Skip to content

Ranch Hand v0.1.0-rc.26 — Public Preview

Ranch Hand v0.1.0-rc.26 installs the verified RepoWrangler v1.0.16 release.

Downloads

Expected executable SHA-256:

text
7d86d3d3f8a033d0d62af80d6878e2ede55e60c0bc4373fc4953edd6849421e8

Corrected first-run setup

Fresh real-mode deployments now select GitHub or Microsoft Entra ID administrator identity before connecting repositories. Setup remains available until the first allowlisted administrator completes a verified sign-in.

GitHub App manifests generated on loopback, private-network, or non-public HTTP deployments no longer request a webhook URL that GitHub cannot reach. These deployments use scheduled and manual synchronization. Public HTTPS deployments continue to receive webhook event subscriptions.

Remote real-mode installations receive a one-time setup token in the protected runtime environment. Ranch Hand shows that token and the exact private-LAN URL only in the active installation result.

Verification

RepoWrangler v1.0.16 passed dependency audit, typecheck, 230 unit tests, 11 release-contract tests, CodeQL, built-server smoke, container first-run smoke, and immutable bundle assembly before publication.

Ranch Hand then independently downloaded the public RepoWrangler release, verified its manifest, checksums, OCI identities, image labels, and Compose bundle, loaded the offline image, and exercised first-run identity configuration through Docker Compose. The test confirmed that the loopback GitHub App manifest contains no webhook fields.

The public RC26 Windows executable was downloaded again after publication, matched its published checksum, booted successfully, and reported the exact v0.1.0-rc.26 and windows/amd64 identities.

Apache-2.0 licensed. Read-only by design.