Skip to content

2026.10.5 — 2026-10-01 ​

Added ​

  • Pin trusted publisher keys by configuration (6f73c21a)

    Trusted plugin publisher keys can now also be pinned in configuration, for installs that are automated, air-gapped or managed as code:

    artemis-studio.plugins.trusted-keys[0].name: Example Publisher artemis-studio.plugins.trusted-keys[0].pem: <PEM certificate or public key>

    or ARTEMIS_STUDIO_PLUGINS_TRUSTED_KEYS_0_NAME and _0_PEM. Studio makes its trusted keys match the list at every start, before any plugin starts, so a plugin signed by a configured key is trusted on the first boot. Removing a key from the list un-trusts it at the next start, exactly as removing it in the UI does: its plugins keep running, marked unverified. A configured key shows "From configuration" under Administration → Plugins → Trusted keys and cannot be removed there or through the API (409, configured-key). An entry Studio cannot read stops startup with its index and the reason. Every change is audited as PLUGIN_KEY_ADD or PLUGIN_KEY_REMOVE by "configuration".

    ADR-0166 amends ADR-0141.

Fixed ​

  • Read the paged list envelope and seed before the traffic runs (39d4b7bf)

    The demo and capture scripts read GET /clusters, /environments, /roles and /users as bare arrays, so since lists answer with {data, ...} the demo seed stopped before registering its cluster. They now read data, asking for size=500.

    The seed also built the dead-letter backlog, the JSON orders, the users and roles and the stopped node only after the traffic loop, so a long demo (TRAFFIC_MINUTES in the hours) showed none of them until it ended. They now come first, and the traffic runs last.

Security ​

  • Update the plugin template's jackson-databind (283e97a1)

    The plugin template pins Studio's Jackson versions; it now pins 2.21.7 and 3.1.7, which fix GHSA-cxp5-3px4-pw24 and GHSA-wv8q-qhhj-9h54, as Studio does. A plugin started from the template should take the same update.

Apache-2.0. Apache ActiveMQ and Apache ActiveMQ Artemis are trademarks of the Apache Software Foundation. Artemis Studio is an independent project, not produced by, endorsed by, or affiliated with the ASF.