Skip to content

v0.1.222

Choose a tag to compare

@github-actions github-actions released this 15 Sep 16:18
· 1407 commits to main since this release
f4d1044

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://getomg.xyz/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.222

Verified updates after the organization transfer

OMG now lives at omg-cli/omg. This release adds
update notices after successful interactive commands and selects the correct
release-signing identity across the repository transfer.

Updating existing installations

Binaries through v0.1.221 have the previous signing repository compiled into
their verifier. They need one verified in-place upgrade using the updated
canonical installer or their package manager.
This replaces the program while retaining configuration and shell integration.
After that transition, direct installations can use omg self-update normally.
Do not bypass provenance verification to cross the signing-identity boundary.

Command update notices

Successful interactive commands can display a cached notice directing users to
omg self-update; installing a shell hook is optional. The first eligible
invocation starts a bounded background check, and a later invocation can display
the result. Checks and notices are limited to once daily. There is no automatic
installation or blocking foreground network request.

Piped output, quiet/JSON/help/internal protocols, self-update, CI and root
sessions remain silent. Failed commands preserve their exit status. Set
OMG_NO_UPDATE_CHECK=1 to opt out. Package-managed installations should use
their package manager for upgrades.

Security and release verification

  • Select the original signing repository through v0.1.221 and omg-cli/omg
    afterward. A failed signature check never retries against another identity.
  • Validate ownership and write permissions for the GitHub CLI verifier path,
    its parents and resolved target; elevated updates reject another user's helper.
  • Restore discovery of the original published attestations after the transfer,
    without rebuilding, re-signing or replacing existing release artifacts.
  • Exercise a real published v0.1.220 to v0.1.221 upgrade in release smoke tests.

CI and QEMU fixes since v0.1.221

  • Scope the trusted QEMU reporter to case receipts so nested transaction evidence
    is not parsed as a case result. Missing or invalid evidence still fails closed.
  • Use the exact versioned Arch publisher image URL after the rolling latest URL
    rotated; retain the reviewed image digest and publisher signature.
  • Run the pinned, checksum-verified Gitleaks CLI after the organization transfer,
    preserving secret detection without the Action wrapper's organization license.

Changes since v0.1.221

The complete non-merge commit ledger below links the implementation and test
changes included in this release. Merge commits are available in the
full comparison.
Release preparation itself updates the package version and these notes.

  • 753cd2d0 test(security): verify published release upgrade path (#424)
  • 1bc1dacd fix(security): scope QEMU reporter to case receipts (#425)
  • e42e29e9 fix(ci): run pinned Gitleaks CLI for organization repositories
  • f2b8a5d7 fix(qemu): use versioned archive for signed Arch image
  • d799152f feat(cli): show update notices after interactive commands
  • 3e668e46 fix(update): bind release verification to the organization cutover
  • 0c3f1883 test(update): use validated release tag in installer gate fixture
  • 95359eb4 fix(update): reject untrusted attestation helper paths
  • 11ab0800 fix(docs): point update notices at the organization
  • b5c6e4e3 chore(release): prepare v0.1.222 verified organization updates
  • 8a495f5e fix(ci): verify organization-signed upgrade sources
  • 88aa3bf8 fix(ci): place update notice tests after public items
  • 18569411 test(release): exercise explicit verified installer migration

See the release overview, migration instructions and complete commit ledger.

Built-in updates and organization migration

  • Show daily cached update notices after successful interactive commands, without requiring a shell hook or blocking on network access.
  • Select exactly one release-signing repository by version across the move to omg-cli/omg; retain verification for existing releases.
  • Require trusted ownership and write permissions for the self-updater's GitHub CLI verifier and its parent paths.
  • Document the one-time verified in-place upgrade for binaries through v0.1.221; subsequent direct-install upgrades use omg self-update.
  • Point update and release links directly at the organization.

CI and QEMU

  • Verify the actual published v0.1.220 to v0.1.221 self-update path.
  • Parse only reviewed case receipts in the trusted QEMU reporter.
  • Restore Arch guest preparation using the exact versioned publisher URL, retaining the reviewed digest and signature.
  • Run the pinned, checksum-verified Gitleaks CLI after the organization transfer.
  • Update installer signer and public-file integrity regression expectations for the reviewed migration.

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.222-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.222-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.222-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.222-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.222-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.222-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.222-*.sha256

Provenance: every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.222-x86_64-linux-arch.tar.gz -R omg-cli/omg --source-ref refs/tags/v0.1.222 --signer-workflow omg-cli/omg/.github/workflows/release.yml

install.sh requires GitHub CLI and successful provenance verification.
omg self-update also fails closed unless provenance verifies; its explicit
unverified-provenance override is a deliberate security downgrade.

Manual Installation

Download and verify exactly the archive matching your platform. For example,
after the checksum and provenance checks above, on Arch x86_64:

tar -xzf omg-v0.1.222-x86_64-linux-arch.tar.gz
cd omg-v0.1.222-x86_64-linux-arch
sudo cp omg /usr/local/bin/

Full Changelog: https://github.com/omg-cli/omg/blob/v0.1.222/docs/changelog.md

Release validation

The downloaded archives and SBOM were verified against source commit f4d1044e6e25c619284feafa76996fb26179ea39, tag v0.1.222 and the organization release workflow.