Range-diff !498

back to !498 backup: encrypt archives to age recipients

 1:  9002a0b <  -:  ------- control: move the feed-line sentence renderer from httpd, so the CLI can share it
 2:  e0ae401 <  -:  ------- feed: a labelled event names the labels
 3:  cf66fc3 <  -:  ------- dashboard, feed: render activity as the web's sentence, not the raw payload
 4:  6dae104 <  -:  ------- feedline: extract FeedLine.Sentence, dedupe runDashboard/runFeed
 5:  2737992 <  -:  ------- dashboard: an assigned issue no longer repeats under open issues
 6:  b39ffae <  -:  ------- notifications list: name --all when the empty inbox is just read items
 7:  061bd06 <  -:  ------- feedline: space between the repository and a tag, job or sha
 8:  3815908 <  -:  ------- notifications list: name --all only when read items exist
 9:  45230cb <  -:  ------- e2e: an assigned issue is not listed under open_issues
10:  d2db7d8 <  -:  ------- changelog: unreleased entry for #265
11:  a3fa0f0 <  -:  ------- usage, help: print the program and the CLI's own path for the command
12:  a8523b1 <  -:  ------- cli: send --path= where the CLI path differs from the server path
13:  a1e67e4 <  -:  ------- e2e: usage prints the CLI's own path, stock ssh the registered one
14:  d905c69 <  -:  ------- flags: print a bad-flag usage line the way a usage refusal does
15:  44191b1 <  -:  ------- auth keys add, pgp add: check --help before reading stdin
16:  4eb0f95 <  -:  ------- help: auth (and any future CLI-only grouping) renders with the registry layout, in the CLI's own paths
17:  7664da8 <  -:  ------- auth --help: force --path= for a bare CLI-only alias group
18:  d5968a8 <  -:  ------- summaries: verb phrases instead of bare nouns
19:  004ff6f <  -:  ------- control, cmd/gitbay: guard nounAliases and aliasGroupNames against drift
20:  ba0a7d3 <  -:  ------- changelog: #267 and the --path= upgrade note
21:  fd270da <  -:  ------- help: no auth <verb> usage or footer over stock ssh
22:  bc76b6f <  -:  ------- changelog: usage refusals name ssh git@<host> outside the CLI
23:  3595439 <  -:  ------- sshd: unregistered-key message names the fingerprint and the real host
24:  e3ba425 <  -:  ------- issue create: --label, --milestone, --assignee
25:  ea552d4 <  -:  ------- mr show: pluralize commits/checks/reviews section headings
26:  86c82f6 <  -:  ------- repo readme: print a repository's README, the web page's file order
27:  6bf4591 <  -:  ------- repo show: truncate the mirror's last-sync time to the second
28:  4fa1930 <  -:  ------- issue create: resolve milestone and assignees first, set fields through issue label/milestone/assign
29:  79fdea2 <  -:  ------- sshd: unregistered-key settings link from the site URL, scheme and port kept
30:  a4152dd <  -:  ------- wiki: issue create synopsis names --label, --milestone, --assignee
31:  0338e6a <  -:  ------- store: run foreign_key_check inside the migration transaction, before commit
32:  d0e26d3 <  -:  ------- web: pin and watch toggles dispatch through repo pin/watch/mute/unwatch
33:  8a379d4 <  -:  ------- web: Cache-Control: no-store on the login-link request
34:  4ffdc2c <  -:  ------- wiki: fix API token-refusal claim, batched-review status, watch/pin dispatch, login-link URL exception
35:  9bcf573 <  -:  ------- account: quote whoami, token create and auth export in forms that run
36:  0e46097 <  -:  ------- cmd/gitbay: test every quoted web command against the registry
37:  f4f897e <  -:  ------- web: range-diff page for a merge request's revisions
38:  e0a00fb <  -:  ------- web: list each MR revision with a compare-to-previous link
39:  6ddd002 <  -:  ------- wiki: Parity reflects the web range-diff view
40:  ca8187d =  1:  ca8187d runner next: say whether the build is trusted
41:  94f55ff =  2:  94f55ff runner: disposable home for untrusted builds
42:  7b64442 =  3:  7b64442 wiki: trusted and untrusted build homes
43:  b022fed =  4:  b022fed status set: ci/ is reserved for the instance's builds
44:  b1f4bf1 =  5:  b1f4bf1 ci: reuse only trusted results on the job's image
45:  dc10160 =  6:  dc10160 repo settings: required contexts turn the checks gate on, pending until reported
46:  d19e518 =  7:  d19e518 wiki: reserved ci/ statuses, trusted reuse, required contexts
47:  7a5f2a1 =  8:  7a5f2a1 changelog: #255, #258
48:  42a7b12 =  9:  42a7b12 wiki, changelog: last finisher sets ci/<job>; required contexts report on heads
49:  c21c7ea = 10:  c21c7ea runner next: send the instance's public ssh destination
50:  28f6758 = 11:  28f6758 runner: builds off the host's loopback when the runner polls over it
51:  23e979a = 12:  23e979a sshd: test the auth limiter's lockout by registration mode
52:  9809a86 = 13:  9809a86 runner host: builds reach only the forge's public ports on it
53:  9467ed2 = 14:  9467ed2 runner egress: remove the rule when it blocks the runner's poll
54:  26e387e = 15:  26e387e wiki: what a build can reach
55:  24c714d = 16:  24c714d runner: builds reach the forge at pasta's host address
56:  dcd9380 = 17:  dcd9380 runner: only a loopback runner's podman builds leave -remote
57:  b4e14d4 = 18:  b4e14d4 store: failed step and reason on a build
58:  6421e2f = 19:  6421e2f runner done: record the failed step and reason
59:  286e0c3 = 20:  286e0c3 runner: name the failed step and report it
60:  e6b51c1 = 21:  e6b51c1 build show: failed step and duration; build log --step, --tail
61:  ec5fe62 = 22:  ec5fe62 web: build log folded by step, failed step open
62:  bb4c0ae = 23:  bb4c0ae wiki: failed step, build log --step and --tail
63:  3bcdce3 = 24:  3bcdce3 web: step fold shows the step's first line; changelog: deploy order
64:  e5b80f7 = 25:  e5b80f7 control: runner done parses its flags through c.parseArgs
65:  ed99c93 = 26:  ed99c93 seal: AES-256-GCM keyring for secret columns
66:  b13a247 = 27:  b13a247 config: server.secret_key_file, outside server.root
67:  1ec2c9c = 28:  1ec2c9c store: seal CI secrets, webhook secrets, mirror tokens and device tokens
68:  24b9cdb = 29:  24b9cdb gitbayd: load the secret key file; admin secrets init, rotate, check
69:  1481a12 = 30:  1481a12 e2e: a key file per instance; the archive carries secrets sealed and no key
70:  7e5de53 = 31:  7e5de53 deploy, wiki: provision and document the secret key file
71:  03e5ee3 = 32:  03e5ee3 config: [backup] age_recipients (filippo.io/age v1.3.2)
72:  12a6859 = 33:  12a6859 backup: encrypt archives to [backup] age_recipients; --verify --identity
73:  03757af = 34:  03757af deploy, wiki: encrypted archives in the backup scripts and docs
 -:  ------- > 35:  0d343c9 sshd: the disable test waits for the connection's account to be recorded