Gitea has released version 28.0.0, dropping the historical 1. prefix. This major update introduces audit logging, bot accounts, HTTPS deploy tokens, user impersonation for administrators, code-owner approval rules, diff file filters, and an Actions queue view. The release also includes security fixes, with details to be published approximately one week post-launch to allow time for upgrades.
Major breaking changes include Git network operations now routing through an internal proxy with new egress rules. The external preset is removed; users must set EGRESS_MODE = strict for deny-by-default policies. In strict mode, entries without a port only allow ports 80 and 443. IP address entries no longer accept wildcards, and domain entries follow curl syntax. Deprecated settings include ALLOWED_DOMAINS, BLOCKED_DOMAINS, and ALLOW_LOCALNET WORKS, replaced by ALLOWED_HOST_LIST and BLOCKED_HOST_LIST.
Completed Actions runs are now deleted after 400 days by default, with logs and artifacts removed alongside. Gitea now refuses to start with Git versions older than 2.25.0. Self-registration is disabled by default unless explicitly enabled via [service] DISABLE_REGISTRATION = false. The [server] DOMAIN setting is ignored; the instance domain now derives from ROOT_URL. Job-level if: conditions are evaluated before matrix expansion and may only reference github, gitea, or inputs contexts.
Source: Hacker News · Summarized by HeadlinesBriefing