# Motrix v2.0.0-beta.17 - Product: Motrix (https://whatsnew.fyi/product/motrix) - Vendor: agalwood - Date: 2026-08-16 - Version: v2.0.0-beta.17 - Original notes: https://github.com/agalwood/Motrix/releases/tag/v2.0.0-beta.17 - Permalink: https://whatsnew.fyi/product/motrix/releases/v2.0.0-beta.17 - Labels: Pre-release What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — Fix non-artifact failure after beta.16 publication by removing Docker Hub repository-description mutation from the release workflow - **changed** — Make anonymous signature verification the final step of the container finalize job - **added** — Add workflow contract that rejects removed Docker Hub login route, repository-description payload, or description step if they return to the security-critical release path - **changed** — Build linux/amd64 on ubuntu-22.04 and linux/arm64 on ubuntu-22.04-arm with native architecture verification before Buildx starts - **changed** — Push each successful platform only by its untagged, content-addressed OCI digest to Docker Hub and GHCR - **changed** — Anonymously pull the exact staged digest from both registries and run complete Server runtime smoke on native runner - **changed** — Bind each platform record to exact version, source commit, workflow run and attempt, native runner identity, raw OCI index hash, image manifest, attestation manifest, max-level provenance, and non-empty SPDX SBOM - **changed** — Allow finalize job to proceed only after complete amd64/arm64 set succeeds with comprehensive validation - **changed** — Recheck both immutable version tags immediately before finalization to resume identical results or repair missing registry - **changed** — Require Docker Hub and GHCR to expose the same final index digest, platform manifests, attestation manifests, provenance, and SBOM set before signing - **changed** — Run complete final public Server runtime smoke on native amd64 and arm64 runners against exact signed digest in both registries - **changed** — Advance stable floating aliases only in the last recovery-safe job after every build, index, signature, provenance, SBOM, anonymous pull, and runtime gate passes - **added** — Ground-up desktop rebuild with Electron 43, React 19, and TypeScript 7, including customizable Dashboard, dark mode, cross-platform application menu, and clearer task-inspector feedback - **added** — Host-neutral download core for desktop app and Node/Web Server with SQLite session recovery, tracker management, UPnP/NAT-PMP, and HTTP, FTP, BitTorrent, and magnet support - **added** — MDXP-based integration for official CLI and browser handoff including local discovery and device-code pairing for remote Server instances - **added** — QuickJS plugin sandbox with capability consent, bundled builtin plugins, and in-app plugin marketplace - **added** — Persistent multi-platform Server containers for NAS and home-server deployments published after complete native architecture set and every public verification gate #### Motrix 2.0.0-beta.17 English | [简体中文](https://github.com/agalwood/Motrix/blob/v2.0.0-beta.17/docs/release-notes/2.0.0-beta.17.zh-CN.md) Motrix 2.0.0-beta.17 is the next Motrix Turbo beta intended for public distribution only after every protected release gate passes. It fixes the non-artifact failure observed after beta.16 had already published and signed its two-registry container index, without moving or reusing the immutable `v2.0.0-beta.16` tag. The [beta.16 historical record](https://github.com/agalwood/Motrix/blob/v2.0.0-beta.17/docs/release-notes/2.0.0-beta.16.md) documents the successful desktop, GitHub prerelease, R2, native platform, cross-registry index, provenance, SBOM, and signature stages, followed by the HTTP 403 that prevented the final public runtime matrix from starting. ##### Release-gate recovery - Removes Docker Hub repository-description mutation from the release workflow. Repository description and overview are publisher metadata, not versioned OCI artifacts, and their administrative access boundary is separate from image publication. - Makes anonymous signature verification the final step of the single container finalize job. A successful finalize result and its verified digest can therefore hand off directly to the native public runtime matrix. - Adds a workflow contract that rejects the removed Docker Hub login route, repository-description payload, or description step if they return to the security-critical release path. - Keeps failures visible and fail-closed. The change does not use `continue-on-error`, does not weaken an artifact, signature, provenance, SBOM, platform, anonymous-pull, or runtime check, and does not broaden release access. ##### Native container publication - Builds `linux/amd64` on `ubuntu-22.04` and `linux/arm64` on `ubuntu-22.04-arm`. Each job proves its GitHub-hosted Linux runner and native architecture before Buildx starts. The container release path does not install or invoke QEMU. - Pushes each successful platform only by its untagged, content-addressed OCI digest to Docker Hub and GHCR. A single architecture never receives the public version tag and cannot become the official release by itself. - Anonymously pulls the exact staged digest from both registries and runs the complete Server runtime smoke on its native runner. Platform metadata is emitted only after both registry smokes succeed. - Binds each platform record to the exact version, source commit, workflow run and attempt, native runner identity, raw OCI index hash, image manifest, attestation manifest, max-level provenance, and non-empty SPDX SBOM. - Allows the single finalize job to proceed only after the complete amd64/arm64 set succeeds. Missing, duplicate, unexpected, cross-wired, shared, ambiguous, conflicting, or future-attempt data fails closed before either version tag can be created. - Rechecks both immutable version tags immediately before finalization. A clean run creates both indexes; a rerun resumes an identical complete result or repairs one missing registry from the verified existing index. A conflicting immutable tag fails closed. - Requires Docker Hub and GHCR to expose the same final index digest, platform manifests, attestation manifests, provenance, and SBOM set before signing. Both signatures are then verified anonymously. - Runs the complete final public Server runtime smoke on native amd64 and arm64 runners against the exact signed digest in both registries. - Advances stable floating aliases only in the last recovery-safe job after every build, index, signature, provenance, SBOM, anonymous pull, and runtime gate passes. Beta releases publish only their immutable version tag, so beta.17 does not update `latest`, `stable`, or another stable alias. The GitHub prerelease, R2 update feed, container registries, and Snap Store remain independently gated publication channels. Their individual safety and recovery rules are s _[Truncated at 4000 characters — full notes: https://github.com/agalwood/Motrix/releases/tag/v2.0.0-beta.17]_