Changelog
10 releases so far. 1.7.0 is current; 1.7.0, 1.6.1, 1.6.0, 1.5.0, 1.4.0, 1.3.0, 1.2.0, 1.1.0, 1.0.0 still work and are supported.
1.8.0 — current
Windows updates now wait for you
An update downloads, and then you run the installer yourself. Smartcom used to launch it when you quit — but these builds are not code-signed, so Windows would put a "Windows protected your PC" warning on screen after the app had already closed, with nothing to explain where it came from.
Now the update panel says "run the installer to finish" and gives you a Show the installer button. Smartcom stays open, you double-click an installer you asked for, and the SmartScreen warning arrives where it makes sense — see how updates work. This is temporary, and goes away once the builds are signed.
Macs can update again
1.7.0 shipped update information that named the .dmg rather than the
.zip, and a Mac installs an update from the .zip — so an
Intel Mac could see 1.7.0 and not install it. Fixed, and both Intel and Apple
Silicon are covered.
Under the hood
- A dependency that was never used has been taken out of the build. It carried a security advisory, and nothing in Smartcom called it.
-
The packaging toolchain was updated, which is what let the Apple Silicon
.dmgbuild again.
Everything in 1.7.0 is here too — the file browser, the scratch pad, connection variables and the rest are listed below.
1.7.0
Get files off a device
Right-click a session tab for Browse files… and the host's filesystem opens as a pane — not a dialog. It tiles beside the terminal in grid mode, goes fullscreen, and pops out to its own monitor, because it is a pane like any other.
- Downloads run through a queue that belongs to the app rather than to the pane, so closing the browser — or popping it out — does not kill a transfer in progress. The queue shows in every window.
- One transfer at a time per host, in parallel across hosts: network gear often offers only a couple of SFTP channels.
-
A file whose name is already taken is saved as
core-01 (2).cfg. Nothing is ever overwritten. - Download file… on the same menu takes a path you type, when you already know what you want and where it is.
It reads and never writes. There is no upload, rename or delete: those would let a misclick edit production equipment from a file manager. This is a way to get a capture or a config off a box.
Stage a command before you send it
The scratch pad now fills in variables and puts the result in a terminal. The job it is for is the awkward one: copy something out, change three values in it, put it back — which otherwise goes through a text editor and loses your global variables on the way.
-
{{NAME}}works exactly as it does in a button. A strip under the pad lists every name you used, where its value comes from, and what it resolves to. -
A name it does not recognise becomes a question. Type
{{var1}}, press Insert, and it asks you whatvar1is — no declaring anything, no saving a button for something you will use once. - Copy puts the resolved text on the clipboard. Insert puts it on the command line and stops, so you press Enter. Send pastes it, and a line ending in a newline will run.
- Each works on your selection when you have one, so you can stage a long block and send three lines of it.
Nothing here is written to disk. The pad is cleared when Smartcom closes, which is deliberate — the thing people park while working on a live box is often a credential.
One connection, many sites
A connection's name, host, username and password can be
{{VARIABLES}} too, read from your global variables file
when you connect. One saved connection per role, and the file says which site you are
working on today.
- The connection form shows what each box will actually become, so a renamed variable is caught where you can fix it.
- A name that is not in your file stops the connection and says which one. It is never sent to the device as literal text — an unresolved password would read as a wrong one, against an account that may lock out.
- If you put a password in your globals file, remember that file is plain text on disk, unlike a password typed into the form, which goes to the operating system's keychain. The form says so where the choice is made.
Smaller things
- Duplicate a session tab — a second connection to the same host from the tab's right-click menu, for when you want to watch a log in one and work in the other.
- Two connections may now share a name. The database used to forbid it, which made importing from two sources unnecessarily painful. Your database is backed up automatically before this change is applied.
1.6.1
Command help while you type
Type a command into a session and the app works out what you are running, then
offers the documentation for it beside the terminal. Not the first word —
sudo -u root tcpdump -i eth0 is a tcpdump question.
Every example becomes a small builder: each placeholder is a field, the command underneath is what will actually be sent, and you can copy it, insert it on the command line and stop there, run it against the session named at the top of the panel, or hand it to the assistant.
-
Pages match what you are connected to — Windows at a PowerShell prompt, Linux for
WSL, and Cisco IOS on a connection
tagged
cisco, whereshowandreloaddeliberately do not fall through to their Linux namesakes. -
Documentation is not a safety review. It describes
rm -rfas cheerfully asls, so anything destructive becomes Review & Run and shows you the command and the box first. - A command goes to the session you opened the page for and to no other. Switch terminals and it tells you, and offers to retarget.
- Ctrl+Shift+T searches all ~7,400 pages by name, description or intent — "restart service", "find large files".
- The set downloads once in the background and works offline afterwards. If it cannot download it says so, and nothing else changes.
Also
- Highlighting in a terminal copies, the way PuTTY does. Right-click still pastes. Switchable in Settings → Terminal.
- A scratch pad in the side panel — somewhere to park text between two terminals. Not a notepad: there is no file and nothing survives closing the app, which is deliberate given what tends to get parked while working on a live box.
- The side panel's tabs are icons; four text tabs no longer fitted.
Fixes
- A form field's list of choices, and a local shell's arguments, could each only ever hold one entry — the box re-derived its text from the parsed value, so the comma or space was eaten the moment it was typed.
- The button-set editor no longer scrolls inside a second scrolling box.
Upgrading
- Nothing to do. On first run the page set downloads in the background; until it finishes the chip stays quiet and everything else behaves as before.
- Command documentation is from the tldr-pages project, used under CC BY 4.0.
1.6.0
Your own machine is a connection
A connection's transport can be a local shell. WSL and each installed
distro, Windows PowerShell, PowerShell 7, Command Prompt and Git Bash on Windows; bash,
zsh, fish and whatever else /etc/shells lists elsewhere. The connection
form scans the machine and offers what is actually installed.
These are real terminals, not piped output. vim, top and
less work, colour works, and the shell is told when the pane is resized —
so a full-screen program redraws to the pane it is in rather than wrapping at 80
columns.
- Everything already built works on one without change: buttons, forms, waiting for a prompt, session logging, the grid, broadcast and detached windows.
- Two things say no on purpose. Copying a script to the host is SSH-only — the file is already on this machine — and SecureCRT export reports local shells as unsupported rather than writing a session that would open nothing.
- The assistant is told the session is your own workstation rather than a remote host, and is more cautious about anything destructive there.
macOS updates stopped stranding one architecture
The Apple builds run on two machines and each wrote its own update feed, so whichever finished second overwrote the first and left one architecture pointed at the wrong download. The two are now merged into a single feed as text, which keeps the installer checksums byte-identical.
1.5.0
Buttons can move files
Download and upload steps move files over SFTP in the middle of a script, so a button can start a packet capture, wait for the device to finish and collect the result unattended.
Both directions are confined to a configured transfer folder, and that is a security boundary rather than tidiness: upload reads from your disk, so an unconfined path in a button downloaded from someone else could post your private key to the author's host while the run looked entirely ordinary. Devices with no SFTP subsystem — a great many switches and firewalls answer SSH and run none — now say so instead of reporting a bare channel failure that reads like a bug.
Variables and control flow
Built-ins such as {{EPOCH}} and {{TIMESTAMP}}, regex captures
from a wait-for-prompt step bound into variables, and while and
forEach loops. Built-ins are computed once per run rather than once per
use, so a filename written in one step and collected in another names the same file.
Loop counts are capped by the engine itself, not only by the schema — a downloaded
button must not be able to hold a shell open issuing commands nobody is reading.
Long-running buttons no longer pin you to one host
The busy flag was shared across every session, so a script running anywhere disabled the buttons everywhere. It is per-session now. Closing a session or quitting while a script is running warns you, names the button, and is honest that stopping the script does not stop what it already started on the far end.
Import from SecureCRT, and the first macOS builds
The SecureCRT session store is read directly, keeping its folder tree as your hierarchy. Credentials are never read — they stay encrypted in SecureCRT's own store — and Telnet and SSH1 sessions are reported rather than silently imported as SSH2. 1.5.0 is also the first release with macOS builds.
1.4.0
Tags on hosts and on button sets
Connections carry tags. Button sets carry tags. A set appears on any connection
sharing one. Tag a switch cisco and every set tagged
cisco shows up on it.
The part that matters is what happens next month: a set installed later, tagged the same way, appears on that switch without you touching the connection again. Naming sets by hand — which is what 1.3.0 added — cannot do that, because the list was a decision about the sets you had at the time. The two are additive: a set shows if it is named or shares a tag.
- All 95 shipped sets arrive tagged with their vendor and platform, so tagging one host is the whole setup — there is no set editing at all.
- Tags travel inside an exported set, so anything you download from the exchange starts matching your existing hosts the moment it is imported. Listings here are filterable by the same tags.
-
Normalised on the way in — lower-cased, trimmed, spaces turned into hyphens,
de-duplicated — so
Customer Acmeandcustomer-acmeare one tag however two people type them, months apart. - A connection with no tags and no named sets still shows everything, which is what every connection you already have looks like after upgrading.
Full page on tagging hosts and sets.
Upgrading
- Nothing to do. The database migrates itself on first run and takes a snapshot first.
- Nothing is tagged until you tag it, and an untagged connection behaves exactly as before.
- Sharing a tagged set with someone on an older build is fine — their build reads the file, ignores the tags and imports the set as it always did. The exchange does not badge a tagged set as needing a newer version, because it does not.
1.3.0
The app ships a button library
Previous versions opened on an empty button panel and a "create your own" invitation. 1.3.0 installs with 2,714 buttons in 95 sets across 23 bundles, covering 20 vendors — Cisco IOS and IOS XE, Junos, Arista EOS, Aruba AOS-CX, Dell OS10, Ruckus ICX, MikroTik RouterOS, FortiGate, PAN-OS, pfSense, UniFi, F5 BIG-IP, Proxmox VE, VMware ESXi, Hyper-V, Linux, Docker, Subversion, Asterisk and Kamailio.
- 1,399 prompt for the value that changes rather than hard-coding it.
- 659 sit behind a confirmation, and 268 of those name the resolved target in the gate — after the form is filled in.
- No bundle exceeds 200 buttons; bigger platforms split into independently importable sets.
- Nothing is force-installed over anything you built. Importing a set never replaces one — it lands beside it, renamed on collision.
Written from documented syntax, not run against live hardware of every platform. The read-only buttons are low risk; test the destructive ones in a lab first. The full list, bundle by bundle.
ED25519 SSH keys
The app generates ED25519 keys, and does so by default. RSA is retained as the compatibility choice, with its key-size box shown only when RSA is selected.
Importing an ED25519 key was broken and is fixed. A key beginning
-----BEGIN OPENSSH PRIVATE KEY----- failed with an OpenSSL error while the
dialog promised "PEM or OpenSSH". Parsing now goes through ssh2 — the same parser that
later authenticates with the key.
That was issue #1, reported by CrustyB, who diagnosed the cause correctly and proposed the fix that was used.
Also: passphrase-protected ED25519 keys work throughout, deployment through the
ssh-copy-id-style workflow works, passphrases stay in the OS vault, and
adding a key under a name already in use is refused rather than silently creating a
second indistinguishable entry.
More on SSH keys.
Finding a button in a panel this size
All four of these exist because the library is now large enough to get in the way.
- Button sets per connection. A connection names the sets it uses and the panel shows only those. Empty means show everything, so nothing changes for connections you already have. How it works.
- Favourites. A set pinned to the top that ignores the per-connection filter, so a starred button follows you between hosts.
- Copy a button into any set under a new name. The copy is a snapshot, not a link — this is how you take a shipped vendor button and adjust it for your kit. More.
- Searchable pickers. "Run another button", "run a whole set" and the startup-script picker were plain dropdowns over every button on the machine. They are filtering comboboxes now.
Export connections for SecureCRT
A CSV for SecureCRT 9.2+ carrying session name, folder, host, port, protocol, username and emulation, with folders preserved as SecureCRT folder paths. It exports connections — buttons, audit history, session logs, global variables and assistant settings do not travel. No credentials are written, usernames are off by default, and serial connections are reported rather than exported. The detail, and why serial is excluded.
AppImage update metadata
The AppImage now carries standard update information and a .zsync file is
published beside it, so external AppImage tooling can see it at all — previously it could
only be updated by the app itself.
What is verified is that the metadata is correct and the AppImage still runs; whether
a given third-party manager acts on it has not been tested against a published
release, and is not claimed here.
Settings survive an AppImage update either way — they live in
~/.config/smartcom-revisited, which the AppImage never
touches.
Upgrading
- Nothing to do. The database migrates itself on first run, and takes a snapshot first.
- Existing connections show every button set, exactly as before, until someone narrows one.
- Existing RSA keys and saved connections keep working with no migration. RSA generation, storage and authentication are untouched.
-
One removal: an old aggregate
Linux.buttons.jsonheld 327 buttons — over the 200 cap — and duplicated the threeLinux-*bundles exactly. Use those three instead.
1.2.0
Global variables
A value you set once that every button can use, with nothing declared per button. Set
KBSTECHLOG to your log collector and any button anywhere can send
wget {{KBSTECHLOG}} — the same {{NAME}} syntax the popup forms
already used.
- Edited from a form in the app, or as the plain text file it really is.
- Works in every place a script takes text: sent commands, the script-library arguments box, a called button set, and the default value of a form field.
- A value the button asks for at run time wins over a global of the same name.
- The file is re-read on every button press, so editing it in your own editor — or pulling a new one from git — takes effect immediately. No restart.
Full page on global variables, including where the file lives and what the syntax will and will not accept.
Show and hide button sets
Right-click the buttons panel for a tick list of every set, plus Check all and Uncheck all. Unticking hides a set from the panel without deleting anything, and the choice is remembered per machine.
Aimed squarely at people who have installed a lot of sets from the exchange: how it works.
Linux packaging fix
The .deb and .rpm did not declare libnss3 or
libasound2, which Electron needs to start. A desktop install has them anyway;
a minimal or server install would install the package and then fail to launch. Fixed, and
verified by installing into a bare container and launching it.
If you reported "installs but will not start on Linux" — this was it.
1.1.0
The AI assistant can actually read your terminal
1.0.0 claimed this and it did not work with local models — the assistant would answer "I don't have the ability to see your terminal". Fixed properly, and with it:
- provider and model dropdowns (Claude, OpenAI, Ollama), switchable mid-conversation;
- a badge on every answer saying what context it was given;
- an elapsed timer while a local model is thinking.
Pasting no longer corrupts multi-line text
Pasting a config into nano over SSH used to merge and re-indent lines. It is
now byte-identical to what you copied, verified up to 21 KB in one paste.
The assistant's Insert button also stopped running multi-line suggestions. It inserts them and waits for you, which is what it always should have done.
1.0.0
First release. SSH and serial in one client, buttons built from coloured blocks, broadcast across sessions, detached windows, session logging and an audit log, key generation and deployment, and PuTTY session import.
Sharing sets between versions: the .buttons.json envelope is still
version 1, and every block type has existed since 1.0.0 — the list has not
grown. What has grown is the optional fields around them: 1.3.0 added three (where a
copied button came from, a description on a set, and a fixed id for Favourites) and
1.4.0 added tags on a set. All four are additive, so files from older releases stay
valid, newer releases import everything older ones produced, and an older build ignores
what it does not recognise.
The one thing an older build cannot do is resolve a global variable, so the exchange marks any set that expects one as needing 1.2.0 or newer.