Commit 2727fd25d8

2727fd25d891ea2c691787c8df9498a31269adab

parent: 47b439b55a

Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success

cmc <hello@cleberg.net> · 2026-09-04 20:09 UTC

CHANGELOG: v1.13.1

Layout: unified · split

CHANGELOG.org +25
@@ -4,6 +4,31 @@ Versioning follows semver from v0.1.0. Database migrations run
44automatically on daemon start; upgrade notes appear per release when
55anything beyond "replace the binary and restart" is needed.
66
7* v1.13.1 — 2026-09-04
8
9A command that reads its payload from stdin says so, and SonarCloud runs
10alongside the vulnerability scan.
11
12- =repo secret set= blocked with nothing printed, which is
13 indistinguishable from a hung connection, and pressing Enter did not
14 end it because the server reads to EOF — so it looked the same before
15 and after the value had been typed, and the secret echoed into the
16 scrollback on the way. A terminal is now told what is wanted and that
17 Ctrl-D ends it; a secret is read without echo and takes one line, so
18 Enter is enough. Piped input is unchanged, byte for byte: =printf %s
19 "$TOKEN" | gitbay repo secret set ...= still sends exactly the token.
20 Applies to =keys add=, =auth pgp add=, =repo deploy-key add= and
21 =release asset add= as well; public keys keep echoing, since they are
22 public. #150
23- A =sonar= CI job reports to SonarCloud, alongside =vuln=. Report-only:
24 it does not gate a build, unlike the vulnerability scan. A merge
25 request from a fork builds without secrets by design, so the job says
26 why it is skipping there rather than failing on a missing credential.
27 Only =SONAR_TOKEN= is secret and it is a build secret; the
28 organization, project key and host are checked in. Ref #149
29
30Replace the binary and reinstall the CLI. No migration.
31
732* v1.13.0 — 2026-09-04
833
934Collaboration. A review is composed and submitted as one thing, a merge