Living ledger

Compared to stock

Same signed foundation. Stricter house rules. A first day that talks. That is how we win without forking.

This page is the living list of how Unwoke is stricter, easier, or not better than official secureblue. The four-column table stays on Features. When we ship something, it gets a line here.

Not affiliated. We overlay their already-signed images. Kernel, SELinux, hardened_malloc, firewall, USBGuard, run0 — that is still them. We did not rewrite the OS.

Checking last green…

Stock secureblue

Signed Fedora Atomic

  • Encrypt checkbox starts off
  • Flatpaks can record Pulse/PipeWire
  • NFS server masked; clients still load
  • Lockdown is opt-in, fewer folder cuts
  • Wiki, then you are on your own
  • ujust audit-secureblue checks their kernel/USBGuard/malloc — not our extra locks

Unwoke

Same kernel. Stricter house.

  • LUKS on, Argon2id 2 GiB
  • Flatpak record blocked (revert one command)
  • NFS/CIFS clients blacklisted too
  • Lockdown on, extra xdg/host-root
  • Setup window talks on day one
  • ujust unwoke-test — PASS / LOOSE / FAIL with a proof path for every overlay lock and shipped-first ticket

Selling point

Prove it on the disk

Stock can tell you their kernel story. They cannot tell you whether our 13 shipped-first locks are actually on this machine. We can. One command. Nothing unlocks.

Stock

ujust audit-secureblue is theirs: kargs, USBGuard, malloc, SELinux. It does not name RAM-disk noexec, extra Flatpak folders, Flatpak record, NFS/CIFS clients, CET, /boot 700, CA trim, or Anaconda encrypt-on. Those tickets are still open requests on their tracker.

Unwoke

ujust unwoke-test (or Setup → Test everything Unwoke added) prints PASS, LOOSE, SKIP, or FAIL plus a proof: path. Do not trust the script: see each lock yourself with the same commands. How-to: Check health.

ujust unwoke-test
== Shipped first (stock tickets still open when we shipped) ==
  PASS  #697 /dev/shm, /tmp, and /var/tmp mounted noexec,nosuid,nodev
        proof: /dev/shm: tmpfs … noexec
  PASS  #2526 cryptsetup default Argon2id memory 2 GiB
        proof: /etc/cryptsetup.conf: pbkdf = argon2id pbkdf-memory = 2097152
RESULT: PASS
13stock FEATs shipped here
0security cuts to ship them
12signed desktop images

Where we beat stock today

Stock asked for these. The living GitHub ledger keeps every ticket: still open, or they shipped after us, or we later took their better patch. Shipped first. No Flathub, no Safe Browsing off, no weaker SELinux.

Trust

Prove every lock on this PC

ujust unwoke-test — PASS/LOOSE/FAIL with a path. Stock’s audit does not cover overlay locks or those 13 tickets.

USB install

Disk encryption on

Stock Anaconda leaves Encrypt unchecked. Our stick starts with LUKS on. Untick if you must.

USB install

Harder-to-crack LUKS

Argon2id memory cost 2 GiB (RFC 9106). Stock’s installer uses a weaker compiled-in default.

Apps

Flatpak cannot record

Pulse + PipeWire capture blocked for Flatpaks. Native speakers stay. ujust set-flatpak-record off

Apps

Tighter Flatpak folders

xdg documents/download/home extras stock’s lockdown command does not force. ujust set-flatpak-lockdown off

Network

NFS/CIFS clients off

Stock only masks the NFS server. We also blacklist client modules. ujust set-network-fs on

Trust

Audit names Flatpak browsers

ujust audit-unwoke warns (fails on browserless). Stock’s audit does not list them yet.

Trust

Audit Flatpak buses

Warns if session-bus / system-bus / the Flatpak portal name is open. Stock audit does not.

USB install

NTS time on the stick

Live Anaconda uses authenticated NTS, not fedora NTP in the clear.

Network

Fuller DHCP anonymity

Release + IAID=mac on top of hostname off. ujust set-dhcp-hostname on

TLS

Mozilla CA set

Fedora extra roots blocklisted. Some gov/old CAs fail. ujust set-extra-cas on

Games

Play window

GameMode (optional sched-ext) only while the game runs. Stock leaves Xwayland/ptrace on. Pitch: Gaming. ujust play steam

Memory

noexec RAM disk

/dev/shm, /tmp, and /var/tmp cannot run payloads. ujust set-ramdisk-exec on

CPU

SHSTK + IBT on

Intel CET glibc tunables default on. ujust set-cet off

Disk

/boot is 700

Kernel image dir not world-readable. ujust set-boot-perm off

First day vs stock

Stock drops you on a hardened desktop and a wiki. We talk, then get out of the way. Locks stay on unless you pick one.

USB stick

Install Unwoke SecureBlue

Dark Anaconda, navy sidebar, our logo. The app is in the grid (stock hides liveinst). Encrypt on by default. Rebase has no installer.

Login

Setup on the dash

GNOME and Kinoite pin Unwoke setup first. Stock has no overlay conversation. Keep defaults is one button.

USBGuard

Asked in the window, default No

We do not freeze tty1 for two minutes before GNOME. Setup → USBGuard. Stock leftover is still their helper — we never silent-enable.

Games

Click Steam

Play window restores when you quit. Stock install-steam leaves Xwayland/ptrace on. Start page has Steam / Gaming / Whonix.

Updates

Signed image without a scavenger hunt

If nobody is logged in, we reboot onto the staged signed image once. If you are in a session, a Reboot button nags. Layered RPMs resume after reboot.

Easy words

Stock is a locked-down Fedora Atomic desktop with Trivalent and a curated store (Bazaar). Unwoke is that same OS with different house rules and a first-day conversation.

The one sentence people get wrong. Default Origin images are not a tighter browser than stock + Trivalent. No Vanadium patches, fat brave_t. For the same house browser as stock, plus extra locks: rebase to *-trivalent.

Scorecard

Privacy

Quieter than stock

Countme, connectivity check, DHCP hostname, thumbnails, Privacy Sandbox, Cast — off. SELinux and Safe Browsing stay. The long version is on Privacy.

House rules

Stricter by default

No store. Flathub/brew/BT/toolbox/camera off. Flatpak lockdown on. Extra Chromium packs on Origin and Trivalent flavors. Wheel off the greeter after a daily user exists.

Trust

Prove it, do not take our word

ujust unwoke-test is on the disk after the next bake. PASS means that lock is really there. FAIL means the image is wrong. Nothing unlocks.

First days

Easier to live with

Setup window, app-grid launcher, ujust why, tutorials, signed-reboot nag, three-question install picker, leftover stock steps in one menu. Same locks, less “is it broken?”

Factory

We watch the oven

Canary on their signed base, pin digest, inspect every flavor, twice-daily rebuild. Recommended Trivalent USBs wrap after each green overlay; Sunday still wraps all twelve. ISO and Pages have their own alarms. Cosign pin flakes retry. Canary hits and new keys still need a human. Full map: Factory.

Browser

Recommended = Trivalent

Stock’s jail plus extra reversible policies. Origin is still an unsuffixed GHCR name if you want Brave Origin on purpose. Browserless is for no image browser.

Where we are stricter than stock

Every line is a default. Each has a revert. Nothing here auto-unlocks.

ThingStockUnwokeRevert
Prove overlay locks on this PC ujust audit-secureblue — kernel, USBGuard, malloc. Does not list our extras or the 13 open FEATs we shipped first ujust unwoke-test — PASS/LOOSE/FAIL + proof path for every overlay lock and shipped-first ticket Hygiene. Does not unlock. Check health
GUI software store Bazaar (curated catalog) Removed. No Discover / GNOME Software either None. Use Flathub via terminal if you want apps
Flathub Verified remote typical Off until you choose ujust set-flathub verified (not full unless you mean it)
Flatpak permission lockdown Opt-in On ujust set-flatpak-lockdown off (or grant in Flatseal)
Homebrew Shipped Off ujust set-brew on
Bluetooth Available Service masked + rfkill. Wi-Fi stays ujust set-bluetooth on
toolbox / distrobox On PATH Wrappers until you opt in. podman stays ujust set-toolbox on
Camera / mic hardware Available Kernel modules + udev locked. Speakers stay ujust set-camera-mic on
Flatpak Pulse/PipeWire record Open request; not default Blocked (independent of lockdown) ujust set-flatpak-record off
Flatpak extra folders Lockdown opt-in, fewer xdg cuts xdg documents/download/… + host-root cut by default ujust set-flatpak-lockdown off
NFS/CIFS nfs-server masked; clients still load Server masked + client modules blacklisted ujust set-network-fs on
Empty-disk encryption Encrypt checkbox off LUKS on unless you untick; 2 GiB Argon2id Untick Encrypt in Anaconda (weaker)
Time (chrony) ISO: fedora NTP pool in the clear. Installed: stock chrony NTS to Cloudflare + nts.ntp.se on the stick and the installed OS ujust set-nts off
DevTools Unlocked Locked on Origin and *-trivalent ujust set-brave-devtools allow
USBGuard at first boot You must remember leftover stock Setup window after login (default No). Never silent-enable. Does not block GDM Skip, or later ujust setup-usbguard
RAM disks + /var/tmp exec allowed on /dev/shm, /tmp, and /var/tmp noexec,nosuid,nodev (bind on /var/tmp) ujust set-ramdisk-exec on
Intel CET (SHSTK/IBT) Open request; no default toggle glibc tunables on (x86_64) ujust set-cet off
/boot mode Typically 755 700 (ostree /usr is not chmod'd) ujust set-boot-perm off
Trusted CAs Full Fedora set Fedora-not-Mozilla roots blocklisted ujust set-extra-cas on
Stock user nags Deprecation / update-verify / flatpak-setup timers Masked (they can re-add Flathub or tell you to rebase to stock). Secure Boot key check stays ujust set-stock-nags on
Avahi / ModemManager Typically on Masked ujust set-extra-daemons on
Fedora countme Timer on Masked ujust set-countme on
Connectivity check HTTP to Fedora/GNOME Off ujust set-connectivity-check on
DHCP hostname / DUID / LLMNR Hostname sent; MAC random only No hostname; iaid=mac; send-release; IPv6 stable-privacy; no LLMNR/mDNS register ujust set-dhcp-hostname on
File thumbnails On (FAQ says turn off) Off ujust set-thumbnails on
Wheel on the greeter Daily user is often wheel Daily non-wheel user before GDM/SDDM, then wheel blocked from GUI ujust set-admin-split off (weaker split)
JavaScript JIT (Origin + *-trivalent) Allowed in Trivalent Blocked by policy ujust set-brave-jitless off
WebGL / WebGPU Allowed Off ujust set-brave-isolation off
Browser uniqueness Stock Trivalent crowd (small) Same binary on *-trivalent, extra packs = rarer. Phone-home off does not fingerprint sites. We still ship packs first. Read Fingerprinting vs locks Optional one pack off if you choose to blend. Not a default.
Extensions Allowed Installs blocked ujust set-brave-extensions allow
Site camera / mic / USB / geo Permission prompts Blocked by policy ujust set-brave-devices off
HTTPS / metrics / autofill / passwords Mostly compile-time on Trivalent Managed JSON pack on (additive on Trivalent) ujust set-brave-hardening off
Screen capture / extra sandbox No extra pack On ujust set-brave-sandbox off
Trivalent Network Service Sandbox Off in settings (can wipe cookies) *-trivalent only: forced on ujust set-trivalent-network-sandbox off
Punycode + strip referrers Optional flags *-trivalent: on via conf.d ujust set-trivalent-referrers off
Origin extra sandbox n/a (they do not ship Origin) Bubblejail on the Origin launcher, default on ujust set-brave-bubblejail off. Refused on Trivalent (their FAQ)
Host browsers on browserless n/a Blocked until you type ALLOW ujust set-allow-browsers on ALLOW
Update origin after first rebase You type the signed rebase First-boot stages ostree-image-signed and nags until you reboot Do not go back to unverified

Where we are easier than stock

This is the part that does not loosen a lock. Stock is also ujust. We added a conversation around the extra knobs.

Pain on stock / a raw overlayWhat Unwoke does
Hardened desktop looks “broken” (no store, no BT, sites without JIT) Unwoke setup in the app grid and on first login. ujust why maps the symptom to the lock. Tutorial button. Nothing turns off until you pick it.
Signed rebase is a second command people forget First-boot stages it. Notification every login and every 15 minutes until you reboot onto the signed image.
Twelve image names Install page: three questions (GNOME/KDE, NVIDIA, Origin/Trivalent/none). Copy buttons. Windows / Linux / macOS order.
Two post-installs (overlay + theirs) Setup → leftover stock: Secure Boot key, kargs, USBGuard, on confirm. Their page still exists. Overlay locks unchanged.
tty1 daily-user prompt looks like a hung install Installer-style “this is not frozen” dialog. Greeter still waits. Skip is still skip. Then Setup → Daily user.
Wiki of ujust commands Tutorials with the secure path first. Features table for the rest. See each lock yourself if you do not trust the script.
No overlay self-test ujust unwoke-test plus Setup → Test everything. Stock audit-secureblue still exists for kernel/USBGuard/malloc.
Mullvad / IVPN / Proton as store apps or Snap ujust install-mullvad / install-ivpn / install-proton: WireGuard or web first; official RPM only after hash + asked locks. Generic: ujust install-vendor NAME.
Stock ujust install-steam turns on unfiltered Flathub with no overlay questions; VPN helpers; Bazaar for the rest ujust install-steam / install-vpn / install-docker / enable-dangerzone / distrobox-assemble are intercepted so overlay locks are asked first. Play window: ujust play steam uses GameMode only while the game runs, then restores (stock leaves Xwayland/ptrace on). Catalog: Stock installers · Play window.
Private GHCR packages block anonymous rebase Factory job tries to set packages Public after a bake. Warn-only if GitHub’s token cannot flip it.

Factory (you never see this, you still benefit)

The living map of auto-heal vs human gates is Factory. Short version:

Stock cannot push to ghcr.io/sergi270710267. After the signed reboot, your PC follows our key, not theirs.

Where stock still wins

Ledger (what we added, so this page stays true)

Newest first. Rebuilt with the site from main (people-facing commits) plus a short seed for early history. Factory-only git (CI pins, snapshot hashes) is omitted. Overlay items still need an image rebuild. Add People: / Vs: / Where: in a commit body to write the Compared row in easy words — otherwise the git subject is used.

WhenWhat landedVs stockWhere
2026-09-09 d5383fc Close this chat; resume from PROGRESS.md on GitHub main. n/a PROGRESS.md
2026-09-09 b77ee03 Factory vendor-watch is contracts-green even when the bot cannot push HTML. n/a vendor-watch.yml, factory-push.sh, Factory GitHub map
2026-08-31 a228a94 GitHub sits with the other top links, not alone on the right. The left rail is grouped: Factory, On the disk, Project. Features and Shipped first can no longer push that rail aside. One unlabeled dump of extra pages. Wide tables used to steal the sidebar. Pages now
2026-08-31 3cb8cb1 Clicking Shipped first no longer knocks the left menu over. That page had a heading id that matched the URL, and its feat cards could shove the rail aside. Other left-rail pages already worked. Pages now
2026-08-31 e96c57c On a wide screen the primary pages stay in a slim top bar. The rest sit in a left rail so the menu is not one crowded wrap. Phones keep the wrapping bar. Stock docs still dump every page in one top row. Pages now
2026-08-31 09c1706 Factory now names every GitHub workflow, CODEOWNERS, the main-strict ruleset, receipt, and GHCR. After a green overlay, the two recommended Trivalent USBs wrap themselves. Sunday still wraps all twelve. Watch issues, not Actions. Stock has no overlay factory. Empty-disk USB used to wait until Sunday even when the overlay was already current. Pages now; USB ISO after the next green overlay
2026-08-31 852fabe DevTools lock is on the image before first boot, not only after apply-boot. USBGuard docs match Setup (not tty1). Inspect can see leftover Origin SUID under usr/lib/opt. selftest could FAIL DevTools on a fresh ostree; Features/Compared still said USBGuard on tty1. Next overlay bake; Pages now
2026-08-31 fa1483c Overlay images already composed. Inspect can see Proton NTsync on the disk. Factory stayed red on a missing-file check for a path crane never unpacked. Next overlay bake
2026-08-31 acdaea8 Overlay bake is not blocked by missing Fedora scx packages or a power-profiles vs tuned-ppd fight. Steam still uses GameMode and powerprofilesctl. Stock ujust install-docker is intercepted: leftover userns asked, podman preferred. Their FAQ documented install-docker with no Unwoke box. Our last overlay tried to bake packages Fedora 44 does not ship. Next overlay bake; Pages now
2026-08-31 b0f4060 Live USB shows Install Unwoke SecureBlue in the grid. USBGuard is asked in the GUI after login (default No) and no longer blocks GDM on tty1. Setup Start has Steam, Gaming, Whonix. Compared has First day vs stock. Stock hides liveinst, dumps USBGuard on a console before the desktop, and has no overlay conversation. Overlay bake then USB wrap; Pages now
2026-08-31 975eb13 USB installer chrome is Unwoke dark. Rebase still has no Anaconda. Install docs still sounded like stock Fedora live. Pages now
2026-08-31 6df1ebd USB Install-to-disk uses Adwaita dark, #050a16 sidebar, Unwoke logo. Same palette as the desktop. Rebase has no Anaconda. Fedora live Anaconda stayed light grey. Our live session was already dark; the installer was not. Overlay bake then next USB wrap; Pages now
2026-08-31 28699d3 After any layered RPM, next login continues the wizard. Unwoke setup is first in Kinoite Kickoff too. If a signed image is staged and nobody is logged in, reboot onto it once. Only Whonix resumed; KDE had no pin; signed rebase waited for a click even at the greeter. Next overlay bake; Pages now
2026-08-31 d028d1a Unwoke setup is first on the GNOME dash. After rpm-ostree layers KVM, next login continues the Whonix wizard. Nothing auto-unlocks. People had to hunt the app grid and remember ujust install-whonix after reboot. Next overlay bake; Pages now
2026-08-31 b014105 TCP timestamps off by default (clock-skew leak). Optional hostname host. Site Anonymity tab: hide IP with Whonix, not host Tor. Do not mix accounts. We did not add host Tor, UTC-by-default, or kloak. Those break security or make you rarer. Next overlay bake; Pages now
2026-08-31 5a92580 ujust install-whonix downloads their archive, refuses a wrong fingerprint, imports qemu:///session, turns off clipboard/USB/mic. ujust start-whonix starts Gateway then Workstation and refuses extra NICs. VirtualBox, unsigned curl, host Tor, shared clipboard. Not Qubes. Not Tails. Next overlay bake; Pages now
2026-08-31 85ad84b Persistent journals, hibernate RAM images, crash dumps, file indexers, and GTK recent-files are off by default. Not Tails — the ostree stays. Revert: ujust set-disk-traces on. Stock keeps last-boot logs and can write RAM to disk. Kicksecure/Tails go further (ram-wipe, live USB); we do not fake that. Next overlay bake; Pages now
2026-08-31 173a7c4 Click Steam. Power profile, GameMode GPU/split-lock, Proton NTsync, and sched-ext if present all turn on. Close Steam and they turn off. No kernel swap. CachyOS keeps a gaming kernel forever. We still will not. Stock still leaves holes on. Next overlay bake; Pages now
2026-08-31 bacf846 A login agent watches Steam. No need to type ujust play stop. The typed command stays as an option. The app-grid Steam icon wraps GameMode. Yesterday you still had to start/stop the window by hand. Stock still leaves holes on. Next overlay bake; Pages now
2026-08-31 15f1eb2 Site nav now has Gaming next to Privacy. Stock leaves holes after you quit. We restore. We do not swap the CachyOS kernel. There was only a how-to under Tutorials and a Setup tab on the OS. Pages now
2026-08-31 af09b69 Setup Gaming tab. ujust play steam uses Fedora GameMode for the match. Close Steam and overlay locks return. Optional asked sched-ext. No CachyOS kernel, no SMT/mitigations flip. unwoke-test FAILs if a play stamp is leftover. Stock install-steam leaves Xwayland/ptrace on. CachyOS swaps the kernel; we keep signed stock. Next overlay bake; Pages now
2026-08-31 11bd171 ujust install-steam/install-vpn/enable-dangerzone/distrobox-assemble and unfiltered Flathub now ask Unwoke locks first. Tailscale repo is watched. Stock scripts are not run blindly. Stock install-vpn can disable Unbound; assemble hits our toolbox stubs; set-flathub-unfiltered was wiped on next boot. Next overlay bake; Pages now
2026-08-31 00cfaa9 ujust install-steam still installs the stock Flathub Steam Flatpak, but asks before unfiltered Flathub, per-app Steam grants, temp noexec, mic, and Bluetooth. Nothing silent. Stock install-steam turns on unfiltered Flathub and skips our lockdown / noexec / mic / BT. Games would not run at their best here. Next overlay bake; Pages now
2026-08-31 8bdb0b6 Payloads that dodge RAM noexec by using /var/tmp cannot exec. Same revert: ujust set-ramdisk-exec on. unwoke-test FAILs if /var/tmp lacks noexec. Stock #697 was only /dev/shm and /tmp. Persistent temp stayed executable. Next overlay bake; Pages now
2026-08-30 31204c2 Other-PC resume is git pull + continuing Unwoke from PROGRESS.md on main. n/a GitHub main
2026-08-30 08c44db NTS on the installed OS, DevTools locked by default, USBGuard asked once (never silent), compose chmod 700 on module dirs, Origin no longer dnf-removes Trivalent. unwoke-test FAILs if noexec or CA trim is not live. Stock ISO NTP is still cleartext; DevTools unlocked; no USBGuard prompt; /usr/src still 755; audit does not fail-closed on those. Next overlay bake; Pages now
2026-08-30 f7876b4 Compared and Features now list every extra lock that was only on Shipped first or the toggle table. Privacy notes resolved drop-in. Those rows were missing from the vs-stock tables even though the OS shipped them. Pages now
2026-08-30 33fbd50 If you do not trust ujust unwoke-test, a tutorial walks each shipped-first ticket and house lock with read-only commands and what healthy output looks like. Stock has no per-lock overlay proof page. Pages now; offline help on next overlay bake
2026-08-30 892cc4d Compared, Home, and Features now put ujust unwoke-test first: PASS/LOOSE/FAIL with a path. Stock audit-secureblue does not cover our extras. Stock has no overlay self-test and those 13 FEATs are still requests. Pages now
2026-08-30 19b07eb unwoke-test now names #391 #697 #887 #1185 #1295 #1569 #1606 #1885 #2156 #2354 #2432 #2508 #2526 with a proof path, not only generic locks. Stock still has those as open requests. Users can see our implementation is actually on the disk. Next overlay bake; Pages now
2026-08-30 ed499e2 Users can run one command (or Setup) and see PASS/LOOSE/FAIL with a proof path for every Unwoke addition. Nothing unlocks. Stock audit-secureblue does not list overlay locks. Ours did not either until now. Next overlay bake; Pages now
2026-08-30 db68456 The Factory page now walks the twice-daily overlay, Sunday all-12 USB, flake retries, and what still needs a human. Stock’s site does not publish this overlay’s bake clock. Ours was still describing four Trivalent USBs and 14-day artifacts. Pages now
2026-08-30 2dfcc9f Perpetual factory: weekly all-12 USB, stale-bake alarm, idle heartbeat. USB ISO
2026-08-30 d5284fd Auto-wrap Origin USB after a green bake; rerun pin-only cosign flakes once. USB ISO
2026-08-30 8814edd Install livesys/anaconda on Origin USB without dnf; curl Brave RPMs. Next overlay bake
2026-08-30 51642f3 Origin USB wrap should build initramfs with dmsquash-live. justdb does not put dracut modules on disk. Re-dispatch Origin iso.yml; no overlay bake
2026-08-30 4601c9e Origin USB wrap should get past titanoboa initramfs. justdb cannot write a malformed ostree sqlite. Re-dispatch Origin iso.yml; no overlay bake
2026-08-30 56a7316 Origin overlay should inspect green, then USB wrap. rpm -i relocates /opt; rpm2cpio keeps usr/lib/opt. Overlay bake now; Origin iso.yml after that bake is green
2026-08-30 d3854b9 Origin compose should get past install-brave-origin.sh. Throwaway dnf must not talk to repo.secureblue.dev. Overlay bake now; Origin iso.yml after that bake is green
2026-08-30 fac79ef Origin USB wrap should dnf like browserless (readable Packages). Stock ISO does not extra-dnf Brave. We no longer extra-dnf it either. Overlay bake now; Origin iso.yml after that bake is green
2026-08-29 Vendor-watch, Setup Strict apps, and ujust install-vendor iterate every vendors{} key. New app = JSON stanza. Heal still HTTPS+checksum only. Next strict app is not a Proton/IVPN special case. CI and search include it automatically. Actions + overlay (manifest on disk)
2026-08-29 ujust install-ivpn / install-mullvad / install-proton: WireGuard or Trivalent first; official RPM/repo only after checksum or gpgcheck and an asked extra origin. No store, no Snap, no unverified Flathub. Easier than hunting RPMs. Stricter than stock Bazaar/Snap. Overlay bake + Pages tutorials
2026-08-29 GTK Unwoke setup, app-grid search for locks, You loosened, offline help, repeating signed-reboot nag with a Reboot button, Trivalent as the recommended default. Easier first day. Same locks. Origin is an explicit pick. Overlay bake + Pages
2026-08-29 USB ISO baker (Titanoboa wrap) plus rebase path. Not Ventoy. Their Secure Boot key. Empty disk without installing stock first. Their ISO picker is still nicer. Weekly ISO + GHCR -iso
2026-08 Canary + digest pin + post-publish inspect + twice-daily bake + factory-alarm. *-trivalent / Origin / browserless. No Bazaar; Flathub/brew/BT/toolbox/camera off; extra Chromium packs; admin-split. Hostile-in-the-clear base cannot silently become our GHCR image. Stricter house; every extra lock has a revert. 12 GHCR images + Actions

Day-by-day git subjects: Changelog. Toggle list: Features. How to actually do the tasks: Tutorials.