<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Gitea?</title>
    <link>https://bumplog.org/apps/gitea/</link>
    <description>Update-safety verdicts for Gitea (go-gitea/gitea), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/gitea/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Gitea v1.26.4 — Safe to update</title>
      <link>https://bumplog.org/apps/gitea/</link>
      <guid isPermaLink="false">bumplog:app:gitea:v1.26.4:safe</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>Safe to update. v1.26.4 contains only a security fix preventing disabled users from being auto-reactivated via OAuth2 and a single bug fix for git log context error handling. The release notes call out no breaking changes, required migrations, or manual upgrade steps. What changed: v1.26.4 is a focused patch release shipping one security fix and one bug fix. The security change closes a gap where disabled user accounts could be silently reactivated when logging in through an OAuth2 provider; disabled accounts now remain inactive after the OAuth2 callback completes. A separate bug fix improves error handling during git log traversal, preventing context errors from being silently ignored. Source release: https://github.com/go-gitea/gitea/releases/tag/v1.26.4</description>
    </item>
  </channel>
</rss>
