A security issue in Omarchy’s default Docker configuration meant that
essentially every program running in the user’s desktop session could escalate
to root without a password, sudo, or a privilege prompt.
If you use Omarchy, the most important takeaway is
simple: update to 4.0.1.
I reported this issue privately through the project’s responsible-disclosure
process. The underlying configuration has since been patched, so I’m publishing
the details now to explain what the issue is and let users know to update their
systems.
Seconding Niri, but also I’ve seen swayfx setups that have Hyprland-like aesthetics.
If you don’t care about fancy effects, I’ve been a river user for years and I like it. Nowadays it is just a compositor and the WM is separate, but river-classic (which includes a WM) has a dwm-like tag system, is programmatically configured (ie you speak to the river IPC in any language of your choosing—by default it’s a shell script but the WM just executes
~/.config/river/initon startup, so that file can be any executable), and is simple and lightweight. The new 0.4.x release separates the compositor and WM, so you can pick or write your own WM that suits your own workflow/use-case, if that’s your thing—it might not be if you don’t want customisability and you just want something that makes the decisions for you to a good enough standard.Thank you for such a good overview! I will likely hop between three advised (Niri, swayfx, and river) since it will be fun to get the feel of TWM options.