krz/gitbay
milestones · labels
CI runs four jobs per push when two would do, and re-runs everything on a rebase
#177 opened by cmc · in v1.15.0
Path filters skip a rebased branch's code jobs, so unverified code looks green
#176 opened by cmc · in v1.15.0
No mr rebase: fast-forward-only repos rebase by hand
#175 opened by cmc
Web: a repository cannot be forked
#174 opened by cmc · in web-parity
Dead-lettered mail logs the recipient address
#173 opened by cmc · in security
Path filters plus require_checks can make a docs-only MR unmergeable
#172 opened by cmc · in v1.14.0
Path filters never apply to the first push of a branch
#171 opened by cmc · in v1.14.0
A wiki should live in the repository, not a companion repo
#170 opened by cmc · in v1.14.0
CI has no path filters, so a docs commit runs the whole suite
#169 opened by cmc · in v1.14.0
Web: a merge request cannot be opened from a fork
#168 opened by cmc · in web-parity
Web: organizations cannot be created, renamed, or deleted
#167 opened by cmc · in web-parity
Web: no account export bundle
#166 opened by cmc · in web-parity
Web: a release cannot be deleted
#165 opened by cmc · in web-parity
Web: dependency status is not shown
#164 opened by cmc · in web-parity
Web: label management has no UI
#163 opened by cmc · in web-parity
Web: a build cannot be cancelled
#162 opened by cmc · in v1.14.0
Web: no form for profile set
#161 opened by cmc · in v1.14.0
Web: no body markup picker on issue and merge request forms
#160 opened by cmc · in v1.14.0
In-flight login mail is dropped on shutdown
#159 opened by cmc · in v1.14.0
A verified non-primary address cannot be used to request a login link
#158 opened by cmc · in v1.14.0
No test enforces that every mutating route carries checkOrigin security
#157 opened by cmc · in v1.14.0
Nothing pins the login() disabled guard, or SetUserDisabled at all security
#156 opened by cmc · in v1.14.0
No way to log into the web without an SSH key
#155 opened by cmc · in v1.14.0
Every branch's CI scan overwrites the SonarCloud project state ci
#154 opened by cmc · in v1.14.0
SonarCloud first scan: five valid findings security
#153 opened by cmc · in security
Force-pushing leaves queued builds that fail on a missing object ci
#152 opened by cmc · in v1.14.0
table header misalignment bug ux web
#151 opened by cmc
A stdin-payload command on a terminal is indistinguishable from a hang cli
#150 opened by cmc · in v1.14.0
Security sweep 2026-09: what was covered, and what was not security
#149 opened by cmc · in security
SSH control commands have no write rate limit; the JSON API has one security
#148 opened by cmc · in security
Review verdicts from accounts without write access satisfy and block merge gates security
#147 opened by cmc · in security
feature request: bookmarks
#146 opened by cmc
No way to ask a specific person for a review collaboration
#145 opened by cmc · in v1.14.0
Runner has no isolation, so a build runs as the runner's user security
#144 opened by cmc · in v1.14.0
Bare go test ./... times out before the e2e suite finishes tooling
#143 opened by cmc · in v1.13.0
CODEOWNERS gating is implied by the file, not chosen
#142 opened by cmc · in v1.11.0
Shutdown waits on idle SSH connections, and a restart locks the CLI out via the auth rate limit cli ops security
#141 opened by cmc · in v1.10.0
Dependency updates available
#140 opened by gitbay-bot
Single-user verification of every collaboration feature docs
#139 opened by cmc · in v1.13.0
Threat-Model wiki page omits the runner docs security
#138 opened by cmc · in v1.9.0
Dashboard and feed queries have no supporting indexes store
#137 opened by cmc · in v1.12.0
Rate limit keys by RemoteAddr, email add is unthrottled, repo owner has no foreign key ops security
#136 opened by cmc · in v1.9.0
Git subprocess arguments are not -- terminated security
#135 opened by cmc · in v1.9.0
Repo header repeats at full size on every page; landing page is a placeholder; mobile tab bar clips design web
#134 opened by cmc · in v1.11.0
Accessibility: pin glyph read aloud, headerless tables, colour-only filter state, double h1 design web
#133 opened by cmc · in v1.11.0
Markdown headings have no anchors; stylesheet has no cache headers web
#132 opened by cmc · in v1.11.0
Stylesheet: scale leaks, dead rules, undefined classes design web
#131 opened by cmc · in v1.11.0
CLI group help is cobra's, command help is the server's cli
#130 opened by cmc · in v1.10.0
Unit coverage of commands is thin; everything is e2e ci
#129 opened by cmc · in v1.10.0
Import yields diff-less MRs unless refs/pull/* came along migration
#128 opened by cmc · in v1.13.0
older →