Commit fad7a633f4

fad7a633f45132422f6648c1c7508b4e19b6539c

parent: fc755889ba

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-29 02:26 UTC

changelog: one #297 entry, upgrade notes after the list, #298 note corrected

Ref #284
Ref #297
Ref #298

Layout: unified · split

CHANGELOG.org +13 −12
@@ -9,8 +9,9 @@ anything beyond "replace the binary and restart" is needed.
9- =webhook add= reads the signing secret from stdin with =--secret -=; 9- =webhook add= reads the signing secret from stdin with =--secret -=;
10 a value on the command line is refused, since argv shows in process 10 a value on the command line is refused, since argv shows in process
11 listings and shell history. A script that passed the value must pipe 11 listings and shell history. A script that passed the value must pipe
12 it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -= 12 it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -=.
13 (#284). 13 The iOS app's webhook add breaks until it sends the secret on stdin
14 (krz/gitbay-ios#21) (#284).
14- =repo import --from= takes http and https URLs only; =git://= is 15- =repo import --from= takes http and https URLs only; =git://= is
15 refused, since its connection cannot be held to a checked address. 16 refused, since its connection cannot be held to a checked address.
16 The host is resolved and checked like a mirror's, git connects only 17 The host is resolved and checked like a mirror's, git connects only
@@ -18,15 +19,6 @@ anything beyond "replace the binary and restart" is needed.
18 global gitconfig are ignored. A source that redirects (a renamed 19 global gitconfig are ignored. A source that redirects (a renamed
19 repository) fails; import from the URL it redirects to. Needs git 20 repository) fails; import from the URL it redirects to. Needs git
20 2.37 or later on the server (#298). 21 2.37 or later on the server (#298).
21*Upgrade note.* =repo import= and mirror sync now refuse a =git://=
22source and a =--from=/remote URL carrying a query or fragment. A
23mirror or import whose host is written numerically (=127.1=,
24=2130706433=, =0x7f.1=) rather than as a dotted address is refused
25too; rewrite it before upgrading.
26- A web session older than 15 minutes cannot mint a credential or grant
27 access — keys, PGP keys, tokens, org membership, and the admin
28 promote/enable actions — and the form it tried shows a sign-in link
29 that returns there (#297).
30- A browser session creates credentials and grants access — keys, PGP 22- A browser session creates credentials and grants access — keys, PGP
31 keys, tokens, verified addresses, org and repository roles, transfers, 23 keys, tokens, verified addresses, org and repository roles, transfers,
32 webhooks, secrets, mirrors, and the admin promote/enable actions — 24 webhooks, secrets, mirrors, and the admin promote/enable actions —
@@ -95,6 +87,12 @@ entries; if extracting one leaves a repository's =refs/= directory
95missing, =gitbayd admin backup --verify <archive>= names it, and 87missing, =gitbayd admin backup --verify <archive>= names it, and
96=mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it. 88=mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it.
97 89
90*Upgrade note.* =repo import= now refuses a =git://= source and a
91=--from= URL carrying a query or fragment. Mirrors and imports whose
92host is written numerically (=127.1=, =2130706433=, =0x7f.1=) rather
93than as a dotted address are refused too; rewrite the URL before
94upgrading (#298).
95
98- A token with a =--ttl= is refused on every command that creates a 96- A token with a =--ttl= is refused on every command that creates a
99 credential: tokens, keys, deploy keys, runner keys, login links, 97 credential: tokens, keys, deploy keys, runner keys, login links,
100 invites, accounts and verified addresses (#257). 98 invites, accounts and verified addresses (#257).
@@ -294,7 +292,10 @@ missing, =gitbayd admin backup --verify <archive>= names it, and
294 hour (#285). *Operators:* tokens minted before the upgrade are 292 hour (#285). *Operators:* tokens minted before the upgrade are
295 refused. git-lfs asks =git-lfs-authenticate= for a token each time 293 refused. git-lfs asks =git-lfs-authenticate= for a token each time
296 it runs, so only a transfer running across the restart fails, with 294 it runs, so only a transfer running across the restart fails, with
297 "repository not found"; running the command again fixes it. 295 "repository not found"; running the command again fixes it. A
296 download from a public repository that presents a token issued
297 before the upgrade is refused the same way, not served anonymously,
298 and needs the same rerun.
298- Every LFS request also repeats the repository check for the token's 299- Every LFS request also repeats the repository check for the token's
299 key: a collaborator whose access is revoked or reduced, or a reader 300 key: a collaborator whose access is revoked or reduced, or a reader
300 of a public repository made private, loses the token's use with the 301 of a public repository made private, loses the token's use with the