dependabot[bot]
4850d25f43
mod: bump gorm.io/gorm from 1.25.12 to 1.31.0
...
Bumps [gorm.io/gorm](https://github.com/go-gorm/gorm ) from 1.25.12 to 1.31.0.
- [Release notes](https://github.com/go-gorm/gorm/releases )
- [Commits](https://github.com/go-gorm/gorm/compare/v1.25.12...v1.31.0 )
---
updated-dependencies:
- dependency-name: gorm.io/gorm
dependency-version: 1.31.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-01 10:02:11 +00:00
Dmitry Afanasiev
6a6364bb5d
chore: update mermaid to 11.9.0 ( #8009 )
...
Co-authored-by: ᴊᴏᴇ ᴄʜᴇɴ <jc@unknwon.io >
2025-09-30 06:11:09 -04:00
dependabot[bot]
35c047dc9d
mod: bump golang.org/x/net from 0.42.0 to 0.43.0 ( #8022 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-02 20:20:15 -04:00
dependabot[bot]
e4923af32d
mod: bump golang.org/x/text from 0.27.0 to 0.28.0 ( #8027 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-02 20:18:18 -04:00
dependabot[bot]
0533fb7744
mod: bump golang.org/x/crypto from 0.40.0 to 0.41.0 ( #8024 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-02 13:13:50 -04:00
dependabot[bot]
28810f7db7
mod: bump github.com/prometheus/client_golang from 1.22.0 to 1.23.0 ( #8026 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-02 12:38:55 -04:00
ᴊᴏᴇ ᴄʜᴇɴ
cfe38e0a08
chore: update Debian and Ubuntu targets in .pkgr.yml
...
[skip ci]
2025-09-01 21:45:41 -04:00
dependabot[bot]
110da379c1
mod: bump github.com/stretchr/testify from 1.10.0 to 1.11.1 ( #8025 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-01 21:19:47 -04:00
dependabot[bot]
37962fcc0b
mod: bump github.com/niklasfasching/go-org from 1.8.0 to 1.9.1 ( #8013 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-03 21:56:02 -04:00
dependabot[bot]
7265a7cd26
mod: bump golang.org/x/net from 0.40.0 to 0.42.0 ( #8014 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-03 21:52:36 -04:00
dependabot[bot]
521fbe34f6
mod: bump golang.org/x/crypto from 0.39.0 to 0.40.0 ( #8016 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-03 16:32:05 -04:00
dependabot[bot]
1375bc401a
mod: bump modernc.org/sqlite from 1.37.1 to 1.38.2 ( #8017 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-03 15:43:27 -04:00
dependabot[bot]
28f83626d4
mod: bump github.com/urfave/cli from 1.22.16 to 1.22.17 ( #7995 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-02 20:17:59 -04:00
dependabot[bot]
dcf8d9340e
mod: bump github.com/sergi/go-diff from 1.3.1 to 1.4.0 ( #7996 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-01 13:10:47 -04:00
dependabot[bot]
76b5d75d79
mod: bump golang.org/x/crypto from 0.38.0 to 0.39.0 ( #7997 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-01 13:10:13 -04:00
dependabot[bot]
454175ece2
mod: bump github.com/Masterminds/semver/v3 from 3.3.1 to 3.4.0 ( #8000 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-01 13:09:19 -04:00
Joe Chen
d940e692ec
chore: fix up links and add CTA in README
...
[skip ci]
2025-06-18 09:46:51 -04:00
Joe Chen
7fc19d094c
chore: update dev_release_patch_version.md
...
[skip ci]
2025-06-08 23:13:35 -04:00
Joe Chen
4e3bf27fe2
chore: update dev_release_patch_version.md
...
[skip ci]
2025-06-08 21:30:40 -04:00
Joe Chen
16b8b0974e
chore: update dev_release_patch_version
...
[skip ci]
2025-06-08 21:23:46 -04:00
Joe Chen
f004b5b472
CHANGELOG: cut entries for 0.13.3 ( #7983 )
...
[skip ci]
2025-06-08 18:53:03 -04:00
Joe Chen
591810e405
web_editor: prohibit CRUD to symbolic files ( #7981 )
...
Fixes
[GHSA-wj44-9vcg-wjq7](https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7 )
---------
Co-authored-by: deepsource-autofix[bot] <62050782+deepsource-autofix[bot]@users.noreply.github.com>
2025-06-08 18:28:28 -04:00
Joe Chen
3c2112215f
ci: only run Docker job for the main repository ( #7980 )
2025-06-08 17:19:48 -04:00
dependabot[bot]
9db5c30c36
mod: bump github.com/pquerna/otp from 1.3.0 to 1.5.0 ( #7972 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-01 12:58:19 -04:00
dependabot[bot]
49f4d4312b
mod: bump github.com/niklasfasching/go-org from 1.7.0 to 1.8.0 ( #7978 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-01 12:50:52 -04:00
dependabot[bot]
0cf12eccae
mod: bump modernc.org/sqlite from 1.37.0 to 1.37.1 ( #7977 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-01 12:50:32 -04:00
dependabot[bot]
495c38825a
mod: bump gorm.io/driver/postgres from 1.5.11 to 1.6.0 ( #7973 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Chen <jc@unknwon.io >
2025-06-01 11:56:55 -04:00
dependabot[bot]
60b912ddda
mod: bump golang.org/x/net from 0.39.0 to 0.40.0 ( #7975 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-01 11:42:13 -04:00
Edoardo Ottavianelli
4d6a0ebaac
security: patch for Stored XSS in PDF renderer ( #7966 )
2025-05-16 15:49:58 -04:00
dependabot[bot]
54fa465da5
mod: bump github.com/go-ldap/ldap/v3 from 3.4.10 to 3.4.11 ( #7960 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-05-01 13:02:00 -04:00
dependabot[bot]
54cd8fd160
mod: bump golang.org/x/net from 0.36.0 to 0.38.0 ( #7946 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Chen <jc@unknwon.io >
2025-04-16 08:48:37 -04:00
dependabot[bot]
7abc81c4d2
mod: bump github.com/prometheus/client_golang from 1.21.0 to 1.21.1 ( #7949 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-15 13:10:30 -04:00
dependabot[bot]
493834861d
mod: bump golang.org/x/text from 0.22.0 to 0.23.0 ( #7950 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-15 13:00:41 -04:00
dependabot[bot]
9a539393bd
mod: bump github.com/editorconfig/editorconfig-core-go/v2 ( #7948 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-14 18:05:48 -04:00
dependabot[bot]
139ea3ce7d
mod: bump modernc.org/sqlite from 1.36.0 to 1.37.0 ( #7947 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Chen <jc@unknwon.io >
2025-04-14 18:00:07 -04:00
dependabot[bot]
4acaaac85a
mod: bump golang.org/x/net from 0.34.0 to 0.36.0 ( #7935 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-04 23:27:10 -05:00
dependabot[bot]
e93ced2163
mod: bump modernc.org/sqlite from 1.34.5 to 1.36.0 ( #7929 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-04 23:18:23 -05:00
dependabot[bot]
9672b6dd6c
mod: bump github.com/prometheus/client_golang from 1.20.5 to 1.21.0 ( #7931 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-04 23:11:43 -05:00
dependabot[bot]
7a12c8418e
mod: bump golang.org/x/text from 0.21.0 to 0.22.0 ( #7933 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-04 23:11:08 -05:00
Joe Chen
2208f17e8e
chore: update Trivy scan config ( #7934 )
2025-03-04 23:07:09 -05:00
宋子桓🌈
46a84fdad5
email: fix unable to override templates in custom directory ( #7905 )
...
Co-authored-by: Joe Chen <jc@unknwon.io >
2025-02-12 21:52:18 -05:00
dependabot[bot]
9c80e6d922
mod: bump modernc.org/sqlite from 1.34.4 to 1.34.5 ( #7906 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-01 23:24:18 -05:00
dependabot[bot]
3a952bd248
mod: bump golang.org/x/net from 0.33.0 to 0.34.0 ( #7908 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-01 23:22:49 -05:00
Joe Chen
96d5d622b8
ci: update GitHub Actions version for Code QL
2025-01-01 19:46:13 -05:00
MarcUs7i
b59e943aa6
Set timeout to explicit 0 in gogs.js ( #7890 )
...
## Describe the pull request
A simple fix in public/js/gogs.js making bug upload not result in a
timeout (added just one line)
Link to the issue: closes https://github.com/gogs/gogs/issues/6149
## Test plan
- Set the max_size of `attachment` to a high number
```toml
[release.attachment]
ENABLED = true
ALLOWED_TYPES = */*
MAX_SIZE = 512
MAX_FILES = 20
```
- Upload a file to releases

It doesn't randomly timeout!
2025-01-01 19:41:24 -05:00
dependabot[bot]
371a6092de
mod: bump modernc.org/sqlite from 1.34.1 to 1.34.4 ( #7893 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-01 11:18:34 -05:00
dependabot[bot]
e6896eb393
mod: bump gorm.io/driver/postgres from 1.5.7 to 1.5.11 ( #7895 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Chen <jc@unknwon.io >
2025-01-01 11:11:51 -05:00
dependabot[bot]
6c04a1ce7c
mod: bump github.com/go-ldap/ldap/v3 from 3.4.8 to 3.4.10 ( #7894 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-01 10:37:55 -05:00
Martin
6bdbb88fb8
gogs.service: Remove syslog.target ( #7681 )
...
Remove syslog.target from service file, this target hasn't existed for
over a decade.
6aa8d43ade/NEWS (L72-L73)
2024-12-26 11:55:46 -05:00
ngn
6b4e8668a1
Adding '|' to the releases page ( #7631 )
...
Adding '|' to the releases page `templates/repo/release/list.tmpl`
i changed this:

to this:

(yes)
2024-12-26 11:15:44 -05:00