Gogs

Lightweight self-hosted git platform, written in Go.

Open Source

Gogs Source Code

Author

gogs

Description

The painless way to host your own Git service

#docker#git#go#gogs#mysql#postgresql#raspberry-pi#self-hosted#source-code-management#sqlite3#version-control

Homepage

https://gogs.io

Repository

  • LicenseMIT
  • Created12 Feb 14
  • Primary languageGo
  • Size212,360 KB
  • Stars47,730
  • Forks5,073
  • Watchers47,730

Language Usage

Language Usage

Project Health

  • Last commit11 days ago
  • Open issues1,010
  • Latest releasev0.14.3

Recent Commits

  • ᴊᴏᴇ ᴄʜᴇɴ(06 Aug 26)

    web: use flamego's built-in plaintext recovery (#8402)

  • ifer47(19 Jul 26)

    docker: stop generating DSA host keys (#8366) Co-authored-by: yangkangkang <[email protected]>

  • ᴊᴏᴇ ᴄʜᴇɴ(17 Jul 26)

    security: fix argument injection via crafted references on repository API endpoints (#8393)

  • ᴊᴏᴇ ᴄʜᴇɴ(16 Jul 26)

    security: harden same-site redirect validation (#8391)

  • ᴊᴏᴇ ᴄʜᴇɴ(16 Jul 26)

    security: fix argument injection via crafted branch names in pull requests (#8390)

  • Arpit Jain(15 Jul 26)

    tool: avoid panic in BasicAuthDecode on a value with no colon (#8387) Signed-off-by: Arpit Jain <[email protected]>

  • ᴊᴏᴇ ᴄʜᴇɴ(12 Jul 26)

    conf: resolve session and TLS cert paths against work directory (#8386)

  • dependabot[bot](12 Jul 26)

    chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 (#8378) Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

  • Joe Chen(12 Jul 26)

    chore: mark portless be interactive in moon [skip ci]

  • Duy P(12 Jul 26)

    web: fix frontend assets behind reverse-proxy subpaths (#8384)

  • dependabot[bot](10 Jul 26)

    chore(deps): bump golang.org/x/crypto from 0.49.0 to 0.52.0 (#8381) Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

  • ᴊᴏᴇ ᴄʜᴇɴ(20 Jun 26)

    chore: remove ineffective CODEOWNERS at root [skip ci]

  • dependabot[bot](16 Jun 26)

    chore(deps-dev): bump vite from 8.0.13 to 8.0.16 (#8367) Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

  • ᴊᴏᴇ ᴄʜᴇɴ(10 Jun 26)

    web: remove the install page (#8350)

  • ᴊᴏᴇ ᴄʜᴇɴ(08 Jun 26)

    web: use a single landing banner for light and dark mode (#8344)

  • ᴊᴏᴇ ᴄʜᴇɴ(08 Jun 26)

    chore: update SHA256 checksum link in release issue templates (#8345) [skip ci]

  • ᴊᴏᴇ ᴄʜᴇɴ(08 Jun 26)

    fix: surface 5xx errors in the SPA boot and route loaders (#8343)

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    release: cut CHANGELOG entries for 0.14.3 (#8338) [skip ci]

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    chore: update CHANGELOG for removed custom templates [skip ci]

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    security: require token auth for org metadata and team list (#8336)

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    security: time out stalled SSH handshakes after 15s (#8335)

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    security: reject path traversal in owner and repository names (#8334)

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    security: verify content hash on LFS dedupe shortcut (#8333)

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    security: walk full upload path for symlinks (#8332)

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    security: harden Git HTTP access checks (#8331)

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    security: upgrade notebookjs and route ipynb HTML through DOMPurify (#8330)

  • ᴊᴏᴇ ᴄʜᴇɴ(07 Jun 26)

    security: enforce RESET_PASSWORD_CODE_LIVES on reset tokens (#8328)

  • ᴊᴏᴇ ᴄʜᴇɴ(06 Jun 26)

    security: require admin for repo settings API endpoints (#8327)

  • ᴊᴏᴇ ᴄʜᴇɴ(06 Jun 26)

    security: restrict ipynb sanitizer to safe image data URIs (#8326)

  • ᴊᴏᴇ ᴄʜᴇɴ(06 Jun 26)

    security: sanitize milestone names in new issue form (#8325)

Gogs Security

5.7/10

Repo Security Summary

Updated 27 Jul 26

  • Maintained10/10
  • Security-Policy10/10
  • Code-Review1/10
  • Dangerous-Workflow10/10
  • CII-Best-Practices0/10
  • Token-Permissions0/10
  • Binary-Artifacts8/10
  • Fuzzing0/10
  • License10/10
  • Branch-ProtectionN/A
  • Signed-Releases0/10
  • SAST7/10
  • Packaging10/10
  • Pinned-Dependencies8/10

Security Advisories (65)

  • mediumPatchedCVSS 4.3

    CVE-2026-52795Authorization Bypass in Watch API allows any user to monitor private repository activity

  • lowPatched

    CVE-2026-52815Unauthenticated Organization Teams Information Disclosure via API

  • mediumPatched

    CVE-2026-52814Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

  • criticalPatchedCVSS 10

    CVE-2026-52813Path Traversal in organization name results in RCE through Git hooks

  • highPatched

    CVE-2026-52812LFS dedupe path leaks private repo content across tenants

  • criticalPatched

    CVE-2026-52811UploadRepoFiles writes outside repo working tree via committed parent sym

  • highPatched

    CVE-2026-52810Write to readonly repositories using receive-pack + service=git-upload-pack confusion

  • highPatched

    GHSA-6vxv-wg6j-5qwpXSS in .ipynb files renderer due to outdated notebookjs

  • lowPatched

    CVE-2026-52809Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

  • mediumPatched

    CVE-2026-52808Write-level collaborators can mutate admin-only repository settings via API

  • highPatched

    CVE-2026-52816Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

  • highPatched

    CVE-2026-52807DOM-based XSS via Milestone Name on New Issue Page

  • criticalPatchedCVSS 9.9

    CVE-2026-52806RCE via git rebase --exec argument injection in pull request merge

  • highPatchedCVSS 8.7

    CVE-2026-52805Migration Redirect Bypass Leads to Internal Repository Theft

  • highPatched

    CVE-2026-52804Privilege Escalation via Collaboration Access Mode Validation

  • mediumPatchedCVSS 5.4

    CVE-2026-52802Open Redirect via redirect_to

  • highPatchedCVSS 8.1

    CVE-2026-52801Ability to import local repositories via Mirror Settings

  • highPatchedCVSS 8.8

    CVE-2026-52800CSRF Leading to Organization Owner Takeover

  • highPatchedCVSS 7.5

    CVE-2026-52799Missing Authorization in Attachment Download

  • highPatchedCVSS 8.9

    CVE-2026-52798Stored XSS in `.ipynb` Preview

  • highPatchedCVSS 7.3

    CVE-2026-26276DOM-based XSS via milestone selection

  • mediumPatched

    CVE-2026-26196Access tokens get exposed through URL params in API requests

  • mediumPatched

    CVE-2026-26195Stored XSS in branch and wiki views through author and committer names

  • highPatched

    CVE-2026-26194Release tag option injection in release deletion

  • highPatchedCVSS 8.7

    CVE-2026-26022Stored XSS via data URI in issue comments

  • mediumPatched

    CVE-2026-25229Authorization bypass allows cross-repository label modification

  • mediumPatched

    CVE-2026-25119Authentication Bypass via Unvalidated Reverse Proxy Headers

  • mediumPatched

    CVE-2026-25120Cross-repository comment deletion

  • mediumPatchedCVSS 6.5

    CVE-2026-23633Arbitrary file read/write via path traversal in Git hook editing

  • mediumPatchedCVSS 6.5

    CVE-2026-23632Update repository content via API with read-only permission

  • highPatched

    CVE-2026-24135Arbitrary file deletion via path traversal in wiki page update

  • mediumPatchedCVSS 6.5

    CVE-2026-22592DoS in repository mirror sync

  • criticalPatched

    CVE-2026-25232Protected branch bypass in web UI

  • mediumPatched

    CVE-2025-65852Authorization bypass in repository deletion API

  • highPatchedCVSS 7.3

    GHSA-26gq-grmh-6xm6Stored XSS via Mermaid diagrams

  • mediumPatchedCVSS 4.9

    CVE-2025-64719DoS in repository/wiki file listing pages

  • mediumPatched

    CVE-2026-25242Unauthenticated file upload

  • highPatched

    CVE-2025-641752FA bypass via recovery code

  • criticalPatched

    CVE-2025-64111RCE in repository put contents API

  • mediumPatched

    CVE-2026-47267SSRF in webhook deliveries

  • criticalPatchedCVSS 10

    CVE-2024-56731Deletion of internal files allows remote command execution

  • highPatchedCVSS 7.7

    CVE-2024-39933Argument Injection when tagging new releases

  • criticalPatchedCVSS 9.9

    CVE-2024-39932Argument Injection during changes preview

  • criticalPatchedCVSS 9.9

    CVE-2024-39931Deletion of internal files

  • criticalPatchedCVSS 9.9

    CVE-2024-39930Argument Injection in the built-in SSH server

  • criticalPatched

    CVE-2024-55947Path Traversal in file update API

  • criticalPatched

    CVE-2024-54148Path Traversal in file editing UI

  • criticalPatchedCVSS 9.3

    CVE-2026-25921 Cross-repository LFS object overwrite via missing content hash verification

  • mediumPatchedCVSS 6.3

    CVE-2025-47943Stored XSS in PDF renderer

  • highPatchedCVSS 8.5

    CVE-2026-52797Overwriting critical files results in a denial of service

  • lowPatchedCVSS 3.5

    CVE-2026-52796DoS in rendering issue index pattern

  • criticalPatched

    CVE-2022-2024OS Command Injection in repo editor on case-insensitive file systems

  • criticalPatched

    CVE-2022-32174Stored XSS Assignee

  • highPatched

    CVE-2022-1993Path Traversal in Git HTTP endpoints

  • criticalPatched

    CVE-2022-1992Path Traversal in file editor on Windows

  • mediumPatched

    CVE-2022-31038XSS vulnerability in repository issue list

  • criticalPatched

    CVE-2022-1986OS Command Injection in file editor

  • criticalPatched

    CVE-2021-32546Remote Command Execution in file editing

  • criticalPatched

    CVE-2022-1884OS Command Injection in file uploading

  • lowPatched

    GHSA-pj96-4jhv-v792XSS in cookies

  • highPatched

    CVE-2022-1285SSRF in webhook

  • mediumPatched

    CVE-2022-1464Stored XSS in issues

  • criticalPatched

    CVE-2022-0415Remote command execution in file uploading

  • mediumPatched

    CVE-2022-0870SSRF in repository migration

  • mediumPatched

    CVE-2022-0871Improper PAM authorization handling

Gogs Website

Website

Introduction - Gogs: A painless self-hosted Git service

The painless way to host your own Git service

Redirects

Redirects to https://gogs.io/getting-started/introduction

Security Checks

All 65 security checks passed

Server Details

  • IP Address162.159.143.13
  • LocationSan Francisco,California,United States of America,NA
  • ISPCloudFlare Inc.
  • ASNAS13335

Associated Countries

  • USUS

Safety Score

Website marked as safe

100%

Blacklist Check

gogs.io was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

Gogs Reviews

More Code Hosting

About the Data: Gogs

Change History

Edit Gogs Data

You can edit Gogs's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access Gogs's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/gogs

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share Gogs

Help your friends compare Code Hosting, and pick privacy-respecting software and services.
Share Gogs and Awesome Privacy with your network!