Skip to content

Peanut Admin v3.0.14

Choose a tag to compare

@xingkoo xingkoo released this 09 Sep 01:39
· 941 commits to main since this release
e30b667

Peanut Admin 3.0.14

Immutable source: annotated tag v3.0.14 at commit e30b667bbfc25d70281ddf1864b99883850afa24.

[3.0.14] - 2026-09-09

Changed

  • Adopted the qualified Peanut Admin Core Alpha.13 Composer and npm packages across all clients,
    including the single Core implementation of Local, Aliyun OSS, Tencent COS and Qiniu drivers.
  • Defined fail-closed Module source-package publication states and content rules; all official
    Modules, including Rich Text, are discovered from plugins.lock for deterministic packaging.
  • Converged the reviewed Gemini refactor as incremental application changes while preserving the
    ThinkPHP application boundary and isolating the rejected mechanical rewrite.

Fixed

  • Replaced temporary or privilege-dependent test paths with executable administrator, import/export,
    member upload, scaffold, SMS reservation and package crash-recovery gates.
  • Rejected environment files, private keys, dependency trees, build output and workspace state from
    Module source packages.
  • Preserved current-session cleanup, article lifecycle guards, file-delete compensation and storage
    provider error handling from the independent source audit.

Delivery

  • This release completed the fixed-candidate P0-E qualification recorded in
    RELEASE_CANDIDATE_LOCK.json.

Known dependency risk

  • A post-release audit found high/moderate advisories in the frozen frontend dependency graphs. The
    immutable v3.0.14 artifacts are therefore not described as vulnerability-free.
  • The development branch now removes all high findings identified in Platform, PC and Web. UniApp
    still inherits one high finding from the Vite 5.2.8 version pinned by the current DCloud Vue 3
    toolchain; it is restricted to controlled build/development use and must be reviewed by 2026-10-09
    or before the next release candidate, whichever comes first.
  • Consumers requiring the dependency remediations should wait for the next qualified release rather
    than treating the moving development branch as a released artifact.

Artifacts and verification

  • Normative deterministic source archive: peanut-admin-3.0.14.tar.gz
    • SHA-256: 8c18d5db656f8e6c35d75cebd357e7f5cdcf8876c9c8fc2ba9587e3190da2626
  • Standalone installer and same-Edition upgrade: peanut-admin-3.0.14-standalone*.tar.gz
  • Multi-tenant installer and same-Edition upgrade: peanut-admin-3.0.14-multi-tenant*.tar.gz
  • Upgrade trust bootstrap: UPGRADE_TRUSTED_KEYS.json
  • Candidate lock: RELEASE_CANDIDATE_LOCK.json
  • External release manifest: RELEASE_MANIFEST.json
    • SHA-256: f30f5c296ef09c8e9d0b9c23ee2a957374075bf27d84686d742349004da80a4e

RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.