CLODEx 1.16.0 Community Observed 7
Pre-releaseCLODEx 1.16.0-communityobserved7 is a separate prerelease for testing the Russian beta interface and the new required first-launch privacy choice for anonymous product statistics.
This is not a stable release. The macOS application is ad-hoc signed but not Apple-notarized, Windows binaries are not Authenticode-signed, Linux packages have no CLODEx vendor signature, auto-update is excluded, and managed CLODEx website sign-in is disabled.
What changed since Community Observed 6
- Added a blocking privacy screen before onboarding or normal IDE use.
- The primary action is Allow anonymous statistics; Continue without statistics remains clearly visible.
- Added System / English / Русский (beta) selection directly on the first-launch screen.
- Telemetry starts only when the current consent version and the anonymous level are stored together.
- Existing Community Observed 6 profiles are asked once after upgrading, including profiles that enabled the older checkbox.
- Anonymous statistics can be disabled or re-enabled later in Settings without signing in.
- PostHog remains backend-only; renderer capture, person profiles, GeoIP enrichment, session recording, exceptions, account identification, remote config, surveys, full telemetry, and AI tracing are disabled.
- Lifecycle events no longer inspect the host process list in this distribution.
- Quick Task, automations, agent retry/recovery, local/cloud execution, Remote Control escalation, and generated-app model calls remain blocked until the first-run choice is saved.
- The packaged-ASAR validator now binds the consent version, UI declaration, and person-profile disable marker.
Privacy boundary
When anonymous statistics are allowed, only centrally allowlisted product events, bounded counters/timings, enum metadata, app version, platform, architecture, and a pseudonymous installation identifier may be sent.
Prompts and messages, source code, commands, tool arguments, file paths, URLs, API keys and credentials, error text, feedback text, and session recordings are not collected by this community-observed telemetry lane.
Downloads
| Platform | File | SHA-256 |
|---|---|---|
| macOS Apple Silicon | clodex-community-observed-1.16.0-communityobserved7-arm64.dmg | 3f1227308e39394caae9ef00a9e1969c68eb25161f05ffc4d4bbbca88b73f650 |
| macOS Intel | clodex-community-observed-1.16.0-communityobserved7-x64.dmg | 484640ade29e8cab53fd2f5c9bd1f1af6d6244109fbb6a4537ad90a0515893e8 |
| Windows x64 | clodex-community-observed-1.16.0-communityobserved7-x64-setup.exe | 44337f3a4bdb2f8c5f866c4e1c3a7bb9008d4e99b77ffe8b0b8a9b43a32e6f2e |
| Debian / Ubuntu x64 | clodex-community-observed_1.16.0-communityobserved7_amd64.deb | b9a9d8df1562878dc44110c8ddf3c215414987285f47f65ec4d0aa7ecb911aed |
| Fedora / RHEL x64 | clodex-community-observed-1.16.0.communityobserved7-1.x86_64.rpm | 7e768a17f26eb64c3b6eff6f39b7c0edd8099760da95bedad6f6122ace09155b |
| Validation evidence | clodex-community-observed-1.16.0-communityobserved7-evidence.zip | d6c39bffe883b1342738773797e2a20329f4c8c85d64084511549b1082568694 |
Download SHA256SUMS.txt from this release and verify the selected file before opening it.
First launch
- Choose System, English, or Русский (beta).
- Review the exact anonymous-statistics boundary.
- Select Allow anonymous statistics or Continue without statistics.
- Change the decision later in Settings → Account if needed.
What to test
- Fresh profile: confirm the privacy screen blocks onboarding and normal IDE use until either choice succeeds.
- Language: switch between System, English, and Русский (beta) on the privacy screen and verify persistence after restart.
- Allow path: confirm the IDE opens and Settings can subsequently disable anonymous statistics.
- Decline path: confirm the IDE opens without PostHog traffic and the choice can later be changed in Settings.
- Upgrade path: start from an observed6 profile and confirm the new versioned choice appears exactly once.
- Exercise providers/models, Max/Ultra modes, terminal, browser, Git, MCP approvals, Quick Task, automations, recovery, and restarts after completing the choice.
- Report untranslated text, blocked-function bypasses, duplicate events, unexpected network requests, or regressions without including API keys or private source code.
Build identity and evidence
- Version: 1.16.0-communityobserved7
- Exact source: 981311304fb4c648ebbaa0b85fbed0602aab2c9f
- Change: Community Observed 6 source → Community Observed 7 source
- Canonical build: GitHub Actions run 29615260553
- Four platform jobs passed exact-source validation, bounded assembly, and upload.
- Outer Actions artifact digests, every internal SHA256SUMS entry, source/version/platform binding, updater exclusion, notices, CycloneDX SBOMs, consent declaration, renderer no-op, and person-profile disablement passed the byte-level audit.
- The evidence archive contains the per-platform manifests, validation reports, SBOMs, warnings, checksums, and audit report.
Installation safety
- macOS: verify the checksum, open the DMG, and copy the app to Applications. If Gatekeeper warns, use Finder's per-application Control-click → Open review path.
- Windows: verify the checksum and use the installer-specific SmartScreen review if Windows reports an unknown publisher.
- Linux: install the DEB or RPM matching the distribution.
- Do not disable Gatekeeper, SmartScreen, Defender, or other operating-system protections globally.