Revisions of forgejo
- update to 7.0.4: * Fixed: CVE-2024-24789: the archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. * the OAuth2 implementation does not always require authentication for public clients, a requirement of RFC 6749 Section 10.2 * forgejo migrate-storage --type actions-artifacts always fails because it picks the wrong path. * avatar files can be found in storage while they do not exist in the database. * repository admins are always denied the right to force merge and instance admins are subject to restrictions to merge that must only apply to repository admins. * non conformance with the Nix tarball fetcher immutable link protocol. * migrated activities (such as reviews) are mapped to the user who initiated the migration rather than the Ghost user, if the external user cannot be mapped to a local one. This mapping mismatch leads to internal server errors in some cases. * a v7.0.0 regression causes [admin].SEND_NOTIFICATION_EMAIL_ON_NEW_USER=true to always be ignored. * using a subquery for user deletion is a performance bottleneck when using mariadb 10 because only mariadb 11 takes advantage of the available index. * a v7.0.3 regression causes the expanding diffs in pull requests to fail with a 404 error. * SourceHut Builds webhook fail when the triggers field is used. * the label list rendering in the issue and pull request timeline is displayed on multiple lines instead of a single one. * Git hooks of this repository seem to be broken." warning when pushing more than one branch at a time. * automerge does not happen when the approval count reaches the required threshold. * the FORCE_PRIVATE=true setting is not consistently enforced. * CSRF validation errors when OAuth is not enabled. * headlines in rendered org-mode do not have a margin on the top (forwarded request 1181169 from rrahl0)
- update to 7.0.2: * regression where subscribing to or unsubscribing from an issue in a repository with no code produced an internal server error. * regression makes all the refs sent in Gitea webhooks to be full refs and might break Woodpecker CI pipelines triggered on tag (CI_COMMIT_TAG contained the full ref). This issue has been fixed in the main branch of Woodpecker CI as well. * the webhook branch filter wrongly applied the match on the full ref for branch creation and deletion (wrongly skipping events). * toggling the WIP state of a pull request is possible from the sidebar, but not from the footer. * when mentioning a user, the markup post-processor does not handle the case where the mentioned user does not exist: it tries to skip to the next node, which in turn, ended up skipping the rest of the line. * excessive and unnecessary database queries when a user with no repositories is viewing their dashboard. * duplicate status check contexts show in the branch protection settings. * profile info fails to render german singular translation. * inline attachments of incoming emails (as they occur for example with Apple Mail) are not attached to comments. (forwarded request 1171482 from rrahl0)
Forwarded request #1170482 from rrahl0 - update to 7.0.1: * LFS data corruption when running the forgejo doctor check --fix CLI command or setting [cron.gc_lfs].ENABLED=true (the default is false) * non backward compatible change in the forgejo admin user create CLI command * error 500 because of an incorrect evaluation of the template when visiting the LFS settings of a repository * GET /repos/{owner}/{name} API endpoint always returns an empty string for the object_format_name field * fuzzy search may fail with bleve
Displaying all 8 revisions