If Gitea discovered some massive CVE, and volentarily went dark to fix it... They would want their code and fix hosted somewhere else.
Not dogfooding your own product seems like a huge red flag to me.
Disclaimer: I'm one of the members of the technical oversight committee of the Gitea project, and am employed to work on Gitea.