Git with a cup of tea! Painless self-hosted all-in-one software development service, including Git hosting, code review, team collaboration, package registry and CI/CD
Find a file
shashank-netapp 03fce8f3d0
Some checks are pending
release-nightly / nightly-binary (push) Waiting to run
release-nightly / nightly-docker-rootful (push) Waiting to run
release-nightly / nightly-docker-rootless (push) Waiting to run
Fixing issue #35530: Password Leak in Log Messages (#35584)
The Gitea codebase was logging `Elasticsearch` and `Meilisearch`
connection strings directly to log files without sanitizing them. Since
connection strings often contain credentials in the format
`protocol://username:password@host:port`, this resulted in passwords
being exposed in plain text in log output.

Fix:
- wrapped all instances of setting.Indexer.RepoConnStr and
setting.Indexer.IssueConnStr with the `util.SanitizeCredentialURLs()`
function before logging them.

Fixes: #35530

Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2025-10-07 09:26:47 -07:00
.devcontainer bump devcontainer to go 1.25 (#35404) 2025-09-04 04:21:00 +00:00
.gitea Update demo site location from try.gitea.io -> demo.gitea.com (#31054) 2024-05-27 15:05:12 +00:00
.github use experimental go json v2 library (#35392) 2025-09-28 08:03:36 +00:00
assets Replace gobwas/glob package (#35478) 2025-09-13 18:01:00 +00:00
build Update gofumpt, add go.mod ignore directive (#35434) 2025-09-08 13:40:08 +02:00
cmd Move some functions to gitrepo package (#35543) 2025-10-07 17:06:51 +08:00
contrib Fix various typos in codebase (#35480) 2025-09-13 10:34:43 -04:00
custom/conf Improve instance wide ssh commit signing (#34341) 2025-06-11 10:32:55 +00:00
docker feat: add riscv64 support (#34199) 2025-04-14 16:32:54 +00:00
models Move some functions to gitrepo package (#35543) 2025-10-07 17:06:51 +08:00
modules Fixing issue #35530: Password Leak in Log Messages (#35584) 2025-10-07 09:26:47 -07:00
options [skip ci] Updated translations via Crowdin 2025-10-05 00:38:21 +00:00
public Update JS and PY dependencies (#35444) 2025-09-10 02:30:20 +02:00
routers Move some functions to gitrepo package (#35543) 2025-10-07 17:06:51 +08:00
services Move some functions to gitrepo package (#35543) 2025-10-07 17:06:51 +08:00
snap go1.25.0 (#35262) 2025-08-15 18:13:24 +08:00
templates feat: adds option to force update new branch in contents routes (#35592) 2025-10-06 21:23:14 -07:00
tests Move some functions to gitrepo package (#35543) 2025-10-07 17:06:51 +08:00
tools Update js dependencies (#35429) 2025-09-07 18:50:44 +02:00
web_src fix: auto-expand and auto-scroll for actions logs (#35570) (#35583) 2025-10-05 10:31:06 +08:00
.air.toml Reduce air verbosity (#31417) 2024-06-19 19:42:06 +00:00
.changelog.yml Update .changelog file to add performance label group (#33472) 2025-02-02 06:40:39 +00:00
.dockerignore Switch to pnpm (#35274) 2025-09-04 01:17:14 +00:00
.editorconfig Cover go.mod and go.sum in .editorconfig (#33960) 2025-03-21 20:48:06 +00:00
.envrc Enable direnv (#31672) 2024-07-23 12:07:41 +00:00
.gitattributes Update JS and PY deps (#34143) 2025-04-07 21:42:32 -07:00
.gitignore feat: adds option to force update new branch in contents routes (#35592) 2025-10-06 21:23:14 -07:00
.gitpod.yml Remove sqlite-viewer and using database client (#31223) 2024-06-03 10:41:29 +00:00
.golangci.yml Enable gocritic equalFold and fix issues (#34952) 2025-07-06 16:53:34 +00:00
.ignore Clean bindata (#34728) 2025-06-16 12:03:51 +00:00
.mailmap [chore] add git mailmap for proper attribution of authorship (#33612) 2025-02-16 20:49:28 +08:00
.markdownlint.yaml Enable markdownlint no-trailing-punctuation and no-blanks-blockquote (#29214) 2024-02-17 13:18:05 +00:00
.npmrc Switch to pnpm (#35274) 2025-09-04 01:17:14 +00:00
.spectral.yaml Add spectral linter for Swagger (#20321) 2022-07-11 18:07:16 -05:00
.yamllint.yaml fully replace drone with actions (#27556) 2023-10-11 06:39:32 +00:00
BSDmakefile Fix build errors on BSD (in BSDMakefile) (#27594) 2023-10-13 15:38:27 +00:00
build.go Refactor embedded assets and drop unnecessary dependencies (#34692) 2025-06-12 03:59:33 +00:00
CHANGELOG-archived.md Fix changelog (main) (#30582) 2024-04-19 06:08:30 +00:00
CHANGELOG.md frontport changelog (#34689) 2025-06-11 16:58:39 +00:00
CODE_OF_CONDUCT.md Fixed minor typos in two files #HSFDPMUW (#34944) 2025-07-06 09:27:26 -07:00
CONTRIBUTING.md Docs/fix typo and grammar in CONTRIBUTING.md (#35024) 2025-07-10 06:11:42 +08:00
crowdin.yml Use Crowdin action for translation sync (#30054) 2024-03-30 18:11:50 +00:00
DCO Remove address from DCO (#22595) 2023-01-24 18:52:38 +00:00
Dockerfile Support Node.js 22.6 with type stripping (#35427) 2025-09-07 08:02:06 +00:00
Dockerfile.rootless Support Node.js 22.6 with type stripping (#35427) 2025-09-07 08:02:06 +00:00
eslint.config.ts Update eslint to v9 (#35485) 2025-09-14 19:15:06 +03:00
flake.lock nix flake use go1.25 (#35288) 2025-08-16 02:47:39 +08:00
flake.nix Switch to pnpm (#35274) 2025-09-04 01:17:14 +00:00
go.mod Use inputs context when parsing workflows (#35590) 2025-10-06 06:09:27 +02:00
go.sum Use inputs context when parsing workflows (#35590) 2025-10-06 06:09:27 +02:00
LICENSE Fix typo 2016-11-08 08:42:05 +01:00
main.go Migrate to urfave v3 (#34510) 2025-06-10 12:35:12 +00:00
main_timezones.go add timetzdata build tag to binary releases (#33463) 2025-02-05 04:17:08 +00:00
MAINTAINERS apply as maintainer (#35424) 2025-09-06 09:56:18 -07:00
Makefile use experimental go json v2 library (#35392) 2025-09-28 08:03:36 +00:00
package.json Use bundled version of spectral (#35573) 2025-10-03 22:25:09 +00:00
playwright.config.ts Add initial typescript config and use it for eslint,vitest,playwright (#31186) 2024-06-28 16:15:51 +00:00
pnpm-lock.yaml Use bundled version of spectral (#35573) 2025-10-03 22:25:09 +00:00
pyproject.toml Replace poetry with uv (#35084) 2025-07-15 21:19:39 +00:00
README.md Switch to pnpm (#35274) 2025-09-04 01:17:14 +00:00
README.zh-cn.md docs: add Chinese translations for README files (#34132) 2025-04-07 11:11:48 -07:00
README.zh-tw.md docs: add Chinese translations for README files (#34132) 2025-04-07 11:11:48 -07:00
SECURITY.md Upgrade security public key (#34956) 2025-07-05 10:11:41 -04:00
stylelint.config.ts Migrate tools and configs to typescript, require node.js >= 22.18.0 (#35421) 2025-09-06 12:58:25 +00:00
tailwind.config.ts Migrate tools and configs to typescript, require node.js >= 22.18.0 (#35421) 2025-09-06 12:58:25 +00:00
tsconfig.json Enable a few more tsconfig options (#35553) 2025-09-30 21:43:41 -07:00
types.d.ts Clean up npm dependencies (#35508) 2025-09-17 21:39:44 +00:00
updates.config.ts Clean up npm dependencies (#35484) 2025-09-15 16:34:54 +02:00
uv.lock Update JS and PY deps (#35565) 2025-10-02 08:45:56 +02:00
vitest.config.ts Convert frontend code to typescript (#31559) 2024-07-07 15:32:30 +00:00
webpack.config.ts Clean up npm dependencies (#35508) 2025-09-17 21:39:44 +00:00

Gitea

Contribute with Gitpod

繁體中文 | 简体中文

Purpose

The goal of this project is to make the easiest, fastest, and most painless way of setting up a self-hosted Git service.

As Gitea is written in Go, it works across all the platforms and architectures that are supported by Go, including Linux, macOS, and Windows on x86, amd64, ARM and PowerPC architectures. This project has been forked from Gogs since November of 2016, but a lot has changed.

For online demonstrations, you can visit demo.gitea.com.

For accessing free Gitea service (with a limited number of repositories), you can visit gitea.com.

To quickly deploy your own dedicated Gitea instance on Gitea Cloud, you can start a free trial at cloud.gitea.com.

Documentation

You can find comprehensive documentation on our official documentation website.

It includes installation, administration, usage, development, contributing guides, and more to help you get started and explore all features effectively.

If you have any suggestions or would like to contribute to it, you can visit the documentation repository

Building

From the root of the source tree, run:

TAGS="bindata" make build

or if SQLite support is required:

TAGS="bindata sqlite sqlite_unlock_notify" make build

The build target is split into two sub-targets:

Internet connectivity is required to download the go and npm modules. When building from the official source tarballs which include pre-built frontend files, the frontend target will not be triggered, making it possible to build without Node.js.

More info: https://docs.gitea.com/installation/install-from-source

Using

After building, a binary file named gitea will be generated in the root of the source tree by default. To run it, use:

./gitea web

Note

If you're interested in using our APIs, we have experimental support with documentation.

Contributing

Expected workflow is: Fork -> Patch -> Push -> Pull Request

Note

  1. YOU MUST READ THE CONTRIBUTORS GUIDE BEFORE STARTING TO WORK ON A PULL REQUEST.
  2. If you have found a vulnerability in the project, please write privately to security@gitea.io. Thanks!

Translating

Crowdin

Translations are done through Crowdin. If you want to translate to a new language, ask one of the managers in the Crowdin project to add a new language there.

You can also just create an issue for adding a language or ask on Discord on the #translation channel. If you need context or find some translation issues, you can leave a comment on the string or ask on Discord. For general translation questions there is a section in the docs. Currently a bit empty, but we hope to fill it as questions pop up.

Get more information from documentation.

Official and Third-Party Projects

We provide an official go-sdk, a CLI tool called tea and an action runner for Gitea Action.

We maintain a list of Gitea-related projects at gitea/awesome-gitea, where you can discover more third-party projects, including SDKs, plugins, themes, and more.

Communication

If you have questions that are not covered by the documentation, you can get in contact with us on our Discord server or create a post in the discourse forum.

Authors

Backers

Thank you to all our backers! 🙏 [Become a backer]

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]

FAQ

How do you pronounce Gitea?

Gitea is pronounced /ɡɪti:/ as in "gi-tea" with a hard g.

Why is this not hosted on a Gitea instance?

We're working on it.

Where can I find the security patches?

In the release log or the change log, search for the keyword SECURITY to find the security patches.

License

This project is licensed under the MIT License. See the LICENSE file for the full license text.

Further information

Looking for an overview of the interface? Check it out!

Login/Register Page

Login Register

User Dashboard

Home Issues Pull Requests Milestones

User Profile

Profile

Explore

Repos Users Orgs

Repository

Home Commits Branches Labels Milestones Releases Tags

Repository Issue

List Issue

Repository Pull Requests

List Pull Request File Commits

Repository Actions

List Details

Repository Activity

Activity Contributors Code Frequency Recent Commits

Organization

Home