jojo/release-notes-published/14.0.4.md
forgejo-release-manager 43075c080a chore(release-notes): Forgejo v14.0.4 [skip ci] (#12074)
https://codeberg.org/forgejo/forgejo/milestone/67354
Co-authored-by: 0ko <0ko@noreply.codeberg.org>
Co-authored-by: viceice <michael.kriese@gmx.de>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12074
Reviewed-by: Michael Kriese <michael.kriese@gmx.de>
Reviewed-by: 0ko <0ko@noreply.codeberg.org>
Co-authored-by: forgejo-release-manager <contact-forgejo-release-manager@forgejo.org>
Co-committed-by: forgejo-release-manager <contact-forgejo-release-manager@forgejo.org>
2026-04-10 14:50:59 +02:00

6.6 KiB

Release notes

  • Security bug fixes
    • PR: Update dependency go to v1.25.9 (v14.0/forgejo)
  • User Interface bug fixes
    • PR (backported): Make overflow-menu Web Component scroll / overflow with JS off
  • Localization
  • Bug fixes
    • PR (backported): fix: out of synchronization error after interrupting a PR merge by user-agent disconnect
    • PR (backported): fix: comment attachment API is more restrictive than the web UI
    • PR (backported): fix: don't trip deleting attachment with missing permission error
  • Included for completeness but not user-facing (chores, etc.)
    • PR: Update dependency happy-dom to v20.8.9 [SECURITY] (v14.0/forgejo)
    • PR (backported): PAM: portable error reporting
    • PR: Update github.com/go-git/go-git/v5 (indirect) to v5.17.1 [SECURITY] (v14.0/forgejo)
    • PR: Update dependency happy-dom to v20.8.8 [SECURITY] (v14.0/forgejo)
    • PR: Update module golang.org/x/net to v0.51.0 [SECURITY] (v14.0/forgejo)
    • PR: Update module golang.org/x/image to v0.38.0 [SECURITY] (v14.0/forgejo)
    • PR (backported): ci: update tests to run debian trixie, remove manual installation from testing
    • PR (backported): fix: prevent container registry headers from leaking into other registries
    • PR (backported): fix: remove template file from generated repo
    • PR (backported): chore(deps): bump xorm to v1.3.9-forgejo.8
    • PR (backported): fix: remove second challenge from WWW-Authenticate header
    • PR (backported): fix: webhook/discord: omit empty embeds.footer from the payload for Spacebar compatibility
    • PR (backported): fix(issue-search): delete issue from indexer on DeleteIssue
    • PR (backported): fix: enforce package quota against package owner, not uploader