Gitea 28.0.0
Package
Gitea drops 1.x versioning and ships 28.0 with security audit logs, token-only bot accounts, admin impersonation, CODEOWNERS approvals, and HTTPS deploy tokens. Self-registration is now disabled by default.
Download BINARY Project website ↗Download Mirrors
Gitea 28.0.0 was released on September 30, 2026. Gitea has dropped its 1.x numbering: what would have been 1.28 is simply 28. We covered the release in the news, and our Gitea app page covers the project.
What is new
- Audit logging of security-relevant events, filterable and exportable as JSONL, with 30-day default retention
- Bot accounts that authenticate only with tokens
- Admin impersonation for troubleshooting permissions, recorded in the audit log
- CODEOWNERS approval as a branch protection rule
- Repository-scoped HTTPS deploy tokens
- Gitea Actions improvements: a build queue view, auto-refreshing workflows, and in-browser artifact viewing
Before upgrading
- Git 2.25 or newer is required on the server
- Self-registration is disabled by default; re-enable it if your instance relies on open sign-up
DOMAINis deprecated in favour ofROOT_URL- Live notifications now use WebSockets; make sure your reverse proxy passes them
Back up the database, repositories, and app.ini first.
Installing
Gitea is a single binary:
wget -O gitea https://dl.gitea.com/gitea/28.0.0/gitea-28.0.0-linux-amd64
chmod +x gitea
./gitea web
For production, run it as a dedicated user under systemd, or use the official gitea/gitea:28.0.0 container. Choosing between Gitea and its fork? See Gitea vs Forgejo.
Verify Your Download
Each binary on dl.gitea.com has matching .sha256 and GPG .asc signature files.