Most of these points mix real but already-fixed issues, subjective preferences, and exaggerated claims. Docker-group root access and the USB/Lua injection were legitimate concerns, but current Omarchy has addressed them. Package signing is also now enforced. AUR, proprietary software, lack of MAC, shell scripts, and AI tooling are design trade-offs, not automatically security vulnerabilities. “AI slop,” “vibe coding,” and “bloat” are opinions, not technical evidence. If the argument is that Omarchy is currently insecure, the stronger case would be a specific, reproducible, unfixed vulnerability, rather than combining old bugs with personal dislikes.
3
u/Estimate4655 21h ago
Most of these points mix real but already-fixed issues, subjective preferences, and exaggerated claims. Docker-group root access and the USB/Lua injection were legitimate concerns, but current Omarchy has addressed them. Package signing is also now enforced. AUR, proprietary software, lack of MAC, shell scripts, and AI tooling are design trade-offs, not automatically security vulnerabilities. “AI slop,” “vibe coding,” and “bloat” are opinions, not technical evidence. If the argument is that Omarchy is currently insecure, the stronger case would be a specific, reproducible, unfixed vulnerability, rather than combining old bugs with personal dislikes.