Skip to content

v1.1.2

Choose a tag to compare

@github-actions github-actions released this 08 Sep 01:56
· 42 commits to main since this release

unslop-windows v1.1.2

Security

  • Elevated Binary Authenticode Verification (unslop.ps1): Prioritized protected system directories (SysWOW64, System32) for OneDriveSetup.exe uninstaller resolution. Strictly enforced cryptographic Get-AuthenticodeSignature verification (Status = Valid, CN=Microsoft Corporation) before executing any user-writable %LOCALAPPDATA% binary in an elevated Administrator context (VULN-01).
  • CLI & Parameter Whitelist Validation Loop (unslop.bat): Implemented strict token whitelist checking (-Undo, -Restore, -DryRun, -WhatIf, -KeepXbox, -KeepOneDrive, -KeepTodos, -ClassicContextMenu, -NoRestart, -ForceRestart, -RunDirect), rejecting unlisted parameters and metacharacters with exit code 1 to eliminate command and argument injection vectors (VULN-02).
  • Fail-Closed Offline Architecture (unslop.bat): Removed unauthenticated Invoke-RestMethod script downloads from GitHub CDN. If unslop.ps1 is missing, the launcher halts with a clear error requiring users to extract the full release archive, eliminating supply chain and MITM risks (VULN-03).
  • Reparse Point & Symlink Defense (unslop.ps1): Decoupled log saving fallback now targets isolated $env:LOCALAPPDATA\unslop-windows\logs and inspects directory attributes for [System.IO.FileAttributes]::ReparsePoint, preventing junction/symlink redirection attacks in shared or multi-user environments (OPSEC-01).
  • Release Archive Unit Test Packaging (.github/workflows/release.yml): Added tests/ directory to Compress-Archive in GitHub Actions release packaging step per ADR-010.

Changed

  • Windows Update Hardware Driver & Firmware Preservation (unslop.ps1): Removed ExcludeWUDriversInQualityUpdate = 1 from debloat passes and added proactive removal of any legacy key so Windows Update hardware CVE patches and firmware updates flow freely (REG-02).

Added

  • Security & Privilege Boundary Unit Tests (tests/unslop.Tests.ps1): Added 3 new unit and AST invariant tests verifying Authenticode verification enforcement, reparse point detection and legacy driver policy cleanup, expanding the test suite to 25 passing assertions.

Quick Installation & Usage

  1. Download unslop-windows-v1.1.2.zip from Assets below.
  2. Extract the archive to any directory.
  3. Right-click unslop.bat and choose Run as administrator (or double-click and accept the UAC elevation prompt).
  4. Select an option from the interactive menu:
    • [1] Full Debloat: Remove OneDrive, telemetry and provisioned bloatware.
    • [2] Gamer Preset: Debloat, keep Xbox & Gaming Services (-KeepXbox).
    • [3] Productivity Preset: Debloat, keep OneDrive & Microsoft To-Do (-KeepOneDrive -KeepTodos).
    • [4] Interactive Toggles: Configure custom feature combinations with visual toggle states.
    • [5] Safe Dry-Run Audit: Inspect all changes safely with zero system modifications (-DryRun).
    • [6] Full Restore / Undo: Symmetrically revert all tweaks back to defaults (-Undo).
    • [7] Custom CLI Flags: Manually enter parameter switches (e.g. -KeepTodos -KeepXbox -NoRestart).
    • [0] Exit: Close the launcher.

Verification & Integrity

Verify archive integrity using the published SHA256SUMS.txt:

Get-FileHash .\unslop-windows-v1.1.2.zip -Algorithm SHA256