Skip to content
GitRiverGitRiver
RU

Changelog

v1.1.0

minor09/25/2026
  • Compatibility layers: the GitHub API (/api/v3) and the GitLab API (/api/v4) - gh, octokit, glab, python-gitlab and the Terraform provider work after changing the instance address and token
  • Built-in SSH server: clone and push over SSH without a system sshd, keys and settings from the admin area without a restart
  • Proxied package delivery: an external registry cache for every format, warm-up, eviction, reports, air-gapped operation
  • Knowledge layer: records in .gitriver/knowledge/, drafts, assembling a batch of drafts into a pull request, a repository tab, secret scanning of records on intake
  • LLM assistant: analysis of a failed CI job and of pull request changes - Pro
  • Code index: a "Symbols" tab, jump to definition and to callers - Pro
  • The license policy is created and attached in the interface (Security tab → Licenses): mode, SPDX list, violation level - Pro
  • A license policy that blocks merging stops a pull request bringing in a dependency with a forbidden license - both on direct merge and in the merge queue; the pull request panel names the offending packages - Pro
  • License check: a dependency is counted once (the lock file takes precedence over the manifest), the project is not listed as its own dependency, Rust dependency licenses are resolved even without Cargo.lock
  • Composer package registry (Packagist v2) - the seventh publishing format; a repository can act as a mirror of an external image registry
  • Import from GitHub, GitLab and Gitea now brings pull requests too; an import report in repository settings
  • Discussion threads in pull requests: replies, resolve marker, unresolved counter, the "all threads resolved" merge rule
  • Merging a pull request runs CI for "on: push", sends the push webhook and resets the mergeability of neighbouring pull requests - previously only a push did this; the merge queue sends notifications and writes to the feed
  • Squash merge no longer fails with "Committer identity unknown" when the target branch has moved ahead
  • Pull request assignees and reviewers are chosen from all repository members, including members of the group and its ancestors (new GET /api/v1/repos/{owner}/{name}/members call)
  • New board columns and the merge commit message use the instance language
  • Commit signature verification against account keys with author email matching; the "signed commits only" branch protection rule; the web editor signs commits with the instance key
  • Foreign code in CI waits for human approval before it takes runners; the wait survives a server restart
  • Remote runners caught up with the built-in one: job log, environment variables on every launch path, if, retry, services, reports, max-parallel, artifacts, retry and manual run
  • Cache across runs on remote runners, separate quotas for the CI cache and release attachments, eviction of forgotten cache
  • Docker-free installation: the whole queue goes to remote runners, a disabled built-in runner is visible in the admin area and the setup wizard
  • CI schedules are materialised in the database; the pipelines page names the reason a schedule stays silent
  • A CI concurrency group keeps its promise by waiting rather than cancelling a job; a group runner serves the whole subtree
  • CI resource slice: limits now cover everything the executor runs, not just the job container - job services, action containers and workspace housekeeping share one slice. The slice reports what it did in the job log, on the settings screen and in metrics, and its limit is set by systemd
  • The default number of concurrent jobs is computed from the available CPU time including that limit: where a limit is set, fewer jobs run at once than before
  • On-demand vulnerability scanning of registry images and Trivy access to private content
  • Image registry rules are set in repository settings, not only through the API: which images a rule covers, how many of the newest tags to keep, from what age to remove, which tags to leave alone entirely, and what is protected from overwriting. The exclude pattern is there for moving tags: buildcache, latest and nightly are overwritten by every build, and protection from overwriting does not suit them
  • Repository rules now count the same way installation limits always did: a tag is removed only when it is both outside the newest kept and older than the age limit. Where both numbers are set in a repository rule, fewer tags are removed than before; setting keep-last to zero brings back removal by age alone
  • Eight notification channels: Matrix added, the Max channel moved to the current Bot API, delivery outcome visible to the repository owner
  • deb and rpm packages, a Helm chart for Kubernetes, multi-replica operation with background job leadership on PostgreSQL locks
  • Mirrors sync on a configured interval, not only on a button press
  • The instance as an OIDC provider: id_token with a verifiable signature (JWKS), UserInfo answers POST as well
  • LDAP sign-in with ldap:// upgraded to TLS via StartTLS - Max
  • SCIM: RFC 7644 filter grammar, externalId on groups, handing a group to provisioning as a separate action - Max
  • Audit log extended: account creation and deactivation, branch protection changes, administrative changes, runner actions, external sign-ins - Max
  • The Max edition - instance-level capabilities: SAML, SCIM, LDAP, audit log, quota assignment, instance-level IP rules, custom branding, knowledge draft limits
  • Pro seats now work: paid sections are open to participants holding an assigned seat; additional seats reach the installation on their own
  • Entitlement confirmation: a signed activation response is valid for a limited time, warnings by email and in the feed, a database fingerprint tells a clone from a replica
  • Temporary account suspension instead of irreversible deletion; changing a group member role in a single action
  • Discussions, packages and versions are read page by page with infinite scroll; branch selection searches on the server
  • Large files (packages, release attachments, backups, LFS) are streamed instead of being read into memory in full
  • Sign-in and permission security: token scope checks on every write operation and on push/LFS, removal of privilege escalation via a stale token, password checks against breach lists, encryption of LDAP and SMTP passwords in the database
  • The API documentation works without internet access; the licence agreement text is served from the distribution rather than from the vendor site
  • Upgrading from 1.0.0: issue and pull request comments, packages and aggregate quota lists are returned as pages instead of arrays
  • Upgrading from 1.0.0: an unknown field in an /api/v1 request body is rejected (400 validation) instead of being dropped silently
  • Upgrading from 1.0.0: GITRIVER_RATE_LIMIT_DISABLED no longer applies - it is replaced by rate_limit_exempt_cidrs listing the exempt addresses
  • A single 67 MB Rust binary, 46 MB memory at idle, 34 crates, 585 /api/v1 calls

v1.0.0

major03/29/2026
  • Git hosting (HTTP + SSH, LFS, GPG, web editor, batch commit)
  • Pull Requests with Code Review, CODEOWNERS, and comment threads
  • Merge Queue with CI integration and temporary branches
  • Issues with Kanban boards, milestones, and templates
  • CI/CD (YAML, DAG, matrix, artifacts, cache, retry, Web Terminal)
  • Remote Runners + Kubernetes Auto-Scaling
  • Container Registry (OCI v2, multi-arch, retention policies, GC)
  • Package Registry (npm, PyPI, Cargo, Maven, NuGet, Generic)
  • GitOps Deploy RiverCD (canary, blue-green, drift detection, sync waves)
  • Notifications - 8 channels: Email, Telegram, Slack, Discord, Teams, Matrix, Webhook, In-app
  • Security: Secret Scanning (17 + custom regex), SARIF, DORA Metrics
  • License Compliance (SPDX, CycloneDX SBOM)
  • Authentication: OAuth2, SAML 2.0, SCIM 2.0, LDAP, 2FA (TOTP)
  • Custom Roles, IP Rules, Storage Quotas
  • Backup & Restore (AES-256-GCM, incremental, S3)
  • Static Sites (Pages) and Wiki
  • Releases with binary artifacts
  • Import from GitHub, GitLab, Bitbucket + mirroring
  • REST API (500+ endpoints) with OpenAPI 3.1
  • Audit Log (logins, impersonation, permission changes, licenses)
  • Webhooks (HMAC-SHA256, retry with backoff, delivery history, SSRF protection)
  • Branch Protection (patterns, required reviews, CI checks, signed commits)
  • Setup Wizard on first launch
  • Licensing (Ed25519, Pro Seats, Heartbeat)
  • Instance Branding (name, logo, CSS, footer)
  • Single Rust binary, ~100 MB RAM idle