Open Source Hacker News (GPT)

Gitea 28.0

Giteareleasebreaking changesegress rules

Gitea has announced v28.0.0, a release that drops the historical 1. prefix from its version numbers so this is 28.0.0 rather than 1.28.0. Highlights include audit logging, bot accounts, HTTPS deploy tokens, user impersonation for administrators, code-owner approval rules, diff file filters, and an Actions queue view. The release contains security fixes, but details are being withheld for about a week to give everyone time to upgrade, and the project thanks contributors and Open Collective supporters.

Before upgrading, the post says to read the breaking changes, back up data, then replace the binary or Docker container and restart, with downloads and installation guide linked from the announcement. Release binaries no longer include 32-bit x86 or gogit builds, and the Snap is no longer built for armhf. Download file names also no longer carry an OS version suffix—for example, gitea-28.0.0-windows-amd64.exe—so any download scripts need updating.

A major breaking change is that migrations, mirrors, and other Git network operations now go through an internal proxy that applies egress settings to direct connections (#39426). Admins should review allow and block lists before upgrading. The external preset has been removed, and for a deny-by-default policy users should set EGRESS_MODE = strict and list allowed hosts. [migrations] EGRESS_MODE covers migrations and mirrors, while [security] EGRESS_MODE covers webhooks and OAuth2.

In strict mode, entries without a port only allow ports 80 and 443. In the default lax mode, [security] ALLOWED_HOST_LIST no longer restricts public hosts; setting [security] EGRESS_MODE = strict keeps it as an exclusive allowlist. Gitea logs a startup warning when the list is set without an explicit EGRESS_MODE, IP address entries no longer accept wildcards, and * is no longer a valid entry.

Domain entries now follow curl syntax: example.com matches the domain and all subdomains, *.example.com matches only subdomains, and example.* is invalid. Invalid [migrations] BLOCKED_HOST_LIST entries now stop Gitea from starting. [migrations] ALLOWED_DOMAINS, BLOCKED_DOMAINS, and ALLOW_LOCALNETWORKS are deprecated in favor of [migrations] ALLOWED_HOST_LIST and BLOCKED_HOST_LIST. The change was contributed by @TheFox0x7.

Completed Actions runs are now deleted after 400 days by default, together with their jobs, logs, and artifacts. A new cleanup_action_runs cron task performs the deletion, by default at midnight. To keep all runs, the post says admins should set the relevant configuration option before upgrading, though the excerpt ends before naming that setting.

Read original →

← Back to home