Upgrade Path

Forgejo 14.0.0 → 15.0.0

5 versions, 1 with breaking changes, 1 with upstream notes or warnings only, 0 required stops

Version by version, oldest first

14.0.1 2026-01-17

Note

This release includes an upgrade of Go version with security fixes. The issues addressed by this update do not pose any risk to the system or data security of Forgejo deployments, only potential for denial of service attacks.

Full release notes for 14.0.1

14.0.2 – 14.0.4: no action items (3 versions)

14.0.5: released after 15.0.0; not on this route

15.0.0 2026-04-16

Breaking

  • Breaking features
  • PR: remove admin-level permissions from repo-specific & public-only access tokens
  • PR: The template generation (POST /repos/{template_owner}/{template_repo}/generate) and repository deletion (DELETE /repos/{username}/{reponame}) APIs have been updated to require the same permission scope as creating a new repository. Either write:user or write:organization is required, depending on the owner of the repository being created or deleted.
  • PR: Accessing the /repositories/{id} API with a public-only access token did not restrict read access to only public repositories, which is now prevented.
  • PR: Accessing the /repos/{owner}/{repo}/issues/{index}/dependencies and /repos/{owner}/{repo}/issues/{index}/blocks APIs with a public-only access token had access to modification operations against private repositories in the form component of the API (not the URL component), which is now prevented.
  • PR: Accessing the /repos/{owner}/{repo}/issues/{index}/dependencies and /repos/{owner}/{repo}/issues/{index}/blocks APIs with a public-only access token could view dependencies or blocking issues from private repositories, which is now prevented.
  • PR: Accessing the /repos/{owner}/{repo}/issues/{index}/timeline API with a public-only access token could view comment cross-references from private repositories, which is now prevented.
  • PR: Accessing the /teams/{id}/repos/{org}/{repo} API with a public-only access token could view private repositories assigned to a team, which is now prevented.
  • PR: Access the watched repos and starred repos of a your own user through /user/subscriptions and /user/starred APIs with a public-only access token could view private repositories, which is now prevented.
  • PR: implement repo-specific access tokens in relevant search & list APIs. Breaking: the following APIs could previously return private repositories when using a public-only access token, but can no longer do so: /user/repos, /users/{username}/repos, /orgs/{org}/repos, and /teams/{id}/repos.
  • PR: implement repo-specific access tokens broadly for universal API permission checks. Breaking: API access with a public-only access token would previously return a 403 Forbidden error when attempting to access a private repository where the repository is on the API path. As part of incorporating the public-only logic into the centralized permission check, these APIs will now return 404 Not Found instead, consistent with how most permission checks are implemented in order to reduce the risk of data probing through error messages.

Breaking

  • Breaking bug fixes
  • PR: fix(ui)!: Remove the instance configuration option repository.pull-request.ADD_CO_COMMITTER_TRAILERS (was enabled by default). It was responsible for addition of unexpected trailers to commit messages in squash merges. These trailers were Co-authored-by: and Co-committed-by:. Both used the pull request author as value, who is also assigned as the author of the squash merge commit, which they were just repeating. Furthermore, Co-committed-by: is an uncommon commit trailer, and there is only one committer for a commit. The trailers were being added by Forgejo while performing the merge, bypassing user input in the UI and weren't shown in it. See further description and more examples in #11097.

Breaking

  • Breaking changes without a feature or bug label
  • PR: In Forgejo v8.0.0, the default location for the config file was changed from /etc/gitea/app.ini to /var/lib/gitea/custom/conf/app.ini. Backward compatibility logic and startup warnings were added to container setup and entrypoint scripts. Now they are removed. This change only affects those using container deployments with rootless images. If you have the config file stored in a volume bound to container's /etc/gitea, move it to the new location or override the environment variable GITEA_APP_INI. An unused volume /etc/gitea can be safely removed from the container after moving the config or if the deployment never used versions prior to v8.0.0.
  • PR (backported): chore(Dockerfile.rootless): update shadowed env variables
  • PR: Make cookie names brand independent. Attention: All users need to re-login, if you haven't manually set a cookie name in the settings. This can be prevented by changing the remember me cookie back to gitea_incredible

Full release notes for 15.0.0 · companion blog post

Release notes from codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Forgejo's release notes list breaking changes under “Breaking …” bullets; those are quoted as “Breaking”. Text the maintainers write above the generated list, and the 7.0.0 “Migration warning” and “Regressions and workarounds” lists, and the hand-written 7.0.3, 7.0.5 and 7.0.6 items (container image, regreSSHion, removed features), and the 10.0.2 “Bug fixes” item on removed TOTP secrets, are quoted as “Note”. Covered from 7.0.0; the 1.18–1.21 releases (tags like v1.21.11-1) are not. The companion blog posts on forgejo.org are not quoted; the full release notes link to them.