In this case, it would appear that Nicholas Merrill, one of the founders of the project, has left for unclear reasons, and CalyxOS is responding by pausing all releases — and security updates — while its release process, signing keys, and security protocols are reworked. The result will be no updates for "four to six months". The project is recommending that its users "should uninstall the OS" and wait for an all-clear signal. CalyxOS may have its work cut out for it when the time comes to try to convince those users to come back. to post comments
No good deed? Posted Aug 8, 2025 18:13 UTC (Fri) by tux3 (subscriber, #101245) [Link] On the other hand, kudos to them for the transparency and clear messaging. A less conscientious project might have tried to minimize, might not have communicated appropriately about why updates have stopped coming, or worse still, might have kept going without taking any action. It looks like they're entering a long tunnel of trying to improve their infra and processes. The sort of project that is willing to bite the bullet and ask their users to uninstall (!) so they can spend a few months overhauling their security, is the sort of project that we shouldn't punish for communicating candidly! Sucks for users who have to go months without a release, but I have to respect the commitment to their ideals, even at the risk of losing users.
Posted Aug 8, 2025 18:13 UTC (Fri) by tux3 (subscriber, #101245) [Link]