# Changelog This changelog goes through the changes that have been made in each release without substantial changes to our git log; to see the highlights of what has been added to each release, please refer to the [blog](https://blog.gitea.com). ## 28.0.0 - 2026-09-30 * BREAKING * Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#39426](https://github.com/go-gitea/gitea/pull/39426)) * Feat(actions)!: add RUN_RETENTION_DAYS to delete old action runs ([#38855](https://github.com/go-gitea/gitea/pull/38855)) * SECURITY * Fix(git): reject invalid and duplicate Git objects on push ([#39472](https://github.com/go-gitea/gitea/pull/39472)) * Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#39426](https://github.com/go-gitea/gitea/pull/39426)) * Fix(ssh): identify presented public keys by fingerprint ([#39423](https://github.com/go-gitea/gitea/pull/39423)) * Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#39399](https://github.com/go-gitea/gitea/pull/39399)) * Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#39219](https://github.com/go-gitea/gitea/pull/39219)) * Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#39063](https://github.com/go-gitea/gitea/pull/39063)) * FEATURES * Feat(actions): update actionslib, support `self:`, misc fixes ([#39358](https://github.com/go-gitea/gitea/pull/39358)) * Feat(api): list all packages for site administrators ([#38968](https://github.com/go-gitea/gitea/pull/38968)) * Feat: manage bot accounts from the admin UI, API and CLI ([#38966](https://github.com/go-gitea/gitea/pull/38966)) * Feat(user): Personal access tokens can be regenerated ([#38907](https://github.com/go-gitea/gitea/pull/38907)) * Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#38822](https://github.com/go-gitea/gitea/pull/38822)) * Feat(actions): add force-cancel workflow run API ([#38756](https://github.com/go-gitea/gitea/pull/38756)) * Feat(licenses): support REUSE specification in licenses ([#38720](https://github.com/go-gitea/gitea/pull/38720)) * Feat(api): add project APIs ([#38691](https://github.com/go-gitea/gitea/pull/38691)) * Feat(webhook): fire repository event on repo rename ([#38641](https://github.com/go-gitea/gitea/pull/38641)) * Feat: admin impersonates a user ([#38614](https://github.com/go-gitea/gitea/pull/38614)) * Feat(actions): add build queue view ([#38585](https://github.com/go-gitea/gitea/pull/38585)) * Feat(setting): add shared [redis] section as default for redis-backed subsystems ([#38550](https://github.com/go-gitea/gitea/pull/38550)) * Feat(repo): prioritize well-known READMEs and optimize discovery ([#38532](https://github.com/go-gitea/gitea/pull/38532)) * Feat(actions): implement adaptive auto-refresh for workflow runs list ([#38329](https://github.com/go-gitea/gitea/pull/38329)) * Feat(auth): add `disable-2fa` command ([#38275](https://github.com/go-gitea/gitea/pull/38275)) * Feat: Add audit logging ([#38189](https://github.com/go-gitea/gitea/pull/38189)) * Feat(repo): add quick repository switcher to repo header ([#38188](https://github.com/go-gitea/gitea/pull/38188)) * Feat(repo): support file exclusion logic in .gitea/template in template generation ([#38064](https://github.com/go-gitea/gitea/pull/38064)) * Feat(web): Add org removal functionality to admin user details page ([#38013](https://github.com/go-gitea/gitea/pull/38013)) * Feat: add watch options ([#37571](https://github.com/go-gitea/gitea/pull/37571)) * Feat: add deploy tokens ([#37306](https://github.com/go-gitea/gitea/pull/37306)) * Feat(diff): Add search and extension filter to diff sidebar ([#37068](https://github.com/go-gitea/gitea/pull/37068)) * Feat: Replace SSE with WebSocket for UI notifications ([#36965](https://github.com/go-gitea/gitea/pull/36965)) * Feat(actions): Add artifact preview in Actions run view ([#36754](https://github.com/go-gitea/gitea/pull/36754)) * Feat(packages): add support for uploading helm provenance files ([#36695](https://github.com/go-gitea/gitea/pull/36695)) * Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#36564](https://github.com/go-gitea/gitea/pull/36564)) * Feat: Add max-parallel Support for Gitea Actions ([#36357](https://github.com/go-gitea/gitea/pull/36357)) * Feat(actions): Add Actions API endpoints for workflow run management and logs ([#35382](https://github.com/go-gitea/gitea/pull/35382)) * Feat: Add block on pending codeowner reviews branch protection ([#34995](https://github.com/go-gitea/gitea/pull/34995)) * ENHANCEMENTS * Enhance: allow auto-closing PRs from PRs ([#39393](https://github.com/go-gitea/gitea/pull/39393)) * Enhance(actions): add pending job status and align job statuses with GitHub ([#39376](https://github.com/go-gitea/gitea/pull/39376)) * Enhance(acme): add configurable ACME profile ([#39375](https://github.com/go-gitea/gitea/pull/39375)) * Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#39363](https://github.com/go-gitea/gitea/pull/39363)) * Enhance: improve issue-pattern capture groups and support both internal&external trackers enabled ([#39354](https://github.com/go-gitea/gitea/pull/39354)) * Enhance: update mermaid to v12 ([#39331](https://github.com/go-gitea/gitea/pull/39331)) * Enhance(notifications): mark current notification page as read ([#39294](https://github.com/go-gitea/gitea/pull/39294)) * Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#39289](https://github.com/go-gitea/gitea/pull/39289)) * Enhance: truncate but show long lines in diffs ([#39279](https://github.com/go-gitea/gitea/pull/39279)) * Enhance(packages): implement npm single-version API and add per-version repository ([#39267](https://github.com/go-gitea/gitea/pull/39267)) * Enhance: move window.config to JSON, improve CSP format ([#39236](https://github.com/go-gitea/gitea/pull/39236)) * Enhance: improve commit page header ([#39229](https://github.com/go-gitea/gitea/pull/39229)) * Enhance: Improve validation errors for secrets/variables ([#39221](https://github.com/go-gitea/gitea/pull/39221)) * Enhance(repo): check full repo name for dangerous operations ([#39213](https://github.com/go-gitea/gitea/pull/39213)) * Enhance(web): hide attachment dropzone on preview tab in combo editor ([#39204](https://github.com/go-gitea/gitea/pull/39204)) * Enhance(web): show attachment URL and UUID in dropzone preview ([#39203](https://github.com/go-gitea/gitea/pull/39203)) * Enhance(actions): make workflow dispatch choice dropdown support search ([#39154](https://github.com/go-gitea/gitea/pull/39154)) * Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#39134](https://github.com/go-gitea/gitea/pull/39134)) * Enhance: use browser's locale to detect week's first day for the contribution map ([#38995](https://github.com/go-gitea/gitea/pull/38995)) * Enhance(ui): forced colors mode enhancements ([#38991](https://github.com/go-gitea/gitea/pull/38991)) * Enhance: user-friendly packages setup manual ([#38946](https://github.com/go-gitea/gitea/pull/38946)) * Enhance: inherit team access for all units ([#38938](https://github.com/go-gitea/gitea/pull/38938)) * Enhance(admin): show impersonation banner and keep password change with the user ([#38924](https://github.com/go-gitea/gitea/pull/38924)) * Enhance(ui): tint toast backgrounds by level ([#38919](https://github.com/go-gitea/gitea/pull/38919)) * Enhance(repo): add default object format setting ([#38877](https://github.com/go-gitea/gitea/pull/38877)) * Enhance(actions): set ref_protected in context ([#38852](https://github.com/go-gitea/gitea/pull/38852)) * Enhance(ui): restyle toasts ([#38842](https://github.com/go-gitea/gitea/pull/38842)) * Enhance: refine repo watching ([#38835](https://github.com/go-gitea/gitea/pull/38835)) * Enhance: fall back to DEFAULT_TEMPLATE.md when style-specific template is missing ([#38803](https://github.com/go-gitea/gitea/pull/38803)) * Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#38770](https://github.com/go-gitea/gitea/pull/38770)) * Enhance(api): expose file mode in contents API response ([#38713](https://github.com/go-gitea/gitea/pull/38713)) * Enhance(tls): use go's tls defaults ([#38687](https://github.com/go-gitea/gitea/pull/38687)) * Enhance(ui): improve luminance calculations ([#38682](https://github.com/go-gitea/gitea/pull/38682)) * Enhance(api): add `tag_filter` query parameter to release list API ([#38681](https://github.com/go-gitea/gitea/pull/38681)) * Enhance(actions): replace `ansi_up` with first-party code ([#38619](https://github.com/go-gitea/gitea/pull/38619)) * Enhance: keep status check list scrolled on merge box reload ([#38597](https://github.com/go-gitea/gitea/pull/38597)) * Enhance(actions): action view enhancements ([#38594](https://github.com/go-gitea/gitea/pull/38594)) * Enhance(ui): tweak tooltip style and misc fixes ([#38524](https://github.com/go-gitea/gitea/pull/38524)) * Enhance: improve e-mail templates ([#38396](https://github.com/go-gitea/gitea/pull/38396)) * Enhance(webhook): add reviewer name to MS Teams review request notifications ([#38289](https://github.com/go-gitea/gitea/pull/38289)) * Enhance: extend