Releases: peanut-business/peanut-admin-code
Release list
Peanut Admin v4.0.0-rc.20
Peanut Admin 4.0.0-rc.20
Immutable source: annotated tag v4.0.0-rc.20 at commit 834b1ae3c7dec0258061c18dc80a18ebd911462c.
[4.0.0-rc.20] - 2026-10-04
Fixed
- Compare official Module manifest identities using the same raw-file SHA-256 representation, so unchanged modules no longer block a downstream APP upgrade. Keep downgrade and changed-content protections for modules that reuse a version.
- Verify archive entries by their actual tar type and stream file hashes when publishing larger SBOMs, preserving complete path and content integrity checks.
- This prerelease uses the Minimum Release Gate; full Stable qualification remains pending.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-4.0.0-rc.20.tar.gz- SHA-256:
3697b0447af2844f8df6072ea070e45d5dffbdf773ec4fedbd36317b54c9e7a0
- SHA-256:
- Standalone development, server and same-Edition upgrade archives:
peanut-admin-4.0.0-rc.20-standalone*.tar.gz - Multi-tenant development, server and same-Edition upgrade archives:
peanut-admin-4.0.0-rc.20-multi-tenant*.tar.gz - Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
4669fb80c921fb07726639397c977536dbd1ab4a42515109136a013338a365a5
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v4.0.0-rc.19
Peanut Admin 4.0.0-rc.19
Immutable source: annotated tag v4.0.0-rc.19 at commit 77241d651a46e705f4e279fac980705d569f7e34.
[4.0.0-rc.19] - 2026-10-04
Changed
- Allow active application-owned
peanut.adminmenu permissions in role assignment while preserving module availability and platform boundaries. - Preserve the existing atomic role-edit transaction and stale-revision protection; directly affected rollback and concurrency checks confirm the current behavior.
- Fix compatible Axios, DOMPurify, devalue and Flysystem dependency advisories; remaining toolchain and output risks require Stable Readiness classification.
- Support Peanut CLI native upstream-upgrade orchestration and distinguish Peanut source upgrades, independent APP releases and production deployment upgrades.
- Verify published Web Core packages through exact gitHead or public npm provenance, including the official workflow signer, source commit/tag, package integrity and successful Action.
- This prerelease uses the Minimum Release Gate; full P0-E and remaining security/recovery qualification remain pending for the final Stable candidate.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-4.0.0-rc.19.tar.gz- SHA-256:
003e65921e8968e2e462c7b58517e0ccec7941f969aebfe9574a291b36cf7633
- SHA-256:
- Standalone development, server and same-Edition upgrade archives:
peanut-admin-4.0.0-rc.19-standalone*.tar.gz - Multi-tenant development, server and same-Edition upgrade archives:
peanut-admin-4.0.0-rc.19-multi-tenant*.tar.gz - Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
938ebdbc11c8eb27ff93c7186c874e4b0f58b2eabda42556c64871910f1fdc4e
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v4.0.0-rc.18
Peanut Admin 4.0.0-rc.18
Immutable source: annotated tag v4.0.0-rc.18 at commit 1c476ad55557437e4e89a52def99d0edea07a877.
[4.0.0-rc.18] - 2026-10-04
Changed
- First public 4.0 prerelease with fixed public PHP Core rc.3 and Web Core rc.4 dependencies.
- Standalone and Multi-tenant development-source and server archives, native application creation, fresh installation and SHA-256 integrity manifests.
- Official module source absorption, stable menu identities, PC public pages in SPA mode, and native same-instance upgrades preserving application data and customization.
- This prerelease uses the Minimum Release Gate. Full P0-E, full browser matrices, SSR, performance and extended recovery/fault qualification remain deferred; this is not a stable release or production deployment qualification.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-4.0.0-rc.18.tar.gz- SHA-256:
ec8ee51066298bd7bb586b5c91685f35ffa24b6abe3990a3596bc61d0033deaa
- SHA-256:
- Standalone development and server archives:
peanut-admin-4.0.0-rc.18-standalone*.tar.gz - Multi-tenant development and server archives:
peanut-admin-4.0.0-rc.18-multi-tenant*.tar.gz - This is the first correct Edition distribution baseline; it intentionally has no upgrade packages. The next release may use this version as its same-Edition upgrade source.
- Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
dae3419bcb7e7fda7d53f63ca35451c959733b1f25817aad7d4ee7ea73c14507
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v3.0.14
Peanut Admin 3.0.14
Immutable source: annotated tag v3.0.14 at commit e30b667bbfc25d70281ddf1864b99883850afa24.
[3.0.14] - 2026-09-09
Changed
- Adopted the qualified Peanut Admin Core Alpha.13 Composer and npm packages across all clients,
including the single Core implementation of Local, Aliyun OSS, Tencent COS and Qiniu drivers. - Defined fail-closed Module source-package publication states and content rules; all official
Modules, including Rich Text, are discovered fromplugins.lockfor deterministic packaging. - Converged the reviewed Gemini refactor as incremental application changes while preserving the
ThinkPHP application boundary and isolating the rejected mechanical rewrite.
Fixed
- Replaced temporary or privilege-dependent test paths with executable administrator, import/export,
member upload, scaffold, SMS reservation and package crash-recovery gates. - Rejected environment files, private keys, dependency trees, build output and workspace state from
Module source packages. - Preserved current-session cleanup, article lifecycle guards, file-delete compensation and storage
provider error handling from the independent source audit.
Delivery
- This release completed the fixed-candidate P0-E qualification recorded in
RELEASE_CANDIDATE_LOCK.json.
Known dependency risk
- A post-release audit found high/moderate advisories in the frozen frontend dependency graphs. The
immutable v3.0.14 artifacts are therefore not described as vulnerability-free. - The development branch now removes all high findings identified in Platform, PC and Web. UniApp
still inherits one high finding from the Vite 5.2.8 version pinned by the current DCloud Vue 3
toolchain; it is restricted to controlled build/development use and must be reviewed by 2026-10-09
or before the next release candidate, whichever comes first. - Consumers requiring the dependency remediations should wait for the next qualified release rather
than treating the moving development branch as a released artifact.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-3.0.14.tar.gz- SHA-256:
8c18d5db656f8e6c35d75cebd357e7f5cdcf8876c9c8fc2ba9587e3190da2626
- SHA-256:
- Standalone installer and same-Edition upgrade:
peanut-admin-3.0.14-standalone*.tar.gz - Multi-tenant installer and same-Edition upgrade:
peanut-admin-3.0.14-multi-tenant*.tar.gz - Upgrade trust bootstrap:
UPGRADE_TRUSTED_KEYS.json - Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
f30f5c296ef09c8e9d0b9c23ee2a957374075bf27d84686d742349004da80a4e
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v3.0.13
Peanut Admin 3.0.13
Immutable source: annotated tag v3.0.13 at commit b6530737a17da4ace56b982ed62ba263ed47eef7.
[3.0.13] - 2026-09-06
Added
- Added deterministic Standalone and Multi-tenant installers from one source identity, with explicit
Edition, Schema and checksum manifests. - Added signed same-Edition upgrade packages and a business-readable preflight/apply/verify/recover
flow that preserves application-owned files, secrets and third-party Modules.
Changed
- Adopted the qualified Peanut Admin Core Alpha.12 Composer and npm packages across every client.
- Demo deployment now consumes the formal Multi-tenant installer and a seed-only overlay instead of
copying product Runtime files from a moving source checkout.
Fixed
- Fixed initial configuration, operation-log export permissions, readiness translations and global
action icons found by the real-browser Demo audit.
Delivery
- This is the first correct dual-Edition installation baseline. It intentionally publishes no upgrade
package from older releases; the next release establishes the first supported same-Edition upgrade.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-3.0.13.tar.gz- SHA-256:
cb5bbb2ee52054d63025512bae21628f5de9310965586c55dc5ad4d98b2c226a
- SHA-256:
- Standalone installer:
peanut-admin-3.0.13-standalone.tar.gz - Multi-tenant installer:
peanut-admin-3.0.13-multi-tenant.tar.gz - This is the first correct Edition distribution baseline; it intentionally has no upgrade packages. The next release may use this version as its signed same-Edition upgrade source.
- Upgrade trust bootstrap:
UPGRADE_TRUSTED_KEYS.json - Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
458124ef90bfe364df935484cdb0448ab80563e3de0d1ae46f490cc53511bf16
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v3.0.12
Peanut Admin 3.0.12
Immutable source: annotated tag v3.0.12 at commit fe328a320b7c68b3c2f47512f2aa4afcad43c630.
[3.0.12] - Pending qualification
Fixed
- Production PHP images now include the release identity and Plugin schema required by installation
preflight and lock validation. deploy-releasevalidates the exact candidate image and Plugin lock before target replacement,
then reconciles locked official Plugins after migrations.- Demo overlays now follow the current Module/service paths, include the installation preflight Host
and strip macOS metadata from their archives.
Delivery
- The application and scaffold candidate share version
3.0.12; the final commit/tree and
qualification identity remain external until the fixed-candidate qualification completes.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-3.0.12.tar.gz- SHA-256:
a70b335809989ec6fa33f43b0107a1a0f657ed1bd92782d6b7dd689b2e5f86ad
- SHA-256:
- Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
8ce1a924e593d34bbf5a5bc18ea51c9cde40232d6f3d093e93e42ad9986c036a
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v3.0.11
Peanut Admin 3.0.11
Immutable source: annotated tag v3.0.11 at commit a55e2e4470a1e8dd140bdb7612d63c397f49f862.
[3.0.11] - Pending qualification
Added
- Added an explicit signed Module package v1→v2 update path, deployment-owned update/retire/Purge
operations and a two-independent-application consumer reference flow. - Added a public consumer task guide, compatibility/command index, redacted diagnostics workflow
and separate ordinary/security issue paths. - Added an eighth fixed-candidate qualification group that consumes the formal scaffold release and
proves the complete Module lifecycle without source-private fixtures.
Security
- Tenant suspension now fails closed across management, API, PC/H5, public content, asynchronous work
and Tenant file delivery, while reactivation restores only valid access.
Delivery
- The application and scaffold candidate share version
3.0.11; the final commit/tree and qualification
identity remain external until CR31 completes.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-3.0.11.tar.gz- SHA-256:
bb4fcc2e53bdea880b2370bafe95ba97bb0cbe7c690a4284af5f6528ec5fdb2a
- SHA-256:
- Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
7c2e79a3cf8e44ae2e25aba7579689bc4df1e61b4c746dc1fb2900125b856c38
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v3.0.5
Peanut Admin 3.0.5
Immutable source: annotated tag v3.0.5 at commit df6e018ffecabba37b0bbdf44b79067da7341552.
[3.0.5] - Pending qualification
Fixed
- Demo overlays and local demo scripts now use
peanut1234; the shorter credential is accepted
only whilePEANUT_DEMO_MODE=enabled, while normal account passwords retain Core policy. - Admin login validation now matches the Core email contract through 255 characters.
- Release,
create-app, independent application, and scaffold-upgrade documentation now describe
the main/tag/manual Release flow and the separate application lifecycle.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-3.0.5.tar.gz- SHA-256:
adda018b58a99746ed40a4ffec419b3c42fdd1c542d3d2a99c9eb1738c1f749e
- SHA-256:
- Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
05559129ebe2ae96cdc27d462f36a9f8f28f59c928e45fef7b4c7e1e9c86cc12
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v3.0.4
Peanut Admin 3.0.4
Immutable source: annotated tag v3.0.4 at commit 3c9f84102bb3fba161883fd683063c5d451217e2.
[3.0.4] - 2026-08-21
Fixed
- Shared Admin Hosts now receive only the
member-apidefault-Tenant binding;admin-web
remains unbound so Tenant-owner login can select an active Tenant membership.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-3.0.4.tar.gz- SHA-256:
08d005360537f80b12666bc3cd39e5c147048c51ef94e41a097626f0419e34b7
- SHA-256:
- Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
91609df35390a4450f4a6b0807bf7ba85a8bf20174f2f63f17149ca28fc23e13
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.
Peanut Admin v3.0.3
Peanut Admin 3.0.3
Immutable source: annotated tag v3.0.3 at commit 4585e1755122059fc614473f19ff80da594d4575.
[3.0.3] - 2026-08-21
Fixed
- Multi-tenant Demo seeding now binds the registered shared Admin Hosts to the default Tenant
for bothadmin-webandmember-api, in addition to the Tenant A/B bindings.
Artifacts and verification
- Normative deterministic source archive:
peanut-admin-3.0.3.tar.gz- SHA-256:
fb65a27ccf2369e740dae31c2e69dd8f0aa5e1c8c2c7f7b3c9ded21101dc9d1e
- SHA-256:
- Candidate lock:
RELEASE_CANDIDATE_LOCK.json - External release manifest:
RELEASE_MANIFEST.json- SHA-256:
df0c8bb788546008c60370586e2c8619524a4aa9eb10576aa34f64f67608fbb3
- SHA-256:
RELEASE_CANDIDATE_LOCK.json binds the external qualification summary to this exact tag.
RELEASE_MANIFEST.json records hashes and sizes for every other attached artifact. GitHub-generated source archives are convenience downloads; the attached deterministic archive is normative.