Upgrade Path

Gitea 1.17.0 → 1.18.0

5 versions, 2 with breaking changes, 0 required stops

Version by version, oldest first

1.17.1: no action items (1 version)

1.17.2 2022-09-06

Breaking — from the release blog

After release we discovered that a template function removal was backported, which may break user templates. (#20932)

Users may need to update their custom templates to stop using this function.

From blog.gitea.com/release-of-1.17.2/

Full release notes for 1.17.2

1.17.3 – 1.17.4: no action items (2 versions)

1.18.0 2022-12-29

Breaking

  • Rework mailer settings (#18982)
  • Remove U2F support (#20141)
  • Refactor i18n to locale (#20153)
  • Enable contenthash in filename for dynamic assets (#20813)

Breaking — from the release blog

Remove ReverseProxy authentication from the API (#22219)

Access to the API was removed for ReverseProxy authentication. Users will now be required to use tokens or basic auth.

Mailing: Rework mailer settings (#18982)

  • If you specify credentials for sending emails but the server doesn't support using them, Gitea will fail to start instead of sending mails unauthenticated.
  • Use unique mailer.PROTOCOL for different mailers (SMTP family, sendmail, dummy), instead of MAILER_TYPE+PROTOCOL.
  • The combined mailer.HOST option has been deprecated in favor of the new mailer.SMTP_ADDR and mailer.SMTP_PORT options.
  • The mailer.IS_TLS_ENABLED option has been deprecated in favor of using the new mailer.PROTOCOL option, which accepts smtp, smtps, smtp+startls, or smtp+unix explicitly. If you don't know what protocol your provider uses but provide a port, you can leave it blank and it will be inferred by the given port. See the non-breaking changes section for more details on the new smtp+unix protocol.
  • The mailer.DISABLE_HELO (default false) option has been replaced with mailer.ENABLE_HELO (default true). It still does the same thing, but the option was negated to be less confusing.
  • The mailer.SKIP_VERIFY option has been replaced with mailer.FORCE_TRUST_SERVER_CERT to sound scarier, and to clarify what it does.
  • The mailer.USE_CERTIFICATE, mailer.CERT_FILE, and mailer.KEY_FILE have been deprecated and renamed to mailer.USE_CLIENT_CERT, mailer.CLIENT_CERT_FILE, and mailer.CLIENT_KEY_FILE.

Some configuration moved from config file to database (#18058)

Two configurations, picture.DISABLE_GRAVATAR and picture.ENABLE_FEDERATED_AVATAR, have been copied to database config setting table so that admins can change them in the admin panel without restarting the gitea service. The existing config settings in app.ini will be migrated to the database on first run after upgrading, then the database settings will take precedence.

Authentication: Remove U2F support (#20141)

Gitea 1.18 completelely removes U2F support. Users should migrate to webauthn if they haven't already.

Templates: Refactor i18n to locale (#20153)

Any user with custom templates will be affected by this and will need to replace .i18n with .locale.

Templates: Remove MD5 function (#20813)

The MD5 function was removed due being insecure, and due to being unused with the new approach. Any user with custom templates will be affected by this and will need to remove any occurrence of the MD5 function.


From blog.gitea.com/release-of-1.18.0/

Full release notes for 1.18.0

Release notes from github.com/go-gitea/gitea/releases, and the official release blog, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else.