Gitea 1.24.0 → 1.27.3
22 versions, 4 with breaking changes, 0 required stops
Version by version, oldest first
1.24.1 – 1.24.7: no action items (7 versions)
1.25.0 2025-10-29
Breaking
- Return 201 Created for CreateVariable API responses (#34517)
- Add label 'state' to metric 'gitea_users' (#34326)
Breaking — from the release blog
Remove deprecated auth sources (#35272)
Deprecated authentication sources have been removed in this version. Please ensure your authentication configuration is up to date before upgrading.
Refactor and update mail templates (#35150)
Mail templates have been refactored to improve maintainability. If you have customized mail templates, please note that this is a breaking change.
Thank you to @techknowlogick for contributing this feature.
1.25.1 – 1.25.5: no action items (5 versions)
1.26.0 2026-04-18
Breaking
- Correct swagger annotations for enums, status codes, and notification state (#37030)
- Remove GET API registration-token (#36801)
- Support Actions
concurrencysyntax (#32751) - Make PUBLIC_URL_DETECTION default to "auto" (#36955)
Breaking — from the release blog
Introduce "config edit-ini" sub command to help maintaining INI config file (#35735)
The standalone environment-to-ini tool was removed and a sub command of gitea has been introduced. If you need to re-create the configuration file with only a subset of keys, you can provide an INI template file and use the "--config-keep-keys" flag.
Correct Swagger annotations for enums, status codes, and notification state (#37030)
The generated OpenAPI description is now aligned with the actual API: enum values, HTTP status codes, and notification state are documented more accurately. If you rely on the published Swagger spec for code generation or contract tests, regenerate clients and re-check any assumptions about optional fields or response shapes.
Thank you to @myers for contributing this change.
Remove GET API registration-token (#36801)
The GET endpoint used to retrieve a registration token has been removed. Automation that still calls it needs to be updated to the supported registration flow for your deployment.
Thank you to @lunny for contributing this change.
Support Actions concurrency syntax (#32751)
Workflows can now use GitHub-style concurrency groups so that new runs cancel or queue relative to in-progress jobs. That changes runtime behavior compared with earlier releases, so review existing workflows after upgrading—especially long-running or overlapping pipelines.
Thank you to @Zettat123 for contributing this feature.
Make PUBLIC_URL_DETECTION default to auto (#36955)
New installations now default to automatic public URL detection. If you depend on a specific explicit URL configuration behind reverse proxies or alternate hostnames, confirm your [server] settings after upgrade so links, webhooks, and redirects still match your environment.
Thank you to @wxiaoguang for contributing this change.
1.26.1 – 1.26.2: no action items (2 versions)
1.26.3 2026-06-20
Warning
Please upgrade to 1.26.4 directly. A regression in this release can cause "context deadline exceeded" errors when opening any repository's code pages (#38177). Please hold off on upgrading until a fix is released.
Breaking
- fix(actions)!: require merged PR to bypass fork PR approval gate (#38010) (#38041)
Breaking — from the release blog
This release tightens the fork pull request approval gate: a pull request from a fork must now be merged before it can bypass the approval gate (#38041). Review your workflow approval settings if you rely on the previous behavior.
1.26.4: no action items (1 version)
1.27.0 2026-07-13
Breaking
- Feat(actions)!: improve support for reusable workflows (#37478)
- Use Content-Security-Policy: script nonce (#37232)
Breaking — from the release blog
Move release artifact signing to sigstore (#38250)
Gitea release artifacts are now signed with sigstore instead of the previous GPG flow. If you verify downloaded binaries or Docker images as part of your deployment pipeline, update your verification step to the sigstore-based process.
Thank you to @TheFox0x7 for contributing this change.
Improve support for reusable workflows (#37478)
Reusable workflows referenced with uses: are now parsed on the Gitea side rather than on the runner. Each called (child) job is inserted as its own ActionRunJob and dispatched as an independent task, so callee logs surface as separate job entries instead of being inlined into the caller's "Set up job" step. Review workflows that rely on reusable-workflow behavior after upgrading.
External reusable workflows (uses: https://other-gitea-instance/OWNER/REPO/.gitea/workflows/test.yaml@REF) are no longer supported. To keep using them, clone the repositories to the local instance and reference them there.
Thank you to @Zettat123 for contributing this change.
Use a Content-Security-Policy script nonce (#37232)
Inline scripts are now allowed via a per-request CSP nonce instead of a broader policy. Custom templates, themes, or embeds that inject inline <script> tags may stop executing until they are updated to carry the nonce. Review custom front-end customizations after upgrading.
Thank you to @wxiaoguang for contributing this change.
X-Content-Type-Options: nosniff is now sent by default (#37354)
All responses now include the X-Content-Type-Options: nosniff header, which stops browsers from MIME-sniffing responses away from their declared Content-Type. If a reverse proxy, embed, or custom asset relied on content sniffing, set X_CONTENT_TYPE_OPTIONS = unset under [security] to remove the header, or override its value as needed.
Thank you to @SAY-5 for contributing this change.
1.27.1 – 1.27.3: no action items (3 versions)
Release notes from github.com/go-gitea/gitea/releases, and the official release blog, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else.