
Reproduces CVE-2026-39866, a workflow_dispatch input template injection in a GitHub Actions workflow, using a pinned snapshot of the vulnerable commit for authorized security research.
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
LawnchairLauncher/lawnchairat commitb089bae8c007f36a8ce0346725182a107d97cd05(2026-04-05), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-04-05; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
[!WARNING] This branch contains major changes from the rebase of Launcher3, including breaking changes that can cause Lawnchair to break.
If you wish to contribute, read our contributing guidelines. This branch will undergo many changes as we slowly refactor our codebase, so the
16-devbranch may be particularly unfriendly to new contributors.For regular users, we recommend staying on Lawnchair 15 Beta 2.1.
Lawnchair is a free, open-source home app for Android. Taking Launcher3—Android’s default home app—as a starting point, it ports Pixel Launcher features and introduces rich customization options.
This branch houses the codebase of Lawnchair 16, which is currently in development and is based on Launcher3 from Android 16. For Lawnchair 9 to 15, see the branches with the 9- to 15- prefixes, respectively.
Lawnchair on Play Store will install as a different app from other sources. Features may be restricted to comply with Google Play's publishing rules.
You can also verify your installation to see if you have installed an official build.
Interested in keeping yourself up-to-date with every Lawnchair development? Try our development builds!
These builds offer the latest features and bug fixes at a cost of performance and additional issues. Make backups before installing!
Download: Obtainium • GitHub • nightly.link
Visit the Lawnchair contributing guidelines for information and tips on contributing to Lawnchair.
If you love what we do, consider supporting us on Open Collective! Your contributions help keep Lawnchair independent and enable us to develop faster.
A huge thank you to our Core Backers ($5+): (These backers directly fund our Project Velocity Fund)
Become a supporter to help us cover our operational costs, or become a Core Backer to be featured here!
View all our links in the Lawnchair Wiki.