Block a user
Config hygiene: env-only tokens + lint to block secrets in manifests/systemd
Post-install health probe + auto-revert to staged previous bundle
Clipboard fallback: permissions-first + download link
Diagnostics UX: show /dev/shm/pikit-diag.log in updater modal
Automated tests for updater flows (pytest + Playwright smoke)
Move updater apply to dedicated systemd runner
Stronger manifest integrity (file hashes + optional ed25519 signature)
Harden updater tar extraction against path traversal