Commit 6821a6f760
Verified · cmc ci/build: success ci/test: success ci/vuln: success
Layout: unified · split
CHANGELOG.org +52
| @@ -4,6 +4,58 @@ Versioning follows semver from v0.1.0. Database migrations run | |||
| 4 | automatically on daemon start; upgrade notes appear per release when | 4 | automatically on daemon start; upgrade notes appear per release when |
| 5 | anything beyond "replace the binary and restart" is needed. | 5 | anything beyond "replace the binary and restart" is needed. |
| 6 | 6 | ||
| 7 | * v1.9.0 — 2026-09-03 | ||
| 8 | |||
| 9 | The runner is no longer an admin, the web no longer reaches around the | ||
| 10 | registry, and the CLI stops paying a handshake per command. | ||
| 11 | |||
| 12 | - =keys add --scope runner= confines a key to =runner next/log/done= and | ||
| 13 | read-only git; the runner commands accept that scope or an admin. The | ||
| 14 | systemd drop-in sandboxes the runner process. gitbay.org's runner now | ||
| 15 | polls as a non-admin =ci= account scoped to one repository. #92 | ||
| 16 | - The web's repo create, issue create and edit, MR edit and both comment | ||
| 17 | forms dispatch the command the CLI runs, so the repository quota, the | ||
| 18 | archived-repository refusal, notifications, the body format and the | ||
| 19 | audit entry hold from a browser. #93 | ||
| 20 | - The CLI shares one SSH connection per instance (=ControlMaster=, five | ||
| 21 | minutes idle): a command costs a round trip instead of a handshake, | ||
| 22 | 0.4 s instead of 4 s from a distant laptop. =no_multiplex = true= on | ||
| 23 | an instance opts out. #94 | ||
| 24 | - A disabled account is refused on every surface, and disabling revokes | ||
| 25 | its API tokens along with its sessions. #95 | ||
| 26 | - CODEOWNERS gates whenever the file exists on the target branch, not | ||
| 27 | only under =require-approvals=. #99 | ||
| 28 | - The HTTP listeners have header and idle timeouts, and SIGTERM drains | ||
| 29 | in-flight requests and SSH sessions before exit. #104 #105 | ||
| 30 | - =git archive= runs under a two-minute deadline and a 512 MiB cap. #124 | ||
| 31 | - Every git invocation ends option parsing before the ref, so a ref | ||
| 32 | shaped like an option is a bad revision and never a flag. #135 | ||
| 33 | - The admin noun is gated in the dispatcher as well as in each handler; | ||
| 34 | registry tests cover that and =ReadsStdin=. #127 | ||
| 35 | - An e2e test runs every =ReadOnly= command against a populated instance | ||
| 36 | and fails on any row it changes. #97 | ||
| 37 | - =http.trusted_proxies= attributes proxied API requests to the last | ||
| 38 | untrusted =X-Forwarded-For= hop for rate limiting; =email add= is | ||
| 39 | capped at five codes an hour per account. #136 | ||
| 40 | - A merge request head is built in the target repository, at | ||
| 41 | =refs/merge-requests/<n>/head=, so a fork's merge request has | ||
| 42 | =ci/<job>= statuses for =require-checks= to gate on. A head from | ||
| 43 | another repository is built without the target's secrets. #98 | ||
| 44 | - Triggers refuse deleting a user or organization that still owns | ||
| 45 | repositories, whatever path the delete takes. #136 | ||
| 46 | - The stylesheet's fonts are served again, and directory crumbs on blob | ||
| 47 | and blame pages link to the tree. #102 #103 | ||
| 48 | - The Threat-Model wiki page covers the runner. #138 | ||
| 49 | |||
| 50 | Replace the binary and restart, reinstall the CLI, and =make | ||
| 51 | deploy-runner=: the runner fetches merge request refs before checkout. | ||
| 52 | Migrations 0032 and 0033 run on start. The daemon host needs git 2.24 | ||
| 53 | or newer for =--end-of-options=. | ||
| 54 | Operators running =gitbay-runner=: give it a non-admin account with a | ||
| 55 | key added by =keys add --scope runner=, remove the admin key it held, | ||
| 56 | and =make deploy-runner= to install the sandboxed unit drop-in; an | ||
| 57 | admin key keeps working meanwhile. | ||
| 58 | |||
| 7 | * v1.8.1 — 2026-09-03 | 59 | * v1.8.1 — 2026-09-03 |
| 8 | 60 | ||
| 9 | Markdown and org files render when opened. | 61 | Markdown and org files render when opened. |