Releases: JuanP-G/MC-ServerLauncher
Release list
MC Server Launcher 1.8.2 — Seguridad / Security
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
Tres correcciones de seguridad. No tienes que hacer nada: basta con actualizar.
- Tu clave de Playit deja de estar expuesta. La app se molesta en guardarla cifrada en disco… y acto seguido se la entregaba al sistema en claro, como parte de la línea de comandos del agente. Eso es visible para todo el equipo: en Linux
/proc/<pid>/cmdlinelo puede leer cualquier usuario, y en Windows cualquier proceso tuyo lo saca por WMI; además las líneas de comandos son justo lo que registran y mandan fuera los antivirus y los sistemas de auditoría. Ahora se le pasa al agente en un fichero privado (permisos0600en Linux y macOS) que se borra en cuanto el agente para. - El Java descargado ya no se instala nunca sin comprobar. La verificación dependía de que Adoptium incluyese el checksum en su respuesta; si no lo incluía, la app descargaba, descomprimía y ejecutaba un Java sin comprobar nada. Era el único binario que la app ejecuta cuya verificación era opcional. Ahora, sin checksum no hay instalación.
- El enlace de actualización se valida. El enlace de «hay una versión nueva» viene de la API de GitHub y se abría sin pasar por la validación que la app ya tenía para el resto de enlaces.
🇬🇧 What's new
Three security fixes. You don't have to do anything: just update.
- Your Playit key is no longer exposed. The app goes to the trouble of storing it encrypted on disk… and then handed it to the system in the clear, as part of the agent's command line. That is visible to the whole machine: on Linux any user can read
/proc/<pid>/cmdline, and on Windows any process of yours can pull it out through WMI — and command lines are exactly what antivirus and audit systems record and ship elsewhere. It is now handed to the agent in a private file (0600permissions on Linux and macOS) that is deleted as soon as the agent stops. - The downloaded Java is never installed unchecked. Verification depended on Adoptium including the checksum in its response; if it didn't, the app downloaded, unpacked and ran a Java that nothing had verified. It was the only binary the app executes whose verification was optional. Now, no checksum means no install.
- The update link is validated. The "a new version is available" link comes from GitHub's API and was opened without going through the validation the app already had for every other link.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.8.2.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.8.1 — Correcciones / Fixes
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
Correcciones sobre la 1.8.0. Recomendada para todo el mundo: una de ellas podía dejarte sin el archivo de arranque del servidor.
- Una descarga cortada ya no destruye lo que tenías. El archivo de destino se vaciaba antes de saber si la descarga iba a salir bien, así que un corte de red a mitad rompía lo que había. En Fabric era peor: como el jar descargado se comprueba y se borra si no pasa la comprobación, cambiar la versión del loader con mala conexión podía dejar el servidor sin jar con el que arrancar. Ahora todo se descarga aparte y solo sustituye al archivo bueno cuando está completo y verificado — servidores de Vanilla, Paper, Fabric y Forge, runtime de Java, mods y el propio instalador de actualizaciones.
- Los errores al instalar un mod ya se ven. Se mostraban en un sitio que solo aparece cuando la lista está vacía, justo cuando no puedes estar instalando nada, y en la ficha de un mod no se mostraban en ningún sitio. Un checksum que no cuadra, la red caída o un jar bloqueado por el servidor encendido fallaban en silencio absoluto. Ahora sale un aviso sobre la tienda y sobre la ficha: verde si ha ido bien, rojo si ha fallado.
- Las preferencias de la bandeja se guardan. Las dos opciones de minimizar y cerrar a la bandeja funcionaban durante la sesión pero volvían a su valor por defecto al reiniciar: nunca llegaban a escribirse en disco.
- Seguridad de la construcción. El AppImage de Linux se generaba con una herramienta descargada de una etiqueta móvil, sin verificar, dentro del mismo proceso que produce el binario que descargáis. Ahora la versión está fijada y se comprueba su SHA-256 antes de ejecutarla.
🇬🇧 What's new
Fixes on top of 1.8.0. Recommended for everyone: one of them could leave you without the server's startup file.
- A cut-off download no longer destroys what you had. The destination file was emptied before knowing whether the download would succeed, so a dropped connection halfway through broke what was there. Fabric had it worse: since the downloaded jar is checked and deleted if it fails that check, changing the loader version on a bad connection could leave the server with no jar to start from. Everything is now downloaded to one side and only replaces the good file once complete and verified — Vanilla, Paper, Fabric and Forge servers, the Java runtime, mods and the updater's own installer.
- Mod install errors are now visible. They were shown in a place that only appears when the list is empty — exactly when you can't be installing anything — and a mod's details page had nowhere to show them at all. A checksum that didn't match, a dropped connection or a jar locked by a running server all failed in complete silence. Now a banner appears over the store and over the details page: green if it worked, red if it failed.
- Tray preferences are saved. The two minimize/close-to-tray options worked during the session but reverted to their defaults on restart: they were never actually written to disk.
- Build security. The Linux AppImage was produced with a tool downloaded from a moving tag, unverified, inside the same job that produces the binary you download. Its version is now pinned and its SHA-256 checked before it runs.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.8.1.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.8.0 — La tienda de mods, entendible / The mod store, in plain language
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
El buscador de mods pasa a ser una tienda de verdad.
- Sabes qué hace cada mod antes de instalarlo. Cada resultado lleva un resumen en lenguaje claro y en tu idioma, no la descripción técnica del autor. Y si además hay que instalarlo en el cliente, te lo avisa ahí mismo.
- Ficha completa sin salir de la app — galería, versiones, dependencias, enlaces y mods relacionados. Instala la versión que quieras desde la propia ficha.
- Panel de filtros — elige varias categorías a la vez (los mods tienen que cumplirlas todas), ve cuáles tienes puestas y quítalas de una en una. Sustituye a la tira de etiquetas, donde la barra de desplazamiento se dibujaba encima de los propios chips y dejaba la mitad fuera de la pantalla.
- Al cambiar un filtro o la búsqueda, la lista vuelve al principio, porque son resultados nuevos. Al pulsar «Cargar más» o al volver de una ficha, se queda donde estabas.
- Más rápido y más limpio — caché en memoria, disco y API para iconos y datos; y dos clics seguidos en filtros distintos ya no mezclan los resultados de las dos búsquedas.
Las categorías se leen de un archivo de datos, así que se pueden ampliar sin tocar el código.
🇬🇧 What's new
The mod browser becomes a proper store.
- You know what each mod does before installing it. Every result carries a plain-language summary in your own language, not the author's technical blurb. And if it also has to be installed on the client, it says so right there.
- A full details page without leaving the app — gallery, versions, dependencies, links and related mods. Install whichever version you want from the page itself.
- Filters panel — pick several categories at once (mods have to match them all), see which ones are applied and remove them one by one. It replaces the tag strip, where the scrollbar was drawn on top of the very chips it was meant to scroll and left half of them off screen.
- Changing a filter or the search takes the list back to the top, because those are new results. Pressing "Load more" or coming back from a details page keeps your position.
- Faster and cleaner — memory, disk and API caching for icons and data; and two quick clicks on different filters no longer mix the results of both searches.
Categories are read from a data file, so they can be extended without touching the code.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.8.0.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.7.3 — Minimizar y cerrar, a tu gusto / Minimize and close, your way
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
Ahora eliges en Ajustes qué hacen los botones de la ventana, y el cambio se aplica al momento, sin reiniciar.
- Al minimizar, enviar a la bandeja (activado por defecto) — la ventana sale de la barra de tareas y la app queda como icono junto al reloj. Desactívalo y minimizar funciona de forma normal.
- Al cerrar (X), enviar a la bandeja en vez de salir (desactivado por defecto) — actívalo si prefieres que la X deje la app en segundo plano; entonces se sale con Salir desde el icono de la bandeja.
Con esas dos casillas puedes dejarlo como en la 1.7.2, recuperar el comportamiento de la 1.6.x o cualquier combinación. En escritorios sin bandeja del sistema (algunos Linux) ambas opciones se ignoran, para que la ventana no quede irrecuperable.
🇬🇧 What's new
You now choose in Settings what the window buttons do, and the change applies immediately, without restarting.
- Minimize sends the app to the tray (on by default) — the window leaves the taskbar and the app becomes the icon next to the clock. Turn it off and minimizing behaves normally.
- Closing (X) sends it to the tray instead of quitting (off by default) — turn it on if you'd rather the X leave the app in the background; you then quit with Quit from the tray icon.
With those two checkboxes you can keep it like 1.7.2, get the 1.6.x behaviour back, or any combination. On desktops with no system tray (some Linux setups) both options are ignored, so the window can never become unreachable.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.7.3.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.7.2 — Minimizar a la bandeja / Minimize to tray
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
- Minimizar manda la app a la bandeja del sistema: la ventana desaparece de la barra de tareas y la app sigue funcionando como icono junto al reloj, con los servidores corriendo.
- El botón de cerrar (X) vuelve a cerrar la aplicación de verdad, con la parada limpia de los servidores de siempre.
- Para recuperar la ventana: clic en el icono de la bandeja (o clic derecho → Mostrar). Clic derecho → Salir también cierra la app.
Esto invierte el comportamiento que introdujo la 1.6.0, donde minimizar mantenía la app en la barra y la X la mandaba a segundo plano.
🇬🇧 What's new
- Minimizing sends the app to the system tray: the window leaves the taskbar and the app lives on as the icon next to the clock, with the servers still running.
- The close (X) button really quits the app again, with the usual clean server shutdown.
- To bring the window back: click the tray icon (or right-click → Show). Right-click → Quit also closes the app.
This reverses the behaviour introduced in 1.6.0, where minimizing kept the app in the taskbar and the X sent it to the background.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.7.2.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.7.1 — Playit más seguro / Safer Playit
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
- Playit es más seguro: el agente oficial que descarga la app se verifica contra un SHA-256 fijado antes de ejecutarse, también cuando ya estaba en caché.
- El proxy de conexión de Playit rechaza ahora el tráfico fuera del flujo esperado, limita los intentos por IP y usa la misma versión del agente que descarga la app.
- Las notificaciones de muertes evitan más falsos positivos, y las preferencias por servidor se copian de forma independiente.
🇬🇧 What's new
- Playit is safer: the official agent the app downloads is verified against a pinned SHA-256 before it runs, including cached copies.
- The Playit connection proxy now rejects traffic outside the expected flow, rate-limits attempts per IP, and uses the same agent version the app downloads.
- Death notifications avoid more false positives, and per-server preferences are copied independently.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.7.1.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.7.0 — Playit fácil + notificaciones / Effortless Playit + notifications
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
- Abre tu servidor a Internet con Playit.gg, sin líos 🌐 — conecta tu cuenta pegando un código de configuración de un solo uso, sin claves ni archivos. La app crea el túnel y ejecuta el agente de Playit por ti, así tu servidor es accesible desde cualquier sitio y tus amigos entran con la dirección pública. No instalas nada, y la app no contiene ningún secreto propio (la credencial vive en un pequeño proxy).
- Estado de Playit claro en cada servidor — verás «Playit activo» en verde cuando el túnel está reenviando tráfico, y el motivo exacto si algo falla, con botón de reintento.
- Notificaciones configurables 🔔 — avisos cuando un jugador entra o sale, alguien muere en PvP, el servidor se cae o el reinicio automático se rinde. Por tipo, de forma global y por servidor, con botón de prueba.
- Ajustes en un solo sitio ⚙️ — idioma, notificaciones y tu conexión de Playit en un único diálogo.
Y todo lo de siempre: varios servidores a la vez, creación automática (tipo, versión, RAM, Java), buscador de mods y plugins de Modrinth, gestión de jugadores, editor visual de server.properties, backups automáticos del mundo y actualizaciones dentro de la app.
🇬🇧 What's new
- Open your server to the Internet with Playit.gg, the easy way 🌐 — connect your account by pasting a one-time setup code, no keys and no files. The app creates the tunnel and runs the Playit agent for you, so your server is reachable from anywhere and friends join with the public address. You install nothing, and the app ships no secret of its own (the credential lives in a small proxy).
- Clear Playit status per server — you'll see "Playit active" in green when the tunnel is forwarding traffic, and the exact reason if something fails, with a retry button.
- Configurable notifications 🔔 — pop-ups when a player joins or leaves, someone dies in PvP, the server crashes or auto-restart gives up. Per type, globally and per server, with a test button.
- Settings in one place ⚙️ — language, notifications and your Playit connection in a single dialog.
Plus everything you already had: multiple servers at once, automatic setup (type, version, RAM, Java), a Modrinth mods and plugins browser, player management, a visual server.properties editor, automatic world backups and in-app updates.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.7.0.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.6.3 — Rendimiento / Performance
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
Versión de rendimiento: cierra la revisión de eficiencia del código.
- Menos consumo en la bandeja: con la ventana oculta, los sondeos de estado (stats, Playit) corren a 1/10 de su ritmo habitual; las notificaciones y la detección de caídas van por eventos y no se ven afectadas. Todo vuelve a la velocidad normal al abrir la ventana.
- Playit compartido: con varios servidores, la consulta de túneles se hace una vez y se comparte entre todos (antes: una petición idéntica al API por servidor cada ~30 s). La clave del agente también se cachea.
- Consola más ligera: los servidores muy verbosos (por ejemplo Forge arrancando) ya no pagan un desplazamiento de lista más una notificación de interfaz por cada línea al llegar al tope; el recorte va por bloques, con una sola actualización.
- Log en disco por lotes: el registro de consola se escribe con un vaciado cada 2 s en vez de uno por línea (el cierre limpio vacía el búfer).
- Limpieza interna: la configuración se lee una vez y se cachea; la paleta de colores por tipo y el log de progreso de los diálogos quedan unificados en un solo sitio.
🇬🇧 What's new
Performance release: closes the code-efficiency review.
- Lower tray usage: with the window hidden, status polling (stats, Playit) runs at 1/10th of its usual rate; notifications and crash detection are event-driven and unaffected. Everything returns to normal when you open the window.
- Shared Playit lookups: with several servers, the tunnel query is made once and shared by all of them (before: one identical API request per server every ~30 s). The agent key is cached too.
- Lighter console: very verbose servers (e.g. Forge booting) no longer pay a list shift plus a UI notification per line once the cap is reached; trimming happens in blocks, with a single update.
- Batched disk log: the console log flushes every 2 s instead of once per line (a clean shutdown drains the buffer).
- Internal cleanup: settings are read once and cached; the per-type colour palette and the dialogs' progress log are unified in one place.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.6.3.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.6.2 — Seguridad / Security
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
Versión de seguridad: completa la revisión iniciada en la 1.6.1.
- Instalador de Forge blindado: su checksum (
.sha1) es ahora obligatorio (antes, si faltaba, se ejecutaba sin verificar) y su estructura se valida antes de pasarlo ajava— un archivo sustituido o truncado se descarta, nunca se ejecuta. - La clave de Playit nunca se guarda sin cifrar: si el cifrado fallara (DPAPI o archivo de clave), la clave no se persiste, queda registrado en el log diario y se te avisa una vez. Sigue funcionando durante la sesión.
server.propertiesa prueba de inyección: los valores del editor visual y el MOTD ya no pueden colar líneas extra (por ejemploenable-rcon=true) mediante saltos de línea.- Nombres de jugador estrictos: whitelist, op, ban, kick y pardon validan contra el patrón real de Minecraft (letras, números y
_, máximo 16) y rechazan el resto con un mensaje claro. - Liberar un puerto es más seguro: se recomprueba que el proceso que lo ocupa siga siendo el mismo justo antes de cerrarlo, para no matar un proceso inocente si el PID se reutilizó.
- Iconos de mods con límites: tamaño máximo de 2 MB (aplicado aunque el servidor mienta en el
Content-Length) y content-type de imagen obligatorio.
🇬🇧 What's new
Security release: completes the review started in 1.6.1.
- Hardened Forge installer: its checksum (
.sha1) is now mandatory (it used to run unverified if missing) and its structure is validated before handing it tojava— a swapped or truncated file is discarded, never executed. - The Playit key is never saved unencrypted: if encryption ever fails (DPAPI or key file), the key isn't persisted, the failure is recorded in the daily log and you're warned once. It keeps working for the session.
- Injection-proof
server.properties: values from the visual editor and the MOTD can no longer sneak extra lines (e.g.enable-rcon=true) via line breaks. - Strict player names: whitelist, op, ban, kick and pardon validate against Minecraft's real pattern (letters, digits and
_, max 16) and reject anything else with a clear message. - Safer port freeing: the process holding the port is re-checked right before closing it, so an innocent process isn't killed if the PID was reused.
- Mod icons with limits: a 2 MB size cap (enforced even if the server lies about
Content-Length) and a mandatory image content-type.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.6.2.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.
MC Server Launcher 1.6.1 — Fiabilidad y seguridad / Reliability and security
🇪🇸 Español · 🇬🇧 English below
🇪🇸 Novedades
Versión de fiabilidad y seguridad: sin funciones nuevas, todo arreglos.
- Guardado a prueba de apagones:
servers.jsonysettings.jsonse escriben de forma atómica, se conserva una copia.bakde la última versión buena y, si el archivo se daña, la app lo recupera sola y te avisa (antes arrancaba «sin servidores» en silencio). - Reiniciar servidores colgados: si el servidor no responde a
stopy hay que forzar el cierre, el reinicio ya no se queda sin hacer nada; y la copia del mundo al detener espera a que el proceso muera del todo, sin backups a medias. - Java para Forge moderno: estos servidores comprueban e instalan ahora el Java correcto antes de arrancar (antes se saltaban la comprobación y fallaban con un error críptico de la JVM).
- Seguridad de actualizaciones: la actualización dentro de la app exige verificar el instalador contra el
SHA256SUMS.txtde la release antes de ejecutarlo; si falta o no cuadra, no se ejecuta nada y se abre la página de la release. - Validación del jar de Fabric: el servidor descargado se valida estructuralmente (versión y loader exactos) y se descarta si no cuadra.
- Detalles: instalar un loader y cancelar la edición ya no desincroniza el tipo del servidor; el contador de jugadores no se puede engañar desde el chat; RAM por defecto unificada (2/4 GB); las notas de novedades no se pierden si su ventana falla.
🇬🇧 What's new
Reliability and security release: no new features, all fixes.
- Power-loss-proof saving:
servers.jsonandsettings.jsonare written atomically, a.bakof the last good version is kept, and if the file gets damaged the app recovers on its own and tells you (it used to silently start "with no servers"). - Restarting hung servers: if the server ignores
stopand has to be force-closed, Restart no longer silently does nothing; and the world backup on stop waits until the process is fully gone, so no more half-written backups. - Java for modern Forge: these servers now also check and install the right Java before starting (the check used to be skipped, failing with a cryptic JVM error).
- Update security: the in-app update now requires verifying the installer against the release's
SHA256SUMS.txtbefore running it; if it's missing or doesn't match, nothing runs and the release page opens instead. - Fabric jar validation: the downloaded Fabric server is structurally validated (exact version and loader) and discarded on mismatch.
- Details: installing a loader then cancelling the edit no longer desyncs the server type; the player counter can't be spoofed from chat; default RAM unified (2/4 GB); what's-new notes aren't lost if their window fails.
📦 Descargas / Downloads
- Windows —
MC-ServerLauncher-Setup-1.6.1.exe+SHA256SUMS.txt - Linux —
MC-ServerLauncher-x86_64.AppImage - macOS —
MC-ServerLauncher-AppleSilicon.dmg·MC-ServerLauncher-Intel.dmg
macOS: la app no está firmada. La primera vez, clic derecho sobre ella → Abrir.
The app is unsigned. The first time, right-click it → Open.