## go-gitea/gitea — v1.28.0-dev…v28.0.0

_588+ commits._

### Features
- **enhance(actions): add pending job status and align job statuses with GitHub (#39376)** (9e7b302)
- **feat(actions): add build queue view (#38585)** (3875db1)
- **feat(actions): Add artifact preview in Actions run view (#36754)** (5a56e11)
- **feat(actions): update actionslib, support `self:`, misc fixes (#39358)** (f757631)
- **enhance(acme): add configurable ACME profile (#39375)** (484981f)
- **enhance: improve issue-pattern capture groups and support both internal&external trackers enabled (#39354)** (b27e7d0)
- **feat: manage bot accounts from the admin UI, API and CLI (#38966)** (3bec08f)
- **enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` (#39289)** (c04802b)
- **feat: Add audit logging (#38189)** (da37b79)
- **enhance(packages): implement npm single-version API and add per-version repository (#39267)** (459fc13)

### Fixes
- **fix(git): reject fsck-invalid objects on push (#39472)** (fb4d5e9)
- **fix(git)!: use internal proxy for all git operations (#39426)** (1b12744)
- **fix(api): commit tree SHA is the commit ID (#39449)** (ebcb015)
- **fix(actions): preserve admitted jobs and runs in their concurrency group (#39461)** (6bb74ed)
- **fix(actions): keep the caller's event and inputs in reusable workflow jobs (#39452)** (0d09986)
- **fix(actions): harden fork pull request run approval (#39399)** (f44e64b)
- **fix: PR merge (#39442)** (ea91028)
- **fix(api): allow pending-inline-comment-only reviews (#39433)** (dcef88a)
- **fix: dedupe issue cross-reference timeline entries (#38881)** (4eebefb)
- **fix(actions): evaluate job-level `if:` before concurrency check (#39437)** (a15f032)
- **fix: preserve SNI for local internal API (#39412)** (d42128d)
- **fix(ssh): fetch ssh key by fingerprint (#39423)** (448f8c6)
- **fix(feed): use meaningful lines as comment excerpt (#39276)** (722e523)
- **fix(migrations): stop endless comment paging when migrating from Gitea (#39419)** (0305869)
- **fix(ui): misc ui fixes (#39336)** (7f3b4a0)
- **fix(issues): don't render team review requests as Ghost (#39416)** (05f049e)
- **fix: sanitize external render command line arguments (#39417)** (671a2f5)
- **fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data (#39406)** (d5ed737)
- **fix(git): keep leading dashes in git grep search patterns (#39404)** (defc9d5)
- **fix(indexer): index full file paths and real offsets in bleve (#39405)** (72243be)
- **perf(references): scan only the keyword window before a reference (#39396)** (8b46a95)
- **fix: use correct content-type for container registry response (#39398)** (7106594)
- **fix(user): allow unblocking users promoted to admin (#39192)** (06e3341)
- **fix(repo): commit page fails to render unsigned commits with a different committer (#39381)** (191287d)
- **fix: use clearer message for ldap auth failure (#39392)** (6146a48)
- **fix(markup): raise KaTeX MAX_CHARS limit to 10000 (#39387)** (8164130)
- **fix: pass merge commit messages to git via stdin (#39269)** (cdf786c)
- **fix(migrations): preserve SHA-256 pull request commit IDs (#39343)** (cc34c26)
- **fix: focus confirm button and use red for delete confirmations (#39350)** (3296046)
- **fix: package registry keypair creation race (#39319)** (fce7b9d)
- **fix(repo): surface unrelated histories on Sync Fork (#39258)** (be7cde7)
- **perf(frontend): enable vite module preload (#39332)** (e77d3bf)
- **fix: add default timeout and handle errors for HaveIBeenPwned API (#39316)** (b2e11dd)
- **fix(user): unify email validation for registration and settings (#39304)** (7ebb2ca)
- **fix: match install page update checker setting with app.ini (#39317)** (31b4d79)
- **fix(actions): use gitea's clock for actions durations (#39323)** (7efd24b)
- **fix(actions): never show negative running durations (#39322)** (f9d3268)
- **fix: classify git failures on stderr, restrict migration failure detail (#39010)** (812191c)
- **fix: correct stdErr match in isErrBlameNotFoundOrNotEnoughLines (#39309)** (85cbf47)
- **fix(ui): use button elements for branch and tag dropdown tabs (#39285)** (8c09116)
- **fix(projects): allow max columns to the limit (#39272)** (40385ef)
- **fix(auth): fix ssh and gpg key verification on windows (#39283)** (79fc119)
- **fix: allow re-requesting uncounted review approvals (#38988)** (d93bd06)
- **fix: restore owner name in PR target branch selector (#39262)** (c9193ad)
- **fix(api): enforce mustNotBeArchived on repo topics routes (#39260)** (8b6ad49)
- **fix: avoid nil panic and refactor some trivial problems (#39251)** (3176f37)
- **fix(automerge): validate head commit before merge (#39235)** (cf0f4dc)
- **fix: restore missing blob file when re-publishing a package (#39239)** (efa69e7)
- **fix: action run list page error (#39212)** (0fff5f4)
- **fix(deps): update module golang.org/x/crypto to v0.56.0 [security] (#39219)** (1b2479b)
- **fix(httplib): prevent leaking localhost:3000 in public links (#39217)** (bcd913a)
- **fix(pulls): hide branch deletion when an open PR uses the branch (#39193)** (52fcd2d)
- **fix: correct repo/attatchment absolute url and release layout (#39178)** (4875bb3)
- **fix(setting): honor bare -1 for timeout settings (#39181)** (fc9800b)
- **fix: charset lookup (#39187)** (be3a6d1)
- **fix(git): keep IPv6 brackets in submodule web links (#39186)** (7c36ae7)

### UI
- **Long diff lines now truncated gracefully** — Diff views now handle very long lines better by truncating them for display while still showing the content, and increased the buffer size for reading large diffs to prevent parsing errors. (1e13bad)

### Backend
- **[skip ci] Updated translations via Crowdin** (1ab2358)
- **[skip ci] Updated translations via Crowdin** (47529e2)
- **[skip ci] Updated translations via Crowdin** (3c5d2d1)
- **enhance: allow auto-closing PRs from PRs (#39393)** (6d59229)
- **[skip ci] Updated translations via Crowdin** (27d787d)
- **enhance(emoji): update to Unicode 17, unify and lazy-load emoji data (#39363)** (64f31d9)
- **[skip ci] Updated translations via Crowdin** (2177969)
- **[skip ci] Updated translations via Crowdin** (de5913d)
- **[skip ci] Updated translations via Crowdin** (9b6a82d)
- **[skip ci] Updated translations via Crowdin** (9ae7ea7)
- **[skip ci] Updated translations via Crowdin** (2a3d047)
- **[skip ci] Updated translations via Crowdin** (6400c15)
- **enhance: update mermaid to v12 (#39331)** (2b10f77)
- **enhance: allow attribute-less MathML elements and complete the Core allowlist (#39337)** (4892a55)
- **[skip ci] Updated translations via Crowdin** (f0d2195)
- **[skip ci] Updated translations via Crowdin** (6294526)
- **enhance(notifications): mark current notification page as read (#39294)** (a583a30)
- **[skip ci] Updated translations via Crowdin** (7b036e9)
- **Added Irish language translations** — Updated Irish (ga-IE) language translations across the platform, adding support for new features including email reply options, issue context menu actions, diff display improvements, audit log management, and audit event filtering. (25984be)
- **Updated translations across languages** — Translation strings were updated via Crowdin for 22 languages, including new audit log labels (Actor and Details) and removal of some outdated diff-related messages. Chinese (Simplified) received the most significant update with 78 new translation strings. (4ed7020)
- **[skip ci] Updated translations via Crowdin** (4d43445)
- **[skip ci] Updated translations via Crowdin** (579de92)
- **enhance: improve e-mail templates (#38396)** (81dee52)
- **[skip ci] Updated translations via Crowdin** (92f2f61)
- **[skip ci] Updated translations via Crowdin** (e8254bd)
- **[skip ci] Updated translations via Crowdin** (1770470)
- **enhance: improve commit page header (#39229)** (87d5497)
- **[skip ci] Updated translations via Crowdin** (e5e7b2e)
- **enhance(web): show attachment URL and UUID in dropzone preview (#39203)** (bde1af5)
- **enhance: move window.config to JSON, improve CSP format (#39236)** (eb501f6)
- **[skip ci] Updated translations via Crowdin** (e4455fb)
- **[skip ci] Updated translations via Crowdin** (231ee19)
- **enhance: Improve validation errors for secrets/variables (#39221)** (2d3ad4a)
- **enhance(web): hide attachment dropzone on preview tab in combo editor (#39204)** (c56b2d3)
- **[skip ci] Updated translations via Crowdin** (dc6ac94)
- **enhance(repo): check full repo name for dangerous operations (#39213)** (8cf7330)
- **[skip ci] Updated translations via Crowdin** (5ec9714)
- **[skip ci] Updated translations via Crowdin** (ee8f2b4)
- **[skip ci] Updated translations via Crowdin** (4f307ec)

### Tests
- **test: stop tests from writing into `~/.ssh` (#39348)** (db7dbd5)
- **test(e2e): log out to switch users in pr-review test (#39328)** (2b6500a)
- **test: release fixtures loader lock before database work (#39263)** (df8e7db)

### Docs
- **docs: Add changelog for 28.0.0 (#39474)** (5a96cc4)
- **docs(webhook): review.type comment lists values the webhook never sends (#39451)** (031c5f1)
- **docs(api): document verification and files on the compare endpoint (#39440)** (3fac505)
- **docs(api): name the unadopted-repository search parameter query (#39370)** (f0f53a7)
- **docs: remove unused COOKIE_USERNAME from app.example.ini (#39365)** (03c7255)
- **docs: document NOTICE_ON_SUCCESS for every cron task (#39352)** (0a8b24c)
- **docs: correct ALLOW_LOCALNETWORKS description in app.example.ini (#39240)** (c0c573f)
- **docs: fix dead localization doc link in the READMEs (#39211)** (ce2fd8d)
- **docs: fix typo in README about app.ini restart (#39223)** (9dd5747)

### Chore
- **ci: Also release for other versions than 1 majors (#39475) (#39476)** (15b8a58)
- **chore: update giteabot to v1.0.7 (#39470)** (9c715c0)
- **chore(deps): update dependencies (#39462)** (fba8d7e)
- **chore: update eslint, enable more rules and fix their findings (#39438)** (857d3d3)
- **chore: quote test name patterns in make targets (#39429)** (a7b0327)
- **chore(frontend): target ES2022 (#39420)** (455f30a)
- **refactor: fix `go vet` errors related to composite literals (#39341)** (19ae1f8)
- **refactor: "install" page (#39400)** (f14cedc)
- **refactor: make git http respond error message (#39390)** (08149f9)
- **chore: refactor StaticRootPath (#39384)** (7637b1b)
- **chore(deps): update dependencies (#39367)** (fc28937)
- **chore: remove CLAUDE.md (#39360)** (a5a6458)
- **chore: update eslint plugins and configure new unicorn rules (#39357)** (309c872)
- **refactor(api): convert bot accounts through the admin user edit endpoint (#39355)** (85eaf5c)
- **refactor: replace AWS SDK with a REST client for CodeCommit migration (#39330)** (afb7ede)
- **refactor: replace Azure Blob SDK with a REST client (#39315)** (c6c671e)
- **build(gogit): disable gogit builds for stable releases (#39324)** (f0a535b)
- **chore: fix various problems (#39298)** (c0ceea2)
- **chore(deps): update actionslib to v1.0.0 (#39295)** (1303382)
- **chore(deps): update dependencies (#39306)** (cefb81a)
- **Standardize system user naming** — Updated internal system user creation functions to follow consistent naming conventions and improved their registration in the system user registry. This ensures audit logs and permission checks correctly recognize CLI and authentication source operations across the codebase. (1280de5)
- **refactor(templates): update djlint to 1.46.0 and resolve its new findings (#39231)** (f5c7b21)
- **refactor: npm route handlers (#39275)** (45a78bb)
- **chore(deps): update dependencies (#39256)** (cc6fc41)
- **refactor: replace jquery.are-you-sure with first-party code (#39233)** (7c280c0)
- **refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" (#39248)** (3bd7ea4)
- **refactor: share package registry error status classification (#39133)** (c285440)
- **chore(deps): update dependency go to v1.27.1 (#39206)** (f735df4)
- **chore: remove dead CSS rules (#39188)** (70678e9)
- **chore(webhook): GET method is not recommended (#39169)** (72afd22)
- **refactor: improve types in the frontend, misc fixes (#39142)** (7c93ead)
- **chore(deps): update dependencies (#39176)** (535fc29)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/go-gitea/gitea?utm_source=github-action)._