0.27.0
First run
These builds are not signed with a paid Apple or Microsoft certificate, so
both systems stop you the first time. Neither message is a finding about
this file — every installer's SHA-256 is under Checksums.
macOS — you will be told the app is "damaged". It is not. macOS shows
that exact wording for any app it cannot trace to a paid Apple Developer ID,
and the dialog's only obvious button moves it to the Trash. Do not use it.
On macOS 15 (Sequoia) and later there is no right-click → Open bypass; Apple
removed it. Drag the app to Applications, then either open
System Settings → Privacy & Security and click Open Anyway, or run:
/usr/bin/xattr -dr com.apple.quarantine /Applications/ShellPilot.appThat clears the download flag and nothing else — the app's signature stays
intact and verifiable with codesign --verify --strict --deep. The full
path is deliberate: a Homebrew or pip xattr earlier on your PATH may not
support -r.
Windows — SmartScreen will warn. Choose More info → Run anyway.
Downloads
Windows
| File | Notes |
|---|---|
ShellPilot-0.27.0-setup.exe |
Installer with desktop and Start-menu shortcuts. Pick this one if unsure. |
ShellPilot-0.27.0-portable.exe |
Single file, no install, keeps its data beside the .exe — runs from a USB stick |
macOS
| File | Notes |
|---|---|
ShellPilot-0.27.0-arm64.dmg |
Apple Silicon (M1 and later) |
ShellPilot-0.27.0-x64.dmg |
Intel Macs |
Linux
| File | Notes |
|---|---|
ShellPilot-0.27.0-x86_64.AppImage |
Any distribution — chmod +x and run |
ShellPilot-0.27.0-amd64.deb |
Debian and Ubuntu — sudo apt install ./ShellPilot-0.27.0-amd64.deb |
Source for the bundled OpenVPN
ShellPilot bundles OpenVPN on macOS and Linux. OpenVPN is GPL-2.0, so the
corresponding source for the exact build in these installers is published
here as openvpn-2.6.22-source.tar.gz — the pinned upstream commit,
unmodified, with its SHA-256 in the table below. scripts/build-openvpn.sh
in this repository is the recipe that turns it into the shipped binary.
Antivirus scan
These builds are unsigned, so every release is scanned before publishing.
| Scanner | Result |
|---|---|
| Microsoft Defender (Windows runner) | no threats found |
ClamAV ClamAV 1.5.3/28117/Tue Sep 8 06:26:31 2026 |
clean |
| VirusTotal (70+ engines) | per-file reports below |
ShellPilot-0.27.0-setup.exeShellPilot-0.27.0-portable.exeShellPilot-0.27.0-x64.dmgShellPilot-0.27.0-arm64.dmgShellPilot-0.27.0-x86_64.AppImageShellPilot-0.27.0-amd64.deb
One or two detections from minor engines are normal for an unsigned
Electron installer. Verify the SHA-256 of what you downloaded against
the value listed below, or build from source.
Checksums
These are the whole reason an unsigned build is still safe to trust: they
prove the file you have is the file this workflow built. Check yours before
running it.
shasum -a 256 <file> # macOS, Linux
certutil -hashfile <file> SHA256 # Windows| File | SHA-256 |
|---|---|
ShellPilot-0.27.0-amd64.deb |
7cc3f13d873f2be71507b2903c10a08eebb94471fb46b24180de0cb80f0f673c |
ShellPilot-0.27.0-arm64.dmg |
73b0d8a5998c3c3378fb1b01e374e0ac1779611879d75d99826ad96659b3c9ad |
ShellPilot-0.27.0-portable.exe |
b7677d9ab9bc75484d2c82f4560024260dfc275831484bc90d295725784d7edf |
ShellPilot-0.27.0-setup.exe |
f071c21a1d36c31d87fcf193d31eed9886b4a9414082866eaa5752224a010f30 |
ShellPilot-0.27.0-x64.dmg |
4ab2ce410f65a47bc1f28427f391a3315776075ed0154d58b5251c83e8bdc4a6 |
ShellPilot-0.27.0-x86_64.AppImage |
ba512a6ab6c4a8e8ac1b99ddbe80f3d76702df40a82e19a5c43399ca564dc349 |
openvpn-2.6.22-source.tar.gz |
e0eac30be2308340564507f056a0090e467c5e78ac80d64a6604cbfbe1a8aa48 |
The .blockmap files are build metadata, not downloads — they describe
binary deltas between versions and are only read by an updater. The source
archives are a snapshot of the repository, not a build.
Full Changelog: v0.26.0...v0.27.0