A security issue in Omarchy’s default Docker configuration meant that
essentially every program running in the user’s desktop session could escalate
to root without a password, sudo, or a privilege prompt.
If you use Omarchy, the most important takeaway is
simple: update to 4.0.1.
I reported this issue privately through the project’s responsible-disclosure
process. The underlying configuration has since been patched, so I’m publishing
the details now to explain what the issue is and let users know to update their
systems.
The hard question becomes is it better for Linux (where anyone can contribute) to get the attention and donations or for commercial software where only nonhuman corporations benefit.
The more power such people have in such positions, the more money they get, the worse it gets. And the bigger the cult might get, which could suck people into the views and so on. Do not underestimate that.