CHANGELOG.org

v1.0.1
gitbay/CHANGELOG.org rendered · source · history · blame · raw

227 lines · 11795 bytes

gitbay changelog

Versioning follows semver from v0.1.0. Database migrations run automatically on daemon start; upgrade notes appear per release when anything beyond "replace the binary and restart" is needed.

v1.0.1 — 2026-08-30

Two CI fixes found by running orgo's release pipeline on this instance.

  • A runner killed between claiming a build and reporting it left the build running forever, and the commit's ci/<job> status pending with it. runner next now fails builds past a 90-minute deadline — longer than the runner's own -timeout — and resolves their commit status. #53
  • gitbay keys add and gitbay repo deploy-key add take stdin as a bare < key.pub, but only forwarded it when --file - appeared in the arguments, so both sent an empty body and rejected input the SSH API accepts. #55

Replace the binary and restart.

v1.0.0 — 2026-08-26

The web finishes the job #35 set it: reading, reviewing and responding, with the CLI still the complete interface. Every capability exists over SSH, every web write dispatches the same control command, and anything whose input is a credential stays on the command line. The Parity page in the wiki is the maintained matrix and says which rows are deliberately CLI-only.

  • Diff view: one foldable section per file with line-number gutters, per-file stats, rename and binary handling, and syntax highlighting run per hunk per side so multi-line constructs lex as real code. Commit and merge request pages share it; review threads anchor inline.
  • Repository facts on the code page: commit, branch and tag counts, detected license, latest release, build status, a language census by tracked bytes, and contributors resolved to accounts by verified email. All derived from git at render time.
  • Account settings on the web: SSH keys with scope, OpenPGP keys, and email addresses. Public keys are the only credential-shaped input the web accepts — they are not secret, and a new user needs one registered before the CLI is reachable to them. Token minting and account export stay SSH-only.
  • Organizations are run from their page: membership and roles, teams, team members, and team repository grants, for org admins.
  • Commit log shows each commit's combined check status and gains a path filter, so per-file history is reachable without editing the URL.
  • Issue references from commit messages read "referenced in commit <sha> by <author>", linking the author when their email is verified here.
  • The rail's focus ring uses the shell's own mark: the light scheme's accent was a dark blue ring on a black rail.

No migrations. No new config.

Upgrading from v0.5.0 is replace-the-binary-and-restart.

v0.5.0 — 2026-08-26

A design pass and a parity pass. The web stops being a read-only mirror of the CLI without becoming the place you are expected to work.

  • New design: a black shell with a persistent left rail carrying cross-repo state (pinned repos, review queue), the repo header rendered identically on every tab so navigation never moves, sharp lines, self-hosted IBM Plex, and code blocks that read against both color schemes. Tree listings sort directories first and carry each file's last commit; diffs, inputs and controls were reworked to match.
  • Web parity with the CLI, dispatched through the same command registry the CLI and JSON API use — every web write is the equivalent gitbay command with --source web:

    • merge requests: review, resolve threads, merge, close, and open a new MR from the browser
    • issues: state, labels, assignees, milestones
    • repositories: settings, branch protection, visibility
    • releases: create and edit; builds: trigger a job

    Commands marked SSH-only still refuse over the web: build secrets, mirror tokens, domain claims, token minting, deletion and transfer.

  • A dashboard that answers "what needs me": review queue, assigned issues, pinned repos, and an activity feed. Author names resolve to accounts and link to profiles wherever commits appear.
  • Build status badges at /{owner}/{repo}/badge/build.svg for public repos.
  • [web] title sets the instance's display name, separate from the hostname commands are pasted with.
  • make build/test/deploy targets.
  • Fixes: the mobile tab strip scrolls sideways only, long commit subjects no longer overflow on narrow screens, the shell fills the viewport with the line-length cap moved onto prose, and the account cell lines up with the page footer.

No migrations. New config: [web] title.

v0.4.0 — 2026-08-25

  • Git LFS: standard clients work over both transports. git-lfs-authenticate joins the SSH dispatcher (deploy keys included; download needs read, upload write), minting stateless repo- and operation-scoped tokens for the batch API and basic transfers. Anonymous HTTPS downloads for public repos; uploads verified against size and sha256 before landing. Storage is content-addressed under [lfs] root behind a small interface an S3-compatible backend can drop into; [lfs] max_object_bytes caps objects (512MB default).
  • Build failures mail the repo's notify targets with the log tail and build link — failed scheduled jobs reach an inbox.
  • release edit updates a release's title and notes (absent flags keep their field); omaha-style CI note rebuilds work again.
  • Syntax highlighting follows the color scheme: class-based chroma with light and dark palettes, the light-pinned code background is gone, and markdown fences and org src blocks highlight too. The UGC sanitizer admits only chroma's token-code classes.

No migrations. New config: [lfs] root, [lfs] max_object_bytes.

v0.3.0 — 2026-08-25

  • CI: .gitbay/ci.yml jobs run as builds claimed by gitbay-runner over SSH (admin-only runner protocol; statuses feed require-checks). Per-repo secrets set over stdin and injected into build environments; cron schedules (server-local time) and tag-glob triggers, mutually exclusive per job; build list/show/log/trigger and a builds tab.
  • Pages: public repos' pages branches served on <owner>.<domain> ([pages] domain), custom domains with DNS TXT ownership challenges and 7-day expiry for pending claims, per-subdomain on-demand ACME.
  • Wikis (.wiki companion repos, access mirrors the parent) and teams within orgs (members-role scoping, per-repo team grants).
  • Activity graphs on user and org pages, backfillable (admin backfill-activity); commits attributed by verified author email, deduped by sha.
  • MR pages list the commits the MR carries; mr show gains a commits section.
  • Per-file history: ?path= on the web log, --path on repo log, history link on blob pages.
  • Mirror status surfaced in repo show and the repo header (admin-only), with sync errors visible; tag-only pushes now schedule mirror syncs.
  • Rendering: GFM tables/strikethrough/autolinks/task lists, blob image previews, raw serves images with real content types (README images render under nosniff), 0BSD license recognition, repo website links, compact dashboard pins.
  • admin user delete for accounts that anchor nothing, with named blockers otherwise.
  • Fixes: wiki pages no longer overflow on mobile (iOS font-inflation trigger), GHSA-free deps, secret values pipe correctly through the CLI.

Migrations 0020-0025 apply on start. New config: [pages] domain. The runner is a new binary (gitbay-runner); see the wiki's Admin guide for setup. Stress-tested against an import of git.git (82k commits): see the wiki's Performance page.

v0.2.0 — 2026-08-24

  • Deploy keys: repo-bound CI keys (repo deploy-key), ro/rw, rename- and transfer-proof.
  • Commit statuses (status set/list), combined state on MR pages, and a require-checks merge gate.
  • Email notifications for issue and MR activity (participants with verified addresses; never the actor).
  • Inline review threads on MR diffs (mr diff-comment/threads/resolve), stale on force-push, require-resolved merge gate.
  • Required approvals with CODEOWNERS (require-approvals; latest review wins, author excluded) and a require-resolved gate; merge gate order is checks → approvals → CODEOWNERS → resolved threads → signatures.
  • Web design revamp: token-based stylesheet (light+dark), wordmark and favicon, aligned layout grid, card-based listings, designed 404, mobile pass.
  • Cross-references and mentions: #N, !N, owner/name#N, @user autolink in issue/MR text, viewer-aware for private repos.
  • Archived repositories (read-only with badge) and repo topics.
  • Blame view with signature-aware attribution and 1000-line pages.
  • Repository search (name/description/topic) and per-repo code search (repo grep, web search tab); blob line anchors.
  • Homepage: dashboard for logged-in users (pinned repos via repo pin, open MRs and issues involving you), landing page for visitors, full public listing at /explore; MR diffs collapsed by default.
  • Milestones (milestone create/list/close, issue/mr milestone) with web progress; issue templates from .gitbay/issue-template*.md (CLI $EDITOR prefill and web form).
  • Issue actions from commit messages landing on the default branch: closes/fixes/resolves #N closes, bare #N leaves a reference comment; once per issue+commit.
  • Vanity Go imports: [go_import] config serves go-import meta tags, so go install gitbay.org/gitbay/cmd/...@latest works.
  • Release script: deploy/release.sh <tag> builds reproducible linux/amd64, linux/arm64, and darwin/arm64 binaries with SHA256SUMS.
  • Repository maintenance: admin gc (repack/prune, per-repo sizes), admin stats (counts + disk usage), weekly gitbay-gc.timer.
  • Releases: tag-anchored notes and binary assets (release commands, assets over SSH stdin/stdout, web releases tab with downloads).
  • GitHub history import: repo import-issues brings issues and PRs (as merged/closed MRs) with comments, labels, and state, attributed inline and resumable.
  • Push and pull mirroring (repo mirror): background sync, read-only pull mirrors, per-mirror status; credentials server-side, SSRF-guarded.
  • Web signup at /register for open and invite instances.
  • Audit log (audit, gitbayd admin audit): every mutating command with source key fingerprint, registrations, force-pushes, auth failures. Hardening: per-IP auth-failure throttling (ssh_auth_rate), max_pack_bytes enforced, admin user disable/enable.
  • Account migration: gitbay migrate --from <host> (bundle export/replay + client-side git mirror); gitbay auth export as a user-level backup.
  • Editable issues and MRs (issue edit, mr edit, web forms).
  • Commit references appear as system messages with linked shas.
  • Design: top nav, repo listing rows (topics, license, last updated), file table headers, README relative-link resolution, branch dropdown, web pinning, org owner picker, label filters, linked usernames and commit parents, /privacy page, blue accent.

Upgrade notes: migrations 0006–0019 apply on start. No config changes required; [go_import], [mirrors], web.privacy_notice, and web.mode = "accounts" are opt-in.

v0.1.0 — 2026-08-24

First tagged release: the complete CLI-first forge. SSH control plane (bare-OpenSSH usable), git over SSH/HTTPS/git-daemon, repos, issues, merge requests (ff/merge/squash/rebase with signature policy), OpenPGP and SSHSIG verification with retroactive re-verification, orgs, repo import, web UI (view-only or accounts mode), registration with invites and SMTP, HTTPS/JSON API with SSH-minted tokens, webhooks, backups, ACME TLS, systemd deployment.