Development pause: Product and site development is frozen as of July 13, 2026. This changelog is the public record of that journey (homelab and preview trains included). Security and critical fixes may ship as patch releases only.
Released July 18, 2026
New appliance setup no longer skips the wizard after creating the admin account.
Always-on appliance requires a valid Business/Pro Lemon product variant. Free or unknown keys no longer unlock discovery.
The name you enter during onboarding fills Network Identifier / friendly site name (no more node-unnamed blank Identity).
Online Lemon validation runs at most every 12 hours when a paid license is already trusted.
Released July 12, 2026
Signed Windows MSI/portable, macOS DMG, and Docker appliance published for public download.
Hub federation, update depot, notify + confirm apply, and scheduled Windows apply in the always-on Business appliance.
Free portable session scanner + Business $40 per appliance. Zero device telemetry. Trust Center and About on the public site.
Feature and site development frozen as of July 13, 2026. Security and critical fixes may still ship as patches.
Released July 11, 2026
Route policy, mTLS depot update guard, dependency audit, and live 401 battery across Hub / Linux / Mac.
Hub update check/download stays JWT-anonymous and enrolled-Node mTLS gated (port 5002), with regression coverage in security-audit.ps1.
Why StacksAtlas exists: local-first craft, federation pivot, signing and LLC red tape, indie partnership pricing. Linked from nav, footer, and Trust Center.
Released July 11, 2026
Remote log abbreviations, offline Threshold WRN once-until-recovery, safer semver compare, Hub offer UX, Notify gated on staged depot, archive purge, depot re-stage warn.
Enrolled Nodes need compose build for Nmap image upgrades; recreate alone can keep an old layer.
Hub preview self-upgrade, Mac Notify + DMG, Linux Deep Scan rebuild to 1.9.4.
Released July 11, 2026
Network link / topology mapping, Hub depot updates, Watchtower compose on the site, federation 5002 firewall, OpenAVC and webhook Alert Scope guides.
Host-side auto-update for standalone Docker Business; Hub depot remains the air-gap path for enrolled Nodes.
Features/demo/FAQ cleanup, Free + Business $40 consistency, thin dark docs scrollbars.
Public stable promote checklist locked; first public stable remains an operator ship gate.
Released July 9, 2026
Hub Dashboard and Federation show Current / Behind / Ahead per enrolled site.
Stage a signed CDN release once on the Hub; Nodes pull over mTLS instead of the public CDN.
Hub can offer an update; each Node still confirms locally. Optional maintenance window per appliance.
MSI and portable apply from Software Updates after checklist confirm.
DMG download path; Docker host pull / compose recreate commands (Watchtower for standalone hosts).
Released July 5, 2026
Same topology canvas quality as a Node, scoped by enrolled site.
Device grid clusters by parent attachment; Hub site filter and expand/collapse all.
Business $40 per appliance; one key per node. Hub is not a license pool.
Uplink, SSID, location, and asset fields across Hub and Node with Human Property Shield.
Reconnect pulse, license mirror, onboarding loops, and Hub live alerts reliability.
Released July 5, 2026
Kind, port/SSID, and parent device with drawer fields, grid columns, and CSV export.
Hierarchical map with LAN/Wi-Fi styling, signal path highlight, and PNG/SVG export.
Backlog and MAC-first parent merge so Hub uplinks survive incomplete Node pushes.
Released July 3, 2026
Public /trust page, security docs cross-links, and sitemap / llms.txt updates.
Admin /audit trail with federation ingest and optional syslog forward.
Strict security-audit.ps1 checks and route policy refresh before promote.
Released July 3, 2026
Shipped plans moved to archive; living references trimmed for pre-publish review.
Installation, legal credits, and pricing copy checked against the Free + Business model.
Released July 5, 2026
Site and Settings promote monitor→control pairing only; Network Pulse plugin docs removed.
Getting Started and Installation link to the two-appliance OpenAVC + StacksAtlas recipe.
Device readings, run actions, and pinned macros visible without accordion taps.
Opening a device clears multi-select so the action bar does not block the drawer.
Dell Technologies and similar vendors no longer show the Logitech logo.
Microsoft.OpenApi bumped to 2.9.0 (patches circular-schema DoS advisory).
Released July 1, 2026
Serial, asset tag, firmware, and warranty in the drawer with Human Property Shield and OpenAVC enrichment.
Export asset fields, import template, and bulk import with Device ID round-trip matching.
PATCH hostname with federation sync; protected from discovery overwrites.
Essential default columns, semantic status filters, toolbar two-row layout, bulk ping/scan/type actions.
Current view, full registry, asset fields, and import template. No jargon.
Inline edits survive auto-refresh; security tooltips and device-type icons improved.
Released June 24, 2026
Link inventory devices to OpenAVC, pin macros, run commands, and read device state (not the Activity log).
Fleet operators use the same drawer; credentials stay on the owning Node.
Control Bridge is Business-appliance only (403 in portable).
Released June 28, 2026
Hub and Node dashboards, devices, users, and alerts get dedicated mobile layouts under the md breakpoint.
Homelab pass across Windows, Mac, and Linux before the next trains.
Released June 28, 2026
Collapsible report sections, sticky export, and faster find-in-page for large inventories.
Released June 24, 2026
Docs and marketing copy tightened around Free portable + Business $40.
Released June 27, 2026
Stability and UX fixes on the 1.8 train before OpenAVC and mobile sweeps.
Released June 29, 2026
KPI strip, Client/Building filters, expandable node table, fleet alert snippet, stepped enroll wizard.
Sticky header + Overview | Network | Security | Actions | History; federation security relay from Hub.
Alerts page: Live Events | Alert History | Audit/Replay with Hub fleet scope bar and deep links.
Release notes chip, pre-update checklist, scheduled maintenance apply, portable Business CTAs.
Hub opens enrolled macOS sites on HTTP :5050 (not :5000); federation API returns per-node ports.
Settings refresh for Free + Business ($40) two-tier model.
Released June 26, 2026
Documented anonymous API policy; SSO cookie handoff (no JWT in URL); same-origin CORS; auth rate limiting; Nmap target validation.
NuGet vulnerability scan + dotnet test in master-build; Dependabot for npm and NuGet.
Progress heartbeat during long Nmap runs; Hub federated status relay; Nmap+Npcap gating aligned with dashboard warnings.
Security route policy, lab-smoke.ps1, and close-out checklist for post-freeze operations.
Released June 2026
2-tier GTM copy, docs alignment, Docker portable compose, optional Deep Scan guide.
Official image excludes Nmap (NPSL); optional Dockerfile.deep-scan.example.
PDF export requires auth; license activate gated post-onboarding; federation pulse token auth.
Released June 25, 2026
Notarized, stapled universal DMG with Install helper and menu bar companion.
Operator-validated universal lipo + DMG publish path for release artifacts.
Released June 2026
Browser opens http://127.0.0.1:5000 (Win) or :5050 (Mac) without certificate warnings on first launch.
One-click trust for portable/MSI, manual .cer import, and platform-specific guidance in onboarding.
Released June 2026
Settings → Infrastructure → Software Updates: one-click Windows MSI and portable upgrades from releases.stacksatlas.com.
Pre-update snapshot before MSI apply; portable uses launcher backup.
Released June 2026
releases.stacksatlas.com stable and preview channels with signature verification.
GET /api/system/version and POST /api/system/updates/check; local publish pipeline (no GitHub Actions).
Released June 2026
One-file StacksAtlas-Portable.exe: no admin, tray icon, Close & remove wipes data.
Run StacksAtlas.app without Install: session data in ~/StacksAtlas-Trial.
Per-device audit and risk grades included in free tier; no license key required.
Released June 21, 2026
Single command lab deploy (`-Local -Deploy`) for Windows MSI, Linux Docker, and Mac universal DMG.
Universal DMG with Install StacksAtlas.app and menu bar companion (Developer ID + notarized in v1.7.6).
Unified Windows, Mac, and Linux release artifacts from a single build pipeline.
Hub tailnet identity, node transport toggle, reachability diagnostics, and field-validated SignalR sync.
Archive, tombstones, remote site reset, and re-enrollment dedup across Hub and enrolled nodes.
Express onboarding wizard with tier entitlements and Business/Pro fleet gates.
Released May 31, 2026
Integrated npm audit directly into the master-build pipeline. The build now enforces a 'High-Severity Fail' policy, preventing insecure code from reaching production.
Resolved 10 high-severity vulnerabilities across the React toolchain (Vite, Rollup, and Next.js) to achieve a zero-vulnerability state.
Upgraded the documentation site to Next.js 16.2.6 and implemented package overrides to resolve critical CSRF and PostCSS XSS vulnerabilities.
Released May 10, 2026
Full OpenID Connect support for Google, Azure AD, and Okta. Features a robust 'Capture-and-Forward' redirect engine for complex NAT/Proxy environments.
Added native bind-based LDAP support with JIT provisioning, allowing enterprise users to log in using existing corporate credentials.
Introduced a dynamic engine to map external groups (OIDC claims, LDAP DNs) directly to StacksAtlas permissions (Admin, Standard, Viewer).
Integrated server-side diagnostic tools to verify OIDC metadata and LDAP bind credentials in real-time before saving configurations.
Hardened system security by enforcing strict RBAC policies on traceroute, diagnostics, and management tools.
Intelligent UI state management that automatically disables destructive actions for View-Only users, preventing unauthorized network changes.
Launched a secure self-service profile endpoint, allowing all users to manage their personal alert preferences without administrative rights.
Implemented a masked 'Write-Only' pattern for sensitive configuration fields, ensuring Client Secrets are never exposed in the UI.
Native payload formatting for Slack (Block Kit), Discord (Rich Embeds), and Microsoft Teams (Adaptive Cards 1.5+). Allows for deep integration into enterprise notification workflows.
Implemented exponential backoff with jitter and a smart Circuit Breaker mechanism to pause failing endpoints, ensuring appliance performance remains stable during external outages.
Added a one-click 'Test Payload' feature and real-time delivery history logs directly in the management UI for instant verification of external alert routing.
Features encryption-at-rest for URLs, masked secret management, and optional HMAC-SHA256 signing for cryptographically verified payload integrity.
Released April 26, 2026
Implemented a 'Ping-First' strategy for subnet sweeps, eliminating the 10-second hang caused by blocking ARP calls.
Reduced mDNS listen windows and increased scan intervals to 5 minutes, significantly lowering network 'tax' during discovery.
Integrated granular phase-timing into the engine via Debug logs, enabling instant performance audits directly from the Dashboard UI.
Introduced a 'Debug Mode' switch on the Logs page for instant, verbose diagnostics without requiring a service restart.
Restored the background security scoring engine to the main sync loop for live vulnerability updates.
Re-implemented event logging for device discovery, roaming, and status changes to restore full history visibility.
Restored Latency History and Stability Score increments to ensure accurate long-term health analytics.
Introduced real-time event streaming to SIEM platforms like Splunk and Elastic, enabling enterprise-wide security correlation.
Consolidated Network Ports and SIEM configuration into a single, high-authority 'Appliance Infrastructure' section with atomic restart controls.
Migrated to a secure, public licensing handshake. Master API Keys are no longer stored within the appliance, significantly hardening the security posture.
Introduced a tiered offline verification system (30-day soft warning, 60-day hard expiry) to ensure business continuity in remote or air-gapped sites.
Completely eliminated legacy 'Mock Mode' bypasses, ensuring mandatory, authoritative validation for all production environments.
Fixed a cross-platform encryption issue preventing database migration between Windows and Docker/Linux.
Hardened auto-detection to ignore 169.254.x.x subnets while keeping them manually selectable.
Released April 25, 2026
Eliminated identity 'ping-pong' by centralizing all device classification logic into a single, authoritative reconciliation engine.
Implemented a hierarchical identity system that prevents low-confidence discovery data from overwriting manual names or high-confidence fingerprints.
Refactored the core API infrastructure into a modular, service-oriented architecture for significantly improved reliability and cold-start speed.
Upgraded internal database encryption with 256-bit peppered entropy and DPAPI-hardened key protection.
Migrated to PBKDF2 with 600,000 iterations and implemented O(1) constant-time API key validation to mitigate timing attacks.
Introduced a sophisticated 0-100 security scoring engine with structured risk tracking for unauthenticated services and remote exposure.
Optimized socket hygiene and concurrency models to boost port enrichment speeds by over 300% on high-density networks.
Implemented full bitwise CIDR masking for all subnet sizes, ensuring 100% accuracy for massive /16 corporate environments.
Moved high-concurrency environment tuning to the host level to eliminate 'ramp-up' latency during initial network sweeps.
Retired the legacy power icon for a modern User Avatar system with integrated profile management and alert diagnostics.
Converted the scan engine to a push-model reactive system for instantaneous, millisecond-accurate progress feedback in the UI.
Standardized all settings layers to use high-performance atomic write patterns, eliminating I/O latency and disk corruption risks.
Released April 19, 2026
Smashed the 'Scan Stall' bug by implementing persistent negative caching for DNS and SNMP. Reduces sparse network scan times by up to 40%.
Scan parameters now apply instantly via a CancellationToken interrupt system. Changes to subnets or intervals no longer wait for the engine sleep cycle.
Eliminated scan 'ramp-up' latency by scaling the .NET ThreadPool proactively to match configured parallelism, preventing thread starvation.
Introduced a high-performance terminal UI for real-time engine logs, featuring millisecond-accurate stage timing and severity filtering.
Eliminated a hidden 5-strike grace period. The engine now respects your configured status thresholds immediately.
Docker/restricted devices responding only to ICMP now show as 'Online' with an 'Unknown MAC' instead of being rejected.
The engine now explicitly logs which IPs were dropped by synthetic filters, providing full transparency into discovery outliers.
Massive expansion of the visual registry including premium logos for Dell, Synology, Samsung, Sennheiser, Yamaha, and major Pro-AV brands.
Smashed the 'Ugly Logo' placeholder bug by replacing the legacy text with a professional, high-quality gradient wordmark.
Refactored detection logic to handle substring matches and common vendor variations (e.g. HPE/Aruba) automatically.
Optimized the discovery engine to support managed network hardware that prioritizes ICMP over ARP responses.
Reduced default discovery timeouts from 2s to 1s to ensure rapid failure detection on large subnets without impacting accuracy.
Released April 18, 2026
Released the first-party StacksAtlas bridge for the OpenAVC platform. Enables real-time 'Network Pulse' status cards on AV control surfaces.
Relaxed Ghost-Ping protection to allow devices that respond to ICMP but delay ARP requests (common in managed switch security profiles).
Hardened neighbor verification to require active ICMP/ARP verification for all passive neighbors, eliminating stale ARP 'ghost' entries.
Running a Traceroute or Deep Scan now automatically promotes the target device to 'Online' status.
Complete refactor of the release history UI with real-time search, collapsible entries, and optimized filtering logic.
Unified industrial-grade icons across all historical release notes for consistent visual governance.
Released April 13, 2026
Implemented a 'Physical Reality Check' for all scans. If a sweep returns suspiciously high counts (>85%), a mandatory triple-verification loop is triggered automatically.
Nmap discovery now monitors OS network buffers for 'Resource temporarily unavailable' errors, aborting unreliable scans rather than reporting false data during system load.
Added randomized micro-delays (0-20ms) to parallel pings to distribute peak network stack pressure and prevent packet reflections.
Full UI-driven control over HTTP/HTTPS ports with a graceful, persistent restart-and-migrate workflow. No command-line access required.
Replaced standard Swagger with a beautiful, high-performance Scalar UI at /api-docs. Securely gated behind Admin roles for internal development.
Upgraded self-signed certificate generation with modern .NET 10 APIs and 'Basic Constraints: CA=True' to satisfy strict browser trust requirements.
Built a robust PBKDF2 hashed token system for external API access, replacing the legacy static JWT model with individually revocable keys and usage auditing.
Updated commercial tier scaffolding (superseded: current model is Free portable + Business $40; see pricing on the home page).
Released April 5, 2026
Implemented a passive 'Stage 0' discovery layer using netstat and arp for instantaneous device recognition on Darwin, bypassing traditional socket throttling.
Refined Role-Based Access Control to allow 'Normal' users read-only access to Dashboards, Topology, and Alert History while strictly gating administrative settings.
Automatic path resolution for Nmap on macOS (Homebrew or Bundle paths) with hardened privileged execution for OS fingerprinting.
Replaced manual fulfillment uploads with an automated Cloudflare R2 pipeline. All installers now support versioned permalinks.
Integrated native Windows MSI generation with industrial code signing into the global CI/CD pipeline.
New root-level automation script for 'One-Click' build, sign, distribute, and git-sync operations.
Implemented 'Neutral Skip' logic across all platforms (Windows, macOS, Linux/Docker) to prevent accidental public releases while keeping the CI dashboard green.
Released March 28, 2026
StacksAtlas can now be deployed natively on Apple Silicon/Intel Macs and any Linux server (Ubuntu, Synology, Unraid) via Docker!
Resolved the 'Ghost Ping' bug on Linux by pivoting to a native Nmap discovery backend, ensuring 100% accurate device counts in Docker.
Implemented GitHub Actions to automatically build and publish Docker images and native macOS binaries on every release.
Released March 1, 2026
A beautiful, interactive Canvas-based Force-Directed Graph mapping the entire scanned subnet in real-time.
Native SNMP v2c support for fetching System Name and Description from managed hardware (Switches, NAS, Routers).
Replaced legacy Windows PInvoke with a robust, cross-platform engine for universal networking compatibility.
Integrated Recog XML signature engine for industrial-grade hardware identification.
Simultaneous ARP+Ping 'racing' logic reduces subnet sweep times by up to 30%.
Fixed startup race conditions; auto-detection now handles late network interface initialization gracefully.
Scanning now starts instantly after creating the initial admin account, no restart required.
Released February 16, 2026
Fixed a critical race condition causing service hangs on startup. Startup is now sub-second.
Fixed race condition where acknowledged security risks were reverting.
Resolved a 'Invalid URL' crash in ApiService and a LiteDB mapping exception.
Fixed regressions in 'Show Archived' toggle and 'New' filter logic.
Fixed issue where manual device edits were not persisting.
Implemented immediate visual feedback for risk acknowledgement.
Added one-click launch support for SSH, Telnet, and FTP.
PDF/CSV reports now include Security Grades (A/C/F).
Added 'Hard Delete' option for complete removal.
Smart sorting for IP addresses in lists and reports.
Manual reset capability for device performance counters.
Released February 7, 2026
'Magic Packet' support to boot up offline workstations remotely.
Visual Traceroute to identify latency bottlenecks.
Historical tracking of MAC-to-IP bindings to spot 'drifting' devices.
Detection of EOL OS (XP/Win7) for immediate risk forecasting.
Added dependency disclosure (Npcap/Nmap).
Fixed critical race conditions and deadlock prevention.
Modernized scrollbars and layout refinements.
Cutdown sweep time from 30s to 5s.
Released January 29, 2026
Integrated Nmap scanning for deep service discovery.
Correctly activated licenses now support 30-day offline grace period.
New progress bar UI provides live feedback during deep scans.
Installer now handles Nmap dependencies automatically.
Native detection for IP Cameras, NDI Video, and Storage Infrastructure.
Splash screen and lock contention resolution.
Automated global repair of legacy stability data.
Native fetching of web page titles for better ID.
Real-time identification of PTP Master clocks.
Added secure encrypted database migration export.
Released January 25, 2026
Enhanced classification for Dante, Q-SYS, Biamp, Shure, and Crestron.
Manual edits to Model or Vendor are protected from automated overwrites.
Specific icons for Microphones, Amplifiers, Mixers, and NAS.
Released January 20, 2026
Added capability to restart the host service/system from the UI.
Added Network Adapter selection and transparency.
Added Backup & Restore (Snapshot) functionality.
Ensuring secure and trusted deployments.
Initial Public Release
Industrial-grade network scanning and identification.
Weighted analytics for predicting hardware failure.
Professional PDF and CSV exports for inventory audits.