Commit c0efa6334a
Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success
Layout: unified · split
CHANGELOG.org +132
| @@ -4,6 +4,138 @@ Versioning follows semver from v0.1.0. Database migrations run | |||
| 4 | automatically on daemon start; upgrade notes appear per release when | 4 | automatically on daemon start; upgrade notes appear per release when |
| 5 | anything beyond "replace the binary and restart" is needed. | 5 | anything beyond "replace the binary and restart" is needed. |
| 6 | 6 | ||
| 7 | * v1.14.0 — 2026-09-06 | ||
| 8 | |||
| 9 | Logging into the web without an SSH key, wikis inside the repository, | ||
| 10 | CI that skips what a change does not touch, and the browser catching up | ||
| 11 | with the command line on nine capabilities. | ||
| 12 | |||
| 13 | ** Accounts and the web | ||
| 14 | |||
| 15 | - A browser session can be requested by mail: the login page takes a | ||
| 16 | username or a verified address and sends a link that works once and | ||
| 17 | expires in fifteen minutes. An account with no SSH key had no way into | ||
| 18 | the web at all. The response never says whether the account exists, and | ||
| 19 | the form appears only when the instance has SMTP. #155 | ||
| 20 | - A login link resolves to any verified address on the account, not only | ||
| 21 | the primary. #158 | ||
| 22 | - Login mail is queued rather than sent from a goroutine, so a link in | ||
| 23 | flight survives a restart. #159 | ||
| 24 | - A suspended account cannot mail itself a session, and a link minted | ||
| 25 | before suspension opens nothing. #156 | ||
| 26 | - The session cookie is =SameSite=Lax=, and a test now walks every | ||
| 27 | mutating route to assert it carries the origin check. #157 | ||
| 28 | - =POST /register= is reachable on an open instance again. | ||
| 29 | |||
| 30 | ** Wikis | ||
| 31 | |||
| 32 | - A wiki lives at =.gitbay/wiki/= on the default branch, so editing one | ||
| 33 | is editing a file in the repository — a push, or the web editor — and | ||
| 34 | it is cloned, diffed and reviewed like anything else. The companion | ||
| 35 | =<repo>.wiki= is gone. #170 | ||
| 36 | |||
| 37 | ** CI | ||
| 38 | |||
| 39 | - Path filters: =paths= and =paths-ignore= per job, so a docs commit | ||
| 40 | does not run the whole suite. #169 | ||
| 41 | - A branch's first push derives its diff base from the merge base | ||
| 42 | rather than treating every file as changed. #171 | ||
| 43 | - A job filtered out records a skipped status instead of nothing, so | ||
| 44 | =require_checks= cannot wait forever for a check that will never | ||
| 45 | arrive. #172 | ||
| 46 | - A force-push no longer leaves queued builds pointing at an object | ||
| 47 | that is gone; the orphan is cancelled when a runner claims it. #152 | ||
| 48 | - A build step's environment is constructed rather than inherited. It | ||
| 49 | was =os.Environ()= plus the build's variables, which handed repository | ||
| 50 | content everything set on the runner service. A step now gets =PATH=, | ||
| 51 | =HOME=, =LANG=, =CI=, its =GITBAY_*= variables and its secrets. =HOME= | ||
| 52 | is the workspace, so a build cannot read the runner's =.netrc=, | ||
| 53 | =.npmrc= or =.gitconfig=, where tools keep credentials. Ref #144 | ||
| 54 | - A runner host can be prepared for rootless podman: | ||
| 55 | =deploy/runner-podman-setup.sh=, the systemd changes it needs, and | ||
| 56 | weekly image pruning. Nothing reads them yet; the preparation ships | ||
| 57 | before the runner that requires it, on purpose. Ref #144 | ||
| 58 | |||
| 59 | ** Collaboration | ||
| 60 | |||
| 61 | - =mr review request --add <user>= asks a particular person for a | ||
| 62 | review, who then carries it in their queue and is notified; | ||
| 63 | =--remove= withdraws the ask. The queue was computed from involvement | ||
| 64 | alone, so a collaborator who had not touched a thread heard nothing. | ||
| 65 | #145 | ||
| 66 | - Bookmarks save someone else's repository to come back to, and the | ||
| 67 | count is the instance's only popularity signal. Separate from pins | ||
| 68 | rather than a flag on them: a pin is private quick access to your own | ||
| 69 | work and drives the rail, a bookmark is public and counted. =repo | ||
| 70 | bookmark=, =repo unbookmark=, =repo bookmarks=, a control on the | ||
| 71 | repository header, the count in the facts bar, and =/bookmarks=. Read | ||
| 72 | access is all a bookmark needs, and one made while a repository was | ||
| 73 | public drops out of the listing if it goes private. #146 | ||
| 74 | |||
| 75 | ** The browser catches up | ||
| 76 | |||
| 77 | Nine capabilities that were CLI-only and had no reason to be: | ||
| 78 | |||
| 79 | - label management — list, create, colour, remove #163 | ||
| 80 | - dependency status under the toggle that turns checks on #164 | ||
| 81 | - release delete #165 | ||
| 82 | - the account export bundle, as a download #166 | ||
| 83 | - organization create and rename; delete stays CLI-only, wanting a | ||
| 84 | typed confirmation, and the page says so #167 | ||
| 85 | - opening a merge request from a fork, with a source picker offering | ||
| 86 | the branches of every fork you can push to #168 | ||
| 87 | - forking a repository #174 | ||
| 88 | - cancelling a queued or running build #162 | ||
| 89 | - the profile form #161, and a markup picker on issue and merge | ||
| 90 | request create #160 | ||
| 91 | - admin table headers align with their columns #151 | ||
| 92 | |||
| 93 | ** CLI | ||
| 94 | |||
| 95 | - =gitbay mr rebase <n>= replays a merge request's branch onto its | ||
| 96 | target and re-pushes it. A repository requiring signed commits accepts | ||
| 97 | only fast-forward merges, so a merge request whose target moved had to | ||
| 98 | be rebased by hand; the refusal already named the procedure and this | ||
| 99 | runs it. The git work is local, so the replayed commits carry your | ||
| 100 | signature — the server still holds no key. A branch in a fork is | ||
| 101 | refused, naming the repository to run it in. #175 | ||
| 102 | |||
| 103 | ** Security | ||
| 104 | |||
| 105 | - Mutating commands are bounded per account in the dispatcher, so SSH, | ||
| 106 | the JSON API and the web spend one budget and a caller cannot refresh | ||
| 107 | it by changing surface. Authentication failures were throttled; | ||
| 108 | commands were not. #148 | ||
| 109 | - A dead-lettered mail is logged by its queue row id, not the recipient | ||
| 110 | address, and the relay's error is redacted before logging because a | ||
| 111 | rejection quotes the address it rejected. The address stays on the | ||
| 112 | row, where =/admin= shows it. One rule for every mail type. #173 | ||
| 113 | - The 2026-09 sweep's coverage — and what it did not reach — is recorded | ||
| 114 | in the wiki's Threat-Model rather than in a closed issue. #149 | ||
| 115 | |||
| 116 | ** Dependencies | ||
| 117 | |||
| 118 | - goldmark 1.8.6, sqlite 1.58.0. #140 | ||
| 119 | |||
| 120 | ** Upgrading | ||
| 121 | |||
| 122 | Replace the binary and reinstall the CLI. One migration (0043, | ||
| 123 | bookmarks), applied on start. | ||
| 124 | |||
| 125 | =limits.write_rate= defaults to 60 mutating commands a minute per | ||
| 126 | account. A script that writes faster will be refused with exit 4 and a | ||
| 127 | retry time; raise it in =[limits]=, or slow the script. Read-only | ||
| 128 | commands, the runner protocol and the host CLI are not counted. | ||
| 129 | |||
| 130 | A companion =<repo>.wiki= repository is no longer read. Move its pages | ||
| 131 | to =.gitbay/wiki/= on the default branch. | ||
| 132 | |||
| 133 | Runner isolation is half done. Builds still run as the runner's user | ||
| 134 | with no container: the step environment no longer leaks the service's, | ||
| 135 | and a host can be prepared for podman, but nothing yet executes a build | ||
| 136 | in one. Do not enable CI for repositories you do not trust. #144 stays | ||
| 137 | open for the execution half. | ||
| 138 | |||
| 7 | * v1.13.3 — 2026-09-05 | 139 | * v1.13.3 — 2026-09-05 |
| 8 | 140 | ||
| 9 | Only a writer's review decides a merge gate, and a scan of one branch | 141 | Only a writer's review decides a merge gate, and a scan of one branch |