Download Latest Version Caprock_0.107.7_x64-setup.exe (9.4 MB) Google Add to Preferred Sources
Home / v0.73.1
Name Modified Size InfoDownloads / Week
Parent folder
caprock_0.73.1_windows_amd64.zip 2026-10-05 9.5 MB
caprock_0.73.1_windows_arm64.zip 2026-10-05 8.7 MB
checksums.txt 2026-10-05 600 Bytes
caprock_0.73.1_darwin_amd64.tar.gz 2026-10-05 9.4 MB
caprock_0.73.1_darwin_arm64.tar.gz 2026-10-05 8.9 MB
caprock_0.73.1_linux_amd64.tar.gz 2026-10-05 9.3 MB
caprock_0.73.1_linux_arm64.tar.gz 2026-10-05 8.7 MB
README.md 2026-10-05 777 Bytes
v0.73.1 source code.tar.gz 2026-10-05 9.3 MB
v0.73.1 source code.zip 2026-10-05 9.7 MB
Totals: 10 Items   73.5 MB 0

Security

  • A tunnel on the Mac no longer hands out the owner's rights. Caprock trusted any request that reached it over 127.0.0.1, so cloudflared, ngrok, Caddy, tailscale serve or ssh -R running on the machine let anyone who reached the tunnel read everything and start commands, with no pairing. A loopback request that carries a proxy header (X-Forwarded-*, Forwarded, Via, X-Real-IP, CF-*, Tailscale-*, Ngrok-*, …) or names a host other than localhost or a loopback address is now treated as a device: it needs a paired device's token and gets that device's role, and without one it gets 401 — on the API and on both WebSockets. The CLI, the hook shim, the statusline, the dashboard and an ssh -L forward are unchanged.
Source: README.md, updated 2026-10-05