Skip to content

Shadowfetch Linux 5.0.0 (Umbra) - ShadowCode

Choose a tag to compare

@Shadowfetchapps Shadowfetchapps released this 01 Oct 01:15
· 56 commits to main since this release

Shadowfetch Linux 5.0.0 — ShadowCode

One Harness. All Models. Shadowfetch Linux 5.0 is rebuilt around ShadowCode 1.0, a preinstalled desktop coding agent that connects your vendor CLIs and local models in one place. Codename Umbra; the APT suite stays umbra, so 4.1 systems upgrade in place.

Download and verify

ISO shadowfetch-5.0.0-amd64.iso — 4,085,778,432 bytes
SHA-256 2d8a72e044e8061bd616b2b4668425cc4d4ec0480a98975f961c0e58cba95e21
Signature shadowfetch-5.0.0-amd64.iso.asc, key 8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1
Boot BIOS and UEFI, amd64
curl -LO https://www.shadowfetch.com/linux/download/shadowfetch-5.0.0-amd64.iso
curl -LO https://www.shadowfetch.com/linux/download/shadowfetch-5.0.0-amd64.iso.sha256
curl -LO https://www.shadowfetch.com/linux/download/shadowfetch-5.0.0-amd64.iso.asc
sha256sum -c shadowfetch-5.0.0-amd64.iso.sha256
gpg --verify shadowfetch-5.0.0-amd64.iso.asc shadowfetch-5.0.0-amd64.iso

The ISO is larger than GitHub's 2 GB asset limit, so it is served from the Shadowfetch download server; this release carries its checksum, signature, SBOM, manifests and the QA evidence bundle.

What's new

  • ShadowCode 1.0, preinstalled — connect Codex, Claude Code and other CLIs, OpenRouter or on-device models from Settings › Accounts.
  • One gold-and-steel look. Fire and Ice are gone; the old offline Ice behaviour lives on as a separate setting, shadowfetch-agent-network online|offline.
  • Welcome offers only Grok Bot, Hermes and OpenClaw (each optional, latest versions, Hermes and OpenClaw installed into your home folder), then hands off to ShadowCode.
  • Removed: Buzz, shadowfetch-codex, shadowfetch-code-agent (ShadowCode connects the CLIs itself).
  • New platform: Debian testing snapshot 20260929, Linux 7.2.6, Plasma 6.7.4, systemd 262, Mesa 26.1.6.
  • Saving service keys no longer prompts for a keyring password; Mission Control fixes (accurate report provenance, undo after an interrupted mission); build secrets scrubbed from the image.
  • Shadowfetch's own packages are now GPL-3.0-or-later.

Full notes: RELEASE-5.0.0.md

Upgrading from 4.1

sudo apt update
sudo apt full-upgrade

Use apt, not fireproof update, for now: it can stop partway when it installs a new Fireproof (every 4.1 → 5.0 upgrade does), and its plan can currently remove the desktop metapackages during a Debian testing transition. If an update already stopped partway: if apt says fireproofd holds the lock, run sudo systemctl kill --signal=KILL fireproofd.service (or sudo systemctl reboot -i); then sudo dpkg --configure -a, sudo apt full-upgrade, sudo apt install shadowfetch-desktop shadowfetch-creative-base, and restart.

Then log out and back in once, check shadowfetch-agent-network status, and connect your services in ShadowCode. Scripts that called shadowfetch-element, shadowfetch-codex or shadowfetch-code-agent need updating.

Known issues (fixes in 5.0.1)

  • Upgrade with sudo apt full-upgrade, not fireproof update, for now (see above).
  • ShadowCode's window grows each time it opens on Wayland, and on 1366×768 screens the first window is too large. Workaround: maximize it. Fixed in ShadowCode 1.0.1.
  • "database is busy" in Mission Control under very heavy disk load while a mission finishes a step. Retry after a few seconds.
  • Live USB only: KDE's update notifier refreshes package lists ~5 minutes after login (~200 MB download, ~350 MB RAM). Stay offline or run systemctl --user stop app-org.kde.discover.notifier@autostart.service.
  • Security advisory: 4.x ISOs shipped a shared DKMS module-signing key. 5.0 removes it; shadowfetch-doctor flags it on upgraded machines — see the release notes.

Acceptance

18 required pre-publication cases are recorded against this exact ISO: 12 pass, 6 waived by the release owner with written reasons (vendor-account cases for Grok Bot and paid code missions, the upgrade harness's recovery leg, and the ShadowCode soak and 45-minute stress cases that the known issues above explain). Details and evidence are in evidence-bundle-5.0.0.tar.gz; host paths in that evidence were redacted before publication, logged in qa/5.0.0/evidence-redactions.md.