Check what comes in.
Managed npm tool installs check signatures before activation. Python tool installs require wheels by default, keeping source-build execution an explicit exception.
OMG / security
Safer installation defaults, with fewer security settings to assemble yourself. Follow the protections and the code behind them.
Explore the updatesManaged npm tool installs check signatures before activation. Python tool installs require wheels by default, keeping source-build execution an explicit exception.
Managed installers use controlled configuration and Linux privilege restrictions. AUR builds use a separate Bubblewrap policy with a private home and no build network by default.
Managed-tool receipts record policy and executable hashes. Staged replacements and activation rollback help preserve a working tool when an update fails.
These protections are implemented in PR #399; check release notes for your installed version. They apply to OMG-managed operations,
including omg tool install. Selecting Node with OMG does not change direct npm commands. Compare the defaults and evidence.
The ongoing work
24 updates · Review and merge status are labeled individually.
The hardening in PR #399 is merged. This feed follows main in both repositories. On main means merged; it does not imply the fix is in your installed release. Check the release notes for the tagged build you use.
This update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.
View commit44630618This update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.
View commitb95c11c7* docs: align security claims with released and current CLI behavior * docs: mark pending audit controls and narrow Rekor claim
View commit15205d9afeat(security): add live security updates page
View commit8728f58fThis update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.
View commit2689828aThis update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.
View commitfd222b32This update is recorded in the project’s public commit history. Open the commit for the complete change and discussion.
View commit37d45dabThe Linux installer privilege restriction is applied through a safe process-launch path, removing the custom unsafe pre-execution block.
View commitb76bf0c7Managed installers receive closed standard input and Linux no_new_privs, limiting privilege gains through executable setuid, setgid and file capabilities.
View commit35923ad4Security receipts include streaming SHA-256 hashes of published executable and script targets, using paths relative to the installation.
View commit8bb84cbcThe previous managed-tool directory is retained through activation. Failed command linking triggers restoration and cleanup of broken links from the failed version.
View commit8e44e924Tool binary entries are resolved and checked against their installation directory before activation and again when shared command links are created.
View commita246f423Each managed installation stores a security receipt describing its source policy, active exceptions and effective verification and build settings.
View commit1fc5d2a8Secured manager commands run outside the project tree. Cargo configuration is isolated and pip configuration files are disabled to limit inherited source settings.
View commit7b0749d2The resolved manager executable is retained for user-managed runtimes, while project-local manager selection is rejected by the secured command builder.
View commit503145ccManager-specific package-name rules reject local paths, Git shorthands and alternate-source specifications for registry-backed tool installs.
View commitcbc9f73cGo tool installs disable CGO and automatic toolchain downloads by default. Each capability has its own package-specific exception.
View commita5a9ec2bnpm first installs with lifecycle scripts disabled, then runs signature checks. An explicitly approved script rebuild happens after verification.
View commitd356fee5Every matching package-specific security override is printed before installation, so exceptions remain visible when installing or updating tools.
View commitf4a89bd4Installer child processes use a restricted executable search path instead of inheriting every directory from the calling shell.
View commit4c8c1917Managed npm, Cargo, pip and Go installs use a separate home and configuration. Defaults disable npm lifecycle scripts, require Python wheels and use Cargo lockfiles, with explicit compatibility exceptions.
View commitfe9cee6dSelected high-risk AUR packages require a second build whose output matches before installation. The policy covers sensitive integration content and privileged package features.
View commit03c692daPackage-manager hardening strengthens trusted executable selection, privilege boundaries and AUR artifact handling, alongside runtime verification improvements.
View commitae5b6738* Fix authentication and ingestion boundaries and enforce CI toolchain ordering * Update Cloudflare test and build tooling to patched sharp closure * Keep dashboard credential helper private to its handler * Pin reviewed installer snapshot and preserve public artifact bytes * Throttle internal firehose requests and protect all API responses * Synchronize safe installer replacement and clarify analytics bounds * Update public installer fixture for reviewed replacement semantics
View commitee38a722Automatically selected from recent public commits using security and hardening titles. Counts describe this feed, not vulnerabilities or completed audits. A commit on main does not necessarily mean it is in a published release. See release notes.
Keep the conversation open
Send a description, the affected version and steps to reproduce. We’ll investigate and work toward a fix.
Report a vulnerability Read the security documentation