electerm/electerm
38.2
Weak · 1 October 2026
88.5k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a cross-platform terminal emulator and remote connection client built on Electron, supporting SSH, SFTP, RDP, VNC, Spice, Telnet, and local shell access. It features a modernized architecture with Vite-based builds, a comprehensive widget framework for running local servers and utilities, and deep integration with AI models for chat, agent-based terminal control, and UI generation. The application provides robust session management through customizable layouts, workspaces, and batch operations, while ensuring security via strict IPC handling, certificate trust, and input validation.
How it got here
2017 — Client-side architecture modernization
23 changes.
This period focused on a comprehensive overhaul of the client-side architecture, migrating from legacy class-based components and Ant Design to a modern React 18 setup with custom high-performance UI elements. The work involved removing obsolete server-side Koa controllers, build tooling, and static assets while introducing new features like AI toggles, SFTP enhancements, and terminal shell integration. Concurrently, the codebase was refactored to use CSS variables for theming and Web Workers for WebSocket management, significantly improving responsiveness and maintainability.
2018–2023 — UI overhaul and platform expansion
24 changes.
This period focused on a comprehensive redesign of the client-side interface, introducing a modernized tabs bar, sidebar, and settings panel with mobile responsiveness and drag-and-drop capabilities. The project significantly expanded its platform support by migrating the build system to Vite and adding native packages for multiple Linux architectures, while also enhancing security through secure IPC and centralized configuration validation.
2024–2026 — Client UI overhaul and protocol expansion
32 changes.
This period focused on a comprehensive rewrite of the client-side interface, introducing a config-driven architecture for bookmarks, a new profile management system, and extensive layout and theme customization options. It significantly expanded supported protocols by adding native clients for RDP, VNC, and Spice, while integrating AI agent capabilities and a built-in widget framework for server-side utilities.
Features
Add Spice protocol support with scaled viewport and mouse fix
Users can now connect to remote desktops using the Spice protocol. This change introduces a new session component that dynamically loads the spice-client library, supports a 'scale viewport' mode to fit the remote display within the browser window while maintaining aspect ratio, and includes a fix to ensure mouse coordinates are correctly mapped when the view is scaled.
src/client/components/spice · high confidence
Add VNC remote session support
Users can now connect to VNC servers via a new VNC session component. This includes a dynamic form for credentials, a session view with clipboard sync, screen selection, and fit-mode controls, along with styling for the viewport and scrollbars.
src/client/components/vnc · high confidence
Add configurable SSH server monitor bar
Users can now enable a persistent monitor bar at the bottom of the SSH session view to track real-time server health. The bar displays configurable metrics including CPU usage (with sparkline history), memory consumption, network upload/download rates, uptime, active users, and disk usage. Clicking a metric opens a detailed popover with sortable process activity tables, allowing users to view and kill processes. The feature is controlled via the \remoteMonitorBarEnabled\ configuration and the \remoteMonitorBarItems\ setting to toggle individual metrics on or off.
src/client/components/remote-monitor · high confidence
Add terminal content triggers
Users can now define and manage terminal content triggers to automate responses based on session output. This change introduces a new UI for creating, editing, and toggling triggers, including support for text/regex matching, configurable actions (such as sending text or notifications), and preset rules. Triggers can be managed globally in the settings panel or applied temporarily to the current session via a dedicated modal, with import/export capabilities for configuration backup.
src/client/components/triggers · high confidence
Electron build configuration and macOS notarization support
The build system now includes a new electron-builder configuration that registers deep-link protocols for SSH, Telnet, RDP, VNC, Serial, Spice, and Electerm, and associates .vv (virt-viewer) files with the application. Additionally, macOS builds are configured for hardened runtime with notarization enabled, supported by a new entitlements file allowing JIT execution and dyld environment variables, while a sample environment file is provided for local test setup.
build · high confidence
Expanded Linux build support for ARM, LoongArch, RISC-V, and PowerPC architectures
The build system now produces native packages for several additional Linux architectures, including ARM64/ARMv7l (with legacy support for older distributions), LoongArch64 (both modern and legacy/old-world ABI), RISC-V 64-bit, and PowerPC 64-bit little-endian. New build scripts handle cross-compiling native modules (such as node-pty and serialport) for these platforms, download the corresponding Electron runtimes, and merge them with the application bundle. Additionally, AppImage builds now automatically install the necessary .desktop file and icon into the user's local applications directory on first run, ensuring the application appears correctly in desktop environments like UOS/Deepin.
build/bin · high confidence
Introduce MCP server with Streamable HTTP transport and Tasks extension support
Added a new Model Context Protocol (MCP) server implementation in \src/app/mcp\ that uses a custom Streamable HTTP transport. This change enables support for long-running tool calls via the \io.modelcontextprotocol/tasks\ extension (SEP-2663), allowing clients to poll for task status and cancel operations. The server now handles protocol version negotiation, manages session IDs via HTTP headers, and includes a dedicated \TaskManager\ for lifecycle management (working, completed, failed, cancelled) with automatic cleanup of expired tasks.
src/app/mcp · high confidence
Introduce address bookmarks and MCP security hardening
The store now supports a new 'address bookmarks' feature, allowing users to save and manage address-based entries separately from standard bookmarks. Additionally, the MCP (Model Context Protocol) handler has been updated to strip dangerous and internal tab properties from tool calls, preventing potential security issues where external agents could inject arbitrary commands or crash the UI by manipulating internal state.
src/client/store · high confidence
Introduce batch operation widget for executing multi-step workflows
A new batch operation widget has been added to the client, allowing users to define and execute multi-step workflows via a JSON editor. The widget supports actions such as SSH connection, command execution, and SFTP upload/download, with built-in logging to track step progress and errors. Users can load a default template, edit the workflow in a simple editor, or use an external system editor, and then execute the sequence with a single click.
src/client/components/batch-op · high confidence
Introduce configurable keyboard shortcuts with a dedicated editor UI
The application now provides a built-in interface for managing keyboard shortcuts, replacing the previous hardcoded configuration. A new shortcuts settings page displays all available actions in a table, allowing users to view, edit, and reset shortcuts via an inline editor that validates inputs and detects conflicts. This change also standardizes shortcut handling across the application, including specific support for SFTP file operations, terminal selection replacement, and AI chat submission, while ensuring correct behavior for IME composition and cross-platform key mappings.
src/client/components/shortcuts · high confidence
Introduce dedicated Web Session component with address bar, zoom, and basic auth
Added a new WebSession component (src/client/components/web) that renders web content via an iframe (in web-app mode) or a native webview, featuring a new AddressBar for URL display and reloading, zoom controls, and a WebAuthModal to handle HTTP basic authentication requests. The component supports custom user agents, allows opening the URL in the default browser, and validates URL formats before rendering.
src/client/components/web · high confidence
Introduce global AI feature toggle and tab title customization
Users can now disable all AI-related UI elements globally by setting \window.et.disableAIFeature = true\, which hides AI buttons, icons, and settings menus. Additionally, a new 'Show only title in tab' setting allows sessions with custom titles to display solely that title in the tab bar, rather than the default host/user fallback, improving tab readability for named sessions.
src/client/common · high confidence
Introduce widget management UI with instance control and logging
Added a new set of React components in src/client/components/widgets that provide a user interface for discovering, configuring, and managing widgets. Users can now browse available widgets, submit configuration forms (supporting various input types like strings, numbers, and booleans), and start instances. The UI includes a tabbed view to switch between available widgets and running instances, allowing users to view instance details, inspect logs, stop instances, and toggle auto-run settings. A custom notification component is used to display operation results and server connection details.
src/client/components/widgets · high confidence
Introduces AI Agent mode with terminal and bookmark management tools
The AI chat now supports an 'Agent' mode that allows the AI to directly interact with the terminal environment. This change adds a suite of agent tools (defined in \agent-tools.js\) enabling the AI to send commands, read terminal output, manage tabs (open, switch, close), and manage bookmarks (list, open, add). The \agent.js\ module implements the agent loop, handling tool execution, auto-compression of context to prevent window overflow, and streaming responses. A new \AgentToolCallCard\ component (\agent-tool-call-card.jsx\) provides a visual interface for users to see the AI's tool calls, arguments, and results in the chat history. Additionally, text file attachments are now supported in AI chats, with size limits and binary file rejection logic implemented in \ai-attachments.js\.
src/client/components/ai · high confidence
New RDP client implementation with file transfer and clipboard support
The RDP session component has been rewritten to use the IronRDP engine, introducing a new client solution that supports file transfer (upload/download) via the CLIPRDR channel, clipboard sharing, and interactive credential prompts for sessions requiring authentication. The implementation includes a dedicated file transfer manager, a keyboard code-scanning utility, and UI components for managing custom resolutions and connection states.
src/client/components/rdp · high confidence
New batch input and command history panels in the footer
The footer now includes a batch input module that lets users type a command and send it to multiple selected terminal tabs at once, with a tab-selection popover for choosing targets. A new command history panel is available in the footer (as a popover) or docked in the right side panel, supporting search, sorting by frequency, and per-command actions (run, copy, delete, add to quick commands, or run in multiple terminals). A multi-tab run modal reuses the same tab-selection logic to execute a chosen command across selected terminals. These changes are implemented in the footer components (batch-input, cmd-history, tab-select, multi-tab-run-modal, and their styles).
src/client/components/footer · high confidence
New built-in widget framework and server instances
Electerm now includes a built-in widget system that allows running persistent server instances and utility tools directly within the application. This release introduces several new widgets: an MCP Server for exposing Electerm APIs to AI assistants, a Local FTP Server, a Static File Server, an SSH Server for testing connections, a Batch Operation widget for multi-step workflows, a File Renamer, and a Local File Server. The framework also provides per-instance logging and lifecycle management, ensuring that widget logs persist to disk for debugging even after the application restarts.
src/app/widgets · high confidence
New custom external editor support and improved search in text editor
The text editor now supports opening files in a custom external editor via a configurable command, with an optional auto-open feature that automatically launches the external editor when a file is edited. The built-in search functionality has been rewritten to correctly highlight matches as the user types, navigate between occurrences, and copy all content, resolving previous issues where search could cause crashes or lose focus.
src/client/components/text-editor · high confidence
New icons for terminal search, split layouts, and AI features
The client now includes dedicated UI icons to support new terminal and interface capabilities. Terminal search options are represented by icons for case sensitivity, whole-word matching, and regular expressions. Split-view functionality is supported by a set of layout icons (single, two/three columns/rows, 2x2 grid, and specific split orientations) and a general split-view toggle icon. Additionally, new icons have been added for AI-related features and a heartbeat/keep-alive status indicator.
src/client/components/icons · high confidence
New profile management UI with multi-protocol support
The application introduces a dedicated profile management interface, allowing users to create and manage connection profiles for SSH, Telnet, VNC, RDP, and FTP. This new UI includes a profile list for navigation, a form for editing profile details (such as name and default status), and protocol-specific tabs for configuring connection parameters like usernames and passwords. The implementation leverages the Ant Design framework for form handling and tab navigation, providing a structured way to organize connection settings separate from bookmarks.
src/client/components/profile · high confidence
New right-side panel component with resize, pin, and tab support
A new right-side panel component has been added to the client UI, providing a resizable and pin-able overlay for displaying contextual information. Users can now toggle the panel's visibility, pin it to dock along the right edge (excluding mobile views), and drag its left edge to adjust its width between 400px and 1000px. The panel supports multiple content tabs—AI, command history, quick commands, and info—indicated by specific icons and titles in the header. It includes keyboard support for closing via the Escape key (while preserving terminal functionality) and uses CSS variables for theming.
src/client/components/side-panel-r · high confidence
New terminal info panel with local system details and configurable logging
The terminal info panel now displays local system information (OS, hostname, kernel, architecture, and shell version) for local terminals, while continuing to show remote monitor details for remote connections. Users can configure terminal logging via a new per-terminal log path editor, toggle terminal log saving, and enable timestamps for log entries. The panel also supports filtering which information items are displayed.
src/client/components/terminal-info · high confidence
New terminal shell integration, command suggestions, and shortcut bar
The terminal now supports shell integration via OSC 633 escape sequences, enabling reliable command tracking, history, and tab completion. This powers a new command suggestion feature that displays suggestions in a dedicated UI component, including password masking for sensitive inputs. Additionally, a new shortcut bar has been introduced for touch devices, providing a customizable set of keyboard shortcuts (Ctrl, Alt, Shift, Meta combinations) to facilitate terminal interaction without a physical keyboard. The changes also include an OSC 52 addon for TUI clipboard support and a drop-file modal for selecting transfer protocols (trz/rz/XMODEM).
src/client/components/terminal · high confidence
New theme management UI with AI generation and color picker
The theme settings interface has been rebuilt to support three editing modes: a text editor, a visual color picker, and an AI-powered generator. Users can now create themes by describing them in natural language, which triggers an AI model to generate a complete color palette. The theme list includes a preview feature that allows users to hover over or click an icon to see the theme applied temporarily before deciding to apply it permanently. Additionally, the editor now uses a color picker component for easier visual adjustments and includes validation to ensure all required color properties are present and correctly formatted.
src/client/components/theme · high confidence
New users receive platform-aware default terminal bookmarks and quick commands
The application now seeds the database with sensible defaults for new installs, including local terminal bookmarks and quick commands tailored to the user's operating system. On Windows, it detects and includes bookmarks for cmd.exe, PowerShell, PowerShell 7, WSL, and Git Bash if they are present on the machine. On macOS and Linux, it detects available POSIX shells (such as zsh, bash, and fish) and creates corresponding bookmarks. Additionally, platform-specific quick commands are provided (e.g., \ls\ and \df\ on Unix, \Get-ChildItem\ on Windows) to help users quickly access common system information. This ensures that new users have immediate access to functional terminal shortcuts without manual configuration.
src/app/upgrade · high confidence
Quick commands: AI generation, drag-and-drop reordering, and export/import
The quick commands feature has been significantly enhanced with several new capabilities. Users can now generate quick commands using AI by describing their needs in natural language, with the system parsing the response into a usable command definition. The quick command list and sub-commands now support drag-and-drop reordering, allowing users to customize the order of commands and steps. Additionally, quick commands can be exported and imported via JSON files, facilitating backup and sharing. The quick command panel also supports being pinned to the right side panel, and users can duplicate existing commands with a single click.
src/client/components/quick-commands · high confidence
Redesigned settings panel with mobile drill-down and new management features
The settings interface has been restructured to support a two-column layout on desktop and a mobile-friendly drill-down view (triggered at 800px) with a breadcrumb navigation. This update introduces dedicated management sections for terminal keyword highlighting (with import/export), deep link protocol registration, global hotkey configuration, and password grouping. It also adds a customizable left sidebar icon selector and improves the bookmark tree with drag-and-drop reordering and a new list component for history and bookmarks.
src/client/components/setting-panel · high confidence
Redesigned tabs bar with new add button menu, layout/workspace controls, and window management
The tabs bar UI has been rebuilt to include a new Add button menu (add-btn-menu) that consolidates creating new SSH sessions, AI-generated bookmarks, and quick connections, alongside tabs for browsing bookmarks and history. A new Layout menu (layout-menu) and workspace controls (workspace-select, workspace-save-modal) allow users to switch between split layouts (single, two columns, grid, etc.) and manage workspaces directly from the tabs bar. Window control buttons (window-control) for minimize, maximize, and close are now rendered within the tabs bar (unless using the system title bar or on macOS), and app dragging is handled by a dedicated AppDrag component that supports double-click to maximize. The tab list itself (index, tab, tab-title) now supports drag-and-drop reordering with visual indicators, auto-scrolling, and pinning, while the no-session state (no-session) provides a centralized entry point for new sessions and history.
src/client/components/tabs · high confidence
Rewritten bookmark form with AI generation and config-driven architecture
The bookmark form has been completely rewritten to use a config-driven architecture (form-renderer, bookmark-schema) that supports a wider range of connection types including SSH, Telnet, Serial, VNC, RDP, FTP, Web, Local, and Spice. A new AI-powered generation workflow allows users to create bookmarks from natural language descriptions, with the AI response validated and fixed against the schema before creation. The form now includes a 'Save and Create New' button, a modal to create bookmarks from history items, and a tree-select component with search for batch operations. UI improvements include a flashing animation on the save button when edits are unsaved, mobile-friendly stacking for login scripts, and persistent AI description input in local storage.
src/client/components/bookmark-form · high confidence
SFTP file manager receives a comprehensive UI and feature overhaul
The SFTP file manager has been significantly updated with a new address bar that includes a keyword filter, hidden file visibility toggle, and drag-and-drop sortable bookmarks. A new file comparison feature allows users to view side-by-side metadata and code diffs for two selected files. The file list rendering now uses a virtual list for improved performance with large directories, and the UI supports displaying owner, group, and file extension information. Additionally, the address bar now supports uploading files directly from the browser in web app mode.
src/client/components/sftp · high confidence
Server process now trusts OS-installed CA certificates
The server process now automatically trusts the operating system's root certificate store for HTTPS connections (such as WebDAV sync and upgrade downloads). This is achieved by loading system CAs into a temporary file and passing it to the child process via the NODE\_EXTRA\_CA\_CERTS environment variable, ensuring secure connections work correctly without requiring manual certificate configuration.
src/app/server · high confidence
Support for multiple LLM API formats and enhanced crash diagnostics
The application now supports connecting to OpenAI Responses and Anthropic Messages APIs in addition to the standard OpenAI Chat Completions format, normalizing responses for consistent use. On startup, the app now includes a crash reporter that detects GPU process failures and provides actionable suggestions (such as disabling GPU or sandbox) via the command line or environment variables. Additionally, the app now supports deep links for protocols like ssh://, telnet://, and vnc://, allowing users to open connections directly from external links.
src/app/lib · high confidence
Support for multiple terminal layout configurations
The application now supports multiple terminal layout configurations, allowing users to arrange their terminal sessions in various grid patterns such as single pane, two or three columns/rows, and 2x2 grids. This change introduces a new layout algorithm and associated UI components that calculate and render session sizes and positions based on the selected layout. Users can now drag and drop tabs between different layout panes and batches, enhancing workflow flexibility. The layout system also accounts for other UI elements like sidebars, footers, and quick command bars to ensure proper spacing and visibility.
src/client/components/layout · high confidence
Support importing SSH configurations as bookmarks
Users can now import existing SSH configurations into the application's bookmark system. This change introduces a new modal interface that displays detected SSH config items, allowing users to review, edit, or delete individual entries before importing them. A notification prompts users to import their SSH configs when visiting the bookmarks tab, with options to load the configs or ignore the prompt. The implementation includes components for displaying and editing SSH config items, handling the import logic, and managing the user interaction flow.
src/client/components/ssh-config · high confidence
Terminal automation: auto-response triggers for common prompts
The terminal now supports automated responses to specific output patterns. This change introduces a trigger engine that monitors the terminal stream and can automatically send text (such as 'yes' for SSH host keys or space for pagers) or send notifications when predefined or custom rules match. It includes built-in presets for common scenarios like Cisco pagers, sudo prompts, and SSH connection confirmations, along with utilities for handling ANSI codes and control characters to ensure reliable matching.
src/client/components/terminal/automation · high confidence
Removals
Removal of legacy Electron main process and embedded server
The application's main entry point (\app.js\), configuration modules (\config.default.js\, \config.sample.js\), logging utility (\log.js\), and embedded Express/WS server (\server.js\) have been removed. This eliminates the previous architecture where the Electron main process directly managed the browser window, handled global state, and ran a local server for terminal emulation and static assets.
app · high confidence
Removal of legacy Koa-based server initialization
The legacy server initialization logic located in \src/server/init\ has been removed. This includes the deletion of \app-init.js\, which previously configured the Koa application with middleware for static file serving, compression, etagging, body parsing, and Pug templating, as well as \common-middleware.js\ which handled context local variables, and the entry point \index.js\. This change eliminates the old server setup code from the codebase.
src/server/init · high confidence
Removal of legacy Pug view templates and static asset includes
The legacy Pug-based view structure has been removed, including the main index template and its partials (head1, head2, footer-js, footer-end). This eliminates the previous mechanism for injecting global JavaScript variables, loading external CDNs for libraries like React, Ant Design, and xterm, and rendering the basic HTML shell, indicating a shift away from this server-side rendered view approach.
views · high confidence
Removal of legacy SSH form component
The legacy SSH form component located at src/client/components/ssh-form/index.jsx has been removed from the codebase. This deletion eliminates the previous implementation that handled SSH connection details (host, username, password, port, title) using Ant Design form fields and managed submission logic for saving and connecting.
src/client/components/ssh-form · high confidence
Removal of legacy build and distribution scripts
The repository has removed several scripts from the \bin/\ directory that were previously used for the build and distribution pipeline. Specifically, \dist.js\ (which handled packaging for Windows, Linux, and macOS using electron-packager), \generate-version.js\ (which wrote version strings to a file), \icon.js\ (which generated system icons), and \www\ (the server entry point) have been deleted. This indicates a shift away from the previous manual build and packaging workflow.
bin · high confidence
Removal of legacy control panel components
The legacy control panel implementation located in \src/client/components/control\ has been removed. This deletion eliminates the previous UI structure, including the \Btns\ toolbar, \Tabs\ for terminal management, \Modal\ for settings/bookmarks, and \List\ components for history and bookmark selection, along with their associated styles. Users will no longer interact with this specific component hierarchy, which has been replaced by the application's current control interface.
src/client/components/control · high confidence
Removal of legacy server utility modules
The \log.js\ and \ua.js\ utility modules in \src/server/utils\ have been removed. This eliminates the custom logging functions (debug, log, err, warn) that previously relied on chalk and lodash, as well as the user-agent parsing middleware that attached browser and device information to the request context. Users will no longer have access to these specific server-side utilities for logging or user-agent detection.
src/server/utils · high confidence
Removal of legacy settings component
The placeholder settings component at src/client/components/setting/index.jsx has been removed. This file previously rendered a static 'settings' div and is no longer part of the application codebase.
src/client/components/setting · high confidence
Removed obsolete Ant Design icon font loader
The custom webpack loader that previously patched Ant Design icon font paths (eot, woff, ttf, svg) to include a git revision query parameter has been removed. This simplifies the build process by eliminating the manual versioning logic for static font assets.
src/client/loaders · high confidence
Removed obsolete SVG icon font
The \app/static/fonts/iconfont.svg\ file has been removed from the application. This eliminates a legacy, manually generated SVG font file (created by FontForge in 2017) that previously provided a set of icon glyphs, reducing the static asset footprint.
app/static · high confidence
Removed server configuration module
The server configuration module at src/server/config/index.js has been removed. This file previously handled loading the default configuration, injecting a timestamped version string derived from package.json, and exporting the frozen configuration object. Its removal simplifies the dev server code structure.
src/server/config · high confidence
Security
Introduce secure preload script for IPC communication
A new preload script has been added to establish a secure bridge between the main process and the renderer using Electron's contextBridge. This script exposes a specific set of APIs to the global window object, including methods for managing zoom levels, opening file dialogs, and invoking synchronous or asynchronous IPC commands. It also provides handlers for sending MCP widget responses and managing webview authentication requests, replacing the previous remote module usage to enhance security.
src/app/preload · high confidence
Architecture
Removal of legacy build tooling and configuration files
The project has removed its legacy build and configuration infrastructure, specifically deleting .babelrc, .eslintrc, config.default.js, electron-builder.json, gulpfile.js, and webpack.config.js. This cleanup eliminates the old Babel/ESLint/Gulp/Webpack setup and associated default configurations, signaling a migration to a different build system or toolchain. The .gitignore file has also been updated to reflect modern Node.js project standards.
(repo-wide) · high confidence
Terminal component logic refactored into modular mixins
The terminal component's implementation has been restructured from a single large file into a set of modular mixins (e.g., \term-attach\, \term-context-menu\, \term-touch\, \term-suggestions\). This change improves code maintainability and enables specific features such as touch-optimized text selection, command suggestions, and granular configuration handling without altering the user-facing terminal capabilities.
src/client/components/terminal/mixins · high confidence
Behavioural changes
Bookmark form components rewritten for config-driven architecture
The bookmark form components in the common directory have been completely rewritten to support a config-driven form system. This introduces new shared UI components including a custom color picker with hex input, category selection with automatic color inheritance, connection hopping with drag-and-drop reordering, SSH tunnel forms with dynamic address display, and exec settings for local bookmarks. The refactoring also adds AI category selection, SSH agent configuration with custom path support, and various field renderers for profiles, proxies, quick commands, and serial paths.
src/client/components/bookmark-form/common · high confidence
Bookmark form configuration is rewritten to use a declarative, shared-field architecture
The bookmark form's configuration logic has been refactored from a monolithic structure into a modular, declarative system. A new \common-fields.js\ module centralizes shared input definitions (such as host, port, encoding, and terminal settings) to reduce duplication and ensure consistency across all connection types. Individual protocol configurations (SSH, FTP, RDP, VNC, Telnet, Serial, Local, Web, and Spice) are now defined as separate, lightweight config objects that compose these common fields and define their specific tabs and validation rules. This change improves maintainability and ensures that updates to common fields automatically propagate to all supported connection types.
src/client/components/bookmark-form/config · high confidence
CSS includes refactored to use CSS variables and remove unused styles
The CSS includes directory has been restructured to support a new theming system. A new \theme.styl\ file introduces CSS custom properties (variables) for colors and contrast, replacing the previous hardcoded color constants defined in \constants.styl\. Several legacy utility files (\animate.styl\, \color.styl\, \width.styl\) have been removed, and \box.styl\ has been updated to remove redundant border utilities, change overflow behavior from \scroll\ to \auto\, and add new cursor and transform utilities. The main \index.styl\ entry point has been updated to reflect these structural changes.
src/client/css/includes · high confidence
Centralized configuration, validation, and security hardening in common module
The src/app/common directory has been restructured to consolidate application settings, data validation, and security controls. Default settings are now defined in config-default.js and default-setting.js, establishing baseline behaviors for the terminal, UI, and sync features. Bookmark data integrity is enforced via new Zod schemas in bookmark-zod-schemas.js, covering SSH, Telnet, Serial, and Local connection types. To address security vulnerabilities, a centralized denylist in dangerous-session-fields.js prevents untrusted inputs (such as deep links or CLI arguments) from injecting dangerous session fields like exec commands or environment variables, a guard actively applied in the new parse-quick-connect.js module. Additionally, file transfer safety is improved with a new sanitize-filename.js module that enforces cross-platform filename rules, and logging is optimized in log.js to suppress verbose IPC noise in production builds.
src/app/common · high confidence
Enhanced sync controls with auto-sync, data selection, and server status comparison
The sync settings page now includes an auto-sync feature that automatically uploads or downloads settings at configurable intervals (from on-change to 24 hours), with a toggle and direction selector in the data transport section. Users can also select specific data types to sync via a new checkbox list. The server data status display has been improved to show the last sync time, source device name, and Electerm version, and includes a new 'Compare' button that reveals a diff view highlighting local vs. remote counts for bookmarks, profiles, and other data types to guide upload or download decisions.
src/client/components/setting-sync · high confidence
Fail loudly on application startup errors
The application now displays an error dialog and exits immediately if the startup process fails, rather than silently crashing with an unhandled promise rejection. This ensures that issues such as failed module requirements, unreadable configuration files, or bad platform integrations are clearly reported to the user for diagnosis.
src/app · high confidence
Introduce loading screen and mobile-optimized branding styles
The application now displays a dedicated loading screen featuring the Electerm logo and a morphing shape animation while resources initialize, replacing the previous behavior where the app started with a transparent background. Additionally, the CSS for the logo background has been updated to scale down on narrow panes, ensuring the watermark displays correctly on mobile devices without being cropped.
src/client/views · high confidence
Major UI architecture overhaul with new error handling and fullscreen support
The main application shell has been completely rewritten to use a modern React functional component with centralized state management, replacing the legacy class-based tab and wrapper system. This change introduces a dedicated error boundary component that provides users with OS-specific troubleshooting commands and direct links to bug reports when the app crashes. It also adds a connection-hopping warning notification for legacy configurations and implements a new CSS-driven fullscreen mode for terminals that correctly manages footer and sidebar visibility. Additionally, a new UI theme system is introduced that dynamically applies CSS variables to the root element, and the upgrade panel has been updated to support multiple download mirrors.
src/client/components/main · high confidence
Migrate build system to Vite and add browser file transfer support
The build configuration has been migrated to Vite, introducing a new development server and build pipeline that includes a custom plugin to disable web-app mode and a stub for Node's diagnostics\_channel to resolve compatibility issues with xterm addons in the browser. Additionally, the new dev server exposes /api/download and /api/upload endpoints, enabling users to download files and directories or upload files directly from the browser interface.
build/vite · high confidence
Migrate to React 18 and Web Worker for WebSocket management
The client entry point has been updated to use React 18's concurrent rendering via \createRoot\, replacing the legacy \render\ method. Additionally, WebSocket connections are now offloaded to a dedicated Web Worker to improve performance and stability, with the main thread loading the worker and the React app at startup.
src/client/entry · high confidence
Mobile UI overhaul and CSS refactoring
The application now features a dedicated mobile layout for screens under 600px, implemented via a new \mobile.styl\ file that adjusts side panels to full-screen drawers, fixes footer positioning relative to the virtual keyboard, and adapts tabs, modals, and form controls for touch interaction. The legacy \index.styl\ global styles have been removed and replaced with CSS variable-driven theming in \basic.styl\, which also introduces visual indicators for drag-and-drop reordering and adjusts scrollbar widths.
src/client/css · high confidence
New bookmark tree list with virtualization, drag-and-drop, and sorting
The bookmark sidebar now uses a new tree-list component that renders bookmarks and groups in a virtualized list for improved performance with large datasets. Users can drag and drop bookmarks and groups to reorder or move them between folders, with visual indicators for drop positions. The list supports keyboard navigation (arrow keys and Enter) when searching, and allows sorting bookmarks by title or host. A new toolbar provides quick access to create, edit, import, and export bookmarks, while a move-item modal enables precise folder transfers. The search bar is static at the top, and category colors are preserved and editable.
src/client/components/tree-list · high confidence
New database migration system with NeDB to SQLite upgrade path
The application now includes a comprehensive database migration framework located in src/app/migrate. This system manages versioned upgrade scripts (v1.3.0 through v1.34.59) that automatically transform legacy data structures—such as consolidating proxy settings, normalizing SSH tunnels and run scripts, and fixing terminal theme defaults—into the current format. Crucially, it introduces a migration path from the legacy NeDB storage to the new Node.js native SQLite database (v2.0.0), ensuring that existing bookmarks, configurations, and terminal themes are preserved and transferred during the upgrade process.
src/app/migrate · high confidence
New password-based login screen with drag area support
The application now presents a dedicated login interface requiring a password when authentication is enabled. This new UI features a custom password input component that supports submission via the Enter key or a click on the arrow icon, along with visual loading states during the authentication check. The layout includes a draggable area at the top for window management and integrates the application logo, ensuring a consistent look and feel for the initial access point.
src/client/components/auth · high confidence
New terminal background options and CSS security hardening
The background component now supports text-based and random mosaic patterns as terminal backgrounds, in addition to images. It also enforces a security rule by stripping @import directives from custom CSS to prevent unauthorized external style injection.
src/client/components/bg · high confidence
Redesigned session control bar and session wrapper with mobile support
The session control bar (session-control.jsx) has been rewritten to provide a unified toolbar for terminal and SFTP panes, featuring pane switching tabs, split-view toggling, keepalive indicators, broadcast input controls, and wrap toggles. A new mobile layout displays pane tabs prominently while hiding other controls behind a menu icon, with a popover for additional actions. The session wrapper (session.jsx) now manages split-view state, drag-and-drop tab reordering, and lazy-loads remote session types (RDP, VNC, Web, Spice). The sessions container (sessions.jsx) handles tab lifecycle operations (reload, delete, edit) and ensures robust rendering by falling back to default sizes for invalid batch data.
src/client/components/session · high confidence
Removal of legacy Koa controller and route definitions
The dedicated controller file (src/server/controllers/index.js) and the corresponding route registration file (src/server/routes/index.js) have been removed. This eliminates the previous implementation that used Koa Router to handle the root path ('/') by invoking a controller to render the 'index' view, aligning with the project's shift to using Webpack for HTML output from Pug templates.
src/server/controllers, src/server/routes · high confidence
Replaces Ant Design UI components with custom, high-performance implementations
The application now uses a suite of custom-built UI components (Modal, Drawer, Notification, Message, Input, etc.) in place of the previous Ant Design equivalents. This change improves interface responsiveness and reduces rendering overhead by eliminating heavy animation and layout calculations. Users will experience faster interactions in settings, modals, and notifications, along with enhanced features such as context menus for text inputs, improved IME support, and visual indicators for password fields.
src/client/components/common · high confidence
Rewritten file transfer system with improved performance and security
The file transfer component has been completely rewritten to improve performance, security, and user experience. Folder transfers are now streamed, significantly speeding up transfers of directories with many small files. A new remote-to-remote transfer handler allows dragging files between different SFTP sessions via a temporary local file. Transfer conflict resolution now supports pre-defined policies and batch actions (skip all, replace all). Security has been enhanced by sanitizing filenames and preventing unsafe path resolution during remote-to-remote transfers. The transfer queue now processes operations sequentially with better state management, and the UI includes improved progress indicators and speed formatting.
src/client/components/file-transfer · high confidence
Rewritten system menu with new sub-menus and layout controls
The system menu component has been completely rewritten to provide a more structured and interactive user interface. This change introduces dedicated sub-menus for Bookmarks, History, and active Tabs, allowing users to quickly navigate their connections. A new Layout submenu has been added, enabling users to change the terminal layout (e.g., single, two columns, grid) directly from the menu. Additionally, the Zoom control is now integrated into the menu system, and the overall UI has been refined with improved styling, icon support, and hover states for better usability.
src/client/components/sys-menu · high confidence
Sidebar UI overhaul with customizable icons, pinned panels, and drag-to-reorder transfers
The sidebar has been rewritten to support a customizable far-left icon bar (driven by \leftSideBarIcons\ config), a pinned state for the bookmarks/history panel that persists across sessions, and scroll-position memory for both lists. The bookmarks and history lists now support a 'double-click to open' mode (controlled by \doubleClickToOpenBookmark\), and the history list can be sorted by connection frequency. File transfer controls now allow drag-and-drop reordering of the transfer queue, and the transfer history modal includes a configurable page size. The 'About' panel now displays the application's running time.
src/client/components/sidebar · high confidence
Fixes
Fixes renderer crashes on Linux ppc64le when system fonts are not detected by Chromium
On Linux ppc64le, Electron's bundled fontconfig may fail to resolve system fonts, causing the renderer to crash with exit code 133. This change adds a build-time patch for ppc64le builds that detects this condition at startup and automatically restarts the application with a custom font configuration file (electerm-fonts.conf) containing explicit font directories and a private cache. If the restart fails or is bypassed, the app falls back to a bundled web font (Maple Mono) to ensure the interface remains usable.
build/ppc64le · high confidence
Removal of legacy development server entry point
The \src/server/app.js\ file, which previously served as the entry point for the development server by initializing the application, configuring the HTTP server, and handling startup logging, has been removed. This change eliminates the manual server startup logic and associated dependencies (such as \bluebird\ and \http\), simplifying the server-side codebase.
src/server · high confidence
Test coverage
Added SSH integration test harness and in-process test server; Added e2e test infrastructure and utilities; Added integration tests for SSH lifecycle, legacy algorithms, and MCP server; Added unit tests for AI, terminal, and database migration modules; Added unit tests for core application modules; Expanded end-to-end test coverage for layout, workspace, and AI features.
Dependencies
1778 commits updating dependencies (4 manifests)
A dependency / build maintenance change in (dependencies) — 1778 commits (1036 fixs), 4 files.
(dependencies) · high confidence · unverified
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 39 → 38 (-0.6)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 30 → 30 (-0.2)
- Architecture 91 → 87 (-4.5)
- Maturity 56 → 56 (-0.2)
- Readiness 43 → 41 (-1.2)
- Security 66 → 63 (-2.7)
- Accessibility 38 → 38 (-0.1)
- Performance 60 (new)
Resolved (38)
- (anonymous) (cognitive 24) (src/client/store/load-data.js)
- (anonymous) (cyclomatic 19) (src/client/store/load-data.js)
- (anonymous) (cyclomatic 26) (src/client/store/watch.js)
- (anonymous) (cyclomatic 66) (src/client/store/common.js)
- (anonymous)::compressChatSession (cognitive 18) (src/client/store/common.js)
- Change-coupling hub: terminal.jsx → session-base.js, attach-addon-custom.js, term-search.jsx (src/client/components/terminal/terminal.jsx)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- FileTooLong: file-transfer/transfer.jsx (src/client/components/file-transfer/transfer.jsx)
- FunctionTooLong: quick-commands-box.QuickCommandsFooterBox (src/client/components/quick-commands/quick-commands-box.jsx)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: src/app/server/session-process.js (src/app/server/session-process.js)
- Hotspot: src/app/server/transfer.js (src/app/server/transfer.js)
- Hotspot: src/app/server/zmodem.js (src/app/server/zmodem.js)
- Hotspot: src/app/widgets/widget-ssh-server.js (src/app/widgets/widget-ssh-server.js)
- Hotspot: src/client/components/remote-monitor/monitor-details.jsx (src/client/components/remote-monitor/monitor-details.jsx)
- Hotspot: src/client/components/remote-monitor/monitor-model.js (src/client/components/remote-monitor/monitor-model.js)
- …and 18 more
New (90)
- (anonymous) (cognitive 26) (src/client/store/load-data.js)
- (anonymous) (cognitive 87) (src/client/store/common.js)
- (anonymous) (cyclomatic 21) (src/client/store/load-data.js)
- (anonymous) (cyclomatic 27) (src/client/store/watch.js)
- (anonymous) (cyclomatic 77) (src/client/store/common.js)
- Boundary-crossing change coupling: bookmark-select.jsx ↔ sidebar.js (src/client/components/sidebar/bookmark-select.jsx)
- Change coupling: agent.js ↔ ai-chat.jsx (src/client/components/ai/agent.js)
- Change coupling: ai-chat-history-item.jsx ↔ ai-chat.jsx (src/client/components/ai/ai-chat-history-item.jsx)
- Change coupling: attach-addon-custom.js ↔ terminal.jsx (src/client/components/terminal/attach-addon-custom.js)
- Change coupling: term-search.jsx ↔ terminal.jsx (src/client/components/terminal/term-search.jsx)
- Documentation: no architecture or design documentation (README.md)
- FunctionTooLong: agent.runAgentLoop (src/client/components/ai/agent.js)
- FunctionTooLong: load-data.default (src/client/store/load-data.js)
- FunctionTooLong: widget-instance-detail.WidgetInstanceDetail (src/client/components/widgets/widget-instance-detail.jsx)
- FunctionTooLong: widget-ssh-server.widgetRun (src/app/widgets/widget-ssh-server.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 70 more
Changes since last survey
- 55 commits — 36 feature/other, 19 fixes
By area
- src/client — 26 commits
- build/docs — 8 commits
- (root) — 6 commits
- src/app — 6 commits
- .github/workflows — 3 commits
- src/test — 3 commits
- .github/SECURITY.md — 1 commit
- build/.sample.env — 1 commit
- build/npm — 1 commit
Notable commits
- fix: Fix Linux appimage integeration issue (#4546)
- fix: AI CHat: Fix AI chat input lagging issue
- fix: AI: Fix cancel request logic
- fix: Fix .vv support
- fix: Fix CI
- fix: Fix CI
- fix: Fix binary trzsz transfer
- fix: Fix ignore
- fix: Fix image bg render to old way
- fix: Fix non-ASCII text garbled in the session log (#4562)
- fix: Fix readme
- fix: Fix security.md
- fix: Fix session log keeping only the last row of long lines (#4496) (#4561)
- fix: Fix spice form
- fix: Fix ssh session mem leak
- fix: Fix tests
- fix: UI: Fix AI preset UI in mobile mode
- fix: UI: Fix cmd history UI
- fix: UI: Fix cmd history scroll issue
- change: #4547 Support load .vv file for Spice bookmark create form
- …and 35 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
electerm/electerm was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 22ad8fe8296e9936a08f0c13b693a4ed0058a14c — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.