Commit Graph
893 Commits
Author SHA1 Message Date
dhhandgithub-actions[bot] 68bdaff26e chore: sync upstream releases 2026-09-01 05:20:42 +00:00
Ryan Hughes 246eea9620 Fix Hermes Desktop keyring detection on Hyprland
Default Electron to the gnome-libsecret password store so Hermes can use GNOME Keyring for secure remote tokens. Declare libsecret as a runtime dependency.
2026-08-30 23:49:02 -04:00
Ryan Hughes 4c41157163 Release omarchy 4.0.2 2026-08-30 23:22:02 -04:00
Ryan Hughes cb84ec0e69 Pin omarchy 4.0.2rc2 on master so edge carries it
Edge is the channel the 4.0.2 RC ISOs point pacman at until the rc-channel
migration lands, but edge only carried omarchy 4.0.1 — older than the
installed 4.0.2rc1, so those installs never saw an upgrade. Bumping master's
pin lets the normal edge pipeline build and publish 4.0.2rc2, whose migration
repoints [omarchy] at the rc channel.

Stable is unaffected: pinned packages never build for stable
(package_builds_for_mirror), it only receives them via the rc->stable advance
at ship time.

(cherry picked from rc-branch pin commit 11767d6)
2026-08-30 16:26:37 -04:00
Ryan HughesandGitHub 4a87a738b2 Number asdcontrol's sudoers policy and add it to the fast ring (#243)
* Use a numbered asdcontrol sudoers priority

* Add asdcontrol to the fast ring
2026-08-30 13:02:46 -04:00
Ryan HughesandGitHub 30d03c4d26 Scope asdcontrol's passwordless sudo grant (#242)
Ship the least-privilege rule with asdcontrol so authorization follows the package lifecycle. Install it after older broad rules for safe staggered upgrades.
2026-08-30 12:59:21 -04:00
Ryan Hughes cf39173553 Revert "Add hey-cli to the fast ring"
This reverts commit 3bfc267a0e.
2026-08-29 13:36:56 -04:00
Ryan Hughes 3bfc267a0e Add hey-cli to the fast ring 2026-08-29 12:09:48 -04:00
Ryan HughesandGitHub 6daa7c90e4 Stage CUPS authorization as settings override (#237) 2026-08-29 02:19:29 -04:00
Ryan Hughes 391b5a201f t3code-patched-bin: 0.0.35-5, rebuilt from v0.0.35-omarchy.5 2026-08-28 22:33:11 -04:00
Ryan HughesandGitHub 4776db7f31 Merge pull request #213 from jeremydixon22/fix/asusctl-6.4.0
Update asusctl to 6.4.0
2026-08-28 18:31:57 -04:00
Ryan Hughes f48d528ca4 t3code-patched-bin 0.0.35-4: rebuild after review
Same upstream release, so only pkgrel moves. Built from v0.0.35-omarchy.4,
which carries the fixes from nine rounds of review on the upstream PR: the
CLI no longer overwrites an unreadable settings.json, setting a
single-appearance theme actually switches the client, reconnects no longer
flash published themes back to stock, and already-shipped clients keep
their config subscription instead of losing it to an unknown event.
2026-08-28 17:46:51 -04:00
Ryan Hughes f84c89d8b3 t3code-patched-bin: record the full artifact-shipping recipe
Comment-only. The .env requirement and the fact that only a PKGBUILD
version change triggers the build server both bit us once each; the
recipe now lives where the next rebuild starts.
2026-08-28 01:32:02 -04:00
Ryan Hughes dd8fd2fed7 t3code-patched-bin 0.0.35-3: bake T3 Connect public config
The r2 artifact was built without the public Connect configuration official
artifacts carry (relay URL, Clerk publishable key, CLI OAuth client id), so
Connect prompted for login with no way to log in. Same code, rebuilt with
the configuration recovered from the published npm t3 package.
2026-08-28 01:27:55 -04:00
Ryan Hughes 267dbdefaa t3code-patched-bin 0.0.35-2: post-review rebuild, fast ring
Rebuilt from v0.0.35-omarchy.2 of the environment-theme branch: the stream
event is capability-gated so old clients keep their config subscription,
republish dedupe is structural, the connect stream is gap-free, default
adoption is scoped per environment and keyed on the set generation, and
reserved theme ids cannot be published over. Joins the fast ring like
t3code-bin so patch rebuilds reach machines quickly.
2026-08-28 01:07:37 -04:00
Ryan Hughes 0fb1c09041 t3code-patched-bin: T3 Code with the environment-theme patches
Built from the environment-theme branch of ryanrhughes/t3code (tag
v0.0.35-omarchy.1) until upstream ships it: the app follows themes the
machine publishes into its state directory -- Omarchy retints it live --
and t3 theme set works. Same packaging as t3code-bin, conflicts with it,
and the next upstream release supersedes it after a rebase.
2026-08-27 23:55:15 -04:00
Ryan Hughes 273dd810da t3code-bin: ship the bundled server CLI as /usr/bin/t3
The desktop bundle already contains the full server -- the same entrypoint
npm's t3 package runs -- so a launcher that starts it through the bundled
Electron as Node puts the CLI on PATH without a second runtime. Upstream
only distributes the CLI via npm, which Omarchy's install scripting cannot
assume.
2026-08-27 23:55:15 -04:00
Ryan HughesandGitHub 01a95d9c28 Merge pull request #217 from fvdb/update-grok-bot-0.29.0
Update grok-bot to 0.29.0
2026-08-27 23:27:32 -04:00
Ryan HughesandGitHub 02d0c4ccd1 Merge pull request #225 from omacom/auto/sync-upstream
chore: sync upstream releases
2026-08-27 23:27:03 -04:00
dhhandgithub-actions[bot] 26ad901df7 chore: sync upstream releases 2026-08-27 22:26:09 +00:00
ryanrhughesandgithub-actions[bot] 84226bd3d1 chore: sync AUR packages 2026-08-27 21:58:26 +00:00
Ryan Hughes dbb5e72051 Build fast-ring for rc as rc, instead of copying stable's artifacts
The rc channel's Arch base can sit anywhere between stable's snapshot and
edge's, so a package built against stable's libraries is not necessarily
correct for rc. Copying stable's fast-ring artifacts into rc therefore shipped
possibly-mislinked packages to RC testers. Fast-ring packages now build
natively for all three channels, each in its own image against its own base
mirror, and the stable release's replication step is gone.

That required separating 'may be built here' from 'whose version wins'. The
release pair is now marked "pinned": its version is set per release on the rc
branch, so it builds for rc only from that branch's worktree
(OMARCHY_RC_PINS=1, set by omarchy-release rc) — master's shipped pins can
never overwrite an in-flight RC, even though check-versions now discovers rc
work like it does for edge and stable.
2026-08-27 12:39:29 -04:00
OmabotandClaude Opus 5 b7c51f84d4 Update aether to 4.29.6
Synced from the AUR at 04592d5. Two upstream releases land together: 4.29.5
hardened the aether protocol imports and moved the repository links from
bjarneo to omacom-io, which is why the url and every source line change here
as well; 4.29.6 disables WebView GPU acceleration on Linux. The packaging
itself is untouched between the two -- only pkgver and the checksums differ --
so taking HEAD rather than pinning 4.29.5 costs nothing and carries the
hardening either way.

aether is fast ring, so this reaches stable without an edge-to-stable
migration once it is built for that mirror.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-27 15:13:19 +00:00
Frank van den Brink 01226e6e66 Update grok-bot to 0.29.0
Pin the official Linux .deb to Cursor stable 0.29.0 (commit f0e5bfce).
Binary, icons, and grokbot:// handler are unchanged from 0.24.0; keep the
Wayland wrapper and /usr/bin/sand compat symlink.

Linux still has no update feed. Leave pinning to update-pkgver.sh.
2026-08-27 17:10:00 +02:00
Ryan HughesandGitHub 370c37670b Merge pull request #211 from tobi/update-omasnap-1.20.0
omasnap: update to 1.20.1
2026-08-27 11:01:26 -04:00
Ryan HughesandGitHub 23739852a5 Merge pull request #207 from omacom-io/auto/sync-upstream
chore: sync upstream releases
2026-08-27 11:01:21 -04:00
dhhandgithub-actions[bot] 28cf03aaca chore: sync upstream releases 2026-08-27 10:00:32 +00:00
Jeremy Dixon 898b256c61 Update asusctl to 6.4.0 2026-08-27 04:51:26 -04:00
ryanrhughesandgithub-actions[bot] 621576ab71 chore: sync AUR packages 2026-08-27 08:06:24 +00:00
Ryan Hughes 1512cb48d8 chore: sync t3code-bin to 0.0.34
Matches what is already published to edge: 0.0.34 was built on the server
before the bump reached git, so the checkout read as out of date and queued a
rebuild of the older 0.0.33-2 that promotion then refused. Produced by
bin/sync-upstream, the same path the scheduled workflow uses.
2026-08-27 01:16:55 -04:00
Ryan Hughes 26bde8fae3 Add channels metadata: membership and build-channel rules for edge/rc/stable
A package's .omarchy/package.json may now pin where it lives with
"channels": [...]. With the key present the package builds in each listed
channel except stable (stable is only fed by promotion); without it, today's
defaults hold (build for edge; fast-ring also builds stable directly).

package_moves_to_channel() is the advance/promote eligibility rule: a member
of the destination channel that is not built there natively.

The release pair (omarchy, omarchy-settings) is edge+rc+stable — edge stays
during the client-migration overlap window and drops later. The dev pair is
pinned to edge only.
2026-08-27 01:10:33 -04:00
Tobi Lutke 633b6e22f9 omasnap: update to 1.20.1 2026-08-26 22:17:37 -04:00
Tobi Lutke 317a7bd197 omasnap: update to 1.20.0 2026-08-26 20:28:01 -04:00
default 9eb78bc832 chore(mise): bump to 2026.8.14 2026-08-26 08:06:08 +00:00
Ryan HughesandGitHub f448847d1f Merge pull request #205 from omacom-io/auto/sync-upstream
chore: sync upstream releases
2026-08-25 18:55:02 -04:00
dhhandgithub-actions[bot] 84cdb1b9f2 chore: sync upstream releases 2026-08-25 19:05:01 +00:00
ryanrhughesandgithub-actions[bot] 262dfd11b2 chore: sync AUR packages 2026-08-25 18:44:05 +00:00
David Heinemeier HanssonandGitHub 0ea0c5f8d1 Merge pull request #150 from spencerbull/dell-xps13-sidecar-amps
Add Dell XPS 13 sidecar amplifier workaround
2026-08-25 17:47:02 +02:00
David Heinemeier Hansson 044e81c636 Release omarchy 4.0.1 2026-08-25 13:04:07 +02:00
David Heinemeier Hansson 4db463cf3c Release omarchy 4.0.1rc5 2026-08-25 12:17:41 +02:00
David Heinemeier Hansson bf1f3e0d8e Release omarchy 4.0.1rc4 2026-08-25 09:28:21 +02:00
David Heinemeier HanssonandGitHub 292d27a4e4 Merge pull request #166 from omacom-io/hermes-agent
Add hermes-desktop
2026-08-25 07:49:30 +02:00
ryanrhughesandgithub-actions[bot] d839d8a49f chore: sync upstream releases 2026-08-25 02:45:50 +00:00
Ryan HughesandGitHub 4b1226ec17 Merge pull request #202 from omacom-io/mise-release-age-fallback
Quarantine fresh upstream releases via min_release_age in the package manifest
2026-08-24 22:44:17 -04:00
Ryan Hughes 699261471a Replace mise's upstream hook with a declarative GitHub-releases provider
After the quarantine moved into the manifest, all mise-bin's hook still knew
was data: the repository, the checksum manifest name, and the asset filename
patterns. That now lives in .omarchy/package.json as an upstream block --

  "upstream": {
    "github": "jdx/mise",
    "checksums": "SHASUMS256.txt",
    "assets": { "x86_64": "mise-{tag}-linux-x64.tar.xz", ... }
  }

-- handled by helpers/upstream-github.sh inside bin/sync-upstream. The
provider walks the release feed (drafts/prereleases excluded), honors
min_release_age and BYPASS_MIN_RELEASE_AGE during selection, reports
published_at so the framework backstop still applies, fails closed on any
unreadable tag or timestamp, and skips the checksum fetch when the newest
qualifying release is already checked in.

upstream.sh remains the escape hatch for feeds that fit no convention
(openai-codex-desktop's Debian index, tmog's version.txt, t3code's
electron-builder manifest); declaring both is an error.
2026-08-24 19:30:33 -04:00
Ryan Hughes 48ad6b9d7b Generalize the release-age quarantine into a manifest policy
Move the hold from a mise-only hardcode to min_release_age in
.omarchy/package.json ("24h", "2d", or bare seconds), alongside source and
release_ring where package policy already lives. bin/sync-upstream exports
the window to every hook as MIN_RELEASE_AGE_SECONDS so a hook that can walk
its release feed selects the newest release that has cleared it, and
enforces it as a backstop: with a policy set, the hook must report
published_at, and a release younger than the window is treated as no
update. A hook that cannot prove the age fails the sync rather than
shipping unverified. BYPASS_MIN_RELEASE_AGE=1 replaces the package-specific
bypass for deliberate emergency updates; scheduled automation never sets it.

The mise hook keeps its release-list walk but reads the window from the
environment and reports published_at; the other upstream hooks are
untouched and unaffected until they opt in.
2026-08-24 19:17:22 -04:00
David Heinemeier Hansson 405576f4e9 Release omarchy 4.0.1rc3 2026-08-24 22:00:51 +02:00
David Heinemeier HanssonandGitHub 1e64b129a3 Merge pull request #185 from tobi/update-omasnap-1.16.0
omasnap: update to 1.19.1
2026-08-24 21:56:47 +02:00
David Heinemeier HanssonandGitHub 720a21f5e9 Merge pull request #198 from fvdb/update-grok-bot-0.24.0
Update grok-bot to 0.24.0
2026-08-24 21:52:10 +02:00
ryanrhughesandgithub-actions[bot] 5b51263adf chore: sync AUR packages 2026-08-24 18:44:12 +00:00