Upgrade Path

Gitea 1.21.0 → 1.27.3

50 versions, 8 with breaking changes, 0 required stops

Version by version, oldest first

1.21.1 – 1.21.11: no action items (11 versions)

1.22.0 2024-05-27

Breaking

  • Improve reverse proxy documents and clarify the AppURL guessing behavior (#31003) (#31020)
  • Remember log in for a month by default (#30150)
  • Breaking summary for template refactoring (#29395)
  • All custom templates need to follow these changes
  • Recommend/convert to use case-sensitive collation for MySQL/MSSQL (#28662)
  • Make offline mode as default to not connect external avatar service by default (#28548)
  • Include public repos in the doer's dashboard for issue search (#28304)
  • Use restricted sanitizer for repository description (#28141)
  • Support storage base path as prefix (#27827)
  • Enhanced auth token / remember me (#27606)
  • Rename the default themes to gitea-light, gitea-dark, gitea-auto (#27419)
  • If you didn't see the new themes, please remove the [ui].THEMES config option from app.ini
  • Require MySQL 8.0, PostgreSQL 12, MSSQL 2012 (#27337)

Breaking — from the release blog

Increased DB requirements (#27337)

Gitea only officially supports DBs that have not reached EOL. There are many database versions that have reached End of Life.

As such, we have increased the DB requirements as follows:

  • MySQL 5.7 → MySQL 8.0
  • PostgreSQL 10 → PostgreSQL 12
  • MSSQL 2008 → MSSQL 2012

Caution

Support for MySQL 5.7, PostgreSQL 10/11, and MSSQL 2008 is dropped. You are encouraged to upgrade to supported versions.

If you have to use an unsupported database version, please get in touch with us for information on our Extended Support Contracts. We can provide testing and support for older databases and integrate those fixes into the Gitea codebase.

MySQL/MSSQL DBs should be case sensitive (#28662)

MySQL (including MariaDB) and MSSQL create databases case-insensitively by default, meaning for example that gitea is equal to GITea.

Historically, this led to many bug reports of functionality behaving unexpectedly, i.e. branches not being able to be inserted because a new branch only differed in casing compared to an existing branch. Gitea was never intended to be used in a case-insensitive DB.

Now, Gitea will explicitly warn you if it detects being run in a case-insensitive DB. If you haven't done so already, please convert your DB to a case-sensitive one.

Note

Postgres and SQLite users are most likely unaffected as those DBs are already case-sensitive by default.

Breaking summary for template refactoring (#29395)

The template system has been refactored, and some template functions may have been changed or removed.

  • Safe is renamed to SafeHTML, and in most cases it shouldn't be used.
  • Escape is renamed to HTMLEscape, and in most cases it shouldn't be used. The template should escape most variables automatically.
  • Str2html is renamed to SanitizeHTML, only use it when necessary, it only "sanitizes" the input by pre-defined rules, but it doesn't "render" or "convert" the content.
  • Use HTMLFormat instead of printf when processing HTML-related contents.

Caution

If you use custom templates (either for the UI or for emails), please read through #29395 to ensure your custom templates will work again.

Default theme change (#27419)

Gitea simplified its theme naming in this release.

The available themes are now gitea-light (previously gitea), gitea-dark (previously arc-green), gitea-auto (previously auto).

This has multiple effects:

  • If you have any custom themes named like that, please rename them to continue using them.
  • It is now possible to check which theme is active by querying the attribute

html[data-theme] instead of the previous html.theme-<theme> when expressing the query as a CSS selector. This change is especially important for third-party tooling whose behavior depends on which theme is active.

  • If you set [ui].DEFAULT_THEME previously, you need to change it to the new theme name.

If you see a black-and-white UI after the update, it is likely that you need to update this setting as the theme cannot be found.

Changed markdown highlighting syntax (#29121)

As we will explain in more detail in the new features, Gitea is now capable of additional alert types using a new syntax.

At the same time, the old syntax > **Note** A note/> **Warning** A warning has been removed, so please rewrite your existing markdown documents to the new syntax where applicable.

If you used:

> **Note** My note

or

> **Warning** My warning

Rewrite these as:

> [!NOTE]
> My note

or

> [!WARNING]
> My warning

Only minimal markdown allowed in repo descriptions (#28141)

Previously, the repository description accepted any sort of markdown. Now, you can only use basic markdown features such as bold, italic, or highlighted text.

Breaking API changes (#27153, #28339)

There were two minor breaking changes to the API in this release:

  • Previously, the push mirror API returned timestamps in an incorrect format. This has now been updated to behave exactly like any other timestamp.
  • The already deprecated (and due to a bug, unusable) pagination parameter per_page has been removed from the list releases endpoint. Instead, you should use the limit parameter.

Login is now remembered for a month by default (#30150)

Previously, your login was only remembered for a week by default. However, many instances don't set the setting and have no explicit security requirements, so having such a short interval is not user-friendly.

If your instance requires a high level of security, you may want to set

[security]
// highlight-next-line
LOGIN_REMEMBER_DAYS = 7

or something similar again.

Removed configurations (#27606, #28527)

Some settings are no longer used. If you previously set any of them, you can now safely remove them from your config:

  • ~~[security].COOKIE_USERNAME~~
  • ~~[cache].ENABLED~~
  • ~~[cache.last_commit].ENABLED~~

Caution

Caches are now enabled by default and cannot be disabled. The default adapter is memory, you can change it to redis, etc. More details are in https://docs.gitea.com/administration/config-cheat-sheet#cache-cache

Support storage base path as prefix (#27827)

This PR will affect all configurations having base_path in the storage section but no base_path in the derived storage configuration sections. The base_path on [storage] will become a prefix for them but will not share the same base_path.

[storage]
; Now it becomes a prefix of derived base_path but not share the name
// highlight-next-line
base_path = xxx 

No Gravatar by default (#28548)

The default value of [server].OFFLINE_MODE has been changed to true, so Gitea will not allow Gravatar queries by default.

However, most existing instances won't be affected by this, as this setting is only used as the default value for the Gravatar settings, not the actual value.

Additionally, it is saved into the config when you install Gitea.

From blog.gitea.com/release-of-1.22.0/

Full release notes for 1.22.0

1.22.1 – 1.22.6: no action items (6 versions)

1.23.0 2025-01-09

Breaking

  • Rename config option [camo].Allways to [camo].Always (#32097)
  • Remove SHA1 for support for SSH RSA signing (#31857)
  • Use UTC as the default timezone when scheduling Actions cron tasks (#31742)
  • Delete Actions logs older than 1 year by default (#31735)
  • Make OIDC introspection authentication strictly require Client ID and secret (#31632)

Breaking — from the release blog

Actions logs expired will be cleaned up in background. (#31735)

A new configuration [actions].LOG_RETENTION_DAYS = 365 was introduced to control how long the logs should be deleted. The default value is 365 days. If you want to keep the logs longer, you need to change the configurations once you upgrade.

Configuration [camo].Allways was corrected to [camo].Always (#32097)

The configuration setting [camo].Allways contained a typo and has been corrected to [camo].Always. Users should update their configuration files to reflect this change to ensure compatibility with the latest version. This adjustment improves clarity and prevents potential misconfigurations caused by the incorrect spelling.

Make OIDC introspection authentication strictly require Client ID and secret (#31632)

OIDC introspection authentication now strictly requires a Client ID and secret, enhancing security. Update your configuration to ensure compatibility.

Remove SHA1 for support for ssh rsa signing (#31857)

Support for SHA1 in SSH RSA signing has been removed due to security concerns. Users should ensure their environments and keys are updated to use more secure algorithms.

Use UTC as default timezone when schedule Actions cron tasks (#31742)

Actions cron tasks now default to UTC for scheduling, ensuring consistency across environments. If the server's local time zone is not UTC, a scheduled task would run at a different time after upgrading Gitea to this version.

Administration URL changed from /admin to /-/admin to allow accounts named admin. (#32189) This maybe a break change for those instances which have customized site header.

The administration URL has been updated to /-/admin to allow accounts named admin. This change may affect instances with customized site headers. Update your configurations or customizations accordingly to prevent disruptions.

From blog.gitea.com/release-of-1.23.0/

Full release notes for 1.23.0

1.23.1: no action items (1 version)

1.23.2 2025-02-05

Breaking

  • Add tests for webhook and fix some webhook bugs (#33396) (#33442)
  • Package webhook’s Organization was incorrectly used as the User struct. This PR fixes the issue.
  • This changelog is just a hint. The change is not really breaking because most fields are the same, most users are not affected.

Full release notes for 1.23.2

1.23.3 – 1.23.8: no action items (6 versions)

1.24.0 2025-06-10

Breaking

  • Make Gitea always use its internal config, ignore /etc/gitconfig (#33076)
  • Improve log format (#33814)
  • Fix markdown render behaviors (#34122)
  • Add package version api endpoints (#34173)

Breaking — from the release blog

Make Gitea always use its internal config, ignore /etc/gitconfig (#33076)

Historically, Gitea has been able to use the system config under /etc/gitconfig to support some edge-case customizations. However, it sometimes causes conflicts, which have arisen multiple times lately. Therefore, we decided to switch away from this practice, adding GIT_CONFIG_NOSYSTEM=1 to all git commands.

If you have made changes to /etc/gitconfig to affect Gitea's behavior, you need to move these config options to Gitea's internal git config file, it is usually in Gitea's {AppDataPath}/home/.gitconfig.

Thank you to @wxiaoguang for contributing this feature.

Improve log format (#33814)

The router log format was changed from

2025/03/06 22:21:12 ...eb/routing/logger.go:102:func1() [I] router: completed GET / for [::1]:52693, 200 OK in 15.9ms @ web/home.go:32(web.Home)

to

2025/03/06 22:20:35 HTTPRequest [I] router: completed GET / for [::1]:52631, 200 OK in 7.5ms @ web/home.go:32(web.Home)

Thank you to @wxiaoguang for contributing this feature.

Fix markdown render behaviors (#34122)

Add config options MATH_CODE_BLOCK_DETECTION, problematic syntaxes are disabled by default.

Some markdown rendering behaviors are improved to match GitHub, please refer to the latest document's "Markdown" page to see the details.

Thank you to @wxiaoguang for contributing this feature.

Add package version api endpoints (#34173)

Two new API endpoints to list versions of a package and to get the latest version of a package were added.

The size field for this endpoint changes case from Size to size for consistency.

Thank you to @KN4CK3R for contributing this feature.

From blog.gitea.com/release-of-1.24.0/

Full release notes for 1.24.0

1.24.1 – 1.24.7: no action items (7 versions)

1.25.0 2025-10-29

Breaking

  • Return 201 Created for CreateVariable API responses (#34517)
  • Add label 'state' to metric 'gitea_users' (#34326)

Breaking — from the release blog

Remove deprecated auth sources (#35272)

Deprecated authentication sources have been removed in this version. Please ensure your authentication configuration is up to date before upgrading.

Refactor and update mail templates (#35150)

Mail templates have been refactored to improve maintainability. If you have customized mail templates, please note that this is a breaking change.

Thank you to @techknowlogick for contributing this feature.

From blog.gitea.com/release-of-1.25.0/

Full release notes for 1.25.0

1.25.1 – 1.25.5: no action items (5 versions)

1.26.0 2026-04-18

Breaking

  • Correct swagger annotations for enums, status codes, and notification state (#37030)
  • Remove GET API registration-token (#36801)
  • Support Actions concurrency syntax (#32751)
  • Make PUBLIC_URL_DETECTION default to "auto" (#36955)

Breaking — from the release blog

Introduce "config edit-ini" sub command to help maintaining INI config file (#35735)

The standalone environment-to-ini tool was removed and a sub command of gitea has been introduced. If you need to re-create the configuration file with only a subset of keys, you can provide an INI template file and use the "--config-keep-keys" flag.

Correct Swagger annotations for enums, status codes, and notification state (#37030)

The generated OpenAPI description is now aligned with the actual API: enum values, HTTP status codes, and notification state are documented more accurately. If you rely on the published Swagger spec for code generation or contract tests, regenerate clients and re-check any assumptions about optional fields or response shapes.

Thank you to @myers for contributing this change.

Remove GET API registration-token (#36801)

The GET endpoint used to retrieve a registration token has been removed. Automation that still calls it needs to be updated to the supported registration flow for your deployment.

Thank you to @lunny for contributing this change.

Support Actions concurrency syntax (#32751)

Workflows can now use GitHub-style concurrency groups so that new runs cancel or queue relative to in-progress jobs. That changes runtime behavior compared with earlier releases, so review existing workflows after upgrading—especially long-running or overlapping pipelines.

Thank you to @Zettat123 for contributing this feature.

Make PUBLIC_URL_DETECTION default to auto (#36955)

New installations now default to automatic public URL detection. If you depend on a specific explicit URL configuration behind reverse proxies or alternate hostnames, confirm your [server] settings after upgrade so links, webhooks, and redirects still match your environment.

Thank you to @wxiaoguang for contributing this change.

From blog.gitea.com/release-of-1.26.0/

Full release notes for 1.26.0

1.26.1 – 1.26.2: no action items (2 versions)

1.26.3 2026-06-20

Warning

Please upgrade to 1.26.4 directly. A regression in this release can cause "context deadline exceeded" errors when opening any repository's code pages (#38177). Please hold off on upgrading until a fix is released.

Breaking

  • fix(actions)!: require merged PR to bypass fork PR approval gate (#38010) (#38041)

Breaking — from the release blog

This release tightens the fork pull request approval gate: a pull request from a fork must now be merged before it can bypass the approval gate (#38041). Review your workflow approval settings if you rely on the previous behavior.

From blog.gitea.com/release-of-1.26.3-and-1.26.4/

Full release notes for 1.26.3

1.26.4: no action items (1 version)

1.27.0 2026-07-13

Breaking

  • Feat(actions)!: improve support for reusable workflows (#37478)
  • Use Content-Security-Policy: script nonce (#37232)

Breaking — from the release blog

Move release artifact signing to sigstore (#38250)

Gitea release artifacts are now signed with sigstore instead of the previous GPG flow. If you verify downloaded binaries or Docker images as part of your deployment pipeline, update your verification step to the sigstore-based process.

Thank you to @TheFox0x7 for contributing this change.

Improve support for reusable workflows (#37478)

Reusable workflows referenced with uses: are now parsed on the Gitea side rather than on the runner. Each called (child) job is inserted as its own ActionRunJob and dispatched as an independent task, so callee logs surface as separate job entries instead of being inlined into the caller's "Set up job" step. Review workflows that rely on reusable-workflow behavior after upgrading.

External reusable workflows (uses: https://other-gitea-instance/OWNER/REPO/.gitea/workflows/test.yaml@REF) are no longer supported. To keep using them, clone the repositories to the local instance and reference them there.

Thank you to @Zettat123 for contributing this change.

Use a Content-Security-Policy script nonce (#37232)

Inline scripts are now allowed via a per-request CSP nonce instead of a broader policy. Custom templates, themes, or embeds that inject inline <script> tags may stop executing until they are updated to carry the nonce. Review custom front-end customizations after upgrading.

Thank you to @wxiaoguang for contributing this change.

X-Content-Type-Options: nosniff is now sent by default (#37354)

All responses now include the X-Content-Type-Options: nosniff header, which stops browsers from MIME-sniffing responses away from their declared Content-Type. If a reverse proxy, embed, or custom asset relied on content sniffing, set X_CONTENT_TYPE_OPTIONS = unset under [security] to remove the header, or override its value as needed.

Thank you to @SAY-5 for contributing this change.

From blog.gitea.com/release-of-1.27.0/

Full release notes for 1.27.0

1.27.1 – 1.27.3: no action items (3 versions)

Release notes from github.com/go-gitea/gitea/releases, and the official release blog, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else.