1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
|
#
# 1.3.1 release
#
r18: {
title: Gitblit 1.3.1 released
id: 1.3.1
date: 2013-07-24
note: ''
If you have forked repositories and your are upgrading from 1.2.x to 1.3.x, please DO NOT RELOCATE your repositories folder when running 1.3.x the first time. Gitblit will update forked repository configs on the first execution and it is critical that ${git.repositoriesFolder} points to the same location used by 1.2.x.
''
html: ~
text: ~
security: ~
fixes:
- Gitblit-as-viewer with no repository urls failed to display summary page (issue 269)
- Fixed incorrect tagger in the dashboard pages (issue-276)
- Automatically decode %7E in repository names from git clients that encode ~ (issue-278)
- Fixed missing Keys class in WAR and Express builds
- Fixed missing model class dependencies in Gitblit Manager build
- Fix for IE10 compatibility mode
- Reset dashboard and activity commit cache on branch REWIND or DELETE
- Fixed bug with adding new local users with external authentication
- Fixed missing clone url on the empty repository page
- Fixed Ubuntu service script for LSB compliance
- Inserted "sleep 5" in Ubuntu & Centos bash script for service restart
changes:
- Use trash icon in Gitblit Reflog for branch and tag deletion
- Update Gitblit Reflog on branch deletion from web UI
- Updated Chinese translation
- Updated Dutch translation
- Updated Spanish translation
- Updated Korean translation
- Updated Brazilian Portuguese translation
additions:
- Added optional browser-side page caching using Last-Modified and Cache-Control for the dashboard, activity, project, and several repository pages (issue-274)
- Added a GET_USER request type for the RPC mechanism (issue-275)
- Added PAMUserService to authenticate against a local Linux/Unix/MacOSX server
dependencyChanges:
- Added libpam4j 1.7
settings:
- { name: 'web.pageCacheExpires', defaultValue: 0 }
- { name: 'realm.pam.backingUserService', defaultValue: 'users.conf' }
- { name: 'realm.pam.serviceName', defaultValue: 'system-auth' }
contributors:
- Rainer Alföldi
- Liyu Wang
- Jeroen Baten
- James Moger
- Stardrad Yin
- Chad Horohoe
- Eduardo Guervós Narvaez
- Dongsu, KIM
- Gareth Collins
- Rafael Cavazin
- Tamás Papp
- Florian Zschocke
- Amélie Benoit
- Gustavo Henrique
}
#
# 1.3.0
#
r17: {
title: Gitblit 1.3.0 Released
id: 1.3.0
date: 2013-07-14
html: ''
Release highlights include:
<ul>
<li>integrated git daemon</li>
<li>compare refs or commits page</li>
<li>completed the Gitblit reflog (formerly pushlog) introduced in 1.2.1</li>
<li>added new dashboard pages</li>
<li>added a stars feature</li>
<li>improved the repository url panel to show your access permission and to offer native app clone links</li>
<li>improved navigation and theme</li>
<li>customizable page header colors and logo</li>
<li>recent activity commit caching to improve performance of dashboard and activity pages</li>
<li>Windows authentication</li>
<li>Salesforce.com authentication</li>
<li>lots of bug fixes</li>
</ul>
<p> </p>
Thank you to <a href="http://syntevo.com">syntevo</a>, <a href="http://atlassian.com">Atlassian</a>, <a href="http://fournova.com">fournova</a>, and <a href="http://github.com">Github</a> for their permission and use of their artwork for the native app clone menus.
''
note: ''
If you have forked repositories and your are upgrading to 1.3.0, please DO NOT RELOCATE your repositories folder when running 1.3.0 the first time. Gitblit will update forked repository configs on the first execution and it is critical that ${git.repositoriesFolder} points to the same location used by 1.2.x.
''
security:
- Raw servlet was insecure. If someone knew the exact repository name and path to a file, the raw blob could be retrieved bypassing security constraints. (issue 198)
fixes:
- Use bash instead of sh in Linux/OSX shell scripts (issue 154)
- Fix NPE when getting user's fork without repository list caching (issue 182)
- Fix internal error on folder history links (issue 192)
- Fix NPE in repositories panel when viewing a federation proposal (issue 195)
- Fix NPEs when initializing the context on a servlet containers which returns a null contextFolder (issue 199)
- Fixed incorrect icon file name for .doc files (issue 200)
- Do not queue emails with no recipients (issue 201)
- Disable view and blame links for deleted blobs (issue 216)
- Fixed 1.2.x regression with individually symlinked repositories (issue 217)
- Fixed UTF-8 encoding errors in email notifications (issue 218)
- Fixed NPE in 1.2.1 Federation Client (issue 219)
- Fixed extracting Groovy scripts on Express installs (issue 220)
- Ensure Redmine url is properly formatted (issue 223)
- Use standard ServletRequestWrapper instead of custom wrapper (issue 224)
- Switch commit message back to a pre and ensure that it is properly escaped when combined with commit message regex substitution (issue 242)
- Fixed AddIndexedBranch tool --branch parameter (issue 247)
- Improve NPE handling for hook script enumeration (issue-253)
- Workaround missing commit information in blame page (JGit bug 374382, issue-254)
- Ignore orphan ".git" folder in the repositories root folder (issue-256)
- Fixed bug where a null permission was added to a user model on a repository rename when the permission had really been inherited from a team membership (issue-259)
- Fixed committer verification with merge commits (issue-264)
- Fixed bug in submodule repository linking (issue-266)
- Could not reset settings with $ or { characters through Gitblit Manager because they are not properly escaped
- Added more error checking to blob page and blame page
- Disable SNI extensions for client SSL connections
- Fixed prettify language extension loading
- Fixed index out of bounds exceptions when generating client certificates for a user when the user's table has been filtered
- Fixed AddindexedBranch tool when specifying the non-default branch.
- Fixed submodule diff display
changes:
- Retrieve summary and metric graphs from Google over https (issue-61)
- Persist originRepository (for forks) in the repository config instead of relying on parsing origin urls which are susceptible to filesystem relocation (issue 190)
- Improved error logging for servlet containers which provide a null contextFolder (issue 199)
- Improve Gerrit change ref decoration in the refs panel (issue 206)
- Display full commit message on commitdiff page (issue-258)
- Improved the repository url display. This display now indicates your repository access permission, per-protocol.
- Automatically encode/decode usernames for urls using %XX notation on space, @, and \
- Disable Gson's pretty printing which has a huge performance gain
- Properly set application/json content-type on api calls
- Make days back filter choices a setting
- Changed default days back filter setting to 7 days
- Set rel="nofollow" on compressed download links
- Improved page title
- Updated Polish translation
- Updated Japanese translation
additions:
- Added a ui for the ref log introduced in 1.2.1 (issue-177)
- Added weblogic.xml to WAR for deployment on WebLogic (issue 199)
- Support setting a custom header logo (issue 208)
- Support header color customizations (issue 209)
- Support username substitution in web.otherUrls (issue 213)
- Option to force client-side basic authentication instead of form-based authentication if web.authenticateViewPages=true (issue 222)
- Set author as tooltip of last change column in the repositories panel (issue-238)
- Setting to automatically create an user account based on an authenticated user principal from the servlet container (issue-246)
- Added WindowsUserService to authenticate users against Windows accounts (issue-250)
- Global and per-repository setting to exclude authors from metrics (issue-251)
- Added commit cache to improve Activity, Dashboard, and Project page generation times
- Added SalesForce.com user service
- Added simple star/unstar function to flag or bookmark interesting repositories
- Added Dashboard page which shows a news feed for starred repositories and offers a filterable list of repositories you care about
- Added client application menus for Git, SmartGit/Hg, SourceTree, Tower, GitHub for Windows, and GitHub for Mac
- Added GO http/https connector thread pool size setting
- Added a server setting to force a particular translation/Locale for all sessions
- Added smart Git Daemon serving. If enabled, git:// access will be offered for any repository which permits anonymous access. If the repository permits anonymous cloning, anonymous git:// clone will be permitted while anonmymous git:// pushes will be rejected.
- Option to automatically tag branch tips on each push with an incremental revision number
- Implemented multiple repository owners
- Optional periodic LDAP user and team pre-fetching & synchronization
- Added config setting to use SMTPS
- Added option to index all local branches in AddIndexedBranches tool
- Display name and version in Tomcat Manager
- FogBugz post-receive hook script
- Chinese translation
- Support --baseFolder parameter in Federation Client
contributors:
- James Moger
- Bandarupalli Satyanarayana
- Chad Horohoe
- Christian Aistleitner
- Colin Bowern
- David Ostrovsky
- Egbert Teeselink
- Hige Maniya
- Hirotaka Honma
- Ikslawek
- Jay Meyer
- John Crygier
- Kensuke Matsuzaki
- Laurens Vrijnsen
- Lee Grofit
- Lukasz Jader
- Martijn Laan
- Matthias Bauer
- Michael Pailloncy
- Michael Schaefers
- Oliver Doepner
- Philip Boutros
- Rafael Cavazin
- Ryan Schneider
- Sakurai Youhei
- Sarah Haselbauer
- Slawomir Bochenski
- Stardrad Yin
- Thomas Pummer
- William Whittle
- Yukihiko Sawanobori
- github/akquinet
- github/dapengme
dependencyChanges:
- JGit 3.0.0.201306101825-r
- Iconic font
- AngularJS 1.0.7
- FreeMarker 2.3.19
- Waffle 1.5
- JNA 3.5.0
- Guava 13.0.1
settings:
- { name: 'git.daemonBindInterface', defaultValue: 'localhost' }
- { name: 'git.daemonPort', defaultValue: 0 }
- { name: 'git.defaultIncrementalPushTagPrefix', defaultValue: 'r' }
- { name: 'mail.smtps', defaultValue: 'false' }
- { name: 'realm.container.autoCreateAccounts', defaultValue: 'false' }
- { name: 'realm.salesforce.backingUserService', defaultValue: 'users.conf' }
- { name: 'realm.salesforce.orgId', defaultValue: 0 }
- { name: 'realm.windows.defaultDomain', defaultValue: ' ' }
- { name: 'realm.windows.backingUserService', defaultValue: 'users.conf' }
- { name: 'web.activityDuration', defaultValue: 7 }
- { name: 'web.activityDurationChoices', defaultValue: '1 3 7 14 21 28' }
- { name: 'web.activityCacheDays', defaultValue: 14 }
- { name: 'web.allowAppCloneLinks', defaultValue: 'true' }
- { name: 'web.forceDefaultLocale', defaultValue: ' ' }
- { name: 'web.headerLogo', defaultValue: '${baseFolder}/logo.png' }
- { name: 'web.headerBackgroundColor', defaultValue: ' ' }
- { name: 'web.headerForegroundColor', defaultValue: ' ' }
- { name: 'web.headerHoverColor', defaultValue: ' ' }
- { name: 'web.headerBorderColor', defaultValue: ' ' }
- { name: 'web.headerBorderFocusColor', defaultValue: ' ' }
- { name: 'web.metricAuthorExclusions', defaultValue: ' ' }
- { name: 'web.overviewReflogCount', defaultValue: 5 }
- { name: 'web.reflogChangesPerPage', defaultValue: 10 }
- { name: 'server.nioThreadPoolSize', defaultValue: 50 }
}
#
# 1.2.1
#
r16: {
title: Gitblit 1.2.1 Released
id: 1.2.1
date: 2013-01-15
html: ''
Because there are now several types of files and folders that must be considered Gitblit data, the default location for data has changed.
<p />
You will need to move a few files around when upgrading. Please review the <a href="upgrade_go.html">upgrading GO</a> or <a href="upgrade_war.html">upgrading WAR</a> page for details.
<p />
<b>Express Users</b> make sure to update your web.xml file with the ${baseFolder} values!
''
fixes:
- Fixed nullpointer on recursively calculating folder sizes when there is a named pipe or symlink in the hierarchy
- Added nullchecking when concurrently forking a repository and trying to display the fork network (issue-187)
- Fixed bug where permission changes were not visible in the web ui to a logged-in user until the user logged-out and then logged back in again (issue-186)
- Fixed nullpointer on creating a repository with mixed case (issue 185)
- Include missing model classes in api library (issue-184)
- Fixed nullpointer when using *web.allowForking = true* && *git.cacheRepositoryList = false* (issue 182)
- Likely fix for commit and commitdiff page failures when a submodule reference changes (issue 178)
- Build project models from the repository model cache, when possible, to reduce page load time (issue 172)
- Fixed loading of Brazilian Portuguese translation from *nix server
additions:
- ''Fanout PubSub service for self-hosted [Sparkleshare](http://sparkleshare.org) notifications.
This service is disabled by default.''
- ''Implemented a simple push log based on a hidden, orphan branch refs/gitblit/pushes (issue 177)
The push log is not currently visible in the ui, but the data will be collected and it will be exposed to the ui in the next release.''
- Support for locally and remotely authenticated accounts in LdapUserService and RedmineUserService (issue 183)
- Added Dutch translation
changes:
- ''Gitblit GO and Gitblit WAR are now both configured by `gitblit.properties`. WAR is no longer configured by `web.xml`.
However, Express for OpenShift continues to be configured by `web.xml`.''
- Support for a *--baseFolder* command-line argument for Gitblit GO and Gitblit Certificate Authority
- Support for specifying a *${baseFolder}* parameter in `gitblit.properties` and `web.xml` for several settings
- Improve history display of a submodule link
- Updated Korean translation
- Updated checkstyle definition
settings:
- { name: fanout.bindInterface, defaultValue: localhost }
- { name: fanout.port, defaultValue: 0 }
- { name: fanout.useNio, defaultValue: 'true' }
- { name: fanout.connectionLimit, defaultValue: 0 }
contributors:
- James Moger
- github/mystygage
- Dongsu, KIM
- Jeroen Baten
- github/inaiat
}
#
# 1.2.0
#
r15: {
title: Gitblit 1.2.0 Released
id: 1.2.0
date: 2012-12-31
note: ''
The permissions model has changed in the 1.2.0 release.
If you are updating your server, you must also update any Gitblit Manager and Federation Client installs to 1.2.0 as well. The data model used by the RPC mechanism has changed slightly for the new permissions infrastructure.
''
fixes:
- Fixed regression in *isFrozen* (issue 181)
- Author metrics can be broken by newlines in email addresses from converted repositories (issue 176)
- Set subjectAlternativeName on generated SSL cert if CN is an ip address (issue 170)
- Fixed incorrect links on history page for files not in the current/active commit (issue 166)
- Empty repository page failed to handle missing repository (issue 160)
- Fixed broken ticgit urls (issue 157)
- Exclude submodules from zip downloads (issue 151)
- Fixed bug where repository ownership was not updated on rename user
- Fixed bug in create/rename repository if you explicitly specified the alias for the root group (e.g. main/myrepo) (issue 143)
- Wrapped Markdown parser with improved exception handler (issue 142)
- Fixed duplicate entries in repository cache (issue 140)
- Fixed connection leak in LDAPUserService (issue 139)
- Fixed bug in commit page where changes to a submodule threw a null pointer exception (issue 132)
- Fixed bug in the diff view for filenames that have non-ASCII characters (issue 128)
additions:
- ''
Implemented discrete repository permissions (issue 36)
- V (view in web ui, RSS feeds, download zip)
- R (clone)
- RW (clone and push)
- RWC (clone and push with ref creation)
- RWD (clone and push with ref creation, deletion)
- RW+ (clone and push with ref creation, deletion, rewind)
While not as sophisticated as Gitolite, this does give finer access controls. These permissions fit in cleanly with the existing users.conf and users.properties files. In Gitblit <= 1.1.0, all your existing user accounts have RW+ access. If you are upgrading to 1.2.0, the RW+ access is *preserved* and you will have to lower/adjust accordingly.
''
- ''Implemented *case-insensitive* regex repository permission matching (issue 36)
This allows you to specify a permission like `RW:mygroup/.*` to grant push privileges to all repositories within the *mygroup* project/folder.''
- Added DELETE, CREATE, and NON-FAST-FORWARD ref change logging
- ''Added support for personal repositories.
Personal repositories can be created by accounts with the *create* permission and are stored in *git.repositoriesFolder/~username*. Each user with personal repositories will have a user page, something like the GitHub profile page. Personal repositories have all the same features as common repositories, except personal repositories can be renamed by their owner.''
- ''Added support for server-side forking of a repository to a personal repository (issue 137)
In order to fork a repository, the user account must have the *fork* permission **and** the repository must *allow forks*. The clone inherits the access list of its origin. i.e. if Team A has clone access to the origin repository, then by default Team A also has clone access to the fork. This is to facilitate collaboration. The fork owner may change access to the fork and add/remove users/teams, etc as required <u>however</u> it should be noted that all personal forks will be enumerated in the fork network regardless of access view restrictions. If you really must have an invisible fork, the clone it locally, create a new repository for your invisible fork, and push it back to Gitblit.''
- Added optional *create-on-push* support
- Added **experimental** JGit-based garbage collection service. This service is disabled by default.
- ''Added support for X509 client certificate authentication. (issue 106)
You can require all git servlet access be authenticated by a client certificate. You may also specify the OID fingerprint to use for mapping a certificate to a username. It should be noted that the user account MUST already exist in Gitblit for this authentication mechanism to work; this mechanism can not be used to automatically create user accounts from a certificate.''
- Revised clean install certificate generation to create a Gitblit GO Certificate Authority certificate; an SSL certificate signed by the CA certificate; and to create distinct server key and server trust stores. <u>The store files have been renamed!</u>
- Added support for Gitblit GO to require usage of client certificates to access the entire server.
- Added **Gitblit Certificate Authority**, an x509 PKI management tool for Gitblit GO to encourage use of x509 client certificate authentication.
- Added web.shortCommitId setting to control length of shortened commit ids
- Added alternate compressed download formats: tar.gz, tar.xz, tar.bzip2 (issue 174)
- Added simple project pages. A project is a subfolder off the *git.repositoriesFolder*.
- Added support for X-Forwarded-Context for Apache subdomain proxy configurations (issue 135)
- Delete branch feature (issue 121)
- Added line links to blob view (issue 130)
- Added HTML sendmail hook script and Gitblit.sendHtmlMail method
- Added RedmineUserService
- Support for committer verification. Requires use of *--no-ff* when merging branches or pull requests. See setup page for details.
- Added Brazilian Portuguese translation
changes:
- Added server setting to specify keystore alias for ssl certificate (issue 98)
- Added optional global and per-repository activity page commit contribution throttle to help tame *really* active repositories (issue 173)
- Added support for symlinks in tree page and commit page (issue 171)
- All access restricted servlets (e.g. DownloadZip, RSS, etc) will try to authenticate using X509 certificates, container principals, cookies, and BASIC headers, in that order.
- Added *groovy* and *scala* to *web.prettyPrintExtensions*
- Added short commit id column to log and history tables (issue 168)
- Teams can now specify the *admin*, *create*, and *fork* roles to simplify user administration
- Use https Gravatar urls to avoid browser complaints
- Added frm to default pretty print extensions (issue 156)
- Expose ReceivePack to Groovy push hooks (issue 125)
- Redirect to summary page when refreshing the empty repository page on a repository that is not empty (issue 129)
- Emit a warning in the log file if running on a Tomcat-based servlet container which is unfriendly to %2F forward-slash url encoding AND Gitblit is configured to mount parameters with %2F forward-slash url encoding (issue 126)
- ''LDAP admin attribute setting is now consistent with LDAP teams setting and admin teams list.
If *realm.ldap.maintainTeams==true* **AND** *realm.ldap.admins* is not empty, then User.canAdmin() is controlled by LDAP administrative team membership. Otherwise, User.canAdmin() is controlled by Gitblit.''
- Support servlet container authentication for existing UserModels (issue 68)
settings:
- { name: web.allowForking, defaultValue: 'true' }
- { name: git.allowCreateOnPush, defaultValue: 'true' }
- { name: git.allowGarbageCollection, defaultValue: 'false' }
- { name: git.garbageCollectionHour, defaultValue: 0 }
- { name: git.defaultGarbageCollectionThreshold, defaultValue: 500k }
- { name: git.defaultGarbageCollectionPeriod, defaultValue: 7 days }
- { name: git.requireClientCertificates, defaultValue: 'false' }
- { name: git.enforceCertificateValidity, defaultValue: 'true' }
- { name: git.certificateUsernameOIDs, defaultValue: CN }
- { name: web.shortCommitIdLength, defaultValue: 8 }
- { name: web.compressedDownloads, defaultValue: zip gz }
- { name: server.requireClientCertificates, defaultValue: 'false' }
dependencyChanges:
- Jetty 7.6.8
- JGit 2.2.0.201212191850-r
- Groovy 1.8.8
- Wicket 1.4.21
- Lucene 3.6.1
- BouncyCastle 1.47
- MarkdownPapers 1.3.2
- JCalendar 1.3.2
- Commons-Compress 1.4.1
- XZ for Java 1.0
contributors:
- James Moger
- github/rafaelcavazin
- github/mallowlabs
- github/sauthieg
- github/ajermakovics
- github/kevinanderson1
- github/jpyeron
}
#
# 1.1.0
#
r14: {
title: Gitblit 1.1.0 Released
id: 1.1.0
date: 2012-08-25
note: If you are updating from an earlier release AND you have indexed branches with the Lucene indexing feature, you need to be aware that this release will completely re-index your repositories. Please be sure to provide ample heap resources as appropriate for your installation.
fixes:
- Bypass Wicket's inability to handle direct url addressing of a view-restricted, grouped repository for new, unauthenticated sessions (e.g. click link from email or rss feed without having an active Wicket session)
- Fixed MailExecutor's failure to cope with mail server connection troubles resulting in 100% CPU usage
- Fixed generated urls in Groovy *sendmail* hook script for grouped repositories
- Fixed generated urls in RSS feeds for grouped repositories
- Fixed nullpointer exception in git servlet security filter (issue 123)
- Eliminated an unnecessary repository enumeration call on the root page which should result in faster page loads (issue 103)
- Gitblit could not delete a Lucene index in a working copy on index upgrade
- Do not index submodule links (issue 119)
- Restore original user or team object on failure to update (issue 118)
- Fixes to relative path determination in repository search algorithm for symlinks (issue 116)
- Fix to GitServlet to allow pushing to symlinked repositories (issue 116)
- Repository URL now uses `X-Forwarded-Proto` and `X-Forwarded-Port`, if available, for reverse proxy configurations (issue 115)
- Output real RAW content, not simulated RAW content (issue 114)
- Fixed Lucene charset encoding bug when reindexing a repository (issue 112)
- Fixed search box linking to Lucene page for grouped repository on Tomcat (issue 111)
- Fixed null pointer in LdapUserSerivce if account has a null email address (issue 110)
- Really fixed failure to update a GO setting from the manager (issue 85)
additions:
- Identified repository list is now cached by default to reduce disk io and to improve performance (issue 103)
- Preliminary bare repository submodule support
- ''
*git.submoduleUrlPatterns* is a space-delimited list of regular expressions for extracting a repository name from a submodule url.
For example, `git.submoduleUrlPatterns = .*?://github.com/(.*)` would extract *gitblit/gitblit.git* from *git://github.git/gitblit/gitblit.git*
**Note:** You may not need this control to work with submodules, but it is there if you do.
- If there are no matches from *git.submoduleUrlPatterns* then the repository name is assumed to be whatever comes after the last `/` character *(e.g. gitblit.git)*
- Gitblit will try to locate this repository relative to the current repository *(e.g. myfolder/myrepo.git, myfolder/mysubmodule.git)* and then at the root level *(mysubmodule.git)* if that fails.
- Submodule references in a working copy will be properly identified as gitlinks, but Gitblit will not traverse into the working copy submodule repository.
''
- ''
Added a repository setting to control authorization as AUTHENTICATED or NAMED. (issue 117)
NAMED is the original behavior for authorizing against a list of permitted users or permitted teams.
AUTHENTICATED allows restricted access for any authenticated user. This is a looser authorization control.
''
- Added default authorization control setting (AUTHENTICATED or NAMED)
- Added setting to control how deep Gitblit will recurse into *git.repositoriesFolder* looking for repositories (issue 103)
- Added setting to specify regex exclusions for repositories (issue 103)
- Blob page now supports displaying images (issue 6)
- Non-image binary files can now be downloaded using the RAW link
- Support StartTLS in LdapUserService (issue 122)
- Added Korean translation
changes:
- Line breaks inserted for readability in raw Markdown content display in the event of a parsing/transformation error. An error message is now displayed prepended to the raw content.
- Improve UTF-8 reading for Markdown files
- Updated Polish translation
- Updated Japanese translation
- Updated Spanish translation
settings:
- { name: git.cacheRepositoryList, defaultValue: 'true' }
- { name: git.submoduleUrlPatterns, defaultValue: * }
- { name: git.searchExclusions, defaultValue: * }
- { name: git.searchRecursionDepth, defaultValue: -1 }
- { name: git.defaultAuthorizationControl, defaultValue: NAMED }
contributors:
- James Moger
- Steffen Gebert
}
#
# 1.0.0
#
r13: {
title: Gitblit 1.0.0 Released
id: 1.0.0
date: 2012-07-14
fixes:
- Fixed bug in Lucene search where old/stale blobs were never properly deleted during incremental updates. This resulted in duplicate blob entries in the index.
- Fixed intermittent bug in identifying line numbers in Lucene search (issue 105)
- Adjust repository identification algorithm to handle the scenario where a repository name collides with a group/folder name (e.g. foo.git and foo/bar.git) (issue 104)
- Fixed bug where a repository set as *authenticated push* did not have anonymous clone access (issue 96)
- Fixed bug in Basic authentication if passwords had a colon
- Fixed bug where the Gitblit Manager could not update a setting that was not referenced in reference.properties (issue 85)
changes:
- ''**Updated Lucene index version which will force a rebuild of ALL your Lucene indexes**
Make sure to properly set *web.blobEncodings* before starting Gitblit if you are updating! (issue 97)''
- Changed default layout for web ui from Fixed-Width layout to Responsive layout (issue 101)
- ''IUserService interface has changed to better accomodate custom authentication and/or custom authorization<
The default `users.conf` now supports persisting display names and email addresses.''
- Updated Japanese translation
additions:
- Added setting to allow specification of a robots.txt file (issue 99)
- ''Added setting to control Responsive layout or Fixed-Width layout (issue 101)
Responsive layout is now the default. This layout gracefully scales the web ui from a desktop layout to a mobile layout by hiding page components. It is easy to try, just resize your browser or point your Android/iOS device to the url of your Gitblit install.''
- Added setting to control charsets for blob string decoding. Default encodings are UTF-8, ISO-8859-1, and the server default charset. (issue 97)
- ''Exposed JGit internal configuration settings in gitblit.properties/web.xml (issue 93)
Review your `gitblit.properties` or `web.xml` for detailed explanations of these settings.''
- Added default access restriction. Applies to new repositories and repositories that have not been configured with Gitblit. (issue 88)
- Added Ivy 2.2.0 dependency which enables Groovy Grapes, a mechanism to resolve and retrieve library dependencies from a Maven 2 repository within a Groovy push hook script
- ''Added setting to control Groovy Grape root folder (location where resolved dependencies are stored)
[Grape](http://groovy.codehaus.org/Grape) allows you to add Maven dependencies to your pre-/post-receive hook script classpath.''
- Added LDAP User Service with many new *realm.ldap* keys
- ''Added support for custom repository properties for Groovy hooks
Custom repository properties complement hook scripts by providing text field prompts in the web ui and the Gitblit Manager for the defined properties. This allows your push hooks to be parameterized.''
- Added script to facilitate proxy environment setup on Linux
- Added Polish translation
- Added Spanish translation
settings:
- { name: groovy.grapeFolder, defaultValue: groovy/grape }
- { name: web.robots.txt, defaultValue: }
- { name: web.useResponsiveLayout, defaultValue: 'true' }
- { name: web.blobEncodings, defaultValue: UTF-8 ISO-8859-1 }
- { name: git.defaultAccessRestriction, defaultValue: NONE }
- { name: git.packedGitWindowSize, defaultValue: 8k }
- { name: git.packedGitLimit, defaultValue: 10m }
- { name: git.deltaBaseCacheLimit, defaultValue: 10m }
- { name: git.packedGitOpenFiles, defaultValue: 128 }
- { name: git.streamFileThreshold, defaultValue: 50m }
- { name: git.packedGitMmap, defaultValue: 'false' }
dependencyChanges:
- Bootstrap 2.0.4
- JGit 2.0.0.201206130900-r
- Groovy 1.8.6
- Gson 1.7.2
- Log4J 1.2.17
- SLF4J 1.6.6
- Apache Commons Daemon 1.0.10
- Ivy 2.2.0
contributors:
- James Moger
- Eduardo Guervos Narvaez
- Lukasz Jader
- github/mragab
- github/jcrygier
- github/zakki
- github/peterloron
}
#
# 0.9.3
#
r12: {
title: Gitblit 0.9.3 Released
id: 0.9.3
date: 2012-04-11
fixes:
- Fixed bug where you could not remove all selections from a RepositoryModel list (permitted users, permitted teams, hook scripts, federation sets, etc) (issue 81)
- Automatically set *java.awt.headless=true* for Gitblit GO
contributors:
- James Moger
}
#
# 0.9.2
#
r11: {
title: Gitblit 0.9.2 Released
id: 0.9.2
date: 2012-04-04
changes:
- Added *clientLogger* bound variable to Groovy hook mechanism to allow custom info and error messages to be returned to the client
fixes:
- Fixed absolute path/canonical path discrepancy between Gitblit and JGit regarding use of symlinks (issue 78)
- Fixed row layout on activity page (issue 79)
- Fixed Centos service script
- Fixed EditRepositoryPage for IE8; missing save button (issue 80)
contributors:
- James Moger
- github/jonnybbb
- github/mohamedmansour
- github/jcrygier
}
#
# 0.9.1
#
r10: {
title: Gitblit 0.9.1 Released
id: 0.9.1
date: 2012-03-27
fixes:
- Lucene folder was stored in working copy instead of in .git folder
contributors:
- James Moger
}
#
# 0.9.0
#
r9: {
title: Gitblit 0.9.0 Released
id: 0.9.0
date: 2012-03-27
security:
- Fixed session fixation vulnerability where the session identifier was not reset during the login process (issue 62)
changes:
- Reject pushes to a repository with a working copy (i.e. non-bare repository) (issue-49)
- Changed default web.datetimestampLongFormat from *EEEE, MMMM d, yyyy h:mm a z* to *EEEE, MMMM d, yyyy HH:mm Z* (issue 50)
- Expanded commit age coloring from 2 days to 30 days (issue 57)
additions:
- ''Added optional Lucene branch indexing (issue 16)
Repository branches may be optionally indexed by Lucene for improved searching. To use this feature you must specify which branches to index within the *Edit Repository* page; _no repositories are automatically indexed_. Gitblit will build or incrementally update enrolled repositories on a 2 minute cycle. (i.e you will have to wait 2-3 minutes after respecifying indexed branches or pushing new commits before Gitblit will build/update the repository Lucene index.)
If a repository has Lucene-indexed branches the *search* form on the repository pages will redirect to the root-level Lucene search page and only the content of those branches can be searched.<br/>
If the repository does not specify any indexed branches then repository commit-traversal search is used.
**Note:** Initial indexing of an existing repository can be memory-exhaustive. Be sure to provide your Gitblit server adequate heap space to index your repositories (e.g. -Xmx1024M).<br/>
See the [setup](setup.html) page for additional details.''
- Allow specifying timezone to use for Gitblit which is independent of both the JVM and the system timezone (issue 54)
- Added a built-in AJP connector for integrating Gitblit GO into an Apache mod_proxy setup (issue 59)
- ''On the Repositories page show a bang *!* character in the color swatch of a repository with a working copy (issue 49)
Push requests to these repositories will be rejected.''
- On all non-bare Repository pages show *WORKING COPY* in the upper right corner (issue 49)
- New setting to prevent display/serving non-bare repositories
- Added *protect-refs.groovy*
- Allow setting default branch (relinking HEAD) to a branch or a tag
- Added Ubuntu service init script (issue 72)
- Added partial Japanese translation
fixes:
- Ensure that Welcome message is parsed using UTF-8 encoding (issue 74)
- Activity page chart layout broken by Google (issue 73)
- Uppercase repositories not selectable in edit palettes (issue 71)
- Not all git notes were properly displayed on the commit page (issue 70)
- Activity page now displays all local branches (issue 65)
- Fixed (harmless) nullpointer on pushing to an empty repository (issue 69)
- Fixed possible nullpointer from the servlet container on startup (issue 67)
- Fixed UTF-8 encoding bug on diff page (issue 66)
- Fixed timezone bugs on the activity page (issue 54)
- Prevent add/edit team with no selected repositories (issue 56)
- Disallow browser autocomplete on add/edit user/team/repository pages
- Fixed username case-sensitivity issues (issue 43)
- Disregard searching a subfolder if Gitblit does not have filesystem permissions (issue 51)
settings:
- { name: web.allowLuceneIndexing, defaultValue: 'true' }
- { name: web.luceneIgnoreExtensions, defaultValue: 7z arc arj bin bmp dll doc docx exe gif gz jar jpg lib lzh odg odf odt pdf ppt png so swf xcf xls xlsx zip }
- { name: web.timezone, defaultValue: }
- { name: server.ajpPort, defaultValue: 0 }
- { name: server.ajpBindInterface, defaultValue: localhost }
- { name: git.onlyAccessBareRepositories, defaultValue: 'false' }
dependencyChanges:
- Bootstrap 2.0.2
- MarkdownPapers 1.2.7
- JGit 1.3.0.201202151440-r
- Wicket 1.4.20
contributors:
- James Moger
- github/lemval
- github/zakki
- github/plm
}
#
# 0.8.2
#
r8: {
title: Gitblit 0.8.2 Released
id: 0.8.2
date: 2012-01-13
fixes:
- Fixed bug when upgrading from users.properties to users.conf (issue 41)
contributors:
- James Moger
}
#
# 0.8.1
#
r7: {
title: Gitblit 0.8.1 Released
id: 0.8.1
date: 2012-01-11
fixes:
- Include missing icon resource for the manager (issue 40)
- Fixed sendmail.groovy message content with incorrect tag/branch labels
contributors:
- James Moger
}
#
# 0.8.0
#
r6: {
title: Gitblit 0.8.0 Released
id: 0.8.0
date: 2012-01-11
additions:
- ''Platform-independent, Groovy push hook script mechanism.
Hook scripts can be set per-repository, per-team, or globally for all repositories.''
- ''*sendmail.groovy* for optional email notifications on push.
You must properly configure your SMTP server settings in `gitblit.properties` or `web.xml` to use *sendmail.groovy*.''
- New global key for mailing lists. This is used in conjunction with the *sendmail.groovy* hook script. All repositories that use the *sendmail.groovy* script will include these addresses in the notification process. Please see the Setup page for more details about configuring sendmail.
- *com.gitblit.GitblitUserService*. This is a wrapper object for the built-in user service implementations. For those wanting to only implement custom authentication it is recommended to subclass GitblitUserService and override the appropriate methods. Going forward, this will help insulate custom authentication from new IUserService API and/or changes in model classes.
- ''New default user service implementation: *com.gitblit.ConfigUserService* (`users.conf`)
This user service implementation allows for serialization and deserialization of more sophisticated Gitblit User objects without requiring the encoding trickery now present in FileUserService (users.properties). This will open the door for more advanced Gitblit features.
For those upgrading from an earlier Gitblit version, a `users.conf` file will automatically be created for you from your existing `users.properties` file on your first launch of Gitblit <u>however</u> you will have to manually set *realm.userService=users.conf* to switch to the new user service.
The original `users.properties` file and the corresponding implementation are **deprecated**.''
- Teams for specifying user-repository access in bulk. Teams may also specify mailing lists addresses and pre- & post- receive hook scripts.
- Gravatar integration
- Activity page for aggregated repository activity. This is a timeline of commit activity over the last N days for one or more repositories.
- *Filters* menu for the Repositories page and Activity page. You can filter by federation set, team, and simple custom regular expressions. Custom expressions can be stored in `gitblit.properties` or `web.xml` or directly defined in your url (issue 27)
- Flash-based 1-step *copy to clipboard* of the primary repository url based on Clippy
- JavaScript-based 3-step (click, ctrl+c, enter) *copy to clipboard* of the primary repository url in the event that you do not want to use Flash on your installation
- Empty repositories now link to an *empty repository* page which gives some direction to the user for the next step in using Gitblit. This page displays the primary push/clone url of the repository and gives sample syntax for the git command-line client. (issue 31)
- Repositories with a *gh-pages* branch will now have a *pages* link which will serve the content of this branch. All resource requests are against the repository, Gitblit does not checkout/export this branch to a temporary filesystem. Jekyll templating is not supported.
- Gitblit Express bundle to get started running Gitblit on RedHat OpenShift cloud <span class="label label-warning">BETA</span>
changes:
- Dropped display of trailing .git from repository names
- ''Gitblit GO is now monolithic like the WAR build. (issue 30)
This change helps adoption of GO in environments without an internet connection or with a restricted connection.''
- Unit testing framework has been migrated to JUnit4 syntax and the test suite has been redesigned to run all unit tests, including rpc, federation, and git push/clone tests
fixes:
- Several a bugs in FileUserService related to cleaning up old repository permissions on a rename or delete
- Renaming a repository into a new subfolder failed (issue 33)
settings:
- { name: groovy.scriptsFolder, defaultValue: groovy }
- { name: groovy.preReceiveScripts, defaultValue: }
- { name: groovy.postReceiveScripts, defaultValue: }
- { name: mail.mailingLists, defaultValue: }
- { name: realm.userService, defaultValue: users.conf }
- { name: web.allowGravatar, defaultValue: 'true' }
- { name: web.activityDuration, defaultValue: 14 }
- { name: web.timeFormat, defaultValue: HH:mm }
- { name: web.datestampLongFormat, defaultValue: "EEEE, MMMM d, yyyy" }
- { name: web.customFilters, defaultValue: }
- { name: web.allowFlashCopyToClipboard, defaultValue: 'true' }
dependencyChanges:
- JGit 1.2.0
- Groovy 1.8.5
- Clippy
contributors:
- James Moger
}
#
# 0.7.0
#
r5: {
title: Gitblit 0.7.0 Released
id: 0.7.0
date: 2011-11-11
security:
- fixed security hole when cloning clone-restricted repository with TortoiseGit (issue 28)
fixes:
- ''federation protocol timestamps. dates are now serialized to the [iso8601](http://en.wikipedia.org/wiki/ISO_8601) standard.
**This breaks 0.6.0 federation clients/servers.**''
- collision on rename for repositories and users
- Gitblit can now browse the Linux kernel repository (issue 25)
- Gitblit now runs on Servlet 3.0 webservers (e.g. Tomcat 7, Jetty 8) (issue 23)
- Set the RSS content type of syndication feeds for Firefox 4 (issue 22)
- RSS feeds are now properly encoded to UTF-8
- RSS feeds now properly generate parameterized links if *web.mountParameters=false*
- Null pointer exception if did not set federation strategy (issue 20)
- Gitblit GO allows SSL renegotiation if running on Java 1.6.0_22 or later
changes:
- updated ui with Twitter Bootstrap CSS toolkit
- repositories list performance by caching repository sizes (issue 27)
- summary page performance by caching metric calculations (issue 25)
additions:
- authenticated JSON RPC mechanism
- Gitblit API RSS/JSON RPC library
- Gitblit Manager (Java/Swing Application) for remote administration of a Gitblit server.
- per-repository setting to skip size calculation (faster repositories page loading)
- per-repository setting to skip summary metrics calculation (faster summary page loading)
- IUserService.setup(IStoredSettings) for custom user service implementations
- setting to control Gitblit GO context path for proxy setups
- *combined-md5* password storage option which stores the hash of username+password as the password
- repository owners are automatically granted access for git, feeds, and zip downloads without explicitly selecting them
- RSS feeds now include regex substitutions on commit messages for bug trackers, etc
settings:
- { name: web.loginMessage, defaultValue: gitblit }
- { name: web.enableRpcServlet, defaultValue: 'true' }
- { name: web.enableRpcManagement, defaultValue: 'false' }
- { name: web.enableRpcAdministration, defaultValue: 'false' }
- { name: server.contextPath, defaultValue: / }
dependencyChanges:
- MarkdownPapers 1.2.5
- Wicket 1.4.19
contributors:
- James Moger
- github/dadalar
- github/alyandon
- github/trygvis
}
#
# 0.6.0
#
r4: {
title: Gitblit 0.6.0 Released
id: 0.6.0
date: 2011-09-27
fixes:
- syndication urls for WAR deployments
- authentication for zip downloads
additions:
- federation feature to allow gitblit instances (or gitblit federation clients) to pull repositories and, optionally, settings and accounts from other gitblit instances. This is something like [svn-sync](http://svnbook.red-bean.com/en/1.5/svn.ref.svnsync.html) for gitblit.
- user role *#notfederated* to prevent a user account from being pulled by a federated Gitblit instance
settings:
- { name: federation.name, defaultValue: }
- { name: federation.passphrase, defaultValue: }
- { name: federation.allowProposals, defaultValue: 'false' }
- { name: federation.proposalsFolder, defaultValue: proposals }
- { name: federation.defaultFrequency, defaultValue: 60 mins }
- { name: federation.sets, defaultValue: }
- { name: "mail.*", defaultValue: }
dependencyChanges:
- MarkdownPapers 1.1.1
- Wicket 1.4.18
- JGit 1.1.0
- google-gson
- javamail
contributors:
- James Moger
}
#
# 0.5.2
#
r3: {
title: Gitblit 0.5.2 Released
id: 0.5.2
date: 2011-07-27
fixes:
- active repositories with a HEAD that pointed to an empty branch caused internal errors (issue 14)
- bare-cloned repositories were listed as (empty) and were not clickable (issue 13)
- default port for Gitblit GO is now 8443 to be more linux/os x friendly (issue 12)
- repositories can now be reliably deleted and renamed (issue 10)
- users can now change their passwords (issue 1)
- always show root repository group first, i.e. do not sort root group with other groups
- tone-down repository group header color
additions:
- optionally display repository on-disk size on repositories page
- forward-slashes ('/', %2F) can be encoded using a custom character to workaround some servlet container default security measures for proxy servers
settings:
- { name: web.showRepositorySizes, defaultValue: 'true' }
- { name: web.forwardSlashCharacter, defaultValue: / }
dependencyChanges:
- MarkdownPapers 1.1.0
- Jetty 7.4.3
contributors:
- James Moger
}
#
# 0.5.1
#
r2: {
title: Gitblit 0.5.1 Released
id: 0.5.1
date: 2011-06-28
changes:
- clarified SSL certificate generation and configuration for both server-side and client-side
- added some more troubleshooting information to documentation
- replaced JavaService with Apache Commons Daemon
contributors:
- James Moger
}
#
# 0.5.0
#
r1: {
title: Gitblit 0.5.0 Released
id: 0.5.0
date: 2011-06-26
text: initial release
contributors:
- James Moger
}
snapshot: ~
release: &r18
releases: &r[1..18]
|