release notes: please mention changed defaults like disabling git hooks explicitly #6558

Closed
opened 2025-11-02 06:59:24 -06:00 by GiteaMirror · 3 comments
Owner

Originally created by @vorlon on GitHub (Dec 20, 2020).

  • Gitea version: 1.13.0

Description

In this release git hooks have been disabled by default for security reasons as detailed in #13058. This is not immediately visible from the changelog/release notes but could be considered a breaking or at least rather important change.
It would be really helpful if changes like this could be explicitly mentioned.

Originally created by @vorlon on GitHub (Dec 20, 2020). - Gitea version: 1.13.0 ## Description In this release git hooks have been disabled by default for security reasons as detailed in #13058. This is not immediately visible from the changelog/release notes but could be considered a breaking or at least rather important change. It would be really helpful if changes like this could be explicitly mentioned.
Author
Owner

@lunny commented on GitHub (Dec 21, 2020):

See https://blog.gitea.io/2020/12/gitea-1.13.0-is-released/#1130httpsgithubcomgo-giteagiteareleasestagv1130---2020-12-01, It's on security section. We missed a security label on the PR. I have added it.

@lunny commented on GitHub (Dec 21, 2020): See https://blog.gitea.io/2020/12/gitea-1.13.0-is-released/#1130httpsgithubcomgo-giteagiteareleasestagv1130---2020-12-01, It's on security section. We missed a security label on the PR. I have added it.
Author
Owner

@vorlon commented on GitHub (Dec 21, 2020):

Sorry, I should have been a bit more verbose.
I noticed it in the security section, but would not have expected a changed default from reading the title. The one following in the list "Disable DSA ssh keys by default" is rather clear on the other hand.
Just as a suggestion, it might be helpful to include some kind of breaking changes list (like changed default values, changed API behaviour etc.) or clearer titles for such issues.

@vorlon commented on GitHub (Dec 21, 2020): Sorry, I should have been a bit more verbose. I noticed it in the security section, but would not have expected a changed default from reading the title. The one following in the list "Disable DSA ssh keys by default" is rather clear on the other hand. Just as a suggestion, it might be helpful to include some kind of breaking changes list (like changed default values, changed API behaviour etc.) or clearer titles for such issues.
Author
Owner

@vorlon commented on GitHub (Dec 21, 2020):

Sorry, I should have been a bit more verbose.
I noticed it in the security section, but would not have expected a changed default from reading the title. The one following in the list "Disable DSA ssh keys by default" is rather clear on the other hand.
Just as a suggestion, it might be helpful to include some kind of breaking changes list (like changed default values, changed API behaviour etc.) or clearer titles for such issues.

@vorlon commented on GitHub (Dec 21, 2020): Sorry, I should have been a bit more verbose. I noticed it in the security section, but would not have expected a changed default from reading the title. The one following in the list "Disable DSA ssh keys by default" is rather clear on the other hand. Just as a suggestion, it might be helpful to include some kind of breaking changes list (like changed default values, changed API behaviour etc.) or clearer titles for such issues.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/gitea#6558