Upgrade Path

Gitea 1.16.0 → 1.17.0

10 versions, 3 with breaking changes, 0 required stops

Version by version, oldest first

1.16.1 – 1.16.3: no action items (3 versions)

1.16.4 2022-03-14

Quoted from blog.gitea.com/release-of-1.16.4/

Breaking — from the release blog

Breaking Change: Refactor mirror code & fix StartToMirror (#19075)

This PR will make old queue entrys unredable for the new version, make sure to flush the mirror sync queue before updating.

Breaking — from the release blog

Breaking Change: Restrict email address validation (#19085)

Narrow the allowed chars a email address can have.

Breaking — from the release blog

Breaking Change: Add pam account authorization check (#18904)

Users of the PAM module who rely on account modules not being checked will need to change their PAM configuration.

Full release notes for 1.16.4

1.16.5 2022-03-24

Breaking — from the release blog

Breaking Change: Bump to build with go1.18 (#19120 et al) (#19127)

Go 1.18 has been released and with its release 1.16 has been deprecated. In order to be able to build with 1.18 several packages have had to be updated. This PR collates these together and changes our build process to build with 1.18.

From blog.gitea.com/release-of-1.16.5/

Full release notes for 1.16.5

1.16.6 – 1.16.9: no action items (4 versions)

1.17.0 2022-07-30

Breaking

  • Require go1.18 for Gitea 1.17 (#19918)
  • Make AppDataPath absolute against the AppWorkPath if it is not (#19815)
  • Nuke the incorrect permission report on /api/v1/notifications (#19761)
  • Refactor git module, make Gitea use internal git config (#19732)
  • Remove RequireHighlightJS field, update plantuml example. (#19615)
  • Increase minimal required git version to 2.0 (#19577)
  • Add a directory prefix gitea-src-VERSION to release-tar-file (#19396)
  • Use "main" as default branch name (#19354)
  • Make cron task no notice on success (#19221)
  • Add pam account authorization check (#19040)
  • Show messages for users if the ROOT_URL is wrong, show JavaScript errors (#18971)
  • Refactor mirror code & fix StartToMirror (#18904)
  • Remove deprecated SSH ciphers from default (#18697)
  • Add the possibility to allow the user to have a favicon which differs from the main logo (#18542)
  • Update reserved usernames list (#18438)
  • Support custom ACME provider (#18340)
  • Change initial TrustModel to committer (#18335)
  • Update HTTP status codes (#18063)
  • Upgrade Alpine from 3.13 to 3.15 (#18050)
  • Restrict email address validation (#17688)
  • Refactor Router Logger (#17308)

Breaking — from the release blog

Internal Gitconfig (#19732)

Previously, Gitea used the users gitconfig ($HOME/.gitconfig) in addition to the system gitconfig (/etc/gitconfig). Now, Gitea uses the system gitconfig (/etc/gitconfig) combined with an internal gitconfig located in {[git].HOME_PATH}/.gitconfig. If you customized your user gitconfig for Gitea, you should add these customizations to one of the available gitconfigs. Additional git-relevant files that are normally in your user home directory, like $HOME/.gnupg, should be moved/ copied to {[git].HOME_PATH}/ as well.

Email address validation restricted (#17688)

With this release, Gitea restricts what is seen as a valid email: Emails must only contain characters in a-zA-Z0-9.!#$%&'*+-/=?^_{|}`~. Additionally, the first letter must be in a-zA-Z0-9, and after the @, only characters in a-zA-Z0-9. can follow.

Renamed configuration options for ACME / Let's Encrypt (#18340)

Configuration settings have been renamed from LETSENCRYPT to ACME. The old settings are deprecated and will be removed in 1.18, you should migrate now.

  • ENABLE_LETSENCRYPT → ENABLE_ACME
  • LETSENCRYPT_URL → ACME_URL
  • LETSENCRYPT_ACCEPTTOS → ACME_ACCEPTTOS
  • LETSENCRYPT_DIRECTORY → ACME_DIRECTORY
  • LETSENCRYPT_EMAIL → ACME_EMAIL

New logger format and configuration (#17308)

This PR substantially changes the logging format of the router logger. If you use this logging for monitoring (e.g. fail2ban) you will need to update this to match the new format. Refer to the documentation on the router logger for new configuration options.

main as default branch (#19354)

The default value of the setting repository.DEFAULT_BRANCH was switched from master to main. If you want to continue using master as default branch name, set this setting. This change is especially relevant for third party tools that assume the default branch of a repository.

Change initial trust model to committer (#18335)

Previously, Gitea would by default use the collaborator trust model. This means only verified commits of collaborators can be trusted. This was quite an aggressive trust model, and now it has changed to match GitHub's behavior of trusting the commiter. This means verified commits in a repository from non-collaborators won't be marked as unverified.

If you rely on the old behavior, you must set DEFAULT_TRUST_MODEL to collaborator.

Require Git >= 2.0 (#19577)

The minimal required Git version has been raised to 2.0. Versions below that are now unsupported and will prevent the application from starting. In general, it is recommended to stay up-to-date with your Git version as some Gitea features or optimizations can only be used once they are available in Git.

Require docker version >= 20.10.6 (#18050)

This is due to an issue with libc of the new base image alpine 3.15.

Require Go >= 1.18 to compile (#19918, #19099)

The minimum version of Go needed to compile Gitea has been increased to 1.18.

Changed handling of custom logo (#18542)

It is now not only possible to set a custom logo, but also a custom favicon. If you are currently using a custom logo, you need to re-run the steps described here.

RequireHighlightJS removed from templates (#19615)

If you use custom templates, check that they do not use RequireHighlightJS anymore as this was outdated already and has now been removed.

Reserved usernames updated (#18438)

The following usernames are now newly reserved: avatar, ssh_info, and swagger_v1.json. The following usernames are no longer reserved: help, install, less, plugins, stars, and template.

If you want to check if you're affected, please run the following Gitea doctor command:

gitea doctor --run check-user-names

Note that this command is only available after upgrading to 1.17.1.

Deprecated SSH ciphers removed from default setting (#18697)

This only affects Gitea instances that have enabled the internal SSH server. Previously, Gitea allowed unsecured algorithms to be used for an SSH connection. Older versions of OpenSSH might not be able to connect to Gitea anymore.

Display messages for users if the ROOT_URL is wrong, show JavaScript errors (#18971)

Previously, Gitea would allow an incorrect ROOT_URL to be set in the settings. This caused unexpected issues when people don't use that URL to visit Gitea. Therefore, Gitea will now show an error in the UI when this is the case. Please check if your ROOT_URL is set correctly and avoid accessing the instance using other URLs to avoid the error message.

/api/v1/notifications does not include repo permissions (#19761)

Previously, /api/v1/notifications returned repository.permissions but the permissions were calculated incorrectly. Due to this and the fact that there exists another route to get the repo permissions, this field will always be null from now on.

HTTP status codes updated: 302 → 307 and 301 → 308 (#18063)

Previously, Gitea often returned the incorrect status codes Found (302) and Moved Permanently (301). All occurrences of such status code were now changed to Temporary Redirect (307) and Permanent Redirect (308) respectively.

No more admin notice about successful cron tasks (#19221)

Successful cron task no longer emit a notification by default. This breaks NO_SUCCESS_NOTICE settings. If you want notices on success, you must set NOTICE_ON_SUCCESS=true.

From blog.gitea.com/release-of-1.17.0/

Full release notes for 1.17.0

Release notes from github.com/go-gitea/gitea/releases, and the official release blog, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else.