CHANGELOG.org

6b01ef3788b21e3a4c027a2afe7e7a5bda9ca000
gitbay/CHANGELOG.org rendered · source · history · blame · raw

116 lines · 6242 bytes

gitbay changelog

Versioning follows semver from v0.1.0. Database migrations run automatically on daemon start; upgrade notes appear per release when anything beyond "replace the binary and restart" is needed.

v0.3.0 — 2026-08-25

  • CI: .gitbay/ci.yml jobs run as builds claimed by gitbay-runner over SSH (admin-only runner protocol; statuses feed require-checks). Per-repo secrets set over stdin and injected into build environments; cron schedules (server-local time) and tag-glob triggers, mutually exclusive per job; build list/show/log/trigger and a builds tab.
  • Pages: public repos' pages branches served on <owner>.<domain> ([pages] domain), custom domains with DNS TXT ownership challenges and 7-day expiry for pending claims, per-subdomain on-demand ACME.
  • Wikis (.wiki companion repos, access mirrors the parent) and teams within orgs (members-role scoping, per-repo team grants).
  • Activity graphs on user and org pages, backfillable (admin backfill-activity); commits attributed by verified author email, deduped by sha.
  • MR pages list the commits the MR carries; mr show gains a commits section.
  • Per-file history: ?path= on the web log, --path on repo log, history link on blob pages.
  • Mirror status surfaced in repo show and the repo header (admin-only), with sync errors visible; tag-only pushes now schedule mirror syncs.
  • Rendering: GFM tables/strikethrough/autolinks/task lists, blob image previews, raw serves images with real content types (README images render under nosniff), 0BSD license recognition, repo website links, compact dashboard pins.
  • admin user delete for accounts that anchor nothing, with named blockers otherwise.
  • Fixes: wiki pages no longer overflow on mobile (iOS font-inflation trigger), GHSA-free deps, secret values pipe correctly through the CLI.

Migrations 0020-0025 apply on start. New config: [pages] domain. The runner is a new binary (gitbay-runner); see the wiki's Admin guide for setup. Stress-tested against an import of git.git (82k commits): see the wiki's Performance page.

v0.2.0 — 2026-08-24

  • Deploy keys: repo-bound CI keys (repo deploy-key), ro/rw, rename- and transfer-proof.
  • Commit statuses (status set/list), combined state on MR pages, and a require-checks merge gate.
  • Email notifications for issue and MR activity (participants with verified addresses; never the actor).
  • Inline review threads on MR diffs (mr diff-comment/threads/resolve), stale on force-push, require-resolved merge gate.
  • Required approvals with CODEOWNERS (require-approvals; latest review wins, author excluded) and a require-resolved gate; merge gate order is checks → approvals → CODEOWNERS → resolved threads → signatures.
  • Web design revamp: token-based stylesheet (light+dark), wordmark and favicon, aligned layout grid, card-based listings, designed 404, mobile pass.
  • Cross-references and mentions: #N, !N, owner/name#N, @user autolink in issue/MR text, viewer-aware for private repos.
  • Archived repositories (read-only with badge) and repo topics.
  • Blame view with signature-aware attribution and 1000-line pages.
  • Repository search (name/description/topic) and per-repo code search (repo grep, web search tab); blob line anchors.
  • Homepage: dashboard for logged-in users (pinned repos via repo pin, open MRs and issues involving you), landing page for visitors, full public listing at /explore; MR diffs collapsed by default.
  • Milestones (milestone create/list/close, issue/mr milestone) with web progress; issue templates from .gitbay/issue-template*.md (CLI $EDITOR prefill and web form).
  • Issue actions from commit messages landing on the default branch: closes/fixes/resolves #N closes, bare #N leaves a reference comment; once per issue+commit.
  • Vanity Go imports: [go_import] config serves go-import meta tags, so go install gitbay.org/gitbay/cmd/...@latest works.
  • Release script: deploy/release.sh <tag> builds reproducible linux/amd64, linux/arm64, and darwin/arm64 binaries with SHA256SUMS.
  • Repository maintenance: admin gc (repack/prune, per-repo sizes), admin stats (counts + disk usage), weekly gitbay-gc.timer.
  • Releases: tag-anchored notes and binary assets (release commands, assets over SSH stdin/stdout, web releases tab with downloads).
  • GitHub history import: repo import-issues brings issues and PRs (as merged/closed MRs) with comments, labels, and state, attributed inline and resumable.
  • Push and pull mirroring (repo mirror): background sync, read-only pull mirrors, per-mirror status; credentials server-side, SSRF-guarded.
  • Web signup at /register for open and invite instances.
  • Audit log (audit, gitbayd admin audit): every mutating command with source key fingerprint, registrations, force-pushes, auth failures. Hardening: per-IP auth-failure throttling (ssh_auth_rate), max_pack_bytes enforced, admin user disable/enable.
  • Account migration: gitbay migrate --from <host> (bundle export/replay + client-side git mirror); gitbay auth export as a user-level backup.
  • Editable issues and MRs (issue edit, mr edit, web forms).
  • Commit references appear as system messages with linked shas.
  • Design: top nav, repo listing rows (topics, license, last updated), file table headers, README relative-link resolution, branch dropdown, web pinning, org owner picker, label filters, linked usernames and commit parents, /privacy page, blue accent.

Upgrade notes: migrations 0006–0019 apply on start. No config changes required; [go_import], [mirrors], web.privacy_notice, and web.mode = "accounts" are opt-in.

v0.1.0 — 2026-08-24

First tagged release: the complete CLI-first forge. SSH control plane (bare-OpenSSH usable), git over SSH/HTTPS/git-daemon, repos, issues, merge requests (ff/merge/squash/rebase with signature policy), OpenPGP and SSHSIG verification with retroactive re-verification, orgs, repo import, web UI (view-only or accounts mode), registration with invites and SMTP, HTTPS/JSON API with SSH-minted tokens, webhooks, backups, ACME TLS, systemd deployment.