If Gitea discovered some massive CVE, and volentarily went dark to fix it... They would want their code and fix hosted somewhere else.
Not dogfooding your own product seems like a huge red flag to me.
Disclaimer: I'm one of the members of the technical oversight committee of the Gitea project, and am employed to work on Gitea.
If Gitea discovered some massive CVE, and volentarily went dark to fix it... They would want their code and fix hosted somewhere else.