Omarchy v4.0.3
Released 2026-09-08. Official notes on GitHub 路 ISO SHA-256 03d60bc74306dca51f96e1a84b690871d8d606826b260edd0208962da8507d14 (how to verify).
Release notes
This release brings amazing out-of-the-box integration for both Hermes and Openclaw as well as additional set of security fixes that were validated and examined by the Omarchy Security team. If you ever find security issues with Omarchy, please follow the responsible disclosure procedure on omarchy.org/security. 馃檹
You can upgrade existing machines with Update > Omarchy.
Install on new machines with the ISO:
Download: https://iso.omarchy.org/omarchy-4.0.3.iso SHA256: 03d60bc74306dca51f96e1a84b690871d8d606826b260edd0208962da8507d14
Additional agentware is here
Add OpenClaw as a desktop app and default coding agent by @spencerbull
Install OpenClaw from Install > AI, open its Control UI as an app, or choose its terminal interface as your default agent. Omarchy manages onboarding and the local user gateway; removal asks before deleting your data.
Add Hermes Desktop and terminal-agent integration by @spencerbull and @smfworks
Install Hermes from Install > AI and use the same installation from the desktop, terminal, and default-agent launcher. Prompted sessions use the native interactive interface, and Omarchy skills are linked into Hermes.
More agents, more everywhere!
- Add T3 Code with Omarchy theme support by @omarchybot, @ryanrhughes
- Add the Perplexity desktop app to the AI menu by @spencerbull
- Add Cursor CLI as a default coding agent by @dhh, @cavanaug
- Add Muse Code as a default coding agent by @jp30566347, @dhh
Compatibility
- Improve fingerprint-reader support during setup by @powderluv
- Update the Panther Lake kernel to 7.2.3 by @ryanrhughes
Fixes
- Fix mise upgrades removing tool versions still in use by @dhh
- Fix oversized 1Password windows on scaled displays by @dhh
- Switch Broadcom Wi-Fi to the DKMS driver after Arch dropped the prebuilt module by @ryanrhughes
Security
- Harden mise command-wrapper input handling by @Adolanium
- Restrict plugin access to authentication services by @acrogenesis, @barmstrong, @ryanrhughes
- Require expiry setup for temporary passwordless sudo by @ErikMelton
- Harden locate indexing with packaged service defaults by @ryanrhughes
- Harden ownership of installed sleep hooks by @acrogenesis
- Harden lock-screen authentication command lookup by @mdisec
- Restrict Kitty remote control to local sockets by @ryanrhughes
Changes since v4.0.2
Full diff: 13 commands added, 0 removed; 0 keybindings added, 0 removed.
Migrations this upgrade ran (9)
Each is a script that ran once on your machine during omarchy update. Descriptions are the scripts' own messages.
- 2026-08-20 Stop mise upgrades from pruning versions still in use src
- 2026-08-26 Install the Hermes CLI wrapper for existing installs src
- 2026-08-27 Link Omarchy agent skills into Hermes skill directories src
- 2026-09-05 Install Cursor CLI via mise wrapper src
- 2026-09-05 Hand Hermes Desktop the Omarchy theme as a skin src
- 2026-09-06 Repair user-owned system-sleep hooks and hybrid GPU service configuration src
- 2026-09-06 Install Muse Code via mise wrapper src
- 2026-09-07 Update Kitty configuration src
- 2026-09-08 Retire the stock user icon font missed by the Quattro upgrade src
Unofficial mirror of public release data. Notes 漏 the Omarchy authors (MIT repository). Bare #numbers are linked to the upstream issue tracker.