Skip to content

Releases: y-sor/clean-room-launcher

v0.6.0 — Clean Room Launcher

Choose a tag to compare

@github-actions github-actions released this 07 Oct 20:52
Immutable release. Only release title and notes can be modified.
0eadb20

Added

  • Added strict user-owned reusable launch presets in
    $XDG_CONFIG_HOME/clroom/presets.yaml (falling back to
    ~/.config/clroom/presets.yaml) with schema clroom.presets.v1.
  • Added --preset=<name>[,...], the ordinary implicit default preset,
    the single none reset token, and unambiguous provider inference for
    provider-bounded presets.
  • Added preset reuse of existing CLROOM skill selection, qualified
    --with/--without resource selectors, explicit environment-name
    admission, and literal provider argv through the same launch pipeline.
  • Added preset provenance to clroom inspect codex human and JSON output.
    JSON inspection advances explicitly to clroom.resolved-launch.v2 rather than
    changing the v1 schema under an existing identifier.

Changed

  • Current source version advances to v0.6.0; publication identity and
    downloadable artifacts remain authoritative in GitHub Releases until the
    separate release lifecycle completes.
  • Explicit CLI CLROOM options remain the highest user-controlled launch layer.
    Ordered preset resource choices are collapsed before the existing
    qualification path so later preset layers and explicit CLI resource choices
    can replace earlier preset intent without creating a second resolver.
  • Native Codex profiles, Claude settings/subagent controls, authentication,
    managed policy, and provider-owned configuration remain provider-native.
    A CLROOM preset is a saved top-level clean/selective launch intent, not a
    replacement provider settings framework.

Security

  • Preset parsing is local, size/count bounded, strict-schema, and fail-closed
    before provider birth for malformed configuration, incompatible providers,
    sensitive provider arguments, or attempts to smuggle CLROOM-owned controls
    through provider argv.
  • Presets do not support shell expansion, command substitution, scripts,
    implicit interpolation, secret values, remote includes/registries, or
    capability expansion. Unsupported resource/cardinality/provider paths remain
    unsupported when named by a preset.
  • Zero-auth provider auth/login/logout boundaries remain closed after
    launcher-owned options are resolved.

Dependencies

  • No runtime or build dependency changes.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • clean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json — release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytes
  • clean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz.sbom.sigstore.json — release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes

Verify the downloaded archive against its release-visible provenance bundle:

gh attestation verify "clean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz"   -R y-sor/clean-room-launcher   --bundle "clean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json"   --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.yml

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.

v0.5.0 — Clean Room Launcher

Choose a tag to compare

@github-actions github-actions released this 05 Oct 17:05
Immutable release. Only release title and notes can be modified.
7dede26

Added

  • Added one typed shared Codex ResolvedLaunch truth for bounded resource
    composition, sanitized human/JSON effective-launch inspection, and the real
    launch path.
  • Added bounded composition of exactly one qualified installed whole Codex
    plugin with exactly one qualified root-user standalone stdio MCP server in the
    same interactive launch.
  • Added exact-candidate real-provider composition rehearsal covering selected
    plugin and MCP runtime visibility, sibling exclusion, environment admission,
    source drift, and task-owned lifecycle closure.

Changed

  • Codex resource planning now resolves plugin and standalone MCP selections from
    one structured request, composes provider activation deterministically, and
    action-time revalidates every selected source before provider birth.
  • Raw provider config/plugin/MCP activation controls remain mutually exclusive
    with CLROOM resource selection, preserving one activation authority.
  • Effective launch inspection reports only bounded identities, decisions,
    qualification state, admitted environment-variable names, boundary controls,
    and a redacted provider-argv count; provider arguments, secret values and
    private paths are not emitted.

Security

  • A source change on either side of a composed Codex launch invalidates the
    whole resolved launch. Plugin/MCP identity overlap and ambient MCP sibling
    layers fail closed.
  • Literal MCP environment values remain refused; every MCP environment-variable
    reference still requires explicit --pass-env=NAME admission.
  • Composition does not add persistent provider configuration mutation,
    marketplace/network installation, remote/OAuth MCP, multiple plugins or MCP
    servers, Claude standalone MCP, --with=all, presets, or component-level
    plugin surgery.

Dependencies

  • No runtime or build dependency changes.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • clean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json — release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytes
  • clean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz.sbom.sigstore.json — release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes

Verify the downloaded archive against its release-visible provenance bundle:

gh attestation verify "clean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz"   -R y-sor/clean-room-launcher   --bundle "clean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json"   --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.yml

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.

v0.4.7 — Clean Room Launcher

Choose a tag to compare

@github-actions github-actions released this 04 Oct 16:52
Immutable release. Only release title and notes can be modified.
c78a580

Added

  • Added bounded standalone Codex MCP selection for one exact root-user stdio
    server per interactive launch, with fail-closed environment admission,
    layer-conflict checks, source revalidation, real-provider initialization and
    task-owned lifecycle closure.
  • Added pre-tag publishable-surface closure: exact release facts, rendered
    release notes and the publish preview are materialized, semantically checked
    against authoritative product/provider facts, content-addressed and required
    by release topology before a protected tag can be created.
  • Added canonical guarded tag, Draft and publish action paths with authoritative
    reconciliation for ambiguous local outcomes, plus post-public verification of
    the real releases/latest/download installer route and an isolated install.
  • Added independent Bing site verification to the generated documentation head,
    with repository tests rejecting a missing or placeholder verification value.

Changed

  • Advances exact macOS Apple Silicon qualification to Codex 0.160.0 and
    Claude Code 2.1.289, with registry/package/native identities frozen into
    accepted pre-tag evidence.
  • A consumed protected release identity now resolves to
    RELEASE_QUARANTINED: release-only candidate lanes remain disabled for that
    identity while ordinary source/docs/CI maintenance continues through normal
    protected-PR gates. A fresh version whose tag is absent returns to the full
    ACTIVE_CANDIDATE topology.
  • IndexNow keeps the same-SHA CI + Pages success dependency but removes the
    duplicate fixed polling deadline; the job-level bounded timeout is the single
    deadline and actual dependency failures still fail immediately.
  • The current candidate changelog section remains active semantic release input.
    Older changelog sections are historical, while current publishable claims are
    validated against the exact candidate/provider facts.
  • Tightens the site and homepage discovery descriptions to a concise CLROOM
    positioning while preserving the product/provider/project-context signals
    enforced by discovery-surface regression tests.

Fixed

  • The protected v0.4.5 and v0.4.6 tags and their unpublished Drafts
    remain incident evidence. They are not moved, reused, manually rewritten or
    promoted; this recovery advances under the fresh v0.4.7 identity from the
    published v0.4.4 baseline.
  • Draft promotion no longer interprets an arbitrary release-by-tag lookup
    failure as proof of absence. The canonical helper proves absence through the
    authenticated release collection, fails closed on uncertainty, and recovers
    existing matching Drafts by numeric release ID.
  • Tag push, Draft create/edit/upload and publish transitions reconcile the
    authoritative destination after simulated or real local post-action errors,
    preventing blind retries after an effect may already have succeeded.
  • Guarded publication remains exact-source-bound: accepted main, protected tag
    target, staged bytes and Draft identity must agree immediately before the one
    publish transition, so an older incident Draft cannot be promoted after main
    has moved.
  • Release quarantine is enforced at the release boundary instead of by a
    repository-wide path allowlist, preventing both consumed-identity reuse and
    accidental freezing of unrelated protected development.

Dependencies

  • The runtime delta from published v0.4.4 includes bounded TOML parsing for
    standalone Codex MCP configuration. The v0.4.7 recovery adds no further
    runtime or build dependency.

Security

  • Before a protected tag, the exact public body/title/state/asset contract is
    rendered and bound to structured provider/product/platform facts; stale or
    unclassified volatile claims block the candidate even when file hashes match.
  • Release-system first-execution closure now covers the canonical external
    action branches before a product tag is consumed, including failure/ambiguity
    reconciliation. Tag and publish remain separate Owner-authorized boundaries.
  • Publication is executed through one checked-in helper that re-verifies the
    Draft and action-time fingerprint immediately before the irreversible
    transition, then reconciles the published object. Public-route install
    verification remains a distinct post-publication state.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • clean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz.provenance.sigstore.json — release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytes
  • clean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz.sbom.sigstore.json — release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes

Verify the downloaded archive against its release-visible provenance bundle:

gh attestation verify "clean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz"   -R y-sor/clean-room-launcher   --bundle "clean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz.provenance.sigstore.json"   --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.yml

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.

v0.4.4 — Clean Room Launcher

Choose a tag to compare

@github-actions github-actions released this 23 Sep 15:53
Immutable release. Only release title and notes can be modified.
8482eb9

Fixed

  • Closed the v0.4.3 post-tag workflow execution escape by invoking the accepted-stage resolver through an explicit shell interpreter instead of relying on an executable Git mode that the file did not have.
  • Added a repository-wide workflow execution contract that rejects direct invocation of non-executable repo-local scripts and runs its negative self-test before expensive release qualification.
  • Added an accepted-main Ubuntu promotion-prepare rehearsal that resolves and verifies the exact staged bytes with the same resolver invocation used by the tag-triggered Release workflow; the protected tag helper now requires that exact-source rehearsal to pass.
  • The protected v0.4.3 tag remains historical evidence of the harness incident. Its Release workflow failed before attestation or Draft creation, no GitHub Release was created for v0.4.3, and the tag is not moved or reused.

Security

  • Release readiness now treats workflow command semantics and tracked executable mode as release-critical evidence, preventing a platform/file-mode mismatch from first surfacing after an immutable tag.
  • Post-tag promotion remains exact-byte-only; the recovery adds no manual upload, tag move, provider rerun, or release-policy bypass.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • clean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz.provenance.sigstore.json — release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytes
  • clean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz.sbom.sigstore.json — release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes

Verify the downloaded archive against its release-visible provenance bundle:

gh attestation verify "clean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz"   -R y-sor/clean-room-launcher   --bundle "clean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz.provenance.sigstore.json"   --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.yml

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.

v0.4.0 — Clean Room Launcher

Choose a tag to compare

@ewgenij87snwork ewgenij87snwork released this 19 Sep 20:16
Immutable release. Only release title and notes can be modified.
97eabd3

Added

  • Added clroom claude --with=plugin:<provider-native-id> for one exact
    already-installed Claude whole plugin per launch, using Claude's session-only
    plugin loading path without installing, updating, or persistently rewriting
    provider state.

Changed

  • Clarified interactive clroom codex as the primary Codex path while keeping
    codex exec for non-interactive automation; this is a documentation change,
    not a new Codex runtime path.
  • Updated pinned CI checkout usage to actions/checkout v7.0.1 and added
    OpenSSF Best Practices status badges; these do not change shipped runtime
    behavior.
  • Hardened public search/discovery metadata: the Limitations front matter is
    valid YAML, the site exposes a shorter SEO tagline, and project crawler/sitemap
    metadata is aligned with the host-root policy without changing the canonical
    URL set.
  • Added Release Contract v1: every stable release is checked against the full
    delta from the latest published stable release, with fail-closed change
    classification, explicit contract-evolution review, exact tracked-content
    review sealing, and a local whole-release audit command.

Compatibility

  • Whole-plugin activation is exactly qualified for Claude Code 2.1.273 on
    macOS Apple Silicon. Baseline clean-launch exact qualification remains Codex
    0.154.0 and Claude Code 2.1.272; documented minimum accepted ranges
    remain Codex 0.147.0+ and Claude Code 2.1.223+.
  • Codex plugin activation, MCP resource selection, --with=all, presets, and
    component-level plugin selection remain outside this release.

Security

  • Selected plugin activation reuses provider inventory/selection truth,
    revalidates the exact active install root around launch, reopens only that
    root read-only, refuses overlapping raw --plugin-dir/--plugin-url
    activation, and leaves persistent Claude configuration unchanged.
  • Activation inventory follows Claude provider-visible plugin surfaces, while
    v0.4.0 activation remains deliberately narrower: a matching plugin manifest
    identity plus only the default one-level skills/<name>/SKILL.md layout is
    qualified. Manifestless/root-single-skill/custom-skill-path bundles and
    slash-command, hook, MCP, agent, LSP, monitor, executable, or settings
    surfaces remain unqualified. Nested non-skill paths and identity are included
    in the fail-closed check, and qualification is revalidated immediately around
    launch.
  • Updated the shipped cap-std / cap-primitives dependency from 4.0.2
    to 4.0.3, incorporating the upstream fix for
    GHSA-hp8f-xmx4-4qrg affecting trailing-slash symlink containment on
    platforms including macOS.
  • Release qualification executes provider canaries against binaries extracted
    from the exact release archive and explicitly verifies both exported
    provenance and SBOM attestation bundles before Draft Release creation.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • clean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json — release-visible Sigstore provenance bundle
  • clean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz.sbom.sigstore.json — release-visible CycloneDX attestation bundle

Verify the downloaded archive against its release-visible provenance bundle:

gh attestation verify "clean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz" \
  -R y-sor/clean-room-launcher \
  --bundle "clean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json" \
  --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.yml

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.

v0.3.1 — Clean Room Launcher

Choose a tag to compare

@github-actions github-actions released this 17 Sep 22:40
Immutable release. Only release title and notes can be modified.
fe7e840

Added

  • Added a pull-request Dependency Review lane that blocks newly introduced
    high/critical known-vulnerable dependencies while leaving existing
    cargo-deny advisory/license policy authoritative.
  • Added dev/test-only cargo-fuzz harnesses and bounded PR smoke fuzzing for
    deterministic schema-admission and manifest-framing boundaries.
  • Added release-visible Sigstore attestation bundles for build provenance and
    the CycloneDX SBOM, with verification bound to the release workflow and source
    identity.

Changed

  • Removed generic Boundary, Boundary controls, Managed, and Model launch
    diagnostics from normal interactive Codex/Claude presentation while
    preserving internal launch-contract classification and fail-closed behavior.
  • Refreshed vulnerability-reporting guidance without claiming a private route
    when repository configuration cannot be verified from the public policy.
  • Replaced GitHub CodeQL Default Setup with a repository-local Advanced Setup
    workflow covering GitHub Actions, Python, and Rust.

Compatibility

  • macOS on Apple Silicon remains the qualified release platform.
  • Exact real-provider qualification targets remain Codex 0.154.0 and Claude
    Code 2.1.272; documented minimum accepted ranges remain Codex 0.147.0+
    and Claude Code 2.1.223+.
  • This patch does not expand Browser, operating-system, provider, credential,
    signing, or notarization support.

Security

  • Release readiness now carries the v0.3.1 version contract while preserving
    locked tests, dependency SCA, public-boundary checks, installer self-test,
    exact real-provider qualification, SBOM/provenance checks, and fail-closed
    artifact metadata validation.
  • Release provenance is exported as verifier-consumable Sigstore bundles for
    the exact archive/SBOM/installer subjects; no long-lived signing secret is
    introduced.
  • Fuzzing and Dependency Review are CI/test-only controls and add no shipped
    runtime dependency. The distributed macOS archive remains unsigned and
    unnotarized at the Apple platform-signing layer.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • clean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz.provenance.sigstore.json — release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytes
  • clean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz.sbom.sigstore.json — release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes

Verify the downloaded archive against its release-visible provenance bundle:

gh attestation verify "clean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz"   -R y-sor/clean-room-launcher   --bundle "clean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz.provenance.sigstore.json"   --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.yml

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.

v0.3.0 — Clean Room Launcher

Choose a tag to compare

@github-actions github-actions released this 17 Sep 02:34
Immutable release. Only release title and notes can be modified.
9e4a393

Added

  • Added provider-state inspection through clroom info codex, backed by explicit
    catalog, resource, plugin-surface, selection, and selection-receipt handling.
  • Added repository discovery checks plus OpenSSF Scorecard and Dependabot
    configuration for the public repository.

Changed

  • Moved the canonical public namespace and documentation/discovery URLs to
    y-sor/clean-room-launcher and y-sor.github.io/clean-room-launcher.
  • Updated exact Claude Code release qualification to 2.1.272 while retaining
    Codex 0.154.0 as the exact Codex qualification target.
  • Hardened release-candidate and tag-release provider provisioning so the
    verified npm tarball bytes are the exact local tarballs installed for real
    provider qualification.

Fixed

  • Added explicit Codex and Claude plugin-state handling and provider-state
    inspection coverage without weakening fail-closed launch behavior.
  • Removed stale public control/execution-map residue and tightened the public
    repository boundary checks after the namespace transfer.

Compatibility

  • macOS on Apple Silicon remains the qualified release platform.
  • Exact real-provider qualification targets are Codex 0.154.0 and Claude Code
    2.1.272; documented minimum accepted ranges remain Codex 0.147.0+ and
    Claude Code 2.1.223+.
  • Linux, Windows, Intel macOS, Homebrew, crates.io distribution, Apple signing,
    and notarization remain outside the qualified release surface.

Security

  • Release readiness continues to run locked tests, dependency SCA review,
    installer self-test, public-boundary checks, exact artifact metadata checks,
    real-provider qualification evidence verification, SBOM generation, and
    provenance verification before release gating.
  • Apps, hooks, and plugins remain disabled by default. The distributed macOS
    archive remains unsigned and unnotarized.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.3.0-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • GitHub build-provenance and SBOM attestations are generated for the exact archive bytes

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and GitHub attestations before use.

Clean Room Launcher 0.2.1

Choose a tag to compare

@github-actions github-actions released this 15 Sep 07:34
efc10a2

Changed

  • Updated the README, demo, and install guidance to present interactive
    clroom codex as the primary Codex launch path and the published GitHub
    installer as the normal installation path.

Fixed

  • Repeated Codex launches no longer fail with CLROOM_CODEX_STATE_DIRTY after
    supported Codex 0.154.0 creates legitimate provider-owned cache or
    plugins state inside an initialized CLROOM shadow home.

Compatibility

  • Exact real-provider qualification remains Codex 0.154.0 and Claude Code
    2.1.263; documented minimum accepted ranges remain Codex 0.147.0+ and
    Claude Code 2.1.223+.
  • This patch adds no platform expansion: macOS on Apple Silicon remains the
    qualified release platform.

Security

  • Capability-owned Codex state is accepted only inside a valid initialized
    CLROOM shadow home and only as real top-level directories; unknown roots,
    symlinks, and invalid entry types remain fail-closed.
  • Apps, hooks, and plugins remain disabled by default. The distributed macOS
    archive remains unsigned and unnotarized.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/ewgenij87snwork/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.2.1-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • GitHub build-provenance and SBOM attestations are generated for the exact archive bytes

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and GitHub attestations before use.

Clean Room Launcher 0.2.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 19:12
329bcd7

Added

  • Added a persistent clean configuration view for interactive clroom codex;
    native --ignore-user-config remains an exec-only enhancement.
  • Selected symlinked global skills preserve canonical-target isolation and
    duplicate-source safety across the qualified provider paths.
  • Codex exec launches with clean user configuration, provider-aware
    selected-skill inventory, and fail-closed filesystem restrictions.
  • Drop-in clroom-codex and clroom-claude provider executables preserve native
    provider arguments, interactive process behavior, and exact --pass-env=NAME
    admission, with Claude parity and duplicate/invalid-name refusal.
  • The release process binds sanitized real-provider startup evidence to Codex
    0.154.0 and Claude Code 2.1.263, alongside canonical release readiness,
    SCA verification, SHA256SUMS, a CycloneDX SBOM, provenance, and GitHub
    attestations.
  • Added checksum-verified one-line macOS Apple Silicon installation from GitHub
    Releases without sudo or shell-configuration mutation.
  • Strengthened documentation discovery assets for search engines and AI-facing
    documentation discovery without changing the supported runtime surface.

Fixed

  • Claude Code 2.1.257+ no longer rejects CLROOM's local selected-skill
    projection as a network path when the outer macOS Seatbelt policy is active.
    The fix preserves denial of sibling projection contents, unselected skills,
    provider state, credential roots, and writes to protected skill sources.

Compatibility

  • macOS on Apple Silicon is the qualified platform for v0.2.0.
  • The exact real-provider qualification targets are Codex 0.154.0 and Claude
    Code 2.1.263. The documented minimum accepted parser/runtime ranges remain
    Codex 0.147.0+ and Claude Code 2.1.223+.
  • Claude Code project and other ambient MCP configurations are not loaded by the
    default v0.2.0 Claude launch. CLROOM starts Claude with
    --strict-mcp-config; MCP servers are considered only when explicitly
    supplied through Claude's own --mcp-config argument.
  • Claude Code -p response-output semantics are not independently qualified by
    this release.

Security

  • The distributed macOS archive is unsigned and unnotarized.
  • The archive records qualification=CANDIDATE; runtime qualification is kept
    as separately verified evidence bound to the exact candidate bytes rather
    than being self-asserted by the archive itself.
  • Linux, Windows, Intel macOS, Homebrew, crates.io distribution, signing, and
    notarization are not claimed by v0.2.0.

Install

curl --proto '=https' --tlsv1.2 -fsSL https://github.com/ewgenij87snwork/clean-room-launcher/releases/latest/download/install.sh | sh

Download and verification

  • install.sh — one-line macOS Apple Silicon installer
  • clean-room-launcher-v0.2.0-aarch64-apple-darwin.tar.gz — macOS Apple Silicon archive
  • SHA256SUMS — SHA-256 digests for the archive, SBOM, and installer
  • sbom.cdx.json — CycloneDX SBOM bound to the archive digest
  • GitHub build-provenance and SBOM attestations are generated for the exact archive bytes

The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and GitHub attestations before use.

v0.1.0-alpha.4.2

v0.1.0-alpha.4.2 Pre-release
Pre-release

Choose a tag to compare

@ewgenij87snwork ewgenij87snwork released this 24 Aug 19:50

Fixed

  • Resolved the Claude concurrent reaper/owner cleanup race. Cleanup is idempotent
    only for an absent generated session leaf under the exact validated private
    layout; unsafe ancestors and leaves remain fail-closed.

Release assets

  • clean-room-launcher-v0.1.0-alpha.4.2-aarch64-apple-darwin.tar.gz
  • SHA256SUMS

Qualification

This prerelease qualifies Codex and Claude on macOS Apple Silicon only. It is
unsigned and unnotarized; Ubuntu and Windows are not qualified by this release.