CHANGELOG.org
116 lines · 6242 bytes
1#+title: gitbay changelog
2
3Versioning follows semver from v0.1.0. Database migrations run
4automatically on daemon start; upgrade notes appear per release when
5anything beyond "replace the binary and restart" is needed.
6
7* v0.3.0 — 2026-08-25
8
9- CI: =.gitbay/ci.yml= jobs run as builds claimed by =gitbay-runner=
10 over SSH (admin-only runner protocol; statuses feed =require-checks=).
11 Per-repo secrets set over stdin and injected into build environments;
12 cron schedules (server-local time) and tag-glob triggers, mutually
13 exclusive per job; =build list/show/log/trigger= and a builds tab.
14- Pages: public repos' =pages= branches served on =<owner>.<domain>=
15 (=[pages] domain=), custom domains with DNS TXT ownership challenges
16 and 7-day expiry for pending claims, per-subdomain on-demand ACME.
17- Wikis (=.wiki= companion repos, access mirrors the parent) and teams
18 within orgs (members-role scoping, per-repo team grants).
19- Activity graphs on user and org pages, backfillable
20 (=admin backfill-activity=); commits attributed by verified author
21 email, deduped by sha.
22- MR pages list the commits the MR carries; =mr show= gains a commits
23 section.
24- Per-file history: =?path== on the web log, =--path= on =repo log=,
25 history link on blob pages.
26- Mirror status surfaced in =repo show= and the repo header
27 (admin-only), with sync errors visible; tag-only pushes now schedule
28 mirror syncs.
29- Rendering: GFM tables/strikethrough/autolinks/task lists, blob image
30 previews, raw serves images with real content types (README images
31 render under nosniff), 0BSD license recognition, repo website links,
32 compact dashboard pins.
33- =admin user delete= for accounts that anchor nothing, with named
34 blockers otherwise.
35- Fixes: wiki pages no longer overflow on mobile (iOS font-inflation
36 trigger), GHSA-free deps, secret values pipe correctly through the
37 CLI.
38
39Migrations 0020-0025 apply on start. New config: =[pages] domain=.
40The runner is a new binary (=gitbay-runner=); see the wiki's Admin
41guide for setup. Stress-tested against an import of git.git (82k
42commits): see the wiki's Performance page.
43
44* v0.2.0 — 2026-08-24
45
46- Deploy keys: repo-bound CI keys (=repo deploy-key=), ro/rw, rename- and
47 transfer-proof.
48- Commit statuses (=status set/list=), combined state on MR pages, and a
49 =require-checks= merge gate.
50- Email notifications for issue and MR activity (participants with
51 verified addresses; never the actor).
52- Inline review threads on MR diffs (=mr diff-comment/threads/resolve=),
53 stale on force-push, =require-resolved= merge gate.
54- Required approvals with CODEOWNERS (=require-approvals=; latest review
55 wins, author excluded) and a =require-resolved= gate; merge gate order
56 is checks → approvals → CODEOWNERS → resolved threads → signatures.
57- Web design revamp: token-based stylesheet (light+dark), wordmark and
58 favicon, aligned layout grid, card-based listings, designed 404,
59 mobile pass.
60- Cross-references and mentions: =#N=, =!N=, =owner/name#N=, =@user=
61 autolink in issue/MR text, viewer-aware for private repos.
62- Archived repositories (read-only with badge) and repo topics.
63- Blame view with signature-aware attribution and 1000-line pages.
64- Repository search (name/description/topic) and per-repo code search
65 (=repo grep=, web search tab); blob line anchors.
66- Homepage: dashboard for logged-in users (pinned repos via =repo pin=,
67 open MRs and issues involving you), landing page for visitors, full
68 public listing at =/explore=; MR diffs collapsed by default.
69- Milestones (=milestone create/list/close=, =issue/mr milestone=) with
70 web progress; issue templates from =.gitbay/issue-template*.md=
71 (CLI =$EDITOR= prefill and web form).
72- Issue actions from commit messages landing on the default branch:
73 =closes/fixes/resolves #N= closes, bare =#N= leaves a reference
74 comment; once per issue+commit.
75- Vanity Go imports: =[go_import]= config serves go-import meta tags, so
76 =go install gitbay.org/gitbay/cmd/...@latest= works.
77- Release script: =deploy/release.sh <tag>= builds reproducible
78 linux/amd64, linux/arm64, and darwin/arm64 binaries with SHA256SUMS.
79- Repository maintenance: =admin gc= (repack/prune, per-repo sizes),
80 =admin stats= (counts + disk usage), weekly =gitbay-gc.timer=.
81- Releases: tag-anchored notes and binary assets (=release= commands,
82 assets over SSH stdin/stdout, web releases tab with downloads).
83- GitHub history import: =repo import-issues= brings issues and PRs
84 (as merged/closed MRs) with comments, labels, and state, attributed
85 inline and resumable.
86- Push and pull mirroring (=repo mirror=): background sync, read-only
87 pull mirrors, per-mirror status; credentials server-side, SSRF-guarded.
88- Web signup at =/register= for open and invite instances.
89- Audit log (=audit=, =gitbayd admin audit=): every mutating command
90 with source key fingerprint, registrations, force-pushes, auth
91 failures. Hardening: per-IP auth-failure throttling
92 (=ssh_auth_rate=), =max_pack_bytes= enforced, =admin user
93 disable/enable=.
94- Account migration: =gitbay migrate --from <host>= (bundle
95 export/replay + client-side git mirror); =gitbay auth export= as a
96 user-level backup.
97- Editable issues and MRs (=issue edit=, =mr edit=, web forms).
98- Commit references appear as system messages with linked shas.
99- Design: top nav, repo listing rows (topics, license, last updated),
100 file table headers, README relative-link resolution, branch
101 dropdown, web pinning, org owner picker, label filters, linked
102 usernames and commit parents, =/privacy= page, blue accent.
103
104Upgrade notes: migrations 0006–0019 apply on start. No config changes
105required; =[go_import]=, =[mirrors]=, =web.privacy_notice=, and
106=web.mode = "accounts"= are opt-in.
107
108* v0.1.0 — 2026-08-24
109
110First tagged release: the complete CLI-first forge. SSH control plane
111(bare-OpenSSH usable), git over SSH/HTTPS/git-daemon, repos, issues,
112merge requests (ff/merge/squash/rebase with signature policy), OpenPGP
113and SSHSIG verification with retroactive re-verification, orgs, repo
114import, web UI (view-only or accounts mode), registration with invites
115and SMTP, HTTPS/JSON API with SSH-minted tokens, webhooks, backups,
116ACME TLS, systemd deployment.