2026.10.5 — 2026-10-01
Added
Pin trusted publisher keys by configuration (6f73c21a)
Trusted plugin publisher keys can now also be pinned in configuration, for installs that are automated, air-gapped or managed as code:
artemis-studio.plugins.trusted-keys[0].name: Example Publisher artemis-studio.plugins.trusted-keys[0].pem: <PEM certificate or public key>
or ARTEMIS_STUDIO_PLUGINS_TRUSTED_KEYS_0_NAME and _0_PEM. Studio makes its trusted keys match the list at every start, before any plugin starts, so a plugin signed by a configured key is trusted on the first boot. Removing a key from the list un-trusts it at the next start, exactly as removing it in the UI does: its plugins keep running, marked unverified. A configured key shows "From configuration" under Administration → Plugins → Trusted keys and cannot be removed there or through the API (409, configured-key). An entry Studio cannot read stops startup with its index and the reason. Every change is audited as PLUGIN_KEY_ADD or PLUGIN_KEY_REMOVE by "configuration".
ADR-0166 amends ADR-0141.
Fixed
Read the paged list envelope and seed before the traffic runs (39d4b7bf)
The demo and capture scripts read GET /clusters, /environments, /roles and /users as bare arrays, so since lists answer with {data, ...} the demo seed stopped before registering its cluster. They now read data, asking for size=500.
The seed also built the dead-letter backlog, the JSON orders, the users and roles and the stopped node only after the traffic loop, so a long demo (TRAFFIC_MINUTES in the hours) showed none of them until it ended. They now come first, and the traffic runs last.
Security
Update the plugin template's jackson-databind (283e97a1)
The plugin template pins Studio's Jackson versions; it now pins 2.21.7 and 3.1.7, which fix GHSA-cxp5-3px4-pw24 and GHSA-wv8q-qhhj-9h54, as Studio does. A plugin started from the template should take the same update.