Commit c0efa6334a
Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success
Layout: unified · split
CHANGELOG.org +132
| @@ -4,6 +4,138 @@ Versioning follows semver from v0.1.0. Database migrations run | ||
| 4 | 4 | automatically on daemon start; upgrade notes appear per release when |
| 5 | 5 | anything beyond "replace the binary and restart" is needed. |
| 6 | 6 | |
| 7 | * v1.14.0 — 2026-09-06 | |
| 8 | ||
| 9 | Logging into the web without an SSH key, wikis inside the repository, | |
| 10 | CI that skips what a change does not touch, and the browser catching up | |
| 11 | with the command line on nine capabilities. | |
| 12 | ||
| 13 | ** Accounts and the web | |
| 14 | ||
| 15 | - A browser session can be requested by mail: the login page takes a | |
| 16 | username or a verified address and sends a link that works once and | |
| 17 | expires in fifteen minutes. An account with no SSH key had no way into | |
| 18 | the web at all. The response never says whether the account exists, and | |
| 19 | the form appears only when the instance has SMTP. #155 | |
| 20 | - A login link resolves to any verified address on the account, not only | |
| 21 | the primary. #158 | |
| 22 | - Login mail is queued rather than sent from a goroutine, so a link in | |
| 23 | flight survives a restart. #159 | |
| 24 | - A suspended account cannot mail itself a session, and a link minted | |
| 25 | before suspension opens nothing. #156 | |
| 26 | - The session cookie is =SameSite=Lax=, and a test now walks every | |
| 27 | mutating route to assert it carries the origin check. #157 | |
| 28 | - =POST /register= is reachable on an open instance again. | |
| 29 | ||
| 30 | ** Wikis | |
| 31 | ||
| 32 | - A wiki lives at =.gitbay/wiki/= on the default branch, so editing one | |
| 33 | is editing a file in the repository — a push, or the web editor — and | |
| 34 | it is cloned, diffed and reviewed like anything else. The companion | |
| 35 | =<repo>.wiki= is gone. #170 | |
| 36 | ||
| 37 | ** CI | |
| 38 | ||
| 39 | - Path filters: =paths= and =paths-ignore= per job, so a docs commit | |
| 40 | does not run the whole suite. #169 | |
| 41 | - A branch's first push derives its diff base from the merge base | |
| 42 | rather than treating every file as changed. #171 | |
| 43 | - A job filtered out records a skipped status instead of nothing, so | |
| 44 | =require_checks= cannot wait forever for a check that will never | |
| 45 | arrive. #172 | |
| 46 | - A force-push no longer leaves queued builds pointing at an object | |
| 47 | that is gone; the orphan is cancelled when a runner claims it. #152 | |
| 48 | - A build step's environment is constructed rather than inherited. It | |
| 49 | was =os.Environ()= plus the build's variables, which handed repository | |
| 50 | content everything set on the runner service. A step now gets =PATH=, | |
| 51 | =HOME=, =LANG=, =CI=, its =GITBAY_*= variables and its secrets. =HOME= | |
| 52 | is the workspace, so a build cannot read the runner's =.netrc=, | |
| 53 | =.npmrc= or =.gitconfig=, where tools keep credentials. Ref #144 | |
| 54 | - A runner host can be prepared for rootless podman: | |
| 55 | =deploy/runner-podman-setup.sh=, the systemd changes it needs, and | |
| 56 | weekly image pruning. Nothing reads them yet; the preparation ships | |
| 57 | before the runner that requires it, on purpose. Ref #144 | |
| 58 | ||
| 59 | ** Collaboration | |
| 60 | ||
| 61 | - =mr review request --add <user>= asks a particular person for a | |
| 62 | review, who then carries it in their queue and is notified; | |
| 63 | =--remove= withdraws the ask. The queue was computed from involvement | |
| 64 | alone, so a collaborator who had not touched a thread heard nothing. | |
| 65 | #145 | |
| 66 | - Bookmarks save someone else's repository to come back to, and the | |
| 67 | count is the instance's only popularity signal. Separate from pins | |
| 68 | rather than a flag on them: a pin is private quick access to your own | |
| 69 | work and drives the rail, a bookmark is public and counted. =repo | |
| 70 | bookmark=, =repo unbookmark=, =repo bookmarks=, a control on the | |
| 71 | repository header, the count in the facts bar, and =/bookmarks=. Read | |
| 72 | access is all a bookmark needs, and one made while a repository was | |
| 73 | public drops out of the listing if it goes private. #146 | |
| 74 | ||
| 75 | ** The browser catches up | |
| 76 | ||
| 77 | Nine capabilities that were CLI-only and had no reason to be: | |
| 78 | ||
| 79 | - label management — list, create, colour, remove #163 | |
| 80 | - dependency status under the toggle that turns checks on #164 | |
| 81 | - release delete #165 | |
| 82 | - the account export bundle, as a download #166 | |
| 83 | - organization create and rename; delete stays CLI-only, wanting a | |
| 84 | typed confirmation, and the page says so #167 | |
| 85 | - opening a merge request from a fork, with a source picker offering | |
| 86 | the branches of every fork you can push to #168 | |
| 87 | - forking a repository #174 | |
| 88 | - cancelling a queued or running build #162 | |
| 89 | - the profile form #161, and a markup picker on issue and merge | |
| 90 | request create #160 | |
| 91 | - admin table headers align with their columns #151 | |
| 92 | ||
| 93 | ** CLI | |
| 94 | ||
| 95 | - =gitbay mr rebase <n>= replays a merge request's branch onto its | |
| 96 | target and re-pushes it. A repository requiring signed commits accepts | |
| 97 | only fast-forward merges, so a merge request whose target moved had to | |
| 98 | be rebased by hand; the refusal already named the procedure and this | |
| 99 | runs it. The git work is local, so the replayed commits carry your | |
| 100 | signature — the server still holds no key. A branch in a fork is | |
| 101 | refused, naming the repository to run it in. #175 | |
| 102 | ||
| 103 | ** Security | |
| 104 | ||
| 105 | - Mutating commands are bounded per account in the dispatcher, so SSH, | |
| 106 | the JSON API and the web spend one budget and a caller cannot refresh | |
| 107 | it by changing surface. Authentication failures were throttled; | |
| 108 | commands were not. #148 | |
| 109 | - A dead-lettered mail is logged by its queue row id, not the recipient | |
| 110 | address, and the relay's error is redacted before logging because a | |
| 111 | rejection quotes the address it rejected. The address stays on the | |
| 112 | row, where =/admin= shows it. One rule for every mail type. #173 | |
| 113 | - The 2026-09 sweep's coverage — and what it did not reach — is recorded | |
| 114 | in the wiki's Threat-Model rather than in a closed issue. #149 | |
| 115 | ||
| 116 | ** Dependencies | |
| 117 | ||
| 118 | - goldmark 1.8.6, sqlite 1.58.0. #140 | |
| 119 | ||
| 120 | ** Upgrading | |
| 121 | ||
| 122 | Replace the binary and reinstall the CLI. One migration (0043, | |
| 123 | bookmarks), applied on start. | |
| 124 | ||
| 125 | =limits.write_rate= defaults to 60 mutating commands a minute per | |
| 126 | account. A script that writes faster will be refused with exit 4 and a | |
| 127 | retry time; raise it in =[limits]=, or slow the script. Read-only | |
| 128 | commands, the runner protocol and the host CLI are not counted. | |
| 129 | ||
| 130 | A companion =<repo>.wiki= repository is no longer read. Move its pages | |
| 131 | to =.gitbay/wiki/= on the default branch. | |
| 132 | ||
| 133 | Runner isolation is half done. Builds still run as the runner's user | |
| 134 | with no container: the step environment no longer leaks the service's, | |
| 135 | and a host can be prepared for podman, but nothing yet executes a build | |
| 136 | in one. Do not enable CI for repositories you do not trust. #144 stays | |
| 137 | open for the execution half. | |
| 138 | ||
| 7 | 139 | * v1.13.3 — 2026-09-05 |
| 8 | 140 | |
| 9 | 141 | Only a writer's review decides a merge gate, and a scan of one branch |