APEX-OS 2026.09.28.2Before the rename

Signed SBOM on every image, and updated documentation

From this build on, every image carries a signed software bill of materials that the update check verifies alongside the signature. The documentation in both repositories was brought up to date with the shipped system.

Released
Channel
edge
OS revision
79c275fc0
Shell revision
cb7add74

Highlights

SecuritySecurity

Every image carries a signed SBOM

Each published image now has a signed software bill of materials (SBOM) attached, and the provenance half of the update check verifies it alongside the image signature.

The SBOM is an SPDX document listing every package found in the image: the RPM set, the npm trees inside the Claude and ChatGPT desktop apps, and the Go and Rust modules inside the binaries. It is signed by the same GitHub build identity as the image.

rime-os #69rime-os dd56a92fbuild 36362322212

Developer changes

  • ImprovedDocumentation matches the shipped system

    Every current doc and README in both repositories was checked against the code and corrected, then rewritten in plain prose.

    Commands, paths, code blocks and signing fingerprints were kept exactly. The docs now cover the redesigned shell, the new boot splash, Hyprland on springs, the login screen's password shapes, the offline first boot and the scx_lavd fix.

    rime-os #69rime-shell #28

Known issues

  • Machines on images built before 2026-09-23 refuse this update

    An older update check misread the SBOM's signature and refuses attested images. A machine on an image built before 2026-09-23 needs provenance=off in /etc/apex/trust.conf for one update, which brings the fixed check.

    rime-os #69rime-os dd56a92f

Provenance

Release
2026.09.28.2
Image digest
sha256:005c718385267acb7ac691931cd4e3ebeed74fda14aa7ec701505a66ab52aece
Channel
edge
Released
2026-09-28T01:09:09.000Z

Published to every image tag (apex, daily, edge, gaming-mesa, gaming-nvidia). All of them are the edge channel today. This page explains the release; it is never consulted by an update. What a machine installs is decided by the registry and the image signature (see Security). Machine-readable: 2026.09.28.2.json.

If something is wrong

Go back to the image you were running before this one. It becomes the default at the next boot; your files and settings stay as they are.

sudo rime rollback && sudo systemctl reboot

On an APEX-named system the command is apex. You can also pick the previous entry in the boot menu. More in Rolling back and Recovery.