This is an additional set of security fixes that were validated and examined by the [Omarchy Security team](https://omarchy.org/teams/#security). If you ever find security issues with Omarchy, please follow the responsible disclosure procedure on [omarchy.org/security](https://omarchy.org/security/). 🙏
You can upgrade existing machines with `Update > Omarchy`.
Install on new machines with the ISO:
- Download: [https://iso.omarchy.org/omarchy-4.0.2.iso](https://iso.omarchy.org/omarchy-4.0.2.iso)
- SHA256: 2ef8e624aa1bec7e277e28056b8535a6c9373ba48d7ede3f1a01cb6d2373cfb8
## Improvements
- Repair legacy paths and privileged files from retired installers by @acrogenesis
- Skip Chromium's new first-run EULA by @hjanuschka
- Improve Apple display brightness detection reliability by @bastidotnet
- Point the RC channel to the dedicated release candidate repository by @ryanrhughes
- Prevent the desktop bar visibility toggle from becoming unresponsive by @ryanrhughes
- Improve automated test suite reliability by @ryanrhughes, @Skeptomenos
## Fixes
- Fix shell injection in theme and application installers by @mdisec, @Adolanium
- Fix Codex usage collection on versi
# Fast-Follow Fixes
This is mostly for a collection of security fixes that was validated and examined by the [new Omarchy Security team](https://omarchy.org/teams/#security). If you ever find security issues with Omarchy, please follow the responsible disclosure procedure on [omarchy.org/security](https://omarchy.org/security/) 🙏
You can upgrade existing machines with `Update > Omarchy`.
Install on new machines with the ISO:
- Download: https://iso.omarchy.org/omarchy-4.0.1.iso
- SHA256: 69cbb4e10d98ad831c3c9f245b5757a9d1fedfd0c9592780e977d6f950dea8c3
## Security
* Launch claude and codex agents with auto-review instead of full bypass by @dhh in #7001
* Stop a video title from becoming the Download Video play command by @acrogenesis in #7847
* Stop an installed theme from running code by @omarchybot in #7884
* Stop the FIDO2 setup staging its authfile at a predictable /tmp path by @mdisec in #7904
* Run notification click actions as safe argv by @ryanrhughes in #7926
* Remove the sudo lockout reset command by @omarchybot in #8046
* Don't put the user in the docker group; make it opt-in by @omarchybot in #8056
* Guard plugin-add against git transport-helper
# The Quattro Release
Omarchy 4 aka Quattro is the biggest release since the project started. The entire desktop shell has been reimagined in [Quickshell](https://quickshell.org): the bar, launcher, menus, notifications, on-screen displays, control panels, lock screen, and polkit agent now all live inside a single long-running shell process with a plugin architecture. That means Waybar, Walker, Mako, SwayOSD, hyprlock, hypridle, swaybg, and polkit-gnome are all gone, replaced by one coherent, fully-themed, IPC-scriptable shell.
You can upgrade an existing Omarchy installation to Quattro by first `Update > Omarchy`, then `Update > Omarchy to Quattro`.
Install on new machines with the ISO:
- Download: https://iso.omarchy.org/omarchy-4.0.0.iso
- SHA256: 9224fab3720560f771969a99a499e5f7e0f8e2d6a0681d872d52f05fb5003da4
Always take a backup of important data!
<img width="3370" height="1894" alt="screenshot-2026-08-14_17-28-56" src="https://github.com/user-attachments/assets/8ed81d7d-751f-4318-9e70-7ca175d22fd5" />
Watch the full introduction video: https://www.youtube.com/watch?v=F7fe9pa8OeE
## Headline Features
- Reimagine the entire desktop shell in [Quicksh
# Omarchy 3.8.4
Update existing installations using Update > Omarchy from Omarchy menu (Super + Alt + Space).
Install on new machines with the ISO:
Download: https://iso.omarchy.org/omarchy-3.8.4.iso
SHA256: 7bc1dc7d98f3d088e57dc06581a494ea441fb15f3edd191360fd1696931bd895
## Fixes
* Fix Neovim theme symlink pointing at the Omarchy 4 theme location by @dhh
* Fix Install > Gaming > Retroarch installer by @dhh
* Fix Foot bindings migration by @dhh
* Fix waybar not restarting correctly by @dhh
**Full Changelog**: https://github.com/basecamp/omarchy/compare/v3.8.3...v3.8.4
# Omarchy 3.8.3
Update existing installations using Update > Omarchy from Omarchy menu (Super + Alt + Space).
Install on new machines with the ISO:
Download: https://iso.omarchy.org/omarchy-3.8.3.iso
SHA256: 40c9368eeb7e021a13d0899b379517843b4839f6e7721473169369fbd0fe61ac
## Additions
- Add easier tmux pane controls with `Alt+Enter` / `Alt+Shift+Enter` / `Alt+Escape` splits, plus CSI-u `Shift+Return` encoding across Alacritty, Foot, Ghostty, and Kitty so tmux can distinguish the bindings. Existing customized configs are migrated without duplicating pane bindings or Foot sections by @dhh
- Set tmux window titles, including the hostname, for better remote server identification in Hyprland groups and migrate the settings to existing configs by @dhh
- Add `cy` alias for running Codex with full local access by @dhh
- Add `mup` alias for updating mise without the release-age guard by @dhh
- Add gtk text scaling at 0.95 on the 2026 Dell XPS 13 DX13260 by @dhh
## Fixes
- Fix the wrong keyboard layout at the LUKS prompt on Plymouth 26 by bundling `/etc/vconsole.conf` into the initramfs by @Zeus-Deus
- Fix missing Mesa Vulkan drivers on systems installed before `vu