Upgrade Path

Forgejo 7.0.0 → 8.0.0

7 versions, 1 with breaking changes, 3 with upstream notes or warnings only, 0 required stops

Version by version, oldest first

7.0.1 – 7.0.2: no action items (2 versions)

7.0.3 2024-05-22

Note

  • Container image upgrades

In the Forgejo v7.0.3 container images, the Git version was upgraded to 2.43.4 which includes fixes for multiple vulnerabilities. However, the vulnerabilities with a high impact can be exploited when Git is used in an environment (or Operating Systems) which is different from the Forgejo OCI image.

Full release notes for 7.0.3

7.0.4: no action items (1 version)

7.0.5 2024-07-03

Note

  • regreSSHion

Recommended action when running Forgejo from a:

  • binary - upgrade the OpenSSH server that was installed independently.
  • root OCI image - upgrade to Forgejo 7.0.5.
  • rootless OCI image - no upgrade is necessary.

CVE-2024-6387 also known as regreSSHion is an Unauthenticated Remote Code Execution (RCE) vulnerability in OpenSSH’s server (sshd) on glibc-based Linux systems. It is strongly recommended that an OpenSSH server installed independently of Forgejo is upgraded as soon as possible.

All Forgejo OCI root images, including 7.0.5 contain an OpenSSH server. They are based on https://alpinelinux.org/ which relies on https://musl.libc.org/ and not https://en.wikipedia.org/wiki/Glibc. As a precaution the Forgejo v7.0.5 root OCI image contains an updated OpenSSH server patched for CVE-2024-6387.

The Forgejo OCI rootless images, including 7.0.5, do not contain an OpenSSH server, they rely on the internal Forgejo implementation of the SSH protocol.

Full release notes for 7.0.5

7.0.6 2024-07-30

Note

Full release notes for 7.0.6

7.0.7 – 7.0.16: released after 8.0.0; not on this route

8.0.0 2024-07-30

Note

A companion blog post provides additional context on this release. In addition to the pull requests listed below, you will find a complete list in the v8.0 milestone.

  • Two frontend features were removed because a license incompatibility was discovered. Read more in the dedicated blog post.
  • PR: Mermaid rendering: %%{init: {"flowchart": {"defaultRenderer": "elk"}} }%% will now fail because ELK is no longer included.
  • PR: Repository citation: Removed the ability to export citations in APA format.

Breaking

Full release notes for 8.0.0

Release notes from codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Forgejo's release notes list breaking changes under “Breaking …” bullets; those are quoted as “Breaking”. Text the maintainers write above the generated list, and the 7.0.0 “Migration warning” and “Regressions and workarounds” lists, and the hand-written 7.0.3, 7.0.5 and 7.0.6 items (container image, regreSSHion, removed features), and the 10.0.2 “Bug fixes” item on removed TOTP secrets, are quoted as “Note”. Covered from 7.0.0; the 1.18–1.21 releases (tags like v1.21.11-1) are not. The companion blog posts on forgejo.org are not quoted; the full release notes link to them.