Free Redmine plugin

SCM Creator for Redmine

Create local repositories, manage GitHub.com mirrors, or browse remote VCSAdmin Git repositories from Redmine project settings.

  • Git, Subversion, Mercurial, and Bazaar repository creation
  • GitHub.com creation, existing repository reuse, and local bare mirrors
  • Read-only VCSAdmin Git access without a local repository copy

Supported providers

Git
Subversion
Mercurial
Bazaar
GitHub.com with a local bare mirror
VCSAdmin Git through its read-only API

What SCM Creator does

SCM Creator provisions repository storage and registers it with a Redmine project. Users with Redmine's Manage repository permission work from the familiar project repository settings instead of asking an administrator to create every repository manually.

Version 2.3.5 adds the sanitized VCSAdmin repository name to synchronization error logs, making repeated API failures easier to attribute without exposing credentials. SCM Creator targets Redmine 6.0 and newer and is maintained by www.SaaS-Secure.com, S. Ruttloff as a modernized continuation of the original plugin by Andriy Lesyuk.

Free download

Current package: redmine_scm-2.3.5.tar.gz

GNU General Public License version 2.

Repository workflows

Create local repositories

Provision repository storage from Redmine project settings using installed SCM command-line tools.

  • Git, Subversion, Mercurial, and Bazaar
  • Configurable repository roots and displayed URLs
  • Optional creation during project creation

Manage GitHub.com mirrors

Create or reuse a GitHub.com repository and maintain the bare local mirror Redmine needs.

  • Public repositories can be mirrored without an API token
  • Repository-specific or environment-supplied tokens
  • Connection test, mirror health, size, and manual refresh

Protect credentials and hooks

Keep authentication out of stored remote URLs while verifying repository-specific webhook requests.

  • Tokens excluded from Git command arguments and logs
  • Signed GitHub push webhooks using HMAC SHA-256
  • Per-mirror locking prevents overlapping refreshes

Validate storage

Check repository roots and mirror targets before filesystem operations begin.

  • Writable-root and optional free-space checks
  • Managed paths restricted beneath configured roots
  • Safe cleanup after an incomplete new clone

Control repository policy

Choose how repository creation, registration, pickup, and deletion fit your Redmine deployment.

  • Creation limits and automatic creation modes
  • Optional lifecycle scripts
  • Managed deletion confirmation and path validation

Connect VCSAdmin Git

Browse a VCSAdmin Git repository through its read-only JSON API without creating a local clone.

  • One repository API URL plus Basic Authentication credentials
  • Tree, history, commits, branches, tags, text files, and diffs
  • Bounded default-branch changeset synchronization

SCM Creator user guide

Follow focused guides for deployment, repository providers, synchronization, and everyday source browsing in Redmine.

Getting started

Install the plugin, run migrations, configure scm.yml, and enable providers.

Installation guide

Local and GitHub

Create managed local repositories or connect credential-safe GitHub.com mirrors.

Provider guides

VCSAdmin Git

Connect a read-only API repository and understand bounded changeset synchronization.

VCSAdmin guide

Browse source

Navigate trees, read text files, inspect commit metadata, and review unified diffs.

Browsing guide

Installation and setup

Install the plugin

Extract the archive so the plugin directory is plugins/redmine_scm, then run the commands from the Redmine root.

tar -xzf redmine_scm-2.3.5.tar.gz -C plugins
bundle install
bundle exec rake redmine:plugins:migrate RAILS_ENV=production

Version 2.3.5 adds no database migration when upgrading from 2.3.4. When upgrading from a release before 2.3, run the migration for the VCSAdmin synchronization lock table. Copy plugins/redmine_scm/config/scm.yml to config/scm.yml, adapt the enabled providers, and restart every Redmine web and background process.

Requirements

  • Redmine 6.0 or newer
  • Command-line client for every enabled local SCM
  • Repository roots writable by the Redmine process
  • Octokit 10 for GitHub.com support
  • Reachable VCSAdmin API v1 endpoint for VCSAdmin Git
  • Redmine database encryption configured before storing repository credentials

GitHub.com configuration

Configure the mirror provider

Keep production tokens in environment variables and reference them from Redmine's config/scm.yml.

production:
  github:
    path: /var/lib/redmine/github_mirrors
    minimum_free_space_mb: 1024
    clone_protocol: ssh
    api:
      token: <%= ENV['REDMINE_SCM_GITHUB_API_TOKEN'] %>
      organization: <%= ENV['REDMINE_SCM_GITHUB_ORGANIZATION'] %>
      register_hook: true

Important boundaries

  • GitHub.com is supported; GitLab requires a separate adapter
  • Deleting a GitHub repository in Redmine removes only the local mirror and Redmine registration
  • Large mirror creation runs synchronously and can take time
  • The plugin creates repositories but does not publish them over HTTP, SSH, or Subversion DAV

VCSAdmin Git configuration

Connect one remote repository

Enable VcsadminGit in Redmine, then add the complete repository-detail API URL and its Basic Authentication credentials in the project repository settings.

https://vcsadmin.example/api/v1/scm/repositories/123

SCM Creator extracts the stable repository ID, stores the normalized API base URL, and validates that exact repository. No separate repository list or selector is required.

Remote and read-only

  • No local Git clone, mirror, checkout, or command execution
  • Credentials use Redmine's encrypted repository password storage
  • Connection tests require Manage repository permission
  • API v1 does not provide blame, archives, statistics, or write access

Available downloads

Current version 2.3.5

Recommended release for Redmine 6.0 and 6.1 installations using local repository creation, GitHub.com mirrors, or VCSAdmin Git.

  • Archive: redmine_scm-2.3.5.tar.gz
  • Supports Redmine 6.0 and 6.1
  • Logs the sanitized VCSAdmin repository name with API failures
Download 2.3.5

Previous release and history

Versions 2.3.4, 2.3.3 and 2.2.1 remain available for existing deployments. New installations and upgrades should use 2.3.5.

Plugin changelog

Version 2.3.5 makes scheduled VCSAdmin failures easier to identify by logging the sanitized repository display name together with stable IDs and request details.

Current version 2.3.5

Version 2.3.5

VCSAdmin API error logs now identify the affected repository clearly without exposing credentials.

  • Adds the sanitized remote repository display name
  • Retains the stable numeric remote repository ID and request ID
  • Requires no database migration from version 2.3.4

Version 2.3.4

Managed local repositories can now be removed reliably when provider roots are world writable or repository files have another owner.

  • Keeps direct-child path validation in place
  • Stops the Redmine record deletion if filesystem cleanup is incomplete
  • Requires no database migration from version 2.3.3

Version 2.3.3

The VCSAdmin Git setup now focuses on the repository an administrator wants to connect.

  • Uses one complete repository-detail API URL
  • Removes the redundant repository list and selector
  • Tests and validates the identified repository directly

Version 2.3.0

Introduced the guarded VCSAdmin Git connector without local repository storage or Git commands.

  • Tree, history, commit, branch, tag, text file, and diff views
  • Bounded changeset import with cursor persistence and deduplication
  • Timeout, TLS, redirect, response-size, and capability safeguards

Version 2.2.x

GitHub mirror security and operations were hardened, with licensing and attribution restored.

  • Credential-safe Git execution and signed webhooks
  • Mirror path, capacity, cleanup, health, and locking checks
  • GPL v2 license, original authorship, and contributor credits

Versions 2.0–2.1

SCM Creator was updated for the current Redmine repository architecture.

  • Redmine 6 and Rails 7 loading, callbacks, forms, and helpers
  • Safe YAML configuration and managed filesystem paths
  • Octokit 10 and current GitHub token authentication

Download SCM Creator 2.3.5

Manage local repositories, GitHub.com mirrors, and read-only VCSAdmin Git access from Redmine 6 while keeping credentials and permissions under administrator control.

Download tar.gz