1
0
mirror of https://github.com/go-gitea/gitea.git synced 2025-01-03 14:57:55 -05:00
Go to file
Jason Song edf98a2dc3
Require approval to run actions for fork pull request (#22803)
Currently, Gitea will run actions automatically which are triggered by
fork pull request. It's a security risk, people can create a PR and
modify the workflow yamls to execute a malicious script.

So we should require approval for first-time contributors, which is the
default strategy of a public repo on GitHub, see [Approving workflow
runs from public
forks](https://docs.github.com/en/actions/managing-workflow-runs/approving-workflow-runs-from-public-forks).

Current strategy:

- don't need approval if it's not a fork PR;
- always need approval if the user is restricted;
- don't need approval if the user can write;
- don't need approval if the user has been approved before;
- otherwise, need approval.

https://user-images.githubusercontent.com/9418365/217207121-badf50a8-826c-4425-bef1-d82d1979bc81.mov

GitHub has an option for that, you can see that at
`/<owner>/<repo>/settings/actions`, and we can support that later.

<img width="835" alt="image"
src="https://user-images.githubusercontent.com/9418365/217199990-2967e68b-e693-4e59-8186-ab33a1314a16.png">

---------

Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2023-02-24 15:58:49 +08:00
.gitea Issue template form (#16349) 2021-09-15 20:33:13 +03:00
.github Improve pull_request_template.md (#22888) 2023-02-20 19:14:02 -05:00
assets Use import of OCI structs (#22765) 2023-02-06 10:07:09 +00:00
build Consume hcaptcha and pwn deps (#22610) 2023-01-29 09:49:51 -06:00
cmd Refactor the setting to make unit test easier (#22405) 2023-02-20 00:12:01 +08:00
contrib Add Bash and Zsh completion scripts (#22646) 2023-02-21 12:32:24 -05:00
custom/conf Add Chef package registry (#22554) 2023-02-06 09:49:21 +08:00
docker Wrap unless-check in docker manifests (#23079) 2023-02-22 16:33:31 -06:00
docs Avoid Hugo from adding quote to actions url (#23097) 2023-02-23 12:19:52 -05:00
models Require approval to run actions for fork pull request (#22803) 2023-02-24 15:58:49 +08:00
modules Fix nil context in RenderMarkdownToHtml (#23092) 2023-02-24 14:36:07 +08:00
options Require approval to run actions for fork pull request (#22803) 2023-02-24 15:58:49 +08:00
public Add Chef package registry (#22554) 2023-02-06 09:49:21 +08:00
routers Require approval to run actions for fork pull request (#22803) 2023-02-24 15:58:49 +08:00
services Require approval to run actions for fork pull request (#22803) 2023-02-24 15:58:49 +08:00
snap Remove unnecessary whitespace in snapcraft.yaml (#22090) 2022-12-10 08:31:16 -06:00
templates Fix nil context in RenderMarkdownToHtml (#23092) 2023-02-24 14:36:07 +08:00
tests Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
tools Move fuzz tests into tests/fuzz (#22376) 2023-01-09 15:30:14 +08:00
web_src Require approval to run actions for fork pull request (#22803) 2023-02-24 15:58:49 +08:00
.air.toml Add more test directory to exclude dir of air, remove watching templates from air include dir because gitea has internal mechanism (#22246) 2022-12-27 14:00:34 +08:00
.changelog.yml Changelog for v1.15.0-rc1 (#16422) 2021-07-15 11:47:57 -04:00
.dockerignore Add .dockerignore (#21753) 2022-11-10 04:04:09 +01:00
.drone.yml only trigger docs build and publish when docs changed (#22968) 2023-02-20 21:08:41 +08:00
.editorconfig Add markdownlint (#20512) 2022-07-28 09:22:47 +08:00
.eslintrc.yaml Refactor hiding-methods, remove jQuery show/hide, remove .hide class, remove inline style=display:none (#22950) 2023-02-19 12:06:14 +08:00
.gitattributes Hook go-licenses into tidy again (#21353) 2022-10-10 20:45:02 +02:00
.gitignore Add go licenses to licenses.txt (#21034) 2022-09-04 00:20:46 +02:00
.gitpod.yml Split default gitpod view to include all tasks (#22555) 2023-01-20 13:46:33 -06:00
.golangci.yml Fix .golangci.yml (#22868) 2023-02-11 21:44:53 +00:00
.ignore Add some .ignore entries (#18296) 2022-01-16 17:26:15 +00:00
.lgtm refactor: ignore LGTM from author of pull request. (#3283) 2018-01-02 06:13:49 -06:00
.markdownlint.yaml Add markdownlint (#20512) 2022-07-28 09:22:47 +08:00
.npmrc Stop packaging node_modules in release tarballs (#15273) 2021-04-09 01:08:14 -04:00
.spectral.yaml Add spectral linter for Swagger (#20321) 2022-07-11 18:07:16 -05:00
.stylelintrc.yaml Upgrade to stylelint 15 (#22944) 2023-02-21 09:23:45 -06:00
BSDmakefile Add BSDmakefile to prevent errors when make is called under FreeBSD (#4446) 2018-07-16 20:45:51 +02:00
build.go Implement FSFE REUSE for golang files (#21840) 2022-11-27 18:20:29 +00:00
CHANGELOG.md Changelog 1.18.5 (#23045) (#23049) 2023-02-21 13:36:19 -06:00
CONTRIBUTING.md Improving CONTRIBUTING.md for backport details (#23057) 2023-02-22 11:49:52 +08:00
DCO Remove address from DCO (#22595) 2023-01-24 18:52:38 +00:00
Dockerfile Add Bash and Zsh completion scripts (#22646) 2023-02-21 12:32:24 -05:00
Dockerfile.rootless Add Bash and Zsh completion scripts (#22646) 2023-02-21 12:32:24 -05:00
go.mod Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
go.sum Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
LICENSE Fix typo 2016-11-08 08:42:05 +01:00
main.go Add Bash and Zsh completion scripts (#22646) 2023-02-21 12:32:24 -05:00
MAINTAINERS Add HesterG to maintainers (#23104) 2023-02-24 14:31:02 +08:00
Makefile update to build with go1.20 (#22732) 2023-02-03 11:23:52 -05:00
package-lock.json Upgrade to stylelint 15 (#22944) 2023-02-21 09:23:45 -06:00
package.json Upgrade to stylelint 15 (#22944) 2023-02-21 09:23:45 -06:00
playwright.config.js Update JS dependencies and eslint config (#21388) 2022-10-10 20:02:20 +08:00
README_ZH.md link update in README files (#22582) 2023-01-23 15:57:57 -05:00
README.md link update in README files (#22582) 2023-01-23 15:57:57 -05:00
SECURITY.md Add markdownlint (#20512) 2022-07-28 09:22:47 +08:00
vitest.config.js Update JS dependencies and eslint (#22190) 2022-12-20 17:15:47 -05:00
webpack.config.js Introduce customized HTML elements, fix incorrect AppUrl usages in templates (#22861) 2023-02-17 22:02:20 +08:00

Gitea

Gitea - Git with a cup of tea

Contribute with Gitpod

View this document in Chinese

Purpose

The goal of this project is to make the easiest, fastest, and most painless way of setting up a self-hosted Git service.

As Gitea is written in Go, it works across all the platforms and architectures that are supported by Go, including Linux, macOS, and Windows on x86, amd64, ARM and PowerPC architectures. You can try it out using the online demo. This project has been forked from Gogs since November of 2016, but a lot has changed.

Building

From the root of the source tree, run:

TAGS="bindata" make build

or if SQLite support is required:

TAGS="bindata sqlite sqlite_unlock_notify" make build

The build target is split into two sub-targets:

  • make backend which requires Go Stable, required version is defined in go.mod.
  • make frontend which requires Node.js LTS or greater and Internet connectivity to download npm dependencies.

When building from the official source tarballs which include pre-built frontend files, the frontend target will not be triggered, making it possible to build without Node.js and Internet connectivity.

Parallelism (make -j <num>) is not supported.

More info: https://docs.gitea.io/en-us/install-from-source/

Using

./gitea web

NOTE: If you're interested in using our APIs, we have experimental support with documentation.

Contributing

Expected workflow is: Fork -> Patch -> Push -> Pull Request

NOTES:

  1. YOU MUST READ THE CONTRIBUTORS GUIDE BEFORE STARTING TO WORK ON A PULL REQUEST.
  2. If you have found a vulnerability in the project, please write privately to security@gitea.io. Thanks!

Translating

Translations are done through Crowdin. If you want to translate to a new language ask one of the managers in the Crowdin project to add a new language there.

You can also just create an issue for adding a language or ask on discord on the #translation channel. If you need context or find some translation issues, you can leave a comment on the string or ask on Discord. For general translation questions there is a section in the docs. Currently a bit empty but we hope to fill it as questions pop up.

https://docs.gitea.io/en-us/translation-guidelines/

Crowdin

Further information

For more information and instructions about how to install Gitea, please look at our documentation. If you have questions that are not covered by the documentation, you can get in contact with us on our Discord server or create a post in the discourse forum.

We maintain a list of Gitea-related projects at gitea/awesome-gitea.

The Hugo-based documentation theme is hosted at gitea/theme.

The official Gitea CLI is developed at gitea/tea.

Authors

Backers

Thank you to all our backers! 🙏 [Become a backer]

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]

FAQ

How do you pronounce Gitea?

Gitea is pronounced /ɡɪti:/ as in "gi-tea" with a hard g.

Why is this not hosted on a Gitea instance?

We're working on it.

License

This project is licensed under the MIT License. See the LICENSE file for the full license text.

Screenshots

Looking for an overview of the interface? Check it out!

Dashboard User Profile Global Issues
Branches Web Editor Activity
New Migration Migrating Pull Request View
Pull Request Dark Diff Review Dark Diff Dark