LocalCloud Security: Signed Releases and Reporting
Get started
local.cloud — Security: Signed Releases and Reporting .md Open tab
Security

LocalCloud security

Check what you install before you run it, keep your data on your machine, and reach us privately when you find a problem.

Report a vulnerability

Email info@local.cloud with the subject "Security report". Include the affected part (CLI, runtime image or website), its version (localcloud --version or the image digest), the steps to reproduce it, and the impact you observed.

Please don't include real credentials or customer data, and test only against systems you own. Our security.txt lists the same contact in the standard format.

Signed CLI releases

Every CLI release publishes archives for macOS and Linux on amd64 and arm64, a SHA256SUMS file, and Sigstore bundles. The bundles are signed by the CLI's GitHub Actions release workflow, so cosign can confirm the files came from that workflow at a release tag. The install script checks each archive against SHA256SUMS before it installs anything.

Check the signature on the v0.1.7 checksums

curl -fsSLO https://github.com/LocalGCloud/localcloud-cli/releases/download/v0.1.7/SHA256SUMS
curl -fsSLO https://github.com/LocalGCloud/localcloud-cli/releases/download/v0.1.7/SHA256SUMS.sigstore.json
cosign verify-blob SHA256SUMS \
  --bundle SHA256SUMS.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/LocalGCloud/localcloud-cli/\.github/workflows/cli-release\.yml@refs/tags/v' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Then check a downloaded archive against them

sha256sum --check --ignore-missing SHA256SUMS

On older macOS versions, use shasum -a 256 --check --ignore-missing SHA256SUMS. Release history is on the changelog.

Runtime image SBOM and provenance

The agentcloud/localcloud image is published for linux/amd64 and linux/arm64. Each platform carries an SPDX software bill of materials and a SLSA build provenance attestation. Inspect them with Docker:

Software bill of materials (SPDX)

docker buildx imagetools inspect agentcloud/localcloud:latest --format '{{ json .SBOM }}'

Build provenance (SLSA)

docker buildx imagetools inspect agentcloud/localcloud:latest --format '{{ json .Provenance }}'

For repeatable CI runs, pin the image by digest rather than the latest tag.

Your data and telemetry

Service data stays in a Docker volume on your machine (localcloud-data by default), and the quick start runs LocalCloud on localhost-only ports. LocalCloud needs no Google Cloud account or credentials.

The runtime sends pseudonymous usage and diagnostic reports. Set LOCALCLOUD_TELEMETRY=false in the container's environment to stop regular reporting. The privacy notice lists what is sent and what else can make network requests.

Desktop view