From 5a96cc454a2e49d4d607401dc68264b16af133b2 Mon Sep 17 00:00:00 2001 From: bircni Date: Tue, 29 Sep 2026 21:06:21 +0200 Subject: [PATCH] docs: Add changelog for 28.0.0 (#39474) --- CHANGELOG.md | 251 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 251 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 70b0998d872..f872f317381 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,257 @@ This changelog goes through the changes that have been made in each release without substantial changes to our git log; to see the highlights of what has been added to each release, please refer to the [blog](https://blog.gitea.com). +## 28.0.0 - 2026-09-30 + +* BREAKING + * Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#39426](https://github.com/go-gitea/gitea/pull/39426)) + * Feat(actions)!: add RUN_RETENTION_DAYS to delete old action runs ([#38855](https://github.com/go-gitea/gitea/pull/38855)) + +* SECURITY + * Fix(git): reject invalid and duplicate Git objects on push ([#39472](https://github.com/go-gitea/gitea/pull/39472)) + * Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#39426](https://github.com/go-gitea/gitea/pull/39426)) + * Fix(ssh): identify presented public keys by fingerprint ([#39423](https://github.com/go-gitea/gitea/pull/39423)) + * Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#39399](https://github.com/go-gitea/gitea/pull/39399)) + * Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#39219](https://github.com/go-gitea/gitea/pull/39219)) + * Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#39063](https://github.com/go-gitea/gitea/pull/39063)) + +* FEATURES + * Feat(actions): update actionslib, support `self:`, misc fixes ([#39358](https://github.com/go-gitea/gitea/pull/39358)) + * Feat(api): list all packages for site administrators ([#38968](https://github.com/go-gitea/gitea/pull/38968)) + * Feat: manage bot accounts from the admin UI, API and CLI ([#38966](https://github.com/go-gitea/gitea/pull/38966)) + * Feat(user): Personal access tokens can be regenerated ([#38907](https://github.com/go-gitea/gitea/pull/38907)) + * Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#38822](https://github.com/go-gitea/gitea/pull/38822)) + * Feat(actions): add force-cancel workflow run API ([#38756](https://github.com/go-gitea/gitea/pull/38756)) + * Feat(licenses): support REUSE specification in licenses ([#38720](https://github.com/go-gitea/gitea/pull/38720)) + * Feat(api): add project APIs ([#38691](https://github.com/go-gitea/gitea/pull/38691)) + * Feat(webhook): fire repository event on repo rename ([#38641](https://github.com/go-gitea/gitea/pull/38641)) + * Feat: admin impersonates a user ([#38614](https://github.com/go-gitea/gitea/pull/38614)) + * Feat(actions): add build queue view ([#38585](https://github.com/go-gitea/gitea/pull/38585)) + * Feat(setting): add shared [redis] section as default for redis-backed subsystems ([#38550](https://github.com/go-gitea/gitea/pull/38550)) + * Feat(repo): prioritize well-known READMEs and optimize discovery ([#38532](https://github.com/go-gitea/gitea/pull/38532)) + * Feat(actions): implement adaptive auto-refresh for workflow runs list ([#38329](https://github.com/go-gitea/gitea/pull/38329)) + * Feat(auth): add `disable-2fa` command ([#38275](https://github.com/go-gitea/gitea/pull/38275)) + * Feat: Add audit logging ([#38189](https://github.com/go-gitea/gitea/pull/38189)) + * Feat(repo): add quick repository switcher to repo header ([#38188](https://github.com/go-gitea/gitea/pull/38188)) + * Feat(repo): support file exclusion logic in .gitea/template in template generation ([#38064](https://github.com/go-gitea/gitea/pull/38064)) + * Feat(web): Add org removal functionality to admin user details page ([#38013](https://github.com/go-gitea/gitea/pull/38013)) + * Feat: add watch options ([#37571](https://github.com/go-gitea/gitea/pull/37571)) + * Feat: add deploy tokens ([#37306](https://github.com/go-gitea/gitea/pull/37306)) + * Feat(diff): Add search and extension filter to diff sidebar ([#37068](https://github.com/go-gitea/gitea/pull/37068)) + * Feat: Replace SSE with WebSocket for UI notifications ([#36965](https://github.com/go-gitea/gitea/pull/36965)) + * Feat(actions): Add artifact preview in Actions run view ([#36754](https://github.com/go-gitea/gitea/pull/36754)) + * Feat(packages): add support for uploading helm provenance files ([#36695](https://github.com/go-gitea/gitea/pull/36695)) + * Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#36564](https://github.com/go-gitea/gitea/pull/36564)) + * Feat: Add max-parallel Support for Gitea Actions ([#36357](https://github.com/go-gitea/gitea/pull/36357)) + * Feat(actions): Add Actions API endpoints for workflow run management and logs ([#35382](https://github.com/go-gitea/gitea/pull/35382)) + * Feat: Add block on pending codeowner reviews branch protection ([#34995](https://github.com/go-gitea/gitea/pull/34995)) + +* ENHANCEMENTS + * Enhance: allow auto-closing PRs from PRs ([#39393](https://github.com/go-gitea/gitea/pull/39393)) + * Enhance(actions): add pending job status and align job statuses with GitHub ([#39376](https://github.com/go-gitea/gitea/pull/39376)) + * Enhance(acme): add configurable ACME profile ([#39375](https://github.com/go-gitea/gitea/pull/39375)) + * Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#39363](https://github.com/go-gitea/gitea/pull/39363)) + * Enhance: improve issue-pattern capture groups and support both internal&external trackers enabled ([#39354](https://github.com/go-gitea/gitea/pull/39354)) + * Enhance: update mermaid to v12 ([#39331](https://github.com/go-gitea/gitea/pull/39331)) + * Enhance(notifications): mark current notification page as read ([#39294](https://github.com/go-gitea/gitea/pull/39294)) + * Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#39289](https://github.com/go-gitea/gitea/pull/39289)) + * Enhance: truncate but show long lines in diffs ([#39279](https://github.com/go-gitea/gitea/pull/39279)) + * Enhance(packages): implement npm single-version API and add per-version repository ([#39267](https://github.com/go-gitea/gitea/pull/39267)) + * Enhance: move window.config to JSON, improve CSP format ([#39236](https://github.com/go-gitea/gitea/pull/39236)) + * Enhance: improve commit page header ([#39229](https://github.com/go-gitea/gitea/pull/39229)) + * Enhance: Improve validation errors for secrets/variables ([#39221](https://github.com/go-gitea/gitea/pull/39221)) + * Enhance(repo): check full repo name for dangerous operations ([#39213](https://github.com/go-gitea/gitea/pull/39213)) + * Enhance(web): hide attachment dropzone on preview tab in combo editor ([#39204](https://github.com/go-gitea/gitea/pull/39204)) + * Enhance(web): show attachment URL and UUID in dropzone preview ([#39203](https://github.com/go-gitea/gitea/pull/39203)) + * Enhance(actions): make workflow dispatch choice dropdown support search ([#39154](https://github.com/go-gitea/gitea/pull/39154)) + * Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#39134](https://github.com/go-gitea/gitea/pull/39134)) + * Enhance: use browser's locale to detect week's first day for the contribution map ([#38995](https://github.com/go-gitea/gitea/pull/38995)) + * Enhance(ui): forced colors mode enhancements ([#38991](https://github.com/go-gitea/gitea/pull/38991)) + * Enhance: user-friendly packages setup manual ([#38946](https://github.com/go-gitea/gitea/pull/38946)) + * Enhance: inherit team access for all units ([#38938](https://github.com/go-gitea/gitea/pull/38938)) + * Enhance(admin): show impersonation banner and keep password change with the user ([#38924](https://github.com/go-gitea/gitea/pull/38924)) + * Enhance(ui): tint toast backgrounds by level ([#38919](https://github.com/go-gitea/gitea/pull/38919)) + * Enhance(repo): add default object format setting ([#38877](https://github.com/go-gitea/gitea/pull/38877)) + * Enhance(actions): set ref_protected in context ([#38852](https://github.com/go-gitea/gitea/pull/38852)) + * Enhance(ui): restyle toasts ([#38842](https://github.com/go-gitea/gitea/pull/38842)) + * Enhance: refine repo watching ([#38835](https://github.com/go-gitea/gitea/pull/38835)) + * Enhance: fall back to DEFAULT_TEMPLATE.md when style-specific template is missing ([#38803](https://github.com/go-gitea/gitea/pull/38803)) + * Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#38770](https://github.com/go-gitea/gitea/pull/38770)) + * Enhance(api): expose file mode in contents API response ([#38713](https://github.com/go-gitea/gitea/pull/38713)) + * Enhance(tls): use go's tls defaults ([#38687](https://github.com/go-gitea/gitea/pull/38687)) + * Enhance(ui): improve luminance calculations ([#38682](https://github.com/go-gitea/gitea/pull/38682)) + * Enhance(api): add `tag_filter` query parameter to release list API ([#38681](https://github.com/go-gitea/gitea/pull/38681)) + * Enhance(actions): replace `ansi_up` with first-party code ([#38619](https://github.com/go-gitea/gitea/pull/38619)) + * Enhance: keep status check list scrolled on merge box reload ([#38597](https://github.com/go-gitea/gitea/pull/38597)) + * Enhance(actions): action view enhancements ([#38594](https://github.com/go-gitea/gitea/pull/38594)) + * Enhance(ui): tweak tooltip style and misc fixes ([#38524](https://github.com/go-gitea/gitea/pull/38524)) + * Enhance: improve e-mail templates ([#38396](https://github.com/go-gitea/gitea/pull/38396)) + * Enhance(webhook): add reviewer name to MS Teams review request notifications ([#38289](https://github.com/go-gitea/gitea/pull/38289)) + * Enhance: extend