Ranch Hand v0.1.0-rc.26 — Public Preview
Ranch Hand v0.1.0-rc.26 installs the verified RepoWrangler v1.0.16 release.
Downloads
Expected executable SHA-256:
7d86d3d3f8a033d0d62af80d6878e2ede55e60c0bc4373fc4953edd6849421e8Corrected first-run setup
Fresh real-mode deployments now select GitHub or Microsoft Entra ID administrator identity before connecting repositories. Setup remains available until the first allowlisted administrator completes a verified sign-in.
GitHub App manifests generated on loopback, private-network, or non-public HTTP deployments no longer request a webhook URL that GitHub cannot reach. These deployments use scheduled and manual synchronization. Public HTTPS deployments continue to receive webhook event subscriptions.
Remote real-mode installations receive a one-time setup token in the protected runtime environment. Ranch Hand shows that token and the exact private-LAN URL only in the active installation result.
Verification
RepoWrangler v1.0.16 passed dependency audit, typecheck, 230 unit tests, 11 release-contract tests, CodeQL, built-server smoke, container first-run smoke, and immutable bundle assembly before publication.
Ranch Hand then independently downloaded the public RepoWrangler release, verified its manifest, checksums, OCI identities, image labels, and Compose bundle, loaded the offline image, and exercised first-run identity configuration through Docker Compose. The test confirmed that the loopback GitHub App manifest contains no webhook fields.
The public RC26 Windows executable was downloaded again after publication, matched its published checksum, booted successfully, and reported the exact v0.1.0-rc.26 and windows/amd64 identities.