发布日期: 2026-08-13
版本号: v1.27.2

该版本更新包含多项安全修复,如更新协作者访问模式和httpsign、修复pull_request_target可重用工作流问题以及增强WebAuthn用户验证等;同时进行了重构,优化了外部渲染和标记渲染。增强功能方面,添加了缺失的npm包元数据属性。此外,修复了大量bug,涉及actions、lfs、packages、storage、migration、ui等多个模块,例如解决工作流输入类型、重试任务读取前次产物、Azure Blob转储失败等问题。Gitea Cloud实例将在指定维护窗口自动升级至此版本。

更新内容 (中文)

  • 安全

    • 修复:更新协作者访问模式及httpsign (#38894, #38862) (#38895)
    • 重构:外部渲染 (#38885) (#38898)
    • 修复(actions):在基础提交时解析pull_request_target可复用工作流 (#38886) (#38897)
    • 重构:标记渲染 (#38864) (#38869)
    • 修复(deps):更新依赖mermaid至v11.16.1 (#38816)
    • 修复(auth):按请求设置WebAuthn用户验证 (#38805) (#38810)
    • 修复:渲染高亮语言 (#38793) (#38795)
  • 增强

    • 增强:添加缺失的npm包元数据属性 (#38826) (#38831)
  • 缺陷修复

    • 修复(actions):为workflow_dispatch保留github.event.inputs字符串格式 (#38899) (#38908)
    • 修复(actions):允许重运行选定作业时读取前次尝试的产物 (#38857) (#38901)
    • 修复(lfs):接受成功传输响应 (#38866) (#38875)
    • 修复(packages):忽略嵌套的Package.swift (#38788) (#38836)
    • 修复:移除arch ParsePackage中包含换行符的成员名 (#38102) (#38830)
    • 修复(storage):解决Azure Blob转储因文件不存在而失败的问题 (#38814) (#38828)
    • 修复(迁移):迁移删除返回JSON重定向 (#38796) (#38825)
    • 修复(UI):将下划线改为默认浏览器样式 (#38819) (#38823)
    • 修复(actions):允许取消无运行作业的流程 (#35842) (#38812)
    • 修复(actions):独立评估每个${{ }}表达式部分 (#38754) (#38797)
    • 修复(actions):在单事务中写入操作任务报告 (#38792) (#38794)
    • 修复:标记链接 (#38764) (#38765)
    • 修复:当内容大小未知时设置Minio分段大小 (#38753) (#38755)
    • 修复:子路径归档下载中的路径转义错误 (#38749) (#38750)
    • 修复:当刷新页面不包含时从UI移除拉取合并框 (#38742) (#38744)
    • 修复(标记):修正代码的双重删除线显示 (#38707) (#38729)
    • 修复(lfs):失败上传删除并发上传的元数据对象 (#38693) (#38722)
    • 修复:使用子路径时修正完整URL (#38712) (#38716)
    • 修复:避免标记渲染 panic 错误 (#38698) (#38703)
    • 修复(UI):提交头像堆栈中参与者过多显示问题 (#38689) (#38700)
    • 修复:支持Alpine注册表APKINDEX.tar.gz的HEAD请求 (#38686) (#38688)
    • 修复(迁移):使用所有已配置的GitHub令牌 (#38841) (#38846)

Gitea Cloud 上的实例将在指定维护窗口内自动升级至此版本。

更新内容 (原始)

  • SECURITY

    • Fix: update collaborator access mode and httpsign (#38894, #38862) (#38895)
    • Refactor: external render (#38885) (#38898)
    • Fix(actions): resolve pull_request_target reusable workflows at the base commit (#38886) (#38897)
    • Refactor: markup render (#38864) (#38869)
    • Fix(deps): update dependency mermaid to v11.16.1 (#38816)
    • Fix(auth): set WebAuthn user verification per request (#38805) (#38810)
    • Fix: render highlight language (#38793) (#38795)
  • ENHANCEMENTS

    • enhance: add missing npm package metadata properties (#38826) (#38831)
  • BUGFIXES

    • fix(actions): keep github.event.inputs as strings for workflow_dispatch (#38899) (#38908)
    • fix(actions): let a rerun of selected jobs read the previous attempt’s artifacts (#38857) (#38901)
    • fix(lfs): accept successful transfer responses (#38866) (#38875)
    • fix(packages): ignore nested Package.swift (#38788) (#38836)
    • fix: drop newline-bearing member names in arch ParsePackage (#38102) (#38830)
    • fix(storage): fix Azure Blob dump failing with file does not exist (#38814) (#38828)
    • fix(migration): migration deletion returned json redirection (#38796) (#38825)
    • fix(ui): change underlines to default browser style (#38819) (#38823)
    • fix(actions): allow cancelling runs without running jobs (#35842) (#38812)
    • fix(actions): evaluate each ${{ }} part on its own (#38754) (#38797)
    • fix(actions): write an action task report in one transaction (#38792) (#38794)
    • fix: markup link (#38764) (#38765)
    • fix: set a minio part size when the content size is unknown (#38753) (#38755)
    • fix: bad path escape in subpath archive download (#38749) (#38750)
    • fix: remove the pull merge box from UI when the refreshed page doesn’t contain it (#38742) (#38744)
    • fix(markdown): fix double strikethough on code (#38707) (#38729)
    • fix(lfs): failed upload deletes a concurrent upload’s meta object (#38693) (#38722)
    • fix: correct full url when using sub-path (#38712) (#38716)
    • fix: avoid markup render panic (#38698) (#38703)
    • fix(ui): too many participants shown in commit avatar stacks (#38689) (#38700)
    • fix: support HEAD requests on Alpine registry APKINDEX.tar.gz (#38686) (#38688)
    • fix(migrations): use all configured GitHub tokens (#38841) (#38846)

Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

下载链接