Skip to content

Releases: Xipher-Labs/walter-os

Walter-OS v0.7.0

Choose a tag to compare

@github-actions github-actions released this 11 Jun 11:52
9f47f61

[0.7.0] - 2026-06-11

🚀 Features

  • Add preview evidence verification (#503)

🐛 Bug Fixes

  • Clarify headscale capver diagnostics (#502)

📚 Documentation

  • Disposition CodeReview Scorecard alert (#505)
  • Add OpenSSF badge filing runbook (#508)
  • Document Headscale helper rollout (#509)
  • Document MaintainedID repo-age signal (#510)

⚙️ Miscellaneous Tasks

  • Reduce stale Actions run noise (#507)

Walter-OS v0.6.2

Choose a tag to compare

@github-actions github-actions released this 09 Jun 10:24
644fc04

[0.6.2] - 2026-06-09

🐛 Bug Fixes

  • Fail closed on LLM runtime mismatch (#435)
  • Harden capability state audit (#446)
  • Tighten Control Tower history writes (#448)
  • Allow service teardown off placement (#452)
  • Parse router env inline comments (#453)
  • Harden cloudflared ready probes (#456)
  • Exclude LiteLLM DB probe session (#458)
  • Guard preview wait timeout size (#461)
  • Harden semantic gate scans (#462)
  • Fail closed on empty Forgejo authors (#463)
  • Reject duplicate preview deploy keys (#465)
  • Reject unsafe preview plan actions (#466)
  • Accept prefixed preview evidence paths (#467)
  • Parse spaced nanobanana capability keys (#454)
  • Reject duplicate agent model domains (#482)
  • Narrow Control Tower test directory type (#487)
  • Restrict review action codex output (#489)
  • Route consensus vote models

📚 Documentation

  • Fix Node 24 metadata span (#478)
  • Make review loop capability-aware (#483)
  • Clarify review-loop routing (#486)
  • Make PR template review routing aware (#488)

🧪 Testing

  • Reject mutable markdownlint install (#455)
  • Guard Headscale capver compose path (#460)

Walter-OS v0.6.1

Choose a tag to compare

@f0x1777 f0x1777 released this 07 Jun 13:42
f044a9a

Walter-OS v0.6.1 Release Notes

Date: 2026-06-07
Status: Alpha patch release

v0.6.1 is a post-v0.6 operational hardening release. It does not change the
v1.0 stability promise. It tightens release hygiene, documents the current
security follow-ups, and makes AI-provider selection easier for operators who
do not have every supported model/tool account.

Highlights

  • Audit-chain follow-ups: signed rows, cross-day close/verify flows, Loki
    verification, and optional Sigstore Rekor anchoring for daily roots.
  • Provider selection: walter providers configure --category llm now supports
    direct Gemini alongside LiteLLM, Anthropic/Claude, OpenAI/Codex/GPT, and
    Ollama/local.
  • AI-stack resilience: the release documents that Claude and Codex are
    supported agent surfaces, not mandatory dependencies, and ships the AI-stack
    watchdog through the Walter-VM alerting Ansible role.
  • Security tracking: GitHub code-scanning alerts were grouped into follow-up
    issues #390 through #396 and dispositioned before the final v0.6.1 cut.
    Some Scorecard alerts remain visible until GitHub settings, repository age,
    or external OpenSSF processes catch up.
  • Capability-token hygiene: the daily audit now checks session capability
    state for malformed JSON, stale token directories, missing material, and
    unsafe key/token permissions.

Upgrade

Preview first:

walter-os upgrade --dry-run

Upgrade the local install:

walter-os upgrade --target v0.6.1

For a Walter-VM host, keep service rollouts explicit:

walter-os upgrade --all --snapshot --yes
walter-os upgrade --all --service n8n

Do not restart or migrate every Docker service automatically. Name each service
that should roll forward.

Provider Selection

Run the LLM provider wizard after upgrading:

walter providers configure --category llm

Current LLM slugs:

  • litellm: self-hosted gateway that can proxy multiple vendors.
  • anthropic: direct Anthropic/Claude account.
  • openai: direct OpenAI/Codex/GPT account.
  • gemini: direct Gemini account.
  • ollama: local inference for security, compliance, or offline workflows.

The wizard writes provider choices to ~/.config/walter-os/providers.yaml and
activates matching private env vars. Secrets stay outside the repository.

Final Hardening Included

The final v0.6.1 cut also includes these post-release-candidate hardening
slices:

  • walter doctor now treats Infisical machine identity as the preferred clean
    install secrets runtime while preserving legacy secrets.env migration
    warnings, mode-0600 checks, and exported key syntax.
  • The Walter-VM alerting Ansible role now deploys ai-stack-watchdog.sh.
  • The daily supply-chain audit now validates capability-token runtime state and
    documents operator recovery in docs/operational/capability-tokens.md.

Still Open

These issues remain intentionally open after v0.6.1:

  • #122: broader audit/supply-chain hardening epic still has remaining slices.
  • #123, #225, #235, #342, #363: product and operations follow-ups that are not
    required to cut this patch release.

Walter-OS v0.6.0

Choose a tag to compare

@github-actions github-actions released this 02 Jun 20:28
39788b4

[0.6.0] - 2026-06-02

🚀 Features

  • Add session state foundation
  • Add session timeout hook
  • Add capability key foundation
  • Add capability token CLI
  • Enforce capability tokens in hooks
  • Add default skill capabilities
  • Require operator challenge for cap mint
  • Dark-first OKLCH token foundation for Control Tower
  • Shared status + async primitives for Control Tower
  • Re-skin live surfaces to the status language
  • Token-theme Grafana embeds + shared TopNav
  • Overview grid, shared nav adoption, and themed pages
  • Add one-command upgrade flow
  • Add sandbox provider shim
  • Add hook sandbox profile
  • Add skill sandbox profile
  • Add high-tier invisible sandbox mounts
  • Wire sandboxed hook gates
  • Add optional Authentik SSO profile
  • Add Forgejo Actions runner profile
  • Add optional Langfuse profile
  • Add optional Listmonk devrel profile
  • Add optional ntfy notification profile
  • Add Renovate self-hosted profile
  • Bake faster-whisper into Hermes STT image
  • Add audit-chain telemetry dashboard
  • Add multi-model routing preferences
  • Add Codex startup doctor probe
  • Add SLSA provenance for releases
  • Add audit chain writer
  • Append audit rows from hook gates
  • Add hackathon repo profile preset (#295)
  • Improve upgrade UX summary

🐛 Bug Fixes

  • Rotate stale idle sessions first
  • Harden session state writes
  • Fail closed on session write errors
  • Guard session test clock
  • Reject malformed session timestamps
  • Enforce idle expiry without reset
  • Report session delete failures
  • Preserve PHI session mode
  • Add session timeout recovery path
  • Allow session restart through expiry
  • Wire session slash command arguments
  • Revoke capability material on expiry
  • Harden capability cleanup paths
  • Resolve openssl and lock session starts
  • Harden install preview and session locks
  • Allow openssl override in hook env
  • Invalidate legacy sessions without caps
  • Reclaim stale session locks by age
  • Keep openssl override out of data env
  • Allow restart of unsafe session state
  • Cleanup stale startup key material
  • Fail non-apt installs without openssl
  • Harden session startup recovery
  • Make session lock wait configurable
  • Add entropy to session id fallback
  • Fail closed on capability chmod errors
  • Enforce session expiry during cap verify
  • Harden capability mint and expiry checks
  • Block direct capability mint entrypoints
  • Block raw capability key access
  • Block read access to capability key material
  • Block writes to capability session state
  • Narrow capability state path guard
  • Block quoted capability mint commands
  • Close capability token review gaps
  • Block ANSI-C quoted capability mint
  • Prioritize capability gate classification
  • Normalize capability gate shell escapes
  • Allow non-mint capability commands
  • Block braced variable capability subcommands
  • Block dynamic capability subcommands
  • Block expanded capability guard bypasses
  • Keep capability blocks terminal
  • Block dynamic cap script mint bypass
  • Block variable-root capability key globs
  • Tighten capability gate review fixes
  • Narrow dynamic mint detection
  • Validate cap list and command substitutions
  • Harden capability token access checks
  • Block relative capability key paths
  • Map macos python dependency
  • Validate capability claim schema
  • Block shell-expanded cap minting
  • Block interpreter cap mint bypasses
  • Hide capability token storage paths
  • Require operator context for cap mint
  • Reject revoked capability copies
  • Block split walter-os mint commands
  • Close capability CLI review gaps
  • Require complete capability host coverage
  • Align capability enforcement with high-tier scope
  • Cover multiedit and ssh git capabilities
  • Cover absolute network commands and cap bootstrap
  • Expand capability egress coverage
  • Fail closed and parse network flags
  • Normalize paths and gh host capabilities
  • Parse positional network hosts
  • Restrict cap mint bootstrap exemption
  • Require pattern caps for approvals
  • Close capability hook parse gaps
  • Normalize capability command hosts
  • Parse shell separators for caps
  • Require caps for every gh host
  • Cover notebook and ssh cap gaps
  • Fail closed on cap tokenization
  • Detect backtick egress commands
  • Close capability hook bash bypasses
  • Cover shell wrapped egress hosts
  • Parse gh host capability targets
  • Block shell-expanded network commands
  • Cover pip and ssh proxy egress
  • Cover curl resolve and path reentry
  • Gate expanded network command words
  • Close package and git parser gaps
  • Cover pip value flags
  • Ignore curl data urls
  • Fail closed on expanded command words
  • Protect capability trust root
  • Tighten capability scope matching
  • Stop host parsing at shell separators
  • Block network command substitutions
  • Detect network commands by position
  • Align capability egress subcommands
  • Inspect wrapped network commands
  • Include curl socks proxy scopes
  • Unwrap command options for egress
  • Handle env split-string wrappers
  • Account for git ssh overrides
  • Align git remote capability gating
  • Detect shell body network commands
  • Clarify capability hook failures
  • Normalize bracketed ipv6 hosts
  • Gate capability bearer token reads
  • Harden capability high-tier detection
  • Gate capability secret reads
  • Require network coverage for pattern caps
  • Require caps for bash protected writes
  • Fail closed on capability inspection gaps
  • Make default skill caps transactional
  • Reset session after default cap mint failure
  • Gate default skill cap loader minting
  • Anchor default skill capability examples
  • Harden default skill capability loading
  • Gate skill cap env override
  • Block broad capability state reads
  • Share protected path capability policy
  • Merge shared protected path policy
  • Protect shared path policy from Bash
  • Close capability hook review gaps
  • Fail closed on invalid protected policy
  • Capture default cap mint errors
  • Sanitize session paths with extglob enabled
  • Allow cap mint help noninteractively
  • Align cap mint challenge docs
  • Allow cap mint stdout redirection
  • Drop unstructured non-English CSVs from ui-ux-pro-max corpus
  • Correct ui-ux-pro-max SKILL.md corpus manifest to real files
  • Translate ui-ux-pro-max quick-reference activation to English
  • Correct false check-pinning.py claim and stale counts in spec
  • Translate stray Chinese cells in ui-ux-pro-max icons/styles CSVs
  • Rewrite ui-ux-pro-max SKILL.md corpus manifest to real files
  • Add 'When to use' section to both new skills (L2-2 conformance)
  • Resolve UX skill review threads
  • Derive repo root for vendored pin audit
  • Harden vendored skill pin audit
  • Harden vendored skill pin checks
  • Cancel SSE reconnect timer and guard setState on unmount
  • Render HA health state as visible text, not colour-only
  • Surface error + retry on AlertFeed and AgentStatusBoard async legs
  • Add error + AsyncSurface triad to ModeIndicator
  • Stop interval stale-closure from masking stale data on error
  • Root ModeIndicator in a labelled section landmark
  • Raise contrast of tiny uppercase metadata labels
  • Address control tower review feedback
  • Keep history version badge server-rendered
  • Harden upgrade preflight checks
  • Address upgrade review followups
  • Fetch target tags from all remotes
  • Run VM upgrade payload under bash
  • Avoid repeated cap hook tokenization
  • Preserve empty cap mint shell tokens
  • Resolve sandbox profile root fallback
  • Address sandbox review nits
  • Harden sandbox provider execution
  • Align sandbox shim review feedback
  • Require executable sandbox providers
  • Simplify sandbox provider lookup
  • Reject Darwin sandbox provider overrides
  • Materialize sandbox profiles atomically
  • Isolate hook sandbox filesystem roots
  • Preserve caller runtime directory mode
  • Avoid moving loopback into nsjail
  • Harden hook profile capability and key rules
  • Allow macos hook sandbox scratch writes
  • Validate sandbox runtime directories
  • Tighten macos hook sandbox writes
  • Clean materialized sandbox profiles
  • Use valid firejail whitelist rules
  • Mount dev null in nsjail profile
  • Preserve sandbox cleanup under errexit
  • Harden sandbox materialization edges
  • Clean sandbox path materialization failures
  • Harden sandbox profile materialization
  • Fail closed sandbox profile materialization
  • Merge sandbox provider hardening
  • Harden sandbox profile materialization
  • Simplify sandbox run validation
  • Guard scratch placeholder grep paths
  • Protect sandbox key scan fifo
  • Harden sandbox key scan wait
  • Merge hook sandbox profile base
  • Escape sandbox regex quotes
  • Narrow session key scan skips
  • Deny writes to sandboxed key files
  • Fail closed on nsjail root materialization
  • Remove stale invisible mount cleanup
  • Escape firejail invisible blacklists
  • Fail closed on missing invisible controls
  • Harden invisible path parsing
  • Require default invisible policy
  • Merge skill sandbox profile base
  • Fail closed on invisible chmod errors
  • Recreate invisible directory placeholders
  • Handle colon-bearing invisible removals
  • Address sandbox hook review gaps
  • Escape sandbox hook control chars
  • Harden sandbox hook JSON escaping
  • Repair Codex skill metadata
  • Accept CRLF skill frontmatter
  • Make Forgejo runner socket opt-in
  • Align Forgejo runner default labels
  • Route Langfuse through loopback
  • Align Langfuse service profile details
  • Simplify Langfuse MinIO healthcheck
  • Align Langfuse port docs and healthcheck
  • Use Listmonk default config path
  • Align ntfy notifications profile
  • Make ntfy network external
  • Keep install dry-run jq-compatible
  • Repair scorecard publishing permissions
  • Harden install platform checks
  • Restore release workflow integrity tests

📚 Documentation

  • Align session start semantics
  • Clarify capability mint approval path
  • Clarify capability high-tier classifier
  • Anchor capability regex example
  • Align skill capability regex examples
  • Align cap mint refusal message
  • Flag impeccable reference files that need the un-vendored CLI
  • Correct pinned-refs header + note CSVs are grep-not-parse
  • Spec for Control Tower UX/UI redes...
Read more

Walter-OS v0.5.1

Choose a tag to compare

@github-actions github-actions released this 31 May 02:50
d4c6cbf

[0.5.1] - 2026-05-30

Walter-OS v0.5.0

Choose a tag to compare

@github-actions github-actions released this 22 May 08:29
61b354d

[0.5.0] - 2026-05-22

⚙️ Miscellaneous Tasks

  • Untrack report.log + gitignore all .log files (closes #144) (#158)

Walter-OS v0.4.5

Choose a tag to compare

@github-actions github-actions released this 21 May 23:59
bace659

Quick follow-up release after v0.4.4 — closes the four follow-up issues filed during the v0.4.4 cross-review cycle + a real production-bug fix the hardened tests caught.

What's in this release

PR Closes Summary
#138 #133, #134 _shell_quote (printf %q) + _xml_escape helpers in install.sh — REPO_ROOT shell-escape in env-file + audit_script XML-escape in launchd plist
#139 #136 CF Access apps for every site that imports admin_auth_gate (added tower + metabase + postiz; renamed hs → headscale-admin)
#140 #132 (spec) Spec + ADR 0017 for OpenClaw transitive-dep shrinkwrap shipping (runtime impl deferred)
#141 Hardened escape-helpers bats — caught a real bash 5.2 production bug that shipped in v0.4.4

The bash 5.2 bug worth highlighting

v0.4.4 shipped _xml_escape which uses bash parameter expansion ${var//pattern/replacement} to escape XML-reserved characters. On bash 5.2+ (Ubuntu 24.04+, current GitHub Actions runners, recent Homebrew on macOS), an unescaped & in the replacement string is interpreted as "the matched text" — so ${v//</&lt;} produced <lt; instead of &lt;. Every plist render on a bash-5.2 host was producing broken XML.

The bug stayed invisible in v0.4.4 because the existing bats tests ran on a macOS bash where patsub_replacement defaults off. PR #141's hardened tests + the CI wiring (the tests existed but weren't actually being run) caught it the first CI cycle. Fix: shopt -u patsub_replacement at the top of _xml_escape.

Cross-review discipline

Codex was the FIRST reviewer on every PR in this batch — not catch-up. Real R1 findings landed in each, including the bash 5.2 bug, the npm link direction, registry pinning on shrinkwrap generation, the CI workflow not actually running the new bats files, the canary-not-in-injected-payload test gap, and the headscale-admin/hs naming mismatch in CF Access.

Upgrading from v0.4.4

Drop-in. The bash 5.2 fix is local to _xml_escape and only matters at install time (when the plist is written). Existing installs that already wrote plists on bash 5.1- aren't affected; future installs on bash 5.2+ now produce correct XML.

Follow-ups still open

  • #132 — OpenClaw shrinkwrap implementation (spec landed in #140; impl deferred to a separate PR after operator sign-off on Candidate A vs B).

🤖 Released after Codex-R1-first reviews on all 4 follow-up PRs.

Walter-OS v0.4.4

Choose a tag to compare

@github-actions github-actions released this 21 May 22:42
854b7e6

v0.4.4 closes the 2026-05-21 external-review remediation cycle: 11 findings (1 BLOCKER + 7 MAJOR + 3 MINOR) closed across 9 merged PRs + 5 follow-up issues filed for residual gaps.

This is the first release where the cross-review discipline (Copilot R1 → Codex R2 standard → collaborative R3) was actually exercised end-to-end. The catch-up Codex run during the cycle surfaced 6 BLOCKERs + 8 MAJORs the Copilot-only rounds missed — including an eval-based RCE that had been introduced in an interim R2 fix. v0.4.4 is the proof point that R2-Codex-standard isn't a fallback; it's a required filter for cross-file data-flow bugs.

What's in the box

Security tooling

  • PR #124 — Hook checksums v2 (content SHA256). The daily audit now detects in-place modification of any ~/.claude/settings.json hook script + emits CRIT. Includes the _safe_expand_env_path allowlist that replaced an eval-based path resolver Codex caught as an RCE vector. Closes F1 BLOCKER.
  • PR #129 — MCP server-registry drift detection. The daily audit now diffs mcp/servers.json against a baseline and flags command / args / url / env / disabled / headers / contexts / load changes (HIGH) + trust changes (MEDIUM) + additions (HIGH). Closes the audit P2 no-op.
  • PR #127 — OpenClaw runtime npm install SHA512-verified via node one-liner (no coreutils dependency) + --ignore-scripts to block lifecycle execution + --registry=https://registry.npmjs.org/ pin.
  • PR #130admin_auth_gate Caddy snippet on 17 admin dashboards. Requires either Tailscale tailnet IP OR Cloudflare-edge IP with valid CF-Access-Authenticated-User-Email header. Header-spoof prevented by tying header acceptance to CF edge ranges. CF ranges centralized in a single env var.

Framework + spec

  • PR #114 — Severity-gate + bounded auto-merge spec/plan/ADR 0015. Four-tier classifier (BLOCKER / MAJOR / MINOR / COSMETIC) + 8-condition gate (C1-C8) with a 10-slug failure enum + explicit BLOCKER action sequence (issue create + PR comment + no auto-close). Runtime implementation tracked separately.

DevEx + operability

  • PR #128 — install.sh: 10 call sites migrated from eval-based run to argv-form run_args; new run_sh (no inner eval) + write_file (preserves trailing newline). Arg-count guards on all three.
  • PR #125 — installer enforces yq presence + mikefarah-flavor on every code path (preflight, --check, install, --step 1, post-snap install). Arch detection (amd64 / arm64 / arm / ppc64le / s390x) for the binary-download fallback. Preflight hard-fails on missing yq (no race with hook writing).
  • PR #126SECURITY.md supported-versions table refreshed (0.4.x current, 0.3.x previous, 0.2.x/0.1.x EOL); CVSS v3.1 ≥ 7.0 explicitly defined; walter / walter-os dual-binary naming clarified.
  • PR #131walter-os doctor three-state secrets probe (ok / warn / fail); new docs/operational/observability.md documenting per-service host privileges with explicit docker.sock + privileged: true + /dev/kmsg caveats; semgrep workflow digest-pinned.

Security fixes caught mid-cycle (Codex cross-review)

  • CRIT (would have shipped) — eval on a $-prefixed hook command from settings.json → arbitrary command execution during the daily audit. Fixed with literal-pattern allowlist (_safe_expand_env_path).
  • MAJORbash -c "$WALTER_OS_HOME..." interpolation in three cmd_doctor sites → command injection via crafted env. Fixed with positional-arg passing.
  • MAJOR — Docker bridge range overlap in default WALTER_LAN_CIDR → any container could reach the auth gate as a "LAN" client. Reverted to 192.168/16-only default.
  • MAJORenvsubst expanding Caddy native {$VAR} placeholders → broken matchers + every admin dashboard down on first install. Fixed with explicit SHELL-FORMAT allowlist.

Process notes

  • AGENTS.md cross-review pattern was respected from the catch-up Codex run forward. Earlier rounds violated R2-Codex-standard by running Copilot-only; that violation is documented in the CHANGELOG so the lesson sticks.
  • Merge required temporarily relaxing branch protection (strict + require_last_push_approval + required_approving_review_count) for the 9-PR batch. All settings restored immediately post-merge.

Follow-ups opened during this cycle (tracking, not blockers for v0.4.4)

  • #132 — OpenClaw transitive-dep lockfile (residual gap from #127's SHA512 verification)
  • #133 — install.sh shell-escape REPO_ROOT in env-file render
  • #134 — install.sh XML-escape audit_script in plist render
  • #136tier-4.md tower CF Access claim contradicts Caddy gate

Upgrading from v0.4.3

This release is a strict superset of v0.4.3. No breaking changes to the public install flow or compose files; operator-visible behavior changes:

  • walter-os doctor now shows ⚠ instead of ✗ when only legacy plaintext secrets.env is present (clean Infisical installs report ✓).
  • walter-os audit (next-day run) emits INFO hook-checksums-v1-schema once, then auto-migrates the baseline to v2 on the next walter-os baseline-hooks.
  • New installs: yq (mikefarah/yq specifically) must be installed before ./install.sh. Remediation steps in the installer error path.

Supply-chain artifacts

The release-security workflow auto-attached:

  • checksums.sha256 — SHA256 of every release artifact
  • checksums.sha256.cosign.bundle — cosign signature over the checksums file (verifiable with cosign verify-blob)
  • walter-os-v0.4.4.sbom.cdx.json — CycloneDX SBOM for the release

🤖 Released after 11 Copilot rounds + 5 Codex rounds across 9 PRs.

Walter-OS v0.4.3

Choose a tag to compare

@github-actions github-actions released this 21 May 16:12
c4abed4

[0.4.3] - 2026-05-21

Walter-OS v0.4.2

Choose a tag to compare

@github-actions github-actions released this 21 May 14:40
88af559

[0.4.2] - 2026-05-21