Gitea Jumps From 1.x to 28.0 and Adds Audit Logs, Bot Accounts, and Admin Impersonation
Gitea, the lightweight self-hosted Git service, released version 28.0 on September 30. The version number is not a typo: Gitea has dropped the 1.x scheme. What would have been 1.28 is now simply 28.
Three admin features
Audit logging. Security-relevant events are now recorded and can be filtered by actor, action, and origin, and exported as JSONL. Retention defaults to 30 days. For anyone running Gitea for a team, this answers “who changed that permission, and when?” for the first time.
Bot accounts. Dedicated automation accounts that authenticate only with access tokens, cannot log in interactively, and have no notifications or email. That is a cleaner home for CI and integration credentials than a shared human account.
Admin impersonation. Administrators can temporarily see Gitea as another user does, which makes permission problems far easier to debug. Both the admin and the impersonated account are recorded in the audit log.
Repositories and Actions
- CODEOWNERS approval can be required by branch protection before merging
- Repository-scoped HTTPS deploy tokens, as an alternative to deploy SSH keys
- Better pull request review filtering, including searching the diff sidebar by file extension
- Gitea Actions: a visible build queue, automatic workflow refresh, and in-browser viewing of artifacts such as text, images, PDFs, and HTML reports
Breaking changes: read before upgrading
- Git 2.25 or newer is required on the server
- Self-registration is now disabled by default. If your instance relies on open sign-up, re-enable it explicitly
- The
DOMAINsetting is deprecated in favour ofROOT_URL - Live notifications moved from server-sent events to WebSockets, so check that your reverse proxy passes WebSocket upgrades
As always, back up the database and data directory first. If you are weighing Gitea against its community fork, Forgejo is the main alternative.