Changelog.
Everything each International Duck project has shipped: 36 version sections and 302 individual entries, transcribed from the CHANGELOG.md each repository maintains, in the order that file lists them, and linked back to the matching GitLab release.
Snapshot taken 2026-10-05 from CHANGELOG.md + GitLab releases API. Where a version has no tagged release the entry says so rather than guessing a date.
Beacon
5 version sections · 70 entries · latest 2.0.0-prerelease (unreleased)
CHANGELOG.md on GitLab All releases Repository
2.0.0-prerelease — Module fixes
- Confetti on Advancement is an actual celebration now. The burst was ~40 dust particles at scale 0.7-1.3 in a single uniform spread — close to invisible in daylight. It now opens with a centre pop, splits into three bands (fast outward ring, slow drift, and a fountain that arcs and falls), doubles the dust scale to 1.2-2.4, and trails
FIREWORKshimmer behind the confetti. Default count 40 → 120, ceiling 200 → 600. Applied to both copies ofFireworksFx(src/main/javaand themc26_3override) so 26.3 does not keep the old effect. - StructureNotifier no longer fails silently. Its detection wrapped everything in an empty
catch (Exception) {}, so a mapping change or a throwing registry lookup looked identical to "you are not inside a structure". Failures are now logged once per session, and a new Debug Log setting reports how many structure starts each chunk actually carries — which is the real question, since a multiplayer server does not send structure starts to clients at all. - The "Redo onboarding" button no longer lies. Its handler called
toast()unconditionally after firing the bridge request, so it reported "First-run setup will run again on the next launch" even when Beacon refused the reset. The message is now the request's success notice, which only fires on anokresponse; a failure surfaces the bridge's own error instead. Covered by a jsdom regression test that mocks the bridge in both states. - Build fix:
AFKFisherreferencedFishingBobberEntity, which does not exist in these mappings — the class isnet.minecraft.world.entity.projectile.FishingHook(seeFishingHookAccessor). All four references corrected; the code never compiled as shipped. - CompactMessages actually collapses duplicates now. The mixin fetched the module, tested
isEnabled()and then had an emptyifbody, somaxCombo()/counterColor()were never called and enabling the module changed nothing — the only collapsing came from BetterChat's separate anti-spam. CompactMessages owns its duplicate detection now and appends a colouredx Nbadge, capped by Max Combo. New Scan Depth and Ignore Timestamps settings. - BetterTab no longer covers the screen.
TabListPlusMixinrewrote every13,11and9inPlayerTabOverlay.extractRenderStateto40to make room for numeric latency — but those literals are row metrics and padding, so the whole tab list inflated several times over. The wide layout is now opt-in via Wide Ping Column (off by default). - SoundMuter's mute no longer sticks. Enabling it used to walk the entire sound registry and
stop()every matching identifier, killing portal/beacon hums mid-loop that nothing ever restarted — so disabling could not bring them back. Muting is preventive only now: the mixin rejects new matching plays, and disabling takes effect immediately with no state to undo. - ItemSearch is reachable. It only accepted
@search <item>while every other module answers to@ModuleName ..., so the conventional@ItemSearch woodreturned "Unknown setting/subcommand", and its only setting was the toggle keybind. Modules can now handle their own subcommands (Module.onCommand), ItemSearch takes@ItemSearch <item>, and it gains Scope and Show Slots settings. - AFK Fisher: the description no longer credits Meteor, the bite
plingis gone (with the now-meaningless Bite Alert setting), and a catch is counted once per bobber instead of once per catch path — the "Caught N fish" tally was inflated. - "Redo onboarding on next launch" no longer silently drops the wizard. The flags really were being cleared and reloaded; the launch check was the problem.
Onboarding.onClientTicksetarmed = falsebefore attempting to open the page, so if that one open failed the setup was dropped for the whole launch with nothing logged. The retry budget now covers both waits (Chromium downloading, and browser-registered-but-won't-take-the-page), the setup only disarms once the page actually opened, and every branch logs — so the next launch's log says exactly whether the reset was written or the show path failed. - Regenerated the module catalogue: it had drifted to 55 modules/232 settings while the Java registry held 56/234 before any of the above.
2.0.0-prerelease — Boot intro polish
- Bumped the mod version to 2.0.0-prerelease.
- The first-run Chromium install now shows a real progress bar (with a percentage) on the loading screen, driven by the download's own byte-level progress instead of an endless spinner.
- The 3D boot intro now preloads before it plays: the first frames — which compile every shader — are drawn invisibly, so the opening no longer hitches.
- The screen stays black through the whole handoff from the Chromium install to the boot intro: the loading screen paints an opaque black frame (no blurred menu underneath) and the wizard's first paint is black, so there is no white flash or menu glimpse.
- The finished 3D beacon now stays on as a live backdrop for the whole onboarding: after the cinematic it settles on the beacon's hero frame and idles in a slow, cheap orbit behind the frosted wizard, and the old flat "transparent logo" welcome card is gone (the PNG only returns as a fallback when WebGL is unavailable).
- Themes got a real art pass (Spicetify-style): each theme gains a two-colour nebula glow and a soft vignette behind the glass, the theme picker swatches now preview each sky (glows + star specks), and Starry Night reads like a proper indigo night with a purple nebula.
- The theme/accent chosen in first-run onboarding now forwards to the main app: the client stores them as
uiTheme/accentand the app reads them back on launch (and pushes its own changes back over the bridge), so the look no longer snaps back to a default. - The top-right Beacon corner logo expands on hover to show the running version, and it now also sits on the main menu even before the first-run setup has been completed.
- The first-run setup now paints an opaque black backdrop for its whole lifetime, so the blurred menu/panorama no longer shows through in the stretch between the install screen and the 3D intro (the app keeps its transparent, world-showing backdrop).
- The standalone "BEACON" wordmark over the intro is gone; the welcome reads "Welcome to Beacon" only.
- Performance pass for the software (SwiftShader) renderer the embedded browser uses: the idle backdrop drops to a lower resolution/24 fps, the cinematic drops MSAA, and the always-on animated atmosphere no longer runs full-screen
filter: blur()(the two big glows are unblurred radial gradients; Mist/Aurora particle blurs are much lighter) — smoother intro and faster menu opens. - The intro's hidden warm-up now pre-renders a spread of timeline frames instead of just the opening frame, so the shader compile no longer stalls the start and the mid-intro energy merge.
- The intro's soundtrack now starts with the first visible frame rather than at mount: it used to run a second or so ahead of the picture during the hidden warm-up, and the opening then snapped forward to catch up — the stall-and-jump at the start.
- Opening the app straight after the first-run setup no longer flashes the wizard's 3D backdrop: one browser serves both pages, so the outgoing page is cleared off the surface before the new one is navigated to.
- Typing in the app's search no longer rebuilds the menu. Only the module boxes that stop matching are hidden and the ones that start matching again are revealed, so the page stops fading out and re-animating on every keystroke.
- The
⌘ Khint box is gone from the search bar. - The GUI key (
Kby default) now also opens Beacon from the main menu, not just in-game — module keybinds still win if one of them is bound to the same key. - "Redo onboarding on next launch" actually replays the whole first run again. It cleared
onboardingSeenbut notintroSeen, and the page gates the 3D cinematic on the second flag — so the wizard came back with no intro at all, which is what made the button look dead. - The wizard's Finish step and its confirmation now both say which key opens Beacon, as a key chip rather than a line of small print. It quotes the key Beacon actually reports (
guiKeyLabel), so it stays correct after a rebind, and the confirmation's version is large because that screen closes itself after ~2.5 s. - Interface sounds are now real: the app plays subtle click/navigation feedback (opt-in via Settings → Interface sounds), and the first-run wizard uses a fuller sting set (page turns, selection, a completion chime).
- The mod author is now "International Duck Incorporated", and Settings gains a "Redo onboarding on next launch" button that re-runs the first-run wizard (and 3D intro) on the next boot.
1.9.0 — Bagley addon extraction
- Extracted the built-in Bagely module into the standalone Bagley Fabric addon. Beacon no longer ships AI endpoint, memory, screenshot, or Bagley-specific platform code.
- Added addon-safe incoming/outgoing chat observation events, generic settings-drawer actions, and module configuration aliases.
- Existing
Bagelyenabled state, settings, and favourites are read asBagleywhen the addon is installed. The addon migrates its privatebeacon-bagely…files to Bagley names without logging credentials. - Added the addon API and player migration guides. The Bagley source tree is published separately for GitLab. All notable changes to Beacon are documented in this file, in the Keep a Changelog format. Per-version notes for older releases (0.2.1 through 1.8.17) remain in
releases/as a historical record; this file is the changelog going forward.
Unreleased — in development
Added
- The first-run onboarding intro is now a real 3D cinematic.
webui/onboarding.htmlopens on a fullscreen WebGL scene that renders the Minecraft beacon fromassets/models/beacon.glb— the centrepiece,GLBConverted, CC-BY-4.0 by owencroft0, attributed inTHIRD_PARTY_NOTICES.txt. Blue energy bands and motes arrive from off-screen, spiral in on a drifting helix, are pulled through the beacon's glass and absorbed at a target measured from the model's own geometry, and then the beacon activates: core emissive, a short flash, a shockwave, UnrealBloom and a Minecraft-style beam, while the camera pushes in for the absorption and opens up for the reveal. The reference clip was used as the audio reference only (it is never rendered): its audio track is the intro's soundtrack, its ~1.1 s of leading silence is skipped, and its measured beats drive the cue table —webui/generate_intro_cues.pyre-measures the clip with ffmpeg and writesassets/audio/beacon-intro.cues.json, whichwebui/intro3d_verify.pycross-checks against the module. The whole cinematic is one pure function of a single visual time (webui/assets/vendor/intro3d-timeline.js) withINTRO_START → … → COMPLETEstates, so it is deterministic, seekable, frame-rate independent and tunable in one table. Rendering never waits on audio: if autoplay is refused the scene still initialises, animates and finishes, and the first tap starts the sound without skipping the shot (Escor the Skip button skips). Every failure — no WebGL, missing module, missing/broken model, failed init, a stall — disposes the scene and hands the screen to the existing onboarding welcome screen, and the intro is never allowed to block onboarding. three.js r180 and the post-processing addons are vendored locally underwebui/assets/vendor/(no CDN), with the rationale inwebui/INTRO3D.mdandwebui/assets/vendor/README.md. - First-run onboarding, wired up.
webui/onboarding.htmlis now packaged asassets/beacon/webui/onboarding.htmland opens automatically on the first launch once the HTML UI is ready: it shows at the main menu, never over a game in progress, and stays pending if Chromium is unavailable so it is not silently consumed.@onboarding(alias@setup) re-opens it at any time, which is how the page is re-tested without deletingbeacon.json. Finishing — or skipping — postsonboarding.completeover the typed bridge and persists the theme, accent, sound toggle, sound volume and favourite modules intobeacon.json(uiTheme,accent,soundVolume,onboardingSeen); favourite ids that match no loaded module are dropped instead of being saved as favourites that could never resolve. The same values are exposed to the UI through the bridge snapshot'spreferences. - Bagley follow-up conversations with an LLM-controlled stop. After a reply, the same requester can continue without repeating Bagley's name for a bounded window (default 45 seconds). The model itself decides when the conversation is over: a new
no_responsetool call (or the[[bagley_no_reply]]marker on endpoints without function support) sends no public chat and immediately ends the listening session, so chat addressed to other players stops triggering Bagley instead of restarting the timer. A marker returned with surrounding text is now treated as a no-reply instead of publishing the model's commentary, follow-up sessions are hard-capped at five consecutive replies, and decision turns never post the public failure apology. - Bagley nearby-entities and Baritone tools.
get_nearby_entitiesshares loaded entities within a requested radius (default 32, max 128 blocks). With Allow Baritone actions (ban risk) enabled,baritone_go_to/baritone_stoplet the model navigate via the installed Baritone mod's#goto/#stopcommands — advertised only when the mod is actually installed, with the model instructed to navigate only to player-provided coordinates. Both were previously stranded in theBeacon-complete-7700335-…bundle and never reached the compiled source, which is why the AI never used Baritone; they now build fromsrc/for all Minecraft targets. - HUD visibility modules. HideScoreboard now provides independent, default-on controls for the sidebar scoreboard and on-screen chat feed. HidePumpkinOverlay is a separate Render module. Both update their render paths directly without forcing a chunk/world renderer rebuild, and legacy
HideOverlaysconfiguration is migrated.
Fixed
- The 3D onboarding intro could never actually run in a build. Beacon's loopback origin sent
connect-src 'none'in its Content-Security-Policy, and three.js downloadsbeacon.glbwithfetch()— which is what that directive governs, notmedia-srcorscript-src. Chromium therefore refused the model request before it left the browser,GLTFLoaderreported a failure and the cinematic skipped straight to the welcome screen. The development harness never showed it becausepython -m http.serversends no CSP at all. The policy now allowsconnect-src 'self'(still nothing off-origin, the page never talks to the Internet), the model and soundtrack are served asmodel/gltf-binaryandaudio/mpeginstead ofapplication/octet-stream(every response also carriesnosniff), andintro3d_verify.pygained a section that checks the packaged origin instead of only the page. - HTML UI console output now reaches the game log. Page-side warnings and errors — including
[Beacon] 3D boot intro unavailable (<reason>)and Chromium's own blocked-subresource reports — are forwarded as[Beacon][HTML UI] …, so a page that degrades no longer leaves the log silent about why. - The intro's beacon is textured again — it is no longer a bare grey cube.
beacon.glbstores its three textures in bufferViews;GLTFLoaderturns each one into ablob:URL and downloads it throughfetch().connect-src 'self'does not matchblob:URLs even though the page created them, so the texture fetches were refused and the model rendered untextured. The served policy now allowsblob:in bothconnect-srcandimg-src(blob:URLs inherit the page's origin and can only be created by it, so no new target is reachable). Verified against real Chromium: with the old policy the three texture fetches are CSP-refused and the shot is a plain cube; with the fix they succeed and the textured beacon renders. - The boot cinematic (and its audio) no longer replays on every launch. The page kept the "seen" flag only in
localStorage, but the loopback origin is a fresh random port and token on every launch, so the store was empty each time.onboarding.intro-seen— which the page already posts but the bridge previously rejected as unknown — now persists a durableintroSeenflag inbeacon.json, the state snapshot exposes it, and the page asks for the snapshot before deciding whether to play (with a short fallback so a dead bridge cannot strand the player).@onboardingstill opens the wizard, but the intro plays only once;#replay(or?replay=1when testing standalone) forces it again. - Fullbright no longer unloads the visible map. Gamma and Potion modes never touch chunk meshes. Entering, changing, or leaving Luminance mode now marks visible-range sections dirty and lets the normal compiler replace them while their old meshes stay on screen, instead of releasing every render buffer up front.
- SoundMuter applies immediately. Enabling the module or any mute filter now stops matching sounds that are already playing through the public per-identifier sound-manager API; future matching sounds remain blocked by the play hook. Unrelated effects and music are left running, and rejoining is no longer required.
- Bagley provider, tool, passive-listener, follow-up, retry, failure reply, memory, nickname, and complete-answer controls. Bagley now has Click GUI controls for provider profile, provider-appropriate reasoning effort, observation tools (tab list, nearby entities, and one current-game screenshot), an explicit ban-risk Baritone-navigation opt-in, client-only tool/loading notices, an opt-in five-second passive-listener decision window, natural same-requester follow-up questions with no-reply decisions, retries, the initial retry-delay seconds (default exponential waits: 5, 10, then 20 seconds), public exhausted-retry replies, busy notices, response token budget, reply detail, response audience, bounded local conversation memory, and protected long-term notes. The default disabled reasoning setting sends
reasoning_effort: noneto Ollama/OpenAI-compatible endpoints, fixing Qwen3 responses that otherwise contain only hidden thinking and no finalmessage.content; OpenRouter instead receives its own excluded structured reasoning object. Tool screenshots are downscaled, attached only to the configured endpoint for a mention-triggered tool call, visibly announced only to the client, deleted locally immediately, and cleanly fall back if a non-vision endpoint returns HTTP 400. Passive windows never enter Bagley memory. Bagley now repairs missing/invalid config schema fields and backs up malformed JSON before recreating a usable local config. OpenRouter-style length-limited output is retried instead of being posted mid-sentence. Its private configuration also supports case-insensitive nickname triggers (includingBagsby default). Memory and durable notes are stored separately inbeacon-bagley-memory.json, and all maintained Minecraft overlays provide the failure toast. - Minecraft 26.3 input target by default. A plain Gradle build now selects the 26.3 overlay, including its SDL keyboard and mouse translation, instead of building a 26.2 jar whose GLFW-style input codes make the Click GUI appear unresponsive on 26.3. Older versions remain available through
-Pmc=<version>. - The build never worked. The committed scaffold could not even configure: it used the pre-26.1 remapping plugin (
fabric-loom1.16.2, a combination that does not exist for the new plugin id) withmodImplementationconfigurations that no longer exist. Now:net.fabricmc.fabric-loom1.17-SNAPSHOT + plainimplementation, per the canonical 26.2 template../gradlew buildis green for the first time in the repository's history. - Chat autocomplete cast every suggestion
Stringtojava.lang.invoke.CallSite— compiled fine, ClassCastException the moment the@menu opened. @searchset the ItemSearch query without lowercasing it (unlike the module's own chat path), so uppercase queries silently matched nothing.- FreecamCoreTest's epsilon was always-red against the shipped float-radian math; BeaconConfigTest still called a stale
EnabledModules.unknownsignature and could not compile against the current tree.
Removed
- The Click GUI HTML prototype (
docs/beacon-ui.html) and its two dedicated checkers — a second implementation of the GUI that only existed to be kept in sync. Seedocs/CLICK-GUI-HTML-REMOVAL.md. - The
@themecommand: it tried to set aBeaconUI.currentThemefield that has never existed on the Java GUI and could only ever fail. Runtime theming does not exist (the palette is compile-time constants); when it does, the command can return with a real implementation behind it. - The stale
dealautocomplete candidate left over from the AH Deal Sniper removal.
Changed
- Prepared Beacon for multi-version Fabric builds from Minecraft 1.21.11 through 26.3: target matrix, per-target build directories, metadata/resource smoke checks, and compile-ready release artifacts.
- De-decompiled (~1,200 lines of CFR artifacts removed): banners, redundant casts,
void x = …eaten declarations, labeled blocks, swallowed mixin(Object)bridges, eaten string literals (logger names, texture identifiers, button labels), and a dozen genericity repairs. - Zero runtime reflection (~850 lines removed): EnderChestCapture (which reflected its own jar), ItemDraw, ReconnectFx, BookTools extraction, UiText, TabListFx and the pasteToBook/copyHeldBook/query field probes are all typed now, javap-verified against the 26.2 jar.
- Chat branding centralised in
net.beacon.utils.BeaconText(one prefix util instead of five ad-hoc§-literal shapes per module). ModuleManagerlookups are O(1) (concurrent class/name indexes; the ordered list stays the source of truth, with a subclass-safe fallback).EventBus.subscribetakes an optional priority: higher runs first, equal priorities keep registration order.- CI on every push (hygiene gate → target metadata smoke checks → compile-ready tests/build) and automated tag releases with checksums.
Added
- Bagley — an opt-in, OpenAI Chat Completions-compatible assistant that replies in public chat when someone says
Bagley. It sends only the triggering message and keeps endpoint credentials in the separate, non-shareableconfig/beacon-bagley.json; see the standalone Bagley repository. Setting.visibleIf(guard, test)— settings can declare they only make sense while another setting's value passes a predicate; the GUI honours it in render, hit-testing and height.- Config share codes:
@config export/@config import <code>— the wholebeacon.jsonas one pasteable string (gzip + URL-safe base64). - Keybind-conflict detection: conflicts are announced at config load and listed by
@binds, because the losing module in a key clash just silently never fires. @bug— a clickable link to a GitLab issue form prefilled from the Bug.md template (versions, OS, reproduce/expect skeleton).- JUnit 5 test suite (41 tests) wired into
./gradlew test, replacing the two hand-run javac harnesses;tools/verify/check_hygiene.pygates the de-decompile/de-reflect invariants in CI.
1.8.17 — and earlier
- See
releases/— one file per version, kept as a historical record.
Venomous
5 version sections · 40 entries · latest Unreleased (unreleased)
CHANGELOG.md on GitLab All releases Repository
Unreleased — in development
- Continued development and maintenance following the migration from GitHub to GitLab.
- Improved project documentation and clarified the project's work-in-progress status.
7.0.0
Added
- Added a Gradle-based Fabric build system with the Gradle wrapper.
- Added automated build and release workflows for stable and nightly builds.
- Added a comprehensive test suite covering:
- Addon metadata
- Compatibility helpers
- Mixin configuration
- Module registry integrity
- Module structure
- Scavenged module logic
- Server analysis
- Anti-vanish behaviour
- Anti-cheat bypass logic
- Movement mathematics
- Placement regressions
- Build scripts
- Added new rendering, HUD, screen, portal, and movement mixins.
- Added movement debugging and supporting movement mathematics utilities.
- Added
MovementMath,PreRotate, and other utility improvements. - Added a GPL-3.0-or-later license and included it in built JAR files.
Changed
- Recovered and migrated the addon from decompiled output into a maintainable Java source tree.
- Cleaned the recovered source tree and moved resources into the standard Fabric layout.
- Updated the project for Minecraft 26.2, Meteor Client 26.2, and Java 25.
- Renamed modules where necessary to avoid collisions with Meteor Client module names.
- Added the
v-prefix to modules that conflict with Meteor's global module registry. - Refined module registration and reorganized modules across combat, detection, ESP, exploit, fun, miscellaneous, movement, player, render, utility, and world categories.
- Improved combat, movement, automation, rendering, networking, and anti-cheat-related modules across the codebase.
- Added lifecycle cleanup and state-reset handling to multiple modules.
- Improved Aimbot, KillAura, Speed, Fly, Disabler, and related modules.
- Improved packet, rotation, portal, and placement handling.
- Updated README documentation with compatibility, installation, build, licensing, and issue-reporting information.
Fixed
- Fixed recovered Java source compilation errors across several modules.
- Fixed runtime issues in combat, movement, detection, exploit, utility, and rendering modules.
- Fixed module-name collisions that could replace Meteor Client modules.
- Fixed several module registration and structure issues.
- Fixed workflow and build configuration issues.
- Fixed executable permissions for
gradlew. - Fixed compatibility and mixin configuration problems.
6.2.6
Added
- Added decompiled Java source for the recovered Venomous addon.
- Added the initial Gradle and Fabric project structure.
- Added module implementations covering combat, detection, ESP, exploits, fun, miscellaneous utilities, movement, rendering, and world interaction.
- Added Venomous resources, including the icon, splashes, metadata, and mixin configuration.
Changed
- Cleaned the recovered source tree and converted it into a conventional source layout.
- Added an initial automated build workflow.
- Started migrating the project from a distributed JAR into a source-based development project.
Fixed
- Fixed initial compilation errors in the recovered source.
- Fixed formatting issues in the original README.
6.1.6
Added
- Added the first recovered Venomous JAR contents, including:
- Fabric metadata
- Mixins
- Venomous addon entrypoint
- Combat modules
- Detection modules
- ESP modules
- Exploit modules
- Fun modules
- Miscellaneous modules
- Movement modules
- Utility modules
- World modules
- Assets and splashes
- Added the initial README.
0.1.0
Added
- Created the Venomous project.
- Added the initial project README and project documentation. [Unreleased]: https://gitlab.com/international-duck-incorporated/Venomous/-/compare/v7.0.0...main [7.0.0]: https://gitlab.com/international-duck-incorporated/Venomous/-/releases/v7.0.0 [6.2.6]: https://gitlab.com/international-duck-incorporated/Venomous/-/releases/v6.2.6 [6.1.6]: https://gitlab.com/international-duck-incorporated/Venomous/-/releases/v6.1.6 [0.1.0]: https://gitlab.com/international-duck-incorporated/Venomous/-/commits/main
NullTrace
5 version sections · 57 entries · latest Unreleased (unreleased)
CHANGELOG.md on GitLab All releases Repository
Unreleased — in development
Added
- Added the central
ConnectionContext/PrivacyPolicy/AuditLedgermodel with explainableALLOW,BLOCK,WARN, andLOGdecisions. - Added
/nulltrace auditand per-serverSTANDARD,STRICT,MAXIMUM_PRIVACY, andCUSTOMprofiles. - Added a pre-connection privacy warning with Cancel and Connect Anyway actions.
- Added configurable client-information normalization for language, view distance, chat visibility, and particles.
- Added an adversarial probe fixture and policy regression tests.
- Added CI dependency reporting, JAR inspection, SHA-256 checksum generation, and checksum release assets.
- Added CurseForge update checks through the public CFWidget metadata API, alongside GitLab, with compatible stable Fabric release selection and independent source failure handling.
- Added regression tests for release metadata, Minecraft-version filtering, and semantic version comparison.
Security
- Removed the redirect-limit raw
Socketside effect; rejected redirect hops are now checked and never opened. - Added AES-GCM encrypted-at-rest storage for session and refresh tokens; exports are redacted and require re-authentication.
- Routed account HTTP requests through the same explicit Minecraft proxy setting as gameplay.
Changed
- Updated the roadmap and release pipeline to describe the GitLab repository and all four supported targets.
- Rewrote the README with official CurseForge and GitLab downloads, current configuration behavior, build/test instructions, and update-check network disclosure.
Fixed
- Prevented older published releases from triggering update notifications or marking the configuration version label as outdated.
2.0.2
Added
- Added explicit filtering for ViaVersion/ViaFabricPlus identity payloads.
- Added resource-pack request identity-header scrubbing.
- Added client-information normalization for common fingerprinting fields.
- Added configurable blocking for server cookies and server transfers.
Fixed
- Corrected repository metadata and documentation links after the GitLab migration.
- Updated the project version metadata to 2.0.2.
2.0.1
Changed
- Migrated the official project repository from GitHub to GitLab.
- Updated NullTrace-owned documentation and repository links to GitLab.
- Added the project logo to the repository assets.
Fixed
- Fixed a version-related issue after the 2.0.0 release.
- Removed the obsolete GitHub build badge from the README.
2.0.0
Added
- Stable NullTrace 2.0.0 release.
- Minecraft 1.21.11 support.
- Minecraft 26.1 support.
- Minecraft 26.2 support.
- Minecraft 26.3 support.
- Multi-version build support using Stonecutter.
- Client-side protections for mod-channel fingerprinting.
- Known-pack filtering.
- Translation/key-resolution protection.
- Resource-pack cache isolation.
- Local/private resource-pack URL protection.
- Server resource-pack control modes.
- Server-pack shader override stripping.
- Configurable chat-signing behavior.
- Minecraft telemetry blocking.
- Account/session management.
- Configurable diagnostics and debug alerts.
- Optional
/nulltracedebug command. - Integrity checking and update/version checking.
- Expanded configuration UI and documentation.
- In-game configuration screenshots.
Changed
- Reworked the project branding under the NullTrace name.
- Expanded README documentation and installation instructions.
- Improved protection configuration and whitelist handling.
- Updated the build toolchain and CI/release automation.
Fixed
- Fixed packet-context and packet-origin handling across Minecraft versions.
- Fixed several channel tracking and fingerprinting edge cases.
- Fixed resource-packet alert thread handling.
- Fixed configuration menu state handling.
- Improved detection alert deduplication.
- Fixed version-range handling for supported Minecraft targets.
Previous Development
- NullTrace originated as a fork of OpSec by aurickk. Earlier development focused on client-side privacy, anti-fingerprinting, resource-pack isolation, network-channel filtering, key-resolution protection, telemetry handling, and related compatibility work. See the Git history for the complete development record.
ChampionsCode
20 version sections · 131 entries · latest Unreleased (unreleased)
CHANGELOG.md on GitLab All releases Repository
Unreleased — in development
Added
- Plug-and-play module folder.
.javafiles belowconfig/champions-mod/modules/are now compiled and registered automatically, so a drop-in module needs no hash confirmation, nojava modules reload, and no console command at all. The folder is scanned at client start and then watched while the game runs: a file that is added, edited, renamed, or deleted reloads or unregisters the group within about two seconds, and reloads never interrupt a module that is mid-run. SetplugAndPlay=falseinconfig/champions-mod/java-runtime.propertiesto restore the previous review-and-confirm workflow, orautoReload=falseto load once at startup without watching. New console commands:java modules folder,java modules auto [on|off|now|watch on|off], and an expandedjava modules status. Changes are reported by source hash, counted injava modules auto, and recorded inaudit.jsonlwithauto=true;java modules unloadstays respected until the files change. - Recursive drop-folder hardening: module sources are recognised at any depth, dot-files and dot-directories (including the generated
.build/folder, editor scratch files such as.Module.java.swp, andModule.java~backups) are ignored everywhere, and a shortREADME.txtexplaining the rules is written into the folder the first time it is created. - Change detection that stays quiet: a metadata fingerprint of the folder is polled once a second, a change is only acted on after a short settled period so a staged file save is one reload, and a folder state that failed to compile is left alone until the files change so compiler errors print once instead of every second.
- Tests for the drop-folder workflow: quiet-period and double-report behaviour, ignoring generated and non-module files, reporting an emptied folder, manual actions surviving a poll, and an end-to-end drop/edit/delete cycle that compiles and discovers a nested module without any registration step.
- Game log window: F6 (
logsin the terminal, or the Java Studio sidebar) opens a live tail of the running game'slogs/latest.logas another workspace window. It follows the end of the log until you scroll away from the bottom, wraps long lines, numbers and colors them by level, and searches as you type: every match is highlighted, Enter/Shift+Enter and the Prev/Next chips walk the matches with a[n/total]counter,Aatoggles case sensitivity,Onlyfilters to matching lines, andLevelcycles an ALL/INFO/WARN/ERROR minimum filter that keeps stack-trace continuation lines visible. Click or drag to select lines; Ctrl+C copies the selection, the matches, or the whole buffer. Reads are incremental and bounded (newest 4 000 lines, one short poll per 400 ms), survive log rotation, and the window keeps its geometry like the others.
0.1.0-beta.3
- Re-release of the 0.1.0-beta.2 changes: the beta.2 tag pipeline built and tested cleanly, but the release job failed to attach its assets (the CLI file upload it used is not permitted for CI job tokens), so the release page shipped empty. This release publishes through the project's generic package registry with release-cli asset links instead, restoring the
downloads/champions-mod-<version>.jarURLs the in-game updater matches. The mod content is identical to 0.1.0-beta.2; see that section below for the full notes.
0.1.0-beta.2
Added
- Windowed workspace: the terminal, ClickGUI, category GUI, and Java Studio are now independent windows of one shared desktop instead of replacing each other. Open several at once, drag each by its title bar, and use the per-window close controls. F7/F8 toggle their window while the workspace is open; ESC or closing the last window closes everything. Navigation buttons ("Terminal", "List GUI", "ClickGUI") open or focus the matching window instead of swapping screens.
- Dropdowns for fixed-choice options: modules declare allowed values (the chat plugin enumerator's MODE is SILENT/AGGRESSIVE), the console's
setvalidates them case-insensitively (storing the canonical spelling), and the ClickGUI renders them as dropdowns instead of free-text fields. - Player dropdown and option-layout fixes in the ClickGUI: dropdowns now stay on screen (clamped horizontally, flipped above the field when the list would run past the bottom), the dropdown's UUID detection matches the option name only (fixing UUIDs being inserted into username fields), option labels and descriptions clip to the label column, and narrow windows switch to a stacked label/description/editor layout.
auxiliary/lookup/player_identityauto-routing: a UUID pasted into USERNAME (or a username into UUID) is detected and resolved instead of failing validation.- F8 terminal
exitcommand (aliases:close,quit) that closes the terminal screen, alongside the existing window close control. - ClickGUI module search box: type to filter the module list by id or name.
- ClickGUI players dropdown for options that take a player identity (name or description mentions player/username/UUID/nickname): lists every player seen during the session, including players who left, with online players highlighted. For UUID options the dropdown inserts the player's dashed UUID. The registry is built passively from the client's own player list and never sends anything.
- ARMED identification box on the main menu showing the ChampionsCode brand, status, and installed version.
- More logging: module registration (builtin and drop-in), console commands (secrets redacted), module run start/finish with duration, authorization denials, and update-check outcomes. Secrets and confirmation phrases are never logged.
docs/writing-your-own-modules.md: a hands-on cookbook for writing your own modules, with a complete worked drop-in example, the builtin-module route, the runtime-Java route, a testing pattern, and the guardrails that always apply.auxiliary/scanner/server_pingmodule: opens one standard server-list status connection to the currently authorized, allowlisted server and reports what any unauthenticated pinger observes without joining (protocol, MOTD, player counts and sample, chat-security flags, mod-platform disclosure). Single target only; no ranges or third-party hosts.auxiliary/lookup/player_identitymodule: resolves one username or UUID against Mojang's public profile API (current name, dashed UUID, skin/cape textures). Contacts only Mojang endpoints, never the connected server.- Startup update checks against the project's public GitLab releases feed with a clickable in-game notice, disableable via
checkOnStart=falseinconfig/champions-mod/update.properties. The check only contactsgitlab.com, never the connected server session, and is skipped in development environments. - F8 console
update checkandupdate download <version>commands. Downloads fetch the latest release JAR into themodsfolder only after verifying its SHA-256 against the release'sSHA256SUMS.txtand never replace a loaded JAR; update checks and downloads are recorded in the local audit log. .gitlab-ci.yml: a GitLab CI pipeline that builds, tests, and verifies the mod onmainand merge requests, and publishes a full GitLab Release (binary JAR, source JAR,SHA256SUMS.txt) with changelog-derived notes when a matchingv<version>tag is pushed.
Changed
- Fixed the terminal input-line offset: the typed text now sits exactly on the
champions@minecraft:~$prompt line (borderless Minecraft 26.3 EditBox renders text at the box top, so the box now starts on the prompt line). - The terminal, ClickGUI, category GUI, and Java Studio no longer dim the world behind them while open. The legal-risk warning popup keeps its dimming to stay unmistakable.
- Clean builds are now bit-for-bit reproducible: the built JAR is repacked once with the order of the
Fabric-Loom-Client-Only-Entriesmanifest attribute sorted; everything else (entry order, timestamps, compression) is preserved. - The sources JAR no longer contains
fabric.mod.json, so loaders ignore it if it is dropped into a mods folder by mistake. - README install and CI sections now point at GitLab Releases and the GitLab CI pipeline, with version-neutral release file names.
- Rewrote
PUBLISHING.mdaround the tag-based GitLab release flow.
Removed
- The committed
release/artifact folder; GitLab Release assets are the single source of published binaries, and a localrelease/folder is now gitignored. - The
.github/workflows/build.ymlGitHub Actions workflow, superseded by the GitLab CI pipeline.
0.1.0-beta.1
Added
- Plug-and-play
exploitandpayloaddrop-in folders undersrc/client/java/com/internationalduck/championscode/module/, with package-level conventions in eachpackage-info.java. ExampleExploitModuleandExamplePayloadModule: fully commented example files in the two folders showing the complete plug-and-play path (module contract, options, findings, registration).ChampionConsole.registerModule(...)hook so client-side drop-in modules can register from theChampionsCliententrypoint, which the coreModuleRegistrycannot reach across the split source sets.docs/exploit-and-payload-files.mddescribing what belongs in each folder, the plug-and-play rules, and how registered files surface in the console and GUIs.- README coverage for the drop-in folders: the two example modules in the module table, a dedicated section on the folders and registration path, and the refreshed Exploits workspace module list.
Changed
- Migrated the official ChampionsCode repository from GitHub to GitLab.
- Updated ChampionsCode-owned repository, release, issue, and clone links to GitLab.
- Retained external project links to their original upstream repositories.
- Added the project branding asset to the repository.
- Moved the rate-limit, boundary-validation, and custom-payload security test modules from
src/main/javainto the new client-sideexploitandpayloadfolders so their client-only imports resolve under the split source sets.
Fixed
- Completed the three security test modules from the previous commit (missing closing braces) and updated them from Yarn names (
MinecraftClient,PlayerMoveC2SPacket,PacketByteBuf) to the project's 26.3 mappings (Minecraft,ServerboundMovePlayerPacket,FriendlyByteBuf), so both source sets compile and the JUnit suite passes.
0.1.0-alpha.16
- Removed the Java and Exploits tabs from the F8 terminal. The warning-gated Exploits filter remains available in the sorted ClickGUI, and exploit modules remain available in the category GUI.
- Added a dedicated F7 ChampionsCode Java Studio with a purple IDE-style layout, workspace file list, multiline source editor, runtime console, command field, lifecycle actions, and persistent movable/resizable geometry.
- Added bounded in-game editing for
.javafiles andchampion-java.jsonbelow the runtime workspace. Ctrl+S and Save file persist changes, emit the new source hash, invalidate stale confirmation naturally, and audit the file name and hash without recording source contents. - Restyled the F8 console as a dark Linux-style terminal with a title bar, shell-like prompt, colored output, history, scrolling, and selectable text.
- Added shared close, maximize/restore, and minimize controls to the terminal, Java Studio, sorted ClickGUI, category panels, and module-settings window. Double-clicking a title bar also toggles maximize.
- Preserved one-based Minecraft 26.3 pointer handling, drag/resize behavior, ClickGUI exploit warnings, exact-target authorization, one-run confirmation, and audit controls.
- Standardized all user-visible product branding on ChampionsCode while retaining stable technical IDs and configuration paths.
0.1.0-alpha.15
- Added an automatic GitHub prerelease job after successful pushes to
main. - The workflow reads and validates the prerelease version from
gradle.properties, creates av<version>tag, and marks the release as a prerelease. - The release uploads the verified binary JAR, source JAR, and SHA-256 manifest.
- Pull requests and manual workflow runs continue to build without publishing.
- Added immutable-tag protection: re-running the same commit is supported, while reusing a version tag for a different commit requires a version bump.
- Correctly treats the GitHub API's
404 Not Foundresponse as an absent tag so the first prerelease can create it. - Limited write permission to the prerelease job; the build job remains read-only.
0.1.0-alpha.14
- Added a dedicated Exploits workspace to the terminal, a ClickGUI Exploits filter, and an
exploitscategory window. - Added a modal legal and operational risk warning when entering an Exploits interface and a fresh mandatory popup before every exploit-research run.
- Added centralized per-run warning acknowledgement, cancellation, selection revalidation, exact-target authorization, and audit events.
- Added
ExploitResearchModuleand a non-executing research workspace module for engagement ID, legal basis, scope, expected impact, and stop conditions. - Fixed dragging throughout the terminal, ClickGUI, category panels, and settings window by using Minecraft 26.3's one-based primary and secondary mouse-button values instead of the older zero-based assumptions.
- Prevented default and restored window sizes from consuming the complete viewport, preserving visible movement space at common GUI scales.
- Added tests for fresh per-run exploit warning acknowledgement and Minecraft 26.3 pointer-button values.
0.1.0-alpha.13
- Retrieved and inventoried the older source archives and loose Java modules, including 108 distinct source-archive module wrapper names across revisions.
- Added Plugin Risk Review, a passive mapping from advertised command roots to non-conclusive defensive hardening profiles.
- Added Declared Dependency Posture for bounded administrator-supplied
name@versioninventory checks without file or network access. - Added defensive Chat Normalization without bypass generation or resend logic.
- Added Chat Game Fairness classification without solving, monitoring live chat, or sending answers.
- Documented duplicate, adapted, and excluded legacy modules, provenance limits, and the clean-room boundary.
- Excluded command abuse, credential theft, chat-filter bypass, automatic game answers, malicious configuration generation, SQLi, SSRF, deserialization, path traversal, griefing, destructive operations, and RCE delivery.
0.1.0-alpha.12
- Added an original multi-window category interface inspired by the general layout concept of classic utility-client module menus.
- Added movable, collapsible, width-resizable Audit, Observe, Replay, Scanner, and Champions control windows with remembered layouts and z-order.
- Added a movable and resizable settings window with direct option editing, authorization arming, module execution, scrolling, and live run status.
- Added the
categoryguicommand withwindowguiandpanelguialiases while keeping the existing sorted-listclickguiinterface. - Added in-GUI navigation between the terminal, list GUI, category GUI, and current-target authorization control.
0.1.0-alpha.11
- Added
authorize currentanddeauthorize currentfor persistent in-game management of the connected exact host. - Added an Authorize current / Remove target toggle and current-target authorization state to the ClickGUI.
- Kept the exact-host authorization gate and one-run confirmation while removing the need to edit or reload the target text file manually.
- Replaced filesystem-path denial output with concise in-game instructions.
0.1.0-alpha.10
- Fixed terminal and ClickGUI title-bar dragging by explicitly maintaining the Minecraft drag state.
- Added bottom-right resize handles and remembered window dimensions to both interfaces.
- Added mouse text selection, selection highlighting, Ctrl+C support, and a Copy button to the terminal output.
- Sorted ClickGUI modules by category and identifier and labeled each row with its category.
- Added persistent ClickGUI idle/running state and visible run-result feedback.
- Shortened non-allowlisted target denials so local filesystem paths are no longer printed in the terminal or ClickGUI.
0.1.0-alpha.9
- Changed the F8 terminal from a full-screen overlay into a movable floating window with a draggable title bar and remembered position.
- Added the
clickguicommand and a movable module browser with module and option lists, direct option editing, confirmation arming, run controls, and terminal navigation. - Replaced the oversized default help dump with a concise quick-start view; full console and runtime Java references remain available through
help consoleandhelp java.
0.1.0-alpha.8
- Replaced ChampionScript and the Volt interpreter with real runtime Java source compilation backed by the standard JDK 25 compiler.
- Added multi-file source sets,
champion-java.json, and theChampionRuntimeAddonstart/stop entrypoint contract. - Added persistent addon lifecycle management with explicit compile, start, reload, stop, diagnostics, client-thread scheduling, and cleanup callbacks.
- Added manual developer-mode opt-in and exact source-set SHA-256 confirmation; any source or manifest change invalidates the confirmation.
- Added deterministic source hashing, manifest validation, compiler tests, an example Java addon, audit events, and detailed unrestricted-code warnings.
- Replaced the Volt GUI tab with a Java developer tab.
0.1.0-alpha.7
- Removed the Unicode em dash character from the current source tree, documentation, UI messages, and packaged release artifacts.
- Replaced the generic CI workflow with an explicit Fabric Minecraft 26.3 build.
- CI now validates the Gradle wrapper, Java 25, configured Minecraft/Fabric versions, tests, packaged Fabric metadata, client mixin presence, and checksums.
- GitHub Actions uploads the binary JAR, source JAR, and SHA-256 manifest for every main-branch push, pull request, and manual workflow run.
- Removed historical binary JARs from the tracked release directory so only the current verified build is published with the source tree.
0.1.0-alpha.6
- Added distinct Console and Volt tabs to the F8 GUI.
- The Volt tab accepts ChampionScript statements directly and supports concise
help,list,show,run, andevalscript-management commands. - Added a complete ChampionScript syntax, runtime-value, and budget reference.
- Preserved the runtime security boundary: no JVM/native injection, reflection, network or packet access, process execution, or game mutation.
- Added GitHub-ready source packaging and release verification.
0.1.0-alpha.5
- Added the payload-free Transaction Echo observer for coarse menu-action to menu-update class correlation and response timing.
- Reviewed AUTISM Client, wakDuper, UI-Utils-Reborn variants, Doujin Dupe, and Dupe-Utils as clean-room research inputs.
- Explicitly excluded packet cancellation, delayed flush queues, fabricated clicks, retained GUIs, reconnect/race automation, and exploit-specific logic.
- Added transaction-flow tests and expanded the clean-room/license record.
0.1.0-alpha.4
- Added the payload-free Wire Lens packet-flow module.
- Added the bounded, non-reinjecting Session Trace metadata timeline.
- Added the read-only Container Integrity synchronization/component audit.
- Added the observe-only Client Resilience burst/error/custom-payload audit.
- Added passive, non-verdict Motion Evidence remote-player telemetry.
- Added a 512-entry packet metadata ring, connection-error counter, inventory snapshots, and remote motion models.
- Added a client
Connectionmixin that records packet class/direction/timing only - never packet bodies. - Added clean-room research notes and telemetry module tests.
0.1.0-alpha.3
- Added
MODE=silent|aggressiveto the chat plugin enumerator (agresivealias accepted). - SILENT now filters default commands and marks non-default candidates without sending anything.
- AGGRESSIVE performs sequential, rate-limited blank/version/v probes only on eligible advertised paths.
- Added live Brigadier-tree revalidation, hazardous/default command filtering, blank-command side-effect protection, and bounded per-probe capture.
- Added version-token extraction and grouped probe transcripts.
- Added command descriptor snapshots and safety-policy/mode tests.
0.1.0-alpha.2
- Adopted the supplied Champions Code logo for the mod icon and branding.
- Added
auxiliary/scanner/chat_plugin_enumerator. - Added a capability-limited active runtime that can send exactly
/pluginsonce. - Added bounded server game-message capture and Bukkit-style plugin-list parsing.
- Added active-run lifecycle, busy-state protection, auditing, documentation, and parser tests.
0.1.0-alpha.1
- Created the Minecraft 26.3 Fabric client project.
- Added the Champions research console and F8 key mapping.
- Added passive fingerprint, connection posture, and plugin-surface modules.
- Added exact-host authorization, one-run confirmation, and JSONL audit logs.
- Added the bounded, read-only ChampionScript runtime and demo script.
- Added unit tests, CI configuration, icon, documentation, and MIT license.
Bagley
1 version sections · 4 entries · latest 1.0.0 (unreleased)
CHANGELOG.md on GitLab All releases Repository
1.0.0
- Extracted the former built-in Bagely module into the standalone Bagley Beacon addon.
- Renamed the module, trigger, public prefix, configuration files, documentation, and source package from Bagely to Bagley.
- Added non-destructive migration for legacy Bagely configuration and conversation-memory files, including the exact old generated system prompt without rewriting custom prompts.
- Requires Beacon 1.9.0 or later for the addon event and settings-action APIs.