← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Gitea 28.0 Released, Drops 1.x Prefix, Adds Audit Logging and Bot Accounts

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Gitea 28.0 removes the 1.x version prefix.
  • New features include audit logging and bot accounts.
  • Security fixes are included; details to follow.
  • Git network operations now use an internal proxy.

Version Numbering Change and Key Features

Gitea has released version 28.0.0, marking a change in its versioning scheme by dropping the historical "1." prefix. This release introduces several new functionalities, including comprehensive audit logging, support for bot accounts, and the ability to use HTTPS deploy tokens.

Other notable additions are user impersonation capabilities for administrators, code-owner approval rules for pull requests, diff file filters, and an improved Actions queue view. The full list of changes is available in the changelog.

Security Updates and Upgrade Considerations

Version 28.0.0 contains security fixes. Specific details regarding these fixes will be published approximately one week after the release to allow users time to upgrade their installations. Users are advised to review the breaking changes and back up their data before upgrading.

The upgrade process involves replacing the Gitea binary or Docker container and restarting the service. Release binaries no longer support 32-bit x86 or gogit builds, and the Snap package is no longer built for armhf. Download file names have also changed, removing the OS version suffix.

Changes to Git Network Operations and Egress Rules

A significant change in Gitea 28.0 is that Git network operations, such as migrations and mirrors, now route through an internal proxy. This proxy applies new egress settings, requiring administrators to review and potentially adjust their allow and block lists before upgrading.

The "external" preset has been removed. For a deny-by-default policy, users must set EGRESS_MODE = strict and explicitly list allowed hosts. In strict mode, entries without a port only permit ports 80 and 443. The default "lax" mode no longer restricts public hosts via ALLOWED_HOST_LIST unless EGRESS_MODE is set to strict. IP address entries no longer accept wildcards, and domain entries now follow curl syntax.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Gitea has released version 28.0, removing the historical 1.x version prefix and introducing new features like audit logging, bot accounts, and HTTPS deploy tokens. This update also includes security fixes and changes to Git network operation egress rules, requiring administrators to review their allow and block lists.