Forgejo 11.0.0 → 12.0.0
4 versions, 1 with breaking changes, 1 with upstream notes or warnings only, 0 required stops
Version by version, oldest first
11.0.1 – 11.0.2: no action items (2 versions)
11.0.3 2025-07-10
Note
Git update fixing CVE-2025-48385
Git vulnerabilities were disclosed 8 July 2025 and require an update of the Git version used by Forgejo to Git v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, or v2.50.1. The containers of this release include a Git binary that is not vulnerable. If Forgejo was installed using a container, it is enough to upgrade the container to get the latest Git binary.
Security bug fixes are only for Git, there are no security fixes for Forgejo itself in this release.
Wiki permissions manual steps
If collaborators with write access can't edit the wiki, an administrator can now go to the Units settings (<user>/<repo>/settings/units#wiki) and Save the wiki settings (no change is needed) to fix the problem. This is a manual step that will trigger a database update that is currently not possible to automate for Forgejo stable releases.
11.0.4 – 11.0.16: released after 12.0.0; not on this route
12.0.0 2025-07-17
Breaking
- Breaking security features
- PR: remove API authentication methods that uses the URL query. They are disabled by default and this only has an impact if
[security].DISABLE_QUERY_AUTH_TOKEN=falseis explicitly set. Read more in the v12.0 companion blog post.
Breaking
- Breaking features
- PR: The
forgejo docscommand is deprecated and CLI errors are now displayed on stderr instead of stdout. These breaking changes happened because the package used to parse the command line arguments was upgraded from v2 to v3. A separate project was initiated to re-implement thedocscommand, but it is not yet production ready. - PR: remove the legacy
TEST_CONFLICTING_PATCHES_WITH_GIT_APPLYsetting
Breaking
- Breaking bug fixes
- PR: fail if
shais not provided to thePOST /repos/{owner}/{repo}/contentsAPI endpoint. Although it was documented to be required, it was not enforced and clients that do not set theshawill no longer succeed.
Release notes from codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Forgejo's release notes list breaking changes under “Breaking …” bullets; those are quoted as “Breaking”. Text the maintainers write above the generated list, and the 7.0.0 “Migration warning” and “Regressions and workarounds” lists, and the hand-written 7.0.3, 7.0.5 and 7.0.6 items (container image, regreSSHion, removed features), and the 10.0.2 “Bug fixes” item on removed TOTP secrets, are quoted as “Note”. Covered from 7.0.0; the 1.18–1.21 releases (tags like v1.21.11-1) are not. The companion blog posts on forgejo.org are not quoted; the full release notes link to them.