Repository navigation
Releases: michael-ltm/sshm
Releases · michael-ltm/sshm
Release list
v0.7.1
Changelog
- 4377f7f: build: pin installers to signed preview 31 assets ( <>)
- 911a82e: build: pin signed preview 32 installers ( <>)
- 2a92760: build: pin signed preview 33 installers ( <>)
- f180582: build: pin signed preview 34 installers (Claude Code noreply@anthropic.com)
- 7cf8f30: feat: add encrypted cloud management and cross-platform terminal UI ( <>)
- 9526fee: feat: add guided pairing and safe inventory lifecycle ( <>)
- fddb873: feat: pair public-IP servers without a callback; tidy home/add UI and rm (Claude Code noreply@anthropic.com)
- 5104ade: feat: rm and TUI delete offer a local+cloud tombstone (Claude Code noreply@anthropic.com)
- 4088b70: fix: define StartSessionAgent for Windows so the client cross-compiles (Claude Code noreply@anthropic.com)
- 3775b8d: fix: enforce safe pairing command bounds (@michael-ltm)
- cbbdf63: fix: execute opted-in macOS commands in the user's desktop keychain session ( <>)
- 5835243: fix: harden Windows pairing service startup ( <>)
- d34fdcd: fix: make POSIX pairing copy-safe ( <>)
- 50ff83a: fix: resolve user execution environments and diagnose session authorization ( <>)
- 30f835d: fix: restore SSH after vault unlock without re-encrypting keys ( <>)
- 430abdc: fix: scope desktop delegation to GitHub credentials and preserve SSH file access ( <>)
- 3657643: fix: support OpenSSH 10.5 pairing (@michael-ltm)
- 3ac3c2c: fix: verify copy-id auth and prompt exec passwords ( <>)
sshm v0.7.0
Highlights
Interactive server management
sshm list/sshm lsnow opens a keyboard-driven server manager in a TTY.- Select a host with the arrow keys, then connect, inspect, test reachability, add or edit descriptions, change the remote password in a direct PTY, set the default host, create hosts, or delete with confirmation.
--plainkeeps deterministic table output for scripts, pipes, and AI tooling.
AI-safe host discovery
- Servers now have first-class
description,group, andtagsmetadata. - The new read-only
find_serversMCP tool ranks hosts by intent without exposing private notes. - AI-visible metadata is bounded and rejects credential-like content;
--redactedprovides share-safe JSON.
Safer destructive and credential operations
- CLI deletion requires typing the exact alias unless
--yesis explicitly supplied. - MCP deletion requires an exact
confirm_alias, is audited, and refuses to remove hosts referenced by project profiles. - Remote password changes run directly inside an SSH PTY. Password bytes never enter MCP payloads, config files, audit logs, or chat.
- Terminal rendering strips control sequences to reduce terminal-output injection risks.
Project profiles and remote workflows (included since v0.5.1)
- Version-3 project profiles capture the server, local root, remote workspace/run root, artifact path, shell, build command, and verification command.
- New MCP tools:
list_projects,get_project,upsert_project, andexec_project. - Detached jobs and
tail_logsnow work across POSIX and Windows remotes. - The bundled sshm skill adds lower-token project workflows plus authorized remote reverse/dynamic-debug guidance.
Compatibility
- Existing version-2 configuration files load without implicit migration and upgrade only when saved.
- Existing server-only CLI and MCP tool names remain available.
Release artifacts
- macOS: amd64, arm64
- Linux: amd64, arm64
- Windows: amd64, arm64
checksums.txtcontains SHA-256 checksums for every archive.
Full details: CHANGELOG.md
v0.5.1
Changelog
- b5a5370: feat: improve ssh diagnostics and transfers ( <>)
v0.5.0
Changelog
- 1d89b80: Merge: secure-by-default key provisioning (v0.5.0) (Claude Fable 5 noreply@anthropic.com)
- d4b90d6: docs(skill): secure server onboarding guidance (Claude Fable 5 noreply@anthropic.com)
- a47e01c: feat(cli): add provision — encrypted key onboarding with optional harden (Claude Fable 5 noreply@anthropic.com)
- e1d9314: feat(cli): gen-key encrypts by default, stores passphrase, writes recovery (Claude Fable 5 noreply@anthropic.com)
- 5cd2ed0: feat(keys): GenerateED25519Encrypted with passphrase support (Claude Fable 5 noreply@anthropic.com)
- 2b93c93: feat(keys): add RandomPassphrase high-entropy generator (Claude Fable 5 noreply@anthropic.com)
- 4a5698e: feat(keystore): StoreAndLoad for linux and windows (Claude Fable 5 noreply@anthropic.com)
- 098dc7a: feat(keystore): StoreAndLoad macOS keychain path with agent fallback (Claude Fable 5 noreply@anthropic.com)
- 888ad83: feat(keystore): shared Result type and agent-load helper (Claude Fable 5 noreply@anthropic.com)
- 3ee3d4d: feat(mcp): gen_key encrypts, returns recovery pointer not passphrase (Claude Fable 5 noreply@anthropic.com)
- c485cc8: fix(provision): persist key auth only after connectivity test confirms it (Claude Fable 5 noreply@anthropic.com)
- 8ae906d: fix: make gen_key resilient to agent failures, verify harden actually disables password auth (Claude Fable 5 noreply@anthropic.com)
- 316c0dc: refactor(ssh): export DialAgent for keystore reuse (Claude Fable 5 noreply@anthropic.com)
v0.4.1
Changelog
- 0e92afe: feat(ssh): support encrypted private keys via ssh-agent lookup (Claude Fable 5 noreply@anthropic.com)
v0.4.0
Changelog
- 1befb44: feat(ssh): proxy/VPN-aware dialing with retry fallback (Claude Opus 4.8 (1M context) noreply@anthropic.com)
- d1f3e13: feat(ssh): support authenticated SOCKS5 proxies ( <>)
- ee016c4: test(ssh): skip known_hosts perm assertions on Windows ( <>)
v0.3.0
Changelog
- 8e17df7: feat(mcp): add upload/download tools via sftp (Claude Opus 4.8 (1M context) noreply@anthropic.com)
- f52398b: feat(mcp): timeout_seconds, partial-output-on-timeout, output cap, parallel exec_multi, detach (Claude Opus 4.8 (1M context) noreply@anthropic.com)
- b47248d: feat(security): verify host keys via TOFU by default (Claude Opus 4.8 (1M context) noreply@anthropic.com)
- d73a0c7: fix(concurrency): serialize config RMW and audit appends ( <>)
- b9ad1d7: fix(mcp): infer auth=key when add_server is given key_path (@michael-ltm)
- b7d3c34: fix(mcp): thread request ctx, deterministic list, version var, gen_key auth, ProbeMany cancel ( <>)
- 4507d52: fix(plugin): make the repo a valid Claude Code marketplace ( <>)
- 7f47a90: fix(plugin): plugin.json author must be an object (Claude Opus 4.7 (1M context) noreply@anthropic.com)
- a323e5e: fix(safety): block flagless shred /dev/*, stop IPv6 regex masking MACs ( <>)
- 00f94cf: fix(safety): broaden secret masking and dangerous-command filter (Claude Opus 4.8 (1M context) noreply@anthropic.com)
- 2488b48: style: gofmt test files ( <>)
v0.2.0
Changelog
- a740b65: chore(mcp): go mod tidy — mcp-go is a direct dependency ( <>)
- 4d75bd6: docs(plugin): correct add_server required-args in quick-reference ( <>)
- c1e8b45: feat(bootstrap): embedded hardening script + runner ( <>)
- 0720649: feat(cli): sshm init ( <>)
- 09fcaff: feat(cli): sshm mcp — start the stdio MCP server ( <>)
- ff97f70: feat(cli): sshm status ( <>)
- 1e9486d: feat(mcp): exec + exec_multi tools with safety filter ( <>)
- 5d0e8c8: feat(mcp): ops tools (bootstrap/gen_key/copy_id/tail_logs) ( <>)
- c653e42: feat(mcp): read-only tools (list/get/test/status) ( <>)
- 7f3f44c: feat(mcp): server skeleton + mcp-go dependency ( <>)
- aa8393c: feat(mcp): write tools (add/edit/remove server) ( <>)
- 6d15dad: feat(plugin): Claude Code plugin sshm-skill ( <>)
- 6e13a0b: feat(safety): append-only JSON-lines audit log ( <>)
- b6eb34c: feat(safety): dangerous command pattern filter ( <>)
- f5dfef7: feat(safety): sensitive data masking ( <>)
- fd5282a: feat(status): rich remote snapshot collector ( <>)
- 59c9e65: fix(cli): init exits non-zero on incomplete bootstrap ( <>)
- 7bc2f34: fix(mcp): audit records when exec bypassed the safety filter (Claude Sonnet 4.6 noreply@anthropic.com)
- 9abc008: fix(mcp): edit_server applies auth/key_path; validate host/auth/port ( <>)
- 1f0d189: fix(safety): catch rm -rf ~/ and uppercase -R; document guardrail scope ( <>)
- c50ed5a: fix(test): portable mcp integration build, dedicated CI step (Claude Sonnet 4.6 noreply@anthropic.com)
- d6d8c65: refactor(bootstrap): fix Run comment, wrap $PM, surface stderr (Claude Sonnet 4.6 noreply@anthropic.com)
- d63271d: refactor(cli): status renders ports comma-separated, aligns flag help ( <>)
- 9926972: refactor(mcp): mask test_connection error at the handler ( <>)
- 7ca471d: refactor(status): brace-group uptime fallback, relax ports grep ( <>)
- 92607b1: test(mcp): stdio integration test for the MCP server ( <>)
- 9e2efc5: test(safety): audit test covers Result masking and timestamp ( <>)
- fabcce1: test(safety): lock priv-key-first masking order; document over-masking ( <>)
v0.1.0
Changelog
- 2a5d26f: build: goreleaser config for multi-arch tarballs + brew + scoop (cloudcli cloudcli@cloudcli.com)
- bd9f42e: feat(cli): cobra root with --json/--config/--no-color globals (cloudcli cloudcli@cloudcli.com)
- a6275dd: feat(cli): config loader + alias resolver utilities (cloudcli cloudcli@cloudcli.com)
- dfe2556: feat(cli): sshm add — wizard + --quick non-interactive (cloudcli cloudcli@cloudcli.com)
- 41156a1: feat(cli): sshm c / connect — interactive SSH session (cloudcli cloudcli@cloudcli.com)
- 5a9f190: feat(cli): sshm copy-id (cloudcli cloudcli@cloudcli.com)
- 24fa74d: feat(cli): sshm edit --set field=value (cloudcli cloudcli@cloudcli.com)
- c02c508: feat(cli): sshm exec — run remote commands (cloudcli cloudcli@cloudcli.com)
- 4eb77f5: feat(cli): sshm gen-key — generate keypair, update key_path (cloudcli cloudcli@cloudcli.com)
- 4b66637: feat(cli): sshm ls (cloudcli cloudcli@cloudcli.com)
- 888b695: feat(cli): sshm rm (cloudcli cloudcli@cloudcli.com)
- 06fce22: feat(cli): sshm show (cloudcli cloudcli@cloudcli.com)
- 5fc5ee6: feat(cli): sshm test — single or --all parallel probe (cloudcli cloudcli@cloudcli.com)
- 5c7280b: feat(config): add types and cross-platform path resolution (cloudcli cloudcli@cloudcli.com)
- 527b972: feat(config): load and atomic save with TOML (cloudcli cloudcli@cloudcli.com)
- 82f9d42: feat(keys): build copy-id remote command + CopyID flow (cloudcli cloudcli@cloudcli.com)
- 9d326b4: feat(keys): generate ed25519 keypair to disk (cloudcli cloudcli@cloudcli.com)
- 18108ea: feat(ssh): Dial, Client, Exec and StreamExec (cloudcli cloudcli@cloudcli.com)
- 6736e93: feat(ssh): build *ssh.ClientConfig from Server entry (cloudcli cloudcli@cloudcli.com)
- 87ec071: feat(status): TCP-connect probe + parallel ProbeMany (cloudcli cloudcli@cloudcli.com)
- 275666e: feat(ui): icon sets with unicode/ascii fallback (cloudcli cloudcli@cloudcli.com)
- 73035ac: feat(ui): lipgloss styles and server-table renderer (cloudcli cloudcli@cloudcli.com)
- 59f5a0d: fix(build): pass tap/bucket tokens to goreleaser brew/scoop publishers (cloudcli cloudcli@cloudcli.com)
- 1c529f3: fix(build): set go.mod minimum to 1.22 per plan (cloudcli cloudcli@cloudcli.com)
- 84817f4: fix(cli): gen-key and copy-id honor --json; CI runs race detector (cloudcli cloudcli@cloudcli.com)
- 42d74ff: fix(test): probe latency assertion tolerates 0 on coarse-clock platforms (cloudcli cloudcli@cloudcli.com)
- 9ab8f24: refactor(cli): DRY config path, add missing resolver error-path test (cloudcli cloudcli@cloudcli.com)
- 4089d3a: refactor(cli): add validates host/port, propagates write errors (cloudcli cloudcli@cloudcli.com)
- 5da758e: refactor(cli): completion uses cmd.OutOrStdout, default branch explicit (cloudcli cloudcli@cloudcli.com)
- d007895: refactor(cli): copy-id zeros password buffer, explicit error discards (cloudcli cloudcli@cloudcli.com)
- 69cc18a: refactor(cli): edit validates port range/auth value, requires --set (cloudcli cloudcli@cloudcli.com)
- d5683f4: refactor(cli): exec uses cmd.ErrOrStderr, documents shell-splitting (cloudcli cloudcli@cloudcli.com)
- ce1ac58: refactor(cli): ls uses fmt.Fprint with error propagation (cloudcli cloudcli@cloudcli.com)
- c67bf08: refactor(cli): renderServerDetail returns and propagates write errors (cloudcli cloudcli@cloudcli.com)
- 2dbfdcb: refactor(cli): rm uses cmd.InOrStdin, propagates write error, more tests (cloudcli cloudcli@cloudcli.com)
- 5348cea: refactor(cli): test sorts aliases, uses ResolveIcons, propagates write errors (cloudcli cloudcli@cloudcli.com)
- 5c60fb2: refactor(config): wrap all Save errors with %w context (cloudcli cloudcli@cloudcli.com)
- e27a8f2: refactor(keys): graceful CRLF handling in CopyID, clean up remote tmp (cloudcli cloudcli@cloudcli.com)
- 425b686: refactor(keys): sanitize comment, roll back on pub-write failure (cloudcli cloudcli@cloudcli.com)
- 8f214d1: refactor(ssh): drain goroutine on cancel, wrap StreamExec error (cloudcli cloudcli@cloudcli.com)
- a536ac2: refactor(ssh): pin go 1.22, return io.Closer from agentAuth, add tests (cloudcli cloudcli@cloudcli.com)
- e41d797: refactor(ssh): wrap PTY-setup errors for diagnostic context (cloudcli cloudcli@cloudcli.com)
- e7ec82c: refactor(test): harden integration script and use stdlib host:port parser (cloudcli cloudcli@cloudcli.com)
- 2f04dd5: refactor(ui): tighten doc wording and pin AuthAgent in tests (cloudcli cloudcli@cloudcli.com)
- 2a1b811: refactor(ui): tighten status column, document styles, guard humanizeSince (cloudcli cloudcli@cloudcli.com)
- 8cfc267: test(config): replace tautological test, add AuditPath coverage (cloudcli cloudcli@cloudcli.com)
- 9d37bbc: test(ssh): docker integration tests for Dial/Exec (cloudcli cloudcli@cloudcli.com)
- 29339fd: test(status): cover ProbeMany fanout, empty map, cancelled context (cloudcli cloudcli@cloudcli.com)