| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| caprock_0.73.1_windows_amd64.zip | 2026-10-05 | 9.5 MB | |
| caprock_0.73.1_windows_arm64.zip | 2026-10-05 | 8.7 MB | |
| checksums.txt | 2026-10-05 | 600 Bytes | |
| caprock_0.73.1_darwin_amd64.tar.gz | 2026-10-05 | 9.4 MB | |
| caprock_0.73.1_darwin_arm64.tar.gz | 2026-10-05 | 8.9 MB | |
| caprock_0.73.1_linux_amd64.tar.gz | 2026-10-05 | 9.3 MB | |
| caprock_0.73.1_linux_arm64.tar.gz | 2026-10-05 | 8.7 MB | |
| README.md | 2026-10-05 | 777 Bytes | |
| v0.73.1 source code.tar.gz | 2026-10-05 | 9.3 MB | |
| v0.73.1 source code.zip | 2026-10-05 | 9.7 MB | |
| Totals: 10 Items | 73.5 MB | 0 | |
Security
- A tunnel on the Mac no longer hands out the owner's rights. Caprock
trusted any request that reached it over 127.0.0.1, so cloudflared, ngrok,
Caddy,
tailscale serveorssh -Rrunning on the machine let anyone who reached the tunnel read everything and start commands, with no pairing. A loopback request that carries a proxy header (X-Forwarded-*,Forwarded,Via,X-Real-IP,CF-*,Tailscale-*,Ngrok-*, …) or names a host other than localhost or a loopback address is now treated as a device: it needs a paired device's token and gets that device's role, and without one it gets401— on the API and on both WebSockets. The CLI, the hook shim, the statusline, the dashboard and anssh -Lforward are unchanged.