Changelog
what changed, when.
Every release, newest first, and how to update. Read the entry for your target version before you update.
011.0.0 · 2026-09-29
Current First marketplace release. It contains everything in 0.3.0 below (public record, proof, follower tools, integrity flags, earning options, operator console) plus the changes listed here. The scoring method and the seal format are unchanged, so no recompute is needed.
Changed
- Console navigation. The console is now the MIKODES Admin Kit 0.3.0. The record's data screens open inside it, in the sidebar: Monitor → Chats (was Operations → Sources), Callers, Calls, Seals (was Operations → Proof), Integrity review, Logs; Money → Revenue centre, VIP members; System → Backup (owners). The addresses under
/admin/ops/…are unchanged and still open on their own. - Setup wizard. Get started asks for the Telegram bot token, with a Test button that asks Telegram who the bot is. A new status check, A chat is recording, stays on the Overview until an approved chat records and names the chats waiting for approval.
- Seal interval wording. README and site texts now say "every 10 minutes" (the default since 0.2.0), not "every hour".
Security
- One on-chain transaction pays one request only, across VIP checkouts and paid listings.
- Paid listings: a request is reused only when the same form is sent twice; the review and the pay page show the description and the join link, with a warning when the link names another public @username than the recorded group's own.
- At most 5 payment requests per visitor in 30 minutes; payment status polls share one chain read, with a site-wide cap.
- Behind a trusted proxy the visitor is the rightmost
X-Forwarded-Forentry; a flood of new addresses can no longer reset the API limits. - Console viewers see that a VIP invite was sent, not the invite link.
- Share-card images have a site-wide render budget (503 with
Retry-Afterabove it); cached cards still load. - Trading-link clicks count once per visitor, venue, token and UTC day.
Fixed
- Share-card images on the hosted live demo returned an error (the demo build did not include the share-card fonts). A self-hosted install was not affected.
Update from 0.3.0
Follow Updating. The database upgrades itself on start; nothing in .env changes.
Known limits
- Tested with 837 automated tests (typecheck and licence check clean). Not yet run against a live Telegram bot, live Telegram Stars or Solana Pay payments, a live Jupiter swap or a mainnet memo. Make one small test of each yourself before you announce it.
- Some trading-venue link formats (Axiom, Bloom, Trojan) are not confirmed in the venues' own docs; the console says so next to each code. Test each link yourself.
- The console's Access settings (maintenance, announcement, blocked countries), tagline, support email, website and legal URLs are not used by the public site.
020.3.0 · 2026-09-25
Added
- Admin console: the MIKODES Admin Kit 0.2.0 at
/adminwith roles (owner, manager, viewer), two-factor, audit log, history with rollback, export and import, status checks and realised revenue. Settings and secrets are edited there; most apply without a restart. Operations screens at/admin/ops: Sources, Callers (notes, merge), Calls, Proof, Integrity, Revenue, Members, Logs, Backup. - Earning options, all off by default: trading links with referral presets and click counting, Jupiter swap with a referral fee, VIP membership (Telegram Stars and Solana Pay), paid listings, sponsored slot, API keys and limits, a calculator.
- Followers: live feed, token pages, tokens list, search, follower simulator, groups directory, share cards, follow alerts by Telegram DM with quiet hours, new bot commands (
/top,/caller,/follow,/token,/settings), an optional reply card in groups. - Integrity flags: coordinated calls, paid promotions (not scored), VIP-lead comparison.
- Design: new public pages and Operations screens, dark and light themes.
Changed
ADMIN_SECRET_KEYis required for the console.ADMIN_TOKENfrom 0.2 is no longer a login: remove it from.env.- Chats must be approved (or listed in
ALLOWED_CHAT_IDS) before anything is recorded.
Known limits
- Tested with 823 automated tests at the time. Not yet run against a live Telegram bot, live Stars or Solana Pay payments, a live Jupiter swap or a mainnet memo.
- The console's Access settings (maintenance, announcement, blocked countries), tagline, support email, website and legal URLs are not used by the public site.
Migration from 0.2
- Back upThe database and
.env(how). - Add the console key
ADMIN_SECRET_KEYfromopenssl rand -hex 32in.env; removeADMIN_TOKEN. - Approve chatsList your chat ids in
ALLOWED_CHAT_IDS, or approve them under Operations → Sources after the update. - Update and startAs in Updating. The schema upgrades itself; your
.envvalues keep working until you save the same setting in the console. - Create the console ownerWith the setup code from the log (how).
030.2.0 · 2026-09-23
- Price correctness on every Solana pool type; a cross-check between price sources (disagreement = unpriceable); migrated tokens re-checked.
- Scoring method 2: volume-weighted exits, liquidity-aware slippage, "low liquidity" and "called after a run-up" labels,
scripts/recompute.ts. - Seals every 10 minutes by default; coverage events sealed; all verifiers reject gaps and overlaps.
- Security fixes: chat approval, sign-in throttle, name sanitizing, wallet validation.
040.1.0 · first release
Telegram recorder, GeckoTerminal and DexScreener prices, follower results and median ranking, Merkle seals with Telegram posts, the operator-signed Solana memo, caller wallet linking and the exit-liquidity check, the public site with proof pages, the offline verifier, exports, the badge and the API.