Forgejo v16.0.0 released
Beyond coding. We Forge. Ein einfacher, selbst gehosteter Git-Service
Version 16.0.0 released. Installation mit meiner Podman Quadlet Installation kinderleicht. Tag gesetzt, neu gestartet, fertig.
Release notes
Breaking security bug fixes
PR: remove default 'REVERSE_PROXY_TRUSTED_PROXIES = *' from docker config
PR: Improved compliance with the config settings
[migrations].ALLOWED_DOMAINS,[migrations].BLOCKED_DOMAINS, and[migrations].ALLOW_LOCALNETWORKS, which control the remotes that Forgejo can access for git & LFS migration and mirroring operations, fixing time-of-check vs. time-of-use issue and missing checks in LFS. git mirror HTTP operations have been adjusted to never follow HTTP redirects in order to ensure that these settings are followed, which will break HTTP mirroring if a redirect is served by the git HTTP remote.Security bug fixes
PR (backported): fix: ensure migrations allow/deny host lists are applied to onedev, pagure, and codebase migrators
Releases Notes -> https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.0.md