Forgejo 14.0.0 → 16.0.5
16 versions, 2 with breaking changes, 2 with upstream notes or warnings only, 0 required stops
Version by version, oldest first
14.0.1 2026-01-17
Note
This release includes an upgrade of Go version with security fixes. The issues addressed by this update do not pose any risk to the system or data security of Forgejo deployments, only potential for denial of service attacks.
14.0.2 – 14.0.4: no action items (3 versions)
14.0.5: released after 15.0.0; not on this route
15.0.0 2026-04-16
Breaking
- Breaking features
- PR: remove admin-level permissions from repo-specific & public-only access tokens
- PR: The template generation (
POST /repos/{template_owner}/{template_repo}/generate) and repository deletion (DELETE /repos/{username}/{reponame}) APIs have been updated to require the same permission scope as creating a new repository. Eitherwrite:userorwrite:organizationis required, depending on the owner of the repository being created or deleted. - PR: Accessing the
/repositories/{id}API with a public-only access token did not restrict read access to only public repositories, which is now prevented. - PR: Accessing the
/repos/{owner}/{repo}/issues/{index}/dependenciesand/repos/{owner}/{repo}/issues/{index}/blocksAPIs with a public-only access token had access to modification operations against private repositories in the form component of the API (not the URL component), which is now prevented. - PR: Accessing the
/repos/{owner}/{repo}/issues/{index}/dependenciesand/repos/{owner}/{repo}/issues/{index}/blocksAPIs with a public-only access token could view dependencies or blocking issues from private repositories, which is now prevented. - PR: Accessing the
/repos/{owner}/{repo}/issues/{index}/timelineAPI with a public-only access token could view comment cross-references from private repositories, which is now prevented. - PR: Accessing the
/teams/{id}/repos/{org}/{repo}API with a public-only access token could view private repositories assigned to a team, which is now prevented. - PR: Access the watched repos and starred repos of a your own user through /user/subscriptions and /user/starred APIs with a public-only access token could view private repositories, which is now prevented.
- PR: implement repo-specific access tokens in relevant search & list APIs. Breaking: the following APIs could previously return private repositories when using a public-only access token, but can no longer do so:
/user/repos,/users/{username}/repos,/orgs/{org}/repos, and/teams/{id}/repos. - PR: implement repo-specific access tokens broadly for universal API permission checks. Breaking: API access with a public-only access token would previously return a
403 Forbiddenerror when attempting to access a private repository where the repository is on the API path. As part of incorporating the public-only logic into the centralized permission check, these APIs will now return404 Not Foundinstead, consistent with how most permission checks are implemented in order to reduce the risk of data probing through error messages.
Breaking
- Breaking bug fixes
- PR: fix(ui)!: Remove the instance configuration option
repository.pull-request.ADD_CO_COMMITTER_TRAILERS(was enabled by default). It was responsible for addition of unexpected trailers to commit messages in squash merges. These trailers wereCo-authored-by:andCo-committed-by:. Both used the pull request author as value, who is also assigned as the author of the squash merge commit, which they were just repeating. Furthermore,Co-committed-by:is an uncommon commit trailer, and there is only one committer for a commit. The trailers were being added by Forgejo while performing the merge, bypassing user input in the UI and weren't shown in it. See further description and more examples in #11097.
Breaking
- Breaking changes without a feature or bug label
- PR: In Forgejo v8.0.0, the default location for the config file was changed from
/etc/gitea/app.inito/var/lib/gitea/custom/conf/app.ini. Backward compatibility logic and startup warnings were added to container setup and entrypoint scripts. Now they are removed. This change only affects those using container deployments with rootless images. If you have the config file stored in a volume bound to container's /etc/gitea, move it to the new location or override the environment variableGITEA_APP_INI. An unused volume/etc/giteacan be safely removed from the container after moving the config or if the deployment never used versions prior to v8.0.0. - PR (backported): chore(Dockerfile.rootless): update shadowed env variables
- PR: Make cookie names brand independent. Attention: All users need to re-login, if you haven't manually set a cookie name in the settings. This can be prevented by changing the remember me cookie back to
gitea_incredible
15.0.1 – 15.0.4: no action items (4 versions)
15.0.5 2026-07-15
Note
Also see a security announcement. Manual action is needed for some v15 deployments, as well as for upgrade to v16.0.0.
15.0.6 – 15.0.9: released after 16.0.0; not on this route
16.0.0 2026-07-16
Note
Learn more about most notable changes and addressing the breaking changes in our news post: Forgejo v16.0 is available.
Git hooks are now stored in a centralized location instead of being duplicated in every repository, and Git hook example files are no longer generated for new repositories. While a backwards-compatible change, your instance can benefit from following an upgrade guide to clean up these files for the existing repositories. As always, make sure you to have a usable backup before upgrading!
Breaking
- Breaking security bug fixes
- PR: remove default 'REVERSE_PROXY_TRUSTED_PROXIES = *' from docker config
- PR: Improved compliance with the config settings
[migrations].ALLOWED_DOMAINS,[migrations].BLOCKED_DOMAINS, and[migrations].ALLOW_LOCALNETWORKS, which control the remotes that Forgejo can access for git & LFS migration and mirroring operations, fixing time-of-check vs. time-of-use issue and missing checks in LFS. git mirror HTTP operations have been adjusted to never follow HTTP redirects in order to ensure that these settings are followed, which will break HTTP mirroring if a redirect is served by the git HTTP remote.
Breaking
16.0.1 – 16.0.5: no action items (5 versions)
Release notes from codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Forgejo's release notes list breaking changes under “Breaking …” bullets; those are quoted as “Breaking”. Text the maintainers write above the generated list, and the 7.0.0 “Migration warning” and “Regressions and workarounds” lists, and the hand-written 7.0.3, 7.0.5 and 7.0.6 items (container image, regreSSHion, removed features), and the 10.0.2 “Bug fixes” item on removed TOTP secrets, are quoted as “Note”. Covered from 7.0.0; the 1.18–1.21 releases (tags like v1.21.11-1) are not. The companion blog posts on forgejo.org are not quoted; the full release notes link to them.