What changed in pm2 from 6 to 7
5 releases numbered after v6.0.14 up to and including v7.0.4, stable releases only. v6.0.14 and v7.0.4 are the newest stable releases of 6 and 7 we track; this page follows them as new ones ship.
- 2 CVEs mentioned
- 1 mentions breaking changes
- 3 remove or deprecate something
50 changes across 5 releases
Added 4
- Start .ts apps with Node.js native type stripping when bun is not installed (Node.js >= 22.18 / 23.6, --experimental-strip-types auto-injected on 22.6+) with ts-node fallback now resolved from the app's own dependencies
- Show pm2 ls host-metrics line by default
- Add adaptive layout to pm2 ls that picks the widest layout fitting the terminal (full, condensed, or ultra-compact mini)
- Add Bun runtime support with ProcessContainerBun.js and ProcessContainerForkBun.js
Changed 14
- Pin OpenTelemetry package versions in pm2 install-otel and re-emit legacy HTTP span tags (http.method, http.status_code, http.target) dropped by @opentelemetry/instrumentation-http >= 0.220
- Filter pm2 ls host-metrics line to only list network interfaces carrying traffic
- Replace pm2 ls host-metrics mem free with ram usage percentage and add GPU memory/temperature when reported
- Show per-interface network errors/drops in pm2 ls host-metrics line when non-zero
- Replace bundled pm2-sysmonit module and systeminformation with lib/tools/SysMetrics.js for Linux/macOS
- Internalize pm2-axon, pm2-axon-rpc, pm2-io-bpm, pm2-io-agent, and fclone as local modules to reduce supply chain surface
- Internalize pm2-multimeter and charm into lib/tools/multimeter with zero external dependencies
- Replace needle with native fetch for CliAuth and TAR publish
- Replace enquirer with lightweight built-in prompt for boilerplate selector
- Replace promptly with built-in lib/tools/prompt
- Replace mkdirp with native fs.mkdirSync({ recursive: true })
- Replace source-map-support with native process.setSourceMapsEnabled()
- Replace sprintf-js with template literals in Dashboard
- Replace url.parse() with native URL constructor in Serve, Utility, and CliAuth
Fixed 19
- Fix pm2 start --container / --container --dist crashing with Cannot find module due to wrong require depth in Containerizer.js
- Bump js-yaml 4.3.0 → 4.3.1
- Fix overlapping reloads colliding on the _old_<pm_id> slot and orphaning a cluster worker by refusing a reload while one is in progress
- Ignore stale exit events from a replaced process to fix double start on Windows with shutdown_with_message
- Fix retrying in NaNms kill log and ~1ms poll spam when kill_retry_time is unset by falling back to KILL_RETRY_TIME constant (100ms, overridable via PM2_KILL_RETRY_TIME)
- Fix pm2 start/restart RPC hanging forever when a cluster worker dies before its online event by having executeApp conclude on exit-before-online
- Surface the daemon's actual error in CLI output instead of masking everything as Process not found
- Fix daemon failing to boot on Node.js < 14.18 by switching embedded vizion from node:-scheme requires to bare specifiers
- Fix pm2 serve returning 403 Forbidden on Windows due to traversal guard using hardcoded / separator
- Fix pm2 ls table misalignment when username exceeds user column width caused by cli-tableau's truncate() miscounting ANSI bytes
- Fix long status lines wrapping on narrow terminals by making Common.printOut ANSI-aware and cropping output to terminal width
- Fix Python and other non-Node interpreter regression on Ubuntu where bun runtime detection used naive substring matching that incorrectly matched paths containing 'bun', causing routing through ProcessContainerForkBun.js and SyntaxError when Python tried to parse the JS container
- Display max_memory_restart in pm2 describe output when set
- Add missing port option to StartOptions TypeScript declaration
- Fix incorrect file permissions on openrc.tpl template
- Fix Windows cmd.exe regression by reverting bin/pm2 launchers to #!/usr/bin/env node shebang to restore compatibility with npm's pm2.cmd shim
- Fix HttpInterface env stripping never executing with WEB_STRIP_ENV_VARS
- Rewrite TreeKill to use single ps snapshot and in-memory tree build to eliminate race conditions and improve SIGKILL escalation
- Fix [object Object] env vars leaked to fork mode subprocesses
Removed 4
- Remove dead code including promise.min.js polyfill, IsAbsolute.js, unused Java/Ruby Dockerfile templates, and always-false win64 platform checks
- Remove old vizion module and 3 submodules
- Require Node.js >= 18.0.0 and drop Node.js 16 support
- Drop auto source map file detection in Common.prepareAppConf
Security 9
- Bump js-yaml 4.1.1 to 4.3.0 to fix quadratic-complexity DoS in merge-key handling
- Bump ws 8.20.0 to 8.21.0 to fix uninitialized-memory disclosure and tiny-fragment DoS
- Bump @pm2/js-api 0.8.0 to 0.8.1 to pull in patched ws@8.21.0
- Fix ReDoS vulnerability in Config.js string-to-array split regex (CVE-2025-5891)
- Update proxy-agent to 6.5.0 and basic-ftp to 5.3.1 (CVE-2026-27699)
- Fix command injection in WebAuth.js open() by replacing exec() with execFile()
- Fix command injection in PM2IO.js open() by replacing exec() with execFile() and validating SUDO_USER
- Fix command injection in lib/tools/open.js by replacing exec() with execFile() and validating SUDO_USER
- Fix prototype pollution in Configuration.set/unset via __proto__ key traversal
Original release notes, newest first
The list above is our reading of these notes; the originals from Unitech are here, one fold per release.
v7.0.4
7.0.4
Features
- Start
.tsapps with Node.js native type stripping when bun is not installed (Node.js >= 22.18 / 23.6,--experimental-strip-typesauto-injected on 22.6+);ts-nodefallback now resolved from the app's own dependencies
Bug Fixes
- Fix
pm2 start --container/--container --distcrashing withCannot find module— wrong require depth inContainerizer.jsfrom the v7 promptly internalization - Bump
js-yaml4.3.0 → 4.3.1 - Fix overlapping reloads colliding on the
_old_<pm_id>slot and orphaning a cluster worker — a reload is now refused while one is in progress #6129 - Ignore stale exit events from a replaced process — fixes double start on Windows with
shutdown_with_message#6142 - Fix
retrying in NaNmskill log and ~1ms poll spam whenkill_retry_timeis unset — fallback toKILL_RETRY_TIMEconstant (100ms,PM2_KILL_RETRY_TIMEoverridable) - Fix
pm2 start/restartRPC hanging forever when a cluster worker dies before itsonlineevent (badnode_args, boot OOM) — executeApp now concludes on exit-before-online - Surface the daemon's actual error in CLI output instead of masking everything as
Process not found - Pin OpenTelemetry package versions in
pm2 install-oteland re-emit legacy HTTP span tags (http.method,http.status_code,http.target) dropped by@opentelemetry/instrumentation-http
= 0.220
Core Refactor
- Remove dead code:
promise.min.jspolyfill (nativePromise),IsAbsolute.js(nativepath.isAbsolute), unused Java/Ruby Dockerfile templates, always-falsewin64platform checks
v7.0.3
Bug Fixes
- Fix daemon failing to boot on Node.js < 14.18 — embedded
vizionusednode:-scheme requires; switched to bare specifiers
v7.0.2
7.0.2
Bug Fixes
- Fix
pm2 servereturning 403 Forbidden on Windows — traversal guard used hardcoded/separator #6109 - Fix
pm2 lstable misalignment when a username exceeds theusercolumn width — cli-tableau'struncate()miscounts ANSI bytes, leaking bold into thewatchingcolumn - Fix long status lines (e.g.
Applying action … on app […]) wrapping on narrow terminals —Common.printOutnow ANSI-aware crops single-line TTY output to terminal width (piped output unaffected)
Features
pm2 lshost-metrics line now shown by defaultpm2 update)pm2 lsadaptive layout: picks the widest layout that fits the terminal — full → condensed → new ultra-compactmini(id · name · status · cpu · mem) — and caps thenamecolumn so long names can't overflow the tablepm2 lshost-metrics line only lists network interfaces carrying traffic (hides idle utun/awdl/bridge/anpi/unused en*)pm2 lshost-metrics line: replacedmem freewithram usage(%), added GPU memory/temperature when reported, per-interface network errors/drops shown when non-zero
Core Refactor
- Drop old vizion module, refactor to support only git and drop 3 submodules
- Replace the bundled
pm2-sysmonitmodule andsysteminformationwithlib/tools/SysMetrics.js(Linux/macOS);pm2 slist/getSystemDataand the Docker metrics path now read this collector. Covered bytest/programmatic/sysmetrics.mocha.js
Security
- Bump
js-yaml4.1.1 → 4.3.0 — fixes quadratic-complexity DoS in merge-key handling (GHSA-h67p-54hq-rp68) #6122 - Bump
ws8.20.0 → 8.21.0 — fixes uninitialized-memory disclosure and tiny-fragment DoS (GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p) #6116 - Bump
@pm2/js-api0.8.0 → 0.8.1, pulling in patchedws@8.21.0(its transitivewswas pinned to the vulnerable 7.x). Production deps are now advisory-free (npm audit --omit=devclean)
v7.0.1
7.0.1
Bug Fixes
- Fix Python (and other non-Node) interpreter regression on Ubuntu: bun runtime detection used a naive
includes('bun')substring check that matched any path containing the letters "bun" — most notably/home/ubuntu/.... Affected paths were routed throughProcessContainerForkBun.jsand crashed withSyntaxError: unterminated string literalwhen Python tried to parse the JS container. Anchored the match to the end of the interpreter path (=== 'bun'or/bun$/) in bothlib/God/ForkMode.jsandlib/Common.js#5990 - Display
max_memory_restartinpm2 describeoutput when set #5925 - Add missing
portoption toStartOptionsTypeScript declaration #6045 - Fix incorrect file permissions on
openrc.tpltemplate (0755 → 0644) #5957 - Fix Windows cmd.exe regression: revert
bin/pm2*launchers to#!/usr/bin/env nodeshebang (was polyglot#!/bin/sh). Polyglot worked on Linux/macOS but broke npm'spm2.cmdshim on Windows —cmd.execan't interpret/bin/shshebang and failed with'"/bin/sh"' is not recognized as an internal or external command. PowerShell's auto-generatedpm2.ps1shim happened to callnodedirectly so it kept working, masking the regression. Bun-only Linux/macOS users (no Node installed) need to symlinknodetobun(sudo ln -s $(which bun) /usr/local/bin/node) — same workaround used in the project's bun test Dockerfile. Documented in README #6108
v7.0.0
7.0.0
Breaking Changes
- Require Node.js >= 18.0.0 (dropped Node.js 16 support)
Core Refactor
- Internalize pm2-axon, pm2-axon-rpc, pm2-io-bpm, pm2-io-agent, fclone as local modules (reduced supply chain surface)
- Internalize pm2-multimeter and charm into lib/tools/multimeter (zero external deps)
- Add Bun runtime support (ProcessContainerBun.js, ProcessContainerForkBun.js)
- Replace
needlewith nativefetch(CliAuth, TAR publish) - Replace
enquirerwith lightweight built-in prompt (boilerplate selector) - Replace
promptlywith built-in lib/tools/prompt - Replace
mkdirpwith nativefs.mkdirSync({ recursive: true }) - Replace
source-map-supportwith nativeprocess.setSourceMapsEnabled() - Replace
sprintf-jswith template literals (Dashboard) - Replace
url.parse()with nativeURLconstructor (Serve, Utility, CliAuth) - Remove
fclonenpm dep, use internalized module - Drop auto source map file detection in Common.prepareAppConf
Security
- CVE-2025-5891 Fix ReDoS in Config.js string-to-array split regex #6075
- CVE-2026-27699 Update proxy-agent to 6.5.0, basic-ftp to 5.3.1 #6088
- Fix command injection in WebAuth.js open() — replace exec() with execFile() #6089
- Fix command injection in PM2IO.js open() — replace exec() with execFile(), validate SUDO_USER
- Fix command injection in lib/tools/open.js — replace exec() with execFile(), validate SUDO_USER
- Fix prototype pollution in Configuration.set/unset via proto key traversal #6089
- Fix HttpInterface env stripping never executing (WEB_STRIP_ENV_VARS) #6089
Bug Fixes
- Rewrite TreeKill: single ps snapshot + in-memory tree build, eliminates race conditions. SIGKILL escalation now targets surviving child processes directly instead of re-walking a dead tree #6084
- Fix [object Object] env vars leaked to fork mode subprocesses #6073
- Fix Windows home path: use os.homedir() instead of HOMEPATH/HOMEDRIVE env vars #6106
- Fix Windows TreeKill callback consistency
- Fix missing BPM monitoring injection in Bun cluster mode (ProcessContainerBun.js)
- Fix ReferenceError crash in Bun cluster console overrides when disable_logs is true
- Fix CliAuth wrong credentials error displaying "undefined" instead of error message
Features
- Add
--ftpoption topm2 servefor directory listing (python http.server style)
Dependencies
- Add OpenTelemetry tracing as direct dependencies (@opentelemetry/api, sdk-node, auto-instrumentations-node)
- Upgrade OpenTelemetry packages to latest
- Update pidusage from 3.0.2 to 4.0.1
- Upgrade ws to ^8.18.0, eventemitter2 to ^6.4.9
- Remove needle, enquirer, promptly, mkdirp, source-map-support, sprintf-js, fclone from npm dependencies
Testing
- Add Docker parallel test runner with Node.js and Bun support
- Add Windows test suite (test/windows.sh)
- Add OpenTelemetry tracing tests
- Add TreeKill unit tests
- Add test scripts for internalized modules (bpm, axon, axon-rpc, io-agent)
- Fix test compatibility for Node.js 22+ and Bun
- CI matrix: Node.js 18, 20 + latest