International DuckIncorporated
Release history

Changelog.

Everything each International Duck project has shipped: 36 version sections and 302 individual entries, transcribed from the CHANGELOG.md each repository maintains, in the order that file lists them, and linked back to the matching GitLab release.

Snapshot taken 2026-10-05 from CHANGELOG.md + GitLab releases API. Where a version has no tagged release the entry says so rather than guessing a date.

Changelog

Beacon

5 version sections · 70 entries · latest 2.0.0-prerelease (unreleased)

2.0.0-prerelease — Module fixes no tagged release yet
  • Confetti on Advancement is an actual celebration now. The burst was ~40 dust particles at scale 0.7-1.3 in a single uniform spread — close to invisible in daylight. It now opens with a centre pop, splits into three bands (fast outward ring, slow drift, and a fountain that arcs and falls), doubles the dust scale to 1.2-2.4, and trails FIREWORK shimmer behind the confetti. Default count 40 → 120, ceiling 200 → 600. Applied to both copies of FireworksFx (src/main/java and the mc26_3 override) so 26.3 does not keep the old effect.
  • StructureNotifier no longer fails silently. Its detection wrapped everything in an empty catch (Exception) {}, so a mapping change or a throwing registry lookup looked identical to "you are not inside a structure". Failures are now logged once per session, and a new Debug Log setting reports how many structure starts each chunk actually carries — which is the real question, since a multiplayer server does not send structure starts to clients at all.
  • The "Redo onboarding" button no longer lies. Its handler called toast() unconditionally after firing the bridge request, so it reported "First-run setup will run again on the next launch" even when Beacon refused the reset. The message is now the request's success notice, which only fires on an ok response; a failure surfaces the bridge's own error instead. Covered by a jsdom regression test that mocks the bridge in both states.
  • Build fix: AFKFisher referenced FishingBobberEntity, which does not exist in these mappings — the class is net.minecraft.world.entity.projectile.FishingHook (see FishingHookAccessor). All four references corrected; the code never compiled as shipped.
  • CompactMessages actually collapses duplicates now. The mixin fetched the module, tested isEnabled() and then had an empty if body, so maxCombo()/counterColor() were never called and enabling the module changed nothing — the only collapsing came from BetterChat's separate anti-spam. CompactMessages owns its duplicate detection now and appends a coloured x N badge, capped by Max Combo. New Scan Depth and Ignore Timestamps settings.
  • BetterTab no longer covers the screen. TabListPlusMixin rewrote every 13, 11 and 9 in PlayerTabOverlay.extractRenderState to 40 to make room for numeric latency — but those literals are row metrics and padding, so the whole tab list inflated several times over. The wide layout is now opt-in via Wide Ping Column (off by default).
  • SoundMuter's mute no longer sticks. Enabling it used to walk the entire sound registry and stop() every matching identifier, killing portal/beacon hums mid-loop that nothing ever restarted — so disabling could not bring them back. Muting is preventive only now: the mixin rejects new matching plays, and disabling takes effect immediately with no state to undo.
  • ItemSearch is reachable. It only accepted @search <item> while every other module answers to @ModuleName ..., so the conventional @ItemSearch wood returned "Unknown setting/subcommand", and its only setting was the toggle keybind. Modules can now handle their own subcommands (Module.onCommand), ItemSearch takes @ItemSearch <item>, and it gains Scope and Show Slots settings.
  • AFK Fisher: the description no longer credits Meteor, the bite pling is gone (with the now-meaningless Bite Alert setting), and a catch is counted once per bobber instead of once per catch path — the "Caught N fish" tally was inflated.
  • "Redo onboarding on next launch" no longer silently drops the wizard. The flags really were being cleared and reloaded; the launch check was the problem. Onboarding.onClientTick set armed = false before attempting to open the page, so if that one open failed the setup was dropped for the whole launch with nothing logged. The retry budget now covers both waits (Chromium downloading, and browser-registered-but-won't-take-the-page), the setup only disarms once the page actually opened, and every branch logs — so the next launch's log says exactly whether the reset was written or the show path failed.
  • Regenerated the module catalogue: it had drifted to 55 modules/232 settings while the Java registry held 56/234 before any of the above.
2.0.0-prerelease — Boot intro polish no tagged release yet
  • Bumped the mod version to 2.0.0-prerelease.
  • The first-run Chromium install now shows a real progress bar (with a percentage) on the loading screen, driven by the download's own byte-level progress instead of an endless spinner.
  • The 3D boot intro now preloads before it plays: the first frames — which compile every shader — are drawn invisibly, so the opening no longer hitches.
  • The screen stays black through the whole handoff from the Chromium install to the boot intro: the loading screen paints an opaque black frame (no blurred menu underneath) and the wizard's first paint is black, so there is no white flash or menu glimpse.
  • The finished 3D beacon now stays on as a live backdrop for the whole onboarding: after the cinematic it settles on the beacon's hero frame and idles in a slow, cheap orbit behind the frosted wizard, and the old flat "transparent logo" welcome card is gone (the PNG only returns as a fallback when WebGL is unavailable).
  • Themes got a real art pass (Spicetify-style): each theme gains a two-colour nebula glow and a soft vignette behind the glass, the theme picker swatches now preview each sky (glows + star specks), and Starry Night reads like a proper indigo night with a purple nebula.
  • The theme/accent chosen in first-run onboarding now forwards to the main app: the client stores them as uiTheme/accent and the app reads them back on launch (and pushes its own changes back over the bridge), so the look no longer snaps back to a default.
  • The top-right Beacon corner logo expands on hover to show the running version, and it now also sits on the main menu even before the first-run setup has been completed.
  • The first-run setup now paints an opaque black backdrop for its whole lifetime, so the blurred menu/panorama no longer shows through in the stretch between the install screen and the 3D intro (the app keeps its transparent, world-showing backdrop).
  • The standalone "BEACON" wordmark over the intro is gone; the welcome reads "Welcome to Beacon" only.
  • Performance pass for the software (SwiftShader) renderer the embedded browser uses: the idle backdrop drops to a lower resolution/24 fps, the cinematic drops MSAA, and the always-on animated atmosphere no longer runs full-screen filter: blur() (the two big glows are unblurred radial gradients; Mist/Aurora particle blurs are much lighter) — smoother intro and faster menu opens.
  • The intro's hidden warm-up now pre-renders a spread of timeline frames instead of just the opening frame, so the shader compile no longer stalls the start and the mid-intro energy merge.
  • The intro's soundtrack now starts with the first visible frame rather than at mount: it used to run a second or so ahead of the picture during the hidden warm-up, and the opening then snapped forward to catch up — the stall-and-jump at the start.
  • Opening the app straight after the first-run setup no longer flashes the wizard's 3D backdrop: one browser serves both pages, so the outgoing page is cleared off the surface before the new one is navigated to.
  • Typing in the app's search no longer rebuilds the menu. Only the module boxes that stop matching are hidden and the ones that start matching again are revealed, so the page stops fading out and re-animating on every keystroke.
  • The ⌘ K hint box is gone from the search bar.
  • The GUI key (K by default) now also opens Beacon from the main menu, not just in-game — module keybinds still win if one of them is bound to the same key.
  • "Redo onboarding on next launch" actually replays the whole first run again. It cleared onboardingSeen but not introSeen, and the page gates the 3D cinematic on the second flag — so the wizard came back with no intro at all, which is what made the button look dead.
  • The wizard's Finish step and its confirmation now both say which key opens Beacon, as a key chip rather than a line of small print. It quotes the key Beacon actually reports (guiKeyLabel), so it stays correct after a rebind, and the confirmation's version is large because that screen closes itself after ~2.5 s.
  • Interface sounds are now real: the app plays subtle click/navigation feedback (opt-in via Settings → Interface sounds), and the first-run wizard uses a fuller sting set (page turns, selection, a completion chime).
  • The mod author is now "International Duck Incorporated", and Settings gains a "Redo onboarding on next launch" button that re-runs the first-run wizard (and 3D intro) on the next boot.
1.9.0 — Bagley addon extraction no tagged release yet
  • Extracted the built-in Bagely module into the standalone Bagley Fabric addon. Beacon no longer ships AI endpoint, memory, screenshot, or Bagley-specific platform code.
  • Added addon-safe incoming/outgoing chat observation events, generic settings-drawer actions, and module configuration aliases.
  • Existing Bagely enabled state, settings, and favourites are read as Bagley when the addon is installed. The addon migrates its private beacon-bagely… files to Bagley names without logging credentials.
  • Added the addon API and player migration guides. The Bagley source tree is published separately for GitLab. All notable changes to Beacon are documented in this file, in the Keep a Changelog format. Per-version notes for older releases (0.2.1 through 1.8.17) remain in releases/ as a historical record; this file is the changelog going forward.
Unreleased — in development no tagged release yet

Added

  • The first-run onboarding intro is now a real 3D cinematic. webui/onboarding.html opens on a fullscreen WebGL scene that renders the Minecraft beacon from assets/models/beacon.glb — the centrepiece, GLBConverted, CC-BY-4.0 by owencroft0, attributed in THIRD_PARTY_NOTICES.txt. Blue energy bands and motes arrive from off-screen, spiral in on a drifting helix, are pulled through the beacon's glass and absorbed at a target measured from the model's own geometry, and then the beacon activates: core emissive, a short flash, a shockwave, UnrealBloom and a Minecraft-style beam, while the camera pushes in for the absorption and opens up for the reveal. The reference clip was used as the audio reference only (it is never rendered): its audio track is the intro's soundtrack, its ~1.1 s of leading silence is skipped, and its measured beats drive the cue table — webui/generate_intro_cues.py re-measures the clip with ffmpeg and writes assets/audio/beacon-intro.cues.json, which webui/intro3d_verify.py cross-checks against the module. The whole cinematic is one pure function of a single visual time (webui/assets/vendor/intro3d-timeline.js) with INTRO_START → … → COMPLETE states, so it is deterministic, seekable, frame-rate independent and tunable in one table. Rendering never waits on audio: if autoplay is refused the scene still initialises, animates and finishes, and the first tap starts the sound without skipping the shot (Esc or the Skip button skips). Every failure — no WebGL, missing module, missing/broken model, failed init, a stall — disposes the scene and hands the screen to the existing onboarding welcome screen, and the intro is never allowed to block onboarding. three.js r180 and the post-processing addons are vendored locally under webui/assets/vendor/ (no CDN), with the rationale in webui/INTRO3D.md and webui/assets/vendor/README.md.
  • First-run onboarding, wired up. webui/onboarding.html is now packaged as assets/beacon/webui/onboarding.html and opens automatically on the first launch once the HTML UI is ready: it shows at the main menu, never over a game in progress, and stays pending if Chromium is unavailable so it is not silently consumed. @onboarding (alias @setup) re-opens it at any time, which is how the page is re-tested without deleting beacon.json. Finishing — or skipping — posts onboarding.complete over the typed bridge and persists the theme, accent, sound toggle, sound volume and favourite modules into beacon.json (uiTheme, accent, soundVolume, onboardingSeen); favourite ids that match no loaded module are dropped instead of being saved as favourites that could never resolve. The same values are exposed to the UI through the bridge snapshot's preferences.
  • Bagley follow-up conversations with an LLM-controlled stop. After a reply, the same requester can continue without repeating Bagley's name for a bounded window (default 45 seconds). The model itself decides when the conversation is over: a new no_response tool call (or the [[bagley_no_reply]] marker on endpoints without function support) sends no public chat and immediately ends the listening session, so chat addressed to other players stops triggering Bagley instead of restarting the timer. A marker returned with surrounding text is now treated as a no-reply instead of publishing the model's commentary, follow-up sessions are hard-capped at five consecutive replies, and decision turns never post the public failure apology.
  • Bagley nearby-entities and Baritone tools. get_nearby_entities shares loaded entities within a requested radius (default 32, max 128 blocks). With Allow Baritone actions (ban risk) enabled, baritone_go_to/baritone_stop let the model navigate via the installed Baritone mod's #goto/#stop commands — advertised only when the mod is actually installed, with the model instructed to navigate only to player-provided coordinates. Both were previously stranded in the Beacon-complete-7700335-… bundle and never reached the compiled source, which is why the AI never used Baritone; they now build from src/ for all Minecraft targets.
  • HUD visibility modules. HideScoreboard now provides independent, default-on controls for the sidebar scoreboard and on-screen chat feed. HidePumpkinOverlay is a separate Render module. Both update their render paths directly without forcing a chunk/world renderer rebuild, and legacy HideOverlays configuration is migrated.

Fixed

  • The 3D onboarding intro could never actually run in a build. Beacon's loopback origin sent connect-src 'none' in its Content-Security-Policy, and three.js downloads beacon.glb with fetch() — which is what that directive governs, not media-src or script-src. Chromium therefore refused the model request before it left the browser, GLTFLoader reported a failure and the cinematic skipped straight to the welcome screen. The development harness never showed it because python -m http.server sends no CSP at all. The policy now allows connect-src 'self' (still nothing off-origin, the page never talks to the Internet), the model and soundtrack are served as model/gltf-binary and audio/mpeg instead of application/octet-stream (every response also carries nosniff), and intro3d_verify.py gained a section that checks the packaged origin instead of only the page.
  • HTML UI console output now reaches the game log. Page-side warnings and errors — including [Beacon] 3D boot intro unavailable (<reason>) and Chromium's own blocked-subresource reports — are forwarded as [Beacon][HTML UI] …, so a page that degrades no longer leaves the log silent about why.
  • The intro's beacon is textured again — it is no longer a bare grey cube. beacon.glb stores its three textures in bufferViews; GLTFLoader turns each one into a blob: URL and downloads it through fetch(). connect-src 'self' does not match blob: URLs even though the page created them, so the texture fetches were refused and the model rendered untextured. The served policy now allows blob: in both connect-src and img-src (blob: URLs inherit the page's origin and can only be created by it, so no new target is reachable). Verified against real Chromium: with the old policy the three texture fetches are CSP-refused and the shot is a plain cube; with the fix they succeed and the textured beacon renders.
  • The boot cinematic (and its audio) no longer replays on every launch. The page kept the "seen" flag only in localStorage, but the loopback origin is a fresh random port and token on every launch, so the store was empty each time. onboarding.intro-seen — which the page already posts but the bridge previously rejected as unknown — now persists a durable introSeen flag in beacon.json, the state snapshot exposes it, and the page asks for the snapshot before deciding whether to play (with a short fallback so a dead bridge cannot strand the player). @onboarding still opens the wizard, but the intro plays only once; #replay (or ?replay=1 when testing standalone) forces it again.
  • Fullbright no longer unloads the visible map. Gamma and Potion modes never touch chunk meshes. Entering, changing, or leaving Luminance mode now marks visible-range sections dirty and lets the normal compiler replace them while their old meshes stay on screen, instead of releasing every render buffer up front.
  • SoundMuter applies immediately. Enabling the module or any mute filter now stops matching sounds that are already playing through the public per-identifier sound-manager API; future matching sounds remain blocked by the play hook. Unrelated effects and music are left running, and rejoining is no longer required.
  • Bagley provider, tool, passive-listener, follow-up, retry, failure reply, memory, nickname, and complete-answer controls. Bagley now has Click GUI controls for provider profile, provider-appropriate reasoning effort, observation tools (tab list, nearby entities, and one current-game screenshot), an explicit ban-risk Baritone-navigation opt-in, client-only tool/loading notices, an opt-in five-second passive-listener decision window, natural same-requester follow-up questions with no-reply decisions, retries, the initial retry-delay seconds (default exponential waits: 5, 10, then 20 seconds), public exhausted-retry replies, busy notices, response token budget, reply detail, response audience, bounded local conversation memory, and protected long-term notes. The default disabled reasoning setting sends reasoning_effort: none to Ollama/OpenAI-compatible endpoints, fixing Qwen3 responses that otherwise contain only hidden thinking and no final message.content; OpenRouter instead receives its own excluded structured reasoning object. Tool screenshots are downscaled, attached only to the configured endpoint for a mention-triggered tool call, visibly announced only to the client, deleted locally immediately, and cleanly fall back if a non-vision endpoint returns HTTP 400. Passive windows never enter Bagley memory. Bagley now repairs missing/invalid config schema fields and backs up malformed JSON before recreating a usable local config. OpenRouter-style length-limited output is retried instead of being posted mid-sentence. Its private configuration also supports case-insensitive nickname triggers (including Bags by default). Memory and durable notes are stored separately in beacon-bagley-memory.json, and all maintained Minecraft overlays provide the failure toast.
  • Minecraft 26.3 input target by default. A plain Gradle build now selects the 26.3 overlay, including its SDL keyboard and mouse translation, instead of building a 26.2 jar whose GLFW-style input codes make the Click GUI appear unresponsive on 26.3. Older versions remain available through -Pmc=<version>.
  • The build never worked. The committed scaffold could not even configure: it used the pre-26.1 remapping plugin (fabric-loom 1.16.2, a combination that does not exist for the new plugin id) with modImplementation configurations that no longer exist. Now: net.fabricmc.fabric-loom 1.17-SNAPSHOT + plain implementation, per the canonical 26.2 template. ./gradlew build is green for the first time in the repository's history.
  • Chat autocomplete cast every suggestion String to java.lang.invoke.CallSite — compiled fine, ClassCastException the moment the @ menu opened.
  • @search set the ItemSearch query without lowercasing it (unlike the module's own chat path), so uppercase queries silently matched nothing.
  • FreecamCoreTest's epsilon was always-red against the shipped float-radian math; BeaconConfigTest still called a stale EnabledModules.unknown signature and could not compile against the current tree.

Removed

  • The Click GUI HTML prototype (docs/beacon-ui.html) and its two dedicated checkers — a second implementation of the GUI that only existed to be kept in sync. See docs/CLICK-GUI-HTML-REMOVAL.md.
  • The @theme command: it tried to set a BeaconUI.currentTheme field that has never existed on the Java GUI and could only ever fail. Runtime theming does not exist (the palette is compile-time constants); when it does, the command can return with a real implementation behind it.
  • The stale deal autocomplete candidate left over from the AH Deal Sniper removal.

Changed

  • Prepared Beacon for multi-version Fabric builds from Minecraft 1.21.11 through 26.3: target matrix, per-target build directories, metadata/resource smoke checks, and compile-ready release artifacts.
  • De-decompiled (~1,200 lines of CFR artifacts removed): banners, redundant casts, void x = … eaten declarations, labeled blocks, swallowed mixin (Object) bridges, eaten string literals (logger names, texture identifiers, button labels), and a dozen genericity repairs.
  • Zero runtime reflection (~850 lines removed): EnderChestCapture (which reflected its own jar), ItemDraw, ReconnectFx, BookTools extraction, UiText, TabListFx and the pasteToBook/copyHeldBook/query field probes are all typed now, javap-verified against the 26.2 jar.
  • Chat branding centralised in net.beacon.utils.BeaconText (one prefix util instead of five ad-hoc §-literal shapes per module).
  • ModuleManager lookups are O(1) (concurrent class/name indexes; the ordered list stays the source of truth, with a subclass-safe fallback).
  • EventBus.subscribe takes an optional priority: higher runs first, equal priorities keep registration order.
  • CI on every push (hygiene gate → target metadata smoke checks → compile-ready tests/build) and automated tag releases with checksums.

Added

  • Bagley — an opt-in, OpenAI Chat Completions-compatible assistant that replies in public chat when someone says Bagley. It sends only the triggering message and keeps endpoint credentials in the separate, non-shareable config/beacon-bagley.json; see the standalone Bagley repository.
  • Setting.visibleIf(guard, test) — settings can declare they only make sense while another setting's value passes a predicate; the GUI honours it in render, hit-testing and height.
  • Config share codes: @config export / @config import <code> — the whole beacon.json as one pasteable string (gzip + URL-safe base64).
  • Keybind-conflict detection: conflicts are announced at config load and listed by @binds, because the losing module in a key clash just silently never fires.
  • @bug — a clickable link to a GitLab issue form prefilled from the Bug.md template (versions, OS, reproduce/expect skeleton).
  • JUnit 5 test suite (41 tests) wired into ./gradlew test, replacing the two hand-run javac harnesses; tools/verify/check_hygiene.py gates the de-decompile/de-reflect invariants in CI.
1.8.17 — and earlier no tagged release yet
  • See releases/ — one file per version, kept as a historical record.
Changelog

Venomous

5 version sections · 40 entries · latest Unreleased (unreleased)

Unreleased — in development no tagged release yet
  • Continued development and maintenance following the migration from GitHub to GitLab.
  • Improved project documentation and clarified the project's work-in-progress status.
7.0.0 · no tagged release yet

Added

  • Added a Gradle-based Fabric build system with the Gradle wrapper.
  • Added automated build and release workflows for stable and nightly builds.
  • Added a comprehensive test suite covering:
    • Addon metadata
    • Compatibility helpers
    • Mixin configuration
    • Module registry integrity
    • Module structure
    • Scavenged module logic
    • Server analysis
    • Anti-vanish behaviour
    • Anti-cheat bypass logic
    • Movement mathematics
    • Placement regressions
    • Build scripts
  • Added new rendering, HUD, screen, portal, and movement mixins.
  • Added movement debugging and supporting movement mathematics utilities.
  • Added MovementMath, PreRotate, and other utility improvements.
  • Added a GPL-3.0-or-later license and included it in built JAR files.

Changed

  • Recovered and migrated the addon from decompiled output into a maintainable Java source tree.
  • Cleaned the recovered source tree and moved resources into the standard Fabric layout.
  • Updated the project for Minecraft 26.2, Meteor Client 26.2, and Java 25.
  • Renamed modules where necessary to avoid collisions with Meteor Client module names.
  • Added the v- prefix to modules that conflict with Meteor's global module registry.
  • Refined module registration and reorganized modules across combat, detection, ESP, exploit, fun, miscellaneous, movement, player, render, utility, and world categories.
  • Improved combat, movement, automation, rendering, networking, and anti-cheat-related modules across the codebase.
  • Added lifecycle cleanup and state-reset handling to multiple modules.
  • Improved Aimbot, KillAura, Speed, Fly, Disabler, and related modules.
  • Improved packet, rotation, portal, and placement handling.
  • Updated README documentation with compatibility, installation, build, licensing, and issue-reporting information.

Fixed

  • Fixed recovered Java source compilation errors across several modules.
  • Fixed runtime issues in combat, movement, detection, exploit, utility, and rendering modules.
  • Fixed module-name collisions that could replace Meteor Client modules.
  • Fixed several module registration and structure issues.
  • Fixed workflow and build configuration issues.
  • Fixed executable permissions for gradlew.
  • Fixed compatibility and mixin configuration problems.
6.2.6 · no tagged release yet

Added

  • Added decompiled Java source for the recovered Venomous addon.
  • Added the initial Gradle and Fabric project structure.
  • Added module implementations covering combat, detection, ESP, exploits, fun, miscellaneous utilities, movement, rendering, and world interaction.
  • Added Venomous resources, including the icon, splashes, metadata, and mixin configuration.

Changed

  • Cleaned the recovered source tree and converted it into a conventional source layout.
  • Added an initial automated build workflow.
  • Started migrating the project from a distributed JAR into a source-based development project.

Fixed

  • Fixed initial compilation errors in the recovered source.
  • Fixed formatting issues in the original README.
6.1.6 · no tagged release yet

Added

  • Added the first recovered Venomous JAR contents, including:
    • Fabric metadata
    • Mixins
    • Venomous addon entrypoint
    • Combat modules
    • Detection modules
    • ESP modules
    • Exploit modules
    • Fun modules
    • Miscellaneous modules
    • Movement modules
    • Utility modules
    • World modules
    • Assets and splashes
  • Added the initial README.
0.1.0 · no tagged release yet

Added

  • Created the Venomous project.
  • Added the initial project README and project documentation. [Unreleased]: https://gitlab.com/international-duck-incorporated/Venomous/-/compare/v7.0.0...main [7.0.0]: https://gitlab.com/international-duck-incorporated/Venomous/-/releases/v7.0.0 [6.2.6]: https://gitlab.com/international-duck-incorporated/Venomous/-/releases/v6.2.6 [6.1.6]: https://gitlab.com/international-duck-incorporated/Venomous/-/releases/v6.1.6 [0.1.0]: https://gitlab.com/international-duck-incorporated/Venomous/-/commits/main
Changelog

NullTrace

5 version sections · 57 entries · latest Unreleased (unreleased)

Unreleased — in development no tagged release yet

Added

  • Added the central ConnectionContext / PrivacyPolicy / AuditLedger model with explainable ALLOW, BLOCK, WARN, and LOG decisions.
  • Added /nulltrace audit and per-server STANDARD, STRICT, MAXIMUM_PRIVACY, and CUSTOM profiles.
  • Added a pre-connection privacy warning with Cancel and Connect Anyway actions.
  • Added configurable client-information normalization for language, view distance, chat visibility, and particles.
  • Added an adversarial probe fixture and policy regression tests.
  • Added CI dependency reporting, JAR inspection, SHA-256 checksum generation, and checksum release assets.
  • Added CurseForge update checks through the public CFWidget metadata API, alongside GitLab, with compatible stable Fabric release selection and independent source failure handling.
  • Added regression tests for release metadata, Minecraft-version filtering, and semantic version comparison.

Security

  • Removed the redirect-limit raw Socket side effect; rejected redirect hops are now checked and never opened.
  • Added AES-GCM encrypted-at-rest storage for session and refresh tokens; exports are redacted and require re-authentication.
  • Routed account HTTP requests through the same explicit Minecraft proxy setting as gameplay.

Changed

  • Updated the roadmap and release pipeline to describe the GitLab repository and all four supported targets.
  • Rewrote the README with official CurseForge and GitLab downloads, current configuration behavior, build/test instructions, and update-check network disclosure.

Fixed

  • Prevented older published releases from triggering update notifications or marking the configuration version label as outdated.
2.0.2 · no tagged release yet

Added

  • Added explicit filtering for ViaVersion/ViaFabricPlus identity payloads.
  • Added resource-pack request identity-header scrubbing.
  • Added client-information normalization for common fingerprinting fields.
  • Added configurable blocking for server cookies and server transfers.

Fixed

  • Corrected repository metadata and documentation links after the GitLab migration.
  • Updated the project version metadata to 2.0.2.
2.0.1 · no tagged release yet

Changed

  • Migrated the official project repository from GitHub to GitLab.
  • Updated NullTrace-owned documentation and repository links to GitLab.
  • Added the project logo to the repository assets.

Fixed

  • Fixed a version-related issue after the 2.0.0 release.
  • Removed the obsolete GitHub build badge from the README.
2.0.0 · release v2.0.0 · 4 artifacts

Added

  • Stable NullTrace 2.0.0 release.
  • Minecraft 1.21.11 support.
  • Minecraft 26.1 support.
  • Minecraft 26.2 support.
  • Minecraft 26.3 support.
  • Multi-version build support using Stonecutter.
  • Client-side protections for mod-channel fingerprinting.
  • Known-pack filtering.
  • Translation/key-resolution protection.
  • Resource-pack cache isolation.
  • Local/private resource-pack URL protection.
  • Server resource-pack control modes.
  • Server-pack shader override stripping.
  • Configurable chat-signing behavior.
  • Minecraft telemetry blocking.
  • Account/session management.
  • Configurable diagnostics and debug alerts.
  • Optional /nulltrace debug command.
  • Integrity checking and update/version checking.
  • Expanded configuration UI and documentation.
  • In-game configuration screenshots.

Changed

  • Reworked the project branding under the NullTrace name.
  • Expanded README documentation and installation instructions.
  • Improved protection configuration and whitelist handling.
  • Updated the build toolchain and CI/release automation.

Fixed

  • Fixed packet-context and packet-origin handling across Minecraft versions.
  • Fixed several channel tracking and fingerprinting edge cases.
  • Fixed resource-packet alert thread handling.
  • Fixed configuration menu state handling.
  • Improved detection alert deduplication.
  • Fixed version-range handling for supported Minecraft targets.
Previous Development no tagged release yet
  • NullTrace originated as a fork of OpSec by aurickk. Earlier development focused on client-side privacy, anti-fingerprinting, resource-pack isolation, network-channel filtering, key-resolution protection, telemetry handling, and related compatibility work. See the Git history for the complete development record.
Changelog

ChampionsCode

20 version sections · 131 entries · latest Unreleased (unreleased)

Unreleased — in development no tagged release yet

Added

  • Plug-and-play module folder. .java files below config/champions-mod/modules/ are now compiled and registered automatically, so a drop-in module needs no hash confirmation, no java modules reload, and no console command at all. The folder is scanned at client start and then watched while the game runs: a file that is added, edited, renamed, or deleted reloads or unregisters the group within about two seconds, and reloads never interrupt a module that is mid-run. Set plugAndPlay=false in config/champions-mod/java-runtime.properties to restore the previous review-and-confirm workflow, or autoReload=false to load once at startup without watching. New console commands: java modules folder, java modules auto [on|off|now|watch on|off], and an expanded java modules status. Changes are reported by source hash, counted in java modules auto, and recorded in audit.jsonl with auto=true; java modules unload stays respected until the files change.
  • Recursive drop-folder hardening: module sources are recognised at any depth, dot-files and dot-directories (including the generated .build/ folder, editor scratch files such as .Module.java.swp, and Module.java~ backups) are ignored everywhere, and a short README.txt explaining the rules is written into the folder the first time it is created.
  • Change detection that stays quiet: a metadata fingerprint of the folder is polled once a second, a change is only acted on after a short settled period so a staged file save is one reload, and a folder state that failed to compile is left alone until the files change so compiler errors print once instead of every second.
  • Tests for the drop-folder workflow: quiet-period and double-report behaviour, ignoring generated and non-module files, reporting an emptied folder, manual actions surviving a poll, and an end-to-end drop/edit/delete cycle that compiles and discovers a nested module without any registration step.
  • Game log window: F6 (logs in the terminal, or the Java Studio sidebar) opens a live tail of the running game's logs/latest.log as another workspace window. It follows the end of the log until you scroll away from the bottom, wraps long lines, numbers and colors them by level, and searches as you type: every match is highlighted, Enter/Shift+Enter and the Prev/Next chips walk the matches with a [n/total] counter, Aa toggles case sensitivity, Only filters to matching lines, and Level cycles an ALL/INFO/WARN/ERROR minimum filter that keeps stack-trace continuation lines visible. Click or drag to select lines; Ctrl+C copies the selection, the matches, or the whole buffer. Reads are incremental and bounded (newest 4 000 lines, one short poll per 400 ms), survive log rotation, and the window keeps its geometry like the others.
0.1.0-beta.3 · release v0.1.0-beta.3 · 3 artifacts
  • Re-release of the 0.1.0-beta.2 changes: the beta.2 tag pipeline built and tested cleanly, but the release job failed to attach its assets (the CLI file upload it used is not permitted for CI job tokens), so the release page shipped empty. This release publishes through the project's generic package registry with release-cli asset links instead, restoring the downloads/champions-mod-<version>.jar URLs the in-game updater matches. The mod content is identical to 0.1.0-beta.2; see that section below for the full notes.
0.1.0-beta.2 · no tagged release yet

Added

  • Windowed workspace: the terminal, ClickGUI, category GUI, and Java Studio are now independent windows of one shared desktop instead of replacing each other. Open several at once, drag each by its title bar, and use the per-window close controls. F7/F8 toggle their window while the workspace is open; ESC or closing the last window closes everything. Navigation buttons ("Terminal", "List GUI", "ClickGUI") open or focus the matching window instead of swapping screens.
  • Dropdowns for fixed-choice options: modules declare allowed values (the chat plugin enumerator's MODE is SILENT/AGGRESSIVE), the console's set validates them case-insensitively (storing the canonical spelling), and the ClickGUI renders them as dropdowns instead of free-text fields.
  • Player dropdown and option-layout fixes in the ClickGUI: dropdowns now stay on screen (clamped horizontally, flipped above the field when the list would run past the bottom), the dropdown's UUID detection matches the option name only (fixing UUIDs being inserted into username fields), option labels and descriptions clip to the label column, and narrow windows switch to a stacked label/description/editor layout.
  • auxiliary/lookup/player_identity auto-routing: a UUID pasted into USERNAME (or a username into UUID) is detected and resolved instead of failing validation.
  • F8 terminal exit command (aliases: close, quit) that closes the terminal screen, alongside the existing window close control.
  • ClickGUI module search box: type to filter the module list by id or name.
  • ClickGUI players dropdown for options that take a player identity (name or description mentions player/username/UUID/nickname): lists every player seen during the session, including players who left, with online players highlighted. For UUID options the dropdown inserts the player's dashed UUID. The registry is built passively from the client's own player list and never sends anything.
  • ARMED identification box on the main menu showing the ChampionsCode brand, status, and installed version.
  • More logging: module registration (builtin and drop-in), console commands (secrets redacted), module run start/finish with duration, authorization denials, and update-check outcomes. Secrets and confirmation phrases are never logged.
  • docs/writing-your-own-modules.md: a hands-on cookbook for writing your own modules, with a complete worked drop-in example, the builtin-module route, the runtime-Java route, a testing pattern, and the guardrails that always apply.
  • auxiliary/scanner/server_ping module: opens one standard server-list status connection to the currently authorized, allowlisted server and reports what any unauthenticated pinger observes without joining (protocol, MOTD, player counts and sample, chat-security flags, mod-platform disclosure). Single target only; no ranges or third-party hosts.
  • auxiliary/lookup/player_identity module: resolves one username or UUID against Mojang's public profile API (current name, dashed UUID, skin/cape textures). Contacts only Mojang endpoints, never the connected server.
  • Startup update checks against the project's public GitLab releases feed with a clickable in-game notice, disableable via checkOnStart=false in config/champions-mod/update.properties. The check only contacts gitlab.com, never the connected server session, and is skipped in development environments.
  • F8 console update check and update download <version> commands. Downloads fetch the latest release JAR into the mods folder only after verifying its SHA-256 against the release's SHA256SUMS.txt and never replace a loaded JAR; update checks and downloads are recorded in the local audit log.
  • .gitlab-ci.yml: a GitLab CI pipeline that builds, tests, and verifies the mod on main and merge requests, and publishes a full GitLab Release (binary JAR, source JAR, SHA256SUMS.txt) with changelog-derived notes when a matching v<version> tag is pushed.

Changed

  • Fixed the terminal input-line offset: the typed text now sits exactly on the champions@minecraft:~$ prompt line (borderless Minecraft 26.3 EditBox renders text at the box top, so the box now starts on the prompt line).
  • The terminal, ClickGUI, category GUI, and Java Studio no longer dim the world behind them while open. The legal-risk warning popup keeps its dimming to stay unmistakable.
  • Clean builds are now bit-for-bit reproducible: the built JAR is repacked once with the order of the Fabric-Loom-Client-Only-Entries manifest attribute sorted; everything else (entry order, timestamps, compression) is preserved.
  • The sources JAR no longer contains fabric.mod.json, so loaders ignore it if it is dropped into a mods folder by mistake.
  • README install and CI sections now point at GitLab Releases and the GitLab CI pipeline, with version-neutral release file names.
  • Rewrote PUBLISHING.md around the tag-based GitLab release flow.

Removed

  • The committed release/ artifact folder; GitLab Release assets are the single source of published binaries, and a local release/ folder is now gitignored.
  • The .github/workflows/build.yml GitHub Actions workflow, superseded by the GitLab CI pipeline.
0.1.0-beta.1 · release v0.1.0-beta.1 · 3 artifacts

Added

  • Plug-and-play exploit and payload drop-in folders under src/client/java/com/internationalduck/championscode/module/, with package-level conventions in each package-info.java.
  • ExampleExploitModule and ExamplePayloadModule: fully commented example files in the two folders showing the complete plug-and-play path (module contract, options, findings, registration).
  • ChampionConsole.registerModule(...) hook so client-side drop-in modules can register from the ChampionsClient entrypoint, which the core ModuleRegistry cannot reach across the split source sets.
  • docs/exploit-and-payload-files.md describing what belongs in each folder, the plug-and-play rules, and how registered files surface in the console and GUIs.
  • README coverage for the drop-in folders: the two example modules in the module table, a dedicated section on the folders and registration path, and the refreshed Exploits workspace module list.

Changed

  • Migrated the official ChampionsCode repository from GitHub to GitLab.
  • Updated ChampionsCode-owned repository, release, issue, and clone links to GitLab.
  • Retained external project links to their original upstream repositories.
  • Added the project branding asset to the repository.
  • Moved the rate-limit, boundary-validation, and custom-payload security test modules from src/main/java into the new client-side exploit and payload folders so their client-only imports resolve under the split source sets.

Fixed

  • Completed the three security test modules from the previous commit (missing closing braces) and updated them from Yarn names (MinecraftClient, PlayerMoveC2SPacket, PacketByteBuf) to the project's 26.3 mappings (Minecraft, ServerboundMovePlayerPacket, FriendlyByteBuf), so both source sets compile and the JUnit suite passes.
0.1.0-alpha.16 · no tagged release yet
  • Removed the Java and Exploits tabs from the F8 terminal. The warning-gated Exploits filter remains available in the sorted ClickGUI, and exploit modules remain available in the category GUI.
  • Added a dedicated F7 ChampionsCode Java Studio with a purple IDE-style layout, workspace file list, multiline source editor, runtime console, command field, lifecycle actions, and persistent movable/resizable geometry.
  • Added bounded in-game editing for .java files and champion-java.json below the runtime workspace. Ctrl+S and Save file persist changes, emit the new source hash, invalidate stale confirmation naturally, and audit the file name and hash without recording source contents.
  • Restyled the F8 console as a dark Linux-style terminal with a title bar, shell-like prompt, colored output, history, scrolling, and selectable text.
  • Added shared close, maximize/restore, and minimize controls to the terminal, Java Studio, sorted ClickGUI, category panels, and module-settings window. Double-clicking a title bar also toggles maximize.
  • Preserved one-based Minecraft 26.3 pointer handling, drag/resize behavior, ClickGUI exploit warnings, exact-target authorization, one-run confirmation, and audit controls.
  • Standardized all user-visible product branding on ChampionsCode while retaining stable technical IDs and configuration paths.
0.1.0-alpha.15 · no tagged release yet
  • Added an automatic GitHub prerelease job after successful pushes to main.
  • The workflow reads and validates the prerelease version from gradle.properties, creates a v<version> tag, and marks the release as a prerelease.
  • The release uploads the verified binary JAR, source JAR, and SHA-256 manifest.
  • Pull requests and manual workflow runs continue to build without publishing.
  • Added immutable-tag protection: re-running the same commit is supported, while reusing a version tag for a different commit requires a version bump.
  • Correctly treats the GitHub API's 404 Not Found response as an absent tag so the first prerelease can create it.
  • Limited write permission to the prerelease job; the build job remains read-only.
0.1.0-alpha.14 · no tagged release yet
  • Added a dedicated Exploits workspace to the terminal, a ClickGUI Exploits filter, and an exploits category window.
  • Added a modal legal and operational risk warning when entering an Exploits interface and a fresh mandatory popup before every exploit-research run.
  • Added centralized per-run warning acknowledgement, cancellation, selection revalidation, exact-target authorization, and audit events.
  • Added ExploitResearchModule and a non-executing research workspace module for engagement ID, legal basis, scope, expected impact, and stop conditions.
  • Fixed dragging throughout the terminal, ClickGUI, category panels, and settings window by using Minecraft 26.3's one-based primary and secondary mouse-button values instead of the older zero-based assumptions.
  • Prevented default and restored window sizes from consuming the complete viewport, preserving visible movement space at common GUI scales.
  • Added tests for fresh per-run exploit warning acknowledgement and Minecraft 26.3 pointer-button values.
0.1.0-alpha.13 · no tagged release yet
  • Retrieved and inventoried the older source archives and loose Java modules, including 108 distinct source-archive module wrapper names across revisions.
  • Added Plugin Risk Review, a passive mapping from advertised command roots to non-conclusive defensive hardening profiles.
  • Added Declared Dependency Posture for bounded administrator-supplied name@version inventory checks without file or network access.
  • Added defensive Chat Normalization without bypass generation or resend logic.
  • Added Chat Game Fairness classification without solving, monitoring live chat, or sending answers.
  • Documented duplicate, adapted, and excluded legacy modules, provenance limits, and the clean-room boundary.
  • Excluded command abuse, credential theft, chat-filter bypass, automatic game answers, malicious configuration generation, SQLi, SSRF, deserialization, path traversal, griefing, destructive operations, and RCE delivery.
0.1.0-alpha.12 · no tagged release yet
  • Added an original multi-window category interface inspired by the general layout concept of classic utility-client module menus.
  • Added movable, collapsible, width-resizable Audit, Observe, Replay, Scanner, and Champions control windows with remembered layouts and z-order.
  • Added a movable and resizable settings window with direct option editing, authorization arming, module execution, scrolling, and live run status.
  • Added the categorygui command with windowgui and panelgui aliases while keeping the existing sorted-list clickgui interface.
  • Added in-GUI navigation between the terminal, list GUI, category GUI, and current-target authorization control.
0.1.0-alpha.11 · no tagged release yet
  • Added authorize current and deauthorize current for persistent in-game management of the connected exact host.
  • Added an Authorize current / Remove target toggle and current-target authorization state to the ClickGUI.
  • Kept the exact-host authorization gate and one-run confirmation while removing the need to edit or reload the target text file manually.
  • Replaced filesystem-path denial output with concise in-game instructions.
0.1.0-alpha.10 · no tagged release yet
  • Fixed terminal and ClickGUI title-bar dragging by explicitly maintaining the Minecraft drag state.
  • Added bottom-right resize handles and remembered window dimensions to both interfaces.
  • Added mouse text selection, selection highlighting, Ctrl+C support, and a Copy button to the terminal output.
  • Sorted ClickGUI modules by category and identifier and labeled each row with its category.
  • Added persistent ClickGUI idle/running state and visible run-result feedback.
  • Shortened non-allowlisted target denials so local filesystem paths are no longer printed in the terminal or ClickGUI.
0.1.0-alpha.9 · no tagged release yet
  • Changed the F8 terminal from a full-screen overlay into a movable floating window with a draggable title bar and remembered position.
  • Added the clickgui command and a movable module browser with module and option lists, direct option editing, confirmation arming, run controls, and terminal navigation.
  • Replaced the oversized default help dump with a concise quick-start view; full console and runtime Java references remain available through help console and help java.
0.1.0-alpha.8 · no tagged release yet
  • Replaced ChampionScript and the Volt interpreter with real runtime Java source compilation backed by the standard JDK 25 compiler.
  • Added multi-file source sets, champion-java.json, and the ChampionRuntimeAddon start/stop entrypoint contract.
  • Added persistent addon lifecycle management with explicit compile, start, reload, stop, diagnostics, client-thread scheduling, and cleanup callbacks.
  • Added manual developer-mode opt-in and exact source-set SHA-256 confirmation; any source or manifest change invalidates the confirmation.
  • Added deterministic source hashing, manifest validation, compiler tests, an example Java addon, audit events, and detailed unrestricted-code warnings.
  • Replaced the Volt GUI tab with a Java developer tab.
0.1.0-alpha.7 · no tagged release yet
  • Removed the Unicode em dash character from the current source tree, documentation, UI messages, and packaged release artifacts.
  • Replaced the generic CI workflow with an explicit Fabric Minecraft 26.3 build.
  • CI now validates the Gradle wrapper, Java 25, configured Minecraft/Fabric versions, tests, packaged Fabric metadata, client mixin presence, and checksums.
  • GitHub Actions uploads the binary JAR, source JAR, and SHA-256 manifest for every main-branch push, pull request, and manual workflow run.
  • Removed historical binary JARs from the tracked release directory so only the current verified build is published with the source tree.
0.1.0-alpha.6 · no tagged release yet
  • Added distinct Console and Volt tabs to the F8 GUI.
  • The Volt tab accepts ChampionScript statements directly and supports concise help, list, show, run, and eval script-management commands.
  • Added a complete ChampionScript syntax, runtime-value, and budget reference.
  • Preserved the runtime security boundary: no JVM/native injection, reflection, network or packet access, process execution, or game mutation.
  • Added GitHub-ready source packaging and release verification.
0.1.0-alpha.5 · no tagged release yet
  • Added the payload-free Transaction Echo observer for coarse menu-action to menu-update class correlation and response timing.
  • Reviewed AUTISM Client, wakDuper, UI-Utils-Reborn variants, Doujin Dupe, and Dupe-Utils as clean-room research inputs.
  • Explicitly excluded packet cancellation, delayed flush queues, fabricated clicks, retained GUIs, reconnect/race automation, and exploit-specific logic.
  • Added transaction-flow tests and expanded the clean-room/license record.
0.1.0-alpha.4 · no tagged release yet
  • Added the payload-free Wire Lens packet-flow module.
  • Added the bounded, non-reinjecting Session Trace metadata timeline.
  • Added the read-only Container Integrity synchronization/component audit.
  • Added the observe-only Client Resilience burst/error/custom-payload audit.
  • Added passive, non-verdict Motion Evidence remote-player telemetry.
  • Added a 512-entry packet metadata ring, connection-error counter, inventory snapshots, and remote motion models.
  • Added a client Connection mixin that records packet class/direction/timing only - never packet bodies.
  • Added clean-room research notes and telemetry module tests.
0.1.0-alpha.3 · no tagged release yet
  • Added MODE=silent|aggressive to the chat plugin enumerator (agresive alias accepted).
  • SILENT now filters default commands and marks non-default candidates without sending anything.
  • AGGRESSIVE performs sequential, rate-limited blank/version/v probes only on eligible advertised paths.
  • Added live Brigadier-tree revalidation, hazardous/default command filtering, blank-command side-effect protection, and bounded per-probe capture.
  • Added version-token extraction and grouped probe transcripts.
  • Added command descriptor snapshots and safety-policy/mode tests.
0.1.0-alpha.2 · no tagged release yet
  • Adopted the supplied Champions Code logo for the mod icon and branding.
  • Added auxiliary/scanner/chat_plugin_enumerator.
  • Added a capability-limited active runtime that can send exactly /plugins once.
  • Added bounded server game-message capture and Bukkit-style plugin-list parsing.
  • Added active-run lifecycle, busy-state protection, auditing, documentation, and parser tests.
0.1.0-alpha.1 · no tagged release yet
  • Created the Minecraft 26.3 Fabric client project.
  • Added the Champions research console and F8 key mapping.
  • Added passive fingerprint, connection posture, and plugin-surface modules.
  • Added exact-host authorization, one-run confirmation, and JSONL audit logs.
  • Added the bounded, read-only ChampionScript runtime and demo script.
  • Added unit tests, CI configuration, icon, documentation, and MIT license.
Changelog

Bagley

1 version sections · 4 entries · latest 1.0.0 (unreleased)

1.0.0 no tagged release yet
  • Extracted the former built-in Bagely module into the standalone Bagley Beacon addon.
  • Renamed the module, trigger, public prefix, configuration files, documentation, and source package from Bagely to Bagley.
  • Added non-destructive migration for legacy Bagely configuration and conversation-memory files, including the exact old generated system prompt without rewriting custom prompts.
  • Requires Beacon 1.9.0 or later for the addon event and settings-action APIs.