# pm2 changelog > Node.js/Bun Production Process Manager with a built-in Load Balancer. - Vendor: Unitech - Category: Infrastructure & DevOps - Official site: https://pm2.keymetrics.io/docs/usage/quick-start/ - Tracked by: What's New (https://whatsnew.fyi/product/pm2) - Harvested from: GitHub (Unitech/pm2) - Entries below: 10 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## Releases ### v7.0.4 - Date: 2026-08-24 - Version: v7.0.4 - Original notes: https://github.com/Unitech/pm2/releases/tag/v7.0.4 - Permalink: https://whatsnew.fyi/product/pm2/releases/v7.0.4 - **added** — Start .ts apps with Node.js native type stripping when bun is not installed (Node.js >= 22.18 / 23.6, --experimental-strip-types auto-injected on 22.6+) with ts-node fallback now resolved from the app's own dependencies - **fixed** — Fix pm2 start --container / --container --dist crashing with Cannot find module due to wrong require depth in Containerizer.js - **fixed** — Bump js-yaml 4.3.0 → 4.3.1 - **fixed** — Fix overlapping reloads colliding on the _old_ slot and orphaning a cluster worker by refusing a reload while one is in progress - **fixed** — Ignore stale exit events from a replaced process to fix double start on Windows with shutdown_with_message - **fixed** — Fix retrying in NaNms kill log and ~1ms poll spam when kill_retry_time is unset by falling back to KILL_RETRY_TIME constant (100ms, overridable via PM2_KILL_RETRY_TIME) - **fixed** — Fix pm2 start/restart RPC hanging forever when a cluster worker dies before its online event by having executeApp conclude on exit-before-online - **fixed** — Surface the daemon's actual error in CLI output instead of masking everything as Process not found - **changed** — Pin OpenTelemetry package versions in pm2 install-otel and re-emit legacy HTTP span tags (http.method, http.status_code, http.target) dropped by @opentelemetry/instrumentation-http >= 0.220 - **removed** — Remove dead code including promise.min.js polyfill, IsAbsolute.js, unused Java/Ruby Dockerfile templates, and always-false win64 platform checks ##### 7.0.4 ###### Features - Start `.ts` apps with Node.js native type stripping when bun is not installed (Node.js >= 22.18 / 23.6, `--experimental-strip-types` auto-injected on 22.6+); `ts-node` fallback now resolved from the app's own dependencies ###### Bug Fixes - Fix `pm2 start --container` / `--container --dist` crashing with `Cannot find module` — wrong require depth in `Containerizer.js` from the v7 promptly internalization - Bump `js-yaml` 4.3.0 → 4.3.1 - Fix overlapping reloads colliding on the `_old_` slot and orphaning a cluster worker — a reload is now refused while one is in progress #6129 - Ignore stale exit events from a replaced process — fixes double start on Windows with `shutdown_with_message` #6142 - Fix `retrying in NaNms` kill log and ~1ms poll spam when `kill_retry_time` is unset — fallback to `KILL_RETRY_TIME` constant (100ms, `PM2_KILL_RETRY_TIME` overridable) - Fix `pm2 start`/`restart` RPC hanging forever when a cluster worker dies before its `online` event (bad `node_args`, boot OOM) — executeApp now concludes on exit-before-online - Surface the daemon's actual error in CLI output instead of masking everything as `Process not found` - Pin OpenTelemetry package versions in `pm2 install-otel` and re-emit legacy HTTP span tags (`http.method`, `http.status_code`, `http.target`) dropped by `@opentelemetry/instrumentation-http` >= 0.220 ###### Core Refactor - Remove dead code: `promise.min.js` polyfill (native `Promise`), `IsAbsolute.js` (native `path.isAbsolute`), unused Java/Ruby Dockerfile templates, always-false `win64` platform checks ### v7.0.3 - Date: 2026-06-29 - Version: v7.0.3 - Original notes: https://github.com/Unitech/pm2/releases/tag/v7.0.3 - Permalink: https://whatsnew.fyi/product/pm2/releases/v7.0.3 - **fixed** — Fix daemon failing to boot on Node.js < 14.18 by switching embedded vizion from node:-scheme requires to bare specifiers ###### Bug Fixes - Fix daemon failing to boot on Node.js < 14.18 — embedded `vizion` used `node:`-scheme requires; switched to bare specifiers ### v7.0.2 - Date: 2026-06-29 - Version: v7.0.2 - Original notes: https://github.com/Unitech/pm2/releases/tag/v7.0.2 - Permalink: https://whatsnew.fyi/product/pm2/releases/v7.0.2 - **fixed** — Fix pm2 serve returning 403 Forbidden on Windows due to traversal guard using hardcoded / separator - **fixed** — Fix pm2 ls table misalignment when username exceeds user column width caused by cli-tableau's truncate() miscounting ANSI bytes - **fixed** — Fix long status lines wrapping on narrow terminals by making Common.printOut ANSI-aware and cropping output to terminal width - **added** — Show pm2 ls host-metrics line by default - **added** — Add adaptive layout to pm2 ls that picks the widest layout fitting the terminal (full, condensed, or ultra-compact mini) - **changed** — Filter pm2 ls host-metrics line to only list network interfaces carrying traffic - **changed** — Replace pm2 ls host-metrics mem free with ram usage percentage and add GPU memory/temperature when reported - **changed** — Show per-interface network errors/drops in pm2 ls host-metrics line when non-zero - **removed** — Remove old vizion module and 3 submodules - **changed** — Replace bundled pm2-sysmonit module and systeminformation with lib/tools/SysMetrics.js for Linux/macOS - **security** — Bump js-yaml 4.1.1 to 4.3.0 to fix quadratic-complexity DoS in merge-key handling - **security** — Bump ws 8.20.0 to 8.21.0 to fix uninitialized-memory disclosure and tiny-fragment DoS - **security** — Bump @pm2/js-api 0.8.0 to 0.8.1 to pull in patched ws@8.21.0 ##### 7.0.2 ###### Bug Fixes - Fix `pm2 serve` returning 403 Forbidden on Windows — traversal guard used hardcoded `/` separator #6109 - Fix `pm2 ls` table misalignment when a username exceeds the `user` column width — cli-tableau's `truncate()` miscounts ANSI bytes, leaking bold into the `watching` column - Fix long status lines (e.g. `Applying action … on app […]`) wrapping on narrow terminals — `Common.printOut` now ANSI-aware crops single-line TTY output to terminal width (piped output unaffected) ###### Features - `pm2 ls` host-metrics line now shown by default`pm2 update`) - `pm2 ls` adaptive layout: picks the widest layout that fits the terminal — full → condensed → new ultra-compact `mini` (`id · name · status · cpu · mem`) — and caps the `name` column so long names can't overflow the table - `pm2 ls` host-metrics line only lists network interfaces carrying traffic (hides idle utun/awdl/bridge/anpi/unused en*) - `pm2 ls` host-metrics line: replaced `mem free` with `ram usage` (%), added GPU memory/temperature when reported, per-interface network errors/drops shown when non-zero ###### Core Refactor - Drop old vizion module, refactor to support only git and drop 3 submodules - Replace the bundled `pm2-sysmonit` module and `systeminformation` with `lib/tools/SysMetrics.js` (Linux/macOS); `pm2 slist`/`getSystemData` and the Docker metrics path now read this collector. Covered by `test/programmatic/sysmetrics.mocha.js` ###### Security - Bump `js-yaml` 4.1.1 → 4.3.0 — fixes quadratic-complexity DoS in merge-key handling (GHSA-h67p-54hq-rp68) #6122 - Bump `ws` 8.20.0 → 8.21.0 — fixes uninitialized-memory disclosure and tiny-fragment DoS (GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p) #6116 - Bump `@pm2/js-api` 0.8.0 → 0.8.1, pulling in patched `ws@8.21.0` (its transitive `ws` was pinned to the vulnerable 7.x). Production deps are now advisory-free (`npm audit --omit=dev` clean) ### v7.0.1 - Date: 2026-05-02 - Version: v7.0.1 - Original notes: https://github.com/Unitech/pm2/releases/tag/v7.0.1 - Permalink: https://whatsnew.fyi/product/pm2/releases/v7.0.1 - **fixed** — Fix Python and other non-Node interpreter regression on Ubuntu where bun runtime detection used naive substring matching that incorrectly matched paths containing 'bun', causing routing through ProcessContainerForkBun.js and SyntaxError when Python tried to parse the JS container - **fixed** — Display max_memory_restart in pm2 describe output when set - **fixed** — Add missing port option to StartOptions TypeScript declaration - **fixed** — Fix incorrect file permissions on openrc.tpl template - **fixed** — Fix Windows cmd.exe regression by reverting bin/pm2 launchers to #!/usr/bin/env node shebang to restore compatibility with npm's pm2.cmd shim ##### 7.0.1 ###### Bug Fixes - Fix Python (and other non-Node) interpreter regression on Ubuntu: bun runtime detection used a naive `includes('bun')` substring check that matched any path containing the letters "bun" — most notably `/home/ubuntu/...`. Affected paths were routed through `ProcessContainerForkBun.js` and crashed with `SyntaxError: unterminated string literal` when Python tried to parse the JS container. Anchored the match to the end of the interpreter path (`=== 'bun'` or `/bun$/`) in both `lib/God/ForkMode.js` and `lib/Common.js` #5990 - Display `max_memory_restart` in `pm2 describe` output when set #5925 - Add missing `port` option to `StartOptions` TypeScript declaration #6045 - Fix incorrect file permissions on `openrc.tpl` template (0755 → 0644) #5957 - Fix Windows cmd.exe regression: revert `bin/pm2*` launchers to `#!/usr/bin/env node` shebang (was polyglot `#!/bin/sh`). Polyglot worked on Linux/macOS but broke npm's `pm2.cmd` shim on Windows — `cmd.exe` can't interpret `/bin/sh` shebang and failed with `'"/bin/sh"' is not recognized as an internal or external command`. PowerShell's auto-generated `pm2.ps1` shim happened to call `node` directly so it kept working, masking the regression. Bun-only Linux/macOS users (no Node installed) need to symlink `node` to `bun` (`sudo ln -s $(which bun) /usr/local/bin/node`) — same workaround used in the project's bun test Dockerfile. Documented in README #6108 ### v7.0.0 - Date: 2026-05-02 - Version: v7.0.0 - Original notes: https://github.com/Unitech/pm2/releases/tag/v7.0.0 - Permalink: https://whatsnew.fyi/product/pm2/releases/v7.0.0 - **removed** — Require Node.js >= 18.0.0 and drop Node.js 16 support - **changed** — Internalize pm2-axon, pm2-axon-rpc, pm2-io-bpm, pm2-io-agent, and fclone as local modules to reduce supply chain surface - **changed** — Internalize pm2-multimeter and charm into lib/tools/multimeter with zero external dependencies - **added** — Add Bun runtime support with ProcessContainerBun.js and ProcessContainerForkBun.js - **changed** — Replace needle with native fetch for CliAuth and TAR publish - **changed** — Replace enquirer with lightweight built-in prompt for boilerplate selector - **changed** — Replace promptly with built-in lib/tools/prompt - **changed** — Replace mkdirp with native fs.mkdirSync({ recursive: true }) - **changed** — Replace source-map-support with native process.setSourceMapsEnabled() - **changed** — Replace sprintf-js with template literals in Dashboard - **changed** — Replace url.parse() with native URL constructor in Serve, Utility, and CliAuth - **removed** — Drop auto source map file detection in Common.prepareAppConf - **security** — Fix ReDoS vulnerability in Config.js string-to-array split regex (CVE-2025-5891) - **security** — Update proxy-agent to 6.5.0 and basic-ftp to 5.3.1 (CVE-2026-27699) - **security** — Fix command injection in WebAuth.js open() by replacing exec() with execFile() - **security** — Fix command injection in PM2IO.js open() by replacing exec() with execFile() and validating SUDO_USER - **security** — Fix command injection in lib/tools/open.js by replacing exec() with execFile() and validating SUDO_USER - **security** — Fix prototype pollution in Configuration.set/unset via __proto__ key traversal - **fixed** — Fix HttpInterface env stripping never executing with WEB_STRIP_ENV_VARS - **fixed** — Rewrite TreeKill to use single ps snapshot and in-memory tree build to eliminate race conditions and improve SIGKILL escalation - **fixed** — Fix [object Object] env vars leaked to fork mode subprocesses ##### 7.0.0 ###### Breaking Changes - Require Node.js >= 18.0.0 (dropped Node.js 16 support) ###### Core Refactor - Internalize pm2-axon, pm2-axon-rpc, pm2-io-bpm, pm2-io-agent, fclone as local modules (reduced supply chain surface) - Internalize pm2-multimeter and charm into lib/tools/multimeter (zero external deps) - Add Bun runtime support (ProcessContainerBun.js, ProcessContainerForkBun.js) - Replace `needle` with native `fetch` (CliAuth, TAR publish) - Replace `enquirer` with lightweight built-in prompt (boilerplate selector) - Replace `promptly` with built-in lib/tools/prompt - Replace `mkdirp` with native `fs.mkdirSync({ recursive: true })` - Replace `source-map-support` with native `process.setSourceMapsEnabled()` - Replace `sprintf-js` with template literals (Dashboard) - Replace `url.parse()` with native `URL` constructor (Serve, Utility, CliAuth) - Remove `fclone` npm dep, use internalized module - Drop auto source map file detection in Common.prepareAppConf ###### Security - CVE-2025-5891 Fix ReDoS in Config.js string-to-array split regex #6075 - CVE-2026-27699 Update proxy-agent to 6.5.0, basic-ftp to 5.3.1 #6088 - Fix command injection in WebAuth.js open() — replace exec() with execFile() #6089 - Fix command injection in PM2IO.js open() — replace exec() with execFile(), validate SUDO_USER - Fix command injection in lib/tools/open.js — replace exec() with execFile(), validate SUDO_USER - Fix prototype pollution in Configuration.set/unset via __proto__ key traversal #6089 - Fix HttpInterface env stripping never executing (WEB_STRIP_ENV_VARS) #6089 ###### Bug Fixes - Rewrite TreeKill: single ps snapshot + in-memory tree build, eliminates race conditions. SIGKILL escalation now targets surviving child processes directly instead of re-walking a dead tree #6084 - Fix [object Object] env vars leaked to fork mode subprocesses #6073 - Fix Windows home path: use os.homedir() instead of HOMEPATH/HOMEDRIVE env vars #6106 - Fix Windows TreeKill callback consistency - Fix missing BPM monitoring injection in Bun cluster mode (ProcessContainerBun.js) - Fix ReferenceError crash in Bun cluster console overrides when disable_logs is true - Fix CliAuth wrong credentials error displaying "undefined" instead of error message ###### Features - Add `--ftp` option to `pm2 serve` for directory listing (python http.server style) ###### Dependencies - Add OpenTelemetry tracing as direct dependencies (@opentelemetry/api, sdk-node, auto-instrumentations-node) - Upgrade OpenTelemetry packages to latest - Update pidusage from 3.0.2 to 4.0.1 - Upgrade ws to ^8.18.0, eventemitter2 to ^6.4.9 - Remove needle, enquirer, promptly, mkdirp, source-map-support, sprintf-js, fclone from npm dependencies ###### Testing - Add Docker parallel test runner with Node.js and Bun support - Add Windows test suite (test/windows.sh) - Add OpenTelemetry tracing tests - Add TreeKill unit tests - Add test scripts for internalized modules (bpm, axon, axon-rpc, io-agent) - Fix test compatibility for Node.js 22+ and Bun - CI matrix: Node.js 18, 20 + latest ### v6.0.14 - Date: 2025-11-26 - Version: v6.0.14 - Original notes: https://github.com/Unitech/pm2/releases/tag/v6.0.14 - Permalink: https://whatsnew.fyi/product/pm2/releases/v6.0.14 - **fixed** — Fixed version of @pm2/pm2-version-check - **security** — Update js-yaml to address CVE-2025-64718 - **changed** — Replace fs.R_OK with fs.constants.F_OK - Fixed version of @pm2/pm2-version-check #6055 - CVE-2025-64718 Update js-yaml - replace fs.R_OK with fs.constants.T_OK #6012 #6019 ### v6.0.13 - Date: 2025-09-22 - Version: v6.0.13 - Original notes: https://github.com/Unitech/pm2/releases/tag/v6.0.13 - Permalink: https://whatsnew.fyi/product/pm2/releases/v6.0.13 - Fix blessed package import ### v6.0.12 - Date: 2025-09-22 - Version: v6.0.12 - Original notes: https://github.com/Unitech/pm2/releases/tag/v6.0.12 - Permalink: https://whatsnew.fyi/product/pm2/releases/v6.0.12 - **removed** — Remove npm-shrinkwrap in favor of fixed dependencies versions - **fixed** — Fix pm2 monit crash - #6037 Drop npm-shrinkwrap in favor of fixed dependencies versions - #5577 fix pm2 monit crash ### v6.0.11 - Date: 2025-09-11 - Version: v6.0.11 - Original notes: https://github.com/Unitech/pm2/releases/tag/v6.0.11 - Permalink: https://whatsnew.fyi/product/pm2/releases/v6.0.11 - **changed** — Replace package-lock.json with npm-shrinkwrap.json - **fixed** — Allow updating namespaced pm2 NPM modules with @org/module-name format - #6034 replace package-lock.json by npm-shrinkwrap.json - #5915 fix allowing to update namespaced pm2 NPM module (@org/module-name) ### v6.0.10 - Date: 2025-09-02 - Version: v6.0.10 - Original notes: https://github.com/Unitech/pm2/releases/tag/v6.0.10 - Permalink: https://whatsnew.fyi/product/pm2/releases/v6.0.10 - revert #5971 #6031