OMG / security

Security,
in the open.

Safer installation defaults, with fewer security settings to assemble yourself. Follow the protections and the code behind them.

Explore the updates
01 / BEFORE INSTALL

Check what comes in.

Managed npm tool installs check signatures before activation. Python tool installs require wheels by default, keeping source-build execution an explicit exception.

02 / DURING INSTALL

Limit what runs.

Managed installers use controlled configuration and Linux privilege restrictions. AUR builds use a separate Bubblewrap policy with a private home and no build network by default.

03 / AFTER INSTALL

Keep the evidence.

Managed-tool receipts record policy and executable hashes. Staged replacements and activation rollback help preserve a working tool when an update fails.

These protections are implemented in PR #399; check release notes for your installed version. They apply to OMG-managed operations, including omg tool install. Selecting Node with OMG does not change direct npm commands. Compare the defaults and evidence.

The ongoing work

A record you can read.

Release hardening PR
Synced with GitHub · refreshes every 5 minutes

24 updates · Review and merge status are labeled individually.

The hardening in PR #399 is merged. This feed follows main in both repositories. On main means merged; it does not imply the fix is in your installed release. Check the release notes for the tagged build you use.

run handoff fixtures without root privileges

On main

This update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.

View commit 44630618

describe security updates as newer CLI checkout (#123)

On main

This update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.

View commit b95c11c7

align website security claims with CLI coverage (#122)

On main

* docs: align security claims with released and current CLI behavior * docs: mark pending audit controls and narrow Rekor claim

View commit 15205d9a

add live security updates page (#106)

On main

feat(security): add live security updates page

View commit 8728f58f

show merged hardening as on main

On main

This update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.

View commit 2689828a

explain managed-install benefits and review status

On main

This update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.

View commit fd222b32

add live security updates page

On main

This update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.

View commit 37d45dab

enforce tool privileges without unsafe

On main

The Linux installer privilege restriction is applied through a safe process-launch path, removing the custom unsafe pre-execution block.

View commit b76bf0c7

deny installer privilege gains

On main

Managed installers receive closed standard input and Linux no_new_privs, limiting privilege gains through executable setuid, setgid and file capabilities.

View commit 35923ad4

hash managed tool entrypoints

On main

Security receipts include streaming SHA-256 hashes of published executable and script targets, using paths relative to the installation.

View commit 8bb84cbc

roll back failed tool activation

On main

The previous managed-tool directory is retained through activation. Failed command linking triggers restoration and cleanup of broken links from the failed version.

View commit 8e44e924

contain managed tool binary links

On main

Tool binary entries are resolved and checked against their installation directory before activation and again when shared command links are created.

View commit a246f423

record managed tool policy receipts

On main

Each managed installation stores a security receipt describing its source policy, active exceptions and effective verification and build settings.

View commit 1fc5d2a8

block parent manager configuration

On main

Secured manager commands run outside the project tree. Cargo configuration is isolated and pip configuration files are disabled to limit inherited source settings.

View commit 7b0749d2

isolate tool manager resolution

On main

The resolved manager executable is retained for user-managed runtimes, while project-local manager selection is rejected by the secured command builder.

View commit 503145cc

reject alternate tool package sources

On main

Manager-specific package-name rules reject local paths, Git shorthands and alternate-source specifications for registry-backed tool installs.

View commit cbc9f73c

constrain Go tool builds

On main

Go tool installs disable CGO and automatic toolchain downloads by default. Each capability has its own package-specific exception.

View commit a5a9ec2b

verify npm packages before scripts

On main

npm first installs with lifecycle scripts disabled, then runs signature checks. An explicitly approved script rebuild happens after verification.

View commit d356fee5

surface tool policy overrides

On main

Every matching package-specific security override is printed before installation, so exceptions remain visible when installing or updating tools.

View commit f4a89bd4

pin tool installer executable path

On main

Installer child processes use a restricted executable search path instead of inheriting every directory from the calling shell.

View commit 4c8c1917

harden managed tool installations

On main

Managed npm, Cargo, pip and Go installs use a separate home and configuration. Defaults disable npm lifecycle scripts, require Python wheels and use Cargo lockfiles, with explicit compatibility exceptions.

View commit fe9cee6d

Require Reproducible Builds for High-Risk AUR Packages

On main

Selected high-risk AUR packages require a second build whose output matches before installation. The policy covers sensitive integration content and privileged package features.

View commit 03c692da

Harden Package-Manager Privilege Boundaries

On main

Package-manager hardening strengthens trusted executable selection, privilege boundaries and AUR artifact handling, alongside runtime verification improvements.

View commit ae5b6738

Harden web boundaries and synchronize the safe installer (#105)

On main

* Fix authentication and ingestion boundaries and enforce CI toolchain ordering * Update Cloudflare test and build tooling to patched sharp closure * Keep dashboard credential helper private to its handler * Pin reviewed installer snapshot and preserve public artifact bytes * Throttle internal firehose requests and protect all API responses * Synchronize safe installer replacement and clarify analytics bounds * Update public installer fixture for reviewed replacement semantics

View commit ee38a722

Automatically selected from recent public commits using security and hardening titles. Counts describe this feed, not vulnerabilities or completed audits. A commit on main does not necessarily mean it is in a published release. See release notes.

Keep the conversation open

Found something?
Tell us privately.

Send a description, the affected version and steps to reproduce. We’ll investigate and work toward a fix.

Report a vulnerability Read the security documentation