Gitea 1.15.0 โ 1.16.0
12 versions, 1 with breaking changes, 0 required stops
Version by version, oldest first
1.15.1 โ 1.15.11: no action items (11 versions)
1.16.0 2022-01-30
Breaking
- Remove golang vendored directory (#18277)
- Paginate releases page & set default page size to 10 (#16857)
- Only allow webhook to send requests to allowed hosts (#17482)
Breaking โ from the release blog
Breaking Changes (or potentially breaking)
Only allow webhook to send requests to allowed hosts (#17482)
For security reasons, the webhook should only send requests to allowed hosts.
This PR introduced ALLOWED_HOST_LIST with default value of external meaning that Webhooks by default can only call external hosts for security reasons.
Although ALLOWED_HOST_LIST was backported to 1.15 the default value is different between 1.15 and 1.16 and is more strict. If you need to allow Webhooks to call local network hosts you must explicitly allow those IPs/Hosts.
Remove golang vendored directory (#18277)
We no longer store the vendored directory within git. Users building directly from git checkouts should run make vendor on pulls or when changing branches.
Paginate releases page & set default page size to 10 (#16857)
We have reduced the number of releases shown on the releases page from 30 to 10 and add paging.
Users may change the default value by setting
[repository.release]
DEFAULT_PAGING_NUM=10
Use shadowing script for docker (#17846)
Too many docker users are caught out by the default location for the app.ini file being environment dependent so that when they docker exec into the container the gitea commands do not work properly and require additional -c arguments to correctly pick up the configuration.
This PR simply shadows the gitea binary using variants of the FHS compatible script to make the command gitea have the default locations by default.
Although this PR should be non-breaking for most configurations and should make things simpler for docker users in general, there was a slightly unforeseen issue in that SSH passthrough configurations that rely on the path of the gitea binary being /app/gitea/gitea will need to update this to /usr/local/bin/gitea (likely including moving their host shim from /app/gitea/gitea to /usr/local/bin/gitea)
Users should use /usr/local/bin/gitea in preference to /app/gitea/gitea when executing on the docker as this will automatically set the correct paths and environment for them.
Support webauthn (#17957)
U2F support has been deprecated by major browsers and therefore we've had to migrate to WebAuthn. We've attempted to create a backwards compatible migration however, the website relying party ID used for webauthentication is not the same as that used by U2F.
In order to support old u2f keys previously registered Gitea will use the app_id extension and will send the contents of [U2F] APP_ID as this app_id. This will need to match your original u2f configuration.
Release notes from github.com/go-gitea/gitea/releases, and the official release blog, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else.