Commit fad7a633f4

fad7a633f45132422f6648c1c7508b4e19b6539c

parent: fc755889ba

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-29 02:26 UTC

changelog: one #297 entry, upgrade notes after the list, #298 note corrected

Ref #284
Ref #297
Ref #298

Layout: unified · split

CHANGELOG.org +13 −12
@@ -9,8 +9,9 @@ anything beyond "replace the binary and restart" is needed.
99- =webhook add= reads the signing secret from stdin with =--secret -=;
1010 a value on the command line is refused, since argv shows in process
1111 listings and shell history. A script that passed the value must pipe
12 it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -=
13 (#284).
12 it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -=.
13 The iOS app's webhook add breaks until it sends the secret on stdin
14 (krz/gitbay-ios#21) (#284).
1415- =repo import --from= takes http and https URLs only; =git://= is
1516 refused, since its connection cannot be held to a checked address.
1617 The host is resolved and checked like a mirror's, git connects only
@@ -18,15 +19,6 @@ anything beyond "replace the binary and restart" is needed.
1819 global gitconfig are ignored. A source that redirects (a renamed
1920 repository) fails; import from the URL it redirects to. Needs git
2021 2.37 or later on the server (#298).
21*Upgrade note.* =repo import= and mirror sync now refuse a =git://=
22source and a =--from=/remote URL carrying a query or fragment. A
23mirror or import whose host is written numerically (=127.1=,
24=2130706433=, =0x7f.1=) rather than as a dotted address is refused
25too; rewrite it before upgrading.
26- A web session older than 15 minutes cannot mint a credential or grant
27 access — keys, PGP keys, tokens, org membership, and the admin
28 promote/enable actions — and the form it tried shows a sign-in link
29 that returns there (#297).
3022- A browser session creates credentials and grants access — keys, PGP
3123 keys, tokens, verified addresses, org and repository roles, transfers,
3224 webhooks, secrets, mirrors, and the admin promote/enable actions —
@@ -95,6 +87,12 @@ entries; if extracting one leaves a repository's =refs/= directory
9587missing, =gitbayd admin backup --verify <archive>= names it, and
9688=mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it.
9789
90*Upgrade note.* =repo import= now refuses a =git://= source and a
91=--from= URL carrying a query or fragment. Mirrors and imports whose
92host is written numerically (=127.1=, =2130706433=, =0x7f.1=) rather
93than as a dotted address are refused too; rewrite the URL before
94upgrading (#298).
95
9896- A token with a =--ttl= is refused on every command that creates a
9997 credential: tokens, keys, deploy keys, runner keys, login links,
10098 invites, accounts and verified addresses (#257).
@@ -294,7 +292,10 @@ missing, =gitbayd admin backup --verify <archive>= names it, and
294292 hour (#285). *Operators:* tokens minted before the upgrade are
295293 refused. git-lfs asks =git-lfs-authenticate= for a token each time
296294 it runs, so only a transfer running across the restart fails, with
297 "repository not found"; running the command again fixes it.
295 "repository not found"; running the command again fixes it. A
296 download from a public repository that presents a token issued
297 before the upgrade is refused the same way, not served anonymously,
298 and needs the same rerun.
298299- Every LFS request also repeats the repository check for the token's
299300 key: a collaborator whose access is revoked or reduced, or a reader
300301 of a public repository made private, loses the token's use with the