Skip to content

Tags: go-gitea/gitea

Tags

v1.27.2

Toggle v1.27.2's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* SECURITY

  * Fix: update collaborator access mode and httpsign (#38894, #38862) (#38895)
  * Refactor: external render (#38885) (#38898)
  * Fix(actions): resolve pull_request_target reusable workflows at the base commit (#38886) (#38897)
  * Refactor: markup render (#38864) (#38869)
  * Fix(deps): update dependency mermaid to v11.16.1 (#38816)
  * Fix(auth): set WebAuthn user verification per request (#38805) (#38810)
  * Fix: render highlight language (#38793) (#38795)

* ENHANCEMENTS
  * enhance: add missing npm package metadata properties (#38826) (#38831)

* BUGFIXES
  * fix(actions): keep github.event.inputs as strings for workflow_dispatch (#38899) (#38908)
  * fix(actions): let a rerun of selected jobs read the previous attempt's artifacts (#38857) (#38901)
  * fix(lfs): accept successful transfer responses (#38866) (#38875)
  * fix(packages): ignore nested Package.swift (#38788) (#38836)
  * fix: drop newline-bearing member names in arch ParsePackage (#38102) (#38830)
  * fix(storage): fix Azure Blob dump failing with file does not exist (#38814) (#38828)
  * fix(migration): migration deletion returned json redirection (#38796) (#38825)
  * fix(ui): change underlines to default browser style (#38819) (#38823)
  * fix(actions): allow cancelling runs without running jobs (#35842) (#38812)
  * fix(actions): evaluate each `${{ }}` part on its own (#38754) (#38797)
  * fix(actions): write an action task report in one transaction (#38792) (#38794)
  * fix: markup link (#38764) (#38765)
  * fix: set a minio part size when the content size is unknown (#38753) (#38755)
  * fix: bad path escape in subpath archive download (#38749) (#38750)
  * fix: remove the pull merge box from UI when the refreshed page doesn't contain it (#38742) (#38744)
  * fix(markdown): fix double strikethough on code (#38707) (#38729)
  * fix(lfs): failed upload deletes a concurrent upload's meta object (#38693) (#38722)
  * fix: correct full url when using sub-path (#38712) (#38716)
  * fix: avoid markup render panic (#38698) (#38703)
  * fix(ui): too many participants shown in commit avatar stacks (#38689) (#38700)
  * fix: support HEAD requests on Alpine registry APKINDEX.tar.gz (#38686) (#38688)
  * fix(migrations): use all configured GitHub tokens (#38841) (#38846)

v1.27.1

Toggle v1.27.1's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* SECURITY

  * fix(oauth2): enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints (#38591) (#38606)

* API
  * fix(api): align Swagger schemas for UserSettings and TopicListResponse (#38590) (#38592)

* ENHANCEMENTS
  * enhance: improve diff contrast in light and dark themes (#37477) (#38574)

* BUGFIXES
  * fix: skip OIDC end-session after password login for OAuth2 users (#38439) (#38666)
  * fix: make Actions log parser support multiple line message encoding (#38659) (#38664)
  * fix(actions): use base branch ref for pull_request_target context (#38636) (#38657)
  * fix(actions): skip already-approved runs in `ApproveRuns` (#38653) (#38654)
  * fix: orgmode render include path (#38642) (#38645)
  * fix(actions): cancel tasks immediately when the runner stopped reporting (#38616) (#38644)
  * fix(issues): fix label bulk-load key and reduce log noise in LoadLabel (#38632) (#38643)
  * fix(actions): improve runner list status sorting, labels and task job links (#38586) (#38633)
  * fix(actions): correctness and hardening fixes (#38518) (#38631)
  * fix(repo): prevent double-write redirect collisions on dependency errors, fix ui (#38627) (#38628)
  * fix: delete repo-scoped rows of seven more tables when deleting a repository (#38534) (#38618)
  * fix(webhook): remove slack channel name check (#38608) (#38612)
  * fix: download dropdown menu clipped on the branches page (#38604) (#38609)
  * fix(project): prevent database mutations on invalid MoveIssues payload (#38600) (#38602)
  * fix(actions): make SingleWorkflow.Marshal round-trip multi-line run blocks (stop silent job stranding) (#38520) (#38599)
  * fix(file-tree): handle submodule links and missing view container (#38033) (#38589)
  * fix(actions): fail unexpandable reusable workflow callers and decouple the job emitter's cross-run processing (#38565) (#38587)
  * fix: keep serving valid ACME cert when renewal fails at startup (#38554) (#38583)
  * fix: branch protection user list (#38570) (#38584)
  * fix(pulls): respect diff.orderFile in diff file tree (#38566) (#38578)
  * fix(issue): make issue action (issue list batch operation) elements have correct attributes (#38575) (#38580)
  * fix(actions): support `matrix` when evaluating workflow `if` expression (#38474) (#38557)
  * fix(actions): align status icon span for Safari rendering (#38558) (#38562)
  * fix: revert git clone http redirection forbidden (#38530) (#38545)
  * fix: clean up orphaned user-keyed tables in deleteUser (#38511) (#38514)
  * fix(actions): coerce workflow_dispatch boolean inputs to native types (#38472) (#38521)
  * fix: make the merge box button red if some checks fail (#38508) (#38516)
  * fix(pull): sign the commit when updating a branch by merge (#38441) (#38499)
  * fix: make commit message merge correctly (#38490) (#38502)
  * fix(actions): explain why a blocked or waiting job has not started (#38476) (#38498)
  * fix(actions): make `cancelled()` work in job `if` evaluation (#38495) (#38497)
  * fix(actions): show retention info on hover for expired artifacts (#38477) (#38493)
  * fix(actions): group reusable-workflow matrix legs in the workflow graph (#38475) (#38492)
  * fix: full file highlighting for git diff with CR char (#38484) (#38491)
  * fix(packages): serve noarch Alpine index for any requested architecture (#38479) (#38486)
  * fix: 500 error when updating user visibility (#38480) (#38483)
  * fix(actions): make job list item fully clickable (#38462) (#38471)
  * fix: mail template for push event (#38467) (#38468)
  * fix: make "test push webhook" always work (#38425) (#38455)
  * fix(actions): prevent bulk actions from affecting all runners (#38453) (#38457)
  * fix(org): align follow button and wrap description (#38448) (#38454)
  * fix(actions): populate `github.event` for scheduled runs (#38446) (#38452)

* MISC
  * refactor: git patch apply (#38637) (#38638)

v1.27.0

Toggle v1.27.0's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* BREAKING

  * Feat(actions)!: improve support for reusable workflows (#37478)
  * Use Content-Security-Policy: script nonce (#37232)

* SECURITY
  * Fix: various security fixes (#38406) (#38426)
  * Fix(security): harden access checks and migration validation (#38324) (#38400)
  * Fix: enforce public-only token scope and harden push options / locale parsing (#38323) (#38399)
  * Fix(pull): re-evaluate review official flag on target branch change (#38319) (#38402)
  * Fix(api): stop leaking private repo metadata after access revocation (#38321) (#38390)
  * Fix(lfs): require proof of possession for cross-repo objects (#38322) (#38389)
  * Fix(mirror): disable HTTP redirects on pull mirror sync (#38320) (#38367)
  * Fix: golang html template url escaping (#38363) (#38369)
  * Fix(release): validate web attachment renames against allowed types (#38314) (#38328)
  * Fix(release): gate draft release attachments on web download endpoints (#38318) (#38325)
  * Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#37786)
  * Fix(oauth): restrict introspection to the token's client (#38042)
  * Fix(api): don't expose private org membership via public_members (#38145)
  * Fix(actions): deny fork-PR cross-repo access via collaborative owner (#38214)
  * Fix(migrations): prevent path traversal in repository restore (#38215)

* FEATURES
  * Feat(actions): add workflow status badge modal (#38196)
  * Feat(actions): support owner-level and global scoped workflows (#38154)
  * Feat(api): support ref suffixes in compare (#38148)
  * Feat(actions): implement `jobs.<job_id>.continue-on-error` (#38100)
  * Feat(actions): show run status on browser tab favicon (#38071)
  * Feat(api): add token introspection and self-deletion endpoint (#37995)
  * Feat(api): add q parameter to list branches API for server-side filtering (#37982)
  * Feat(repo): split repository creation limit into user and org scopes (#37872)
  * Feat(actions): bulk delete, disable and enable runners in admin UI (#37869)
  * Feat(actions): List workflows that were executed once but got removed from the default branch (#37835)
  * Feat(org): add team visibility so org members can discover teams (#37680)
  * Feat: add raw diff/patch endpoint for repository comparisons (#37632)
  * Feat: Add avatar stacks (#37594)
  * Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) (#37500)
  * Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support (#37433)
  * Support for Custom URI Schemes in OAuth2 Redirect URIs (#37356)
  * Feat(orgs): Add search bar for organization members tab page (#37347)
  * Feat(api): Add assignees APIs (#37330)
  * Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs (#37196)
  * Serve OpenAPI 3.0 spec at /openapi.v1.json (#37038)
  * Add project column picker to issue and pull request sidebar (#37037)
  * Allow multiple projects per issue and pull requests (#36784)
  * Feat(ui): add "follow rename" to file commit history list (#34994)
  * Feat(ssh): auto generate additional ssh keys (#33974)

* ENHANCEMENTS
  * Enhance(actions): only create filtered-out workflow commit status for required contexts (#38371) (#38385)
  * Enhance: allow builtin default git config options to be overridden (#38172)
  * Enhance: allow MathML core elements (#38034)
  * Enhance(markup): improve issue title rendering (#37908)
  * Enhance(actions): set descriptive browser tab title on run view (#37870)
  * Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 (#37866)
  * Enhance(actions): show workflow name from YAML instead of filename (#37833)
  * Feat(actions): add before/after to PR synchronize event payload (#37827)
  * Enhance(actions): add branch filters to run list (#37826)
  * Enhance(actions): Make Summary UI more beautiful with more infos (#37824)
  * Feat: add copy button to action step header, improve other copy buttons (#37744)
  * Fix(icon): use repo-forked icon to display forks count (#37731)
  * Feat(api): add sort and order query parameters to job list endpoints (#37672)
  * Feat(api): add last_sync to repository API (#37566)
  * Enhance: Adjust Workflow Graph styling (#37497)
  * Improve code editor text selection and clean up lint enablement (#37474)
  * Add mirror auth updates to repo edit API and settings (#37468)
  * Replace `olivere/elastic` with REST API client, add OpenSearch support (#37411)
  * Feat: Add default PR branch update style setting (#37410)
  * Fix inconsistent disabled styling on logged-out repo header buttons (#37406)
  * Allow fast-forward-only merge when signed commits are required (#37335)
  * Enhance styling in actions page (#37323)
  * Fix: improve actions status icons and texts (#37206)
  * Make Markdown fenced code block work with more syntaxes (#37154)
  * Fix: Sort action run jobs by JobID and Name with matrix examples (#37046)
  * Add API endpoint to reply to pull request review comments (#36683)

* PERFORMANCE
  * Perf(actions): debounce runner heartbeat writes and throttle task picks (#38281) (#38368)
  * Perf(web): sort the action_run query by a repo-scoped index when possible (#38155)
  * Perf: Various performance regression fixes (#38078)
  * Perf: extend action `c_u` index to include `created_unix` for faster dashboard feeds (#38076)
  * Batch-load related data in actions run, job, and task API endpoints (#37032)

* BUGFIXES
  * Fix(util): reject invalid characters between time-estimate units (#38416) (#38423)
  * Fix: represent a deleted assignee team as a Ghost team (#38413) (#38419)
  * Fix(turnstile): route CAPTCHA verification through the configured proxy (#38412) (#38420)
  * Fix: refresh pull request merge box when the commit status is pending (#38410) (#38411)
  * Fix: actions task state concurrent update (#38405) (#38409)
  * Fix(actions): keep workflow run trailing on one row with long branch names (#38382) (#38403)
  * Fix(web): use locale-aware date formatting for contribution calendar tooltips (#38398) (#38401)
  * Fix: co-author detection (#38392) (#38397)
  * Fix: incorrect co-author detection on commit page (#38386) (#38387)
  * Fix(ui): restore commits table column widths (#38379) (#38383)
  * Fix: minio init check (#38355) (#38361)
  * Fix: org project view assignee list (#38357) (#38360)
  * Fix(actions): release claimed task if context is cancelled during `FetchTask` (#38343) (#38347)
  * Fix(actions): make runner list pagination order deterministic (#38313) (#38327)
  * Fix: Improve since/until when counting commits for X-Total-Count (#38243) (#38304)
  * Fix(actions): prevent chevron overlap with log text when timestamps are enabled (#38227) (#38307)
  * Fix(workflows): branch protection status checks fail when workflow uses on: paths filter (#38237) (#38302)
  * Fix(oauth2): persist linkAccountData during auto-link 2FA flow (#38274) (#38295)
  * Fix(actions): allow Actions bot to push to protected branches (#38284) (#38293)
  * Fix(actions): include all aggregable run statuses in status filter (#38280) (#38287)
  * Fix(archiver): use serializable repo-archive queue payload (#38273) (#38283)
  * Fix: update npm dependencies, fix misc issues (#38257)
  * Fix(api): respect since/until when counting commits for X-Total-Count (#38204)
  * Fix: codemirror regressions (#38248)
  * Fix(api): support HEAD requests on all API GET endpoints (#38245)
  * Fix(actions): Cleanup workflow status badge code (#38241)
  * Fix(web): Correctly align the "disabled" label on larger workflow names (#38240)
  * Fix(actions): don't swallow HTML entities into linkified URLs (#38239)
  * Fix(packages): accept npm "repository" and "bin" in string form (#38236)
  * Fix(actions): fix 500 error when canceling a canceling task (#38223)
  * Fix(deps): update module golang.org/x/image to v0.43.0 [security] (#38219)
  * Fix(mssql): convert legacy DATETIME columns to DATETIME2 (#38216)
  * Fix(api): deny private org member enumeration via /members (#38213)
  * Fix(actions): ensure all waiting jobs get runners in large workflows (#38200)
  * Fix(deps): update go dependencies (#38194)
  * Fix(deps): update npm dependencies (#38193)
  * Fix(cli): default must-change-password to false for bot users (#38175)
  * Fix(actions): show run index in run view and fix summary graph height (#38165)
  * Fix: csp (#38162)
  * Fix(deps): update npm dependencies (#38123)
  * Fix(mssql): expand legacy issue and comment long-text columns (#38120)
  * Fix(packages): validate debian distribution and component names (#38116)
  * Fix(packages): validate module version in goproxy ParsePackage (#38104)
  * Fix(deps): update dependency esbuild to v0.28.1 [security] (#38097)
  * Fix: git push hook post receive (#38089)
  * Fix(ui): prevent commit status popup overflowing its row (#38081)
  * Fix: validate gem name in rubygems parseMetadataFile (#38061)
  * Fix: commit display name (#38057)
  * Fix: csp regressions (#38047)
  * Fix: api error message (#38031)
  * Fix(deps): update npm dependencies (#38029)
  * Fix: pgsql lint (#38022)
  * Fix(indexer): fix assignee filters in issue search (#38021)
  * Fix: various dropdown problems (#38020)
  * Fix: refactor git error handling and make archive streaming handle non-existing commit id (#38007)
  * Fix: raise git required version to 2.13 (#37996)
  * Fix: remove "no-transfrom" from the cache-control header (#37985)
  * Fix(deps): update module github.com/google/go-github/v87 to v88 (#37971)
  * Fix: use committer time where ever possible as default (#37969)
  * Fix(deps): update npm dependencies, remove nolyfill (#37968)
  * Fix(deps): update go dependencies (#37967)
  * Fix(pull): preserve squash message trailers and additional commit messages (#37954)
  * Fix(deps): update module golang.org/x/image to v0.41.0 [security] (#37904)
  * Fix: support ##[command] log prefix in action run UI (#37882)
  * Fix(deps): update module github.com/google/go-github/v86 to v87 (#37845)
  * Fix(deps): update npm dependencies (#37844)
  * Fix(deps): update go dependencies (#37841)
  * Fix(frontend): resolve Vite assets by manifest source path (#37836)
  * Fix(locales): Replace hardcoded strings (#37788)
  * Fix(packages): render markdown links relative to linked repo (#37676)
  * Fix: persist mirror repository metadata (#37519)
  * Fix cmd tests by mocking builtin paths (#37369)
  * Add `form-fetch-action` to some forms, fix "fetch action" resp bug (#37305)
  * Feat: execute post run cleanup when workflow is cancelled (#37275)
  * Fix `relative-time` error and improve global error handler (#37241)
  * Refactor flash message and remove SanitizeHTML template func (#37179)

* TESTING
  * Test(e2e): fix race in pdf file render test (#38380) (#38381)
  * Test: compare key file contents instead of `FileInfo` in `TestInitKeys` (#38330) (#38331)
  * Test: speed up two tests (#37905)
  * Test: Fix random failure test (#37887)
  * Test: fix flaky `issue-comment` close test (#37880)
  * Test: enable WAL for sqlite integration tests (#37861)
  * Test: fix flaky `TestResourceIndex` and reduce its runtime (#37847)
  * Test: run `TestAPIRepoMigrate` offline via a local clone source (#37817)
  * Ci: shard tests and reduce redundant work (#37618)
  * Test(e2e): run playwright via container (#37300)
  * Remove external service dependencies in migration tests (#36866)

* BUILD
  * Fix(actions): authenticate snapcraft before nightly remote build (#38252)
  * Ci: cap Elasticsearch heap in db-tests (#37816)
  * Build(snap): publish nightly version to snapcraft via actions (#37814)
  * Ci: split pgsql shards into plain jobs, dedupe setup actions (#37802)
  * Ci: narrow files-changed frontend filter (#37749)
  * Ci: add `zizmor` to `lint-actions` (#37720)
  * Chore: clean up "contrib" dir (#37690)
  * Fix: snap build (main branch) (#37685)
  * Ci: Also lint json5 files (#37659)
  * Feat(editor): broaden language detection in web code editor (#37619)
  * Build: update pnpm to v11 (#37591)
  * Refactor(deps): migrate from `nektos/act` fork to `gitea/runner` (#37557)
  * Refactor: lint bare `fill`/`stroke` colors, add vars for git graph color series (#37543)
  * Update go js py dependencies (#37525)
  * Ci: lint PR titles with commitlint (#37498)
  * Chore: upgrade Go version in devcontainer image to 1.26 (#37374)
  * Update GitHub Actions to latest major versions (#37313)
  * Update go js dependencies (#37312)
  * Fail vite build on rolldown warnings via NODE_ENV=test (#37270)
  * Remove htmx (#37224)
  * Replace custom Go formatter with `golangci-lint fmt` (#37194)
  * Refactor htmx and fetch-action related code (#37186)
  * Integrate renovate bot for all dependency updates (#37050)
  * Build(sign): move to sigstore (#38250)

* DOCS
  * Docs: update changelog for 1.26.3 & 1.26.4 (#38178)
  * Docs: fix duplicated word in foreachref doc comment (#38161)
  * Docs: Clarify criteria for becoming a merger (#38113)
  * Docs: Publish TOC Election Result 2026 (#38111)
  * Docs: mark openapi3 as autogenerated in attributes (#37963)
  * Docs: add development setup guide (#37960)

* MISC
  * Revert(sign): restore gpg (#38251)
  * Refactor: replace legacy `delete-button` with `link-action` (#38143)
  * Refactor(actions): read runner capabilities from proto field (#38068)
  * Refactor(api): clarify APIError message usage and fix legacy lint error (#38012)
  * Refactor: Use db.Get[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record (#37977)
  * Fix(deps): update go dependencies (#37851)
  * Ci: Fix sync PR labels from the conventional-commit title (#37784) (#37825)
  * Ci: tweak `files-changed`, add `free-disk-space` (#37819)
  * Fix(deps): update module golang.org/x/crypto to v0.52.0 [security] (#37806)
  * Test(e2e): add comment, release, star, PR and fork tests (#37800)
  * Chore: simplify issue and pull request templates (#37799)
  * Chore: Update giteabot to fix failure when backport (#37789)
  * Fix(api): handle partial failures in push mirror synchronization gracefully (#37782)
  * Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 (#37771)
  * Ci: split giteabot workflow (#37770)
  * Fix(deps): update npm dependencies (#37768)
  * Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go (#37764)
  * Fix(deps): update module google.golang.org/grpc to v1.81.1 (#37762)
  * Ci: fix cache-related issues (#37761)
  * Chore: fix tests (#37760)
  * Fix(deps): update module github.com/google/go-github/v85 to v86 (#37754)
  * Fix(deps): update npm dependencies (#37753)
  * Fix(deps): update go dependencies (#37752)
  * Chore(deps): update action dependencies (#37751)
  * Fix(markup): wrap indented code blocks for the code-copy button (#37748)
  * Chore(db): introduce db.Session and db.EngineMigration interfaces (#37746)
  * Feat(web): also display PR counts in repo list (#37739)
  * Refactor(glob): use strings.Builder for regexp compilation (#37730)
  * Chore(doctor): remove four obsolete doctor check implementations (#37728)
  * Refactor(org): simplify owner-team org repo creation logic (#37727)
  * Refactor: move `workflowpattern` into `modules/actions` (#37717)
  * Chore: clean up tests (#37715)
  * Style: misc UI fixes (#37691)
  * Ci: add shellcheck linter (#37682)
  * Fix: catch and fix more lint problems (#37674)
  * Fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test (#37662)
  * Fix(deps): update npm dependencies (#37647)
  * Ci(renovate): update Go import paths on major bumps (#37641)
  * Fix(deps): update go dependencies (major) (#37639)
  * Chore(deps): update action dependencies (major) (#37638)
  * Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 (#37637)
  * Fix(deps): update npm dependencies (#37636)
  * Refactor(log): replace log.Critical with log.Error (#37624)
  * Build(deps): bump fast-uri from 3.1.0 to 3.1.2 (#37616)
  * Feat(oauth): Support AWS Cognito OAuth2 provider (#37607)
  * Chore(deps): update action dependencies (#37603)
  * Ci: allow `chore` type in PR title lint (#37575)
  * Refactor: only reset a database table when the table's data was changed (#37573)
  * Ci: increase renovate frequency and fix RENOVATE_ALLOWED_POST_UPGRADE_COMMANDS (#37565)
  * Refactor: use modernc sqlite driver as default (#37562)
  * Docs: fix 4 typos in CHANGELOG.md (#37549)
  * Fix(deps): update go dependencies (#37541)
  * Chore(deps): update action dependencies (#37540)
  * Refactor pull request view (6) (#37522)
  * Fix: redirect early CLI console logger to stderr (#37507)
  * Refactor "flex-list" to "flex-divided-list" (#37505)
  * Refactor compare diff/pull page (1) (#37481)
  * Refactor pull request view (4) (#37451)
  * Update 1.26.1 changelog in main (#37442)
  * Refactor: use named `Permission` field in `Repository` struct instead of anonymous embedding (#37441)
  * Refactor: serve site manifest via `/assets/site-manifest.json` endpoint (#37405)
  * Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites (#37364)
  * Update `Block a user` form (#37359)
  * Move review request functions to a standalone file (#37358)
  * Feat(security): set X-Content-Type-Options: nosniff by default (#37354)
  * Enable strict TypeScript, add `errorMessage` helper (#37292)
  * Refactor frontend `tw-justify-between` layouts to `flex-left-right` (#37291)
  * Update Nix flake (#37284)
  * Fix Repository transferring page (#37277)
  * Remove `SubmitEvent` polyfill (#37276)
  * Remove dead code identified by `deadcode` tool (#37271)
  * Upgrade go-git to v5.18.0 (#37268)
  * Don't add useless labels which will bother changelog generation (#37267)
  * Move heatmap to first-party code (#37262)
  * Tests/integration: simplify code (#37249)
  * Add pagination and search box to org teams list (#37245)
  * Remove error returns from crypto random helpers and callers (#37240)
  * Add `ExternalIDClaim` option for OAuth2 OIDC auth source (#37229)
  * Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries (#37210)
  * Refactor "htmx" to "fetch action" (#37208)
  * Update go js py dependencies (#37204)
  * Add comment for the design of "user activity time" (#37195)
  * Remove outdated RunUser logic (#37180)
  * Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files (#37150)
  * Update javascript dependencies (#37142)
  * Update go dependencies (#37141)
  * Frontport changelog of v1.26.0-rc0 (#37138)
  * Introduce `ActionRunAttempt` to represent each execution of a run (#37119)
  * Workflow Artifact Info Hover (#37100)
  * Extend issue context popup beyond markdown content (#36908)
  * Add bulk repository deletion for organizations (#36763)
  * Feat: Add bypass allowlist for branch protection (#36514)

v1.28.0-dev

Toggle v1.28.0-dev's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2…

….42.0 (#38266)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[gitlab.com/gitlab-org/api/client-go/v2](https://gitlab.com/gitlab-org/api/client-go)
| `v2.40.1` → `v2.42.0` |
![age](https://developer.mend.io/api/mc/badges/age/go/gitlab.com%2fgitlab-org%2fapi%2fclient-go%2fv2/v2.42.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/gitlab.com%2fgitlab-org%2fapi%2fclient-go%2fv2/v2.40.1/v2.42.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/37531) for more information.

---

### Release Notes

<details>
<summary>gitlab-org/api/client-go
(gitlab.com/gitlab-org/api/client-go/v2)</summary>

###
[`v2.42.0`](https://gitlab.com/gitlab-org/api/client-go/tags/v2.42.0)

[Compare
Source](https://gitlab.com/gitlab-org/api/client-go/compare/v2.41.0...v2.42.0)

#### 2.42.0

##### 🚀 Features

- Add missing fields to project level jira integration
([!2925](https://gitlab.com/gitlab-org/api/client-go/-/merge_requests/2925))
by [Heidi Berry](https://gitlab.com/heidi.berry)

###
[2.42.0](https://gitlab.com/gitlab-org/api/client-go/compare/v2.41.0...v2.42.0)
(2026-06-24)

###
[`v2.41.0`](https://gitlab.com/gitlab-org/api/client-go/tags/v2.41.0)

[Compare
Source](https://gitlab.com/gitlab-org/api/client-go/compare/v2.40.1...v2.41.0)

#### 2.41.0

##### 🚀 Features

- Add missing attributes and endpoints to group
([!2905](https://gitlab.com/gitlab-org/api/client-go/-/merge_requests/2905))
by [Jimmy Spagnola](https://gitlab.com/jspagnola)

##### 🔄 Other Changes

- chore(deps): update docker docker tag to v29.5.3
([!2924](https://gitlab.com/gitlab-org/api/client-go/-/merge_requests/2924))
by [GitLab Dependency
Bot](https://gitlab.com/gitlab-dependency-update-bot)

###
[2.41.0](https://gitlab.com/gitlab-org/api/client-go/compare/v2.40.1...v2.41.0)
(2026-06-23)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Only on Monday (`* * * * 1`)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNDEuNSIsInVwZGF0ZWRJblZlciI6IjQzLjE0MS41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

v1.27.0-rc0

Toggle v1.27.0-rc0's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* BREAKING

  * Feat(actions)!: improve support for reusable workflows (#37478)
  * Use Content-Security-Policy: script nonce (#37232)

* SECURITY
  * Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#37786)
  * Fix(oauth): restrict introspection to the token's client (#38042)
  * Fix(api): don't expose private org membership via public_members (#38145)
  * Fix(actions): deny fork-PR cross-repo access via collaborative owner (#38214)
  * Fix(migrations): prevent path traversal in repository restore (#38215)

* FEATURES
  * Feat(actions): add workflow status badge modal (#38196)
  * Feat(actions): support owner-level and global scoped workflows (#38154)
  * Feat(api): support ref suffixes in compare (#38148)
  * Feat(actions): implement `jobs.<job_id>.continue-on-error` (#38100)
  * Feat(actions): show run status on browser tab favicon (#38071)
  * Feat(api): add token introspection and self-deletion endpoint (#37995)
  * Feat(api): add q parameter to list branches API for server-side filtering (#37982)
  * Feat(repo): split repository creation limit into user and org scopes (#37872)
  * Feat(actions): bulk delete, disable and enable runners in admin UI (#37869)
  * Feat(actions): List workflows that were executed once but got removed from the default branch (#37835)
  * Feat(org): add team visibility so org members can discover teams (#37680)
  * Feat: add raw diff/patch endpoint for repository comparisons (#37632)
  * Feat: Add avatar stacks (#37594)
  * Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) (#37500)
  * Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support (#37433)
  * Support for Custom URI Schemes in OAuth2 Redirect URIs (#37356)
  * Feat(orgs): Add search bar for organization members tab page (#37347)
  * Feat(api): Add assignees APIs (#37330)
  * Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs (#37196)
  * Serve OpenAPI 3.0 spec at /openapi.v1.json (#37038)
  * Add project column picker to issue and pull request sidebar (#37037)
  * Allow multiple projects per issue and pull requests (#36784)
  * Feat(ui): add "follow rename" to file commit history list (#34994)
  * Feat(ssh): auto generate additional ssh keys (#33974)

* ENHANCEMENTS
  * Enhance: allow builtin default git config options to be overridden (#38172)
  * Enhance: allow MathML core elements (#38034)
  * Enhance(markup): improve issue title rendering (#37908)
  * Enhance(actions): set descriptive browser tab title on run view (#37870)
  * Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 (#37866)
  * Enhance(actions): show workflow name from YAML instead of filename (#37833)
  * Feat(actions): add before/after to PR synchronize event payload (#37827)
  * Enhance(actions): add branch filters to run list (#37826)
  * Enhance(actions): Make Summary UI more beautiful with more infos (#37824)
  * Feat: add copy button to action step header, improve other copy buttons (#37744)
  * Fix(icon): use repo-forked icon to display forks count (#37731)
  * Feat(api): add sort and order query parameters to job list endpoints (#37672)
  * Feat(api): add last_sync to repository API (#37566)
  * Enhance: Adjust Workflow Graph styling (#37497)
  * Improve code editor text selection and clean up lint enablement (#37474)
  * Add mirror auth updates to repo edit API and settings (#37468)
  * Replace `olivere/elastic` with REST API client, add OpenSearch support (#37411)
  * Feat: Add default PR branch update style setting (#37410)
  * Fix inconsistent disabled styling on logged-out repo header buttons (#37406)
  * Allow fast-forward-only merge when signed commits are required (#37335)
  * Enhance styling in actions page (#37323)
  * Fix: improve actions status icons and texts (#37206)
  * Make Markdown fenced code block work with more syntaxes (#37154)
  * Fix: Sort action run jobs by JobID and Name with matrix examples (#37046)
  * Add API endpoint to reply to pull request review comments (#36683)

* PERFORMANCE
  * Perf(web): sort the action_run query by a repo-scoped index when possible (#38155)
  * Perf: Various performance regression fixes (#38078)
  * Perf: extend action `c_u` index to include `created_unix` for faster dashboard feeds (#38076)
  * Batch-load related data in actions run, job, and task API endpoints (#37032)

* BUGFIXES
  * Fix: update npm dependencies, fix misc issues (#38257)
  * Fix(api): respect since/until when counting commits for X-Total-Count (#38204)
  * Fix: codemirror regressions (#38248)
  * Fix(api): support HEAD requests on all API GET endpoints (#38245)
  * Fix(actions): Cleanup workflow status badge code (#38241)
  * Fix(web): Correctly align the "disabled" label on larger workflow names (#38240)
  * Fix(actions): don't swallow HTML entities into linkified URLs (#38239)
  * Fix(packages): accept npm "repository" and "bin" in string form (#38236)
  * Fix(actions): fix 500 error when canceling a canceling task (#38223)
  * Fix(deps): update module golang.org/x/image to v0.43.0 [security] (#38219)
  * Fix(mssql): convert legacy DATETIME columns to DATETIME2 (#38216)
  * Fix(api): deny private org member enumeration via /members (#38213)
  * Fix(actions): ensure all waiting jobs get runners in large workflows (#38200)
  * Fix(deps): update go dependencies (#38194)
  * Fix(deps): update npm dependencies (#38193)
  * Fix(cli): default must-change-password to false for bot users (#38175)
  * Fix(actions): show run index in run view and fix summary graph height (#38165)
  * Fix: csp (#38162)
  * Fix(deps): update npm dependencies (#38123)
  * Fix(mssql): expand legacy issue and comment long-text columns (#38120)
  * Fix(packages): validate debian distribution and component names (#38116)
  * Fix(packages): validate module version in goproxy ParsePackage (#38104)
  * Fix(deps): update dependency esbuild to v0.28.1 [security] (#38097)
  * Fix: git push hook post receive (#38089)
  * Fix(ui): prevent commit status popup overflowing its row (#38081)
  * Fix: validate gem name in rubygems parseMetadataFile (#38061)
  * Fix: commit display name (#38057)
  * Fix: csp regressions (#38047)
  * Fix: api error message (#38031)
  * Fix(deps): update npm dependencies (#38029)
  * Fix: pgsql lint (#38022)
  * Fix(indexer): fix assignee filters in issue search (#38021)
  * Fix: various dropdown problems (#38020)
  * Fix: refactor git error handling and make archive streaming handle non-existing commit id (#38007)
  * Fix: raise git required version to 2.13 (#37996)
  * Fix: remove "no-transfrom" from the cache-control header (#37985)
  * Fix(deps): update module github.com/google/go-github/v87 to v88 (#37971)
  * Fix: use committer time where ever possible as default (#37969)
  * Fix(deps): update npm dependencies, remove nolyfill (#37968)
  * Fix(deps): update go dependencies (#37967)
  * Fix(pull): preserve squash message trailers and additional commit messages (#37954)
  * Fix(deps): update module golang.org/x/image to v0.41.0 [security] (#37904)
  * Fix: support ##[command] log prefix in action run UI (#37882)
  * Fix(deps): update module github.com/google/go-github/v86 to v87 (#37845)
  * Fix(deps): update npm dependencies (#37844)
  * Fix(deps): update go dependencies (#37841)
  * Fix(frontend): resolve Vite assets by manifest source path (#37836)
  * Fix(locales): Replace hardcoded strings (#37788)
  * Fix(packages): render markdown links relative to linked repo (#37676)
  * Fix: persist mirror repository metadata (#37519)
  * Fix cmd tests by mocking builtin paths (#37369)
  * Add `form-fetch-action` to some forms, fix "fetch action" resp bug (#37305)
  * Feat: execute post run cleanup when workflow is cancelled (#37275)
  * Fix `relative-time` error and improve global error handler (#37241)
  * Refactor flash message and remove SanitizeHTML template func (#37179)

* TESTING
  * Test: speed up two tests (#37905)
  * Test: Fix random failure test (#37887)
  * Test: fix flaky `issue-comment` close test (#37880)
  * Test: enable WAL for sqlite integration tests (#37861)
  * Test: fix flaky `TestResourceIndex` and reduce its runtime (#37847)
  * Test: run `TestAPIRepoMigrate` offline via a local clone source (#37817)
  * Ci: shard tests and reduce redundant work (#37618)
  * Test(e2e): run playwright via container (#37300)
  * Remove external service dependencies in migration tests (#36866)

* BUILD
  * Fix(actions): authenticate snapcraft before nightly remote build (#38252)
  * Ci: cap Elasticsearch heap in db-tests (#37816)
  * Build(snap): publish nightly version to snapcraft via actions (#37814)
  * Ci: split pgsql shards into plain jobs, dedupe setup actions (#37802)
  * Ci: narrow files-changed frontend filter (#37749)
  * Ci: add `zizmor` to `lint-actions` (#37720)
  * Chore: clean up "contrib" dir (#37690)
  * Fix: snap build (main branch) (#37685)
  * Ci: Also lint json5 files (#37659)
  * Feat(editor): broaden language detection in web code editor (#37619)
  * Build: update pnpm to v11 (#37591)
  * Refactor(deps): migrate from `nektos/act` fork to `gitea/runner` (#37557)
  * Refactor: lint bare `fill`/`stroke` colors, add vars for git graph color series (#37543)
  * Update go js py dependencies (#37525)
  * Ci: lint PR titles with commitlint (#37498)
  * Chore: upgrade Go version in devcontainer image to 1.26 (#37374)
  * Update GitHub Actions to latest major versions (#37313)
  * Update go js dependencies (#37312)
  * Fail vite build on rolldown warnings via NODE_ENV=test (#37270)
  * Remove htmx (#37224)
  * Replace custom Go formatter with `golangci-lint fmt` (#37194)
  * Refactor htmx and fetch-action related code (#37186)
  * Integrate renovate bot for all dependency updates (#37050)
  * Build(sign): move to sigstore (#38250)

* DOCS
  * Docs: update changelog for 1.26.3 & 1.26.4 (#38178)
  * Docs: fix duplicated word in foreachref doc comment (#38161)
  * Docs: Clarify criteria for becoming a merger (#38113)
  * Docs: Publish TOC Election Result 2026 (#38111)
  * Docs: mark openapi3 as autogenerated in attributes (#37963)
  * Docs: add development setup guide (#37960)

* MISC
  * Revert(sign): restore gpg (#38251)
  * Refactor: replace legacy `delete-button` with `link-action` (#38143)
  * Refactor(actions): read runner capabilities from proto field (#38068)
  * Refactor(api): clarify APIError message usage and fix legacy lint error (#38012)
  * Refactor: Use db.Get[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record (#37977)
  * Fix(deps): update go dependencies (#37851)
  * Ci: Fix sync PR labels from the conventional-commit title (#37784) (#37825)
  * Ci: tweak `files-changed`, add `free-disk-space` (#37819)
  * Fix(deps): update module golang.org/x/crypto to v0.52.0 [security] (#37806)
  * Test(e2e): add comment, release, star, PR and fork tests (#37800)
  * Chore: simplify issue and pull request templates (#37799)
  * Chore: Update giteabot to fix failure when backport (#37789)
  * Fix(api): handle partial failures in push mirror synchronization gracefully (#37782)
  * Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 (#37771)
  * Ci: split giteabot workflow (#37770)
  * Fix(deps): update npm dependencies (#37768)
  * Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go (#37764)
  * Fix(deps): update module google.golang.org/grpc to v1.81.1 (#37762)
  * Ci: fix cache-related issues (#37761)
  * Chore: fix tests (#37760)
  * Fix(deps): update module github.com/google/go-github/v85 to v86 (#37754)
  * Fix(deps): update npm dependencies (#37753)
  * Fix(deps): update go dependencies (#37752)
  * Chore(deps): update action dependencies (#37751)
  * Fix(markup): wrap indented code blocks for the code-copy button (#37748)
  * Chore(db): introduce db.Session and db.EngineMigration interfaces (#37746)
  * Feat(web): also display PR counts in repo list (#37739)
  * Refactor(glob): use strings.Builder for regexp compilation (#37730)
  * Chore(doctor): remove four obsolete doctor check implementations (#37728)
  * Refactor(org): simplify owner-team org repo creation logic (#37727)
  * Refactor: move `workflowpattern` into `modules/actions` (#37717)
  * Chore: clean up tests (#37715)
  * Style: misc UI fixes (#37691)
  * Ci: add shellcheck linter (#37682)
  * Fix: catch and fix more lint problems (#37674)
  * Fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test (#37662)
  * Fix(deps): update npm dependencies (#37647)
  * Ci(renovate): update Go import paths on major bumps (#37641)
  * Fix(deps): update go dependencies (major) (#37639)
  * Chore(deps): update action dependencies (major) (#37638)
  * Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 (#37637)
  * Fix(deps): update npm dependencies (#37636)
  * Refactor(log): replace log.Critical with log.Error (#37624)
  * Build(deps): bump fast-uri from 3.1.0 to 3.1.2 (#37616)
  * Feat(oauth): Support AWS Cognito OAuth2 provider (#37607)
  * Chore(deps): update action dependencies (#37603)
  * Ci: allow `chore` type in PR title lint (#37575)
  * Refactor: only reset a database table when the table's data was changed (#37573)
  * Ci: increase renovate frequency and fix RENOVATE_ALLOWED_POST_UPGRADE_COMMANDS (#37565)
  * Refactor: use modernc sqlite driver as default (#37562)
  * Docs: fix 4 typos in CHANGELOG.md (#37549)
  * Fix(deps): update go dependencies (#37541)
  * Chore(deps): update action dependencies (#37540)
  * Refactor pull request view (6) (#37522)
  * Fix: redirect early CLI console logger to stderr (#37507)
  * Refactor "flex-list" to "flex-divided-list" (#37505)
  * Refactor compare diff/pull page (1) (#37481)
  * Refactor pull request view (4) (#37451)
  * Update 1.26.1 changelog in main (#37442)
  * Refactor: use named `Permission` field in `Repository` struct instead of anonymous embedding (#37441)
  * Refactor: serve site manifest via `/assets/site-manifest.json` endpoint (#37405)
  * Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites (#37364)
  * Update `Block a user` form (#37359)
  * Move review request functions to a standalone file (#37358)
  * Feat(security): set X-Content-Type-Options: nosniff by default (#37354)
  * Enable strict TypeScript, add `errorMessage` helper (#37292)
  * Refactor frontend `tw-justify-between` layouts to `flex-left-right` (#37291)
  * Update Nix flake (#37284)
  * Fix Repository transferring page (#37277)
  * Remove `SubmitEvent` polyfill (#37276)
  * Remove dead code identified by `deadcode` tool (#37271)
  * Upgrade go-git to v5.18.0 (#37268)
  * Don't add useless labels which will bother changelog generation (#37267)
  * Move heatmap to first-party code (#37262)
  * Tests/integration: simplify code (#37249)
  * Add pagination and search box to org teams list (#37245)
  * Remove error returns from crypto random helpers and callers (#37240)
  * Add `ExternalIDClaim` option for OAuth2 OIDC auth source (#37229)
  * Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries (#37210)
  * Refactor "htmx" to "fetch action" (#37208)
  * Update go js py dependencies (#37204)
  * Add comment for the design of "user activity time" (#37195)
  * Remove outdated RunUser logic (#37180)
  * Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files (#37150)
  * Update javascript dependencies (#37142)
  * Update go dependencies (#37141)
  * Frontport changelog of v1.26.0-rc0 (#37138)
  * Introduce `ActionRunAttempt` to represent each execution of a run (#37119)
  * Workflow Artifact Info Hover (#37100)
  * Extend issue context popup beyond markdown content (#36908)
  * Add bulk repository deletion for organizations (#36763)
  * Feat: Add bypass allowlist for branch protection (#36514)

v1.26.4

Toggle v1.26.4's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* SECURITY

  * fix(auth): do not auto-reactivate disabled users on OAuth2 callback (#38009) (#38183)

* BUGFIXES
  * fix: walk git log context error handling (#38182) (#38185)

v1.26.3

Toggle v1.26.3's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* BREAKING

  * fix(actions)!: require merged PR to bypass fork PR approval gate (#38010) (#38041)

* SECURITY
  * fix(hostmatcher): patch incorrect private list (#38170) (#38173)
  * fix: Various security fixes (#38103) (#38151)
  * fix: Various sec fixes (#38108) (#38147)
  * fix: allow git clone of private repos with anonymous code access (#38074) (#38146)
  * fix(auth): ignore stale OIDC external login links to organizations (#37875) (#38141)
  * fix(hostmatcher): block reserved IP ranges from external/private filters (#38039) (#38059)
  * fix(lfs): require Code-unit access for cross-repo LFS object reuse (#38006) (#38050)
  * fix(lfs): reject unknown SSH LFS sub-verbs to prevent auth bypass (#38008) (#38015)
  * fix: bound CODEOWNERS regex match time (#38011) (#38025)
  * fix: bound debian ParseControlFile to a single control stanza (#38044) (#38055)
  * fix(deps): update module golang.org/x/net to v0.55.0 [security] (#37813) (#37829)

* API
  * feat(api): add Link header in ListForks (#38052) (#38063)

* BUGFIXES
  * fix: Fix the panic when ssh remote lfs endpoint parsing failure (#38026) (#38158)
  * fix(api): nil pointer panic when filtering tracked times by a non-existent user (#38112) (#38115)
  * fix: keep literal "false" value displayed in workflow_dispatch choice dropdowns (#38080) (#38096)
  * fix: parse HEAD ref (#38119)
  * fix: git cmd (#38084) (#38087)
  * fix(releases): generate notes for initial tag (#37697) (#37986)
  * fix(actions): return 404 when job log blob is missing (#38003) (#38004)
  * fix(actions): exclude `workflow_call` from workflow trigger detection (#37894) (#37899)
  * fix(actions): keep action run title clickable when commit subject is a URL (#37867) (#37898)
  * fix(actions): reject workflow_dispatch for workflows without that trigger (#37660) (#37895)
  * fix(actions): ack re-sent `UpdateLog` finalize idempotently (#37885) (#37892)
  * fix: http content file render (#37850) (#37856)
  * fix(issues): clear stale ReviewTypeRequest when submitting pending review (#37809) (#37815)
  * fix: Fix issue target branch selection for non-collaborators (#36916) (#38164)

* BUILD
  * fix(deps): update `@playwright/test` to 1.60.0 (#38144)
  * ci: add `tools/ci-tools.ts` for the PR labeler workflow (#37831)
  * fix(build): swagger css import (#37801) (#37803)

v1.26.2

Toggle v1.26.2's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* SECURITY

  * fix(permissions): Fix reading permission (#37769)
  * fix(actions): make artifact signature payloads unambiguous (#37707)
  * fix: Unify public-only token filtering in API queries and repo access checks (#37118)
  * fix: Add missed token scope checking (#37735)
  * fix(oauth): bind token exchanges to the original client request (#37704)
  * fix(oauth): strengthen PKCE validation and refresh token replay protection (#37706)
  * fix(web): enforce token scopes on raw, media, and attachment downloads (#37698)
  * fix(security): enforce wiki git writes and LFS token access at request time (#37695)
  * feat(api): encrypt AWS creds (#37679)
  * fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test
  * fix(packages): Add label for private and internal package and fix composor package source permission check (#37610)
  * fix(git): Fix smart http request scope bug (#37583)
  * Fix basic auth bug (#37503)
  * Fix allow maintainer edit permission check (#37479) (#37484)
  * Fix URL sanitization to handle schemeless credentials (#37440) (#37471)
  * Fix attachment Content-Security-Policy (#37455) (#37464)
  * chore(deps): bump go-git/go-git/v5 to 5.19.0 (#37608)

* BUGFIXES
  * fix(pull): handle empty pull request files view to allow reviews (#37783)
  * fix(markup): make RenderString never fail (#37779)
  * fix: add natural sort to sortTreeViewNodes (#37772)
  * fix: package creation unique conflict (#37774)
  * fix!: add DEFAULT_TITLE_SOURCE setting for pull request title default behavior (#37465)
  * fix: Allow direct commits for unprotected files with push restrictions (#37657)
  * fix(actions): wrong assumption that run id always >= job id (#37737)
  * fix(auth): set User-Agent on avatar fetch and sync avatar on link-account register (#37564) (#37588)
  * fix(actions): deadlock between PrepareRunAndInsert and UpdateTaskByState (#37692)
  * fix(repo): /generate must sync the branch table for the new repo (#37693)
  * build: Fix snap build (1.26)
  * fix(actions): run TransferLogs on UpdateLog{Rows:[], NoMore:true} (#37631)
  * fix show correct mergebase
  * fix: make clone URL respect public URL detection setting (#37615)
  * fix: "run as root" check (#37622)
  * chore(deps): update dependency go to v1.26.3 (#37601)
  * Compare dropdown fails when selecting branch with no common merge-base (#37470)
  * fix: treat email addresses case-insensitively (#37600)
  * fix(actions): fix blank lines after ::endgroup:: (#37597)
  * fix(actions): report individual step status in workflow job API response (#37592)
  * fix: Invalid UTF-8 commit messages in JSON API responses (#37542)
  * fix: use consistent GetUser family functions (#37553)
  * fix(api): return 409 message instead of empty JSON for wrong commit id (#37572)
  * fix(actions): prevent panic when workflow contains null jobs (#37570)
  * Make ServeSetHeaders default to download attachment if filename exists (#37552) (#37555)
  * Fix(actions): validate workflow param to prevent 500 error (#37546) (#37554)
  * Don't unblock run-level-concurrency-blocked runs in the resolver (#37461) (#37538)
  * Fix(packages): use file names for generic web downloads (#37514) (#37520)
  * Fix merge autodetect can't close other PRs but only the last one when multiple PRs are pushed at once (#37512) (#37516)
  * Fix update branch protection order (#37508) (#37513)
  * Fix mCaptcha broken after Vite migration (#37492) (#37509)
  * Fix review submission from single-commit PR view (#37475) (#37485)
  * Fix scheduled action panic with null event payload (#37459) (#37466)
  * Make GetPossibleUserByID can handle deleted user (#37430) (#37431)
  * Remove excessive quote from terraform instructions (#37424) (#37426)
  * Fix color regressions, add `priority` color (#37417) (#37421)

* MISC
  * Add CurrentURL template variable back (#37444) (#37449)

v1.26.1

Toggle v1.26.1's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* BUGFIXES

  * Add event.schedule context for schedule actions task (#37320) (#37348)
  * Fix an issue where changing an organization's visibility caused problems when users had forked its repositories. (#37324) (#37344)
  * Use modern "git update-index --cacheinfo" syntax to support more file names (#37338) (#37343)
  * Fix URL related escaping for oauth2 (#37334) (#37340)
  * When the requested arch rpm is missing fall back to noarch (#37236) (#37339)
  * Fix actions concurrency groups cross-branch leak (#37311) (#37331)
  * Fix bug when accessing user badges (#37321) (#37329)
  * Fix AppFullLink (#37325) (#37328)
  * Fix container auth for public instance (#37290) (#37294)
  * Enhance GetActionWorkflow to support fallback references (#37189) (#37283)
  * Fix vite manifest update masking build errors (#37279) (#37310)
  * Fix Mermaid diagrams failing when node labels contain line breaks (#37296) (#37299)
  * Use TriggerEvent instead of Event in workflow runs API response for scheduled runs (#37288) #37360
  * Add URL to Learn more about blocking a user. (#37355) #37367
  * Fix button layout shift when collapsing file tree in editor (#37363) #37375
  * Fix org team assignee/reviewer lookups for team member permissions (#37365) #37391
  * Fix repo init README EOL (#37388) #37399
  * Fix: dump with default zip type produces uncompressed zip (#37401)#37402

v1.26.0

Toggle v1.26.0's commit message

Verified

This tag was signed with the committer’s verified signature.
lunny Lunny Xiao
* BREAKING

  * Correct swagger annotations for enums, status codes, and notification state (#37030)
  * Remove GET API registration-token (#36801)
  * Support Actions `concurrency` syntax (#32751)
  * Make PUBLIC_URL_DETECTION default to "auto" (#36955)
* SECURITY
  * Bound PageSize in `ListUnadoptedRepositories` (#36884)
* FEATURES
  * Support Actions `concurrency` syntax (#32751)
  * Add terraform state registry (#36710)
  * Instance-wide (global) info banner and maintenance mode (#36571)
  * Support rendering OpenAPI spec (#36449)
  * Add keyboard shortcuts for repository file and code search (#36416)
  * Add support for archive-upload rpc (#36391)
  * Add ability to download subpath archive (#36371)
  * Add workflow dependencies visualization (#26062) (#36248) & Restyle Workflow Graph (#36912)
  * Automatic generation of release notes (#35977)
  * Add "Go to file", "Delete Directory" to repo file list page (#35911)
  * Introduce "config edit-ini" sub command to help maintaining INI config file (#35735)
  * Add button to re-run failed jobs in Actions (#36924)
  * Support actions and reusable workflows from private repos (#32562)
  * Add summary to action runs view (#36883)
  * Add user badges (#36752)
  * Add configurable permissions for Actions automatic tokens (#36173)
  * Add per-runner "Disable/Pause"  (#36776)
  * Feature non-zipped actions artifacts (action v7 / nodejs / npm v6.2.0) (#36786)
* PERFORMANCE
  * WorkflowDispatch API optionally return runid (#36706)
  * Add render cache for SVG icons (#36863)
  * Load `mentionValues` asynchronously (#36739)
  * Lazy-load some Vue components, fix heatmap chunk loading on every page (#36719)
  * Load heatmap data asynchronously (#36622)
  * Use prev/next pagination for user profile activities page to speed up (#36642)
  * Refactor cat-file batch operations and support `--batch-command` approach (#35775)
  * Use merge tree to detect conflicts when possible (#36400)
* ENHANCEMENTS
  * Implement logout redirection for reverse proxy auth setups (#36085) (#37171)
  * Adds option to force update new branch in contents routes (#35592)
  * Add viewer controller for mermaid (zoom, drag) (#36557)
  * Add code editor setting dropdowns (#36534)
  * Add `elk` layout support to mermaid (#36486)
  * Add resolve/unresolve review comment API endpoints (#36441)
  * Allow configuring default PR base branch (fixes #36412) (#36425)
  * Add support for RPM Errata (updateinfo.xml) (#37125)
  * Require additional user confirmation for making repo private (#36959)
  * Add `actions.WORKFLOW_DIRS` setting (#36619)
  * Avoid opening new tab when downloading actions logs (#36740)
  * Implements OIDC RP-Initiated Logout (#36724)
  * Show workflow link (#37070)
  * Desaturate dark theme background colors (#37056)
  * Refactor "org teams" page and help new users to "add member" to an org (#37051)
  * Add webhook name field to improve webhook identification (#37025) (#37040)
  * Make task list checkboxes clickable in the preview tab (#37010)
  * Improve severity labels in Actions logs and tweak colors (#36993)
  * Linkify URLs in Actions workflow logs (#36986)
  * Allow text selection on checkbox labels (#36970)
  * Support dark/light theme images in markdown (#36922)
  * Enable native dark mode for swagger-ui (#36899)
  * Rework checkbox styling, remove `input` border hover effect (#36870)
  * Refactor storage content-type handling of ServeDirectURL (#36804)
  * Use "Enable Gravatar" but not "Disable" (#36771)
  * Use case-insensitive matching for Git error "Not a valid object name" (#36728)
  * Add "Copy Source" to markup comment menu (#36726)
  * Change image transparency grid to CSS (#36711)
  * Add "Run" prefix for unnamed action steps (#36624)
  * Persist actions log time display settings in `localStorage` (#36623)
  * Use first commit title for multi-commit PRs and fix auto-focus title field (#36606)
  * Improve BuildCaseInsensitiveLike with lowercase (#36598)
  * Improve diff highlighting (#36583)
  * Exclude cancelled runs from failure-only email notifications (#36569)
  * Use full-file highlighting for diff sections (#36561)
  * Color command/error logs in Actions log (#36538)
  * Add paging headers (#36521)
  * Improve timeline entries for WIP prefix changes in pull requests (#36518)
  * Add FOLDER_ICON_THEME configuration option (#36496)
  * Normalize guessed languages for code highlighting (#36450)
  * Add chunked transfer encoding support for LFS uploads (#36380)
  * Indicate when only optional checks failed (#36367)
  * Add 'allow_maintainer_edit' API option for creating a pull request (#36283)
  * Support closing keywords with URL references (#36221)
  * Improve diff file headers (#36215)
  * Fix and enhance comment editor monospace toggle (#36181)
  * Add git.DIFF_RENAME_SIMILARITY_THRESHOLD option (#36164)
  * Add matching pair insertion to markdown textarea (#36121)
  * Add sorting/filtering to admin user search API endpoint (#36112)
  * Allow action user have read permission in public repo like other user (#36095)
  * Disable matchBrackets in monaco (#36089)
  * Use GitHub-style commit message for squash merge (#35987)
  * Make composer registry support tar.gz and tar.bz2 and fix bugs (#35958)
  * Add GITEA_PR_INDEX env variable to githooks (#35938)
  * Add proper error message if session provider can not be created (#35520)
  * Add button to copy file name in PR files (#35509)
  * Move `X_FRAME_OPTIONS` setting from `cors` to `security` section (#30256)
  * Add placeholder content for empty content page (#37114)
  * Add `DEFAULT_DELETE_BRANCH_AFTER_MERGE` setting (#36917)
  * Redirect to the only OAuth2 provider when no other login methods and fix various problems (#36901)
  * Add admin badge to navbar avatar (#36790)
  * Add `never` option to `PUBLIC_URL_DETECTION` configuration (#36785)
  * Add background and run count to actions list page (#36707)
  * Add icon to buttons "Close with Comment", "Close Pull Request", "Close Issue" (#36654)
  * Add support for in_progress event in workflow_run webhook (#36979)
  * Report commit status for pull_request_review events (#36589)
  * Render merged pull request title as such in dashboard feed (#36479)
  * Feature to be able to filter project boards by milestones (#36321)
  * Use user id in noreply emails (#36550)
  * Enable pagination on GiteaDownloader.getIssueReactions() (#36549)
  * Remove striped tables in UI (#36509)
  * Improve control char rendering and escape button styling (#37094)
  * Support legacy run/job index-based URLs and refactor migration 326 (#37008)
  * Add date to "No Contributions" tooltip (#36190)
  * Show edit page confirmation dialog on tree view file change (#36130)
  * Mention proc-receive in text for dashboard.resync_all_hooks func (#35991)
  * Reuse selectable style for wiki (#35990)
  * Support blue yellow colorblind theme (#35910)
  * Support selecting theme on the footer (#35741)
  * Improve online runner check (#35722)
  * Add quick approve button on PR page (#35678)
  * Enable commenting on expanded lines in PR diffs (#35662)
  * Print PR-Title into tooltip for actions (#35579)
  * Use explicit, stronger defaults for newly generated repo signing keys for Debian (#36236)
  * Improve the compare page (#36261)
  * Unify repo names in system notices (#36491)
  * Move package settings to package instead of being tied to version (#37026)
  * Add Actions API rerun endpoints for runs and jobs (#36768)
  * Add branch_count to repository API (#35351) (#36743)
  * Add created_by filter to SearchIssues (#36670)
  * Allow admins to rename non-local users (#35970)
  * Support updating branch via API (#35951)
  * Add an option to automatically verify SSH keys from LDAP (#35927)
  * Make "update file" API can create a new file when SHA is not set (#35738)
  * Update issue.go with labels documentation (labels content, not ids) (#35522)
  * Expose content_version for optimistic locking on issue and PR edits (#37035)
  * Pass ServeHeaderOptions by value instead of pointer, fine tune httplib tests (#36982)
* BUGFIXES
  * Frontend iframe renderer framework: 3D models, OpenAPI (#37233) (#37273)
  * Fix CODEOWNERS absolute path matching. (#37244) (#37264)
  * Swift registry metadata: preserve more JSON fields and accept empty metadata (#37254) (#37261)
  * Fix user ssh key exporting and tests (#37256) (#37258)
  * Fix team member avatar size and add tooltip (#37253)
  * Fix commit title rendering in action run and blame (#37243) (#37251)
  * Fix corrupted JSON caused by goccy library (#37214) (#37220)
  * Add test for "fetch redirect", add CSS value validation for external render (#37207) (#37216)
  * Fix incorrect concurrency check (#37205) (#37215)
  * Fix handle missing base branch in PR commits API (#37193) (#37203)
  * Fix encoding for Matrix Webhooks (#37190) (#37201)
  * Fix handle fork-only commits in compare API (#37185) (#37199)
  * Indicate form field readonly via background, fix RunUser config (#37175, #37180) (#37178)
  * Report structurally invalid workflows to users (#37116) (#37164)
  * Fix API not persisting pull request unit config when has_pull_requests is not set (#36718)
  * Rename CSS variables and improve colorblind themes (#36353)
  * Hide `add-matcher` and `remove-matcher` from actions job logs (#36520)
  * Prevent navigation keys from triggering actions during IME composition (#36540)
  * Fix vertical alignment of `.commit-sign-badge` children (#36570)
  * Fix duplicate startup warnings in admin panel (#36641)
  * Fix CODEOWNERS review request attribution using comment metadata (#36348)
  * Fix HTML tags appearing in wiki table of contents (#36284)
  * Fix various bugs (#37096)
  * Fix various legacy problems (#37092)
  * Fix RPM Registry 404 when package name contains 'package' (#37087)
  * Merge some standalone Vite entries into index.js (#37085)
  * Fix various problems (#37077)
  * Fix issue label deletion with Actions tokens (#37013)
  * Hide delete branch or tag buttons in mirror or archived repositories. (#37006)
  * Fix org contact email not clearable once set (#36975)
  * Fix a bug when forking a repository in an organization (#36950)
  * Preserve sort order of exclusive labels from template repo (#36931)
  * Make container registry support Apple Container (basic auth) (#36920)
  * Fix the wrong push commits in the pull request when force push (#36914)
  * Add class "list-header-filters" to the div for projects (#36889)
  * Fix dbfs error handling (#36844)
  * Fix incorrect viewed files counter if reverted change was viewed (#36819)
  * Refactor avatar package, support default avatar fallback (#36788)
  * Fix README symlink resolution in subdirectories like .github (#36775)
  * Fix CSS stacking context issue in actions log (#36749)
  * Add gpg signing for merge rebase and update by rebase (#36701)
  * Delete non-exist branch should return 404 (#36694)
  * Fix `TestActionsCollaborativeOwner` (#36657)
  * Fix multi-arch Docker build SIGILL by splitting frontend stage (#36646)
  * Fix linguist-detectable attribute being ignored for configuration files (#36640)
  * Fix state desync in ComboMarkdownEditor (#36625)
  * Unify DEFAULT_SHOW_FULL_NAME output in templates and dropdown (#36597)
  * Pull Request Pusher should be the author of the merge (#36581)
  * Fix various version parsing problems (#36553)
  * Fix highlight diff result (#36539)
  * Fix mirror sync parser and fix mirror messages (#36504)
  * Fix bug when list pull request commits (#36485)
  * Fix various bugs (#36446)
  * Fix issue filter menu layout (#36426)
  * Restrict branch naming when new change matches with protection rules (#36405)
  * Fix link/origin referrer and login redirect (#36279)
  * Generate IDs for HTML headings without id attribute (#36233)
  * Use a migration test instead of a wrong test which populated the meta test repositories and fix a migration bug (#36160)
  * Fix issue close timeline icon (#36138)
  * Fix diff blob excerpt expansion (#35922)
  * Fix external render (#35727)
  * Fix review request webhook bug (#35339) (#35723)
  * Fix shutdown waitgroup panic (#35676)
  * Cleanup ActionRun creation (#35624)
  * Fix possible bug when migrating issues/pull requests (#33487)
  * Various fixes (#36697)
  * Apply notify/register mail flags during install load (#37120)
  * Repair duration display for bad stopped timestamps (#37121)
  * Fix(upgrade.sh): use HTTPS for GPG key import and restore SELinux context after upgrade (#36930)
  * Fix various trivial problems (#36921)
  * Fix various trivial problems (#36953)
  * Fix NuGet package upload error handling (#37074)
  * Fix CodeQL code scanning alerts (#36858)
  * Refactor issue sidebar and fix various problems (#37045)
  * Fix various problems (#37029)
  * Fix relative-time RangeError (#37021)
  * Fix chroma lexer mapping (#36629)
  * Fix typos and grammar in English locale (#36751)
  * Fix milestone/project text overflow in issue sidebar (#36741)
  * Fix `no-content` message not rendering after comment edit (#36733)
  * Fix theme loading in development (#36605)
  * Fix workflow run jobs API returning null steps (#36603)
  * Fix timeline event layout overflow with long content (#36595)
  * Fix minor UI issues in runner edit page (#36590)
  * Fix incorrect vendored detections (#36508)
  * Fix editorconfig not respected in PR Conversation view (#36492)
  * Don't create self-references in merged PRs (#36490)
  * Fix potential incorrect runID in run status update (#36437)
  * Fix file-tree ui error when adding files to repo without commits (#36312)
  * Improve image captcha contrast for dark mode (#36265)
  * Fix panic in blame view when a file has only a single commit (#36230)
  * Fix spelling error in migrate-storage cmd utility (#36226)
  * Fix code highlighting on blame page (#36157)
  * Fix nilnil in onedev downloader (#36154)
  * Fix actions lint (#36029)
  * Fix oauth2 session gob register (#36017)
  * Fix Arch repo pacman.conf snippet (#35825)
  * Fix a number of `strictNullChecks`-related issues (#35795)
  * Fix URLJoin, markup render link reoslving, sign-in/up/linkaccount page common data (#36861)
  * Hide delete directory button for mirror or archive repository and disable the menu item if user have no permission (#36384)
  * Update message severity colors, fix navbar double border (#37019)
  * Inline and lazy-load EasyMDE CSS, fix border colors (#36714)
  * Closed milestones with no issues now show as 100% completed (#36220)
  * Add test for ExtendCommentTreePathLength migration and fix bugs (#35791)
  * Only turn links to current instance into hash links (#36237)
  * Fix typos in code comments: doesnt, dont, wont (#36890)
* REFACTOR
  * Clean up and improve non-gitea js error filter (#37148) (#37155)
  * Always show owner/repo name in compare page dropdowns (#37172) (#37200)
  * Remove dead CSS rules (#37173) (#37177)
  * Replace Monaco with CodeMirror (#36764)
  * Replace CSRF cookie with `CrossOriginProtection` (#36183)
  * Replace index with id in actions routes (#36842)
  * Remove unnecessary function parameter (#35765)
  * Move jobparser from act repository to Gitea (#36699)
  * Refactor compare router param parse (#36105)
  * Optimize 'refreshAccesses' to perform update without removing then adding (#35702)
  * Clean up checkbox cursor styles (#37016)
  * Remove undocumented support of signing key in the repository git configuration file (#36143)
  * Switch `cmd/` to use constructor functions. (#36962)
  * Use `relative-time` to render absolute dates (#36238)
  * Some refactors about GetMergeBase (#36186)
  * Some small refactors (#36163)
  * Use gitRepo as parameter instead of repopath when invoking sign functions (#36162)
  * Move blame to gitrepo (#36161)
  * Move some functions to gitrepo package to reduce RepoPath reference directly (#36126)
  * Use gitrepo's clone and push when possible (#36093)
  * Remove mermaid margin workaround (#35732)
  * Move some functions to gitrepo package (#35543)
  * Move GetDiverging functions to gitrepo (#35524)
  * Use global lock instead of status pool for cron lock (#35507)
  * Use explicit mux instead of DefaultServeMux (#36276)
  * Use gitrepo's push function (#36245)
  * Pass request context to generateAdditionalHeadersForIssue (#36274)
  * Move assign project when creating pull request to the same database transaction (#36244)
  * Move catfile batch to a sub package of git module (#36232)
  * Use gitrepo.Repository instead of wikipath (#35398)
  * Use experimental go json v2 library (#35392)
  * Refactor template render (#36438)
  * Refactor GetRepoRawDiffForFile to avoid unnecessary pipe or goroutine (#36434)
  * Refactor text utility classes to Tailwind CSS (#36703)
  * Refactor git command stdio pipe (#36422)
  * Refactor git command context & pipeline (#36406)
  * Refactor git command stdio pipe (#36393)
  * Remove unused functions (#36672)
  * Refactor Actions Token Access (#35688)
  * Move commit related functions to gitrepo package (#35600)
  * Move archive function to repo_model and gitrepo (#35514)
  * Move some functions to gitrepo package (#35503)
  * Use git model to detect whether branch exist instead of gitrepo method (#35459)
  * Some refactor for repo path (#36251)
  * Extract helper functions from SearchIssues (#36158)
  * Refactor merge conan and container auth preserve actions taskID (#36560)
  * Refactor Nuget Auth to reuse Basic Auth Token Validation (#36558)
  * Refactor ActionsTaskID (#36503)
  * Refactor auth middleware (#36848)
  * Refactor code render and render control chars (#37078)
  * Clean up AppURL, remove legacy origin-url webcomponent (#37090)
  * Remove `util.URLJoin` and replace all callers with direct path concatenation (#36867)
  * Replace legacy tw-flex utility classes with flex-text-block/inline (#36778)
  * Mark unused&immature activitypub as "not implemented" (#36789)
* TESTING
  * Add e2e tests for server push events (#36879)
  * Rework e2e tests (#36634)
  * Add e2e reaction test, improve accessibility, enable parallel testing (#37081)
  * Increase e2e test timeouts on CI to fix flaky tests (#37053)
* BUILD
  * Upgrade go-git to v5.18.0 (#37269)
  * Replace rollup-plugin-license with rolldown-license-plugin (#37130) (#37158)
  * Bump min go version to 1.26.2 (#37139) (#37143)
  * Convert locale files from ini to json format (#35489)
  * Bump golangci-lint to 2.7.2, enable modernize stringsbuilder (#36180)
  * Port away from `flake-utils` (#35675)
  * Remove nolint (#36252)
  * Update the Unlicense copy to latest version (#36636)
  * Update to go 1.26.0 and golangci-lint 2.9.0 (#36588)
  * Replace `google/go-licenses` with custom generation (#36575)
  * Update go dependencies (#36548)
  * Bump appleboy/git-push-action from 1.0.0 to 1.2.0 (#36306)
  * Remove fomantic form module (#36222)
  * Bump setup-node to v6, re-enable cache (#36207)
  * Bump crowdin/github-action from 1 to 2 (#36204)
  * Revert "Bump alpine to 3.23 (#36185)" (#36202)
  * Update chroma to v2.21.1 (#36201)
  * Bump astral-sh/setup-uv from 6 to 7 (#36198)
  * Bump docker/build-push-action from 5 to 6 (#36197)
  * Bump aws-actions/configure-aws-credentials from 4 to 5 (#36196)
  * Bump dev-hanz-ops/install-gh-cli-action from 0.1.0 to 0.2.1 (#36195)
  * Add JSON linting (#36192)
  * Enable dependabot for actions (#36191)
  * Bump alpine to 3.23 (#36185)
  * Update chroma to v2.21.0 (#36171)
  * Update JS deps and eslint enhancements (#36147)
  * Update JS deps (#36091)
  * update golangci-lint to v2.7.0 (#36079)
  * Update JS deps, fix deprecations (#36040)
  * Update JS deps (#35978)
  * Add toolchain directive to go.mod (#35901)
  * Move `gitea-vet` to use `go tool` (#35878)
  * Update to go 1.25.4 (#35877)
  * Enable TypeScript `strictNullChecks` (#35843)
  * Enable `vue/require-typed-ref` eslint rule (#35764)
  * Update JS dependencies (#35759)
  * Move `codeformat` folder to tools (#35758)
  * Update dependencies (#35733)
  * Bump happy-dom from 20.0.0 to 20.0.2 (#35677)
  * Bump setup-go to v6 (#35660)
  * Update JS deps, misc tweaks (#35643)
  * Bump happy-dom from 19.0.2 to 20.0.0 (#35625)
  * Use bundled version of spectral (#35573)
  * Update JS and PY deps (#35565)
  * Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 (#35557)
  * Migrate from webpack to vite (#37002)
  * Update JS dependencies and misc tweaks (#37064)
  * Update to eslint 10 (#36925)
  * Optimize Docker build with dependency layer caching (#36864)
  * Update JS deps (#36850)
  * Update tool dependencies and fix new lint issues (#36702)
  * Remove redundant linter rules (#36658)
  * Move Fomantic dropdown CSS to custom module (#36530)
  * Remove and forbid `@ts-expect-error` (#36513)
  * Refactor git command stderr handling (#36402)
  * Enable gocheckcompilerdirectives linter (#36156)
  * Replace `lint-go-gopls` with additional `govet` linters (#36028)
  * Update golangci-lint to v2.6.0 (#35801)
  * Misc tool tweaks (#35734)
  * Add cache to container build (#35697)
  * Upgrade vite (#37126)
  * Update `setup-uv` to v8.0.0 (#37101)
  * Upgrade `go-git` to v5.17.2 and related dependencies (#37060)
  * Raise minimum Node.js version to 22.18.0 (#37058)
  * Upgrade `golang.org/x/image` to v0.38.0 (#37054)
  * Update minimum go version to 1.26.1, golangci-lint to 2.11.2, fix test style (#36876)
  * Enable eslint concurrency (#36878)
  * Vendor relative-time-element as local web component (#36853)
  * Update material-icon-theme v5.32.0 (#36832)
  * Update Go dependencies (#36781)
  * Upgrade minimatch (#36760)
  * Remove i18n backport tool at the moment because of translation format changed (#36643)
  * Update emoji data for Unicode 16 (#36596)
  * Update JS dependencies, adjust webpack config, misc fixes (#36431)
  * Update material-icon-theme to v5.31.0 (#36427)
  * Update JS and PY deps (#36383)
  * Bump alpine to 3.23, add platforms to `docker-dryrun` (#36379)
  * Update JS deps (#36354)
  * Update goldmark to v1.7.16 (#36343)
  * Update chroma to v2.22.0 (#36342)
* DOCS
  * Update AI Contribution Policy (#37022)
  * Update AGENTS.md with additional guidelines (#37018)
  * Add missing cron tasks to example ini (#37012)
  * Add AI Contribution Policy to CONTRIBUTING.md (#36651)
  * Minor punctuation improvement in CONTRIBUTING.md (#36291)
  * Add documentation for markdown anchor post-processing (#36443)
* MISC
  * Correct spelling (#36783)
  * Update Nix flake (#37110)
  * Update Nix flake (#37024)
  * Add valid github scopes (#36977)
  * Update Nix flake (#36943)
  * Update Nix flake (#36902)
  * Update Nix flake (#36857)
  * Update Nix flake (#36787)