Affected by GO-2022-0369
and 22 other vulnerabilities
GO-2022-0369 : Gogs vulnerable to improper PAM authorization handling in gogs.io/gogs
GO-2022-0473 : Cross site scripting via cookies in gogs in gogs.io/gogs
GO-2022-0483 : Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs
GO-2022-0554 : Unrestricted Upload of File with Dangerous Type in Gogs in gogs.io/gogs
GO-2022-0556 : OS Command Injection in file editor in Gogs in gogs.io/gogs
GO-2022-0562 : Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs
GO-2022-0570 : Path Traversal in file editor on Windows in Gogs in gogs.io/gogs
GO-2022-0583 : Server-Side Request Forgery in gogs webhook in gogs.io/gogs
GO-2022-1060 : Gogs vulnerable to Cross-site Scripting in gogs.io/gogs
GO-2023-1596 : Gogs OS Command Injection vulnerability in gogs.io/gogs
GO-2023-1971 : Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
GO-2024-3275 : Unpatched Remote Code Execution in Gogs in gogs.io/gogs
GO-2024-3355 : Remote Command Execution in file editing in gogs in gogs.io/gogs
GO-2024-3356 : Path Traversal in file update API in gogs in gogs.io/gogs
Discover Packages
gogs.io/gogs
command
module
Version:
v0.7.0
Opens a new window with list of versions in this module.
Published: Nov 8, 2015
License: MIT
Opens a new window with license information.
Imports: 5
Opens a new window with list of imports.
Imported by: 1
Opens a new window with list of known importers.
README
README
¶
Gogs - Go Git Service
Current version: 0.7.0 Beta
NOTICES
Due to testing purpose, data of try.gogs.io has been reset in Jan 28, 2015 and will reset multiple times after. Please do NOT put your important data on the site.
The demo site try.gogs.io is running under develop
branch.
‼You MUST read CONTRIBUTING.md before you start filing an issue or making a Pull Request, and MUST discuss with us on Gitter for UI changes and feature Pull Requests, otherwise it's high possibilities that we are not going to merge it. ‼
If you think there are vulnerabilities in the project, please talk privately to u@gogs.io . Thanks!
If you're interested in using APIs, we have experimental support with documentation .
If your team/company is using Gogs and would like to put your logo on our website , contact us by any means.
简体中文
Purpose
The goal of this project is to make the easiest, fastest, and most painless way of setting up a self-hosted Git service. With Go, this can be done with an independent binary distribution across ALL platforms that Go supports, including Linux, Mac OS X, Windows and ARM.
Overview
Please see the Documentation for common usages and change log.
See the Trello Board to follow the develop team.
Want to try it before doing anything else? Do it online or go down to the Installation -> Install from binary section!
Having trouble? Get help with Troubleshooting .
Want to help with localization? Check out the guide !
Features
Activity timeline
SSH and HTTP/HTTPS protocols
SMTP/LDAP/Reverse proxy authentication
Reverse proxy with sub-path
Account/Organization/Repository management
Repository/Organization webhooks (including Slack)
Repository Git hooks/deploy keys
Repository issues and pull requests
Add/Remove repository collaborators
Gravatar and custom source
Mail service
Administration panel
CI integration: Drone
Supports MySQL, PostgreSQL, SQLite3 and TiDB (experimental)
Multi-language support (14 languages )
System Requirements
A cheap Raspberry Pi is powerful enough for basic functionality.
2 CPU cores and 1GB RAM would be the baseline for teamwork.
Browser Support
Please see Semantic UI for specific versions of supported browsers.
The official support minimal size is 1024*768 , UI may still looks right in smaller size but no promises and fixes.
Installation
Make sure you install the prerequisites first.
There are 5 ways to install Gogs:
Tutorials
Screencasts
Deploy to Cloud
Product Support
Acknowledgments
Router and middleware mechanism of Macaron .
Modules design is inspired by WeTalk .
System Monitor Status is inspired by GoBlog .
Thanks lavachen and Rocker for designing Logo.
Thanks Crowdin for providing open source translation plan.
Thanks DigitalOcean for hosting home and demo sites.
Contributors
License
This project is under the MIT License. See the LICENSE file for the full license text.
Expand ▾
Collapse ▴
Documentation
¶
Gogs (Go Git Service) is a painless self-hosted Git Service.
Source Files
¶
Directories
¶
modules
auth/ldap
Package ldap provide functions & structure to query a LDAP ldap directory For now, it's mainly tested again an MS Active Directory service, see README.md for more information
Package ldap provide functions & structure to query a LDAP ldap directory For now, it's mainly tested again an MS Active Directory service, see README.md for more information
avatar
It is recommend to use this way cacheDir := "./cache" defaultImg := "./default.jpg" http.Handle("/avatar/", avatar.CacheServer(cacheDir, defaultImg))
It is recommend to use this way cacheDir := "./cache" defaultImg := "./default.jpg" http.Handle("/avatar/", avatar.CacheServer(cacheDir, defaultImg))
cron
Package cron implements a cron spec parser and job runner.
Package cron implements a cron spec parser and job runner.
crypto/ssh
Package ssh implements an SSH client and server.
Package ssh implements an SSH client and server.
Package agent implements a client to an ssh-agent daemon.
crypto/ssh/terminal
Package terminal provides support functions for dealing with terminals, as commonly found on UNIX systems.
Package terminal provides support functions for dealing with terminals, as commonly found on UNIX systems.
crypto/ssh/test
This package contains integration tests for the golang.org/x/crypto/ssh package.
This package contains integration tests for the golang.org/x/crypto/ssh package.
ssh
Prototype, git client looks like do not recognize req.Reply.
Prototype, git client looks like do not recognize req.Reply.
uuid
Package uuid provides implementation of Universally Unique Identifier (UUID).
Package uuid provides implementation of Universally Unique Identifier (UUID).
Click to show internal directories.
Click to hide internal directories.