-
v0.6.9 Stable
released this
2026-07-06 22:28:00 +00:00 | 91 commits to main since this releaseAdded
ForgejoTagProtectionCRD + controller: declaratively manage a repo's
tag-protection rules (globnamePattern+whitelistUsernames/whitelistTeams)
through the gitea SDK'stag_protectionsAPI. Because the API has no get-by-name
and keys rules by int64 ID, Converge lists (paginated), matches on the natural
namePatternkey, create-or-edits, and storesstatus.tagProtectionIDfor
edit/delete — mirroringForgejoLabel. Lets tag creation (e.g. releasev*tags)
be restricted to the in-cluster pipeline identity.ForgejoCollaboratorCRD + controller: declaratively grant a user direct
collaborator access (read/write/admin) on a single repository via
AddCollaborator(idempotent PUT), removing it on delete. This is the only way to
grant write on a user-owned repo (sean/*) —ForgejoTeamonly covers
org-owned repos — so a dedicated non-adminpipeline-botcan be given write on
each pipeline repo without the site-admin token.ForgejoBranchProtection: merge-whitelist fields (enableMergeWhitelist,
mergeWhitelistUsernames,mergeWhitelistTeams). With push disabled, protected
branches advance only via PR merges; enabling this + listingpipeline-botforces
every change to a protected branch through the pipeline (no human or bot outside
the whitelist can merge).
Included changes (v0.6.8 -> v0.6.9)
4b1c1ef9e473feat(crd): ForgejoTagProtection + ForgejoCollaborator + merge-whitelistc0152458da61fix(cicd): auto-resolve CHANGELOG land conflicts via .gitattributes merge=union16b1f5d488f5fix(ci): pin golang:1.26 builder base by digesta6ab3a1ab9cachore: retrigger CI (transient buildkit lease error)8c50685f4aa8docs(forgejorepository): correct stale cloneAddrFor comment (no server derivation)
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads