NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2083 by repository stars
Last release 6 days ago
03 Oct 2026
Ships unpredictably
gaps range from 8 days to 6 months
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
340 releases · first in 2024
One column per month.
Nothing published for this version
修复 #482 : JWT_TOKEN_SECRET 缺省值为公开的 your-secret-key ,攻击者可据此伪造平台管理员 token。 空库首次启动会自动创建 k8m 平台管理员账户,因此仅修改默认密码无法阻止伪造; 一旦 JWT 密钥被知晓,伪造 token 在修改密码后依然有效。
修复 #482:JWT_TOKEN_SECRET 缺省值为公开的 your-secret-key,攻击者可据此伪造平台管理员 token。
空库首次启动会自动创建 k8m 平台管理员账户,因此仅修改默认密码无法阻止伪造;
一旦 JWT 密钥被知晓,伪造 token 在修改密码后依然有效。
改用服务端会话(Opaque Token)凭证
user_sessions 表与 TokenService:签发 256 位随机凭证(库中仅存 SHA-256 哈希);your-secret-key 一类公开默认值问题从机制上消失覆盖范围
/params/user/role 获取,移除 jwt-decode 依赖存量数据兼容(无需重新生成密钥)
启动时自动执行一次幂等迁移,把升级前已签发的密钥登记为服务端会话:
| 密钥类型 | 来源字段 | 有效期 |
|---|---|---|
| OpenAPI 密钥 | api_keys.key |
取 api_keys.expires_at |
| MCP 密钥 | mcp_keys.jwt |
签发时间 + 10 年(该表未存过期字段) |
迁移仅登记密钥表中确实存在的凭证,因此用公开默认密钥伪造的 JWT 依然无法通过校验。
--jwt-token-secret / 环境变量 JWT_TOKEN_SECRET 保留但不再生效,启动时会打印弃用提示;pkg/service/token_test.go:覆盖签发与校验、哈希不落明文、单条撤销、按用户全量撤销、非法有效期拒绝、伪造凭证拒绝。
Nothing published for this version
chore(deps): update frontend and backend dependencies to latest ( #481 ) @weibaohui
前端:vite 8(rolldown 内核)、antd 6、@ant-design/x 2、@ant-design/icons 6、@XTerm 6、monaco-editor 0.56、react-router-dom 7、fontawesome 7 及全部 minor/patch 更新
后端:Go 1.27.0、mcp-go 1.0.0、gorm 1.31.2、k8s.io 0.34.11 及 171 个传递依赖刷新
关键修复:
go:embed all:ui/dist:vite 8 共享 chunk 以 _ 开头,默认 embed 模式排除导致页面 404 白屏min/vs 目录布局扁平化,构建改为整目录拷贝contentRender、Sender suffix)有意不升级(上游阻塞,详见 PR #481):React 19(amis 6 使用 findDOMNode)、k8s.io ≥0.35(kom 依赖已移除的 kubectl API)、TypeScript 7(生态未跟上)
真实 k3s v1.34.4 集群端到端实测:Pod 终端(xterm 6 命令执行)、Pod 日志、YAML 编辑器(monaco 0.56)、AI 对话(x v2 Markdown 渲染)、18 个菜单页面遍历 0 崩溃
Full Changelog: v0.26.19...v0.26.20
🤖 Generated with Claude Code
Nothing published for this version
fix(ui): remove stray mobx-react-lite@^5.0.0 dependency causing blank page ( #480 ) @weibaohui
修复 v0.26.18 中打开页面白屏、无法登录的问题(#469):意外混入的 mobx-react-lite@^5.0.0 与 amis 的幽灵依赖冲突,导致模块加载时抛出 mobx-react-lite requires mobx at least version 7。已删除该无用依赖并实测验证(白屏复现 → 修复后登录页正常)。
Full Changelog: v0.26.18...v0.26.19
🤖 Generated with Claude Code
Nothing published for this version
ci(workflows): disable SLSA provenance to fix Aliyun registry push ( #478 ) @weibaohui
Nothing published for this version
What’s Changed 修复 界面 显示问题
修复 界面 显示问题
Nothing published for this version
Kubeconfig 导出插件 : 新增 kubeconfig_export 插件,支持为集群生成和导出 kubeconfig 文件,支持按命名空间和角色限制导出范围
kubeconfig_export 插件,支持为集群生成和导出 kubeconfig 文件,支持按命名空间和角色限制导出范围/admin/plugin/list API 新增分页支持,优化大量插件时的浏览体验Nothing published for this version
fix: 修复 Dependabot 安全漏洞 ( #451 ) @weibaohui
Nothing published for this version
fix: 支持通过MD5值解析集群ID ( #445 ) @weibaohui
Nothing published for this version
调整集群切换ID编码方式 ( #443 ) @weibaohui
Nothing published for this version
fix: 将DecodeBase64替换为UrlSafeBase64Decode以支持URL安全编码 ( #441 ) @weibaohui
Nothing published for this version
yaml编辑器新增使用ai生成yaml功能 ( #440 ) @weibaohui
Nothing published for this version
新增AI Log 智能解读功能 ( #438 ) @weibaohui
Nothing published for this version
修复 AI 描述功能的空指针异常错误 ( #437 ) @weibaohui
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →