This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+6 more
Affected surfaces
ReleasePort's take
Light signalVersion v1.6.2 adds a resetpwd CLI command and expands the gocronx-admin UI with audit logs, statistics dashboards, host management, user tools, and OS‑aware registration tabs.
Why it matters: The new resetpwd command lets operators quickly restore user access; expanded admin features improve observability and control over hosts and users.
Summary
AI summaryBroad release touches Others, Bug Fixes, New Features, and gocronx-admin.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Uses crypto.getRandomValues for password generation in gocronx-admin UI forms. Uses crypto.getRandomValues for password generation in gocronx-admin UI forms. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Feature | Low |
Adds resetpwd command to CLI for resetting a user's password. Adds resetpwd command to CLI for resetting a user's password. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Completes migration of web/gocronx-admin frontend. Completes migration of web/gocronx-admin frontend. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Adds audit-log and login-log pages to gocronx-admin. Adds audit-log and login-log pages to gocronx-admin. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Adds gocron statistics dashboard to gocronx-admin. Adds gocron statistics dashboard to gocronx-admin. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Adds host list page and route module to gocronx-admin. Adds host list page and route module to gocronx-admin. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Adds user-list, change-password, 2FA, host-edit, and host API to gocronx-admin. Adds user-list, change-password, 2FA, host-edit, and host API to gocronx-admin. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Bootstraps new frontend alongside web/vue in gocronx-admin. Bootstraps new frontend alongside web/vue in gocronx-admin. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Sets default UI language of gocronx-admin to English. Sets default UI language of gocronx-admin to English. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Shows OS‑aware tabs in auto‑register dialog for host component. Shows OS‑aware tabs in auto‑register dialog for host component. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Ports 'Save as Template' from web/vue to task component. Ports 'Save as Template' from web/vue to task component. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Adapts auth flow in gocronx-admin for gocron backend. Adapts auth flow in gocronx-admin for gocron backend. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Feature | Low |
Ports cron help and rich preview from template edit to task component. Ports cron help and rich preview from template edit to task component. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Feature | Low |
Adds Apply Template action on template list in gocronx-admin. Adds Apply Template action on template list in gocronx-admin. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Feature | Low |
Supports {{variable_name}} placeholders when applying templates. Supports {{variable_name}} placeholders when applying templates. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Feature | Low |
Adds issue templates and security policy documentation. Adds issue templates and security policy documentation. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Medium |
Unwraps one extra level when reading 2FA setup response. Unwraps one extra level when reading 2FA setup response. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Medium |
Fills target ID and name on audit create actions. Fills target ID and name on audit create actions. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Medium |
Uses legal timestamp for scheduler_lock to support MySQL strict mode. Uses legal timestamp for scheduler_lock to support MySQL strict mode. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Hardens CLI resetpwd output and safety checks. Hardens CLI resetpwd output and safety checks. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Renders circle markers on execution trend chart in dashboard. Renders circle markers on execution trend chart in dashboard. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Restores ArtCountTo metric accidentally deleted from dashboard. Restores ArtCountTo metric accidentally deleted from dashboard. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Loads Iconify icons offline to fix blank icon issues in gocronx-admin UI. Loads Iconify icons offline to fix blank icon issues in gocronx-admin UI. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Parses gocron responses even when they use text/plain content-type. Parses gocron responses even when they use text/plain content-type. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Points production API base URL to same‑origin instead of Apifox mock in gocronx-admin. Points production API base URL to same‑origin instead of Apifox mock in gocronx-admin. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Refreshes kept‑alive list pages on re‑activation in gocronx-admin UI. Refreshes kept‑alive list pages on re‑activation in gocronx-admin UI. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Upgrades eslint-plugin-vue to version 10 for ESLint 10 compatibility during build. Upgrades eslint-plugin-vue to version 10 for ESLint 10 compatibility during build. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Removes optional email step from install wizard flow. Removes optional email step from install wizard flow. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Bugfix | Low |
Keeps ArtTableHeader #right slot visible on mobile phones. Keeps ArtTableHeader #right slot visible on mobile phones. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
Full changelog
Changelog
New Features
- 4fc41b9b3dd06377ab804ad863bd23c9b9673e21 feat(cli): add resetpwd command to reset a user's password
- 764390f7a7afd1b6b95e80e538278e5f65bf0269 feat(frontend): complete web/gocronx-admin migration
- 95d051a36998859bda422d942050b312831b5ef0 feat(gocronx-admin): adapt auth flow for gocron backend
- 464e979bf6140d23024168af8c497758ae373977 feat(gocronx-admin): add audit-log and login-log pages
- 19b63666299da96c6e3b938fab4bf585f2676eb1 feat(gocronx-admin): add gocron statistics dashboard
- 0dfa3e29bc2446c36d3c75cad02606a2dde42117 feat(gocronx-admin): add host list page + route module
- 65fc62a82ea5d2f07ee5ab5664f937c9a95535dc feat(gocronx-admin): add user-list, change-password, 2FA, host-edit, host api
- b032974094abcb2f945834a82271b5d0a3c31d89 feat(gocronx-admin): bootstrap new frontend alongside web/vue
- 0c55fa0a4d23bab7ed3504217dcb376d6a270260 feat(gocronx-admin): default UI language to English
- fa9690f1eae3607e39ced0ada2a3dfb666ed971f feat(host): auto-register dialog shows OS-aware tabs
- 193369edbf150b8ac0e8d25fcef4f71324e32804 feat(task): port 'Save as Template' from web/vue
- 64c491d69dd081fbd4aaf895c036fe737ff7bf13 feat(task): port cron help + rich preview from template edit
- 980e201ae5f6e57339f889557950c3eb3cb34642 feat(template): add Apply Template action on template list
- 12ca0ee157fc8b8eddbf54ae062def47c5952014 feat(template): support {{variable_name}} placeholders on apply
- f348e653a4ba1794edab53c56e204c4fff375ab5 feat: add issue templates and security policy #190
- 97a8a189273553aaeed5d8089e9c85acb2174623 feat: add issue templates and security policy #190
Bug Fixes
- cf795af978c9f7548303641efe4865e93b2e1e62 fix(2fa): unwrap one level too many when reading setup response
- 861b44bdcf0e7f58ae3e59922977054bab018c7d fix(audit): fill target id+name on create actions
- 612c0d977f22120cb26735ece822e85d508a7410 fix(ci): generate auto-import types via build-only before vue-tsc type-check
- 51dbd25453f93ea196186c3b7a0a228d04531697 fix(cli): harden resetpwd output and safety
- 3b838ae7dba027e37572eb046bdf91192c377fd3 fix(dashboard): render circle markers on execution trend chart
- 7928617eb511ffde51e60a7f346a058b36e0cf0a fix(dashboard): restore ArtCountTo accidentally deleted
- 6645b2aa55b64a1c0a01d2b9d4295bb2b2ccbd5f fix(gocronx-admin): format datetime columns in audit/login log
- 970acc689120f8cabeed4a8bd34ea2022169664e fix(gocronx-admin): load Iconify icons offline to fix blank icons
- 64e647d57aca041051009c903a4b7ad6622d19f7 fix(gocronx-admin): parse gocron responses despite text/plain content-type
- 169e541c23d05721c5ea162e1c7c33723da4ae19 fix(gocronx-admin): point production API base to same-origin instead of Apifox mock
- ad963691360915e1b921a7d3f5044c5dc5356300 fix(gocronx-admin): refresh kept-alive list pages on re-activation
- ca32251fb304b6c17685056ec723c0f03a557d90 fix(gocronx-admin): upgrade eslint-plugin-vue to v10 for ESLint 10 compat
- be9ab520b56e8dec35a81032fd8e5f368f6b2f54 fix(gocronx-admin): use crypto.getRandomValues for password generation
- 2511c5742acd7a1bd22d1f47cda4dedc35bd6a0a fix(install): remove optional email step from install wizard
- fa16edeee6bcecdb5d84ad4a79a1914447a602ea fix(leader): use legal timestamp for scheduler_lock to support MySQL strict mode #183
- 2e839cc2c220c381653f3414cee568a9bd4dd08f fix(mobile): keep ArtTableHeader #right slot visible on phones
- c8888440310a6084f9ff93eaa23e570f6078f58a fix(mobile): shrink ElMessageBox width to fit small viewports
- a8e98b237a5e7e8276eaeac5b3732a0e621e4324 fix(models): drop MySQL-only column types from task.go (rebase fixup)
- e9d77d5846a1ca351420e3308313f80196c664b6 fix(qa): ISSUE-001 — redirect to /install when system is uninstalled
- 4cc93b5d2dfa0e83310de7e661189f15f7f44bc7 fix(qa): ISSUE-002 — silence router validator for intentional absolute paths
- 9a8e21629bb2b7544b85608b97d0dc25fcf9baa9 fix(qa): ISSUE-003 — escape vue-i18n special chars in template strings
- 90be3b74d4a5e1c933474b6b5ad78e918fd91f90 fix(table-header): make toolbar icons visible on white cards
- f35256489950d1d57e172fc87d9350231955427d fix(task): GORM default:1 tag ate zero values on Create
- e263722267abe3a5a172201b326bdd9ae1b489fe fix(task): don't copy notify settings from applied template
- 75c5f8b490ac62c909b697e3f6f57d26c3d2f6ef fix(task-log): strip backend
separator from Host column - 6b8b842fc35f6b06393231710ca49320699dc96c fix: default home /task/list, template created_at column, User flat entry
Others
- 0bfa34fe0206705f05c9b9cfd81a0c1c765366b0 build: speed up docker build with cache mounts and persist sqlite db in the volume
- c19e552e4b5a4bcdc24c8f9739ab869199d1af7f build: switch all build/CI/packaging from web/vue to gocronx-admin
- 52f5d032b0d1058ce3f56dd6332769caefc881ae chore(admin): drop leftover search/globalSearch config + i18n
- 05c57178967f457591c31e81121efd78f76f989b chore(admin): remove autoClose + unused api/utils/mock
- ad3bb1683d8edab4728fdb4615d5f45fd3eba92e chore(admin): remove ceremony, socket, global-search, dead events
- 88130b838354b70484df8c0159eaa420ab4cc3c8 chore(admin): remove unused ArtException + ArtResultPage scaffolds
- 773c12aab549f51206d21600e90f057c62b33127 chore(admin): remove unused chart and card components
- c09d08e49e5ebf590318d29c748b533fd1ebbe2d chore(admin): remove unused form widgets and their heavy deps
- c7cab19d2cce1219aba391b4b3d3de377ebd1b32 chore(admin): remove unused media, banner, back-to-top components
- acd3e7191ecf28e38e691723bb18c43b1f117767 chore(admin): remove watermark + festival orphan state
- 283d2cb4588698d77840a7fd4b39e68d2bc829ed chore(gocronx-admin): run clean:dev to strip demo content
- a7a1b8367c7ff11a4c6a23321e5a1653ce9e2e62 chore(ui): silence console welcome banner and router warn
- ae9792ef6c45b5ba14f9a2abf57c7173b12fa5d1 chore(user-center): drop 'ID N' row from profile card
- b03f7b8312df08202c192486163dd8c48413a425 chore: bump version to 1.6.2
- 1f6ee47fbda1d6019484c7c60c009db3fb7bd236 chore: gitignore docs/superpowers working docs
- 0731aa45d6f60b8b636e467aa28de5f25a63d93a chore: remove deprecated web/vue frontend
- 32e287f83b8635601b6a0574ad83665853c2b8cd chore: remove useless file
- c8094f15e827d8b6050d6c7a7f11a408a752e3a9 chore: stop tracking GOCRONX_ADMIN_MIGRATION.md (keep local only)
- 659f0bbadf4f8428e894df38cfced1ba60661238 chore: update readme images
- dc9a3a7bbb8874b0e36a3d07f7c546a3f611616c ci: bump GitHub Actions to Node 24 compatible versions
- 5eb633ba3582cc9e5d6b63d63b64a453f6448410 refactor(ip): normalize client IP at source
- 9574f3a16ceb30e09eb8e19d88a93e96959428cc refactor(router): group Dashboard + Tasks + Templates under one sidebar parent
- 07c6182bd566f876ef2b2cc6aaf33ef93d071fea refactor(router): split Users into its own sidebar group, add icons everywhere
- 1cf2b20f26a64788e1e88481fcfe14458f796a98 refactor(ui): drop fake Lock Screen + default avatar
- 24f3401bdc32eaadc8bf51302686f2999c69a45f style(design): FINDING-001 — default setting guide to hidden
- e1ffcc99056ddc891718a227172e22f7cb899752 style(design): FINDING-002 — pin Actions column to right on all lists
- 750c2b2dab50d38fcd2c4378f1dc2fa60cd41180 style(design): FINDING-003 — hide work tab on mobile
- 3661c2031f13db7367ca4fa17562024c007f34de style(design): FINDING-005 — dashboard table uses min-width
- 9a34cc866afb069af218d80f60889783d54722ca style(gocronx-admin): apply prettier formatting and drop unused visualizer import
- 97c3c78919947ee351090f6ab73de29b42215756 style(password-forms): inline labels, centered submit, shared layout
- 113070e70e4aba249038de10f662e7631b920ec6 style(task): uniform width for task-list header buttons
- 31fa798e041bcb650c32a10b99f17b3a53c784fb style(user-center): tidy Change Password form layout
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]