All news
ai

Show HN: Bor – Open-source policy management for Linux deskt

08 Aug 2026

Show HN: Bor – Open-source policy management for Linux desktops

What happened

  • gRPC was updated to version 1.82.1.
  • golang.org/x/crypto was updated to version 0.52.0.
  • Bor v0.8.0 has been released.
  • This release adds three new policy types: Thunderbird, Microsoft Edge for Business, and Firewalld zones.
  • The release includes a full web UI overhaul.
  • The release adds finer-grained RBAC.
  • The release includes a dedicated security hardening pass.
  • Thunderbird policy type allows Mozilla Thunderbird to be managed on enrolled desktops.
  • Microsoft Edge for Business policy type allows Edge on Linux to be managed on enrolled desktops.
  • Firewalld zone policy type manages firewalld zones on enrolled nodes including services, ports, forward ports, rich rules, masquerade, interfaces, sources, and zone target.
  • Polkit rules now support variable conditions via action.lookup().
  • User and role administration is now guarded by per-action permissions instead of a single blanket permission.
  • The web UI now includes URL routing with real URLs for every page.
  • The policy editor is now a routed, full-page instead of nested modals.
  • Node and compliance lists are now paginated, filtered, and sorted server-side.
  • Firefox, Thunderbird, Chrome, and Edge policy catalogues are now generated from protobuf annotations.
  • Agent identity is now strictly bound to the mTLS client certificate.
  • Legacy SHA-256-encrypted TOTP secrets are transparently migrated to HKDF-derived encryption on first read.
  • The Ubuntu PPA and Fedora COPR repository import helpers now block redirect-based SSRF.
  • Audit log CSV export is guarded against spreadsheet formula injection.
  • The auto-generated initial admin password is no longer printed to the server log.
  • The server TLS certificate is automatically regenerated when its SANs no longer match the configured hostnames.
  • All open Dependabot alerts were resolved, including the react-router RSC CSRF advisory (GHSA-qwww-vcr4-c8h2).
  • The frontend moved to React 19.2 and react-router 8.3.
  • TypeScript typecheck is now enforced in CI.
  • Agents must be upgraded to v0.8.0 to enforce the new Thunderbird, Edge, and Firewalld policy types.
  • The protobuf policy schema gained thunderbird.proto and firewalld.proto.
  • Frontend development now requires Node.js 22.22+.
  • The web UI achieves WCAG 2.2 AA accessibility compliance.

Numbers

  • gRPC was updated to version 1.82.1. (1.82.1)
  • golang.org/x/crypto was updated to version 0.52.0. (0.52.0)
  • Frontend development now requires Node.js 22.22+. (22.22+)

Why founders should care

  • May indicate faster shipping cycles for teams adopting the new tools.

Sources