Skip to content

Releases: omg-cli/omg

v0.1.224

Choose a tag to compare

@github-actions github-actions released this 23 Sep 18:43
f0d8cb5

Beta preview

OMG is approaching its beta release. Core workflows are documented and exercised across supported targets, while CLI flags and on-disk formats may still change before beta.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later pre-beta releases.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://getomg.xyz/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.224

See full changelog for details.


Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.224-x86_64-linux-arch.tar.gz
Debian (APT 6) x86_64 omg-v0.1.224-x86_64-linux-debian.tar.gz
Ubuntu (APT 6) x86_64 omg-v0.1.224-x86_64-linux-ubuntu.tar.gz
Debian 13 / Ubuntu 26.04 (APT 7) x86_64 omg-v0.1.224-x86_64-linux-debian-trixie.tar.gz
Fedora/RHEL x86_64 omg-v0.1.224-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.224-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.224-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.224-*.sha256

Provenance: every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.224-x86_64-linux-arch.tar.gz -R omg-cli/omg --source-ref refs/tags/v0.1.224 --signer-workflow omg-cli/omg/.github/workflows/release.yml

install.sh requires GitHub CLI and successful provenance verification.
omg self-update also fails closed unless provenance verifies; its explicit
unverified-provenance override is a deliberate security downgrade.

Manual Installation

Download and verify exactly the archive matching your platform. For example,
after the checksum and provenance checks above, on Arch x86_64:

tar -xzf omg-v0.1.224-x86_64-linux-arch.tar.gz
cd omg-v0.1.224-x86_64-linux-arch
sudo install -m 0755 omg omgd /usr/local/bin/

Full Changelog: https://github.com/omg-cli/omg/blob/v0.1.224/docs/changelog.md

v0.1.223

Choose a tag to compare

@github-actions github-actions released this 16 Sep 12:33
321b302

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://getomg.xyz/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.223

Matching CLI and daemon updates

Every Linux and macOS release archive now includes both omg and omgd.
The built-in updater requires both from the same checksum- and provenance-verified
archive, stages both before replacement, prevents concurrent updates, and restores
previous files on reported replacement failures. Each replacement is atomic;
the pair is not one power-loss-atomic filesystem transaction.

Upgrade instructions

For direct installations running v0.1.222, run:

omg self-update
omg self-update --force

The first command runs the old updater, which only replaces the CLI. The second
runs the fixed updater and repairs the daemon installation too. Subsequent updates
replace both binaries in one command. Older installations crossing the signing
repository migration should follow the v0.1.222 migration instructions first.
Package-managed installations should use their package manager instead.

Restart any already-running daemon to load its new executable. For the systemd
user service, use systemctl --user restart omgd.service. For a manually started
daemon, stop that process and run omg daemon. Updating files does not restart
existing processes.

QEMU and CI

Release-candidate QEMU testing also exposed a Debian daemon SIGSEGV during
foreground startup. Request and background status workers could concurrently
access libapt, whose Rust binding documents that it is not thread-safe. Native
APT cache construction, use and destruction now share a process-wide lock;
new tests exercise concurrent native status queries. Pure-Rust lookup paths
remain independent of this lock.

The stricter QEMU check found the missing daemon in the previously published
Ubuntu, Debian and Fedora archives (#433).
The packaging correction passed staged QEMU before this release; published
verification remains a separate requirement before closing that issue.

Every selected Linux guest checks direct and foreground daemon startup, real IPC,
private socket permissions, singleton rejection, graceful shutdown and restart.
Missing evidence fails closed. Missing daemon binaries now produce an explicit
diagnostic in guest logs.

Independent distro lanes remove the wait for unrelated builds. Verified base-image
caching preserves disposable overlays, digest checks and controller isolation.
GitHub-hosted runners replace the Blacksmith trial. Documentation-only changes
avoid unnecessary builds, with exact-commit release gates retained.

Complete changes since v0.1.222

  • 2df007e7: trial Blacksmith Linux runners (#429).
  • 58e7e15b: restore GitHub-hosted runners (#430).
  • ad500149: documentation build selection and quick-gate caching (#431).
  • b8fd7ce0: paired self-updates, all-target daemon packaging, shell startup correction and mandatory QEMU daemon coverage (#432).
  • Release preparation: bump package and lockfile versions, document migration and add missing-daemon diagnostics.

Full comparison.

See the release overview and complete commit ledger.

Daemon updates

  • Serialize native APT cache lifetimes across daemon request and background workers. A Debian QEMU restart exposed a SIGSEGV while both paths could enter libapt concurrently; retain the lock through cache destruction and test concurrent native status queries.
  • Update omg and omgd together from the same verified release archive. Refuse incomplete pairs, stage both binaries before replacing either, serialize concurrent updaters, and restore previous files on replacement failures.
  • Include omgd in every Linux and macOS release archive. Self-update now reports both installed binaries and reminds users to restart an already-running daemon.

CI and QEMU

  • Require real daemon startup, IPC, singleton, shutdown and restart checks in every selected Linux guest, with bounded evidence and mandatory receipts.
  • Explain missing daemon payloads explicitly in guest failure logs; v0.1.222 non-Arch archives do not satisfy the stricter check.
  • Start each distro guest as soon as its own build completes and cache only digest-verified base images.
  • Restore GitHub-hosted runners after the Blacksmith trial, skip documentation-only builds where appropriate, and restore quick-gate caching.
  • Check the current user's daemon socket at shell startup instead of trusting a global process-name match.

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.223-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.223-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.223-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.223-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.223-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.223-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.223-*.sha256

Provenance: every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.223-x86_64-linux-arch.tar.gz -R omg-cli/omg --source-ref refs/tags/v0.1.223 --signer-workflow omg-cli/omg/.github/workflows/release.yml

install.sh requires GitHub CLI and successful provenance verification.
omg self-update also fails closed unless provenance verifies; its explicit
unverified-provenance override is a deliberate security downgrade.

Manual Installation

Download and verify exactly the archive matching your platform. For example,
after the checksum and provenance checks above, on Arch x86_64:

tar -xzf omg-v0.1.223-x86_64-linux-arch.tar.gz
cd omg-v0.1.223-x86_64-linux-arch
sudo install -m 0755 omg omgd /usr/local/bin/

Full Changelog: https://github.com/omg-cli/omg/blob/v0.1.223/docs/changelog.md

v0.1.222

Choose a tag to compare

@github-actions github-actions released this 15 Sep 16:18
f4d1044

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://getomg.xyz/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.222

Verified updates after the organization transfer

OMG now lives at omg-cli/omg. This release adds
update notices after successful interactive commands and selects the correct
release-signing identity across the repository transfer.

Updating existing installations

Binaries through v0.1.221 have the previous signing repository compiled into
their verifier. They need one verified in-place upgrade using the updated
canonical installer or their package manager.
This replaces the program while retaining configuration and shell integration.
After that transition, direct installations can use omg self-update normally.
Do not bypass provenance verification to cross the signing-identity boundary.

Command update notices

Successful interactive commands can display a cached notice directing users to
omg self-update; installing a shell hook is optional. The first eligible
invocation starts a bounded background check, and a later invocation can display
the result. Checks and notices are limited to once daily. There is no automatic
installation or blocking foreground network request.

Piped output, quiet/JSON/help/internal protocols, self-update, CI and root
sessions remain silent. Failed commands preserve their exit status. Set
OMG_NO_UPDATE_CHECK=1 to opt out. Package-managed installations should use
their package manager for upgrades.

Security and release verification

  • Select the original signing repository through v0.1.221 and omg-cli/omg
    afterward. A failed signature check never retries against another identity.
  • Validate ownership and write permissions for the GitHub CLI verifier path,
    its parents and resolved target; elevated updates reject another user's helper.
  • Restore discovery of the original published attestations after the transfer,
    without rebuilding, re-signing or replacing existing release artifacts.
  • Exercise a real published v0.1.220 to v0.1.221 upgrade in release smoke tests.

CI and QEMU fixes since v0.1.221

  • Scope the trusted QEMU reporter to case receipts so nested transaction evidence
    is not parsed as a case result. Missing or invalid evidence still fails closed.
  • Use the exact versioned Arch publisher image URL after the rolling latest URL
    rotated; retain the reviewed image digest and publisher signature.
  • Run the pinned, checksum-verified Gitleaks CLI after the organization transfer,
    preserving secret detection without the Action wrapper's organization license.

Changes since v0.1.221

The complete non-merge commit ledger below links the implementation and test
changes included in this release. Merge commits are available in the
full comparison.
Release preparation itself updates the package version and these notes.

  • 753cd2d0 test(security): verify published release upgrade path (#424)
  • 1bc1dacd fix(security): scope QEMU reporter to case receipts (#425)
  • e42e29e9 fix(ci): run pinned Gitleaks CLI for organization repositories
  • f2b8a5d7 fix(qemu): use versioned archive for signed Arch image
  • d799152f feat(cli): show update notices after interactive commands
  • 3e668e46 fix(update): bind release verification to the organization cutover
  • 0c3f1883 test(update): use validated release tag in installer gate fixture
  • 95359eb4 fix(update): reject untrusted attestation helper paths
  • 11ab0800 fix(docs): point update notices at the organization
  • b5c6e4e3 chore(release): prepare v0.1.222 verified organization updates
  • 8a495f5e fix(ci): verify organization-signed upgrade sources
  • 88aa3bf8 fix(ci): place update notice tests after public items
  • 18569411 test(release): exercise explicit verified installer migration

See the release overview, migration instructions and complete commit ledger.

Built-in updates and organization migration

  • Show daily cached update notices after successful interactive commands, without requiring a shell hook or blocking on network access.
  • Select exactly one release-signing repository by version across the move to omg-cli/omg; retain verification for existing releases.
  • Require trusted ownership and write permissions for the self-updater's GitHub CLI verifier and its parent paths.
  • Document the one-time verified in-place upgrade for binaries through v0.1.221; subsequent direct-install upgrades use omg self-update.
  • Point update and release links directly at the organization.

CI and QEMU

  • Verify the actual published v0.1.220 to v0.1.221 self-update path.
  • Parse only reviewed case receipts in the trusted QEMU reporter.
  • Restore Arch guest preparation using the exact versioned publisher URL, retaining the reviewed digest and signature.
  • Run the pinned, checksum-verified Gitleaks CLI after the organization transfer.
  • Update installer signer and public-file integrity regression expectations for the reviewed migration.

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.222-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.222-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.222-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.222-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.222-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.222-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.222-*.sha256

Provenance: every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.222-x86_64-linux-arch.tar.gz -R omg-cli/omg --source-ref refs/tags/v0.1.222 --signer-workflow omg-cli/omg/.github/workflows/release.yml

install.sh requires GitHub CLI and successful provenance verification.
omg self-update also fails closed unless provenance verifies; its explicit
unverified-provenance override is a deliberate security downgrade.

Manual Installation

Download and verify exactly the archive matching your platform. For example,
after the checksum and provenance checks above, on Arch x86_64:

tar -xzf omg-v0.1.222-x86_64-linux-arch.tar.gz
cd omg-v0.1.222-x86_64-linux-arch
sudo cp omg /usr/local/bin/

Full Changelog: https://github.com/omg-cli/omg/blob/v0.1.222/docs/changelog.md

Release validation

The downloaded archives and SBOM were verified against source commit f4d1044e6e25c619284feafa76996fb26179ea39, tag v0.1.222 and the organization release workflow.

v0.1.221

Choose a tag to compare

@github-actions github-actions released this 15 Sep 05:36
b058c1a

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://getomg.xyz/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.221

Security release: changes since v0.1.220

This release brings the merged security work into an installable build, adds
layered mise configuration and AUR-only updates, and strengthens release
verification. The linked changes below are implementation evidence, not a claim
that untrusted packages become harmless or that OMG supports every mise feature.

Package, runtime and privilege protections

  • Upgrade rustls to 0.23.45 in both product and fuzz lockfiles for
    RUSTSEC-2026-0285,
    published September 14. The fix rejects TLS 1.3 handshake messages at an
    incorrect encryption level. The release audit caught this before publication.

  • AUR builds validate archive identity and metadata before elevation, reject
    unsafe paths and links, and require additional approval and paired-build
    evidence for high-risk payloads. Offline Git source preparation and tainted
    checkout replacement address separate build and host-execution boundaries.

  • Managed npm tools stage with lifecycle scripts disabled and verify available
    registry signature/provenance evidence before activation. Package-scoped
    exceptions remain explicit. pip, Cargo and Go installation paths constrain
    source/configuration inheritance according to their supported policies.

  • Managed tool receipts and entrypoint hashes record what was installed; failed
    activation rolls back and managed links remain within the owned tool root.

  • Privileged operations use validated executable and state paths. Root ignores
    caller-controlled state and trust overrides. Installer subprocesses use Linux
    no-new-privileges controls, and atomic replacement does not preserve set-ID bits.

  • CI/container configuration writers reject redirected destinations and unsafe
    parents. Daemon path failures remain errors. Signed package database handling,
    completion output and nested parsing gained additional validation.

See #394,
#399, and
#414 for scope, tests and limitations.

Features and compatibility changes

  • omg update --aur-only limits Arch updates to AUR packages; it is intended for
    workflows where the distribution's own updater continues to own official
    packages. This does not establish default adoption or complete integration
    with Omarchy. #401
  • Supported mise tool pins, environments and tasks now use layered discovery,
    local/selected-environment overrides and task dependencies. Previously ignored
    layers may now affect a project. Review the
    migration guide
    before upgrading. Unsupported mise constructs are not advertised as parity.
    #403,
    #404
  • Interactive Bash, Zsh and Fish hooks can advise when a newer OMG release is
    available. Daily checks run in the background, offline failures are silent,
    and installation remains explicit. The first check populates a cache for a
    later terminal opening. Set OMG_NO_UPDATE_CHECK=1 before the hook to opt out.
    Notice behavior
  • DNF/RPM inventory observation and cached/check-only update behavior include
    fixes; CLI and platform regression fixtures have been updated accordingly.

CI, QEMU and release verification

  • QEMU controllers move to architecture-pinned Debian Trixie images and require
    QEMU packages at or above Debian's fix for
    CVE-2026-48914
    before parsing guest images or booting. Installed package versions are exported
    with the run evidence; guest distributions remain unchanged.
  • Main-push guest runs consume the same staged artifact decision as preparation,
    preventing unpublished release versions from being selected as published inputs.
  • All eight release prerequisite workflows run on every main push, including
    workflow-only fixes. PR path filtering remains; main trades additional runs for
    complete evidence tied to the exact release commit.
  • Published QEMU inputs now require attestations tied to the repository, tag,
    source commit and release workflow; adjacent checksums alone are insufficient.
  • QEMU runs with UID/GID 65534, no effective capabilities, no-new-privileges and
    seccomp. Root/unfiltered fallbacks are rejected. Guest lifecycle, reboot,
    package transaction and inventory evidence remain separate checked outcomes.
  • Publication requires the latest successful push runs for the exact source
    commit across CI, benchmark, audit, secrets, CodeQL, coverage, Docker and staged
    QEMU. Older green results cannot override a newer failed run.
  • PR smoke/QEMU execution no longer receives Sentry credentials. KVM access and
    GitHub credentials are scoped. A default-branch reporter handles completed
    push/manual/nightly QEMU runs, validates run/attempt identity and reviewed case
    IDs, and creates a harness issue when failure evidence is absent or invalid.
    PR runs cannot invoke the privileged reporter. Only current-main successful
    push evidence can close matching issues.
  • Guest image verification binds publisher signatures to reviewed keys and
    image bytes. Debian cloud images retain an explicit unsigned-checksum
    exception. Reviews expire, with an advance maintenance issue and documented
    renewal procedure. An expired review cannot authorize image parsing.
  • Required inventory and skip policies bind exact inventory digests to expected
    cases. Offline cases use isolated network namespaces; explicitly networked
    cases retain their required behavior. Controller egress rejects private,
    metadata and runner destinations and permits public web traffic plus explicit
    DNS resolvers and configured public NTP servers. Public web destinations are not domain allowlisted.
  • Reset install/remove trials require distinct boot identities, matching initial
    state and health evidence for every trial. Final health admission checks kernel
    and product crash evidence, serial output and controller OOM state. Torn UTF-8
    console bytes do not disable crash-signature detection.
  • Privacy-export fault tests require observed full-storage/read-only conditions,
    injected fsync errors and interruption, preserved prior data and recovery.
    They do not claim whole-system power-loss coverage or physical-disk durability.
  • Main and release-tag rules prevent unreviewed direct main updates, require the
    configured PR checks, and prohibit changing published version tags. CI waits
    for independent release prerequisites before creating an immutable tag.
  • Compiled QEMU dependency caches reduce repeated build work. CodeQL Rust uses
    its supported build mode without the redundant release compilation; Actions
    analysis is separate. Fuzz toolchain/target selection and offline changelog
    generation are repaired.

These are intentional operator contract changes. ARM QEMU still requires an
authorized KVM-capable ARM runner; the published Linux archives are x86_64 and
macOS is ARM64. There is no measured universal security or performance guarantee.
See #413,
#415, and
#417, and
#421.

Complete source history

This ledger includes all 115 non-merge commits after v0.1.220 through 762e496b. It includes maintenance, documentation and intermediate fixes; entries are not counts of distinct security findings. The final comparison also includes later release-documentation and integration commits.

  • 94b31bf6 docs: elevate README to world class and align documentation with code stack (#393)
  • ecf049fe fix(security): land the pending security branch and remediate 2026-09-10 audit findings (#394)
  • bc7fe493 docs: update changelog [skip ci]
  • 04642bf7 Update benchmark results [skip ci]
  • 7dfcd9f8 Harden security boundaries and verify candidates through reviewed QEMU CI
  • abb42d1b Gate QEMU on harness fixtures and update vulnerable release tooling
  • 14e18d90 Fix hosted root and macOS regressions without weak...
Read more

v0.1.220

Choose a tag to compare

@github-actions github-actions released this 09 Sep 17:13
8a2d1f0

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://getomg.xyz/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.220

Review

  • Audit: Verify cross-filesystem migration copies file contents

🐛 Bug Fixes

  • Audit: Copy history across filesystems when atomic migration fails

prepare_system_audit_directory refused to migrate /var/log/omg when

rename(2) returned EXDEV (e.g. btrfs subvolume mounts), failing every

privileged operation until an operator intervened. Fall back to a

byte-verified copy: stage under a temp sibling, preserve ownership and

modes, fsync, verify path/size snapshot, rename into place, then remove

the source. Symlinks and special files still fail closed.

  • Install: Point bootstrap at getomg.xyz and sync installer to the release bucket

👷 CI/CD

  • Release: Verify installer sidecar and stop claiming latest-version early

The new bucket installer upload wrote a hash-only sidecar and printed

latest-version success before that marker was published. Use a standard

sha256sum sidecar, round-trip verify it, and echo installer success only

after the script itself is confirmed.

📚 Documentation

  • Record installer domain repair [skip ci]
  • Record v0.1.219 release verification [skip ci]

🔧 Maintenance

  • Checkpoint generated astra report

🧪 Testing

  • Audit: Restore elevated-path isolation skips

OMG_DATA_DIR is still ignored when running as root, so these fixtures

must not touch the real /var/lib/omg audit log in elevated CI.

Merged pull requests

This release includes every PR merged between v0.1.219 and v0.1.220:

  • #392 chore(release): prepare v0.1.220 — version bump and changelog promotion (d95e47cd)
  • #391 fix(audit): copy audit history across filesystems when atomic migration fails — EXDEV migration plus SHA-256 content-digest verification (08be0a66; commits d651f6d9, 3c31eef4, de64c751)
  • #390 fix(install): point bootstrap at getomg.xyz and sync installer to the release bucket — canonical installer domain and release-bucket installer with sha256 sidecar (1a7f492f; commits 5fd3ce04, 3066811e)
  • #388 chore: checkpoint generated astra report (d7358d89)

Direct-to-main documentation commits are also included: 2e4c05b8, 3caaf155, 3bd9192e ([skip ci]).

Performance

  • Benchmark green on the exact tagged SHA 8a2d1f00 (run 34377481911): search 18.8 ms / 12.3x vs pacman, status 9.8 ms — unchanged from the v0.1.219 baseline. The 0.1.220 changes (audit migration fallback, installer/CI) do not touch the query hot path.
  • The v0.1.219 baseline (search 18.8 ms) reflects the accepted metadata-scan cost from #372; see the v0.1.219 release notes for the regression-gate rationale.

Known limitations

  • Audit migration has not fired on every host: the EXDEV fallback first runs when a privileged operation next needs to move /var/log/omg to /var/lib/omg/audit. If /var/log and /var/lib are on the same filesystem, hosts continue to use the plain atomic rename(2) path.
  • Non-gating CI checks remain red (pre-existing, unchanged): the coverage container (elevated-path isolation), the docker-e2e test_docker_update_check flake, and QEMU arm64 guest legs on runners without /dev/kvm.
  • Dependabot: one high-severity dependency alert on main is still open.
  • omg.latham.cloud/install.sh still serves the legacy installer until the omg-web site redeploys; use https://getomg.xyz/install.sh (canonical) or https://releases.omg.latham.cloud/install.sh (release bucket).

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.220-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.220-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.220-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.220-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.220-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.220-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.220-*.sha256

Provenance (recommended): every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.220-x86_64-linux-arch.tar.gz -R PyRo1121/omg

omg self-update and install.sh perform this check automatically whenever
the GitHub CLI is installed locally.

Manual Installation

Linux/macOS:

tar -xzf omg-v0.1.220-*.tar.gz
cd omg-v0.1.220-*
sudo cp omg /usr/local/bin/

Full Changelog: https://github.com/PyRo1121/omg/blob/main/docs/changelog.md

v0.1.219

Choose a tag to compare

@github-actions github-actions released this 09 Sep 03:10
v0.1.219
646c35e

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://omg.olenlatham.dev/install.sh | bash

What's New in v0.1.219

Merged pull requests (since v0.1.218)

Package manager correctness and freshness:

  • #353 fix(debian): index freshness survives list removal
  • #355 fix(debian): installed state owns its dpkg-status source
  • #356 fix(debian): qualified name[:arch[:component]] lookups on mapped indexes
  • #357 fix(arch): source identity changes invalidate handles/workers/daemons by inequality
  • #359 fix(daemon): persisted status expires without renewing its memory TTL
  • #360 fix(aur): own and validate metadata index bytes before lookup
  • #361 fix(debian): validate FST mapping contents instead of generation sidecars
  • #362 fix(debian): one published snapshot for native and archived views
  • #363 fix(privilege): isolate elevated state instead of transferring ownership
  • #364 fix(arch): detect sync database changes hidden by maximum timestamps
  • #365 fix(arch): reject catalog loads tagged with a later source identity
  • #366 fix(daemon): publish package index and source identity together
  • #372 fix(arch): detect local package metadata changes (desc edits, symlinks)
  • #381 fix(arch): delete versioned source-identity caches on invalidate

CI, benchmarks and release tooling:

  • #374/#375/#382 duration-unit Clippy repairs and distinct QEMU concurrency groups
  • #377 integration of audit checkpoints with current main fixes
  • #379 run shared checks once and remove the redundant Arch lane
  • #380/#383/#384 QEMU transaction and benchmark fixture checkpoints
  • #378 align the enterprise policy fixture with the strict schema
  • #385 fix(bench): headline label resolution plus runtime mutation re-entrancy fix
  • #387 bench: refresh the performance baseline for the accepted metadata-scan cost

Docs and fixtures:

  • #371 docs: correct security claims and operational guidance
  • #373 fix(hooks): require exact generated content before uninstall
  • #386 chore(release): prepare v0.1.219

Performance note

Search benchmarks now measure the end-to-end CLI including the local metadata
observation introduced with #372 (user-selected tradeoff). The refreshed
baseline records 18.8ms search / 12.3x vs pacman on the CI runner. Moving the
catalog observation off the async request path remains a documented follow-up.

Known limitations at release

  • Docker E2E test_docker_update_check remains flaky (pre-existing).
  • QEMU arm64 guest legs intermittently land on runners without /dev/kvm.
  • Coverage-container fixture tests skip when elevated processes ignore caller
    path overrides; they retain non-root coverage in the portable job.

v0.1.218

Choose a tag to compare

@github-actions github-actions released this 04 Sep 15:03
2d8c6f6

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://raw.githubusercontent.com/PyRo1121/omg/main/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.218

🐛 Bug Fixes

  • Cli: Keep redirected output plain
  • Cli: Honor setup skip options
  • Cli: Focus root command discovery
  • Cli: Handle closed output pipes
  • Release: Recover verified R2 syncs
  • Ci: Use matched benchmark control
  • Ci: Account for benchmark uncertainty
  • Ci: Modernize gates and release ownership
  • Ci: Benchmark workflow changes
  • Ci: Retry benchmark history publication
  • Ci: Normalize benchmark regressions against control

📚 Documentation

  • Audit: Record v0.1.217 publication

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.218-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.218-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.218-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.218-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.218-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.218-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.218-*.sha256

Provenance (recommended): every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.218-x86_64-linux-arch.tar.gz -R PyRo1121/omg

omg self-update and install.sh perform this check automatically whenever
the GitHub CLI is installed locally.

Manual Installation

Linux/macOS:

tar -xzf omg-v0.1.218-*.tar.gz
cd omg-v0.1.218-*
sudo cp omg /usr/local/bin/

Full Changelog: https://github.com/PyRo1121/omg/blob/main/docs/changelog.md

v0.1.217

Choose a tag to compare

@github-actions github-actions released this 04 Sep 01:59
2bb9103

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://raw.githubusercontent.com/PyRo1121/omg/main/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.217

🐛 Bug Fixes

  • Cli: Repair update UX and runtime dispatch

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.217-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.217-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.217-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.217-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.217-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.217-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.217-*.sha256

Provenance (recommended): every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.217-x86_64-linux-arch.tar.gz -R PyRo1121/omg

omg self-update and install.sh perform this check automatically whenever
the GitHub CLI is installed locally.

Manual Installation

Linux/macOS:

tar -xzf omg-v0.1.217-*.tar.gz
cd omg-v0.1.217-*
sudo cp omg /usr/local/bin/

Full Changelog: https://github.com/PyRo1121/omg/blob/main/docs/changelog.md

v0.1.216

Choose a tag to compare

@github-actions github-actions released this 03 Sep 20:17
f8e6d89

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://raw.githubusercontent.com/PyRo1121/omg/main/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.216

Style

  • Search: Drop per-row separators, tighten list rhythm
  • Update: Inline source badge in update list rows
  • Policy: Warn about missing policy file once per process
  • Info: Render sync-DB info through the shared kv renderer
  • Test: Rustfmt the R2 --remote rollback assertion (#185)

#181 squash-merged with a cargo fmt --check failure on the new

rollback CLI guard. Reapply rustfmt on current main.

⚠️ Breaking Changes

  • Sanitize remote strings at render boundaries; revert breaking sha2/p256/p384 bump

⚡ Performance

  • Runtimes: Skip vendor fetch for exact version requests

resolve_requested_version returns early when the request is not partial, so exact versions and aliases avoid list_available network work.

✨ New Features

  • Runtimes: Uninstall versions via omg use RUNTIME VERSION --uninstall
  • Hook: Add --uninstall removing shell integration with backup
  • Install: Add --uninstall removing binaries and shell integration
  • Runtimes: Add native Deno management

Install verified Deno release archives, resolve stable aliases and project pins, expose the vendor bin directory without shims, and register Deno across CLI discovery and health checks.

  • Hooks: Resolve project runtime ranges

Read Python and Deno project pins, map compatible requests to installed versions, normalize Java feature pins, and keep each vendor bin directory intact on PATH.

🐛 Bug Fixes

  • Ci: Align tests with current CLI contracts
  • Tui: Sanitize remaining team fields
  • Doctor: Report healthy runs with warnings
  • Sanitize TUI team names
  • Sanitize TUI package versions
  • Ci: Merge main and resolve progress.rs clippy conflict

Take main's later mechanical clippy form (allow reason, take()

clear/drop) and keep this branch's portable dead_code/guard bindings.

  • Ci: Gate fast-path block instead of stubbing for backend-less builds
  • Ci: Repair debian-pure transaction lane call and drop dead import
  • Ci: Satisfy portable clippy gate without touching behavior
  • Ci: Gate elevated fast-path helpers for backend-less feature combos
  • Ci: Un-gate ensure_local_archive_consent for backend-less feature combos
  • Ci: Format tree with pinned rustfmt to unblock Quick Gate
  • Sanitize plain update summary rows
  • Strip bidi controls from PKGBUILD review
  • Tea: Sanitize package versions (#193)

fix(tea): sanitize package versions

  • Sanitize repo field and invisible chars in terminal text

    • Render the tea info Source field through sanitize_terminal_text; repo

from daemon IPC is untrusted like name/version/description/url.

  • Extend sanitize_terminal_text to strip zero-width and invisible

formatting characters (U+200B-200F, U+2060-2064, U+2028/2029, U+FEFF)

in addition to control bytes and bidi overrides/isolates.

  • Add unit tests for the sanitizer (control/OSC, bidi, invisible,

separators, visible multibyte preservation) and harden the tea info

view test with zero-width and repo payloads.

COM-183

  • Sanitize tea package versions
  • Sanitize AUR build package names
  • Sanitize update summary fields
  • Clippy: Clear gate after progress-lane migration (mechanical only)
  • Test: Create GnuPG home with 0700 in round-trip test
  • Secrets: Detect Google OAuth and OpenAI key formats
  • Rollback: Remove historical worktree after successful rebuild
  • Keyserver: Safe getuid and extracted home validation
  • Sbom: Populate component licenses from package databases
  • Team: Back up local omg.lock before a pull overwrites it
  • History: Archive retired transactions instead of dropping them
  • Rust: Stream component archives through disk

Share tar entry safety across runtime and component extraction, and replace Rust's in-memory XZ buffer with a bounded same-filesystem temporary file.

  • Python: Select exact standalone assets

Page through bounded GitHub release results, reject incompatible build variants, preserve Python prerelease identity, and stop an install search after the matching page.

  • Java: Normalize Adoptium feature requests

Accept Java feature pins such as 21 and 21.0, reject unsupported update requests before network access, and keep the extracted JDK bin directory intact.

  • Osv: Scope cache key by ecosystem and validate severity scores
  • Update: Refresh Arch daemon snapshot after sync before probing
  • Clippy: Clear main gate blocked by recent landings
  • Config: Preserve comments and unknown keys on save
  • Doctor: Bound DNS resolution and detect stale db.lck
  • Release: Publish R2 objects to the remote bucket (#184)
  • fix(release): publish R2 objects to the remote bucket

Wrangler 4 defaults r2 object commands to local Miniflare storage, so

sync-r2 could succeed without writing omg-releases. Pass --remote and

stop using stdin as --file=-.

  • Update: Do not leave an AUR spinner live on skipped hosts (#189)

The joined check started a "Checking AUR packages" bar before the lane

could skip. Debian and test_mode never finished it, so the ticker stayed

on screen. Only start that bar when the lane actually runs, and clear it

on official or policy errors. The search picker test now asserts the

real JSON/TTY gate instead of an inverted attended check.

  • Bench: Archive documented update-only hyperfine runs (#188)

#179 rejected every export without search.json, including

./benchmark-hyperfine.sh --update which only writes update.json.

Keep fail-closed for any other scenario set.

  • Search: Never group an explicitly queried language pack
  • Security: Sanitize AUR-controlled strings at info render sites
  • Deps: Restore audited crypto pins broken by renovate #183
  • Release: Publish R2 objects to the remote bucket (#181)

Wrangler 4 defaults r2 object commands to local Miniflare storage, so

sync-r2 could succeed without writing omg-releases. Pass --remote and

stop using stdin as --file=-.

  • Ci: Dispatch Release after tagging so GITHUB_TOKEN actually publishes (#180)

Tag pushes made with GITHUB_TOKEN do not start other workflows, which is why

v0.1.215 never became GitHub Latest after CI tagged it.

📚 Documentation

  • Separate enterprise dashboard policy from local policy.toml

omg enterprise policy show reads dashboard TEAM_POLICIES.

The local host file is omg audit policy, not that command.

  • Correct stale CLI and runtime guidance

🔧 Maintenance

  • Sync Cargo.lock with toml_edit
  • Deps: Update rust dependencies (#183)

🧪 Testing

  • Expose remaining raw team fields
  • Expose raw team names in TUI
  • Expose raw package versions in TUI
  • Ci: Refresh the isolated fuzz lockfile
  • Expose bidi controls in PKGBUILD review
  • Expose raw version text in tea info

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.216-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.216-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.216-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.216-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.216-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.216-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.216-*.sha256

Provenance (recommended): every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.216-x86_64-linux-arch.tar.gz -R PyRo1121/omg

omg self-update and install.sh perform this check automatically whenever
the GitHub CLI is installed locally.

Manual Installation

Linux/macOS:

tar -xzf omg-v0.1.216-*.tar.gz
cd omg-v0.1.216-*
sudo cp omg /usr/local/bin/

Full Changelog: https://github.com/PyRo1121/omg/blob/main/docs/changelog.md

v0.1.215

Choose a tag to compare

@github-actions github-actions released this 03 Sep 02:29
e4d3f42

What's Changed

  • fix(ci): dispatch Release after tagging @PyRo1121 (#180)
  • Record verified hyperfine runs and ship current search ranking @PyRo1121 (#178)
  • fix: remove sudo pacman -U, scrub stale domain, and publish alpha releases as latest @PyRo1121 (#177)
  • fix(ci): require every platform build and ship alpha prereleases @PyRo1121 (#176)
  • fix(ci): unbreak debian Clippy and macOS self-update tests @PyRo1121 (#175)
  • test(audit): pin corrupt-log recovery @PyRo1121 (#172)
  • feat: ungate CLI features and drop the omg license alias @PyRo1121 (#174)
  • docs: streamline README to focus on core product value @PyRo1121 (#173)
  • chore(license): relicense OMG to MIT and remove commercial pricing sheet @PyRo1121 (#171)
  • test(ci): align sync fixtures and fuzz lock @PyRo1121 (#169)
  • fix(daemon): make audit log self-healing and expand fast query resilience @PyRo1121 (#170)
  • fix(arch): align CLI package operations with upstream ALPM standards @PyRo1121 (#167)
  • fix(aur): offload blocking async work @PyRo1121 (#166)
  • fix(arch): verify synchronized database signatures @PyRo1121 (#165)
  • test(aur): pin reviewed PKGBUILD seal @PyRo1121 (#164)
  • fix(aur): install build dependencies without makepkg @PyRo1121 (#163)
  • fix(aur): install required sibling outputs together @PyRo1121 (#162)
  • fix(homebrew): read current native API cache @PyRo1121 (#161)
  • fix(daemon): index Fedora and Homebrew backends @PyRo1121 (#160)
  • test(slsa): pin multi-SAN identity selection @PyRo1121 (#158)
  • fix(tui): serialize prompts through terminal ownership @PyRo1121 (#157)
  • fix(daemon): debounce sequential index refreshes @PyRo1121 (#156)
  • fix(http): retry truncated AUR response bodies @PyRo1121 (#155)
  • fix(http): reject redirect downgrades and retry transient statuses @PyRo1121 (#154)
  • fix: require consent for ALPM collateral package mutations @PyRo1121 (#153)
  • style: rustfmt W12-A-01 update refresh path @cursor[bot] (#152)
  • fix: refresh daemon index before update list reuse (W12-A-01) @PyRo1121 (#151)
  • fix: align test policy helper with the real policy load path (W12-B-03, W12-B-08) @PyRo1121 (#150)
  • fix: handle absolute symlink targets per dpkg semantics (W1-B-01) @cursor[bot] (#149)
  • chore(deps): update rust dependencies @renovate[bot] (#129)
  • fix: handle absolute symlink targets per dpkg semantics (W1-B-01) @PyRo1121 (#148)
  • fix: honor or reject omg daemon --foreground (W10-A2-01) @PyRo1121 (#147)
  • fix: honor telemetry opt-out in usage sync (W8-B-02) @PyRo1121 (#146)
  • fix: guard fish hook invocations and survive malformed pins (W2-B-01, W2-B-02) @PyRo1121 (#143)
  • test(cli): make CLI fixtures hermetic against host state @PyRo1121 (#130)
  • fix: give daemon responses their own size budget (W2-A-03) @PyRo1121 (#145)
  • fix: validate team gist remotes by parsed host (W8-B-03) @PyRo1121 (#144)
  • fix: fail audit --fix loudly on backends that cannot apply it (W3-A-01) @PyRo1121 (#142)
  • fix: make doctor backend-aware and exit nonzero on issues (W3-A-02, W3-A-03) @PyRo1121 (#141)
  • docs: remove omgd --foreground references and fix systemd unit (W2-D-01) @PyRo1121 (#140)
  • fix: quarantine corrupt history.json instead of wedging (W1-A-05) @PyRo1121 (#139)
  • fix: make cargo-deny CI gate fail on violations (W3-B-01) @PyRo1121 (#133)
  • fix: replace yanked spin versions to satisfy deny policy (W3-D-01) @PyRo1121 (#138)
  • fix: verify cached AUR artifacts were built from the reviewed PKGBUILD (SEC-R2-01) @PyRo1121 (#137)
  • fix: verify Rekor SignedEntryTimestamp before trusting entries (W1-A-01) @PyRo1121 (#136)
  • fix: gate team push/pull/status behind the team-sync license (SEC-G1-01) @PyRo1121 (#135)
  • fix: refuse self-update when provenance cannot be verified (SEC-R1-02) @PyRo1121 (#134)
  • fix: SBOM advisory matching respects versions (W5-B-01) @PyRo1121 (#132)
  • fix: atomic tool updates (W4-A-01) @PyRo1121 (#131)
  • fix(aur): validate RPC response boundaries @PyRo1121 (#128)
  • fix(aur): preserve fakeroot metadata in sandbox @PyRo1121 (#127)
  • test(arch): trust unsigned fixture databases @PyRo1121 (#126)
  • test: align stale coverage contracts @PyRo1121 (#125)
  • fix(tui): run package searches in background @PyRo1121 (#124)
  • fix(aur): honor split-package dependency overrides @PyRo1121 (#123)
  • fix(tui): allow repeated package searches @PyRo1121 (#121)
  • fix(ci): unblock leftover debian unit tests after #114 @cursor[bot] (#120)
  • fix(update): refresh metadata before planning changes @PyRo1121 (#122)
  • test(security): accept pinned Rust toolchain action @PyRo1121 (#119)
  • fix(debian): retain locks through cancelled configuration @PyRo1121 (#117)
  • fix(install): require local archive consent first @PyRo1121 (#118)
  • fix(ci): unblock debian/fedora/macos/coverage/e2e @PyRo1121 (#114)
  • fix(deps): restore audited cryptography pins @PyRo1121 (#115)
  • fix(dnf): preserve inventory on metadata failures @PyRo1121 (#111)
  • fix(license): record the expiry clock before JWT exp rejects @cursor[bot] (#113)
  • fix(daemon): select one Debian package candidate @PyRo1121 (#110)
  • fix(ci): actually install nextest after SHA-pinning install-action @PyRo1121 (#93)
  • chore(deps): update rust dependencies @renovate[bot] (#91)
  • fix(debian): offload package configuration @PyRo1121 (#108)
  • fix(license): persist a monotonic expiry clock @PyRo1121 (#112)
  • fix(http): let active downloads exceed total timeout @PyRo1121 (#109)
  • chore: add isolated OMG CLI verification skill @PyRo1121 (#107)
  • fix(debian): preserve pending dpkg updates @PyRo1121 (#106)
  • fix(rust): refresh rolling toolchain channels @PyRo1121 (#104)
  • fix(usage): remove identifiers from sync payload @PyRo1121 (#102)
  • chore(workspace): remove stale targets and platform claim @PyRo1121 (#103)
  • fix(privacy): export durable state and purge telemetry @PyRo1121 (#101)
  • fix(migrate): require consent before import @PyRo1121 (#100)
  • fix(ci): restore baseline checks @PyRo1121 (#105)
  • fix: never collapse unparseable versions to zero (ARCH-R14) @PyRo1121 (#99)
  • fix: route version ordering through panic-free comparator @PyRo1121 (#94)
  • fix: align orphan counting with pacman -Qdt on both paths @PyRo1121 (#96)
  • fix: enforce SecurityPolicy in the AUR update lane @PyRo1121 (#98)
  • feat(runtimes): resolve partial versions to newest matching vendor release @PyRo1121 (#97)
  • fix(brew): survive null cask desc and disambiguate formula/cask installs @PyRo1121 (#95)
  • chore(deps): update rust dependencies @renovate[bot] (#90)
  • chore(deps): bump the dependencies group across 1 directory with 42 updates @dependabot[bot] (#88)
  • [DeployLint demo] Touch protected CI workflow path @PyRo1121 (#89)

Full Changelog: v0.1.214...v0.1.215