Git with a cup of tea! Painless self-hosted all-in-one software development service, includes Git hosting, code review, team collaboration, package registry and CI/CD
Go to file
Kemal Zebari 7adc4717ec
Include file extension checks in attachment API (#32151)
From testing, I found that issue posters and users with repository write
access are able to edit attachment names in a way that circumvents the
instance-level file extension restrictions using the edit attachment
APIs. This snapshot adds checks for these endpoints.
2024-11-06 21:34:32 +00:00
.devcontainer bump to go 1.23 (#31855) 2024-09-10 02:23:07 +00:00
.gitea Update demo site location from try.gitea.io -> demo.gitea.com (#31054) 2024-05-27 15:05:12 +00:00
.github use rebuilt mssql-2017 image (#32109) 2024-09-23 16:54:20 -04:00
assets Update go dependencies (#32389) 2024-10-31 12:05:54 +00:00
build refactor: remove redundant err declarations (#32381) 2024-10-30 19:36:24 +00:00
cmd chore: fix some function names in comment (#32300) 2024-10-22 08:41:05 +08:00
contrib Add `gh-access-token` flag into backport script (#32283) 2024-10-17 01:43:48 -04:00
custom/conf Use 8 as default value for git lfs concurrency (#32421) 2024-11-05 13:10:57 +00:00
docker Update README.md (#30856) 2024-05-03 23:53:18 -04:00
models Fix milestone deadline and date related problems (#32339) 2024-11-05 07:46:40 +00:00
modules Updated tokenizer to better matching when search for code snippets (#32261) 2024-11-06 20:51:20 +00:00
options Add some handy markdown editor features (#32400) 2024-11-04 10:14:36 +00:00
public Update JS and PY dependencies (#32388) 2024-10-31 04:19:15 +00:00
routers Include file extension checks in attachment API (#32151) 2024-11-06 21:34:32 +00:00
services Include file extension checks in attachment API (#32151) 2024-11-06 21:34:32 +00:00
snap bump to go 1.23 (#31855) 2024-09-10 02:23:07 +00:00
templates Include file extension checks in attachment API (#32151) 2024-11-06 21:34:32 +00:00
tests Include file extension checks in attachment API (#32151) 2024-11-06 21:34:32 +00:00
tools Add `lint-go-gopls` (#30729) 2024-06-05 09:22:38 +08:00
web_src Correctly query the primary button in a form (#32438) 2024-11-07 04:21:53 +08:00
.air.toml Reduce `air` verbosity (#31417) 2024-06-19 19:42:06 +00:00
.changelog.yml Adapt `.changelog.yml` to new labeling system (#27701) 2023-10-20 00:22:00 +02:00
.dockerignore Add `/public/assets/img/webpack` to ignore files again (#30451) 2024-04-13 04:28:20 +02:00
.editorconfig
.envrc Enable direnv (#31672) 2024-07-23 12:07:41 +00:00
.eslintrc.yaml Update JS and PY dependencies (#32388) 2024-10-31 04:19:15 +00:00
.gitattributes Add `interface{}` to `any` replacement to `make fmt`, exclude `*.pb.go` (#30461) 2024-04-13 17:32:15 +00:00
.gitignore Enable direnv (#31672) 2024-07-23 12:07:41 +00:00
.gitpod.yml Remove sqlite-viewer and using database client (#31223) 2024-06-03 10:41:29 +00:00
.golangci.yml Enable `unparam` linter (#31277) 2024-06-11 18:47:45 +00:00
.ignore Add `/options/license` and `/options/gitignore` to `.ignore` (#30219) 2024-03-31 22:22:29 +02:00
.markdownlint.yaml Enable markdownlint `no-trailing-punctuation` and `no-blanks-blockquote` (#29214) 2024-02-17 13:18:05 +00:00
.npmrc Upgrade to npm lockfile v3 and explicitely set it (#23561) 2023-03-18 19:38:10 +01:00
.spectral.yaml
.yamllint.yaml fully replace drone with actions (#27556) 2023-10-11 06:39:32 +00:00
BSDmakefile Fix build errors on BSD (in BSDMakefile) (#27594) 2023-10-13 15:38:27 +00:00
CHANGELOG-archived.md Fix changelog (main) (#30582) 2024-04-19 06:08:30 +00:00
CHANGELOG.md Fix changelog (main) (#30582) 2024-04-19 06:08:30 +00:00
CODE_OF_CONDUCT.md Add Gitea Community Code of Conduct (#23188) 2023-03-09 10:49:34 +08:00
CONTRIBUTING.md Have new announcement about docs contributions (#31364) 2024-06-14 11:17:05 +08:00
DCO
Dockerfile bump to go 1.23 (#31855) 2024-09-10 02:23:07 +00:00
Dockerfile.rootless bump to go 1.23 (#31855) 2024-09-10 02:23:07 +00:00
LICENSE
MAINTAINERS Add bohde as maintainer (#31601) 2024-07-10 08:18:35 +08:00
Makefile add {{TEST_MINIO_ENDPOINT}} for local testing "with/without" docker + fix pgsql testing doc (#32105) 2024-10-03 01:00:56 +00:00
README.md README Badge maintenance (#31441) 2024-06-21 13:18:39 +00:00
README_ZH.md README Badge maintenance (#31441) 2024-06-21 13:18:39 +00:00
SECURITY.md typo on date in security document (#31617) 2024-07-11 21:51:08 +00:00
build.go User/Org Feed render description as per web (#23887) 2023-04-04 04:39:47 +01:00
crowdin.yml Use Crowdin action for translation sync (#30054) 2024-03-30 18:11:50 +00:00
flake.lock Fix update flake (#31626) 2024-07-12 16:25:54 +00:00
flake.nix Fix update flake (#31626) 2024-07-12 16:25:54 +00:00
go.mod Make LFS http_client parallel within a batch. (#32369) 2024-11-04 04:49:08 +00:00
go.sum Update go dependencies (#32389) 2024-10-31 12:05:54 +00:00
main.go Add some tests to clarify the "must-change-password" behavior (#30693) 2024-04-27 12:23:37 +00:00
package-lock.json Update JS and PY dependencies (#32388) 2024-10-31 04:19:15 +00:00
package.json Update JS and PY dependencies (#32388) 2024-10-31 04:19:15 +00:00
playwright.config.ts Add initial typescript config and use it for eslint,vitest,playwright (#31186) 2024-06-28 16:15:51 +00:00
poetry.lock Update JS and PY dependencies (#32388) 2024-10-31 04:19:15 +00:00
poetry.toml Clean up pyproject.toml and package.json, fix poetry options (#25327) 2023-06-18 18:13:08 +00:00
pyproject.toml Update JS and PY dependencies (#32388) 2024-10-31 04:19:15 +00:00
stylelint.config.js Enable `declaration-block-no-redundant-longhand-properties` (#30950) 2024-05-12 02:33:05 +00:00
tailwind.config.js Add spacing to global error message (#31826) 2024-08-14 01:58:26 +00:00
tsconfig.json Move web globals to `web_src/js/globals.d.ts` (#31943) 2024-08-30 07:36:53 +00:00
updates.config.js Update JS dependencies (#31120) 2024-05-28 01:50:28 +00:00
vitest.config.ts Convert frontend code to typescript (#31559) 2024-07-07 15:32:30 +00:00
webpack.config.js Add back esbuild-loader for .js files (#31585) 2024-07-09 09:28:43 +00:00

README.md

Gitea

Contribute with Gitpod

View this document in Chinese

Purpose

The goal of this project is to make the easiest, fastest, and most painless way of setting up a self-hosted Git service.

As Gitea is written in Go, it works across all the platforms and architectures that are supported by Go, including Linux, macOS, and Windows on x86, amd64, ARM and PowerPC architectures. This project has been forked from Gogs since November of 2016, but a lot has changed.

For online demonstrations, you can visit demo.gitea.com.

For accessing free Gitea service (with a limited number of repositories), you can visit gitea.com.

To quickly deploy your own dedicated Gitea instance on Gitea Cloud, you can start a free trial at cloud.gitea.com.

Building

From the root of the source tree, run:

TAGS="bindata" make build

or if SQLite support is required:

TAGS="bindata sqlite sqlite_unlock_notify" make build

The build target is split into two sub-targets:

  • make backend which requires Go Stable, the required version is defined in go.mod.
  • make frontend which requires Node.js LTS or greater.

Internet connectivity is required to download the go and npm modules. When building from the official source tarballs which include pre-built frontend files, the frontend target will not be triggered, making it possible to build without Node.js.

More info: https://docs.gitea.com/installation/install-from-source

Using

./gitea web

[!NOTE] If you're interested in using our APIs, we have experimental support with documentation.

Contributing

Expected workflow is: Fork -> Patch -> Push -> Pull Request

[!NOTE]

  1. YOU MUST READ THE CONTRIBUTORS GUIDE BEFORE STARTING TO WORK ON A PULL REQUEST.
  2. If you have found a vulnerability in the project, please write privately to security@gitea.io. Thanks!

Translating

Translations are done through Crowdin. If you want to translate to a new language ask one of the managers in the Crowdin project to add a new language there.

You can also just create an issue for adding a language or ask on discord on the #translation channel. If you need context or find some translation issues, you can leave a comment on the string or ask on Discord. For general translation questions there is a section in the docs. Currently a bit empty but we hope to fill it as questions pop up.

https://docs.gitea.com/contributing/localization

Crowdin

Further information

For more information and instructions about how to install Gitea, please look at our documentation. If you have questions that are not covered by the documentation, you can get in contact with us on our Discord server or create a post in the discourse forum.

We maintain a list of Gitea-related projects at gitea/awesome-gitea.

The official Gitea CLI is developed at gitea/tea.

Authors

Backers

Thank you to all our backers! 🙏 [Become a backer]

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]

FAQ

How do you pronounce Gitea?

Gitea is pronounced /ɡɪti:/ as in "gi-tea" with a hard g.

Why is this not hosted on a Gitea instance?

We're working on it.

License

This project is licensed under the MIT License. See the LICENSE file for the full license text.

Screenshots

Looking for an overview of the interface? Check it out!

Dashboard User Profile Global Issues
Branches Web Editor Activity
New Migration Migrating Pull Request View
Pull Request Dark Diff Review Dark Diff Dark