tokens (#37013)
      * Hide delete branch or tag buttons in mirror or archived repositories. (#37006)
      * Fix org contact email not clearable once set (#36975)
      * Fix a bug when forking a repository in an organization (#36950)
      * Preserve sort order of exclusive labels from template repo (#36931)
      * Make container registry support Apple Container (basic auth) (#36920)
      * Fix the wrong push commits in the pull request when force push (#36914)
      * Add class "list-header-filters" to the div for projects (#36889)
      * Fix dbfs error handling (#36844)
      * Fix incorrect viewed files counter if reverted change was viewed (#36819)
      * Refactor avatar package, support default avatar fallback (#36788)
      * Fix README symlink resolution in subdirectories like .github (#36775)
      * Fix CSS stacking context issue in actions log (#36749)
      * Add gpg signing for merge rebase and update by rebase (#36701)
      * Delete non-exist branch should return 404 (#36694)
      * Fix `TestActionsCollaborativeOwner` (#36657)
      * Fix multi-arch Docker build SIGILL by splitting frontend stage (#36646)
      * Fix linguist-detectable attribute being ignored for configuration files (#36640)
      * Fix state desync in ComboMarkdownEditor (#36625)
      * Unify DEFAULT_SHOW_FULL_NAME output in templates and dropdown (#36597)
      * Pull Request Pusher should be the author of the merge (#36581)
      * Fix various version parsing problems (#36553)
      * Fix highlight diff result (#36539)
      * Fix mirror sync parser and fix mirror messages (#36504)
      * Fix bug when list pull request commits (#36485)
      * Fix various bugs (#36446)
      * Fix issue filter menu layout (#36426)
      * Restrict branch naming when new change matches with protection rules (#36405)
      * Fix link/origin referrer and login redirect (#36279)
      * Generate IDs for HTML headings without id attribute (#36233)
      * Use a migration test instead of a wrong test which populated the meta test repositories and fix a migration bug (#36160)
      * Fix issue close timeline icon (#36138)
      * Fix diff blob excerpt expansion (#35922)
      * Fix external render (#35727)
      * Fix review request webhook bug (#35339) (#35723)
      * Fix shutdown waitgroup panic (#35676)
      * Cleanup ActionRun creation (#35624)
      * Fix possible bug when migrating issues/pull requests (#33487)
      * Various fixes (#36697)
      * Apply notify/register mail flags during install load (#37120)
      * Repair duration display for bad stopped timestamps (#37121)
      * Fix(upgrade.sh): use HTTPS for GPG key import and restore SELinux context after upgrade (#36930)
      * Fix various trivial problems (#36921)
      * Fix various trivial problems (#36953)
      * Fix NuGet package upload error handling (#37074)
      * Fix CodeQL code scanning alerts (#36858)
      * Refactor issue sidebar and fix various problems (#37045)
      * Fix various problems (#37029)
      * Fix relative-time RangeError (#37021)
      * Fix chroma lexer mapping (#36629)
      * Fix typos and grammar in English locale (#36751)
      * Fix milestone/project text overflow in issue sidebar (#36741)
      * Fix `no-content` message not rendering after comment edit (#36733)
      * Fix theme loading in development (#36605)
      * Fix workflow run jobs API returning null steps (#36603)
      * Fix timeline event layout overflow with long content (#36595)
      * Fix minor UI issues in runner edit page (#36590)
      * Fix incorrect vendored detections (#36508)
      * Fix editorconfig not respected in PR Conversation view (#36492)
      * Don't create self-references in merged PRs (#36490)
      * Fix potential incorrect runID in run status update (#36437)
      * Fix file-tree ui error when adding files to repo without commits (#36312)
      * Improve image captcha contrast for dark mode (#36265)
      * Fix panic in blame view when a file has only a single commit (#36230)
      * Fix spelling error in migrate-storage cmd utility (#36226)
      * Fix code highlighting on blame page (#36157)
      * Fix nilnil in onedev downloader (#36154)
      * Fix actions lint (#36029)
      * Fix oauth2 session gob register (#36017)
      * Fix Arch repo pacman.conf snippet (#35825)
      * Fix a number of `strictNullChecks`-related issues (#35795)
      * Fix URLJoin, markup render link reoslving, sign-in/up/linkaccount page common data (#36861)
      * Hide delete directory button for mirror or archive repository and disable the menu item if user have no permission (#36384)
      * Update message severity colors, fix navbar double border (#37019)
      * Inline and lazy-load EasyMDE CSS, fix border colors (#36714)
      * Closed milestones with no issues now show as 100% completed (#36220)
      * Add test for ExtendCommentTreePathLength migration and fix bugs (#35791)
      * Only turn links to current instance into hash links (#36237)
      * Fix typos in code comments: doesnt, dont, wont (#36890)
    * REFACTOR
      * Replace Monaco with CodeMirror (#36764)
      * Replace CSRF cookie with `CrossOriginProtection` (#36183)
      * Replace index with id in actions routes (#36842)
      * Remove unnecessary function parameter (#35765)
      * Move jobparser from act repository to Gitea (#36699)
      * Refactor compare router param parse (#36105)
      * Optimize 'refreshAccesses' to perform update without removing then adding (#35702)
      * Clean up checkbox cursor styles (#37016)
      * Remove undocumented support of signing key in the repository git configuration file (#36143)
      * Switch `cmd/` to use constructor functions. (#36962)
      * Use `relative-time` to render absolute dates (#36238)
      * Some refactors about GetMergeBase (#36186)
      * Some small refactors (#36163)
      * Use gitRepo as parameter instead of repopath when invoking sign functions (#36162)
      * Move blame to gitrepo (#36161)
      * Move some functions to gitrepo package to reduce RepoPath reference directly (#36126)
      * Use gitrepo's clone and push when possible (#36093)
      * Remove mermaid margin workaround (#35732)
      * Move some functions to gitrepo package (#35543)
      * Move GetDiverging functions to gitrepo (#35524)
      * Use global lock instead of status pool for cron lock (#35507)
      * Use explicit mux instead of DefaultServeMux (#36276)
      * Use gitrepo's push function (#36245)
      * Pass request context to generateAdditionalHeadersForIssue (#36274)
      * Move assign project when creating pull request to the same database transaction (#36244)
      * Move catfile batch to a sub package of git module (#36232)
      * Use gitrepo.Repository instead of wikipath (#35398)
      * Use experimental go json v2 library (#35392)
      * Refactor template render (#36438)
      * Refactor GetRepoRawDiffForFile to avoid unnecessary pipe or goroutine (#36434)
      * Refactor text utility classes to Tailwind CSS (#36703)
      * Refactor git command stdio pipe (#36422)
      * Refactor git command context & pipeline (#36406)
      * Refactor git command stdio pipe (#36393)
      * Remove unused functions (#36672)
      * Refactor Actions Token Access (#35688)
      * Move commit related functions to gitrepo package (#35600)
      * Move archive function to repo_model and gitrepo (#35514)
      * Move some functions to gitrepo package (#35503)
      * Use git model to detect whether branch exist instead of gitrepo method (#35459)
      * Some refactor for repo path (#36251)
      * Extract helper functions from SearchIssues (#36158)
      * Refactor merge conan and container auth preserve actions taskID (#36560)
      * Refactor Nuget Auth to reuse Basic Auth Token Validation (#36558)
      * Refactor ActionsTaskID (#36503)
      * Refactor auth middleware (#36848)
      * Refactor code render and render control chars (#37078)
      * Clean up AppURL, remove legacy origin-url webcomponent (#37090)
      * Remove `util.URLJoin` and replace all callers with direct path concatenation (#36867)
      * Replace legacy tw-flex utility classes with flex-text-block/inline (#36778)
      * Mark unused&immature activitypub as "not implemented" (#36789)
    * TESTING
      * Add e2e tests for server push events (#36879)
      * Rework e2e tests (#36634)
      * Add e2e reaction test, improve accessibility, enable parallel testing (#37081)
      * Increase e2e test timeouts on CI to fix flaky tests (#37053)
    * BUILD
      * Convert locale files from ini to json format (#35489)
      * Bump golangci-lint to 2.7.2, enable modernize stringsbuilder (#36180)
      * Port away from `flake-utils` (#35675)
      * Remove nolint (#36252)
      * Update the Unlicense copy to latest version (#36636)
      * Update to go 1.26.0 and golangci-lint 2.9.0 (#36588)
      * Replace `google/go-licenses` with custom generation (#36575)
      * Update go dependencies (#36548)
      * Bump appleboy/git-push-action from 1.0.0 to 1.2.0 (#36306)
      * Remove fomantic form module (#36222)
      * Bump setup-node to v6, re-enable cache (#36207)
      * Bump crowdin/github-action from 1 to 2 (#36204)
      * Revert "Bump alpine to 3.23 (#36185)" (#36202)
      * Update chroma to v2.21.1 (#36201)
      * Bump astral-sh/setup-uv from 6 to 7 (#36198)
      * Bump docker/build-push-action from 5 to 6 (#36197)
      * Bump aws-actions/configure-aws-credentials from 4 to 5 (#36196)
      * Bump dev-hanz-ops/install-gh-cli-action from 0.1.0 to 0.2.1 (#36195)
      * Add JSON linting (#36192)
      * Enable dependabot for actions (#36191)
      * Bump alpine to 3.23 (#36185)
      * Update chroma to v2.21.0 (#36171)
      * Update JS deps and eslint enhancements (#36147)
      * Update JS deps (#36091)
      * update golangci-lint to v2.7.0 (#36079)
      * Update JS deps, fix deprecations (#36040)
      * Update JS deps (#35978)
      * Add toolchain directive to go.mod (#35901)
      * Move `gitea-vet` to use `go tool` (#35878)
      * Update to go 1.25.4 (#35877)
      * Enable TypeScript `strictNullChecks` (#35843)
      * Enable `vue/require-typed-ref` eslint rule (#35764)
      * Update JS dependencies (#35759)
      * Move `codeformat` folder to tools (#35758)
      * Update dependencies (#35733)
      * Bump happy-dom from 20.0.0 to 20.0.2 (#35677)
      * Bump setup-go to v6 (#35660)
      * Update JS deps, misc tweaks (#35643)
      * Bump happy-dom from 19.0.2 to 20.0.0 (#35625)
      * Use bundled version of spectral (#35573)
      * Update JS and PY deps (#35565)
      * Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 (#35557)
      * Migrate from webpack to vite (#37002)
      * Update JS dependencies and misc tweaks (#37064)
      * Update to eslint 10 (#36925)
      * Optimize Docker build with dependency layer caching (#36864)
      * Update JS deps (#36850)
      * Update tool dependencies and fix new lint issues (#36702)
      * Remove redundant linter rules (#36658)
      * Move Fomantic dropdown CSS to custom module (#36530)
      * Remove and forbid `@ts-expect-error` (#36513)
      * Refactor git command stderr handling (#36402)
      * Enable gocheckcompilerdirectives linter (#36156)
      * Replace `lint-go-gopls` with additional `govet` linters (#36028)
      * Update golangci-lint to v2.6.0 (#35801)
      * Misc tool tweaks (#35734)
      * Add cache to container build (#35697)
      * Upgrade vite (#37126)
      * Update `setup-uv` to v8.0.0 (#37101)
      * Upgrade `go-git` to v5.17.2 and related dependencies (#37060)
      * Raise minimum Node.js version to 22.18.0 (#37058)
      * Upgrade `golang.org/x/image` to v0.38.0 (#37054)
      * Update minimum go version to 1.26.1, golangci-lint to 2.11.2, fix test style (#36876)
      * Enable eslint concurrency (#36878)
      * Vendor relative-time-element as local web component (#36853)
      * Update material-icon-theme v5.32.0 (#36832)
      * Update Go dependencies (#36781)
      * Upgrade minimatch (#36760)
      * Remove i18n backport tool at the moment because of translation format changed (#36643)
      * Update emoji data for Unicode 16 (#36596)
      * Update JS dependencies, adjust webpack config, misc fixes (#36431)
      * Update material-icon-theme to v5.31.0 (#36427)
      * Update JS and PY deps (#36383)
      * Bump alpine to 3.23, add platforms to `docker-dryrun` (#36379)
      * Update JS deps (#36354)
      * Update goldmark to v1.7.16 (#36343)
      * Update chroma to v2.22.0 (#36342)
    * DOCS
      * Update AI Contribution Policy (#37022)
      * Update AGENTS.md with additional guidelines (#37018)
      * Add missing cron tasks to example ini (#37012)
      * Add AI Contribution Policy to CONTRIBUTING.md (#36651)
      * Minor punctuation improvement in CONTRIBUTING.md (#36291)
      * Add documentation for markdown anchor post-processing (#36443)
    * MISC
      * Correct spelling (#36783)
      * Update Nix flake (#37110)
      * Update Nix flake (#37024)
      * Add valid github scopes (#36977)
      * Update Nix flake (#36943)
      * Update Nix flake (#36902)
      * Update Nix flake (#36857)
      * Update Nix flake (#36787)
    
    
  • v1.25.5

    * SECURITY
      * Toolchain Update to Go 1.25.6 (#36480) (#36487)
      * Adjust the toolchain version (#36537) (#36542)
      * Update toolchain to 1.25.8 for v1.25 (#36888)
      * Prevent redirect bypasses via backslash-encoded paths (#36660) (#36716)
      * Fix get release draft permission check (#36659) (#36715)
      * Fix a bug user could change another user's primary email (#36586) (#36607)
      * Fix OAuth2 authorization code expiry and reuse handling (#36797) (#36851)
      * Add validation constraints for repository creation fields (#36671) (#36757)
      * Fix bug to check whether user can update pull request branch or rebase branch (#36465) (#36838)
      * Add migration http transport for push/sync mirror lfs (#36665) (#36691)
      * Fix track time list permission check (#36662) (#36744)
      * Fix track time issue id (#36664) (#36689)
      * Fix path resolving (#36734) (#36746)
      * Fix dump release asset bug (#36799) (#36839)
      * Fix org permission API visibility checks for hidden members and private orgs (#36798) (#36841)
      * Fix forwarded proto handling for public URL detection (#36810) (#36836)
      * Add a git grep search timeout (#36809) (#36835)
      * Fix oauth2 s256 (#36462) (#36477)
    * ENHANCEMENTS
      * Make `security-check` informational only (#36681) (#36852)
      * Upgrade to github.com/cloudflare/circl 1.6.3, svgo 4.0.1, markdownlint-cli 0.48.0 (#36840)
      * Add some validation on values provided to USER_DISABLED_FEATURES and EXTERNAL_USER_DISABLED_FEATURES (#36688) (#36692)
      * Upgrade gogit to 5.16.5 (#36687)
      * Add wrap to runner label list (#36565) (#36574)
      * Add dnf5 command for Fedora in RPM package instructions (#36527) (#36572)
      * Allow scroll propagation outside code editor (#36502) (#36510)
    * BUGFIXES
      * Fix non-admins unable to automerge PRs from forks (#36833) (#36843)
      * Fix bug when pushing mirror with wiki (#36795) (#36807)
      * Fix artifacts v4 backend upload problems (#36805) (#36834)
      * Fix CRAN package version validation to allow more than 4 version components (#36813) (#36821)
      * Fix force push time-line commit comments of pull request (#36653) (#36717)
      * Fix SVG height calculation in diff viewer (#36748) (#36750)
      * Fix push time bug (#36693) (#36713)
      * Fix bug the protected branch rule name is conflicted with renamed branch name (#36650) (#36661)
      * Fix bug when do LFS GC (#36500) (#36608)
      * Fix focus lost bugs in the Monaco editor (#36609)
      * Reprocess htmx content after loading more files (#36568) (#36577)
      * Fix assignee sidebar links and empty placeholder (#36559) (#36563)
      * Fix issues filter dropdown showing empty label scope section (#36535) (#36544)
      * Fix various mermaid bugs (#36547) (#36552)
      * Fix data race when uploading container blobs concurrently (#36524) (#36526)
      * Correct spacing between username and bot label (#36473) (#36484)
    
  • v1.25.4

    * SECURITY
      * Release attachments must belong to the intended repo (#36347) (#36375)
      * Fix permission check on org project operations (#36318) (#36373)
      * Clean watches when make a repository private and check permission when send release emails (#36319) (#36370)
      * Add more check for stopwatch read or list (#36340) (#36368)
      * Fix openid setting check (#36346) (#36361)
      * Fix cancel auto merge bug (#36341) (#36356)
      * Fix delete attachment check (#36320) (#36355)
      * LFS locks must belong to the intended repo (#36344) (#36349)
      * Fix bug on notification read (#36339) #36387
    * ENHANCEMENTS
      * Add more routes to the "expensive" list (#36290)
      * Make "commit statuses" API accept slashes in "ref" (#36264) (#36275)
    * BUGFIXES
      * Fix markdown newline handling during IME composition (#36421) #36424
      * Fix missing repository id when migrating release attachments (#36389)
      * Fix bug when compare in the pull request (#36363) (#36372)
      * Fix incorrect text content detection (#36364) (#36369)
      * Fill missing `has_code` in repository api (#36338) (#36359)
      * Fix notifications pagination query parameters (#36351) (#36358)
      * Fix some trivial problems (#36336) (#36337)
      * Prevent panic when GitLab release has more links than sources (#36295) (#36305)
      * Fix stats bug when syncing release (#36285) (#36294)
      * Always honor user's choice for "delete branch after merge" (#36281) (#36286)
      * Use the requested host for LFS links (#36242) (#36258)
      * Fix panic when get editor config file (#36241) (#36247)
      * Fix regression in writing authorized principals (#36213) (#36218)
      * Fix WebAuthn error checking (#36219) (#36235)
    
  • v1.25.3

    * SECURITY
      * Bump toolchain to go1.25.5, misc fixes (#36082)
    * ENHANCEMENTS
      * Add strikethrough button to markdown editor (#36087) (#36104)
      * Add "site admin" back to profile menu (#36010) (#36013)
      * Improve math rendering (#36124) (#36125)
    * BUGFIXES
      * Check user visibility when redirecting to a renamed user (#36148) (#36159)
      * Fix various bugs (#36139) (#36151)
      * Fix bug when viewing the commit diff page with non-ANSI files (#36149) (#36150)
      * Hide RSS icon when viewing a file not under a branch (#36135) (#36141)
      * Fix SVG size calulation, only use `style` attribute (#36133) (#36134)
      * Make Golang correctly delete temp files during uploading (#36128) (#36129)
      * Fix the bug when ssh clone with redirect user or repository (#36039) (#36090)
      * Use Golang net/smtp instead of gomail's smtp to send email (#36055) (#36083)
      * Fix edit user email bug in API (#36068) (#36081)
      * Fix bug when updating user email (#36058) (#36066)
      * Fix incorrect viewed files counter if file has changed (#36009) (#36047)
      * Fix container registry error handling (#36021) (#36037)
      * Fix webAuthn insecure error view (#36165) (#36179)
      * Fix some file icon ui (#36078) (#36088)
      * Fix Actions `pull_request.paths` being triggered incorrectly by rebase (#36045) (#36054)
      * Fix error handling in mailer and wiki services (#36041) (#36053)
      * Fix bugs when comparing and creating pull request (#36166) (#36144)
    
  • v1.25.2

    * SECURITY
      * Upgrade golang.org/x/crypto to 0.45.0 (#35985) (#35988)
      * Fix various permission & login related bugs (#36002) (#36004)
    * ENHANCEMENTS
      * Display source code downloads last for release attachments (#35897) (#35903)
      * Change project default column icon to 'star' (#35967) (#35979)
    * BUGFIXES
      * Allow empty commit when merging pull request with squash style (#35989) (#36003)
      * Fix container push tag overwriting (#35936) (#35954)
      * Fix corrupted external render content (#35946) and upgrade golang.org/x packages (#35950)
      * Limit reading bytes instead of ReadAll (#35928) (#35934)
      * Use correct form field for allowed force push users in branch protection API (#35894) (#35908)
      * Fix team member access check (#35899) (#35905)
      * Fix conda null depend issue (#35900) (#35902)
      * Set the dates to now when not specified by the caller (#35861) (#35874)
      * Fix gogit ListEntriesRecursiveWithSize (#35862)
      * Misc CSS fixes (#35888) (#35981)
      * Don't show unnecessary error message to end users for DeleteBranchAfterMerge (#35937) (#35941)
      * Load jQuery as early as possible to support custom scripts (#35926) (#35929)
      * Allow to display embed images/pdfs when SERVE_DIRECT was enabled on MinIO storage (#35882) (#35917)
      * Make OAuth2 issuer configurable (#35915) (#35916)
      * Fix #35763: Add proper page title for project pages (#35773) (#35909)
      * Fix avatar upload error handling (#35887) (#35890)
      * Contribution heatmap improvements (#35876) (#35880)
      * Remove padding override on `.ui .sha.label` (#35864) (#35873)
      * Fix pull description code label background (#35865) (#35870)
    
  • v1.25.1

    * BUGFIXES
      * Make ACME email optional (#35849) #35857
      * Add a doctor command to fix inconsistent run status (#35840) (#35845)
      * Remove wrong code (#35846)
      * Fix viewed files number is not right if not all files loaded (#35821) (#35844)
      * Fix incorrect pull request counter (#35819) (#35841)
      * Upgrade go mail to 0.7.2 and fix the bug (#35833) (#35837)
      * Revert gomail to v0.7.0 to fix sending mail failed (#35816) (#35824)
      * Fix clone mixed bug (#35810) (#35822)
      * Fix cli "Before" handling (#35797) (#35808)
      * Improve and fix markup code preview rendering (#35777) (#35787)
      * Fix actions rerun bug (#35783) (#35784)
      * Fix actions schedule update issue (#35767) (#35774)
      * Fix circular spin animation direction (#35785) (#35823)
      * Fix file extension on gogs.png (#35793) (#35799)
      * Add pnpm to Snapcraft (#35778)