Skip to content
CAI
Software that uses CAICheck a score

go-gitea/gitea

57.3

Adequate · 6 August 2026

309.5k

lines of production code

Go

with TypeScript

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Gitea is a self-hosted Git service that manages repositories, issues, and code search. It supports a wide range of package registries, including container images, Go, and various Linux distributions. The system provides comprehensive CI/CD capabilities through GitHub Actions, with support for workflow parsing, job execution, and log storage. Additionally, it offers robust authentication methods, including LDAP, OAuth2, and WebAuthn, alongside extensive Docker and deployment tooling for production use.

How it got here

2014–2019 — Architecture modernization and infrastructure expansion

63 changes.

This period focused on modernizing the codebase's architecture by modularizing settings, routing, and various utility packages, while significantly expanding infrastructure support for Docker, SSH, and external authentication. The team also upgraded the frontend build system to Vite, replaced the Markdown parser with Goldmark, and introduced new capabilities like PAM and reCAPTCHA support.

2020–2022 — Modular architecture and package registry

86 changes.

This period focused on restructuring the codebase into a modular architecture, particularly within the models and modules directories, while introducing a comprehensive package registry supporting formats like Docker, NuGet, and Helm. The work also included significant improvements to the UI, security hardening, and the addition of new features such as passkey authentication and advanced issue tracking.

2023–2024 — Search, Actions, and Package Registry expansion

57 changes.

This period focused on expanding Gitea's core capabilities by introducing a modular Actions system for workflow automation and a comprehensive code search backend supporting multiple engines like Elasticsearch and Meilisearch. The team also significantly broadened package registry support to include Alpine, Arch Linux, and Go, while implementing distributed locking and SSH-based LFS transfer to improve scalability and security.

2025–2026 — modularization and feature expansion

17 changes.

This period focused on refactoring the codebase into a more modular structure, introducing new modules for Git attributes, globbing, and model migrations. Concurrently, significant features were added, including Terraform package support, Jupyter notebook rendering, and GitHub Actions job parsing, alongside improvements to the web editor and commit status handling.

Features

Add Alpine package metadata parsing

The Gitea application now includes a new module for parsing Alpine package metadata. This addition enables the system to extract package details such as name, version, description, license, and dependencies from Alpine package files, supporting future integration with the Alpine package registry.

modules/packages/alpine, modules/packages/maven, modules/packages/rpm · high confidence

Add Arch package registry support

Added support for parsing Arch Linux packages (.pkg.tar.zst/xz/gz) by introducing the \modules/packages/arch\ module. This includes \metadata.go\ and \metadata\_test.go\, which implement the logic to extract package metadata (name, version, description, dependencies, etc.) from the \.PKGINFO\ file within Arch packages. The implementation includes validation for package names and versions, and enforces bounds on file list sizes to prevent metadata amplification.

(repo-wide) · high confidence

Add CLI commands for managing authentication sources and actions

Administrators can now manage external authentication sources (LDAP, OAuth2, SMTP) and generate runner tokens for Actions via the command line. The \gitea admin auth\ subcommand allows adding, updating, listing, and deleting LDAP and OAuth2 authentication sources, as well as sending mail. Additionally, a new \gitea actions generate-runner-token\ command enables generating tokens for Actions runners, with support for specifying repository or global scope.

cmd · high confidence

Add Cargo HTTP index support for package registry

The system now generates and maintains a Cargo HTTP index for Rust packages. This new functionality allows users to interact with their Rust packages via the standard Cargo HTTP registry protocol, enabling seamless integration with Rust tooling. The implementation includes logic to build, update, and rebuild the index repository, ensuring that package metadata and version information are correctly exposed through the HTTP interface.

services/packages/cargo · high confidence

Add Composer package metadata parsing and validation

Users can now upload and store Composer (PHP) packages. The system parses \composer.json\ metadata (description, readme, comments, authors, license, etc.) and validates package names and versions. It supports \.zip\, \.tar.gz\, and \.tar.bz2\ archive formats for package uploads.

modules/packages/composer · high confidence

Add Conan package support

Added support for the Conan package manager, introducing new database models and search capabilities for Conan recipes and packages. This enables users to store, search, and manage Conan packages within the package registry.

models/packages/conan · high confidence

Add Debian package parsing and validation

Introduces new logic in the Debian package module to parse .deb files, extracting metadata such as package name, version, architecture, and control file contents. The implementation includes validation for package names, versions, and architectures, and restricts parsing to a single control stanza to prevent security issues where crafted control files could smuggle additional stanzas. It also handles various compression formats (gzip, xz, zstd) for the control archive and validates distribution and component names.

modules/packages/debian · high confidence

Add Docker entrypoint script for container initialization

A new entrypoint script is added to the Docker image to handle container startup tasks. It validates the Docker version to ensure compatibility with Alpine 3.14+, and dynamically adjusts the 'git' user's UID and GID in /etc/passwd and /data directories based on environment variables (USER, USER\_UID, USER\_GID). The script also ensures required directories exist and executes the s6-svscan service manager.

docker/root/usr/bin · high confidence

Add FHS-compliant wrapper script for Gitea

A new shell script at contrib/fhs-compliant-script/gitea has been added to provide a Filesystem Hierarchy Standard (FHS) compliant way to run Gitea. The script acts as a wrapper that sets default paths for the binary (/usr/lib/gitea/gitea), working directory (/var/lib/gitea), and configuration file (/etc/gitea/app.ini). It parses command-line arguments to detect if a custom config is specified; if not, it passes the default config path to the Gitea binary using exec.

contrib/fhs-compliant-script · high confidence

Add Gitea upgrade script

A new shell script, contrib/upgrade.sh, is introduced to automate the in-place upgrade of Gitea from binary distributions. The script handles downloading the new binary, verifying checksums and GPG signatures, creating a database backup, and managing the Gitea service lifecycle. It also includes a README explaining that files in subdirectories are templates.

contrib · high confidence

Add Go package registry support

Users can now upload and manage Go packages. The system validates the structure of Go module archives, ensuring that the package name and version are correctly extracted and that the version string is valid according to semantic versioning rules. This includes handling edge cases such as invalid structures, missing go.mod files, and oversized go.mod files.

modules/packages/goproxy, routers/api/packages/goproxy · high confidence

Add HTTP authentication header parsing utility

A new module at modules/auth/httpauth provides a ParseAuthorizationHeader function that parses HTTP Authorization headers into structured BasicAuth or BearerToken objects, supporting case-insensitive matching for 'basic', 'token', and 'bearer' schemes. The change includes corresponding unit tests to verify correct parsing and error handling.

modules/auth/httpauth · high confidence

Add Helm Chart metadata parsing support

Users can now parse Helm chart archives (.tgz) to extract metadata such as name, version, and dependencies from the Chart.yaml file. This new capability allows the application to validate and read Helm chart metadata, supporting features like chart registry integration.

modules/packages/helm · high confidence

Add Helm Chart registry support

Users can now store and manage Helm charts through the package registry. This change introduces new API endpoints to generate the Helm charts index, download package files, and upload new Helm chart archives, enabling integration with Helm-based CI/CD workflows.

routers/api/packages/helm · high confidence

Add Jupyter Notebook (.ipynb) rendering support

Users can now view rendered Jupyter notebooks directly in the browser. The system parses .ipynb files and renders code cells, markdown, and various output types (text, images, HTML, LaTeX) as HTML. The renderer supports nbformat 4+ and includes security measures such as disabling JavaScript execution, sanitizing HTML output, and limiting the number of rendered cells to prevent performance issues.

modules/markup/jupyter · high confidence

Add NuGet metadata and symbol extraction support

The NuGet package registry now supports parsing package metadata from .nuspec files and extracting portable PDB symbols from .snupkg files. Users can now upload NuGet packages with richer metadata (authors, description, dependencies, etc.) and upload symbol packages for debugging support.

modules/packages/nuget · high confidence

Add NuGet v2 and v3 API endpoints

The NuGet package registry now exposes full v2 (OData/Atom) and v3 (JSON) API endpoints, including service indexes, search, registration, and download routes. This enables NuGet clients to discover, search, and download packages via the standard NuGet protocol interfaces.

routers/api/packages/nuget · high confidence

Add PAM authentication support

Users can now authenticate using PAM (Pluggable Authentication Module) if the system has PAM support enabled at build time. The \modules/auth/pam\ module provides an \Auth\ function that interacts with the PAM stack for authentication and account management. When PAM is not available, a stub implementation returns an error, ensuring the application remains functional without PAM.

modules/auth/pam · high confidence

Add PyPI Simple Repository API template

A new template for the PyPI Simple Repository API (PEP 503) has been added, generating the HTML index page that lists package files with their SHA-256 hashes and Python version requirements.

templates/api/packages/pypi · high confidence

Add RPM registry and package signing support

Introduces a new RPM package registry that automatically generates and maintains repository metadata files (primary.xml, updateinfo.xml) for each package group, enabling users to consume RPM packages via standard repository tools. Additionally, the system now supports signing RPM packages with GPG keys, ensuring package integrity and authenticity for end-users.

services/packages/rpm · high confidence

Add Terraform state and lock file support

New files (lock.go, state.go) in the terraform package introduce support for parsing and managing Terraform state and lock files. Users can now store and retrieve Terraform state information (serial, lineage) and lock metadata (operation, info, who, version, path) for packages, enabling Gitea to track and manage Terraform-related package data.

modules/packages/terraform · high confidence

Add URI module to open local files and remote HTTP/HTTPS URLs

A new 'uri' module has been introduced to provide a unified way to open both local files and remote HTTP/HTTPS URLs. The module includes an 'Open' function for simple access and an 'OpenWithClient' function that allows callers to supply a custom HTTP client. This design enables stricter security controls, such as validating redirect targets to prevent Server-Side Request Forgery (SSRF) attacks, by allowing the caller to enforce policies on the HTTP client used for remote resources.

modules/uri · high confidence

Add WebAuthn module for passkey authentication

Users can now use passkeys (WebAuthn) to sign in and register for the first time, as a new webauthn module has been introduced to handle the initialization and user mapping required for this authentication method.

modules/auth/webauthn · high confidence

Add advanced label set for issue tracking

A new 'Advanced' label set has been introduced in the contrib/options directory, providing a comprehensive set of predefined labels for issue tracking. This includes status labels (e.g., Needs feedback, In progress, Completed), kind labels (e.g., Bug, Feature, Security), reviewed states (e.g., Invalid, Duplicate, Confirmed), and priority levels (High, Medium, Low, Critical), each with specific hex color codes for visual identification.

contrib/options · high confidence

Add container package metadata parsing for OCI and Helm charts

The modules/packages/container module now includes new files (const.go, metadata.go, helm/helm.go) that define constants, metadata structures, and parsing logic for container images and Helm charts. This enables the system to extract and store metadata such as image type (OCI/Docker vs Helm), platform, description, authors, licenses, and labels from container image configurations and Helm chart metadata.

modules/packages/container · high confidence

Add container package search and tag listing capabilities

A new search.go file is added to the container package models, introducing functions to retrieve container blobs by image, digest, and tag, as well as to list and sort image tags. This enables the system to query and display container image metadata, supporting the broader container package registry feature.

models/packages/container · high confidence

Add git for-each-ref parsing and formatting utilities

Introduced a new \modules/git/foreachref\ package that provides a \Format\ struct and \Parser\ to generate and parse \git for-each-ref\ output. The \Format\ type constructs the \--format\ flag string for git commands, while the \Parser\ processes the resulting output into structured maps of reference fields. This includes support for multi-line fields and configurable buffer sizes to handle large reference contents.

modules/git/foreachref · high confidence

Add global lock module for distributed locking

Introduced a new \globallock\ module that provides distributed locking capabilities for multi-instance Gitea deployments. The module supports both in-memory locking (for single-instance setups) and Redis-based locking (for distributed environments), allowing multiple Gitea instances to coordinate access to shared resources safely.

modules/globallock · high confidence

Add hCaptcha integration module

Introduces a new \modules/hcaptcha\ package that provides an hCaptcha client for verifying CAPTCHA tokens via the hCaptcha API, including error code definitions and unit tests with a mocked HTTP transport.

modules/hcaptcha · high confidence

Add mCaptcha support as a new CAPTCHA provider

Users can now use mCaptcha for form protection. This change introduces a new module in modules/mcaptcha that implements the client logic to verify CAPTCHA tokens against an mCaptcha server, including the associated unit tests.

modules/mcaptcha · high confidence

Add natural sort and base utility functions

The modules/base package now includes a natural sort implementation that correctly orders strings containing numbers (e.g., 'v1.2' before 'v1.10.0'), addressing previous sorting issues in repository tree and file lists. Additionally, the base module introduces several utility functions: \FileSize\ for human-readable file size formatting, \StringsToInt64s\/\Int64sToStrings\ for slice conversions, and \CreateTimeLimitCode\/\VerifyTimeLimitCode\ for generating and verifying time-limited codes. These changes improve the consistency of list ordering and provide reusable base utilities for the rest of the application.

modules/base · high confidence

Add orgmode markup rendering support

Users can now view Org mode (.org) files with rendered HTML output, including support for standard links, internal file links, media (images and videos), source code highlighting, and include directives. The implementation registers a new renderer that converts Org syntax to HTML, handling link resolution and media embedding, with tests verifying the rendering of links, media, and code blocks.

modules/markup/orgmode · high confidence

Add password complexity and pwned-checking utilities

The \modules/auth/password\ package was introduced, providing functions to validate password complexity against configurable character classes (lowercase, uppercase, digits, special characters) and to check passwords against the 'Have I Been Pwned' database. This includes a \Generate\ function for creating random passwords and \IsComplexEnough\ for validation, along with corresponding tests.

modules/auth/password · high confidence

Add pprof profiling module for CPU and memory dumps

A new \modules/pprof\ module has been introduced, providing functions to generate CPU and memory profile dumps. This enables the application to capture performance data to disk, supporting debugging and profiling workflows.

modules/pprof · high confidence

Add proxy module for HTTP requests and environment variables

A new proxy module has been introduced to manage HTTP proxy settings. This module provides functions to retrieve the configured proxy URL, determine if a specific host or URL should be proxied based on a list of host patterns, and return an HTTP client function that respects proxy settings or falls back to environment variables. Additionally, it offers a utility to append the proxy URL to environment variables for processes that require it.

modules/proxy · high confidence

Add pure SSH LFS support

Gitea now supports Git LFS operations (download, upload, and locking) over SSH. This change introduces a new backend implementation that translates the SSH protocol into internal HTTP requests, allowing users to perform LFS operations without requiring an HTTP server. The implementation includes a new \modules/lfstransfer\ module with backend, lock, and utility packages that handle the SSH-based LFS protocol.

modules/lfstransfer · high confidence

Add reCAPTCHA verification module

The codebase now includes a new \modules/recaptcha\ package that implements verification of Google reCAPTCHA tokens by calling the Google API. This introduces the core logic for validating reCAPTCHA responses, including error handling for specific reCAPTCHA error codes.

modules/recaptcha · high confidence

Add repository statistics correction and initialization

The models package now includes a new \repostats\ subpackage that provides functions to correct and verify repository, label, and user statistics (such as num\_watches, num\_stars, num\_issues, and num\_pulls) against the database. This includes an \Init\ function in \models/init.go\ to load unit configurations, and a \CheckRepoStats\ function that iterates through repositories and labels to fix inconsistent counters. Tests have been added to verify the consistency of fixtures and the correctness of the stats correction logic.

models, models/repostats · high confidence

Add secret encryption and decryption utilities

A new secret module has been introduced, providing AES-based encryption and decryption functions for internal use. This includes helper functions to encrypt and decrypt strings using a provided key, with specific error messages for invalid hex strings, incorrect keys, and malformed ciphertext.

modules/secret · high confidence

Add sitemap generation module

A new sitemap module has been introduced, providing the core logic for generating XML sitemaps and sitemap indexes. The implementation enforces a 50,000 URL limit per sitemap and a 50 MB file size limit to prevent excessive memory usage. This change adds the foundational components required for search engine optimization (SEO) by allowing the application to produce standard-compliant sitemaps.

modules/avatar/identicon, modules/sitemap · high confidence

Add support for Azure Blob Storage and refactor storage module

The storage module has been refactored to support multiple storage backends, including a new implementation for Azure Blob Storage alongside existing support for local and MinIO/S3 storage. This change introduces a self-registering storage system that allows different storage types to be registered and initialized independently. The implementation includes helper functions for path handling and a discard storage for uninitialized states. Tests have been added to verify the new Azure Blob storage functionality and the behavior of the storage system.

modules/storage · high confidence

Add support for Pub packages

The system now supports the Dart Pub package registry, allowing users to publish and retrieve Dart packages through the API. This introduces new endpoints for listing package versions, retrieving version metadata, and handling package uploads, effectively enabling integration with the Pub repository specification.

routers/api/packages/pub · high confidence

Add support for external frontend renderers for 3D models and OpenAPI specs

The system now supports rendering 3D model files and OpenAPI/Swagger specifications via external frontend renderers. This introduces a new \modules/markup/external\ package that registers built-in renderers for 3D models (e.g., .glb, .gltf, .obj) and OpenAPI files (.yaml, .json, .yml), as well as asciicast files. These renderers operate in an iframe to allow interactive frontend-based rendering, with content passed via base64 encoding or temp files. The change also adds a generic \Renderer\ struct to support custom external renderers defined in the configuration, enabling third-party tools to process markup files.

modules/markup/external · high confidence

Add support for hosting Alpine Linux package repositories

A new Alpine package registry has been introduced, allowing users to host and manage Alpine Linux packages. The implementation includes endpoints for retrieving repository keys, downloading package index files (with fallback to 'noarch' for cross-architecture compatibility), and uploading new package files. This adds a new package type (Alpine) to the system's package management capabilities.

routers/api/packages/alpine · high confidence

Add support for managing Terraform state files

Users can now upload, download, and manage Terraform state files through the API. This includes locking state files to prevent concurrent modifications, enforcing that the latest version cannot be deleted, and providing a read-only view of the state's lock status. The change introduces new API endpoints for state management and integrates with the package service to handle state-specific validation and locking logic.

routers/api/packages/terraform, services/packages/pkgspec, services/packages/terraform · high confidence

Add support for parsing Vagrant package metadata

The Vagrant package handler now includes a new metadata parsing module that extracts information such as author, description, project URL, and repository URL from Vagrant box files. This enables the system to read and store metadata from Vagrant packages, with corresponding unit tests added to verify the parsing logic.

modules/packages/pub, modules/packages/vagrant · high confidence

Add support for rendering terminal output with colors

Users can now view colored terminal/console output directly in the repository view. The new console renderer detects terminal escape sequences and converts them into styled HTML, allowing syntax-highlighted terminal logs to be displayed natively rather than as plain text.

modules/markup/console · high confidence

Add system app state storage and cache support

A new app state storage mechanism is introduced in the system module, providing a generic interface (StateStore) and a database-backed implementation (DBStore) for persisting application state items. This includes a RuntimeState struct for tracking runtime information such as the last application path and custom configuration. The change adds the core files (appstate.go, db.go, item\_runtime.go) and their tests, enabling future features to store and retrieve state via the database rather than memory or file system alone.

modules/system · high confidence

Add template variable expansion utility

A new \Expand\ function has been added to the \modules/templates/vars\ package, enabling the replacement of \{variable}\ placeholders in template strings with values from a provided map. This utility supports Unicode characters in variable names and gracefully handles missing or malformed syntax by returning the original template text alongside an error. The change includes comprehensive test coverage for various template scenarios.

modules/templates/vars · high confidence

Add zstd compression module with seekable support

A new \modules/zstd\ package has been introduced to provide a high-level API for reading and writing zstd-compressed data, including support for seekable zstd streams. This module wraps the \klauspost/compress/zstd\ library and the \zstd-seekable-format-go\ package, exposing options for encoder/decoder configuration and enabling partial reads via the \SeekableReader\ and \SeekableWriter\ types.

modules/zstd · high confidence

Added DB indexer stub implementation

A new DB indexer implementation has been added to the codebase, providing a basic structure for database-backed indexing. The \Indexer\ type implements the \internal.Indexer\ interface with \Init\, \Ping\, and \Close\ methods. The \Init\ method returns true to indicate the index exists, while \Ping\ and \Close\ are no-ops, reflecting the assumption that database availability is tied to the application's own health.

modules/indexer/internal/db · medium confidence

Added Gitea monitoring dashboards and service init scripts

Users can now monitor Gitea metrics via a new Grafana mixin in contrib/grafana-monitoring-mixin, which provides configurable dashboards and Prometheus alerts for Gitea's built-in metrics endpoint. Additionally, new service initialization scripts have been added for FreeBSD, Gentoo, OpenBSD, OpenWrt, and macOS (launchd) to help deploy Gitea as a background service, and sample privacy and terms-of-service HTML pages have been added to the contrib/sample-page directory.

contrib/grafana-monitoring-mixin, contrib/sample-page, contrib/service · high confidence

Added database-backed filesystem (DBFS) for storing and retrieving action logs

Introduced a new \models/dbfs\ package that implements a database-backed filesystem, allowing action logs to be stored in the database rather than the local filesystem. This enables log storage to be shared across a Gitea cluster and provides a standard file-like interface (Read/Write/Seek) for log files, supporting operations like creating, reading, writing, renaming, and removing files within the database.

models/dbfs · high confidence

Added graceful release/reopen manager

A new \releasereopen\ module has been introduced to manage the lifecycle of components that need to be reopened or released gracefully. This manager allows registering multiple \ReleaseReopener\ instances and invoking their \ReleaseReopen\ methods in a controlled manner, ensuring that all registered components are properly handled during shutdown or state transitions. The implementation includes a thread-safe manager that tracks and coordinates these operations.

modules/graceful/releasereopen · high confidence

Automated package cleanup and expired data removal

A new automated cleanup mechanism has been introduced to manage package retention policies. The system now executes defined cleanup rules to remove expired package versions based on age and keep-count settings. Additionally, it performs a cleanup of expired, unreferenced blobs and orphaned package data, ensuring that storage is reclaimed automatically.

services/packages/cleanup · high confidence

Centralize and standardize input validation rules

The validation module now provides a unified binding rule system that validates Git reference names, URLs, glob patterns, regex patterns, usernames, and badge slugs. This change introduces a centralized \AddBindingRules\ function that registers these validation rules with the HTTP request binding layer, ensuring consistent error handling and validation across the application.

modules/validation · high confidence

Centralized branch, commit status, and LFS models in models/git

The \models/git\ package now contains the core data models and their associated query logic for branches, commit statuses, LFS objects, LFS locks, and protected branches. This consolidation provides a unified interface for repository metadata, including branch listing and filtering, commit status tracking and summary, LFS object management, and branch protection rule evaluation.

models/git · high confidence

Centralized repository permission and access control logic

The repository permission and access control logic has been consolidated into the \models/perm/access\ package. This includes the \Permission\ struct and its associated methods (e.g., \CanRead\, \CanWrite\, \UnitAccessMode\) which determine user and anonymous access levels to repository units. The \access.go\ file introduces optimized database operations for managing user and team access records, while \repo\_permission.go\ handles the calculation of granular permissions for individual users, teams, and anonymous visitors. Corresponding tests in \access\_test.go\, \repo\_permission\_test.go\, and \actions\_repo\_permission\_test.go\ verify these permission calculations, including specific checks for Actions token permissions and fork PR cross-repo access restrictions.

models/perm/access · high confidence

Cloudflare Turnstile CAPTCHA integration

Added support for Cloudflare Turnstile as a CAPTCHA provider. The new \modules/turnstile\ module implements server-side verification of Turnstile tokens, including error code handling and HTTP client configuration that respects the application's proxy settings.

modules/turnstile · high confidence

Debian package search and metadata retrieval

Added search and metadata retrieval for Debian packages, enabling filtering by distribution, component, and architecture. This includes functions to list available distributions, components, and architectures, as well as searching for packages matching specific criteria.

models/packages/debian · high confidence

Enable default CSV file rendering in the browser

CSV and TSV files are now rendered as interactive HTML tables by default, allowing users to view structured data directly in the repository view. The renderer automatically detects the delimiter (comma, semicolon, etc.) and limits output to a configurable maximum file size and row count, displaying a warning with a link to the raw file if the content is too large to display fully.

modules/markup/csv · high confidence

Expanded package registry support with new search and metadata models

The packages model layer now includes dedicated search and descriptor files for Alpine, Arch, Conda, CRAN, NuGet, and RPM registries, alongside core models for package blobs, uploads, cleanup rules, and properties. This adds the ability to query and filter packages by registry-specific attributes (such as branches, repositories, architectures, channels, and groups) and provides structured metadata handling for each supported package type.

models/packages · high confidence

Implement git-based code search using git grep

Added a new git-based code search implementation in the gitgrep module, introducing the PerformSearch function to execute git grep searches with support for exact, word, and regex modes, and the indexSettingToGitGrepPathspecList helper to map indexer settings to git pathspecs. A corresponding test file was added to verify the pathspec list generation.

modules/indexer/code/gitgrep · high confidence

Import and integrate the Gitea Actions job parser

The \modules/actions/jobparser\ package has been added to Gitea, providing the core logic for parsing and evaluating GitHub Actions workflows. This includes the \jobparser\ module which handles parsing workflow YAML, evaluating expressions, and managing job states. The package includes new files such as \evaluator.go\ for expression evaluation, \interpeter.go\ for interpreter setup, \model.go\ for data structures, and \uses.go\ for parsing reusable workflow references. Tests are also included in \jobparser\_test.go\ and related test data files to ensure correct parsing and round-trip serialization of workflows.

modules/actions/jobparser · high confidence

Internal API and proxy protocol support

The modules/private package now provides a structured internal API client for inter-process communication, including functions for Git hooks (pre-receive, post-receive, proc-receive), SSH key management, email sending, manager commands (shutdown, restart, logging control), and Actions runner token generation. The internal request handling has been refactored to use a shared HTTP transport that correctly handles local (Unix socket or loopback) versus remote connections, skipping TLS verification only for local targets to prevent MITM attacks on internal tokens. Additionally, the proxyprotocol package has been introduced to support HAProxy Proxy Protocol v1/v2, allowing Gitea to correctly identify client IPs when running behind a proxy.

modules/private · high confidence

Introduce Arch Linux package repository support

Users can now host Arch Linux packages within Gitea. This change adds the core repository logic, including version comparison (vercmp) and signing capabilities using the ProtonMail/go-crypto library, enabling the creation and management of Arch-style package indexes.

services/packages/arch · high confidence

Introduce CurrentUsername utility for OS user detection

A new user module has been added to the codebase, providing a CurrentUsername function that retrieves the current operating system user. The implementation prioritizes the standard library's user.Current() method, with a fallback to environment variables (USER/USERNAME) for compatibility. A corresponding test suite verifies the function's behavior across different environments.

modules/user · high confidence

Introduce Docker templates for Gitea configuration and SSH daemon

Added new template files for the Docker image: app.ini, which configures Gitea's runtime settings (including SSH, database, and logging), and sshd\_config, which sets up the OpenSSH server with environment-variable-driven parameters (such as port, log level, and user restrictions). These templates enable dynamic configuration of the application and SSH service at container startup.

docker/root/etc/templates · high confidence

Introduce Git pipeline abstractions for LFS and object listing

The \modules/git/pipeline\ package now provides dedicated functions for Git operations, including \FindLFSFile\ to locate commits containing specific LFS pointer hashes, \RevListObjects\ to list objects between commits, and \CatFileBatch\ helpers for batched object retrieval. These changes introduce a new pipeline-based interface for these Git commands, supported by corresponding unit tests.

modules/git/pipeline · high confidence

Introduce HTML utility helpers for safe HTML generation

A new \htmlutil\ module is added, providing safe HTML generation utilities. This includes an \HTMLBuilder\ for constructing HTML strings with automatic escaping, an \HTMLWriter\ for streaming HTML output, and helper functions like \HTMLFormat\ and \EscapeString\ to ensure proper HTML escaping and formatting. These tools are intended to reduce manual escaping errors in template rendering.

modules/htmlutil · high confidence

Introduce Prometheus metrics collector for Gitea

A new Prometheus metrics collector is introduced in the modules/metrics package, exposing a comprehensive set of Gitea system statistics. The collector defines descriptors for core entities such as users, repositories, issues, and comments. Notably, it separates open and closed issues into distinct metrics, adds breakdowns for issues by label and repository, and includes build information. The users metric is extended with a 'state' label, and project boards are exposed as 'projects\_boards'.

modules/metrics · high confidence

Introduce SVG badge generation for CI/CD status

A new \modules/badge\ package has been added to generate SVG badges for CI/CD status indicators. This includes the core logic for calculating text width and rendering badges, along with a comprehensive map of DejaVu font glyph widths to ensure accurate layout. The implementation supports both 'flat' and 'flat-square' styles, allowing the system to display build and action statuses with consistent, scalable graphics.

modules/badge · high confidence

Added new modules/git/url/url.go and url\_test.go files that provide structured parsing for Git URLs (including HTTP(S), SSH, and file schemes) and generate web links for repositories. This introduces the ParseGitURL and ParseRepositoryURL functions, enabling the system to correctly interpret various Git remote URLs and extract owner, repository, and remaining path components for internal use.

modules/git/url · high confidence

Introduce a new Gitea-specific profiling and tracing module

A new \modules/gtprof\ package has been added to provide a Gitea-specific profiling and tracing system, distinct from standard pprof or GNU gprof. This includes a \Tracer\ for managing trace spans with hierarchical context propagation, a \TraceSpan\ model with attributes and events, and a built-in memory-based message recorder (\modules/tailmsg\) to capture and store trace logs. The module supports pluggable trace starters, allowing integration with external tracing systems, and includes a test suite to verify span hierarchy and context propagation.

modules/gtprof · high confidence

Introduce abstract JSON interface to support Go 1.22+ experimental JSON v2

The \modules/json\ package now provides an abstract interface for JSON handling, allowing the application to switch between the standard library's \encoding/json\ (v1) and the new \encoding/json/v2\ (v2) via build tags. This change enables users to opt into the experimental JSON v2 library by setting the \goexperiment.jsonv2\ build tag, which changes serialization behavior (e.g., handling of nil slices/maps and case-insensitive unmarshalling) while maintaining backward compatibility for existing code. The module also includes a helper function \UnmarshalHandleDoubleEncode\ to work around specific XORM-related encoding issues.

modules/json · high confidence

Introduce centralized HTTP caching and ETag support

A new \modules/httpcache\ package is added, providing a centralized way to handle HTTP caching headers. This includes setting \Cache-Control\ headers (supporting public/private, max-age, and no-cache modes) and implementing ETag-based caching with \If-None-Match\ and \If-Modified-Since\ header validation. The implementation also supports weak ETag matching, allowing requests with weak validators (prefixed with 'W/') to be correctly identified as not modified, returning a 304 Not Modified response when appropriate.

modules/httpcache · high confidence

Introduce configurable file and folder icon themes

The file icon module has been refactored to support distinct icon themes for files and folders. A new 'material' theme provides rich, context-aware icons for files and folders based on file names, extensions, and language IDs, while the existing 'basic' theme provides simple octicon-based icons. Users can now configure separate themes for files (UI.FileIconTheme) and folders (UI.FolderIconTheme) via settings, allowing for a more visually rich file tree view.

modules/fileicon · high confidence

Introduce database-backed session storage

A new database-backed session provider (DBProvider) is added to modules/session, allowing sessions to be persisted in the application database rather than only in memory, Redis, or files. The implementation includes DBStore and DBProvider structs that handle reading, writing, and garbage-collecting session data via the auth package, and registers itself as "db". This enables users to configure their session store to use the database for session persistence.

modules/session · high confidence

Introduce dedicated module for generating cryptographic secrets and keys

A new \modules/generate\ package has been added to centralize the generation of cryptographic secrets and keys. This includes functions for creating internal tokens and JWT secrets using the \golang-jwt/jwt/v5\ library, as well as generating RSA, ECDSA, and ED25519 SSH keys with enforced minimum bit-lengths defined in the new \modules/consts/asymkey.go\. The module also provides utilities for decoding and validating base64-encoded JWT secrets, ensuring consistent security standards across the application.

modules/generate · high confidence

Introduce dedicated test logger for structured test output

A new \modules/testlogger\ package has been added to provide a dedicated logger for tests. This logger captures log output during test execution and writes it to the testing log, ensuring that log messages are associated with the correct test context. The implementation includes a \TestLogEventWriter\ that routes logs to the test runner, and an \Init\ function to register the writer. This change improves test output clarity by preventing log messages from being lost or misattributed, and includes safeguards against data races and timeout handling for slow tests.

modules/testlogger · high confidence

Introduce file-backed buffer utility

Added a new \filebuffer\ module that provides a \FileBackedBuffer\ type, which keeps data in memory up to a configurable size and automatically spills to a temporary file when the limit is exceeded. This utility implements standard Go interfaces (\io.ReadWriteCloser\, \io.ReadSeekCloser\, \io.ReaderAt\) and includes corresponding unit tests.

modules/util/filebuffer · high confidence

Introduce hostmatcher module for HTTP request validation

A new \hostmatcher\ module has been added to enforce allow and block lists for HTTP requests, providing stricter control over outbound connections. The module introduces support for \external\, \private\, and \loopback\ network categories, along with CIDR and wildcard pattern matching. It includes a comprehensive set of reserved IP ranges (such as cloud metadata endpoints and CGNAT) to prevent SSRF attacks, ensuring that internal or reserved addresses cannot be accessed via the public internet. This module is used to secure HTTP transports by validating hosts and IPs against configured policies.

modules/hostmatcher · high confidence

Introduce internal HTML attribute protection and final processing

Added new internal modules (finalprocessor.go, renderinternal.go) and tests (internal\_test.go) to handle safe attribute rendering and HTML post-processing. The RenderInternal struct generates a secure ID to prefix class attributes (e.g., data-attr-class), which are later recovered and restored to their original values during the final processing stage. This mechanism ensures that HTML attributes are safely handled and that extra head content can be injected into the output. The implementation includes logic to detect HTML, replace protected attributes with their original values, and manage the output buffer.

modules/markup/internal · high confidence

Introduce internal code indexer interface and data models

The code indexer module now defines a new internal package containing the core interface and data structures for code search. This includes the \Indexer\ interface with methods for indexing, deleting, and searching code, as well as the \SearchOptions\ struct that allows filtering by repository, keyword, language, and search mode. New data models such as \SearchResult\, \SearchResultLanguages\, and \RepoChanges\ are introduced to support these operations. A dummy implementation is also provided for testing or fallback purposes.

modules/indexer/code/internal · high confidence

Introduce internal issue indexer model and interface

The \modules/indexer/issues/internal\ package now provides the core data structures and interface for issue indexing. \IndexerData\ defines the fields stored in the index, including support for filtering by \is\_archived\ status, multiple \project\_ids\, and various user IDs (assignee, mention, review). \SearchOptions\ enables searching by keyword, filtering by state (closed, pull request), labels, projects, and sorting by creation/update time or comment count. A \dummyIndexer\ implementation is also included for testing or fallback purposes.

modules/indexer/issues/internal · high confidence

Introduce internal modules for package storage, hashing, and PyPI metadata

The \modules/packages\ directory now includes new internal utilities to support package registries. A \ContentStore\ wrapper is added to manage blob storage and direct serving URLs. A \HashedBuffer\ and \MultiHasher\ are introduced to compute MD5, SHA1, SHA256, and SHA512 checksums for package content. Additionally, a \BoundedFileList\ is provided to safely track file entries in package archives, and a \Metadata\ struct is defined for PyPI package information.

modules/packages · high confidence

Introduce layered asset filesystem with embedded and local layers

The \modules/assetfs\ package has been refactored to support a layered filesystem architecture. This introduces a new \LayeredFS\ that can stack multiple asset sources, such as embedded bindata and local filesystem directories, allowing the system to prioritize embedded assets while falling back to local files. The change includes a new \embed.go\ implementation for handling embedded assets and a \layered.go\ module that manages the layering logic, along with comprehensive tests for both embedded and layered file system operations.

modules/assetfs · high confidence

Introduce mdstripper module for markdown text extraction

Added a new mdstripper module that parses Markdown content using the Goldmark library to extract plain text and collect links. This new component enables the system to strip all markup and code blocks from Markdown input, facilitating the extraction of clean text and associated references.

modules/markup/mdstripper · high confidence

Introduce modular Actions support for workflows, logs, and event matching

The \modules/actions\ package now provides core infrastructure for Gitea Actions, including workflow detection and parsing, scoped workflow support, log management, and GitHub event matching. New files include \artifacts.go\ for building HMAC signatures for artifacts, \commit\_status\_info.go\ for mapping commit statuses to action jobs, \github.go\ for mapping GitHub webhook events to Gitea's internal event types, \log.go\ for handling task logs (writing, reading, transferring, and removing), \scoped\_workflows.go\ for listing and matching workflows in custom directories, \task\_state.go\ for managing task and step states, and \workflows.go\ for listing, validating, and detecting workflows. Tests are added for all new modules.

modules/actions · high confidence

Introduce new CSV parsing module

A new \modules/csv\ package has been added to handle CSV file parsing and delimiter detection. This module provides functions to create CSV readers with specific delimiters, automatically determine the correct delimiter from file content or extension (supporting .csv, .tsv, and .psv), and format parsing errors for users.

modules/csv · high confidence

Introduce new LFS client and content store abstractions

The \modules/lfs\ package is restructured with new abstractions for LFS clients and content storage. A \Client\ interface and \ContentStore\ are introduced to manage LFS operations, with separate \HTTPClient\ and \FilesystemClient\ implementations for network and local storage. The \ContentStore\ now handles object verification by validating content hashes and sizes during upload. Additionally, the \BasicTransferAdapter\ is added to handle standard HTTP-based LFS transfers.

modules/lfs · high confidence

Introduce new database models for Actions artifacts, runs, jobs, and job summaries

The models/actions package now includes new database models and their associated query helpers for Actions artifacts, run attempts, job lists, and job summaries. This adds the underlying data structures and persistence logic for tracking workflow runs, individual job executions, artifact storage metadata, and step-level job summaries (GITHUB\_STEP\_SUMMARY). The changes also include test coverage for job status aggregation and matrix sorting logic.

models/actions · high confidence

Introduce new references module for parsing issue/PR references

The \modules/references\ package has been introduced to handle the parsing and processing of cross-references to issues, pull requests, and commits. This new module defines the core logic for identifying and extracting references from text, including support for numeric and alphanumeric issue identifiers, cross-repository references, and commit SHA references. The implementation includes regex patterns for various reference formats and provides functions to find all issue references within a given text, enabling features like automatic issue closing/reopening based on keywords and URL-based references.

modules/references · high confidence

Introduce password breach checking via Have I Been Pwned

Users can now have their passwords checked against the Have I Been Pwned database to detect if a password has been compromised in a data breach. This new module provides a client to query the HIBP API, allowing the system to identify and warn about passwords that appear in known breaches.

modules/auth/password/pwn · high confidence

Introduce process manager for tracking and managing background processes

The \modules/process\ package now provides a centralized process manager that tracks background operations via a context-based system. This allows the application to monitor active processes, retrieve their stack traces for debugging, and manage their lifecycle (including cancellation and timeout handling). The implementation includes platform-specific handling for Unix (setting process groups to avoid zombies) and Windows, along with a new error type for execution failures.

modules/process · high confidence

Introduce scoped template execution with isolated function maps

A new \scopedtmpl\ module provides a \ScopedTemplate\ type that allows registering global template functions and then creating isolated \TemplateExecutor\ instances for specific templates. Each executor carries its own function map, enabling concurrent template rendering with different context-specific functions without cross-contamination. The implementation includes a test verifying that concurrent executions using different function maps produce distinct, correct outputs, and another confirming that HTML escaping is correctly applied to template content.

modules/templates/scopedtmpl · medium confidence

Introduce snap packaging for Gitea

Added snap packaging infrastructure for Gitea, including a snapcraft.yaml configuration and build/pull scripts. This enables Gitea to be distributed as a Snap package, supporting amd64 and arm64 architectures with strict confinement. The build process uses Go 1.26 and Node 24, and the snap includes support for removable media.

snap · high confidence

Introduce structured issue template support

A new template parsing and validation system has been added to the \modules/issue\ module, enabling users to define issue forms with various field types (markdown, textarea, input, dropdown, checkboxes) and attributes (labels, descriptions, default values, visibility). This allows repositories to provide structured issue submission forms with customizable fields, including support for dropdowns with default values and comma-delimited labels.

modules/issue · high confidence

Introduce system setting and app state models with caching

Added new models for system settings and application state, including a cached getter for system settings that invalidates its cache when the database revision changes. The system setting model includes a version field that increments on each update, and the app state model provides a mechanism to store and retrieve application-wide state in the database.

models/system · high confidence

Introduces a new config value retrieval system

The modules/setting/config package now provides a new mechanism for retrieving configuration values, featuring a generic Option type that supports dynamic and file-based configuration sources. This change introduces getter interfaces and a caching mechanism for system settings, allowing for more flexible and efficient access to configuration data across the application.

modules/setting/config · high confidence

Introduces a new web routing and middleware system

The \modules/web\ package has been refactored to provide a new, more flexible routing and middleware system. This includes a new \Router\ implementation wrapping \go-chi/chi/v5\ with support for pre-middlewares, route grouping, and path pattern matching. A key addition is the \RouterMockPoint\ and \RouteMock\ APIs, which allow developers to inject mock handlers at specific points in the middleware chain during testing, simplifying the process of mocking route execution in unit tests.

modules/web · high confidence

Introduces an LRU-cache wrapper for compiled regular expressions

A new \modules/regexplru\ package is added, providing a \GetCompiled\ function that caches compiled \regexp.Regexp\ objects in a Least Recently Used (LRU) cache. This change improves performance by avoiding repeated compilation of frequently used regular expressions, with a corresponding test suite verifying caching behavior and error handling.

modules/regexplru · high confidence

Introduces internal indexer and pagination utilities

The indexer module now includes new internal packages: a base36 encoding helper, a basic Indexer interface with a dummy implementation, and a paginator parser that converts db.ListOptions into skip/limit values for search queries.

modules/indexer/internal · high confidence

Maven package registry implementation

Added support for the Maven package registry, including routing, metadata generation, and file serving logic. This introduces new endpoints for downloading and providing headers for Maven packages, handling metadata XML responses, and managing checksums (MD5, SHA1, SHA256, SHA512) for package files.

routers/api/packages/maven · high confidence

Meilisearch indexer implementation added

The Meilisearch backend for the indexer module has been implemented, introducing new files for filtering, indexing, and utility functions. This adds support for searching, filtering, and paging issues via Meilisearch, including versioned index management and health checks.

modules/indexer/internal/meilisearch · high confidence

Meilisearch-based issue indexer implementation

The Meilisearch-based issue indexer has been implemented, introducing a new search backend for issues. This change adds support for filtering issues by assignee, archived status, and multiple projects, while also enabling search mode configuration and pagination limits. The implementation includes the core indexer logic, test coverage, and integration with the Meilisearch client.

modules/indexer/issues/meilisearch · high confidence

Migrate frontend build system from Webpack to Vite

The project has switched its frontend build tooling from Webpack to Vite. This change affects how static assets, JavaScript, and CSS templates are compiled and served. Users will benefit from faster development server startup times and improved hot-reload capabilities during development. The migration also involves updating the corresponding build configuration files and template references to align with the new Vite-based pipeline.

templates · high confidence

New Elasticsearch code indexer implementation

A new Elasticsearch-based code indexer has been introduced in the codebase, providing the underlying storage and search logic for code search features. The implementation includes the core indexer logic and a corresponding test suite, enabling users to perform code searches using the Elasticsearch backend.

modules/indexer/code/elasticsearch · high confidence

New activity and notification models for the dashboard and user feeds

The \models/activities\ package now contains the core data models and query logic for user activity feeds and notifications. This includes the \Action\ model representing various repository events (commits, issues, PRs, etc.) and the \Notification\ model for tracking user notifications. New functions have been added to load, filter, and paginate activity feeds and notifications, supporting features like the user dashboard, activity heatmaps, and real-time notification updates. Tests have been added to verify the behavior of these new models and their interactions with the database.

models/activities · high confidence

New build tools for generating assets and API specs

Added new build scripts to generate bindata, emoji data, gitignore files, Go license information, and OpenAPI 3.0 specifications. The \generate-bindata.go\ script creates embedded asset bundles, while \generate-emoji.go\ fetches and processes emoji data from the gemoji repository, supporting skin tones and Unicode 16. The \generate-gitignores.go\ script downloads and extracts GitHub's official gitignore templates, with optional GitHub API token authentication. The \generate-go-licenses.go\ script replaces the external \google/go-licenses\ dependency with a custom Go implementation that scans module dependencies for license files. Additionally, \generate-openapi.go\ and its associated \openapi3gen\ package convert Swagger 2.0 specifications to OpenAPI 3.0, extracting shared enum types and fixing schema formats. A new \update-locales.sh\ script manages locale file cleanup and organization.

build · high confidence

New generic container utilities: Set type and FilterSlice function

The container module now includes a generic Set type that supports adding, removing, and checking for elements, as well as set operations like union. Additionally, a new FilterSlice function is available to filter and deduplicate slices based on a provided inclusion function.

modules/container · high confidence

New generic optional type with serialization support

A new \modules/optional\ package introduces a generic \Option\[T\]\ type that can hold a value or be empty (None). This type supports JSON and YAML serialization/deserialization, allowing optional fields to be cleanly represented in API responses and configuration files. The package also includes helper functions like \ParseBool\ and \FromPtr\ to convert values into the optional type.

modules/optional · high confidence

New modular editor and form components

The codebase introduces a suite of new, modular components for the web interface: a unified Markdown editor (ComboMarkdownEditor) that consolidates toolbar actions, text expansion, and file upload handling; a reusable confirmation modal (ConfirmModal); an avatar cropper (Cropper); a quick-submit handler for forms (QuickSubmit); and specialized modules for label editing, search boxes, and scoped workflow configuration. These components replace previous ad-hoc implementations, providing a consistent, type-safe, and testable foundation for user interactions like editing content, submitting forms, and managing repository settings.

_web\src/js/features/comp · high confidence

New paginator module for consistent pagination UI

A new \modules/paginator\ package has been introduced to standardize pagination logic across the application. This module provides a \Paginator\ struct and a \Page\ type that calculate page numbers, determine if 'Previous'/'Next' buttons should be shown, and generate a list of page numbers to display in templates. This enables a consistent pagination experience in the user interface, such as on the user dashboard and file commit history lists.

modules/paginator · high confidence

New request context abstraction for request-scoped data

A new \modules/reqctx\ package has been introduced to provide a structured way to store and retrieve request-specific data within the application's context. This change introduces a \RequestContext\ interface and a \RequestDataStore\ mechanism that allows components to safely store and retrieve data associated with the current HTTP request, replacing previous ad-hoc context usage patterns.

modules/reqctx · high confidence

New rotating file writer utility for log management

A new \rotatingfilewriter\ module has been introduced to handle log file rotation, supporting size-based and daily rotation, optional GZIP compression of old files, and cleanup of expired backups. This replaces the previous logger system with a dedicated utility that manages file descriptors, handles concurrent access safely, and integrates with the application's graceful shutdown process.

modules/util/rotatingfilewriter · high confidence

New update checker module for remote version detection

A new \modules/updatechecker\ package has been introduced to handle checking for new Gitea versions. This module fetches the latest version from a remote JSON endpoint, stores the result in the application state, and provides functions to compare the remote version against the currently installed version to determine if an update is available.

modules/updatechecker · high confidence

Refactor auth models into the models/auth package

The authentication models have been reorganized into the models/auth package. This includes the AccessToken, AuthToken, OAuth2Application, Session, Source, and TwoFactor models, along with their corresponding test files. This change consolidates all authentication-related data models and their database interactions into a single, dedicated package, improving code organization and maintainability.

models/auth · high confidence

Refactor issue and comment models into the models/issues package

The issue and comment models have been reorganized into the models/issues package, introducing dedicated files for assignees, comments, content history, and dependencies. This change improves code structure and performance by consolidating related logic, adding new database tables (e.g., issue\_assignees, issue\_content\_history), and implementing features like issue pinning, content history tracking, and dependency management.

models/issues · high confidence

Refactored password hashing into a modular, configurable system

The password hashing module has been restructured to support multiple algorithms (Argon2, Bcrypt, PBKDF2, Scrypt) with configurable parameters. This change allows administrators to select and tune the strength of password hashing algorithms, improving security by enabling stronger defaults and allowing for future algorithm updates without breaking existing hashes.

modules/auth/password/hash · high confidence

Replace Monaco with CodeMirror for web-based code editing

The web-based code editor has been migrated from Monaco to CodeMirror, introducing a new command palette for quick access to editor actions, a context menu with options like 'Go to Definition' and 'Change All Occurrences', and improved language detection for various file types. The new editor also features a command palette accessible via F1, a context menu with navigation and editing options, and enhanced syntax highlighting and linting capabilities.

_web\src/js/modules/codeeditor · high confidence

Restructure Docker image publishing with multi-arch and rootless support

The Docker build and release process has been restructured to support multi-architecture images (amd64, arm64, and riscv64) and a separate rootless variant. The new manifest templates (manifest.tmpl and manifest.rootless.tmpl) define platform-specific image tags for these architectures, ensuring that nightly and release builds are published with the correct architecture suffixes. This change enables users to pull pre-built images for a wider range of hardware, including ARM and RISC-V platforms, while maintaining a distinct 'rootless' image for enhanced security.

docker · high confidence

Secrets storage with SecretKey encryption

Secrets are now stored in the database in encrypted form, using the system's SECRET\_KEY for encryption. This change introduces the \models/secret\ package, which handles the creation, update, and retrieval of encrypted secrets. The implementation includes logic to scope secrets to organizations, users, or repositories, and provides functions to insert and update encrypted secret data. Additionally, the codebase adds tests for the secret scoping and inheritance logic, ensuring that secrets are correctly scoped and that inherited secrets are properly filtered based on the caller's secrets policy.

models/secret · high confidence

Support for Swift package registry metadata parsing

Added support for parsing Swift package metadata from uploaded archives. The system now extracts package details such as description, keywords, license, repository URLs, and author information from a JSON metadata file included in the package. It also parses the \Package.swift\ manifest files to determine the Swift tools version. This enables Gitea to serve as a Swift package registry, providing structured metadata about Swift packages hosted on the platform.

modules/packages/swift · high confidence

Support for YAML-based label templates with color validation

The label module now supports loading label templates from YAML files, allowing for more structured and maintainable label definitions. The system validates hex color codes during template parsing, ensuring that all colors are normalized to a 6-character hex format. This change introduces a new \Label\ struct with support for exclusive labels and descriptions, and includes tests for both the new YAML parser and the legacy text-based format.

modules/label · high confidence

Support for multiple commit authors in commit views

Commit pages now display an 'avatar stack' showing all participants (authors and co-authors) for a commit, rather than just the primary author. This is achieved by introducing new model types (CommitParticipant, AvatarStackData) that aggregate all git identities associated with a commit and map them to Gitea users, enabling the UI to render multiple avatars for a single commit.

models/gituser · high confidence

Track pull request review state and auto-merge scheduling

The system now persists each user's file-level review state (viewed, unviewed, or changed) for pull requests, enabling accurate tracking of which files have been reviewed. Additionally, the platform supports scheduling pull requests for automatic merging once all checks succeed, with options to delete the branch after the merge.

models/pull · high confidence

Updated file icon mappings for improved visual identification

The file icon configuration has been updated with new mappings for folder and SVG file types, including Rust, Cargo, CSS, Sass, and various framework-specific icons (e.g., Angular, Azure, Astro). This change enhances the visual distinction of files and directories in the repository tree and file list views, making it easier to identify file types at a glance.

options · high confidence

Vite frontend build integration and asset manifest support

The public module now supports Vite-based frontend builds. A new manifest parser resolves hashed asset paths from the Vite build output, enabling correct static asset URLs in production. In development, a middleware proxies requests to the Vite dev server, allowing hot-reloading and source-level asset serving. The system also handles CSS link generation for Vite entries and falls back to static asset paths for custom themes not present in the manifest.

modules/public · high confidence

Security

Enforce two-factor authentication (2FA) for all users

Users are now required to enable two-factor authentication (TOTP or WebAuthn) to access their accounts. This change enforces 2FA as a security measure, requiring users to configure a second authentication factor before they can log in or perform actions.

services · high confidence

Hardened locale middleware against Accept-Language DoS and improved form validation

The locale middleware now bounds the length of the Accept-Language header to prevent a quadratic-time denial-of-service vulnerability in the language parser. Additionally, new middleware files (binding, cookie, data, flash, locale) provide robust form validation, cookie management, and flash message handling, ensuring that user-facing error messages and form data are correctly mapped and displayed.

modules/web/middleware · high confidence

Improved detection and escaping of ambiguous and invisible Unicode characters

The \modules/charset\ package has been refactored to improve the detection and escaping of ambiguous and invisible Unicode characters. A new \ambiguous.go\ file introduces a locale-aware system for identifying ambiguous characters (e.g., visually similar characters that could be used for spoofing), with generated data in \ambiguous\_gen.go\ and corresponding tests in \ambiguous\_gen\_test.go\. The \escape\_stream.go\ implementation now uses these tables to identify and escape invisible and ambiguous characters in HTML output, controlled by the \UI.AmbiguousUnicodeDetection\ setting. This change enhances security by mitigating risks associated with bidirectional text and invisible characters, while also improving the rendering of plain text files containing non-ANSI or ambiguous characters.

modules/charset · high confidence

Architecture

Centralized API request and response models

The API request and response models have been moved from the root of the codebase into the \modules/structs\ package. This refactoring consolidates all API-related structs, including those for webhooks, issues, pull requests, and user management, into a single, organized location. This change improves code maintainability and ensures that all API payloads and responses are defined in one place, making it easier to update and validate API contracts.

modules/structs · high confidence

Consolidate repository logic into the modules/repository package

Repository-related functions such as branch synchronization, commit handling, repository creation, deletion, forking, and initialization have been moved from the models and services layers into the new modules/repository package. This change centralizes repository management logic, making it easier to maintain and test, and provides a cleaner separation between domain models and utility functions.

modules/repository · high confidence

Refactor and modularize settings into dedicated configuration files

The configuration loading logic for various subsystems (Actions, Admin, API, Attachments, Cache, etc.) has been extracted from the monolithic \setting.go\ into separate, dedicated files (e.g., \actions.go\, \admin.go\, \api.go\). This modularization improves code maintainability and testability by isolating the loading and validation of each subsystem's settings. The changes include the addition of new configuration options such as \DEFAULT\_Actions\_URL\, \USERS\_DISABLED\_FEATURES\, and \SWAGGER\_URL\, alongside the removal of legacy or unused settings.

modules/setting · high confidence

Refactor code indexer into a dedicated module

The code indexer implementation has been moved from the root of the \modules/indexer\ directory into a new \modules/indexer/code\ subdirectory. This refactoring organizes the code search and indexing logic into a dedicated package, separating it from other indexer types and improving codebase structure.

modules/indexer/code · high confidence

Refactor markup rendering into modular processor files

The markup rendering logic has been refactored from a monolithic structure into separate, focused files (e.g., html.go, html\_link.go, html\_issue.go) to improve maintainability and testability. This change introduces a modular processor pipeline where each component (links, issues, mentions, emojis, etc.) is handled by a dedicated processor function. The \PostProcessDefault\ and \PostProcessCommitMessage\ functions now explicitly define the order of these processors, ensuring consistent rendering behavior across different contexts like commit messages and wiki pages.

modules/markup · high confidence

Refactor project model into dedicated sub-package

The project model code has been reorganized into a new \models/project\ sub-package, splitting the logic into separate files for columns (\column.go\), issues (\issue.go\), and templates (\template.go\), accompanied by corresponding unit tests (\\*\_test.go\). This structural change improves code maintainability and aligns the project model with the codebase's modular architecture.

models/project · high confidence

Refactor web route handler and router structure

The internal routing structure has been refactored, moving towards a cleaner separation of concerns between web and API routes. This change improves the maintainability of the codebase and supports future enhancements to the web interface. Users will experience a more stable and consistent routing behavior across the application.

routers · high confidence

Reorganize organization and team models into a dedicated subpackage

The organization and team model logic has been moved from the root models package into a new models/organization subpackage. This refactoring groups all organization-related structs (Organization, Team, OrgUser, TeamInvite, etc.) and their associated test files into a single directory, improving code organization and reducing circular dependencies. The functionality for managing organizations, teams, and their members remains the same, but the code is now structured to better reflect the domain boundaries.

models/organization · high confidence

The repository model, along with associated types and functions for attachments, avatars, collaboration, forks, git operations, issues, language stats, licenses, mirrors, and organization repositories, has been moved into the new \models/repo\ sub-package. This refactoring consolidates repository-related data access and model logic into a dedicated package, improving code organization and separation of concerns within the application's data layer.

models/repo · high confidence

Rewrite the queue module with a new modular architecture

The queue module has been completely rewritten to introduce a modular backend architecture. The new design separates the queue implementation into a common interface (baseQueue) and distinct backend implementations: channel (in-memory), LevelDB, and Redis, each with their own base implementation files (base\_channel.go, base\_levelqueue.go, base\_redis.go). A new manager (manager.go) centralizes the creation and lifecycle of managed queues, while a worker pool system (workerqueue.go, workergroup.go) handles concurrent processing. This refactoring improves testability and allows for different queue storage backends to be swapped or extended more easily.

modules/queue · high confidence

User model refactored into the models/user package

The user-related model logic, including avatars, badges, blocking, email addresses, external logins, following, and redirects, has been moved into the models/user package. This refactoring organizes the codebase by moving these components from their previous locations into a dedicated sub-package, improving maintainability and separation of concerns.

models/user · high confidence

Webhook model and task logic moved to models/webhook package

The webhook data models, including the Webhook and HookTask structs, along with their associated database operations and test files, have been restructured into the models/webhook package. This change organizes the codebase by moving webhook-related code into a dedicated sub-package, improving modularity and separation of concerns for webhook delivery and task management.

models/webhook · high confidence

Behavioural changes

Add OpenID discovery cache and SSRF protection for OpenID requests

The OpenID authentication module now caches OpenID provider discovery information with a 24-hour TTL, improving performance by reducing repeated network calls. Additionally, the OpenID client is now protected against Server-Side Request Forgery (SSRF) attacks by validating that requests do not target internal, loopback, or reserved addresses, ensuring compliance with the operator's ALLOWED\_HOST\_LIST settings.

modules/auth/openid · high confidence

A new \path\ token filter has been added to the Bleve indexer. This filter processes file paths to generate tokens for each component of the path (e.g., \foo/bar/baz\ generates \foo\, \foo/bar\, and \foo/bar/baz\), and also generates reversed paths. This enables searching for files by partial path segments or filenames without needing the full path, improving code search capabilities.

modules/indexer/code/bleve/token · high confidence

Admin panel JavaScript modules converted to TypeScript

The JavaScript files in the admin feature directory (common, config, selfcheck, users) have been converted to TypeScript, introducing strict typing and helper utilities (e.g., ConfigFormValueMapper for system config forms). This conversion includes adding tests for the config form value mapping logic and implementing specific admin UI behaviors like bulk runner actions and user list search form handling with TypeScript.

_web\src/js/features/admin · high confidence

Admin task model and migration decryption logic moved to models/admin

The \Task\ model, which manages administrative tasks and handles decryption of migration credentials (including AWS secrets), has been moved into the \models/admin\ package. This change organizes the codebase by separating admin-related models and their associated logic, such as \MigrateConfig\ and \LoadRepo\/\LoadDoer\/\LoadOwner\ helper methods, into a dedicated sub-package.

models/admin · high confidence

Centralized configuration for repository unit defaults and disabled features

The repository unit configuration has been consolidated into the \models/unit\ package, introducing explicit defaults for new repositories (Code, Issues, Pull Requests, Releases, Wiki, Projects, Packages, and Actions) and specific defaults for forks, mirrors, and templates. Administrators can now globally disable specific repository units (such as Issues or Actions) via the \Repository.DisabledRepoUnits\ setting, and override the default enabled units for new repositories using \Repository.DefaultRepoUnits\. The system also enforces that at least one unit remains enabled and handles invalid or duplicate configuration keys gracefully.

models/unit · medium confidence

Database connection and collation handling refactored into the models/db package

The database connection logic, context management, and collation checking have been consolidated into the models/db package. Users will see improved handling of database collations for MySQL and MSSQL, with automatic detection and warning logs if case-sensitive collation is not used. Additionally, connection string generation and driver registration for PostgreSQL, SQLite, and MSSQL have been centralized, ensuring consistent database initialization and error handling across all supported database types.

models/db · high confidence

Database-backed issue indexer implementation

The issue indexer now uses a database-backed implementation (modules/indexer/issues/db) to handle searching, filtering, and paging of issues. This change introduces support for filtering by assignee, searching by issue ID, and sorting by exclusive labels (issue priority), while also including public repositories in the dashboard issue search and fixing sorting and counting bugs in the project issues list.

modules/indexer/issues/db · medium confidence

Decouple unit test code from business code

The \models/unittest\ package has been refactored to decouple test utilities from the main application codebase. This includes moving consistency checks, fixture loading, and assertion helpers into a dedicated \unittest\ package. The fixture loader now uses a generic interface (\FixturesLoader\) with an internal implementation, allowing for future vendor-based loaders. Additionally, a new \MockServerOptions\ struct and \NewMockWebServer\ function are introduced to facilitate HTTP server mocking in tests, and a \reflection\ helper is added to simplify accessing struct fields via reflection. These changes improve test maintainability and reduce coupling between test code and production code.

models/unittest · high confidence

Docker entrypoint script updated with default paths

The Docker image now includes a new shell script at /usr/local/bin/gitea that sets default values for GITEA\_WORK\_DIR and GITEA\_CUSTOM to /data/gitea, and executes the Gitea binary located at /app/gitea/gitea. This change ensures that the containerized application uses the correct working directory and custom path by default.

docker/root/usr/local · high confidence

Docker image configuration updates

The Docker image now includes a new /etc/nsswitch.conf file to configure name resolution and user/group lookups, and adds a /etc/s6/.s6-svscan/finish script to handle service scanning termination.

docker/root/etc, docker/root/etc/s6/.s6-svscan · low confidence

Extracted AccessMode type and parsing logic into models/perm

The AccessMode type, along with its constants (None, Read, Write, Admin, Owner) and the ParseAccessMode function, have been moved from their previous location into the models/perm package. This refactoring centralizes access mode definitions and their string conversion and parsing logic, making them more easily reusable across the codebase. A corresponding test file has been added to verify the parsing and string conversion behavior.

models/perm · high confidence

Improved Docker container startup and configuration handling

The Docker image now uses s6-init for more robust service management, ensuring all services stop cleanly when Gitea stops. The startup script (setup) now correctly sets permissions for .ssh and authorized\_keys to prevent SSH clone/push/pull failures. It also supports the GITEA\_CUSTOM environment variable for custom configuration, allows SSH\_LISTEN\_PORT configuration, and uses environment variables to generate app.ini via envsubst. Additionally, the container includes a finish script to manage s6-svscanctl for proper shutdown.

docker/root/etc/s6/gitea · medium confidence

Improved accessibility and fixed dropdown behavior

Added an accessibility reference document and implemented ARIA patches for Fomantic UI components to improve screen reader support. Specifically, the dropdown module was patched to handle literal text values (such as 'false') correctly and to hide empty dividers, while the modal module was updated to prevent form submission issues and reset forms on hide. Additionally, a new tab switcher was introduced to manage tabbed interfaces, and the transition module was refactored to support CSS-based animations.

_web\src/js/modules/fomantic · high confidence

Improved file type detection for SVG, AVIF, and OGG formats

The typesniffer module now provides more accurate content-type detection for several file formats. SVG images are correctly identified even when surrounded by HTML or XML headers. AVIF images are detected via the ISO base media file format header. OGG files are distinguished as either audio or video based on their internal headers (e.g., 'theora' for video). Additionally, the sniffer now correctly handles MP3 files with ID3 headers, ensuring that text files with ID3 tags are not misidentified as audio.

modules/typesniffer · high confidence

Internal SSH server initialization and host key management refactored

The internal SSH server startup and host key management have been restructured into dedicated modules (init.go, ssh.go, ssh\_graceful.go). The SSH module now handles the creation of the TrustedUserCAKeys file and directory, manages graceful server lifecycle, and provides functions to generate and initialize default host keys (RSA, ECDSA, ED25519). This change improves the reliability of the built-in SSH server by ensuring proper initialization and cleanup, while also adding tests for key generation and initialization.

modules/ssh · medium confidence

Introduce SVG icon processing and caching

The modules/svg package now includes a processor that normalizes SVG content by stripping XML headers, comments, and unnecessary attributes, while enforcing default width and height. The SVG rendering system has been refactored to cache processed SVGs in memory, improving performance for icon rendering. Tests have been added to verify the normalization logic and caching behavior.

modules/svg · high confidence

Introduce a shared search mode configuration for indexers

A new indexer module has been added to define and manage search mode configurations. This introduces a standardized set of search modes (exact, words, fuzzy, and regexp) that can be reused across different indexer implementations, ensuring consistent search behavior and reducing code duplication.

modules/indexer · medium confidence

Issue search now supports filtering by assignee

The Bleve-based issue indexer has been refactored to support searching, filtering, and paging. A key new capability is the ability to filter issues by assignee, allowing users to find issues assigned to specific users or to filter for unassigned issues. The indexer now maps and indexes fields such as \assignee\_ids\, \is\_archived\, \is\_closed\, and \is\_public\, enabling more granular search queries. The implementation includes a custom analyzer for issue indexing and handles fuzziness in search queries dynamically based on keyword length.

modules/indexer/issues/bleve, modules/indexer/issues/elasticsearch · high confidence

Migrate GPG and SSH key models to the new error system

The \models/asymkey\ package now uses a dedicated error types (e.g., \ErrKeyUnableVerify\, \ErrKeyNotExist\) that wrap standard errors like \util.ErrNotExist\ and \util.ErrAlreadyExist\. This change ensures that key-related errors are properly unwrapped and handled by the application's error system, improving error reporting and consistency across the codebase.

models/asymkey · high confidence

Migrate admin authentication source templates to Go templates

The admin authentication source templates for LDAP, OAuth2, SMTP, and SSPI have been converted from the legacy template format to Go templates. This change updates the user interface for configuring these authentication sources, ensuring consistent rendering and improved maintainability of the admin settings pages.

templates/admin/auth · high confidence

Migrate i18n locale storage from INI to JSON format

The i18n module now loads locale data from JSON files instead of the previous INI format. This change introduces a new \LocaleStore\ implementation that parses JSON-based translation files, supporting both string and HTML-safe translation keys. The \TrString\ and \TrHTML\ methods now rely on this new store, which also provides fallback to a default language and improved handling of template arguments. Tests confirm that JSON-based locale loading and translation retrieval work correctly.

modules/translation/i18n · medium confidence

Migrate repository stats indexing to a database-backed implementation

The repository statistics indexer has been refactored to use a database-backed approach (DBIndexer) instead of previous methods. This change introduces a new \modules/indexer/stats\ package containing \db.go\, \indexer.go\, \queue.go\, and associated tests. The \DBIndexer\ now handles the logic for calculating and saving language statistics to the database, including checks for empty repositories and missing default branches. The implementation leverages the \context.Context\ for database operations and integrates with the existing queue system for asynchronous updates.

modules/indexer/stats · high confidence

Migrate tools and configs to TypeScript and enforce Node.js 22.18.0

The \tools/\ directory has been migrated from JavaScript to TypeScript, and the project now requires Node.js version 22.18.0 or higher. This migration includes new TypeScript implementations for CI label synchronization (\ci-tools.ts\), ESLint rules (\unescaped-html-literal.ts\), and various asset generation scripts (\generate-codemirror-languages.ts\, \generate-images.ts\, \generate-svg.ts\, \generate-svg-vscode-extensions.json\).

tools · high confidence

Migration module refactored into modular components with schema validation

The migration module has been restructured into distinct, focused files (e.g., comment.go, issue.go, downloader.go) that define standard data structures and interfaces for importing and exporting repository data. A new validation layer has been introduced, using JSON Schema definitions (in schemas/) to verify the integrity of migration files during the import process, ensuring that required fields are present and correctly typed. This change improves the reliability of the migration process by catching malformed or incomplete data early, and provides a cleaner, more maintainable codebase for handling different types of repository data like issues, pull requests, and releases.

modules/migration · high confidence

New modular emoji processing with Unicode 16 support and skin tone variants

The emoji module has been refactored into a new, standalone package (modules/emoji) that replaces the previous implementation. This update expands the emoji dataset to include Unicode 16 and adds support for skin tone variants, ensuring more accurate detection and rendering of emojis. The new implementation utilizes a Trie-based approach for efficient emoji detection and replacement, and includes a comprehensive test suite to verify lookup, replacement, and indexing functionality.

modules/emoji · high confidence

OpenSSH container startup and configuration logic restructured

The Docker container's OpenSSH service is now managed via new s6-service scripts (finish, run, setup) that handle host key generation, certificate loading, and sshd\_config templating. This change introduces support for configurable SSH ports, host certificates, MaxStartups, MaxSessions, and extra sshd\_config parameters via environment variables, while also ensuring the service waits before restarting on failure.

docker/root/etc/s6/openssh · medium confidence

Redesign of the Docker rootless image entrypoint and configuration handling

The Docker rootless image now uses a new entrypoint script that validates the Docker version compatibility with Alpine 3.14+ and executes a new setup script. The setup script initializes directories (home, custom, temp) with 0700 permissions and generates the app.ini configuration file from environment variables. A new \environment-to-ini\ helper bridges environment variables to the INI file, and a wrapper script ensures the correct working directory and config path are passed to the Gitea binary.

docker/rootless/usr · high confidence

Refactor avatar logic into a dedicated models/avatars package

Avatar generation and management code has been moved from the root models package into a new models/avatars package. This change includes the implementation of avatar link generation, email hashing, and Libravatar URL construction within this new package, along with corresponding unit tests for hashing and link generation.

models/avatars · high confidence

Refactor container registry implementation into dedicated router files

The container registry API handlers have been refactored from a single file into separate modules for blobs, manifests, and general container operations. This change improves code organization and maintainability of the container registry feature, with no change to the external API or user-facing behavior.

routers/api/packages/container · high confidence

Refactor dump module to use mholt/archives

The dump module has been refactored to use the github.com/mholt/archives library for creating archives. This change introduces support for multiple archive formats including zip, tar, tar.sz, tar.gz, tar.xz, tar.bz2, tar.br, tar.lz4, and tar.zst. The new implementation provides a more robust and flexible way to create dump archives with various compression options.

modules/dump · high confidence

Refactor git module to use a shared cat-file batch process

The git module now uses a shared, long-lived \git cat-file\ process to efficiently retrieve object info and content, replacing the previous per-request command spawning. This change introduces new files in the \modules/git\ package, including \catfile\_batch.go\ and its command/legacy implementations, along with \archive.go\, \blame.go\, \blob.go\, and \branch.go\. Users benefit from improved performance and resource management when accessing repository contents, blame history, and branch information, as the system reuses the same git process for multiple operations within a request context.

modules/git · high confidence

Refactor graceful shutdown and restart logic

The graceful module has been refactored to improve shutdown reliability and restart behavior. Key changes include: adding a new context-based API (ShutdownContext, HammerContext, TerminateContext) for managing shutdown phases; implementing the systemd-notify protocol for status reporting and watchdog support; ensuring graceful restart works for Unix sockets; fixing panics during wrappedConn close and shutdown waitgroup errors; and making the internal SSH server host key path configurable. The manager now handles signal processing (SIGHUP, SIGUSR1, SIGUSR2, SIGINT, SIGTERM) more robustly, and the Windows service implementation has been updated to support immediate hammering.

modules/graceful · high confidence

Refactor model migration system into a decoupled package

The model migration logic has been refactored into a new \modelmigration\ package, separating it from the existing \models\ package to improve code organization and maintainability. This change introduces a new \base\ subpackage containing shared migration utilities such as \RecreateTables\ for safely rebuilding database tables, \HashToken\ for secure token hashing, and \DropTableColumns\ for schema updates. The migration registry in \migrations.go\ now orchestrates a comprehensive set of database schema changes, including adding columns for branch protection, updating webhook headers, fixing commit status URLs, and cleaning up orphaned data. Test fixtures have been added to verify the correctness of these migrations against various database states.

modelmigration · high confidence

Refactor options module to use unified asset layering

The options module is restructured to provide a unified view of static assets by layering custom user-provided files over built-in defaults. The new \AssetFS()\ function combines these layers, allowing components to read locale, readme, gitignore, license, and label data from either embedded bindata or the local filesystem depending on build tags. This change simplifies how the application accesses and overrides built-in static content.

modules/options · high confidence

Refactor time formatting and timestamp handling in the timeutil module

The timeutil module has been refactored to improve time formatting and timestamp handling. A new \since.go\ file introduces a \timeSincePro\ function that generates localized, human-readable relative time strings (e.g., '1 hour, 2 minutes') by leveraging the \translation.Locale\ interface. The \TimeStamp\ and \TimeStampNano\ types in \timestamp.go\ and \timestampnano.go\ have been updated to support localization-aware time conversion and formatting, including the addition of \AsTimeInLocation\ methods and improved \IsZero\ checks. These changes ensure that time displays are consistent, localized, and correctly handle zero-time edge cases.

modules/timeutil · medium confidence

Refactor translation module with JSON locale files and new Locale interface

The translation module has been refactored to support JSON-based locale files instead of the previous format, and introduces a new \Locale\ interface with methods like \Tr\, \TrN\, and \PrettyNumber\. A \MockLocale\ implementation is provided for testing, and the \InitLocales\ function now loads translations from JSON files, sorting supported languages by name. The \translation.go\ file defines the core logic for locale initialization, language matching, and number formatting, while \translation\_test.go\ adds tests for the \PrettyNumber\ functionality.

modules/translation · high confidence

Refactored Bleve code indexer to support filename search and improved text analysis

The Bleve code indexer has been refactored to support searching by filename, with a dedicated analyzer and tokenizer for filename fields. The indexer now distinguishes between text and non-text files, ensuring that non-text files are still indexed by name while their content is excluded. Additionally, the implementation introduces a custom Unicode normalization token filter and specific analyzers for repository data and filenames, enhancing search relevance and accuracy.

modules/indexer/code/bleve · high confidence

Refactored Bleve indexer with batched operations and dynamic fuzziness

The Bleve indexer implementation has been refactored to improve performance and search accuracy. A new FlushingBatch component automatically flushes index operations to the underlying store once a batch limit is reached, optimizing write performance. Additionally, the system now dynamically calculates search fuzziness based on keyword length and character type, applying a maximum fuzziness of 2 for standard keywords while disabling fuzziness for non-letter characters (such as CJK or file extensions) to prevent false positives.

modules/indexer/internal/bleve · high confidence

Refactored Git attribute handling with new module

The \modules/git/attribute\ package was introduced to centralize and refactor Git attribute management. This new module provides structured types and helper methods for parsing and querying Git attributes, including support for Linguist and GitLab-specific attributes. The refactoring includes a batch checker for efficient attribute retrieval and a single-checker for individual file checks, both of which handle context cancellation and error reporting more robustly. Tests were added to verify the new attribute parsing and checking logic.

modules/git/attribute · high confidence

Refactored Git command execution and error handling

The Git command execution layer has been refactored to improve security and error management. The \gitcmd\ package now enforces strict separation between trusted and dynamic arguments, preventing command injection risks by validating that dynamic arguments do not start with a dash. Error handling has been standardized with a new \RunStdError\ interface that explicitly captures and exposes stderr output, making it easier to parse Git's error messages. Additionally, the \Command\ struct now manages context and pipeline cancellation more robustly, and the codebase has been reorganized to move Git command logic into the \modules/git/gitcmd\ directory.

modules/git/gitcmd · high confidence

Refactored HTTP request and response handling in the httplib module

The httplib module has been refactored to use the standard Go HTTP library for making requests, introducing a new Request builder with context, transport, and timeout support. Additionally, file serving and header management have been consolidated into new functions (ServeSetHeaders, ServeUserContentByReader) that handle Content-Disposition encoding, Content-Security-Policy headers for different content types, and HTTP range requests, with comprehensive tests added for these behaviors.

modules/httplib · high confidence

Refactored Markdown parsing by extracting and customizing Goldmark components

The Markdown rendering engine was migrated from blackfriday to goldmark, with the core parsing logic for footnotes and linkification extracted into the common markup module. This refactoring allows for custom ID generation (preserving underscores in auto-generated IDs) and improved handling of URL and email linkification, resulting in more consistent and correct rendering of user-generated content.

modules/markup/common · high confidence

Refactored and expanded the util package with new utility functions and tests

The modules/util package was refactored and expanded with a suite of new utility functions and corresponding tests. This includes a new error handling system with translatable error wrappers, file operation retry logic for handling busy files, and helpers for path joining and validation. Additional utilities were added for color contrast calculation, key pair generation, data packing/unpacking, slice diffing, and time formatting. The refactoring also introduces a generic map value retrieval function and improves existing IO and sanitization helpers.

modules/util · high confidence

Refactored authentication source implementations

The authentication source implementations for local database, LDAP, and OAuth2 have been refactored to use a new interface-based structure. This change introduces dedicated packages for each source type (db, ldap, oauth2) with separate files for configuration, authentication logic, and provider registration. The refactoring ensures that each source type properly implements the expected interfaces (PasswordAuthenticator, Config, etc.) without breaking import cycles, and adds interface assertion tests to guarantee compatibility.

services/auth · high confidence

Refactored avatar processing and hashing logic

The avatar module was refactored to support multiple image formats (PNG, JPEG, GIF, and WebP) and to enforce stricter validation, including maximum width and height limits. The \processAvatarImage\ function now explicitly checks for supported MIME types and rejects unsupported formats like SVG. Additionally, the \HashAvatar\ function was introduced to generate unique hashes for avatars using SHA-256, ensuring distinct outputs for different unique IDs.

modules/avatar · high confidence

Refactored cache module with new abstractions and implementations

The cache module has been refactored to introduce a new \StringCache\ interface and a context-level ephemeral cache. The refactoring includes a new \cachegroup\ package that defines cache key groups for users, emails, and GPG keys. The implementation now supports Redis and in-memory backends with improved error handling for cached errors and safer cache key generation.

modules/cache · high confidence

Refactored code syntax highlighting module

The code highlighting module has been refactored to use the Chroma library (v2.3.0) for syntax highlighting, replacing the previous implementation. This change introduces a new \modules/highlight\ package containing \highlight.go\ for rendering code, \lexerdetect.go\ for lexer detection and mapping, and associated benchmark and unit tests. The refactoring improves performance by caching lexer lookups and ensures consistent syntax highlighting across file views, diffs, and blame pages.

modules/highlight · high confidence

Refactored container package registry implementation

The container package has been refactored to improve code organization and fix concurrency issues. A new BlobUploader component was introduced to handle chunked blob uploads, addressing a data race that occurred during concurrent uploads. Additionally, cleanup logic for expired blob uploads and uploaded blobs has been reorganized into dedicated functions, and helper functions for updating repository names and parsing manifest metadata have been added to the common module.

services/packages/container · high confidence

Refactored issue indexer with new internal structure and tests

The issue indexer module has been refactored, introducing new internal structures for search options and indexer initialization. The change includes a new \dboptions.go\ file that handles the conversion of search options, and an \indexer.go\ file that manages the global indexer state and queue processing. Additionally, \indexer\_test.go\ has been added to provide comprehensive test coverage for the DB-based issue search functionality, ensuring that keyword, ID, repository, and other filters work correctly.

modules/indexer/issues · high confidence

Refactored math rendering in Markdown to support block and inline math

The math rendering logic in the Markdown processor has been refactored into a dedicated \math\ package, introducing new AST nodes and parsers for both block-level (e.g., \$$...$$\) and inline (e.g., \$...$\) math expressions. This change restructures how math content is parsed and rendered, ensuring that math blocks are correctly identified and processed without interfering with surrounding text. The implementation adds specific parsers for dollar signs and square brackets, along with corresponding renderers that output the appropriate HTML structure for math content.

modules/markup/markdown/math · high confidence

Refactored router logging and request tracking

The router logging system has been refactored to use a new \requestRecord\-based architecture. This introduces a dedicated middleware (\NewRequestInfoHandler\) that tracks request lifecycle events, enabling more granular logging of request start, slow query detection (via a background goroutine), and end-of-request status. The \FuncInfo\ struct and associated helper functions have been extracted into \funcinfo.go\ to manage function metadata for log messages. Additionally, the \context.go\ file adds support for marking long-polling requests and updating panic errors in the context, improving observability for specific request types.

modules/web/routing · high confidence

Refactored template rendering system with new utility modules

The template rendering system has been refactored to improve maintainability and functionality. A new expression evaluator module (modules/templates/eval) was added to support dynamic template expressions. Template helper functions have been reorganized into dedicated utility files (util\_date, util\_avatar, util\_actions, etc.) and grouped logically. The HTML renderer now provides prettier error messages that highlight the specific line and position of template compilation or execution errors. Additionally, the template system now supports hot-reloading of templates in development mode, allowing developers to see changes immediately without restarting the server.

modules/templates · high confidence

Refactored webhook event system with granular event types

The webhook module has been restructured to support a more granular and comprehensive set of webhook events. The new system distinguishes between specific pull request review states (approved, rejected, commented) and includes dedicated event types for workflow runs and jobs, as well as issue and pull request metadata changes (assign, label, milestone). This allows users to configure webhooks to trigger on more specific conditions, such as individual review outcomes or workflow job statuses, rather than broad categories.

modules/webhook · medium confidence

Refined vendor and language detection in the analyze module

The analyze module now provides more accurate identification of vendored directories and code languages. The IsVendor function has been updated to exclude specific paths (such as .gitignore, .gitattributes, .github, and .gitea) from being marked as vendored, ensuring these files are not treated as third-party dependencies. Additionally, the module introduces new functions for detecting code language based on file name and content, and for identifying generated code, improving the precision of code analysis in diffs and statistics.

modules/analyze · medium confidence

Replace external glob library with internal implementation

The \modules/glob\ package has been replaced with a new internal implementation, removing the dependency on the \gobwas/glob\ package. This change improves performance by using \strings.Builder\ for regular expression compilation and ensures the codebase relies on internal utilities rather than external dependencies.

modules/glob · high confidence

Replaced Elasticsearch client with native HTTP REST API for indexing and searching

The internal Elasticsearch indexer has been refactored to use the standard Go HTTP client for the REST API instead of the previous third-party library. This change enables support for both Elasticsearch and OpenSearch clusters, as the implementation targets the shared REST subset for Elasticsearch 7/8/9 and OpenSearch 3. The new \Indexer\ struct manages HTTP connections, handles index creation and health checks, and constructs query DSLs for search operations.

modules/indexer/internal/elasticsearch · medium confidence

Reworked Actions and Admin UI with new CSS modules

The Actions and Admin pages now feature a modernized interface with improved layout and styling. The Actions page introduces a new CSS module (web\_src/css/actions.css) that styles the runner list, run list items, and workflow groups, while the Admin page receives a new CSS module (web\_src/css/admin.css) for horizontal definition lists and table overflow handling. Additionally, the Avatar component gains a new CSS module (web\_src/css/avatar.css) that styles the avatar stack with hover-spread animations and overflow chips. These changes enhance the visual consistency and usability of the CI/CD and administrative sections.

_web\src · high confidence

Rewrite markdown rendering to use Goldmark

The markdown rendering engine has been replaced with Goldmark, introducing support for new features such as KaTeX math rendering, color previews in code spans, and attention blocks (e.g., \> \[!NOTE\]) with corresponding icons. The system now parses YAML frontmatter to render metadata as tables or collapsible details, and supports relative links for commits, mentions, and issues. Additionally, the implementation includes improved handling of task list checkboxes, code block styling, and table alignment.

modules/markup/markdown · high confidence

Rewrite the logging system with an event-driven architecture

The logging module has been rewritten to use an event-driven architecture, introducing a new \EventWriter\ interface and \LoggerImpl\ that dispatches log events to multiple writers (console, file, network) via channels. This refactoring improves performance by reducing allocations and allows for better control over log formatting, colorization, and pausing. The change includes new files for colorized console output, file rotation, and connection-based logging, alongside tests for the new formatting and level handling.

modules/log · high confidence

Treat commit status warnings as failures in combined state

The logic for combining multiple commit statuses has been updated so that a warning state now results in an overall failure status, aligning the combined state with the API and UI. The \Combine\ method in the \commitstatus\ module now treats warnings as failures, and the corresponding tests have been added to verify this behavior.

modules/commitstatus · high confidence

Unified NoSQL connection management for Redis and LevelDB

The NoSQL module has been refactored to use a centralized connection manager that handles both Redis and LevelDB connections. This change introduces a unified approach to managing database connections, supporting advanced Redis features like Sentinel authentication, cluster configurations, and TLS options. The refactoring also includes improved error handling for malformed connection strings and prevents potential deadlocks by managing LevelDB locks more effectively.

modules/nosql · high confidence

Updated asset bundles for code highlighting, emojis, and licensing

The \assets\ directory now includes newly generated or updated data files: \codemirror-languages.json\ for web-based code syntax highlighting, \emoji.json\ for supported emoji characters and aliases, and \go-licenses.json\ for third-party Go dependency licenses. Additionally, a new \favicon.svg\ file has been added to the assets. These changes update the static resources used by the application's UI and compliance tracking.

assets · high confidence

Fixes

Refactored markup rendering context for repository content

The \models/renderhelper\ package was restructured to provide dedicated rendering contexts for different types of repository content. New helper structs—\RepoComment\, \RepoFile\, \RepoWiki\, and \SimpleDocument\—each implement the \markup.RenderHelper\ interface to handle link resolution and commit ID validation specific to their context (e.g., resolving relative links against the correct base path for files, comments, or wiki pages). This change ensures that rendered content, such as commit messages, file views, and wiki pages, correctly resolves internal links and handles edge cases like deleted repositories.

models/renderhelper · medium confidence

Test coverage

Add SHA-256 test repositories for Git; Add e2e tests for file rendering and real-time events; Add unit tests for the paginator package; Added empty Git repository fixture for testing; Added test fixture for commit-between scenarios; Added test fixture for git repository with submodules; Added test fixture for language stats; Added test fixture for pull request \#4; Added test fixtures for Git merge scenarios; Added test fixtures for git notes functionality; Added test fixtures for git repository state; Added test repository for git blame functionality; Added tests for the issues indexer; New test helper utilities for file, log, and Redis operations.

Dependencies

Updated Go and JavaScript dependencies

The project's Go dependencies have been updated, including golang.org/x/crypto to v0.54.0, golang.org/x/net to v0.57.0, and google.golang.org/grpc to v1.82.1. Additionally, the Node.js build environment has been upgraded to require version 22.18.0 or higher, and the package manager has been switched to pnpm v11.18.0.

(dependencies) · high confidence

Housekeeping

Updated changelog for Gitea v1.27.1

The changelog has been updated to include release notes for version 1.27.1, ensuring that users are informed about the changes and improvements in this latest release.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 57.

Lenses

  • Code Health 80
  • Architecture 100
  • Maturity 75
  • Readiness 76
  • Security 74
  • Domain Modelling 45
  • Accessibility 57

Changes since last survey

  • 300 commits — 154 feature/other, 146 fixes

By area

  • (root) — 58 commits
  • web_src/js — 28 commits
  • options/locale — 23 commits
  • .github/workflows — 22 commits
  • modules/git — 19 commits
  • routers/web — 19 commits
  • services/actions — 12 commits
  • models/actions — 10 commits
  • routers/api — 10 commits
  • web_src/css — 8 commits
  • templates/repo — 7 commits
  • modules/actions — 5 commits
  • services/repository — 5 commits
  • services/webhook — 5 commits
  • tests/integration — 5 commits
  • models/issues — 4 commits
  • modules/gitrepo — 4 commits
  • services/gitdiff — 4 commits
  • modules/packages — 3 commits
  • .github/actions — 2 commits

Notable commits

  • fix: build: fix snapcraft release (#38260)
  • fix: chore(ci): fix renovate custom manager regex (#38656)
  • fix: chore: fix git diff render (#38746)
  • fix: ci: fix jq broken pipe in cache-prune (#38734)
  • fix: enhance(ui): tweak tooltip style and misc fixes (#38524)
  • fix: fix(actions): address workflow status badge review feedback (#38241)
  • fix: fix(actions): align status icon span for Safari rendering (#38558)
  • fix: fix(actions): allow Actions bot to push to protected branches (#38284)
  • fix: fix(actions): authenticate snapcraft before nightly remote build (#38252)
  • fix: fix(actions): cancel tasks immediately when the runner stopped reporting (#38616)
  • fix: fix(actions): coerce workflow_dispatch boolean inputs to native types (#38472)
  • fix: fix(actions): correctness and hardening fixes (#38518)
  • fix: fix(actions): deny fork-PR cross-repo access via collaborative owner (#38214)
  • fix: fix(actions): don't swallow HTML entities into linkified URLs (#38239)
  • fix: fix(actions): dynamic matrix expansion correctness fixes (#38690)
  • fix: fix(actions): ensure all waiting jobs get runners in large workflows (#38200)
  • fix: fix(actions): explain why a blocked or waiting job has not started (#38476)
  • fix: fix(actions): fail unexpandable reusable workflow callers and decouple the job emitter's cross-run processing (#38565)
  • fix: fix(actions): fix 500 error when canceling a canceling task (#38223)
  • fix: fix(actions): fix runner docs link (#38783)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

go-gitea/gitea was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d8c3a1afda60459094b8dd4cf110b6375100b3b5 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.