Releases: Leetxy/ClashXY
Release list
ClashXY 1.9.1 (unsigned prerelease)
Warning
Unsigned prerelease for testing only. The first-party ClashXY application, installer, and generated uninstaller do not yet have a trusted Authenticode signature. Windows may display an unknown-publisher warning. Verify the published SHA-256 checksums before running. This build will be promoted only after code signing and clean Windows 10/11 lifecycle validation are complete.
ClashXY 1.9.1 release candidate
ClashXY is a Windows Mihomo client with general Clash subscription/YAML support
and optional 2S-UI account and device management.
Highlights
- Chinese and English UI with generated locale discovery.
- HTTPS subscriptions, local YAML, custom YAML, profile switching, proxy groups,
rules, connections, logs, providers, and delay testing. - Optional 2S-UI login, dedicated API Token provisioning, managed Client/device
creation, traffic display, pause, token rotation, detach, and deletion. - Windows TUN lifecycle recovery for network changes, sleep/resume, Mihomo crash,
restart, and auto-connect. - Serialized Core lifecycle operations and verified official Mihomo update,
rollback, digest, platform, version, and download-deadline checks. - Native single instance, system tray, close-to-tray, and startup registration.
- Per-machine x64 installer with Simplified Chinese/English setup UI and preserved
application data during upgrades.
Release artifacts
ClashXY-Windows-x64-1.9.1-build15.zipClashXY-Setup-x64-1.9.1-build15.exeSHA256SUMS-1.9.1-build15.txt
The bundled unmodified Mihomo core is v1.19.30 Windows x64 compatible:
- SHA-256:
cf894375dbc00ab6708c1314ac35bbd29059f4c37f315353aaca7f1a9c566de6 - Release and corresponding source: https://github.com/MetaCubeX/mihomo/releases/tag/v1.19.30
- License: GPL-3.0; the binary bundle contains the full license and third-party
notices.
Verification
-
Flutter analysis: no issues.
-
Flutter tests: 73 passed.
-
Windows Release build and administrator manifest: verified.
-
Isolated 2S-UI/Reality/Mihomo/TUN/HTTP lifecycle E2E: three consecutive passes.
-
Installer migration:
1.9.0+14to1.9.1+15; existing application data
hashes unchanged; uninstall cleanup verified. -
Source commit:
ba0dd6a73f25228656b945ae36fe5a931f2cecbc. -
Main-branch build, checksums, and GitHub provenance: https://github.com/Leetxy/ClashXY/actions/runs/32798212814.
Code signing policy
Read the ClashXY code signing policy.
The SignPath Foundation application is pending. No artifact in this prerelease is signed, and provider approval is not claimed. If the application is accepted, signed release pages will include the required acknowledgement:
Free code signing provided by SignPath.io, certificate by SignPath Foundation
Repository rename and provenance
The GitHub account was renamed from ltxy12138-ai to Leetxy after these exact artifacts were built and attested. Current source, issues, and future releases use https://github.com/Leetxy/ClashXY.
The existing v1.9.1 GitHub attestations are immutable and remain bound to their original repository identity. Verify each downloaded artifact separately:
gh attestation verify .\ClashXY-Windows-x64-1.9.1-build15.zip --repo ltxy12138-ai/ClashXY
gh attestation verify .\ClashXY-Setup-x64-1.9.1-build15.exe --repo ltxy12138-ai/ClashXYNew artifacts created after the rename will use Leetxy/ClashXY.
Publication gates
This candidate must not be promoted to the final public release until the
first-party application, installer, and generated uninstaller have the same trusted, timestamped Authenticode publisher and the documented
clean Windows 10/11 lifecycle smoke test is complete.