Skip to content

Releases: AxsionDev/Lunos

Lunos for VS Code 1.18.40

Choose a tag to compare

@github-actions github-actions released this 27 Sep 13:37
1e0507a

VS Code Marketplace and Open VSX: publisher axsion, extension lunos. Verify with sha256sum -c lunos.vsix.sha256 or gh attestation verify lunos.vsix --repo AxsionDev/Lunos.

v1.18.40

Choose a tag to compare

@github-actions github-actions released this 26 Sep 13:08

Warning

Desktop app (removed from this release): it updates itself to upstream opencode.

This release included desktop installers named opencode-desktop-*. Those builds install as "OpenCode" (app ID ai.opencode.desktop) and check upstream opencode's GitHub releases for updates, not Lunos's. On start, and every 10 minutes after, they download upstream opencode's latest desktop build and offer to restart into it, even when it is an older version. If you accept, you are running upstream opencode, without Lunos's data-residency enforcement or audit log.

The CLI is not affected. lunos-ai from npm, the install script and the lunos-* archives never had this problem.

If you installed the desktop app from this or another release up to v1.18.40, uninstall it:

  • macOS: delete OpenCode.app from Applications.
  • Windows: uninstall "OpenCode" in Settings → Apps.
  • Linux: sudo apt remove opencode or sudo dnf remove opencode, or delete the AppImage. The package is named opencode, the same as upstream's, so if you also installed upstream opencode's desktop app this removes that too.

Its settings live under ai.opencode.desktop, the same folder upstream opencode's desktop app uses, so they may be shared with upstream.

Fixed on dev in #64: the desktop app installs as "Lunos" (tech.lunos.desktop), updates only from Lunos releases, and never offers a downgrade. It ships as lunos-desktop-* from the next release. The desktop files and update feeds have been removed from v1.18.34 to v1.18.40. SHA256SUMS still lists them; verify with --ignore-missing, as the deployment guide shows.


Last release: v1.18.39
Target ref: c550fc2

Core

Improvements

  • e2e6509 feat(memory): TUI memory browser (XCOD-94) (@pminev1)
  • 837c825 feat(memory): lunos memory review commands, and project memory outside git (XCOD-94, part 3 of 3) (@pminev1)
  • c1e0ce8 feat(memory): remember and recall with the section 5 bounds (XCOD-94, part 2 of 3) (@pminev1)
  • 62c9751 feat(memory): Cognee memory backend, config and off switches (XCOD-94, part 1 of 3) (@pminev1)
  • 7b4a7d6 feat(XCOD-108): CI check that documents agree with the sovereignty claim table (@pminev1)
  • fd83451 feat(XCOD-108): licence data in the release SBOM (the XCOD-64 gap) (@pminev1)
  • da38e32 docs(XCOD-105): marketplace review criteria, submission and removal, first review log; spec fields (@pminev1)
  • 5f9a1e0 feat(XCOD-105): curate lunos-community — review blocks, licences, pinned versions, integrity (@pminev1)
  • dbff912 feat(XCOD-105): review status, pinned versions and integrity checks at install (@pminev1)
  • b1a525b test(XCOD-103): audit trail end to end through the real CLI (@pminev1)
  • f8301df feat(XCOD-103): emit tool, permission, MCP, marketplace, policy and upgrade events; audit CLI; SIEM forwarding (stages 2-3) (@pminev1)
  • 5e8ac61 docs(XCOD-102): sample managed policy, macOS profile, Windows/Linux deployment notes (stage 5) (@pminev1)
  • 267a76b feat(XCOD-102): lunos debug config --sources (stage 4) (@pminev1)
  • 81dadbd feat(XCOD-102): marketplace policy from managed config; locked allow list (stage 3) (@pminev1)
  • d44022c style(XCOD-102): prettier (@pminev1)
  • e1cdc17 feat(XCOD-102): enforce locked keys where the action happens (stage 2) (@pminev1)
  • bfb6abe feat(XCOD-102): Lunos managed-config paths and locked keys (stage 1: paths and the lock pass) (@pminev1)
  • bdf4f37 feat(XCOD-106): sign release checksums and the SBOM with Sigstore; document how to verify (@pminev1)
  • 21444d0 docs(XCOD-104): admin console and SSO decision document; recommends defer (@pminev1)
  • d72e90a feat(XCOD-98): keep a dismissed question's drafts on its rejected tool part (@pminev1)
  • 65d2901 docs(XCOD-89): npm 12 needs --allow-scripts=lunos-ai to install a working CLI (@pminev1)
  • 04c8df4 sync release versions for v1.18.39

Bugfixes

  • 9772eb8 fix(memory): ask before remembering by default, and guard memory files from edits (XCOD-94) (@pminev1)
  • 27eab5e fix(XCOD-102): keep Schema class instances when applying locks (@pminev1)
  • 6c02efa fix(XCOD-112): refuse a second marketplace under a name already in use; make ambiguity choices distinguishable (@pminev1)
  • 3cb300f fix(XCOD-100): check paths in their on-disk case, so a wrong-case project path isn't external (@pminev1)
  • 4bb2b44 fix(XCOD-99): send one research/dev-cycle reminder per step instead of saving a copy each step (@pminev1)
  • 7c41978 fix(XCOD-111): allow lunos-ai's postinstall in the upgrade hint and npm auto-upgrade (@pminev1)
  • 77865cb fix(XCOD-95): make the seed manifest match what lunos.tech publishes (@pminev1)
  • d449384 fix(XCOD-96): v1 plugin loader logs v2 plugin files at DEBUG, not ERROR; XCOD-86 exit report (@pminev1)

SDK

  • 1dbf1d6 chore(XCOD-98): regenerate the OpenAPI spec for question.reject's optional drafts body (@pminev1)

Community Contributors Input

Thank you to 2 community contributors:

  • @pminev1:
    • docs: residency policy is enforced from v1.18.39
    • Merge pull request #33 from AxsionDev/docs-residency-fixed-1-18-39
    • fix(XCOD-96): v1 plugin loader logs v2 plugin files at DEBUG, not ERROR; XCOD-86 exit report
    • Merge pull request #34 from AxsionDev/xcod-96-v2-plugin-log
    • docs(XCOD-89): npm 12 needs --allow-scripts=lunos-ai to install a working CLI
    • Merge pull request #35 from AxsionDev/xcod-89-npm12-install
    • fix(XCOD-95): make the seed manifest match what lunos.tech publishes
    • Merge pull request #36 from AxsionDev/xcod-95-reconcile-manifest
    • docs: CHANGELOG by release, and name the one Lunos host the CLI contacts
    • fix(XCOD-111): allow lunos-ai's postinstall in the upgrade hint and npm auto-upgrade
    • fix(XCOD-99): send one research/dev-cycle reminder per step instead of saving a copy each step
    • fix(XCOD-100): check paths in their on-disk case, so a wrong-case project path isn't external
    • fix(XCOD-112): refuse a second marketplace under a name already in use; make ambiguity choices distinguishable
    • test(XCOD-100): scope the onDiskCase unit tests to POSIX; Windows defers to normalizePath
    • feat(XCOD-98): keep a dismissed question's drafts on its rejected tool part
    • feat(XCOD-98): double-Esc to dismiss a question, undo with ctrl+z, answer it later
    • fix(XCOD-98): create the dismissal state before the memos that read it; restore drafts on every read
    • chore(XCOD-98): regenerate the OpenAPI spec for question.reject's optional drafts body
    • docs(XCOD-104): admin console and SSO decision document; recommends defer
    • feat(XCOD-106): sign release checksums and the SBOM with Sigstore; document how to verify
    • feat(XCOD-102): Lunos managed-config paths and locked keys (stage 1: paths and the lock pass)
    • feat(XCOD-102): enforce locked keys where the action happens (stage 2)
    • style(XCOD-102): prettier
    • feat(XCOD-102): marketplace policy from managed config; locked allow list (stage 3)
    • feat(XCOD-102): lunos debug config --sources (stage 4)
    • docs(XCOD-102): sample managed policy, macOS profile, Windows/Linux deployment notes (stage 5)
    • fix(XCOD-102): keep Schema class instances when applying locks
    • feat(XCOD-103): one hash-chained audit stream with a versioned schema (stage 1: the writer)
    • feat(XCOD-103): emit tool, permission, MCP, marketplace, policy and upgrade events; audit CLI; SIEM forwarding (stages 2-3)
    • test(XCOD-103): audit trail end to end through the real CLI
    • docs(XCOD-103): audit log reference, v1 format note, SIEM recipe (stage 4)
    • fix(XCOD-103): CSV export carries every event field (kind, marketplace, patterns, transport, method, …)
    • Merge origin/dev into xcod-102-org-policy
    • feat(XCOD-105): review status, pinned versions and integrity checks at install
    • feat(XCOD-105): curate lunos-community — review blocks, licences, pinned versions, integrity
    • fix(XCOD-105): drop two entries that fail the open-source licence criterion
    • docs(XCOD-105): marketplace review criteria, submission and removal, first review log; spec fields
    • feat(XCOD-105): seed skill source — research-mode, bug-investigation, code-review-methodology
    • feat(XCOD-105): list the seed skill source and a whitespace-check hook
    • feat(XCOD-108): licence data in the release SBOM (the XCOD-64 gap)
    • feat(XCOD-108): CI check that documents agree with the sovereignty claim table
    • feat(XCOD-107): high-contrast theme and reduced-motion setting for the TUI
    • fix(XCOD-107): status that relied on colour alone gets a distinct glyph
    • fix(XCOD-105): state exactly what the whitespace-check hook covers
    • Merge origin/dev into xcod-105-curated-catalog
    • fix(XCOD-103): read only the log's tail per event; rotated files never overwrite each other
    • docs(trust): add the Trust pack and pre-filled CAIQ v3.0.1 answers (XCOD-108)
    • style(trust): prettier (XCOD-108)
    • fix(trust): extract all 295 CAIQ v3.0.1 questions and tighten three answers (XCOD-108)
    • docs: link the Trust pack from the README and the deployment guide (XCOD-108)
    • docs: label unreleased audit and policy features, and state the audit log path (XCOD-110)
    • feat(memory): Cognee memory backend, config and off switches (XCOD-94, part 1 of 3)
    • feat(memory): remember and recall with the section 5 bounds (XCOD-94, part 2 of 3)
    • feat(memory): lunos memory review commands, and project memory outside git (XCOD-94, part 3 of 3)
    • fix(memory): ask before remembering by default, and guard memory files from edits (XCOD-94)
    • Merge branch 'xcod-94-memory-tools' into xcod-94-memory-review
    • feat(memory): TUI memory browser (XCOD-94)
    • Merge origin/dev into xcod-94-memory-tools
    • Merge branch 'xcod-94-memory-review' into xcod-94-memory-tui
    • do...
Read more

v1.18.39

Choose a tag to compare

@github-actions github-actions released this 25 Sep 05:57

Warning

Desktop app (removed from this release): it updates itself to upstream opencode.

This release included desktop installers named opencode-desktop-*. Those builds install as "OpenCode" (app ID ai.opencode.desktop) and check upstream opencode's GitHub releases for updates, not Lunos's. On start, and every 10 minutes after, they download upstream opencode's latest desktop build and offer to restart into it, even when it is an older version. If you accept, you are running upstream opencode, without Lunos's data-residency enforcement or audit log.

The CLI is not affected. lunos-ai from npm, the install script and the lunos-* archives never had this problem.

If you installed the desktop app from this or another release up to v1.18.40, uninstall it:

  • macOS: delete OpenCode.app from Applications.
  • Windows: uninstall "OpenCode" in Settings → Apps.
  • Linux: sudo apt remove opencode or sudo dnf remove opencode, or delete the AppImage. The package is named opencode, the same as upstream's, so if you also installed upstream opencode's desktop app this removes that too.

Its settings live under ai.opencode.desktop, the same folder upstream opencode's desktop app uses, so they may be shared with upstream.

Fixed on dev in #64: the desktop app installs as "Lunos" (tech.lunos.desktop), updates only from Lunos releases, and never offers a downgrade. It ships as lunos-desktop-* from the next release. The desktop files and update feeds have been removed from v1.18.34 to v1.18.40. SHA256SUMS still lists them; verify with --ignore-missing, as the deployment guide shows.


Last release: v1.18.38
Target ref: 28078c3

Core

Improvements

  • e5f415c feat(XCOD-84): find and open artifacts; export as the in-perimeter share path (@pminev1)
  • eb388a8 docs(XCOD-85): memory-layer spike, recommend defer plus a zero-build convention (@pminev1)
  • 13fc765 feat(XCOD-82): background subagents as a documented setting, /tasks, lifecycle (part 2) (@pminev1)
  • 4efafa9 feat(XCOD-82): configurable subagent model selection (part 1 of XCOD-82) (@pminev1)
  • 926c997 feat(XCOD-83): skill allowed-tools, agent/skill context for hooks, subagent parity (@pminev1)
  • 50f683b feat(XCOD-88): make a marketplace install command copied from lunos.tech work on a fresh install (@pminev1)
  • d4815e7 feat(XCOD-75): add the tool domain to the v2 plugin API (@pminev1)
  • d4bc293 refactor(XCOD-76): delete the unreachable v2 plugin event API (@pminev1)
  • a3a69bc feat(XCOD-92): publish lunos-ai and platform packages with Lunos npm metadata (@pminev1)
  • d9b0352 feat(XCOD-91): Lunos update reminder, /upgrade, daily CLI notice, 24h cache (@pminev1)
  • 17782a7 feat(XCOD-90): show the Lunos version clearly in the TUI and CLI (@pminev1)
  • 5a6dc6e docs(XCOD-79): ship the reference deployment config the guide walks through (@pminev1)
  • 1a2ed2f feat(XCOD-87): turn session sharing off by default (@pminev1)
  • 0f9acdf docs(marketplace): bring the seed-manifest mapping decisions up to date (@pminev1)
  • a222f0c sync release versions for v1.18.38

Bugfixes

  • 4d57a25 fix(XCOD-77): debug commands no longer truncate piped output (@pminev1)
  • a8e5353 fix(XCOD-80): put session-share uploads under the residency policy (@pminev1)
  • 83197f0 fix(XCOD-93): enforce the residency policy on the live session path (@pminev1)
  • 0f55a12 fix(XCOD-91): stop update checks and upgrades from tracking upstream opencode (@pminev1)
  • a7c1e05 fix(marketplace): name Claude Code marketplaces instead of a raw schema error (@pminev1)
  • a8c170e fix(marketplace): plain messages for refusals only; faults keep the crash banner (@pminev1)

SDK

  • da42f62 docs(XCOD-74): retire PLAN.md as the plugin API's source of truth (@pminev1)

Community Contributors Input

Thank you to 2 community contributors:

  • @pminev1:
    • docs(marketplace): add the 2026-09-24 marketplace review fix plan
    • fix(marketplace): plain messages for refusals only; faults keep the crash banner
    • fix(marketplace): name Claude Code marketplaces instead of a raw schema error
    • docs(marketplace): bring the seed-manifest mapping decisions up to date
    • fix(XCOD-91): stop update checks and upgrades from tracking upstream opencode
    • feat(XCOD-87): turn session sharing off by default
    • fix(XCOD-93): enforce the residency policy on the live session path
    • Merge branch 'fix-residency-live-path' into xcod-79-reference-config
    • docs(XCOD-79): ship the reference deployment config the guide walks through
    • docs(XCOD-93): correct the residency claim until the enforcement fix ships
    • Merge pull request #14 from AxsionDev/docs-xcod-93-residency-correction
    • Merge pull request #15 from AxsionDev/fix-residency-live-path
    • Merge remote-tracking branch 'origin/dev' into xcod-87-share-off-by-default
    • Merge pull request #16 from AxsionDev/xcod-87-share-off-by-default
    • Merge remote-tracking branch 'origin/dev' into xcod-79-reference-config
    • Merge pull request #17 from AxsionDev/xcod-79-reference-config
    • feat(XCOD-90): show the Lunos version clearly in the TUI and CLI
    • Merge pull request #19 from AxsionDev/xcod-90-version-label
    • Merge remote-tracking branch 'origin/dev' into xcod-91-lunos-upgrade
    • feat(XCOD-91): Lunos update reminder, /upgrade, daily CLI notice, 24h cache
    • Merge pull request #18 from AxsionDev/xcod-91-lunos-upgrade
    • feat(XCOD-92): publish lunos-ai and platform packages with Lunos npm metadata
    • Merge pull request #20 from AxsionDev/xcod-92-npm-metadata
    • docs(XCOD-74): retire PLAN.md as the plugin API's source of truth
    • Merge pull request #21 from AxsionDev/xcod-74-retire-plan
    • refactor(XCOD-76): delete the unreachable v2 plugin event API
    • Merge pull request #22 from AxsionDev/xcod-76-delete-event-api
    • feat(XCOD-75): add the tool domain to the v2 plugin API
    • Merge pull request #23 from AxsionDev/xcod-75-tool-domain
    • feat(XCOD-88): make a marketplace install command copied from lunos.tech work on a fresh install
    • Merge pull request #24 from AxsionDev/xcod-88-marketplace-install
    • feat(XCOD-83): skill allowed-tools, agent/skill context for hooks, subagent parity
    • Merge pull request #25 from AxsionDev/xcod-83-tool-scoping
    • fix(XCOD-83): make SkillV2.Info.allowedTools mutable to match the generated SDK
    • Merge pull request #26 from AxsionDev/fix-skill-allowedtools-type
    • feat(XCOD-82): configurable subagent model selection (part 1 of XCOD-82)
    • Merge pull request #27 from AxsionDev/xcod-82-subagent-models
    • feat(XCOD-82): background subagents as a documented setting, /tasks, lifecycle (part 2)
    • Merge pull request #28 from AxsionDev/xcod-82-background
    • fix(XCOD-80): put session-share uploads under the residency policy
    • Merge pull request #29 from AxsionDev/xcod-80-share-residency
    • docs(XCOD-85): memory-layer spike, recommend defer plus a zero-build convention
    • Merge pull request #30 from AxsionDev/xcod-85-memory-spike
    • fix(XCOD-77): debug commands no longer truncate piped output
    • Merge pull request #31 from AxsionDev/xcod-77-debug-stdout
    • feat(XCOD-84): find and open artifacts; export as the in-perimeter share path
    • Merge pull request #32 from AxsionDev/xcod-84-artifacts
  • @pminevp:
    • Merge pull request #13 from AxsionDev/marketplace-refusals

v1.18.38

Choose a tag to compare

@github-actions github-actions released this 24 Sep 11:23

Warning

Desktop app (removed from this release): it updates itself to upstream opencode.

This release included desktop installers named opencode-desktop-*. Those builds install as "OpenCode" (app ID ai.opencode.desktop) and check upstream opencode's GitHub releases for updates, not Lunos's. On start, and every 10 minutes after, they download upstream opencode's latest desktop build and offer to restart into it, even when it is an older version. If you accept, you are running upstream opencode, without Lunos's data-residency enforcement or audit log.

The CLI is not affected. lunos-ai from npm, the install script and the lunos-* archives never had this problem.

If you installed the desktop app from this or another release up to v1.18.40, uninstall it:

  • macOS: delete OpenCode.app from Applications.
  • Windows: uninstall "OpenCode" in Settings → Apps.
  • Linux: sudo apt remove opencode or sudo dnf remove opencode, or delete the AppImage. The package is named opencode, the same as upstream's, so if you also installed upstream opencode's desktop app this removes that too.

Its settings live under ai.opencode.desktop, the same folder upstream opencode's desktop app uses, so they may be shared with upstream.

Fixed on dev in #64: the desktop app installs as "Lunos" (tech.lunos.desktop), updates only from Lunos releases, and never offers a downgrade. It ships as lunos-desktop-* from the next release. The desktop files and update feeds have been removed from v1.18.34 to v1.18.40. SHA256SUMS still lists them; verify with --ignore-missing, as the deployment guide shows.


Last release: v1.18.37
Target ref: 71b9eba

Core

Improvements

  • 5fcdbb1 test(XCOD-72): read back the config path install reports, restore shared global config (@pminev1)
  • 1e34053 feat(XCOD-72): tabbed TUI Discover view across all four content kinds (@pminev1)
  • 1af8181 feat(XCOD-72): search and install every marketplace content kind from the CLI (@pminev1)
  • fb3921e test(XCOD-69): update CLI help snapshot for mcp search and --yes; prettier (@pminev1)
  • d8f62c1 feat(XCOD-69): seed the community marketplace with MCP servers (@pminev1)
  • b7912b8 sync release versions for v1.18.37

Bugfixes

  • 5f31205 fix(marketplace): print install refusals as plain errors, not 'Unexpected error' (@pminev1)
  • 4ee9b6d fix(marketplace): resolve scoped entry names (@scope/pkg) by bare name (@pminev1)
  • bf2d0f7 fix(marketplace): list/add/update count every content kind, not only plugins (@pminev1)
  • b9cbc15 fix(marketplace): read header refs from exportable env var names (X-Api-Key -> X_API_KEY) (@pminev1)
  • ef42b73 fix(XCOD-69): block config substitution tokens in marketplace MCP entries (@pminev1)

Community Contributors Input

Thank you to 2 community contributors:

  • @pminev1:
    • fix(XCOD-69): block config substitution tokens in marketplace MCP entries
    • feat(XCOD-69): seed the community marketplace with MCP servers
    • docs(XCOD-69): document MCP discovery and add-by-name
    • test(XCOD-69): update CLI help snapshot for mcp search and --yes; prettier
    • feat(XCOD-72): add skills and hooks as typed marketplace content kinds
    • feat(XCOD-72): search and install every marketplace content kind from the CLI
    • feat(XCOD-72): tabbed TUI Discover view across all four content kinds
    • test(XCOD-72): read back the config path install reports, restore shared global config
    • Merge remote-tracking branch 'origin/dev' into xcod-72-marketplace-content-kinds
    • fix(marketplace): read header refs from exportable env var names (X-Api-Key -> X_API_KEY)
    • fix(marketplace): list/add/update count every content kind, not only plugins
    • fix(marketplace): source community plugins from npm, drop 11 uninstallable entries
    • fix(marketplace): resolve scoped entry names (@scope/pkg) by bare name
    • fix(marketplace): print install refusals as plain errors, not 'Unexpected error'
    • fix(tui): let Discover switch tabs away from an empty list
    • Merge pull request #11 from AxsionDev/marketplace-npm-sources
    • Merge pull request #12 from AxsionDev/marketplace-cli-fixes
  • @pminevp:
    • Merge pull request #10 from AxsionDev/xcod-72-marketplace-content-kinds

v1.18.37

Choose a tag to compare

@github-actions github-actions released this 22 Sep 16:31

Warning

Desktop app (removed from this release): it updates itself to upstream opencode.

This release included desktop installers named opencode-desktop-*. Those builds install as "OpenCode" (app ID ai.opencode.desktop) and check upstream opencode's GitHub releases for updates, not Lunos's. On start, and every 10 minutes after, they download upstream opencode's latest desktop build and offer to restart into it, even when it is an older version. If you accept, you are running upstream opencode, without Lunos's data-residency enforcement or audit log.

The CLI is not affected. lunos-ai from npm, the install script and the lunos-* archives never had this problem.

If you installed the desktop app from this or another release up to v1.18.40, uninstall it:

  • macOS: delete OpenCode.app from Applications.
  • Windows: uninstall "OpenCode" in Settings → Apps.
  • Linux: sudo apt remove opencode or sudo dnf remove opencode, or delete the AppImage. The package is named opencode, the same as upstream's, so if you also installed upstream opencode's desktop app this removes that too.

Its settings live under ai.opencode.desktop, the same folder upstream opencode's desktop app uses, so they may be shared with upstream.

Fixed on dev in #64: the desktop app installs as "Lunos" (tech.lunos.desktop), updates only from Lunos releases, and never offers a downgrade. It ships as lunos-desktop-* from the next release. The desktop files and update feeds have been removed from v1.18.34 to v1.18.40. SHA256SUMS still lists them; verify with --ignore-missing, as the deployment guide shows.


Warning

Affected: local file disclosure in lunos mcp add <name> (marketplace install).

In this release, installing an MCP server by name from a marketplace does not fully sanitize the entry before writing it to your config. A malicious marketplace can craft an entry whose URL or header names contain config substitution tokens ({file:…}). When Lunos then loads your config, it reads the referenced local file (for example an SSH key) and sends its contents to the server named in the entry.

You are only exposed if you added a third-party marketplace (lunos marketplace add …) and installed an MCP server from it with lunos mcp add <name>. MCP servers added with an explicit --url or command, and the Lunos community marketplace (AxsionDev/Lunos), are not affected.

Check and mitigate now:

  • Open your global config (~/.config/opencode/opencode.json or .jsonc) and look under mcp for any {file: or {env: that you did not write yourself, in a URL or in a header name. Remove that entry if you find one.
  • Until you upgrade, don't install MCP servers by name from marketplaces you don't trust.

Fixed in v1.18.38 (via #10). Upgrade with npm i -g lunos-ai@latest.


Last release: v1.18.35
Target ref: e4450d9

Core

Improvements

  • 7d091bd feat(marketplace): install MCP servers by name from a marketplace (@pminev1)
  • a6d8e0b feat(marketplace): convert a manifest MCP entry into config (@pminev1)
  • 68b8284 feat(marketplace): resolve an entry name across added marketplaces (@pminev1)
  • b4b65d7 feat(marketplace): discover MCP servers across added marketplaces (@pminev1)
  • cb06c67 docs(XCOD-67): correct two audit errors, add two defects found by running it (@pminev1)
  • 7039369 docs(XCOD-70): plugin API v2 plan-vs-implementation audit (@pminev1)
  • 4d8a9b8 feat(XCOD-68): config-driven lifecycle hooks (@pminev1)
  • 1e3f5b8 docs(XCOD-67): scope gap closure to v2 per owner decision (@pminev1)
  • 57ea4d3 docs(XCOD-67): correct the audit — two parallel skill implementations (@pminev1)
  • 586fd52 docs(XCOD-67): skills parity audit against Claude Code (@pminev1)
  • 9f10369 sync release versions for v1.18.35

Bugfixes

  • be0a067 fix(marketplace): close the overwrite-guard hole and make the secret test real (@pminev1)
  • 45fdda2 fix(marketplace): refuse to overwrite an existing MCP server entry (@pminev1)
  • 11a56f5 fix(marketplace): make MCP discovery tests actually load their manifests (@pminev1)
  • 36b9743 fix(marketplace): test MCP discovery through the real deps surface (@pminev1)
  • 6e7bd99 feat(XCOD-71): port research-mode onto Lunos, fixing two hooks defects (@pminev1)
  • 5cb10d1 fix(XCOD-73): await debug skill stdout, retract G10/G11 as artifacts (@pminev1)
  • a8d594e fix(XCOD-67): enforce skill permissions on the slash-command surface (@pminev1)
  • 8940528 docs(XCOD-67): characterise the discovery defect, resize the permission fix (@pminev1)

Community Contributors Input

Thank you to 2 community contributors:

  • @pminev1:
    • chore(XCOD-49): repoint the last opencode-* dist paths and refresh the credential doc
    • Merge branch 'xcod-49-stale-paths' into dev
    • docs(XCOD-59): preserve marketplace registry design specs in specs/
    • docs(XCOD-59): record registry home decision and brief lunos-web agents
    • feat(XCOD-64): add release SBOM and a real vulnerability-handling policy
    • feat(XCOD-61): add provider jurisdiction metadata as a side table
    • docs(XCOD-61): generate per-provider jurisdiction reference
    • Merge branch 'xcod-59-registry-specs' into dev
    • Merge branch 'xcod-64-sbom-vuln-process' into dev
    • Merge branch 'xcod-61-provider-jurisdiction' into dev
    • feat(XCOD-62): enforce data-residency policy and audit model egress
    • Merge branch 'xcod-62-residency-controls' into xcod-63-deployment-guide
    • docs(XCOD-63): self-hosted deployment guide for procurement reviewers
    • docs(XCOD-46): point every README install command at Lunos
    • docs(XCOD-65): re-tailor README sections that still described opencode
    • Merge pull request #2 from AxsionDev/xcod-65-readme-sections
    • docs(XCOD-67): skills parity audit against Claude Code
    • docs(XCOD-67): correct the audit — two parallel skill implementations
    • docs(XCOD-67): scope gap closure to v2 per owner decision
    • Merge pull request #3 from AxsionDev/xcod-67-skills-audit
    • feat(XCOD-68): config-driven lifecycle hooks
    • docs(XCOD-70): plugin API v2 plan-vs-implementation audit
    • docs(XCOD-67): correct two audit errors, add two defects found by running it
    • docs(XCOD-67): characterise the discovery defect, resize the permission fix
    • fix(XCOD-67): enforce skill permissions on the slash-command surface
    • feat(marketplace): add an optional mcp array to the manifest schema
    • fix(XCOD-73): await debug skill stdout, retract G10/G11 as artifacts
    • Merge pull request #7 from AxsionDev/xcod-73-debug-stdout-fix
    • feat(XCOD-71): port research-mode onto Lunos, fixing two hooks defects
    • Merge pull request #8 from AxsionDev/xcod-71-skill-hook-port
    • feat(marketplace): discover MCP servers across added marketplaces
    • fix(marketplace): test MCP discovery through the real deps surface
    • fix(marketplace): make MCP discovery tests actually load their manifests
    • feat(marketplace): resolve an entry name across added marketplaces
    • feat(marketplace): convert a manifest MCP entry into config
    • feat(marketplace): install MCP servers by name from a marketplace
    • fix(marketplace): refuse to overwrite an existing MCP server entry
    • fix(marketplace): close the overwrite-guard hole and make the secret test real
  • @pminevp:
    • Merge pull request #4 from AxsionDev/xcod-68-config-hooks
    • Merge pull request #5 from AxsionDev/xcod-70-plugin-api-docs
    • Merge pull request #6 from AxsionDev/xcod-67-skill-unification
    • Merge pull request #9 from AxsionDev/mcp-marketplace

v1.18.35

Choose a tag to compare

@github-actions github-actions released this 21 Sep 13:24

Warning

Desktop app (removed from this release): it updates itself to upstream opencode.

This release included desktop installers named opencode-desktop-*. Those builds install as "OpenCode" (app ID ai.opencode.desktop) and check upstream opencode's GitHub releases for updates, not Lunos's. On start, and every 10 minutes after, they download upstream opencode's latest desktop build and offer to restart into it, even when it is an older version. If you accept, you are running upstream opencode, without Lunos's data-residency enforcement or audit log.

The CLI is not affected. lunos-ai from npm, the install script and the lunos-* archives never had this problem.

If you installed the desktop app from this or another release up to v1.18.40, uninstall it:

  • macOS: delete OpenCode.app from Applications.
  • Windows: uninstall "OpenCode" in Settings → Apps.
  • Linux: sudo apt remove opencode or sudo dnf remove opencode, or delete the AppImage. The package is named opencode, the same as upstream's, so if you also installed upstream opencode's desktop app this removes that too.

Its settings live under ai.opencode.desktop, the same folder upstream opencode's desktop app uses, so they may be shared with upstream.

Fixed on dev in #64: the desktop app installs as "Lunos" (tech.lunos.desktop), updates only from Lunos releases, and never offers a downgrade. It ships as lunos-desktop-* from the next release. The desktop files and update feeds have been removed from v1.18.34 to v1.18.40. SHA256SUMS still lists them; verify with --ignore-missing, as the deployment guide shows.


Last release: v1.18.32
Target ref: 2508a6b

Core

  • a0366ae sync release versions for v1.18.32

Community Contributors Input

Thank you to 1 community contributor:

  • @pminev1:
    • fix(release): compute the next version from lunos-ai, not upstream's opencode-ai (XCOD-49)
    • Merge branch 'xcod-49-version-source' into dev

v1.18.32

Choose a tag to compare

@github-actions github-actions released this 21 Sep 12:55

Last release: v0.0.0-dev-202609181053
Target ref: 44cbe15

Core

Bugfixes

  • 98540a0 fix(ci): point the Dockerfile at the lunos-* dist dirs and brand the entrypoint (XCOD-49) (@pminev1)
  • 5b57036 fix(release): publish lunos-ai even when a platform package cannot (XCOD-49) (@pminev1)
  • 7c9e849 fix(release): serialize npm publishes and retry on E429 (XCOD-49) (@pminev1)
  • 086a780 fix(release): publish platform packages as lunos-*, not upstream's names (@pminev1)
  • 70cdf83 fix(ci): let the release publish unsigned, disable upstream-owned legs (XCOD-49) (@pminev1)
  • cb7ee9b fix(release): name release assets lunos-* to match the installer (XCOD-50) (@pminev1)

Desktop

Bugfixes

  • 25831fb fix(desktop): rebrand user-visible strings to Lunos (XCOD-44) (@pminev1)

Community Contributors Input

Thank you to 1 community contributor:

  • @pminev1:
    • fix(release): name release assets lunos-* to match the installer (XCOD-50)
    • docs: sprint close-out assessment and reconstructed GTM plan
    • fix(install): point usage examples at an existing branch (XCOD-46)
    • Merge branch 'xcod-46-install-usage-url' into dev
    • Merge branch 'xcod-release-asset-naming' into dev
    • Merge remote-tracking branch 'origin/dev' into dev
    • docs(gtm): establish the build-in-public cadence, staged behind the gate (XCOD-31)
    • Merge branch 'xcod-31-build-in-public-cadence' into dev
    • docs: add a curated root CHANGELOG.md (XCOD-31)
    • Merge branch 'xcod-31-changelog' into dev
    • Merge branch 'dev' of https://github.com/pminev1/Lunos into dev
    • docs(XCOD-17): record provisional legal entity decision — Axsion
    • Merge branch 'xcod-17-legal-entity-decision' into dev
    • docs: propagate the XCOD-17 entity decision to CHANGELOG and XCOD-19
    • style: prettier-normalize the XCOD-19 triage table
    • docs(XCOD-17): name the registered entity — ITService EOOD, not "Axsion"
    • docs(XCOD-20): verify AC-3 splash and default theme under a pty
    • Merge branch 'agent/task' into dev
    • docs(XCOD-20): reference XCOD-56 for the home-screen tips defect
    • docs(XCOD-26): research social handles, move repo to AxsionDev/Lunos
    • Merge branch 'xcod-26-social-handles-claim-pack' into dev
    • fix(tui): name the shipped binary in home-screen tips (XCOD-56)
    • legal(XCOD-51): name ITService EOOD as a copyright holder in LICENSE
    • Merge branch 'xcod-56-home-screen-tips-lunos' into dev
    • Merge branch 'xcod-51-license-entity-copyright' into dev
    • docs: triage the XCOD sprint board by cost-to-review
    • fix(tui): rebrand user-visible TUI strings (XCOD-44, partial)
    • Merge branch 'xcod-44-user-visible-branding' into dev
    • fix(tui): rebrand the JSX and template-literal strings (XCOD-44)
    • docs: update sprint triage to current state
    • docs(XCOD-52): recommend the DCO for contributor licensing
    • legal(XCOD-52): adopt the DCO for contributor licensing
    • docs(XCOD-55): scope the EU-sovereignty claim, defer hosted infrastructure
    • docs: update sprint triage — 6 of 14 in Review
    • docs(XCOD-53): preliminary trademark risk signal — not a clearance
    • docs(XCOD-22): flag that XCOD-53 raises the trademark risk
    • docs: record XCOD-53 outcome in the sprint triage
    • docs(XCOD-53): record the owner decision to defer clearance
    • fix(desktop): rebrand user-visible strings to Lunos (XCOD-44)
    • Merge branch 'xcod-44-desktop-branding' into dev
    • docs: XCOD-44 desktop done, docs site scoped
    • docs(web): rebrand the English docs site to Lunos (XCOD-44)
    • Merge branch 'xcod-44-docs-branding' into dev
    • docs: XCOD-44 complete — 7 of 14 in Review
    • fix(ci): re-point publish.yml repo guards at AxsionDev/Lunos (XCOD-49)
    • Merge branch 'xcod-49-repo-guards' into dev
    • fix(ci): let the release publish unsigned, disable upstream-owned legs (XCOD-49)
    • Merge branch 'xcod-49-unsigned-release' into dev
    • docs: record XCOD-49 findings in the sprint triage
    • fix(ci): wire NODE_AUTH_TOKEN and de-deadlock concurrency (XCOD-48)
    • Merge branch 'xcod-48-npm-auth-wiring' into dev
    • docs: add a consolidated owner action checklist
    • fix(release): publish platform packages as lunos-*, not upstream's names
    • Merge branch 'xcod-48-npm-package-naming' into dev
    • docs: note the npm naming fix in the owner checklist
    • fix(release): don't let AI changelog generation fail the release (XCOD-49)
    • Merge branch 'xcod-49-changelog-fallback' into dev
    • fix(release): make changelog generation vendor-neutral (XCOD-49)
    • Merge branch 'xcod-49-changelog-provider-agnostic' into dev
    • fix(ci): gate the Windows electron Azure login too (XCOD-49)
    • Merge branch 'xcod-49-windows-electron-gate' into dev
    • fix(release): skip the @opencode-ai/* library publishes (XCOD-49)
    • Merge branch 'xcod-49-skip-upstream-scoped-pkgs' into dev
    • fix(ci): gate the signed-Windows verification on sign_windows too (XCOD-49)
    • Merge branch 'xcod-49-verify-signed-gate' into dev
    • fix(ci): point the CLI artifact globs at the lunos-* build output (XCOD-49)
    • Merge branch 'xcod-49-lunos-artifact-globs' into dev
    • fix(release): serialize npm publishes and retry on E429 (XCOD-49)
    • Merge branch 'xcod-49-npm-publish-retry' into dev
    • fix(release): publish lunos-ai even when a platform package cannot (XCOD-49)
    • Merge branch 'xcod-49-publish-entrypoint-first' into dev
    • docs(XCOD-54): assess CRA status — outside scope today, steward as fallback
    • Merge branch 'xcod-54-cra-assessment' into dev
    • docs(XCOD-53): search EUIPO/USPTO, correct the threat, accept the risk
    • Merge branch 'xcod-53-register-searches' into dev
    • fix(ci): point the Dockerfile at the lunos-* dist dirs and brand the entrypoint (XCOD-49)
    • Merge branch 'xcod-49-dockerfile-paths' into dev
    • fix(release): skip desktop updater signing when the Tauri key is absent (XCOD-49)
    • Merge branch 'xcod-49-tauri-updater-gate' into dev

v0.0.0-dev-202609181053 (Phase 0 install verification)

Choose a tag to compare

@pminev1 pminev1 released this 18 Sep 11:57

Verification prerelease for XCOD-20 (Phase 0 exit criterion). Not a public release.

Binaries are the CI-built artifacts from workflow run 35335881462 (build-cli, succeeded). Assets use the corrected lunos-* naming that the install script expects — see XCOD-20 and the release-asset naming fix.

Unsigned: the fork has no Apple/Azure code-signing secrets. Install via:

curl -fsSL https://github.com/pminev1/Lunos/raw/main/install | bash -s -- --version 0.0.0-dev-202609181053