Omarchy v4.0.2
Released 2026-08-31. Official notes on GitHub 路 ISO SHA-256 2ef8e624aa1bec7e277e28056b8535a6c9373ba48d7ede3f1a01cb6d2373cfb8 (how to verify).
Release notes
This is an additional set of security fixes that were validated and examined by the聽Omarchy Security team. If you ever find security issues with Omarchy, please follow the responsible disclosure procedure on聽omarchy.org/security.聽馃檹
You can upgrade existing machines with聽Update > Omarchy.
Install on new machines with the ISO:
- Download:聽https://iso.omarchy.org/omarchy-4.0.2.iso
- SHA256: 2ef8e624aa1bec7e277e28056b8535a6c9373ba48d7ede3f1a01cb6d2373cfb8
Improvements
- Repair legacy paths and privileged files from retired installers by @acrogenesis
- Skip Chromium's new first-run EULA by @hjanuschka
- Improve Apple display brightness detection reliability by @bastidotnet
- Point the RC channel to the dedicated release candidate repository by @ryanrhughes
- Prevent the desktop bar visibility toggle from becoming unresponsive by @ryanrhughes
- Improve automated test suite reliability by @ryanrhughes, @Skeptomenos
Fixes
- Fix shell injection in theme and application installers by @mdisec, @Adolanium
- Fix Codex usage collection on version 0.149 by @orienw
- Fix migration failures on Bash 5.3 by @ryanrhughes
- Fix SSH hardening verification failing on OpenSSH 10.x by @ryanrhughes
- Prevent web app installers from creating nested directories via the app name by @Chessing234
Security
- Require signed packages from the Omarchy repository by @ryanrhughes
- Harden CUPS printer discovery and administration by @mdisec
- Secure Plymouth and SDDM asset publication by @AFOliveira, @ErikMelton, @itz4blitz
- Secure Windows VM host mounts in Codex by @AFOliveira
- Prevent remote image injection in shell text elements by @ErikMelton
- Harden browser policy directory permissions by @acrogenesis
- Restrict sudoers rule for timezone updates by @omarchybot
- Validate web app URLs and escape desktop entry values by @bastidotnet, @Chessing234
- Harden existing SSH installations and disable password authentication by default by @acrogenesis, @ryanrhughes
- Close unprivileged input and SSH escalation paths by @acrogenesis, @fuchsblau, @ryanrhughes
Deprecations
- Temporarily remove automatic printer discovery by @omarchybot
Changes since v4.0.1
Full diff: 1 commands added, 0 removed; 0 keybindings added, 0 removed.
Migrations this upgrade ran (10)
Each is a script that ran once on your machine during omarchy update. Descriptions are the scripts' own messages.
- 2026-08-23 Stop world-writable Chromium and Firefox policy directories src
- 2026-08-24 Require signed packages from the Omarchy repository src
- 2026-08-25 Skip Chromium's new first-run EULA on machines already on Quattro src
- 2026-08-27 Separate printer discovery from root and print-filter access src
- 2026-08-27 Drop the default input group grant, which allowed unprivileged keylogging src
- 2026-08-29 Temporarily remove automatic printer discovery src
- 2026-08-29 Remove privileged files left behind by retired Omarchy installers src
- 2026-08-30 Repair legacy XCompose and remove vulnerable Omarchy 3 power udev rules src
- 2026-08-30 Point rc-channel installs at the rc package repository src
- 2026-08-30 Disable SSH password authentication, or sshd itself when no key is authorized src
Unofficial mirror of public release data. Notes 漏 the Omarchy authors (MIT repository). Bare #numbers are linked to the upstream issue tracker.