Skip to content

0.6.0

Choose a tag to compare

@github-actions github-actions released this 31 Aug 13:29
· 31 commits to main since this release
4a7ecce

Downloads

Windows

File Notes
ShellPilot-0.6.0-setup.exe Installer with desktop and Start-menu shortcuts. Pick this one if unsure.
ShellPilot-0.6.0-portable.exe Single file, no install, keeps its data beside the .exe — runs from a USB stick

macOS

File Notes
ShellPilot-0.6.0-arm64.dmg Apple Silicon (M1 and later)
ShellPilot-0.6.0-x64.dmg Intel Macs

Linux

File Notes
ShellPilot-0.6.0-x86_64.AppImage Any distribution — chmod +x and run
ShellPilot-0.6.0-amd64.deb Debian and Ubuntu — sudo apt install ./ShellPilot-0.6.0-amd64.deb

Source for the bundled OpenVPN

ShellPilot bundles OpenVPN on macOS and Linux. OpenVPN is GPL-2.0, so the
corresponding source for the exact build in these installers is published
here as openvpn-2.6.22-source.tar.gz — the pinned upstream commit,
unmodified, with its SHA-256 in the table below. scripts/build-openvpn.sh
in this repository is the recipe that turns it into the shipped binary.


Antivirus scan

These builds are unsigned, so every release is scanned before publishing.

Scanner Result
Microsoft Defender (Windows runner) no threats found
ClamAV ClamAV 1.5.3/28109/Mon Aug 31 06:24:07 2026 clean
VirusTotal (70+ engines) per-file reports below

One or two detections from minor engines are normal for an unsigned
Electron installer. Verify the SHA-256 of what you downloaded against
the value listed below, or build from source.

Checksums

These are the whole reason an unsigned build is still safe to trust: they
prove the file you have is the file this workflow built. Check yours before
running it.

shasum -a 256 <file>                      # macOS, Linux
certutil -hashfile <file> SHA256          # Windows
File SHA-256
ShellPilot-0.6.0-amd64.deb 7976e1e92a96d514e3c93ab37a5d5c8fa86c37d822cfe082716b66bda9f0101a
ShellPilot-0.6.0-arm64.dmg 027d0839fc6d4e38840faf4b841f05c3e618740c6489a587e4382374c71b60e3
ShellPilot-0.6.0-portable.exe 2e263402885d28657664ec857c2d8b2c2501256024d773bdfaae1538b6576405
ShellPilot-0.6.0-setup.exe f69f02e11157b7bf4fe3b2e7a6622127ada7ec7ec9d2c9ea8b50c7a9c437a2af
ShellPilot-0.6.0-x64.dmg 947fbd6a74c97abcb940bf7d180843ceb9533d2ed678b50ad334604f6052e245
ShellPilot-0.6.0-x86_64.AppImage 8515c037d384549e13b6ffbbc88d1fbde74c98f9851024e6ebe7a50e1e669dcc
openvpn-2.6.22-source.tar.gz e0eac30be2308340564507f056a0090e467c5e78ac80d64a6604cbfbe1a8aa48

The .blockmap files are build metadata, not downloads — they describe
binary deltas between versions and are only read by an updater. The source
archives are a snapshot of the repository, not a build.

Builds are not notarized — the macOS apps are ad-hoc signed, the Windows
ones unsigned. SmartScreen will warn on first run — choose More info → Run
anyway
. On macOS, first run only: right-click the app → Open, or go to
System Settings → Privacy & Security and click Open Anyway. If you would
rather use the Terminal, /usr/bin/xattr -cr /Applications/ShellPilot.app clears
the quarantine flag (spelt with the full path, because a Homebrew or pip xattr
earlier on your PATH may not support -r). Every installer's SHA-256 is
listed under Checksums above, which is the strongest integrity check available
here.


What's Changed

  • VPN tunnels: bundle OpenVPN and Wintun, generate WireGuard keys, watch engine CVEs (0.6.0) by @ZeeshanSultan in #15
  • Fix the two things that broke the 0.6.0 release build by @ZeeshanSultan in #16

Full Changelog: v0.5.1...v0.6.0