Gitea 1.14.0 โ 1.15.0
7 versions, 1 with breaking changes, 0 required stops
Version by version, oldest first
1.14.1 โ 1.14.6: no action items (6 versions)
1.14.7: released after 1.15.0; not on this route
1.15.0 2021-08-22
Breaking
- Make app.ini permissions more restrictive (#16266)
- Refactor Webhook + Add X-Hub-Signature (#16176)
- Add asymmetric JWT signing (#16010)
- Clean-up the settings hierarchy for issue_indexer queue (#16001)
- Change default queue settings to be low go-routines (#15964)
- Improve assets handler middleware (#15961)
- Rename StaticUrlPrefix to AssetUrlPrefix (#15779)
- Use a generic markup class to display externally rendered files and diffs (#15735)
- Add frontend testing, require node 12 (#15315)
- Move (custom) assets into subpath
/assets(#15219) - Use level config in log section when sub log section not set level (#15176)
- Links in markdown should be absolute to the repository not the server (#15088)
- Upgrade to the latest version of golang-jwt (#16590) (#16606)
- Set minimum supported version of go to 1.16 (#16710)
Breaking โ from the release blog
Breaking Changes (or potentially breaking)
Upgrade to the latest version of golang-jwt and increase minimum go to 1.16 (#16590) (#16606) (#16710)
The minimum version of Go Gitea can be compiled with has been increased to 1.16 as Go 1.14 and Go 1.15 are no longer supported by the go developers.
Changed mapping of :latest on docker #16421
The docker tag logic has changed to map :latest to match the latest tag on the 1.15 branch and :dev to represent the latest build on the main branch. Users who wish to use the development version of Gitea - with all its latest features should switch to use the :dev tag for docker. We would like to encourage at least some users to consider using :dev.
More restrictive app.ini permissions #16266
The default file permissions mode for app.ini has changed to -rw------- when Gitea creates this file.
Webhook Refactors #16176
Webhook payloads have been changed so that the Secret field is no longer passed as part of the payload and the history shows the real URL that was sent in the webhook.
Asymmetric JWT Signing Key #16010
We have added asymmetric JWT signing and Gitea will use an asymmetric keypair for JWT signing by default.
- Asymmetric algorithms require a secret asymmetric key pair to be in
JWT_SIGNING_PRIVATE_KEY_FILE(by defaultAPP_DATA_PATH/jwt), a pair will be generated if it is not present. (NB: this was originally inCUSTOM_PATHbut was changed by #16227) - The original symmetric
JWT_SECRETwill only be used ifJWT_SIGNING_ALGORITHMis set toHS256(previous default),HS384orHS512. - As a result of the change of algorithm gitea OAuth2 tokens (and potentially the client secret) will need to be regenerated unless you change your
JWT_SIGNING_ALGORITHMback toHS256. - Legacy installations of Drone assume a short key length, however as no automated migrations are run by Drone you'll need to do them manually if the column type for
user_oauth_tokenanduser_oauth_refreshare limited to 500 characters.
-- an example manual migration for Drone database connected to postgresql
alter table users alter column user_oauth_token type bytea using convert_to(user_oauth_token, 'LATIN1');
alter table users alter column user_oauth_refresh type bytea using convert_to(user_oauth_refresh, 'LATIN1');
Clean-up the settings hierarchy for issue_indexer queue #16001
We have changed the priority of settings below:
[queue.issue_indexer]TYPEnow overrides[indexers]ISSUE_INDEXER_QUEUE_TYPE[queue.issue_indexer]DATADIRoverrides[indexers]ISSUE_INDEXER_QUEUE_DIR[queue.issue_indexer]CONN_STRoverrides[indexers]ISSUE_INDEXER_QUEUE_CONN_STR[queue.issue_indexer]BATCH_LENGTHoverrides[indexers]ISSUE_INDEXER_QUEUE_BATCH_NUMBER[queue.issue_indexer]LENGTHoverrides[indexers]UPDATE_BUFFER_LEN
It is not expected that many people will experience effects from this change.
Change default queue settings to be low go-routines #15964
We have changed the default configuration for queues to make them low goroutines by default:
- As a result of this PR instead of each queue having their own level db by default, the queues will use a common level db. It is recommended to ensure that queues are empty before upgrading using
gitea manager flush-queuesor on the admin pages. - Starting workers are now 0 with boost workers at 1. If you have explicitly set BOOST_WORKERS = 0 you will need to explicitly set
WORKERSto at least 1. Administrators of busy sites should tune their WORKERS, BOOST_WORKERS, & DATADIR parameters as needed.
Merged assets handler middleware #15961
This PR merges two assets handler middleware as one and move it before session middleware to reduce unnecessary memory usage. The additional support for CORS on assets may cause some breakage for sites using CDN assets. Administrators should change [cors] section in the app.ini to add the domains if enabled.
Rename StaticUrlPrefix to AssetUrlPrefix #15779
This PR renames the template variable StaticUrlPrefix to AssetUrlPrefix. Administrators with Custom templates that use the StaticUrlPrefix will need update these to use AssetUrlPrefix.
Use markup class for rendering External markup #15735
This PR essentially changes the markdown css class to markup. Administrators with css/less customization targeting the .markdown class should update these to use .markup.
Update Node to v12 #15315
This PR increases the minimum required node version for compiling the frontend to v12.
Add /assets as root dir of public files #15219
This PR moves root directory of public files from / to /assets.
All pages and resources rendered from custom/public will now be rendered at /assets instead of /. This means that if you have a impressum.html - you need to update links to this to /assets/impressum.html. Similarly for users of STL renderers and external markup renderers.
Administrators should check custom templates to ensure that these are correct.
If you have previously placed robots.txt within custom/public you must move it to custom instead.
Inherit log level in sub log section #15176
Sub loggers will inherit their log level from the main log level - previously these would default to info. Administrators should check their log configuration.
Make links in markdown absolute to the repository not the server #15088
This PR changes the rendering of links in markdown to make them absolute to the current repository in keeping with Github. This may change rendering of some pages however, the previous behaviour was not compatible with Github so was a bug.
Release notes from github.com/go-gitea/gitea/releases, and the official release blog, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else.