All notable changes, new features, security updates, and bug fixes will be documented in this file. The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
CHANGELOG
Changelog
Explore the evolution and iterations of every GETSSH release.
[3.0.0-preview] - Upcoming Release (2026-10-10)
๐ 3.0 Next-Gen Architecture, ENDLESS UI & Deep Overhaul Preview
Release Strategy & Public Testing Roadmap Note:
The 3.0 PREVIEW stage will exclusively offer the FUSION edition (the first four major roadmap featuresโAI Ops Copilot, Isolated Workspaces, PLUGIN 2.0 ecosystem, and Fleet Ops & DB Tunnelsโare all completed in 3.0 and available for early testing).
The 3.0 PREVIEW public testing will actively run and iterate through the end of this year, culminating in the 3.0.0 Official Release (which will simultaneously launch FUSION STABLE and LITE STABLE). Continuous high-frequency iterations will proceed throughout the preview period, bringing even more capabilities to the 3.0.0 stable release.
- Deep Architectural Overhaul & 120+ Bugs / Vulnerabilities Fixed: We methodically combed through and deeply explored the entire software architecture, resolving approximately 120+ bugs and vulnerabilities. The codebase underwent an almost complete architectural reconstruction from the ground up, bringing an unprecedented leap in system resilience and fault tolerance.
- Brand-New ENDLESS UI (Your All-New Server DASHBOARD):
- The entire interface transitions to the new ENDLESS UI design language: cleaner, more intuitive, significantly faster, and deeply attuned to your operational workflow.
- Transcending traditional terminal boundaries, ENDLESS UI integrates global host inventory, real-time node telemetry, multi-pane splitting, and automated workflows into your comprehensive Server DASHBOARD.
- PLUGIN 2.0 Substantial Architecture Rebuild:
- The plugin ecosystem has been completely re-architected into PLUGIN 2.0.
- Engineered with an ultra-low-latency inter-process bus, new plugin lifecycle primitives, hardened isolation sandboxes, and modern UI extension slotsโmaking custom extensions snappier, safer, and zero-trust compliant.
- AI ENVIRONMENT Comprehensive Reconstruction:
- Rebuilt the entire AI execution environment tailored for mission-critical infrastructure operations.
- Revamped model protocol adapters, context orchestration state machines, and reasoning-chain isolation to deliver reliable Function Calling and multi-step Agent problem-solving.
- Deeply wired MCP protocols and local/remote environment probes directly into the runtime for robust, hallucination-resistant Ops Copilot execution.
- Decoupled AI Ops Copilot: Native BYOK model integration providing incident root-cause diagnosis and reviewable diff patches, with destructive actions strictly gated by human confirmation.
- Brand New Nexus Core Multiplexing Engine: Native event loop scheduling drives input-to-render latency under 5ms, ensuring fluid 60fps rendering even during high-burst log output.
- Dynamic Backpressure & Circular Ring Buffer: Bounded memory footprint during high-throughput log streams, eliminating memory leaks and UI freezes.
- Native Dual-Pane Streaming SFTP Drawer: Integrated visual file manager with drag-and-drop transfers, resumable uploads, and remote editingโcompletely free out of the box.
- Hardware Secure Enclave Integration: Private keys and host credentials bind directly to macOS Keychain / Linux Secret Service with hardware AES-256-GCM encryption, running 100% offline and air-gapped.
[2.0.0] (Build R7K4S) - 2026-05-28 โ 2026-06-04
๐ฆ Four-Zone Rust Native Core Refactoring โ 100% Complete
This is a monumental Preview release marking the complete Rust-ification of GETSSH's performance-critical code paths. All four security & performance zones have been fully migrated from Node.js/V8 to Rust N-API native extensions, making GETSSH one of the most security-hardened Electron SSH clients in existence.
๐ฆ Zone 1: Watchdog Process Guardian
- Rust Standalone Daemon:
rust-core/watchdogis a fully independent Rust binary that runs outside the Electron main process, communicating via Unix Domain Sockets (macOS/Linux) and Named Pipes (Windows). - 60-Second Physical Kill: If the Watchdog receives no heartbeat within 60 seconds (e.g., the process is frozen or injected), it issues a physical-level
SIGKILLagainst the parent process via OS APIs and displays a desktop notification, preventing the app from running in a hijacked state. - SAFE MODE Awareness: If the main process boots in SAFE MODE (post-crash recovery), the Watchdog automatically enters silent mode and will not trigger the kill sequence.
- Production Path Bridging: Full
app.isPackageddual-path resolution ensures the Watchdog binary is accurately located in both development and packaged production environments.
๐ฆ Zone 2: Vault Local Credential Encryption Engine
getssh-vaultN-API Extension: Rust encryption logic compiled into a.nodenative extension via@napi-rs, loaded directly by the Electron main process.- AES-256-GCM Hardware-Grade Encryption: Uses the Rust
aes-gcmcrate to perform physical-level encryption and decryption of localprofiles.enc, eliminating potential vulnerabilities in Node.js'scryptomodule. - Master Password + Biometric Dual Gate:
cryptoHandler.tsintegrates full master password validation andsystemPreferences.promptTouchIDbiometric authentication.
๐ฆ Zone 3: Sysprobe System Metrics Probe
getssh-sysprobeN-API Extension: Uses Rust'ssysinfocrate to collect CPU, memory, network, and disk metrics directly at the OS level.- Eliminated
node:osDependency: EndedsystemHandler.ts's reliance onnode:ospolling. System metrics no longer pass through the V8 string serialization layer โ throughput efficiency is massively improved with zero UI jank.
๐ฆ Zone 4: Hybrid SFTP Engine
sftp-streamZero-Copy N-API Engine:rust-core/sftp-streamtakes over the heaviest disk I/O during file uploads and downloads.- Node-Rust Pipeline Bridge: Network
Bufferdata fromssh2is consumed directly in Rust and streamed to disk, completely bypassing V8 string parsing โ a true "Node handles networking, Rust handles heavy I/O" dual-engine architecture. - Large File Download Confirmation: Before initiating a pure-download, the user is shown the file's size and must confirm, preventing accidental downloads of large files.
๐ฅ Exterminating the adm-zip Memory Tumor (getssh-unarchive)
- New
getssh-unarchiveRust N-API Extension: Completely replaces the pure-JSadm-ziplibrary inPluginManager.ts, whose full in-memory approach was a time-bomb OOM waiting to detonate. - Zero-Copy Streaming Extraction: Uses Rust's
zipcrate andstd::io::copyto stream files from archives directly to disk, never touching JavaScript/V8 heap memory. Memory peak stays under 10MB regardless of archive size. - Military-Grade Zip Slip Defense: Every archive entry path is rigorously validated in Rust. If any path traversal sequence (
../) or absolute root prefix is detected, the extraction immediately trips a circuit breaker, physically destroys all already-extracted debris files, and throws a hard error โ completely sealing the Zip Slip attack vector. tokioAsync Non-Blocking Extraction: Extraction runs insidetokio::task::spawn_blocking, keeping the Electron main process and renderer completely responsive throughout.
๐ฆ Cross-Platform Production Packaging
- ASAR Physical Ejection: Added
"asarUnpack": ["**/*.node"]toelectron-builderconfig, ensuring all Rust N-API native extensions are ejected from theapp.asarvirtual filesystem into the physicalapp.asar.unpackeddirectory, permanently eliminating dynamic library loading failures in packaged builds. - Watchdog Binary Injection:
extraResourcesconfig ensures the pre-compiledwatchdogbinary is injected verbatim into the final package'sresourcesdirectory. - macOS Hardened Runtime & Signing Prep: Enabled
hardenedRuntime: trueand createdbuild/entitlements.mac.plistwithcom.apple.security.cs.allow-unsigned-executable-memory(V8 JIT compatibility) andcom.apple.security.cs.disable-library-validation(allows loading self-compiled Rust.nodeextensions), perfectly circumventing macOS 10.15+ Gatekeeper crashes. - Dependency Cleanup: Completely removed
adm-zipand@types/adm-zipfrom the project root, further purifying the dependency tree.
๐ Plugin SDK v2.0 โ Full Security Sandbox Deployment
ctx.net.fetchNetwork Bridge: Safely injectedctx.net.fetch(url, options)into the backend plugin Node VM sandbox Context. Plugins must explicitly declare"net:fetch"in theirpackage.jsoncapabilitiesarray โ any undeclared call is immediately blocked with aSecurityError.- Ultimate SSRF Defense Wall: The underlying fetch interceptor enforces strict DNS/regex dual defense, absolutely blocking any requests to loopback addresses (
127.0.0.1,localhost,0.0.0.0) and private IP ranges (192.168.x.x,10.x.x.x,172.16.x.x). ctx.ui.registerSettingsNo-Code Settings Form: Injected a schema registration API into the controlledctx.uinamespace. Backend plugins can register typed config schemas (string,number,boolean,password) duringactivate. The main process syncs schemas to the frontend Zustand Store viasync-plugin-settings-schemaIPC, dynamically rendering host-styled form components in a dedicated "Plugin Settings" tab inSettings.tsxโ with live hot-reload on schema updates.ctx.host.clipboardAudited Clipboard Access: Injectedclipboard.writeTextandclipboard.readTextinto the controlledctx.hostnamespace, bridging directly to Electron's nativeclipboardmodule. AnyreadTextcall forces an OS-native notification (containing the plugin name) to prevent silent data exfiltration, alongside a full audit log in the main process.window.GETSSH.registerPanel/openPanelImmersive Panel Views: Exposed panel registration and open APIs to frontend plugins via the preload script. AddedPluginPanelTabroute type tosessionStore.tsand introduced<webview>sandboxed full-screen rendering in theSessionManager.tsxrender tree โ enabling plugins to take over the entire main workspace view from the sidebar.
๐๏ธ Infrastructure Overhaul Phase 1: React 19 Core Engine Hot-Swap
A landmark milestone for GETSSH's technology stack modernization. We have fully migrated the frontend runtime from React 18 to React 19, adopting all new concurrent rendering features and upgrading the UI component library and type system to ensure every future feature ships on the most cutting-edge foundation possible.
โ๏ธ React 19 Core Migration
- Full React 19.0.0 Upgrade:
react,react-dom,@types/react, and@types/react-domall promoted to19.0.0+. The application now runs entirely on the React 19 concurrent rendering model. forwardRefRemoval Pre-check: A global codebase scan confirmed zeroReact.forwardRefwrappers remain โ the project naturally adapts to React 19's native ref-as-prop paradigm with no migration work required.- Entry File Compliance Verified: Confirmed
main.tsxusesReactDOM.createRoot, fully compliant with React 19's mandatory API. No legacyReactDOM.rendercalls remain. - React 19 Strict Type Tightening Fix: Fixed a
useRef<NodeJS.Timeout>()error inConnectForm.tsxtriggered by React 19's stricter generic inference rules. Updated to the canonicaluseRef<NodeJS.Timeout | null>(null)form. - Lucide React Latest Upgrade: Upgraded
lucide-reactto the latest version. All icon import names were validated for compatibility with the new API spec โ zero naming conflicts or deprecation warnings. @testing-library/reactReact 19 Alignment: Simultaneously upgraded the testing library to the latest version, ensuring full API compatibility with React 19.
๐งน Physical Dependency Purge & Tree Rebuild
- Ghost Dependency Extermination: Completely destroyed the mixed
node_modulesdirectory and cross-contaminatedpackage-lock.json, then executednpm cache clean --forceto purge OS-level NPM cache โ eliminating every last React 18 fragment from the root. - Critical
pnpm node-linker=hoistedFix: Diagnosed and resolved a critical runtime crash caused bypnpm's default symlink storage strategy conflicting with Electron's CJS nativerequirehook. Thessh2internal dependency path resolution was failing (Cannot find module './constants.js'). Enforcingnode-linker=hoistedin.npmrcforcespnpmto physically hoist packages, perfectly resolving native CJS module path resolution in Electron. - Clean Dependency Tree Sealed: Ran a fresh
pnpm installfrom the finalizedpackage.json, completing the pure rebuild and sealing the dependency ecosystem.
๐ช๏ธ Infrastructure Overhaul Phase 2: Tailwind CSS v4 & Vite 8 Upgrade
- Tailwind v4 Engine Upgrade: Upgraded from Tailwind CSS v3 to v4. Eliminated the bulky
tailwind.config.jsand transitioned to pure CSS configuration via@import "tailwindcss";and@themeblocks, unleashing the next-generation lightning-fast styling engine. - Vite 8 Integration: Elevated the build toolchain to Vite 8.0, migrating flawlessly to the new
@tailwindcss/viteplugin andvite.config.mtsconfiguration format, achieving extreme development server boot speeds.
๐ Infrastructure Overhaul Phase 3: Electron 42 & Node 22 Ultimate Leap
- Next-Gen Electron Kernel: Upgraded the core framework from the legacy Electron 32 branch directly to the bleeding-edge Electron 42.3.0.
- Node 22 Backend Environment: Upgraded native backend types to Node 22, unlocking the latest V8 features and robust security patches.
- IPC API Modernization: Remapped and resolved deprecation warnings introduced by Electron 42, ensuring window frame controls, system event listeners, and inter-process communications remain perfectly intact.
๐ Xterm.js Architecture Cleanup & Hardening
- N-API PTY Resurrection: Completely eradicated the obsolete
@homebridge/node-pty-prebuilt-multiarchbranch and returned to the officialnode-ptymainstream, directly leveraging N-API prebuilds for maximum stability. - Unified Xterm Ecosystem: Scanned and wiped all legacy
xterm-addon-*stray dependencies. Standardized the entire terminal rendering engine on the official@xterm/namespace (e.g.,@xterm/addon-fit,@xterm/addon-search,@xterm/addon-webgl,@xterm/addon-canvas). - WebGL/Canvas Failover: Forged an intelligent rendering failover mechanism in
Terminal.tsx. The terminal automatically attempts high-performance WebGL rendering, and elegantly falls back to Canvas on context loss or unsupported transparent environments.
๐ก๏ธ TypeScript 6.0 Strict Defense
- ES2023 Target Enforced: Elevated the global TypeScript target and module system to
ESNext/ES2023, enforcing strict module resolution withisolatedModulesandallowImportingTsExtensions. - Zero-Tolerance Type Checks: Fixed implicit
anyleaks insftpHandler.tsnative callbacks, and cemented critical null pointer exceptions incryptoHandler.ts(Rust N-API decryption boundary) andsshHandler.ts(Proxy connection fallback), achieving absolute zero compiler errors understrict: true.
๐ก๏ธ Full Codebase Security Audit & Bug Fixes
- IPC Path Traversal Sealed: Implemented strict file path boundary validation on the
getssh-plugin://custom protocol handler inelectron/main/index.ts, intercepting../../backtracking attacks and ensuring plugins can only read assets within their authorized directory. - Plugin Arbitrary Install Path Vulnerability Fixed: Added OS-level temp directory legitimacy checks to the plugin install commit path in
PluginManager.ts, blocking unauthorized directory tampering. - SFTP Write Privilege Escalation Defense: Enforced write path locking in the
sftpHandler.tsdownload interface to only allow writes withinDownloadsorDesktopdirectories, preventing malicious plugins from injecting auto-start trojans via the SFTP bridge. - TypeScript Zero-Error Seal: Systematically cleared 70+ legacy TypeScript type errors across
src/types.d.ts(completing missingelectronAPIinterface definitions),LeafPane.tsx,PluginPane.tsx,TerminalPane.tsx,SplitPane.tsx,App.tsx, and more core components โ achieving a confirmed zero-errornpx tsc --noEmitoutput.
๐ฆ "Small & Beautiful" DMG Ultimate Compression
- Locale Eradication: Injected
electronLanguages: ["en-US", "zh-CN"]into theelectron-builderconfig, surgically slicing away over 50 unnecessary.pakand.lprojlanguage binaries from the Electron Framework. - Pure JS Tree-Shaking: Transferred pure JavaScript node modules (
dompurify,p-limit,socks,http-proxy-agent) todevDependencies. The Vite/esbuild bundler now absorbs them natively into the finalindex.js, permanently banishing thousands of disjointed files fromapp.asar. - N-API Dev Bloat Excluded: Excluded
rust-core/**/node_modules/**from the packaging scope, preventing ~17MB of useless@napi-rscompile-time binaries from leaking into the production app. - Result: The fully compressed ARM64
.dmgsize plunged to a historical 101 MB โ practically the physical limit for a full-scale Electron 42 environment.
๐ Security & Lock UX Improvements
- CommandCenter One-Tap Lock Button: Added a "Lock Profile" button to the WelcomePane command center. Users can now manually trigger a lock at any time without waiting for the timeout timer.
- Smart Disabled State: When no master password is set, the "Lock Profile" button is automatically grayed out with a tooltip guiding the user to configure their security settings.
- CryptoModal Full i18n: The lock and unlock screens in
CryptoModalnow fully integratereact-i18next, supporting seamless Chinese/English switching with zero hardcoded English strings remaining. - Gaussian Blur Privacy Shield on Lock: When the lock screen is triggered, the background is immediately overlaid with a 40px-strength Gaussian blur (applied via inline styles to reliably bypass Tailwind JIT thermal behavior), protecting sensitive server information from bystander view.
- Global Crypto State (Single Source of Truth):
cryptoMode,masterPassword, and related state have been migrated fromApp.tsxlocal state into theuseCryptoStoreZustand global store, ensuring all UI components (CommandCenter, CryptoModal) share a consistent, real-time view of authentication state.
[1.3.1] (Build K9V2X) - 2026-05-21
๐ The First Multi-Protocol Era
This release marks a historic milestone for GETSSH, evolving from a standard SSH client into a full-spectrum multi-protocol terminal platform. We have pioneered a Smart Protocol Detection engine that drastically lowers the learning curve for beginners. Simply type intuitively (like entering localhost), and the system magically sniffs your intent, automatically routing and binding the correct underlying protocol instantly!
๐ ๏ธ Native PTY & Multi-Protocol Routing
- Native Local Shell (PTY) Integration: We completely abandoned the pseudo-local approach of forcing SSH loops over
::1. A brand newptyHandler.tsnative process gateway has been developed, directly spawning OS-native Bash / Zsh / PowerShell within the Electron Node process. This permanently eliminates the notoriousconnect ECONNREFUSED ::1:22errors, granting you zero-latency, full-privileged local terminal access. - Schema Persistence Hotfix: Deeply patched a critical vulnerability in
profileHandler.tswhere theprotocolparameter was lost during profile serialization. All protocol preferences (SSH, Local, Telnet) are now meticulously preserved across application restarts. - Smart Protocol Lock for New Sessions: Completely overhauled the auto-detection engine in
ConnectForm.tsx. Protocol auto-switching (e.g., typinglocalhostto switch to Local) now exclusively triggers for "unsaved new sessions". Once saved, the protocol is permanently locked, preventing catastrophic protocol overwrites when editing hostnames. - 100% Protocol State Binding: Fixed an issue where rapidly switching between hosts with different protocols in the sidebar failed to visually update the form UI and highlight states.
๐จ Obsidian Aesthetics & Layout Optimization
- Monochrome Geek Filter & Active Awakening: Forced a cool, desaturated filter (
filter saturate-0) on all OS icons (Ubuntu, Windows, Debian, etc.) in the sidebar by default, allowing them to perfectly stealth into the deep Obsidian UI. When a host is connected, the system immediately "breaks the seal", injecting the high-saturation original brand colors (saturate-100 opacity-90) as a striking visual reward. - Shrink-Proof Framework Reinforcement: Forged a cool-grey, right-angled exclusive border (
bg-black/20 border border-black/30 rounded-none) for the OS badges, strictly injecting theshrink-0gene. Even with ridiculously long server names, the system badges remain rigid and immune to any distortion. - Command Center (WelcomePane) Alias Escalation: Refactored the rendering logic for startup cards. The WelcomePane no longer displays cold IP addresses; instead, it strictly prioritizes displaying your carefully crafted Aliases, making the management of hundreds of servers vastly more intuitive.
- Physical Sidebar Expansion: Heeding the calls of our DevOps power users, we physically widened the left host list panel by 25%. This grants enterprise-grade server naming conventions much more breathing room, drastically reducing text overflow truncation.
โ๏ธ Background Updater Engine Refactoring
- Hardcore Regex SemVer Extraction: Completely scrapped the fragile
split('.')string slicing approach in the updater module. The newly introduced regex enginev.match(/(\d+)\.(\d+)\.(\d+)/)easily bypasses noise likeV.prefixes or_K9V2Xsuffixes, surgically extracting the core semantic version. - IPC Payload Alignment: Fixed a deceptive bug where clicking "Check for Updates" in Settings always claimed "Already the latest version". The backend now strictly adheres to the
{ hasUpdate, version, url }data schema when transmitting detection reports via IPC, accurately triggering new version discovery modals.
๐ i18n Completion & Hidden Hotfixes
- Complete Settings Panel Localization: Eliminated all remaining hardcoded English fragments across the "Settings - Terminal" and "Settings - About" panels.
- Auto-Start Proxy Dispatch: Patched a hidden flaw where enabling Auto-Start dropped the
proxyPortparameter, causing proxy configurations to fail during silent boot. - Anti-Tampering Tag Injection: Restored the missing semantic version
v1.3.1in the About panel, pairing it with the build codeK9V2Xto construct an impenetrable version tracking wall.
[1.2.1] - 2026-05-05
๐ Architecture Refactoring & Productivity Leap
- Extreme Main Process Modularization:
- Dismantled the bloated
electron/main/index.ts(reduced from ~700 to ~250 lines). - Abstracted
ConnectionManager,sshHandler,sftpHandler, andcryptoHandlerinto independent modules.
- Dismantled the bloated
- Comprehensive SFTP Completion:
- Native Creation Support: Added "New File" and "New Folder" functions using native React Modals instead of system Prompts.
- Address Bar Navigation: Address bar now supports click-to-edit absolute path jumps.
- Symlink Support: Fixed SFTP symbolic link icon rendering and traversal.
- Silent Updates & Notifications:
- Implemented a fully automated background version checker. New updates trigger a red badge in the sidebar and a lightweight Toast notification.
- Optimized regex for seamless GitHub API
V-prefix parsing.
๐ Bug Fixes
- SFTP Directory Parsing: Fixed file list rendering failures on Oracle Cloud Ubuntu instances.
- Symlink Support: Fixed navigation into symbolic link directories.
- Update Algorithm Correction: Fixed
compareSemVerlogic handling GitHub tag case-sensitivity. - Interaction Deadlocks: Replaced macOS-hanging
window.promptcalls with controlled React Modals. - Connection Stability: Improved SSH heartbeat mechanics for shaky network environments.
[1.2.0] - 2026-05-03
๐ Production Ready
This is the most critical milestone in GETSSH history. We have reached the pinnacle of aesthetic design, while significantly upgrading the kernel architecture, security, and production bundle size.
โก Core Performance & I/O Revolution
- Fully Asynchronous File System:
- Completed
PluginManagerrefactoring from synchronous blockingfsto asynchronousfs.promises. - Install/Uninstall Boost: Eliminated UI freezing during massive plugin operations.
- Completed
- Auto-Start Logic Fix:
- Fixed ignoring session-specific ports on startup.
โ ๏ธ State Modernization
- Zustand Full Migration (Single Source of Truth):
- Migrated
App.tsxfromuseStateto a global Zustand state tree. - Eliminated "State Islands", guaranteeing real-time consistency across Tabs, Sessions, and Configs.
- Migrated
- Zero-Loss Terminal Persistence:
- Adopted a "CSS Persistent Mount" strategy, keeping terminal DOM instances alive across page routing.
๐ Ironclad Security Hardening
- Zip Slip & Path Traversal Prevention: Retained strict boundary checks in asynchronous I/O modes.
- SVG XSS Filtering: Deep-scanned plugin icons using
DOMParserto intercept XSS vectors. - Iframe Sandbox Isolation: Stripped
allow-same-originfrom plugin runtimes for physical API isolation.
๐ฆ Bundling & Size Optimization
- Magic Bundle Shrink: Reduced macOS size from ~450MB to ~83MB.
- Extreme Compression: Applied
maximumlevel ASAR compression.
[1.1.0] - 2026-04-20
โจ Features
- Multilingual System (i18n): Introduced full i18n support.
- Enhanced SFTP: Added drag-and-drop uploads, real-time renaming, and chmod support.
- Auto-Start: Start specific SSH tunnels automatically on app launch.
[1.0.0] - 2026-04-10
โจ Initial Release
- Core SSH Engine: Based on xterm.js and ssh2.
- SafeStorage: AES-256 local credential encryption using Master Password.
- Responsive UI: Dynamic Dark/Light mode switching.
"From monoliths to secure sandboxes, GETSSH is dedicated to building the most hardcore productivity tools."