Gitea 28.0
First reported by Blog.gitea ·
Gitea now requires review of network egress rules for Git operations, potentially blocking existing migrations and mirrors.
Gitea has released version 28.0.0, marking a transition by dropping the traditional '1.' prefix from its version numbers. This update introduces several key features including enhanced audit logging for security-relevant events, dedicated bot accounts for automation, and HTTPS deploy tokens for repository access. Administrators gain new capabilities such as user impersonation for troubleshooting and a more comprehensive view of actions workflows. Significant changes also affect Git network operations with a new internal proxy and egress rules, requiring users to review their allow and block lists. Additionally, completed Actions runs will now expire after 400 days by default, and Gitea now mandates Git version 2.25 or newer. Self-registration is disabled by default, and the server domain configuration has been updated. The release also refines pull request diffs with search and filtering, introduces code-owner approval rules for merges, and allows more granular control over repository notification preferences.
The introduction of an internal proxy for Git network operations, along with new egress rules, signifies a more robust security posture for Gitea instances. This change necessitates a review of existing configurations, particularly for CI/CD pipelines relying on mirrors or migrations, as outdated allow/block lists could lead to failures. The shift towards stricter egress control, including the deprecation of certain configuration directives in favor of host lists, indicates a move towards more explicit and secure network management within the platform.
Furthermore, the enhanced audit logging and dedicated bot accounts point to Gitea's maturation as an enterprise-grade solution, catering to organizations with stringent compliance and automation requirements. The expiration of Actions run history by default also addresses storage concerns and aligns with best practices for data lifecycle management in self-hosted environments. These developments collectively suggest Gitea is actively addressing the needs of larger deployments by bolstering security, management, and operational efficiency.
AI-written summary. May contain errors.