Gitea 28.0 Drops 1.x Versioning, Adds Audit Logs and Bot Accounts

Gitea jumps from the 1.x series to version 28.0, bringing audit logging, bot accounts, admin impersonation, and new collaboration features.

Gitea 28.0 is now available, marking a notable change for the self-hosted Git platform as the project drops the historical 1.x prefix from its version numbers. What was previously Gitea 1.28 is now simply Gitea 28.

Beyond the versioning change, one major addition is built-in audit logging, allowing Gitea to record security-relevant events and expose them through administration, organization, repository, and user settings. Events can be filtered by actor, action, and origin. Administrators can export the collected data in JSONL format. Audit logging is disabled by default and retains events for 30 days unless configured otherwise.

Gitea 28.0 also introduces dedicated bot accounts for automation. Unlike regular users, these accounts authenticate using access tokens, cannot log in interactively, and do not receive notifications or emails. Administrators can create and manage bot accounts through the web interface, API, or command line.

Another useful administrative addition is user impersonation. Administrators can temporarily view Gitea as a particular user sees it, making it easier to investigate permissions or access problems without needing the user’s credentials. When audit logging is enabled, actions during an impersonated session record both the administrator and the impersonated account.

Repository management gets several improvements as well. Gitea now supports repository-scoped HTTPS deploy tokens, providing an HTTPS counterpart to SSH deploy keys with read-only or read-write access. Branch protection can require approval from matching CODEOWNERS entries before a pull request is merged.

Reviewing larger pull requests is easier thanks to a new search field and file-extension filter in the diff sidebar. Both the file tree and displayed diff are filtered. The selected extension filter is stored in the URL so the view can be shared with others.

Gitea Actions receives a large set of improvements. A new build queue shows which jobs are running and which are waiting for runners, with repository-level and instance-wide views. Workflow run lists refresh automatically, and build artifacts can be browsed and previewed directly in the browser, including text files, images, PDFs, and generated HTML reports.

Keep in mind that several breaking changes require administrator review before upgrading. Git 2.25 or newer is now required, and Gitea will refuse to start with older versions. Additionally, self-registration is disabled by default unless explicitly enabled. The previous [server] DOMAIN setting is no longer used; the instance domain is now derived from ROOT_URL.

Git migrations, mirrors, and other network operations now pass through an internal proxy with revised egress rules. Installations using custom allowlists or blocklists should review their configuration before moving to 28.0.

Completed Gitea Actions runs have a new default retention policy. Runs, jobs, logs, and artifacts are removed after 400 days unless RUN_RETENTION_DAYS is changed. Setting the value to 0 keeps them indefinitely.

Finally, live notifications have moved from server-sent events to WebSockets. Administrators running Gitea behind a reverse proxy should ensure WebSocket upgrade headers are forwarded correctly. Otherwise, notification counts and stopwatch updates fall back to polling.

For more information, see the announcement. The project recommends backing up existing data and reviewing the documented breaking changes before upgrading.

Bobby Borisov

Bobby Borisov

Bobby, an editor-in-chief at Linuxiac, is a Linux professional with over 20 years of experience. With a strong focus on Linux and open-source software, he has worked as a Senior Linux System Administrator, Software Developer, and DevOps Engineer for small and large multinational companies.

Leave a Reply

Your email address will not be published. Required fields are marked *