CHANGELOG.org

v0.4.0
gitbay/CHANGELOG.org rendered · source · history · blame · raw

138 lines · 7386 bytes

  1#+title: gitbay changelog
  2
  3Versioning follows semver from v0.1.0. Database migrations run
  4automatically on daemon start; upgrade notes appear per release when
  5anything beyond "replace the binary and restart" is needed.
  6
  7* v0.4.0 — 2026-08-25
  8
  9- Git LFS: standard clients work over both transports.
 10  =git-lfs-authenticate= joins the SSH dispatcher (deploy keys
 11  included; download needs read, upload write), minting stateless
 12  repo- and operation-scoped tokens for the batch API and basic
 13  transfers. Anonymous HTTPS downloads for public repos; uploads
 14  verified against size and sha256 before landing. Storage is
 15  content-addressed under =[lfs] root= behind a small interface an
 16  S3-compatible backend can drop into; =[lfs] max_object_bytes= caps
 17  objects (512MB default).
 18- Build failures mail the repo's notify targets with the log tail and
 19  build link — failed scheduled jobs reach an inbox.
 20- =release edit= updates a release's title and notes (absent flags
 21  keep their field); omaha-style CI note rebuilds work again.
 22- Syntax highlighting follows the color scheme: class-based chroma
 23  with light and dark palettes, the light-pinned code background is
 24  gone, and markdown fences and org src blocks highlight too. The UGC
 25  sanitizer admits only chroma's token-code classes.
 26
 27No migrations. New config: =[lfs] root=, =[lfs] max_object_bytes=.
 28
 29* v0.3.0 — 2026-08-25
 30
 31- CI: =.gitbay/ci.yml= jobs run as builds claimed by =gitbay-runner=
 32  over SSH (admin-only runner protocol; statuses feed =require-checks=).
 33  Per-repo secrets set over stdin and injected into build environments;
 34  cron schedules (server-local time) and tag-glob triggers, mutually
 35  exclusive per job; =build list/show/log/trigger= and a builds tab.
 36- Pages: public repos' =pages= branches served on =<owner>.<domain>=
 37  (=[pages] domain=), custom domains with DNS TXT ownership challenges
 38  and 7-day expiry for pending claims, per-subdomain on-demand ACME.
 39- Wikis (=.wiki= companion repos, access mirrors the parent) and teams
 40  within orgs (members-role scoping, per-repo team grants).
 41- Activity graphs on user and org pages, backfillable
 42  (=admin backfill-activity=); commits attributed by verified author
 43  email, deduped by sha.
 44- MR pages list the commits the MR carries; =mr show= gains a commits
 45  section.
 46- Per-file history: =?path== on the web log, =--path= on =repo log=,
 47  history link on blob pages.
 48- Mirror status surfaced in =repo show= and the repo header
 49  (admin-only), with sync errors visible; tag-only pushes now schedule
 50  mirror syncs.
 51- Rendering: GFM tables/strikethrough/autolinks/task lists, blob image
 52  previews, raw serves images with real content types (README images
 53  render under nosniff), 0BSD license recognition, repo website links,
 54  compact dashboard pins.
 55- =admin user delete= for accounts that anchor nothing, with named
 56  blockers otherwise.
 57- Fixes: wiki pages no longer overflow on mobile (iOS font-inflation
 58  trigger), GHSA-free deps, secret values pipe correctly through the
 59  CLI.
 60
 61Migrations 0020-0025 apply on start. New config: =[pages] domain=.
 62The runner is a new binary (=gitbay-runner=); see the wiki's Admin
 63guide for setup. Stress-tested against an import of git.git (82k
 64commits): see the wiki's Performance page.
 65
 66* v0.2.0 — 2026-08-24
 67
 68- Deploy keys: repo-bound CI keys (=repo deploy-key=), ro/rw, rename- and
 69  transfer-proof.
 70- Commit statuses (=status set/list=), combined state on MR pages, and a
 71  =require-checks= merge gate.
 72- Email notifications for issue and MR activity (participants with
 73  verified addresses; never the actor).
 74- Inline review threads on MR diffs (=mr diff-comment/threads/resolve=),
 75  stale on force-push, =require-resolved= merge gate.
 76- Required approvals with CODEOWNERS (=require-approvals=; latest review
 77  wins, author excluded) and a =require-resolved= gate; merge gate order
 78  is checks → approvals → CODEOWNERS → resolved threads → signatures.
 79- Web design revamp: token-based stylesheet (light+dark), wordmark and
 80  favicon, aligned layout grid, card-based listings, designed 404,
 81  mobile pass.
 82- Cross-references and mentions: =#N=, =!N=, =owner/name#N=, =@user=
 83  autolink in issue/MR text, viewer-aware for private repos.
 84- Archived repositories (read-only with badge) and repo topics.
 85- Blame view with signature-aware attribution and 1000-line pages.
 86- Repository search (name/description/topic) and per-repo code search
 87  (=repo grep=, web search tab); blob line anchors.
 88- Homepage: dashboard for logged-in users (pinned repos via =repo pin=,
 89  open MRs and issues involving you), landing page for visitors, full
 90  public listing at =/explore=; MR diffs collapsed by default.
 91- Milestones (=milestone create/list/close=, =issue/mr milestone=) with
 92  web progress; issue templates from =.gitbay/issue-template*.md=
 93  (CLI =$EDITOR= prefill and web form).
 94- Issue actions from commit messages landing on the default branch:
 95  =closes/fixes/resolves #N= closes, bare =#N= leaves a reference
 96  comment; once per issue+commit.
 97- Vanity Go imports: =[go_import]= config serves go-import meta tags, so
 98  =go install gitbay.org/gitbay/cmd/...@latest= works.
 99- Release script: =deploy/release.sh <tag>= builds reproducible
100  linux/amd64, linux/arm64, and darwin/arm64 binaries with SHA256SUMS.
101- Repository maintenance: =admin gc= (repack/prune, per-repo sizes),
102  =admin stats= (counts + disk usage), weekly =gitbay-gc.timer=.
103- Releases: tag-anchored notes and binary assets (=release= commands,
104  assets over SSH stdin/stdout, web releases tab with downloads).
105- GitHub history import: =repo import-issues= brings issues and PRs
106  (as merged/closed MRs) with comments, labels, and state, attributed
107  inline and resumable.
108- Push and pull mirroring (=repo mirror=): background sync, read-only
109  pull mirrors, per-mirror status; credentials server-side, SSRF-guarded.
110- Web signup at =/register= for open and invite instances.
111- Audit log (=audit=, =gitbayd admin audit=): every mutating command
112  with source key fingerprint, registrations, force-pushes, auth
113  failures. Hardening: per-IP auth-failure throttling
114  (=ssh_auth_rate=), =max_pack_bytes= enforced, =admin user
115  disable/enable=.
116- Account migration: =gitbay migrate --from <host>= (bundle
117  export/replay + client-side git mirror); =gitbay auth export= as a
118  user-level backup.
119- Editable issues and MRs (=issue edit=, =mr edit=, web forms).
120- Commit references appear as system messages with linked shas.
121- Design: top nav, repo listing rows (topics, license, last updated),
122  file table headers, README relative-link resolution, branch
123  dropdown, web pinning, org owner picker, label filters, linked
124  usernames and commit parents, =/privacy= page, blue accent.
125
126Upgrade notes: migrations 0006–0019 apply on start. No config changes
127required; =[go_import]=, =[mirrors]=, =web.privacy_notice=, and
128=web.mode = "accounts"= are opt-in.
129
130* v0.1.0 — 2026-08-24
131
132First tagged release: the complete CLI-first forge. SSH control plane
133(bare-OpenSSH usable), git over SSH/HTTPS/git-daemon, repos, issues,
134merge requests (ff/merge/squash/rebase with signature policy), OpenPGP
135and SSHSIG verification with retroactive re-verification, orgs, repo
136import, web UI (view-only or accounts mode), registration with invites
137and SMTP, HTTPS/JSON API with SSH-minted tokens, webhooks, backups,
138ACME TLS, systemd deployment.