Renovate demo โ€” live dependency-update PRs

A fresh Gitea instance and Renovate bot ran in GitHub Actions (bash Renovate/scripts/demo.sh, minus the Jenkins step) against this repository's actual dependencies. Every pull request, label, and diff below is real output from that run โ€” not a mock-up โ€” captured before the ephemeral Gitea instance was torn down. Generated 2026-08-14 09:52 UTC.

Pull requests opened

Total
10
๐Ÿ”ด Security
0
๐ŸŸก Major
0
๐ŸŸข Docker digest
0
๐Ÿ”ต Spring Boot
0

How Renovate is configured

Pull requests

โšช Dependency update #1

Pin dependencies

renovate/pin-dependencies โ†’ main opened 2026-08-14 09:52 UTC +54 -54 ยท 25 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| azul/zulu-openjdk | stage | pinDigest |  โ†’ `dd0fb36` |
| [debian](https://hub.docker.com/_/debian) ([source](https://github.com/debuerreotype/docker-debian-artifacts)) | final | pinDigest |  โ†’ `3a39a05` |
| [debian](https://hub.docker.com/_/debian) ([source](https://github.com/debuerreotype/docker-debian-artifacts)) | stage | pinDigest |  โ†’ `3a39a05` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://github.com/adoptium/containers)) | final | pinDigest |  โ†’ `a214efa` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://github.com/adoptium/containers)) | stage | pinDigest |  โ†’ `c42fecf` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://github.com/adoptium/containers)) | final | pinDigest |  โ†’ `e8acde9` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://github.com/adoptium/containers)) | final | pinDigest |  โ†’ `c42fecf` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://github.com/adoptium/containers)) | final | pinDigest |  โ†’ `f9b2951` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://github.com/adoptium/containers)) | final | pinDigest |  โ†’ `3f08b13` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://github.com/adoptium/containers)) | stage | pinDigest |  โ†’ `1ff7630` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://github.com/adoptium/containers)) | stage | pinDigest |  โ†’ `3f08b13` |
| gcr.io/distroless/base-debian13 | final | pinDigest |  โ†’ `f4a335c` |
| gcr.io/distroless/static-debian13 | final | pinDigest |  โ†’ `9197324` |
| ghcr.io/graalvm/native-image-community | final | pinDigest |  โ†’ `7187b4a` |
| ghcr.io/graalvm/native-image-community | stage | pinDigest |  โ†’ `7187b4a` |
| [gitea/gitea](https://github.com/go-gitea/gitea) |  | pinDigest |  โ†’ `76f516a` |
| jenkins/jenkins | final | pinDigest |  โ†’ `69bc8e2` |
| [maven](https://hub.docker.com/_/maven) ([source](https://github.com/carlossg/docker-maven)) | stage | pinDigest |  โ†’ `4015718` |
| [maven](https://hub.docker.com/_/maven) ([source](https://github.com/carlossg/docker-maven)) | stage | pinDigest |  โ†’ `c07f7cc` |
| [maven](https://hub.docker.com/_/maven) ([source](https://github.com/carlossg/docker-maven)) | stage | pinDigest |  โ†’ `1b1fc6d` |
| nginx | final | pinDigest |  โ†’ `4a73073` |
| [openjdk](https://hub.docker.com/_/openjdk) ([source](https://github.com/docker-library/openjdk)) | final | pinDigest |  โ†’ `1b92d43` |
| [openjdk](https://hub.docker.com/_/openjdk) ([source](https://github.com/docker-library/openjdk)) | stage | pinDigest |  โ†’ `1b92d43` |

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Enabled.

โ™ป **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

๐Ÿ‘ป **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZG9ja2VyIiwicmVub3ZhdGUiXX0=-->
Build Docker Images/Dockerfile.crac-azul-distroless-base+3 -3
@@ -35,7 +35,7 @@
# โ”€โ”€ Stage 1: Maven build โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
# Pin to a specific digest after first pull (see pull-base-images.sh).
-FROM azul/zulu-openjdk:25-jdk-crac AS builder
+FROM azul/zulu-openjdk:25-jdk-crac@sha256:dd0fb366addc01d5bbef00b7c7429177228f807d63908d60aabd71ea8883f4fe AS builder
WORKDIR /workspace
COPY mvnw mvnw
@@ -62,7 +62,7 @@ RUN ./mvnw package -DskipTests --no-transfer-progress
# โ”€โ”€ Stage 2: jlink โ€“ minimal CRaC-capable JRE โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
# Using the Azul Zulu CRaC JDK ensures the jlink output JRE contains the
# CRaC-patched JVM binary required for checkpoint and restore.
-FROM azul/zulu-openjdk:25-jdk-crac AS jre-builder
+FROM azul/zulu-openjdk:25-jdk-crac@sha256:dd0fb366addc01d5bbef00b7c7429177228f807d63908d60aabd71ea8883f4fe AS jre-builder
WORKDIR /jlink-workspace
COPY --from=builder /workspace/target/HelloConference-0.0.1-SNAPSHOT.jar app.jar
@@ -124,7 +124,7 @@ RUN LIBZ=$(ldconfig -p 2>/dev/null | awk '/libz\.so\.1 /{print $NF; exit}') && \
# build-crac-azul-distroless-base.sh runs this image with --privileged to create
# the checkpoint, then docker commit bakes the checkpoint directory into the
# final image.
-FROM gcr.io/distroless/base-debian13
+FROM gcr.io/distroless/base-debian13@sha256:f4a335ca209e1d2ee873102c17c389ad0142e3d5b21aee2817e9cc9c01d87d20
ENV JAVA_HOME=/jre
ENV PATH="/jre/bin:${PATH}"
Build Docker Images/Dockerfile.jlink-cds-distroless-base+4 -4
@@ -41,7 +41,7 @@
# โš  spring.context.exit=onRefresh requires Spring Boot 3.2+.
# โ”€โ”€ Stage 1: Maven build โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:25-jdk AS builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS builder
WORKDIR /workspace
COPY mvnw mvnw
@@ -53,7 +53,7 @@ COPY src src
RUN ./mvnw package -DskipTests --no-transfer-progress
# โ”€โ”€ Stage 2: jlink โ€“ tightly scoped minimal JRE โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:25-jdk AS jre-builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS jre-builder
WORKDIR /jlink-workspace
COPY --from=builder /workspace/target/HelloConference-0.0.1-SNAPSHOT.jar app.jar
@@ -113,7 +113,7 @@ RUN /jre-minimal/bin/java -Xshare:dump 2>&1 | tail -5 && \
# archive is written to disk.
# The exact same JRE binary (/jre-minimal/bin/java) is used here and at
# runtime so the archive is guaranteed compatible.
-FROM debian:13-slim AS cds-builder
+FROM debian:13-slim@sha256:3a39a0592364683e6bab97937b72cad5a8fa6dcbbee90edb3bb48c7f8e94f258 AS cds-builder
COPY --from=jre-builder /jre-minimal /jre
COPY --from=builder /workspace/target/HelloConference-0.0.1-SNAPSHOT.jar /app/app.jar
WORKDIR /app
@@ -126,7 +126,7 @@ RUN /jre/bin/java \
|| { echo "โŒ CDS archive not created"; exit 1; }
# โ”€โ”€ Stage 4: distroless runtime โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM gcr.io/distroless/base-debian13
+FROM gcr.io/distroless/base-debian13@sha256:f4a335ca209e1d2ee873102c17c389ad0142e3d5b21aee2817e9cc9c01d87d20
ENV JAVA_HOME=/jre
ENV PATH="/jre/bin:${PATH}"
Build Docker Images/Dockerfile.jlink-distroless-base+3 -3
@@ -2,7 +2,7 @@
# jlink JRE is glibc-linked (Temurin) โ†’ needs glibc โ†’ distroless/base, not static
# โ”€โ”€ Stage 1: Maven build โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:25-jdk AS builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS builder
WORKDIR /workspace
COPY mvnw mvnw
@@ -14,7 +14,7 @@ COPY src src
RUN ./mvnw package -DskipTests --no-transfer-progress
# โ”€โ”€ Stage 2: jlink โ€“ minimal JRE scoped to app deps โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:25-jdk AS jre-builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS jre-builder
WORKDIR /jlink-workspace
COPY --from=builder /workspace/target/HelloConference-0.0.1-SNAPSHOT.jar app.jar
@@ -44,7 +44,7 @@ RUN set -eux; \
--output /jre-minimal
# โ”€โ”€ Stage 3: distroless runtime โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM gcr.io/distroless/base-debian13
+FROM gcr.io/distroless/base-debian13@sha256:f4a335ca209e1d2ee873102c17c389ad0142e3d5b21aee2817e9cc9c01d87d20
ENV JAVA_HOME=/jre
ENV PATH="/jre/bin:${PATH}"
Build Docker Images/Dockerfile.jlink-full-distroless-base+3 -3
@@ -2,7 +2,7 @@
# jlink JRE is glibc-linked (Temurin) โ†’ needs glibc โ†’ distroless/base, not static
# โ”€โ”€ Stage 1: Maven build โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:25-jdk AS builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS builder
WORKDIR /workspace
COPY mvnw mvnw
@@ -14,7 +14,7 @@ COPY src src
RUN ./mvnw package -DskipTests --no-transfer-progress
# โ”€โ”€ Stage 2: jlink โ€“ full JRE (all modules except jlink/jpackage) โ”€
-FROM eclipse-temurin:25-jdk AS jre-builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS jre-builder
RUN MODULES=$(java --list-modules | sed 's/@.*//' | \
grep -vE '^jdk\.(jlink|jpackage)$' | \
@@ -29,7 +29,7 @@ RUN MODULES=$(java --list-modules | sed 's/@.*//' | \
--output /jre-full
# โ”€โ”€ Stage 3: distroless runtime โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM gcr.io/distroless/base-debian13
+FROM gcr.io/distroless/base-debian13@sha256:f4a335ca209e1d2ee873102c17c389ad0142e3d5b21aee2817e9cc9c01d87d20
ENV JAVA_HOME=/jre
ENV PATH="/jre/bin:${PATH}"
Build Docker Images/Dockerfile.jlink-netty-distroless-base+3 -3
@@ -12,7 +12,7 @@
# The swap is done entirely inside the builder โ€“ pom.xml on the host is unchanged.
# โ”€โ”€ Stage 1: Maven build โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:25-jdk AS builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS builder
WORKDIR /workspace
COPY mvnw mvnw
@@ -36,7 +36,7 @@ RUN printf '\nspring.main.web-application-type=reactive\n' \
RUN ./mvnw package -DskipTests --no-transfer-progress
# โ”€โ”€ Stage 2: jlink โ€“ minimal JRE scoped to Netty/WebFlux deps โ”€
-FROM eclipse-temurin:25-jdk AS jre-builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS jre-builder
WORKDIR /jlink-workspace
COPY --from=builder /workspace/target/HelloConference-0.0.1-SNAPSHOT.jar app.jar
@@ -66,7 +66,7 @@ RUN set -eux; \
--output /jre-minimal
# โ”€โ”€ Stage 3: distroless runtime โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM gcr.io/distroless/base-debian13
+FROM gcr.io/distroless/base-debian13@sha256:f4a335ca209e1d2ee873102c17c389ad0142e3d5b21aee2817e9cc9c01d87d20
ENV JAVA_HOME=/jre
ENV PATH="/jre/bin:${PATH}"
Build Docker Images/Dockerfile.jlink-tuned-distroless-base+3 -3
@@ -30,7 +30,7 @@
# container environments (common in Kubernetes). Standard practice.
# โ”€โ”€ Stage 1: Maven build โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:25-jdk AS builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS builder
WORKDIR /workspace
COPY mvnw mvnw
@@ -42,7 +42,7 @@ COPY src src
RUN ./mvnw package -DskipTests --no-transfer-progress
# โ”€โ”€ Stage 2: jlink โ€“ tightly scoped minimal JRE โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:25-jdk AS jre-builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS jre-builder
WORKDIR /jlink-workspace
COPY --from=builder /workspace/target/HelloConference-0.0.1-SNAPSHOT.jar app.jar
@@ -86,7 +86,7 @@ RUN set -eux; \
--output /jre-minimal
# โ”€โ”€ Stage 3: distroless runtime โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM gcr.io/distroless/base-debian13
+FROM gcr.io/distroless/base-debian13@sha256:f4a335ca209e1d2ee873102c17c389ad0142e3d5b21aee2817e9cc9c01d87d20
ENV JAVA_HOME=/jre
ENV PATH="/jre/bin:${PATH}"
Build Docker Images/Dockerfile.jre-temurin+2 -2
@@ -1,5 +1,5 @@
# Runtime base: eclipse-temurin:25-jre (Temurin 25.0.3+9 / Ubuntu 26.04)
-FROM eclipse-temurin:25-jdk AS builder
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS builder
WORKDIR /workspace
COPY mvnw mvnw
@@ -10,7 +10,7 @@ RUN chmod +x mvnw && ./mvnw dependency:go-offline -q --no-transfer-progress 2>/d
COPY src src
RUN ./mvnw package -DskipTests --no-transfer-progress
-FROM eclipse-temurin:25-jre
+FROM eclipse-temurin:25-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
WORKDIR /app
COPY --from=builder /workspace/target/HelloConference-0.0.1-SNAPSHOT.jar app.jar
EXPOSE 8080
Build Docker Images/Dockerfile.native-debian-slim+2 -2
@@ -1,7 +1,7 @@
# Runtime base: debian:13-slim (Debian 13 Trixie)
# Native binary is dynamically linked against glibc + libz.so.1 (zlib).
# distroless/base-debian13 lacks zlib; distroless/static lacks glibc entirely.
-FROM ghcr.io/graalvm/native-image-community:25i2 AS builder
+FROM ghcr.io/graalvm/native-image-community:25i2@sha256:7187b4a37ebd4055f7a5fb518f9882ad6e25331862633991cbe007a1f43d739d AS builder
WORKDIR /workspace
RUN microdnf install -y findutils --setopt=install_weak_deps=0 && \
@@ -15,7 +15,7 @@ RUN chmod +x mvnw && ./mvnw dependency:go-offline -q --no-transfer-progress 2>/d
COPY src src
RUN ./mvnw -Pnative native:compile -DskipTests --no-transfer-progress
-FROM debian:13-slim
+FROM debian:13-slim@sha256:3a39a0592364683e6bab97937b72cad5a8fa6dcbbee90edb3bb48c7f8e94f258
WORKDIR /app
COPY --from=builder /workspace/target/HelloConference .
EXPOSE 8080
Build Docker Images/Dockerfile.native-minimal-distroless-static+2 -2
@@ -6,7 +6,7 @@
# image size on disk but significantly increases runtime memory usage.
# โš  First build: ~20 min (musl + zlib compiled from source + native compile).
# Docker caches every toolchain layer; reruns on source changes are fast.
-FROM ghcr.io/graalvm/native-image-community:25i2 AS toolchain
+FROM ghcr.io/graalvm/native-image-community:25i2@sha256:7187b4a37ebd4055f7a5fb518f9882ad6e25331862633991cbe007a1f43d739d AS toolchain
RUN microdnf install -y \
gcc make tar gzip curl findutils \
@@ -47,7 +47,7 @@ COPY src src
RUN NATIVE_IMAGE_OPTIONS="--static --libc=musl -Os" \
./mvnw -Pnative native:compile -DskipTests --no-transfer-progress
-FROM gcr.io/distroless/static-debian13
+FROM gcr.io/distroless/static-debian13@sha256:9197324ba51d9cd071af8505989365c006adf9d6d2067eada25aef00abbb5278
COPY --from=builder /workspace/target/HelloConference /HelloConference
EXPOSE 8080
ENTRYPOINT ["/HelloConference"]
Build Docker Images/Dockerfile.native-netty-scratch+1 -1
@@ -14,7 +14,7 @@
# โš  First build: ~20-25 min. Subsequent source-only rebuilds use cached layers.
# โ”€โ”€ Stage 1: toolchain (musl libc + static zlib) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM ghcr.io/graalvm/native-image-community:25i2 AS toolchain
+FROM ghcr.io/graalvm/native-image-community:25i2@sha256:7187b4a37ebd4055f7a5fb518f9882ad6e25331862633991cbe007a1f43d739d AS toolchain
RUN microdnf install -y \
gcc binutils make tar gzip curl findutils \
Build Docker Images/Dockerfile.native-scratch+1 -1
@@ -6,7 +6,7 @@
# โš  First build: ~20-25 min. Subsequent source-only rebuilds use cached layers.
# โ”€โ”€ Stage 1: toolchain (musl libc + static zlib) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM ghcr.io/graalvm/native-image-community:25i2 AS toolchain
+FROM ghcr.io/graalvm/native-image-community:25i2@sha256:7187b4a37ebd4055f7a5fb518f9882ad6e25331862633991cbe007a1f43d739d AS toolchain
RUN microdnf install -y \
gcc binutils make tar gzip curl findutils \
Callback Server/Dockerfile+2 -2
@@ -1,4 +1,4 @@
-FROM eclipse-temurin:25-jdk AS build
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS build
WORKDIR /build
COPY pom.xml .
COPY src src
@@ -10,7 +10,7 @@ RUN --mount=type=cache,target=/root/.m2 \
COPY exploit-class/ExploitPayload.java /exploit-class/
RUN javac -source 8 -target 8 /exploit-class/ExploitPayload.java
-FROM eclipse-temurin:25-jre
+FROM eclipse-temurin:25-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
WORKDIR /app
COPY --from=build /build/target/*.jar app.jar
# Serve the compiled exploit class via HTTP at /exploit/ExploitPayload.class
OWASP Dependency Check/docker/Dockerfile.nvd-cache+2 -2
@@ -18,7 +18,7 @@
# โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
# โ”€โ”€ Stage 1: download NVD data with vulnz โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:21-jre-alpine AS downloader
+FROM eclipse-temurin:21-jre-alpine@sha256:3f08b13888f595cc49edabea7250ba69499ba25602b267da591720769400e08c AS downloader
ARG VULNZ_VERSION=9.0.4
ARG NVD_API_KEY=""
@@ -50,7 +50,7 @@ RUN set -e; \
fi
# โ”€โ”€ Stage 2: serve with nginx โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM nginx:alpine
+FROM nginx:alpine@sha256:4a73073bd557c65b759505da037898b61f1be6cbcc3c2c3aeac22d2a470c1752
COPY --from=downloader /nvd-cache /usr/share/nginx/html
OpenRewrite/Dockerfile+2 -2
@@ -11,7 +11,7 @@
# bash scripts/run-image.sh # run on http://localhost:8080
# โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
# โ”€โ”€ Stage 1: Build โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:21-jdk-alpine AS builder
+FROM eclipse-temurin:21-jdk-alpine@sha256:1ff763083f2993d57d0bf374ab10bb3e2cb873af6c13a04458ebbd3e0337dc76 AS builder
WORKDIR /workspace
# Copy Maven wrapper and pom first so dependency layer is cached
COPY .mvn/ .mvn/
@@ -23,7 +23,7 @@ RUN ./mvnw -B dependency:go-offline -q
COPY src/ src/
RUN ./mvnw -B clean package -DskipTests -q
# โ”€โ”€ Stage 2: Runtime โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
-FROM eclipse-temurin:21-jre-alpine
+FROM eclipse-temurin:21-jre-alpine@sha256:3f08b13888f595cc49edabea7250ba69499ba25602b267da591720769400e08c
LABEL org.opencontainers.image.title="openrewrite-demo"
LABEL org.opencontainers.image.description="OpenRewrite migration demo โ€” Spring Boot + JUnit 4 before rewrite"
LABEL org.opencontainers.image.base.name="eclipse-temurin:21-jre-alpine"
Performance Improvement/Dockerfile.java17+2 -2
@@ -1,10 +1,10 @@
-FROM maven:3-eclipse-temurin-17 AS build
+FROM maven:3-eclipse-temurin-17@sha256:4015718012bbf1113ec6cfae2b950be328d90265ceb60f92b26c3ea7c4d14ee8 AS build
WORKDIR /build
COPY pom.xml .
COPY src src
RUN mvn package -DskipTests -q
-FROM eclipse-temurin:17-jdk
+FROM eclipse-temurin:17-jdk@sha256:f9b295135b39ed8c650c713c6116600dd4c39ac5f3883f566d96fdec917ce3b2
WORKDIR /app
COPY --from=build /build/target/benchmarks.jar benchmarks.jar
ENTRYPOINT ["java", "-jar", "benchmarks.jar", "-rf", "json", "-rff", "/results/results.json"]
Performance Improvement/Dockerfile.java25+2 -2
@@ -1,10 +1,10 @@
-FROM maven:3-eclipse-temurin-25 AS build
+FROM maven:3-eclipse-temurin-25@sha256:1b1fc6d0168ea616afd1c861d6f32ec37c9ec2ffe88a0351b3771dd4ad86b0d8 AS build
WORKDIR /build
COPY pom.xml .
COPY src src
RUN mvn package -DskipTests -q -Dmaven.compiler.source=25 -Dmaven.compiler.target=25
-FROM eclipse-temurin:25-jdk
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12
WORKDIR /app
COPY --from=build /build/target/benchmarks.jar benchmarks.jar
# Java 25 flags: compact headers (JEP 450) reduce per-object memory, preview features.
Performance Improvement/Dockerfile.java28+3 -3
@@ -1,5 +1,5 @@
-FROM maven:3-eclipse-temurin-21 AS maven
-FROM openjdk:28-ea-trixie AS build
+FROM maven:3-eclipse-temurin-21@sha256:c07f7ccfb8ca6c9fa29ee523f00afa7d2ca6132c92f8652c4aebb5ee3491f502 AS maven
+FROM openjdk:28-ea-trixie@sha256:1b92d439fa6b6d7b2e5dd5f1bd2b6f00346ff1a0ad020ad4f260480541b39c8d AS build
COPY --from=maven /usr/share/maven /usr/share/maven
ENV PATH="/usr/share/maven/bin:${PATH}"
WORKDIR /build
@@ -14,7 +14,7 @@ COPY src src
RUN mvn package -Pvalhalla -DskipTests -q \
-Dmaven.compiler.source=28 -Dmaven.compiler.target=28
-FROM openjdk:28-ea-trixie
+FROM openjdk:28-ea-trixie@sha256:1b92d439fa6b6d7b2e5dd5f1bd2b6f00346ff1a0ad020ad4f260480541b39c8d
WORKDIR /app
COPY --from=build /build/target/benchmarks.jar benchmarks.jar
# Java 28 EA with Valhalla value types enabled.
Renovate/docker/docker-compose.yml+1 -1
@@ -35,7 +35,7 @@ services:
# Pinned to a specific version โ€” Renovate will detect newer releases and
# open a PR automatically, demonstrating the "Container Base Images" section.
gitea:
- image: gitea/gitea:1.22.3
+ image: gitea/gitea:1.22.3@sha256:76f516a1a8c27e8f8e9773639bf337c0176547a2d42a80843e3f2536787341c6
container_name: gitea
restart: unless-stopped
networks:
Renovate/docker/jenkins/Dockerfile+1 -1
@@ -1,4 +1,4 @@
-FROM jenkins/jenkins:latest-jdk25
+FROM jenkins/jenkins:latest-jdk25@sha256:69bc8e22df80ad708fc0cebbbeaeca3813ca2fa53f5fbb3cc361941e7ea5e430
USER root
Vulnerable Application Old Java/Dockerfile.escalation+2 -2
@@ -10,7 +10,7 @@
# This is the "false sense of security" scenario:
# "We run as non-root, we're safe!" โ€” WRONG if packages are vulnerable.
-FROM maven:3-eclipse-temurin-17 AS build
+FROM maven:3-eclipse-temurin-17@sha256:4015718012bbf1113ec6cfae2b950be328d90265ceb60f92b26c3ea7c4d14ee8 AS build
WORKDIR /build
COPY pom.xml .
COPY src src
@@ -18,7 +18,7 @@ RUN mvn package -DskipTests -q
# โš ๏ธ Old image with vulnerable packages
# Uses Java 11 JRE so log4j-core 2.14.1 starts without JVM binary-compat crashes
-FROM eclipse-temurin:11-jre-jammy
+FROM eclipse-temurin:11-jre-jammy@sha256:e8acde9cc75b96765f005857cfeb7f826409177482c3f70400d5a94328689d56
WORKDIR /app
# โš ๏ธ policykit-1 includes pkexec (SUID root) vulnerable to CVE-2021-4034
Vulnerable Application Old Java/Dockerfile.nonroot+2 -2
@@ -11,14 +11,14 @@
# This demonstrates: even if an attacker gets RCE via Log4Shell,
# they can barely do anything in this container.
-FROM maven:3-eclipse-temurin-17 AS build
+FROM maven:3-eclipse-temurin-17@sha256:4015718012bbf1113ec6cfae2b950be328d90265ceb60f92b26c3ea7c4d14ee8 AS build
WORKDIR /build
COPY pom.xml .
COPY src src
RUN mvn package -DskipTests -q
# โœ… Modern minimal image โ€” no extra packages
-FROM eclipse-temurin:25-jre
+FROM eclipse-temurin:25-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
WORKDIR /app
# eclipse-temurin:25-jre already ships an 'ubuntu' user (uid=1000, gid=1000)
Vulnerable Application Old Java/Dockerfile.root+2 -2
@@ -9,7 +9,7 @@
#
# Compare Trivy scans: trivy image vuln-app:root vs trivy image vuln-app:safe
-FROM maven:3-eclipse-temurin-17 AS build
+FROM maven:3-eclipse-temurin-17@sha256:4015718012bbf1113ec6cfae2b950be328d90265ceb60f92b26c3ea7c4d14ee8 AS build
WORKDIR /build
COPY pom.xml .
COPY src src
@@ -17,7 +17,7 @@ RUN mvn package -DskipTests -q
# โš ๏ธ Old runtime image โ€” Ubuntu 22.04 with hundreds of known CVEs
# Uses Java 11 JRE so log4j-core 2.14.1 starts without JVM binary-compat crashes
-FROM eclipse-temurin:11-jre-jammy
+FROM eclipse-temurin:11-jre-jammy@sha256:e8acde9cc75b96765f005857cfeb7f826409177482c3f70400d5a94328689d56
WORKDIR /app
# โš ๏ธ Install a dangerous mix of packages:
Vulnerable Application/Dockerfile.escalation+2 -2
@@ -1,5 +1,5 @@
# Non-root but with extra packages (for scan comparison)
-FROM eclipse-temurin:25-jdk AS build
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS build
WORKDIR /build
COPY mvnw mvnw.cmd ./
COPY .mvn .mvn
@@ -7,7 +7,7 @@ COPY pom.xml .
COPY src src
RUN chmod +x mvnw && ./mvnw package -DskipTests -q
-FROM eclipse-temurin:25-jre
+FROM eclipse-temurin:25-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
WORKDIR /app
RUN chown -R ubuntu:ubuntu /app
COPY --from=build --chown=ubuntu:ubuntu /build/target/*.jar app.jar
Vulnerable Application/Dockerfile.nonroot+2 -2
@@ -1,5 +1,5 @@
# ๐Ÿ”’ SECURE โ€” modern minimal image, non-root, no extra packages
-FROM eclipse-temurin:25-jdk AS build
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS build
WORKDIR /build
COPY mvnw mvnw.cmd ./
COPY .mvn .mvn
@@ -7,7 +7,7 @@ COPY pom.xml .
COPY src src
RUN chmod +x mvnw && ./mvnw package -DskipTests -q
-FROM eclipse-temurin:25-jre
+FROM eclipse-temurin:25-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
WORKDIR /app
RUN chown -R ubuntu:ubuntu /app
COPY --from=build --chown=ubuntu:ubuntu /build/target/*.jar app.jar
Vulnerable Application/Dockerfile.root+2 -2
@@ -9,7 +9,7 @@
#
# Compare Trivy scans: trivy image vuln-app:root vs trivy image vuln-app:safe
-FROM eclipse-temurin:25-jdk AS build
+FROM eclipse-temurin:25-jdk@sha256:c42fecf62f32725c65cfea284c012526d6fb31cc78123c740ebdc1cfd2dced12 AS build
WORKDIR /build
COPY mvnw mvnw.cmd ./
COPY .mvn .mvn
@@ -17,7 +17,7 @@ COPY pom.xml .
COPY src src
RUN chmod +x mvnw && ./mvnw package -DskipTests -q
-FROM eclipse-temurin:25-jre
+FROM eclipse-temurin:25-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
WORKDIR /app
COPY --from=build /build/target/*.jar app.jar
EXPOSE 8080
โšช Dependency update #2

Update dependency com.unboundid:unboundid-ldapsdk to v7.0.5

renovate/com.unboundid-unboundid-ldapsdk-7.x โ†’ main opened 2026-08-14 09:52 UTC +1 -1 ยท 1 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [com.unboundid:unboundid-ldapsdk](https://github.com/pingidentity/ldapsdk) | `7.0.1` โ†’ `7.0.5` | ![age](https://developer.mend.io/api/mc/badges/age/maven/com.unboundid:unboundid-ldapsdk/7.0.5?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/com.unboundid:unboundid-ldapsdk/7.0.1/7.0.5?slim=true) |

---

### Release Notes

<details>
<summary>pingidentity/ldapsdk (com.unboundid:unboundid-ldapsdk)</summary>

### [`v7.0.5`](https://github.com/pingidentity/ldapsdk/releases/tag/7.0.5): UnboundID LDAP SDK for Java 7.0.5

[Compare Source](https://github.com/pingidentity/ldapsdk/compare/7.0.4...7.0.5)

We have just released version 7.0.5 of the [UnboundID LDAP SDK for Java](https://github.com/pingidentity/ldapsdk). It is available for download from [GitHub](https://github.com/pingidentity/ldapsdk/releases) and [SourceForge](https://sourceforge.net/projects/ldap-sdk/files/), and it is available in the [Maven Central Repository](https://central.sonatype.com/artifact/com.unboundid/unboundid-ldapsdk/7.0.5). You can find the release notes for this release (and all previous versions) at <https://docs.ldap.com/ldap-sdk/docs/release-notes.html>, but hereโ€™s a summary of the changes:

- We have updated the persistence framework to provide improved security validation when using Java serialization for certain fields. In general, we donโ€™t recommend the use of Java serialization in the persistence framework, since there are security concerns, and since the persisted objects can only be used by Java applications. If you wish to store an object in an LDAP server that has fields of types that arenโ€™t supported by the out-of-the-box persistence framework, we recommend creating a custom `ObjectEncoder` to handle the conversion to and from LDAP attributes.

- We updated the usage information for the `ldapdelete` tool to include a `--searchBaseDN` argument that was mentioned in the description but omitted from the set of sample arguments.

- We updated the documentation to include the latest revisions of a number of LDAP-related specifications, including draft-bouchez-scram-mcf, draft-codere-ldapsyntax, draft-kaliski-asn1-layman-guide, draft-ietf-kitten-password-storage, draft-ietf-kitten-sasl-ht, draft-khan-ldap-bind-return-dn, and draft-sabadello-did-challenge-sasl.

### [`v7.0.4`](https://github.com/pingidentity/ldapsdk/releases/tag/7.0.4): UnboundID LDAP SDK for Java 7.0.4

[Compare Source](https://github.com/pingidentity/ldapsdk/compare/7.0.3...7.0.4)

We have just released version 7.0.4 of the [UnboundID LDAP SDK for Java](https://github.com/pingidentity/ldapsdk). It is available for download from [GitHub](https://github.com/pingidentity/ldapsdk/releases) and [SourceForge](https://sourceforge.net/projects/ldap-sdk/files/), and it is available in the [Maven Central Repository](https://central.sonatype.com/artifact/com.unboundid/unboundid-ldapsdk/7.0.4). You can find the release notes for this release (and all previous versions) at <https://docs.ldap.com/ldap-sdk/docs/release-notes.html>, but hereโ€™s a summary of the changes:

- We added a โ€œdiscard resultsโ€ search result listener that can be used in cases where a search should be performed, but the actual matching entries and references arenโ€™t needed (for example, if you only need to know the number of matching entries).

- We added client-side support for a W3C trace context request control that can be included in requests sent to the latest versions of the Ping Identity Directory Server or ForgeRock Directory Services. This can be used to convey information for use in distributed tracing (e.g., via OpenTelemetry).

- We improved debug logging when adding or removing servers from the blacklist used to temporarily avoid creating connections to a server when using the round robin and fewest connections server set.

- We updated the `PropertyManager` class to make it possible to cache property values for faster access with less contention. Caching is disabled by default, although you can enable it by specifying a maximum cache duration. You can also programmatically clear the cache and pre-populate the cache based on currently defined system properties and environment variables.

- We improved performance and reduced contention when retrieving the values of environment variables from the JVM process.

- We updated the documentation to include the latest revisions of draft-bouchez-scram-mcf and draft-codere-ldapsyntax in the set of LDAP-related specifications.

### [`v7.0.3`](https://github.com/pingidentity/ldapsdk/releases/tag/7.0.3): UnboundID LDAP SDK for Java 7.0.3

[Compare Source](https://github.com/pingidentity/ldapsdk/compare/7.0.2...7.0.3)

We have just released version 7.0.3 of the [UnboundID LDAP SDK for Java](https://github.com/pingidentity/ldapsdk). It is available for download from [GitHub](https://github.com/pingidentity/ldapsdk/releases) and [SourceForge](https://sourceforge.net/projects/ldap-sdk/files/), and it is available in the [Maven Central Repository](https://central.sonatype.com/artifact/com.unboundid/unboundid-ldapsdk/7.0.3). You can find the release notes for this release (and all previous versions) at <https://docs.ldap.com/ldap-sdk/docs/release-notes.html>, but hereโ€™s a summary of the changes:

- We fixed an issue in which the LDAP SDK did not properly handle certificates with a notBefore or notAfter timestamp that fell in the year 2049 if that timestamp was encoded with the antiquated UTCTime syntax (which only uses two digits to encode the year). It incorrectly used a year of 1949 instead of 2049.

- We updated the `ldifmodify` tool so that it will report an error if any of the `sourceLDIF`, `changesLDIF`, or `targetLDIF` arguments refer to the same file. Previously, the tool would run, but could yield incomplete results if an input file was also used as an output file.

- We updated the IP address argument value validator to improve performance and to catch additional types of malformed IPv4 addresses that were previously accepted due to leniency in Javaโ€™s `InetAddress.getByName` implementation.

- We simplified and improved the `toLowerCase`, `toUpperCase`, and `getBytes` methods in the `StaticUtils` class. The former implementations were more efficient than the versions provided in the Java String class in older Java versions when primarily dealing with ASCII strings, but this is no longer the case in newer versions of Java where strings are backed by byte arrays rather than character arrays.

- We updated client-side support for the Ping-proprietary transaction settings request control to make it possible to request that the server acquire a lock using a client-specified scope under a specified set of conditions. This allows more control in the event of lock conflicts in cases where the client is able to determine which operations are most likely to conflict with each other. For example, in a multi-tenant server, it may be useful to specify a scope that includes a tenant-specific identifier so that only operations associated with that tenant will be affected by the scoped lock.

- We also updated the transaction settings request control to make it possible to override the conditions under which the server may attempt to acquire a single-writer lock. This was previously only controlled through the server configuration.

- We improved error reporting in the dump-dns tool for use with the Ping Identity Directory Server.

- We updated client-side support for the Ping Identity Directory Serverโ€™s version monitor entry to handle attributes used to indicate whether the server is running in FIPS 140-2-compliant or FIPS 140-3-compliant mode.

- We updated the documentation to include the newest versions of the draft-bucksch-sasl-passkey, draft-bucksch-sasl-rememberme, draft-codere-ldapsyntax, draft-ietf-kitten-sasl-ht, draft-ietf-kitten-sasl-rememberme, and draft-schmaus-kitten-sasl-ht specifications.

### [`v7.0.2`](https://github.com/pingidentity/ldapsdk/releases/tag/7.0.2): UnboundID LDAP SDK for Java 7.0.2

[Compare Source](https://github.com/pingidentity/ldapsdk/compare/7.0.1...7.0.2)

We have just released version 7.0.2 of the [UnboundID LDAP SDK for Java](https://github.com/pingidentity/ldapsdk). It is available for download from [GitHub](https://github.com/pingidentity/ldapsdk/releases) and [SourceForge](https://sourceforge.net/projects/ldap-sdk/files/), and it is available in the [Maven Central Repository](https://central.sonatype.com/artifact/com.unboundid/unboundid-ldapsdk/7.0.2). You can find the release notes for this release (and all previous versions) at <https://docs.ldap.com/ldap-sdk/docs/release-notes.html>, but hereโ€™s a summary of the changes:

- We added support for using the 2.x version of the Bouncy Castle FIPS-compliant security provider, which provides support for FIPS 140-3 compliance. The 1.x version of the library, offering FIPS 140-2 compliance, is still supported. To use the LDAP SDK in this mode, you should ensure that the necessary jar files are in the classpath, and then you should call `CryptoHelper.setUseFIPSMode("BCFIPS2")` as early as possible in the life of the application.

- We added a new `PropertyManager` class that can be used to retrieve the value of specified properties using either system properties or environment variables. Values can be optionally parsed as Booleans, numbers, or comma-delimited lists. Most uses of system properties within the LDAP SDK have been updated to support the new `PropertyManager` mechanism so that itโ€™s possible to set values as environment variables as an alternative to system properties.

- We fixed a bug in the `SSLUtil.certificateToString` method that prevented it from including the notBefore and notAfter timestamps in the string representation.

- We added client-side support for the Ping Identity Directory Serverโ€™s new to-be-deleted accessibility state for use with the get subtree accessibility and set subtree accessibility extended operations.

- We updated the `MoveSubtree` utility class to provide the ability to use the new to-be-deleted accessibility state (as an alternative to the hidden state) for the target subtree before starting to remove entries from the source server.

- We added a new `SubtreeAccessibilityState.isMoreRestrictiveThan` method that can be used to determine whether one accessibility state is considered more restrictive than another.

- Updated the documentation to include the latest versions of the following LDAP-related specifications:
  - draft-coretta-ldap-subnf-01
  - draft-coretta-oiddir-radit
  - draft-coretta-oiddir-radsa
  - draft-coretta-oiddir-radua
  - draft-coretta-oiddir-roadmap
  - draft-coretta-oiddir-schema
  - draft-ietf-kitten-scram-2fa
  - draft-melnikov-sasl2
  - draft-melnikov-scram-bis
  - draft-melnikov-scram-sha-512
  - draft-melnikov-scram-sha3-512

</details>

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

โ™ป **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->
Callback Server/pom.xml+1 -1
@@ -29,7 +29,7 @@
<dependency>
<groupId>com.unboundid</groupId>
<artifactId>unboundid-ldapsdk</artifactId>
- <version>7.0.1</version>
+ <version>7.0.5</version>
</dependency>
</dependencies>
โšช Dependency update #3

Update dependency org.codehaus.mojo:build-helper-maven-plugin to v3.6.1

renovate/org.codehaus.mojo-build-helper-maven-plugin-3.x โ†’ main opened 2026-08-14 09:52 UTC +1 -1 ยท 1 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [org.codehaus.mojo:build-helper-maven-plugin](https://www.mojohaus.org/build-helper-maven-plugin/) ([source](https://github.com/mojohaus/build-helper-maven-plugin)) | `3.6.0` โ†’ `3.6.1` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.codehaus.mojo:build-helper-maven-plugin/3.6.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.codehaus.mojo:build-helper-maven-plugin/3.6.0/3.6.1?slim=true) |

---

### Release Notes

<details>
<summary>mojohaus/build-helper-maven-plugin (org.codehaus.mojo:build-helper-maven-plugin)</summary>

### [`v3.6.1`](https://github.com/mojohaus/build-helper-maven-plugin/releases/tag/3.6.1)

[Compare Source](https://github.com/mojohaus/build-helper-maven-plugin/compare/3.6.0...3.6.1)

<!-- Optional: add a release summary here -->

#### ๐Ÿ“ Documentation updates

- Rename Goals to Plugin Documentation in the site menu ([#&#8203;229](https://github.com/mojohaus/build-helper-maven-plugin/pull/229)) [@&#8203;slawekjaranowski](https://github.com/slawekjaranowski)
- update the documentation for adding more resource directories ([#&#8203;213](https://github.com/mojohaus/build-helper-maven-plugin/pull/213)) [@&#8203;mjj042](https://github.com/mjj042)

#### ๐Ÿ‘ป Maintenance

- Use common release-drafter configuration ([#&#8203;230](https://github.com/mojohaus/build-helper-maven-plugin/pull/230)) [@&#8203;slawekjaranowski](https://github.com/slawekjaranowski)

#### ๐Ÿ“ฆ Dependency updates

- Bump org.codehaus.mojo:mojo-parent from 87 to 91 ([#&#8203;228](https://github.com/mojohaus/build-helper-maven-plugin/pull/228)) @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot)
- Bump org.apache.maven.shared:file-management from 3.1.0 to 3.2.0 ([#&#8203;222](https://github.com/mojohaus/build-helper-maven-plugin/pull/222)) @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot)
- Bump org.codehaus.mojo:mojo-parent from 86 to 87 ([#&#8203;221](https://github.com/mojohaus/build-helper-maven-plugin/pull/221)) @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot)
- Bump org.codehaus.mojo:mojo-parent from 85 to 86 ([#&#8203;219](https://github.com/mojohaus/build-helper-maven-plugin/pull/219)) @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot)
- Bump org.codehaus.plexus:plexus-utils from 4.0.1 to 4.0.2 ([#&#8203;220](https://github.com/mojohaus/build-helper-maven-plugin/pull/220)) @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot)
- Bump org.codehaus.mojo:mojo-parent from 84 to 85 ([#&#8203;217](https://github.com/mojohaus/build-helper-maven-plugin/pull/217)) @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot)
- Bump org.codehaus.mojo:mojo-parent from 82 to 84 ([#&#8203;214](https://github.com/mojohaus/build-helper-maven-plugin/pull/214)) @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot)

</details>

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

โ™ป **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->
Performance Improvement/pom.xml+1 -1
@@ -149,7 +149,7 @@
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>build-helper-maven-plugin</artifactId>
- <version>3.6.0</version>
+ <version>3.6.1</version>
<executions>
<execution>
<id>add-valhalla-source</id>
โšช Dependency update #4

Update dependency com.fasterxml.jackson.core:jackson-databind to v2.22.1

renovate/jackson-monorepo โ†’ main opened 2026-08-14 09:52 UTC +2 -2 ยท 2 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) ([source](https://github.com/FasterXML/jackson-databind)) | `2.13.4.1` โ†’ `2.22.1` | ![age](https://developer.mend.io/api/mc/badges/age/maven/com.fasterxml.jackson.core:jackson-databind/2.22.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/com.fasterxml.jackson.core:jackson-databind/2.13.4.1/2.22.1?slim=true) |

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

โ™ป **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->
Vulnerable Application Old Java/pom.xml+1 -1
@@ -75,7 +75,7 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
- <version>2.13.4.1</version>
+ <version>2.22.1</version>
</dependency>
</dependencies>
Vulnerable Application/pom.xml+1 -1
@@ -60,7 +60,7 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
- <version>2.13.4.1</version>
+ <version>2.22.1</version>
</dependency>
</dependencies>
โšช Dependency update #5

Update dependency org.apache.maven.plugins:maven-shade-plugin to v3.6.2

renovate/org.apache.maven.plugins-maven-shade-plugin-3.x โ†’ main opened 2026-08-14 09:52 UTC +1 -1 ยท 1 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [org.apache.maven.plugins:maven-shade-plugin](https://maven.apache.org/plugins/) ([source](https://github.com/apache/maven-shade-plugin)) | `3.5.1` โ†’ `3.6.2` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.maven.plugins:maven-shade-plugin/3.6.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.maven.plugins:maven-shade-plugin/3.5.1/3.6.2?slim=true) |

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

โ™ป **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->
Performance Improvement/pom.xml+1 -1
@@ -85,7 +85,7 @@
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-shade-plugin</artifactId>
- <version>3.5.1</version>
+ <version>3.6.2</version>
<executions>
<execution>
<phase>package</phase>
โšช Dependency update #6

Update dependency org.owasp:dependency-check-maven to v12.2.2

renovate/org.owasp-dependency-check-maven-12.x โ†’ main opened 2026-08-14 09:52 UTC +1 -1 ยท 1 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [org.owasp:dependency-check-maven](https://github.com/dependency-check/DependencyCheck.git) ([source](https://github.com/dependency-check/DependencyCheck/tree/HEAD/maven)) | `12.1.1` โ†’ `12.2.2` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.owasp:dependency-check-maven/12.2.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.owasp:dependency-check-maven/12.1.1/12.2.2?slim=true) |

---

### Release Notes

<details>
<summary>dependency-check/DependencyCheck (org.owasp:dependency-check-maven)</summary>

### [`v12.2.2`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1222-2026-05-03)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.2.1...v12.2.2)

**NOTE**: The database schema was updated to fix [#&#8203;8466](https://github.com/dependency-check/DependencyCheck/pull/8466) - if using an external database the update scripts must be run!

- feat: improve Sonatype Guide / OSS Index cache handling and insufficient credits error reporting ([#&#8203;8451](https://github.com/dependency-check/DependencyCheck/pull/8451))
- feat: support and prefer githubID vuln identifiers from RetireJS ([#&#8203;8419](https://github.com/dependency-check/DependencyCheck/pull/8419))
- fix(db): widen reference URL column to handle long Mozilla CVE URLs ([#&#8203;8467](https://github.com/dependency-check/DependencyCheck/pull/8467))
- fix: add corepack to docker image ([#&#8203;8386](https://github.com/dependency-check/DependencyCheck/pull/8386))
- fix: bump open-vulnerability-clients to resolve NVD timestamp parsing errors ([#&#8203;8427](https://github.com/dependency-check/DependencyCheck/pull/8427))
- fix: de-duplicate and sort both `includedBy` and `projectReferences` in reports ([#&#8203;8440](https://github.com/dependency-check/DependencyCheck/pull/8440))
- fix: migrate default OSS Index API URL to Sonatype Guide; supporting optional username ([#&#8203;8404](https://github.com/dependency-check/DependencyCheck/pull/8404))
- docs: correct missing documentation for Gradle plugin ([#&#8203;8431](https://github.com/dependency-check/DependencyCheck/pull/8431))
- docs: tweak docs site structure; documenting missing analyzers ([#&#8203;8462](https://github.com/dependency-check/DependencyCheck/pull/8462))
- chore: remove spurious bundle-audit log line when there are no errors ([#&#8203;8454](https://github.com/dependency-check/DependencyCheck/pull/8454))
- chore: tidy CHANGELOG formatting ([#&#8203;8414](https://github.com/dependency-check/DependencyCheck/pull/8414))
- chore(fp): remove duplicate log4j FP suppressions ([#&#8203;8468](https://github.com/dependency-check/DependencyCheck/pull/8468))
- build(deps): bump apache.ant.version from 1.10.16 to 1.10.17 ([#&#8203;8416](https://github.com/dependency-check/DependencyCheck/pull/8416))
- build(deps): bump com.fasterxml.jackson:jackson-bom from 2.21.2 to 2.21.3 ([#&#8203;8465](https://github.com/dependency-check/DependencyCheck/pull/8465))
- build(deps): bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre ([#&#8203;8420](https://github.com/dependency-check/DependencyCheck/pull/8420))
- build(deps): bump com.mysql:mysql-connector-j from 9.6.0 to 9.7.0 ([#&#8203;8445](https://github.com/dependency-check/DependencyCheck/pull/8445))
- build(deps): bump commons-codec:commons-codec from 1.21.0 to 1.22.0 ([#&#8203;8453](https://github.com/dependency-check/DependencyCheck/pull/8453))
- build(deps): bump commons-io:commons-io from 2.21.0 to 2.22.0 ([#&#8203;8448](https://github.com/dependency-check/DependencyCheck/pull/8448))
- build(deps): bump httpcomponents.client.version from 5.6 to 5.6.1 ([#&#8203;8432](https://github.com/dependency-check/DependencyCheck/pull/8432))
- build(deps): bump joda-time:joda-time from 2.14.1 to 2.14.2 ([#&#8203;8464](https://github.com/dependency-check/DependencyCheck/pull/8464))
- build(deps): bump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.0 ([#&#8203;8452](https://github.com/dependency-check/DependencyCheck/pull/8452))
- build(deps): bump org.jsoup:jsoup from 1.22.1 to 1.22.2 ([#&#8203;8437](https://github.com/dependency-check/DependencyCheck/pull/8437))
- build(deps): bump org.postgresql:postgresql from 42.7.10 to 42.7.11 ([#&#8203;8463](https://github.com/dependency-check/DependencyCheck/pull/8463))
- build(deps): bump the actions-deps group with 8 updates ([#&#8203;8472](https://github.com/dependency-check/DependencyCheck/pull/8472))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/106?closed=1)

### [`v12.2.1`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1221-2026-04-11)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.2.0...v12.2.1)

- fix(core): correct xml schema validation handling without needing external access ([#&#8203;8272](https://github.com/dependency-check/DependencyCheck/pull/8272))
- fix(deps): upgrade slf4j and logback ([#&#8203;8306](https://github.com/dependency-check/DependencyCheck/pull/8306))
- fix(test): disable pnpm analyzer during test ([#&#8203;8305](https://github.com/dependency-check/DependencyCheck/pull/8305))
- fix: Correct published/hosted suppressions namespace header and indent ([#&#8203;8258](https://github.com/dependency-check/DependencyCheck/pull/8258))
- fix: Suppress noisy WARN logging from Apache Lucene within Maven and Ant plugins ([#&#8203;8248](https://github.com/dependency-check/DependencyCheck/pull/8248))
- fix: [#&#8203;8140](https://github.com/dependency-check/DependencyCheck/pull/8140) AssemblyAnalyzer version resolution issue ([#&#8203;8352](https://github.com/dependency-check/DependencyCheck/pull/8352))
- fix: [#&#8203;8140](https://github.com/dependency-check/DependencyCheck/pull/8140) fix version resolution
- fix: [#&#8203;8140](https://github.com/dependency-check/DependencyCheck/pull/8140) hint azure\_identity\_library\_for\_.net
- fix: [#&#8203;8356](https://github.com/dependency-check/DependencyCheck/pull/8356) narrow down VersionFilterAnalyzer scope to JAR files ([#&#8203;8358](https://github.com/dependency-check/DependencyCheck/pull/8358))
- fix: correct parsing for CVSSv4 strings with Provider Urgency ([#&#8203;8377](https://github.com/dependency-check/DependencyCheck/pull/8377))
- fix: evidence source in Retire JS analyzer ([#&#8203;8303](https://github.com/dependency-check/DependencyCheck/pull/8303))
- fix: exclude deprecations from Yarn Berry audit results ([#&#8203;8380](https://github.com/dependency-check/DependencyCheck/pull/8380))
- fix: improve PEAnalyzer reliability by migrating to maintained PE/COFF 4J library fork ([#&#8203;8245](https://github.com/dependency-check/DependencyCheck/pull/8245))
- fix: improve configuration consistency (casing) ([#&#8203;8355](https://github.com/dependency-check/DependencyCheck/pull/8355))
- fix: improve logging of unexpected Java Errors during processing of NVD ([#&#8203;8250](https://github.com/dependency-check/DependencyCheck/pull/8250))
- fix: raw type warning in ProcessReader ([#&#8203;8324](https://github.com/dependency-check/DependencyCheck/pull/8324))
- fix: suppress false positives for zabbix-utils [#&#8203;8087](https://github.com/dependency-check/DependencyCheck/pull/8087) ([#&#8203;8218](https://github.com/dependency-check/DependencyCheck/pull/8218))
- fix: update docs ([#&#8203;8405](https://github.com/dependency-check/DependencyCheck/pull/8405))
- fix: warn if deprecated configs are used ([#&#8203;8366](https://github.com/dependency-check/DependencyCheck/pull/8366))
- docs: define schema locations in XML examples ([#&#8203;8254](https://github.com/dependency-check/DependencyCheck/pull/8254))
- docs: document external data sources and hostnames ([#&#8203;8219](https://github.com/dependency-check/DependencyCheck/pull/8219))
- docs: ensure OSS Index URL override is consistently documented ([#&#8203;8338](https://github.com/dependency-check/DependencyCheck/pull/8338))
- docs: fix minor typo in README ([#&#8203;8246](https://github.com/dependency-check/DependencyCheck/pull/8246))
- chore: avoid use of parent pom and maven properties where unnecessary ([#&#8203;8322](https://github.com/dependency-check/DependencyCheck/pull/8322))
- chore: bump java development to 25.0 ([#&#8203;8365](https://github.com/dependency-check/DependencyCheck/pull/8365))
- chore: fix Charset warnings; preferring typed charsets ([#&#8203;8326](https://github.com/dependency-check/DependencyCheck/pull/8326))
- chore: fix Maven scm tags after 12.2.1-SNAPSHOT bump ([#&#8203;8265](https://github.com/dependency-check/DependencyCheck/pull/8265))
- chore: pin GitHub actions to specific SHAs rather than mutable tags ([#&#8203;8381](https://github.com/dependency-check/DependencyCheck/pull/8381))
- chore: remove unused properties and schemas ([#&#8203;8378](https://github.com/dependency-check/DependencyCheck/pull/8378))
- test: Make tests locale independent ([#&#8203;8328](https://github.com/dependency-check/DependencyCheck/pull/8328))
- test: [#&#8203;8140](https://github.com/dependency-check/DependencyCheck/pull/8140) reproduce current behavior
- test: avoid polluting test classpaths with sample dependencies to be scanned ([#&#8203;8267](https://github.com/dependency-check/DependencyCheck/pull/8267))
- build: improve GHA workflow experience for forks ([#&#8203;8285](https://github.com/dependency-check/DependencyCheck/pull/8285))
- build: use maven jdk toolchains to build with Java 25; test against Java 11/17/21/25 ([#&#8203;8292](https://github.com/dependency-check/DependencyCheck/pull/8292))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/104?closed=1)

### [`v12.2.0`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1220-2026-01-09)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.9...v12.2.0)

- feat: package and utilize generated suppression file ([#&#8203;8116](https://github.com/dependency-check/DependencyCheck/pull/8116))
- feat: override pnpm audit registry parameter ([#&#8203;8158](https://github.com/dependency-check/DependencyCheck/pull/8158))
- feat: support multiple cvssBelow thresholds per version ([#&#8203;2563](https://github.com/dependency-check/DependencyCheck/pull/2563)) ([#&#8203;8024](https://github.com/dependency-check/DependencyCheck/pull/8024))
- feat: usage telemetry via scarf ([#&#8203;8066](https://github.com/dependency-check/DependencyCheck/pull/8066))
- feat: add new suppression xsd allowing grouping of suppressions ([#&#8203;7957](https://github.com/dependency-check/DependencyCheck/pull/7957))
- fix: add hint for Elastic APM Java agent CPE mapping ([#&#8203;8200](https://github.com/dependency-check/DependencyCheck/pull/8200))
- fix: Allow NVD data feed metadata downloads to fail on 1st Jan while logging correct errors ([#&#8203;8205](https://github.com/dependency-check/DependencyCheck/pull/8205))
- fix: correct XML/JSON report CVSS field & HTML report URL mappings ([#&#8203;8156](https://github.com/dependency-check/DependencyCheck/pull/8156))
- fix: log GrokAssembly output when dotnet invocation fails ([#&#8203;8141](https://github.com/dependency-check/DependencyCheck/pull/8141))
- fix: correct reliability of Central etc (JCS cache) analyzers on Java 25/Docker by making CLI classpath deterministic  ([#&#8203;8117](https://github.com/dependency-check/DependencyCheck/pull/8117))
- fix(ant): resolve relative paths against basedir ([#&#8203;8202](https://github.com/dependency-check/DependencyCheck/pull/8202))
- fix(ant): resolve paths relative to basedir for suppression and output
- docs: Update & correct README ([#&#8203;8166](https://github.com/dependency-check/DependencyCheck/pull/8166))
- docs: update suppression schema version ([#&#8203;8136](https://github.com/dependency-check/DependencyCheck/pull/8136))
- docs: fix typos in some files ([#&#8203;8135](https://github.com/dependency-check/DependencyCheck/pull/8135))
- chore: remove duplicate suppression rules from base that are in the generated branch ([#&#8203;8138](https://github.com/dependency-check/DependencyCheck/pull/8138))
- chore: remove suppression rules that were deleted from the generatedSuppression branch ([#&#8203;8119](https://github.com/dependency-check/DependencyCheck/pull/8119))
- build: transition dependency to `org.eclipse.parsson` groupId ([#&#8203;8128](https://github.com/dependency-check/DependencyCheck/pull/8128))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/103?closed=1)

### [`v12.1.9`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1219-2025-11-11)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.8...v12.1.9)

- fix: correct bundle audit gem in Dockerfile ([#&#8203;8121](https://github.com/dependency-check/DependencyCheck/pull/8121))
- fix: normalization during comparisons ([#&#8203;8046](https://github.com/dependency-check/DependencyCheck/pull/8046))
- fix(fp): Improve false positive suppression for matches against golang web\_project ([#&#8203;8059](https://github.com/dependency-check/DependencyCheck/pull/8059))
- fix(fp): Consolidate/update icu4j suppressions for false positives ([#&#8203;8062](https://github.com/dependency-check/DependencyCheck/pull/8062))
- fix(fp): Correct GRPC java suppressions for newer C/C++/native false positives ([#&#8203;8063](https://github.com/dependency-check/DependencyCheck/pull/8063))
- fix(fp): Suppress false positive CPEs for protobuf-java per [#&#8203;7854](https://github.com/dependency-check/DependencyCheck/pull/7854) ([#&#8203;8064](https://github.com/dependency-check/DependencyCheck/pull/8064))
- docs: document multiple configurations for gradle ([#&#8203;8111](https://github.com/dependency-check/DependencyCheck/pull/8111))
- docs: fix typos in some files ([#&#8203;8106](https://github.com/dependency-check/DependencyCheck/pull/8106))
- docs: Update SBT plugin link; fix dead report link ([#&#8203;8086](https://github.com/dependency-check/DependencyCheck/pull/8086))
- docs: fix [#&#8203;8076](https://github.com/dependency-check/DependencyCheck/pull/8076) - Error in documentation "Suppressing False Positives" ([#&#8203;8077](https://github.com/dependency-check/DependencyCheck/pull/8077))
- chore: Replace deprecated lucene methods ([#&#8203;8079](https://github.com/dependency-check/DependencyCheck/pull/8079))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/102?closed=1)

### [`v12.1.8`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1218-2025-10-13)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.7...v12.1.8)

- fix: improve VulnerableSoftware comparison ([#&#8203;8031](https://github.com/dependency-check/DependencyCheck/pull/8031))
- docs: Improve Gradle docs wrt experimental analyzers, use of Central and Proxy configuration ([#&#8203;8036](https://github.com/dependency-check/DependencyCheck/pull/8036))
- docs: add note about central analyzer for gradle ([#&#8203;8038](https://github.com/dependency-check/DependencyCheck/pull/8038))
- build: fix flaky central test ([#&#8203;8039](https://github.com/dependency-check/DependencyCheck/pull/8039))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/101?closed=1)

### [`v12.1.7`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1217-2025-10-12)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.6...v12.1.7)

- fix: disable central analyzer after failures ([#&#8203;7993](https://github.com/dependency-check/DependencyCheck/pull/7993))
- fix: Suppress JVM warnings from Lucene within CLI ([#&#8203;8003](https://github.com/dependency-check/DependencyCheck/pull/8003))
- fix: Clean up Apache Lucene logging via SLF4j redirect ([#&#8203;7979](https://github.com/dependency-check/DependencyCheck/pull/7979))
- fix: Correct Archive Analyzer behaviour on certain tgz archives ([#&#8203;7986](https://github.com/dependency-check/DependencyCheck/pull/7986))
- fix: Update NVD CPE search URLs in generated reports to match new search interface ([#&#8203;7970](https://github.com/dependency-check/DependencyCheck/pull/7970))
- fix: improve OSS Index Error Reporting ([#&#8203;7977](https://github.com/dependency-check/DependencyCheck/pull/7977))
- fix(fp): Consolidate false positive suppression for false positives on Redis client libs ([#&#8203;8017](https://github.com/dependency-check/DependencyCheck/pull/8017))
- fix(fp): Fix more common false positives for popular PHP/composer frameworks with generic names ([#&#8203;7994](https://github.com/dependency-check/DependencyCheck/pull/7994))
- docs: improve slack notification documentation ([#&#8203;8026](https://github.com/dependency-check/DependencyCheck/pull/8026))
- docs: Documentation artifactory settings fix ([#&#8203;7999](https://github.com/dependency-check/DependencyCheck/pull/7999))
- docs: Clarify Nexus Analyzer requirements and usage ([#&#8203;8000](https://github.com/dependency-check/DependencyCheck/pull/8000))
- build: Build amd64 and arm64 multi-platform Docker image ([#&#8203;7952](https://github.com/dependency-check/DependencyCheck/pull/7952))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/100?closed=1)

### [`v12.1.6`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1216-2025-09-24)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.5...v12.1.6)

- fix: Disable OSS Index if its credentials are missing ([#&#8203;7963](https://github.com/dependency-check/DependencyCheck/pull/7963))
- fix: Correct CVSSv4 parsing for low precision OSSIndex values ([#&#8203;7935](https://github.com/dependency-check/DependencyCheck/pull/7935))
- fix(fp): Fix false positives for Redis Server against NPM/JS client libs ([#&#8203;7942](https://github.com/dependency-check/DependencyCheck/pull/7942))
- docs: Fix legacy GitHub links within docs and CHANGELOG ([#&#8203;7944](https://github.com/dependency-check/DependencyCheck/pull/7944))
- chore: fix version typo in security policy ([#&#8203;7936](https://github.com/dependency-check/DependencyCheck/pull/7936))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/99?closed=1)

### [`v12.1.5`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1215-2025-09-20)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.4...v12.1.5)

- **fix**: Update to support OSS Index Authentication Requirements ([#&#8203;7920](https://github.com/dependency-check/DependencyCheck/pull/7920))
  - Note: OSS Index will require authentication starting 9/22/2025. Users must configure a free account to continue using the OSS Index Analyzer.
- fix: add CVSSv4 to suppressed entries in JSON report ([#&#8203;7900](https://github.com/dependency-check/DependencyCheck/pull/7900))
- fix: correctly utilize CVSSv4 from ossindex ([#&#8203;7899](https://github.com/dependency-check/DependencyCheck/pull/7899))
- fix: npe when processing cve with empty configuration ([#&#8203;7888](https://github.com/dependency-check/DependencyCheck/pull/7888))
- fix: Return unsorted vulnerabilities in new HashSet, avoiding CoMod ([#&#8203;7848](https://github.com/dependency-check/DependencyCheck/pull/7848))
- fix: Return unsorted vulnerabilities in new HashSet, avoiding CoMod
- fix: class loading problem with fat jars ([#&#8203;7786](https://github.com/dependency-check/DependencyCheck/pull/7786)) ([#&#8203;7787](https://github.com/dependency-check/DependencyCheck/pull/7787))
- fix: Improve Artifactory handler log message ([#&#8203;7838](https://github.com/dependency-check/DependencyCheck/pull/7838))
- fix: classloading problem with fat jars ([#&#8203;7786](https://github.com/dependency-check/DependencyCheck/pull/7786))
- fix: Add null checking when parsing the license json in AbstractNpmAnalyzer. ([#&#8203;7784](https://github.com/dependency-check/DependencyCheck/pull/7784))
- fix(fp): resolves several false positives related to CVE-2021-41033 ([#&#8203;7736](https://github.com/dependency-check/DependencyCheck/pull/7736))
- docs: Clarify format of exclude patterns ([#&#8203;7879](https://github.com/dependency-check/DependencyCheck/pull/7879))
- docs: Document poetry-based analysis behaviour in Python analyzer ([#&#8203;7855](https://github.com/dependency-check/DependencyCheck/pull/7855))
- docs: request FP reporters use the latest version of ODC. ([#&#8203;7820](https://github.com/dependency-check/DependencyCheck/pull/7820))
- docs: update development pre-reqs ([#&#8203;7792](https://github.com/dependency-check/DependencyCheck/pull/7792))
- docs: fix minor typos in false positive issue template ([#&#8203;7763](https://github.com/dependency-check/DependencyCheck/pull/7763))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/98?closed=1)

### [`v12.1.4`](https://github.com/dependency-check/DependencyCheck/compare/v12.1.3...v12.1.4)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.3...v12.1.4)

### [`v12.1.3`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1213-2025-06-10)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.2...v12.1.3)

- fix: correct regex matches introduced in 12.1.2 ([#&#8203;7726](https://github.com/dependency-check/DependencyCheck/pull/7726))
- build(deps): bump org.semver4j:semver4j from 5.7.0 to 5.7.1 ([#&#8203;7718](https://github.com/dependency-check/DependencyCheck/pull/7718))
- build(deps): bump junit.version from 5.13.0 to 5.13.1 ([#&#8203;7719](https://github.com/dependency-check/DependencyCheck/pull/7719))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/97?closed=1)

### [`v12.1.2`](https://github.com/dependency-check/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-1212-2025-06-07)

[Compare Source](https://github.com/dependency-check/DependencyCheck/compare/v12.1.1...v12.1.2)

- fix: Allow configuring OSS Index user/pw directly ([#&#8203;7640](https://github.com/dependency-check/DependencyCheck/pull/7640))
- fix: remove vulnerable transitive dependency - beanutils ([#&#8203;7705](https://github.com/dependency-check/DependencyCheck/pull/7705))
- fix: Simplify PHP framework suppression for Composer ([#&#8203;7693](https://github.com/dependency-check/DependencyCheck/pull/7693))
- fix: update CPE pattern to remove FP ([#&#8203;7684](https://github.com/dependency-check/DependencyCheck/pull/7684))
- fix(cli): Patch generated Windows shell script for JAVACMD installs with spaces ([#&#8203;7653](https://github.com/dependency-check/DependencyCheck/pull/7653))
- fix: Resolve various WCAG accessibility / css issues in the HTML report ([#&#8203;7629](https://github.com/dependency-check/DependencyCheck/pull/7629))
- fix: [#&#8203;7510](https://github.com/dependency-check/DependencyCheck/pull/7510) Display a dedicated message when receiving an HTTP 403 ([#&#8203;7575](https://github.com/dependency-check/DependencyCheck/pull/7575))
- docs: Make `Vulnerability Sources` in `Related Work` clearer ([#&#8203;7691](https://github.com/dependency-check/DependencyCheck/pull/7691))
- docs: [#&#8203;7610](https://github.com/dependency-check/DependencyCheck/pull/7610) add a reference to NVD mirroring in getting started documentation ([#&#8203;7611](https://github.com/dependency-check/DependencyCheck/pull/7611))

See the full listing of [changes](https://github.com/dependency-check/DependencyCheck/milestone/96?closed=1)

</details>

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

โ™ป **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->
Vulnerable Application/pom.xml+1 -1
@@ -74,7 +74,7 @@
<plugin>
<groupId>org.owasp</groupId>
<artifactId>dependency-check-maven</artifactId>
- <version>12.1.1</version>
+ <version>12.2.2</version>
<configuration>
<formats>
<format>HTML</format>
โšช Dependency update #7

Update gitea/gitea Docker tag to v1.27.2

renovate/gitea-gitea-1.x โ†’ main opened 2026-08-14 09:52 UTC +1 -1 ยท 1 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [gitea/gitea](https://github.com/go-gitea/gitea) | minor | `1.22.3` โ†’ `1.27.2` |

---

### Release Notes

<details>
<summary>go-gitea/gitea (gitea/gitea)</summary>

### [`v1.27.2`](https://github.com/go-gitea/gitea/releases/tag/v1.27.2)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.1...v1.27.2)

- SECURITY
  - Fix: update collaborator access mode and httpsign ([#&#8203;38894](https://github.com/go-gitea/gitea/issues/38894), [#&#8203;38862](https://github.com/go-gitea/gitea/issues/38862)) ([#&#8203;38895](https://github.com/go-gitea/gitea/issues/38895))
  - Refactor: external render ([#&#8203;38885](https://github.com/go-gitea/gitea/issues/38885)) ([#&#8203;38898](https://github.com/go-gitea/gitea/issues/38898))
  - Fix(actions): resolve pull\_request\_target reusable workflows at the base commit ([#&#8203;38886](https://github.com/go-gitea/gitea/issues/38886)) ([#&#8203;38897](https://github.com/go-gitea/gitea/issues/38897))
  - Refactor: markup render ([#&#8203;38864](https://github.com/go-gitea/gitea/issues/38864)) ([#&#8203;38869](https://github.com/go-gitea/gitea/issues/38869))
  - Fix(deps): update dependency mermaid to v11.16.1 ([#&#8203;38816](https://github.com/go-gitea/gitea/issues/38816))
  - Fix(auth): set WebAuthn user verification per request ([#&#8203;38805](https://github.com/go-gitea/gitea/issues/38805)) ([#&#8203;38810](https://github.com/go-gitea/gitea/issues/38810))
  - Fix: render highlight language ([#&#8203;38793](https://github.com/go-gitea/gitea/issues/38793)) ([#&#8203;38795](https://github.com/go-gitea/gitea/issues/38795))

- ENHANCEMENTS
  - enhance: add missing npm package metadata properties ([#&#8203;38826](https://github.com/go-gitea/gitea/issues/38826)) ([#&#8203;38831](https://github.com/go-gitea/gitea/issues/38831))

- BUGFIXES
  - fix(actions): keep github.event.inputs as strings for workflow\_dispatch ([#&#8203;38899](https://github.com/go-gitea/gitea/issues/38899)) ([#&#8203;38908](https://github.com/go-gitea/gitea/issues/38908))
  - fix(actions): let a rerun of selected jobs read the previous attempt's artifacts ([#&#8203;38857](https://github.com/go-gitea/gitea/issues/38857)) ([#&#8203;38901](https://github.com/go-gitea/gitea/issues/38901))
  - fix(lfs): accept successful transfer responses ([#&#8203;38866](https://github.com/go-gitea/gitea/issues/38866)) ([#&#8203;38875](https://github.com/go-gitea/gitea/issues/38875))
  - fix(packages): ignore nested Package.swift ([#&#8203;38788](https://github.com/go-gitea/gitea/issues/38788)) ([#&#8203;38836](https://github.com/go-gitea/gitea/issues/38836))
  - fix: drop newline-bearing member names in arch ParsePackage ([#&#8203;38102](https://github.com/go-gitea/gitea/issues/38102)) ([#&#8203;38830](https://github.com/go-gitea/gitea/issues/38830))
  - fix(storage): fix Azure Blob dump failing with file does not exist ([#&#8203;38814](https://github.com/go-gitea/gitea/issues/38814)) ([#&#8203;38828](https://github.com/go-gitea/gitea/issues/38828))
  - fix(migration): migration deletion returned json redirection ([#&#8203;38796](https://github.com/go-gitea/gitea/issues/38796)) ([#&#8203;38825](https://github.com/go-gitea/gitea/issues/38825))
  - fix(ui): change underlines to default browser style ([#&#8203;38819](https://github.com/go-gitea/gitea/issues/38819)) ([#&#8203;38823](https://github.com/go-gitea/gitea/issues/38823))
  - fix(actions): allow cancelling runs without running jobs ([#&#8203;35842](https://github.com/go-gitea/gitea/issues/35842)) ([#&#8203;38812](https://github.com/go-gitea/gitea/issues/38812))
  - fix(actions): evaluate each `${{ }}` part on its own ([#&#8203;38754](https://github.com/go-gitea/gitea/issues/38754)) ([#&#8203;38797](https://github.com/go-gitea/gitea/issues/38797))
  - fix(actions): write an action task report in one transaction ([#&#8203;38792](https://github.com/go-gitea/gitea/issues/38792)) ([#&#8203;38794](https://github.com/go-gitea/gitea/issues/38794))
  - fix: markup link ([#&#8203;38764](https://github.com/go-gitea/gitea/issues/38764)) ([#&#8203;38765](https://github.com/go-gitea/gitea/issues/38765))
  - fix: set a minio part size when the content size is unknown ([#&#8203;38753](https://github.com/go-gitea/gitea/issues/38753)) ([#&#8203;38755](https://github.com/go-gitea/gitea/issues/38755))
  - fix: bad path escape in subpath archive download ([#&#8203;38749](https://github.com/go-gitea/gitea/issues/38749)) ([#&#8203;38750](https://github.com/go-gitea/gitea/issues/38750))
  - fix: remove the pull merge box from UI when the refreshed page doesn't contain it ([#&#8203;38742](https://github.com/go-gitea/gitea/issues/38742)) ([#&#8203;38744](https://github.com/go-gitea/gitea/issues/38744))
  - fix(markdown): fix double strikethough on code ([#&#8203;38707](https://github.com/go-gitea/gitea/issues/38707)) ([#&#8203;38729](https://github.com/go-gitea/gitea/issues/38729))
  - fix(lfs): failed upload deletes a concurrent upload's meta object ([#&#8203;38693](https://github.com/go-gitea/gitea/issues/38693)) ([#&#8203;38722](https://github.com/go-gitea/gitea/issues/38722))
  - fix: correct full url when using sub-path ([#&#8203;38712](https://github.com/go-gitea/gitea/issues/38712)) ([#&#8203;38716](https://github.com/go-gitea/gitea/issues/38716))
  - fix: avoid markup render panic ([#&#8203;38698](https://github.com/go-gitea/gitea/issues/38698)) ([#&#8203;38703](https://github.com/go-gitea/gitea/issues/38703))
  - fix(ui): too many participants shown in commit avatar stacks ([#&#8203;38689](https://github.com/go-gitea/gitea/issues/38689)) ([#&#8203;38700](https://github.com/go-gitea/gitea/issues/38700))
  - fix: support HEAD requests on Alpine registry APKINDEX.tar.gz ([#&#8203;38686](https://github.com/go-gitea/gitea/issues/38686)) ([#&#8203;38688](https://github.com/go-gitea/gitea/issues/38688))
  - fix(migrations): use all configured GitHub tokens ([#&#8203;38841](https://github.com/go-gitea/gitea/issues/38841)) ([#&#8203;38846](https://github.com/go-gitea/gitea/issues/38846))

Instances on **[Gitea Cloud](https://cloud.gitea.com)** will be automatically upgraded to this version during the specified maintenance window.

### [`v1.27.1`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1271---2026-07-27)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.0...v1.27.1)

- SECURITY
  - Fix: orgmode render include path ([#&#8203;38642](https://github.com/go-gitea/gitea/issues/38642)) ([#&#8203;38645](https://github.com/go-gitea/gitea/issues/38645))
  - Fix: git patch apply ([#&#8203;38637](https://github.com/go-gitea/gitea/issues/38637)) ([#&#8203;38638](https://github.com/go-gitea/gitea/issues/38638))
  - Fix(oauth2): enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints ([#&#8203;38591](https://github.com/go-gitea/gitea/issues/38591)) ([#&#8203;38606](https://github.com/go-gitea/gitea/issues/38606))

- API
  - fix(api): align Swagger schemas for UserSettings and TopicListResponse ([#&#8203;38590](https://github.com/go-gitea/gitea/issues/38590)) ([#&#8203;38592](https://github.com/go-gitea/gitea/issues/38592))

- ENHANCEMENTS
  - enhance: improve diff contrast in light and dark themes ([#&#8203;37477](https://github.com/go-gitea/gitea/issues/37477)) ([#&#8203;38574](https://github.com/go-gitea/gitea/issues/38574))

- BUGFIXES
  - fix: skip OIDC end-session after password login for OAuth2 users ([#&#8203;38439](https://github.com/go-gitea/gitea/issues/38439)) ([#&#8203;38666](https://github.com/go-gitea/gitea/issues/38666))
  - fix: make Actions log parser support multiple line message encoding ([#&#8203;38659](https://github.com/go-gitea/gitea/issues/38659)) ([#&#8203;38664](https://github.com/go-gitea/gitea/issues/38664))
  - fix(actions): use base branch ref for pull\_request\_target context ([#&#8203;38636](https://github.com/go-gitea/gitea/issues/38636)) ([#&#8203;38657](https://github.com/go-gitea/gitea/issues/38657))
  - fix(actions): skip already-approved runs in `ApproveRuns` ([#&#8203;38653](https://github.com/go-gitea/gitea/issues/38653)) ([#&#8203;38654](https://github.com/go-gitea/gitea/issues/38654))
  - fix: orgmode render include path ([#&#8203;38642](https://github.com/go-gitea/gitea/issues/38642)) ([#&#8203;38645](https://github.com/go-gitea/gitea/issues/38645))
  - fix(actions): cancel tasks immediately when the runner stopped reporting ([#&#8203;38616](https://github.com/go-gitea/gitea/issues/38616)) ([#&#8203;38644](https://github.com/go-gitea/gitea/issues/38644))
  - fix(issues): fix label bulk-load key and reduce log noise in LoadLabel ([#&#8203;38632](https://github.com/go-gitea/gitea/issues/38632)) ([#&#8203;38643](https://github.com/go-gitea/gitea/issues/38643))
  - fix(actions): improve runner list status sorting, labels and task job links ([#&#8203;38586](https://github.com/go-gitea/gitea/issues/38586)) ([#&#8203;38633](https://github.com/go-gitea/gitea/issues/38633))
  - fix(actions): correctness and hardening fixes ([#&#8203;38518](https://github.com/go-gitea/gitea/issues/38518)) ([#&#8203;38631](https://github.com/go-gitea/gitea/issues/38631))
  - fix(repo): prevent double-write redirect collisions on dependency errors, fix ui ([#&#8203;38627](https://github.com/go-gitea/gitea/issues/38627)) ([#&#8203;38628](https://github.com/go-gitea/gitea/issues/38628))
  - fix: delete repo-scoped rows of seven more tables when deleting a repository ([#&#8203;38534](https://github.com/go-gitea/gitea/issues/38534)) ([#&#8203;38618](https://github.com/go-gitea/gitea/issues/38618))
  - fix(webhook): remove slack channel name check ([#&#8203;38608](https://github.com/go-gitea/gitea/issues/38608)) ([#&#8203;38612](https://github.com/go-gitea/gitea/issues/38612))
  - fix: download dropdown menu clipped on the branches page ([#&#8203;38604](https://github.com/go-gitea/gitea/issues/38604)) ([#&#8203;38609](https://github.com/go-gitea/gitea/issues/38609))
  - fix(project): prevent database mutations on invalid MoveIssues payload ([#&#8203;38600](https://github.com/go-gitea/gitea/issues/38600)) ([#&#8203;38602](https://github.com/go-gitea/gitea/issues/38602))
  - fix(actions): make SingleWorkflow\.Marshal round-trip multi-line run blocks (stop silent job stranding) ([#&#8203;38520](https://github.com/go-gitea/gitea/issues/38520)) ([#&#8203;38599](https://github.com/go-gitea/gitea/issues/38599))
  - fix(file-tree): handle submodule links and missing view container ([#&#8203;38033](https://github.com/go-gitea/gitea/issues/38033)) ([#&#8203;38589](https://github.com/go-gitea/gitea/issues/38589))
  - fix(actions): fail unexpandable reusable workflow callers and decouple the job emitter's cross-run processing ([#&#8203;38565](https://github.com/go-gitea/gitea/issues/38565)) ([#&#8203;38587](https://github.com/go-gitea/gitea/issues/38587))
  - fix: keep serving valid ACME cert when renewal fails at startup ([#&#8203;38554](https://github.com/go-gitea/gitea/issues/38554)) ([#&#8203;38583](https://github.com/go-gitea/gitea/issues/38583))
  - fix: branch protection user list ([#&#8203;38570](https://github.com/go-gitea/gitea/issues/38570)) ([#&#8203;38584](https://github.com/go-gitea/gitea/issues/38584))
  - fix(pulls): respect diff.orderFile in diff file tree ([#&#8203;38566](https://github.com/go-gitea/gitea/issues/38566)) ([#&#8203;38578](https://github.com/go-gitea/gitea/issues/38578))
  - fix(issue): make issue action (issue list batch operation) elements have correct attributes ([#&#8203;38575](https://github.com/go-gitea/gitea/issues/38575)) ([#&#8203;38580](https://github.com/go-gitea/gitea/issues/38580))
  - fix(actions): support `matrix` when evaluating workflow `if` expression ([#&#8203;38474](https://github.com/go-gitea/gitea/issues/38474)) ([#&#8203;38557](https://github.com/go-gitea/gitea/issues/38557))
  - fix(actions): align status icon span for Safari rendering ([#&#8203;38558](https://github.com/go-gitea/gitea/issues/38558)) ([#&#8203;38562](https://github.com/go-gitea/gitea/issues/38562))
  - fix: revert git clone http redirection forbidden ([#&#8203;38530](https://github.com/go-gitea/gitea/issues/38530)) ([#&#8203;38545](https://github.com/go-gitea/gitea/issues/38545))
  - fix: clean up orphaned user-keyed tables in deleteUser ([#&#8203;38511](https://github.com/go-gitea/gitea/issues/38511)) ([#&#8203;38514](https://github.com/go-gitea/gitea/issues/38514))
  - fix(actions): coerce workflow\_dispatch boolean inputs to native types ([#&#8203;38472](https://github.com/go-gitea/gitea/issues/38472)) ([#&#8203;38521](https://github.com/go-gitea/gitea/issues/38521))
  - fix: make the merge box button red if some checks fail ([#&#8203;38508](https://github.com/go-gitea/gitea/issues/38508)) ([#&#8203;38516](https://github.com/go-gitea/gitea/issues/38516))
  - fix(pull): sign the commit when updating a branch by merge ([#&#8203;38441](https://github.com/go-gitea/gitea/issues/38441)) ([#&#8203;38499](https://github.com/go-gitea/gitea/issues/38499))
  - fix: make commit message merge correctly ([#&#8203;38490](https://github.com/go-gitea/gitea/issues/38490)) ([#&#8203;38502](https://github.com/go-gitea/gitea/issues/38502))
  - fix(actions): explain why a blocked or waiting job has not started ([#&#8203;38476](https://github.com/go-gitea/gitea/issues/38476)) ([#&#8203;38498](https://github.com/go-gitea/gitea/issues/38498))
  - fix(actions): make `cancelled()` work in job `if` evaluation ([#&#8203;38495](https://github.com/go-gitea/gitea/issues/38495)) ([#&#8203;38497](https://github.com/go-gitea/gitea/issues/38497))
  - fix(actions): show retention info on hover for expired artifacts ([#&#8203;38477](https://github.com/go-gitea/gitea/issues/38477)) ([#&#8203;38493](https://github.com/go-gitea/gitea/issues/38493))
  - fix(actions): group reusable-workflow matrix legs in the workflow graph ([#&#8203;38475](https://github.com/go-gitea/gitea/issues/38475)) ([#&#8203;38492](https://github.com/go-gitea/gitea/issues/38492))
  - fix: full file highlighting for git diff with CR char ([#&#8203;38484](https://github.com/go-gitea/gitea/issues/38484)) ([#&#8203;38491](https://github.com/go-gitea/gitea/issues/38491))
  - fix(packages): serve noarch Alpine index for any requested architecture ([#&#8203;38479](https://github.com/go-gitea/gitea/issues/38479)) ([#&#8203;38486](https://github.com/go-gitea/gitea/issues/38486))
  - fix: 500 error when updating user visibility ([#&#8203;38480](https://github.com/go-gitea/gitea/issues/38480)) ([#&#8203;38483](https://github.com/go-gitea/gitea/issues/38483))
  - fix(actions): make job list item fully clickable ([#&#8203;38462](https://github.com/go-gitea/gitea/issues/38462)) ([#&#8203;38471](https://github.com/go-gitea/gitea/issues/38471))
  - fix: mail template for push event ([#&#8203;38467](https://github.com/go-gitea/gitea/issues/38467)) ([#&#8203;38468](https://github.com/go-gitea/gitea/issues/38468))
  - fix: make "test push webhook" always work ([#&#8203;38425](https://github.com/go-gitea/gitea/issues/38425)) ([#&#8203;38455](https://github.com/go-gitea/gitea/issues/38455))
  - fix(actions): prevent bulk actions from affecting all runners ([#&#8203;38453](https://github.com/go-gitea/gitea/issues/38453)) ([#&#8203;38457](https://github.com/go-gitea/gitea/issues/38457))
  - fix(org): align follow button and wrap description ([#&#8203;38448](https://github.com/go-gitea/gitea/issues/38448)) ([#&#8203;38454](https://github.com/go-gitea/gitea/issues/38454))
  - fix(actions): populate `github.event` for scheduled runs ([#&#8203;38446](https://github.com/go-gitea/gitea/issues/38446)) ([#&#8203;38452](https://github.com/go-gitea/gitea/issues/38452))

- MISC
  - refactor: git patch apply ([#&#8203;38637](https://github.com/go-gitea/gitea/issues/38637)) ([#&#8203;38638](https://github.com/go-gitea/gitea/issues/38638))

### [`v1.27.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1270---2026-07-13)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.4...v1.27.0)

- BREAKING
  - Feat(actions)!: improve support for reusable workflows ([#&#8203;37478](https://github.com/go-gitea/gitea/issues/37478))
  - Use Content-Security-Policy: script nonce ([#&#8203;37232](https://github.com/go-gitea/gitea/issues/37232))

- SECURITY
  - Fix: various security fixes ([#&#8203;38406](https://github.com/go-gitea/gitea/issues/38406)) ([#&#8203;38426](https://github.com/go-gitea/gitea/issues/38426))
  - Fix(security): harden access checks and migration validation ([#&#8203;38324](https://github.com/go-gitea/gitea/issues/38324)) ([#&#8203;38400](https://github.com/go-gitea/gitea/issues/38400))
  - Fix: enforce public-only token scope and harden push options / locale parsing ([#&#8203;38323](https://github.com/go-gitea/gitea/issues/38323)) ([#&#8203;38399](https://github.com/go-gitea/gitea/issues/38399))
  - Fix(pull): re-evaluate review official flag on target branch change ([#&#8203;38319](https://github.com/go-gitea/gitea/issues/38319)) ([#&#8203;38402](https://github.com/go-gitea/gitea/issues/38402))
  - Fix(api): stop leaking private repo metadata after access revocation ([#&#8203;38321](https://github.com/go-gitea/gitea/issues/38321)) ([#&#8203;38390](https://github.com/go-gitea/gitea/issues/38390))
  - Fix(lfs): require proof of possession for cross-repo objects ([#&#8203;38322](https://github.com/go-gitea/gitea/issues/38322)) ([#&#8203;38389](https://github.com/go-gitea/gitea/issues/38389))
  - Fix(mirror): disable HTTP redirects on pull mirror sync ([#&#8203;38320](https://github.com/go-gitea/gitea/issues/38320)) ([#&#8203;38367](https://github.com/go-gitea/gitea/issues/38367))
  - Fix(release): validate web attachment renames against allowed types ([#&#8203;38314](https://github.com/go-gitea/gitea/issues/38314)) ([#&#8203;38328](https://github.com/go-gitea/gitea/issues/38328))
  - Fix(release): gate draft release attachments on web download endpoints ([#&#8203;38318](https://github.com/go-gitea/gitea/issues/38318)) ([#&#8203;38325](https://github.com/go-gitea/gitea/issues/38325))
  - Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 \[security] ([#&#8203;37786](https://github.com/go-gitea/gitea/issues/37786))
  - Fix(oauth): restrict introspection to the token's client ([#&#8203;38042](https://github.com/go-gitea/gitea/issues/38042))
  - Fix(api): don't expose private org membership via public\_members ([#&#8203;38145](https://github.com/go-gitea/gitea/issues/38145))
  - Fix(actions): deny fork-PR cross-repo access via collaborative owner ([#&#8203;38214](https://github.com/go-gitea/gitea/issues/38214))
  - Fix(migrations): prevent path traversal in repository restore ([#&#8203;38215](https://github.com/go-gitea/gitea/issues/38215))
  - Feat(security): set X-Content-Type-Options: nosniff by default ([#&#8203;37354](https://github.com/go-gitea/gitea/issues/37354))

- FEATURES
  - Feat(actions): add workflow status badge modal ([#&#8203;38196](https://github.com/go-gitea/gitea/issues/38196))
  - Feat(actions): support owner-level and global scoped workflows ([#&#8203;38154](https://github.com/go-gitea/gitea/issues/38154))
  - Feat(api): support ref suffixes in compare ([#&#8203;38148](https://github.com/go-gitea/gitea/issues/38148))
  - Feat(actions): implement `jobs.<job_id>.continue-on-error` ([#&#8203;38100](https://github.com/go-gitea/gitea/issues/38100))
  - Feat(actions): show run status on browser tab favicon ([#&#8203;38071](https://github.com/go-gitea/gitea/issues/38071))
  - Feat(api): add token introspection and self-deletion endpoint ([#&#8203;37995](https://github.com/go-gitea/gitea/issues/37995))
  - Feat(repo): split repository creation limit into user and org scopes ([#&#8203;37872](https://github.com/go-gitea/gitea/issues/37872))
  - Feat(actions): bulk delete, disable and enable runners in admin UI ([#&#8203;37869](https://github.com/go-gitea/gitea/issues/37869))
  - Feat(actions): List workflows that were executed once but got removed from the default branch ([#&#8203;37835](https://github.com/go-gitea/gitea/issues/37835))
  - Feat(org): add team visibility so org members can discover teams ([#&#8203;37680](https://github.com/go-gitea/gitea/issues/37680))
  - Feat: add raw diff/patch endpoint for repository comparisons ([#&#8203;37632](https://github.com/go-gitea/gitea/issues/37632))
  - Feat(oauth): Support AWS Cognito OAuth2 provider ([#&#8203;37607](https://github.com/go-gitea/gitea/issues/37607))
  - Feat: Add avatar stacks ([#&#8203;37594](https://github.com/go-gitea/gitea/issues/37594))
  - Feat(actions): add job summaries (GITHUB\_STEP\_SUMMARY) ([#&#8203;37500](https://github.com/go-gitea/gitea/issues/37500))
  - Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support ([#&#8203;37433](https://github.com/go-gitea/gitea/issues/37433))
  - Support for Custom URI Schemes in OAuth2 Redirect URIs ([#&#8203;37356](https://github.com/go-gitea/gitea/issues/37356))
  - Feat(orgs): Add search bar for organization members tab page ([#&#8203;37347](https://github.com/go-gitea/gitea/issues/37347))
  - Feat(api): Add assignees APIs ([#&#8203;37330](https://github.com/go-gitea/gitea/issues/37330))
  - Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow\_id}/runs ([#&#8203;37196](https://github.com/go-gitea/gitea/issues/37196))
  - Introduce `ActionRunAttempt` to represent each execution of a run ([#&#8203;37119](https://github.com/go-gitea/gitea/issues/37119))
  - Serve OpenAPI 3.0 spec at /openapi.v1.json ([#&#8203;37038](https://github.com/go-gitea/gitea/issues/37038))
  - Add project column picker to issue and pull request sidebar ([#&#8203;37037](https://github.com/go-gitea/gitea/issues/37037))
  - Allow multiple projects per issue and pull requests ([#&#8203;36784](https://github.com/go-gitea/gitea/issues/36784))
  - Add bulk repository deletion for organizations ([#&#8203;36763](https://github.com/go-gitea/gitea/issues/36763))
  - Add API endpoint to reply to pull request review comments ([#&#8203;36683](https://github.com/go-gitea/gitea/issues/36683))
  - Feat: Add bypass allowlist for branch protection ([#&#8203;36514](https://github.com/go-gitea/gitea/issues/36514))
  - Feat(ui): add "follow rename" to file commit history list ([#&#8203;34994](https://github.com/go-gitea/gitea/issues/34994))
  - Feat(ssh): auto generate additional ssh keys ([#&#8203;33974](https://github.com/go-gitea/gitea/issues/33974))

- ENHANCEMENTS
  - Enhance(actions): only create filtered-out workflow commit status for required contexts ([#&#8203;38371](https://github.com/go-gitea/gitea/issues/38371)) ([#&#8203;38385](https://github.com/go-gitea/gitea/issues/38385))
  - Enhance: allow builtin default git config options to be overridden ([#&#8203;38172](https://github.com/go-gitea/gitea/issues/38172))
  - Enhance: allow MathML core elements ([#&#8203;38034](https://github.com/go-gitea/gitea/issues/38034))
  - Feat(api): add q parameter to list branches API for server-side filtering ([#&#8203;37982](https://github.com/go-gitea/gitea/issues/37982))
  - Enhance(markup): improve issue title rendering ([#&#8203;37908](https://github.com/go-gitea/gitea/issues/37908))
  - Enhance(actions): set descriptive browser tab title on run view ([#&#8203;37870](https://github.com/go-gitea/gitea/issues/37870))
  - Enhance(actions): show workflow name from YAML instead of filename ([#&#8203;37833](https://github.com/go-gitea/gitea/issues/37833))
  - Feat(actions): add before/after to PR synchronize event payload ([#&#8203;37827](https://github.com/go-gitea/gitea/issues/37827))
  - Enhance(actions): add branch filters to run list ([#&#8203;37826](https://github.com/go-gitea/gitea/issues/37826))
  - Enhance(actions): Make Summary UI more beautiful with more infos ([#&#8203;37824](https://github.com/go-gitea/gitea/issues/37824))
  - Feat: add copy button to action step header, improve other copy buttons ([#&#8203;37744](https://github.com/go-gitea/gitea/issues/37744))
  - Feat(web): also display PR counts in repo list ([#&#8203;37739](https://github.com/go-gitea/gitea/issues/37739))
  - Fix(icon): use repo-forked icon to display forks count ([#&#8203;37731](https://github.com/go-gitea/gitea/issues/37731))
  - Feat(api): add sort and order query parameters to job list endpoints ([#&#8203;37672](https://github.com/go-gitea/gitea/issues/37672))
  - Feat(api): add last\_sync to repository API ([#&#8203;37566](https://github.com/go-gitea/gitea/issues/37566))
  - Enhance: Adjust Workflow Graph styling ([#&#8203;37497](https://github.com/go-gitea/gitea/issues/37497))
  - Improve code editor text selection and clean up lint enablement ([#&#8203;37474](https://github.com/go-gitea/gitea/issues/37474))
  - Add mirror auth updates to repo edit API and settings ([#&#8203;37468](https://github.com/go-gitea/gitea/issues/37468))
  - Feat: Add default PR branch update style setting ([#&#8203;37410](https://github.com/go-gitea/gitea/issues/37410))
  - Fix inconsistent disabled styling on logged-out repo header buttons ([#&#8203;37406](https://github.com/go-gitea/gitea/issues/37406))
  - Allow fast-forward-only merge when signed commits are required ([#&#8203;37335](https://github.com/go-gitea/gitea/issues/37335))
  - Enhance styling in actions page ([#&#8203;37323](https://github.com/go-gitea/gitea/issues/37323))
  - Add `ExternalIDClaim` option for OAuth2 OIDC auth source ([#&#8203;37229](https://github.com/go-gitea/gitea/issues/37229))
  - Fix: improve actions status icons and texts ([#&#8203;37206](https://github.com/go-gitea/gitea/issues/37206))
  - Make Markdown fenced code block work with more syntaxes ([#&#8203;37154](https://github.com/go-gitea/gitea/issues/37154))
  - Fix: Sort action run jobs by JobID and Name with matrix examples ([#&#8203;37046](https://github.com/go-gitea/gitea/issues/37046))
  - Add pagination and search box to org teams list ([#&#8203;37245](https://github.com/go-gitea/gitea/issues/37245))
  - Workflow Artifact Info Hover ([#&#8203;37100](https://github.com/go-gitea/gitea/issues/37100))
  - Feat(editor): broaden language detection in web code editor ([#&#8203;37619](https://github.com/go-gitea/gitea/issues/37619))

- PERFORMANCE
  - Perf(actions): debounce runner heartbeat writes and throttle task picks ([#&#8203;38281](https://github.com/go-gitea/gitea/issues/38281)) ([#&#8203;38368](https://github.com/go-gitea/gitea/issues/38368))
  - Perf(web): sort the action\_run query by a repo-scoped index when possible ([#&#8203;38155](https://github.com/go-gitea/gitea/issues/38155))
  - Perf: Various performance regression fixes ([#&#8203;38078](https://github.com/go-gitea/gitea/issues/38078))
  - Perf: extend action `c_u` index to include `created_unix` for faster dashboard feeds ([#&#8203;38076](https://github.com/go-gitea/gitea/issues/38076))
  - Batch-load related data in actions run, job, and task API endpoints ([#&#8203;37032](https://github.com/go-gitea/gitea/issues/37032))

- BUGFIXES
  - Fix(util): reject invalid characters between time-estimate units ([#&#8203;38416](https://github.com/go-gitea/gitea/issues/38416)) ([#&#8203;38423](https://github.com/go-gitea/gitea/issues/38423))
  - Fix: represent a deleted assignee team as a Ghost team ([#&#8203;38413](https://github.com/go-gitea/gitea/issues/38413)) ([#&#8203;38419](https://github.com/go-gitea/gitea/issues/38419))
  - Fix(turnstile): route CAPTCHA verification through the configured proxy ([#&#8203;38412](https://github.com/go-gitea/gitea/issues/38412)) ([#&#8203;38420](https://github.com/go-gitea/gitea/issues/38420))
  - Fix: refresh pull request merge box when the commit status is pending ([#&#8203;38410](https://github.com/go-gitea/gitea/issues/38410)) ([#&#8203;38411](https://github.com/go-gitea/gitea/issues/38411))
  - Fix: actions task state concurrent update ([#&#8203;38405](https://github.com/go-gitea/gitea/issues/38405)) ([#&#8203;38409](https://github.com/go-gitea/gitea/issues/38409))
  - Fix(actions): keep workflow run trailing on one row with long branch names ([#&#8203;38382](https://github.com/go-gitea/gitea/issues/38382)) ([#&#8203;38403](https://github.com/go-gitea/gitea/issues/38403))
  - Fix(web): use locale-aware date formatting for contribution calendar tooltips ([#&#8203;38398](https://github.com/go-gitea/gitea/issues/38398)) ([#&#8203;38401](https://github.com/go-gitea/gitea/issues/38401))
  - Fix: co-author detection ([#&#8203;38392](https://github.com/go-gitea/gitea/issues/38392)) ([#&#8203;38397](https://github.com/go-gitea/gitea/issues/38397))
  - Fix: incorrect co-author detection on commit page ([#&#8203;38386](https://github.com/go-gitea/gitea/issues/38386)) ([#&#8203;38387](https://github.com/go-gitea/gitea/issues/38387))
  - Fix(ui): restore commits table column widths ([#&#8203;38379](https://github.com/go-gitea/gitea/issues/38379)) ([#&#8203;38383](https://github.com/go-gitea/gitea/issues/38383))
  - Fix: golang html template url escaping ([#&#8203;38363](https://github.com/go-gitea/gitea/issues/38363)) ([#&#8203;38369](https://github.com/go-gitea/gitea/issues/38369))
  - Fix: minio init check ([#&#8203;38355](https://github.com/go-gitea/gitea/issues/38355)) ([#&#8203;38361](https://github.com/go-gitea/gitea/issues/38361))
  - Fix: org project view assignee list ([#&#8203;38357](https://github.com/go-gitea/gitea/issues/38357)) ([#&#8203;38360](https://github.com/go-gitea/gitea/issues/38360))
  - Fix(actions): release claimed task if context is cancelled during `FetchTask` ([#&#8203;38343](https://github.com/go-gitea/gitea/issues/38343)) ([#&#8203;38347](https://github.com/go-gitea/gitea/issues/38347))
  - Fix(actions): make runner list pagination order deterministic ([#&#8203;38313](https://github.com/go-gitea/gitea/issues/38313)) ([#&#8203;38327](https://github.com/go-gitea/gitea/issues/38327))
  - Fix: Improve since/until when counting commits for X-Total-Count ([#&#8203;38243](https://github.com/go-gitea/gitea/issues/38243)) ([#&#8203;38304](https://github.com/go-gitea/gitea/issues/38304))
  - Fix(actions): prevent chevron overlap with log text when timestamps are enabled ([#&#8203;38227](https://github.com/go-gitea/gitea/issues/38227)) ([#&#8203;38307](https://github.com/go-gitea/gitea/issues/38307))
  - Fix(workflows): branch protection status checks fail when workflow uses on: paths filter ([#&#8203;38237](https://github.com/go-gitea/gitea/issues/38237)) ([#&#8203;38302](https://github.com/go-gitea/gitea/issues/38302))
  - Fix(oauth2): persist linkAccountData during auto-link 2FA flow ([#&#8203;38274](https://github.com/go-gitea/gitea/issues/38274)) ([#&#8203;38295](https://github.com/go-gitea/gitea/issues/38295))
  - Fix(actions): allow Actions bot to push to protected branches ([#&#8203;38284](https://github.com/go-gitea/gitea/issues/38284)) ([#&#8203;38293](https://github.com/go-gitea/gitea/issues/38293))
  - Fix(actions): include all aggregable run statuses in status filter ([#&#8203;38280](https://github.com/go-gitea/gitea/issues/38280)) ([#&#8203;38287](https://github.com/go-gitea/gitea/issues/38287))
  - Fix(archiver): use serializable repo-archive queue payload ([#&#8203;38273](https://github.com/go-gitea/gitea/issues/38273)) ([#&#8203;38283](https://github.com/go-gitea/gitea/issues/38283))
  - Fix: update npm dependencies, fix misc issues ([#&#8203;38257](https://github.com/go-gitea/gitea/issues/38257))
  - Fix(api): respect since/until when counting commits for X-Total-Count ([#&#8203;38204](https://github.com/go-gitea/gitea/issues/38204))
  - Fix: codemirror regressions ([#&#8203;38248](https://github.com/go-gitea/gitea/issues/38248))
  - Fix(api): support HEAD requests on all API GET endpoints ([#&#8203;38245](https://github.com/go-gitea/gitea/issues/38245))
  - Fix(actions): Cleanup workflow status badge code ([#&#8203;38241](https://github.com/go-gitea/gitea/issues/38241))
  - Fix(web): Correctly align the "disabled" label on larger workflow names ([#&#8203;38240](https://github.com/go-gitea/gitea/issues/38240))
  - Fix(actions): don't swallow HTML entities into linkified URLs ([#&#8203;38239](https://github.com/go-gitea/gitea/issues/38239))
  - Fix(packages): accept npm "repository" and "bin" in string form ([#&#8203;38236](https://github.com/go-gitea/gitea/issues/38236))
  - Fix(actions): fix 500 error when canceling a canceling task ([#&#8203;38223](https://github.com/go-gitea/gitea/issues/38223))
  - Fix(deps): update module golang.org/x/image to v0.43.0 \[security] ([#&#8203;38219](https://github.com/go-gitea/gitea/issues/38219))
  - Fix(mssql): convert legacy DATETIME columns to DATETIME2 ([#&#8203;38216](https://github.com/go-gitea/gitea/issues/38216))
  - Fix(api): deny private org member enumeration via /members ([#&#8203;38213](https://github.com/go-gitea/gitea/issues/38213))
  - Fix(actions): ensure all waiting jobs get runners in large workflows ([#&#8203;38200](https://github.com/go-gitea/gitea/issues/38200))
  - Fix(deps): update go dependencies ([#&#8203;38194](https://github.com/go-gitea/gitea/issues/38194))
  - Fix(deps): update npm dependencies ([#&#8203;38193](https://github.com/go-gitea/gitea/issues/38193))
  - Fix(cli): default must-change-password to false for bot users ([#&#8203;38175](https://github.com/go-gitea/gitea/issues/38175))
  - Fix(actions): show run index in run view and fix summary graph height ([#&#8203;38165](https://github.com/go-gitea/gitea/issues/38165))
  - Fix: csp ([#&#8203;38162](https://github.com/go-gitea/gitea/issues/38162))
  - Fix(deps): update npm dependencies ([#&#8203;38123](https://github.com/go-gitea/gitea/issues/38123))
  - Fix(mssql): expand legacy issue and comment long-text columns ([#&#8203;38120](https://github.com/go-gitea/gitea/issues/38120))
  - Fix(packages): validate debian distribution and component names ([#&#8203;38116](https://github.com/go-gitea/gitea/issues/38116))
  - Fix(packages): validate module version in goproxy ParsePackage ([#&#8203;38104](https://github.com/go-gitea/gitea/issues/38104))
  - Fix(deps): update dependency esbuild to v0.28.1 \[security] ([#&#8203;38097](https://github.com/go-gitea/gitea/issues/38097))
  - Fix: git push hook post receive ([#&#8203;38089](https://github.com/go-gitea/gitea/issues/38089))
  - Fix(ui): prevent commit status popup overflowing its row ([#&#8203;38081](https://github.com/go-gitea/gitea/issues/38081))
  - Fix: validate gem name in rubygems parseMetadataFile ([#&#8203;38061](https://github.com/go-gitea/gitea/issues/38061))
  - Fix: commit display name ([#&#8203;38057](https://github.com/go-gitea/gitea/issues/38057))
  - Fix: csp regressions ([#&#8203;38047](https://github.com/go-gitea/gitea/issues/38047))
  - Fix: api error message ([#&#8203;38031](https://github.com/go-gitea/gitea/issues/38031))
  - Fix(deps): update npm dependencies ([#&#8203;38029](https://github.com/go-gitea/gitea/issues/38029))
  - Fix: pgsql lint ([#&#8203;38022](https://github.com/go-gitea/gitea/issues/38022))
  - Fix(indexer): fix assignee filters in issue search ([#&#8203;38021](https://github.com/go-gitea/gitea/issues/38021))
  - Fix: various dropdown problems ([#&#8203;38020](https://github.com/go-gitea/gitea/issues/38020))
  - Fix: refactor git error handling and make archive streaming handle non-existing commit id ([#&#8203;38007](https://github.com/go-gitea/gitea/issues/38007))
  - Fix: raise git required version to 2.13 ([#&#8203;37996](https://github.com/go-gitea/gitea/issues/37996))
  - Fix: remove "no-transfrom" from the cache-control header ([#&#8203;37985](https://github.com/go-gitea/gitea/issues/37985))
  - Fix(deps): update module github.com/google/go-github/v87 to v88 ([#&#8203;37971](https://github.com/go-gitea/gitea/issues/37971))
  - Fix: use committer time where ever possible as default ([#&#8203;37969](https://github.com/go-gitea/gitea/issues/37969))
  - Fix(deps): update npm dependencies, remove nolyfill ([#&#8203;37968](https://github.com/go-gitea/gitea/issues/37968))
  - Fix(deps): update go dependencies ([#&#8203;37967](https://github.com/go-gitea/gitea/issues/37967))
  - Fix(pull): preserve squash message trailers and additional commit messages ([#&#8203;37954](https://github.com/go-gitea/gitea/issues/37954))
  - Fix(deps): update module golang.org/x/image to v0.41.0 \[security] ([#&#8203;37904](https://github.com/go-gitea/gitea/issues/37904))
  - Fix: support ##\[command] log prefix in action run UI ([#&#8203;37882](https://github.com/go-gitea/gitea/issues/37882))
  - Fix(deps): update module github.com/google/go-github/v86 to v87 ([#&#8203;37845](https://github.com/go-gitea/gitea/issues/37845))
  - Fix(deps): update npm dependencies ([#&#8203;37844](https://github.com/go-gitea/gitea/issues/37844))
  - Fix(deps): update go dependencies ([#&#8203;37841](https://github.com/go-gitea/gitea/issues/37841))
  - Fix(frontend): resolve Vite assets by manifest source path ([#&#8203;37836](https://github.com/go-gitea/gitea/issues/37836))
  - Fix(locales): Replace hardcoded strings ([#&#8203;37788](https://github.com/go-gitea/gitea/issues/37788))
  - Fix(packages): render markdown links relative to linked repo ([#&#8203;37676](https://github.com/go-gitea/gitea/issues/37676))
  - Fix: persist mirror repository metadata ([#&#8203;37519](https://github.com/go-gitea/gitea/issues/37519))
  - Fix cmd tests by mocking builtin paths ([#&#8203;37369](https://github.com/go-gitea/gitea/issues/37369))
  - Add `form-fetch-action` to some forms, fix "fetch action" resp bug ([#&#8203;37305](https://github.com/go-gitea/gitea/issues/37305))
  - Feat: execute post run cleanup when workflow is cancelled ([#&#8203;37275](https://github.com/go-gitea/gitea/issues/37275))
  - Fix `relative-time` error and improve global error handler ([#&#8203;37241](https://github.com/go-gitea/gitea/issues/37241))
  - Refactor flash message and remove SanitizeHTML template func ([#&#8203;37179](https://github.com/go-gitea/gitea/issues/37179))
  - Fix Repository transferring page ([#&#8203;37277](https://github.com/go-gitea/gitea/issues/37277))

- TESTING
  - Test(e2e): fix race in pdf file render test ([#&#8203;38380](https://github.com/go-gitea/gitea/issues/38380)) ([#&#8203;38381](https://github.com/go-gitea/gitea/issues/38381))
  - Test: compare key file contents instead of `FileInfo` in `TestInitKeys` ([#&#8203;38330](https://github.com/go-gitea/gitea/issues/38330)) ([#&#8203;38331](https://github.com/go-gitea/gitea/issues/38331))
  - Test: speed up two tests ([#&#8203;37905](https://github.com/go-gitea/gitea/issues/37905))
  - Test: Fix random failure test ([#&#8203;37887](https://github.com/go-gitea/gitea/issues/37887))
  - Test: fix flaky `issue-comment` close test ([#&#8203;37880](https://github.com/go-gitea/gitea/issues/37880))
  - Test: enable WAL for sqlite integration tests ([#&#8203;37861](https://github.com/go-gitea/gitea/issues/37861))
  - Test: fix flaky `TestResourceIndex` and reduce its runtime ([#&#8203;37847](https://github.com/go-gitea/gitea/issues/37847))
  - Test: run `TestAPIRepoMigrate` offline via a local clone source ([#&#8203;37817](https://github.com/go-gitea/gitea/issues/37817))
  - Ci: shard tests and reduce redundant work ([#&#8203;37618](https://github.com/go-gitea/gitea/issues/37618))
  - Test(e2e): run playwright via container ([#&#8203;37300](https://github.com/go-gitea/gitea/issues/37300))
  - Remove external service dependencies in migration tests ([#&#8203;36866](https://github.com/go-gitea/gitea/issues/36866))
  - Refactor: only reset a database table when the table's data was changed ([#&#8203;37573](https://github.com/go-gitea/gitea/issues/37573))

- BUILD
  - Refactor: use modernc sqlite driver as default ([#&#8203;37562](https://github.com/go-gitea/gitea/issues/37562))
  - Fix(actions): authenticate snapcraft before nightly remote build ([#&#8203;38252](https://github.com/go-gitea/gitea/issues/38252))
  - Ci: cap Elasticsearch heap in db-tests ([#&#8203;37816](https://github.com/go-gitea/gitea/issues/37816))
  - Build(snap): publish nightly version to snapcraft via actions ([#&#8203;37814](https://github.com/go-gitea/gitea/issues/37814))
  - Ci: split pgsql shards into plain jobs, dedupe setup actions ([#&#8203;37802](https://github.com/go-gitea/gitea/issues/37802))
  - Ci: narrow files-changed frontend filter ([#&#8203;37749](https://github.com/go-gitea/gitea/issues/37749))
  - Ci: add `zizmor` to `lint-actions` ([#&#8203;37720](https://github.com/go-gitea/gitea/issues/37720))
  - Chore: clean up "contrib" dir ([#&#8203;37690](https://github.com/go-gitea/gitea/issues/37690))
  - Fix: snap build (main branch) ([#&#8203;37685](https://github.com/go-gitea/gitea/issues/37685))
  - Ci: Also lint json5 files ([#&#8203;37659](https://github.com/go-gitea/gitea/issues/37659))
  - Build: update pnpm to v11 ([#&#8203;37591](https://github.com/go-gitea/gitea/issues/37591))
  - Refactor(deps): migrate from `nektos/act` fork to `gitea/runner` ([#&#8203;37557](https://github.com/go-gitea/gitea/issues/37557))
  - Update go js py dependencies ([#&#8203;37525](https://github.com/go-gitea/gitea/issues/37525))
  - Ci: lint PR titles with commitlint ([#&#8203;37498](https://github.com/go-gitea/gitea/issues/37498))
  - Chore: upgrade Go version in devcontainer image to 1.26 ([#&#8203;37374](https://github.com/go-gitea/gitea/issues/37374))
  - Update GitHub Actions to latest major versions ([#&#8203;37313](https://github.com/go-gitea/gitea/issues/37313))
  - Update go js dependencies ([#&#8203;37312](https://github.com/go-gitea/gitea/issues/37312))
  - Fail vite build on rolldown warnings via NODE\_ENV=test ([#&#8203;37270](https://github.com/go-gitea/gitea/issues/37270))
  - Replace custom Go formatter with `golangci-lint fmt` ([#&#8203;37194](https://github.com/go-gitea/gitea/issues/37194))
  - Integrate renovate bot for all dependency updates ([#&#8203;37050](https://github.com/go-gitea/gitea/issues/37050))
  - Build(sign): move to sigstore ([#&#8203;38250](https://github.com/go-gitea/gitea/issues/38250))

- DOCS
  - Docs: update changelog for 1.26.3 & 1.26.4 ([#&#8203;38178](https://github.com/go-gitea/gitea/issues/38178))
  - Update 1.26.1 changelog in main ([#&#8203;37442](https://github.com/go-gitea/gitea/issues/37442))
  - Docs: fix duplicated word in foreachref doc comment ([#&#8203;38161](https://github.com/go-gitea/gitea/issues/38161))
  - Docs: Clarify criteria for becoming a merger ([#&#8203;38113](https://github.com/go-gitea/gitea/issues/38113))
  - Docs: Publish TOC Election Result 2026 ([#&#8203;38111](https://github.com/go-gitea/gitea/issues/38111))
  - Docs: mark openapi3 as autogenerated in attributes ([#&#8203;37963](https://github.com/go-gitea/gitea/issues/37963))
  - Docs: add development setup guide ([#&#8203;37960](https://github.com/go-gitea/gitea/issues/37960))

- MISC
  - Refactor: lint bare `fill`/`stroke` colors, add vars for git graph color series ([#&#8203;37543](https://github.com/go-gitea/gitea/issues/37543))
  - Remove htmx ([#&#8203;37224](https://github.com/go-gitea/gitea/issues/37224))
  - Refactor htmx and fetch-action related code ([#&#8203;37186](https://github.com/go-gitea/gitea/issues/37186))
  - Revert(sign): restore gpg ([#&#8203;38251](https://github.com/go-gitea/gitea/issues/38251))
  - Refactor: replace legacy `delete-button` with `link-action` ([#&#8203;38143](https://github.com/go-gitea/gitea/issues/38143))
  - Refactor(actions): read runner capabilities from proto field ([#&#8203;38068](https://github.com/go-gitea/gitea/issues/38068))
  - Refactor(api): clarify APIError message usage and fix legacy lint error ([#&#8203;38012](https://github.com/go-gitea/gitea/issues/38012))
  - Refactor: Use db.Get\[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record ([#&#8203;37977](https://github.com/go-gitea/gitea/issues/37977))
  - Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 ([#&#8203;37866](https://github.com/go-gitea/gitea/issues/37866))
  - Fix(deps): update go dependencies ([#&#8203;37851](https://github.com/go-gitea/gitea/issues/37851))
  - Ci: Fix sync PR labels from the conventional-commit title ([#&#8203;37784](https://github.com/go-gitea/gitea/issues/37784)) ([#&#8203;37825](https://github.com/go-gitea/gitea/issues/37825))
  - Ci: tweak `files-changed`, add `free-disk-space` ([#&#8203;37819](https://github.com/go-gitea/gitea/issues/37819))
  - Fix(deps): update module golang.org/x/crypto to v0.52.0 \[security] ([#&#8203;37806](https://github.com/go-gitea/gitea/issues/37806))
  - Test(e2e): add comment, release, star, PR and fork tests ([#&#8203;37800](https://github.com/go-gitea/gitea/issues/37800))
  - Chore: simplify issue and pull request templates ([#&#8203;37799](https://github.com/go-gitea/gitea/issues/37799))
  - Chore: Update giteabot to fix failure when backport ([#&#8203;37789](https://github.com/go-gitea/gitea/issues/37789))
  - Fix(api): handle partial failures in push mirror synchronization gracefully ([#&#8203;37782](https://github.com/go-gitea/gitea/issues/37782))
  - Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 ([#&#8203;37771](https://github.com/go-gitea/gitea/issues/37771))
  - Ci: split giteabot workflow ([#&#8203;37770](https://github.com/go-gitea/gitea/issues/37770))
  - Fix(deps): update npm dependencies ([#&#8203;37768](https://github.com/go-gitea/gitea/issues/37768))
  - Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go ([#&#8203;37764](https://github.com/go-gitea/gitea/issues/37764))
  - Fix(deps): update module google.golang.org/grpc to v1.81.1 ([#&#8203;37762](https://github.com/go-gitea/gitea/issues/37762))
  - Ci: fix cache-related issues ([#&#8203;37761](https://github.com/go-gitea/gitea/issues/37761))
  - Chore: fix tests ([#&#8203;37760](https://github.com/go-gitea/gitea/issues/37760))
  - Fix(deps): update module github.com/google/go-github/v85 to v86 ([#&#8203;37754](https://github.com/go-gitea/gitea/issues/37754))
  - Fix(deps): update npm dependencies ([#&#8203;37753](https://github.com/go-gitea/gitea/issues/37753))
  - Fix(deps): update go dependencies ([#&#8203;37752](https://github.com/go-gitea/gitea/issues/37752))
  - Chore(deps): update action dependencies ([#&#8203;37751](https://github.com/go-gitea/gitea/issues/37751))
  - Fix(markup): wrap indented code blocks for the code-copy button ([#&#8203;37748](https://github.com/go-gitea/gitea/issues/37748))
  - Chore(db): introduce db.Session and db.EngineMigration interfaces ([#&#8203;37746](https://github.com/go-gitea/gitea/issues/37746))
  - Refactor(glob): use strings.Builder for regexp compilation ([#&#8203;37730](https://github.com/go-gitea/gitea/issues/37730))
  - Chore(doctor): remove four obsolete doctor check implementations ([#&#8203;37728](https://github.com/go-gitea/gitea/issues/37728))
  - Refactor(org): simplify owner-team org repo creation logic ([#&#8203;37727](https://github.com/go-gitea/gitea/issues/37727))
  - Refactor: move `workflowpattern` into `modules/actions` ([#&#8203;37717](https://github.com/go-gitea/gitea/issues/37717))
  - Chore: clean up tests ([#&#8203;37715](https://github.com/go-gitea/gitea/issues/37715))
  - Style: misc UI fixes ([#&#8203;37691](https://github.com/go-gitea/gitea/issues/37691))
  - Ci: add shellcheck linter ([#&#8203;37682](https://github.com/go-gitea/gitea/issues/37682))
  - Fix: catch and fix more lint problems ([#&#8203;37674](https://github.com/go-gitea/gitea/issues/37674))
  - Fix(deps): update dependency mermaid to v11.15.0 \[security], add e2e test ([#&#8203;37662](https://github.com/go-gitea/gitea/issues/37662))
  - Fix(deps): update npm dependencies ([#&#8203;37647](https://github.com/go-gitea/gitea/issues/37647))
  - Ci(renovate): update Go import paths on major bumps ([#&#8203;37641](https://github.com/go-gitea/gitea/issues/37641))
  - Fix(deps): update go dependencies (major) ([#&#8203;37639](https://github.com/go-gitea/gitea/issues/37639))
  - Chore(deps): update action dependencies (major) ([#&#8203;37638](https://github.com/go-gitea/gitea/issues/37638))
  - Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 ([#&#8203;37637](https://github.com/go-gitea/gitea/issues/37637))
  - Fix(deps): update npm dependencies ([#&#8203;37636](https://github.com/go-gitea/gitea/issues/37636))
  - Refactor(log): replace log.Critical with log.Error ([#&#8203;37624](https://github.com/go-gitea/gitea/issues/37624))
  - Build(deps): bump fast-uri from 3.1.0 to 3.1.2 ([#&#8203;37616](https://github.com/go-gitea/gitea/issues/37616))
  - Chore(deps): update action dependencies ([#&#8203;37603](https://github.com/go-gitea/gitea/issues/37603))
  - Ci: allow `chore` type in PR title lint ([#&#8203;37575](https://github.com/go-gitea/gitea/issues/37575))
  - Ci: increase renovate frequency and fix RENOVATE\_ALLOWED\_POST\_UPGRADE\_COMMANDS ([#&#8203;37565](https://github.com/go-gitea/gitea/issues/37565))
  - Docs: fix 4 typos in CHANGELOG.md ([#&#8203;37549](https://github.com/go-gitea/gitea/issues/37549))
  - Fix(deps): update go dependencies ([#&#8203;37541](https://github.com/go-gitea/gitea/issues/37541))
  - Chore(deps): update action dependencies ([#&#8203;37540](https://github.com/go-gitea/gitea/issues/37540))
  - Refactor pull request view (6) ([#&#8203;37522](https://github.com/go-gitea/gitea/issues/37522))
  - Fix: redirect early CLI console logger to stderr ([#&#8203;37507](https://github.com/go-gitea/gitea/issues/37507))
  - Refactor "flex-list" to "flex-divided-list" ([#&#8203;37505](https://github.com/go-gitea/gitea/issues/37505))
  - Refactor compare diff/pull page (1) ([#&#8203;37481](https://github.com/go-gitea/gitea/issues/37481))
  - Refactor pull request view (4) ([#&#8203;37451](https://github.com/go-gitea/gitea/issues/37451))
  - Refactor: use named `Permission` field in `Repository` struct instead of anonymous embedding ([#&#8203;37441](https://github.com/go-gitea/gitea/issues/37441))
  - Replace `olivere/elastic` with REST API client, add OpenSearch support ([#&#8203;37411](https://github.com/go-gitea/gitea/issues/37411))
  - Refactor: serve site manifest via `/assets/site-manifest.json` endpoint ([#&#8203;37405](https://github.com/go-gitea/gitea/issues/37405))
  - Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites ([#&#8203;37364](https://github.com/go-gitea/gitea/issues/37364))
  - Update `Block a user` form ([#&#8203;37359](https://github.com/go-gitea/gitea/issues/37359))
  - Move review request functions to a standalone file ([#&#8203;37358](https://github.com/go-gitea/gitea/issues/37358))
  - Enable strict TypeScript, add `errorMessage` helper ([#&#8203;37292](https://github.com/go-gitea/gitea/issues/37292))
  - Refactor frontend `tw-justify-between` layouts to `flex-left-right` ([#&#8203;37291](https://github.com/go-gitea/gitea/issues/37291))
  - Update Nix flake ([#&#8203;37284](https://github.com/go-gitea/gitea/issues/37284))
  - Remove `SubmitEvent` polyfill ([#&#8203;37276](https://github.com/go-gitea/gitea/issues/37276))
  - Remove dead code identified by `deadcode` tool ([#&#8203;37271](https://github.com/go-gitea/gitea/issues/37271))
  - Upgrade go-git to v5.18.0 ([#&#8203;37268](https://github.com/go-gitea/gitea/issues/37268))
  - Don't add useless labels which will bother changelog generation ([#&#8203;37267](https://github.com/go-gitea/gitea/issues/37267))
  - Move heatmap to first-party code ([#&#8203;37262](https://github.com/go-gitea/gitea/issues/37262))
  - Tests/integration: simplify code ([#&#8203;37249](https://github.com/go-gitea/gitea/issues/37249))
  - Remove error returns from crypto random helpers and callers ([#&#8203;37240](https://github.com/go-gitea/gitea/issues/37240))
  - Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries ([#&#8203;37210](https://github.com/go-gitea/gitea/issues/37210))
  - Refactor "htmx" to "fetch action" ([#&#8203;37208](https://github.com/go-gitea/gitea/issues/37208))
  - Update go js py dependencies ([#&#8203;37204](https://github.com/go-gitea/gitea/issues/37204))
  - Add comment for the design of "user activity time" ([#&#8203;37195](https://github.com/go-gitea/gitea/issues/37195))
  - Remove outdated RunUser logic ([#&#8203;37180](https://github.com/go-gitea/gitea/issues/37180))
  - Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files ([#&#8203;37150](https://github.com/go-gitea/gitea/issues/37150))
  - Update javascript dependencies ([#&#8203;37142](https://github.com/go-gitea/gitea/issues/37142))
  - Update go dependencies ([#&#8203;37141](https://github.com/go-gitea/gitea/issues/37141))
  - Frontport changelog of v1.26.0-rc0 ([#&#8203;37138](https://github.com/go-gitea/gitea/issues/37138))
  - Extend issue context popup beyond markdown content ([#&#8203;36908](https://github.com/go-gitea/gitea/issues/36908))

### [`v1.26.4`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1264---2026-06-21)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.3...v1.26.4)

- SECURITY
  - fix(auth): do not auto-reactivate disabled users on OAuth2 callback ([#&#8203;38009](https://github.com/go-gitea/gitea/issues/38009)) ([#&#8203;38183](https://github.com/go-gitea/gitea/issues/38183))

- BUGFIXES
  - fix: walk git log context error handling ([#&#8203;38182](https://github.com/go-gitea/gitea/issues/38182)) ([#&#8203;38185](https://github.com/go-gitea/gitea/issues/38185))

### [`v1.26.3`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1263---2026-06-18)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.2...v1.26.3)

- BREAKING
  - fix(actions)!: require merged PR to bypass fork PR approval gate ([#&#8203;38010](https://github.com/go-gitea/gitea/issues/38010)) ([#&#8203;38041](https://github.com/go-gitea/gitea/issues/38041))

- SECURITY
  - fix(hostmatcher): patch incorrect private list ([#&#8203;38170](https://github.com/go-gitea/gitea/issues/38170)) ([#&#8203;38173](https://github.com/go-gitea/gitea/issues/38173))
  - fix: Various security fixes ([#&#8203;38103](https://github.com/go-gitea/gitea/issues/38103)) ([#&#8203;38151](https://github.com/go-gitea/gitea/issues/38151))
  - fix: Various sec fixes ([#&#8203;38108](https://github.com/go-gitea/gitea/issues/38108)) ([#&#8203;38147](https://github.com/go-gitea/gitea/issues/38147))
  - fix: allow git clone of private repos with anonymous code access ([#&#8203;38074](https://github.com/go-gitea/gitea/issues/38074)) ([#&#8203;38146](https://github.com/go-gitea/gitea/issues/38146))
  - fix(auth): ignore stale OIDC external login links to organizations ([#&#8203;37875](https://github.com/go-gitea/gitea/issues/37875)) ([#&#8203;38141](https://github.com/go-gitea/gitea/issues/38141))
  - fix(hostmatcher): block reserved IP ranges from external/private filters ([#&#8203;38039](https://github.com/go-gitea/gitea/issues/38039)) ([#&#8203;38059](https://github.com/go-gitea/gitea/issues/38059))
  - fix(lfs): require Code-unit access for cross-repo LFS object reuse ([#&#8203;38006](https://github.com/go-gitea/gitea/issues/38006)) ([#&#8203;38050](https://github.com/go-gitea/gitea/issues/38050))
  - fix(lfs): reject unknown SSH LFS sub-verbs to prevent auth bypass ([#&#8203;38008](https://github.com/go-gitea/gitea/issues/38008)) ([#&#8203;38015](https://github.com/go-gitea/gitea/issues/38015))
  - fix: bound CODEOWNERS regex match time ([#&#8203;38011](https://github.com/go-gitea/gitea/issues/38011)) ([#&#8203;38025](https://github.com/go-gitea/gitea/issues/38025))
  - fix: bound debian ParseControlFile to a single control stanza ([#&#8203;38044](https://github.com/go-gitea/gitea/issues/38044)) ([#&#8203;38055](https://github.com/go-gitea/gitea/issues/38055))
  - fix(deps): update module golang.org/x/net to v0.55.0 \[security] ([#&#8203;37813](https://github.com/go-gitea/gitea/issues/37813)) ([#&#8203;37829](https://github.com/go-gitea/gitea/issues/37829))

- API
  - feat(api): add Link header in ListForks ([#&#8203;38052](https://github.com/go-gitea/gitea/issues/38052)) ([#&#8203;38063](https://github.com/go-gitea/gitea/issues/38063))

- BUGFIXES
  - fix: Fix the panic when ssh remote lfs endpoint parsing failure ([#&#8203;38026](https://github.com/go-gitea/gitea/issues/38026)) ([#&#8203;38158](https://github.com/go-gitea/gitea/issues/38158))
  - fix(api): nil pointer panic when filtering tracked times by a non-existent user ([#&#8203;38112](https://github.com/go-gitea/gitea/issues/38112)) ([#&#8203;38115](https://github.com/go-gitea/gitea/issues/38115))
  - fix: keep literal "false" value displayed in workflow\_dispatch choice dropdowns ([#&#8203;38080](https://github.com/go-gitea/gitea/issues/38080)) ([#&#8203;38096](https://github.com/go-gitea/gitea/issues/38096))
  - fix: parse HEAD ref ([#&#8203;38119](https://github.com/go-gitea/gitea/issues/38119))
  - fix: git cmd ([#&#8203;38084](https://github.com/go-gitea/gitea/issues/38084)) ([#&#8203;38087](https://github.com/go-gitea/gitea/issues/38087))
  - fix(releases): generate notes for initial tag ([#&#8203;37697](https://github.com/go-gitea/gitea/issues/37697)) ([#&#8203;37986](https://github.com/go-gitea/gitea/issues/37986))
  - fix(actions): return 404 when job log blob is missing ([#&#8203;38003](https://github.com/go-gitea/gitea/issues/38003)) ([#&#8203;38004](https://github.com/go-gitea/gitea/issues/38004))
  - fix(actions): exclude `workflow_call` from workflow trigger detection ([#&#8203;37894](https://github.com/go-gitea/gitea/issues/37894)) ([#&#8203;37899](https://github.com/go-gitea/gitea/issues/37899))
  - fix(actions): keep action run title clickable when commit subject is a URL ([#&#8203;37867](https://github.com/go-gitea/gitea/issues/37867)) ([#&#8203;37898](https://github.com/go-gitea/gitea/issues/37898))
  - fix(actions): reject workflow\_dispatch for workflows without that trigger ([#&#8203;37660](https://github.com/go-gitea/gitea/issues/37660)) ([#&#8203;37895](https://github.com/go-gitea/gitea/issues/37895))
  - fix(actions): ack re-sent `UpdateLog` finalize idempotently ([#&#8203;37885](https://github.com/go-gitea/gitea/issues/37885)) ([#&#8203;37892](https://github.com/go-gitea/gitea/issues/37892))
  - fix: http content file render ([#&#8203;37850](https://github.com/go-gitea/gitea/issues/37850)) ([#&#8203;37856](https://github.com/go-gitea/gitea/issues/37856))
  - fix(issues): clear stale ReviewTypeRequest when submitting pending review ([#&#8203;37809](https://github.com/go-gitea/gitea/issues/37809)) ([#&#8203;37815](https://github.com/go-gitea/gitea/issues/37815))
  - fix: Fix issue target branch selection for non-collaborators ([#&#8203;36916](https://github.com/go-gitea/gitea/issues/36916)) ([#&#8203;38164](https://github.com/go-gitea/gitea/issues/38164))

- BUILD
  - fix(deps): update `@playwright/test` to 1.60.0 ([#&#8203;38144](https://github.com/go-gitea/gitea/issues/38144))
  - ci: add `tools/ci-tools.ts` for the PR labeler workflow ([#&#8203;37831](https://github.com/go-gitea/gitea/issues/37831))
  - fix(build): swagger css import ([#&#8203;37801](https://github.com/go-gitea/gitea/issues/37801)) ([#&#8203;37803](https://github.com/go-gitea/gitea/issues/37803))

### [`v1.26.2`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1262---2026-05-20)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.1...v1.26.2)

- SECURITY
  - fix(permissions): Fix reading permission ([#&#8203;37769](https://github.com/go-gitea/gitea/issues/37769))
  - fix(actions): make artifact signature payloads unambiguous ([#&#8203;37707](https://github.com/go-gitea/gitea/issues/37707))
  - fix: Unify public-only token filtering in API queries and repo access checks ([#&#8203;37118](https://github.com/go-gitea/gitea/issues/37118))
  - fix: Add missed token scope checking ([#&#8203;37735](https://github.com/go-gitea/gitea/issues/37735))
  - fix(oauth): bind token exchanges to the original client request ([#&#8203;37704](https://github.com/go-gitea/gitea/issues/37704))
  - fix(oauth): strengthen PKCE validation and refresh token replay protection ([#&#8203;37706](https://github.com/go-gitea/gitea/issues/37706))
  - fix(web): enforce token scopes on raw, media, and attachment downloads ([#&#8203;37698](https://github.com/go-gitea/gitea/issues/37698))
  - fix(security): enforce wiki git writes and LFS token access at request time ([#&#8203;37695](https://github.com/go-gitea/gitea/issues/37695))
  - feat(api): encrypt AWS creds ([#&#8203;37679](https://github.com/go-gitea/gitea/issues/37679))
  - fix(deps): update dependency mermaid to v11.15.0 \[security], add e2e test
  - fix(packages): Add label for private and internal package and fix composor package source permission check ([#&#8203;37610](https://github.com/go-gitea/gitea/issues/37610))
  - fix(git): Fix smart http request scope bug ([#&#8203;37583](https://github.com/go-gitea/gitea/issues/37583))
  - Fix basic auth bug ([#&#8203;37503](https://github.com/go-gitea/gitea/issues/37503))
  - Fix allow maintainer edit permission check ([#&#8203;37479](https://github.com/go-gitea/gitea/issues/37479)) ([#&#8203;37484](https://github.com/go-gitea/gitea/issues/37484))
  - Fix URL sanitization to handle schemeless credentials ([#&#8203;37440](https://github.com/go-gitea/gitea/issues/37440)) ([#&#8203;37471](https://github.com/go-gitea/gitea/issues/37471))
  - Fix attachment Content-Security-Policy ([#&#8203;37455](https://github.com/go-gitea/gitea/issues/37455)) ([#&#8203;37464](https://github.com/go-gitea/gitea/issues/37464))
  - chore(deps): bump go-git/go-git/v5 to 5.19.0 ([#&#8203;37608](https://github.com/go-gitea/gitea/issues/37608))

- BUGFIXES
  - fix(pull): handle empty pull request files view to allow reviews ([#&#8203;37783](https://github.com/go-gitea/gitea/issues/37783))
  - fix(markup): make RenderString never fail ([#&#8203;37779](https://github.com/go-gitea/gitea/issues/37779))
  - fix: add natural sort to sortTreeViewNodes ([#&#8203;37772](https://github.com/go-gitea/gitea/issues/37772))
  - fix: package creation unique conflict ([#&#8203;37774](https://github.com/go-gitea/gitea/issues/37774))
  - fix!: add DEFAULT\_TITLE\_SOURCE setting for pull request title default behavior ([#&#8203;37465](https://github.com/go-gitea/gitea/issues/37465))
  - fix: Allow direct commits for unprotected files with push restrictions ([#&#8203;37657](https://github.com/go-gitea/gitea/issues/37657))
  - fix(actions): wrong assumption that run id always >= job id ([#&#8203;37737](https://github.com/go-gitea/gitea/issues/37737))
  - fix(auth): set User-Agent on avatar fetch and sync avatar on link-account register ([#&#8203;37564](https://github.com/go-gitea/gitea/issues/37564)) ([#&#8203;37588](https://github.com/go-gitea/gitea/issues/37588))
  - fix(actions): deadlock between PrepareRunAndInsert and UpdateTaskByState ([#&#8203;37692](https://github.com/go-gitea/gitea/issues/37692))
  - fix(repo): /generate must sync the branch table for the new repo ([#&#8203;37693](https://github.com/go-gitea/gitea/issues/37693))
  - build: Fix snap build (1.26)
  - fix(actions): run TransferLogs on UpdateLog{Rows:\[], NoMore:true} ([#&#8203;37631](https://github.com/go-gitea/gitea/issues/37631))
  - fix show correct mergebase
  - fix: make clone URL respect public URL detection setting ([#&#8203;37615](https://github.com/go-gitea/gitea/issues/37615))
  - fix: "run as root" check ([#&#8203;37622](https://github.com/go-gitea/gitea/issues/37622))
  - chore(deps): update dependency go to v1.26.3 ([#&#8203;37601](https://github.com/go-gitea/gitea/issues/37601))
  - Compare dropdown fails when selecting branch with no common merge-base ([#&#8203;37470](https://github.com/go-gitea/gitea/issues/37470))
  - fix: treat email addresses case-insensitively ([#&#8203;37600](https://github.com/go-gitea/gitea/issues/37600))
  - fix(actions): fix blank lines after ::endgroup:: ([#&#8203;37597](https://github.com/go-gitea/gitea/issues/37597))
  - fix(actions): report individual step status in workflow job API response ([#&#8203;37592](https://github.com/go-gitea/gitea/issues/37592))
  - fix: Invalid UTF-8 commit messages in JSON API responses ([#&#8203;37542](https://github.com/go-gitea/gitea/issues/37542))
  - fix: use consistent GetUser family functions ([#&#8203;37553](https://github.com/go-gitea/gitea/issues/37553))
  - fix(api): return 409 message instead of empty JSON for wrong commit id ([#&#8203;37572](https://github.com/go-gitea/gitea/issues/37572))
  - fix(actions): prevent panic when workflow contains null jobs ([#&#8203;37570](https://github.com/go-gitea/gitea/issues/37570))
  - Make ServeSetHeaders default to download attachment if filename exists ([#&#8203;37552](https://github.com/go-gitea/gitea/issues/37552)) ([#&#8203;37555](https://github.com/go-gitea/gitea/issues/37555))
  - Fix(actions): validate workflow param to prevent 500 error ([#&#8203;37546](https://github.com/go-gitea/gitea/issues/37546)) ([#&#8203;37554](https://github.com/go-gitea/gitea/issues/37554))
  - Don't unblock run-level-concurrency-blocked runs in the resolver ([#&#8203;37461](https://github.com/go-gitea/gitea/issues/37461)) ([#&#8203;37538](https://github.com/go-gitea/gitea/issues/37538))
  - Fix(packages): use file names for generic web downloads ([#&#8203;37514](https://github.com/go-gitea/gitea/issues/37514)) ([#&#8203;37520](https://github.com/go-gitea/gitea/issues/37520))
  - Fix merge autodetect can't close other PRs but only the last one when multiple PRs are pushed at once ([#&#8203;37512](https://github.com/go-gitea/gitea/issues/37512)) ([#&#8203;37516](https://github.com/go-gitea/gitea/issues/37516))
  - Fix update branch protection order ([#&#8203;37508](https://github.com/go-gitea/gitea/issues/37508)) ([#&#8203;37513](https://github.com/go-gitea/gitea/issues/37513))
  - Fix mCaptcha broken after Vite migration ([#&#8203;37492](https://github.com/go-gitea/gitea/issues/37492)) ([#&#8203;37509](https://github.com/go-gitea/gitea/issues/37509))
  - Fix review submission from single-commit PR view ([#&#8203;37475](https://github.com/go-gitea/gitea/issues/37475)) ([#&#8203;37485](https://github.com/go-gitea/gitea/issues/37485))
  - Fix scheduled action panic with null event payload ([#&#8203;37459](https://github.com/go-gitea/gitea/issues/37459)) ([#&#8203;37466](https://github.com/go-gitea/gitea/issues/37466))
  - Make GetPossibleUserByID can handle deleted user ([#&#8203;37430](https://github.com/go-gitea/gitea/issues/37430)) ([#&#8203;37431](https://github.com/go-gitea/gitea/issues/37431))
  - Remove excessive quote from terraform instructions ([#&#8203;37424](https://github.com/go-gitea/gitea/issues/37424)) ([#&#8203;37426](https://github.com/go-gitea/gitea/issues/37426))
  - Fix color regressions, add `priority` color ([#&#8203;37417](https://github.com/go-gitea/gitea/issues/37417)) ([#&#8203;37421](https://github.com/go-gitea/gitea/issues/37421))

- MISC
  - Add CurrentURL template variable back ([#&#8203;37444](https://github.com/go-gitea/gitea/issues/37444)) ([#&#8203;37449](https://github.com/go-gitea/gitea/issues/37449))

### [`v1.26.1`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1261---2026-04-21)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.0...v1.26.1)

- BUGFIXES
  - Add event.schedule context for schedule actions task ([#&#8203;37320](https://github.com/go-gitea/gitea/issues/37320)) ([#&#8203;37348](https://github.com/go-gitea/gitea/issues/37348))
  - Fix an issue where changing an organization's visibility caused problems when users had forked its repositories. ([#&#8203;37324](https://github.com/go-gitea/gitea/issues/37324)) ([#&#8203;37344](https://github.com/go-gitea/gitea/issues/37344))
  - Use modern "git update-index --cacheinfo" syntax to support more file names ([#&#8203;37338](https://github.com/go-gitea/gitea/issues/37338)) ([#&#8203;37343](https://github.com/go-gitea/gitea/issues/37343))
  - Fix URL related escaping for oauth2 ([#&#8203;37334](https://github.com/go-gitea/gitea/issues/37334)) ([#&#8203;37340](https://github.com/go-gitea/gitea/issues/37340))
  - When the requested arch rpm is missing fall back to noarch ([#&#8203;37236](https://github.com/go-gitea/gitea/issues/37236)) ([#&#8203;37339](https://github.com/go-gitea/gitea/issues/37339))
  - Fix actions concurrency groups cross-branch leak ([#&#8203;37311](https://github.com/go-gitea/gitea/issues/37311)) ([#&#8203;37331](https://github.com/go-gitea/gitea/issues/37331))
  - Fix bug when accessing user badges ([#&#8203;37321](https://github.com/go-gitea/gitea/issues/37321)) ([#&#8203;37329](https://github.com/go-gitea/gitea/issues/37329))
  - Fix AppFullLink ([#&#8203;37325](https://github.com/go-gitea/gitea/issues/37325)) ([#&#8203;37328](https://github.com/go-gitea/gitea/issues/37328))
  - Fix container auth for public instance ([#&#8203;37290](https://github.com/go-gitea/gitea/issues/37290)) ([#&#8203;37294](https://github.com/go-gitea/gitea/issues/37294))
  - Enhance GetActionWorkflow to support fallback references ([#&#8203;37189](https://github.com/go-gitea/gitea/issues/37189)) ([#&#8203;37283](https://github.com/go-gitea/gitea/issues/37283))
  - Fix vite manifest update masking build errors ([#&#8203;37279](https://github.com/go-gitea/gitea/issues/37279)) ([#&#8203;37310](https://github.com/go-gitea/gitea/issues/37310))
  - Fix Mermaid diagrams failing when node labels contain line breaks ([#&#8203;37296](https://github.com/go-gitea/gitea/issues/37296)) ([#&#8203;37299](https://github.com/go-gitea/gitea/issues/37299))
  - Use TriggerEvent instead of Event in workflow runs API response for scheduled runs ([#&#8203;37288](https://github.com/go-gitea/gitea/issues/37288)) [#&#8203;37360](https://github.com/go-gitea/gitea/issues/37360)
  - Add URL to Learn more about blocking a user. ([#&#8203;37355](https://github.com/go-gitea/gitea/issues/37355)) [#&#8203;37367](https://github.com/go-gitea/gitea/issues/37367)
  - Fix button layout shift when collapsing file tree in editor ([#&#8203;37363](https://github.com/go-gitea/gitea/issues/37363)) [#&#8203;37375](https://github.com/go-gitea/gitea/issues/37375)
  - Fix org team assignee/reviewer lookups for team member permissions ([#&#8203;37365](https://github.com/go-gitea/gitea/issues/37365)) [#&#8203;37391](https://github.com/go-gitea/gitea/issues/37391)
  - Fix repo init README EOL ([#&#8203;37388](https://github.com/go-gitea/gitea/issues/37388)) [#&#8203;37399](https://github.com/go-gitea/gitea/issues/37399)
  - Fix: dump with default zip type produces uncompressed zip ([#&#8203;37401](https://github.com/go-gitea/gitea/issues/37401)) [#&#8203;37402](https://github.com/go-gitea/gitea/issues/37402)

### [`v1.26.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1260---2026-04-17)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.25.5...v1.26.0)

- BREAKING
  - Correct swagger annotations for enums, status codes, and notification state ([#&#8203;37030](https://github.com/go-gitea/gitea/issues/37030))
  - Remove GET API registration-token ([#&#8203;36801](https://github.com/go-gitea/gitea/issues/36801))
  - Support Actions `concurrency` syntax ([#&#8203;32751](https://github.com/go-gitea/gitea/issues/32751))
  - Make PUBLIC\_URL\_DETECTION default to "auto" ([#&#8203;36955](https://github.com/go-gitea/gitea/issues/36955))
- SECURITY
  - Bound PageSize in `ListUnadoptedRepositories` ([#&#8203;36884](https://github.com/go-gitea/gitea/issues/36884))
- FEATURES
  - Support Actions `concurrency` syntax ([#&#8203;32751](https://github.com/go-gitea/gitea/issues/32751))
  - Add terraform state registry ([#&#8203;36710](https://github.com/go-gitea/gitea/issues/36710))
  - Instance-wide (global) info banner and maintenance mode ([#&#8203;36571](https://github.com/go-gitea/gitea/issues/36571))
  - Support rendering OpenAPI spec ([#&#8203;36449](https://github.com/go-gitea/gitea/issues/36449))
  - Add keyboard shortcuts for repository file and code search ([#&#8203;36416](https://github.com/go-gitea/gitea/issues/36416))
  - Add support for archive-upload rpc ([#&#8203;36391](https://github.com/go-gitea/gitea/issues/36391))
  - Add ability to download subpath archive ([#&#8203;36371](https://github.com/go-gitea/gitea/issues/36371))
  - Add workflow dependencies visualization ([#&#8203;26062](https://github.com/go-gitea/gitea/issues/26062)) ([#&#8203;36248](https://github.com/go-gitea/gitea/issues/36248)) & Restyle Workflow Graph ([#&#8203;36912](https://github.com/go-gitea/gitea/issues/36912))
  - Automatic generation of release notes ([#&#8203;35977](https://github.com/go-gitea/gitea/issues/35977))
  - Add "Go to file", "Delete Directory" to repo file list page ([#&#8203;35911](https://github.com/go-gitea/gitea/issues/35911))
  - Introduce "config edit-ini" sub command to help maintaining INI config file ([#&#8203;35735](https://github.com/go-gitea/gitea/issues/35735))
  - Add button to re-run failed jobs in Actions ([#&#8203;36924](https://github.com/go-gitea/gitea/issues/36924))
  - Support actions and reusable workflows from private repos ([#&#8203;32562](https://github.com/go-gitea/gitea/issues/32562))
  - Add summary to action runs view ([#&#8203;36883](https://github.com/go-gitea/gitea/issues/36883))
  - Add user badges ([#&#8203;36752](https://github.com/go-gitea/gitea/issues/36752))
  - Add configurable permissions for Actions automatic tokens ([#&#8203;36173](https://github.com/go-gitea/gitea/issues/36173))
  - Add per-runner "Disable/Pause"  ([#&#8203;36776](https://github.com/go-gitea/gitea/issues/36776))
  - Feature non-zipped actions artifacts (action v7 / nodejs / npm v6.2.0) ([#&#8203;36786](https://github.com/go-gitea/gitea/issues/36786))
- PERFORMANCE
  - WorkflowDispatch API optionally return runid ([#&#8203;36706](https://github.com/go-gitea/gitea/issues/36706))
  - Add render cache for SVG icons ([#&#8203;36863](https://github.com/go-gitea/gitea/issues/36863))
  - Load `mentionValues` asynchronously ([#&#8203;36739](https://github.com/go-gitea/gitea/issues/36739))
  - Lazy-load some Vue components, fix heatmap chunk loading on every page ([#&#8203;36719](https://github.com/go-gitea/gitea/issues/36719))
  - Load heatmap data asynchronously ([#&#8203;36622](https://github.com/go-gitea/gitea/issues/36622))
  - Use prev/next pagination for user profile activities page to speed up ([#&#8203;36642](https://github.com/go-gitea/gitea/issues/36642))
  - Refactor cat-file batch operations and support `--batch-command` approach ([#&#8203;35775](https://github.com/go-gitea/gitea/issues/35775))
  - Use merge tree to detect conflicts when possible ([#&#8203;36400](https://github.com/go-gitea/gitea/issues/36400))
- ENHANCEMENTS
  - Implement logout redirection for reverse proxy auth setups ([#&#8203;36085](https://github.com/go-gitea/gitea/issues/36085)) ([#&#8203;37171](https://github.com/go-gitea/gitea/issues/37171))
  - Adds option to force update new branch in contents routes ([#&#8203;35592](https://github.com/go-gitea/gitea/issues/35592))
  - Add viewer controller for mermaid (zoom, drag) ([#&#8203;36557](https://github.com/go-gitea/gitea/issues/36557))
  - Add code editor setting dropdowns ([#&#8203;36534](https://github.com/go-gitea/gitea/issues/36534))
  - Add `elk` layout support to mermaid ([#&#8203;36486](https://github.com/go-gitea/gitea/issues/36486))
  - Add resolve/unresolve review comment API endpoints ([#&#8203;36441](https://github.com/go-gitea/gitea/issues/36441))
  - Allow configuring default PR base branch (fixes [#&#8203;36412](https://github.com/go-gitea/gitea/issues/36412)) ([#&#8203;36425](https://github.com/go-gitea/gitea/issues/36425))
  - Add support for RPM Errata (updateinfo.xml) ([#&#8203;37125](https://github.com/go-gitea/gitea/issues/37125))
  - Require additional user confirmation for making repo private ([#&#8203;36959](https://github.com/go-gitea/gitea/issues/36959))
  - Add `actions.WORKFLOW_DIRS` setting ([#&#8203;36619](https://github.com/go-gitea/gitea/issues/36619))
  - Avoid opening new tab when downloading actions logs ([#&#8203;36740](https://github.com/go-gitea/gitea/issues/36740))
  - Implements OIDC RP-Initiated Logout ([#&#8203;36724](https://github.com/go-gitea/gitea/issues/36724))
  - Show workflow link ([#&#8203;37070](https://github.com/go-gitea/gitea/issues/37070))
  - Desaturate dark theme background colors ([#&#8203;37056](https://github.com/go-gitea/gitea/issues/37056))
  - Refactor "org teams" page and help new users to "add member" to an org ([#&#8203;37051](https://github.com/go-gitea/gitea/issues/37051))
  - Add webhook name field to improve webhook identification ([#&#8203;37025](https://github.com/go-gitea/gitea/issues/37025)) ([#&#8203;37040](https://github.com/go-gitea/gitea/issues/37040))
  - Make task list checkboxes clickable in the preview tab ([#&#8203;37010](https://github.com/go-gitea/gitea/issues/37010))
  - Improve severity labels in Actions logs and tweak colors ([#&#8203;36993](https://github.com/go-gitea/gitea/issues/36993))
  - Linkify URLs in Actions workflow logs ([#&#8203;36986](https://github.com/go-gitea/gitea/issues/36986))
  - Allow text selection on checkbox labels ([#&#8203;36970](https://github.com/go-gitea/gitea/issues/36970))
  - Support dark/light theme images in markdown ([#&#8203;36922](https://github.com/go-gitea/gitea/issues/36922))
  - Enable native dark mode for swagger-ui ([#&#8203;36899](https://github.com/go-gitea/gitea/issues/36899))
  - Rework checkbox styling, remove `input` border hover effect ([#&#8203;36870](https://github.com/go-gitea/gitea/issues/36870))
  - Refactor storage content-type handling of ServeDirectURL ([#&#8203;36804](https://github.com/go-gitea/gitea/issues/36804))
  - Use "Enable Gravatar" but not "Disable" ([#&#8203;36771](https://github.com/go-gitea/gitea/issues/36771))
  - Use case-insensitive matching for Git error "Not a valid object name" ([#&#8203;36728](https://github.com/go-gitea/gitea/issues/36728))
  - Add "Copy Source" to markup comment menu ([#&#8203;36726](https://github.com/go-gitea/gitea/issues/36726))
  - Change image transparency grid to CSS ([#&#8203;36711](https://github.com/go-gitea/gitea/issues/36711))
  - Add "Run" prefix for unnamed action steps ([#&#8203;36624](https://github.com/go-gitea/gitea/issues/36624))
  - Persist actions log time display settings in `localStorage` ([#&#8203;36623](https://github.com/go-gitea/gitea/issues/36623))
  - Use first commit title for multi-commit PRs and fix auto-focus title field ([#&#8203;36606](https://github.com/go-gitea/gitea/issues/36606))
  - Improve BuildCaseInsensitiveLike with lowercase ([#&#8203;36598](https://github.com/go-gitea/gitea/issues/36598))
  - Improve diff highlighting ([#&#8203;36583](https://github.com/go-gitea/gitea/issues/36583))
  - Exclude cancelled runs from failure-only email notifications ([#&#8203;36569](https://github.com/go-gitea/gitea/issues/36569))
  - Use full-file highlighting for diff sections ([#&#8203;36561](https://github.com/go-gitea/gitea/issues/36561))
  - Color command/error logs in Actions log ([#&#8203;36538](https://github.com/go-gitea/gitea/issues/36538))
  - Add paging headers ([#&#8203;36521](https://github.com/go-gitea/gitea/issues/36521))
  - Improve timeline entries for WIP prefix changes in pull requests ([#&#8203;36518](https://github.com/go-gitea/gitea/issues/36518))
  - Add FOLDER\_ICON\_THEME configuration option ([#&#8203;36496](https://github.com/go-gitea/gitea/issues/36496))
  - Normalize guessed languages for code highlighting ([#&#8203;36450](https://github.com/go-gitea/gitea/issues/36450))
  - Add chunked transfer encoding support for LFS uploads ([#&#8203;36380](https://github.com/go-gitea/gitea/issues/36380))
  - Indicate when only optional checks failed ([#&#8203;36367](https://github.com/go-gitea/gitea/issues/36367))
  - Add 'allow\_maintainer\_edit' API option for creating a pull request ([#&#8203;36283](https://github.com/go-gitea/gitea/issues/36283))
  - Support closing keywords with URL references ([#&#8203;36221](https://github.com/go-gitea/gitea/issues/36221))
  - Improve diff file headers ([#&#8203;36215](https://github.com/go-gitea/gitea/issues/36215))
  - Fix and enhance comment editor monospace toggle ([#&#8203;36181](https://github.com/go-gitea/gitea/issues/36181))
  - Add git.DIFF\_RENAME\_SIMILARITY\_THRESHOLD option ([#&#8203;36164](https://github.com/go-gitea/gitea/issues/36164))
  - Add matching pair insertion to markdown textarea ([#&#8203;36121](https://github.com/go-gitea/gitea/issues/36121))
  - Add sorting/filtering to admin user search API endpoint ([#&#8203;36112](https://github.com/go-gitea/gitea/issues/36112))
  - Allow action user have read permission in public repo like other user ([#&#8203;36095](https://github.com/go-gitea/gitea/issues/36095))
  - Disable matchBrackets in monaco ([#&#8203;36089](https://github.com/go-gitea/gitea/issues/36089))
  - Use GitHub-style commit message for squash merge ([#&#8203;35987](https://github.com/go-gitea/gitea/issues/35987))
  - Make composer registry support tar.gz and tar.bz2 and fix bugs ([#&#8203;35958](https://github.com/go-gitea/gitea/issues/35958))
  - Add GITEA\_PR\_INDEX env variable to githooks ([#&#8203;35938](https://github.com/go-gitea/gitea/issues/35938))
  - Add proper error message if session provider can not be created ([#&#8203;35520](https://github.com/go-gitea/gitea/issues/35520))
  - Add button to copy file name in PR files ([#&#8203;35509](https://github.com/go-gitea/gitea/issues/35509))
  - Move `X_FRAME_OPTIONS` setting from `cors` to `security` section ([#&#8203;30256](https://github.com/go-gitea/gitea/issues/30256))
  - Add placeholder content for empty content page ([#&#8203;37114](https://github.com/go-gitea/gitea/issues/37114))
  - Add `DEFAULT_DELETE_BRANCH_AFTER_MERGE` setting ([#&#8203;36917](https://github.com/go-gitea/gitea/issues/36917))
  - Redirect to the only OAuth2 provider when no other login methods and fix various problems ([#&#8203;36901](https://github.com/go-gitea/gitea/issues/36901))
  - Add admin badge to navbar avatar ([#&#8203;36790](https://github.com/go-gitea/gitea/issues/36790))
  - Add `never` option to `PUBLIC_URL_DETECTION` configuration ([#&#8203;36785](https://github.com/go-gitea/gitea/issues/36785))
  - Add background and run count to actions list page ([#&#8203;36707](https://github.com/go-gitea/gitea/issues/36707))
  - Add icon to buttons "Close with Comment", "Close Pull Request", "Close Issue" ([#&#8203;36654](https://github.com/go-gitea/gitea/issues/36654))
  - Add support for in\_progress event in workflow\_run webhook ([#&#8203;36979](https://github.com/go-gitea/gitea/issues/36979))
  - Report commit status for pull\_request\_review events ([#&#8203;36589](https://github.com/go-gitea/gitea/issues/36589))
  - Render merged pull request title as such in dashboard feed ([#&#8203;36479](https://github.com/go-gitea/gitea/issues/36479))
  - Feature to be able to filter project boards by milestones ([#&#8203;36321](https://github.com/go-gitea/gitea/issues/36321))
  - Use user id in noreply emails ([#&#8203;36550](https://github.com/go-gitea/gitea/issues/36550))
  - Enable pagination on GiteaDownloader.getIssueReactions() ([#&#8203;36549](https://github.com/go-gitea/gitea/issues/36549))
  - Remove striped tables in UI ([#&#8203;36509](https://github.com/go-gitea/gitea/issues/36509))
  - Improve control char rendering and escape button styling ([#&#8203;37094](https://github.com/go-gitea/gitea/issues/37094))
  - Support legacy run/job index-based URLs and refactor migration 326 ([#&#8203;37008](https://github.com/go-gitea/gitea/issues/37008))
  - Add date to "No Contributions" tooltip ([#&#8203;36190](https://github.com/go-gitea/gitea/issues/36190))
  - Show edit page confirmation dialog on tree view file change ([#&#8203;36130](https://github.com/go-gitea/gitea/issues/36130))
  - Mention proc-receive in text for dashboard.resync\_all\_hooks func ([#&#8203;35991](https://github.com/go-gitea/gitea/issues/35991))
  - Reuse selectable style for wiki ([#&#8203;35990](https://github.com/go-gitea/gitea/issues/35990))
  - Support blue yellow colorblind theme ([#&#8203;35910](https://github.com/go-gitea/gitea/issues/35910))
  - Support selecting theme on the footer ([#&#8203;35741](https://github.com/go-gitea/gitea/issues/35741))
  - Improve online runner check ([#&#8203;35722](https://github.com/go-gitea/gitea/issues/35722))
  - Add quick approve button on PR page ([#&#8203;35678](https://github.com/go-gitea/gitea/issues/35678))
  - Enable commenting on expanded lines in PR diffs ([#&#8203;35662](https://github.com/go-gitea/gitea/issues/35662))
  - Print PR-Title into tooltip for actions ([#&#8203;35579](https://github.com/go-gitea/gitea/issues/35579))
  - Use explicit, stronger defaults for newly generated repo signing keys for Debian ([#&#8203;36236](https://github.com/go-gitea/gitea/issues/36236))
  - Improve the compare page ([#&#8203;36261](https://github.com/go-gitea/gitea/issues/36261))
  - Unify repo names in system notices ([#&#8203;36491](https://github.com/go-gitea/gitea/issues/36491))
  - Move package settings to package instead of being tied to version ([#&#8203;37026](https://github.com/go-gitea/gitea/issues/37026))
  - Add Actions API rerun endpoints for runs and jobs ([#&#8203;36768](https://github.com/go-gitea/gitea/issues/36768))
  - Add branch\_count to repository API ([#&#8203;35351](https://github.com/go-gitea/gitea/issues/35351)) ([#&#8203;36743](https://github.com/go-gitea/gitea/issues/36743))
  - Add created\_by filter to SearchIssues ([#&#8203;36670](https://github.com/go-gitea/gitea/issues/36670))
  - Allow admins to rename non-local users ([#&#8203;35970](https://github.com/go-gitea/gitea/issues/35970))
  - Support updating branch via API ([#&#8203;35951](https://github.com/go-gitea/gitea/issues/35951))
  - Add an option to automatically verify SSH keys from LDAP ([#&#8203;35927](https://github.com/go-gitea/gitea/issues/35927))
  - Make "update file" API can create a new file when SHA is not set ([#&#8203;35738](https://github.com/go-gitea/gitea/issues/35738))
  - Update issue.go with labels documentation (labels content, not ids) ([#&#8203;35522](https://github.com/go-gitea/gitea/issues/35522))
  - Expose content\_version for optimistic locking on issue and PR edits ([#&#8203;37035](https://github.com/go-gitea/gitea/issues/37035))
  - Pass ServeHeaderOptions by value instead of pointer, fine tune httplib tests ([#&#8203;36982](https://github.com/go-gitea/gitea/issues/36982))
- BUGFIXES
  - Frontend iframe renderer framework: 3D models, OpenAPI ([#&#8203;37233](https://github.com/go-gitea/gitea/issues/37233)) ([#&#8203;37273](https://github.com/go-gitea/gitea/issues/37273))
  - Fix CODEOWNERS absolute path matching. ([#&#8203;37244](https://github.com/go-gitea/gitea/issues/37244)) ([#&#8203;37264](https://github.com/go-gitea/gitea/issues/37264))
  - Swift registry metadata: preserve more JSON fields and accept empty metadata ([#&#8203;37254](https://github.com/go-gitea/gitea/issues/37254)) ([#&#8203;37261](https://github.com/go-gitea/gitea/issues/37261))
  - Fix user ssh key exporting and tests ([#&#8203;37256](https://github.com/go-gitea/gitea/issues/37256)) ([#&#8203;37258](https://github.com/go-gitea/gitea/issues/37258))
  - Fix team member avatar size and add tooltip ([#&#8203;37253](https://github.com/go-gitea/gitea/issues/37253))
  - Fix commit title rendering in action run and blame ([#&#8203;37243](https://github.com/go-gitea/gitea/issues/37243)) ([#&#8203;37251](https://github.com/go-gitea/gitea/issues/37251))
  - Fix corrupted JSON caused by goccy library ([#&#8203;37214](https://github.com/go-gitea/gitea/issues/37214)) ([#&#8203;37220](https://github.com/go-gitea/gitea/issues/37220))
  - Add test for "fetch redirect", add CSS value validation for external render ([#&#8203;37207](https://github.com/go-gitea/gitea/issues/37207)) ([#&#8203;37216](https://github.com/go-gitea/gitea/issues/37216))
  - Fix incorrect concurrency check ([#&#8203;37205](https://github.com/go-gitea/gitea/issues/37205)) ([#&#8203;37215](https://github.com/go-gitea/gitea/issues/37215))
  - Fix handle missing base branch in PR commits API ([#&#8203;37193](https://github.com/go-gitea/gitea/issues/37193)) ([#&#8203;37203](https://github.com/go-gitea/gitea/issues/37203))
  - Fix encoding for Matrix Webhooks ([#&#8203;37190](https://github.com/go-gitea/gitea/issues/37190)) ([#&#8203;37201](https://github.com/go-gitea/gitea/issues/37201))
  - Fix handle fork-only commits in compare API ([#&#8203;37185](https://github.com/go-gitea/gitea/issues/37185)) ([#&#8203;37199](https://github.com/go-gitea/gitea/issues/37199))
  - Indicate form field readonly via background, fix RunUser config ([#&#8203;37175](https://github.com/go-gitea/gitea/issues/37175), [#&#8203;37180](https://github.com/go-gitea/gitea/issues/37180)) ([#&#8203;37178](https://github.com/go-gitea/gitea/issues/37178))
  - Report structurally invalid workflows to users ([#&#8203;37116](https://github.com/go-gitea/gitea/issues/37116)) ([#&#8203;37164](https://github.com/go-gitea/gitea/issues/37164))
  - Fix API not persisting pull request unit config when has\_pull\_requests is not set ([#&#8203;36718](https://github.com/go-gitea/gitea/issues/36718))
  - Rename CSS variables and improve colorblind themes ([#&#8203;36353](https://github.com/go-gitea/gitea/issues/36353))
  - Hide `add-matcher` and `remove-matcher` from actions job logs ([#&#8203;36520](https://github.com/go-gitea/gitea/issues/36520))
  - Prevent navigation keys from triggering actions during IME composition ([#&#8203;36540](https://github.com/go-gitea/gitea/issues/36540))
  - Fix vertical alignment of `.commit-sign-badge` children ([#&#8203;36570](https://github.com/go-gitea/gitea/issues/36570))
  - Fix duplicate startup warnings in admin panel ([#&#8203;36641](https://github.com/go-gitea/gitea/issues/36641))
  - Fix CODEOWNERS review request attribution using comment metadata ([#&#8203;36348](https://github.com/go-gitea/gitea/issues/36348))
  - Fix HTML tags appearing in wiki table of contents ([#&#8203;36284](https://github.com/go-gitea/gitea/issues/36284))
  - Fix various bugs ([#&#8203;37096](https://github.com/go-gitea/gitea/issues/37096))
  - Fix various legacy problems ([#&#8203;37092](https://github.com/go-gitea/gitea/issues/37092))
  - Fix RPM Registry 404 when package name contains 'package' ([#&#8203;37087](https://github.com/go-gitea/gitea/issues/37087))
  - Merge some standalone Vite entries into index.js ([#&#8203;37085](https://github.com/go-gitea/gitea/issues/37085))
  - Fix various problems ([#&#8203;37077](https://github.com/go-gitea/gitea/issues/37077))
  - Fix issue label deletion with Actions tokens ([#&#8203;37013](https://github.com/go-gitea/gitea/issues/37013))
  - Hide delete branch or tag buttons in mirror or archived repositories. ([#&#8203;37006](https://github.com/go-gitea/gitea/issues/37006))
  - Fix org contact email not clearable once set ([#&#8203;36975](https://github.com/go-gitea/gitea/issues/36975))
  - Fix a bug when forking a repository in an organization ([#&#8203;36950](https://github.com/go-gitea/gitea/issues/36950))
  - Preserve sort order of exclusive labels from template repo ([#&#8203;36931](https://github.com/go-gitea/gitea/issues/36931))
  - Make container registry support Apple Container (basic auth) ([#&#8203;36920](https://github.com/go-gitea/gitea/issues/36920))
  - Fix the wrong push commits in the pull request when force push ([#&#8203;36914](https://github.com/go-gitea/gitea/issues/36914))
  - Add class "list-header-filters" to the div for projects ([#&#8203;36889](https://github.com/go-gitea/gitea/issues/36889))
  - Fix dbfs error handling ([#&#8203;36844](https://github.com/go-gitea/gitea/issues/36844))
  - Fix incorrect viewed files counter if reverted change was viewed ([#&#8203;36819](https://github.com/go-gitea/gitea/issues/36819))
  - Refactor avatar package, support default avatar fallback ([#&#8203;36788](https://github.com/go-gitea/gitea/issues/36788))
  - Fix README symlink resolution in subdirectories like .github ([#&#8203;36775](https://github.com/go-gitea/gitea/issues/36775))
  - Fix CSS stacking context issue in actions log ([#&#8203;36749](https://github.com/go-gitea/gitea/issues/36749))
  - Add gpg signing for merge rebase and update by rebase ([#&#8203;36701](https://github.com/go-gitea/gitea/issues/36701))
  - Delete non-exist branch should return 404 ([#&#8203;36694](https://github.com/go-gitea/gitea/issues/36694))
  - Fix `TestActionsCollaborativeOwner` ([#&#8203;36657](https://github.com/go-gitea/gitea/issues/36657))
  - Fix multi-arch Docker build SIGILL by splitting frontend stage ([#&#8203;36646](https://github.com/go-gitea/gitea/issues/36646))
  - Fix linguist-detectable attribute being ignored for configuration files ([#&#8203;36640](https://github.com/go-gitea/gitea/issues/36640))
  - Fix state desync in ComboMarkdownEditor ([#&#8203;36625](https://github.com/go-gitea/gitea/issues/36625))
  - Unify DEFAULT\_SHOW\_FULL\_NAME output in templates and dropdown ([#&#8203;36597](https://github.com/go-gitea/gitea/issues/36597))
  - Pull Request Pusher should be the author of the merge ([#&#8203;36581](https://github.com/go-gitea/gitea/issues/36581))
  - Fix various version parsing problems ([#&#8203;36553](https://github.com/go-gitea/gitea/issues/36553))
  - Fix highlight diff result ([#&#8203;36539](https://github.com/go-gitea/gitea/issues/36539))
  - Fix mirror sync parser and fix mirror messages ([#&#8203;36504](https://github.com/go-gitea/gitea/issues/36504))
  - Fix bug when list pull request commits ([#&#8203;36485](https://github.com/go-gitea/gitea/issues/36485))
  - Fix various bugs ([#&#8203;36446](https://github.com/go-gitea/gitea/issues/36446))
  - Fix issue filter menu layout ([#&#8203;36426](https://github.com/go-gitea/gitea/issues/36426))
  - Restrict branch naming when new change matches with protection rules ([#&#8203;36405](https://github.com/go-gitea/gitea/issues/36405))
  - Fix link/origin referrer and login redirect ([#&#8203;36279](https://github.com/go-gitea/gitea/issues/36279))
  - Generate IDs for HTML headings without id attribute ([#&#8203;36233](https://github.com/go-gitea/gitea/issues/36233))
  - Use a migration test instead of a wrong test which populated the meta test repositories and fix a migration bug ([#&#8203;36160](https://github.com/go-gitea/gitea/issues/36160))
  - Fix issue close timeline icon ([#&#8203;36138](https://github.com/go-gitea/gitea/issues/36138))
  - Fix diff blob excerpt expansion ([#&#8203;35922](https://github.com/go-gitea/gitea/issues/35922))
  - Fix external render ([#&#8203;35727](https://github.com/go-gitea/gitea/issues/35727))
  - Fix review request webhook bug ([#&#8203;35339](https://github.com/go-gitea/gitea/issues/35339)) ([#&#8203;35723](https://github.com/go-gitea/gitea/issues/35723))
  - Fix shutdown waitgroup panic ([#&#8203;35676](https://github.com/go-gitea/gitea/issues/35676))
  - Cleanup ActionRun creation ([#&#8203;35624](https://github.com/go-gitea/gitea/issues/35624))
  - Fix possible bug when migrating issues/pull requests ([#&#8203;33487](https://github.com/go-gitea/gitea/issues/33487))
  - Various fixes ([#&#8203;36697](https://github.com/go-gitea/gitea/issues/36697))
  - Apply notify/register mail flags during install load ([#&#8203;37120](https://github.com/go-gitea/gitea/issues/37120))
  - Repair duration display for bad stopped timestamps ([#&#8203;37121](https://github.com/go-gitea/gitea/issues/37121))
  - Fix(upgrade.sh): use HTTPS for GPG key import and restore SELinux context after upgrade ([#&#8203;36930](https://github.com/go-gitea/gitea/issues/36930))
  - Fix various trivial problems ([#&#8203;36921](https://github.com/go-gitea/gitea/issues/36921))
  - Fix various trivial problems ([#&#8203;36953](https://github.com/go-gitea/gitea/issues/36953))
  - Fix NuGet package upload error handling ([#&#8203;37074](https://github.com/go-gitea/gitea/issues/37074))
  - Fix CodeQL code scanning alerts ([#&#8203;36858](https://github.com/go-gitea/gitea/issues/36858))
  - Refactor issue sidebar and fix various problems ([#&#8203;37045](https://github.com/go-gitea/gitea/issues/37045))
  - Fix various problems ([#&#8203;37029](https://github.com/go-gitea/gitea/issues/37029))
  - Fix relative-time RangeError ([#&#8203;37021](https://github.com/go-gitea/gitea/issues/37021))
  - Fix chroma lexer mapping ([#&#8203;36629](https://github.com/go-gitea/gitea/issues/36629))
  - Fix typos and grammar in English locale ([#&#8203;36751](https://github.com/go-gitea/gitea/issues/36751))
  - Fix milestone/project text overflow in issue sidebar ([#&#8203;36741](https://github.com/go-gitea/gitea/issues/36741))
  - Fix `no-content` message not rendering after comment edit ([#&#8203;36733](https://github.com/go-gitea/gitea/issues/36733))
  - Fix theme loading in development ([#&#8203;36605](https://github.com/go-gitea/gitea/issues/36605))
  - Fix workflow run jobs API returning null steps ([#&#8203;36603](https://github.com/go-gitea/gitea/issues/36603))
  - Fix timeline event layout overflow with long content ([#&#8203;36595](https://github.com/go-gitea/gitea/issues/36595))
  - Fix minor UI issues in runner edit page ([#&#8203;36590](https://github.com/go-gitea/gitea/issues/36590))
  - Fix incorrect vendored detections ([#&#8203;36508](https://github.com/go-gitea/gitea/issues/36508))
  - Fix editorconfig not respected in PR Conversation view ([#&#8203;36492](https://github.com/go-gitea/gitea/issues/36492))
  - Don't create self-references in merged PRs ([#&#8203;36490](https://github.com/go-gitea/gitea/issues/36490))
  - Fix potential incorrect runID in run status update ([#&#8203;36437](https://github.com/go-gitea/gitea/issues/36437))
  - Fix file-tree ui error when adding files to repo without commits ([#&#8203;36312](https://github.com/go-gitea/gitea/issues/36312))
  - Improve image captcha contrast for dark mode ([#&#8203;36265](https://github.com/go-gitea/gitea/issues/36265))
  - Fix panic in blame view when a file has only a single commit ([#&#8203;36230](https://github.com/go-gitea/gitea/issues/36230))
  - Fix spelling error in migrate-storage cmd utility ([#&#8203;36226](https://github.com/go-gitea/gitea/issues/36226))
  - Fix code highlighting on blame page ([#&#8203;36157](https://github.com/go-gitea/gitea/issues/36157))
  - Fix nilnil in onedev downloader ([#&#8203;36154](https://github.com/go-gitea/gitea/issues/36154))
  - Fix actions lint ([#&#8203;36029](https://github.com/go-gitea/gitea/issues/36029))
  - Fix oauth2 session gob register ([#&#8203;36017](https://github.com/go-gitea/gitea/issues/36017))
  - Fix Arch repo pacman.conf snippet ([#&#8203;35825](https://github.com/go-gitea/gitea/issues/35825))
  - Fix a number of `strictNullChecks`-related issues ([#&#8203;35795](https://github.com/go-gitea/gitea/issues/35795))
  - Fix URLJoin, markup render link reoslving, sign-in/up/linkaccount page common data ([#&#8203;36861](https://github.com/go-gitea/gitea/issues/36861))
  - Hide delete directory button for mirror or archive repository and disable the menu item if user have no permission ([#&#8203;36384](https://github.com/go-gitea/gitea/issues/36384))
  - Update message severity colors, fix navbar double border ([#&#8203;37019](https://github.com/go-gitea/gitea/issues/37019))
  - Inline and lazy-load EasyMDE CSS, fix border colors ([#&#8203;36714](https://github.com/go-gitea/gitea/issues/36714))
  - Closed milestones with no issues now show as 100% completed ([#&#8203;36220](https://github.com/go-gitea/gitea/issues/36220))
  - Add test for ExtendCommentTreePathLength migration and fix bugs ([#&#8203;35791](https://github.com/go-gitea/gitea/issues/35791))
  - Only turn links to current instance into hash links ([#&#8203;36237](https://github.com/go-gitea/gitea/issues/36237))
  - Fix typos in code comments: doesnt, dont, wont ([#&#8203;36890](https://github.com/go-gitea/gitea/issues/36890))
- REFACTOR
  - Clean up and improve non-gitea js error filter ([#&#8203;37148](https://github.com/go-gitea/gitea/issues/37148)) ([#&#8203;37155](https://github.com/go-gitea/gitea/issues/37155))
  - Always show owner/repo name in compare page dropdowns ([#&#8203;37172](https://github.com/go-gitea/gitea/issues/37172)) ([#&#8203;37200](https://github.com/go-gitea/gitea/issues/37200))
  - Remove dead CSS rules ([#&#8203;37173](https://github.com/go-gitea/gitea/issues/37173)) ([#&#8203;37177](https://github.com/go-gitea/gitea/issues/37177))
  - Replace Monaco with CodeMirror ([#&#8203;36764](https://github.com/go-gitea/gitea/issues/36764))
  - Replace CSRF cookie with `CrossOriginProtection` ([#&#8203;36183](https://github.com/go-gitea/gitea/issues/36183))
  - Replace index with id in actions routes ([#&#8203;36842](https://github.com/go-gitea/gitea/issues/36842))
  - Remove unnecessary function parameter ([#&#8203;35765](https://github.com/go-gitea/gitea/issues/35765))
  - Move jobparser from act repository to Gitea ([#&#8203;36699](https://github.com/go-gitea/gitea/issues/36699))
  - Refactor compare router param parse ([#&#8203;36105](https://github.com/go-gitea/gitea/issues/36105))
  - Optimize 'refreshAccesses' to perform update without removing then adding ([#&#8203;35702](https://github.com/go-gitea/gitea/issues/35702))
  - Clean up checkbox cursor styles ([#&#8203;37016](https://github.com/go-gitea/gitea/issues/37016))
  - Remove undocumented support of signing key in the repository git configuration file ([#&#8203;36143](https://github.com/go-gitea/gitea/issues/36143))
  - Switch `cmd/` to use constructor functions. ([#&#8203;36962](https://github.com/go-gitea/gitea/issues/36962))
  - Use `relative-time` to render absolute dates ([#&#8203;36238](https://github.com/go-gitea/gitea/issues/36238))
  - Some refactors about GetMergeBase ([#&#8203;36186](https://github.com/go-gitea/gitea/issues/36186))
  - Some small refactors ([#&#8203;36163](https://github.com/go-gitea/gitea/issues/36163))
  - Use gitRepo as parameter instead of repopath when invoking sign functions ([#&#8203;36162](https://github.com/go-gitea/gitea/issues/36162))
  - Move blame to gitrepo ([#&#8203;36161](https://github.com/go-gitea/gitea/issues/36161))
  - Move some functions to gitrepo package to reduce RepoPath reference directly ([#&#8203;36126](https://github.com/go-gitea/gitea/issues/36126))
  - Use gitrepo's clone and push when possible ([#&#8203;36093](https://github.com/go-gitea/gitea/issues/36093))
  - Remove mermaid margin workaround ([#&#8203;35732](https://github.com/go-gitea/gitea/issues/35732))
  - Move some functions to gitrepo package ([#&#8203;35543](https://github.com/go-gitea/gitea/issues/35543))
  - Move GetDiverging functions to gitrepo ([#&#8203;35524](https://github.com/go-gitea/gitea/issues/35524))
  - Use global lock instead of status pool for cron lock ([#&#8203;35507](https://github.com/go-gitea/gitea/issues/35507))
  - Use explicit mux instead of DefaultServeMux ([#&#8203;36276](https://github.com/go-gitea/gitea/issues/36276))
  - Use gitrepo's push function ([#&#8203;36245](https://github.com/go-gitea/gitea/issues/36245))
  - Pass request context to generateAdditionalHeadersForIssue ([#&#8203;36274](https://github.com/go-gitea/gitea/issues/36274))
  - Move assign project when creating pull request to the same database transaction ([#&#8203;36244](https://github.com/go-gitea/gitea/issues/36244))
  - Move catfile batch to a sub package of git module ([#&#8203;36232](https://github.com/go-gitea/gitea/issues/36232))
  - Use gitrepo.Repository instead of wikipath ([#&#8203;35398](https://github.com/go-gitea/gitea/issues/35398))
  - Use experimental go json v2 library ([#&#8203;35392](https://github.com/go-gitea/gitea/issues/35392))
  - Refactor template render ([#&#8203;36438](https://github.com/go-gitea/gitea/issues/36438))
  - Refactor GetRepoRawDiffForFile to avoid unnecessary pipe or goroutine ([#&#8203;36434](https://github.com/go-gitea/gitea/issues/36434))
  - Refactor text utility classes to Tailwind CSS ([#&#8203;36703](https://github.com/go-gitea/gitea/issues/36703))
  - Refactor git command stdio pipe ([#&#8203;36422](https://github.com/go-gitea/gitea/issues/36422))
  - Refactor git command context & pipeline ([#&#8203;36406](https://github.com/go-gitea/gitea/issues/36406))
  - Refactor git command stdio pipe ([#&#8203;36393](https://github.com/go-gitea/gitea/issues/36393))
  - Remove unused functions ([#&#8203;36672](https://github.com/go-gitea/gitea/issues/36672))
  - Refactor Actions Token Access ([#&#8203;35688](https://github.com/go-gitea/gitea/issues/35688))
  - Move commit related functions to gitrepo package ([#&#8203;35600](https://github.com/go-gitea/gitea/issues/35600))
  - Move archive function to repo\_model and gitrepo ([#&#8203;35514](https://github.com/go-gitea/gitea/issues/35514))
  - Move some functions to gitrepo package ([#&#8203;35503](https://github.com/go-gitea/gitea/issues/35503))
  - Use git model to detect whether branch exist instead of gitrepo method ([#&#8203;35459](https://github.com/go-gitea/gitea/issues/35459))
  - Some refactor for repo path ([#&#8203;36251](https://github.com/go-gitea/gitea/issues/36251))
  - Extract helper functions from SearchIssues ([#&#8203;36158](https://github.com/go-gitea/gitea/issues/36158))
  - Refactor merge conan and container auth preserve actions taskID ([#&#8203;36560](https://github.com/go-gitea/gitea/issues/36560))
  - Refactor Nuget Auth to reuse Basic Auth Token Validation ([#&#8203;36558](https://github.com/go-gitea/gitea/issues/36558))
  - Refactor ActionsTaskID ([#&#8203;36503](https://github.com/go-gitea/gitea/issues/36503))
  - Refactor auth middleware ([#&#8203;36848](https://github.com/go-gitea/gitea/issues/36848))
  - Refactor code render and render control chars ([#&#8203;37078](https://github.com/go-gitea/gitea/issues/37078))
  - Clean up AppURL, remove legacy origin-url webcomponent ([#&#8203;37090](https://github.com/go-gitea/gitea/issues/37090))
  - Remove `util.URLJoin` and replace all callers with direct path concatenation ([#&#8203;36867](https://github.com/go-gitea/gitea/issues/36867))
  - Replace legacy tw-flex utility classes with flex-text-block/inline ([#&#8203;36778](https://github.com/go-gitea/gitea/issues/36778))
  - Mark unused\&immature activitypub as "not implemented" ([#&#8203;36789](https://github.com/go-gitea/gitea/issues/36789))
- TESTING
  - Add e2e tests for server push events ([#&#8203;36879](https://github.com/go-gitea/gitea/issues/36879))
  - Rework e2e tests ([#&#8203;36634](https://github.com/go-gitea/gitea/issues/36634))
  - Add e2e reaction test, improve accessibility, enable parallel testing ([#&#8203;37081](https://github.com/go-gitea/gitea/issues/37081))
  - Increase e2e test timeouts on CI to fix flaky tests ([#&#8203;37053](https://github.com/go-gitea/gitea/issues/37053))
- BUILD
  - Upgrade go-git to v5.18.0 ([#&#8203;37269](https://github.com/go-gitea/gitea/issues/37269))
  - Replace rollup-plugin-license with rolldown-license-plugin ([#&#8203;37130](https://github.com/go-gitea/gitea/issues/37130)) ([#&#8203;37158](https://github.com/go-gitea/gitea/issues/37158))
  - Bump min go version to 1.26.2 ([#&#8203;37139](https://github.com/go-gitea/gitea/issues/37139)) ([#&#8203;37143](https://github.com/go-gitea/gitea/issues/37143))
  - Convert locale files from ini to json format ([#&#8203;35489](https://github.com/go-gitea/gitea/issues/35489))
  - Bump golangci-lint to 2.7.2, enable modernize stringsbuilder ([#&#8203;36180](https://github.com/go-gitea/gitea/issues/36180))
  - Port away from `flake-utils` ([#&#8203;35675](https://github.com/go-gitea/gitea/issues/35675))
  - Remove nolint ([#&#8203;36252](https://github.com/go-gitea/gitea/issues/36252))
  - Update the Unlicense copy to latest version ([#&#8203;36636](https://github.com/go-gitea/gitea/issues/36636))
  - Update to go 1.26.0 and golangci-lint 2.9.0 ([#&#8203;36588](https://github.com/go-gitea/gitea/issues/36588))
  - Replace `google/go-licenses` with custom generation ([#&#8203;36575](https://github.com/go-gitea/gitea/issues/36575))
  - Update go dependencies ([#&#8203;36548](https://github.com/go-gitea/gitea/issues/36548))
  - Bump appleboy/git-push-action from 1.0.0 to 1.2.0 ([#&#8203;36306](https://github.com/go-gitea/gitea/issues/36306))
  - Remove fomantic form module ([#&#8203;36222](https://github.com/go-gitea/gitea/issues/36222))
  - Bump setup-node to v6, re-enable cache ([#&#8203;36207](https://github.com/go-gitea/gitea/issues/36207))
  - Bump crowdin/github-action from 1 to 2 ([#&#8203;36204](https://github.com/go-gitea/gitea/issues/36204))
  - Revert "Bump alpine to 3.23 ([#&#8203;36185](https://github.com/go-gitea/gitea/issues/36185))" ([#&#8203;36202](https://github.com/go-gitea/gitea/issues/36202))
  - Update chroma to v2.21.1 ([#&#8203;36201](https://github.com/go-gitea/gitea/issues/36201))
  - Bump astral-sh/setup-uv from 6 to 7 ([#&#8203;36198](https://github.com/go-gitea/gitea/issues/36198))
  - Bump docker/build-push-action from 5 to 6 ([#&#8203;36197](https://github.com/go-gitea/gitea/issues/36197))
  - Bump aws-actions/configure-aws-credentials from 4 to 5 ([#&#8203;36196](https://github.com/go-gitea/gitea/issues/36196))
  - Bump dev-hanz-ops/install-gh-cli-action from 0.1.0 to 0.2.1 ([#&#8203;36195](https://github.com/go-gitea/gitea/issues/36195))
  - Add JSON linting ([#&#8203;36192](https://github.com/go-gitea/gitea/issues/36192))
  - Enable dependabot for actions ([#&#8203;36191](https://github.com/go-gitea/gitea/issues/36191))
  - Bump alpine to 3.23 ([#&#8203;36185](https://github.com/go-gitea/gitea/issues/36185))
  - Update chroma to v2.21.0 ([#&#8203;36171](https://github.com/go-gitea/gitea/issues/36171))
  - Update JS deps and eslint enhancements ([#&#8203;36147](https://github.com/go-gitea/gitea/issues/36147))
  - Update JS deps ([#&#8203;36091](https://github.com/go-gitea/gitea/issues/36091))
  - update golangci-lint to v2.7.0 ([#&#8203;36079](https://github.com/go-gitea/gitea/issues/36079))
  - Update JS deps, fix deprecations ([#&#8203;36040](https://github.com/go-gitea/gitea/issues/36040))
  - Update JS deps ([#&#8203;35978](https://github.com/go-gitea/gitea/issues/35978))
  - Add toolchain directive to go.mod ([#&#8203;35901](https://github.com/go-gitea/gitea/issues/35901))
  - Move `gitea-vet` to use `go tool` ([#&#8203;35878](https://github.com/go-gitea/gitea/issues/35878))
  - Update to go 1.25.4 ([#&#8203;35877](https://github.com/go-gitea/gitea/issues/35877))
  - Enable TypeScript `strictNullChecks` ([#&#8203;35843](https://github.com/go-gitea/gitea/issues/35843))
  - Enable `vue/require-typed-ref` eslint rule ([#&#8203;35764](https://github.com/go-gitea/gitea/issues/35764))
  - Update JS dependencies ([#&#8203;35759](https://github.com/go-gitea/gitea/issues/35759))
  - Move `codeformat` folder to tools ([#&#8203;35758](https://github.com/go-gitea/gitea/issues/35758))
  - Update dependencies ([#&#8203;35733](https://github.com/go-gitea/gitea/issues/35733))
  - Bump happy-dom from 20.0.0 to 20.0.2 ([#&#8203;35677](https://github.com/go-gitea/gitea/issues/35677))
  - Bump setup-go to v6 ([#&#8203;35660](https://github.com/go-gitea/gitea/issues/35660))
  - Update JS deps, misc tweaks ([#&#8203;35643](https://github.com/go-gitea/gitea/issues/35643))
  - Bump happy-dom from 19.0.2 to 20.0.0 ([#&#8203;35625](https://github.com/go-gitea/gitea/issues/35625))
  - Use bundled version of spectral ([#&#8203;35573](https://github.com/go-gitea/gitea/issues/35573))
  - Update JS and PY deps ([#&#8203;35565](https://github.com/go-gitea/gitea/issues/35565))
  - Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 ([#&#8203;35557](https://github.com/go-gitea/gitea/issues/35557))
  - Migrate from webpack to vite ([#&#8203;37002](https://github.com/go-gitea/gitea/issues/37002))
  - Update JS dependencies and misc tweaks ([#&#8203;37064](https://github.com/go-gitea/gitea/issues/37064))
  - Update to eslint 10 ([#&#8203;36925](https://github.com/go-gitea/gitea/issues/36925))
  - Optimize Docker build with dependency layer caching ([#&#8203;36864](https://github.com/go-gitea/gitea/issues/36864))
  - Update JS deps ([#&#8203;36850](https://github.com/go-gitea/gitea/issues/36850))
  - Update tool dependencies and fix new lint issues ([#&#8203;36702](https://github.com/go-gitea/gitea/issues/36702))
  - Remove redundant linter rules ([#&#8203;36658](https://github.com/go-gitea/gitea/issues/36658))
  - Move Fomantic dropdown CSS to custom module ([#&#8203;36530](https://github.com/go-gitea/gitea/issues/36530))
  - Remove and forbid `@ts-expect-error` ([#&#8203;36513](https://github.com/go-gitea/gitea/issues/36513))
  - Refactor git command stderr handling ([#&#8203;36402](https://github.com/go-gitea/gitea/issues/36402))
  - Enable gocheckcompilerdirectives linter ([#&#8203;36156](https://github.com/go-gitea/gitea/issues/36156))
  - Replace `lint-go-gopls` with additional `govet` linters ([#&#8203;36028](https://github.com/go-gitea/gitea/issues/36028))
  - Update golangci-lint to v2.6.0 ([#&#8203;35801](https://github.com/go-gitea/gitea/issues/35801))
  - Misc tool tweaks ([#&#8203;35734](https://github.com/go-gitea/gitea/issues/35734))
  - Add cache to container build ([#&#8203;35697](https://github.com/go-gitea/gitea/issues/35697))
  - Upgrade vite ([#&#8203;37126](https://github.com/go-gitea/gitea/issues/37126))
  - Update `setup-uv` to v8.0.0 ([#&#8203;37101](https://github.com/go-gitea/gitea/issues/37101))
  - Upgrade `go-git` to v5.17.2 and related dependencies ([#&#8203;37060](https://github.com/go-gitea/gitea/issues/37060))
  - Raise minimum Node.js version to 22.18.0 ([#&#8203;37058](https://github.com/go-gitea/gitea/issues/37058))
  - Upgrade `golang.org/x/image` to v0.38.0 ([#&#8203;37054](https://github.com/go-gitea/gitea/issues/37054))
  - Update minimum go version to 1.26.1, golangci-lint to 2.11.2, fix test style ([#&#8203;36876](https://github.com/go-gitea/gitea/issues/36876))
  - Enable eslint concurrency ([#&#8203;36878](https://github.com/go-gitea/gitea/issues/36878))
  - Vendor relative-time-element as local web component ([#&#8203;36853](https://github.com/go-gitea/gitea/issues/36853))
  - Update material-icon-theme v5.32.0 ([#&#8203;36832](https://github.com/go-gitea/gitea/issues/36832))
  - Update Go dependencies ([#&#8203;36781](https://github.com/go-gitea/gitea/issues/36781))
  - Upgrade minimatch ([#&#8203;36760](https://github.com/go-gitea/gitea/issues/36760))
  - Remove i18n backport tool at the moment because of translation format changed ([#&#8203;36643](https://github.com/go-gitea/gitea/issues/36643))
  - Update emoji data for Unicode 16 ([#&#8203;36596](https://github.com/go-gitea/gitea/issues/36596))
  - Update JS dependencies, adjust webpack config, misc fixes ([#&#8203;36431](https://github.com/go-gitea/gitea/issues/36431))
  - Update material-icon-theme to v5.31.0 ([#&#8203;36427](https://github.com/go-gitea/gitea/issues/36427))
  - Update JS and PY deps ([#&#8203;36383](https://github.com/go-gitea/gitea/issues/36383))
  - Bump alpine to 3.23, add platforms to `docker-dryrun` ([#&#8203;36379](https://github.com/go-gitea/gitea/issues/36379))
  - Update JS deps ([#&#8203;36354](https://github.com/go-gitea/gitea/issues/36354))
  - Update goldmark to v1.7.16 ([#&#8203;36343](https://github.com/go-gitea/gitea/issues/36343))
  - Update chroma to v2.22.0 ([#&#8203;36342](https://github.com/go-gitea/gitea/issues/36342))
- DOCS
  - Update AI Contribution Policy ([#&#8203;37022](https://github.com/go-gitea/gitea/issues/37022))
  - Update AGENTS.md with additional guidelines ([#&#8203;37018](https://github.com/go-gitea/gitea/issues/37018))
  - Add missing cron tasks to example ini ([#&#8203;37012](https://github.com/go-gitea/gitea/issues/37012))
  - Add AI Contribution Policy to CONTRIBUTING.md ([#&#8203;36651](https://github.com/go-gitea/gitea/issues/36651))
  - Minor punctuation improvement in CONTRIBUTING.md ([#&#8203;36291](https://github.com/go-gitea/gitea/issues/36291))
  - Add documentation for markdown anchor post-processing ([#&#8203;36443](https://github.com/go-gitea/gitea/issues/36443))
- MISC
  - Correct spelling ([#&#8203;36783](https://github.com/go-gitea/gitea/issues/36783))
  - Update Nix flake ([#&#8203;37110](https://github.com/go-gitea/gitea/issues/37110))
  - Update Nix flake ([#&#8203;37024](https://github.com/go-gitea/gitea/issues/37024))
  - Add valid github scopes ([#&#8203;36977](https://github.com/go-gitea/gitea/issues/36977))
  - Update Nix flake ([#&#8203;36943](https://github.com/go-gitea/gitea/issues/36943))
  - Update Nix flake ([#&#8203;36902](https://github.com/go-gitea/gitea/issues/36902))
  - Update Nix flake ([#&#8203;36857](https://github.com/go-gitea/gitea/issues/36857))
  - Update Nix flake ([#&#8203;36787](https://github.com/go-gitea/gitea/issues/36787))

### [`v1.25.5`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1255---2026-03-10)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.25.4...v1.25.5)

- SECURITY
  - Toolchain Update to Go 1.25.6 ([#&#8203;36480](https://github.com/go-gitea/gitea/issues/36480)) ([#&#8203;36487](https://github.com/go-gitea/gitea/issues/36487))
  - Adjust the toolchain version ([#&#8203;36537](https://github.com/go-gitea/gitea/issues/36537)) ([#&#8203;36542](https://github.com/go-gitea/gitea/issues/36542))
  - Update toolchain to 1.25.8 for v1.25 ([#&#8203;36888](https://github.com/go-gitea/gitea/issues/36888))
  - Prevent redirect bypasses via backslash-encoded paths ([#&#8203;36660](https://github.com/go-gitea/gitea/issues/36660)) ([#&#8203;36716](https://github.com/go-gitea/gitea/issues/36716))
  - Fix get release draft permission check ([#&#8203;36659](https://github.com/go-gitea/gitea/issues/36659)) ([#&#8203;36715](https://github.com/go-gitea/gitea/issues/36715))
  - Fix a bug user could change another user's primary email ([#&#8203;36586](https://github.com/go-gitea/gitea/issues/36586)) ([#&#8203;36607](https://github.com/go-gitea/gitea/issues/36607))
  - Fix OAuth2 authorization code expiry and reuse handling ([#&#8203;36797](https://github.com/go-gitea/gitea/issues/36797)) ([#&#8203;36851](https://github.com/go-gitea/gitea/issues/36851))
  - Add validation constraints for repository creation fields ([#&#8203;36671](https://github.com/go-gitea/gitea/issues/36671)) ([#&#8203;36757](https://github.com/go-gitea/gitea/issues/36757))
  - Fix bug to check whether user can update pull request branch or rebase branch ([#&#8203;36465](https://github.com/go-gitea/gitea/issues/36465)) ([#&#8203;36838](https://github.com/go-gitea/gitea/issues/36838))
  - Add migration http transport for push/sync mirror lfs ([#&#8203;36665](https://github.com/go-gitea/gitea/issues/36665)) ([#&#8203;36691](https://github.com/go-gitea/gitea/issues/36691))
  - Fix track time list permission check ([#&#8203;36662](https://github.com/go-gitea/gitea/issues/36662)) ([#&#8203;36744](https://github.com/go-gitea/gitea/issues/36744))
  - Fix track time issue id ([#&#8203;36664](https://github.com/go-gitea/gitea/issues/36664)) ([#&#8203;36689](https://github.com/go-gitea/gitea/issues/36689))
  - Fix path resolving ([#&#8203;36734](https://github.com/go-gitea/gitea/issues/36734)) ([#&#8203;36746](https://github.com/go-gitea/gitea/issues/36746))
  - Fix dump release asset bug ([#&#8203;36799](https://github.com/go-gitea/gitea/issues/36799)) ([#&#8203;36839](https://github.com/go-gitea/gitea/issues/36839))
  - Fix org permission API visibility checks for hidden members and private orgs ([#&#8203;36798](https://github.com/go-gitea/gitea/issues/36798)) ([#&#8203;36841](https://github.com/go-gitea/gitea/issues/36841))
  - Fix forwarded proto handling for public URL detection ([#&#8203;36810](https://github.com/go-gitea/gitea/issues/36810)) ([#&#8203;36836](https://github.com/go-gitea/gitea/issues/36836))
  - Add a git grep search timeout ([#&#8203;36809](https://github.com/go-gitea/gitea/issues/36809)) ([#&#8203;36835](https://github.com/go-gitea/gitea/issues/36835))
  - Fix oauth2 s256 ([#&#8203;36462](https://github.com/go-gitea/gitea/issues/36462)) ([#&#8203;36477](https://github.com/go-gitea/gitea/issues/36477))
- ENHANCEMENTS
  - Make `security-check` informational only ([#&#8203;36681](https://github.com/go-gitea/gitea/issues/36681)) ([#&#8203;36852](https://github.com/go-gitea/gitea/issues/36852))
  - Upgrade to github.com/cloudflare/circl 1.6.3, svgo 4.0.1, markdownlint-cli 0.48.0 ([#&#8203;36840](https://github.com/go-gitea/gitea/issues/36840))
  - Add some validation on values provided to USER\_DISABLED\_FEATURES and EXTERNAL\_USER\_DISABLED\_FEATURES ([#&#8203;36688](https://github.com/go-gitea/gitea/issues/36688)) ([#&#8203;36692](https://github.com/go-gitea/gitea/issues/36692))
  - Upgrade gogit to 5.16.5 ([#&#8203;36687](https://github.com/go-gitea/gitea/issues/36687))
  - Add wrap to runner label list ([#&#8203;36565](https://github.com/go-gitea/gitea/issues/36565)) ([#&#8203;36574](https://github.com/go-gitea/gitea/issues/36574))
  - Add dnf5 command for Fedora in RPM package instructions ([#&#8203;36527](https://github.com/go-gitea/gitea/issues/36527)) ([#&#8203;36572](https://github.com/go-gitea/gitea/issues/36572))
  - Allow scroll propagation outside code editor ([#&#8203;36502](https://github.com/go-gitea/gitea/issues/36502)) ([#&#8203;36510](https://github.com/go-gitea/gitea/issues/36510))
- BUGFIXES
  - Fix non-admins unable to automerge PRs from forks ([#&#8203;36833](https://github.com/go-gitea/gitea/issues/36833)) ([#&#8203;36843](https://github.com/go-gitea/gitea/issues/36843))
  - Fix bug when pushing mirror with wiki ([#&#8203;36795](https://github.com/go-gitea/gitea/issues/36795)) ([#&#8203;36807](https://github.com/go-gitea/gitea/issues/36807))
  - Fix artifacts v4 backend upload problems ([#&#8203;36805](https://github.com/go-gitea/gitea/issues/36805)) ([#&#8203;36834](https://github.com/go-gitea/gitea/issues/36834))
  - Fix CRAN package version validation to allow more than 4 version components ([#&#8203;36813](https://github.com/go-gitea/gitea/issues/36813)) ([#&#8203;36821](https://github.com/go-gitea/gitea/issues/36821))
  - Fix force push time-line commit comments of pull request ([#&#8203;36653](https://github.com/go-gitea/gitea/issues/36653)) ([#&#8203;36717](https://github.com/go-gitea/gitea/issues/36717))
  - Fix SVG height calculation in diff viewer ([#&#8203;36748](https://github.com/go-gitea/gitea/issues/36748)) ([#&#8203;36750](https://github.com/go-gitea/gitea/issues/36750))
  - Fix push time bug ([#&#8203;36693](https://github.com/go-gitea/gitea/issues/36693)) ([#&#8203;36713](https://github.com/go-gitea/gitea/issues/36713))
  - Fix bug the protected branch rule name is conflicted with renamed branch name ([#&#8203;36650](https://github.com/go-gitea/gitea/issues/36650)) ([#&#8203;36661](https://github.com/go-gitea/gitea/issues/36661))
  - Fix bug when do LFS GC ([#&#8203;36500](https://github.com/go-gitea/gitea/issues/36500)) ([#&#8203;36608](https://github.com/go-gitea/gitea/issues/36608))
  - Fix focus lost bugs in the Monaco editor ([#&#8203;36609](https://github.com/go-gitea/gitea/issues/36609))
  - Reprocess htmx content after loading more files ([#&#8203;36568](https://github.com/go-gitea/gitea/issues/36568)) ([#&#8203;36577](https://github.com/go-gitea/gitea/issues/36577))
  - Fix assignee sidebar links and empty placeholder ([#&#8203;36559](https://github.com/go-gitea/gitea/issues/36559)) ([#&#8203;36563](https://github.com/go-gitea/gitea/issues/36563))
  - Fix issues filter dropdown showing empty label scope section ([#&#8203;36535](https://github.com/go-gitea/gitea/issues/36535)) ([#&#8203;36544](https://github.com/go-gitea/gitea/issues/36544))
  - Fix various mermaid bugs ([#&#8203;36547](https://github.com/go-gitea/gitea/issues/36547)) ([#&#8203;36552](https://github.com/go-gitea/gitea/issues/36552))
  - Fix data race when uploading container blobs concurrently ([#&#8203;36524](https://github.com/go-gitea/gitea/issues/36524)) ([#&#8203;36526](https://github.com/go-gitea/gitea/issues/36526))
  - Correct spacing between username and bot label ([#&#8203;36473](https://github.com/go-gitea/gitea/issues/36473)) ([#&#8203;36484](https://github.com/go-gitea/gitea/issues/36484))

### [`v1.25.4`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1254---2026-01-15)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.25.3...v1.25.4)

- SECURITY
  - Release attachments must belong to the intended repo ([#&#8203;36347](https://github.com/go-gitea/gitea/issues/36347)) ([#&#8203;36375](https://github.com/go-gitea/gitea/issues/36375))
  - Fix permission check on org project operations ([#&#8203;36318](https://github.com/go-gitea/gitea/issues/36318)) ([#&#8203;36373](https://github.com/go-gitea/gitea/issues/36373))
  - Clean watches when make a repository private and check permission when send release emails ([#&#8203;36319](https://github.com/go-gitea/gitea/issues/36319)) ([#&#8203;36370](https://github.com/go-gitea/gitea/issues/36370))
  - Add more check for stopwatch read or list ([#&#8203;36340](https://github.com/go-gitea/gitea/issues/36340)) ([#&#8203;36368](https://github.com/go-gitea/gitea/issues/36368))
  - Fix openid setting check ([#&#8203;36346](https://github.com/go-gitea/gitea/issues/36346)) ([#&#8203;36361](https://github.com/go-gitea/gitea/issues/36361))
  - Fix cancel auto merge bug ([#&#8203;36341](https://github.com/go-gitea/gitea/issues/36341)) ([#&#8203;36356](https://github.com/go-gitea/gitea/issues/36356))
  - Fix delete attachment check ([#&#8203;36320](https://github.com/go-gitea/gitea/issues/36320)) ([#&#8203;36355](https://github.com/go-gitea/gitea/issues/36355))
  - LFS locks must belong to the intended repo ([#&#8203;36344](https://github.com/go-gitea/gitea/issues/36344)) ([#&#8203;36349](https://github.com/go-gitea/gitea/issues/36349))
  - Fix bug on notification read ([#&#8203;36339](https://github.com/go-gitea/gitea/issues/36339)) [#&#8203;36387](https://github.com/go-gitea/gitea/issues/36387)
- ENHANCEMENTS
  - Add more routes to the "expensive" list ([#&#8203;36290](https://github.com/go-gitea/gitea/issues/36290))
  - Make "commit statuses" API accept slashes in "ref" ([#&#8203;36264](https://github.com/go-gitea/gitea/issues/36264)) ([#&#8203;36275](https://github.com/go-gitea/gitea/issues/36275))
- BUGFIXES
  - Fix git http service handling ([#&#8203;36396](https://github.com/go-gitea/gitea/issues/36396))
  - Fix markdown newline handling during IME composition ([#&#8203;36421](https://github.com/go-gitea/gitea/issues/36421)) ([#&#8203;36424](https://github.com/go-gitea/gitea/issues/36424))
  - Fix missing repository id when migrating release attachments ([#&#8203;36389](https://github.com/go-gitea/gitea/issues/36389))
  - Fix bug when compare in the pull request ([#&#8203;36363](https://github.com/go-gitea/gitea/issues/36363)) ([#&#8203;36372](https://github.com/go-gitea/gitea/issues/36372))
  - Fix incorrect text content detection ([#&#8203;36364](https://github.com/go-gitea/gitea/issues/36364)) ([#&#8203;36369](https://github.com/go-gitea/gitea/issues/36369))
  - Fill missing `has_code` in repository api ([#&#8203;36338](https://github.com/go-gitea/gitea/issues/36338)) ([#&#8203;36359](https://github.com/go-gitea/gitea/issues/36359))
  - Fix notifications pagination query parameters ([#&#8203;36351](https://github.com/go-gitea/gitea/issues/36351)) ([#&#8203;36358](https://github.com/go-gitea/gitea/issues/36358))
  - Fix some trivial problems ([#&#8203;36336](https://github.com/go-gitea/gitea/issues/36336)) ([#&#8203;36337](https://github.com/go-gitea/gitea/issues/36337))
  - Prevent panic when GitLab release has more links than sources ([#&#8203;36295](https://github.com/go-gitea/gitea/issues/36295)) ([#&#8203;36305](https://github.com/go-gitea/gitea/issues/36305))
  - Fix stats bug when syncing release ([#&#8203;36285](https://github.com/go-gitea/gitea/issues/36285)) ([#&#8203;36294](https://github.com/go-gitea/gitea/issues/36294))
  - Always honor user's choice for "delete branch after merge" ([#&#8203;36281](https://github.com/go-gitea/gitea/issues/36281)) ([#&#8203;36286](https://github.com/go-gitea/gitea/issues/36286))
  - Use the requested host for LFS links ([#&#8203;36242](https://github.com/go-gitea/gitea/issues/36242)) ([#&#8203;36258](https://github.com/go-gitea/gitea/issues/36258))
  - Fix panic when get editor config file ([#&#8203;36241](https://github.com/go-gitea/gitea/issues/36241)) ([#&#8203;36247](https://github.com/go-gitea/gitea/issues/36247))
  - Fix regression in writing authorized principals ([#&#8203;36213](https://github.com/go-gitea/gitea/issues/36213)) ([#&#8203;36218](https://github.com/go-gitea/gitea/issues/36218))
  - Fix WebAuthn error checking ([#&#8203;36219](https://github.com/go-gitea/gitea/issues/36219)) ([#&#8203;36235](https://github.com/go-gitea/gitea/issues/36235))

### [`v1.25.3`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1253---2025-12-17)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.25.2...v1.25.3)

- SECURITY
  - Bump toolchain to go1.25.5, misc fixes ([#&#8203;36082](https://github.com/go-gitea/gitea/issues/36082))
- ENHANCEMENTS
  - Add strikethrough button to markdown editor ([#&#8203;36087](https://github.com/go-gitea/gitea/issues/36087)) ([#&#8203;36104](https://github.com/go-gitea/gitea/issues/36104))
  - Add "site admin" back to profile menu ([#&#8203;36010](https://github.com/go-gitea/gitea/issues/36010)) ([#&#8203;36013](https://github.com/go-gitea/gitea/issues/36013))
  - Improve math rendering ([#&#8203;36124](https://github.com/go-gitea/gitea/issues/36124)) ([#&#8203;36125](https://github.com/go-gitea/gitea/issues/36125))
- BUGFIXES
  - Check user visibility when redirecting to a renamed user ([#&#8203;36148](https://github.com/go-gitea/gitea/issues/36148)) ([#&#8203;36159](https://github.com/go-gitea/gitea/issues/36159))
  - Fix various bugs ([#&#8203;36139](https://github.com/go-gitea/gitea/issues/36139)) ([#&#8203;36151](https://github.com/go-gitea/gitea/issues/36151))
  - Fix bug when viewing the commit diff page with non-ANSI files ([#&#8203;36149](https://github.com/go-gitea/gitea/issues/36149)) ([#&#8203;36150](https://github.com/go-gitea/gitea/issues/36150))
  - Hide RSS icon when viewing a file not under a branch ([#&#8203;36135](https://github.com/go-gitea/gitea/issues/36135)) ([#&#8203;36141](https://github.com/go-gitea/gitea/issues/36141))
  - Fix SVG size calulation, only use `style` attribute ([#&#8203;36133](https://github.com/go-gitea/gitea/issues/36133)) ([#&#8203;36134](https://github.com/go-gitea/gitea/issues/36134))
  - Make Golang correctly delete temp files during uploading ([#&#8203;36128](https://github.com/go-gitea/gitea/issues/36128)) ([#&#8203;36129](https://github.com/go-gitea/gitea/issues/36129))
  - Fix the bug when ssh clone with redirect user or repository ([#&#8203;36039](https://github.com/go-gitea/gitea/issues/36039)) ([#&#8203;36090](https://github.com/go-gitea/gitea/issues/36090))
  - Use Golang net/smtp instead of gomail's smtp to send email ([#&#8203;36055](https://github.com/go-gitea/gitea/issues/36055)) ([#&#8203;36083](https://github.com/go-gitea/gitea/issues/36083))
  - Fix edit user email bug in API ([#&#8203;36068](https://github.com/go-gitea/gitea/issues/36068)) ([#&#8203;36081](https://github.com/go-gitea/gitea/issues/36081))
  - Fix bug when updating user email ([#&#8203;36058](https://github.com/go-gitea/gitea/issues/36058)) ([#&#8203;36066](https://github.com/go-gitea/gitea/issues/36066))
  - Fix incorrect viewed files counter if file has changed ([#&#8203;36009](https://github.com/go-gitea/gitea/issues/36009)) ([#&#8203;36047](https://github.com/go-gitea/gitea/issues/36047))
  - Fix container registry error handling ([#&#8203;36021](https://github.com/go-gitea/gitea/issues/36021)) ([#&#8203;36037](https://github.com/go-gitea/gitea/issues/36037))
  - Fix webAuthn insecure error view ([#&#8203;36165](https://github.com/go-gitea/gitea/issues/36165)) ([#&#8203;36179](https://github.com/go-gitea/gitea/issues/36179))
  - Fix some file icon ui ([#&#8203;36078](https://github.com/go-gitea/gitea/issues/36078)) ([#&#8203;36088](https://github.com/go-gitea/gitea/issues/36088))
  - Fix Actions `pull_request.paths` being triggered incorrectly by rebase ([#&#8203;36045](https://github.com/go-gitea/gitea/issues/36045)) ([#&#8203;36054](https://github.com/go-gitea/gitea/issues/36054))
  - Fix error handling in mailer and wiki services ([#&#8203;36041](https://github.com/go-gitea/gitea/issues/36041)) ([#&#8203;36053](https://github.com/go-gitea/gitea/issues/36053))
  - Fix bugs when comparing and creating pull request ([#&#8203;36166](https://github.com/go-gitea/gitea/issues/36166)) ([#&#8203;36144](https://github.com/go-gitea/gitea/issues/36144))

### [`v1.25.2`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1252---2025-11-23)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.25.1...v1.25.2)

- SECURITY
  - Upgrade golang.org/x/crypto to 0.45.0 ([#&#8203;35985](https://github.com/go-gitea/gitea/issues/35985)) ([#&#8203;35988](https://github.com/go-gitea/gitea/issues/35988))
  - Fix various permission & login related bugs ([#&#8203;36002](https://github.com/go-gitea/gitea/issues/36002)) ([#&#8203;36004](https://github.com/go-gitea/gitea/issues/36004))
- ENHANCEMENTS
  - Display source code downloads last for release attachments ([#&#8203;35897](https://github.com/go-gitea/gitea/issues/35897)) ([#&#8203;35903](https://github.com/go-gitea/gitea/issues/35903))
  - Change project default column icon to 'star' ([#&#8203;35967](https://github.com/go-gitea/gitea/issues/35967)) ([#&#8203;35979](https://github.com/go-gitea/gitea/issues/35979))
- BUGFIXES
  - Allow empty commit when merging pull request with squash style ([#&#8203;35989](https://github.com/go-gitea/gitea/issues/35989)) ([#&#8203;36003](https://github.com/go-gitea/gitea/issues/36003))
  - Fix container push tag overwriting ([#&#8203;35936](https://github.com/go-gitea/gitea/issues/35936)) ([#&#8203;35954](https://github.com/go-gitea/gitea/issues/35954))
  - Fix corrupted external render content ([#&#8203;35946](https://github.com/go-gitea/gitea/issues/35946)) and upgrade golang.org/x packages ([#&#8203;35950](https://github.com/go-gitea/gitea/issues/35950))
  - Limit reading bytes instead of ReadAll ([#&#8203;35928](https://github.com/go-gitea/gitea/issues/35928)) ([#&#8203;35934](https://github.com/go-gitea/gitea/issues/35934))
  - Use correct form field for allowed force push users in branch protection API ([#&#8203;35894](https://github.com/go-gitea/gitea/issues/35894)) ([#&#8203;35908](https://github.com/go-gitea/gitea/issues/35908))
  - Fix team member access check ([#&#8203;35899](https://github.com/go-gitea/gitea/issues/35899)) ([#&#8203;35905](https://github.com/go-gitea/gitea/issues/35905))
  - Fix conda null depend issue ([#&#8203;35900](https://github.com/go-gitea/gitea/issues/35900)) ([#&#8203;35902](https://github.com/go-gitea/gitea/issues/35902))
  - Set the dates to now when not specified by the caller ([#&#8203;35861](https://github.com/go-gitea/gitea/issues/35861)) ([#&#8203;35874](https://github.com/go-gitea/gitea/issues/35874))
  - Fix gogit ListEntriesRecursiveWithSize ([#&#8203;35862](https://github.com/go-gitea/gitea/issues/35862))
  - Misc CSS fixes ([#&#8203;35888](https://github.com/go-gitea/gitea/issues/35888)) ([#&#8203;35981](https://github.com/go-gitea/gitea/issues/35981))
  - Don't show unnecessary error message to end users for DeleteBranchAfterMerge ([#&#8203;35937](https://github.com/go-gitea/gitea/issues/35937)) ([#&#8203;35941](https://github.com/go-gitea/gitea/issues/35941))
  - Load jQuery as early as possible to support custom scripts ([#&#8203;35926](https://github.com/go-gitea/gitea/issues/35926)) ([#&#8203;35929](https://github.com/go-gitea/gitea/issues/35929))
  - Allow to display embed images/pdfs when SERVE\_DIRECT was enabled on MinIO storage ([#&#8203;35882](https://github.com/go-gitea/gitea/issues/35882)) ([#&#8203;35917](https://github.com/go-gitea/gitea/issues/35917))
  - Make OAuth2 issuer configurable ([#&#8203;35915](https://github.com/go-gitea/gitea/issues/35915)) ([#&#8203;35916](https://github.com/go-gitea/gitea/issues/35916))
  - Fix [#&#8203;35763](https://github.com/go-gitea/gitea/issues/35763): Add proper page title for project pages ([#&#8203;35773](https://github.com/go-gitea/gitea/issues/35773)) ([#&#8203;35909](https://github.com/go-gitea/gitea/issues/35909))
  - Fix avatar upload error handling ([#&#8203;35887](https://github.com/go-gitea/gitea/issues/35887)) ([#&#8203;35890](https://github.com/go-gitea/gitea/issues/35890))
  - Contribution heatmap improvements ([#&#8203;35876](https://github.com/go-gitea/gitea/issues/35876)) ([#&#8203;35880](https://github.com/go-gitea/gitea/issues/35880))
  - Remove padding override on `.ui .sha.label` ([#&#8203;35864](https://github.com/go-gitea/gitea/issues/35864)) ([#&#8203;35873](https://github.com/go-gitea/gitea/issues/35873))
  - Fix pull description code label background ([#&#8203;35865](https://github.com/go-gitea/gitea/issues/35865)) ([#&#8203;35870](https://github.com/go-gitea/gitea/issues/35870))

### [`v1.25.1`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1251---2025-11-03)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.25.0...v1.25.1)

- BUGFIXES
  - Make ACME email optional ([#&#8203;35849](https://github.com/go-gitea/gitea/issues/35849)) [#&#8203;35857](https://github.com/go-gitea/gitea/issues/35857)
  - Add a doctor command to fix inconsistent run status ([#&#8203;35840](https://github.com/go-gitea/gitea/issues/35840)) ([#&#8203;35845](https://github.com/go-gitea/gitea/issues/35845))
  - Remove wrong code ([#&#8203;35846](https://github.com/go-gitea/gitea/issues/35846))
  - Fix viewed files number is not right if not all files loaded ([#&#8203;35821](https://github.com/go-gitea/gitea/issues/35821)) ([#&#8203;35844](https://github.com/go-gitea/gitea/issues/35844))
  - Fix incorrect pull request counter ([#&#8203;35819](https://github.com/go-gitea/gitea/issues/35819)) ([#&#8203;35841](https://github.com/go-gitea/gitea/issues/35841))
  - Upgrade go mail to 0.7.2 and fix the bug ([#&#8203;35833](https://github.com/go-gitea/gitea/issues/35833)) ([#&#8203;35837](https://github.com/go-gitea/gitea/issues/35837))
  - Revert gomail to v0.7.0 to fix sending mail failed ([#&#8203;35816](https://github.com/go-gitea/gitea/issues/35816)) ([#&#8203;35824](https://github.com/go-gitea/gitea/issues/35824))
  - Fix clone mixed bug ([#&#8203;35810](https://github.com/go-gitea/gitea/issues/35810)) ([#&#8203;35822](https://github.com/go-gitea/gitea/issues/35822))
  - Fix cli "Before" handling ([#&#8203;35797](https://github.com/go-gitea/gitea/issues/35797)) ([#&#8203;35808](https://github.com/go-gitea/gitea/issues/35808))
  - Improve and fix markup code preview rendering ([#&#8203;35777](https://github.com/go-gitea/gitea/issues/35777)) ([#&#8203;35787](https://github.com/go-gitea/gitea/issues/35787))
  - Fix actions rerun bug ([#&#8203;35783](https://github.com/go-gitea/gitea/issues/35783)) ([#&#8203;35784](https://github.com/go-gitea/gitea/issues/35784))
  - Fix actions schedule update issue ([#&#8203;35767](https://github.com/go-gitea/gitea/issues/35767)) ([#&#8203;35774](https://github.com/go-gitea/gitea/issues/35774))
  - Fix circular spin animation direction ([#&#8203;35785](https://github.com/go-gitea/gitea/issues/35785)) ([#&#8203;35823](https://github.com/go-gitea/gitea/issues/35823))
  - Fix file extension on gogs.png ([#&#8203;35793](https://github.com/go-gitea/gitea/issues/35793)) ([#&#8203;35799](https://github.com/go-gitea/gitea/issues/35799))
  - Add pnpm to Snapcraft ([#&#8203;35778](https://github.com/go-gitea/gitea/issues/35778))

### [`v1.25.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1250---2025-10-30)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.24.7...v1.25.0)

- BREAKING
  - Return 201 Created for CreateVariable API responses ([#&#8203;34517](https://github.com/go-gitea/gitea/issues/34517))
  - Add label 'state' to metric 'gitea\_users' ([#&#8203;34326](https://github.com/go-gitea/gitea/issues/34326))
- SECURITY
  - Upgrade security public key ([#&#8203;34956](https://github.com/go-gitea/gitea/issues/34956))
  - Also include all security fixes in 1.24.x after 1.25.0-rc0
- FEATURES
  - Stream repo zip/tar.gz/bundle achives by default ([#&#8203;35487](https://github.com/go-gitea/gitea/issues/35487))
  - Use configurable remote name for git commands ([#&#8203;35172](https://github.com/go-gitea/gitea/issues/35172))
  - Send email on Workflow Run Success/Failure ([#&#8203;34982](https://github.com/go-gitea/gitea/issues/34982))
  - Refactor OpenIDConnect to support SSH/FullName sync ([#&#8203;34978](https://github.com/go-gitea/gitea/issues/34978))
  - Refactor repo contents API and add "contents-ext" API ([#&#8203;34822](https://github.com/go-gitea/gitea/issues/34822))
  - Add support for 3D/CAD file formats preview ([#&#8203;34794](https://github.com/go-gitea/gitea/issues/34794))
  - Improve instance wide ssh commit signing ([#&#8203;34341](https://github.com/go-gitea/gitea/issues/34341))
  - Edit file workflow for creating a fork and proposing changes ([#&#8203;34240](https://github.com/go-gitea/gitea/issues/34240))
  - Follow file symlinks in the UI to their target ([#&#8203;28835](https://github.com/go-gitea/gitea/issues/28835))
  - Allow renaming/moving binary/LFS files in the UI ([#&#8203;34350](https://github.com/go-gitea/gitea/issues/34350))
- PERFORMANCE
  - Improve the performance when detecting the file editable ([#&#8203;34653](https://github.com/go-gitea/gitea/issues/34653))
- ENHANCEMENTS
  - Enable more markdown paste features in textarea editor ([#&#8203;35494](https://github.com/go-gitea/gitea/issues/35494))
  - Don't store repo archives on `gitea dump` ([#&#8203;35467](https://github.com/go-gitea/gitea/issues/35467))
  - Always return the relevant status information, even if no status exists. ([#&#8203;35335](https://github.com/go-gitea/gitea/issues/35335))
  - Add start time on perf trace because it seems some steps haven't been recorded. ([#&#8203;35282](https://github.com/go-gitea/gitea/issues/35282))
  - Remove deprecated auth sources ([#&#8203;35272](https://github.com/go-gitea/gitea/issues/35272))
  - When sorting issues by nearest due date, issues without due date should be sorted ascending ([#&#8203;35267](https://github.com/go-gitea/gitea/issues/35267))
  - Disable field count validation of CSV viewer ([#&#8203;35228](https://github.com/go-gitea/gitea/issues/35228))
  - Add `has_code` to repository REST API ([#&#8203;35214](https://github.com/go-gitea/gitea/issues/35214))
  - Display pull request in merged commit view ([#&#8203;35202](https://github.com/go-gitea/gitea/issues/35202))
  - Support Basic Authentication for archive downloads ([#&#8203;35087](https://github.com/go-gitea/gitea/issues/35087))
  - Add hover background to table rows in user and repo admin page ([#&#8203;35072](https://github.com/go-gitea/gitea/issues/35072))
  - Partially refresh notifications list ([#&#8203;35010](https://github.com/go-gitea/gitea/issues/35010))
  - Also display "recently pushed branch" alert on PR view ([#&#8203;35001](https://github.com/go-gitea/gitea/issues/35001))
  - Refactor time tracker UI ([#&#8203;34983](https://github.com/go-gitea/gitea/issues/34983))
  - Improve CLI commands ([#&#8203;34973](https://github.com/go-gitea/gitea/issues/34973))
  - Improve project & label color picker and image scroll ([#&#8203;34971](https://github.com/go-gitea/gitea/issues/34971))
  - Improve NuGet API Parity ([#&#8203;21291](https://github.com/go-gitea/gitea/issues/21291)) ([#&#8203;34940](https://github.com/go-gitea/gitea/issues/34940))
  - Support getting last commit message using contents-ext API ([#&#8203;34904](https://github.com/go-gitea/gitea/issues/34904))
  - Adds title on branch commit counts ([#&#8203;34869](https://github.com/go-gitea/gitea/issues/34869))
  - Add "Cancel workflow run" button to Actions list page ([#&#8203;34817](https://github.com/go-gitea/gitea/issues/34817))
  - Improve img lazy loading ([#&#8203;34804](https://github.com/go-gitea/gitea/issues/34804))
  - Forks repository list page follow other repositories page ([#&#8203;34784](https://github.com/go-gitea/gitea/issues/34784))
  - Add ff\_only parameter to POST /repos/{owner}/{repo}/merge-upstream ([#&#8203;34770](https://github.com/go-gitea/gitea/issues/34770))
  - Rework delete org and rename org UI ([#&#8203;34762](https://github.com/go-gitea/gitea/issues/34762))
  - Improve nuget/rubygems package registries ([#&#8203;34741](https://github.com/go-gitea/gitea/issues/34741))
  - Add repo file tree item link behavior ([#&#8203;34730](https://github.com/go-gitea/gitea/issues/34730))
  - Add issue delete notifier ([#&#8203;34592](https://github.com/go-gitea/gitea/issues/34592))
  - Improve Actions list ([#&#8203;34530](https://github.com/go-gitea/gitea/issues/34530))
  - Add a default tab on repo header when migrating ([#&#8203;34503](https://github.com/go-gitea/gitea/issues/34503))
  - Add post-installation redirect based on admin account status ([#&#8203;34493](https://github.com/go-gitea/gitea/issues/34493))
  - Trigger 'unlabeled' event when label is Deleted from PR ([#&#8203;34316](https://github.com/go-gitea/gitea/issues/34316))
  - Support annotated tags when using create release API ([#&#8203;31840](https://github.com/go-gitea/gitea/issues/31840))
  - Use lfs label for lfs file rather than a long description ([#&#8203;34363](https://github.com/go-gitea/gitea/issues/34363))
  - Add "View workflow file" to Actions list page ([#&#8203;34538](https://github.com/go-gitea/gitea/issues/34538))
  - Move organization's visibility change to danger zone. ([#&#8203;34814](https://github.com/go-gitea/gitea/issues/34814))
  - Don't block site admin's operation if SECRET\_KEY is lost ([#&#8203;35721](https://github.com/go-gitea/gitea/issues/35721))
  - Make restricted users can access public repositories ([#&#8203;35693](https://github.com/go-gitea/gitea/issues/35693))
  - The status icon of the Action step is consistent with GitHub ([#&#8203;35618](https://github.com/go-gitea/gitea/issues/35618)) [#&#8203;35621](https://github.com/go-gitea/gitea/issues/35621)
- BUGFIXES
  - Update tab title when navigating file tree ([#&#8203;35757](https://github.com/go-gitea/gitea/issues/35757)) [#&#8203;35772](https://github.com/go-gitea/gitea/issues/35772)
  - Fix "ref-issue" handling in markup ([#&#8203;35739](https://github.com/go-gitea/gitea/issues/35739)) [#&#8203;35771](https://github.com/go-gitea/gitea/issues/35771)
  - Fix webhook to prevent tag events from bypassing branch filters targets ([#&#8203;35567](https://github.com/go-gitea/gitea/issues/35567)) [#&#8203;35577](https://github.com/go-gitea/gitea/issues/35577)
  - Fix markup init after issue comment editing ([#&#8203;35536](https://github.com/go-gitea/gitea/issues/35536)) [#&#8203;35537](https://github.com/go-gitea/gitea/issues/35537)
  - Fix creating pull request failure when the target branch name is the same as some tag ([#&#8203;35552](https://github.com/go-gitea/gitea/issues/35552)) [#&#8203;35582](https://github.com/go-gitea/gitea/issues/35582)
  - Fix auto-expand and auto-scroll for actions logs ([#&#8203;35570](https://github.com/go-gitea/gitea/issues/35570)) ([#&#8203;35583](https://github.com/go-gitea/gitea/issues/35583)) [#&#8203;35586](https://github.com/go-gitea/gitea/issues/35586)
  - Use inputs context when parsing workflows ([#&#8203;35590](https://github.com/go-gitea/gitea/issues/35590)) [#&#8203;35595](https://github.com/go-gitea/gitea/issues/35595)
  - Fix diffpatch API endpoint ([#&#8203;35610](https://github.com/go-gitea/gitea/issues/35610)) [#&#8203;35613](https://github.com/go-gitea/gitea/issues/35613)
  - Creating push comments before invoke pull request checking ([#&#8203;35647](https://github.com/go-gitea/gitea/issues/35647)) [#&#8203;35668](https://github.com/go-gitea/gitea/issues/35668)
  - Fix missing Close when error occurs and abused connection pool ([#&#8203;35658](https://github.com/go-gitea/gitea/issues/35658)) [#&#8203;35670](https://github.com/go-gitea/gitea/issues/35670)
  - Fix build ([#&#8203;35674](https://github.com/go-gitea/gitea/issues/35674))
  - Use LFS object size instead of blob size when viewing a LFS file ([#&#8203;35679](https://github.com/go-gitea/gitea/issues/35679))
  - Fix workflow run event status while rerunning a failed job ([#&#8203;35689](https://github.com/go-gitea/gitea/issues/35689))
  - Avoid emoji mismatch and allow to only enable chosen emojis ([#&#8203;35692](https://github.com/go-gitea/gitea/issues/35692))
  - Refactor legacy code, fix LFS auth bypass, fix symlink bypass ([#&#8203;35708](https://github.com/go-gitea/gitea/issues/35708))
  - Fix various trivial problems ([#&#8203;35714](https://github.com/go-gitea/gitea/issues/35714))
  - Fix attachment file size limit in server backend ([#&#8203;35519](https://github.com/go-gitea/gitea/issues/35519))
  - Honor delete branch on merge repo setting when using merge API ([#&#8203;35488](https://github.com/go-gitea/gitea/issues/35488))
  - Fix external render, make iframe render work ([#&#8203;35727](https://github.com/go-gitea/gitea/issues/35727), [#&#8203;35730](https://github.com/go-gitea/gitea/issues/35730))
  - Upgrade go mail to 0.7.2 ([#&#8203;35748](https://github.com/go-gitea/gitea/issues/35748))
  - Revert [#&#8203;18491](https://github.com/go-gitea/gitea/issues/18491), fix oauth2 client link account ([#&#8203;35745](https://github.com/go-gitea/gitea/issues/35745))
  - Fix different behavior in status check pattern matching with double stars ([#&#8203;35474](https://github.com/go-gitea/gitea/issues/35474))
  - Fix overflow in notifications list ([#&#8203;35446](https://github.com/go-gitea/gitea/issues/35446))
  - Fix package link setting can only list limited repositories ([#&#8203;35394](https://github.com/go-gitea/gitea/issues/35394))
  - Extend comment treepath length ([#&#8203;35389](https://github.com/go-gitea/gitea/issues/35389))
  - Fix font-size in inline code comment preview ([#&#8203;35209](https://github.com/go-gitea/gitea/issues/35209))
  - Move git config/remote to gitrepo package and add global lock to resolve possible conflict when updating repository git config file ([#&#8203;35151](https://github.com/go-gitea/gitea/issues/35151))
  - Change some columns from text to longtext and fix column wrong type caused by xorm ([#&#8203;35141](https://github.com/go-gitea/gitea/issues/35141))
  - Redirect to a presigned URL of HEAD for HEAD requests ([#&#8203;35088](https://github.com/go-gitea/gitea/issues/35088))
  - Fix git commit committer parsing and add some tests ([#&#8203;35007](https://github.com/go-gitea/gitea/issues/35007))
  - Fix OCI manifest parser ([#&#8203;34797](https://github.com/go-gitea/gitea/issues/34797))
  - Refactor FindOrgOptions to use enum instead of bool, fix membership visibility ([#&#8203;34629](https://github.com/go-gitea/gitea/issues/34629))
  - Fix notification count positioning for variable-width elements ([#&#8203;34597](https://github.com/go-gitea/gitea/issues/34597))
  - Keeping consistent between UI and API about combined commit status state and fix some bugs ([#&#8203;34562](https://github.com/go-gitea/gitea/issues/34562))
  - Fix possible panic ([#&#8203;34508](https://github.com/go-gitea/gitea/issues/34508))
  - Fix autofocus behavior ([#&#8203;34397](https://github.com/go-gitea/gitea/issues/34397))
  - Fix Actions API ([#&#8203;35204](https://github.com/go-gitea/gitea/issues/35204))
  - Fix ListWorkflowRuns OpenAPI response model. ([#&#8203;35026](https://github.com/go-gitea/gitea/issues/35026))
  - Small fix in Pull Requests page ([#&#8203;34612](https://github.com/go-gitea/gitea/issues/34612))
  - Fix http auth header parsing ([#&#8203;34936](https://github.com/go-gitea/gitea/issues/34936))
  - Fix modal + form abuse ([#&#8203;34921](https://github.com/go-gitea/gitea/issues/34921))
  - Fix PR toggle WIP ([#&#8203;34920](https://github.com/go-gitea/gitea/issues/34920))
  - Fix log fmt ([#&#8203;34810](https://github.com/go-gitea/gitea/issues/34810))
  - Replace stopwatch toggle with explicit start/stop actions ([#&#8203;34818](https://github.com/go-gitea/gitea/issues/34818))
  - Fix some package registry problems ([#&#8203;34759](https://github.com/go-gitea/gitea/issues/34759))
  - Fix RPM package download routing & missing package version count ([#&#8203;34909](https://github.com/go-gitea/gitea/issues/34909))
  - Fix repo search input height ([#&#8203;34330](https://github.com/go-gitea/gitea/issues/34330))
  - Fix "The sidebar of the repository file list does not have a fixed height [#&#8203;34298](https://github.com/go-gitea/gitea/issues/34298)" ([#&#8203;34321](https://github.com/go-gitea/gitea/issues/34321))
  - Fix minor typos in two files #HSFDPMUW ([#&#8203;34944](https://github.com/go-gitea/gitea/issues/34944))
  - Fix actions skipped commit status indicator ([#&#8203;34507](https://github.com/go-gitea/gitea/issues/34507))
  - Fix job status aggregation logic ([#&#8203;35000](https://github.com/go-gitea/gitea/issues/35000))
  - Fix broken OneDev migration caused by various REST API changes in OneDev 7.8.0 and later ([#&#8203;35216](https://github.com/go-gitea/gitea/issues/35216))
  - Fix typo in oauth2\_full\_name\_claim\_name string ([#&#8203;35199](https://github.com/go-gitea/gitea/issues/35199))
  - Fix typo in locale\_en-US.ini ([#&#8203;35196](https://github.com/go-gitea/gitea/issues/35196))
- API
  - Exposing TimeEstimate field in the API ([#&#8203;35475](https://github.com/go-gitea/gitea/issues/35475))
  - UpdateBranch API supports renaming a branch ([#&#8203;35374](https://github.com/go-gitea/gitea/issues/35374))
  - Add `owner` and `parent` fields clarification to docs ([#&#8203;35023](https://github.com/go-gitea/gitea/issues/35023))
  - Improve OAuth2 provider (correct Issuer, respect ENABLED) ([#&#8203;34966](https://github.com/go-gitea/gitea/issues/34966))
  - Add a `login`/`login-name`/`username` disambiguation to affected endpoint parameters and response/request models ([#&#8203;34901](https://github.com/go-gitea/gitea/issues/34901))
  - Do not mutate incoming options to SearchRepositoryByName ([#&#8203;34553](https://github.com/go-gitea/gitea/issues/34553))
  - Do not mutate incoming options to RenderUserSearch and SearchUsers  ([#&#8203;34544](https://github.com/go-gitea/gitea/issues/34544))
  - Export repo's manual merge settings ([#&#8203;34502](https://github.com/go-gitea/gitea/issues/34502))
  - Add date range filtering to commit retrieval endpoints ([#&#8203;34497](https://github.com/go-gitea/gitea/issues/34497))
  - Add endpoint deleting workflow run ([#&#8203;34337](https://github.com/go-gitea/gitea/issues/34337))
  - Add workflow\_run api + webhook ([#&#8203;33964](https://github.com/go-gitea/gitea/issues/33964))
- REFACTOR
  - Move updateref and removeref to gitrepo and remove unnecessary open repository ([#&#8203;35511](https://github.com/go-gitea/gitea/issues/35511))
  - Remove unused param `doer` ([#&#8203;34545](https://github.com/go-gitea/gitea/issues/34545))
  - Split GetLatestCommitStatus as two functions ([#&#8203;34535](https://github.com/go-gitea/gitea/issues/34535))
  - Use gitrepo.SetDefaultBranch when set default branch of wiki repository ([#&#8203;33911](https://github.com/go-gitea/gitea/issues/33911))
  - Refactor editor ([#&#8203;34780](https://github.com/go-gitea/gitea/issues/34780))
  - Refactor packages ([#&#8203;34777](https://github.com/go-gitea/gitea/issues/34777))
  - Refactor container package ([#&#8203;34877](https://github.com/go-gitea/gitea/issues/34877))
  - Refactor "change file" API ([#&#8203;34855](https://github.com/go-gitea/gitea/issues/34855))
  - Rename pull request GetGitRefName to GetGitHeadRefName to prepare introducing GetGitMergeRefName ([#&#8203;35093](https://github.com/go-gitea/gitea/issues/35093))
  - Move git command to git/gitcmd ([#&#8203;35483](https://github.com/go-gitea/gitea/issues/35483))
  - Use db.WithTx/WithTx2 instead of TxContext when possible ([#&#8203;35428](https://github.com/go-gitea/gitea/issues/35428))
  - Support Node.js 22.6 with type stripping ([#&#8203;35427](https://github.com/go-gitea/gitea/issues/35427))
  - Migrate tools and configs to typescript, require node.js >= 22.18.0 ([#&#8203;35421](https://github.com/go-gitea/gitea/issues/35421))
  - Check user and repo for redirects when using git via SSH transport ([#&#8203;35416](https://github.com/go-gitea/gitea/issues/35416))
  - Remove the duplicated function GetTags ([#&#8203;35375](https://github.com/go-gitea/gitea/issues/35375))
  - Refactor to use reflect.TypeFor ([#&#8203;35370](https://github.com/go-gitea/gitea/issues/35370))
  - Deleting branch could delete broken branch which has database record but git branch is missing ([#&#8203;35360](https://github.com/go-gitea/gitea/issues/35360))
  - Exit with success when already up to date ([#&#8203;35312](https://github.com/go-gitea/gitea/issues/35312))
  - Split admin config settings templates to make it maintain easier ([#&#8203;35294](https://github.com/go-gitea/gitea/issues/35294))
  - A small refactor to use context in the service layer ([#&#8203;35179](https://github.com/go-gitea/gitea/issues/35179))
  - Refactor and update mail templates ([#&#8203;35150](https://github.com/go-gitea/gitea/issues/35150))
  - Use db.WithTx/WithTx2 instead of TxContext when possible ([#&#8203;35130](https://github.com/go-gitea/gitea/issues/35130))
  - Align `issue-title-buttons` with `list-header` ([#&#8203;35018](https://github.com/go-gitea/gitea/issues/35018))
  - Add Notifications section in User Settings ([#&#8203;35008](https://github.com/go-gitea/gitea/issues/35008))
  - Tweak placement of diff file menu ([#&#8203;34999](https://github.com/go-gitea/gitea/issues/34999))
  - Refactor mail template and support preview ([#&#8203;34990](https://github.com/go-gitea/gitea/issues/34990))
  - Rerun job only when run is done ([#&#8203;34970](https://github.com/go-gitea/gitea/issues/34970))
  - Merge index.js ([#&#8203;34963](https://github.com/go-gitea/gitea/issues/34963))
  - Refactor "delete-button" to "link-action" ([#&#8203;34962](https://github.com/go-gitea/gitea/issues/34962))
  - Refactor webhook and fix feishu/lark secret ([#&#8203;34961](https://github.com/go-gitea/gitea/issues/34961))
  - Exclude devtest.ts from tailwindcss ([#&#8203;34935](https://github.com/go-gitea/gitea/issues/34935))
  - Refactor head navbar icons ([#&#8203;34922](https://github.com/go-gitea/gitea/issues/34922))
  - Improve html escape ([#&#8203;34911](https://github.com/go-gitea/gitea/issues/34911))
  - Improve tags list page ([#&#8203;34898](https://github.com/go-gitea/gitea/issues/34898))
  - Improve `labels-list` rendering ([#&#8203;34846](https://github.com/go-gitea/gitea/issues/34846))
  - Remove unused variable HUGO\_VERSION ([#&#8203;34840](https://github.com/go-gitea/gitea/issues/34840))
  - Correct migration tab name ([#&#8203;34826](https://github.com/go-gitea/gitea/issues/34826))
  - Refactor template helper ([#&#8203;34819](https://github.com/go-gitea/gitea/issues/34819))
  - Use `shallowRef` instead of `ref` in `.vue` files where possible ([#&#8203;34813](https://github.com/go-gitea/gitea/issues/34813))
  - Use standalone function to update repository cols ([#&#8203;34811](https://github.com/go-gitea/gitea/issues/34811))
  - Refactor wiki ([#&#8203;34805](https://github.com/go-gitea/gitea/issues/34805))
  - Remove unnecessary duplicate code ([#&#8203;34733](https://github.com/go-gitea/gitea/issues/34733))
  - Refactor embedded assets and drop unnecessary dependencies ([#&#8203;34692](https://github.com/go-gitea/gitea/issues/34692))
  - Update x/crypto package and make builtin SSH use default parameters ([#&#8203;34667](https://github.com/go-gitea/gitea/issues/34667))
  - Add `--color-logo`, matching the logo's primary color ([#&#8203;34639](https://github.com/go-gitea/gitea/issues/34639))
  - Add openssh-keygen to rootless image ([#&#8203;34625](https://github.com/go-gitea/gitea/issues/34625))
  - Replace update repository function in some places ([#&#8203;34566](https://github.com/go-gitea/gitea/issues/34566))
  - Change "rejected" to "changes requested" in 3rd party PR review notification ([#&#8203;34481](https://github.com/go-gitea/gitea/issues/34481))
  - Remove legacy template helper functions ([#&#8203;34426](https://github.com/go-gitea/gitea/issues/34426))
  - Use run-name and evaluate workflow variables ([#&#8203;34301](https://github.com/go-gitea/gitea/issues/34301))
  - Move HasWiki to repository service package ([#&#8203;33912](https://github.com/go-gitea/gitea/issues/33912))
  - Move some functions from package git to gitrepo ([#&#8203;33910](https://github.com/go-gitea/gitea/issues/33910))
- TESTING
  - Add webhook test for push event ([#&#8203;34442](https://github.com/go-gitea/gitea/issues/34442))
  - Add a webhook push test for dev branch ([#&#8203;34421](https://github.com/go-gitea/gitea/issues/34421))
  - Add migrations tests ([#&#8203;34456](https://github.com/go-gitea/gitea/issues/34456)) ([#&#8203;34498](https://github.com/go-gitea/gitea/issues/34498))
- STYLE
  - Enforce explanation for necessary nolints and fix bugs ([#&#8203;34883](https://github.com/go-gitea/gitea/issues/34883))
  - Fix remaining issues after `gopls modernize` formatting ([#&#8203;34771](https://github.com/go-gitea/gitea/issues/34771))
  - Update gofumpt, add go.mod ignore directive ([#&#8203;35434](https://github.com/go-gitea/gitea/issues/35434))
  - Enforce nolint scope ([#&#8203;34851](https://github.com/go-gitea/gitea/issues/34851))
  - Enable gocritic `equalFold` and fix issues ([#&#8203;34952](https://github.com/go-gitea/gitea/issues/34952))
  - Run `gopls modernize` on codebase ([#&#8203;34751](https://github.com/go-gitea/gitea/issues/34751))
  - Upgrade `gopls` to v0.19.0, add `make fix` ([#&#8203;34772](https://github.com/go-gitea/gitea/issues/34772))
- BUILD
  - bump archives\&rar dep ([#&#8203;35637](https://github.com/go-gitea/gitea/issues/35637)) [#&#8203;35638](https://github.com/go-gitea/gitea/issues/35638)
  - Use github.com/mholt/archives replace github.com/mholt/archiver ([#&#8203;35390](https://github.com/go-gitea/gitea/issues/35390))
  - Update JS and PY dependencies ([#&#8203;35444](https://github.com/go-gitea/gitea/issues/35444))
  - Upgrade devcontainer go version to 1.24.6 ([#&#8203;35298](https://github.com/go-gitea/gitea/issues/35298))
  - Upgrade golang to 1.25.1 and add descriptions for the swagger structs' fields ([#&#8203;35418](https://github.com/go-gitea/gitea/issues/35418))
  - Update JS and PY deps ([#&#8203;35191](https://github.com/go-gitea/gitea/issues/35191))
  - Update JS and PY dependencies ([#&#8203;34391](https://github.com/go-gitea/gitea/issues/34391))
  - Update go tool dependencies ([#&#8203;34845](https://github.com/go-gitea/gitea/issues/34845))
  - Update `uint8-to-base64`, remove type stub ([#&#8203;34844](https://github.com/go-gitea/gitea/issues/34844))
  - Switch to `@resvg/resvg-wasm` for `generate-images` ([#&#8203;35415](https://github.com/go-gitea/gitea/issues/35415))
  - Switch to pnpm ([#&#8203;35274](https://github.com/go-gitea/gitea/issues/35274))
  - Update chroma to v2.20.0 ([#&#8203;35220](https://github.com/go-gitea/gitea/issues/35220))
  - Migrate to urfave v3 ([#&#8203;34510](https://github.com/go-gitea/gitea/issues/34510))
  - Update JS deps, regenerate SVGs ([#&#8203;34640](https://github.com/go-gitea/gitea/issues/34640))
  - Upgrade dependencies ([#&#8203;35384](https://github.com/go-gitea/gitea/issues/35384))
  - Bump `@github/relative-time-element` to v4.4.8 ([#&#8203;34413](https://github.com/go-gitea/gitea/issues/34413))
  - Update JS dependencies ([#&#8203;34951](https://github.com/go-gitea/gitea/issues/34951))
  - Upgrade orgmode to v1.8.0 ([#&#8203;34721](https://github.com/go-gitea/gitea/issues/34721))
  - Raise minimum Node.js version to 20, test on 24 ([#&#8203;34713](https://github.com/go-gitea/gitea/issues/34713))
  - Update JS deps ([#&#8203;34701](https://github.com/go-gitea/gitea/issues/34701))
  - Upgrade htmx to 2.0.6 ([#&#8203;34887](https://github.com/go-gitea/gitea/issues/34887))
  - Update eslint to v9 ([#&#8203;35485](https://github.com/go-gitea/gitea/issues/35485))
  - Update js dependencies ([#&#8203;35429](https://github.com/go-gitea/gitea/issues/35429))
  - Clean up npm dependencies ([#&#8203;35508](https://github.com/go-gitea/gitea/issues/35508))
  - Clean up npm dependencies ([#&#8203;35484](https://github.com/go-gitea/gitea/issues/35484))
  - Bump setup-node to v5 ([#&#8203;35448](https://github.com/go-gitea/gitea/issues/35448))
- MISC
  - Add gitignore rules to exclude LLM instruction files ([#&#8203;35076](https://github.com/go-gitea/gitea/issues/35076))
  - Gitignore: Visual Studio settings folder ([#&#8203;34375](https://github.com/go-gitea/gitea/issues/34375))
  - Improve language in en-US locale strings ([#&#8203;35124](https://github.com/go-gitea/gitea/issues/35124))
  - Fixed all grammatical errors in locale\_en-US.ini ([#&#8203;35053](https://github.com/go-gitea/gitea/issues/35053))
  - Docs/fix typo and grammar in CONTRIBUTING.md ([#&#8203;35024](https://github.com/go-gitea/gitea/issues/35024))
  - Improve english grammar and readability in locale\_en-US.ini ([#&#8203;35017](https://github.com/go-gitea/gitea/issues/35017))

### [`v1.24.7`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1247---2025-10-24)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.24.6...v1.24.7)

- SECURITY
  - Refactor legacy code ([#&#8203;35708](https://github.com/go-gitea/gitea/issues/35708)) ([#&#8203;35713](https://github.com/go-gitea/gitea/issues/35713))
  - Fixing issue [#&#8203;35530](https://github.com/go-gitea/gitea/issues/35530): Password Leak in Log Messages ([#&#8203;35584](https://github.com/go-gitea/gitea/issues/35584)) ([#&#8203;35665](https://github.com/go-gitea/gitea/issues/35665))
  - Fix a bug missed return ([#&#8203;35655](https://github.com/go-gitea/gitea/issues/35655)) ([#&#8203;35671](https://github.com/go-gitea/gitea/issues/35671))
- BUGFIXES
  - Fix inputing review comment will remove reviewer ([#&#8203;35591](https://github.com/go-gitea/gitea/issues/35591)) ([#&#8203;35664](https://github.com/go-gitea/gitea/issues/35664))
- TESTING
  - Mock external service in hcaptcha TestCaptcha ([#&#8203;35604](https://github.com/go-gitea/gitea/issues/35604)) ([#&#8203;35663](https://github.com/go-gitea/gitea/issues/35663))
  - Fix build ([#&#8203;35669](https://github.com/go-gitea/gitea/issues/35669))

### [`v1.24.6`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1246---2025-09-10)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.24.5...v1.24.6)

- SECURITY
  - Upgrade xz to v0.5.15 ([#&#8203;35385](https://github.com/go-gitea/gitea/issues/35385))
- BUGFIXES
  - Fix a compare page 404 bug when the pull request disabled ([#&#8203;35441](https://github.com/go-gitea/gitea/issues/35441)) ([#&#8203;35453](https://github.com/go-gitea/gitea/issues/35453))
  - Fix bug when issue disabled, pull request number in the commit message cannot be redirected ([#&#8203;35420](https://github.com/go-gitea/gitea/issues/35420)) ([#&#8203;35442](https://github.com/go-gitea/gitea/issues/35442))
  - Add author.name field to Swift Package Registry API response ([#&#8203;35410](https://github.com/go-gitea/gitea/issues/35410)) ([#&#8203;35431](https://github.com/go-gitea/gitea/issues/35431))
  - Remove usernames when empty in discord webhook ([#&#8203;35412](https://github.com/go-gitea/gitea/issues/35412)) ([#&#8203;35417](https://github.com/go-gitea/gitea/issues/35417))
  - Allow foreachref parser to grow its buffer ([#&#8203;35365](https://github.com/go-gitea/gitea/issues/35365)) ([#&#8203;35376](https://github.com/go-gitea/gitea/issues/35376))
  - Allow deleting comment with content via API like web did ([#&#8203;35346](https://github.com/go-gitea/gitea/issues/35346)) ([#&#8203;35354](https://github.com/go-gitea/gitea/issues/35354))
  - Fix atom/rss mixed error ([#&#8203;35345](https://github.com/go-gitea/gitea/issues/35345)) ([#&#8203;35347](https://github.com/go-gitea/gitea/issues/35347))
  - Fix review request webhook bug ([#&#8203;35339](https://github.com/go-gitea/gitea/issues/35339))
  - Remove duplicate html IDs ([#&#8203;35210](https://github.com/go-gitea/gitea/issues/35210)) ([#&#8203;35325](https://github.com/go-gitea/gitea/issues/35325))
  - Fix LFS range size header response ([#&#8203;35277](https://github.com/go-gitea/gitea/issues/35277)) ([#&#8203;35293](https://github.com/go-gitea/gitea/issues/35293))
  - Fix GitHub release assets URL validation ([#&#8203;35287](https://github.com/go-gitea/gitea/issues/35287)) ([#&#8203;35290](https://github.com/go-gitea/gitea/issues/35290))
  - Fix token lifetime, closes [#&#8203;35230](https://github.com/go-gitea/gitea/issues/35230) ([#&#8203;35271](https://github.com/go-gitea/gitea/issues/35271)) ([#&#8203;35281](https://github.com/go-gitea/gitea/issues/35281))
  - Fix push commits comments when changing the pull request target branch ([#&#8203;35386](https://github.com/go-gitea/gitea/issues/35386)) ([#&#8203;35443](https://github.com/go-gitea/gitea/issues/35443))

### [`v1.24.5`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1245---2025-08-12)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.24.4...v1.24.5)

- BUGFIXES
  - Fix a bug where lfs gc never worked. ([#&#8203;35198](https://github.com/go-gitea/gitea/issues/35198)) ([#&#8203;35255](https://github.com/go-gitea/gitea/issues/35255))
  - Reload issue when sending webhook to make num comments is right. ([#&#8203;35243](https://github.com/go-gitea/gitea/issues/35243)) ([#&#8203;35248](https://github.com/go-gitea/gitea/issues/35248))
  - Fix bug when review pull request commits ([#&#8203;35192](https://github.com/go-gitea/gitea/issues/35192)) ([#&#8203;35246](https://github.com/go-gitea/gitea/issues/35246))
- MISC
  - Vertically center "Show Resolved" ([#&#8203;35211](https://github.com/go-gitea/gitea/issues/35211)) ([#&#8203;35218](https://github.com/go-gitea/gitea/issues/35218))

### [`v1.24.4`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1244---2025-08-03)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.24.3...v1.24.4)

- BUGFIXES
  - Fix various bugs (1.24) ([#&#8203;35186](https://github.com/go-gitea/gitea/issues/35186))
  - Fix migrate input box bug ([#&#8203;35166](https://github.com/go-gitea/gitea/issues/35166)) ([#&#8203;35171](https://github.com/go-gitea/gitea/issues/35171))
  - Only hide dropzone when no files have been uploaded ([#&#8203;35156](https://github.com/go-gitea/gitea/issues/35156)) ([#&#8203;35167](https://github.com/go-gitea/gitea/issues/35167))
  - Fix review comment/dimiss comment x reference can be refereced back ([#&#8203;35094](https://github.com/go-gitea/gitea/issues/35094)) ([#&#8203;35099](https://github.com/go-gitea/gitea/issues/35099))
  - Fix submodule nil check ([#&#8203;35096](https://github.com/go-gitea/gitea/issues/35096)) ([#&#8203;35098](https://github.com/go-gitea/gitea/issues/35098))
- MISC
  - Don't use full-file highlight when there is a git diff textconv ([#&#8203;35114](https://github.com/go-gitea/gitea/issues/35114)) ([#&#8203;35119](https://github.com/go-gitea/gitea/issues/35119))
  - Increase gap on latest commit ([#&#8203;35104](https://github.com/go-gitea/gitea/issues/35104)) ([#&#8203;35113](https://github.com/go-gitea/gitea/issues/35113))

### [`v1.24.3`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1243---2025-07-15)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.24.2...v1.24.3)

- BUGFIXES
  - Fix form property assignment edge case ([#&#8203;35073](https://github.com/go-gitea/gitea/issues/35073)) ([#&#8203;35078](https://github.com/go-gitea/gitea/issues/35078))
  - Improve submodule relative path handling ([#&#8203;35056](https://github.com/go-gitea/gitea/issues/35056)) ([#&#8203;35075](https://github.com/go-gitea/gitea/issues/35075))
  - Fix incorrect comment diff hunk parsing, fix github asset ID nil panic ([#&#8203;35046](https://github.com/go-gitea/gitea/issues/35046)) ([#&#8203;35055](https://github.com/go-gitea/gitea/issues/35055))
  - Fix updating user visibility ([#&#8203;35036](https://github.com/go-gitea/gitea/issues/35036)) ([#&#8203;35044](https://github.com/go-gitea/gitea/issues/35044))
  - Support base64-encoded agit push options ([#&#8203;35037](https://github.com/go-gitea/gitea/issues/35037)) ([#&#8203;35041](https://github.com/go-gitea/gitea/issues/35041))
  - Make submodule link work with relative path ([#&#8203;35034](https://github.com/go-gitea/gitea/issues/35034)) ([#&#8203;35038](https://github.com/go-gitea/gitea/issues/35038))
  - Fix bug when displaying git user avatar in commits list ([#&#8203;35006](https://github.com/go-gitea/gitea/issues/35006))
  - Fix API response for swagger spec ([#&#8203;35029](https://github.com/go-gitea/gitea/issues/35029))
  - Start automerge check again after the conflict check and the schedule ([#&#8203;34988](https://github.com/go-gitea/gitea/issues/34988)) ([#&#8203;35002](https://github.com/go-gitea/gitea/issues/35002))
  - Fix the response format for actions/workflows ([#&#8203;35009](https://github.com/go-gitea/gitea/issues/35009)) ([#&#8203;35016](https://github.com/go-gitea/gitea/issues/35016))
  - Fix repo settings and protocol log problems ([#&#8203;35012](https://github.com/go-gitea/gitea/issues/35012)) ([#&#8203;35013](https://github.com/go-gitea/gitea/issues/35013))
  - Fix project images scroll ([#&#8203;34971](https://github.com/go-gitea/gitea/issues/34971)) ([#&#8203;34972](https://github.com/go-gitea/gitea/issues/34972))
  - Mark old reviews as stale on agit pr updates ([#&#8203;34933](https://github.com/go-gitea/gitea/issues/34933)) ([#&#8203;34965](https://github.com/go-gitea/gitea/issues/34965))
  - Fix git graph page ([#&#8203;34948](https://github.com/go-gitea/gitea/issues/34948)) ([#&#8203;34949](https://github.com/go-gitea/gitea/issues/34949))
  - Don't send trigger for a pending review's comment create/update/delete ([#&#8203;34928](https://github.com/go-gitea/gitea/issues/34928)) ([#&#8203;34939](https://github.com/go-gitea/gitea/issues/34939))
  - Fix some log and UI problems ([#&#8203;34863](https://github.com/go-gitea/gitea/issues/34863)) ([#&#8203;34868](https://github.com/go-gitea/gitea/issues/34868))
  - Fix archive API ([#&#8203;34853](https://github.com/go-gitea/gitea/issues/34853)) ([#&#8203;34857](https://github.com/go-gitea/gitea/issues/34857))
  - Ignore force pushes for changed files in a PR review ([#&#8203;34837](https://github.com/go-gitea/gitea/issues/34837)) ([#&#8203;34843](https://github.com/go-gitea/gitea/issues/34843))
  - Fix SSH LFS timeout ([#&#8203;34838](https://github.com/go-gitea/gitea/issues/34838)) ([#&#8203;34842](https://github.com/go-gitea/gitea/issues/34842))
  - Fix team permissions ([#&#8203;34827](https://github.com/go-gitea/gitea/issues/34827)) ([#&#8203;34836](https://github.com/go-gitea/gitea/issues/34836))
  - Fix job status aggregation logic ([#&#8203;34823](https://github.com/go-gitea/gitea/issues/34823)) ([#&#8203;34835](https://github.com/go-gitea/gitea/issues/34835))
  - Fix issue filter ([#&#8203;34914](https://github.com/go-gitea/gitea/issues/34914)) ([#&#8203;34915](https://github.com/go-gitea/gitea/issues/34915))
  - Fix typo in pull request merge warning message text ([#&#8203;34899](https://github.com/go-gitea/gitea/issues/34899)) ([#&#8203;34903](https://github.com/go-gitea/gitea/issues/34903))
  - Support the open-icon of folder ([#&#8203;34168](https://github.com/go-gitea/gitea/issues/34168)) ([#&#8203;34896](https://github.com/go-gitea/gitea/issues/34896))
  - Optimize flex layout of release attachment area ([#&#8203;34885](https://github.com/go-gitea/gitea/issues/34885)) ([#&#8203;34886](https://github.com/go-gitea/gitea/issues/34886))
  - Fix the issue of abnormal interface when there is no issue-item on the project page ([#&#8203;34791](https://github.com/go-gitea/gitea/issues/34791)) ([#&#8203;34880](https://github.com/go-gitea/gitea/issues/34880))
  - Skip updating timestamp when sync branch ([#&#8203;34875](https://github.com/go-gitea/gitea/issues/34875))
  - Fix required contexts and commit status matching bug ([#&#8203;34815](https://github.com/go-gitea/gitea/issues/34815)) ([#&#8203;34829](https://github.com/go-gitea/gitea/issues/34829))

### [`v1.24.2`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1242---2025-06-20)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.24.1...v1.24.2)

- BUGFIXES
  - Fix container range bug ([#&#8203;34795](https://github.com/go-gitea/gitea/issues/34795)) ([#&#8203;34796](https://github.com/go-gitea/gitea/issues/34796))
  - Upgrade chi to v5.2.2 ([#&#8203;34798](https://github.com/go-gitea/gitea/issues/34798)) ([#&#8203;34799](https://github.com/go-gitea/gitea/issues/34799))
- BUILD
  - Bump poetry feature to new url for dev container ([#&#8203;34787](https://github.com/go-gitea/gitea/issues/34787)) ([#&#8203;34790](https://github.com/go-gitea/gitea/issues/34790))

### [`v1.24.1`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1241---2025-06-18)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.24.0...v1.24.1)

- ENHANCEMENTS
  - Improve alignment of commit status icon on commit page ([#&#8203;34750](https://github.com/go-gitea/gitea/issues/34750)) ([#&#8203;34757](https://github.com/go-gitea/gitea/issues/34757))
  - Support title and body query parameters for new PRs ([#&#8203;34537](https://github.com/go-gitea/gitea/issues/34537)) ([#&#8203;34752](https://github.com/go-gitea/gitea/issues/34752))

- BUGFIXES
  - When using rules to delete packages, remove unclean bugs ([#&#8203;34632](https://github.com/go-gitea/gitea/issues/34632)) ([#&#8203;34761](https://github.com/go-gitea/gitea/issues/34761))
  - Fix ghost user in feeds when pushing in an actions, it should be gitea-actions ([#&#8203;34703](https://github.com/go-gitea/gitea/issues/34703)) ([#&#8203;34756](https://github.com/go-gitea/gitea/issues/34756))
  - Prevent double markdown link brackets when pasting URL ([#&#8203;34745](https://github.com/go-gitea/gitea/issues/34745)) ([#&#8203;34748](https://github.com/go-gitea/gitea/issues/34748))
  - Prevent duplicate form submissions when creating forks ([#&#8203;34714](https://github.com/go-gitea/gitea/issues/34714)) ([#&#8203;34735](https://github.com/go-gitea/gitea/issues/34735))
  - Fix markdown wrap ([#&#8203;34697](https://github.com/go-gitea/gitea/issues/34697)) ([#&#8203;34702](https://github.com/go-gitea/gitea/issues/34702))
  - Fix pull requests API convert panic when head repository is deleted. ([#&#8203;34685](https://github.com/go-gitea/gitea/issues/34685)) ([#&#8203;34687](https://github.com/go-gitea/gitea/issues/34687))
  - Fix commit message rendering and some UI problems ([#&#8203;34680](https://github.com/go-gitea/gitea/issues/34680)) ([#&#8203;34683](https://github.com/go-gitea/gitea/issues/34683))
  - Fix container range bug ([#&#8203;34725](https://github.com/go-gitea/gitea/issues/34725)) ([#&#8203;34732](https://github.com/go-gitea/gitea/issues/34732))
  - Fix incorrect cli default values ([#&#8203;34765](https://github.com/go-gitea/gitea/issues/34765)) ([#&#8203;34766](https://github.com/go-gitea/gitea/issues/34766))
  - Fix dropdown filter ([#&#8203;34708](https://github.com/go-gitea/gitea/issues/34708)) ([#&#8203;34711](https://github.com/go-gitea/gitea/issues/34711))
  - Hide href attribute of a tag if there is no target\_url ([#&#8203;34556](https://github.com/go-gitea/gitea/issues/34556)) ([#&#8203;34684](https://github.com/go-gitea/gitea/issues/34684))
  - Fix tag target ([#&#8203;34781](https://github.com/go-gitea/gitea/issues/34781)) [#&#8203;34783](https://github.com/go-gitea/gitea/issues/34783)

### [`v1.24.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1240---2025-05-26)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.8...v1.24.0)

- BREAKING
  - Make Gitea always use its internal config, ignore `/etc/gitconfig` ([#&#8203;33076](https://github.com/go-gitea/gitea/issues/33076))
  - Improve log format ([#&#8203;33814](https://github.com/go-gitea/gitea/issues/33814))
  - Fix markdown render behaviors ([#&#8203;34122](https://github.com/go-gitea/gitea/issues/34122))
  - Add package version api endpoints ([#&#8203;34173](https://github.com/go-gitea/gitea/issues/34173))

- FEATURES
  - Enforce two-factor auth (2FA: TOTP or WebAuthn) ([#&#8203;34187](https://github.com/go-gitea/gitea/issues/34187))
  - Add fullscreen mode as a more efficient operation way to view projects ([#&#8203;34081](https://github.com/go-gitea/gitea/issues/34081))
  - Add anonymous access support for private/unlisted repositories ([#&#8203;34051](https://github.com/go-gitea/gitea/issues/34051))
  - Support public code/issue access for private repositories ([#&#8203;33127](https://github.com/go-gitea/gitea/issues/33127))
  - Add middleware for request prioritization ([#&#8203;33951](https://github.com/go-gitea/gitea/issues/33951))
  - Add cli flags LDAP group configuration ([#&#8203;33933](https://github.com/go-gitea/gitea/issues/33933))
  - Add file tree to file view page ([#&#8203;32721](https://github.com/go-gitea/gitea/issues/32721))
  - Add material icons for file list ([#&#8203;33837](https://github.com/go-gitea/gitea/issues/33837))
  - Artifacts download api for artifact actions v4 ([#&#8203;33510](https://github.com/go-gitea/gitea/issues/33510))
  - Support choose email when creating a commit via web UI ([#&#8203;33432](https://github.com/go-gitea/gitea/issues/33432))
  - Add basic auth support to rss/atom feeds ([#&#8203;33371](https://github.com/go-gitea/gitea/issues/33371))
  - Add sorting by exclusive labels (issue priority) ([#&#8203;33206](https://github.com/go-gitea/gitea/issues/33206))
  - Add sub issue list support ([#&#8203;32940](https://github.com/go-gitea/gitea/issues/32940))
  - Private README.md for organization ([#&#8203;32872](https://github.com/go-gitea/gitea/issues/32872))
  - Email option to embed images as base64 instead of link ([#&#8203;32061](https://github.com/go-gitea/gitea/issues/32061))
  - Option to delay conflict checking of old pull requests until page view ([#&#8203;27779](https://github.com/go-gitea/gitea/issues/27779))
  - Worktime tracking for the organization level ([#&#8203;19808](https://github.com/go-gitea/gitea/issues/19808))

- PERFORMANCE
  - Add cache for common package queries ([#&#8203;22491](https://github.com/go-gitea/gitea/issues/22491))
  - Move issue pin to an standalone table for querying performance ([#&#8203;33452](https://github.com/go-gitea/gitea/issues/33452))
  - Improve commits list performance to reduce unnecessary database queries ([#&#8203;33528](https://github.com/go-gitea/gitea/issues/33528))
  - Optimize total count of feed when loading activities in user dashboard. ([#&#8203;33841](https://github.com/go-gitea/gitea/issues/33841))
  - Optimize heatmap query ([#&#8203;33853](https://github.com/go-gitea/gitea/issues/33853))
  - Only use prev and next buttons for pagination on user dashboard ([#&#8203;33981](https://github.com/go-gitea/gitea/issues/33981))
  - Improve pull request list API performance ([#&#8203;34052](https://github.com/go-gitea/gitea/issues/34052))
  - Cache GPG keys, emails and users when list commits ([#&#8203;34086](https://github.com/go-gitea/gitea/issues/34086))
  - Refactor Git Attribute & performance optimization ([#&#8203;34154](https://github.com/go-gitea/gitea/issues/34154))
  - Performance optimization for tags synchronization ([#&#8203;34355](https://github.com/go-gitea/gitea/issues/34355)) [#&#8203;34522](https://github.com/go-gitea/gitea/issues/34522)

- ENHANCEMENTS
  - Code
    - Display when a release attachment was uploaded ([#&#8203;34261](https://github.com/go-gitea/gitea/issues/34261))
    - Support creating relative link to raw path in markdown ([#&#8203;34105](https://github.com/go-gitea/gitea/issues/34105))
    - Improve code block readability and isolate copy button ([#&#8203;34009](https://github.com/go-gitea/gitea/issues/34009))
    - Improve repository commit view ([#&#8203;33877](https://github.com/go-gitea/gitea/issues/33877))
    - Full-file syntax highlighting for diff pages ([#&#8203;33766](https://github.com/go-gitea/gitea/issues/33766))
    - Clone repository with Tea CLI ([#&#8203;33725](https://github.com/go-gitea/gitea/issues/33725))
    - Improve sync fork behavior ([#&#8203;33319](https://github.com/go-gitea/gitea/issues/33319))
    - Make git clone URL could use current signed-in user ([#&#8203;33091](https://github.com/go-gitea/gitea/issues/33091))
    - Add submodule diff links ([#&#8203;33097](https://github.com/go-gitea/gitea/issues/33097))
    - Link to tree views of submodules if possible ([#&#8203;33424](https://github.com/go-gitea/gitea/issues/33424))
    - Only keep popular licenses ([#&#8203;33832](https://github.com/go-gitea/gitea/issues/33832))
    - De-emphasize signed commits ([#&#8203;31160](https://github.com/go-gitea/gitea/issues/31160))

  - Actions
    - Add flat-square action badge style ([#&#8203;34062](https://github.com/go-gitea/gitea/issues/34062))
    - Update action status badge layout ([#&#8203;34018](https://github.com/go-gitea/gitea/issues/34018))
    - Download actions job logs from API ([#&#8203;33858](https://github.com/go-gitea/gitea/issues/33858))
    - Always show the "rerun" button for action jobs ([#&#8203;33692](https://github.com/go-gitea/gitea/issues/33692))
    - Add auto-expanding running actions step ([#&#8203;30058](https://github.com/go-gitea/gitea/issues/30058))
    - Update status check for all supported on.pull\_request.types in Gitea ([#&#8203;33117](https://github.com/go-gitea/gitea/issues/33117))
    - Workflow\_dispatch use workflow from trigger branch ([#&#8203;33098](https://github.com/go-gitea/gitea/issues/33098))
    - Add action auto-scroll ([#&#8203;30057](https://github.com/go-gitea/gitea/issues/30057))
    - Add workflow\_job webhook ([#&#8203;33694](https://github.com/go-gitea/gitea/issues/33694))
    - Add a button editing action secret ([#&#8203;34462](https://github.com/go-gitea/gitea/issues/34462))

  - Pull Request
    - Auto expand "New PR" form ([#&#8203;33971](https://github.com/go-gitea/gitea/issues/33971))
    - Mark parent directory as viewed when all files are viewed ([#&#8203;33958](https://github.com/go-gitea/gitea/issues/33958))
    - Show info about maintainers are allowed to edit a PR ([#&#8203;33738](https://github.com/go-gitea/gitea/issues/33738))
    - Automerge supports deleting branch automatically after merging ([#&#8203;32343](https://github.com/go-gitea/gitea/issues/32343))
    - Add additional command hints for PowerShell & CMD ([#&#8203;33548](https://github.com/go-gitea/gitea/issues/33548))

  - Issues
    - Allow filtering issues by any assignee ([#&#8203;33343](https://github.com/go-gitea/gitea/issues/33343))
    - Show warning on navigation if currently editing comment or title ([#&#8203;32920](https://github.com/go-gitea/gitea/issues/32920))
    - Make tracked time representation display as hours ([#&#8203;33315](https://github.com/go-gitea/gitea/issues/33315))
    - Add No Results Prompt Message on Issue List Page ([#&#8203;33699](https://github.com/go-gitea/gitea/issues/33699))
    - Add sort option recentclose for issues and pulls ([#&#8203;34525](https://github.com/go-gitea/gitea/issues/34525)) [#&#8203;34539](https://github.com/go-gitea/gitea/issues/34539)

  - Packages
    - Link to nuget dependencies ([#&#8203;26554](https://github.com/go-gitea/gitea/issues/26554))
    - Add composor source field ([#&#8203;33502](https://github.com/go-gitea/gitea/issues/33502))

  - Administration
    - Improve navbar: add "admin" tip, add "active" style ([#&#8203;32927](https://github.com/go-gitea/gitea/issues/32927))
    - Add a option "--user-type bot" to admin user create, improve role display ([#&#8203;27885](https://github.com/go-gitea/gitea/issues/27885))
    - Improve admin user view page ([#&#8203;33735](https://github.com/go-gitea/gitea/issues/33735))
    - Support performance trace ([#&#8203;32973](https://github.com/go-gitea/gitea/issues/32973))
    - Change pprof labels to be prometheus compatible ([#&#8203;32865](https://github.com/go-gitea/gitea/issues/32865))
    - Allow admins and org owners to change org member public status ([#&#8203;28294](https://github.com/go-gitea/gitea/issues/28294))
    - Optimize the installation page ([#&#8203;32994](https://github.com/go-gitea/gitea/issues/32994))
    - Make public URL generation configurable ([#&#8203;34250](https://github.com/go-gitea/gitea/issues/34250))
    - Add a --fullname arg to gitea admin user create. ([#&#8203;34241](https://github.com/go-gitea/gitea/issues/34241))

  - Others
    - Improve oauth2 error handling ([#&#8203;33969](https://github.com/go-gitea/gitea/issues/33969))
    - Fail mirroring more gracefully ([#&#8203;34002](https://github.com/go-gitea/gitea/issues/34002))
    - Align User Details Page Header Layout with Design Specifications ([#&#8203;34192](https://github.com/go-gitea/gitea/issues/34192))
    - Webhook add X-Gitea-Hook-Installation-Target-Type Header ([#&#8203;33752](https://github.com/go-gitea/gitea/issues/33752))
    - Optimize the dashboard ([#&#8203;32990](https://github.com/go-gitea/gitea/issues/32990))
    - Improve button layout on small screens ([#&#8203;33633](https://github.com/go-gitea/gitea/issues/33633))
    - Add cropping support when modifying the user/org/repo avatar ([#&#8203;33498](https://github.com/go-gitea/gitea/issues/33498))
    - Make ROOT\_URL support using request Host header ([#&#8203;32564](https://github.com/go-gitea/gitea/issues/32564))
    - Add `show more` organizations icon in user's profile ([#&#8203;32986](https://github.com/go-gitea/gitea/issues/32986))
    - Introduce `--page-space-bottom` at 64px ([#&#8203;30692](https://github.com/go-gitea/gitea/issues/30692))
    - Improve theme display ([#&#8203;30671](https://github.com/go-gitea/gitea/issues/30671))
    - Add alphabetical project sorting ([#&#8203;33504](https://github.com/go-gitea/gitea/issues/33504))
    - Add global lock for migrations to make upgrade more safe with multiple replications ([#&#8203;33706](https://github.com/go-gitea/gitea/issues/33706))
    - Add descriptions for private repo public access settings and improve the UI ([#&#8203;34057](https://github.com/go-gitea/gitea/issues/34057))

- API
  - Actions Runner rest api ([#&#8203;33873](https://github.com/go-gitea/gitea/issues/33873))
  - Inclusion of rename organization api ([#&#8203;33303](https://github.com/go-gitea/gitea/issues/33303))
  - Add API to support link package to repository and unlink it ([#&#8203;33481](https://github.com/go-gitea/gitea/issues/33481))
  - Add API endpoint to request contents of multiple files simultaniously ([#&#8203;34139](https://github.com/go-gitea/gitea/issues/34139))
  - Actions artifacts API list/download check status upload confirmed ([#&#8203;34273](https://github.com/go-gitea/gitea/issues/34273))
  - Add API routes to lock and unlock issues ([#&#8203;34165](https://github.com/go-gitea/gitea/issues/34165))
  - Fix some user name usages ([#&#8203;33689](https://github.com/go-gitea/gitea/issues/33689))
  - Allow filtering /repos/{owner}/{repo}/pulls by target base branch queryparam ([#&#8203;33684](https://github.com/go-gitea/gitea/issues/33684))
  - Improve swagger generation ([#&#8203;33664](https://github.com/go-gitea/gitea/issues/33664))
  - Support Ephemeral action runners ([#&#8203;33570](https://github.com/go-gitea/gitea/issues/33570))
  - Support workflow event dispatch via API ([#&#8203;33545](https://github.com/go-gitea/gitea/issues/33545))
  - Support workflow event dispatch via API ([#&#8203;32059](https://github.com/go-gitea/gitea/issues/32059))
  - Added Description Field for Secrets and Variables  ([#&#8203;33526](https://github.com/go-gitea/gitea/issues/33526))
  - Reject star-related requests if stars are disabled ([#&#8203;33208](https://github.com/go-gitea/gitea/issues/33208))
  - Let API create and edit system webhooks, attempt 2 ([#&#8203;33180](https://github.com/go-gitea/gitea/issues/33180))
  - Use `Project-URL` metadata field to get a PyPI package's homepage URL ([#&#8203;33089](https://github.com/go-gitea/gitea/issues/33089))
  - Add `last_committer_date` and `last_author_date` for file contents API ([#&#8203;32921](https://github.com/go-gitea/gitea/issues/32921))

- REFACTORS
  - Remove context from git struct ([#&#8203;33793](https://github.com/go-gitea/gitea/issues/33793))
  - Refactor admin/common.ts ([#&#8203;33788](https://github.com/go-gitea/gitea/issues/33788))
  - Refactor repo-settings.ts ([#&#8203;33785](https://github.com/go-gitea/gitea/issues/33785))
  - Refactor repo-issue.ts ([#&#8203;33784](https://github.com/go-gitea/gitea/issues/33784))
  - Small refactor to reduce unnecessary database queries and remove duplicated functions ([#&#8203;33779](https://github.com/go-gitea/gitea/issues/33779))
  - Refactor initRepoBranchTagSelector to use new init framework ([#&#8203;33776](https://github.com/go-gitea/gitea/issues/33776))
  - Refactor buttons to use new init framework ([#&#8203;33774](https://github.com/go-gitea/gitea/issues/33774))
  - Refactor markup and pdf-viewer to use new init framework ([#&#8203;33772](https://github.com/go-gitea/gitea/issues/33772))
  - Refactor error system ([#&#8203;33771](https://github.com/go-gitea/gitea/issues/33771))
  - Refactor mail code ([#&#8203;33768](https://github.com/go-gitea/gitea/issues/33768))
  - Update TypeScript types ([#&#8203;33799](https://github.com/go-gitea/gitea/issues/33799))
  - Refactor older tests to use testify ([#&#8203;33140](https://github.com/go-gitea/gitea/issues/33140))
  - Move notifywatch to service layer ([#&#8203;33825](https://github.com/go-gitea/gitea/issues/33825))
  - Decouple context from repository related structs ([#&#8203;33823](https://github.com/go-gitea/gitea/issues/33823))
  - Remove context from mail struct ([#&#8203;33811](https://github.com/go-gitea/gitea/issues/33811))
  - Refactor dropdown ellipsis ([#&#8203;34123](https://github.com/go-gitea/gitea/issues/34123))
  - Refactor functions to reduce repopath expose ([#&#8203;33892](https://github.com/go-gitea/gitea/issues/33892))
  - Refactor repo-diff.ts ([#&#8203;33746](https://github.com/go-gitea/gitea/issues/33746))
  - Refactor web route handler ([#&#8203;33488](https://github.com/go-gitea/gitea/issues/33488))
  - Refactor user & avatar ([#&#8203;33433](https://github.com/go-gitea/gitea/issues/33433))
  - Refactor user package ([#&#8203;33423](https://github.com/go-gitea/gitea/issues/33423))
  - Refactor decouple context from migration structs ([#&#8203;33399](https://github.com/go-gitea/gitea/issues/33399))
  - Refactor context flash msg and global variables ([#&#8203;33375](https://github.com/go-gitea/gitea/issues/33375))
  - Refactor response writer & access logger ([#&#8203;33323](https://github.com/go-gitea/gitea/issues/33323))
  - Refactor ref type ([#&#8203;33242](https://github.com/go-gitea/gitea/issues/33242))
  - Refactor context repository ([#&#8203;33202](https://github.com/go-gitea/gitea/issues/33202))
  - Refactor legacy JS ([#&#8203;33115](https://github.com/go-gitea/gitea/issues/33115))
  - Refactor legacy line-number and scroll code ([#&#8203;33094](https://github.com/go-gitea/gitea/issues/33094))
  - Refactor env var related code ([#&#8203;33075](https://github.com/go-gitea/gitea/issues/33075))
  - Move SetMerged to service layer ([#&#8203;33045](https://github.com/go-gitea/gitea/issues/33045))
  - Merge updatecommentattachment functions ([#&#8203;33044](https://github.com/go-gitea/gitea/issues/33044))
  - Refactor pull-request compare\&create page ([#&#8203;33071](https://github.com/go-gitea/gitea/issues/33071))
  - Refactor repo-new\.ts ([#&#8203;33070](https://github.com/go-gitea/gitea/issues/33070))
  - Refactor pagination ([#&#8203;33037](https://github.com/go-gitea/gitea/issues/33037))
  - Refactor tests ([#&#8203;33021](https://github.com/go-gitea/gitea/issues/33021))
  - Refactor markup render to fix various path problems ([#&#8203;34114](https://github.com/go-gitea/gitea/issues/34114))
  - Refactor Branch struct in package modules/git ([#&#8203;33980](https://github.com/go-gitea/gitea/issues/33980))
  - Don't create duplicated functions for code repositories and wiki repositories ([#&#8203;33924](https://github.com/go-gitea/gitea/issues/33924))
  - Move git references checking to gitrepo packages to reduce expose of repository path ([#&#8203;33891](https://github.com/go-gitea/gitea/issues/33891))
  - Refactor cache-control ([#&#8203;33861](https://github.com/go-gitea/gitea/issues/33861))
  - Decouple diff stats query from actual diffing ([#&#8203;33810](https://github.com/go-gitea/gitea/issues/33810))
  - Move part of updating protected branch logic to service layer ([#&#8203;33742](https://github.com/go-gitea/gitea/issues/33742))
  - Decouple Batch from git.Repository to simplify usage without requiring the creation of a Repository struct. ([#&#8203;34001](https://github.com/go-gitea/gitea/issues/34001))
  - Refactor tmpl and blob\_excerpt ([#&#8203;32967](https://github.com/go-gitea/gitea/issues/32967))
  - Refactor template & test related code ([#&#8203;32938](https://github.com/go-gitea/gitea/issues/32938))
  - Refactor db package and remove unnecessary `DumpTables` ([#&#8203;32930](https://github.com/go-gitea/gitea/issues/32930))
  - Refactor pprof labels and process desc ([#&#8203;32909](https://github.com/go-gitea/gitea/issues/32909))
  - Refactor repo-projects.ts ([#&#8203;32892](https://github.com/go-gitea/gitea/issues/32892))
  - Refactor getpatch/getdiff functions and remove unnecessary fallback ([#&#8203;32817](https://github.com/go-gitea/gitea/issues/32817))
  - Uniform all temporary directories and allow customizing temp path ([#&#8203;32352](https://github.com/go-gitea/gitea/issues/32352))
  - Remove context from retry downloader ([#&#8203;33871](https://github.com/go-gitea/gitea/issues/33871))
  - Refactor global init code and add more comments ([#&#8203;33755](https://github.com/go-gitea/gitea/issues/33755))
  - Remove some unnecessary template helpers ([#&#8203;33069](https://github.com/go-gitea/gitea/issues/33069))
  - Move and rename UpdateRepository ([#&#8203;34136](https://github.com/go-gitea/gitea/issues/34136))
  - Move hooks function to gitrepo and reduce expose repopath ([#&#8203;33890](https://github.com/go-gitea/gitea/issues/33890))
  - Add abstraction layer to delete repository from disk ([#&#8203;33879](https://github.com/go-gitea/gitea/issues/33879))
  - Add abstraction layer to check if the repository exists on disk ([#&#8203;33874](https://github.com/go-gitea/gitea/issues/33874))
  - Move ParseCommitWithSSHSignature to service layer ([#&#8203;34087](https://github.com/go-gitea/gitea/issues/34087))
  - Move duplicated functions ([#&#8203;33977](https://github.com/go-gitea/gitea/issues/33977))
  - Extract code to their own functions for push update ([#&#8203;33944](https://github.com/go-gitea/gitea/issues/33944))
  - Move gitgraph from modules to services layer ([#&#8203;33527](https://github.com/go-gitea/gitea/issues/33527))
  - Move commits signature and verify functions to service layers ([#&#8203;33605](https://github.com/go-gitea/gitea/issues/33605))
  - Use `CloseIssue` and `ReopenIssue` instead of `ChangeStatus` ([#&#8203;32467](https://github.com/go-gitea/gitea/issues/32467))
  - Refactor arch route handlers ([#&#8203;32993](https://github.com/go-gitea/gitea/issues/32993))
  - Refactor "string truncate" ([#&#8203;32984](https://github.com/go-gitea/gitea/issues/32984))
  - Refactor arch route handlers ([#&#8203;32972](https://github.com/go-gitea/gitea/issues/32972))
  - Clarify path param naming ([#&#8203;32969](https://github.com/go-gitea/gitea/issues/32969))
  - Refactor request context ([#&#8203;32956](https://github.com/go-gitea/gitea/issues/32956))
  - Move some errors to their own sub packages ([#&#8203;32880](https://github.com/go-gitea/gitea/issues/32880))
  - Move RepoTransfer from models to models/repo sub package ([#&#8203;32506](https://github.com/go-gitea/gitea/issues/32506))
  - Move delete deploy keys into service layer ([#&#8203;32201](https://github.com/go-gitea/gitea/issues/32201))
  - Refactor webhook events ([#&#8203;33337](https://github.com/go-gitea/gitea/issues/33337))
  - Move some Actions related functions from `routers` to `services` ([#&#8203;33280](https://github.com/go-gitea/gitea/issues/33280))
  - Refactor RefName ([#&#8203;33234](https://github.com/go-gitea/gitea/issues/33234))
  - Refactor context RefName and RepoAssignment ([#&#8203;33226](https://github.com/go-gitea/gitea/issues/33226))
  - Refactor repository transfer ([#&#8203;33211](https://github.com/go-gitea/gitea/issues/33211))
  - Refactor error system ([#&#8203;33626](https://github.com/go-gitea/gitea/issues/33626))
  - Refactor error system ([#&#8203;33610](https://github.com/go-gitea/gitea/issues/33610))
  - Refactor package (routes and error handling, npm peer dependency) ([#&#8203;33111](https://github.com/go-gitea/gitea/issues/33111))
  - Use test context in tests and new loop system in benchmarks ([#&#8203;33648](https://github.com/go-gitea/gitea/issues/33648))
  - Some small refactors ([#&#8203;33144](https://github.com/go-gitea/gitea/issues/33144))
  - Simplify context ref name ([#&#8203;33267](https://github.com/go-gitea/gitea/issues/33267))

- BUGFIXES
  - Fix some dropdown problems on the issue sidebar ([#&#8203;34308](https://github.com/go-gitea/gitea/issues/34308)) [#&#8203;34327](https://github.com/go-gitea/gitea/issues/34327)
  - Do not return archive download URLs in API if downloads are disabled ([#&#8203;34324](https://github.com/go-gitea/gitea/issues/34324)) [#&#8203;34338](https://github.com/go-gitea/gitea/issues/34338)
  - Fix LFS files being editable in web UI ([#&#8203;34356](https://github.com/go-gitea/gitea/issues/34356)) [#&#8203;34362](https://github.com/go-gitea/gitea/issues/34362)
  - Fix only text/\* being viewable in web UI ([#&#8203;34374](https://github.com/go-gitea/gitea/issues/34374)) [#&#8203;34378](https://github.com/go-gitea/gitea/issues/34378)
  - Fix LFS file not stored in LFS when uploaded/edited via API or web UI ([#&#8203;34367](https://github.com/go-gitea/gitea/issues/34367))
  - Grey out expired artifact on Artifacts list ([#&#8203;34314](https://github.com/go-gitea/gitea/issues/34314)) [#&#8203;34404](https://github.com/go-gitea/gitea/issues/34404)
  - Fix incorrect divergence cache after switching default branch ([#&#8203;34370](https://github.com/go-gitea/gitea/issues/34370)) [#&#8203;34406](https://github.com/go-gitea/gitea/issues/34406)
  - Refactor commit message rendering and fix bugs ([#&#8203;34412](https://github.com/go-gitea/gitea/issues/34412)) [#&#8203;34414](https://github.com/go-gitea/gitea/issues/34414)
  - Merge and tweak markup editor expander CSS ([#&#8203;34409](https://github.com/go-gitea/gitea/issues/34409)) [#&#8203;34415](https://github.com/go-gitea/gitea/issues/34415)
  - Fix GetUsersByEmails ([#&#8203;34423](https://github.com/go-gitea/gitea/issues/34423)) [#&#8203;34425](https://github.com/go-gitea/gitea/issues/34425)
  - Only git operations should update last changed of a repository ([#&#8203;34388](https://github.com/go-gitea/gitea/issues/34388)) [#&#8203;34427](https://github.com/go-gitea/gitea/issues/34427)
  - Fix comment textarea scroll issue in Firefox ([#&#8203;34438](https://github.com/go-gitea/gitea/issues/34438)) [#&#8203;34446](https://github.com/go-gitea/gitea/issues/34446)
  - Fix repo broken check ([#&#8203;34444](https://github.com/go-gitea/gitea/issues/34444)) [#&#8203;34452](https://github.com/go-gitea/gitea/issues/34452)
  - Fix remove org user failure on mssql ([#&#8203;34449](https://github.com/go-gitea/gitea/issues/34449)) [#&#8203;34453](https://github.com/go-gitea/gitea/issues/34453)
  - Fix Workflow run Not Found page ([#&#8203;34459](https://github.com/go-gitea/gitea/issues/34459)) [#&#8203;34466](https://github.com/go-gitea/gitea/issues/34466)
  - When updating comment, if the content is the same, just return and not update the database ([#&#8203;34422](https://github.com/go-gitea/gitea/issues/34422)) [#&#8203;34464](https://github.com/go-gitea/gitea/issues/34464)
  - Fix project board view ([#&#8203;34470](https://github.com/go-gitea/gitea/issues/34470)) [#&#8203;34475](https://github.com/go-gitea/gitea/issues/34475)
  - Fix get / delete runner to use consistent http 404 and 500 status ([#&#8203;34480](https://github.com/go-gitea/gitea/issues/34480)) [#&#8203;34488](https://github.com/go-gitea/gitea/issues/34488)
  - Fix url validation in webhook add/edit API ([#&#8203;34492](https://github.com/go-gitea/gitea/issues/34492)) [#&#8203;34496](https://github.com/go-gitea/gitea/issues/34496)
  - Fix edithook api can not update package, status and workflow\_job events ([#&#8203;34495](https://github.com/go-gitea/gitea/issues/34495)) [#&#8203;34499](https://github.com/go-gitea/gitea/issues/34499)
  - Fix ephemeral runner deletion ([#&#8203;34447](https://github.com/go-gitea/gitea/issues/34447)) [#&#8203;34513](https://github.com/go-gitea/gitea/issues/34513)
  - Don't display error log when .git-blame-ignore-revs doesn't exist ([#&#8203;34457](https://github.com/go-gitea/gitea/issues/34457))
  - Only allow admins to rename default/protected branches ([#&#8203;33276](https://github.com/go-gitea/gitea/issues/33276))
  - Improve "lock conversation" UI ([#&#8203;34207](https://github.com/go-gitea/gitea/issues/34207))
  - Fix incorrect file links ([#&#8203;34189](https://github.com/go-gitea/gitea/issues/34189))
  - Optimize Overflow Menu ([#&#8203;34183](https://github.com/go-gitea/gitea/issues/34183))
  - Check user/org repo limit instead of doer ([#&#8203;34147](https://github.com/go-gitea/gitea/issues/34147))
  - Make markdown render match GitHub's behavior ([#&#8203;34129](https://github.com/go-gitea/gitea/issues/34129))
  - Fix team permission ([#&#8203;34128](https://github.com/go-gitea/gitea/issues/34128))
  - Correctly handle submodule view and avoid throwing 500 error ([#&#8203;34121](https://github.com/go-gitea/gitea/issues/34121))
  - Fix users being able bypass limits with repo transfers ([#&#8203;34031](https://github.com/go-gitea/gitea/issues/34031))
  - Avoid creating unnecessary temporary cat file sub process ([#&#8203;33942](https://github.com/go-gitea/gitea/issues/33942))
  - Refactor organization menu ([#&#8203;33928](https://github.com/go-gitea/gitea/issues/33928))
  - Fix various Fomantic UI and htmx problems ([#&#8203;33851](https://github.com/go-gitea/gitea/issues/33851))
  - Fix 500 error when error occurred in migration page ([#&#8203;33256](https://github.com/go-gitea/gitea/issues/33256))
  - Validate that the tag doesn't exist when creating a tag via the web ([#&#8203;33241](https://github.com/go-gitea/gitea/issues/33241))
  - Add missed transaction on setmerged ([#&#8203;33079](https://github.com/go-gitea/gitea/issues/33079))
  - Rework create/fork/adopt/generate repository to make sure resources will be cleanup once failed ([#&#8203;31035](https://github.com/go-gitea/gitea/issues/31035))
  - Valid email address should only start with alphanumeric ([#&#8203;28174](https://github.com/go-gitea/gitea/issues/28174))
  - Fix webhook url ([#&#8203;34186](https://github.com/go-gitea/gitea/issues/34186))
  - Fix "toAbsoluteLocaleDate" test when system locale is not en-US ([#&#8203;33939](https://github.com/go-gitea/gitea/issues/33939))
  - Fix file name could not be searched if the file was not a text file when using the Bleve indexer ([#&#8203;33959](https://github.com/go-gitea/gitea/issues/33959))
  - Fix cannot delete runners via the modal dialog ([#&#8203;33895](https://github.com/go-gitea/gitea/issues/33895))
  - Fix unpin hint on the pinned pull requests ([#&#8203;33207](https://github.com/go-gitea/gitea/issues/33207))
  - Fix parentCommit invalid memory address or nil pointer dereference. ([#&#8203;33204](https://github.com/go-gitea/gitea/issues/33204))
  - Fix comment header padding ([#&#8203;33377](https://github.com/go-gitea/gitea/issues/33377))
  - Fix some migration and repo name problems ([#&#8203;33986](https://github.com/go-gitea/gitea/issues/33986))
  - Fix various trivial frontend problems ([#&#8203;34263](https://github.com/go-gitea/gitea/issues/34263))
  - Fix Set Email Preference dropdown and button placement ([#&#8203;34255](https://github.com/go-gitea/gitea/issues/34255))
  - Fix quoted replies incorrectly render user input as part of the quote ([#&#8203;34216](https://github.com/go-gitea/gitea/issues/34216))
  - Fix button alignments and remove unnecessary styles ([#&#8203;34206](https://github.com/go-gitea/gitea/issues/34206))
  - Restore form inputs on organization create error ([#&#8203;34201](https://github.com/go-gitea/gitea/issues/34201))
  - Try to fix ACME (3rd) ([#&#8203;33807](https://github.com/go-gitea/gitea/issues/33807))
  - Fix incorrect ref "blob" ([#&#8203;33240](https://github.com/go-gitea/gitea/issues/33240))
  - Fix dynamic content loading init problem ([#&#8203;33748](https://github.com/go-gitea/gitea/issues/33748))
  - Fix git empty check and HEAD request ([#&#8203;33690](https://github.com/go-gitea/gitea/issues/33690))
  - Fix Untranslated Text on Actions Page ([#&#8203;33635](https://github.com/go-gitea/gitea/issues/33635))
  - Fix issue label delete incorrect labels webhook payload ([#&#8203;34575](https://github.com/go-gitea/gitea/issues/34575))
  - Fix incorrect page navigation with up and down arrow on last item of dashboard repos ([#&#8203;34570](https://github.com/go-gitea/gitea/issues/34570))
  - Fix/improve avatar sync from LDAP ([#&#8203;34573](https://github.com/go-gitea/gitea/issues/34573))
  - Fix some trivial problems ([#&#8203;34579](https://github.com/go-gitea/gitea/issues/34579))
  - Retain issue sort type when a keyword search is introduced ([#&#8203;34559](https://github.com/go-gitea/gitea/issues/34559))
  - Always use an empty line to separate the commit message and trailer ([#&#8203;34512](https://github.com/go-gitea/gitea/issues/34512))
  - Fix line-button issue after file selection in file tree ([#&#8203;34574](https://github.com/go-gitea/gitea/issues/34574))
  - Fix doctor deleting orphaned issues attachments ([#&#8203;34142](https://github.com/go-gitea/gitea/issues/34142))
  - Add webhook assigning test and fix possible bug ([#&#8203;34420](https://github.com/go-gitea/gitea/issues/34420))
  - Fix possible nil description of pull request when migrating from CodeCommit ([#&#8203;34541](https://github.com/go-gitea/gitea/issues/34541))
  - Refactor commit reader ([#&#8203;34542](https://github.com/go-gitea/gitea/issues/34542))
  - Fix possible pull request broken when leave the page immediately after clicking the update button [#&#8203;34509](https://github.com/go-gitea/gitea/issues/34509)
  - Ignore "Close" error when uploading container blob ([#&#8203;34620](https://github.com/go-gitea/gitea/issues/34620))
  - Fix missed merge commit sha and time when migrating from codecommit ([#&#8203;34645](https://github.com/go-gitea/gitea/issues/34645))
  - Fix GetUsersByEmails ([#&#8203;34643](https://github.com/go-gitea/gitea/issues/34643))
  - Misc CSS fixes ([#&#8203;34638](https://github.com/go-gitea/gitea/issues/34638))
  - Add codecommit to supported services in api docs ([#&#8203;34626](https://github.com/go-gitea/gitea/issues/34626))
  - Validate hex colors when creating/editing labels ([#&#8203;34623](https://github.com/go-gitea/gitea/issues/34623))
  - Fix possible pull request broken when leave the page immediately after clicking the update button ([#&#8203;34509](https://github.com/go-gitea/gitea/issues/34509))
  - Fix margin issue in markup paragraph rendering ([#&#8203;34599](https://github.com/go-gitea/gitea/issues/34599))
  - Fix migration pull request title too long ([#&#8203;34577](https://github.com/go-gitea/gitea/issues/34577))
  - Fix footnote jump behavior on the issue page. ([#&#8203;34621](https://github.com/go-gitea/gitea/issues/34621))
  - Fix "oras" OCI client compatibility ([#&#8203;34666](https://github.com/go-gitea/gitea/issues/34666))
  - Fix last admin check when syncing users ([#&#8203;34649](https://github.com/go-gitea/gitea/issues/34649))
  - Fix skip paths check on tag push events in workflows ([#&#8203;34602](https://github.com/go-gitea/gitea/issues/34602)) [#&#8203;34670](https://github.com/go-gitea/gitea/issues/34670)

- MISC

  - Bump to alpine 3.22 ([#&#8203;34613](https://github.com/go-gitea/gitea/issues/34613))
  - Make pull request and issue history more compact ([#&#8203;34588](https://github.com/go-gitea/gitea/issues/34588))
  - Run integration tests against postgres 14 ([#&#8203;34514](https://github.com/go-gitea/gitea/issues/34514)) [#&#8203;34536](https://github.com/go-gitea/gitea/issues/34536)
  - Enable addtional linters ([#&#8203;34085](https://github.com/go-gitea/gitea/issues/34085))
  - Enable testifylint rules ([#&#8203;34075](https://github.com/go-gitea/gitea/issues/34075))
  - Enable staticcheck QFxxxx rules ([#&#8203;34064](https://github.com/go-gitea/gitea/issues/34064))
  - Improve Actions test ([#&#8203;32883](https://github.com/go-gitea/gitea/issues/32883))
  - Drop fomantic build ([#&#8203;33845](https://github.com/go-gitea/gitea/issues/33845))
  - Go1.24 ([#&#8203;33562](https://github.com/go-gitea/gitea/issues/33562))
  - Run yamllint with strict mode, fix issue ([#&#8203;33551](https://github.com/go-gitea/gitea/issues/33551))
  - Disable cron task to update license ([#&#8203;33486](https://github.com/go-gitea/gitea/issues/33486))
  - Optimize makefile help information generation ([#&#8203;33390](https://github.com/go-gitea/gitea/issues/33390))
  - Convert github.com/xanzy/go-gitlab into gitlab.com/gitlab-org/api/client-go ([#&#8203;33126](https://github.com/go-gitea/gitea/issues/33126))
  - Add missed changelogs ([#&#8203;33649](https://github.com/go-gitea/gitea/issues/33649))
  - Update .changelog file to add performance label group ([#&#8203;33472](https://github.com/go-gitea/gitea/issues/33472))
  - Add missing POPULATE\_SQUASH\_COMMENT\_WITH\_COMMIT\_MESSAGES in app.example.ini ([#&#8203;33363](https://github.com/go-gitea/gitea/issues/33363))
  - Update README screenshots ([#&#8203;33347](https://github.com/go-gitea/gitea/issues/33347))
  - Update unrs-resolver ([#&#8203;34279](https://github.com/go-gitea/gitea/issues/34279))
  - Update go\&js dependencies ([#&#8203;34262](https://github.com/go-gitea/gitea/issues/34262))
  - Optimize the calling code of queryElems ([#&#8203;34235](https://github.com/go-gitea/gitea/issues/34235))
  - Update protected\_branch.tmpl ([#&#8203;34193](https://github.com/go-gitea/gitea/issues/34193))
  - Feat/optimize span svg layout ([#&#8203;34185](https://github.com/go-gitea/gitea/issues/34185))
  - Set MERMAID\_MAX\_SOURCE\_CHARACTERS to 50000 ([#&#8203;34152](https://github.com/go-gitea/gitea/issues/34152))
  - Update JS and PY deps ([#&#8203;34143](https://github.com/go-gitea/gitea/issues/34143))
  - Add Chinese translations for README files ([#&#8203;34132](https://github.com/go-gitea/gitea/issues/34132))
  - Use `overflow-wrap: anywhere` to replace `word-break: break-all` ([#&#8203;34126](https://github.com/go-gitea/gitea/issues/34126))
  - Clarify ownership in password change error messages ([#&#8203;34092](https://github.com/go-gitea/gitea/issues/34092))
  - Add toggleClass function in dom.ts ([#&#8203;34063](https://github.com/go-gitea/gitea/issues/34063))
  - Update to golangci-lint v2 ([#&#8203;34054](https://github.com/go-gitea/gitea/issues/34054))
  - Update Makefile test comments ([#&#8203;34013](https://github.com/go-gitea/gitea/issues/34013))
  - Update go mod dependencies ([#&#8203;33988](https://github.com/go-gitea/gitea/issues/33988))
  - Use filepath.Join instead of path.Join for file system file operations ([#&#8203;33978](https://github.com/go-gitea/gitea/issues/33978))
  - Prepare common tmpl functions in a middleware ([#&#8203;33957](https://github.com/go-gitea/gitea/issues/33957))
  - Remove unused or abused styles ([#&#8203;33918](https://github.com/go-gitea/gitea/issues/33918))
  - Update JS and PY deps, misc tweaks ([#&#8203;33903](https://github.com/go-gitea/gitea/issues/33903))
  - Try to figure out attribute checker problem ([#&#8203;33901](https://github.com/go-gitea/gitea/issues/33901))
  - Add lock for a repository pull mirror ([#&#8203;33876](https://github.com/go-gitea/gitea/issues/33876))
  - Fine tune push mirror UI ([#&#8203;33866](https://github.com/go-gitea/gitea/issues/33866))
  - Improve issue & code search ([#&#8203;33860](https://github.com/go-gitea/gitea/issues/33860))
  - Use pullrequestlist instead of \[]\*pullrequest ([#&#8203;33765](https://github.com/go-gitea/gitea/issues/33765))
  - Upgrade act to 0.261.4 and actions-proto-go to v0.4.1 ([#&#8203;33760](https://github.com/go-gitea/gitea/issues/33760))
  - Align sidebar gears to the right ([#&#8203;33721](https://github.com/go-gitea/gitea/issues/33721))
  - Update Go dependencies (skip blevesearch, meilisearch) ([#&#8203;33655](https://github.com/go-gitea/gitea/issues/33655))
  - Add migrations and doctor fixes ([#&#8203;33556](https://github.com/go-gitea/gitea/issues/33556))
  - Remove "class-name" from svg icon ([#&#8203;33540](https://github.com/go-gitea/gitea/issues/33540))
  - Update MAINTAINERS ([#&#8203;33529](https://github.com/go-gitea/gitea/issues/33529))
  - Add "No data available" display when list is empty ([#&#8203;33517](https://github.com/go-gitea/gitea/issues/33517))
  - Use `git diff-tree` for `DiffFileTree` on diff pages ([#&#8203;33514](https://github.com/go-gitea/gitea/issues/33514))
  - Give organisation members access to organisation feeds ([#&#8203;33508](https://github.com/go-gitea/gitea/issues/33508))
  - Update feishu icon ([#&#8203;33470](https://github.com/go-gitea/gitea/issues/33470))
  - Hide/disable unusable UI elements when a repository is archived ([#&#8203;33459](https://github.com/go-gitea/gitea/issues/33459))
  - Update `@github/text-expander-element` to 2.9.0 ([#&#8203;33435](https://github.com/go-gitea/gitea/issues/33435))
  - Do not access GitRepo when a repo is being created ([#&#8203;33380](https://github.com/go-gitea/gitea/issues/33380))
  - Fix incorrect ref usages ([#&#8203;33301](https://github.com/go-gitea/gitea/issues/33301))
  - Prepare for support performance trace ([#&#8203;33286](https://github.com/go-gitea/gitea/issues/33286))
  - Enable Typescript `noImplicitThis` ([#&#8203;33250](https://github.com/go-gitea/gitea/issues/33250))
  - Remove unused CSS styles and move some styles to proper files ([#&#8203;33217](https://github.com/go-gitea/gitea/issues/33217))
  - Add .run to gitignore ([#&#8203;33175](https://github.com/go-gitea/gitea/issues/33175))
  - Fix typo in gitea downloader test and add missing codebase in `ToGitServiceType` ([#&#8203;33146](https://github.com/go-gitea/gitea/issues/33146))
  - Remove extended glob pattern from branch protection UI ([#&#8203;33125](https://github.com/go-gitea/gitea/issues/33125))
  - Clean up legacy form CSS styles ([#&#8203;33081](https://github.com/go-gitea/gitea/issues/33081))
  - Unset XDG\_HOME\_CONFIG as gitea manages configuration locations ([#&#8203;33067](https://github.com/go-gitea/gitea/issues/33067))
  - Add IntelliJ Gateway's .uuid to gitignore ([#&#8203;33052](https://github.com/go-gitea/gitea/issues/33052))
  - User facing messages for AGit errors ([#&#8203;33012](https://github.com/go-gitea/gitea/issues/33012))
  - Always show assignees on right ([#&#8203;33006](https://github.com/go-gitea/gitea/issues/33006))
  - Fix eslint ([#&#8203;33002](https://github.com/go-gitea/gitea/issues/33002))
  - Update JS dependencies ([#&#8203;32914](https://github.com/go-gitea/gitea/issues/32914))
  - Bump x/net ([#&#8203;32896](https://github.com/go-gitea/gitea/issues/32896)) ([#&#8203;32900](https://github.com/go-gitea/gitea/issues/32900))
  - Only activity tab needs heatmap data loading ([#&#8203;34652](https://github.com/go-gitea/gitea/issues/34652))

### [`v1.23.8`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1238---2025-05-11)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.7...v1.23.8)

- SECURITY
  - Fix a bug when uploading file via lfs ssh command ([#&#8203;34408](https://github.com/go-gitea/gitea/issues/34408)) ([#&#8203;34411](https://github.com/go-gitea/gitea/issues/34411))
  - Update net package ([#&#8203;34228](https://github.com/go-gitea/gitea/issues/34228)) ([#&#8203;34232](https://github.com/go-gitea/gitea/issues/34232))
- BUGFIXES
  - Fix releases sidebar navigation link ([#&#8203;34436](https://github.com/go-gitea/gitea/issues/34436)) [#&#8203;34439](https://github.com/go-gitea/gitea/issues/34439)
  - Fix bug webhook milestone is not right. ([#&#8203;34419](https://github.com/go-gitea/gitea/issues/34419)) [#&#8203;34429](https://github.com/go-gitea/gitea/issues/34429)
  - Fix two missed null value checks on the wiki page. ([#&#8203;34205](https://github.com/go-gitea/gitea/issues/34205)) ([#&#8203;34215](https://github.com/go-gitea/gitea/issues/34215))
  - Swift files can be passed either as file or as form value ([#&#8203;34068](https://github.com/go-gitea/gitea/issues/34068)) ([#&#8203;34236](https://github.com/go-gitea/gitea/issues/34236))
  - Fix bug when API get pull changed files for deleted head repository ([#&#8203;34333](https://github.com/go-gitea/gitea/issues/34333)) ([#&#8203;34368](https://github.com/go-gitea/gitea/issues/34368))
  - Upgrade github v61 -> v71 to fix migrating bug ([#&#8203;34389](https://github.com/go-gitea/gitea/issues/34389))
  - Fix bug when visiting comparation page ([#&#8203;34334](https://github.com/go-gitea/gitea/issues/34334)) ([#&#8203;34364](https://github.com/go-gitea/gitea/issues/34364))
  - Fix wrong review requests when updating the pull request ([#&#8203;34286](https://github.com/go-gitea/gitea/issues/34286)) ([#&#8203;34304](https://github.com/go-gitea/gitea/issues/34304))
  - Fix github migration error when using multiple tokens ([#&#8203;34144](https://github.com/go-gitea/gitea/issues/34144)) ([#&#8203;34302](https://github.com/go-gitea/gitea/issues/34302))
  - Explicitly not update indexes when sync database schemas ([#&#8203;34281](https://github.com/go-gitea/gitea/issues/34281)) ([#&#8203;34295](https://github.com/go-gitea/gitea/issues/34295))
  - Fix panic when comment is nil ([#&#8203;34257](https://github.com/go-gitea/gitea/issues/34257)) ([#&#8203;34277](https://github.com/go-gitea/gitea/issues/34277))
  - Fix project board links to related Pull Requests ([#&#8203;34213](https://github.com/go-gitea/gitea/issues/34213)) ([#&#8203;34222](https://github.com/go-gitea/gitea/issues/34222))
  - Don't assume the default wiki branch is master in the wiki API ([#&#8203;34244](https://github.com/go-gitea/gitea/issues/34244)) ([#&#8203;34245](https://github.com/go-gitea/gitea/issues/34245))
- DOCUMENTATION
  - Update token creation API swagger documentation ([#&#8203;34288](https://github.com/go-gitea/gitea/issues/34288)) ([#&#8203;34296](https://github.com/go-gitea/gitea/issues/34296))
- MISC
  - Fix CI Build ([#&#8203;34315](https://github.com/go-gitea/gitea/issues/34315))
  - Add riscv64 support ([#&#8203;34199](https://github.com/go-gitea/gitea/issues/34199)) ([#&#8203;34204](https://github.com/go-gitea/gitea/issues/34204))
  - Bump go version in go.mod ([#&#8203;34160](https://github.com/go-gitea/gitea/issues/34160))
  - remove hardcoded 'code' string in clone\_panel.tmpl ([#&#8203;34153](https://github.com/go-gitea/gitea/issues/34153)) ([#&#8203;34158](https://github.com/go-gitea/gitea/issues/34158))

### [`v1.23.7`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1237---2025-04-07)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.6...v1.23.7)

- Enhancements
  - Add a config option to block "expensive" pages for anonymous users ([#&#8203;34024](https://github.com/go-gitea/gitea/issues/34024)) ([#&#8203;34071](https://github.com/go-gitea/gitea/issues/34071))
  - Also check default ssh-cert location for host ([#&#8203;34099](https://github.com/go-gitea/gitea/issues/34099)) ([#&#8203;34100](https://github.com/go-gitea/gitea/issues/34100)) ([#&#8203;34116](https://github.com/go-gitea/gitea/issues/34116))
- BUGFIXES
  - Fix discord webhook 400 status code when description limit is exceeded ([#&#8203;34084](https://github.com/go-gitea/gitea/issues/34084)) ([#&#8203;34124](https://github.com/go-gitea/gitea/issues/34124))
  - Get changed files based on merge base when checking `pull_request` actions trigger ([#&#8203;34106](https://github.com/go-gitea/gitea/issues/34106)) ([#&#8203;34120](https://github.com/go-gitea/gitea/issues/34120))
  - Fix invalid version in RPM package path ([#&#8203;34112](https://github.com/go-gitea/gitea/issues/34112)) ([#&#8203;34115](https://github.com/go-gitea/gitea/issues/34115))
  - Return default avatar url when user id is zero rather than updating database ([#&#8203;34094](https://github.com/go-gitea/gitea/issues/34094)) ([#&#8203;34095](https://github.com/go-gitea/gitea/issues/34095))
  - Add additional ReplaceAll in pathsep to cater for different pathsep ([#&#8203;34061](https://github.com/go-gitea/gitea/issues/34061)) ([#&#8203;34070](https://github.com/go-gitea/gitea/issues/34070))
  - Try to fix check-attr bug ([#&#8203;34029](https://github.com/go-gitea/gitea/issues/34029)) ([#&#8203;34033](https://github.com/go-gitea/gitea/issues/34033))
  - Git client will follow 301 but 307 ([#&#8203;34005](https://github.com/go-gitea/gitea/issues/34005)) ([#&#8203;34010](https://github.com/go-gitea/gitea/issues/34010))
  - Fix block expensive for 1.23 ([#&#8203;34127](https://github.com/go-gitea/gitea/issues/34127))
  - Fix markdown frontmatter rendering ([#&#8203;34102](https://github.com/go-gitea/gitea/issues/34102)) ([#&#8203;34107](https://github.com/go-gitea/gitea/issues/34107))
  - Add new CLI flags to set name and scopes when creating a user with access token ([#&#8203;34080](https://github.com/go-gitea/gitea/issues/34080)) ([#&#8203;34103](https://github.com/go-gitea/gitea/issues/34103))
  - Do not show 500 error when default branch doesn't exist ([#&#8203;34096](https://github.com/go-gitea/gitea/issues/34096)) ([#&#8203;34097](https://github.com/go-gitea/gitea/issues/34097))
  - Hide activity contributors, recent commits and code frequrency left tabs if there is no code permission ([#&#8203;34053](https://github.com/go-gitea/gitea/issues/34053)) ([#&#8203;34065](https://github.com/go-gitea/gitea/issues/34065))
  - Simplify emoji rendering ([#&#8203;34048](https://github.com/go-gitea/gitea/issues/34048)) ([#&#8203;34049](https://github.com/go-gitea/gitea/issues/34049))
  - Adjust the layout of the toolbar on the Issues/Projects page ([#&#8203;33667](https://github.com/go-gitea/gitea/issues/33667)) ([#&#8203;34047](https://github.com/go-gitea/gitea/issues/34047))
  - Pull request updates will also trigger code owners review requests ([#&#8203;33744](https://github.com/go-gitea/gitea/issues/33744)) ([#&#8203;34045](https://github.com/go-gitea/gitea/issues/34045))
  - Fix org repo creation being limited by user limits ([#&#8203;34030](https://github.com/go-gitea/gitea/issues/34030)) ([#&#8203;34044](https://github.com/go-gitea/gitea/issues/34044))
  - Fix git client accessing renamed repo ([#&#8203;34034](https://github.com/go-gitea/gitea/issues/34034)) ([#&#8203;34043](https://github.com/go-gitea/gitea/issues/34043))
  - Fix the issue with error message logging for the `check-attr` command on Windows OS. ([#&#8203;34035](https://github.com/go-gitea/gitea/issues/34035)) ([#&#8203;34036](https://github.com/go-gitea/gitea/issues/34036))
  - Polyfill WeakRef ([#&#8203;34025](https://github.com/go-gitea/gitea/issues/34025)) ([#&#8203;34028](https://github.com/go-gitea/gitea/issues/34028))

### [`v1.23.6`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1236---2025-03-24)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.5...v1.23.6)

- SECURITY
  - Fix LFS URL ([#&#8203;33840](https://github.com/go-gitea/gitea/issues/33840)) ([#&#8203;33843](https://github.com/go-gitea/gitea/issues/33843))
  - Update jwt and redis packages ([#&#8203;33984](https://github.com/go-gitea/gitea/issues/33984)) ([#&#8203;33987](https://github.com/go-gitea/gitea/issues/33987))
  - Update golang crypto and net ([#&#8203;33989](https://github.com/go-gitea/gitea/issues/33989))
- BUGFIXES
  - Drop timeout for requests made to the internal hook api ([#&#8203;33947](https://github.com/go-gitea/gitea/issues/33947)) ([#&#8203;33970](https://github.com/go-gitea/gitea/issues/33970))
  - Fix maven panic when no package exists ([#&#8203;33888](https://github.com/go-gitea/gitea/issues/33888)) ([#&#8203;33889](https://github.com/go-gitea/gitea/issues/33889))
  - Fix markdown render ([#&#8203;33870](https://github.com/go-gitea/gitea/issues/33870)) ([#&#8203;33875](https://github.com/go-gitea/gitea/issues/33875))
  - Fix auto concurrency cancellation skips commit status updates ([#&#8203;33764](https://github.com/go-gitea/gitea/issues/33764)) ([#&#8203;33849](https://github.com/go-gitea/gitea/issues/33849))
  - Fix oauth2 auth ([#&#8203;33961](https://github.com/go-gitea/gitea/issues/33961)) ([#&#8203;33962](https://github.com/go-gitea/gitea/issues/33962))
  - Fix incorrect 1.23 translations ([#&#8203;33932](https://github.com/go-gitea/gitea/issues/33932))
  - Try to figure out attribute checker problem ([#&#8203;33901](https://github.com/go-gitea/gitea/issues/33901)) ([#&#8203;33902](https://github.com/go-gitea/gitea/issues/33902))
  - Ignore trivial errors when updating push data ([#&#8203;33864](https://github.com/go-gitea/gitea/issues/33864)) ([#&#8203;33887](https://github.com/go-gitea/gitea/issues/33887))
  - Fix some UI problems for 1.23 ([#&#8203;33856](https://github.com/go-gitea/gitea/issues/33856))
  - Removing unwanted ui container ([#&#8203;33833](https://github.com/go-gitea/gitea/issues/33833)) ([#&#8203;33835](https://github.com/go-gitea/gitea/issues/33835))
  - Support disable passkey auth ([#&#8203;33348](https://github.com/go-gitea/gitea/issues/33348)) ([#&#8203;33819](https://github.com/go-gitea/gitea/issues/33819))
  - Do not call "git diff" when listing PRs ([#&#8203;33817](https://github.com/go-gitea/gitea/issues/33817))
  - Try to fix ACME (3rd) ([#&#8203;33807](https://github.com/go-gitea/gitea/issues/33807)) ([#&#8203;33808](https://github.com/go-gitea/gitea/issues/33808))
  - Fix incorrect code search indexer options ([#&#8203;33992](https://github.com/go-gitea/gitea/issues/33992)) [#&#8203;33999](https://github.com/go-gitea/gitea/issues/33999)

### [`v1.23.5`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1235---2025-03-04)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.4...v1.23.5)

- SECURITY
  - Bump x/oauth2 & x/crypto ([#&#8203;33704](https://github.com/go-gitea/gitea/issues/33704)) ([#&#8203;33727](https://github.com/go-gitea/gitea/issues/33727))
- PERFORMANCE
  - Optimize user dashboard loading ([#&#8203;33686](https://github.com/go-gitea/gitea/issues/33686)) ([#&#8203;33708](https://github.com/go-gitea/gitea/issues/33708))
- BUGFIXES
  - Fix navbar dropdown item align ([#&#8203;33782](https://github.com/go-gitea/gitea/issues/33782))
  - Fix inconsistent closed issue list icon ([#&#8203;33722](https://github.com/go-gitea/gitea/issues/33722)) ([#&#8203;33728](https://github.com/go-gitea/gitea/issues/33728))
  - Fix for Maven Package Naming Convention Handling ([#&#8203;33678](https://github.com/go-gitea/gitea/issues/33678)) ([#&#8203;33679](https://github.com/go-gitea/gitea/issues/33679))
  - Improve Open-with URL encoding ([#&#8203;33666](https://github.com/go-gitea/gitea/issues/33666)) ([#&#8203;33680](https://github.com/go-gitea/gitea/issues/33680))
  - Deleting repository should unlink all related packages ([#&#8203;33653](https://github.com/go-gitea/gitea/issues/33653)) ([#&#8203;33673](https://github.com/go-gitea/gitea/issues/33673))
  - Fix omitempty bug ([#&#8203;33663](https://github.com/go-gitea/gitea/issues/33663)) ([#&#8203;33670](https://github.com/go-gitea/gitea/issues/33670))
  - Upgrade go-crypto from 1.1.4 to 1.1.6 ([#&#8203;33745](https://github.com/go-gitea/gitea/issues/33745)) ([#&#8203;33754](https://github.com/go-gitea/gitea/issues/33754))
  - Fix OCI image.version annotation for releases to use full semver ([#&#8203;33698](https://github.com/go-gitea/gitea/issues/33698)) ([#&#8203;33701](https://github.com/go-gitea/gitea/issues/33701))
  - Try to fix ACME path when renew ([#&#8203;33668](https://github.com/go-gitea/gitea/issues/33668)) ([#&#8203;33693](https://github.com/go-gitea/gitea/issues/33693))
  - Fix mCaptcha bug ([#&#8203;33659](https://github.com/go-gitea/gitea/issues/33659)) ([#&#8203;33661](https://github.com/go-gitea/gitea/issues/33661))
  - Git graph: don't show detached commits ([#&#8203;33645](https://github.com/go-gitea/gitea/issues/33645)) ([#&#8203;33650](https://github.com/go-gitea/gitea/issues/33650))
  - Use MatchPhraseQuery for bleve code search ([#&#8203;33628](https://github.com/go-gitea/gitea/issues/33628))
  - Adjust appearance of commit status webhook ([#&#8203;33778](https://github.com/go-gitea/gitea/issues/33778)) [#&#8203;33789](https://github.com/go-gitea/gitea/issues/33789)
  - Upgrade golang net from 0.35.0 -> 0.36.0 ([#&#8203;33795](https://github.com/go-gitea/gitea/issues/33795)) [#&#8203;33796](https://github.com/go-gitea/gitea/issues/33796)

### [`v1.23.4`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1234---2025-02-16)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.3...v1.23.4)

- SECURITY
  - Enhance routers for the Actions variable operations ([#&#8203;33547](https://github.com/go-gitea/gitea/issues/33547)) ([#&#8203;33553](https://github.com/go-gitea/gitea/issues/33553))
  - Enhance routers for the Actions runner operations ([#&#8203;33549](https://github.com/go-gitea/gitea/issues/33549)) ([#&#8203;33555](https://github.com/go-gitea/gitea/issues/33555))
  - Fix project issues list and counting ([#&#8203;33594](https://github.com/go-gitea/gitea/issues/33594)) [#&#8203;33619](https://github.com/go-gitea/gitea/issues/33619)
- PERFORMANCES
  - Performance optimization for pull request files loading comments attachments ([#&#8203;33585](https://github.com/go-gitea/gitea/issues/33585)) ([#&#8203;33592](https://github.com/go-gitea/gitea/issues/33592))
- BUGFIXES
  - Add a transaction to `pickTask` ([#&#8203;33543](https://github.com/go-gitea/gitea/issues/33543)) ([#&#8203;33563](https://github.com/go-gitea/gitea/issues/33563))
  - Fix mirror bug ([#&#8203;33597](https://github.com/go-gitea/gitea/issues/33597)) ([#&#8203;33607](https://github.com/go-gitea/gitea/issues/33607))
  - Use default Git timeout when checking repo health ([#&#8203;33593](https://github.com/go-gitea/gitea/issues/33593)) ([#&#8203;33598](https://github.com/go-gitea/gitea/issues/33598))
  - Fix PR's target branch dropdown ([#&#8203;33589](https://github.com/go-gitea/gitea/issues/33589)) ([#&#8203;33591](https://github.com/go-gitea/gitea/issues/33591))
  - Fix various problems (artifact order, api empty slice, assignee check, fuzzy prompt, mirror proxy, adopt git) ([#&#8203;33569](https://github.com/go-gitea/gitea/issues/33569)) ([#&#8203;33577](https://github.com/go-gitea/gitea/issues/33577))
  - Rework suggestion backend ([#&#8203;33538](https://github.com/go-gitea/gitea/issues/33538)) ([#&#8203;33546](https://github.com/go-gitea/gitea/issues/33546))
  - Fix context usage ([#&#8203;33554](https://github.com/go-gitea/gitea/issues/33554)) ([#&#8203;33557](https://github.com/go-gitea/gitea/issues/33557))
  - Only show the latest version in the Arch index ([#&#8203;33262](https://github.com/go-gitea/gitea/issues/33262)) ([#&#8203;33580](https://github.com/go-gitea/gitea/issues/33580))
  - Skip deletion error for action artifacts ([#&#8203;33476](https://github.com/go-gitea/gitea/issues/33476)) ([#&#8203;33568](https://github.com/go-gitea/gitea/issues/33568))
  - Make actions URL in commit status webhooks absolute ([#&#8203;33620](https://github.com/go-gitea/gitea/issues/33620)) [#&#8203;33632](https://github.com/go-gitea/gitea/issues/33632)
  - Add missing locale ([#&#8203;33641](https://github.com/go-gitea/gitea/issues/33641)) [#&#8203;33642](https://github.com/go-gitea/gitea/issues/33642)

### [`v1.23.3`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1233---2025-02-06)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.2...v1.23.3)

- Security
  - Build Gitea with Golang v1.23.6 to fix security bugs
- BUGFIXES
  - Fix a bug caused by status webhook template [#&#8203;33512](https://github.com/go-gitea/gitea/issues/33512)

### [`v1.23.2`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1232---2025-02-04)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.1...v1.23.2)

- BREAKING
  - Add tests for webhook and fix some webhook bugs ([#&#8203;33396](https://github.com/go-gitea/gitea/issues/33396)) ([#&#8203;33442](https://github.com/go-gitea/gitea/issues/33442))
    - Package webhookโ€™s Organization was incorrectly used as the User struct. This PR fixes the issue.
    - This changelog is just a hint. The change is not really breaking because most fields are the same, most users are not affected.
- ENHANCEMENTS
  - Clone button enhancements ([#&#8203;33362](https://github.com/go-gitea/gitea/issues/33362)) ([#&#8203;33404](https://github.com/go-gitea/gitea/issues/33404))
  - Repo homepage styling tweaks ([#&#8203;33289](https://github.com/go-gitea/gitea/issues/33289)) ([#&#8203;33381](https://github.com/go-gitea/gitea/issues/33381))
  - Add a confirm dialog for "sync fork" ([#&#8203;33270](https://github.com/go-gitea/gitea/issues/33270)) ([#&#8203;33273](https://github.com/go-gitea/gitea/issues/33273))
  - Make tracked time representation display as hours ([#&#8203;33315](https://github.com/go-gitea/gitea/issues/33315)) ([#&#8203;33334](https://github.com/go-gitea/gitea/issues/33334))
  - Improve sync fork behavior ([#&#8203;33319](https://github.com/go-gitea/gitea/issues/33319)) ([#&#8203;33332](https://github.com/go-gitea/gitea/issues/33332))
- BUGFIXES
  - Fix code button alignment ([#&#8203;33345](https://github.com/go-gitea/gitea/issues/33345)) ([#&#8203;33351](https://github.com/go-gitea/gitea/issues/33351))
  - Correct bot label `vertical-align` ([#&#8203;33477](https://github.com/go-gitea/gitea/issues/33477)) ([#&#8203;33480](https://github.com/go-gitea/gitea/issues/33480))
  - Fix SSH LFS memory usage ([#&#8203;33455](https://github.com/go-gitea/gitea/issues/33455)) ([#&#8203;33460](https://github.com/go-gitea/gitea/issues/33460))
  - Fix issue sidebar dropdown keyboard support ([#&#8203;33447](https://github.com/go-gitea/gitea/issues/33447)) ([#&#8203;33450](https://github.com/go-gitea/gitea/issues/33450))
  - Fix user avatar ([#&#8203;33439](https://github.com/go-gitea/gitea/issues/33439))
  - Fix `GetCommitBranchStart` bug ([#&#8203;33298](https://github.com/go-gitea/gitea/issues/33298)) ([#&#8203;33421](https://github.com/go-gitea/gitea/issues/33421))
  - Add pubdate for repository rss and add some tests ([#&#8203;33411](https://github.com/go-gitea/gitea/issues/33411)) ([#&#8203;33416](https://github.com/go-gitea/gitea/issues/33416))
  - Add missed auto merge feed message on dashboard ([#&#8203;33309](https://github.com/go-gitea/gitea/issues/33309)) ([#&#8203;33405](https://github.com/go-gitea/gitea/issues/33405))
  - Fix issue suggestion bug ([#&#8203;33389](https://github.com/go-gitea/gitea/issues/33389)) ([#&#8203;33391](https://github.com/go-gitea/gitea/issues/33391))
  - Make issue suggestion work for all editors ([#&#8203;33340](https://github.com/go-gitea/gitea/issues/33340)) ([#&#8203;33342](https://github.com/go-gitea/gitea/issues/33342))
  - Fix issue count ([#&#8203;33338](https://github.com/go-gitea/gitea/issues/33338)) ([#&#8203;33341](https://github.com/go-gitea/gitea/issues/33341))
  - Fix Account linking page ([#&#8203;33325](https://github.com/go-gitea/gitea/issues/33325)) ([#&#8203;33327](https://github.com/go-gitea/gitea/issues/33327))
  - Fix closed dependency title ([#&#8203;33285](https://github.com/go-gitea/gitea/issues/33285)) ([#&#8203;33287](https://github.com/go-gitea/gitea/issues/33287))
  - Fix sidebar milestone link ([#&#8203;33269](https://github.com/go-gitea/gitea/issues/33269)) ([#&#8203;33272](https://github.com/go-gitea/gitea/issues/33272))
  - Fix missing license when sync mirror ([#&#8203;33255](https://github.com/go-gitea/gitea/issues/33255)) ([#&#8203;33258](https://github.com/go-gitea/gitea/issues/33258))
  - Fix upload file form ([#&#8203;33230](https://github.com/go-gitea/gitea/issues/33230)) ([#&#8203;33233](https://github.com/go-gitea/gitea/issues/33233))
  - Fix mirror bug ([#&#8203;33224](https://github.com/go-gitea/gitea/issues/33224)) ([#&#8203;33225](https://github.com/go-gitea/gitea/issues/33225))
  - Fix system admin cannot fork or get private fork with API ([#&#8203;33401](https://github.com/go-gitea/gitea/issues/33401)) ([#&#8203;33417](https://github.com/go-gitea/gitea/issues/33417))
  - Fix push message behavior ([#&#8203;33215](https://github.com/go-gitea/gitea/issues/33215)) ([#&#8203;33317](https://github.com/go-gitea/gitea/issues/33317))
  - Trivial fixes ([#&#8203;33304](https://github.com/go-gitea/gitea/issues/33304)) ([#&#8203;33312](https://github.com/go-gitea/gitea/issues/33312))
  - Fix "stop time tracking button" on navbar ([#&#8203;33084](https://github.com/go-gitea/gitea/issues/33084)) ([#&#8203;33300](https://github.com/go-gitea/gitea/issues/33300))
  - Fix tag route and empty repo ([#&#8203;33253](https://github.com/go-gitea/gitea/issues/33253))
  - Fix cache test triggered by non memory cache ([#&#8203;33220](https://github.com/go-gitea/gitea/issues/33220)) ([#&#8203;33221](https://github.com/go-gitea/gitea/issues/33221))
  - Revert empty lfs ref name ([#&#8203;33454](https://github.com/go-gitea/gitea/issues/33454)) ([#&#8203;33457](https://github.com/go-gitea/gitea/issues/33457))
  - Fix flex width ([#&#8203;33414](https://github.com/go-gitea/gitea/issues/33414)) ([#&#8203;33418](https://github.com/go-gitea/gitea/issues/33418))
  - Fix commit status events ([#&#8203;33320](https://github.com/go-gitea/gitea/issues/33320)) [#&#8203;33493](https://github.com/go-gitea/gitea/issues/33493)
  - Fix unnecessary comment when moving issue on the same project column ([#&#8203;33496](https://github.com/go-gitea/gitea/issues/33496)) [#&#8203;33499](https://github.com/go-gitea/gitea/issues/33499)
  - Add timetzdata build tag to binary releases ([#&#8203;33463](https://github.com/go-gitea/gitea/issues/33463)) [#&#8203;33503](https://github.com/go-gitea/gitea/issues/33503)
- MISC
  - Use ProtonMail/go-crypto to replace keybase/go-crypto ([#&#8203;33402](https://github.com/go-gitea/gitea/issues/33402)) ([#&#8203;33410](https://github.com/go-gitea/gitea/issues/33410))
  - Update katex to latest version ([#&#8203;33361](https://github.com/go-gitea/gitea/issues/33361))
  - Update go tool dependencies ([#&#8203;32916](https://github.com/go-gitea/gitea/issues/32916)) ([#&#8203;33355](https://github.com/go-gitea/gitea/issues/33355))

### [`v1.23.1`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1231---2025-01-09)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.23.0...v1.23.1)

- ENHANCEMENTS
  - Move repo size to sidebar ([#&#8203;33155](https://github.com/go-gitea/gitea/issues/33155)) ([#&#8203;33182](https://github.com/go-gitea/gitea/issues/33182))
- BUGFIXES
  - Use updated path to s6-svscan after alpine upgrade ([#&#8203;33185](https://github.com/go-gitea/gitea/issues/33185)) ([#&#8203;33188](https://github.com/go-gitea/gitea/issues/33188))
  - Fix fuzz test ([#&#8203;33156](https://github.com/go-gitea/gitea/issues/33156)) ([#&#8203;33158](https://github.com/go-gitea/gitea/issues/33158))
  - Fix raw file API ref handling ([#&#8203;33172](https://github.com/go-gitea/gitea/issues/33172)) ([#&#8203;33189](https://github.com/go-gitea/gitea/issues/33189))
  - Fix ACME panic ([#&#8203;33178](https://github.com/go-gitea/gitea/issues/33178)) ([#&#8203;33186](https://github.com/go-gitea/gitea/issues/33186))
  - Fix branch dropdown not display ref name ([#&#8203;33159](https://github.com/go-gitea/gitea/issues/33159)) ([#&#8203;33183](https://github.com/go-gitea/gitea/issues/33183))
  - Fix assignee list overlapping in Issue sidebar ([#&#8203;33176](https://github.com/go-gitea/gitea/issues/33176)) ([#&#8203;33181](https://github.com/go-gitea/gitea/issues/33181))
  - Fix sync fork for consistency ([#&#8203;33147](https://github.com/go-gitea/gitea/issues/33147)) [#&#8203;33192](https://github.com/go-gitea/gitea/issues/33192)
  - Fix editor markdown not incrementing in a numbered list ([#&#8203;33187](https://github.com/go-gitea/gitea/issues/33187)) [#&#8203;33193](https://github.com/go-gitea/gitea/issues/33193)

### [`v1.23.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1230---2025-01-08)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.22.6...v1.23.0)

- BREAKING
  - Rename config option `[camo].Allways` to `[camo].Always` ([#&#8203;32097](https://github.com/go-gitea/gitea/issues/32097))
  - Remove SHA1 for support for ssh rsa signing ([#&#8203;31857](https://github.com/go-gitea/gitea/issues/31857))
  - Use UTC as default timezone when schedule Actions cron tasks ([#&#8203;31742](https://github.com/go-gitea/gitea/issues/31742))
  - Delete Actions logs older than 1 year by default ([#&#8203;31735](https://github.com/go-gitea/gitea/issues/31735))
  - Make OIDC introspection authentication strictly require Client ID and secret ([#&#8203;31632](https://github.com/go-gitea/gitea/issues/31632))

- SECURITY
  - Include file extension checks in attachment API ([#&#8203;32151](https://github.com/go-gitea/gitea/issues/32151))
  - Include all security fixes which have been backported to v1.22

- FEATURES
  - Allow to fork repository into the same owner ([#&#8203;32819](https://github.com/go-gitea/gitea/issues/32819))
  - Support "merge upstream branch" (Sync fork) ([#&#8203;32741](https://github.com/go-gitea/gitea/issues/32741))
  - Add Arch package registry ([#&#8203;32692](https://github.com/go-gitea/gitea/issues/32692))
  - Allow to disable the password-based login (sign-in) form ([#&#8203;32687](https://github.com/go-gitea/gitea/issues/32687))
  - Allow cropping an avatar before setting it ([#&#8203;32565](https://github.com/go-gitea/gitea/issues/32565))
  - Support quote selected comments to reply ([#&#8203;32431](https://github.com/go-gitea/gitea/issues/32431))
  - Add reviewers selection to new pull request ([#&#8203;32403](https://github.com/go-gitea/gitea/issues/32403))
  - Suggestions for issues ([#&#8203;32327](https://github.com/go-gitea/gitea/issues/32327))
  - Add priority to protected branch ([#&#8203;32286](https://github.com/go-gitea/gitea/issues/32286))
  - Included tag search capabilities ([#&#8203;32045](https://github.com/go-gitea/gitea/issues/32045))
  - Add option to filter board cards by labels and assignees ([#&#8203;31999](https://github.com/go-gitea/gitea/issues/31999))
  - Add automatic light/dark option for the colorblind theme ([#&#8203;31997](https://github.com/go-gitea/gitea/issues/31997))
  - Support migration from AWS CodeCommit ([#&#8203;31981](https://github.com/go-gitea/gitea/issues/31981))
  - Introduce globallock as distributed locks ([#&#8203;31908](https://github.com/go-gitea/gitea/issues/31908) & [#&#8203;31813](https://github.com/go-gitea/gitea/issues/31813))
  - Support compression for Actions logs & enable by default ([#&#8203;31761](https://github.com/go-gitea/gitea/issues/31761) & [#&#8203;32013](https://github.com/go-gitea/gitea/issues/32013))
  - Add pure SSH LFS support ([#&#8203;31516](https://github.com/go-gitea/gitea/issues/31516))
  - Add Passkey login support ([#&#8203;31504](https://github.com/go-gitea/gitea/issues/31504))
  - Actions support workflow dispatch event ([#&#8203;28163](https://github.com/go-gitea/gitea/issues/28163))
  - Support repo license ([#&#8203;24872](https://github.com/go-gitea/gitea/issues/24872))
  - Issue time estimate, meaningful time tracking ([#&#8203;23113](https://github.com/go-gitea/gitea/issues/23113))
  - GitHub like repo home page ([#&#8203;32213](https://github.com/go-gitea/gitea/issues/32213) & [#&#8203;32847](https://github.com/go-gitea/gitea/issues/32847))
  - Rearrange Clone Panel ([#&#8203;31142](https://github.com/go-gitea/gitea/issues/31142))
  - Enhancing Gitea OAuth2 Provider with Granular Scopes for Resource Access ([#&#8203;32573](https://github.com/go-gitea/gitea/issues/32573))
  - Use env GITEA\_RUNNER\_REGISTRATION\_TOKEN as global runner token ([#&#8203;32946](https://github.com/go-gitea/gitea/issues/32946)) [#&#8203;32964](https://github.com/go-gitea/gitea/issues/32964)
  - Update i18n.go - Language Picker ([#&#8203;32933](https://github.com/go-gitea/gitea/issues/32933)) [#&#8203;32935](https://github.com/go-gitea/gitea/issues/32935)

- PERFORMANCE
  - Perf: add extra index to notification table ([#&#8203;32395](https://github.com/go-gitea/gitea/issues/32395))
  - Introduce OrgList and add LoadTeams, optimaze Load teams for orgs ([#&#8203;32543](https://github.com/go-gitea/gitea/issues/32543))
  - Improve performance of diffs ([#&#8203;32393](https://github.com/go-gitea/gitea/issues/32393))
  - Make LFS http\_client parallel within a batch. ([#&#8203;32369](https://github.com/go-gitea/gitea/issues/32369))
  - Add new index for action to resolve the performance problem ([#&#8203;32333](https://github.com/go-gitea/gitea/issues/32333))
  - Improve get feed with pagination ([#&#8203;31821](https://github.com/go-gitea/gitea/issues/31821))
  - Performance improvements for pull request list API ([#&#8203;30490](https://github.com/go-gitea/gitea/issues/30490))
  - Use batch database operations instead of one by one to optimze api pulls ([#&#8203;32680](https://github.com/go-gitea/gitea/issues/32680))
  - Use gitrepo.GetTreePathLatestCommit to get file lastest commit instead from latest commit cache ([#&#8203;32987](https://github.com/go-gitea/gitea/issues/32987)) [#&#8203;33046](https://github.com/go-gitea/gitea/issues/33046)

- ENHANCEMENTS
  - Code
    - Remove unnecessary border in repo home page sidebar ([#&#8203;32767](https://github.com/go-gitea/gitea/issues/32767))
    - Add 'Copy path' button to file view ([#&#8203;32584](https://github.com/go-gitea/gitea/issues/32584))
    - Improve diff file tree ([#&#8203;32658](https://github.com/go-gitea/gitea/issues/32658))
    - Add new \[lfs\_client].BATCH\_SIZE and \[server].LFS\_MAX\_BATCH\_SIZE config settings. ([#&#8203;32307](https://github.com/go-gitea/gitea/issues/32307))
    - Updated tokenizer to better matching when search for code snippets ([#&#8203;32261](https://github.com/go-gitea/gitea/issues/32261))
    - Change the code search to sort results by relevance ([#&#8203;32134](https://github.com/go-gitea/gitea/issues/32134))
    - Support migrating GitHub/GitLab PR draft status ([#&#8203;32242](https://github.com/go-gitea/gitea/issues/32242))
    - Move lock icon position and add additional tooltips to branch list page ([#&#8203;31839](https://github.com/go-gitea/gitea/issues/31839))
    - Add tag name in the commits list ([#&#8203;31082](https://github.com/go-gitea/gitea/issues/31082))
    - Add `MAX_ROWS` option for CSV rendering ([#&#8203;30268](https://github.com/go-gitea/gitea/issues/30268))
    - Allow code search by filename ([#&#8203;32210](https://github.com/go-gitea/gitea/issues/32210))
    - Make git push options accept short name ([#&#8203;32245](https://github.com/go-gitea/gitea/issues/32245))
    - Repo file list enhancements ([#&#8203;32835](https://github.com/go-gitea/gitea/issues/32835))

  - Markdown & Editor
    - Refactor markdown math render, add dollor-backquote syntax support ([#&#8203;32831](https://github.com/go-gitea/gitea/issues/32831))
    - Make Monaco theme follow browser, fully type codeeditor.ts ([#&#8203;32756](https://github.com/go-gitea/gitea/issues/32756))
    - Refactor markdown editor and use it for milestone description editor ([#&#8203;32688](https://github.com/go-gitea/gitea/issues/32688))
    - Add some handy markdown editor features ([#&#8203;32400](https://github.com/go-gitea/gitea/issues/32400))
    - Improve markdown textarea for indentation and lists ([#&#8203;31406](https://github.com/go-gitea/gitea/issues/31406))

  - Issue
    - Add label/author/assignee filters to the user/org home issue list ([#&#8203;32779](https://github.com/go-gitea/gitea/issues/32779))
    - Refactor issue filter (labels, poster, assignee) ([#&#8203;32771](https://github.com/go-gitea/gitea/issues/32771))
    - Style unification for the issue\_management area ([#&#8203;32605](https://github.com/go-gitea/gitea/issues/32605))
    - Add "View all branches/tags" entry to Branch Selector ([#&#8203;32653](https://github.com/go-gitea/gitea/issues/32653))
    - Improve textarea paste ([#&#8203;31948](https://github.com/go-gitea/gitea/issues/31948))
    - Add avif image file support ([#&#8203;32508](https://github.com/go-gitea/gitea/issues/32508))
    - Prevent from submitting issue/comment on uploading ([#&#8203;32263](https://github.com/go-gitea/gitea/issues/32263))
    - Issue Templates: add option to have dropdown printed list ([#&#8203;31577](https://github.com/go-gitea/gitea/issues/31577))
    - Allow searching issues by ID ([#&#8203;31479](https://github.com/go-gitea/gitea/issues/31479))
    - Add `is_archived` option for issue indexer ([#&#8203;32735](https://github.com/go-gitea/gitea/issues/32735))
    - Improve attachment upload methods ([#&#8203;30513](https://github.com/go-gitea/gitea/issues/30513))
    - Support issue template assignees ([#&#8203;31083](https://github.com/go-gitea/gitea/issues/31083))
    - Prevent simultaneous editing of comments and issues ([#&#8203;31053](https://github.com/go-gitea/gitea/issues/31053))
    - Add issue comment when moving issues from one column to another of the project ([#&#8203;29311](https://github.com/go-gitea/gitea/issues/29311))

  - Pull Request
    - Display head branch more comfortable on pull request view ([#&#8203;32000](https://github.com/go-gitea/gitea/issues/32000))
    - Simplify review UI ([#&#8203;31062](https://github.com/go-gitea/gitea/issues/31062))
    - Allow force push to protected branches ([#&#8203;28086](https://github.com/go-gitea/gitea/issues/28086))
    - Add line-through for deleted branch on pull request view page ([#&#8203;32500](https://github.com/go-gitea/gitea/issues/32500))
    - Support requested\_reviewers data in comment webhook events ([#&#8203;26178](https://github.com/go-gitea/gitea/issues/26178))
    - Allow maintainers to view and edit files of private repos when "Allow maintainers to edit" is enabled ([#&#8203;32215](https://github.com/go-gitea/gitea/issues/32215))
    - Allow including `Reviewed-on`/`Reviewed-by` lines for custom merge messages ([#&#8203;31211](https://github.com/go-gitea/gitea/issues/31211))

  - Actions
    - Render job title as commit message ([#&#8203;32748](https://github.com/go-gitea/gitea/issues/32748))
    - Refactor RepoActionView\.vue, add `::group::` support ([#&#8203;32713](https://github.com/go-gitea/gitea/issues/32713))
    - Make RepoActionView\.vue support `##[group]` ([#&#8203;32770](https://github.com/go-gitea/gitea/issues/32770))
    - Support `pull_request_target` event for commit status ([#&#8203;31703](https://github.com/go-gitea/gitea/issues/31703))
    - Detect whether action view branch was deleted ([#&#8203;32764](https://github.com/go-gitea/gitea/issues/32764))
    - Allow users with write permission to run actions ([#&#8203;32644](https://github.com/go-gitea/gitea/issues/32644))
    - Show latest run when visit /run/latest ([#&#8203;31808](https://github.com/go-gitea/gitea/issues/31808))

  - Packages
    - Improve rubygems package registry ([#&#8203;31357](https://github.com/go-gitea/gitea/issues/31357))
    - Add support for npm bundleDependencies ([#&#8203;30751](https://github.com/go-gitea/gitea/issues/30751))
    - Add signature support for the RPM module ([#&#8203;27069](https://github.com/go-gitea/gitea/issues/27069))
    - Extract and display readme and comments for Composer packages ([#&#8203;30927](https://github.com/go-gitea/gitea/issues/30927))

  - Project
    - Add title to project view page ([#&#8203;32747](https://github.com/go-gitea/gitea/issues/32747))
    - Set the columns height to hug all its contents ([#&#8203;31726](https://github.com/go-gitea/gitea/issues/31726))
    - Rename project `board` -> `column` to make the UI less confusing ([#&#8203;30170](https://github.com/go-gitea/gitea/issues/30170))

  - User & Organazition
    - Use better name for userinfo structure ([#&#8203;32544](https://github.com/go-gitea/gitea/issues/32544))
    - Use user.FullName in Oauth2 id\_token response ([#&#8203;32542](https://github.com/go-gitea/gitea/issues/32542))
    - Limit org member view of restricted users ([#&#8203;32211](https://github.com/go-gitea/gitea/issues/32211))
    - Allow disabling authentication related user features ([#&#8203;31535](https://github.com/go-gitea/gitea/issues/31535))
    - Add option to change mail from user display name ([#&#8203;31528](https://github.com/go-gitea/gitea/issues/31528))
    - Use FullName in Emails to address the recipient if possible ([#&#8203;31527](https://github.com/go-gitea/gitea/issues/31527))

  - Administration
    - Add support for a credentials chain for minio access ([#&#8203;31051](https://github.com/go-gitea/gitea/issues/31051))
    - Move admin routers from /admin to /-/admin ([#&#8203;32189](https://github.com/go-gitea/gitea/issues/32189))
    - Add cache test for admins ([#&#8203;31265](https://github.com/go-gitea/gitea/issues/31265))
    - Add option for mailer to override mail headers ([#&#8203;27860](https://github.com/go-gitea/gitea/issues/27860))
    - Azure blob storage support ([#&#8203;30995](https://github.com/go-gitea/gitea/issues/30995))
    - Supports forced use of S3 virtual-hosted style ([#&#8203;30969](https://github.com/go-gitea/gitea/issues/30969))
    - Move repository visibility to danger zone in the settings area ([#&#8203;31126](https://github.com/go-gitea/gitea/issues/31126))

  - Others
    - Remove urls from translations ([#&#8203;31950](https://github.com/go-gitea/gitea/issues/31950))
    - Simplify 404/500 page ([#&#8203;31409](https://github.com/go-gitea/gitea/issues/31409))
    - Optimize installation-page experience ([#&#8203;32558](https://github.com/go-gitea/gitea/issues/32558))
    - Refactor login page ([#&#8203;31530](https://github.com/go-gitea/gitea/issues/31530))
    - Add new event commit status creation and webhook implementation ([#&#8203;27151](https://github.com/go-gitea/gitea/issues/27151))
    - Repo Activity: count new issues that were closed ([#&#8203;31776](https://github.com/go-gitea/gitea/issues/31776))
    - Set manual `tabindex`es on login page ([#&#8203;31689](https://github.com/go-gitea/gitea/issues/31689))
    - Add `YEAR`, `MONTH`, `MONTH_ENGLISH`, `DAY` variables for template repos ([#&#8203;31584](https://github.com/go-gitea/gitea/issues/31584))
    - Add typescript guideline and typescript-specific eslint plugins and fix issues ([#&#8203;31521](https://github.com/go-gitea/gitea/issues/31521))
    - Make toast support preventDuplicates ([#&#8203;31501](https://github.com/go-gitea/gitea/issues/31501))
    - Fix tautological conditions ([#&#8203;30735](https://github.com/go-gitea/gitea/issues/30735))
    - Issue change title notifications ([#&#8203;33050](https://github.com/go-gitea/gitea/issues/33050)) [#&#8203;33065](https://github.com/go-gitea/gitea/issues/33065)

- API
  - Implement update branch API ([#&#8203;32433](https://github.com/go-gitea/gitea/issues/32433))
  - Fix missing outputs for jobs with matrix ([#&#8203;32823](https://github.com/go-gitea/gitea/issues/32823))
  - Make API "compare" accept commit IDs ([#&#8203;32801](https://github.com/go-gitea/gitea/issues/32801))
  - Add github compatible tarball download API endpoints ([#&#8203;32572](https://github.com/go-gitea/gitea/issues/32572))
  - Harden runner updateTask and updateLog api ([#&#8203;32462](https://github.com/go-gitea/gitea/issues/32462))
  - Add `DISABLE_ORGANIZATIONS_PAGE` and `DISABLE_CODE_PAGE` settings for explore pages and fix an issue related to user search ([#&#8203;32288](https://github.com/go-gitea/gitea/issues/32288))
  - Make admins adhere to branch protection rules ([#&#8203;32248](https://github.com/go-gitea/gitea/issues/32248))
  - Calculate `PublicOnly` for org membership only once ([#&#8203;32234](https://github.com/go-gitea/gitea/issues/32234))
  - Allow filtering PRs by poster in the ListPullRequests API ([#&#8203;32209](https://github.com/go-gitea/gitea/issues/32209))
  - Return 404 instead of error when commit not exist ([#&#8203;31977](https://github.com/go-gitea/gitea/issues/31977))
  - Save initial signup information for users to aid in spam prevention ([#&#8203;31852](https://github.com/go-gitea/gitea/issues/31852))
  - Fix upload maven pacakge parallelly ([#&#8203;31851](https://github.com/go-gitea/gitea/issues/31851))
  - Fix null requested\_reviewer from API ([#&#8203;31773](https://github.com/go-gitea/gitea/issues/31773))
  - Add permission description for API to add repo collaborator ([#&#8203;31744](https://github.com/go-gitea/gitea/issues/31744))
  - Add return type to GetRawFileOrLFS and GetRawFile ([#&#8203;31680](https://github.com/go-gitea/gitea/issues/31680))
  - Add skip secondary authorization option for public oauth2 clients ([#&#8203;31454](https://github.com/go-gitea/gitea/issues/31454))
  - Add tag protection via rest api [#&#8203;17862](https://github.com/go-gitea/gitea/issues/17862) ([#&#8203;31295](https://github.com/go-gitea/gitea/issues/31295))
  - Document possible action types for the user activity feed API ([#&#8203;31196](https://github.com/go-gitea/gitea/issues/31196))
  - Add topics for repository API ([#&#8203;31127](https://github.com/go-gitea/gitea/issues/31127))
  - Add support for searching users by email ([#&#8203;30908](https://github.com/go-gitea/gitea/issues/30908))
  - Add API endpoints for getting action jobs status ([#&#8203;26673](https://github.com/go-gitea/gitea/issues/26673))

- REFACTOR
  - Update JS and PY dependencies ([#&#8203;31940](https://github.com/go-gitea/gitea/issues/31940))
  - Enable `no-jquery/no-parse-html-literal` and fix violation ([#&#8203;31684](https://github.com/go-gitea/gitea/issues/31684))
  - Refactor image diff ([#&#8203;31444](https://github.com/go-gitea/gitea/issues/31444))
  - Refactor CSRF token ([#&#8203;32216](https://github.com/go-gitea/gitea/issues/32216))
  - Fix some typescript issues ([#&#8203;32586](https://github.com/go-gitea/gitea/issues/32586))
  - Refactor names ([#&#8203;31405](https://github.com/go-gitea/gitea/issues/31405))
  - Use per package global lock for container uploads instead of memory lock ([#&#8203;31860](https://github.com/go-gitea/gitea/issues/31860))
  - Move team related functions to service layer ([#&#8203;32537](https://github.com/go-gitea/gitea/issues/32537))
  - Move GetFeeds to service layer ([#&#8203;32526](https://github.com/go-gitea/gitea/issues/32526))
  - Resolve lint for unused parameter and unnecessary type arguments ([#&#8203;30750](https://github.com/go-gitea/gitea/issues/30750))
  - Reimplement GetUserOrgsList to make it simple and clear ([#&#8203;32486](https://github.com/go-gitea/gitea/issues/32486))
  - Move some functions from issue.go to standalone files ([#&#8203;32468](https://github.com/go-gitea/gitea/issues/32468))
  - Refactor sidebar assignee\&milestone\&project selectors ([#&#8203;32465](https://github.com/go-gitea/gitea/issues/32465))
  - Refactor sidebar label selector ([#&#8203;32460](https://github.com/go-gitea/gitea/issues/32460))
  - Fix a number of typescript issues ([#&#8203;32459](https://github.com/go-gitea/gitea/issues/32459))
  - Refactor language menu and dom utils ([#&#8203;32450](https://github.com/go-gitea/gitea/issues/32450))
  - Refactor issue page info ([#&#8203;32445](https://github.com/go-gitea/gitea/issues/32445))
  - Split issue sidebar into small templates ([#&#8203;32444](https://github.com/go-gitea/gitea/issues/32444))
  - Refactor template ctx and render utils ([#&#8203;32422](https://github.com/go-gitea/gitea/issues/32422))
  - Refactor repo legacy ([#&#8203;32404](https://github.com/go-gitea/gitea/issues/32404))
  - Refactor markup package ([#&#8203;32399](https://github.com/go-gitea/gitea/issues/32399))
  - Refactor markup render system ([#&#8203;32533](https://github.com/go-gitea/gitea/issues/32533) & [#&#8203;32589](https://github.com/go-gitea/gitea/issues/32589) & [#&#8203;32612](https://github.com/go-gitea/gitea/issues/32612))
  - Refactor the DB migration system slightly ([#&#8203;32344](https://github.com/go-gitea/gitea/issues/32344))
  - Remove jQuery import from some files ([#&#8203;32512](https://github.com/go-gitea/gitea/issues/32512))
  - Strict pagination check ([#&#8203;32548](https://github.com/go-gitea/gitea/issues/32548))
  - Split mail sender sub package from mailer service package ([#&#8203;32618](https://github.com/go-gitea/gitea/issues/32618))
  - Remove outdated code about fixture generation ([#&#8203;32708](https://github.com/go-gitea/gitea/issues/32708))
  - Refactor RepoBranchTagSelector ([#&#8203;32681](https://github.com/go-gitea/gitea/issues/32681))
  - Refactor issue list ([#&#8203;32755](https://github.com/go-gitea/gitea/issues/32755))
  - Refactor LabelEdit ([#&#8203;32752](https://github.com/go-gitea/gitea/issues/32752))
  - Split issue/pull view router function as multiple smaller functions ([#&#8203;32749](https://github.com/go-gitea/gitea/issues/32749))
  - Refactor some LDAP code ([#&#8203;32849](https://github.com/go-gitea/gitea/issues/32849))
  - Unify repo search order by logic ([#&#8203;30876](https://github.com/go-gitea/gitea/issues/30876))
  - Remove duplicate empty repo check in delete branch API ([#&#8203;32569](https://github.com/go-gitea/gitea/issues/32569))
  - Replace deprecated `math/rand` functions ([#&#8203;30733](https://github.com/go-gitea/gitea/issues/30733))
  - Remove fomantic dimmer module ([#&#8203;30723](https://github.com/go-gitea/gitea/issues/30723))
  - Add types to fetch,toast,bootstrap,svg ([#&#8203;31627](https://github.com/go-gitea/gitea/issues/31627))
  - Refactor webhook ([#&#8203;31587](https://github.com/go-gitea/gitea/issues/31587))
  - Move AddCollabrator and CreateRepositoryByExample to service layer ([#&#8203;32419](https://github.com/go-gitea/gitea/issues/32419))
  - Refactor RepoRefByType ([#&#8203;32413](https://github.com/go-gitea/gitea/issues/32413))
  - Refactor: remove redundant err declarations ([#&#8203;32381](https://github.com/go-gitea/gitea/issues/32381))
  - Refactor markup code ([#&#8203;31399](https://github.com/go-gitea/gitea/issues/31399))
  - Refactor render system (orgmode) ([#&#8203;32671](https://github.com/go-gitea/gitea/issues/32671))
  - Refactor render system ([#&#8203;32492](https://github.com/go-gitea/gitea/issues/32492))
  - Refactor markdown render ([#&#8203;32736](https://github.com/go-gitea/gitea/issues/32736) & [#&#8203;32728](https://github.com/go-gitea/gitea/issues/32728))
  - Refactor repo unit "disabled" check ([#&#8203;31389](https://github.com/go-gitea/gitea/issues/31389))
  - Refactor route path normalization ([#&#8203;31381](https://github.com/go-gitea/gitea/issues/31381))
  - Refactor to use UnsafeStringToBytes ([#&#8203;31358](https://github.com/go-gitea/gitea/issues/31358))
  - Migrate vue components to setup ([#&#8203;32329](https://github.com/go-gitea/gitea/issues/32329))
  - Refactor globallock ([#&#8203;31933](https://github.com/go-gitea/gitea/issues/31933))
  - Use correct function name ([#&#8203;31887](https://github.com/go-gitea/gitea/issues/31887))
  - Use a common message template instead of a special one ([#&#8203;31878](https://github.com/go-gitea/gitea/issues/31878))
  - Fix a number of Typescript issues ([#&#8203;31877](https://github.com/go-gitea/gitea/issues/31877))
  - Refactor dropzone ([#&#8203;31482](https://github.com/go-gitea/gitea/issues/31482))
  - Move custom `tw-` helpers to tailwind plugin ([#&#8203;31184](https://github.com/go-gitea/gitea/issues/31184))
  - Replace `gt-word-break` with `tw-break-anywhere` ([#&#8203;31183](https://github.com/go-gitea/gitea/issues/31183))
  - Drop `IDOrderDesc` for listing Actions task and always order by `id DESC` ([#&#8203;31150](https://github.com/go-gitea/gitea/issues/31150))
  - Split common-global.js into separate files ([#&#8203;31438](https://github.com/go-gitea/gitea/issues/31438))
  - Improve detecting empty files ([#&#8203;31332](https://github.com/go-gitea/gitea/issues/31332))
  - Use `querySelector` over alternative DOM methods ([#&#8203;31280](https://github.com/go-gitea/gitea/issues/31280))
  - Remove jQuery `.text()` ([#&#8203;30506](https://github.com/go-gitea/gitea/issues/30506))
  - Use repo as of renderctx's member rather than a repoPath on metas ([#&#8203;29222](https://github.com/go-gitea/gitea/issues/29222))
  - Refactor some frontend problems ([#&#8203;32646](https://github.com/go-gitea/gitea/issues/32646))
  - Refactor DateUtils and merge TimeSince ([#&#8203;32409](https://github.com/go-gitea/gitea/issues/32409))
  - Replace DateTime with proper functions ([#&#8203;32402](https://github.com/go-gitea/gitea/issues/32402))
  - Replace DateTime with DateUtils ([#&#8203;32383](https://github.com/go-gitea/gitea/issues/32383))
  - Convert frontend code to typescript ([#&#8203;31559](https://github.com/go-gitea/gitea/issues/31559))
  - Refactor maven package registry ([#&#8203;33049](https://github.com/go-gitea/gitea/issues/33049)) [#&#8203;33057](https://github.com/go-gitea/gitea/issues/33057)
  - Refactor testfixtures [#&#8203;33028](https://github.com/go-gitea/gitea/issues/33028)

- BUGFIXES
  - Fix issues with inconsistent spacing in areas ([#&#8203;32607](https://github.com/go-gitea/gitea/issues/32607))
  - Fix incomplete Actions status aggregations ([#&#8203;32859](https://github.com/go-gitea/gitea/issues/32859))
  - In some lfs server implementations, they require the ref attribute. ([#&#8203;32838](https://github.com/go-gitea/gitea/issues/32838))
  - Update the list of watchers and stargazers when clicking watch/unwatch or star/unstar ([#&#8203;32570](https://github.com/go-gitea/gitea/issues/32570))
  - Fix `recentupdate` sorting bugs ([#&#8203;32505](https://github.com/go-gitea/gitea/issues/32505))
  - Fix incorrect "Target branch does not exist" in PR title ([#&#8203;32222](https://github.com/go-gitea/gitea/issues/32222))
  - Handle "close" actionable references for manual merges ([#&#8203;31879](https://github.com/go-gitea/gitea/issues/31879))
  - render plain text file if the LFS object doesn't exist ([#&#8203;31812](https://github.com/go-gitea/gitea/issues/31812))
  - Fix Null Pointer error for CommitStatusesHideActionsURL ([#&#8203;31731](https://github.com/go-gitea/gitea/issues/31731))
  - Fix loadRepository error when access user dashboard ([#&#8203;31719](https://github.com/go-gitea/gitea/issues/31719))
  - Hide the "Details" link of commit status when the user cannot access actions ([#&#8203;30156](https://github.com/go-gitea/gitea/issues/30156))
  - Fix duplicate dropdown dividers ([#&#8203;32760](https://github.com/go-gitea/gitea/issues/32760))
  - Fix SSPI button visibility when SSPI is the only enabled method ([#&#8203;32841](https://github.com/go-gitea/gitea/issues/32841))
  - Fix overflow on org header ([#&#8203;32837](https://github.com/go-gitea/gitea/issues/32837))
  - Exclude protected branches from recently pushed ([#&#8203;31748](https://github.com/go-gitea/gitea/issues/31748))
  - Fix large image overflow in comment page ([#&#8203;31740](https://github.com/go-gitea/gitea/issues/31740))
  - Fix milestone deadline and date related problems ([#&#8203;32339](https://github.com/go-gitea/gitea/issues/32339))
  - Fix markdown preview $$ support ([#&#8203;31514](https://github.com/go-gitea/gitea/issues/31514))
  - Fix a compilation error in the Gitpod environment ([#&#8203;32559](https://github.com/go-gitea/gitea/issues/32559))
  - Fix PR diff review form submit ([#&#8203;32596](https://github.com/go-gitea/gitea/issues/32596))
  - Fix a number of typescript issues ([#&#8203;32308](https://github.com/go-gitea/gitea/issues/32308))
  - Fix some function names in comment ([#&#8203;32300](https://github.com/go-gitea/gitea/issues/32300))
  - Fix absolute-date ([#&#8203;32375](https://github.com/go-gitea/gitea/issues/32375))
  - Clarify Actions resources ownership ([#&#8203;31724](https://github.com/go-gitea/gitea/issues/31724))
  - Try to fix ACME directory problem ([#&#8203;33072](https://github.com/go-gitea/gitea/issues/33072)) [#&#8203;33077](https://github.com/go-gitea/gitea/issues/33077)
  - Inherit submodules from template repository content ([#&#8203;16237](https://github.com/go-gitea/gitea/issues/16237)) [#&#8203;33068](https://github.com/go-gitea/gitea/issues/33068)
  - Use project's redirect url instead of composing url ([#&#8203;33058](https://github.com/go-gitea/gitea/issues/33058)) [#&#8203;33064](https://github.com/go-gitea/gitea/issues/33064)
  - Fix toggle commit body button ui when latest commit message is long ([#&#8203;32997](https://github.com/go-gitea/gitea/issues/32997)) [#&#8203;33034](https://github.com/go-gitea/gitea/issues/33034)
  - Fix package error handling and npm meta and empty repo guide [#&#8203;33112](https://github.com/go-gitea/gitea/issues/33112)
  - Fix empty git repo handling logic and fix mobile view ([#&#8203;33101](https://github.com/go-gitea/gitea/issues/33101)) [#&#8203;33102](https://github.com/go-gitea/gitea/issues/33102)
  - Fix line-number and scroll bugs ([#&#8203;33094](https://github.com/go-gitea/gitea/issues/33094)) [#&#8203;33095](https://github.com/go-gitea/gitea/issues/33095)
  - Fix bleve fuzziness search ([#&#8203;33078](https://github.com/go-gitea/gitea/issues/33078)) [#&#8203;33087](https://github.com/go-gitea/gitea/issues/33087)
  - Fix broken forms [#&#8203;33082](https://github.com/go-gitea/gitea/issues/33082)
  - Fix empty repo updated time ([#&#8203;33120](https://github.com/go-gitea/gitea/issues/33120)) [#&#8203;33124](https://github.com/go-gitea/gitea/issues/33124)
  - Add missing transaction when set merge [#&#8203;33113](https://github.com/go-gitea/gitea/issues/33113)
  - Fix issue comment number ([#&#8203;30556](https://github.com/go-gitea/gitea/issues/30556)) [#&#8203;33055](https://github.com/go-gitea/gitea/issues/33055)
  - Fix duplicate co-author in squashed merge commit messages ([#&#8203;33020](https://github.com/go-gitea/gitea/issues/33020)) [#&#8203;33054](https://github.com/go-gitea/gitea/issues/33054)
  - Fix Agit pull request permission check ([#&#8203;32999](https://github.com/go-gitea/gitea/issues/32999)) [#&#8203;33005](https://github.com/go-gitea/gitea/issues/33005)
  - Fix scoped label ui when contains emoji ([#&#8203;33007](https://github.com/go-gitea/gitea/issues/33007)) [#&#8203;33014](https://github.com/go-gitea/gitea/issues/33014)
  - Fix bug on activities ([#&#8203;33008](https://github.com/go-gitea/gitea/issues/33008)) [#&#8203;33016](https://github.com/go-gitea/gitea/issues/33016)
  - Fix review code comment avatar alignment ([#&#8203;33031](https://github.com/go-gitea/gitea/issues/33031)) [#&#8203;33032](https://github.com/go-gitea/gitea/issues/33032)
  - Fix templating in pull request comparison ([#&#8203;33025](https://github.com/go-gitea/gitea/issues/33025)) [#&#8203;33038](https://github.com/go-gitea/gitea/issues/33038)
  - Fix bug automerge cannot be chosed when there is only 1 merge style ([#&#8203;33040](https://github.com/go-gitea/gitea/issues/33040)) [#&#8203;33043](https://github.com/go-gitea/gitea/issues/33043)
  - Fix settings not being loaded at CLI ([#&#8203;26402](https://github.com/go-gitea/gitea/issues/26402)) [#&#8203;33048](https://github.com/go-gitea/gitea/issues/33048)
  - Support for email addresses containing uppercase characters when activating user account ([#&#8203;32998](https://github.com/go-gitea/gitea/issues/32998)) [#&#8203;33001](https://github.com/go-gitea/gitea/issues/33001)
  - Support org labels when adding labels by label names ([#&#8203;32988](https://github.com/go-gitea/gitea/issues/32988)) [#&#8203;32996](https://github.com/go-gitea/gitea/issues/32996)
  - Do not render truncated links in markdown ([#&#8203;32980](https://github.com/go-gitea/gitea/issues/32980)) [#&#8203;32983](https://github.com/go-gitea/gitea/issues/32983)
  - Demilestone should not include milestone ([#&#8203;32923](https://github.com/go-gitea/gitea/issues/32923)) [#&#8203;32979](https://github.com/go-gitea/gitea/issues/32979)
  - Fix Azure blob object Seek ([#&#8203;32974](https://github.com/go-gitea/gitea/issues/32974)) [#&#8203;32975](https://github.com/go-gitea/gitea/issues/32975)
  - Fix maven pom inheritance ([#&#8203;32943](https://github.com/go-gitea/gitea/issues/32943)) [#&#8203;32976](https://github.com/go-gitea/gitea/issues/32976)
  - Fix textarea newline handle ([#&#8203;32966](https://github.com/go-gitea/gitea/issues/32966)) [#&#8203;32977](https://github.com/go-gitea/gitea/issues/32977)
  - Fix outdated tmpl code ([#&#8203;32953](https://github.com/go-gitea/gitea/issues/32953)) [#&#8203;32961](https://github.com/go-gitea/gitea/issues/32961)
  - Fix commit range paging ([#&#8203;32944](https://github.com/go-gitea/gitea/issues/32944)) [#&#8203;32962](https://github.com/go-gitea/gitea/issues/32962)
  - Fix repo avatar conflict ([#&#8203;32958](https://github.com/go-gitea/gitea/issues/32958)) [#&#8203;32960](https://github.com/go-gitea/gitea/issues/32960)
  - Fix trailing comma not matched in the case of alphanumeric issue ([#&#8203;32945](https://github.com/go-gitea/gitea/issues/32945))
  - Relax the version checking for Arch packages ([#&#8203;32908](https://github.com/go-gitea/gitea/issues/32908)) [#&#8203;32913](https://github.com/go-gitea/gitea/issues/32913)
  - Add more load functions to make sure the reference object loaded ([#&#8203;32901](https://github.com/go-gitea/gitea/issues/32901)) [#&#8203;32912](https://github.com/go-gitea/gitea/issues/32912)
  - Filter reviews of one pull request in memory instead of database to reduce slow response because of lacking database index ([#&#8203;33106](https://github.com/go-gitea/gitea/issues/33106)) [#&#8203;33128](https://github.com/go-gitea/gitea/issues/33128)
  - Fix git remote error check, fix dependencies, fix js error ([#&#8203;33129](https://github.com/go-gitea/gitea/issues/33129)) [#&#8203;33133](https://github.com/go-gitea/gitea/issues/33133)

- MISC
  - Optimize branch protection rule loading ([#&#8203;32280](https://github.com/go-gitea/gitea/issues/32280))
  - Bump to go 1.23 ([#&#8203;31855](https://github.com/go-gitea/gitea/issues/31855))
  - Remove unused call to $.HeadRepo in view\_title template ([#&#8203;32317](https://github.com/go-gitea/gitea/issues/32317))
  - Do not display `attestation-manifest` and use short sha256 instead of full sha256 ([#&#8203;32851](https://github.com/go-gitea/gitea/issues/32851))
  - Upgrade htmx to 2.0.4 ([#&#8203;32834](https://github.com/go-gitea/gitea/issues/32834))
  - Improve JSX/TSX support in code editor ([#&#8203;32833](https://github.com/go-gitea/gitea/issues/32833))
  - Add User-Agent for gitea's self-implemented lfs client. ([#&#8203;32832](https://github.com/go-gitea/gitea/issues/32832))
  - Use errors.New to replace fmt.Errorf with no parameters ([#&#8203;32800](https://github.com/go-gitea/gitea/issues/32800))
  - Add "n commits" link to contributors in contributors graph page ([#&#8203;32799](https://github.com/go-gitea/gitea/issues/32799))
  - Update dependencies, tweak eslint ([#&#8203;32719](https://github.com/go-gitea/gitea/issues/32719))
  - Remove all "floated" CSS styles ([#&#8203;32691](https://github.com/go-gitea/gitea/issues/32691))
  - Show tag name on branch/tag selector if repo shown from tag ref ([#&#8203;32689](https://github.com/go-gitea/gitea/issues/32689))
  - Use new mail package instead of an unmintained one ([#&#8203;32682](https://github.com/go-gitea/gitea/issues/32682))
  - Optimize the styling of icon buttons within file-header-right ([#&#8203;32675](https://github.com/go-gitea/gitea/issues/32675))
  - Validate OAuth Redirect URIs ([#&#8203;32643](https://github.com/go-gitea/gitea/issues/32643))
  - Support optional/configurable IAMEndpoint for Minio Client ([#&#8203;32581](https://github.com/go-gitea/gitea/issues/32581)) ([#&#8203;32581](https://github.com/go-gitea/gitea/issues/32581))
  - Make search box in issue sidebar dropdown list always show when scrolling ([#&#8203;32576](https://github.com/go-gitea/gitea/issues/32576))
  - Bump CI,Flake and Snap to Node 22 ([#&#8203;32487](https://github.com/go-gitea/gitea/issues/32487))
  - Update `github.com/meilisearch/meilisearch-go` ([#&#8203;32484](https://github.com/go-gitea/gitea/issues/32484))
  - Add `DEFAULT_MIRROR_REPO_UNITS` and `DEFAULT_TEMPLATE_REPO_UNITS` options ([#&#8203;32416](https://github.com/go-gitea/gitea/issues/32416))
  - Update go dependencies ([#&#8203;32389](https://github.com/go-gitea/gitea/issues/32389))
  - Update JS and PY dependencies ([#&#8203;32388](https://github.com/go-gitea/gitea/issues/32388))
  - Upgrade rollup to 4.24.0 ([#&#8203;32312](https://github.com/go-gitea/gitea/issues/32312))
  - Upgrade vue to 3.5.12 ([#&#8203;32311](https://github.com/go-gitea/gitea/issues/32311))
  - Improve the maintainblity of the reserved username list ([#&#8203;32229](https://github.com/go-gitea/gitea/issues/32229))
  - Upgrade htmx to 2.0.3 ([#&#8203;32192](https://github.com/go-gitea/gitea/issues/32192))
  - Count typescript files as frontend for labeling ([#&#8203;32088](https://github.com/go-gitea/gitea/issues/32088))
  - Only use Host header from reverse proxy ([#&#8203;32060](https://github.com/go-gitea/gitea/issues/32060))
  - Failed authentications are logged to level Warning ([#&#8203;32016](https://github.com/go-gitea/gitea/issues/32016))
  - Enhance USER\_DISABLED\_FEATURES to allow disabling change username or full name ([#&#8203;31959](https://github.com/go-gitea/gitea/issues/31959))
  - Distinguish official vs non-official reviews, add tool tips, and upgrโ€ฆ ([#&#8203;31924](https://github.com/go-gitea/gitea/issues/31924))
  - Update mermaid to v11 ([#&#8203;31913](https://github.com/go-gitea/gitea/issues/31913))
  - Bump relative-time-element to v4.4.3 ([#&#8203;31910](https://github.com/go-gitea/gitea/issues/31910))
  - Upgrade `htmx` to `2.0.2` ([#&#8203;31847](https://github.com/go-gitea/gitea/issues/31847))
  - Add warning message in merge instructions when `AutodetectManualMerge` was not enabled ([#&#8203;31805](https://github.com/go-gitea/gitea/issues/31805))
  - Add types to various low-level functions ([#&#8203;31781](https://github.com/go-gitea/gitea/issues/31781))
  - Update JS dependencies ([#&#8203;31766](https://github.com/go-gitea/gitea/issues/31766))
  - Remove unused code from models/repos/release.go ([#&#8203;31756](https://github.com/go-gitea/gitea/issues/31756))
  - Support delete user email in admin panel ([#&#8203;31690](https://github.com/go-gitea/gitea/issues/31690))
  - Add `username` to OIDC introspection response ([#&#8203;31688](https://github.com/go-gitea/gitea/issues/31688))
  - Use GetDisplayName() instead of DisplayName() to generate rss feeds ([#&#8203;31687](https://github.com/go-gitea/gitea/issues/31687))
  - Code editor theme enhancements ([#&#8203;31629](https://github.com/go-gitea/gitea/issues/31629))
  - Update JS dependencies ([#&#8203;31616](https://github.com/go-gitea/gitea/issues/31616))
  - Add types for js globals ([#&#8203;31586](https://github.com/go-gitea/gitea/issues/31586))
  - Add back esbuild-loader for .js files ([#&#8203;31585](https://github.com/go-gitea/gitea/issues/31585))
  - Don't show hidden labels when filling out an issue template ([#&#8203;31576](https://github.com/go-gitea/gitea/issues/31576))
  - Allow synchronizing user status from OAuth2 login providers ([#&#8203;31572](https://github.com/go-gitea/gitea/issues/31572))
  - Display app name in the registration email title ([#&#8203;31562](https://github.com/go-gitea/gitea/issues/31562))
  - Use stable version of fabric ([#&#8203;31526](https://github.com/go-gitea/gitea/issues/31526))
  - Support legacy \_links LFS batch responses ([#&#8203;31513](https://github.com/go-gitea/gitea/issues/31513))
  - Fix JS error with disabled attachment and easymde ([#&#8203;31511](https://github.com/go-gitea/gitea/issues/31511))
  - Always use HTML attributes for avatar size ([#&#8203;31509](https://github.com/go-gitea/gitea/issues/31509))
  - Use nolyfill to remove some polyfills ([#&#8203;31468](https://github.com/go-gitea/gitea/issues/31468))
  - Disable issue/PR comment button given empty input ([#&#8203;31463](https://github.com/go-gitea/gitea/issues/31463))
  - Add simple JS init performance trace ([#&#8203;31459](https://github.com/go-gitea/gitea/issues/31459))
  - Bump htmx to 2.0.0 ([#&#8203;31413](https://github.com/go-gitea/gitea/issues/31413))
  - Update JS dependencies, remove `eslint-plugin-jquery` ([#&#8203;31402](https://github.com/go-gitea/gitea/issues/31402))
  - Split org Propfile README to a new tab `overview` ([#&#8203;31373](https://github.com/go-gitea/gitea/issues/31373))
  - Update nix flake and add gofumpt ([#&#8203;31320](https://github.com/go-gitea/gitea/issues/31320))
  - Code optimization ([#&#8203;31315](https://github.com/go-gitea/gitea/issues/31315))
  - Enable poetry non-package mode ([#&#8203;31282](https://github.com/go-gitea/gitea/issues/31282))
  - Optimize profile layout to enhance visual experience ([#&#8203;31278](https://github.com/go-gitea/gitea/issues/31278))
  - Update `golang.org/x/net` ([#&#8203;31260](https://github.com/go-gitea/gitea/issues/31260))
  - Bump `@github/relative-time-element` to v4.4.1 ([#&#8203;31232](https://github.com/go-gitea/gitea/issues/31232))
  - Remove unnecessary inline style for tab-size ([#&#8203;31224](https://github.com/go-gitea/gitea/issues/31224))
  - Update golangci-lint to v1.59.0 ([#&#8203;31221](https://github.com/go-gitea/gitea/issues/31221))
  - Update chroma to v2.14.0 ([#&#8203;31177](https://github.com/go-gitea/gitea/issues/31177))
  - Update JS dependencies ([#&#8203;31120](https://github.com/go-gitea/gitea/issues/31120))
  - Improve the handling of `jobs.<job_id>.if` ([#&#8203;31070](https://github.com/go-gitea/gitea/issues/31070))
  - Clean up revive linter config, tweak golangci output ([#&#8203;30980](https://github.com/go-gitea/gitea/issues/30980))
  - Use CSS `inset` shorthand ([#&#8203;30939](https://github.com/go-gitea/gitea/issues/30939))
  - Forbid deprecated `break-word` in CSS ([#&#8203;30934](https://github.com/go-gitea/gitea/issues/30934))
  - Remove obsolete monaco workaround ([#&#8203;30893](https://github.com/go-gitea/gitea/issues/30893))
  - Update JS dependencies, add new eslint rules ([#&#8203;30840](https://github.com/go-gitea/gitea/issues/30840))
  - Fix body margin shifting with modals, fix error on project column edit ([#&#8203;30831](https://github.com/go-gitea/gitea/issues/30831))
  - Remove disk-clean workflow ([#&#8203;30741](https://github.com/go-gitea/gitea/issues/30741))
  - Bump `github.com/google/go-github` to v61 ([#&#8203;30738](https://github.com/go-gitea/gitea/issues/30738))
  - Add built js files to eslint ignore ([#&#8203;30737](https://github.com/go-gitea/gitea/issues/30737))
  - Use `ProtonMail/go-crypto` for `opengpg` in tests ([#&#8203;30736](https://github.com/go-gitea/gitea/issues/30736))
  - Upgrade xorm to v1.3.9 and improve some migrations Sync ([#&#8203;29899](https://github.com/go-gitea/gitea/issues/29899))
  - Added default sorting milestones by name ([#&#8203;27084](https://github.com/go-gitea/gitea/issues/27084))
  - Enable `unparam` linter ([#&#8203;31277](https://github.com/go-gitea/gitea/issues/31277))
  - Use Alpine 3.21 for the docker images ([#&#8203;32924](https://github.com/go-gitea/gitea/issues/32924)) [#&#8203;32951](https://github.com/go-gitea/gitea/issues/32951)
  - Bump x/net ([#&#8203;32896](https://github.com/go-gitea/gitea/issues/32896)) [#&#8203;32899](https://github.com/go-gitea/gitea/issues/32899)
  - Use -s -w ldflags for release artifacts ([#&#8203;33041](https://github.com/go-gitea/gitea/issues/33041)) [#&#8203;33042](https://github.com/go-gitea/gitea/issues/33042)
  - Remove aws go sdk package dependency ([#&#8203;33029](https://github.com/go-gitea/gitea/issues/33029)) [#&#8203;33047](https://github.com/go-gitea/gitea/issues/33047)

### [`v1.22.6`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1226---2024-12-12)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.22.5...v1.22.6)

- SECURITY
  - Fix misuse of PublicKeyCallback([#&#8203;32810](https://github.com/go-gitea/gitea/issues/32810))
- BUGFIXES
  - Fix lfs migration ([#&#8203;32812](https://github.com/go-gitea/gitea/issues/32812)) ([#&#8203;32818](https://github.com/go-gitea/gitea/issues/32818))
  - Add missing two sync feed for refs/pull ([#&#8203;32815](https://github.com/go-gitea/gitea/issues/32815))
- TESTING
  - Avoid MacOS keychain dialog in integration tests ([#&#8203;32813](https://github.com/go-gitea/gitea/issues/32813)) ([#&#8203;32816](https://github.com/go-gitea/gitea/issues/32816))

### [`v1.22.5`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1225---2024-12-11)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.22.4...v1.22.5)

- SECURITY
  - Upgrade crypto library ([#&#8203;32791](https://github.com/go-gitea/gitea/issues/32791))
  - Fix delete branch perm checking ([#&#8203;32654](https://github.com/go-gitea/gitea/issues/32654)) ([#&#8203;32707](https://github.com/go-gitea/gitea/issues/32707))
- BUGFIXES
  - Add standard-compliant route to serve outdated R packages ([#&#8203;32783](https://github.com/go-gitea/gitea/issues/32783)) ([#&#8203;32789](https://github.com/go-gitea/gitea/issues/32789))
  - Fix internal server error when updating labels without write permission ([#&#8203;32776](https://github.com/go-gitea/gitea/issues/32776)) ([#&#8203;32785](https://github.com/go-gitea/gitea/issues/32785))
  - Add Swift login endpoint ([#&#8203;32693](https://github.com/go-gitea/gitea/issues/32693)) ([#&#8203;32701](https://github.com/go-gitea/gitea/issues/32701))
  - Fix fork page branch selection ([#&#8203;32711](https://github.com/go-gitea/gitea/issues/32711)) ([#&#8203;32725](https://github.com/go-gitea/gitea/issues/32725))
  - Fix word overflow in file search page ([#&#8203;32695](https://github.com/go-gitea/gitea/issues/32695)) ([#&#8203;32699](https://github.com/go-gitea/gitea/issues/32699))
  - Fix gogit `GetRefCommitID` ([#&#8203;32705](https://github.com/go-gitea/gitea/issues/32705)) ([#&#8203;32712](https://github.com/go-gitea/gitea/issues/32712))
  - Fix race condition in mermaid observer ([#&#8203;32599](https://github.com/go-gitea/gitea/issues/32599)) ([#&#8203;32673](https://github.com/go-gitea/gitea/issues/32673))
  - Fixe a keystring misuse and refactor duplicates keystrings ([#&#8203;32668](https://github.com/go-gitea/gitea/issues/32668)) ([#&#8203;32792](https://github.com/go-gitea/gitea/issues/32792))
  - Bump relative-time-element to v4.4.4 ([#&#8203;32739](https://github.com/go-gitea/gitea/issues/32739))
- PERFORMANCE
  - Make wiki pages visit fast ([#&#8203;32732](https://github.com/go-gitea/gitea/issues/32732)) ([#&#8203;32745](https://github.com/go-gitea/gitea/issues/32745))
- MISC
  - Don't create action when syncing mirror pull refs ([#&#8203;32659](https://github.com/go-gitea/gitea/issues/32659)) ([#&#8203;32664](https://github.com/go-gitea/gitea/issues/32664))

### [`v1.22.4`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1224---2024-11-14)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.22.3...v1.22.4)

- SECURITY
  - Fix basic auth with webauthn ([#&#8203;32531](https://github.com/go-gitea/gitea/issues/32531)) ([#&#8203;32536](https://github.com/go-gitea/gitea/issues/32536))
  - Refactor internal routers (partial backport, auth token const time comparing) ([#&#8203;32473](https://github.com/go-gitea/gitea/issues/32473)) ([#&#8203;32479](https://github.com/go-gitea/gitea/issues/32479))
- PERFORMANCE
  - Remove transaction for archive download ([#&#8203;32186](https://github.com/go-gitea/gitea/issues/32186)) ([#&#8203;32520](https://github.com/go-gitea/gitea/issues/32520))
- BUGFIXES
  - Fix `missing signature key` error when pulling Docker images with `SERVE_DIRECT` enabled ([#&#8203;32365](https://github.com/go-gitea/gitea/issues/32365)) ([#&#8203;32397](https://github.com/go-gitea/gitea/issues/32397))
  - Fix get reviewers fails when selecting user without pull request permissions unit ([#&#8203;32415](https://github.com/go-gitea/gitea/issues/32415)) ([#&#8203;32616](https://github.com/go-gitea/gitea/issues/32616))
  - Fix adding index files to tmp directory ([#&#8203;32360](https://github.com/go-gitea/gitea/issues/32360)) ([#&#8203;32593](https://github.com/go-gitea/gitea/issues/32593))
  - Fix PR creation on forked repositories via API ([#&#8203;31863](https://github.com/go-gitea/gitea/issues/31863)) ([#&#8203;32591](https://github.com/go-gitea/gitea/issues/32591))
  - Fix missing menu tabs in organization project view page ([#&#8203;32313](https://github.com/go-gitea/gitea/issues/32313)) ([#&#8203;32592](https://github.com/go-gitea/gitea/issues/32592))
  - Support HTTP POST requests to `/userinfo`, aligning to OpenID Core specification ([#&#8203;32578](https://github.com/go-gitea/gitea/issues/32578)) ([#&#8203;32594](https://github.com/go-gitea/gitea/issues/32594))
  - Fix debian package clean up cron job ([#&#8203;32351](https://github.com/go-gitea/gitea/issues/32351)) ([#&#8203;32590](https://github.com/go-gitea/gitea/issues/32590))
  - Fix GetInactiveUsers ([#&#8203;32540](https://github.com/go-gitea/gitea/issues/32540)) ([#&#8203;32588](https://github.com/go-gitea/gitea/issues/32588))
  - Allow the actions user to login via the jwt token ([#&#8203;32527](https://github.com/go-gitea/gitea/issues/32527)) ([#&#8203;32580](https://github.com/go-gitea/gitea/issues/32580))
  - Fix submodule parsing ([#&#8203;32571](https://github.com/go-gitea/gitea/issues/32571)) ([#&#8203;32577](https://github.com/go-gitea/gitea/issues/32577))
  - Refactor find forks and fix possible bugs that weaken permissions check ([#&#8203;32528](https://github.com/go-gitea/gitea/issues/32528)) ([#&#8203;32547](https://github.com/go-gitea/gitea/issues/32547))
  - Fix some places that don't respect org full name setting ([#&#8203;32243](https://github.com/go-gitea/gitea/issues/32243)) ([#&#8203;32550](https://github.com/go-gitea/gitea/issues/32550))
  - Refactor push mirror find and add check for updating push mirror ([#&#8203;32539](https://github.com/go-gitea/gitea/issues/32539)) ([#&#8203;32549](https://github.com/go-gitea/gitea/issues/32549))
  - Fix basic auth with webauthn ([#&#8203;32531](https://github.com/go-gitea/gitea/issues/32531)) ([#&#8203;32536](https://github.com/go-gitea/gitea/issues/32536))
  - Fix artifact v4 upload above 8MB ([#&#8203;31664](https://github.com/go-gitea/gitea/issues/31664)) ([#&#8203;32523](https://github.com/go-gitea/gitea/issues/32523))
  - Fix oauth2 error handle not return immediately ([#&#8203;32514](https://github.com/go-gitea/gitea/issues/32514)) ([#&#8203;32516](https://github.com/go-gitea/gitea/issues/32516))
  - Fix action not triggered when commit message is too long ([#&#8203;32498](https://github.com/go-gitea/gitea/issues/32498)) ([#&#8203;32507](https://github.com/go-gitea/gitea/issues/32507))
  - Fix `GetRepoLink` nil pointer dereference on dashboard feed page when repo is deleted with actions enabled ([#&#8203;32501](https://github.com/go-gitea/gitea/issues/32501)) ([#&#8203;32502](https://github.com/go-gitea/gitea/issues/32502))
  - Fix `missing signature key` error when pulling Docker images with `SERVE_DIRECT` enabled ([#&#8203;32397](https://github.com/go-gitea/gitea/issues/32397)) ([#&#8203;32397](https://github.com/go-gitea/gitea/issues/32397))
  - Fix the permission check for user search API and limit the number of returned users for `/user/search` ([#&#8203;32310](https://github.com/go-gitea/gitea/issues/32310))
  - Fix SearchIssues swagger docs ([#&#8203;32208](https://github.com/go-gitea/gitea/issues/32208)) ([#&#8203;32298](https://github.com/go-gitea/gitea/issues/32298))
  - Fix dropdown content overflow ([#&#8203;31610](https://github.com/go-gitea/gitea/issues/31610)) ([#&#8203;32250](https://github.com/go-gitea/gitea/issues/32250))
  - Disable Oauth check if oauth disabled ([#&#8203;32368](https://github.com/go-gitea/gitea/issues/32368)) ([#&#8203;32480](https://github.com/go-gitea/gitea/issues/32480))
  - Respect renamed dependencies of Cargo registry ([#&#8203;32430](https://github.com/go-gitea/gitea/issues/32430)) ([#&#8203;32478](https://github.com/go-gitea/gitea/issues/32478))
  - Fix mermaid diagram height when initially hidden ([#&#8203;32457](https://github.com/go-gitea/gitea/issues/32457)) ([#&#8203;32464](https://github.com/go-gitea/gitea/issues/32464))
  - Fix broken releases when re-pushing tags ([#&#8203;32435](https://github.com/go-gitea/gitea/issues/32435)) ([#&#8203;32449](https://github.com/go-gitea/gitea/issues/32449))
  - Only provide the commit summary for Discord webhook push events ([#&#8203;32432](https://github.com/go-gitea/gitea/issues/32432)) ([#&#8203;32447](https://github.com/go-gitea/gitea/issues/32447))
  - Only query team tables if repository is under org when getting assignees ([#&#8203;32414](https://github.com/go-gitea/gitea/issues/32414)) ([#&#8203;32426](https://github.com/go-gitea/gitea/issues/32426))
  - Fix created\_unix for mirroring ([#&#8203;32342](https://github.com/go-gitea/gitea/issues/32342)) ([#&#8203;32406](https://github.com/go-gitea/gitea/issues/32406))
  - Respect UI.ExploreDefaultSort setting again ([#&#8203;32357](https://github.com/go-gitea/gitea/issues/32357)) ([#&#8203;32385](https://github.com/go-gitea/gitea/issues/32385))
  - Fix broken image when editing comment with non-image attachments ([#&#8203;32319](https://github.com/go-gitea/gitea/issues/32319)) ([#&#8203;32345](https://github.com/go-gitea/gitea/issues/32345))
  - Fix disable 2fa bug ([#&#8203;32320](https://github.com/go-gitea/gitea/issues/32320)) ([#&#8203;32330](https://github.com/go-gitea/gitea/issues/32330))
  - Always update expiration time when creating an artifact ([#&#8203;32281](https://github.com/go-gitea/gitea/issues/32281)) ([#&#8203;32285](https://github.com/go-gitea/gitea/issues/32285))
  - Fix null errors on conversation holder ([#&#8203;32258](https://github.com/go-gitea/gitea/issues/32258)) ([#&#8203;32266](https://github.com/go-gitea/gitea/issues/32266)) ([#&#8203;32282](https://github.com/go-gitea/gitea/issues/32282))
  - Only rename a user when they should receive a different name ([#&#8203;32247](https://github.com/go-gitea/gitea/issues/32247)) ([#&#8203;32249](https://github.com/go-gitea/gitea/issues/32249))
  - Fix checkbox bug on private/archive filter ([#&#8203;32236](https://github.com/go-gitea/gitea/issues/32236)) ([#&#8203;32240](https://github.com/go-gitea/gitea/issues/32240))
  - Add a doctor check to disable the "Actions" unit for mirrors ([#&#8203;32424](https://github.com/go-gitea/gitea/issues/32424)) ([#&#8203;32497](https://github.com/go-gitea/gitea/issues/32497))
  - Quick fix milestone deadline 9999 ([#&#8203;32423](https://github.com/go-gitea/gitea/issues/32423))
  - Make `show stats` work when only one file changed ([#&#8203;32244](https://github.com/go-gitea/gitea/issues/32244)) ([#&#8203;32268](https://github.com/go-gitea/gitea/issues/32268))
  - Make `owner/repo/pulls` handlers use "PR reader" permission ([#&#8203;32254](https://github.com/go-gitea/gitea/issues/32254)) ([#&#8203;32265](https://github.com/go-gitea/gitea/issues/32265))
  - Update scheduled tasks even if changes are pushed by "ActionsUser" ([#&#8203;32246](https://github.com/go-gitea/gitea/issues/32246)) ([#&#8203;32252](https://github.com/go-gitea/gitea/issues/32252))
- MISC
  - Remove unnecessary code: `GetPushMirrorsByRepoID` called on all repo pages ([#&#8203;32560](https://github.com/go-gitea/gitea/issues/32560)) ([#&#8203;32567](https://github.com/go-gitea/gitea/issues/32567))
  - Improve some sanitizer rules ([#&#8203;32534](https://github.com/go-gitea/gitea/issues/32534))
  - Update nix development environment vor v1.22.x ([#&#8203;32495](https://github.com/go-gitea/gitea/issues/32495))
  - Add warn log when deleting inactive users ([#&#8203;32318](https://github.com/go-gitea/gitea/issues/32318)) ([#&#8203;32321](https://github.com/go-gitea/gitea/issues/32321))
  - Update github.com/go-enry/go-enry to v2.9.1 ([#&#8203;32295](https://github.com/go-gitea/gitea/issues/32295)) ([#&#8203;32296](https://github.com/go-gitea/gitea/issues/32296))
  - Warn users when they try to use a non-root-url to sign in/up ([#&#8203;32272](https://github.com/go-gitea/gitea/issues/32272)) ([#&#8203;32273](https://github.com/go-gitea/gitea/issues/32273))

</details>

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Enabled.

โ™ป **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZG9ja2VyIiwicmVub3ZhdGUiXX0=-->
Renovate/docker/docker-compose.yml+1 -1
@@ -35,7 +35,7 @@ services:
# Pinned to a specific version โ€” Renovate will detect newer releases and
# open a PR automatically, demonstrating the "Container Base Images" section.
gitea:
- image: gitea/gitea:1.22.3
+ image: gitea/gitea:1.27.2@sha256:d20286ca2b2e170fdf628e7231b8a31a3220ade39ff462b55041d43d1fc757dd
container_name: gitea
restart: unless-stopped
networks:
โšช Dependency update #8

Update log4j2 monorepo to v2.26.1

renovate/log4j2-monorepo โ†’ main opened 2026-08-14 09:52 UTC +3 -3 ยท 2 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [org.apache.logging.log4j:log4j-core](https://logging.apache.org/log4j/2.x/) ([source](https://github.com/apache/logging-log4j2)) | `2.14.1` โ†’ `2.26.1` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.logging.log4j:log4j-core/2.26.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.logging.log4j:log4j-core/2.14.1/2.26.1?slim=true) |
| [org.apache.logging.log4j:log4j-api](https://logging.apache.org/log4j/2.x/) ([source](https://github.com/apache/logging-log4j2)) | `2.14.1` โ†’ `2.26.1` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.logging.log4j:log4j-api/2.26.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.logging.log4j:log4j-api/2.14.1/2.26.1?slim=true) |

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

โ™ป **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->
Vulnerable Application Old Java/pom.xml+2 -2
@@ -61,14 +61,14 @@
<dependency>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-api</artifactId>
- <version>2.14.1</version>
+ <version>2.26.1</version>
</dependency>
<!-- โš ๏ธ Log4Shell โ€” CVE-2021-44228 (CVSS 10.0) -->
<dependency>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-core</artifactId>
- <version>2.14.1</version>
+ <version>2.26.1</version>
</dependency>
<!-- โš ๏ธ Jackson Databind โ€” CVE-2022-42003, CVE-2022-42004 -->
Vulnerable Application/pom.xml+1 -1
@@ -55,7 +55,7 @@
<dependency>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-core</artifactId>
- <version>2.14.1</version>
+ <version>2.26.1</version>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
โšช Dependency update #9

Update testcontainers-java monorepo to v1.21.4

renovate/testcontainers-java-monorepo โ†’ main opened 2026-08-14 09:52 UTC +1 -1 ยท 1 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [org.testcontainers:junit-jupiter](https://java.testcontainers.org) ([source](https://github.com/testcontainers/testcontainers-java)) | `1.20.4` โ†’ `1.21.4` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.testcontainers:junit-jupiter/1.21.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.testcontainers:junit-jupiter/1.20.4/1.21.4?slim=true) |
| [org.testcontainers:postgresql](https://java.testcontainers.org) ([source](https://github.com/testcontainers/testcontainers-java)) | `1.20.4` โ†’ `1.21.4` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.testcontainers:postgresql/1.21.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.testcontainers:postgresql/1.20.4/1.21.4?slim=true) |
| [org.testcontainers:testcontainers](https://java.testcontainers.org) ([source](https://github.com/testcontainers/testcontainers-java)) | `1.20.4` โ†’ `1.21.4` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.testcontainers:testcontainers/1.21.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.testcontainers:testcontainers/1.20.4/1.21.4?slim=true) |

---

### Release Notes

<details>
<summary>testcontainers/testcontainers-java (org.testcontainers:junit-jupiter)</summary>

### [`v1.21.4`](https://github.com/testcontainers/testcontainers-java/releases/tag/1.21.4)

[Compare Source](https://github.com/testcontainers/testcontainers-java/compare/1.21.3...1.21.4)

This release makes version 1.21.x works with recent Docker Engine changes.

### [`v1.21.3`](https://github.com/testcontainers/testcontainers-java/releases/tag/1.21.3)

[Compare Source](https://github.com/testcontainers/testcontainers-java/compare/1.21.2...1.21.3)

##### What's Changed

- Update testcontainers/sshd version to 1.3.0 ([#&#8203;10377](https://github.com/testcontainers/testcontainers-java/issues/10377)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Support docker/mcp-gateway image ([#&#8203;10378](https://github.com/testcontainers/testcontainers-java/issues/10378)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Update testcontainers version to 1.21.2 ([#&#8203;10369](https://github.com/testcontainers/testcontainers-java/issues/10369)) [@&#8203;github-actions](https://github.com/github-actions)
- Update docs version to 1.21.2 ([#&#8203;10368](https://github.com/testcontainers/testcontainers-java/issues/10368)) [@&#8203;github-actions](https://github.com/github-actions)

### [`v1.21.2`](https://github.com/testcontainers/testcontainers-java/releases/tag/1.21.2)

[Compare Source](https://github.com/testcontainers/testcontainers-java/compare/1.21.1...1.21.2)

##### What's Changed

- Update ryuk version to 0.12.0 ([#&#8203;10357](https://github.com/testcontainers/testcontainers-java/issues/10357)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Update docs version to 1.21.1 ([#&#8203;10281](https://github.com/testcontainers/testcontainers-java/issues/10281)) [@&#8203;github-actions](https://github.com/github-actions)
- Update testcontainers version to 1.21.1 ([#&#8203;10282](https://github.com/testcontainers/testcontainers-java/issues/10282)) [@&#8203;github-actions](https://github.com/github-actions)

##### ๐Ÿ“– Documentation

- Add DockerMcpGatewayContainer ([#&#8203;10364](https://github.com/testcontainers/testcontainers-java/issues/10364)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

##### ๐Ÿ“ฆ Dependency updates

- Update Gradle Wrapper from undefined to 8.14.2 ([#&#8203;10352](https://github.com/testcontainers/testcontainers-java/issues/10352)) [@&#8203;github-actions](https://github.com/github-actions)

### [`v1.21.1`](https://github.com/testcontainers/testcontainers-java/releases/tag/1.21.1)

[Compare Source](https://github.com/testcontainers/testcontainers-java/compare/1.21.0...1.21.1)

##### What's Changed

- Update docs version to 1.21.0 ([#&#8203;10193](https://github.com/testcontainers/testcontainers-java/issues/10193)) [@&#8203;github-actions](https://github.com/github-actions)
- Update testcontainers version to 1.21.0 ([#&#8203;10194](https://github.com/testcontainers/testcontainers-java/issues/10194)) [@&#8203;github-actions](https://github.com/github-actions)

##### ๐Ÿš€ Features & Enhancements

- Expose Loki in LgtmContainer ([#&#8203;10256](https://github.com/testcontainers/testcontainers-java/issues/10256)) [@&#8203;jaydeluca](https://github.com/jaydeluca)
- Add support to pull model for DockerModelRunnerContainer ([#&#8203;10253](https://github.com/testcontainers/testcontainers-java/issues/10253)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

##### ๐Ÿ› Bug Fixes

- Use generic init script filename when copying it into a Cassandra container ([#&#8203;9606](https://github.com/testcontainers/testcontainers-java/issues/9606)) [@&#8203;maximevw](https://github.com/maximevw)

##### ๐Ÿ“– Documentation

- Add support to clickhouse JDBC V2 ([#&#8203;10280](https://github.com/testcontainers/testcontainers-java/issues/10280)) [@&#8203;thiagohora](https://github.com/thiagohora)
- Fix register listener for kafka docs ([#&#8203;10268](https://github.com/testcontainers/testcontainers-java/issues/10268)) [@&#8203;julianladisch](https://github.com/julianladisch)

##### ๐Ÿ“ฆ Dependency updates

- Update checkstyle version to 10.23.0 ([#&#8203;10196](https://github.com/testcontainers/testcontainers-java/issues/10196)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

### [`v1.21.0`](https://github.com/testcontainers/testcontainers-java/releases/tag/1.21.0)

[Compare Source](https://github.com/testcontainers/testcontainers-java/compare/1.20.6...1.21.0)

##### What's Changed

- Fix typo in LGTM container method ([#&#8203;10189](https://github.com/testcontainers/testcontainers-java/issues/10189)) [@&#8203;jaydeluca](https://github.com/jaydeluca)
- Pass `start` command required in Solr 10 ([#&#8203;10174](https://github.com/testcontainers/testcontainers-java/issues/10174)) [@&#8203;epugh](https://github.com/epugh)
- \[solr] Replace "create\_core" with "create" command ([#&#8203;10172](https://github.com/testcontainers/testcontainers-java/issues/10172)) [@&#8203;epugh](https://github.com/epugh)
- Update docs version to ${GITHUB\_REF##\*/} ([#&#8203;10063](https://github.com/testcontainers/testcontainers-java/issues/10063)) [@&#8203;github-actions](https://github.com/github-actions)
- Update testcontainers version to ${GITHUB\_REF##\*/} ([#&#8203;10062](https://github.com/testcontainers/testcontainers-java/issues/10062)) [@&#8203;github-actions](https://github.com/github-actions)

##### โš ๏ธ Breaking API changes

- Remove spock-core from spock module ([#&#8203;10069](https://github.com/testcontainers/testcontainers-java/issues/10069)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Uses `clickhouse/clickhouse-server` as Docker Image in ClickHouseProvider ([#&#8203;8738](https://github.com/testcontainers/testcontainers-java/issues/8738)) [@&#8203;linghengqian](https://github.com/linghengqian)

##### ๐Ÿš€ Features & Enhancements

- Expose Tempo in LgtmContainer ([#&#8203;10192](https://github.com/testcontainers/testcontainers-java/issues/10192)) [@&#8203;jaydeluca](https://github.com/jaydeluca)
- Allow spock tests to be skipped when Docker is unavailable ([#&#8203;10180](https://github.com/testcontainers/testcontainers-java/issues/10180)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Support new chromadb api version ([#&#8203;10170](https://github.com/testcontainers/testcontainers-java/issues/10170)) [@&#8203;dev-jonghoonpark](https://github.com/dev-jonghoonpark)
- Add default database name to MongoDB Atlas ([#&#8203;10034](https://github.com/testcontainers/testcontainers-java/issues/10034)) [@&#8203;blancqua](https://github.com/blancqua)
- \[servicebus] Skip waiting for sql to be ready ([#&#8203;10092](https://github.com/testcontainers/testcontainers-java/issues/10092)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Support additional flags in FirestoreEmulatorContainer ([#&#8203;10067](https://github.com/testcontainers/testcontainers-java/issues/10067)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

##### โ˜ ๏ธ Deprecations

- Deprecate getUserPass and add getPassword ([#&#8203;10064](https://github.com/testcontainers/testcontainers-java/issues/10064)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

##### ๐Ÿ› Bug Fixes

- Fix connection leak in JdbcDatabaseDelegate ([#&#8203;9662](https://github.com/testcontainers/testcontainers-java/issues/9662)) [@&#8203;froque](https://github.com/froque)
- Allow configuring the AlwaysPullPolicy ([#&#8203;10188](https://github.com/testcontainers/testcontainers-java/issues/10188)) [@&#8203;sebastian-steiner](https://github.com/sebastian-steiner)

##### ๐Ÿ“– Documentation

- Add DockerModelRunnerContainer to core ([#&#8203;10183](https://github.com/testcontainers/testcontainers-java/issues/10183)) [@&#8203;kiview](https://github.com/kiview)
- Allow configuring the AlwaysPullPolicy ([#&#8203;10188](https://github.com/testcontainers/testcontainers-java/issues/10188)) [@&#8203;sebastian-steiner](https://github.com/sebastian-steiner)
- Fix Apache Solr link ([#&#8203;10171](https://github.com/testcontainers/testcontainers-java/issues/10171)) [@&#8203;epugh](https://github.com/epugh)
- Remove incubator note from Solr docs ([#&#8203;10173](https://github.com/testcontainers/testcontainers-java/issues/10173)) [@&#8203;epugh](https://github.com/epugh)
- Remove linked-container ([#&#8203;10065](https://github.com/testcontainers/testcontainers-java/issues/10065)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

##### ๐Ÿงน Housekeeping

- Add SFTP host key check example ([#&#8203;10127](https://github.com/testcontainers/testcontainers-java/issues/10127)) [@&#8203;julianladisch](https://github.com/julianladisch)
- Remove linked-container ([#&#8203;10065](https://github.com/testcontainers/testcontainers-java/issues/10065)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

##### ๐Ÿ“ฆ Dependency updates

- Update Gradle Wrapper from undefined to 8.13 ([#&#8203;10033](https://github.com/testcontainers/testcontainers-java/issues/10033)) [@&#8203;github-actions](https://github.com/github-actions)
- Update docker-java version to 3.4.2 ([#&#8203;10071](https://github.com/testcontainers/testcontainers-java/issues/10071)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

### [`v1.20.6`](https://github.com/testcontainers/testcontainers-java/releases/tag/1.20.6)

[Compare Source](https://github.com/testcontainers/testcontainers-java/compare/1.20.5...1.20.6)

##### What's Changed

- Bump confluentinc/cp-kcat from 7.4.1 to 7.9.0 ([#&#8203;10000](https://github.com/testcontainers/testcontainers-java/issues/10000)) [@&#8203;julianladisch](https://github.com/julianladisch)
- Set sourceCompatibility and targetCompatibility to 1.8 in `spock` module

### [`v1.20.5`](https://github.com/testcontainers/testcontainers-java/releases/tag/1.20.5)

[Compare Source](https://github.com/testcontainers/testcontainers-java/compare/1.20.4...1.20.5)

##### What's Changed

- Add `ServiceBusEmulatorContainer` to Azure module ([#&#8203;9795](https://github.com/testcontainers/testcontainers-java/issues/9795)) [@&#8203;nagyesta](https://github.com/nagyesta)
- Add `EventHubsEmulatorContainer` to Azure module ([#&#8203;9665](https://github.com/testcontainers/testcontainers-java/issues/9665)) [@&#8203;nagyesta](https://github.com/nagyesta)
- Add `AzuriteContainer` to Azure module ([#&#8203;9661](https://github.com/testcontainers/testcontainers-java/issues/9661)) [@&#8203;nagyesta](https://github.com/nagyesta)
- Add `ldap` module ([#&#8203;9987](https://github.com/testcontainers/testcontainers-java/issues/9987)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Add `scylladb` module ([#&#8203;8002](https://github.com/testcontainers/testcontainers-java/issues/8002)) [@&#8203;mkorolyov](https://github.com/mkorolyov)
- Add `pinecone` module ([#&#8203;9911](https://github.com/testcontainers/testcontainers-java/issues/9911)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

##### ๐Ÿš€ Features & Enhancements

- Set `RABBITMQ_DEFAULT_USER` env var with `withAdminUser` ([#&#8203;9571](https://github.com/testcontainers/testcontainers-java/issues/9571)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Move ollama port to a constant and provide new `getPort` method ([#&#8203;9623](https://github.com/testcontainers/testcontainers-java/issues/9623)) [@&#8203;edeandrea](https://github.com/edeandrea)
-

##### ๐Ÿ› Bug Fixes

- Fix reuse support for `CouchbaseContainer` ([#&#8203;9957](https://github.com/testcontainers/testcontainers-java/issues/9957)) [@&#8203;albihnf](https://github.com/albihnf)
- Fix `SolrContainer` start parameters for version >= 9.7.0 ([#&#8203;9926](https://github.com/testcontainers/testcontainers-java/issues/9926)) [@&#8203;mkr](https://github.com/mkr)
- Fix clickhouse authentication ([#&#8203;9942](https://github.com/testcontainers/testcontainers-java/issues/9942)) [@&#8203;livk-cloud](https://github.com/livk-cloud)
- Fix cluster creation with `ConfluentKafkaContainer` and `KafkaContainer` ([#&#8203;9910](https://github.com/testcontainers/testcontainers-java/issues/9910)) [@&#8203;eddumelendez](https://github.com/eddumelendez)

##### ๐Ÿ“– Documentation

- Fix typos ([#&#8203;9783](https://github.com/testcontainers/testcontainers-java/issues/9783)) [@&#8203;NathanBaulch](https://github.com/NathanBaulch)
- Added Dash0 as Adoptor ([#&#8203;9630](https://github.com/testcontainers/testcontainers-java/issues/9630)) [@&#8203;CodingFabian](https://github.com/CodingFabian)
- Improve Docker Compose docs ([#&#8203;9461](https://github.com/testcontainers/testcontainers-java/issues/9461)) [@&#8203;etrandafir93](https://github.com/etrandafir93)

##### ๐Ÿงน Housekeeping

- Use docker/setup-docker-action ([#&#8203;9625](https://github.com/testcontainers/testcontainers-java/issues/9625)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Declare Java action in windows workflow ([#&#8203;9604](https://github.com/testcontainers/testcontainers-java/issues/9604)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Test against multiple Java versions ([#&#8203;8988](https://github.com/testcontainers/testcontainers-java/issues/8988)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Don't extend configuration compileOnly and testCompile from shaded ([#&#8203;9579](https://github.com/testcontainers/testcontainers-java/issues/9579)) [@&#8203;patrick-dedication](https://github.com/patrick-dedication)
- Remove specific Java version for testing in gradle files ([#&#8203;9626](https://github.com/testcontainers/testcontainers-java/issues/9626)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Drop references to `vectorized/redpanda` image ([#&#8203;9624](https://github.com/testcontainers/testcontainers-java/issues/9624)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Polish AbstractPulsar test ([#&#8203;9600](https://github.com/testcontainers/testcontainers-java/issues/9600)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Polish BigtableEmulatorContainer test ([#&#8203;9599](https://github.com/testcontainers/testcontainers-java/issues/9599)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Fix typo in SolrContainer ([#&#8203;9572](https://github.com/testcontainers/testcontainers-java/issues/9572)) [@&#8203;dajudge](https://github.com/dajudge)

##### ๐Ÿ“ฆ Dependency updates

- Update docker-java version to 3.4.1 ([#&#8203;9627](https://github.com/testcontainers/testcontainers-java/issues/9627)) [@&#8203;eddumelendez](https://github.com/eddumelendez)
- Adjust shadow gradle plugin coordinates ([#&#8203;9577](https://github.com/testcontainers/testcontainers-java/issues/9577)) [@&#8203;patrick-dedication](https://github.com/patrick-dedication)

</details>

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

โ™ป **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->
Testcontainers/pom.xml+1 -1
@@ -20,7 +20,7 @@
<properties>
<java.version>25</java.version>
- <testcontainers.version>1.20.4</testcontainers.version>
+ <testcontainers.version>1.21.4</testcontainers.version>
</properties>
<dependencies>
โšช Dependency update #10

Update actions/cache action to v6

renovate/actions-cache-6.x โ†’ main opened 2026-08-14 09:52 UTC +2 -2 ยท 1 file(s)
Renovate's PR description (raw)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/cache](https://github.com/actions/cache) | action | major | `v4` โ†’ `v6` |

---

### Release Notes

<details>
<summary>actions/cache (actions/cache)</summary>

### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0)

[Compare Source](https://github.com/actions/cache/compare/v6.0.0...v6.1.0)

##### What's Changed

- Bump [@&#8203;actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@&#8203;jasongin](https://github.com/jasongin) in [#&#8203;1768](https://github.com/actions/cache/pull/1768)

**Full Changelog**: <https://github.com/actions/cache/compare/v6...v6.1.0>

### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0)

[Compare Source](https://github.com/actions/cache/compare/v6.0.0...v6.0.0)

##### What's Changed

- Update packages, migrate to ESM by [@&#8203;Samirat](https://github.com/Samirat) in [#&#8203;1760](https://github.com/actions/cache/pull/1760)

**Full Changelog**: <https://github.com/actions/cache/compare/v5...v6.0.0>

### [`v6`](https://github.com/actions/cache/compare/v5.1.0...v6.0.0)

[Compare Source](https://github.com/actions/cache/compare/v5.1.0...v6.0.0)

### [`v5.1.0`](https://github.com/actions/cache/releases/tag/v5.1.0)

[Compare Source](https://github.com/actions/cache/compare/v5.0.5...v5.1.0)

##### What's Changed

- Bump [@&#8203;actions/cache](https://github.com/actions/cache) to v5.1.0 - handle read-only cache access by [@&#8203;jasongin](https://github.com/jasongin) in [#&#8203;1775](https://github.com/actions/cache/pull/1775)

**Full Changelog**: <https://github.com/actions/cache/compare/v5...v5.1.0>

### [`v5.0.5`](https://github.com/actions/cache/releases/tag/v5.0.5)

[Compare Source](https://github.com/actions/cache/compare/v5.0.4...v5.0.5)

##### What's Changed

- Update ts-http-runtime dependency by [@&#8203;yacaovsnc](https://github.com/yacaovsnc) in [#&#8203;1747](https://github.com/actions/cache/pull/1747)

**Full Changelog**: <https://github.com/actions/cache/compare/v5...v5.0.5>

### [`v5.0.4`](https://github.com/actions/cache/releases/tag/v5.0.4)

[Compare Source](https://github.com/actions/cache/compare/v5.0.3...v5.0.4)

##### What's Changed

- Add release instructions and update maintainer docs by [@&#8203;Link-](https://github.com/Link-) in [#&#8203;1696](https://github.com/actions/cache/pull/1696)
- Potential fix for code scanning alert no. 52: Workflow does not contain permissions by [@&#8203;Link-](https://github.com/Link-) in [#&#8203;1697](https://github.com/actions/cache/pull/1697)
- Fix workflow permissions and cleanup workflow names / formatting by [@&#8203;Link-](https://github.com/Link-) in [#&#8203;1699](https://github.com/actions/cache/pull/1699)
- docs: Update examples to use the latest version by [@&#8203;XZTDean](https://github.com/XZTDean) in [#&#8203;1690](https://github.com/actions/cache/pull/1690)
- Fix proxy integration tests by [@&#8203;Link-](https://github.com/Link-) in [#&#8203;1701](https://github.com/actions/cache/pull/1701)
- Fix cache key in examples.md for bun.lock by [@&#8203;RyPeck](https://github.com/RyPeck) in [#&#8203;1722](https://github.com/actions/cache/pull/1722)
- Update dependencies & patch security vulnerabilities by [@&#8203;Link-](https://github.com/Link-) in [#&#8203;1738](https://github.com/actions/cache/pull/1738)

##### New Contributors

- [@&#8203;XZTDean](https://github.com/XZTDean) made their first contribution in [#&#8203;1690](https://github.com/actions/cache/pull/1690)
- [@&#8203;RyPeck](https://github.com/RyPeck) made their first contribution in [#&#8203;1722](https://github.com/actions/cache/pull/1722)

**Full Changelog**: <https://github.com/actions/cache/compare/v5...v5.0.4>

### [`v5.0.3`](https://github.com/actions/cache/releases/tag/v5.0.3)

[Compare Source](https://github.com/actions/cache/compare/v5.0.2...v5.0.3)

##### What's Changed

- Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>)
- Bump `@actions/core` to v2.0.3

**Full Changelog**: <https://github.com/actions/cache/compare/v5...v5.0.3>

### [`v5.0.2`](https://github.com/actions/cache/releases/tag/v5.0.2): v.5.0.2

[Compare Source](https://github.com/actions/cache/compare/v5.0.1...v5.0.2)

##### v5.0.2

##### What's Changed

When creating cache entries, 429s returned from the cache service will not be retried.

### [`v5.0.1`](https://github.com/actions/cache/releases/tag/v5.0.1)

[Compare Source](https://github.com/actions/cache/compare/v5...v5.0.1)

> \[!IMPORTANT]
> **`actions/cache@v5` runs on the Node.js 24 runtime and requires a minimum Actions Runner version of `2.327.1`.**
>
> If you are using self-hosted runners, ensure they are updated before upgrading.

***

##### v5.0.1

##### What's Changed

- fix: update [@&#8203;actions/cache](https://github.com/actions/cache) for Node.js 24 punycode deprecation by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1685](https://github.com/actions/cache/pull/1685)
- prepare release v5.0.1 by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1686](https://github.com/actions/cache/pull/1686)

##### v5.0.0

##### What's Changed

- Upgrade to use node24 by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1630](https://github.com/actions/cache/pull/1630)
- Prepare v5.0.0 release by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1684](https://github.com/actions/cache/pull/1684)

**Full Changelog**: <https://github.com/actions/cache/compare/v5...v5.0.1>

### [`v5.0.0`](https://github.com/actions/cache/releases/tag/v5.0.0)

[Compare Source](https://github.com/actions/cache/compare/v5...v5)

> \[!IMPORTANT]
> **`actions/cache@v5` runs on the Node.js 24 runtime and requires a minimum Actions Runner version of `2.327.1`.**
>
> If you are using self-hosted runners, ensure they are updated before upgrading.

***

##### What's Changed

- Upgrade to use node24 by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1630](https://github.com/actions/cache/pull/1630)
- Prepare v5.0.0 release by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1684](https://github.com/actions/cache/pull/1684)

**Full Changelog**: <https://github.com/actions/cache/compare/v4.3.0...v5.0.0>

### [`v5`](https://github.com/actions/cache/compare/v4.3.0...v5)

[Compare Source](https://github.com/actions/cache/compare/v4.3.0...v5)

</details>

---

### Configuration

๐Ÿ“… **Schedule**: (in timezone Europe/Amsterdam)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

๐Ÿšฆ **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

โ™ป **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

๐Ÿ”• **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->
.github/workflows/owasp-dc.yml+2 -2
@@ -45,7 +45,7 @@ jobs:
- name: Restore NVD cache
id: restore-nvd-cache
- uses: actions/cache/restore@v4
+ uses: actions/cache/restore@v6
with:
path: |
OWASP Dependency Check/data/nvd-cache
@@ -71,7 +71,7 @@ jobs:
- name: Save NVD cache
if: always()
- uses: actions/cache/save@v4
+ uses: actions/cache/save@v6
with:
path: |
OWASP Dependency Check/data/nvd-cache