Upgrade Path

Forgejo 11.0.0 → 12.0.0

4 versions, 1 with breaking changes, 1 with upstream notes or warnings only, 0 required stops

Version by version, oldest first

11.0.1 – 11.0.2: no action items (2 versions)

11.0.3 2025-07-10

Note

Git update fixing CVE-2025-48385

Git vulnerabilities were disclosed 8 July 2025 and require an update of the Git version used by Forgejo to Git v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, or v2.50.1. The containers of this release include a Git binary that is not vulnerable. If Forgejo was installed using a container, it is enough to upgrade the container to get the latest Git binary.

Security bug fixes are only for Git, there are no security fixes for Forgejo itself in this release.

Wiki permissions manual steps

If collaborators with write access can't edit the wiki, an administrator can now go to the Units settings (<user>/<repo>/settings/units#wiki) and Save the wiki settings (no change is needed) to fix the problem. This is a manual step that will trigger a database update that is currently not possible to automate for Forgejo stable releases.

Full release notes for 11.0.3

11.0.4 – 11.0.16: released after 12.0.0; not on this route

12.0.0 2025-07-17

Breaking

  • Breaking security features
  • PR: remove API authentication methods that uses the URL query. They are disabled by default and this only has an impact if [security].DISABLE_QUERY_AUTH_TOKEN=false is explicitly set. Read more in the v12.0 companion blog post.

Breaking

  • Breaking features
  • PR: The forgejo docs command is deprecated and CLI errors are now displayed on stderr instead of stdout. These breaking changes happened because the package used to parse the command line arguments was upgraded from v2 to v3. A separate project was initiated to re-implement the docs command, but it is not yet production ready.
  • PR: remove the legacy TEST_CONFLICTING_PATCHES_WITH_GIT_APPLY setting

Breaking

  • Breaking bug fixes
  • PR: fail if sha is not provided to the POST /repos/{owner}/{repo}/contents API endpoint. Although it was documented to be required, it was not enforced and clients that do not set the sha will no longer succeed.

Full release notes for 12.0.0

Release notes from codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Forgejo's release notes list breaking changes under “Breaking …” bullets; those are quoted as “Breaking”. Text the maintainers write above the generated list, and the 7.0.0 “Migration warning” and “Regressions and workarounds” lists, and the hand-written 7.0.3, 7.0.5 and 7.0.6 items (container image, regreSSHion, removed features), and the 10.0.2 “Bug fixes” item on removed TOTP secrets, are quoted as “Note”. Covered from 7.0.0; the 1.18–1.21 releases (tags like v1.21.11-1) are not. The companion blog posts on forgejo.org are not quoted; the full release notes link to them.