Repository navigation
Releases: y-sor/clean-room-launcher
Release list
v0.6.0 — Clean Room Launcher
Added
- Added strict user-owned reusable launch presets in
$XDG_CONFIG_HOME/clroom/presets.yaml(falling back to
~/.config/clroom/presets.yaml) with schemaclroom.presets.v1. - Added
--preset=<name>[,...], the ordinary implicitdefaultpreset,
the singlenonereset token, and unambiguous provider inference for
provider-bounded presets. - Added preset reuse of existing CLROOM skill selection, qualified
--with/--withoutresource selectors, explicit environment-name
admission, and literal provider argv through the same launch pipeline. - Added preset provenance to
clroom inspect codexhuman and JSON output.
JSON inspection advances explicitly toclroom.resolved-launch.v2rather than
changing the v1 schema under an existing identifier.
Changed
- Current source version advances to
v0.6.0; publication identity and
downloadable artifacts remain authoritative in GitHub Releases until the
separate release lifecycle completes. - Explicit CLI CLROOM options remain the highest user-controlled launch layer.
Ordered preset resource choices are collapsed before the existing
qualification path so later preset layers and explicit CLI resource choices
can replace earlier preset intent without creating a second resolver. - Native Codex profiles, Claude settings/subagent controls, authentication,
managed policy, and provider-owned configuration remain provider-native.
A CLROOM preset is a saved top-level clean/selective launch intent, not a
replacement provider settings framework.
Security
- Preset parsing is local, size/count bounded, strict-schema, and fail-closed
before provider birth for malformed configuration, incompatible providers,
sensitive provider arguments, or attempts to smuggle CLROOM-owned controls
through provider argv. - Presets do not support shell expansion, command substitution, scripts,
implicit interpolation, secret values, remote includes/registries, or
capability expansion. Unsupported resource/cardinality/provider paths remain
unsupported when named by a preset. - Zero-auth provider auth/login/logout boundaries remain closed after
launcher-owned options are resolved.
Dependencies
- No runtime or build dependency changes.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digestclean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json— release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytesclean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz.sbom.sigstore.json— release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes
Verify the downloaded archive against its release-visible provenance bundle:
gh attestation verify "clean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz" -R y-sor/clean-room-launcher --bundle "clean-room-launcher-v0.6.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json" --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.ymlThe distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.
v0.5.0 — Clean Room Launcher
Added
- Added one typed shared Codex
ResolvedLaunchtruth for bounded resource
composition, sanitized human/JSON effective-launch inspection, and the real
launch path. - Added bounded composition of exactly one qualified installed whole Codex
plugin with exactly one qualified root-user standalone stdio MCP server in the
same interactive launch. - Added exact-candidate real-provider composition rehearsal covering selected
plugin and MCP runtime visibility, sibling exclusion, environment admission,
source drift, and task-owned lifecycle closure.
Changed
- Codex resource planning now resolves plugin and standalone MCP selections from
one structured request, composes provider activation deterministically, and
action-time revalidates every selected source before provider birth. - Raw provider config/plugin/MCP activation controls remain mutually exclusive
with CLROOM resource selection, preserving one activation authority. - Effective launch inspection reports only bounded identities, decisions,
qualification state, admitted environment-variable names, boundary controls,
and a redacted provider-argv count; provider arguments, secret values and
private paths are not emitted.
Security
- A source change on either side of a composed Codex launch invalidates the
whole resolved launch. Plugin/MCP identity overlap and ambient MCP sibling
layers fail closed. - Literal MCP environment values remain refused; every MCP environment-variable
reference still requires explicit--pass-env=NAMEadmission. - Composition does not add persistent provider configuration mutation,
marketplace/network installation, remote/OAuth MCP, multiple plugins or MCP
servers, Claude standalone MCP,--with=all, presets, or component-level
plugin surgery.
Dependencies
- No runtime or build dependency changes.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digestclean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json— release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytesclean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz.sbom.sigstore.json— release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes
Verify the downloaded archive against its release-visible provenance bundle:
gh attestation verify "clean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz" -R y-sor/clean-room-launcher --bundle "clean-room-launcher-v0.5.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json" --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.ymlThe distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.
v0.4.7 — Clean Room Launcher
Added
- Added bounded standalone Codex MCP selection for one exact root-user stdio
server per interactive launch, with fail-closed environment admission,
layer-conflict checks, source revalidation, real-provider initialization and
task-owned lifecycle closure. - Added pre-tag publishable-surface closure: exact release facts, rendered
release notes and the publish preview are materialized, semantically checked
against authoritative product/provider facts, content-addressed and required
by release topology before a protected tag can be created. - Added canonical guarded tag, Draft and publish action paths with authoritative
reconciliation for ambiguous local outcomes, plus post-public verification of
the realreleases/latest/downloadinstaller route and an isolated install. - Added independent Bing site verification to the generated documentation head,
with repository tests rejecting a missing or placeholder verification value.
Changed
- Advances exact macOS Apple Silicon qualification to Codex
0.160.0and
Claude Code2.1.289, with registry/package/native identities frozen into
accepted pre-tag evidence. - A consumed protected release identity now resolves to
RELEASE_QUARANTINED: release-only candidate lanes remain disabled for that
identity while ordinary source/docs/CI maintenance continues through normal
protected-PR gates. A fresh version whose tag is absent returns to the full
ACTIVE_CANDIDATEtopology. - IndexNow keeps the same-SHA CI + Pages success dependency but removes the
duplicate fixed polling deadline; the job-level bounded timeout is the single
deadline and actual dependency failures still fail immediately. - The current candidate changelog section remains active semantic release input.
Older changelog sections are historical, while current publishable claims are
validated against the exact candidate/provider facts. - Tightens the site and homepage discovery descriptions to a concise CLROOM
positioning while preserving the product/provider/project-context signals
enforced by discovery-surface regression tests.
Fixed
- The protected
v0.4.5andv0.4.6tags and their unpublished Drafts
remain incident evidence. They are not moved, reused, manually rewritten or
promoted; this recovery advances under the freshv0.4.7identity from the
publishedv0.4.4baseline. - Draft promotion no longer interprets an arbitrary release-by-tag lookup
failure as proof of absence. The canonical helper proves absence through the
authenticated release collection, fails closed on uncertainty, and recovers
existing matching Drafts by numeric release ID. - Tag push, Draft create/edit/upload and publish transitions reconcile the
authoritative destination after simulated or real local post-action errors,
preventing blind retries after an effect may already have succeeded. - Guarded publication remains exact-source-bound: accepted main, protected tag
target, staged bytes and Draft identity must agree immediately before the one
publish transition, so an older incident Draft cannot be promoted after main
has moved. - Release quarantine is enforced at the release boundary instead of by a
repository-wide path allowlist, preventing both consumed-identity reuse and
accidental freezing of unrelated protected development.
Dependencies
- The runtime delta from published
v0.4.4includes bounded TOML parsing for
standalone Codex MCP configuration. Thev0.4.7recovery adds no further
runtime or build dependency.
Security
- Before a protected tag, the exact public body/title/state/asset contract is
rendered and bound to structured provider/product/platform facts; stale or
unclassified volatile claims block the candidate even when file hashes match. - Release-system first-execution closure now covers the canonical external
action branches before a product tag is consumed, including failure/ambiguity
reconciliation. Tag and publish remain separate Owner-authorized boundaries. - Publication is executed through one checked-in helper that re-verifies the
Draft and action-time fingerprint immediately before the irreversible
transition, then reconciles the published object. Public-route install
verification remains a distinct post-publication state.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digestclean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz.provenance.sigstore.json— release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytesclean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz.sbom.sigstore.json— release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes
Verify the downloaded archive against its release-visible provenance bundle:
gh attestation verify "clean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz" -R y-sor/clean-room-launcher --bundle "clean-room-launcher-v0.4.7-aarch64-apple-darwin.tar.gz.provenance.sigstore.json" --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.ymlThe distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.
v0.4.4 — Clean Room Launcher
Fixed
- Closed the v0.4.3 post-tag workflow execution escape by invoking the accepted-stage resolver through an explicit shell interpreter instead of relying on an executable Git mode that the file did not have.
- Added a repository-wide workflow execution contract that rejects direct invocation of non-executable repo-local scripts and runs its negative self-test before expensive release qualification.
- Added an accepted-main Ubuntu promotion-prepare rehearsal that resolves and verifies the exact staged bytes with the same resolver invocation used by the tag-triggered Release workflow; the protected tag helper now requires that exact-source rehearsal to pass.
- The protected v0.4.3 tag remains historical evidence of the harness incident. Its Release workflow failed before attestation or Draft creation, no GitHub Release was created for v0.4.3, and the tag is not moved or reused.
Security
- Release readiness now treats workflow command semantics and tracked executable mode as release-critical evidence, preventing a platform/file-mode mismatch from first surfacing after an immutable tag.
- Post-tag promotion remains exact-byte-only; the recovery adds no manual upload, tag move, provider rerun, or release-policy bypass.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digestclean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz.provenance.sigstore.json— release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytesclean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz.sbom.sigstore.json— release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes
Verify the downloaded archive against its release-visible provenance bundle:
gh attestation verify "clean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz" -R y-sor/clean-room-launcher --bundle "clean-room-launcher-v0.4.4-aarch64-apple-darwin.tar.gz.provenance.sigstore.json" --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.ymlThe distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.
v0.4.0 — Clean Room Launcher
Added
- Added
clroom claude --with=plugin:<provider-native-id>for one exact
already-installed Claude whole plugin per launch, using Claude's session-only
plugin loading path without installing, updating, or persistently rewriting
provider state.
Changed
- Clarified interactive
clroom codexas the primary Codex path while keeping
codex execfor non-interactive automation; this is a documentation change,
not a new Codex runtime path. - Updated pinned CI checkout usage to
actions/checkoutv7.0.1 and added
OpenSSF Best Practices status badges; these do not change shipped runtime
behavior. - Hardened public search/discovery metadata: the Limitations front matter is
valid YAML, the site exposes a shorter SEO tagline, and project crawler/sitemap
metadata is aligned with the host-root policy without changing the canonical
URL set. - Added Release Contract v1: every stable release is checked against the full
delta from the latest published stable release, with fail-closed change
classification, explicit contract-evolution review, exact tracked-content
review sealing, and a local whole-release audit command.
Compatibility
- Whole-plugin activation is exactly qualified for Claude Code
2.1.273on
macOS Apple Silicon. Baseline clean-launch exact qualification remains Codex
0.154.0and Claude Code2.1.272; documented minimum accepted ranges
remain Codex0.147.0+and Claude Code2.1.223+. - Codex plugin activation, MCP resource selection,
--with=all, presets, and
component-level plugin selection remain outside this release.
Security
- Selected plugin activation reuses provider inventory/selection truth,
revalidates the exact active install root around launch, reopens only that
root read-only, refuses overlapping raw--plugin-dir/--plugin-url
activation, and leaves persistent Claude configuration unchanged. - Activation inventory follows Claude provider-visible plugin surfaces, while
v0.4.0 activation remains deliberately narrower: a matching plugin manifest
identity plus only the default one-levelskills/<name>/SKILL.mdlayout is
qualified. Manifestless/root-single-skill/custom-skill-path bundles and
slash-command, hook, MCP, agent, LSP, monitor, executable, or settings
surfaces remain unqualified. Nested non-skill paths and identity are included
in the fail-closed check, and qualification is revalidated immediately around
launch. - Updated the shipped
cap-std/cap-primitivesdependency from4.0.2
to4.0.3, incorporating the upstream fix for
GHSA-hp8f-xmx4-4qrgaffecting trailing-slash symlink containment on
platforms including macOS. - Release qualification executes provider canaries against binaries extracted
from the exact release archive and explicitly verifies both exported
provenance and SBOM attestation bundles before Draft Release creation.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digestclean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json— release-visible Sigstore provenance bundleclean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz.sbom.sigstore.json— release-visible CycloneDX attestation bundle
Verify the downloaded archive against its release-visible provenance bundle:
gh attestation verify "clean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz" \
-R y-sor/clean-room-launcher \
--bundle "clean-room-launcher-v0.4.0-aarch64-apple-darwin.tar.gz.provenance.sigstore.json" \
--signer-workflow y-sor/clean-room-launcher/.github/workflows/release.ymlThe distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.
v0.3.1 — Clean Room Launcher
Added
- Added a pull-request Dependency Review lane that blocks newly introduced
high/critical known-vulnerable dependencies while leaving existing
cargo-denyadvisory/license policy authoritative. - Added dev/test-only
cargo-fuzzharnesses and bounded PR smoke fuzzing for
deterministic schema-admission and manifest-framing boundaries. - Added release-visible Sigstore attestation bundles for build provenance and
the CycloneDX SBOM, with verification bound to the release workflow and source
identity.
Changed
- Removed generic
Boundary,Boundary controls,Managed, andModellaunch
diagnostics from normal interactive Codex/Claude presentation while
preserving internal launch-contract classification and fail-closed behavior. - Refreshed vulnerability-reporting guidance without claiming a private route
when repository configuration cannot be verified from the public policy. - Replaced GitHub CodeQL Default Setup with a repository-local Advanced Setup
workflow covering GitHub Actions, Python, and Rust.
Compatibility
- macOS on Apple Silicon remains the qualified release platform.
- Exact real-provider qualification targets remain Codex
0.154.0and Claude
Code2.1.272; documented minimum accepted ranges remain Codex0.147.0+
and Claude Code2.1.223+. - This patch does not expand Browser, operating-system, provider, credential,
signing, or notarization support.
Security
- Release readiness now carries the v0.3.1 version contract while preserving
locked tests, dependency SCA, public-boundary checks, installer self-test,
exact real-provider qualification, SBOM/provenance checks, and fail-closed
artifact metadata validation. - Release provenance is exported as verifier-consumable Sigstore bundles for
the exact archive/SBOM/installer subjects; no long-lived signing secret is
introduced. - Fuzzing and Dependency Review are CI/test-only controls and add no shipped
runtime dependency. The distributed macOS archive remains unsigned and
unnotarized at the Apple platform-signing layer.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digestclean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz.provenance.sigstore.json— release-visible Sigstore bundle for build provenance of the exact archive, SBOM, and installer bytesclean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz.sbom.sigstore.json— release-visible Sigstore bundle for the CycloneDX SBOM attestation bound to the exact archive bytes
Verify the downloaded archive against its release-visible provenance bundle:
gh attestation verify "clean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz" -R y-sor/clean-room-launcher --bundle "clean-room-launcher-v0.3.1-aarch64-apple-darwin.tar.gz.provenance.sigstore.json" --signer-workflow y-sor/clean-room-launcher/.github/workflows/release.ymlThe distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and release-visible GitHub attestation bundles before use.
v0.3.0 — Clean Room Launcher
Added
- Added provider-state inspection through
clroom info codex, backed by explicit
catalog, resource, plugin-surface, selection, and selection-receipt handling. - Added repository discovery checks plus OpenSSF Scorecard and Dependabot
configuration for the public repository.
Changed
- Moved the canonical public namespace and documentation/discovery URLs to
y-sor/clean-room-launcherandy-sor.github.io/clean-room-launcher. - Updated exact Claude Code release qualification to
2.1.272while retaining
Codex0.154.0as the exact Codex qualification target. - Hardened release-candidate and tag-release provider provisioning so the
verified npm tarball bytes are the exact local tarballs installed for real
provider qualification.
Fixed
- Added explicit Codex and Claude plugin-state handling and provider-state
inspection coverage without weakening fail-closed launch behavior. - Removed stale public control/execution-map residue and tightened the public
repository boundary checks after the namespace transfer.
Compatibility
- macOS on Apple Silicon remains the qualified release platform.
- Exact real-provider qualification targets are Codex
0.154.0and Claude Code
2.1.272; documented minimum accepted ranges remain Codex0.147.0+and
Claude Code2.1.223+. - Linux, Windows, Intel macOS, Homebrew, crates.io distribution, Apple signing,
and notarization remain outside the qualified release surface.
Security
- Release readiness continues to run locked tests, dependency SCA review,
installer self-test, public-boundary checks, exact artifact metadata checks,
real-provider qualification evidence verification, SBOM generation, and
provenance verification before release gating. - Apps, hooks, and plugins remain disabled by default. The distributed macOS
archive remains unsigned and unnotarized.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/y-sor/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.3.0-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digest- GitHub build-provenance and SBOM attestations are generated for the exact archive bytes
The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and GitHub attestations before use.
Clean Room Launcher 0.2.1
Changed
- Updated the README, demo, and install guidance to present interactive
clroom codexas the primary Codex launch path and the published GitHub
installer as the normal installation path.
Fixed
- Repeated Codex launches no longer fail with
CLROOM_CODEX_STATE_DIRTYafter
supported Codex0.154.0creates legitimate provider-ownedcacheor
pluginsstate inside an initialized CLROOM shadow home.
Compatibility
- Exact real-provider qualification remains Codex
0.154.0and Claude Code
2.1.263; documented minimum accepted ranges remain Codex0.147.0+and
Claude Code2.1.223+. - This patch adds no platform expansion: macOS on Apple Silicon remains the
qualified release platform.
Security
- Capability-owned Codex state is accepted only inside a valid initialized
CLROOM shadow home and only as real top-level directories; unknown roots,
symlinks, and invalid entry types remain fail-closed. - Apps, hooks, and plugins remain disabled by default. The distributed macOS
archive remains unsigned and unnotarized.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/ewgenij87snwork/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.2.1-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digest- GitHub build-provenance and SBOM attestations are generated for the exact archive bytes
The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and GitHub attestations before use.
Clean Room Launcher 0.2.0
Added
- Added a persistent clean configuration view for interactive
clroom codex;
native--ignore-user-configremains an exec-only enhancement. - Selected symlinked global skills preserve canonical-target isolation and
duplicate-source safety across the qualified provider paths. - Codex exec launches with clean user configuration, provider-aware
selected-skill inventory, and fail-closed filesystem restrictions. - Drop-in
clroom-codexandclroom-claudeprovider executables preserve native
provider arguments, interactive process behavior, and exact--pass-env=NAME
admission, with Claude parity and duplicate/invalid-name refusal. - The release process binds sanitized real-provider startup evidence to Codex
0.154.0and Claude Code2.1.263, alongside canonical release readiness,
SCA verification,SHA256SUMS, a CycloneDX SBOM, provenance, and GitHub
attestations. - Added checksum-verified one-line macOS Apple Silicon installation from GitHub
Releases withoutsudoor shell-configuration mutation. - Strengthened documentation discovery assets for search engines and AI-facing
documentation discovery without changing the supported runtime surface.
Fixed
- Claude Code
2.1.257+no longer rejects CLROOM's local selected-skill
projection as a network path when the outer macOS Seatbelt policy is active.
The fix preserves denial of sibling projection contents, unselected skills,
provider state, credential roots, and writes to protected skill sources.
Compatibility
- macOS on Apple Silicon is the qualified platform for
v0.2.0. - The exact real-provider qualification targets are Codex
0.154.0and Claude
Code2.1.263. The documented minimum accepted parser/runtime ranges remain
Codex0.147.0+and Claude Code2.1.223+. - Claude Code project and other ambient MCP configurations are not loaded by the
defaultv0.2.0Claude launch. CLROOM starts Claude with
--strict-mcp-config; MCP servers are considered only when explicitly
supplied through Claude's own--mcp-configargument. - Claude Code
-presponse-output semantics are not independently qualified by
this release.
Security
- The distributed macOS archive is unsigned and unnotarized.
- The archive records
qualification=CANDIDATE; runtime qualification is kept
as separately verified evidence bound to the exact candidate bytes rather
than being self-asserted by the archive itself. - Linux, Windows, Intel macOS, Homebrew, crates.io distribution, signing, and
notarization are not claimed byv0.2.0.
Install
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/ewgenij87snwork/clean-room-launcher/releases/latest/download/install.sh | shDownload and verification
install.sh— one-line macOS Apple Silicon installerclean-room-launcher-v0.2.0-aarch64-apple-darwin.tar.gz— macOS Apple Silicon archiveSHA256SUMS— SHA-256 digests for the archive, SBOM, and installersbom.cdx.json— CycloneDX SBOM bound to the archive digest- GitHub build-provenance and SBOM attestations are generated for the exact archive bytes
The distributed archive is currently unsigned at the Apple platform-signing layer. Verify the checksums and GitHub attestations before use.
v0.1.0-alpha.4.2
Fixed
- Resolved the Claude concurrent reaper/owner cleanup race. Cleanup is idempotent
only for an absent generated session leaf under the exact validated private
layout; unsafe ancestors and leaves remain fail-closed.
Release assets
clean-room-launcher-v0.1.0-alpha.4.2-aarch64-apple-darwin.tar.gzSHA256SUMS
Qualification
This prerelease qualifies Codex and Claude on macOS Apple Silicon only. It is
unsigned and unnotarized; Ubuntu and Windows are not qualified by this release.