Unofficial community reference. Not affiliated with 37signals or the Omacom Foundation. Download Omarchy only from omarchy.org.
omarchylinux.org Unofficial field manual

Omarchy v4.0.2

Released 2026-08-31. Official notes on GitHub 路 ISO SHA-256 2ef8e624aa1bec7e277e28056b8535a6c9373ba48d7ede3f1a01cb6d2373cfb8 (how to verify).

Release notes

This is an additional set of security fixes that were validated and examined by the聽Omarchy Security team. If you ever find security issues with Omarchy, please follow the responsible disclosure procedure on聽omarchy.org/security.聽馃檹

You can upgrade existing machines with聽Update > Omarchy.

Install on new machines with the ISO:

Improvements

  • Repair legacy paths and privileged files from retired installers by @acrogenesis
  • Skip Chromium's new first-run EULA by @hjanuschka
  • Improve Apple display brightness detection reliability by @bastidotnet
  • Point the RC channel to the dedicated release candidate repository by @ryanrhughes
  • Prevent the desktop bar visibility toggle from becoming unresponsive by @ryanrhughes
  • Improve automated test suite reliability by @ryanrhughes, @Skeptomenos

Fixes

  • Fix shell injection in theme and application installers by @mdisec, @Adolanium
  • Fix Codex usage collection on version 0.149 by @orienw
  • Fix migration failures on Bash 5.3 by @ryanrhughes
  • Fix SSH hardening verification failing on OpenSSH 10.x by @ryanrhughes
  • Prevent web app installers from creating nested directories via the app name by @Chessing234

Security

  • Require signed packages from the Omarchy repository by @ryanrhughes
  • Harden CUPS printer discovery and administration by @mdisec
  • Secure Plymouth and SDDM asset publication by @AFOliveira, @ErikMelton, @itz4blitz
  • Secure Windows VM host mounts in Codex by @AFOliveira
  • Prevent remote image injection in shell text elements by @ErikMelton
  • Harden browser policy directory permissions by @acrogenesis
  • Restrict sudoers rule for timezone updates by @omarchybot
  • Validate web app URLs and escape desktop entry values by @bastidotnet, @Chessing234
  • Harden existing SSH installations and disable password authentication by default by @acrogenesis, @ryanrhughes
  • Close unprivileged input and SSH escalation paths by @acrogenesis, @fuchsblau, @ryanrhughes

Deprecations

  • Temporarily remove automatic printer discovery by @omarchybot

Changes since v4.0.1

Full diff: 1 commands added, 0 removed; 0 keybindings added, 0 removed.

Migrations this upgrade ran (10)

Each is a script that ran once on your machine during omarchy update. Descriptions are the scripts' own messages.

  • 2026-08-23 Stop world-writable Chromium and Firefox policy directories src
  • 2026-08-24 Require signed packages from the Omarchy repository src
  • 2026-08-25 Skip Chromium's new first-run EULA on machines already on Quattro src
  • 2026-08-27 Separate printer discovery from root and print-filter access src
  • 2026-08-27 Drop the default input group grant, which allowed unprivileged keylogging src
  • 2026-08-29 Temporarily remove automatic printer discovery src
  • 2026-08-29 Remove privileged files left behind by retired Omarchy installers src
  • 2026-08-30 Repair legacy XCompose and remove vulnerable Omarchy 3 power udev rules src
  • 2026-08-30 Point rc-channel installs at the rc package repository src
  • 2026-08-30 Disable SSH password authentication, or sshd itself when no key is authorized src

Unofficial mirror of public release data. Notes 漏 the Omarchy authors (MIT repository). Bare #numbers are linked to the upstream issue tracker.