CHANGELOG.org
175 lines · 9235 bytes
1#+title: gitbay changelog
2
3Versioning follows semver from v0.1.0. Database migrations run
4automatically on daemon start; upgrade notes appear per release when
5anything beyond "replace the binary and restart" is needed.
6
7* v0.5.0 — 2026-08-26
8
9A design pass and a parity pass. The web stops being a read-only
10mirror of the CLI without becoming the place you are expected to work.
11
12- New design: a black shell with a persistent left rail carrying
13 cross-repo state (pinned repos, review queue), the repo header
14 rendered identically on every tab so navigation never moves, sharp
15 lines, self-hosted IBM Plex, and code blocks that read against both
16 color schemes. Tree listings sort directories first and carry each
17 file's last commit; diffs, inputs and controls were reworked to
18 match.
19- Web parity with the CLI, dispatched through the same command
20 registry the CLI and JSON API use — every web write is the
21 equivalent =gitbay= command with =--source web=:
22 - merge requests: review, resolve threads, merge, close, and open a
23 new MR from the browser
24 - issues: state, labels, assignees, milestones
25 - repositories: settings, branch protection, visibility
26 - releases: create and edit; builds: trigger a job
27 Commands marked SSH-only still refuse over the web: build secrets,
28 mirror tokens, domain claims, token minting, deletion and transfer.
29- A dashboard that answers "what needs me": review queue, assigned
30 issues, pinned repos, and an activity feed. Author names resolve to
31 accounts and link to profiles wherever commits appear.
32- Build status badges at =/{owner}/{repo}/badge/build.svg= for public
33 repos.
34- =[web] title= sets the instance's display name, separate from the
35 hostname commands are pasted with.
36- =make build/test/deploy= targets.
37- Fixes: the mobile tab strip scrolls sideways only, long commit
38 subjects no longer overflow on narrow screens, the shell fills the
39 viewport with the line-length cap moved onto prose, and the account
40 cell lines up with the page footer.
41
42No migrations. New config: =[web] title=.
43
44* v0.4.0 — 2026-08-25
45
46- Git LFS: standard clients work over both transports.
47 =git-lfs-authenticate= joins the SSH dispatcher (deploy keys
48 included; download needs read, upload write), minting stateless
49 repo- and operation-scoped tokens for the batch API and basic
50 transfers. Anonymous HTTPS downloads for public repos; uploads
51 verified against size and sha256 before landing. Storage is
52 content-addressed under =[lfs] root= behind a small interface an
53 S3-compatible backend can drop into; =[lfs] max_object_bytes= caps
54 objects (512MB default).
55- Build failures mail the repo's notify targets with the log tail and
56 build link — failed scheduled jobs reach an inbox.
57- =release edit= updates a release's title and notes (absent flags
58 keep their field); omaha-style CI note rebuilds work again.
59- Syntax highlighting follows the color scheme: class-based chroma
60 with light and dark palettes, the light-pinned code background is
61 gone, and markdown fences and org src blocks highlight too. The UGC
62 sanitizer admits only chroma's token-code classes.
63
64No migrations. New config: =[lfs] root=, =[lfs] max_object_bytes=.
65
66* v0.3.0 — 2026-08-25
67
68- CI: =.gitbay/ci.yml= jobs run as builds claimed by =gitbay-runner=
69 over SSH (admin-only runner protocol; statuses feed =require-checks=).
70 Per-repo secrets set over stdin and injected into build environments;
71 cron schedules (server-local time) and tag-glob triggers, mutually
72 exclusive per job; =build list/show/log/trigger= and a builds tab.
73- Pages: public repos' =pages= branches served on =<owner>.<domain>=
74 (=[pages] domain=), custom domains with DNS TXT ownership challenges
75 and 7-day expiry for pending claims, per-subdomain on-demand ACME.
76- Wikis (=.wiki= companion repos, access mirrors the parent) and teams
77 within orgs (members-role scoping, per-repo team grants).
78- Activity graphs on user and org pages, backfillable
79 (=admin backfill-activity=); commits attributed by verified author
80 email, deduped by sha.
81- MR pages list the commits the MR carries; =mr show= gains a commits
82 section.
83- Per-file history: =?path== on the web log, =--path= on =repo log=,
84 history link on blob pages.
85- Mirror status surfaced in =repo show= and the repo header
86 (admin-only), with sync errors visible; tag-only pushes now schedule
87 mirror syncs.
88- Rendering: GFM tables/strikethrough/autolinks/task lists, blob image
89 previews, raw serves images with real content types (README images
90 render under nosniff), 0BSD license recognition, repo website links,
91 compact dashboard pins.
92- =admin user delete= for accounts that anchor nothing, with named
93 blockers otherwise.
94- Fixes: wiki pages no longer overflow on mobile (iOS font-inflation
95 trigger), GHSA-free deps, secret values pipe correctly through the
96 CLI.
97
98Migrations 0020-0025 apply on start. New config: =[pages] domain=.
99The runner is a new binary (=gitbay-runner=); see the wiki's Admin
100guide for setup. Stress-tested against an import of git.git (82k
101commits): see the wiki's Performance page.
102
103* v0.2.0 — 2026-08-24
104
105- Deploy keys: repo-bound CI keys (=repo deploy-key=), ro/rw, rename- and
106 transfer-proof.
107- Commit statuses (=status set/list=), combined state on MR pages, and a
108 =require-checks= merge gate.
109- Email notifications for issue and MR activity (participants with
110 verified addresses; never the actor).
111- Inline review threads on MR diffs (=mr diff-comment/threads/resolve=),
112 stale on force-push, =require-resolved= merge gate.
113- Required approvals with CODEOWNERS (=require-approvals=; latest review
114 wins, author excluded) and a =require-resolved= gate; merge gate order
115 is checks → approvals → CODEOWNERS → resolved threads → signatures.
116- Web design revamp: token-based stylesheet (light+dark), wordmark and
117 favicon, aligned layout grid, card-based listings, designed 404,
118 mobile pass.
119- Cross-references and mentions: =#N=, =!N=, =owner/name#N=, =@user=
120 autolink in issue/MR text, viewer-aware for private repos.
121- Archived repositories (read-only with badge) and repo topics.
122- Blame view with signature-aware attribution and 1000-line pages.
123- Repository search (name/description/topic) and per-repo code search
124 (=repo grep=, web search tab); blob line anchors.
125- Homepage: dashboard for logged-in users (pinned repos via =repo pin=,
126 open MRs and issues involving you), landing page for visitors, full
127 public listing at =/explore=; MR diffs collapsed by default.
128- Milestones (=milestone create/list/close=, =issue/mr milestone=) with
129 web progress; issue templates from =.gitbay/issue-template*.md=
130 (CLI =$EDITOR= prefill and web form).
131- Issue actions from commit messages landing on the default branch:
132 =closes/fixes/resolves #N= closes, bare =#N= leaves a reference
133 comment; once per issue+commit.
134- Vanity Go imports: =[go_import]= config serves go-import meta tags, so
135 =go install gitbay.org/gitbay/cmd/...@latest= works.
136- Release script: =deploy/release.sh <tag>= builds reproducible
137 linux/amd64, linux/arm64, and darwin/arm64 binaries with SHA256SUMS.
138- Repository maintenance: =admin gc= (repack/prune, per-repo sizes),
139 =admin stats= (counts + disk usage), weekly =gitbay-gc.timer=.
140- Releases: tag-anchored notes and binary assets (=release= commands,
141 assets over SSH stdin/stdout, web releases tab with downloads).
142- GitHub history import: =repo import-issues= brings issues and PRs
143 (as merged/closed MRs) with comments, labels, and state, attributed
144 inline and resumable.
145- Push and pull mirroring (=repo mirror=): background sync, read-only
146 pull mirrors, per-mirror status; credentials server-side, SSRF-guarded.
147- Web signup at =/register= for open and invite instances.
148- Audit log (=audit=, =gitbayd admin audit=): every mutating command
149 with source key fingerprint, registrations, force-pushes, auth
150 failures. Hardening: per-IP auth-failure throttling
151 (=ssh_auth_rate=), =max_pack_bytes= enforced, =admin user
152 disable/enable=.
153- Account migration: =gitbay migrate --from <host>= (bundle
154 export/replay + client-side git mirror); =gitbay auth export= as a
155 user-level backup.
156- Editable issues and MRs (=issue edit=, =mr edit=, web forms).
157- Commit references appear as system messages with linked shas.
158- Design: top nav, repo listing rows (topics, license, last updated),
159 file table headers, README relative-link resolution, branch
160 dropdown, web pinning, org owner picker, label filters, linked
161 usernames and commit parents, =/privacy= page, blue accent.
162
163Upgrade notes: migrations 0006–0019 apply on start. No config changes
164required; =[go_import]=, =[mirrors]=, =web.privacy_notice=, and
165=web.mode = "accounts"= are opt-in.
166
167* v0.1.0 — 2026-08-24
168
169First tagged release: the complete CLI-first forge. SSH control plane
170(bare-OpenSSH usable), git over SSH/HTTPS/git-daemon, repos, issues,
171merge requests (ff/merge/squash/rebase with signature policy), OpenPGP
172and SSHSIG verification with retroactive re-verification, orgs, repo
173import, web UI (view-only or accounts mode), registration with invites
174and SMTP, HTTPS/JSON API with SSH-minted tokens, webhooks, backups,
175ACME TLS, systemd deployment.