From 67389fdd48662f7496bfffe457ff55ec53b7b667 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Tue, 22 Sep 2026 07:11:48 -1000 Subject: Release v2.8.0 --- CHANGELOG.txt | 58 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 56 insertions(+), 2 deletions(-) (limited to 'CHANGELOG.txt') diff --git a/CHANGELOG.txt b/CHANGELOG.txt index 5a3ac51..67b2670 100644 --- a/CHANGELOG.txt +++ b/CHANGELOG.txt @@ -5,6 +5,60 @@ Notable changes to this fork, newest release first. History before v2.0.0 belongs to upstream cgit and is not covered here. +v2.8.0 (2026-09-16) +------------------- + +A feature and hardening release. Commit trailers get a table of their own, the +mailmap is applied everywhere a person is named, the per-repository filter gate +gives way to a trust switch for scanned repositories, and an audit closed every +crash and every request that could reach git unchecked. + +Added +..... + +* Commit trailers shown as a table under the message, behind enable-trailers. +* trailer-filter, with link-trailers.lua linking Fixes, Reverts, Closes, Bug and + bare URLs. +* The .mailmap at HEAD applied to every ident and search, behind enable-mailmap. + +Changed +....... + +* enable-filter-overrides became trust-scan-config, gating only the risky keys a + scanned repository's own cgitrc or git config can set. +* A request may name a revision only by hex id or ref name, and the log search + matches literally. +* A die inside git answers a 500 page and logs the reason. +* The static ttl covers only the pages whose content the id fixes. +* One phrase and status for a bad object id or a revision that is not a commit. +* A scan path that is itself a repository is named after its directory. +* The tag page shows the tagged object's full id. + +Fixed +..... + +* Crashes on a repository without a path, an unknown page name, an empty url, a + repo.* key after scan-path, a broken git config in a scanned repository, an + unparsable commit and a history with a missing parent object. +* A full cache disk no longer fails every cacheable request, and an error mid + page finishes the page instead of starting a second response. +* Revisions, paths and snapshot names can no longer reach git as options, + pathspec magic or archive members outside the extraction directory. +* Filters answer one error page when they cannot run, start with SIGPIPE at its + default and no longer leave a page half written when they exit early. +* Limits hold for a diff limited to a directory, a large symlink target and a + deep chain of single directories. +* The about page no longer serves the repository's own files beside a readme on + disk. +* Snapshots of dash-named tags, a missing compressor, nested tags, dumb clones + of an empty repository, a symlink cycle under the scan path, the fallback + default branch, a blank line in mimetype-file and a POST body arriving in + pieces all answer correctly. +* Commit encoding, trailer splitting, notes lookup, subject truncation, ref + decorations and statistics buckets render correctly in their edge cases. +* Two builds of the same sources are byte for byte identical. + + v2.7.1 (2026-09-08) ------------------- @@ -353,7 +407,7 @@ Changed constant time even for unknown users, and a protected repository with no resolvable users denies everyone. * The avatar filters skip missing addresses instead of hashing garbage, - normalize the rest, and expose size, style and URL settings. + normalise the rest, and expose size, style and URL settings. * link-commits.lua takes a user-editable list of pattern and URL rules instead of a hardcoded issue reference, resolving all matches in one pass. * The syntax highlighter falls back through an extension map when lexer @@ -534,7 +588,7 @@ Fixed because git's error output was compressed into the archive. * Numerous crashes, among them out-of-bounds accesses on short paths and empty URLs, NULL dereferences on odd blobs and authorless commits, a division by - zero in the diffstat and undefined ctype behavior on negative chars. + zero in the diffstat and undefined ctype behaviour on negative chars. * Truncated pages after stat-only diffs and binary blames, a 200 instead of a 404 for unknown blob paths, submodule hashes losing digits in diffs, pager links dropping search terms containing reserved characters, a missing updated -- cgit v2.8.0