CHANGELOG.org

v1.0.1
gitbay/CHANGELOG.org rendered · source · history · blame · raw

227 lines · 11795 bytes

  1#+title: gitbay changelog
  2
  3Versioning follows semver from v0.1.0. Database migrations run
  4automatically on daemon start; upgrade notes appear per release when
  5anything beyond "replace the binary and restart" is needed.
  6
  7* v1.0.1 — 2026-08-30
  8
  9Two CI fixes found by running orgo's release pipeline on this instance.
 10
 11- A runner killed between claiming a build and reporting it left the build
 12  =running= forever, and the commit's =ci/<job>= status pending with it.
 13  =runner next= now fails builds past a 90-minute deadline — longer than the
 14  runner's own =-timeout= — and resolves their commit status. #53
 15- =gitbay keys add= and =gitbay repo deploy-key add= take stdin as a bare
 16  =< key.pub=, but only forwarded it when =--file -= appeared in the
 17  arguments, so both sent an empty body and rejected input the SSH API
 18  accepts. #55
 19
 20Replace the binary and restart.
 21
 22* v1.0.0 — 2026-08-26
 23
 24The web finishes the job #35 set it: reading, reviewing and responding,
 25with the CLI still the complete interface. Every capability exists over
 26SSH, every web write dispatches the same control command, and anything
 27whose input is a credential stays on the command line. The [[https://gitbay.org/krz/gitbay/wiki/Parity][Parity]] page in
 28the wiki is the maintained matrix and says which rows are deliberately
 29CLI-only.
 30
 31- Diff view: one foldable section per file with line-number gutters,
 32  per-file stats, rename and binary handling, and syntax highlighting
 33  run per hunk per side so multi-line constructs lex as real code.
 34  Commit and merge request pages share it; review threads anchor
 35  inline.
 36- Repository facts on the code page: commit, branch and tag counts,
 37  detected license, latest release, build status, a language census by
 38  tracked bytes, and contributors resolved to accounts by verified
 39  email. All derived from git at render time.
 40- Account settings on the web: SSH keys with scope, OpenPGP keys, and
 41  email addresses. Public keys are the only credential-shaped input the
 42  web accepts — they are not secret, and a new user needs one
 43  registered before the CLI is reachable to them. Token minting and
 44  account export stay SSH-only.
 45- Organizations are run from their page: membership and roles, teams,
 46  team members, and team repository grants, for org admins.
 47- Commit log shows each commit's combined check status and gains a path
 48  filter, so per-file history is reachable without editing the URL.
 49- Issue references from commit messages read "referenced in commit
 50  <sha> by <author>", linking the author when their email is verified
 51  here.
 52- The rail's focus ring uses the shell's own mark: the light scheme's
 53  accent was a dark blue ring on a black rail.
 54
 55No migrations. No new config.
 56
 57Upgrading from v0.5.0 is replace-the-binary-and-restart.
 58
 59* v0.5.0 — 2026-08-26
 60
 61A design pass and a parity pass. The web stops being a read-only
 62mirror of the CLI without becoming the place you are expected to work.
 63
 64- New design: a black shell with a persistent left rail carrying
 65  cross-repo state (pinned repos, review queue), the repo header
 66  rendered identically on every tab so navigation never moves, sharp
 67  lines, self-hosted IBM Plex, and code blocks that read against both
 68  color schemes. Tree listings sort directories first and carry each
 69  file's last commit; diffs, inputs and controls were reworked to
 70  match.
 71- Web parity with the CLI, dispatched through the same command
 72  registry the CLI and JSON API use — every web write is the
 73  equivalent =gitbay= command with =--source web=:
 74  - merge requests: review, resolve threads, merge, close, and open a
 75    new MR from the browser
 76  - issues: state, labels, assignees, milestones
 77  - repositories: settings, branch protection, visibility
 78  - releases: create and edit; builds: trigger a job
 79  Commands marked SSH-only still refuse over the web: build secrets,
 80  mirror tokens, domain claims, token minting, deletion and transfer.
 81- A dashboard that answers "what needs me": review queue, assigned
 82  issues, pinned repos, and an activity feed. Author names resolve to
 83  accounts and link to profiles wherever commits appear.
 84- Build status badges at =/{owner}/{repo}/badge/build.svg= for public
 85  repos.
 86- =[web] title= sets the instance's display name, separate from the
 87  hostname commands are pasted with.
 88- =make build/test/deploy= targets.
 89- Fixes: the mobile tab strip scrolls sideways only, long commit
 90  subjects no longer overflow on narrow screens, the shell fills the
 91  viewport with the line-length cap moved onto prose, and the account
 92  cell lines up with the page footer.
 93
 94No migrations. New config: =[web] title=.
 95
 96* v0.4.0 — 2026-08-25
 97
 98- Git LFS: standard clients work over both transports.
 99  =git-lfs-authenticate= joins the SSH dispatcher (deploy keys
100  included; download needs read, upload write), minting stateless
101  repo- and operation-scoped tokens for the batch API and basic
102  transfers. Anonymous HTTPS downloads for public repos; uploads
103  verified against size and sha256 before landing. Storage is
104  content-addressed under =[lfs] root= behind a small interface an
105  S3-compatible backend can drop into; =[lfs] max_object_bytes= caps
106  objects (512MB default).
107- Build failures mail the repo's notify targets with the log tail and
108  build link — failed scheduled jobs reach an inbox.
109- =release edit= updates a release's title and notes (absent flags
110  keep their field); omaha-style CI note rebuilds work again.
111- Syntax highlighting follows the color scheme: class-based chroma
112  with light and dark palettes, the light-pinned code background is
113  gone, and markdown fences and org src blocks highlight too. The UGC
114  sanitizer admits only chroma's token-code classes.
115
116No migrations. New config: =[lfs] root=, =[lfs] max_object_bytes=.
117
118* v0.3.0 — 2026-08-25
119
120- CI: =.gitbay/ci.yml= jobs run as builds claimed by =gitbay-runner=
121  over SSH (admin-only runner protocol; statuses feed =require-checks=).
122  Per-repo secrets set over stdin and injected into build environments;
123  cron schedules (server-local time) and tag-glob triggers, mutually
124  exclusive per job; =build list/show/log/trigger= and a builds tab.
125- Pages: public repos' =pages= branches served on =<owner>.<domain>=
126  (=[pages] domain=), custom domains with DNS TXT ownership challenges
127  and 7-day expiry for pending claims, per-subdomain on-demand ACME.
128- Wikis (=.wiki= companion repos, access mirrors the parent) and teams
129  within orgs (members-role scoping, per-repo team grants).
130- Activity graphs on user and org pages, backfillable
131  (=admin backfill-activity=); commits attributed by verified author
132  email, deduped by sha.
133- MR pages list the commits the MR carries; =mr show= gains a commits
134  section.
135- Per-file history: =?path== on the web log, =--path= on =repo log=,
136  history link on blob pages.
137- Mirror status surfaced in =repo show= and the repo header
138  (admin-only), with sync errors visible; tag-only pushes now schedule
139  mirror syncs.
140- Rendering: GFM tables/strikethrough/autolinks/task lists, blob image
141  previews, raw serves images with real content types (README images
142  render under nosniff), 0BSD license recognition, repo website links,
143  compact dashboard pins.
144- =admin user delete= for accounts that anchor nothing, with named
145  blockers otherwise.
146- Fixes: wiki pages no longer overflow on mobile (iOS font-inflation
147  trigger), GHSA-free deps, secret values pipe correctly through the
148  CLI.
149
150Migrations 0020-0025 apply on start. New config: =[pages] domain=.
151The runner is a new binary (=gitbay-runner=); see the wiki's Admin
152guide for setup. Stress-tested against an import of git.git (82k
153commits): see the wiki's Performance page.
154
155* v0.2.0 — 2026-08-24
156
157- Deploy keys: repo-bound CI keys (=repo deploy-key=), ro/rw, rename- and
158  transfer-proof.
159- Commit statuses (=status set/list=), combined state on MR pages, and a
160  =require-checks= merge gate.
161- Email notifications for issue and MR activity (participants with
162  verified addresses; never the actor).
163- Inline review threads on MR diffs (=mr diff-comment/threads/resolve=),
164  stale on force-push, =require-resolved= merge gate.
165- Required approvals with CODEOWNERS (=require-approvals=; latest review
166  wins, author excluded) and a =require-resolved= gate; merge gate order
167  is checks → approvals → CODEOWNERS → resolved threads → signatures.
168- Web design revamp: token-based stylesheet (light+dark), wordmark and
169  favicon, aligned layout grid, card-based listings, designed 404,
170  mobile pass.
171- Cross-references and mentions: =#N=, =!N=, =owner/name#N=, =@user=
172  autolink in issue/MR text, viewer-aware for private repos.
173- Archived repositories (read-only with badge) and repo topics.
174- Blame view with signature-aware attribution and 1000-line pages.
175- Repository search (name/description/topic) and per-repo code search
176  (=repo grep=, web search tab); blob line anchors.
177- Homepage: dashboard for logged-in users (pinned repos via =repo pin=,
178  open MRs and issues involving you), landing page for visitors, full
179  public listing at =/explore=; MR diffs collapsed by default.
180- Milestones (=milestone create/list/close=, =issue/mr milestone=) with
181  web progress; issue templates from =.gitbay/issue-template*.md=
182  (CLI =$EDITOR= prefill and web form).
183- Issue actions from commit messages landing on the default branch:
184  =closes/fixes/resolves #N= closes, bare =#N= leaves a reference
185  comment; once per issue+commit.
186- Vanity Go imports: =[go_import]= config serves go-import meta tags, so
187  =go install gitbay.org/gitbay/cmd/...@latest= works.
188- Release script: =deploy/release.sh <tag>= builds reproducible
189  linux/amd64, linux/arm64, and darwin/arm64 binaries with SHA256SUMS.
190- Repository maintenance: =admin gc= (repack/prune, per-repo sizes),
191  =admin stats= (counts + disk usage), weekly =gitbay-gc.timer=.
192- Releases: tag-anchored notes and binary assets (=release= commands,
193  assets over SSH stdin/stdout, web releases tab with downloads).
194- GitHub history import: =repo import-issues= brings issues and PRs
195  (as merged/closed MRs) with comments, labels, and state, attributed
196  inline and resumable.
197- Push and pull mirroring (=repo mirror=): background sync, read-only
198  pull mirrors, per-mirror status; credentials server-side, SSRF-guarded.
199- Web signup at =/register= for open and invite instances.
200- Audit log (=audit=, =gitbayd admin audit=): every mutating command
201  with source key fingerprint, registrations, force-pushes, auth
202  failures. Hardening: per-IP auth-failure throttling
203  (=ssh_auth_rate=), =max_pack_bytes= enforced, =admin user
204  disable/enable=.
205- Account migration: =gitbay migrate --from <host>= (bundle
206  export/replay + client-side git mirror); =gitbay auth export= as a
207  user-level backup.
208- Editable issues and MRs (=issue edit=, =mr edit=, web forms).
209- Commit references appear as system messages with linked shas.
210- Design: top nav, repo listing rows (topics, license, last updated),
211  file table headers, README relative-link resolution, branch
212  dropdown, web pinning, org owner picker, label filters, linked
213  usernames and commit parents, =/privacy= page, blue accent.
214
215Upgrade notes: migrations 0006–0019 apply on start. No config changes
216required; =[go_import]=, =[mirrors]=, =web.privacy_notice=, and
217=web.mode = "accounts"= are opt-in.
218
219* v0.1.0 — 2026-08-24
220
221First tagged release: the complete CLI-first forge. SSH control plane
222(bare-OpenSSH usable), git over SSH/HTTPS/git-daemon, repos, issues,
223merge requests (ff/merge/squash/rebase with signature policy), OpenPGP
224and SSHSIG verification with retroactive re-verification, orgs, repo
225import, web UI (view-only or accounts mode), registration with invites
226and SMTP, HTTPS/JSON API with SSH-minted tokens, webhooks, backups,
227ACME TLS, systemd deployment.