Gitea releases version 28.0.0, drops 1.x version prefix
Gitea has released version 28.0.0, renaming its versioning scheme to drop the historical '1.' prefix so this release is 28.0.0 instead of 1.28.0. The update adds audit logging, bot accounts, HTTPS deploy tokens, admin user impersonation, code-owner approval rules, diff file filters, and an Actions queue view, alongside unspecified security fixes to be detailed later. Release builds drop support for 32-bit x86, gogit, and armhf Snap packages, and network operations for migrations, mirrors, webhooks and OAuth2 now route through a new internal proxy with configurable egress allow/block lists.
GoKawiil's interpretation of the reporting above, not reported fact.
The shift to stricter default network egress controls suggests Gitea's maintainers are prioritizing security hardening for self-hosted instances, which could require administrators to reconfigure allow lists before upgrading or risk broken integrations. Dropping 32-bit and gogit builds indicates the project is narrowing its supported platform matrix, likely to simplify maintenance. The delayed disclosure of security fix details gives administrators a window to patch before vulnerabilities become public knowledge.
- Gitea now uses a simplified version numbering scheme starting with 28.0.0.
- New features include audit logging, bot accounts, HTTPS deploy tokens, and admin impersonation.
- Administrators must review egress settings and drop 32-bit/armhf/gogit dependencies before upgrading.
Source: blog.gitea.com — Technical Oversight Committee, 2026-09-30
Published there as: “Gitea 28.0.0 Is Released”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.