Skip to content

CLODEx 1.16.0 Community Observed 7

Pre-release
Pre-release

Choose a tag to compare

@mereyabdenbekuly-ctrl mereyabdenbekuly-ctrl released this 17 Jul 22:03
9813113

CLODEx 1.16.0-communityobserved7 is a separate prerelease for testing the Russian beta interface and the new required first-launch privacy choice for anonymous product statistics.

This is not a stable release. The macOS application is ad-hoc signed but not Apple-notarized, Windows binaries are not Authenticode-signed, Linux packages have no CLODEx vendor signature, auto-update is excluded, and managed CLODEx website sign-in is disabled.

What changed since Community Observed 6

  • Added a blocking privacy screen before onboarding or normal IDE use.
  • The primary action is Allow anonymous statistics; Continue without statistics remains clearly visible.
  • Added System / English / Русский (beta) selection directly on the first-launch screen.
  • Telemetry starts only when the current consent version and the anonymous level are stored together.
  • Existing Community Observed 6 profiles are asked once after upgrading, including profiles that enabled the older checkbox.
  • Anonymous statistics can be disabled or re-enabled later in Settings without signing in.
  • PostHog remains backend-only; renderer capture, person profiles, GeoIP enrichment, session recording, exceptions, account identification, remote config, surveys, full telemetry, and AI tracing are disabled.
  • Lifecycle events no longer inspect the host process list in this distribution.
  • Quick Task, automations, agent retry/recovery, local/cloud execution, Remote Control escalation, and generated-app model calls remain blocked until the first-run choice is saved.
  • The packaged-ASAR validator now binds the consent version, UI declaration, and person-profile disable marker.

Privacy boundary

When anonymous statistics are allowed, only centrally allowlisted product events, bounded counters/timings, enum metadata, app version, platform, architecture, and a pseudonymous installation identifier may be sent.

Prompts and messages, source code, commands, tool arguments, file paths, URLs, API keys and credentials, error text, feedback text, and session recordings are not collected by this community-observed telemetry lane.

Downloads

Platform File SHA-256
macOS Apple Silicon clodex-community-observed-1.16.0-communityobserved7-arm64.dmg 3f1227308e39394caae9ef00a9e1969c68eb25161f05ffc4d4bbbca88b73f650
macOS Intel clodex-community-observed-1.16.0-communityobserved7-x64.dmg 484640ade29e8cab53fd2f5c9bd1f1af6d6244109fbb6a4537ad90a0515893e8
Windows x64 clodex-community-observed-1.16.0-communityobserved7-x64-setup.exe 44337f3a4bdb2f8c5f866c4e1c3a7bb9008d4e99b77ffe8b0b8a9b43a32e6f2e
Debian / Ubuntu x64 clodex-community-observed_1.16.0-communityobserved7_amd64.deb b9a9d8df1562878dc44110c8ddf3c215414987285f47f65ec4d0aa7ecb911aed
Fedora / RHEL x64 clodex-community-observed-1.16.0.communityobserved7-1.x86_64.rpm 7e768a17f26eb64c3b6eff6f39b7c0edd8099760da95bedad6f6122ace09155b
Validation evidence clodex-community-observed-1.16.0-communityobserved7-evidence.zip d6c39bffe883b1342738773797e2a20329f4c8c85d64084511549b1082568694

Download SHA256SUMS.txt from this release and verify the selected file before opening it.

First launch

  1. Choose System, English, or Русский (beta).
  2. Review the exact anonymous-statistics boundary.
  3. Select Allow anonymous statistics or Continue without statistics.
  4. Change the decision later in Settings → Account if needed.

What to test

  1. Fresh profile: confirm the privacy screen blocks onboarding and normal IDE use until either choice succeeds.
  2. Language: switch between System, English, and Русский (beta) on the privacy screen and verify persistence after restart.
  3. Allow path: confirm the IDE opens and Settings can subsequently disable anonymous statistics.
  4. Decline path: confirm the IDE opens without PostHog traffic and the choice can later be changed in Settings.
  5. Upgrade path: start from an observed6 profile and confirm the new versioned choice appears exactly once.
  6. Exercise providers/models, Max/Ultra modes, terminal, browser, Git, MCP approvals, Quick Task, automations, recovery, and restarts after completing the choice.
  7. Report untranslated text, blocked-function bypasses, duplicate events, unexpected network requests, or regressions without including API keys or private source code.

Build identity and evidence

  • Version: 1.16.0-communityobserved7
  • Exact source: 981311304fb4c648ebbaa0b85fbed0602aab2c9f
  • Change: Community Observed 6 source → Community Observed 7 source
  • Canonical build: GitHub Actions run 29615260553
  • Four platform jobs passed exact-source validation, bounded assembly, and upload.
  • Outer Actions artifact digests, every internal SHA256SUMS entry, source/version/platform binding, updater exclusion, notices, CycloneDX SBOMs, consent declaration, renderer no-op, and person-profile disablement passed the byte-level audit.
  • The evidence archive contains the per-platform manifests, validation reports, SBOMs, warnings, checksums, and audit report.

Installation safety

  • macOS: verify the checksum, open the DMG, and copy the app to Applications. If Gatekeeper warns, use Finder's per-application Control-click → Open review path.
  • Windows: verify the checksum and use the installer-specific SmartScreen review if Windows reports an unknown publisher.
  • Linux: install the DEB or RPM matching the distribution.
  • Do not disable Gatekeeper, SmartScreen, Defender, or other operating-system protections globally.