Sally is a security shell for authorized, workspace-scoped security operations. It provides one command environment for native tools, managed runtimes, disposable sandboxes, evidence, and repeatable security workflows. The product is also described as Sally Security Shell, security shell, and Sally shell.
This repository is the official public binary distribution channel. Each current release exposes the Windows and Linux install packages that passed their platform gates, while release notes remain as version history. It does not contain Sally source code, signing private keys, updater metadata, checksums, or SBOMs. Product documentation and the signed update channel are available at sally.st4ck.kr.
The release badge and the latest release are the authoritative current version.
| Platform | Package |
|---|---|
| Windows 10 or later, x86_64 | Sally-Windows-x86_64-Setup.exe |
| Linux, glibc x86_64 | Sally-Linux-x86_64.tar.gz |
| macOS Apple Silicon, arm64 | Sally-macOS-arm64.pkg — release gate pending |
| macOS Intel, x86_64 | Sally-macOS-x86_64.pkg — release gate pending |
Run the Windows Setup EXE directly. The Linux archive contains only
Sally-Setup. Windows packages currently
do not carry an Authenticode publisher signature, so Windows may show an
Unknown Publisher warning. Confirm this repository, the exact filename, and
the SHA-256 recorded in the signed stable update manifest before running the
installer.
Each version keeps its vX.Y.Z tag and release notes in the
release history. Only the
latest release retains
downloadable binaries. Older releases remain available as patch-note history
and direct users to the current download.
Signed updater metadata uses the same vX.Y.Z product release version as the
public GitHub tag to enforce downgrade and replay protection. This is the sole
release identity, and Sally does not accept unsigned update metadata.
Each GitHub Release includes exactly:
- versionless platform packages that passed their release gates;
- immutable release notes identifying the shared
vX.Y.Zproduct version.
The trusted release pipeline generates and verifies SHA-256 checksums and platform CycloneDX SBOMs without attaching them as public Release assets. The official website serves the exact-byte Ed25519 manifest and signature used by Sally's updater.
The stable updater endpoints are:
https://sally.st4ck.kr/updates/stable/manifest.jsonhttps://sally.st4ck.kr/updates/stable/manifest.sig
Sally is proprietary software. Copyright (c) 2026 stack1245. All rights reserved. See LICENSE.