-
9.0.0-beta.4
Pre-releaseSome checks failedGenerate Release / semantic-release (push) Has been skippedDocker Test / build image (push) Successful in 11m51sGrinder Container IT / containers (push) Failing after 6m28sBuild Release / Preparations (push) Successful in 9sDocumentation / Help image (push) Successful in 2m26sDocumentation / Writerside webhelp (push) Successful in 2m26sTest / build (push) Successful in 30m47sBuild Release / JARs, media and checksums (push) Successful in 20m21sQodana / notify (push) Successful in 38sQodana / scan (push) Successful in 11m53sBuild Release / Docker images (push) Successful in 15m51sGrinder Container IT / containers (pull_request) Failing after 6m32sDocker Test / build image (pull_request) Successful in 12m1sBuild Release / Forgejo release (push) Successful in 2m11sBuild Release / VirusTotal scan (push) Successful in 1m30sBuild Release / Publish Maven (push) Successful in 8m50sBuild Release / News on Discord (push) Successful in 23sBuild Release / Mirror release outward (push) Failing after 7m9sTest / build (pull_request) Successful in 30m51sreleased this
2026-09-27 20:33:21 +02:00 | -1537 commits to main since this release✂️ Refactor
- api: make the chunked-line backend reachable from a test (80e4a2b)
- api: one local runner, taking labelled commands (2a68d10)
📔 Docs
- append the container-ownership audit, with every finding and its resolution (2bea631)
- correct four stale references to
cleanup()and a configuration-cache claim it was part of (f7b6d6c) - make the self-extracting server pack buildable off Linux, and runnable on Windows (885580c)
- record that a bind mount is resolved by the daemon, and re-derive the api count (bab9e35)
- record that a gate nobody sets is an absent guard, not a skipped one (650c321)
- record the benchmark source set and the three things it does not inherit (166d151)
- record the Rosetta exit-code trap and where the PowerShell checks live (355e875)
- record what a repository-wide assertion audit found (66913f1)
- ci: record that a Forgejo run has two numbers and the routes disagree (c493137)
- grinder,ci: record the two labels, and that two refs build every commit in parallel (ee0cdd8), closes #678
📦 Other
- regenerate the license agreement for the dependency bumps (8bc69ef)
- update the shipped manifest snapshot to Minecraft 26.3 (152f895)
🦊 CI/CD
- bump dokka 2.1.0 -> 2.2.0 (19096ae)
- bump jackson, springdoc, bouncycastle and install4j (5bfca6b)
- bump Kotlin 2.4.10 -> 2.4.20 (3b242ca)
- bump pf4j 3.15.0 -> 3.16.0 (fdc1920)
- bump Spring Boot 4.1.0 -> 4.1.1, plugin and BOM together (5acc101)
- bump the license-report plugin 3.0.1 -> 3.1.4 (b53955f)
- app: stop re-declaring what java-conventions already does for
test(f7e1d0f) - grinder: give the store benchmark its own source set (9eaea96)
- ask Qodana for @Test methods that assert nothing (f4a761e)
- give the grinder's container tests the daemon to themselves (de38369), closes #678
- run the container-engine integration tests on every push (f273ca5)
🧪 Tests
- api: ask fish and PowerShell themselves whether the templates parse (aa77104)
- api: make three tests that only looked like guards actually assert (ecfef13)
- api: pin that a template probe's container can actually see the templates (205474d)
- api: pin that staging writes no empty file, and that a missing jar resource is loud (3a52fc9)
- api: pin that the Batch wrapper starts a pack whose path contains an apostrophe (22bcf36)
- api: pin the other copyFileFromJar overload, which had the same hole (3f391ef)
- api: pin the PowerShell installer-Java override and its fallback on every push (87660a6)
- grinder: pin that a container says which engine made it (e0dfbbf)
- grinder: stop the store benchmark claiming to be a test (d0caf44)
🚀 Features
- grinder: give a container engine an identity, before anything uses it (6e75484)
🛠 Fixes
- api: close the same hole in the directory-taking copyFileFromJar, and repair the test it fooled (bf29b30)
- api: copy the templates into the probe container instead of bind-mounting them (fe961ca)
- api: decide the template checks by completion marker, not exit code (f2d97ca)
- api: hand PowerShell the start script's path instead of pasting it into a string (8a85fdb)
- api: make a PowerShell glob that matches nothing a failure, not a silent pass (e5efd09)
- api: stop staging a Java batch template that does not exist, and fail loudly when one is missing (25f3355)
- app: stop logging a stack trace for a database that is merely absent (136a27a)
- app: tell the analyser that GridFS really does return null, rather than let it be wrong twice (6a72173)
- ci,grinder: authenticate the ghcr pull, and finish raising the container ITs' waits (40921ac)
- ci: link the Qodana artifact by run id, which is not the number in a run's URL (06eb59a)
- ci: upload plugin-grinder's test results too (ecaf2cf)
- grinder,ci: close the audit's findings — a vacuous assertion, a loose one, and a silent skip (797c247)
- grinder: assert what close promises, not what a quiet daemon happens to deliver (240dd82)
- grinder: drop the benchmark's unused import and its unresolvable KDoc link (cb61d70)
- grinder: make the benchmark a program, because a Test task cannot escape
check(ad52693) - grinder: make the ownership fixture stoppable, which is what the third guard was failing on (283710a)
- grinder: reattach three KDoc blocks the container-IT edits stranded (7d70e44)
- grinder: scope the container IT's assertions to the engine that made the containers (589c1d3)
- grinder: stamp which engine made a container, and never reap your own (87e8ce6)
VirusTotal
ServerPackCreator-9.0.0-beta.4.jar- https://www.virustotal.com/gui/file-analysis/ZDM3ZGQ1NDdkNTliMzdmY2VjMzk1ZDk0MGZlZDkwY2M6MTc5MDUzOTAxMA==serverpackcreator-api-9.0.0-beta.4-javadoc.jar- https://www.virustotal.com/gui/file-analysis/MjVhOWI4NTdmYWNhY2FmNTRiN2QyNDkzNmNmMTk1NDE6MTc5MDUzOTAxOA==serverpackcreator-api-9.0.0-beta.4-sources.jar- https://www.virustotal.com/gui/file-analysis/OWM5YzE5MjA4ZWQ5MjlhMjc5NmNjNDVhMjgzMjBlYjk6MTc5MDUzOTAyMQ==serverpackcreator-api-9.0.0-beta.4.jar- https://www.virustotal.com/gui/file-analysis/OTQ3NDc1MzkwZjMzZjQxOTE1ZmRlZjFjMWYyZDhhNmQ6MTc5MDUzOTAyMw==serverpackcreator-app-9.0.0-beta.4-javadoc.jar- https://www.virustotal.com/gui/file-analysis/MzhhMzVmMjBjMzdiMGQ0MGZlODkxN2I2ODMzMWJmODQ6MTc5MDUzOTAyNQ==serverpackcreator-plugin-example-9.0.0-beta.4.jar- https://www.virustotal.com/gui/file-analysis/OGNkYjFiNGUzNWU5MWQxYzU0MmIwNTBiYjM4N2U0Yzk6MTc5MDUzOTAyNg==ServerPackCreator-9_0_0-beta_4-Installer-Linux-amd64.sh- https://www.virustotal.com/gui/file-analysis/YWU0NTY2ZWU2OTg2NDVmOGI2NjA3ZDgwYjJlZTM2YTI6MTc5MDUzOTAzNA==ServerPackCreator-9_0_0-beta_4-Installer-Mac.dmg- https://www.virustotal.com/gui/file-analysis/ZDk5NzAzNGM3ZGI2NzMzMjQ0NGE5OWVhNjBhMjBkYjQ6MTc5MDUzOTA0Mg==ServerPackCreator-9_0_0-beta_4-Installer-Windows-x86_64.exe- https://www.virustotal.com/gui/file-analysis/MWNhN2ZiODFhMzg2MTQyNGQwMjVlZDY0MGEwZGVjMzc6MTc5MDUzOTA1MQ==
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
continuous
Pre-releaseAll checks were successfulDocumentation / Writerside webhelp (push) Successful in 2m42sGrinder Container IT / containers (push) Successful in 6m23sContinuous / Build JAR (push) Successful in 9m23sDocker Test / build image (push) Successful in 13m57sGrinder Container IT / containers (pull_request) Successful in 6m49sQodana / scan (push) Successful in 15m24sDocker Test / build image (pull_request) Successful in 15m53sDocumentation / Help image (push) Successful in 4m14sTest / build (push) Successful in 10m42sContinuous / Build AppImage (x86_64) (push) Successful in 2m14sContinuous / Build AppImage (aarch64) (push) Successful in 2m36sTest / build (pull_request) Successful in 11m40sQodana / notify (push) Successful in 31sContinuous / Build Install4J Media (push) Successful in 9m13sContinuous / Continuous Pre-Release (push) Successful in 4m8sreleased this
2026-09-27 18:11:01 +02:00 | 0 commits to develop since this release🔄 Continuous Dev-Build
Built: 2026-09-27 18:13:54 UTC
Commit:40921acdcc7029f2f69832c18ca3f450a0c2b382
This is an automated development build, updated every time changes are pushed to
develop.⚠️ Warning: Do not use unless you have been told to, or are curious about the contents of the dev build.
🚫 Do not link to this release.
Downloads
-
Source code (ZIP)
139 downloads
-
Source code (TAR.GZ)
53 downloads
-
Source code (ZIP)
-
9.0.0-beta.3
Pre-releaseSome checks failedGenerate Release / semantic-release (push) Has been skippedDocker Test / build image (push) Successful in 18m21sBuild Release / Preparations (push) Successful in 8sDocumentation / Help image (push) Successful in 2m22sDocumentation / Writerside webhelp (push) Successful in 2m8sTest / build (push) Successful in 31m31sQodana / notify (push) Successful in 30sQodana / scan (push) Successful in 12m53sBuild Release / JARs, media and checksums (push) Successful in 30m58sBuild Release / Docker images (push) Successful in 19m34sBuild Release / Forgejo release (push) Successful in 3m30sBuild Release / Publish Maven (push) Successful in 9m5sBuild Release / VirusTotal scan (push) Successful in 1m35sBuild Release / News on Discord (push) Successful in 31sBuild Release / Mirror release outward (push) Failing after 5m52sreleased this
2026-09-24 20:58:01 +02:00 | -1476 commits to main since this release✂️ Refactor
- api: give ServerPackGeneration a place for scan findings (35e6e66)
- api: give the modpack malware scan an observable seam (8b108fb)
- api: make ServerPackHandler.run's security scan injectable (a260780)
- app: give DatabaseStorageService the delete it never had (9cd0297)
📔 Docs
- analyse test depth and residual defects in the upload pass (f377983)
- audit the upload/check/storage pass against the conventions (e768516)
- correct four doc comments that described code that does not exist (3fb0333)
- mark the size row as app-scoped, not published-API (03ba296)
- record how each audit and analysis finding was closed (d2a2c46)
- record the new test seams, the springdoc correction, and B41/B42 (d5ec010)
- record the test-database follow-up and refresh the app count (c648840)
- record the upload/check/storage pass and refresh the counts (ea22bf6)
- api: document SecurityScans' companion instead of leaving it bare (310494e)
- api: document the last two undocumented companions (4940f18)
- api: say plainly that checkForInvalidPathCharacters returns true when CLEAN (9a088d5)
- app: document ConsolePrompt's companion (0fb7c27)
- app: record the embedded MongoDB setup and its landmines (8b61065)
🧪 Tests
- api: pin that a bad exclusion filter names the exclusion field (ae375df)
- api: pin that a modpack's server-icon survives having a manifest (71b348e)
- api: pin that a Modrinth index is actually read (cf05195)
- api: pin that a scan finding is not a generation failure (05c8eb9)
- api: pin that a ZIP modpack is scanned after it is extracted (6703b71)
- api: pin that an unextractable modpack fails its checks (e44ba09)
- api: pin that trimming a trailing dot trims only the trailing one (8ef6f2e)
- api: pin that unzipArchive declares no checked exception to Java (060266e)
- app: boot the context test against the embedded database (e94e32d)
- app: bound the suite's MongoDB server-selection timeout (c98cc3f)
- app: characterize the storage seam and both cleanup schedules (187ecad)
- app: cover the 415 refusal and both sweeps against a real database (bcb25ed)
- app: pin how a recorded download is identified and ordered (59c2cff)
- app: pin that a rejected upload costs nothing durable (5a857c3)
- app: pin that a stored file reports its size in bytes (3657fcb)
- app: pin that a throwing task must not kill the generation queue (fdffd4a)
- app: pin that an archive never travels through the heap (c9567b3)
- app: pin that an upload filename cannot steer the path it is written to (3002c30)
- app: pin that an upload name cannot inject a Content-Disposition parameter (65ced9b)
- app: pin the destructive edges of both nightly sweeps (131501f)
- app: pin the GridFS id round-trip, the empty miss, and the delete (30b335d)
- app: pin the paginated event sort too (eb76d83)
- app: repair a guard that stopped reproducing its own condition (aa0fe0e)
- app: run the persistence tests against a real MongoDB, in-process (4fbba1d)
- frontend: pin the regeneration path's ids and its error handler (5899b57)
🛠 Fixes
- make a generation's success mean the generation worked (6b7d890)
- report archive sizes in bytes, and stop hiding small packs (0111d3d)
- stop handing server paths and stack traces to anonymous callers (f5755f7)
- stop the regeneration path reporting ids that do not exist (8e10961)
- api: dispatch to the Modrinth manifest parser that nothing called (872900a)
- api: find a modpack's server-icon inside the modpack (62b5c26)
- api: handle an unreadable modpack directory instead of asserting on it (9148e28)
- api: let a failed extraction fail the modpack instead of vanishing (645b181)
- api: report a bad exclusion filter as an exclusion problem (c7bed07)
- api: restore Java source compatibility on unzipArchive (c9639c5)
- api: scan the modpack after it is extracted, not before (cb495c6)
- api: trim only the trailing dot or space, in both sanitisers (22ddd51)
- app: build the Content-Disposition header instead of interpolating it (011e782)
- app: declare the upload endpoint as multipart, and regenerate the spec (8a9e337)
- app: give a recorded download its own id, and sort on fields that exist (f05d28c)
- app: keep an upload's filename out of the path it is written to (57b172c)
- app: keep the generation queue alive when a task throws (fc8b89c)
- app: make both nightly sweeps survive the rows they trip over (282fa35)
- app: reclaim an orphaned pack once, not once per directory entry (94e38c1)
- app: reclaim the GridFS copy on delete, and return empty for a miss (25908c6)
- app: stream archives instead of carrying them through the heap (8bbd000)
- app: sweep orphaned files through storage, and stop asserting fileID (5aa02a7)
- app: type the GridFS miss honestly, and prove the guard fires (f150c06)
- app: validate an upload before storing it, and hash it without a heap copy (2a13cd2)
- build: publish kotlin-stdlib with a version, unbreaking the Maven release (43dc174)
VirusTotal
ServerPackCreator-9.0.0-beta.3.jar- https://www.virustotal.com/gui/file-analysis/YTgyNmNlOWNjNGZmOTVjMWY2YWYxZTZhZmFkZjg3ZWI6MTc5MDI4MTQyNw==serverpackcreator-api-9.0.0-beta.3-javadoc.jar- https://www.virustotal.com/gui/file-analysis/NWE3MDZlZGU0NWZjNGRlMzM2NTk5NzkxNmFhM2I0NmQ6MTc5MDI4MTQyOQ==serverpackcreator-api-9.0.0-beta.3-sources.jar- https://www.virustotal.com/gui/file-analysis/YzhhZGVmYzM4M2U3ZTA1NTEyZGNlZmVkZWIxZTRhN2M6MTc5MDI4MTQzMQ==serverpackcreator-api-9.0.0-beta.3.jar- https://www.virustotal.com/gui/file-analysis/MWZlN2IzOWIzYjNhMDBkMmJkY2NhZTE4ZGE3OTFjZDY6MTc5MDI4MTQzNA==serverpackcreator-app-9.0.0-beta.3-javadoc.jar- https://www.virustotal.com/gui/file-analysis/ZmQzZTZlMjA2M2NjMTg2MTEzZmY4OGFjMzVmYzZlNjE6MTc5MDI4MTQzNg==serverpackcreator-plugin-example-9.0.0-beta.3.jar- https://www.virustotal.com/gui/file-analysis/YTdhODA0ZDExNTBhMmNiMDViMjkyZmYxZmQ3NTViNmU6MTc5MDI4MTQzNw==ServerPackCreator-9_0_0-beta_3-Installer-Linux-amd64.sh- https://www.virustotal.com/gui/file-analysis/OGY5MmQ3MGZkOWM1NTNiZDIyOTBkZjU5OTIxYzg3YmQ6MTc5MDI4MTQ0Ng==ServerPackCreator-9_0_0-beta_3-Installer-Mac.dmg- https://www.virustotal.com/gui/file-analysis/Y2I0ZjE2M2E2YTFkMDk0ZmU0ODJhYTc3M2U5ZTJmMmE6MTc5MDI4MTQ1NQ==ServerPackCreator-9_0_0-beta_3-Installer-Windows-x86_64.exe- https://www.virustotal.com/gui/file-analysis/OThjMDFhYzM0N2Y5YzFjMzBhYjEzZGI0YTMyNDAyODg6MTc5MDI4MTQ2Mw==
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
9.0.0-beta.2
Pre-releaseSome checks failedGenerate Release / semantic-release (push) Has been skippedDocker Test / build image (push) Successful in 18m10sBuild Release / Preparations (push) Successful in 1m9sDocumentation / Help image (push) Successful in 2m34sDocumentation / Writerside webhelp (push) Successful in 2m43sQodana / notify (push) Successful in 11sQodana / scan (push) Successful in 14m15sTest / build (push) Successful in 30m50sBuild Release / JARs, media and checksums (push) Successful in 27m53sBuild Release / Forgejo release (push) Successful in 3m0sBuild Release / VirusTotal scan (push) Successful in 1m42sBuild Release / Docker images (push) Successful in 19m38sBuild Release / Publish Maven (push) Failing after 6m27sBuild Release / Mirror release outward (push) Has been skippedBuild Release / News on Discord (push) Has been skippedreleased this
2026-09-22 20:49:06 +02:00 | -1406 commits to main since this release✂️ Refactor
- apply the five Qodana style notes that were actually improvements (5194af2)
- api: give the versionmeta snapshot locals speaking names (2b4228b)
- app: fold the four-site stdin test into ConsolePromptTest (351a264)
- app: read the home directory through ConsolePrompt (7d09c22)
- app: return whether a headless verb did what it was asked (4fcb499)
- clientside: let a guard see which client a fetcher got (69c1584)
- grinder: drop what the configuration extraction left behind (5d5435e)
- grinder: give the snapshot cache a window it does not yet use (05fed81)
⏩ Performance
- grinder: derive the report's selection once per store change (d0c0e5a)
- grinder: page with subList instead of copying the tail (b533afc)
- grinder: stop the report walking the whole store per request (8bfa261)
📔 Docs
- audit the Qodana-817 remediation (2f7c47e)
- close B39 and half of B38, and open B40 for the baseline (c7a2e37)
- close B40, and record why it landed by other means (2f1ef98)
- close the analysis findings, and retract one of them (ecc6234)
- close the Qodana-817 audit findings (bc39f0b)
- close two audit findings on the 2026-09-19/20 commits (710c2f7)
- correct three test counts, and record what the KDoc defect teaches (a3a149b)
- describe updating a server pack as a feature you can rely on (2dafb32)
- keep the hand-written 9.0.0-beta.1 release notes in the repo (a88c08a)
- reattach four KDoc blocks that had come loose from their declarations (60ab1f5)
- reattach or retire fourteen more KDoc blocks that had come loose (dae6834)
- reattach the two orphaned blocks the new guard found (a6ec920)
- record M4 closed, with the mutation that proves each new guard (52074eb)
- record that the root-level documents have two generated copies (6414f91)
- record the Qodana verdicts and the scan's blind spot as B38 and B39 (47a1603)
- the READMEs speak the six verdicts, not the deleted confidence scale (57434cb)
- app: record the ConsolePrompt landmine and why it exists (f689fa4)
- app: record the exit-code contract and its landmine (82f28d5)
- app: say what
runwith no subcommand actually does (8a6fa73) - ci: make the awk escaping comment readable (762ec50)
- ci: record the two undeclared limits the release notes outgrew (37f4e43)
- clientside: landmine the per-instance HttpClient, and correct the count (34fff82)
- clientside: restore the two arguments a deleted doc copy took with it (9c76272)
- grinder: name the firewall rule that was never there (d4fecb0)
- grinder: record what the report cached and what it quietly did not (c80ba52)
- grinder: record why the report stopped answering (eadf345)
- grinder: the report was never wedged, and the docs said it was (1239418)
- readme: document generating a server pack from the commandline (9de625c)
📦 Other
- qodana: encode the twelve standing won't-fix verdicts (8784620)
- qodana: refuse the eleven style notes that were wrong or worse (6b91956)
🦊 CI/CD
- qodana: generate the sources the scan cannot see (2d2a2d6)
🧪 Tests
- api: close the update mechanism's remaining test debt (2f37954)
- api: pin that no KDoc block comes loose from its declaration (5410807)
- api: pin what regenerating over an existing server pack does today (65071b6)
- api: red pin for a first generation losing the local variables.txt (b57efd7)
- api: red pin for a list-setting overwriting its own default (942382d)
- api: red pins for lazy mode ignoring protection and reporting nothing (f5ef805)
- api: red pins for what an update must guarantee (960e186)
- app: pin ConsolePrompt (RED) (3d024a3)
- app: pin that a path argument is reported, never thrown (RED) (4a44b38)
- app: pin that an interactive prompt leaves System.in open (RED) (f2c0d3a)
- app: pin that lang accepts the locale it displayed (RED) (2f38d92)
- app: pin the headless outcomes (one RED) (f4df200)
- clientside: red pin for a new HttpClient per fetcher (c7906d6)
- grinder: red pins for the three ways the report scales with the store (bfae849)
🚀 Features
- api: make updating an existing server pack safe for a running server (ee629eb)
- app: implement ConsolePrompt (80df991)
- app: take Update Server Packs out of its experimental state (006e46a)
- build: name the AppImage _experimental, and stop spelling that name twice (74a73b3)
- grinder: serve the report through the cache, on a configurable pool (148ccb3)
🛠 Fixes
- api: decide preservation once, and stop lazy mode ignoring it (5bc4e27)
- api: keep server.properties and variables.txt in an updated pack's archive (6ac06c3)
- api: stop a list-setting from overwriting its own shipped default (011af4f)
- app: ask for a config file, not a home directory (b2cd0ab)
- app: exit non-zero when a one-shot run failed (caa24ed)
- app: offer the locales lang actually accepts (0b58755)
- app: report a bad path to a headless verb instead of throwing (c539cfd)
- app: report a configs-directory that cannot be read (43e649e)
- app: say "directory" when cgen rejects a non-directory (b6dd98b)
- app: stop the interactive prompts closing System.in (b4c8e41)
- build: package the api javadoc jar during build, not just generate it (4e58c66)
- build: publish the library, not just its javadoc (5229508)
- ci: cap the mirrored GitHub release body at 125,000 characters (e4f1c53)
- ci: escape the changelog version where awk cannot undo it (7b5b3a3)
- ci: skip assets the Forgejo release already carries (02dd499)
- ci: stop curl -sf hiding why a release step failed (f889895)
- ci: the release body travels in a file, never in curl's argv (ae3102c)
- clientside: share one HttpClient instead of one per fetcher (5f78389)
VirusTotal
ServerPackCreator-9.0.0-beta.2.jar- https://www.virustotal.com/gui/file-analysis/NThhNDJjNmQxNWViNjM1YzM3OTI0ZmQxODkwMzFjMjU6MTc5MDEwNzQwMA==serverpackcreator-api-9.0.0-beta.2-javadoc.jar- https://www.virustotal.com/gui/file-analysis/OTg2ZWQ0ZWVkOGY2ZTFiNmY2ZjRjYWRmNGU3ZWM0ZTQ6MTc5MDEwNzQwMg==serverpackcreator-api-9.0.0-beta.2-sources.jar- https://www.virustotal.com/gui/file-analysis/MzVkNTNmOThlMGRhZTNhY2I1NWRkYmVlNWVlNTlhN2U6MTc5MDEwNzQwNA==serverpackcreator-api-9.0.0-beta.2.jar- https://www.virustotal.com/gui/file-analysis/NmNjMWVjMWRmNTcwZTM0N2VhZTY4NDNmYTQ3NzFmY2Q6MTc5MDEwNzQwNw==serverpackcreator-app-9.0.0-beta.2-javadoc.jar- https://www.virustotal.com/gui/file-analysis/YmE4YzkxODhiZTBlN2JhMTQ0OWZlODE1NTJmYzAzMzE6MTc5MDEwNzQwOQ==serverpackcreator-plugin-example-9.0.0-beta.2.jar- https://www.virustotal.com/gui/file-analysis/ZGRkNzM4ODJlOWNjZjFhMWFiNTA2ZDU3YTkyZmMyNzQ6MTc5MDEwNzQxMA==ServerPackCreator-9_0_0-beta_2-Installer-Linux-amd64.sh- https://www.virustotal.com/gui/file-analysis/MWI5NjRjZTdiNWJhZDViM2UxMTZiZjI2NGNmYTJkNTY6MTc5MDEwNzQxNw==ServerPackCreator-9_0_0-beta_2-Installer-Mac.dmg- https://www.virustotal.com/gui/file-analysis/ZTNmY2MzZDU1NGU5YWFmZTMxYTUxNTU1NmVjOWJiMTM6MTc5MDEwNzQyNg==ServerPackCreator-9_0_0-beta_2-Installer-Windows-x86_64.exe- https://www.virustotal.com/gui/file-analysis/ZWQ5OTlmMWNmNzc4MmYzMTM5ZmY1ZTQ4MzcyMGU3MTE6MTc5MDEwNzQzNQ==
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
9.0.0-beta.1
Pre-releaseSome checks failedGenerate Release / semantic-release (push) Has been skippedBuild Release / Preparations (push) Successful in 35sDocker Test / build image (push) Successful in 18m30sDocumentation / Help image (push) Successful in 3m15sDocumentation / Writerside webhelp (push) Successful in 2m33sQodana / notify (push) Successful in 17sQodana / scan (push) Successful in 11m27sTest / build (push) Successful in 28m15sBuild Release / JARs, media and checksums (push) Successful in 29m47sBuild Release / Forgejo release (push) Failing after 1m12sBuild Release / VirusTotal scan (push) Has been skippedBuild Release / Docker images (push) Successful in 18m30sBuild Release / Publish Maven (push) Successful in 5m8sBuild Release / Mirror release outward (push) Has been skippedBuild Release / News on Discord (push) Has been skippedreleased this
2026-09-15 19:38:49 +02:00 | -1311 commits to main since this releaseServerPackCreator 9.0.0-beta.1
The first beta of the 9.0.0 line, and the first 9.0.0 build aimed at people who are not
already following the alphas.Most of the work since 8.1.2 went into one question: which mods are client-only, and how do we
stop guessing? The answer has two halves, and they reach you very differently.The first half is the automatic detection built into every server pack generation, and it got
substantially more accurate. You get that one for free — in the GUI, the CLI and the web UI
alike, without doing anything.The second half is new tooling that can prove a mod is clientside, by booting a real server with
it and watching it die. That half is command-line only and needs Docker. There is no GUI for it
in this release — if you use ServerPackCreator through its window, it is not something you will
see. It is there for people comfortable running the jar with arguments.Alongside both sit a pile of fixes to the generated start scripts, without which a lot of modern
Forge packs simply never started.This is a beta. It has had far less real-world mileage than 8.1.2. Keep a backup of your
configuration, and — as always — test your server pack before you hand it to anyone.
Clientside-mod detection
Forge packs on Minecraft's newer year-based versions got detection at all. The scanner was
picked by comparing only the minor part of the Minecraft version, so on a26.xversion every
jar failed the scan and was kept. Those packs now get themods.tomlscan that actually works.Be aware of what that means in practice: if your pack quietly relied on nothing ever being
excluded, mods will now start being excluded. That is the bug being fixed rather than a new one,
but it is a visible change — check your first server pack after upgrading.Related, on the same code path: a NeoForge pack on a Minecraft version the version parser could not
hold (26, for instance) used to throw and abort the whole generation. Both cases now fall back
to the modern scanner instead.Fabric, Quilt and their API jars stopped being thrown away.
- Fabric API, QFAPI and
quilt_basewere being treated as "the platform" rather than as real
dependencies. They are now reported properly, which means a Fabric API jar that a custom
clientside list had disabled gets pulled back into the server pack when something you kept
depends on it. - Mods now resolve dependencies through a jar's declared aliases. Fabric API calls itself
fabric-apibut providesfabric, so a mod depending onfabricwas naming an id no jar
answered to — and the pack it produced installed and then died on load. - A Quilt jar with no
quilt.mod.json— which is most of them, since Quilt runs Fabric mods —
now reads its Fabric descriptor instead of discarding everything the jar declared.
The bundled clientside-mod list grew from 496 to 548 entries. One of those is a repair rather
than an addition: in 8.1.2 theconfigured-line was missing its trailing comma, welding it to
connectedness-into a single nonsense entry, so neither mod was ever excluded. They are two
entries again.One bad list entry no longer kills the generation. With regex filtering enabled, a single
malformed entry used to throw straight out of the mod-list compiler and abort everything. Now that
entry simply never matches, the problem is logged once, and every other entry still applies.
New: check a mod yourself — command line only
Not available in the GUI. These are four new commands for the jar, usable as launch arguments
or inside the interactive CLI (-cli). If you only ever use the graphical window, skip this
section — nothing here changes what that window does.Command What it does -scan <dir> --loader <L> --minecraft <V>Reads the declared sideness of local jars and prints JSON. No network, no boot. -clientsidereport <url>Metadata-only report for a CurseForge or Modrinth project. Fast. -verifyclientside <url>The decisive one: downloads the mod and its dependencies, builds a server pack, and boots a real dedicated server in a container to see what actually happens. -clientsideapply --report <json>Feeds accepted entries from a report into your clientside-mod list. The reason
-verifyclientsideexists is that what a mod says about itself is not reliable. A mod
can declare itself server-safe and still crash a server, because its client-only code was wired up
wrong — and CurseForge has no sideness field at all, so for CurseForge mods there is nothing to
declare. Only a crash proves anything.Each check ends in one of six verdicts:
Meaning 🟢 CONFIRMED A server actually died with this mod installed, and a rule named why. The only verdict strong enough to act on. 🔵 CLEAR The server reached its ready line and nothing went wrong — proven fine for that build. ⚪ INCONCLUSIVE The boot ran and did something odd, with nothing explaining why. 🛠 ERROR The check could not be run and it is fixable at your end — a failed download, a pack that would not generate. 🔒 LOCKED The mod author opted out of CurseForge distribution, so there is no file to download. Retrying never helps; try the same project on Modrinth. 🚫 UNVERIFIABLE The check was never possible for reasons outside both you and the mod — a required dependency nobody published for that loader and Minecraft version, for example. Read
CLEARhonestly: it means this build, with these dependencies, on that Minecraft
version, started cleanly. It is not a general guarantee.
Server packs that actually start
All three start-script templates were fixed, and these are the difference between a server that
boots and one that does not:-Djava.security.manager=allowis fatal from Java 24 onward — the JVM refuses to start at
all. The templates now pass it only below Java 24. Minecraft 26.x requires Java 25, so before
this every Forge pack on a modern Minecraft was dying before Forge even loaded.- The check guarding that flag read the Java version before the script had worked one out, so it
was still the literal placeholderdo_not_manually_edit— meaning a pack that installs its own
Java passed the fatal flag anyway. The version is now read after the Java check, and the guard
fails safe. - From Java 24 the templates run the Forge installer themselves and launch from
unix_args.txt
(win_args.txton Windows) instead of handing the install to the ServerStarterJar. This fixes the
maddening one where a fresh Forge pack printed "The server installed successfully", exited 0,
and never launched — and then worked if you ran it a second time. - The ServerStarterJar is also bypassed for Forge on Minecraft 1.20.2 and 1.20.3, which it cannot
launch at all. - fish start scripts were added alongside bash and PowerShell.
- The server's real exit code is now passed back out of the script, so service wrappers and
restart-on-crash setups see what actually happened.
Faster, and it no longer freezes on a bad connection
- Startup no longer waits on the network. Version metadata refreshes in the background instead
of during construction: roughly 399 ms → 47 ms in the median case, and far more than that when
you are offline. Version dropdowns still wait for real data before they are shown, so they stay
correct. - Every outbound request now has a timeout — 5 s connect, 15 s read, 60 s for downloads, all
configurable. Previously nothing had one, so a host that silently dropped packets could leave the
splash screen stuck at 20 % with no way out but killing the process. Setting a timeout to0
restores the old unbounded behaviour if you want it. - Startup makes half the requests it used to — 24 down to 12, and 489 KB down to 214 KB — by
asking whether a manifest changed instead of re-downloading it. - Typing in the config editor is much cheaper. The editor's background check used to make an
HTTP request and re-parse the whole launcher manifest on every pause in typing. Both are now
remembered. Failures deliberately are not cached, so a momentary network blip does not leave the
editor insisting the server is unavailable until you restart. - Autocomplete no longer reinstalls the entire look-and-feel on every keystroke.
- Saving settings no longer leaves the unsaved-changes marker stuck on.
- If you run two or more plugins, their tabs now appear once each instead of once per installed
plugin.
Docker and the web UI
Read this one if you run ServerPackCreator as a service.
Spring Boot 4 retired the
spring.data.mongodb.uriproperty. A retired property does not warn — it
is simply not read — so ServerPackCreator was silently ignoring every configured database host,
credential and database name and falling back to Spring's own default. The property is now
spring.mongodb.uri.- Your
serverpackcreator.propertiesneeds no edit. ServerPackCreator reads the new key, falls
back to the old one if that is all it finds, and rewrites it under the new name. The old line is
deliberately left in place so a downgrade still finds its URI. - Docker users setting
SPC_DATABASE_HOST/_PORT/_DB/_USERNAME/_PASSWORDneed
change nothing — the container builds the new property itself. - You do need to update anything of your own that writes the old key — your own
overrides.properties, a deployment script, an environment variable you set by hand. Nothing
ServerPackCreator can do will fix those, and Spring will ignore them without saying so. - A side effect worth knowing: URI query parameters work again, because the property they were on
was being ignored entirely.
Also in this area:
- The container no longer loses its
--homeargument. The web service was overwriting the last
element of its argument list rather than appending to it, so the value of the final argument was
silently dropped — and in the container that argument is--home. - Startup no longer dies if the database is not up yet. Index creation moved off the startup
path; previously, losing the race with thedbservice meant a 30-second wait, a timeout, and a
dead application — which is the normal first boot of a compose stack. - The fallback database URI was never a valid URI (it carried literal backslashes), so every fresh
web installation started from something the driver rejects. Fixed, and existing installs repair
themselves. - Run-configuration mod lists are now stored in the document itself. This removes roughly 550
database round-trips per created run configuration. Stored documents are migrated automatically on
first start. If you consume/api/v2/runconfigsdirectly,startArgs,clientModsand
whitelistedModsare now plain string arrays. - Duplicate run-configuration detection was matching configurations that shared a single mod.
It now requires an exact match.
The update checker
Pre-release ordering was broken, and this release is the one that fixes it. The check compared
only the number after the dot, ignoring the channel, so withbeta.3published:- someone on
alpha.2was offeredbeta.3— correct by accident,3 > 2 - someone on
alpha.5was offered nothing at all —3 > 5is false
Channels are now ordered properly (alpha → beta → release) with the number as a tie-break. Update
checks are also bounded by the new network timeouts, rather than potentially hanging forever.
Breaking changes
Five, and four of them affect nobody running ServerPackCreator normally. Listed with who
actually needs to care:Change Who it affects Version metadata is handed out as immutable snapshots Plugin authors only. Three return types narrowed: LegacyFabricMeta.supportedMinecraftVersions()toList, andForgeMeta.getForgeMeta()/NeoForgeMeta.getNeoForgeMeta()toMap. Widen your declarations. If you were modifying what you got back, stop — you were corrupting shared state. This also fixes crashes and silently-empty reads while the background refresh was running.JsonBasedScannerremovedPlugin authors only, and only one that subclassed it. Extend JsonDescriptorScannerinstead — samegetJarJson, plus the scanning contract. Every concrete scanner keeps its name and signature.The headless-browser download route was removed Only the new -verifyclientsidecommand, which cannot verify a CurseForge project whose author opted out of distribution. It reports why and points you at Modrinth. It had already stopped working anyway. Nothing about normal server-pack generation changes.ConfidenceandaggregateFordeletedNobody. Internal to an unpublished module, replaced by the six verdicts above. One grinder deploy script instead of two Only people self-hosting a grinder instance. update-grinder.shis gone;sudo ./install-grinder.shdoes that job.
Upgrading from 8.1.x
If you use the GUI or the CLI: nothing to do. Java 21 is still what you need, unchanged from
8.1.2. Do check your first generated server pack, since Forge clientside detection now works where
it previously did nothing.If you run Docker or the web UI: see the database property above. In short — the application
migrates itself, but anything you wrote that setsspring.data.mongodb.urimust be changed to
spring.mongodb.uri.If you write plugins against
serverpackcreator-api:- Widen the three narrowed return types listed above.
- Replace
JsonBasedScannerwithJsonDescriptorScanner. - Require kotlinx-coroutines 1.11.0 or newer. If your build pins 1.10.x, you get a
NoSuchMethodErrorat runtime, not a compile error. - If you call
ListUtilities.parallelMapwithout passing your own context, elements now run on the
shared dispatcher instead of being accidentally serialised onto one thread. A lambda that mutates
shared state without synchronisation can now race — pass a single-threaded context to keep the old
behaviour. - If you construct
ApiPluginsdirectly, callloadAndStart()afterwards. - If you read version metadata immediately after constructing it and need fresh upstream data, call
awaitManifestRefresh(timeoutMillis). - An unusable home directory now throws
IllegalStateException, notIOException.
Known limitations
- The clientside-checking commands have no GUI. They are command-line only in this release.
-verifyclientsideis slow and heavy. Minutes per mod, and the first run downloads a
Minecraft server and a modloader — a few hundred MB of disk. It needs Docker.- CurseForge needs an API key (
CURSEFORGE_API_KEY) for any of the clientside commands to
resolve a CurseForge link. Modrinth does not. - Mods whose authors opted out of CurseForge distribution cannot be verified at all. There is no
file to download. Check the same project on Modrinth instead. - The grinder daemon and its GUI plugin are not part of this download. What ships here is the
detection built into generation, the four CLI commands, and the bundled clientside-mod list.
Downloads
File What it is ServerPackCreator-9_0_0-beta_1-Installer-Windows-x86_64.exeWindows installer, bundles Java 21 ServerPackCreator-9_0_0-beta_1-Installer-Mac.dmgmacOS installer, bundles Java 21 ServerPackCreator-9_0_0-beta_1-Installer-Linux-amd64.shLinux installer, bundles Java 21 ServerPackCreator-9.0.0-beta.1.jarThe application as a plain jar. Requires Java 21 serverpackcreator-plugin-example-9.0.0-beta.1.jarExample plugin, for plugin authors serverpackcreator-api-9.0.0-beta.1.jar+-sources/-javadocThe API library, also on Maven Central serverpackcreator-api-9.0.0-beta.1-dokka-html.zipAPI documentation as browsable HTML serverpackcreator-app-9.0.0-beta.1-javadoc.jarApplication javadoc checksum.txtSHA-256 of every file above updates.xmlUpdate descriptor, used by the installers Docker images are published as
griefed/serverpackcreator:9.0.0-beta.1on Docker Hub and ghcr.io.
Full changelog
1,121 changes since 8.1.2. The complete commit-level list — including the 297 documentation and
277 test commits left out above — is in
CHANGELOG.md at this tag.Found a problem? Open an issue — beta
feedback is the entire point of a beta.VirusTotal
ServerPackCreator-9.0.0-beta.1.jar- https://www.virustotal.com/gui/file-analysis/ODIxMmRiNDcwZjhiMWI2NTM2MjhmY2VjYjNlZjMxZTE6MTc4OTc1MDc2MQ==serverpackcreator-api-9.0.0-beta.1-javadoc.jar- https://www.virustotal.com/gui/file-analysis/ZjQzNDM2ZDZiZWMzMjEyOTBmNmFmMjI4YWQ2MDI2MDQ6MTc4OTc1MDc2Mw==serverpackcreator-api-9.0.0-beta.1-sources.jar- https://www.virustotal.com/gui/file-analysis/NDVkYzYyNTMzODVhYmYwMDc4MDY0NDZhYzVkNmM3NTk6MTc4OTc1MDc2OA==serverpackcreator-api-9.0.0-beta.1.jar- https://www.virustotal.com/gui/file-analysis/MjBjZGVjYjc2NGRlMmMwMTNmNTMxYjA2OGQ0MGEwZGQ6MTc4OTc1MDc3MQ==serverpackcreator-app-9.0.0-beta.1-javadoc.jar- https://www.virustotal.com/gui/file-analysis/MWNlMGU2MjY1OGU5ODcxZDdhY2U0ZjU4Mzc2MzU3ZDY6MTc4OTc1MDc3Ng==serverpackcreator-plugin-example-9.0.0-beta.1.jar- https://www.virustotal.com/gui/file-analysis/YTVjNDMxNDVmZDcyOGMzMWIwZGQzYTZjYjMwZmEwOWY6MTc4OTc1MDc3Nw==ServerPackCreator-9_0_0-beta_1-Installer-Linux-amd64.sh- https://www.virustotal.com/gui/file-analysis/NWU3MjEzNGVkNDQxYWNhMmE1OWY2NGI2ZWNhZWQ0NTE6MTc4OTc1MDg1OA==ServerPackCreator-9_0_0-beta_1-Installer-Mac.dmg- https://www.virustotal.com/gui/file-analysis/ZTdmZGQ4MDVmMWU0MGIwMjMwYjM2NmIzMWI2NmQxZjQ6MTc4OTc1MDk0Ng==ServerPackCreator-9_0_0-beta_1-Installer-Windows-x86_64.exe- https://www.virustotal.com/gui/file-analysis/MGRjYzU2YzI2YjViNjhiY2E5NGE0YmEzZjdlOTQ0OGU6MTc4OTc1MTAyMA==
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Fabric API, QFAPI and
-
9.0.0-alpha.9
Pre-releaseSome checks failedGenerate Release / semantic-release (push) Has been skippedBuild Release / Preparations (push) Successful in 22sDocker Test / build image (push) Successful in 20m53sDocker Test / build image (pull_request) Successful in 14m20sDocumentation / Help image (push) Successful in 2m2sDocumentation / Writerside webhelp (push) Successful in 2m10sTest / build (push) Successful in 35m36sBuild Release / Docker images (push) Successful in 16m38sQodana / notify (push) Successful in 15sQodana / scan (push) Successful in 21m49sBuild Release / JARs, media and checksums (push) Successful in 23m34sBuild Release / Forgejo release (push) Successful in 2m40sBuild Release / VirusTotal scan (push) Successful in 1m38sBuild Release / Publish Maven (push) Successful in 6m9sBuild Release / News on Discord (push) Successful in 41sBuild Release / Mirror release outward (push) Failing after 5m56sTest / build (pull_request) Successful in 48m11sreleased this
2026-09-14 19:33:33 +02:00 | -1309 commits to main since this release✂️ Refactor
- clientside: a seam for what a Forge-family loader provides (599a81d)
- clientside: drop a fixture no guard reads (3ba3404)
- clientside: let the registry offer more than one ref per mod id (89730de)
- clientside: name the verdict after the target, not the loader (1d21e26)
- clientside: route the dependency comparison through VersionOfFile (bcce3c6)
📔 Docs
- audit and analysis of the UNVERIFIABLE pass (iteration 1) (1983d94)
- audit and analysis, iteration 2 (3d29c5b)
- audit and analysis, iteration 3 (b818eda)
- close B36 — the Connector boot is dropped, not deferred (d3131bc)
- document the last 9 declarations Dokka reported silent (dc763e9)
- iteration 1's resolutions, and why four findings were recorded rather than rewritten (2cb1259)
- iteration 2's resolutions, and M-4 corrected in place (7cc2905)
- iteration 3's resolutions, and what three passes were each good for (e6b6ed0)
- make the renamed field findable, and scope the channel rule (4d605ad)
- measured counts, and three lessons from the loader-choice pass (a8bb9f7)
- re-measure clientside after the end-to-end guards (13cc457)
- the branch's measured equivalence against develop (99c0896)
- the false positive in the published list, and the audit that missed it (8c3f6a4)
- the field report that found a class, not a case (32c9b58)
- the grind axis, and the per-loader claims it made false (08116fa)
- the three landmines the audit iterations produced (e8c7915)
- the two facts a real jar had to settle, and what they show (9f660ad)
- the UNVERIFIABLE pass, its landmines and its two deferrals (f823999)
- the whole branch proved equivalent to develop for every pre-existing guard (5a38e8d)
- what the public grinder's 40 dependency failures turned out to be (aa7de38)
- clientside: the two ways a loader choice is now re-opened after staging (92a9f51)
- clientside: why LOADER_PRIORITY starts at NeoForge, measured (071f023)
- plugin-grinder: document the 19 declarations Dokka reported silent (80d3ffc)
📦 Other
- Run claude doctor (fbe8136)
🧪 Tests
- pin the six rules the analysis found asserted nowhere (8c9415d)
- api: pin that an unparseable Minecraft version cannot crash NeoForge dispatch (0c10011)
- clientside: both new refusals reach re-selection, through real staging (53be818)
- clientside: name the sampled artifact's guards after what they pin, and pin the producer (3e1e135)
- clientside: pin a client-only dependency as decisive evidence (RED) (ad0accd)
- clientside: pin botanypots as a mod id no guess can reach (RED) (5b904a7)
- clientside: pin re-selecting the loader from the jar (red) (c51d67e)
- clientside: pin that a clean boot outranks an inherited client-only proof (52d46b9)
- clientside: pin that a Connector placeholder is not a Forge mod (3a671ff)
- clientside: pin that a CurseForge dependency is found across the version line (3853b77)
- clientside: pin that a Forge-family loader provides its own id (RED) (f898e49)
- clientside: pin that a forked project serves its original's mod id (red) (7c8207a)
- clientside: pin that a release beats a newer-Minecraft beta (4eadf4e)
- clientside: pin that a verdict names the file staging selected (e9f6910)
- clientside: pin that Quilt's
unlessclause satisfies a requirement (c1ac29d) - clientside: pin the Connector marker in NeoForge's renamed descriptor (de4ffee)
- clientside: pin the line prefix, and a dot that must not separate (RED) (f28e997)
- clientside: pin the loader gate to the descriptor eras (851098c)
- clientside: pin the plain build over its own variant (RED) (9e2a199)
- clientside: pin the three defects the audit found (red) (99fefab)
- clientside: pin the two ways a declared range fails to narrow (RED) (c5b3f0d)
- clientside: pin the two ways a dependency ref goes missing or is invented (red) (9643d2d)
- clientside: pin three CurseForge ids no slug guess can reach (RED) (739febe)
- grinder: pin that a verdict's identity is its Minecraft line (6066438)
- grinder: pin that only a followable scheme becomes an href (red) (52c09e7)
- grinder: pin that the Filename column names the sampled artifact (cbddb26)
🚀 Features
- clientside,grinder: grind one target per Minecraft version-line (d39af6e)
- clientside: boot a caller-chosen target, and carry its Minecraft version (f81ea45)
- clientside: MinecraftLinePolicy, which lines of a project get ground (4aee754)
- clientside: pickGrindTargets, one loader per Minecraft line (21310b7)
- grinder: SPC_GRINDER_MINECRAFT_LINES_NEWEST and _LINE_ANCHORS (e0ac9fb)
- grinder: the report shows and filters the Minecraft line (602f088)
- plugin-grinder: show the Minecraft line a verdict is about (b05379a)
🛠 Fixes
- build: refuse to configure a Dokka module that has no module.md (fae4402)
- build: stop dokkaJavadocJar failing on a duplicate index.html (780115b)
- ci: publish the api's javadoc jar, not every module's (0731b75)
- ci: stop five workflows running on the creation of alpha/beta (b8b28d8)
- clientside,grinder: a clean boot outranks an inherited client-only proof (4bc3516)
- clientside,grinder: judge a demand the loader itself has to satisfy (60ad8fe)
- clientside: a bundled jar's own demands bind like a staged jar's (6acd289)
- clientside: a dependency the loader calls client-only is a finding (2226261)
- clientside: a verdict names the artifact that actually staged (4bdc748)
- clientside: an
unlessalternative counts when it is bundled, not only provided (e775fbd) - clientside: an exhausted backtrack is nobody's failure, not the host's (6ce930d)
- clientside: an untagged file means Forge only where the facet did not exist (fc7baf3)
- clientside: ask a dead pin once, like a live one (5db90b2)
- clientside: ask CurseForge for the dependency's version line (cf78607)
- clientside: fetch a dependency from the other platform when ours has none (7028c7e)
- clientside: honour Quilt's
unlessclause when staging a dependency (1443d9f) - clientside: honour the range a jar declares, and file a mixin failure as one (2af13e9)
- clientside: judge a demand on the loader's own id (78bebad)
- clientside: keep both disagreement channels, and order the retries in one place (4e70870)
- clientside: prefer a plain build over its own variant (6aeec16)
- clientside: prefer the newest release, then beta, then alpha (eb277c8)
- clientside: re-check a publishable crash on its own era's other loader (17d1f19)
- clientside: reach the fork that serves the original's mod id (6ee12d4)
- clientside: reaching Mojang's rendering layer is client-only evidence (85133ad)
- clientside: read a jar's loader at the descriptor era it was built in (3d61e97)
- clientside: read a line-prefixed version, and stop a dot separating one (551bcb2)
- clientside: read the Connector marker from both TOML descriptors (7e4611e)
- clientside: read the mod's own version, qualifier and all (e35dfcc)
- clientside: refuse a loader that cannot reach the build the jar demands (9a52ef9)
- clientside: resolve a pinned dependency, and stop inventing a
nullone (37e2d27) - clientside: resolve betterquesting, sewingkit and botanypots on CurseForge (bee99ba)
- clientside: resolve botanypots, a slug the guess cannot reach (56cfd7d)
- clientside: resolve the six mod ids observed going unresolved (a237817)
- clientside: verify a Connector placeholder under the loader it really is (971d9e8)
- clientside: verify a mis-ticked jar under the loader it declares (355d322)
- docs: resolve the KDoc links whose targets exist but are unreachable (3e60748)
- docs: stop documenting Confidence, which was deleted (deefe7f)
- grinder: key a verdict on its Minecraft line, not its modloader (cafa60a)
- grinder: link a project only when the scheme is one a browser should follow (a862556)
- grinder: re-file boot artifacts written before the Minecraft line (179bc9c)
- grinder: the Filename column carries the sampled artifact's real name (ab188df)
- plugin-grinder: add the module.md every Dokka task in this module requires (f797481)
VirusTotal
ServerPackCreator-9.0.0-alpha.9.jar- https://www.virustotal.com/gui/file-analysis/YjMyM2RhNTk2YWU1MWRhOWI4MzgxMjQyMDgyYWFkZTQ6MTc4OTQxMjg0NQ==serverpackcreator-api-9.0.0-alpha.9-javadoc.jar- https://www.virustotal.com/gui/file-analysis/ZjQzNDM2ZDZiZWMzMjEyOTBmNmFmMjI4YWQ2MDI2MDQ6MTc4OTQxMjg0Ng==serverpackcreator-api-9.0.0-alpha.9-sources.jar- https://www.virustotal.com/gui/file-analysis/YzZlZGJiOWE5MGQ3MzdiY2M5MGRiNmU2OGFmMTM3NjU6MTc4OTQxMjg0OQ==serverpackcreator-api-9.0.0-alpha.9.jar- https://www.virustotal.com/gui/file-analysis/YzEyYzc5ZjAyNjllOTgwMTQ1ZjMyMjQ0ZjIyMjBhZTA6MTc4OTQxMjg1MQ==serverpackcreator-app-9.0.0-alpha.9-javadoc.jar- https://www.virustotal.com/gui/file-analysis/NzM0OTMxYmZiOTI2ZmI1MjlkNWVhNzZmMjQzZGRlMzA6MTc4OTQxMjg1Mw==serverpackcreator-plugin-example-9.0.0-alpha.9.jar- https://www.virustotal.com/gui/file-analysis/OWNkZDY4MDdkZWZjZGI0ZDE5OTFhZTgyNTY4YzM5NDc6MTc4OTQxMjg1NA==ServerPackCreator-9_0_0-alpha_9-Installer-Linux-amd64.sh- https://www.virustotal.com/gui/file-analysis/YWU5ZjkxMGY0ZTRjMWNiZWM0ZjBlN2JjYTYxODQ1OGI6MTc4OTQxMjg2NA==ServerPackCreator-9_0_0-alpha_9-Installer-Mac.dmg- https://www.virustotal.com/gui/file-analysis/OGY5OTYzNTZhNmU5OWU2MzRlOGFiNGQ5YTkyODRjYjA6MTc4OTQxMjg3NQ==ServerPackCreator-9_0_0-alpha_9-Installer-Windows-x86_64.exe- https://www.virustotal.com/gui/file-analysis/ZjUyODVmNDBiOTZmNGFiZGM4ZDFiYmMxMDY4ZjU0N2U6MTc4OTQxMjg4NQ==
Downloads
-
Source code (ZIP)
1 download
-
Source code (TAR.GZ)
1 download
-
9.0.0-alpha.8
Pre-releaseSome checks failedGenerate Release / semantic-release (push) Has been skippedBuild Release / Preparations (push) Successful in 12sDocker Test / build image (push) Successful in 17m45sDocumentation / Help image (push) Successful in 3m4sDocumentation / Writerside webhelp (push) Successful in 2m30sQodana / notify (push) Successful in 9sQodana / scan (push) Successful in 11m16sBuild Release / Docker images (push) Successful in 19m8sBuild Release / JARs, media and checksums (push) Successful in 32m22sTest / build (push) Successful in 43m21sBuild Release / Forgejo release (push) Successful in 3m31sBuild Release / Publish Maven (push) Failing after 4m54sBuild Release / News on Discord (push) Has been skippedBuild Release / VirusTotal scan (push) Successful in 1m39sBuild Release / Mirror release outward (push) Has been skippedDocker Test / build image (pull_request) Successful in 21m56sTest / build (pull_request) Successful in 16m11sreleased this
2026-09-09 20:48:47 +02:00 | -1195 commits to main since this release⚠ BREAKING CHANGES
- api: publish every version meta as a snapshot, not as live state
- clientside: delete Confidence and aggregateFor
- grinder: one deploy script, with the mode decided by uid
- clientside,grinder,app: remove the headless-browser download route
✂️ Refactor
- clientside: ask the learned refs once in mappingsFor (61e0bc9)
- clientside: delete the dead deriveStems, keeping what it documented (850f89c)
- clientside: gather patch neighbours from one set, not two (579c7cf)
- clientside: move the confidence fold into the companion (33cec03)
- clientside: one ambiguity fold, and no nullable reason to interpolate (9b58349)
- clientside: one type for what a boot did, not two (2a194ce)
- clientside: read the placeholder marker without a deprecated call (1ebfd7d)
- clientside: route every boot attempt through one BootVerifier.boot (c3fe991)
- clientside: the audit's three LOW code findings (9ee88ba)
- clientside: the ladder reads its patterns from the rules file (d2d08c7)
- grinder: drop the dead decisive() from the fallback renderer (b174662)
- grinder: escape the Scanned cell like every other one (4e4cd96)
- grinder: extract the configuration and the sweep out of main (6de769d)
- grinder: rename CrashLogStore to BootLogStore (6ec7dc0)
- grinder: stop depending on Confidence (a9ed8e7)
📔 Docs
- audit and analyse today's commits (cf6cdc3)
- clientside 438 -> 466 in the root status table (b37d74a)
- clientside 466 -> 471 in the root status table (f4cf9ab)
- clientside 475, grinder 509 in the root status table (955319d)
- close B35 per the backlog's own convention and record the census (f7ffd9d)
- close B36 — the store was reset, so the requeue was never needed (8b5248a)
- close both audit logs — every finding resolved or accepted (786b7bf)
- close the documentation debt both batches left (309a0ff)
- close the landing obligations for the decisive-evidence gate (d64b649)
- close the plugin-recursion issue and record how it hid (127c3ec)
- commit the iteration-41 audit that was sitting in the working tree (e053654)
- complete the Refactor-state migration whose other half was committed by mistake (7e484cc)
- correct the grinder suite count for the new endpoint guards (a2580fd)
- correct the grinder suite count in the log (142f53d)
- file B35 for the verdict store per-record whole-file rewrite (746c0dd)
- file B36 — the published HIGH verdicts need re-grinding after deploy (592f1ce)
- mark the superseded precedence as history, and correct the suite count (659bb6f)
- plugin-grinder 72 -> 73 in the root status table (f50c867)
- record B6's merge gate — HIGH 8 -> 4, controls held, no regressions (3af47ea)
- record both dependency defects and the test-boundary lesson (7c54a0f)
- record feature B and the two inverted safety properties (f0bbd89)
- record that a survived boot counts, and that a refusal names the lock (93cedad)
- record that CI caught the clean-build break and the red went unactioned (f68041c), closes #301 #306
- record that optional dependencies are flagged, not required (cb72743)
- record the analysis fixes and the audit sweep that found nothing open (7425f22)
- record the audit resolutions and the landmines they produced (c6833b3)
- record the audit's resolution, the boot's owner, and the crash-log store (e78fd65)
- record the by-file dependency count and the clean-build gap (aef58a4)
- record the decisive-evidence gate and the census that justified it (8695a52)
- record the Docker IT, B0 regression and Fabric API acceptance runs (16a0d4c)
- record the equivalence check against develop's test tree (4107e86)
- record the equivalence proof, its four signature changes and 16 deltas (22759c3)
- record the four-verdict result system and where its rules live (8e337ff)
- record the hostname, Forge-launch and scan-date findings (5cbce8e)
- record the live verification of per-attempt boot-log capture (b6ec278)
- record the Logs column sort in the grinder's snapshot (557ad1f)
- record the measured ServerStarterJar/Forge range (84a6d58)
- record the plugin module and the new grinder endpoint (1a62eed)
- record the re-grind queue and its three placement landmines (f210c8c)
- record the report query layer and its measurements (fbab42c)
- record the rules' measured recovery and the poisoned cache tuple (1e5b21d)
- record the shared staging directory behind the 26.2 boots (5c4fcfa)
- record the source-jar entry and the re-check that stayed local (7a7d9e9)
- record the tmpfs exec decision and what noexec was costing (4ffe309)
- record the two-pattern split and why only one is publishable (7706a4c)
- record what the crash-log census changed in the clientside engine (7ac5a5b)
- record why a jar's own range now re-selects instead of refusing (b8a6081)
- record why the browser download route is gone, in every place that claimed it (125d64f)
- refresh the clientside row after the three field-report fixes (6c8f066)
- regenerate the license report after the Playwright removal (e42cb53)
- sync the suite counts after restoring the shutdown guards (9568120)
- the 2026-09-08 audit and analysis of the backtrack range (997051d)
- the analysis and audit, in the refactor log (86d3d44)
- the audit findings, and the gate that keeps the patch fallback safe (c2123f2)
- the six verdicts, and the three ways a dependency was "unavailable" (a8d1dab)
- api: document the eight declarations dokka reported undocumented (428c6e7)
- app: document GuiProps, ConfigEditor, BeanConfiguration and the CLI parsers (c61329a)
- app: document the modpack/storage/stats services and the entry point (715eaa7)
- app: document the settings panels, GUI components and task queue (f81c4ba)
- app: document the web entities, stats and the scroll components (edd1be0)
- app: finish the dokka backlog — 626 → 0 undocumented (acfed4b)
- audit: cite commit subjects, and correct the premise the rebase was proposed on (ab13c6f)
- audit: close iteration 33, and add the convention MED-3 earns (f397a11)
- audit: iteration 25 — shutdown during a re-grind drain, and a log line that prints a data class (ef88492)
- audit: iteration 26 — a negative sleep, an unbounded read, and a URL nobody checks (35f6206)
- audit: iteration 27 — findings and resolutions (997fb21)
- audit: iteration 28 — header/cell coupling, sibling-marker review (7dcbd10)
- audit: iteration 29 — the template change (5ef46ce)
- audit: iteration 30 resolutions and the iteration 31 re-audit (6d0c62b), closes #301 #306
- audit: iteration 32, and fix the api suite count it found stale (712f633)
- audit: name the dead commits by subject, and record the repo-wide citation sweep (d83dfd9)
- audit: record the history rebuild that closed MED-1, LOW-1 and MED-2's instances (0930519)
- audit: resolutions for iterations 25 and 26 (1d221ef)
- ci: record the two mirror failures, and why
newsis not gated on the mirror (01cc1f2) - clientside,grinder: document what dokka reported undocumented (9000e99)
- clientside: close the candidate half of the untagged-loader rule (361db79)
- clientside: document the backtrack's data classes, and reunite one orphaned KDoc (03032f4)
- clientside: landmine the silent rung, and correct two counts that had drifted (49ffa77)
- clientside: name every prevented-grind path, not just the staging ones (ccc839b)
- clientside: re-attach seven KDoc blocks, and correct the decisive set (d72a949)
- clientside: record the confidence-keyed refusal split (d8239ca)
- clientside: record the Connector-placeholder scanner redirect (de7245e)
- clientside: record the decorated-version defect and the refusal vocabulary (ab27873)
- clientside: record the dependency-set backtrack (9f2f5a2)
- clientside: record the NeoForge/Forge 1.20.1 parity band (7ad0a77)
- clientside: record the nested-jar blind spot in the backtrack (5e84224)
- clientside: record the untagged-loader landmine and the candidate half (e05f2ef)
- clientside: record the version-range fixes and the open CurseForge gap (8514e93)
- grinder: correct the claim that Logs is meaningless to sort (62e41bb)
- grinder: document the boot-rule status field and drop a stale claim (1007993)
- grinder: landmine the four defects worth not re-introducing (2ac1d8e)
- grinder: re-attach six KDoc blocks that documented nothing (f131d2e)
- grinder: record sortKey and the single confidence rank table (9de940d), closes #4
- grinder: record the missing-image outage and what it changed (7b45d7f)
- grinder: repair three KDoc links to the deleted Confidence type (482f54c)
- plugin-example: document the addons logger companion (57d22b5)
📦 Other
- api: refresh the shipped manifest snapshots (89639fc)
- clientside: correct three statements this branch made stale (37158ae)
- plugin-grinder: ignore the module's ServerPackCreator test home (22d3143)
🦊 CI/CD
- drop the Playwright dependency and its CI prerequisite (5dc2002)
🧪 Tests
- close the coverage gaps the analysis found (M-3, M-4, M-5, L-1) (4dcf250)
- api,clientside: pin that an optional dependency is not a requirement (5029ef9)
- api,clientside: pin that quilt_base is a mod, not the Quilt platform (24aa11c)
- api: pin B0's generation regression check, and the gap it found (18fa4ec)
- api: pin every Minecraft list accessor, not the three written down (8bb194e)
- api: pin Fabric API as a dependency and every declared version range (5027907)
- api: pin that a missing malware scanner cannot abort generation (0029414)
- api: pin that a Quilt pack scan keeps a Fabric jar's dependencies (5788bab)
- api: pin that a scan reports the Minecraft the jar declares (b54b4df)
- api: pin that an extension belongs to one plugin (bbfdf42)
- api: pin that an unreadable Minecraft version takes the bypass (ad4ef05)
- api: pin that no version meta hands out live state (fdbedd4)
- api: pin that setupQuilt notices a pack with no Minecraft server jar (4a84a2d)
- api: pin that version metadata is not handed out as live state (7ae95ab)
- api: pin which Forge versions bypass the ServerStarterJar (ec19d82)
- api: reproduce the plugin-loading recursion in the suite (b5f74ee)
- clientside,grinder: pin per-attempt staging to (platform, slug, loader) (638cbf0)
- clientside,grinder: pin whose boot disproves, and whose identity is reaped (b70bbf7)
- clientside: characterize the filename pattern before depending on it (da56caa)
- clientside: close the coverage gaps the same-day analysis found (89ae3d8)
- clientside: pin a crash re-check spanning loaders and Minecraft lines (1f4dea4)
- clientside: pin a loader that never bootstrapped as inconclusive (7f8aa8b)
- clientside: pin all sixteen ladder rungs, not ten of them (930e2a6)
- clientside: pin an unreadable @argfile as inconclusive (b74e624)
- clientside: pin bumping the pack to a version the jar itself accepts (f0a6d5c)
- clientside: pin comma-separated unions of version ranges (c972efb)
- clientside: pin operator-editable console rules and their place in the ladder (f12b9db)
- clientside: pin that a bundled dependency is never fetched or missing (5f60a72)
- clientside: pin that a component too large to represent is unreadable (9fbfffa)
- clientside: pin that a confirmation names the rule that decided it (9e39825)
- clientside: pin that a Connector placeholder is scanned as Fabric (0396459)
- clientside: pin that a constraint narrows dependency choice but never empties it (2ebc6b0)
- clientside: pin that a dependency is sought at the version being booted (2f31bd8)
- clientside: pin that a dependency never crosses a Minecraft version (c065ce9)
- clientside: pin that a dependency the jar never asks for cannot refuse a boot (fd1a164)
- clientside: pin that a file carries every project its page links (66a10b3)
- clientside: pin that a jar staged under two refs counts once (3c110a0)
- clientside: pin that a loader too old for the mod is re-checked (0e8de06)
- clientside: pin that a mapped, resolved, unstageable dependency refuses (3d79f0d)
- clientside: pin that a mod cannot claim the launcher's excuse (ff8dc82)
- clientside: pin that a Modrinth source jar is not a mod file (bcc8021)
- clientside: pin that a nested library's version reaches the conflict check (f8326eb)
- clientside: pin that a pack with no server jar is inconclusive (1a8dea2)
- clientside: pin that a refusal names mods, not platform ids (5568b0a)
- clientside: pin that a resolved dependency knows its own name (fbea4b0)
- clientside: pin that a rule which decided a boot is named on the verdict (4c7bcba)
- clientside: pin that a self-contradicting dependency set backtracks (be01428)
- clientside: pin that a staged dependency cannot refuse its own boot (d2a6f0d)
- clientside: pin that a survived boot counts, and a locked download says so (6d6bdfe)
- clientside: pin that a wrong-Minecraft dependency is dropped pre-boot (17dfa82)
- clientside: pin that an all-untagged project is still ground (acc44f2)
- clientside: pin that an unmet dependency names why it is unmet (0ed2674)
- clientside: pin that an unobtainable dependency is not preferred (a4e2c82)
- clientside: pin that an unreadable staged version is not a conflict (9d67140)
- clientside: pin that an unresolved required id asks the linked projects (7a66dc5)
- clientside: pin that an untagged file is unknown, not incompatible (6410c9f)
- clientside: pin that attribution annotates and never moves a verdict (7ac7da0)
- clientside: pin that client-only proof is about the mod, not the build (901b03f)
- clientside: pin that every ladder rung finds its bundled pattern (312459e)
- clientside: pin that extracting the ladder into rules changes no verdict (1312bc0)
- clientside: pin that Fabric API's modules resolve to Fabric API (b011ac5)
- clientside: pin that folding no unmet dependencies answers, not throws (17d8332)
- clientside: pin that metadata sideness is decided by rules too (dd549fb)
- clientside: pin that NeoForge runs Forge mods on Minecraft 1.20.1 (821b2d3)
- clientside: pin that one mod id can be served by two projects (ac5bdcd)
- clientside: pin that QSL's module ids resolve to QSL (20f12f7)
- clientside: pin that the learned map can outlive the process (056246f)
- clientside: pin that there is one download route and no browser fallback (6ff2b4b)
- clientside: pin that YACL's versioned mod id resolves to its project (5142840)
- clientside: pin the ambiguity rule across a pack, not just within a jar (838f35a)
- clientside: pin the client-library evidence that shipped as an example (a2dfcb4)
- clientside: pin the environment excuses the crash logs demanded (5c3df0a)
- clientside: pin the fold that replaces aggregateFor (69b23fe)
- clientside: pin the four-state verdict, and that a prevented grind is an Error (c6790cd)
- clientside: pin the id-to-project mapping learned from staged jars (3e104eb)
- clientside: pin the manifest-id to platform-project mapping (50f3a01)
- clientside: pin the patch-version dependency fallback (fd732d3)
- clientside: pin the per-attempt boot-artifact sink (b291160)
- clientside: pin the refusal path the first label fix missed (63521e8)
- clientside: pin the refusal split on mapping confidence (08a40a6)
- clientside: pin the two platform shapes that produced live false positives (576912c)
- clientside: pin the two prevented-grind paths the redesign missed (c453b8d)
- clientside: pin the version a jar's own range would have us pick (d2fb045)
- clientside: pin version-constraint matching across both loader grammars (211a639)
- clientside: pin what a finished boot leaves behind (4002b42)
- clientside: pin which rung decided a boot, against five real logs (cc3cbb1)
- clientside: pin which unmet dependencies may refuse a boot (89d388e)
- clientside: pin who a prevented grind is blamed on (ed492bf)
- clientside: reproduce JEI's refusal — a jar range that excludes its own version (f980c13)
- clientside: separate the two dependency-preference arms that never were (dbd6864)
- grinder: execute the dashboard's script under node (e91c4d6)
- grinder: gate the store benchmark and answer B35 with numbers (375f1bb)
- grinder: hold the loader-line wiring the step-down pin never reached (def87f1)
- grinder: pin --requeue-since, the selector an outage needs (0836c71)
- grinder: pin a durable home for crash consoles, and the endpoint buttons (bde4f73)
- grinder: pin a non-negative slice, a bounded crash-log read, and a rejected link (7f5a8c5)
- grinder: pin a self-contained live dashboard for /status (179b292)
- grinder: pin an immediate re-grind queue that ignores freshness (552b49f)
- grinder: pin coalesced verdict writes (B35) (c9275c5)
- grinder: pin each column against its own sentinel before restructuring (4265c07)
- grinder: pin every field of the LoaderVerdict-to-GrindVerdict mapping (991fea0)
- grinder: pin per-attempt keeping, pruning, the budget and adoption (6702820)
- grinder: pin sorting by the Logs column (056fc55)
- grinder: pin template provenance on the path production takes (0531ce6)
- grinder: pin that a blamed dependency is queued, and record the live run (47ccb99)
- grinder: pin that a boot can execute from its own tmpfs (5d57bfa)
- grinder: pin that a boot container can resolve its own hostname (775a41f)
- grinder: pin that a crashed boot's console is copied out of staging (c8bbf85)
- grinder: pin that a failed install is not reported as a skipped one (2ee4925)
- grinder: pin that a failed queue write leaves no scratch behind (c5e1c56)
- grinder: pin that a missing runtime image stops the daemon (ac3f151)
- grinder: pin that a restored id with no usable ref leaves no entry (d7596cf)
- grinder: pin that a thrown loader install names the exception (ba09ca0)
- grinder: pin that an unavailable loader install says why (5c420cf)
- grinder: pin that an unreadable verdict store is not overwritten (b1b9c4f)
- grinder: pin that an unusable knob value falls back like an unparseable one (f433539)
- grinder: pin that confidence sorts by severity, not alphabetically (13de74b)
- grinder: pin that every table header has a cell beneath it (bfc1278)
- grinder: pin that Fabric and Quilt can step down a loader build (436de8f)
- grinder: pin that Forge boots from its argfile, not the starter jar (8c306f7)
- grinder: pin that only a confirmation is published (6e8cd71)
- grinder: pin that the container-stop drain gives up (cdc45ba)
- grinder: pin that the pass counter is not shadowed (96701a3)
- grinder: pin that the report and CSV speak the four verdicts (34e405b)
- grinder: pin the declared sideness and jar scan on a recorded verdict (c0a81f0)
- grinder: pin the file that carries the learned map across restarts (da10248)
- grinder: pin the Filename column beside the name pattern (eaf52b5)
- grinder: pin the JSON verdict feed the GUI plugin reads (1b671e6)
- grinder: pin the per-pass counters as per-pass (c097498)
- grinder: pin the report server's favicon (3c534e0)
- grinder: pin the scan date on the overview and in the CSV (4dd5c24)
- grinder: pin the shutdown gap, the live pass size, and a sliced wait (d20fc2c)
- grinder: pin verdict filtering, sorting and paging as a pure unit (ef5f159)
- grinder: prove the Logs sort through the real handler (aca684c)
- grinder: restore the five shutdown guards a refactor deleted (audit H1) (3ef3930)
- plugin-grinder: pin the audit's four findings and the missing edge cases (70301ac)
- plugin-grinder: pin the clientside-entry injection (732fdc7)
- plugin-grinder: pin the Declared and JAR sideness columns (03cf347)
- plugin-grinder: pin the URL rule, the client and the selection store (98ecefc)
- plugin-grinder: pin the verdict table's selection logic (758ea95)
🚀 Features
- ci: announce releases on Discord from Forgejo (4f42a76)
- clientside,grinder,app: remove the headless-browser download route (04e746a)
- clientside,grinder: a verified LWJGL rule, and the harness defect it found (3fd6eb8)
- clientside: ask the linked projects when a required id resolves to nothing (b99a850)
- clientside: collect a boot's console, server logs and crash reports (ebc72b3)
- clientside: fold one loader's evidence into the four-state verdict (fa3400a)
- clientside: hand every boot attempt's artifacts to a sink (a6f9292)
- clientside: learn the id-to-project bridge from the jars staging downloads (e504d1c)
- clientside: let an operator's console rules decide a boot (0d0b43d)
- clientside: LOCKED and UNVERIFIABLE, so ERROR means what it says (8093d4b)
- clientside: map a manifest mod id to its platform project ref (fb4d5bd)
- clientside: match a dependency file against its declared constraint (1a3d715)
- clientside: match a mod file's version against its declared constraint (bdd9cd9)
- clientside: metadata sideness is decided by rules, not by a hardcoded fold (5ed6357)
- clientside: name the rule that decided a boot, on the outcome itself (9eaf2a3)
- clientside: record the dependency a crash names, without moving the verdict (ffe3843)
- clientside: ship the built-in ladder as an editable rules file (53b2e16)
- clientside: split refusable dependencies from merely-unmapped ones (3d2c3c9)
- clientside: stage the dependencies a jar manifest declares alone (18f59b4)
- clientside: the four-state verdict and the pure policy that decides it (2c611da)
- clientside: delete Confidence and aggregateFor (8c18001)
- grinder: --bootstrap prepares a host that never ran the grinder (02b3fac)
- grinder: --clear installs onto a clean slate (d6cf580)
- grinder: --requeue-since, for a window the daemon was broken in (4976ff7)
- grinder: a live, framework-free dashboard for /status (4e1e544)
- grinder: add an unattended update script for the deployed service (a087cdf)
- grinder: an immediate re-grind queue that jumps the crawl and the TTL (2376d75)
- grinder: audit a live grinder's published verdicts against their evidence (90bdb84)
- grinder: give the report a favicon (0c80e2a)
- grinder: grant the build account sudo for the run instead of demanding it (3658eee)
- grinder: install the headless browser prerequisite instead of warning about it (799fc95)
- grinder: keep crashed boots' consoles and reach every endpoint from the report (f94a4c7)
- grinder: keep every non-survived attempt's logs and link them per row (f249e18)
- grinder: make the verdict-less rule fallback an operator choice (41be7a2)
- grinder: persist the learned mod-id map to SPC_GRINDER_HOME (35c77cb)
- grinder: publish only confirmations, and record what the mod claimed (a7cda82)
- grinder: record the sideness and jar scan behind every verdict (6b86c1a)
- grinder: render the report from a server-side query (d41c37e)
- grinder: requeue a dependency blamed for a crash, and show the staged pack (1714da9)
- grinder: select verdicts server-side by search, filter, sort and page (b9b06be)
- grinder: serve verdicts as JSON at /verdicts.json (8338460)
- grinder: show the sampled artifact's pattern beside the published one (15c25dd)
- grinder: show when each mod was scanned (3b1392f)
- grinder: sort the report by the Logs column (8fc40bf)
- grinder: the report and CSV speak the four verdicts (d0adf2d)
- grinder: wire the console-rule file, its errors and the rule column (a05a259)
- grinder: one deploy script, with the mode decided by uid (f8f41db)
- plugin-grinder: fetch verdicts and persist the selection (c17cf9a)
- plugin-grinder: inject the selection into clientMods before generation (0a0c6e6)
- plugin-grinder: scaffold the module and its plugin descriptor (0885d32)
- plugin-grinder: show Declared and JAR sideness beside the verdict (9c3ef12)
- plugin-grinder: the four-pane GUI tab (a68204a)
🛠 Fixes
- api,clientside: an optional dependency is not a requirement (88a6a19)
- api,clientside: never boot a jar on a runtime it does not declare (2a073a0)
- api,clientside: quilt_base is a QSL module, so stop excusing it as the platform (98f183f)
- api,clientside: stop leaking exit hooks, keep errors visible, serialise refreshes (e716460)
- api: a malware scanner that cannot run must not abort generation (9808923)
- api: bypass the ServerStarterJar where it cannot launch Forge (c9106d0)
- api: fetch the Minecraft server jar for Quilt on its own terms (7e327da)
- api: keep a Fabric jar's declaration when scanning a Quilt pack (804efd8)
- api: load plugins as a step, after the API they reach into exists (1d7b05d)
- api: never compare an unreadable Minecraft version component (4af6631)
- api: publish version metadata as snapshots, not as live mutable state (7e2d49a)
- api: put the refresh coroutine on the lock it was supposed to take (a27b632)
- api: rescue a dependency by the ids a mod actually answers to (cd18edf)
- api: scope an extension lookup to the plugin it was asked about (431f3f8)
- api: stop excluding Fabric API and QFAPI, and record dependency version ranges (ea7933c)
- api: publish every version meta as a snapshot, not as live state (c3d2238)
- ci: probe the mirror before the release POST, and make
mirrorre-runnable (deafdd5) - clientside,grinder: a slug is not an identity — stage per platform (82c0c9c)
- clientside: a cross-loader survivor is not the verdict's own boot (43d5948)
- clientside: a dependency in the pack cannot refuse its own boot (f2d8b7d)
- clientside: a dependency the candidate ships is never fetched or missing (5154070)
- clientside: a digit-less wildcard constraint must accept, not refuse (edd9627)
- clientside: a grind that never ran is an Error, on every path (5a25860)
- clientside: a loader that never bootstrapped is not a mod crash (f3ca8d2)
- clientside: a Modrinth source jar is not a mod file (14c8539)
- clientside: a nested library counts as staged when judging the pack (2939982)
- clientside: a pack with no Minecraft server jar is a launch failure (f3e5575)
- clientside: a staging refusal names why each dependency is unmet (06c3ac3)
- clientside: a version component we cannot represent is unreadable (60a0e77)
- clientside: a version we cannot read is not evidence of a conflict (3156d60)
- clientside: an unreadable @argfile is a broken install, not a mod crash (c54637d)
- clientside: anchor the launcher's argfile excuse to line start (b88f502)
- clientside: backtrack a dependency whose demands the pack cannot meet (20f5895)
- clientside: bump the pack to a Minecraft version the jar itself accepts (79617c1)
- clientside: carry every linked project, not only the required ones (1a798cf)
- clientside: client-only proof is about the mod, so it crosses builds and loaders (a808a86)
- clientside: count a staged dependency once, by file rather than by ref (0761aef)
- clientside: count a survived boot, and say why a locked file would not download (5afd1ef)
- clientside: credit the deciding rule, not one that merely matched alongside (b5e08ec)
- clientside: do not remember an id a restore had no ref for (dd0482b)
- clientside: drop a dependency whose descriptor excludes the pack's Minecraft (ba2947a)
- clientside: fail a rule's missing or unreadable verdict safe to INCONCLUSIVE (b76a6c9)
- clientside: give a resolved dependency its real slug, on both platforms (742e9fa)
- clientside: grind a project whose files carry no loader tag (fb9d845)
- clientside: implement ModPlatform.name in the two test fixtures (b3d7e65)
- clientside: key the refusal split on mapping confidence, not distance (625145c)
- clientside: let NeoForge boot a Forge jar on Minecraft 1.20.1 (2329996)
- clientside: look for a dependency at the Minecraft version being booted (67b848f)
- clientside: LWJGL and FML's invalid-dist are decisive, and now shipped (bb82781)
- clientside: make a ladder rung that cannot find its pattern say so (0cd909f)
- clientside: make preventionCauseFor total (1b7f883)
- clientside: name the mod, not its platform id, when a dependency is missing (ad3bbbb)
- clientside: name the third refusal branch, and call a locked dependency locked (b3f50b6)
- clientside: never stage a dependency for another Minecraft version (6e3063a)
- clientside: prefer a dependency file that can actually be downloaded (307f3e5)
- clientside: publish only a crash that is decisive evidence of sideness (556efc0)
- clientside: re-check a crash across loaders and Minecraft lines (39d3403)
- clientside: re-check the newest loader build for any boot the build could explain (542f1fb)
- clientside: re-select a Minecraft version the jar accepts, don't refuse (793a5a7)
- clientside: read a comma-separated union of version ranges (3c19f8a)
- clientside: refuse when a mapped dependency has no usable file (b55e972)
- clientside: remember every project that proves a mod id, and try each (c7cbad2)
- clientside: resolve Fabric API's module ids to Fabric API (7062157)
- clientside: resolve QSL's module ids to QSL (cbf1f08)
- clientside: resolve YACL's versioned mod id to its project (ac9612f)
- clientside: scan a Connector placeholder as the Fabric mod it wraps (bcb9cfc)
- clientside: stage a dependency from a neighbouring patch release (3bd168f)
- clientside: stop scoring harness failures as the mod's crash (467a4da)
- clientside: the console decides, the metadata only declares (8d5e693)
- clientside: the jar decides which platform dependencies it actually needs (e018250)
- clientside: treat a file with no loader tag as unknown, not incompatible (98e2395)
- grinder: a slice that cannot go negative, a tail that is not read whole, a link that is refused (17df60c)
- grinder: actually consult the template-provenance check before serving a cached install (1ee6873)
- grinder: boot Forge from its argfile instead of the ServerStarterJar (02cc17e)
- grinder: bound the container-stop drain so shutdown cannot hang (eecbbd9)
- grinder: close the remaining audit-32 findings, and record what was not closed (5c51d78)
- grinder: close the shutdown gap the drain opened, and stop making a queued re-grind wait (447acaf)
- grinder: close the verdict store on shutdown, and stop shadowing it (acaf8d7)
- grinder: coalesce verdict-store writes (B35) (136d571)
- grinder: delete the queue's scratch file when a write fails (b3f538f)
- grinder: fall back when a knob is unusable, not only when it is unparseable (0e6eb1b)
- grinder: grade the audit per verdict, not per kept console (18cd412)
- grinder: leave the Forge launch path to the templates (a392857)
- grinder: let Fabric and Quilt step down a loader build (3a17016)
- grinder: log the exception a loader install threw, not only its message (8743571)
- grinder: make a boot container's own hostname resolvable (583d35f)
- grinder: mount a boot's tmpfs executable (00ac21d)
- grinder: prove chromium launches for the service account, not just that it installed (4ec3ba3)
- grinder: read the unit that systemd actually runs, not the checkout's pristine copy (c2b6596)
- grinder: reap the identity the staging was named from (0e717fe)
- grinder: refuse to deploy from a copy inside the checkout it wipes (e821d76)
- grinder: refuse to grind without the runtime image (1172eef)
- grinder: reset the per-pass counters when a pass begins (ae2c7de)
- grinder: say why a loader install is unavailable, not that none is cached (7bb2a32)
- grinder: sort confidence by severity, from a single rank table (8eff064)
- grinder: tell an attempted install apart from a suppressed one (b96ee46)
- grinder: the audit IT reads the CSV column that exists (84119c1)
- grinder: the dashboard links only absolute http(s) URLs (4fe0745)
- grinder: the pass-completion log prints the pass number again (59f7d71)
- grinder: tolerate unknown fields and preserve an unreadable verdict store (3f60ad3)
- plugin-grinder: close the audit's findings (ed8198d)
- plugin-grinder: give JAR sideness a width its commonest value fits in (b0bc490)
- plugin-grinder: widen Declared so CONTRADICTORY stops clipping (adb2174)
VirusTotal
ServerPackCreator-9.0.0-alpha.8.jar- https://www.virustotal.com/gui/file-analysis/MjU0ZTBjMjFlNGQxMzc2ZGZlMjEwMzFhMjkwNjBhZDI6MTc4ODk4NDUzOQ==serverpackcreator-api-9.0.0-alpha.8-javadoc.jar- https://www.virustotal.com/gui/file-analysis/ZjQzNDM2ZDZiZWMzMjEyOTBmNmFmMjI4YWQ2MDI2MDQ6MTc4ODk4NDU0MA==serverpackcreator-api-9.0.0-alpha.8-sources.jar- https://www.virustotal.com/gui/file-analysis/ZjA4MWM2MTBmNWQ2ZGY0MTViYjQyNjA4N2VhMDQ2OGU6MTc4ODk4NDU0Mg==serverpackcreator-api-9.0.0-alpha.8.jar- https://www.virustotal.com/gui/file-analysis/ZWEzNDE1ZTk1MTNmNjUzNGUwMjExMzRkMTVkMTMyNjY6MTc4ODk4NDU0NQ==serverpackcreator-app-9.0.0-alpha.8-javadoc.jar- https://www.virustotal.com/gui/file-analysis/ZGNlNGMxMWI4MDE3Yzc1ZGVmOGY0NjQxMzg3MjY0Mzc6MTc4ODk4NDU0OA==serverpackcreator-plugin-example-9.0.0-alpha.8.jar- https://www.virustotal.com/gui/file-analysis/ZDk4NDUwZTAyNmQzZjdkNWY2Y2Y0ZTBjMzYyNWIxYTQ6MTc4ODk4NDU0OQ==ServerPackCreator-9_0_0-alpha_8-Installer-Linux-amd64.sh- https://www.virustotal.com/gui/file-analysis/NDE1YWUwNmI2NWRkNzY1ODA4MjE5YWFlYjYzNWViMDQ6MTc4ODk4NDU1OA==ServerPackCreator-9_0_0-alpha_8-Installer-Mac.dmg- https://www.virustotal.com/gui/file-analysis/OGU5NTk2ZDI5YjBhNDljMTE3OWFhNjAyMWJhMmY5Njg6MTc4ODk4NDU2Ng==ServerPackCreator-9_0_0-alpha_8-Installer-Windows-x86_64.exe- https://www.virustotal.com/gui/file-analysis/MjFkMGRhYjE5NDZkMjA3MDk5MDdhYzQ3YTk1MzY4N2U6MTc4ODk4NDU3OA==
Downloads
-
Source code (ZIP)
1 download
-
Source code (TAR.GZ)
2 downloads
-
9.0.0-alpha.7
Pre-releaseSome checks failedGenerate Release / semantic-release (push) Has been skippedBuild Release / Preparations (push) Successful in 56sDocker Test / build image (push) Successful in 18m7sDocumentation / Help image (push) Successful in 6m5sDocumentation / Writerside webhelp (push) Successful in 1m58sTest / build (push) Successful in 16m7sQodana / notify (push) Successful in 19sQodana / scan (push) Successful in 15m54sBuild Release / Docker images (push) Successful in 15m36sBuild Release / JARs, media and checksums (push) Successful in 34m52sBuild Release / Forgejo release (push) Successful in 3m29sBuild Release / VirusTotal scan (push) Successful in 3m8sBuild Release / Publish Maven (push) Successful in 8m16sBuild Release / Mirror release outward (push) Failing after 1m15sreleased this
2026-08-23 18:12:52 +02:00 | -728 commits to main since this release✂️ Refactor
- audit iteration 19's consistency findings, and the re-derived counts (4b9c056)
- clientside: extract the navigation options so they can be pinned (723394f)
- clientside: split staging from selection in prepareBootPack (45b7fac)
- grinder: drop a branch that cannot change an output (72dc9d2)
- grinder: read the container-user override in the entry point (c14e750)
📔 Docs
- audit iteration 17 — the container-identity branch (6054c0d)
- audit iteration 18, and the two findings it fixed in passing (f81c174)
- audit iteration 19 — third pass and the equivalence check (4a1b7a5)
- audit iteration 20 — the graceful-shutdown branch (975a951)
- audit iteration 21 — second pass over the shutdown work (95198b6)
- audit iteration 22 — third pass and the equivalence check (b01fed9)
- audit iteration 23 — the CPU-cap branch (b27b535)
- correct the clientside suite count to the 113 the run reports (b31667a)
- record iteration 23's resolutions, and why M3 stands (50987b7)
- record the container-identity outage and the /as-properties endpoint (76a6769)
- record the CPU-cap knob and the quota-without-period finding (751edb2)
- record the cross-loader reconciliation and the CurseForge window (8f8b165)
- record the memory knob and the heap derivation behind its warning (54d32af)
- record the other-version crash re-check and what arms it (ae2a11b)
- grinder: close the deployment gaps this outage ran into (31e6967)
- grinder: explain a crash weighed against another loader (415284e)
- grinder: tell the operator what a re-checked crash looks like (a0263c2)
- grinder: the shutdown contract, and the cgroup fact behind it (067ebc3)
🧪 Tests
- pin the two joins audit iteration 17 found unguarded (02d8a39)
- clientside: pin cross-loader reconciliation and CurseForge file paging (5b5151f)
- clientside: pin that a verdict's own console is the log that is kept (01f153a)
- clientside: pin that an aborted navigation means the download started (a435735)
- clientside: pin the other-version crash re-check (847bdd0)
- grinder: drive SPC's real updater against the live /as-properties (c3cbf50)
- grinder: pin audit iteration 17's two silent-corruption findings (93bbab2)
- grinder: pin audit iteration 21's two shutdown gaps (8236c93)
- grinder: pin how the CPU cap is reported to the operator (f3b72af)
- grinder: pin that a failed install names an unwritable mount (5ecf8cd)
- grinder: pin that a positive CPU cap stays a cap (ebb8a2a)
- grinder: pin that the knob defaults and the class defaults agree (d005852)
- grinder: pin the per-container CPU cap and its wiring (6b159bf)
- grinder: pin the per-container memory cap and both caps' wiring (1fc9720)
- grinder: pin the pollable fallback-list properties document (47f9917)
- grinder: pin the shared window positively and against the real cap (2a90aa0)
- grinder: pin the shutdown invariant, its wiring and its 15s window (25c0c2c)
- grinder: pin what stopping the service must do to workers and containers (312745b)
- grinder: pin which uid:gid a container runs as (2964419)
🚀 Features
- grinder: express the container CPU cap in cores, against a stated period (00b5e77)
- grinder: make the per-container CPU cap configurable (65c921c)
- grinder: make the per-container memory cap configurable, with its warning (61fed6a)
- grinder: serve the fallback list as pollable properties at /as-properties (6be42c4)
- grinder: stop containers and workers gracefully, then kill them (25541a8)
🛠 Fixes
- ci: drop the gitlab.com release mirror, and stop curl hiding why (3b29a57)
- clientside: a crash cannot outrank another loader's clean boot (e4ea0b8)
- clientside: don't log "re-checking 0 other version(s)" (3400ff4)
- clientside: keep the file when CurseForge aborts the navigation (9df60fc)
- clientside: keep the reported verdict's own boot console (f036bf4)
- clientside: re-check a crash against the mod's other versions (7daca76)
- grinder: decide "uncapped" from the request, not from the arithmetic (11dfba6)
- grinder: diagnose a failed install from the whole console (8ec7440)
- grinder: make Ctrl-C stop a one-shot run, and share one 15s window (c7cc767)
- grinder: make the shared shutdown window real above eight containers (f7b0302)
- grinder: publish the worker list before starting the workers (6042833)
- grinder: report the CPU cap the way the operator set it (63cfd46)
- grinder: run containers as the owner of the pack they mount (de20741)
- grinder: stop two silent corruptions found by audit iteration 17 (3b4dc45)
VirusTotal
ServerPackCreator-9.0.0-alpha.7.jar- https://www.virustotal.com/gui/file-analysis/NzBlMjVjN2U4NzRiNWJlNmM2MWIwYTkwNWRlZTg3YjA6MTc4NzUwNjg3NQ==serverpackcreator-api-9.0.0-alpha.7-javadoc.jar- https://www.virustotal.com/gui/file-analysis/ZjQzNDM2ZDZiZWMzMjEyOTBmNmFmMjI4YWQ2MDI2MDQ6MTc4NzUwNjg3Ng==serverpackcreator-api-9.0.0-alpha.7-sources.jar- https://www.virustotal.com/gui/file-analysis/YTYzNWIyNDljYmZiNDM2NzdkZjFlNjYyNzdhMDNmNDU6MTc4NzUwNjg3OA==serverpackcreator-api-9.0.0-alpha.7.jar- https://www.virustotal.com/gui/file-analysis/MDE0NzZlNDFjZmFmMzAwMTEyMzg3MjBlZTY2ODE5NTU6MTc4NzUwNjg4MQ==serverpackcreator-app-9.0.0-alpha.7-javadoc.jar- https://www.virustotal.com/gui/file-analysis/ODY5NzZjMTNiZmZkNjEyNWU3ZGM5NzhjMDU5ZjMyOGM6MTc4NzUwNjg4Mw==serverpackcreator-plugin-example-9.0.0-alpha.7.jar- https://www.virustotal.com/gui/file-analysis/MWQ5YjdiZmRhNjc5NDA0Y2VjYTVjMTQ0NzFmZjYwNjE6MTc4NzUwNjg4Mw==
Downloads
-
Source code (ZIP)
2 downloads
-
Source code (TAR.GZ)
1 download
-
9.0.0-alpha.6
Pre-releaseSome checks failedGenerate Release / semantic-release (push) Has been skippedDocker Test / build image (push) Successful in 15m29sBuild Release / Preparations (push) Successful in 14sDocumentation / Help image (push) Successful in 2m48sDocumentation / Writerside webhelp (push) Successful in 1m20sTest / build (push) Successful in 13m25sQodana / notify (push) Successful in 7sQodana / scan (push) Successful in 12m22sBuild Release / Docker images (push) Successful in 12m33sBuild Release / JARs, media and checksums (push) Successful in 27m34sBuild Release / Forgejo release (push) Successful in 2m54sBuild Release / VirusTotal scan (push) Successful in 2m55sBuild Release / Publish Maven (push) Successful in 6m38sBuild Release / Mirror release outward (push) Failing after 3m1sreleased this
2026-08-23 10:53:24 +02:00 | -659 commits to main since this release⚠ BREAKING CHANGES
- modscanning: remove the deprecated JsonBasedScanner
✂️ Refactor
- adopt the Kotlin idioms Qodana flagged (d37fc61)
- collapse the redundant conditionals Qodana flagged (4e16694)
- use multi-dollar string literals for dollar-heavy patterns (98942b1), closes #106
- api: compile the Forge annotation-scanner's regexes once (10a5811)
- api: extract how a timeout is applied into URL.timedConnection (555e9c7)
- api: extract manifest refreshing into ManifestUpdater (832bf43)
- api: hoist the per-file path resolution out of the gatherer's walk (0e97be4)
- api: index the Quilt scan by jar instead of searching it per entry (fca71d3)
- api: inject PathsConfig's working directory (3c068ce)
- api: make ModpackZipInspector's archive-opening injectable (8e0c840)
- api: make the launcher-manifest candidates askable (765e1d5)
- api: narrow ManifestUpdater to internal, and correct the timeout landmine (342e630)
- app: extract the upload duplicate-check from saveUploadedFile (aa763be)
- app: move the check-timer's server probe and pack-name read behind the view model (d6be4b5)
- app: put the migration's database access behind MigrationStore (5afd12c)
- app: split the suggestion parse out of allSuggestions (dd4c217)
- grinder: drop the bind guards' !! and over-tight exception type (ad7aff5)
- grinder: extract the Preferences-node claim from main() (7cd43b5)
- grinder: extract the report URL from main() (e04c02e)
- modscanning: extract the scanner contract and share the dispatch (d04a62a)
- modscanning: remove the deprecated JsonBasedScanner (d132522)
- web: extract the config-location composition from start() (18f25c6)
📔 Docs
- add a CI secrets reference for the Forgejo workflows (5eeb4a7)
- add BUILD.md, a contributor-facing map of the build (fd8d674)
- add Kent Beck's ordering mantra to the conventions (52a192c)
- answer the Docker/Mongo investigation's open question (21bab7f)
- audit iteration 12 — the systemd home-resolution branch, and its resolutions (3e873af)
- audit iteration 13 — the report bind-address branch, and its resolutions (1db4b60)
- audit iteration 15 — third pass, auditing the first two passes' fixes (8ffc8bf)
- audit iteration 16 — the deployment script and unit (03524c2)
- audit the build-docs branch (fa3cdd1)
- audit the context/documentation commits (iteration 10) (08728c2)
- audit the coroutines/catalog branch, fourth pass (9560ec0)
- audit the parallelMap/coroutines branch, post-remediation pass (b33da60)
- audit the post-migration commits (iteration 8) (3db2fcc)
- audit the readme-refresh and jpa-relics branches (c97ac45)
- audit the remediation (iteration 9) (47bfaf0)
- audit the security-manager branch, second pass (141dc20)
- backlog the CLAUDE.md trim, deferred behind the open merges (3256fef)
- bring root CLAUDE.md back under the large-memory floor (5f7298b), closes #1 #2
- carry iteration 4's guards into the refactor-state table (35bcbdb)
- carry iteration 6's guards into the refactor-state table (34331ad)
- cite commit subjects in the audit report too, and record iteration 4 (f971438)
- cite commit subjects instead of hashes, and correct the stale timeout landmine (2052180)
- clear B30/B31/B32 from the backlog and record them (d37be2d)
- close L3 in the audit after fixing it (8f3a51f)
- close out audit findings H-1 and M-3 (1f7aef2)
- close out the audit findings (96b802a)
- Consolidate the two audit files into claude-docs/REFACTOR-AUDIT.md (eda82e2)
- correct the id types in the published API spec (8796eaa)
- correct the last copy of the clientside-workflow miscount (f9c9d88)
- correct the marker rule — B35 was tried and does not work (0138f87)
- correct the published run-configuration API shape (f391518)
- correct two CLAUDE.md claims that outlived the backlog items behind them (6f7e95c)
- load the build and CI landmines only when they apply (8dd6af0)
- mark the lazy-loading saving as unverified, because it is (6c94565), closes claude-code#16299 #16299 #22170 #16299
- point BUILD.md at where CI lives and what it needs (882f967)
- record iteration 16's resolutions, and the JVM trap in the README (845fb63)
- record M-2 as fixed and repair a stray edit in the audit (d56bb4e)
- record that URI query parameters reach the driver again (a7cf04a)
- record the build layout after the simplification (24e00c5)
- record the catalog, [plugins] and Kotlin-unification work (57ba3f2)
- record the equivalence audit, its method, and the two findings it surfaced (3e70bb4)
- record the generation-throughput work, including the corrected estimates (53f3e12)
- record the grinder's report bind address in the status table (7033c23)
- record the GUI typing-path work (613b9ec)
- record the index-creation landmine and iteration 5 (2955212)
- record the network/startup work and backlog its follow-ups (aea1ea5)
- record the parallelMap fix, the coroutines floor and the BOM landmine (1cc6c4b)
- record the Qodana moderate cleanup and the two new pins (d280474)
- record the render-vs-prop test rule, and why the tooltips stay untested (b0ee703)
- record the systemd home-resolution trap and the ordering it depends on (bb6545b)
- record the two API-shape changes the generation branch left unrecorded (17a621e)
- record the web query-shape and DBRef-flattening work (e484a28)
- record what actually blocks the configuration cache (5fc3ca3)
- regenerate the API spec for the merged entities, and correct the suite counts (f158362)
- regenerate the OpenAPI spec from the controllers (ef13d48)
- stop CI-SECRETS.md pinning an install4j version it does not own (9832ace)
- the paths: scoping works — verified, and the earlier test was the wrong one (fb96ea3), closes #16299 #22170
- api: make the SKIP_JAVA_CHECK read intentional and guarded (c0b1457)
- app: re-verify the Mongo URI landmine at the versions now resolved (e3289e3)
- ci: record the release pipeline's two silent killers and the alpha-tag repair (7780da5)
- deprecation: suppress the intentional 6.0.0 deprecation warnings (9f92e8a)
- modscanning: record the scan-log-level rules (4f67393)
- modscanning: record the shared dispatch and correct the versioning-scheme survey (d76e2ed)
- readme: refresh stale content (d1ece9b)
- updater: record the pre-release ordering fix (486976e)
📦 Other
- Change logging to suggest report to author and include exception in log (6026f36)
- ignore Claude Code's per-developer files (f32c820)
- Please Please Please test your server packs before you release them (d858b8f)
- Refactor audit thanks to Claude (bd62619)
- Regenerate the license agreement for install4j-runtime 13.1 (1c90465)
- Update-To-Date license agreement (2611aed)
- web: drop the JPA/H2/JDBC relics from the Spring properties (24390e3)
🦊 CI/CD
- add a [plugins] catalog section and alias it from the build scripts (a8f1588)
- align springGradle with springBoot at 4.1.0 (f4dec99)
- Bump install4j to 13 (2c8de2c)
- bump Kover to 0.9.9 (96cb684)
- bump the Kotlin compiler to 2.4.10 (f0bf003)
- bump third-party library versions in the catalog (e55ddfe)
- collapse the four Kotlin entries onto one version ref (2be03f8)
- consume plugin markers in buildSrc instead of implementation artifacts (6325735)
- declare repositories once, in settings.gradle.kts (260f6f0)
- drop the orphaned io.spring.dependency-management plugin (66c77c0)
- let Gradle provision the JDK for the modules, not just for buildSrc (efcfbc8)
- move library versions into the version catalog (010e2f3)
- move the version catalog to gradle/libs.versions.toml (3e4afb9)
- remove cross-project configuration from the root build (689e4dc)
- remove duplicated and dead build logic (7511673)
- remove script-object captures from task actions (0c3da90)
- replace plugin-example's configuration-time copies with a Copy task (2c48f22)
- replace the configuration-time copies with real Copy tasks (2eccd20)
- route nekodetector and the Boot BOM through the catalog (b4e6fe9)
- scope publishing and signing to the api module (5992f57)
- upgrade Gradle to 9.7.1 (2f6894a)
- use lazy task references everywhere (45bce07)
- fix the credentials and references the migration got wrong (d894362)
- fix the ordering and re-run defects the first release would have hit (dfd4352)
- make the Docker diagnostic name its runner, and record what B26-B29 still need (e295ee0)
- move CI/CD to Forgejo, and retire GitLab CI (832eb46), closes forgejo#9203
- stop a release publishing its prereleases' changelogs, and fail loudly on upload errors (d00d094)
🧪 Tests
- make three guards that passed for the wrong reason actually bite (d3b20a0)
- api: pin hasteBinPreChecks before it stops reading whole files (522ab1e)
- api: pin home resolution against an unwritable working directory (ada7476)
- api: pin how often a modpack archive's central directory is read (e79f0ee)
- api: pin that a fresh install's fallback database-URI is usable (594cf5a)
- api: pin that an unknown Java version drops the security-manager flag (0ff2784)
- api: pin that an unreachable host leaves the present manifest intact (a189022)
- api: pin that HTTP calls give up instead of hanging forever (13a4b97)
- api: pin that parallelMap neither leaks a thread nor serialises (e55ba89)
- api: pin that the fallback-list refresh gives up instead of hanging (8ba6484)
- api: pin that the regex mod-lists are not shared between reads (40b0934)
- api: pin that the writability probe cannot be defeated by a name collision (af939d0)
- api: pin the cost of the clientside-exclusion loop (ac50171)
- api: pin the Java-resolve and fail-safe guard in all three templates (63a0860)
- api: pin what a manifest check costs (7dedca7)
- app: assert the components that only work if Spring created them (a9ddf98)
- app: characterize the EventService and RunConfigurationService store loops (d603378)
- app: characterize VersionChecker's pre-release comparison (ec79084)
- app: cover the migration runner's safety decisions (f021610)
- app: pin how often the check-timer consults the network and the disk (6537259)
- app: pin that a duplicate hash cannot break the upload check (7965520)
- app: pin that an upload's duplicate-check does not scan the collection (57090e1)
- app: pin that index creation is never a condition of starting up (ff83e6d)
- app: pin that the autocomplete list is parsed once, not per keystroke (1e9c748)
- app: pin that the database-URI key is one Spring Boot still reads (a2cdb9e)
- app: pin that the declared upload-hash index is actually created (3a7efd6)
- app: pin that the stats endpoint counts instead of scanning (0e0fc76)
- app: pin that the update check gives up instead of hanging (b58f866)
- app: pin the 9.0.0 migration for the renamed database property (4a84834)
- app: pin the migrated collection's name against the mapping it mirrors (c7e9a40)
- app: pin the two VersionChecker pre-release comparison defects (866c139)
- app: read the shipped application.properties, not the test copy that shadows it (8ad9f2f)
- frontend: assert the rendered mod-lists, not the props they came from (15b7754)
- grinder: bound the ordering guard to main's own body (b4f5c4e)
- grinder: pin that an already-bracketed IPv6 bind is not bracketed twice (badcc93)
- grinder: pin that the SPC environment is claimed before the first log statement (4624a57)
- grinder: pin that the unit tells the operator how to provide Java (68046d4)
- grinder: pin the logged report URL for wildcard and IPv6 binds (041d3f9)
- grinder: pin the report's bind address and its wiring (7b8e762)
- grinder: pin the systemd unit against the variables the service reads (c618340)
- modscanning: pin Forge scanner selection across both Minecraft schemes (f8cb89b)
- modscanning: pin that a Forge mod without dependencies keeps its id (b0e52a3)
- modscanning: pin the shared scanner dispatch directly (9a37368)
- web: pin the eight-location Spring config chain (d321722)
- web: replace WebServiceTest with a real application-context test (c8b5512)
🚀 Features
- api: add configurable network timeouts (8af3540)
- api: offer an ETag so the Forge manifest can answer 304 too (71c83c1)
- app: add an indexed findBySha256 to the modpack repository (26f342e)
- app: report the renamed database property when upgrading to 9.0.0 (2f91f5f)
- build: cross-package the aarch64 AppImage, so it needs no arm runner (ee766bb)
- ci: expire test.yml's artifacts instead of keeping them for 90 days (5b32620)
- ci: link the Qodana report artifact from Discord, not the run page (1cd2ac2)
- ci: put the report's expiry in the Discord message as a Discord timestamp (420a46b)
- grinder: make the report's bind address configurable (f91cedf)
- grinder: ship an example systemd unit and an installer (f9a0494)
🛠 Fixes
- If no (Neo)Forge or Minecraft dependency is declared, assume sideness server (7abd7c8)
- api: bound the fallback-list refresh (733db7c)
- api: halve startup requests and skip unchanged manifests (5f92b63)
- api: hand out a fresh regex mod-list per read (9b00946)
- api: make the fallback database-URI a URI the driver accepts (add8982)
- api: measure a HasteBin candidate without materialising it (b5add6c)
- api: never resolve the home directory to a place SPC cannot write (b470496)
- api: probe writability with a name nothing else can hold (79c34df)
- api: read a modpack archive once per inspection (cd75f24)
- api: refresh the version manifests in the background, not during construction (211dc83)
- api: resolve Java after installing it, and fail safe when it is unknown (5f4bce2)
- api: route every outbound call through one timed opener (5625223)
- api: route the HasteBin POST through the shared opener too (e1a593e)
- api: sanitise a network timeout once per assignment (9ef4191)
- api: stop a bad regex aborting the mod-list, and hoist the loop invariants (f77a5c6)
- api: stop parallelMap leaking a thread per call, and make it parallel (ae18f56)
- api: write the database-URI under the key Spring Boot 4 actually reads (f509eed)
- app: bound the update check's requests (27f544b)
- app: cache the autocomplete parse, and stop reinstalling the LAF per keystroke (a7b3ff9)
- app: count the stats totals instead of scanning three collections (13467fc)
- app: create the declared indexes after startup, not during it (93cee51)
- app: create the indexes the web module declares (327e458)
- app: embed the run-configuration mod lists, and migrate what is stored (918ca03)
- app: key the installer-probe memo on a Triple instead of NUL-delimited text (bc6c78c)
- app: look an upload's hash up by index instead of scanning every modpack (4f82e4b)
- app: stop the check-timer re-probing the network and re-parsing the manifest (e4ec252)
- app: tolerate duplicate hashes in the upload duplicate-check (1b287ab)
- build: declare mockk explicitly in -app so it matches -api (e732079)
- build: declare the Java compilations on dokka's HTML publication too (dbcb80c)
- build: import Boot's BOM as a platform so the catalog wins (3ab1abe)
- build: keep the install4j plugin off buildSrc's compile classpath (6969313)
- build: replace the Gradle APIs 9.7 deprecates and 10 removes (8a795b4)
- ci: drop the Qodana Cloud token the project cannot have (d4af07b)
- ci: keep the Forgejo token out of release-generate's remote URL (20cd6ed)
- ci: make the sibling-container steps work under docker-in-docker (d21caeb)
- ci: pin semantic-release's plugin majors so a preset bump can't break the release (97f487e)
- ci: rename the Forgejo credentials off the reserved FORGEJO_ prefix (710e8ea)
- ci: scope the Forgejo credential to the checkout, not the runner (5039fd7)
- ci: stop running jobs inside tool containers, and drop the inert permissions (5bc0434)
- ci: use Forgejo's patched artifact actions, which do not refuse a non-GitHub host (8830248)
- docs: repair the broken KDoc links and drop a redundant inner modifier (b5dec4d)
- grinder: close every finding from audit iteration 16 (70a10fd)
- grinder: don't bracket an already-bracketed IPv6 bind, and stop --help truncating (6d4a86c)
- grinder: harden the installer, and record audit iteration 14 (f158699)
- grinder: make the logged report URL openable for wildcard and IPv6 binds (43249a6)
- grinder: pin SPC's home to the daemon's base before anything logs (d4eec4b)
- modscanning: log a jar with no descriptor at debug, keep real failures loud (30bcdc6)
- modscanning: select the Forge scanner from the whole Minecraft version (4dbf653)
- modscanning: treat an absent dependencies block as no dependencies (46a8a7b)
- updater: order pre-releases by channel, and pick the latest by version (f6df209)
VirusTotal
ServerPackCreator-9.0.0-alpha.6.jar- https://www.virustotal.com/gui/file-analysis/NmI1ZDczZWM4MjAyNTliZTZmODJiMTk5Mzc1YTcyN2Q6MTc4NzQ3OTAxMg==serverpackcreator-api-9.0.0-alpha.6-javadoc.jar- https://www.virustotal.com/gui/file-analysis/ZjQzNDM2ZDZiZWMzMjEyOTBmNmFmMjI4YWQ2MDI2MDQ6MTc4NzQ3OTAxMg==serverpackcreator-api-9.0.0-alpha.6-sources.jar- https://www.virustotal.com/gui/file-analysis/ZTNmYTZiZTVkZDRjZmZlYWYxNTg3OWE0YzU5NTQ3OWU6MTc4NzQ3OTAxNA==serverpackcreator-api-9.0.0-alpha.6.jar- https://www.virustotal.com/gui/file-analysis/NTY5NjliNGY2OGE5NmEzNTM4MWNjNWYyMGE4ZmQxN2Y6MTc4NzQ3OTAxOA==serverpackcreator-app-9.0.0-alpha.6-javadoc.jar- https://www.virustotal.com/gui/file-analysis/YjgyYjc3MTMyMzJmNzBkYTI1MzllZjZhMzgxODMyMTg6MTc4NzQ3OTAyMA==serverpackcreator-plugin-example-9.0.0-alpha.6.jar- https://www.virustotal.com/gui/file-analysis/NzJhOTE3OTBlNGMwN2Y3YzQ2ZGVlYzE2MGI1NTEwYmM6MTc4NzQ3OTAyMQ==
Downloads
-
Source code (ZIP)
1 download
-
Source code (TAR.GZ)
1 download
-
Pre-Release 9.0.0-alpha.5
Pre-releaseSome checks failedclientside-report-reusable.yml / RELEASE: 9.0.0-alpha.5 (push) Failing after 0sCreate GitHub Pre-Release after GitLab tag mirror / Preparations (push) Successful in 13sCreate GitHub Pre-Release after GitLab tag mirror / JAR and media (push) Failing after 11sCreate GitHub Pre-Release after GitLab tag mirror / PreRelease (push) Failing after 7sCreate GitHub Pre-Release after GitLab tag mirror / News on Discord (push) Has been skippedTest / build (push) Failing after 19m9sreleased this
2026-08-15 00:16:10 +02:00 | -395 commits to main since this release9.0.0-alpha.5 (2026-08-14)
✂️ Refactor
- Remove dead code after modscan-rewrite (0df7b28)
- api: build ScannedMod complete instead of assigning into it (7a37426)
- api: compare scanned mods by jar, not by filename (8d0022c)
- api: read the exclusion filter once instead of three times (198ff2b)
- api: remove the unreachable copy-loop from the Quilt arm (9459b0c)
- api: rename ScanResult.kt to ScannedMod.kt (4793620)
- clientside: rename Sideness to DeclaredSupport (90fed95)
📔 Docs
- close out the audit after the tidy-up branch (6a88369)
- correct the stale app and web-frontend test counts (13d63a9)
- move the dated narrative history out of CLAUDE.md into REFACTOR-LOG.md (0e31fd2), closes gitlab-runner#27496
- record the I-6 fix and correct the suite count (39a285c)
- record the modscanning hardening and correct the modloader-fallback claim (1f93755)
- update the refactor audit to reflect the remediation (51a8db3)
- api: correct ReadmeExamplesTest's stale and invented references (3fabed7)
- api: document the scanned-mod types (d6b86ee)
- clientside: record why DeclaredSupport and Sideness stay separate (6fc8c26)
- grinder: add a clone-to-results quickstart (385532b)
📦 Other
- Add clientside-only mods to the list. Thanks to @ModernGamingWorld @szszabi2002 @Joly0 for the reports! (5a03123)
- api: drop the unused SupportedModloaders.quilt import (d9a9778)
🦊 CI/CD
- run the frontend Vitest suite as part of
check(33a6361) - deps: bump org.jetbrains.kotlin:kotlin-test-junit5 (f4e4e20)
- deps: bump org.junit.platform:junit-platform-launcher (3b17c1f)
🧪 Tests
- Use correct syntax to test contents (d185fd7)
- api: pin auto-exclusion and Quilt de-duplication in ModListCompiler (7279962)
- api: pin dependency extraction and Forge platform-side inference (5eb1edd)
- api: pin that an unrecognised modloader still yields every mod - RED (b8f809f)
- api: pin that the dependency rescue reaches clientside mods - RED (d8dfeb4)
- api: pin the Quilt arm against a fabric-only jar (581ca46)
- api: pin the SERVER default for a descriptor without an environment (793b8fc)
- api: pin the unreadable-jar sideness and modID fallback (010db69)
🛠 Fixes
- Aggregate Quilt-scan results to prevent double-entries (35cb727)
- Prevent duplicate entries (7004f3c)
- Prevent the modID being the same by acquiring it from the mod-file (2ec5ff2)
- Quilt mod with no env is not treated as SERVER (bf226c2)
- Vastly improve automated modscanning to catch and process sideness more reliably, as well as taking care of dependencies (0a12d41)
- api: include every mod when the modloader is unrecognised (2eafe1b)
- api: let the dependency rescue reach clientside mods (35c5787)
- api: log the Quilt entry being replaced, not its replacement (b855873)
About Pre-Releases
Do not release or publish a server pack generated using a pre-release of ServerPackCreator to your users.
If you do, and it turns out that your server pack doesn't work because of a bug in ServerPackCreator, that's on you for using a pre-release.When using pre-release installers, make sure to uninstall the previous pre-release first. Otherwise, the installers
own version checks may trigger an error out of my control. After uninstalling, install the newly downloaded one and
you're good to go.Only use the installers if you are versed in system-administration, manually editing and removing services, editing registries,
so on and so forth.Alphas
Alphas are feature-incomplete and very likely to have bugs. Consider them broken by default. Use at your own risk!
Betas
Betas are feature-complete and probably have bugs. Additional features may be added during the beta-phase of any given release, though.
If you are updating from version 5 or older and used the installers, then make sure to uninstall any previous version(s)
before using the installers for versions 6 and newer.Additional Installer-Notes
It is recommended to have administration-privileges when using the Windows and macOS installers.
I am not a member of the Apple Developer Program and won't pay for codesign-certificates, therefor installers are unsigned.
Running a given installer may produce warnings depending on what OS you are using. You may choose to install it anyway, please be aware though that doing so is, in general, not a safe practice. For ServerPackCreator, though, it is unfortunately the only way to run the installer.macOS DMG
MacOS will complain about potential security risks and refuse to install and run ServerPackCreator. To circumvent this, please see the official guides depending on your version of macOS: Ventura, Monterey or newer.
Windows EXE
Hit "More information" if the Windows SmartScreen-message pops up. Afterward, a button will appear which will let you run the installer anyway.
Downloads
-
Source code (ZIP)
1 download
-
Source code (TAR.GZ)
0 downloads