Omarchy 4.0.1 is available as a security-focused update for the Arch Linux-based desktop distribution created by David Heinemeier Hansson. The release notes describe it as a fast follow-up to the Omarchy 4 Quattro release.

The project lists several changes in the 4.0.1 release. One change limits Claude and Codex agent launches to an auto-review path instead of a full bypass. That setting is designed to place a review step between an AI tool and system-level actions.
Other fixes address a video title being used as a download command, installed themes that could run code and a FIDO2 setup file being placed at a predictable temporary path. FIDO2 is a security standard used by hardware keys and passkeys.
The release also changes notification click actions to use safe argument handling. It removes a command that could reset a sudo lockout, makes Docker group membership opt-in and guards a plugin installation path against Git transport-helper URLs.
Omarchy’s GitHub release page tells existing users to update through the Omarchy menu. New installations can use the published ISO and verify the SHA256 value listed on the release page. That hash is a way to check whether a downloaded file matches the project’s published file.
The Register reported that Omarchy 4.0.1 followed the distribution’s Quattro release and described Omarchy as a customized Arch Linux system. Its coverage also placed the security update in the project’s wider effort to bring more structure to a fast-moving desktop environment.
The release does not turn Omarchy into a general-purpose security guarantee. It addresses specific code paths named in the notes. Users still need to update the system, review installed software and follow the project’s responsible-disclosure process if they find another issue.
Omarchy 4.0.1 is therefore a maintenance story rather than a new desktop launch. The useful change is the list of concrete protections and safer defaults. The project has published the update, its checksum and the upgrade route, giving users a way to verify the package before installing it.



