xds/rbac: apply header matcher checks to nested and/or/not rules - #9258
Merged
Merged
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #9258 +/- ##
==========================================
- Coverage 83.30% 83.15% -0.15%
==========================================
Files 420 423 +3
Lines 34106 35261 +1155
==========================================
+ Hits 28413 29323 +910
- Misses 4260 4427 +167
- Partials 1433 1511 +78
🚀 New features to boost your workflow:
|
Contributor
Author
|
gentle ping |
easwars
approved these changes
Aug 6, 2026
easwars
left a comment
Contributor
There was a problem hiding this comment.
LGTM, modulo couple of minor nits
Comment on lines
+173
to
+175
| if name == ":scheme" || strings.HasPrefix(name, "grpc-") { | ||
| return fmt.Errorf("rbac: header matcher for %v is :scheme or starts with grpc", name) | ||
| } |
Contributor
There was a problem hiding this comment.
Nit: Can we split the check so that we get a finer grained error and use %q formatting directive:
if name == ":scheme" {
return fmt.Errorf("rbac: header matcher for %q is %q", name, ":scheme")
}
if strings.HasPrefix(name, "grpc-") {
return fmt.Errorf("rbac: header matcher for %q starts with %q", name, "grpc-")
}
Contributor
Author
There was a problem hiding this comment.
Done, split into two checks with %q.
|
|
||
| gotPerm := perm.GetRule().(*v3rbacpb.Permission_NotRule).NotRule.GetRule().(*v3rbacpb.Permission_Header).Header.GetName() | ||
| if gotPerm != ":authority" { | ||
| t.Errorf("nested permission host matcher name = %q, want %q", gotPerm, ":authority") |
Contributor
There was a problem hiding this comment.
Nit: here and down below s/nested/Nested
Contributor
Author
There was a problem hiding this comment.
Done, capitalized both.
easwars
approved these changes
Aug 10, 2026
Contributor
|
@nvxbug Thank you for your contribution! |
easwars
pushed a commit
to easwars/grpc-go
that referenced
this pull request
Aug 19, 2026
…c#9258) parseConfig only walks the top-level Permissions and Principals of each RBAC policy when it applies the A41 header-name rules, so a header matcher nested inside an and_rules, or_rules, or not_rule is never checked. A control plane can put a `:scheme` or `grpc-` prefixed matcher inside a nested rule to slip past the validation A41 says must reject it, and a nested `host` matcher never gets rewritten to `:authority`, so it silently fails to match the header grpc-go actually carries (a deny policy on a nested host matcher fails open). Walk the full permission and principal trees so both the :scheme/grpc- rejection and the host to :authority rewrite reach matchers at any depth. Doing it in parseConfig keeps the check in the one place that already owns A41 validation, and folds the two former top-level passes into a single recursive walk shared by permissions and principals. RELEASE NOTES: - xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. - xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. (cherry picked from commit 1f4c6f3)
easwars
added a commit
that referenced
this pull request
Aug 19, 2026
Original PRs: #9258 and #9332 RELEASE NOTES: - xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. - xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. - xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. - xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. - xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. --------- Co-authored-by: Naveed <naveed@bugqore.com> Co-authored-by: Markus Magnuson <331091+alimony@users.noreply.github.com>
eleboucher
pushed a commit
to eleboucher/runner-k8s-plugin
that referenced
this pull request
Aug 19, 2026
…(#83) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.0` → `v1.83.1` |  |  | --- ### Release Notes <details> <summary>grpc/grpc-go (google.golang.org/grpc)</summary> ### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1 [Compare Source](grpc/grpc-go@v1.83.0...v1.83.1) ### Security - xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) ### Performance - transport: Restrict memory overhead of buffering small data frames. ([#​9331](grpc/grpc-go#9331)) ### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0 [Compare Source](grpc/grpc-go@v1.82.1...v1.83.0) ### Security - server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`. - xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions. - xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`. - xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#​9223](grpc/grpc-go#9223)) ### New Features - xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#​9133](grpc/grpc-go#9133)) - xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. ([#​9145](grpc/grpc-go#9145)) - authz: Add `OnPolicyUpdate` callback to `FileWatcherOptions` to notify when an authz policy is loaded or updated. ([#​9142](grpc/grpc-go#9142)) - Special Thanks: [@​hnefatl](https://github.com/hnefatl) - xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true`. ([#​9119](grpc/grpc-go#9119)) - xds: Add support for xDS-based HTTP CONNECT proxies. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true`. ([#​9151](grpc/grpc-go#9151)) - xds: Add support for `contains_match` in route header matchers. ([#​9223](grpc/grpc-go#9223)) ### Bug Fixes - credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. ([#​9197](grpc/grpc-go#9197)) - grpc: Fix compilation on Plan 9 targets (`GOOS=plan9`), broken since v1.81.0. ([#​9255](grpc/grpc-go#9255)) - Special Thanks: [@​Yusufihsangorgel](https://github.com/Yusufihsangorgel) ### [`v1.82.1`](https://github.com/grpc/grpc-go/releases/tag/v1.82.1): Release 1.82.1 [Compare Source](grpc/grpc-go@v1.82.0...v1.82.1) ### Security - server: Stop reading from the connection when flooded by HTTP/2 frames. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`. - xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions. - xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`. </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Paris) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjMxLjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInR5cGUvbWlub3IiXX0=--> Reviewed-on: https://git.erwanleboucher.dev/eleboucher/runner-k8s-plugin/pulls/83
nschloe
pushed a commit
to live-clones/forgejo
that referenced
this pull request
Sep 3, 2026
…/forgejo) (#14216) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.1` → `v1.83.1` |  |  | --- >⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2779) for more information. --- ### gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation [CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](GHSA-vp52-pcj8-j9qc) <details> <summary>More information</summary> #### Details ##### Impact An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation. Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS). ##### Patches The change to fix this issue is merged in `master` and a patch release, 1.83.1, has been published that contains this fix. ##### Workarounds This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads. This behavior is enabled by default. A temporary escape hatch is provided via the environment variable `GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false` to disable the feature if unforeseen issues arise, but it will be removed in a future release. #### Severity - CVSS Score: 8.7 / 10 (High) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N` #### References - [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc) - [https://nvd.nist.gov/vuln/detail/CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) - [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331) - [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333) - [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176) - [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77) - [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go) - [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-vp52-pcj8-j9qc) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>grpc/grpc-go (google.golang.org/grpc)</summary> ### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1 [Compare Source](grpc/grpc-go@v1.83.0...v1.83.1) ### Security - xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) ### Performance - transport: Restrict memory overhead of buffering small data frames. ([#​9331](grpc/grpc-go#9331)) ### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0 [Compare Source](grpc/grpc-go@v1.82.2...v1.83.0) ### Security - server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`. - xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions. - xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`. - xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#​9223](grpc/grpc-go#9223)) ### New Features - xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#​9133](grpc/grpc-go#9133)) - xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. ([#​9145](grpc/grpc-go#9145)) - authz: Add `OnPolicyUpdate` callback to `FileWatcherOptions` to notify when an authz policy is loaded or updated. ([#​9142](grpc/grpc-go#9142)) - Special Thanks: [@​hnefatl](https://github.com/hnefatl) - xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true`. ([#​9119](grpc/grpc-go#9119)) - xds: Add support for xDS-based HTTP CONNECT proxies. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true`. ([#​9151](grpc/grpc-go#9151)) - xds: Add support for `contains_match` in route header matchers. ([#​9223](grpc/grpc-go#9223)) ### Bug Fixes - credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. ([#​9197](grpc/grpc-go#9197)) - grpc: Fix compilation on Plan 9 targets (`GOOS=plan9`), broken since v1.81.0. ([#​9255](grpc/grpc-go#9255)) - Special Thanks: [@​Yusufihsangorgel](https://github.com/Yusufihsangorgel) ### [`v1.82.2`](https://github.com/grpc/grpc-go/releases/tag/v1.82.2): Release 1.82.2 [Compare Source](grpc/grpc-go@v1.82.1...v1.82.2) ### Security - server: Reject requests missing both `:authority` and `Host` headers with HTTP 400 and status `Internal`. ([#​9365](grpc/grpc-go#9365)) - Special Thanks: [@​winklemad](https://github.com/winklemad) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC41Mi4wIiwidXBkYXRlZEluVmVyIjoiNDQuNTIuMCIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19--> Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14216 Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
GiteaBot
pushed a commit
to go-gitea/terraform-provider-gitea
that referenced
this pull request
Sep 25, 2026
… (#211) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.1` → `v1.83.1` |  |  | --- ### gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers [CVE-2026-84445](https://nvd.nist.gov/vuln/detail/CVE-2026-84445) / [GHSA-2v4p-qf9q-27wj](GHSA-2v4p-qf9q-27wj) / [GO-2026-6443](https://pkg.go.dev/vuln/GO-2026-6443) <details> <summary>More information</summary> #### Details A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS). Servers built with `xds.NewGRPCServer` install an xDS routing interceptor on every RPC. This interceptor looks up the request’s `:authority` header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither `:authority` nor `Host`. When this happened, the xDS routing interceptor attempted to access the first element of an empty slice of authorities, leading to an index out of bounds panic. Since the per-RPC goroutine does not recover from panics, the entire server process would terminate. This panic occurs in the interceptor pipeline, meaning the transport credentials handshake (TLS, mTLS, or ALTS) and HTTP/2 connection establishment must complete successfully before the crafted request can reach this logic. - Insecure/Standard TLS: If the server permits insecure (plaintext) connections or standard credentials (where client certs are not checked), any unauthenticated remote attacker can trigger the crash. - mTLS / ALTS: If strict transport-level authentication is enforced at the network edge or transport layer (e.g., requiring a valid client certificate), the attacker must possess valid transport credentials to initiate the stream and trigger the panic. ##### Impact An attacker can cause a complete outage of the gRPC server by sending a request missing both `:authority` and `Host` headers, provided they can successfully establish a transport connection. ##### Patches The issue has been addressed in `master` (and backported to `1.83.2` and `1.82.2`). The fix updates the HTTP/2 transport layer to reject requests missing both `:authority` and `Host` headers early, maintaining consistency with and other gRPC language implementations. #### Severity High #### References - [https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj](https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj) - [https://github.com/grpc/grpc-go/issues/9354](https://github.com/grpc/grpc-go/issues/9354) - [https://github.com/grpc/grpc-go/pull/9365](https://github.com/grpc/grpc-go/pull/9365) - [https://github.com/grpc/grpc-go/pull/9366](https://github.com/grpc/grpc-go/pull/9366) - [https://github.com/grpc/grpc-go/pull/9367](https://github.com/grpc/grpc-go/pull/9367) - [https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7](https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7) - [https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4](https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4) - [https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f](https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f) - [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go) - [https://github.com/grpc/grpc-go/releases/tag/v1.82.2](https://github.com/grpc/grpc-go/releases/tag/v1.82.2) - [https://github.com/grpc/grpc-go/releases/tag/v1.83.2](https://github.com/grpc/grpc-go/releases/tag/v1.83.2) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-2v4p-qf9q-27wj) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Server panic via missing authority or Host headers in google.golang.org/grpc [CVE-2026-84445](https://nvd.nist.gov/vuln/detail/CVE-2026-84445) / [GHSA-2v4p-qf9q-27wj](GHSA-2v4p-qf9q-27wj) / [GO-2026-6443](https://pkg.go.dev/vuln/GO-2026-6443) <details> <summary>More information</summary> #### Details In google.golang.org/grpc, servers configured with xDS routing can panic when processing requests that lack both :authority and Host headers. The HTTP/2 transport layer accepted requests missing these headers, and the xDS server routing interceptor attempted to index the empty authority slice, causing an unhandled panic and terminating the server. #### Severity Unknown #### References - [https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj](https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj) - [https://github.com/grpc/grpc-go/issues/9354](https://github.com/grpc/grpc-go/issues/9354) - [https://github.com/grpc/grpc-go/pull/9365](https://github.com/grpc/grpc-go/pull/9365) This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6443) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)). </details> --- ### gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion [CVE-2026-84303](https://nvd.nist.gov/vuln/detail/CVE-2026-84303) / [GHSA-qc2q-p7wx-3px3](GHSA-qc2q-p7wx-3px3) / [GO-2026-6441](https://pkg.go.dev/vuln/GO-2026-6441) <details> <summary>More information</summary> #### Details ##### Summary A vulnerability in the xDS RBAC HTTP filter implementation in grpc-go allows remote attackers to bypass authorization policies (specifically DENY rules) by using mixed-case or canonical-case header matchers (e.g., X-Role instead of x-role). Additionally, the safety guards introduced by gRFC A41 to block grpc- prefixed headers can be evaded via variations in casing (e.g., Grpc-Status). ##### Impact When an operator defines an RBAC policy referencing headers containing uppercase letters (e.g. X-Role), grpc-go fails to match incoming metadata keys because they are unconditionally lowercased. Because of this case-sensitivity mismatch, a policy designed to block requests containing specific header values fails open: the rule is evaluated as a non-match, and traffic that should have been rejected is served. Furthermore, gRFC A41 requires rejecting configuration schemas specifying header matchers starting with grpc-. Because this check is executed case-sensitively in grpc-go, attackers can bypass the validation by specifying titles like Grpc-Status. ##### Patches The problem is fixed in `master` and in the 1.83.1 release. #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` #### References - [https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3](https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3) - [https://nvd.nist.gov/vuln/detail/CVE-2026-84303](https://nvd.nist.gov/vuln/detail/CVE-2026-84303) - [https://github.com/grpc/grpc-go/pull/9332](https://github.com/grpc/grpc-go/pull/9332) - [https://github.com/grpc/grpc-go/pull/9335](https://github.com/grpc/grpc-go/pull/9335) - [https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8](https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8) - [https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe](https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe) - [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go) - [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-qc2q-p7wx-3px3) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation [CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](GHSA-vp52-pcj8-j9qc) / [GO-2026-6348](https://pkg.go.dev/vuln/GO-2026-6348) <details> <summary>More information</summary> #### Details ##### Impact An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation. Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS). ##### Patches The change to fix this issue is merged in `master` and a patch release, 1.83.1, has been published that contains this fix. ##### Workarounds This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads. This behavior is enabled by default. A temporary escape hatch is provided via the environment variable `GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false` to disable the feature if unforeseen issues arise, but it will be removed in a future release. #### Severity - CVSS Score: 8.7 / 10 (High) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N` #### References - [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc) - [https://nvd.nist.gov/vuln/detail/CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) - [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331) - [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333) - [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176) - [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77) - [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go) - [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-vp52-pcj8-j9qc) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc [CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](GHSA-vp52-pcj8-j9qc) / [GO-2026-6348](https://pkg.go.dev/vuln/GO-2026-6348) <details> <summary>More information</summary> #### Details Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc #### Severity Unknown #### References - [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc) - [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176) - [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77) - [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331) - [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333) - [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1) This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6348) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)). </details> --- ### Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc [CVE-2026-84303](https://nvd.nist.gov/vuln/detail/CVE-2026-84303) / [GHSA-qc2q-p7wx-3px3](GHSA-qc2q-p7wx-3px3) / [GO-2026-6441](https://pkg.go.dev/vuln/GO-2026-6441) <details> <summary>More information</summary> #### Details In google.golang.org/grpc, the xDS RBAC HTTP filter does not lowercase header matcher names before evaluating them against incoming request metadata. When an RBAC policy defines rules (such as DENY) referencing headers with uppercase or mixed-case characters, the rule fails to match, causing authorization policies to fail open. Additionally, callers can evade gRFC A41 validation blocking "grpc-" prefixed headers and ":scheme" via variations in casing. #### Severity Unknown #### References - [https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3](https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3) - [https://github.com/grpc/grpc-go/pull/9332](https://github.com/grpc/grpc-go/pull/9332) This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6441) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)). </details> --- ### Release Notes <details> <summary>grpc/grpc-go (google.golang.org/grpc)</summary> ### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1 [Compare Source](grpc/grpc-go@v1.83.0...v1.83.1) ### Security - xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) ### Performance - transport: Restrict memory overhead of buffering small data frames. ([#​9331](grpc/grpc-go#9331)) ### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0 [Compare Source](grpc/grpc-go@v1.82.2...v1.83.0) ### Security - server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`. - xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions. - xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`. - xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#​9223](grpc/grpc-go#9223)) ### New Features - xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#​9133](grpc/grpc-go#9133)) - xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. ([#​9145](grpc/grpc-go#9145)) - authz: Add `OnPolicyUpdate` callback to `FileWatcherOptions` to notify when an authz policy is loaded or updated. ([#​9142](grpc/grpc-go#9142)) - Special Thanks: [@​hnefatl](https://github.com/hnefatl) - xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true`. ([#​9119](grpc/grpc-go#9119)) - xds: Add support for xDS-based HTTP CONNECT proxies. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true`. ([#​9151](grpc/grpc-go#9151)) - xds: Add support for `contains_match` in route header matchers. ([#​9223](grpc/grpc-go#9223)) ### Bug Fixes - credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. ([#​9197](grpc/grpc-go#9197)) - grpc: Fix compilation on Plan 9 targets (`GOOS=plan9`), broken since v1.81.0. ([#​9255](grpc/grpc-go#9255)) - Special Thanks: [@​Yusufihsangorgel](https://github.com/Yusufihsangorgel) ### [`v1.82.2`](https://github.com/grpc/grpc-go/releases/tag/v1.82.2): Release 1.82.2 [Compare Source](grpc/grpc-go@v1.82.1...v1.82.2) ### Security - server: Reject requests missing both `:authority` and `Host` headers with HTTP 400 and status `Internal`. ([#​9365](grpc/grpc-go#9365)) - Special Thanks: [@​winklemad](https://github.com/winklemad) </details> --- Reviewed-on: https://gitea.com/gitea/terraform-provider-gitea/pulls/211 Reviewed-by: Lunny Xiao <xiaolunwen@gmail.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Jercik
added a commit
to Jercik/forgejo
that referenced
this pull request
Oct 3, 2026
* [v16.0/forgejo] fix: prevent panic by returning error if dbfs file does not exist (#13697)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13649
Resolves https://codeberg.org/forgejo/forgejo/issues/13636.
Co-authored-by: Andreas Ahlenstorf <andreas@ahlenstorf.ch>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13697
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] fix: bad quoting in hook scripts allow word splitting, leading to hook script errors (#13726)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13679
Should fix #13662
Co-authored-by: erik <erik_se@posteo.de>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13726
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] fix: trigger Actions for original commits (#13706) (#13736)
Resolves https://codeberg.org/forgejo/forgejo/issues/12572.
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13706
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
(cherry picked from commit 43ced2b1c0360005e8c59ed5ab9ea326485a9ef4)
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13736
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] fix: send 401 responses when accessing endpoints that don't support session auth (#13742)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13740
Fixes #13555.
Floccus is a browser extension which supports git-based syncing. It does not isolate its cookie jar, and so requests to the git endpoints send browser cookies. Forgejo doesn't permit session cookies to access to git endpoints (changed in v16 https://codeberg.org/forgejo/forgejo/pulls/12715#issuecomment-15841751), but the presence of the cookies would trigger Forgejo into redirecting the request to `/user/login` rather than providing a `401 Unauthorized` response. Floccus requires a 401 unauthorized response in order to send its configured credentials; so it would get stuck in a redirect loop even though it had credentials available, never sending them.
After manual testing, an additional change was added to prevent Floccus' behaviour from invalidating the user's perfectly valid session, which would occur when the first `401 Unauthorized` response was issued. Now, session invalidation only occurs if session authentication was attempted.
## Testing
In addition to automated testing, this issue was reproduced interactively with the Floccus browser extension, both experiencing the problem, and testing the fix. "Remember Me" cookie persistence was also revalidated manually by removing session cookies and reaccessing Forgejo, verifying new session cookies were provisioned.
Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13742
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] fix: error when replying to comments on removed lines-of-code in review (#13766)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13718
When a pull request review comment is placed on a `previous` line -- a line that was removed in the PR, or a line on the left-hand-side of the diff -- it is not possible to reply to the comment. A 500 error will occur when posting the comment, and the server will log an error similar to this:
```
testlogger.go:411: 2026/07/31 14:06:54 .../repo/pull_review.go:135:CreateCodeComment() [E] CreateCodeComment: LineBlame[refs/pull/1/head, /tmp/TestPullRequestCommentPlacement1823572717/001/user2/repo-testpullrequestcommentplacement_reply_to_review_on_removed_change-f58f427a.git, file1.md, -50]: exit status 128 - fatal: bad revision ''
- fatal: bad revision ''
```
The cause is that when creating a comment, Forgejo is attempting to fill out a variety of fields such as the commit SHA and patch for the comment, even in a reply. Replies to positive line numbers (`proposed` lines) check for existing comments that are being replied to, and copy those fields from the original comment. Replies to negative line numbers (`previous` lines) did not hit this code path.
The fix is to run the search for the comment being replied to in both cases.
Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13766
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* Update dependency postcss to v8.5.23 [SECURITY] (v16.0/forgejo) (#13762)
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13762
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix: exclude deleted artifacts when calculating storage consumption (#13798)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13786
Resolves https://codeberg.org/forgejo/forgejo/issues/13781.
Co-authored-by: Andreas Ahlenstorf <andreas@ahlenstorf.ch>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13798
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix: use HTML link for pull request webhook (#13802)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13692
- Resolves forgejo/forgejo#13501
- Regression of forgejo/forgejo!12643, I would argue that the webhook code should've used `HTMLURL` already instead (all the other events already do).
Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13802
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* Update dependency mermaid to v11.16.1 [SECURITY] (v16.0/forgejo) (#13809)
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13809
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* fix(ui): hashbox alignment (#13768) (#13810)
Backport: https://codeberg.org/forgejo/forgejo/pulls/13768
---
Followup to forgejo/forgejo!7822, forgejo/forgejo!8721
Fix signature part not filling the whole height, fix vertical alignment of placeholder avatar. With a little E2E test verifying just one property. We don't have any E2E coverage for hashbox, so we finally gain some as a foundation.
(cherry picked from commit a67fbbd87d07e3adc5e771fcd247bcef6f3dac14)
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13810
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix(package/pypi): response header based on PEP691 (#13816)
The response Content-Type doesn't match PEP691 so `uv` is rejecting it.
```
error: Unsupported `Content-Type` "application/json" for ...
Expected JSON or HTML.
```
Resolves #13703
Co-authored-by: trim21 <trim21@noreply.codeberg.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13816
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix: bump minimum version to use git-replay on (#13824)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13591
While git-replay is generally available since version 2.44, until a fix
released with version 2.54 it will spawn empty commits if a commit was
already part of the base branch, instead of skipping it like git-rebase.
See https://github.com/git/git/commit/0ee71f4bd035db61342c2c5a25984e4545347c11
Co-authored-by: BtbN <btbn@btbn.de>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13824
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix: prevent Actions trigger `pull_request` from drifting (#13828)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13752
The `pull_request` Actions trigger suffers from the problem described in https://codeberg.org/forgejo/forgejo/issues/12572, too. Follow-up to https://codeberg.org/forgejo/forgejo/pulls/13706.
Co-authored-by: Andreas Ahlenstorf <andreas@ahlenstorf.ch>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13828
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>
* [v16.0/forgejo] chore: retry diff page load on TestPullRequestCommentPlacement when expected commit isn't matched (#13825)
**Backport:** #13808
Fixes #13275, an intermittent test failure.
The cause of this failure was identified in https://codeberg.org/forgejo/forgejo/issues/13275#issuecomment-20580638, but efforts to fix the queuing proved implausible at the moment (immediate mode execution caused deadlocks between multiple interacting systems). This is a simple fix for the test failure, reloading the page if the concurrent work to sync the PR reference isn't complete yet.
Backport from `forgejo` to `v16.0/forgejo` required incorporation of diagnostic changes from #13757 which added the new parameter to `assertFilesChangedDiff`, and otherwise involved no conflicts.
(cherry picked from commit 2fdeaf24b902cca5dee56eeaae48d4e6714e8270)
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13808
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13825
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] chore: make `TestCannotCreatePrivateKey` pass in Guix container (#13836)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13794
`/dev` is writable in Guix container. Use a directory at the root of the file system, more likely to not be writable in containers.
Co-authored-by: Maxim Cournoyer <maxim@guixotic.coop>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13836
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix(api): unblock fall-through to urlencoded names in wiki (#13842)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13720
Helps with https://codeberg.org/forgejo/forgejo/issues/13719
Co-authored-by: Ben Tasker <bentasker@noreply.codeberg.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13842
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] fix: expire task logs even if there is no log file (#13851)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13839
Resolves https://codeberg.org/forgejo/forgejo/issues/13790.
Co-authored-by: Andreas Ahlenstorf <andreas@ahlenstorf.ch>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13851
Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org>
* [v16.0/forgejo] webhook(matrix): fix stateKey collision swallowing messages (#13862)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13820
The previous stateKey computation depended on the sent text, which could
be the same for 2 events (e.g. a user makes 2 comments on the same PR).
Fixes #13813
Co-authored-by: oliverpool <git@olivier.pfad.fr>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13862
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
Reviewed-by: oliverpool <oliverpool@noreply.codeberg.org>
* [v16.0/forgejo] fix(conda): parse null dependencies as empty array (#13871)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13865
- It's possible for the package upload to indicate there's no
dependencies via the `null` value. However, as does Conda itself, the
such value is still transformed to a empty array.
- Remove `omitempty` so a empty array value is stored (in the database)
and send (to the API consumer) explicitly.
- Resolves forgejo/forgejo#13413
Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13871
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>
* [v16.0/forgejo] fix(api): mark fields for issue dependencies/blocks as required (#13872)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13864
Ref: forgejo/forgejo#13439
The description of the API routes already make it clear that this struct (as HTTP body) should used to specify the dependency/block/target issue.
Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13872
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>
* [v16.0/forgejo] fix: do not read past the last line when formatting zoekt search results (#13889)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13811
When `REPO_INDEXER_TYPE = zoekt` is used, a code search could fail if the last line of a file matches but does not include a newline.
```
PANIC: runtime error: index out of range [2] with length 2
...
forgejo.org/modules/indexer/code/zoekt/zoekt.go:510 (0x62223da)
forgejo.org/modules/indexer/code/search.go:76 (0x622c483)
forgejo.org/modules/indexer/code/search.go:140 (0x622cf44)
...
```
Clamp the upper bound to the number of lines that actually exist.
Co-authored-by: nsprd <nsprd@pm.me>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13889
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix: adopt repositories from user settings (#13902)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13659
Regression of forgejo/forgejo!10287
## Test
1. Go to your forgejo's data directory, inside that the directory where the git repositories are stored.
2. Go to a directory of any user you've access to, run inside of that directory `git init --bare pr-13659.git`.
3. Navigate to `/user/settings/repos`
4. Observe that there's a repository you can adopt, and that the dialog associated with the buttons works.
Reported-by: 0ko
Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13902
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* Update go toolchain directive to v1.26.6 [SECURITY] (v16.0/forgejo) (#13915)
* Update golang.org/x/mod (indirect) to v0.40.0 [SECURITY] (v16.0/forgejo) (#13916)
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/mod](https://pkg.go.dev/golang.org/x/mod) | [`v0.37.0` → `v0.40.0`](https://cs.opensource.google/go/x/mod/+/refs/tags/v0.37.0...refs/tags/v0.40.0) |  |  |
---
### Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
[CVE-2026-56865](https://nvd.nist.gov/vuln/detail/CVE-2026-56865) / [GO-2026-6179](https://pkg.go.dev/vuln/GO-2026-6179)
<details>
<summary>More information</summary>
#### Details
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache.
This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log.
All tiles are now correctly verified against their parents.
In order to determine if you have been affected:
rm -r go.sum go.work.sum vendor/ && go mod tidy
#### Severity
Unknown
#### References
- [https://go.dev/issue/80744](https://go.dev/issue/80744)
- [https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
- [https://go.dev/cl/814960](https://go.dev/cl/814960)
- [https://go.dev/cl/815020](https://go.dev/cl/815020)
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6179) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>
---
### Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
[CVE-2026-56864](https://nvd.nist.gov/vuln/detail/CVE-2026-56864) / [GO-2026-6180](https://pkg.go.dev/vuln/GO-2026-6180)
<details>
<summary>More information</summary>
#### Details
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log.
This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log.
In order to determine if you have been affected:
rm -r go.sum go.work.sum vendor/ && go mod tidy
#### Severity
Unknown
#### References
- [https://go.dev/issue/80745](https://go.dev/issue/80745)
- [https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
- [https://go.dev/cl/815000](https://go.dev/cl/815000)
- [https://go.dev/cl/815020](https://go.dev/cl/815020)
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6180) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNy4xIiwidXBkYXRlZEluVmVyIjoiNDQuMTcuMSIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13916
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>
* Update module golang.org/x/image to v0.45.0 [SECURITY] (v16.0/forgejo) (#13927)
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13927
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] i18n: translations update from Codeberg Translate
Backport: https://codeberg.org/forgejo/forgejo/pulls/13467
Translation updates that were relevant to v16 branch were picked from this commit: 17d255ae08fb883244b17feab9910c63407e8d3b
Changes to strings that are only present in the newer branches were not picked.
Below is a list of co-authors of the ported commit. It may contain co-authors who's changes were not picked due to only being relevant to newer branches.
Co-authored-by: 0ko <0ko@noreply.codeberg.org>
Co-authored-by: 20Niko10 <20niko10@noreply.codeberg.org>
Co-authored-by: Atalanttore <atalanttore@noreply.codeberg.org>
Co-authored-by: Benedikt Straub <benedikt-straub@web.de>
Co-authored-by: Codeberg Translate <translate@codeberg.org>
Co-authored-by: Cyborus <cyborus@noreply.codeberg.org>
Co-authored-by: Edgarsons <edgarsons@noreply.codeberg.org>
Co-authored-by: Elviska <elviska@noreply.codeberg.org>
Co-authored-by: ErenayDev <erenaydev@proton.me>
Co-authored-by: Erin of Yukis <ntninja@noreply.codeberg.org>
Co-authored-by: EternalAbby <eternalabby@noreply.codeberg.org>
Co-authored-by: Fjuro <fjuro@noreply.codeberg.org>
Co-authored-by: Gusted <postmaster@gusted.xyz>
Co-authored-by: Kyush <kyush@noreply.codeberg.org>
Co-authored-by: Nikolaus Delrow <github@koolych.ru>
Co-authored-by: ShutterStarTW <shutterstartw@noreply.codeberg.org>
Co-authored-by: SomeTr <sometr@noreply.codeberg.org>
Co-authored-by: Teeed <teeed@noreply.codeberg.org>
Co-authored-by: ThinkRoot <thinkroot@noreply.codeberg.org>
Co-authored-by: WKobes <wkobes@noreply.codeberg.org>
Co-authored-by: WebSpider <webspider@noreply.codeberg.org>
Co-authored-by: Wuzzy <wuzzy@disroot.org>
Co-authored-by: Zughy <zughy@noreply.codeberg.org>
Co-authored-by: admindev <admindev@noreply.codeberg.org>
Co-authored-by: artnay <artnay@noreply.codeberg.org>
Co-authored-by: bespinas <bespinas@noreply.codeberg.org>
Co-authored-by: bittin <bittin@noreply.codeberg.org>
Co-authored-by: codeeleven <codeeleven@noreply.codeberg.org>
Co-authored-by: dennis-emstone <dennis-emstone@noreply.codeberg.org>
Co-authored-by: dsonck <dsonck@noreply.codeberg.org>
Co-authored-by: dyniec <dyniec@noreply.codeberg.org>
Co-authored-by: fbausch <fbausch@noreply.codeberg.org>
Co-authored-by: gallegonovato <gallegonovato@noreply.codeberg.org>
Co-authored-by: itscrystalline <itscrystalline@noreply.codeberg.org>
Co-authored-by: joxeankoret <joxeankoret@noreply.codeberg.org>
Co-authored-by: jsyoon <jsyoon@noreply.codeberg.org>
Co-authored-by: kaua <kaua@noreply.codeberg.org>
Co-authored-by: kdh8219 <kdh8219@monamo.dev>
Co-authored-by: khangreat <khangreat@noreply.codeberg.org>
Co-authored-by: kzzzl <kzzzl@noreply.codeberg.org>
Co-authored-by: lapor <lapor@noreply.codeberg.org>
Co-authored-by: leiho-kristal-herdoilduak <leiho-kristal-herdoilduak@noreply.codeberg.org>
Co-authored-by: m4rc3l <m4rc3l@noreply.codeberg.org>
Co-authored-by: markinosags <markinosags@noreply.codeberg.org>
Co-authored-by: menneske <menneske@noreply.codeberg.org>
Co-authored-by: ommrianxo <ommrianxo@noreply.codeberg.org>
Co-authored-by: pixelcode <pixelcode@noreply.codeberg.org>
Co-authored-by: pkkim <pkkim@noreply.codeberg.org>
Co-authored-by: sinsky <sinsky@noreply.codeberg.org>
Co-authored-by: vmtj <vmtj@noreply.codeberg.org>
Co-authored-by: woolhat <woolhat@noreply.codeberg.org>
Co-authored-by: xtex <xtexchooser@duck.com>
Co-authored-by: yitian <yitian@noreply.codeberg.org>
* fix: public-only and repo-specific access to /repos/{owner}/{repo}/pulls/{index}/update
* fix: expand local reusable workflows from base branch w/ pull_request_target
* fix: disallow owner as collaboration access mode
An repository admin could (self-)escalate to repository owner
permissions. A higher permission mode than a repository admin.
* chore: add integration test
* Update go toolchain directive to v1.26.7 (v16.0/forgejo) (#13992)
* [v16.0/forgejo] fix(security): prevent unauthorized access to draft release attachments (#14024)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13934
The `GetReleaseAttachment` API endpoint (`GET /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id}`) and the web attachment download route (`ServeAttachment`, `GET /attachments/{uuid}`) did not check whether the release is a draft. Users holding only repository **read** permission (including unauthenticated callers on public repositories) could enumerate release/attachment IDs and retrieve the metadata and the full contents of attachments belonging to draft releases that are otherwise hidden from them.
`GetRelease` and `ListReleaseAttachments` already return 404 for draft releases when the caller lacks write permission on the releases unit (added in the 2026-06-10 security patches), but these two endpoints were missed. This is the same class of issue fixed upstream by Gitea in [CVE-2026-27660](https://nvd.nist.gov/vuln/detail/CVE-2026-27660) and [GHSA-q9pg-jj6x-j9p6](https://github.com/go-gitea/gitea/security/advisories/GHSA-q9pg-jj6x-j9p6).
Co-authored-by: trim21 <trim21@noreply.codeberg.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14024
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] fix: organization team set as 'admin' is granted 'owner' permission over related repositories (#14034)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14032
Fixes #13983. An organization team that is configured as an "Administrator access" is actually being granted Owner access over the repositories associated with the team, rather than Administrator access, allowing access to transfer ownership and related owner functionality. The intended mechanism for this access to be granted is through the owner team. (While that's somewhat inflexible as it grants owner access to all repositories, this applies to a small subset of capability differences between Admin and Owner access.)
Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14034
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] fix: Add title and org name to org project header (#14065)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13586
Fixes #13585.
Signed-off-by: Nils Philippsen <nils@redhat.com>
Co-authored-by: Nils Philippsen <nils@redhat.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14065
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] chore(ci): use oci/ci:3 instead of oci/playwright:latest for e2e (#14066)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/13941
- oci/ci:3 now also have the packages playwright need pre-installed
- add a cache for the browsers so they are only downloaded when needed (over 1GB)
Co-authored-by: limiting-factor <limiting-factor@posteo.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14066
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix: codepaths where git repos are not closed correctly, may relate to leaking `git cat-file --batch[-check]` commands (#14089)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14080
While investigating the Codeberg results from #13778, I found two places where git repositories are opened by Forgejo and not closed:
- When generating the error response `could not find '%s' to be a commit, branch or tag in the head repository %s/%s` from compare API calls. As a request-bound repository, it is unlikely to have a leaking impact.
- When executing post-receive hook. As an internal API which has no timeout and is bound to the process's hammer context, it is suspicious for meeting multiple criteria for a problem identified in #13778, but without a complete explanation of how it would work. (see https://codeberg.org/forgejo/forgejo/pulls/13778#issuecomment-21663806 for more detailed analysis)
Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14089
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* Update module code.forgejo.org/xorm/xorm to v1.4.1 (v16.0/forgejo) (#14098)
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [code.forgejo.org/xorm/xorm](https://code.forgejo.org/xorm/xorm) | `v1.4.0` → `v1.4.1` |  |  |
---
### Release Notes
<details>
<summary>xorm/xorm (code.forgejo.org/xorm/xorm)</summary>
### [`v1.4.1`](https://code.forgejo.org/xorm/xorm/releases/tag/v1.4.1)
[Compare Source](https://code.forgejo.org/xorm/xorm/compare/v1.4.0...v1.4.1)
<!--start release-notes-assistant-->
<!--URL:https://code.forgejo.org/xorm/xorm-->
- bug fixes
- [PR](https://code.forgejo.org/xorm/xorm/pulls/167): <!--number 167 --><!--line 0 --><!--description Zml4OiB1c2UgYGRyaXZlci5WYWx1ZXJgIHRvIHNlcmlhbGl6ZSBgT3B0aW9uW1RdYCBpbiBgQWxsQ29scygpYA==-->fix: use `driver.Valuer` to serialize `Option[T]` in `AllCols()`<!--description-->
- other
- [PR](https://code.forgejo.org/xorm/xorm/pulls/166): <!--number 166 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL2dvbGFuZ2NpL2dvbGFuZ2NpLWxpbnQvdjIvY21kL2dvbGFuZ2NpLWxpbnQgdG8gdjIuMTMuMQ==-->Update module github.com/golangci/golangci-lint/v2/cmd/golangci-lint to v2.13.1<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/165): <!--number 165 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL3N0cmV0Y2hyL3Rlc3RpZnkgdG8gdjEuMTIuMQ==-->Update module github.com/stretchr/testify to v1.12.1<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/164): <!--number 164 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNw==-->Update go toolchain directive to v1.26.7<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/163): <!--number 163 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL3N0cmV0Y2hyL3Rlc3RpZnkgdG8gdjEuMTIuMA==-->Update module github.com/stretchr/testify to v1.12.0<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/162): <!--number 162 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNTA=-->Update module github.com/mattn/go-sqlite3 to v1.14.50<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/161): <!--number 161 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNg==-->Update go toolchain directive to v1.26.6<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/160): <!--number 160 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDk=-->Update module github.com/mattn/go-sqlite3 to v1.14.49<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/159): <!--number 159 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBtdmRhbi5jYy9nb2Z1bXB0IHRvIHYwLjExLjA=-->Update module mvdan.cc/gofumpt to v0.11.0<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/156): <!--number 156 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvY2hlY2tvdXQgdG8gdjYuMS4w-->Update actions/checkout to v6.1.0<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/158): <!--number 158 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZy5vcmcveC90ZXh0IChpbmRpcmVjdCkgdG8gdjAuMzkuMCBbU0VDVVJJVFld-->Update golang.org/x/text (indirect) to v0.39.0 \[SECURITY]<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/157): <!--number 157 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZy5vcmcveC9uZXQgKGluZGlyZWN0KSB0byB2MC41Ni4wIFtTRUNVUklUWV0=-->Update golang.org/x/net (indirect) to v0.56.0 \[SECURITY]<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/155): <!--number 155 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDg=-->Update module github.com/mattn/go-sqlite3 to v1.14.48<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/154): <!--number 154 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTMuNA==-->Update <https://data.forgejo.org/actions/forgejo-release> action to v2.13.4<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/153): <!--number 153 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNQ==-->Update go toolchain directive to v1.26.5<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/152): <!--number 152 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvc2V0dXAtZ28gdG8gdjYuNS4w-->Update actions/setup-go to v6.5.0<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/151): <!--number 151 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDc=-->Update module github.com/mattn/go-sqlite3 to v1.14.47<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/150): <!--number 150 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDY=-->Update module github.com/mattn/go-sqlite3 to v1.14.46<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/149): <!--number 149 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvZm9yZ2Vqby1yZWxlYXNlIHRvIHYyLjEzLjE=-->Update actions/forgejo-release to v2.13.1<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/148): <!--number 148 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL2phY2tjL3BneC92NSB0byB2NS4xMC4w-->Update module github.com/jackc/pgx/v5 to v5.10.0<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/147): <!--number 147 --><!--line 0 --><!--description VXBkYXRlIGFjdGlvbnMvZm9yZ2Vqby1yZWxlYXNlIHRvIHYyLjEzLjA=-->Update actions/forgejo-release to v2.13.0<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/146): <!--number 146 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnaXRodWIuY29tL21hdHRuL2dvLXNxbGl0ZTMgdG8gdjEuMTQuNDU=-->Update module github.com/mattn/go-sqlite3 to v1.14.45<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/145): <!--number 145 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/144): <!--number 144 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/143): <!--number 143 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/142): <!--number 142 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/139): <!--number 139 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/141): <!--number 141 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/140): <!--number 140 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/138): <!--number 138 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZyBwYWNrYWdlcyB0byB2MS4yNi40-->Update golang packages to v1.26.4<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/132): <!--number 132 --><!--line 0 --><!--description Y2k6IHJ1biBhbGwgeG9ybSB0ZXN0cyBvbiBhcm02NA==-->ci: run all xorm tests on arm64<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/137): <!--number 137 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9hY3Rpb25zL2Zvcmdlam8tcmVsZWFzZSBhY3Rpb24gdG8gdjIuMTIuMQ==-->Update <https://data.forgejo.org/actions/forgejo-release> action to v2.12.1<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/136): <!--number 136 --><!--line 0 --><!--description Y2hvcmUoZGVwcyk6IHdvcmthcm91bmQgYW1iaWd1b3VzIHJlZmVyZW5jZSBlcnJvciBpbiBjYXNjYWRpbmctcHI=-->chore(deps): workaround ambiguous reference error in cascading-pr<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/135): <!--number 135 --><!--line 0 --><!--description Y2hvcmUoZGVwcyk6IFVwZ3JhZGUgY2FzY2FkaW5nLXByIHYyLjMuMg==-->chore(deps): Upgrade cascading-pr v2.3.2<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/134): <!--number 134 --><!--line 0 --><!--description UmVwbGFjZSBOb2RlLmpzIHdpdGggZGF0YS5mb3JnZWpvLm9yZy9vY2kvbm9kZSAyNC10cml4aWU=-->Replace Node.js with data.forgejo.org/oci/node 24-trixie<!--description-->
- [PR](https://code.forgejo.org/xorm/xorm/pulls/133): <!--number 133 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZy5vcmcveC9uZXQgKGluZGlyZWN0KSB0byB2MC41NS4wIFtTRUNVUklUWV0=-->Update golang.org/x/net (indirect) to v0.55.0 \[SECURITY]<!--description-->
<!--end release-notes-assistant-->
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zOS4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMyIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->
Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14098
* [v16.0/forgejo] fix(ci): semgrep duplicate id (#14102)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14085
In addtion, use validate before --test otherwise validation errors may be very cryptic. For instance:
```sh
$ semgrep validate .semgrep/config
[00.03][WARNING]: invalid rule .semgrep.config.unit-test-missing-setup-function, .semgrep/config/unit-test.yaml:9:9: Expected a string value for .semgrep.config.unit-test-missing-setup-function
```
versus:
```sh
$ semgrep --test .semgrep/tests/ --config .semgrep/config/
...
-------------------------------------------------------------------------------
The following config files produced errors:
.semgrep/config/unit-test.yaml: Traceback (most recent call last):
File "/usr/lib/python3.12/site-packages/semgrep/test.py", line 313, in invoke_semgrep_multi
output = semgrep.run_scan.run_scan_and_return_json(
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/semgrep/run_scan.py", line 1757, in run_scan_and_return_json
) = run_scan(
^^^^^^^^^
File "/usr/lib/python3.12/site-packages/semgrep/telemetry.py", line 468, in inner
return f(*args, **kwargs)
^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/semgrep/simple_profiling.py", line 100, in wrapper
result = func(*args, **kwargs)
^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/semgrep/run_scan.py", line 1447, in run_scan
sanity_check_resolved_config(real_config_errors, configs_obj)
File "/usr/lib/python3.12/site-packages/semgrep/run_scan.py", line 201, in sanity_check_resolved_config
raise SemgrepError(
semgrep.error.SemgrepError: invalid configuration file found (1 configs were invalid)
```
### Compliance
- [x] I confirm that I make this contribution in accordance with [Forgejo's AI Agreement](https://codeberg.org/forgejo/governance/src/commit/9084720dc6a7fbf1d3f358919d46bd6adfb55287/AIAgreement.md).
Co-authored-by: limiting-factor <limiting-factor@posteo.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14102
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>
* [v16.0/forgejo] fix: add line wrapping to webhook ms teams card (#14115)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14058
Co-authored-by: nightfurysl2001 <nightfurysl2001@outlook.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14115
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] chore(tests): increase doRepoWikiGitOperationInner from 2 to 60 seconds (#14109)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14105
There is no benefit in requiring part of a test (a git command in this case) runs under 2 seconds as it makes it sensitive to high loads. What matters is to have a timeout in case it blocks forever.
Co-authored-by: limiting-factor <limiting-factor@posteo.com>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14109
Reviewed-by: limiting-factor <limiting-factor@noreply.codeberg.org>
* [v16.0/forgejo] fix(ui): fix hashbox design in commit based review (#14118)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14116
In addition remove unused class variable from commits list
Regression of 4392dee96d7437ca3d47ed156883b43cb02385d3
Co-authored-by: Beowulf <beowulf@beocode.eu>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14118
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* Update forgejo go-chi packages (v16.0/forgejo) (#14146)
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [code.forgejo.org/go-chi/captcha](https://code.forgejo.org/go-chi/captcha) | `v1.0.2` → `v1.0.3` |  |  |
| [code.forgejo.org/go-chi/session](https://code.forgejo.org/go-chi/session) | `v1.0.4` → `v1.1.0` |  |  |
---
### Release Notes
<details>
<summary>go-chi/captcha (code.forgejo.org/go-chi/captcha)</summary>
### [`v1.0.3`](https://code.forgejo.org/go-chi/captcha/releases/tag/v1.0.3)
[Compare Source](https://code.forgejo.org/go-chi/captcha/compare/v1.0.2...v1.0.3)
<!--start release-notes-assistant-->
<!--URL:https://code.forgejo.org/go-chi/captcha-->
- other
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/65): <!--number 65 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZGF0YS5mb3JnZWpvLm9yZy9nb2xhbmdjaS9nb2xhbmdjaS1saW50LWFjdGlvbiBhY3Rpb24gdG8gdjkuMy4w-->Update <https://data.forgejo.org/golangci/golangci-lint-action> action to v9.3.0<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/68): <!--number 68 --><!--line 0 --><!--description Y2k6IHB1Ymxpc2ggYXV0b21hdGVkIHJlbGVhc2Vz-->ci: publish automated releases<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/66): <!--number 66 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNQ==-->Update go toolchain directive to v1.26.5<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/63): <!--number 63 --><!--line 0 --><!--description UGluIGRlcGVuZGVuY2llcw==-->Pin dependencies<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/64): <!--number 64 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ29sYW5nY2kvZ29sYW5nY2ktbGludCB0byB2Mi4xMi4y-->Update dependency golangci/golangci-lint to v2.12.2<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/62): <!--number 62 --><!--line 0 --><!--description VXBkYXRlIGdvIHRvb2xjaGFpbiBkaXJlY3RpdmUgdG8gdjEuMjYuNCBbU0VDVVJJVFld-->Update go toolchain directive to v1.26.4 \[SECURITY]<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/60): <!--number 60 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL2NoZWNrb3V0IGFjdGlvbiB0byB2Ng==-->Update <https://code.forgejo.org/actions/checkout> action to v6<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/59): <!--number 59 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjY=-->Update dependency go to v1.26<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/58): <!--number 58 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ29sYW5nY2kvZ29sYW5nY2ktbGludCB0byB2Mi4xMS40-->Update dependency golangci/golangci-lint to v2.11.4<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/57): <!--number 57 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjExLjM=-->Update module golangci-lint to v2.11.3<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/55): <!--number 55 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjExLjI=-->Update module golangci-lint to v2.11.2<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/53): <!--number 53 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjExLjE=-->Update module golangci-lint to v2.11.1<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/50): <!--number 50 --><!--line 0 --><!--description UmVwbGFjZSBOb2RlLmpzIHdpdGggZGF0YS5mb3JnZWpvLm9yZy9vY2kvbm9kZSAyNC10cml4aWU=-->Replace Node.js with data.forgejo.org/oci/node 24-trixie<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/51): <!--number 51 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuOA==-->Update dependency go to v1.25.8<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/49): <!--number 49 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjEwLjE=-->Update module golangci-lint to v2.10.1<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/48): <!--number 48 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuNw==-->Update dependency go to v1.25.7<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/47): <!--number 47 --><!--line 0 --><!--description UmVwbGFjZSBodHRwczovL2dpdGh1Yi5jb20vZ29sYW5nY2kvZ29sYW5nY2ktbGludC1hY3Rpb24gYWN0aW9uIHdpdGggaHR0cHM6Ly9kYXRhLmZvcmdlam8ub3JnL2dvbGFuZ2NpL2dvbGFuZ2NpLWxpbnQtYWN0aW9uIHY5-->Replace <https://github.com/golangci/golangci-lint-action> action with <https://data.forgejo.org/golangci/golangci-lint-action> v9<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/46): <!--number 46 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuNg==-->Update dependency go to v1.25.6<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/45): <!--number 45 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjguMA==-->Update module golangci-lint to v2.8.0<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/44): <!--number 44 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjcuMg==-->Update module golangci-lint to v2.7.2<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/43): <!--number 43 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjcuMQ==-->Update module golangci-lint to v2.7.1<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/42): <!--number 42 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuNQ==-->Update dependency go to v1.25.5<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/41): <!--number 41 --><!--line 0 --><!--description UmVwbGFjZSBOb2RlLmpzIHdpdGggZGF0YS5mb3JnZWpvLm9yZy9vY2kvbm9kZSAyNC1ib29rd29ybQ==-->Replace Node.js with data.forgejo.org/oci/node 24-bookworm<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/40): <!--number 40 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjYuMg==-->Update module golangci-lint to v2.6.2<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/38): <!--number 38 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vZ2l0aHViLmNvbS9nb2xhbmdjaS9nb2xhbmdjaS1saW50LWFjdGlvbiBhY3Rpb24gdG8gdjk=-->Update <https://github.com/golangci/golangci-lint-action> action to v9<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/39): <!--number 39 --><!--line 0 --><!--description VXBkYXRlIE5vZGUuanMgdG8gdjI0-->Update Node.js to v24<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/37): <!--number 37 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjUuNA==-->Update dependency go to v1.25.4<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/36): <!--number 36 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjYuMQ==-->Update module golangci-lint to v2.6.1<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/35): <!--number 35 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjYuMA==-->Update module golangci-lint to v2.6.0<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/34): <!--number 34 --><!--line 0 --><!--description VXBkYXRlIGdvbGFuZyBwYWNrYWdlcyB0byB2MS4yNSAobWlub3Ip-->Update golang packages to v1.25 (minor)<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/32): <!--number 32 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuOA==-->Update dependency go to v1.24.8<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/30): <!--number 30 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL2NoZWNrb3V0IGFjdGlvbiB0byB2NQ==-->Update <https://code.forgejo.org/actions/checkout> action to v5<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/31): <!--number 31 --><!--line 0 --><!--description VXBkYXRlIGh0dHBzOi8vY29kZS5mb3JnZWpvLm9yZy9hY3Rpb25zL3NldHVwLWdvIGFjdGlvbiB0byB2Ng==-->Update <https://code.forgejo.org/actions/setup-go> action to v6<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/29): <!--number 29 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjUuMA==-->Update module golangci-lint to v2.5.0<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/28): <!--number 28 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuNw==-->Update dependency go to v1.24.7<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/27): <!--number 27 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjQuMA==-->Update module golangci-lint to v2.4.0<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/25): <!--number 25 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuNg==-->Update dependency go to v1.24.6<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/24): <!--number 24 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjMuMQ==-->Update module golangci-lint to v2.3.1<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/23): <!--number 23 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjMuMA==-->Update module golangci-lint to v2.3.0<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/22): <!--number 22 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjIuMg==-->Update module golangci-lint to v2.2.2<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/21): <!--number 21 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuNQ==-->Update dependency go to v1.24.5<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/20): <!--number 20 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjIuMQ==-->Update module golangci-lint to v2.2.1<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/19): <!--number 19 --><!--line 0 --><!--description VXBkYXRlIG1vZHVsZSBnb2xhbmdjaS1saW50IHRvIHYyLjIuMA==-->Update module golangci-lint to v2.2.0<!--description-->
- [PR](https://code.forgejo.org/go-chi/captcha/pulls/18): <!--number 18 --><!--line 0 --><!--description VXBkYXRlIGRlcGVuZGVuY3kgZ28gdG8gdjEuMjQuNA==-->Update dependency go to v1.24.4<!--description-->
<!--end release-notes-assistant-->
</details>
<details>
<summary>go-chi/session (code.forgejo.org/go-chi/session)</summary>
### [`v1.1.0`](https://code.forgejo.org/go-chi/session/compare/v1.0.4...v1.1.0)
[Compare Source](https://code.forgejo.org/go-chi/session/compare/v1.0.4...v1.1.0)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zOS4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMyIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14146
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
* [v16.0/forgejo] fix: simplify concurrency in `GetContributorStats` (#14159)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14149
There's a bug in the current implementation of `GetContributorStats`
that has to do with concurrency. The function is fairly simple, if
there's no generated resulted (in the cache) then start a goroutine that
generates this. Wait for up to 5 seconds to get the result, otherwise
indicate to the client that generation has started but have to call
again later to get the result (or get told it's still busy).
This behavior of waiting up to 5 seconds is being done by passing a
channel to the goroutine. When the goroutine successfully generated the
data and stored it in the cache, it does a blocking send to the channel
to indicate it's done. However, if this happened after the 5 seconds
there was no goroutine/code reading from that channel and the goroutine
gets stuck.
Simplify this by removing this 'waiting up to x seconds' behavior and
always tell the client to come back later if there's nothing in the
cache. This does increases network traffic, but the current client (the
web UI which we control) checks every second and no heavy database
operations or cache operations has to be executed to return that there's
no data yet. I feel this is preferred over fixing this concurrency bug,
as it makes reasoning about this behavior quite easier (and as well
testing).
This bug caused `git cat-file` processes from lingering, ref: forgejo/forgejo#12970
Co-authored-by: Gusted <postmaster@gusted.xyz>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14159
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* [v16.0/forgejo] chore: improve reliability of TestPullRequestCommentPlacement on force push tests (#14207)
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/14201
There are a few test cases in `TestPullRequestCommentPlacement` which do force pushes, and the test code currently doesn't access their commit ID after the force push. This prevented them from having the reliability fix from https://codeberg.org/forgejo/forgejo/issues/13808 applied to them, and has now been fixed.
Co-authored-by: Mathieu Fenniak <mathieu@fenniak.net>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14207
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* Update module golang.org/x/crypto to v0.56.0 [SECURITY] (v16.0/forgejo) (#14224)
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/crypto](https://pkg.go.dev/golang.org/x/crypto) | [`v0.55.0` → `v0.56.0`](https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.55.0...refs/tags/v0.56.0) |  |  |
---
> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2779) for more information.
---
### Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
[CVE-2026-78662](https://nvd.nist.gov/vuln/detail/CVE-2026-78662) / [GO-2026-6354](https://pkg.go.dev/vuln/GO-2026-6354)
<details>
<summary>More information</summary>
#### Details
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.
Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
#### Severity
Unknown
#### References
- [https://go.dev/issue/81316](https://go.dev/issue/81316)
- [https://go.dev/cl/826504](https://go.dev/cl/826504)
- [https://groups.google.com/g/golang-announce/c/1y3fb2np35U](https://groups.google.com/g/golang-announce/c/1y3fb2np35U)
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6354) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>
---
### Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
[CVE-2026-56855](https://nvd.nist.gov/vuln/detail/CVE-2026-56855) / [GO-2026-6355](https://pkg.go.dev/vuln/GO-2026-6355)
<details>
<summary>More information</summary>
#### Details
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.
Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
#### Severity
Unknown
#### References
- [https://go.dev/issue/81317](https://go.dev/issue/81317)
- [https://go.dev/cl/826524](https://go.dev/cl/826524)
- [https://groups.google.com/g/golang-announce/c/1y3fb2np35U](https://groups.google.com/g/golang-announce/c/1y3fb2np35U)
This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6355) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC41Mi4wIiwidXBkYXRlZEluVmVyIjoiNDQuNTIuMCIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19-->
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14224
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
* Update google.golang.org/grpc (indirect) to v1.83.1 [SECURITY] (v16.0/forgejo) (#14216)
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.1` → `v1.83.1` |  |  |
---
> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2779) for more information.
---
### gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
[CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](https://github.com/advisories/GHSA-vp52-pcj8-j9qc)
<details>
<summary>More information</summary>
#### Details
##### Impact
An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation.
Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS).
##### Patches
The change to fix this issue is merged in `master` and a patch release, 1.83.1, has been published that contains this fix.
##### Workarounds
This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads.
This behavior is enabled by default. A temporary escape hatch is provided via the environment variable `GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false` to disable the feature if unforeseen issues arise, but it will be removed in a future release.
#### Severity
- CVSS Score: 8.7 / 10 (High)
- Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N`
#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc)
- [https://nvd.nist.gov/vuln/detail/CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304)
- [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331)
- [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333)
- [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176)
- [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77)
- [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go)
- [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1)
This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-vp52-pcj8-j9qc) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>
---
### Release Notes
<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>
### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.83.0...v1.83.1)
### Security
- xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#​9258](https://github.com/grpc/grpc-go/issues/9258))
- Special Thanks: [@​nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#​9258](https://github.com/grpc/grpc-go/issues/9258))
- Special Thanks: [@​nvxbug](https://github.com/nvxbug)
- xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#​9332](https://github.com/grpc/grpc-go/issues/9332))
- Special Thanks: [@​alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#​9332](https://github.com/grpc/grpc-go/issues/9332))
- Special Thanks: [@​alimony](https://github.com/alimony)
- xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#​9332](https://github.com/grpc/grpc-go/issues/9332))
- Special Thanks: [@​alimony](https://github.com/alimony)
### Performance
- transport: Restrict memory overhead of buffering small data frames. ([#​9331](https://github.com/grpc/grpc-go/issues/9331))
### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0
[Compare Source](https://github.com/grpc/grpc-go/compare/v1.82.2...v1.83.0)
### Security
- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`.
- xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open.
- xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions.
- xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`.
- xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#​9223](https://github.com/grpc/grpc-go/issues/9223))
### New Features
- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#​9133](https://github.com/grpc/grpc-go/issues/9133))
- xds: Enable xDS configura…
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
parseConfig only walks the top-level Permissions and Principals of each RBAC policy when it applies the A41 header-name rules, so a header matcher nested inside an and_rules, or_rules, or not_rule is never checked. A control plane can put a
:schemeorgrpc-prefixed matcher inside a nested rule to slip past the validation A41 says must reject it, and a nestedhostmatcher never gets rewritten to:authority, so it silently fails to match the header grpc-go actually carries (a deny policy on a nested host matcher fails open).Walk the full permission and principal trees so both the :scheme/grpc- rejection and the host to :authority rewrite reach matchers at any depth. Doing it in parseConfig keeps the check in the one place that already owns A41 validation, and folds the two former top-level passes into a single recursive walk shared by permissions and principals.
RELEASE NOTES:
PrincipalorPermissionrules with:schemeorgrpc-prefixed header matchers were not rejected, which could cause DENY rules to fail open.hostheader matcher was not being replaced with:authorityin nestedPrincipalorPermissionrules.