Forgejo 8.0.0 → 9.0.0
4 versions, 1 with breaking changes, 2 with upstream notes or warnings only, 0 required stops
Version by version, oldest first
8.0.1 2024-08-09
Note
This is a security release. See the documentation for more information on the upgrade procedure.
- Security bug fixes A change introduced in Forgejo v1.21 allows a Forgejo user with write permission on a repository description to inject a client-side script into the web page viewed by the visitor. This XSS allows for
hrefin anchor elements to be set to ajavascript:URI in the repository description, which will execute the specified script upon clicking (and not upon loading).AllowStandardURLsis now called for the repository description policy, which ensures that URIs in anchor elements aremailto:,http://orhttps://and thereby disallowing thejavascript:URI.
8.0.2 2024-08-29
Note
This is a security release. See the documentation for more information on the upgrade procedure.
- Security The scope of application tokens was not verified when writing containers or Conan packages. This is of no consequence when the user associated with the application token does not have write access to packages. If the user has write access to packages, such a token can be used to write containers and Conan packages. An application token that was used to write containers or Conan packages without the
package:writescope will now fail with an unauthorized error. It must be re-created to include thepackage:writescope.
8.0.3: no action items (1 version)
9.0.0 2024-10-16
Breaking
- PR: OIDC integrations that POST to
/login/oauth/introspectwithout sending HTTP basic authentication will now fail with a 401 HTTP Unauthorized error. To fix the error, the client must begin sending HTTP basic authentication with a valid client ID and secret. This endpoint was previously authenticated via the introspection token itself, which is less secure. - PR (backported): Fixing this bug is a breaking change because existing tokens with a public scope will no longer return private resources. They have to be deleted and re-created without the public scope to restore their original behavior. The public scope of an application token does not filter out private repositories, organizations or packages in some cases. This scope is not the default, it has to be manually set via the web UI or the API. When the public scope is explicitly added to an application token that is allowed to list the repositories and packages of a user or an organization, it is meant as a restriction. For instance if a user has two repositories, one private and the other publicly visible, a token with the public scope used with the API endpoint listing the repositories that belong to this user must only return the publicly visible one and not reveal the existence of the private one.
- PR: Drop support to build Forgejo with the optional go-git Git backend. It only affects users who built Forgejo manually using
TAGS=gogits, which no longer has any effect. Moving forward, we only support the default backend using the git binary. Please get in touch if you used the go-git backend and require any assistance moving away from it.
Release notes from codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Forgejo's release notes list breaking changes under “Breaking …” bullets; those are quoted as “Breaking”. Text the maintainers write above the generated list, and the 7.0.0 “Migration warning” and “Regressions and workarounds” lists, and the hand-written 7.0.3, 7.0.5 and 7.0.6 items (container image, regreSSHion, removed features), and the 10.0.2 “Bug fixes” item on removed TOTP secrets, are quoted as “Note”. Covered from 7.0.0; the 1.18–1.21 releases (tags like v1.21.11-1) are not. The companion blog posts on forgejo.org are not quoted; the full release notes link to them.