Codeberg vs Forgejo

Compare Codeberg and Forgejo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: GitHub, GitLab, SourceHut

Logo: Codeberg

Codeberg

Germany· Git Hosting

Needs review

Shortlist Codeberg when you need a free, German non-profit host for FLOSS Git projects with optional Pages, request-gated Woodpecker CI, and Weblate—and you accept community-funded SLAs. Skip when you need large private monorepos, paid enterprise compliance packaging, or GitHub/GitLab marketplace depth; self-host Forgejo or stay on GitLab/GitHub instead.

EU-operated (DE)Open source (Forgejo)Non-profit e.V.FLOSS-focusedHosting in GermanyNo ad tracking (claimed)
Logo: Forgejo

Forgejo

Germany· Git Hosting

Needs review

Shortlist Forgejo when you want a lightweight, self-hosted Git forge with GitHub-like UX, Actions-style CI on your runners, package registry, and non-profit Codeberg e.V. governance (GPLv3+ from v9). Skip when you need fully managed SaaS with enterprise SLA, or GitLab-class advanced CI/PM out of the box—consider GitLab CE/EE or GitHub instead. If you want hosted EU public forge without ops, evaluate Codeberg rather than self-hosting Forgejo.

Open source (GPLv3+)Self-hostedCodeberg e.V. (DE)Forgejo Actions CIPackage registryGitea migration path
Codeberg vs Forgejo: Snapshot
FeatureLogo: CodebergCodebergLogo: ForgejoForgejo
Country of originGermanyGermany
CategoryGit HostingGit Hosting
Open sourceYesYes
Self-hostedNoYes
HeadquartersGermanyGermany
Legal entityCodeberg e.V. (Amtsgericht Charlottenburg VR36929; Arminiusstraße 2-4, 10551 Berlin)Codeberg e.V. (domain custody; project under non-profit umbrella)
Governing lawGermany (association / platform Terms of Use; content subject to German law)Germany (association registered Berlin; Charlottenburg VR36929)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyPrimary services on association-controlled bare-metal in Berlin (Germany); backups/redundancy/DR/DDoS and related tasks use German providers netcup GmbH and Hetzner Online GmbH (FAQ). Privacy policy: servers physically in Germany; fuller third-party list available on request. Payment processors for donations/memberships.Self-host path: no vendor multi-tenant hosting—repos, backups, email, CDN, and Actions runners are chosen by the operator. Codeberg.org and other public instances are separate hosted data paths under those operators, not implied by installing Forgejo.
Summary

Non-profit German Git forge (Forgejo) for free/open-source projects, with Pages, Woodpecker CI, and Weblate—operated by Codeberg e.V. in Berlin.

Self-hosted lightweight Free Software forge (Git, issues, packages, Actions CI) under Codeberg e.V.—distinct from Codeberg.org hosting.

Tags
At a glance: Codeberg vs Forgejo
At a glanceLogo: CodebergCodebergLogo: ForgejoForgejo
HQBerlin, Germany (Codeberg e.V.)Not listed
Legal formRegistered non-profit association (e.V.)Not listed
StackForgejo + Pages + Woodpecker CI + WeblateNot listed
Commercial modelFree for eligible FLOSS; donations & optional membershipNot listed
Self-host productNo (host Forgejo yourself)Not listed
Product typeNot listedSelf-hosted software forge (not Codeberg SaaS)
Umbrella / domainsNot listedCodeberg e.V., Berlin, Germany
LicenseNot listedGPLv3+ (v9+); MIT (≤v8)
OriginNot listedGitea hard fork (early 2024); project started Oct 2022
InstallNot listedBinary, Docker; community packages
Release cadenceNot listed~Quarterly stable, annual LTS, frequent patches
Key capabilities: Codeberg vs Forgejo
Key capabilitiesLogo: CodebergCodebergLogo: ForgejoForgejo
EU-operated (DE)YesNot listed
Open source (Forgejo)YesYes
Non-profit e.V.YesNot listed
FLOSS-focusedYesNot listed
Hosting in GermanyYesNot listed
No ad tracking (claimed)YesNot listed
Self-hostedNot listedYes
Codeberg e.V. (DE)Not listedYes
Forgejo Actions CINot listedYes
Package registryNot listedYes
Gitea migration pathNot listedYes

Codeberg

  • Forgejo Git forge (issues, PRs, wikis, packages)

    Hosted Forgejo instance with standard forge workflows: Git repos, issues, pull requests, wikis, and package features. UI is familiar to GitHub users, which lowers migration cost for FLOSS teams. Public content must meet free-license rules in the Terms of Use.

  • Codeberg Pages (git-pages static sites)

    Publish static sites at username.codeberg.page or custom domains via the git-pages stack (webhook or Forgejo Actions deploy). Suited to project docs and simple sites—not a full CMS or dynamic app host. Pages stack has been migrating from legacy pages-server v2; check current docs for deprecations.

  • Woodpecker CI (request-gated) + self-hosted agents

    Optional CI on ci.codeberg.org after a volunteer-reviewed access request. linux/amd64 only on the shared instance; provided as-is with resource-use expectations. Orgs can attach self-hosted Woodpecker agents or run their own Woodpecker linked to Codeberg.

  • Codeberg Translate (Weblate)

    Hosted Weblate at translate.codeberg.org for collaborative localization of FOSS projects. Useful when i18n is part of release process without standing up a separate Weblate server.

  • Non-profit governance and no ad tracking

    Operated by Codeberg e.V. (Berlin); funded by donations/memberships, not ads. Privacy policy and site claim no third-party advertising cookies or tracking analytics; session cookies only for CSRF/login. Optional e.V. membership carries voting rights over association leadership.

Forgejo

  • Self-hosted Git forge with familiar collaboration UX

    Run Git repositories, pull requests and code review, issues/boards, wikis, and releases on infrastructure you control. Install from official binaries or Docker; first registered user becomes admin. Suited to teams that want GitHub-like workflows without SaaS tenancy.

  • Forgejo Actions CI/CD with self-hosted runners

    YAML workflows under .forgejo/workflows (GitHub Actions–inspired syntax, not identical) run on runners you register and label. Supports push/PR/schedule/dispatch, reusable workflows, matrices, services, and OIDC ID tokens. Advanced enterprise CI depth still lags GitLab/GitHub per project comparisons.

  • Integrated package registry

    Publish and pull packages from the same forge—including container images, npm, and other package ecosystems listed in project docs—so artifacts stay next to the source repos that produce them. Operators still size storage and retention themselves.

  • Non-profit governance under Codeberg e.V.

    Domains are in custody of Berlin-registered non-profit Codeberg e.V.; contributor-defined governance and public sustainability tracking. Hard fork of Gitea since early 2024; GPLv3+ from v9.0. Distinct from for-profit Gitea Ltd control of the Gitea trademark/domains.

  • Gitea migration path and LTS cadence

    Documented upgrades from Gitea preserve instance data; stable releases about every three months plus annual LTS and frequent security/bug patches. Operators must plan major-version upgrades manually—container tags intentionally avoid a floating latest major.

  • Experimental forge federation (ForgeFed / ActivityPub)

    Active R&D toward federated forge features with monthly progress reporting. Still experimental: moderation/access control incomplete; breaking federation changes possible, including burning an ActivityPub domain. Not a production federation default.

Assurance & compliance: Codeberg vs Forgejo
Assurance & complianceLogo: CodebergCodebergLogo: ForgejoForgejo
Independent security / no-logs audit
Not found

No public third-party security or no-logs audit PDF found on imprint/privacy/docs at research time.

Not found

Public security process and release notes exist; no independent public penetration-test report found for the project as a whole.

ISO 27001
Not found

No Codeberg e.V. ISO 27001 claim found on public legal/docs pages (infra partners may hold their own certs).

Not found

No ISO 27001 certification published for Forgejo software/project.

SOC 2 / SOC 3
Not found

No SOC 2/3 report advertised for Codeberg.org.

Not found

No SOC 2 for Forgejo. Do not confuse with historical Gitea Cloud SOC2 marketing.

GDPR / EU data protection
Vendor claimed

German controller (Codeberg e.V.) with detailed GDPR privacy policy, named DPO (privacy@codeberg.org), DE hosting claims; project owners remain responsible when they process personal data via CI/Pages/repos.

Partial

EU non-profit umbrella and self-host model; controller obligations sit with the operator of each instance. Confirm policies for any hosted instance (Codeberg/public) separately.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU non-profit entity, no known US parent, primary and named backup/DR hosts are German (bare-metal Berlin; netcup; Hetzner). Not a vendor 'CLOUD Act free' claim. Residual risk via any undisclosed processors and US-law reach on global users—confirm full subprocessor list on request. Not legal advice.

Partial

Assessment: EU non-profit custody (Codeberg e.V.), no known US parent; self-host has no Forgejo multi-tenant subprocessors. Exposure rises if you host on AWS/GCP/Azure/US SaaS or use a US-jurisdiction public instance. Not legal advice.

Data processing agreement (B2B)
Not found

No standard commercial B2B DPA product page found; service is free FLOSS community hosting, not a paid enterprise SaaS SKU. Privacy policy describes processing; ask the association if you need a formal Art. 28 arrangement.

Not applicable

Self-hosted software download is not a vendor processing service. Request a DPA from whoever operates a hosted instance (e.g. Codeberg) if applicable.

EU AI Act
Not applicable

Codeberg is a code forge/host, not an AI system product. Terms restrict repos that mostly consist of generative-AI-written code.

Not applicable

Forge is not an AI product.

Considerations & known limitations: Codeberg vs Forgejo
Considerations & known limitationsLogo: CodebergCodebergLogo: ForgejoForgejo
FLOSS mission limits private/proprietary use
High

Public content must use free licenses; private repos are a small convenience for FLOSS contributors, not a commercial private-hosting product. Proprietary monorepos belong elsewhere or on self-hosted Forgejo.

Not listed
No commercial availability SLA
Medium

Donation-funded community infrastructure with explicit disclaimer of warranties. Orgs must keep independent backups and exit plans; do not treat Codeberg as sole system of record for critical business IP without risk acceptance.

Not listed
No public ISO/SOC certification pack
Medium

Procurement teams expecting vendor ISO 27001 or SOC 2 attestations will not find them advertised for Codeberg.org. Mitigate with your own threat model, encryption at rest in repos where needed, and self-hosting if cert packs are mandatory.

Low

Procurement checklists expecting vendor ISO 27001/SOC 2 will not find them for Forgejo as a project; rely on your own hosting controls and review process.

Shared CI is request-gated and best-effort
Medium

Woodpecker access requires volunteer approval; shared runners are linux/amd64 and may break for maintenance. Plan self-hosted agents for heavy or multi-arch pipelines.

Not listed
Full third-party list on request only
Low

FAQ names netcup and Hetzner for backups/DR/DDoS; privacy policy says the complete third-party list is available on request. Request it in writing before high-sensitivity workloads.

Not listed
You operate the forge and runnersNot listed
Medium

Upgrades (especially major versions), backups, auth, storage, TLS, and Actions runner capacity are on the operator. Not a managed SaaS.

Advanced CI/PM behind GitLab/GitHubNot listed
Medium

Project comparison marks advanced CI and heavy project-management needs as weaker than GitLab/GitHub. Validate Actions and boards against your pipelines.

Federation is experimentalNot listed
Medium

ActivityPub/ForgeFed may break; moderation/access control incomplete; domains can be burned for federation use.

Self-host vs Codeberg/public instancesNot listed
Low

Codeberg and other public instances have their own ToS, moderation, and infrastructure. Do not inherit their residency claims when self-hosting—or vice versa.

GPLv3+ redistribution obligationsNot listed
Low

From v9.0, redistributing modified Forgejo generally requires corresponding source under GPL terms. Internal run-from-official-images is usually simpler; still not legal advice.

Fit

Codeberg

Best fit when

  • FLOSS maintainers and contributors who need public Git hosting under free licenses
  • Teams migrating public projects off GitHub for non-profit governance or reduced US-platform dependency
  • Projects that want static docs sites (Pages) and collaborative translation (Weblate) next to the forge
  • Orgs comfortable with donation-funded infrastructure and volunteer-reviewed CI access
  • Users who prefer a Forgejo/GitHub-like UI over email-centric forges

Poor fit when

  • Closed-source product teams needing large private monorepos or paid private Git as a product
  • Enterprises requiring commercial SLAs, formal ISO/SOC evidence packs, or full DevSecOps suites out of the box
  • Workloads that depend on automatic pull-mirrors from other forges (disabled on Codeberg)
  • Heavy multi-arch CI fleets needing always-on shared runners without self-hosted agents
  • Anyone seeking a general-purpose personal cloud or media backup host

Consider instead when

  • When: You need proprietary private repos with commercial support and marketplace CI

    Consider: GitHub or GitLab SaaS

    Deeper integrations and paid compliance packaging; US/corporate ownership and different privacy posture.

  • When: You need full control of policies, SSO, and data plane under your own DPA

    Consider: Self-hosted Forgejo (or self-managed GitLab) on EU infrastructure

    Codeberg.org is not a private enterprise SKU; Forgejo is the self-host path Codeberg documents.

  • When: You prefer minimal-web, email/patch-oriented FLOSS workflows

    Consider: SourceHut

    Different UX and commercial model; still not a German non-profit.

Forgejo

Best fit when

  • Teams that will self-host Git hosting and accept ops for upgrades, backups, auth, and runners
  • Organizations leaving Gitea over for-profit trademark/domain control and wanting a hard-fork FOSS path
  • Groups that need a lighter footprint than GitLab but still want PRs, issues, packages, and CI
  • FOSS communities and public-interest projects aligned with non-profit Codeberg e.V. umbrella
  • Buyers who can treat federation as experimental R&D, not a day-one requirement

Poor fit when

  • Buyers seeking a vendor-operated multi-tenant SaaS with enterprise support contract from Forgejo Inc.—that product shape does not exist
  • Orgs that need mature advanced CI/CD and deep project management comparable to GitLab/GitHub today
  • Teams unwilling to run or buy infrastructure for the forge and Actions runners
  • Anyone equating forgejo.org downloads with Codeberg.org hosting terms and residency

Consider instead when

  • When: You want a German non-profit public forge without self-hosting

    Consider: Codeberg

    Hosted service using Forgejo; separate ToS, moderation, and infrastructure from self-host software

  • When: You need advanced CI/CD and rich project management on a single platform

    Consider: GitLab CE/EE (self-host or SaaS) or GitHub

    Heavier ops or US-jurisdiction SaaS tradeoffs

  • When: You prefer staying on the Gitea project line or Gitea Cloud

    Consider: Gitea

    Closer upstream to some ecosystems; different governance and open-core/SaaS posture

  • When: You want a minimal email-oriented forge workflow

    Consider: SourceHut

    Different UX philosophy from GitHub-like Forgejo

Open questions for due diligence

Codeberg

  • Will Codeberg e.V. provide a written Art. 28 DPA and current subprocessor list for our legal file?
  • What backup retention, restore RPO/RTO, and export tooling apply if we treat the forge as critical infrastructure?
  • Can our CI profile (arch, minutes, secrets handling) be met with shared Woodpecker, self-hosted agents, or a private Woodpecker link?
  • Are any remaining Pages v2 projects still on our migration path to git-pages?

Forgejo

  • Who will own production ops: upgrades, backups, secrets, and Actions runners capacity?
  • If considering Codeberg or another public instance instead of self-host, what are that operator's DPA, residency, and subprocessors?
  • Do GPLv3+ redistribution rules affect your packaging, appliances, or downstream products?
  • Which CI workflows must be proven on Forgejo Actions (not assumed from GitHub Actions) before cutover?
  • Is experimental federation a requirement, or should it stay disabled?