Omarchy 4.0.2 ships security, automation fixes
Omarchy 4.0.2 hardens its agentic Arch-based Linux desktop with signed-package enforcement, shell-injection fixes, stronger SSH and privilege controls, and more reliable automated testing. The update is available through Omarchy’s built-in updater or a new ISO; see the release notes at https://github.com/omacom/omarchy/releases/tag/v4.0.2 and the project homepage at https://omarchy.org/.
This is less a feature update than a trust-boundary reset: an agent-ready developer workstation must treat installers, plugins, and inherited permissions as security-critical code.
- –Signed packages and hardened CUPS, Plymouth, SDDM, browser-policy, and sudoers paths improve supply-chain and privilege safety.
- –Shell-injection fixes plus URL and desktop-entry validation directly reduce risk from themes, web apps, and other user-controlled inputs.
- –SSH password authentication is disabled by default, while input and SSH escalation paths receive additional protection.
- –More reliable automated tests make Omarchy a stronger candidate for repeatable AI-agent desktop benchmarks and controlled development environments.
- –Core hardening still does not fully solve extension risk: Omarchy’s plugin-security discussion notes that plugins currently execute inside the main Quickshell process, leaving isolation as an open concern (discussion: https://github.com/omacom/omarchy/discussions/8957).
DISCOVERED
2h ago
2026-09-02
PUBLISHED
2h ago
2026-09-02
RELEVANCE
AUTHOR
The PrimeTime