v1.18.37
Warning
Desktop app (removed from this release): it updates itself to upstream opencode.
This release included desktop installers named opencode-desktop-*. Those builds install as "OpenCode" (app ID ai.opencode.desktop) and check upstream opencode's GitHub releases for updates, not Lunos's. On start, and every 10 minutes after, they download upstream opencode's latest desktop build and offer to restart into it, even when it is an older version. If you accept, you are running upstream opencode, without Lunos's data-residency enforcement or audit log.
The CLI is not affected. lunos-ai from npm, the install script and the lunos-* archives never had this problem.
If you installed the desktop app from this or another release up to v1.18.40, uninstall it:
- macOS: delete
OpenCode.appfrom Applications. - Windows: uninstall "OpenCode" in Settings → Apps.
- Linux:
sudo apt remove opencodeorsudo dnf remove opencode, or delete the AppImage. The package is namedopencode, the same as upstream's, so if you also installed upstream opencode's desktop app this removes that too.
Its settings live under ai.opencode.desktop, the same folder upstream opencode's desktop app uses, so they may be shared with upstream.
Fixed on dev in #64: the desktop app installs as "Lunos" (tech.lunos.desktop), updates only from Lunos releases, and never offers a downgrade. It ships as lunos-desktop-* from the next release. The desktop files and update feeds have been removed from v1.18.34 to v1.18.40. SHA256SUMS still lists them; verify with --ignore-missing, as the deployment guide shows.
Warning
Affected: local file disclosure in lunos mcp add <name> (marketplace install).
In this release, installing an MCP server by name from a marketplace does not fully sanitize the entry before writing it to your config. A malicious marketplace can craft an entry whose URL or header names contain config substitution tokens ({file:…}). When Lunos then loads your config, it reads the referenced local file (for example an SSH key) and sends its contents to the server named in the entry.
You are only exposed if you added a third-party marketplace (lunos marketplace add …) and installed an MCP server from it with lunos mcp add <name>. MCP servers added with an explicit --url or command, and the Lunos community marketplace (AxsionDev/Lunos), are not affected.
Check and mitigate now:
- Open your global config (
~/.config/opencode/opencode.jsonor.jsonc) and look undermcpfor any{file:or{env:that you did not write yourself, in a URL or in a header name. Remove that entry if you find one. - Until you upgrade, don't install MCP servers by name from marketplaces you don't trust.
Fixed in v1.18.38 (via #10). Upgrade with npm i -g lunos-ai@latest.
Last release: v1.18.35
Target ref: e4450d9
Core
Improvements
7d091bdfeat(marketplace): install MCP servers by name from a marketplace (@pminev1)a6d8e0bfeat(marketplace): convert a manifest MCP entry into config (@pminev1)68b8284feat(marketplace): resolve an entry name across added marketplaces (@pminev1)b4b65d7feat(marketplace): discover MCP servers across added marketplaces (@pminev1)cb06c67docs(XCOD-67): correct two audit errors, add two defects found by running it (@pminev1)7039369docs(XCOD-70): plugin API v2 plan-vs-implementation audit (@pminev1)4d8a9b8feat(XCOD-68): config-driven lifecycle hooks (@pminev1)1e3f5b8docs(XCOD-67): scope gap closure to v2 per owner decision (@pminev1)57ea4d3docs(XCOD-67): correct the audit — two parallel skill implementations (@pminev1)586fd52docs(XCOD-67): skills parity audit against Claude Code (@pminev1)9f10369sync release versions for v1.18.35
Bugfixes
be0a067fix(marketplace): close the overwrite-guard hole and make the secret test real (@pminev1)45fdda2fix(marketplace): refuse to overwrite an existing MCP server entry (@pminev1)11a56f5fix(marketplace): make MCP discovery tests actually load their manifests (@pminev1)36b9743fix(marketplace): test MCP discovery through the real deps surface (@pminev1)6e7bd99feat(XCOD-71): port research-mode onto Lunos, fixing two hooks defects (@pminev1)5cb10d1fix(XCOD-73): await debug skill stdout, retract G10/G11 as artifacts (@pminev1)a8d594efix(XCOD-67): enforce skill permissions on the slash-command surface (@pminev1)8940528docs(XCOD-67): characterise the discovery defect, resize the permission fix (@pminev1)
Community Contributors Input
Thank you to 2 community contributors:
- @pminev1:
- chore(XCOD-49): repoint the last opencode-* dist paths and refresh the credential doc
- Merge branch 'xcod-49-stale-paths' into dev
- docs(XCOD-59): preserve marketplace registry design specs in specs/
- docs(XCOD-59): record registry home decision and brief lunos-web agents
- feat(XCOD-64): add release SBOM and a real vulnerability-handling policy
- feat(XCOD-61): add provider jurisdiction metadata as a side table
- docs(XCOD-61): generate per-provider jurisdiction reference
- Merge branch 'xcod-59-registry-specs' into dev
- Merge branch 'xcod-64-sbom-vuln-process' into dev
- Merge branch 'xcod-61-provider-jurisdiction' into dev
- feat(XCOD-62): enforce data-residency policy and audit model egress
- Merge branch 'xcod-62-residency-controls' into xcod-63-deployment-guide
- docs(XCOD-63): self-hosted deployment guide for procurement reviewers
- docs(XCOD-46): point every README install command at Lunos
- docs(XCOD-65): re-tailor README sections that still described opencode
- Merge pull request #2 from AxsionDev/xcod-65-readme-sections
- docs(XCOD-67): skills parity audit against Claude Code
- docs(XCOD-67): correct the audit — two parallel skill implementations
- docs(XCOD-67): scope gap closure to v2 per owner decision
- Merge pull request #3 from AxsionDev/xcod-67-skills-audit
- feat(XCOD-68): config-driven lifecycle hooks
- docs(XCOD-70): plugin API v2 plan-vs-implementation audit
- docs(XCOD-67): correct two audit errors, add two defects found by running it
- docs(XCOD-67): characterise the discovery defect, resize the permission fix
- fix(XCOD-67): enforce skill permissions on the slash-command surface
- feat(marketplace): add an optional mcp array to the manifest schema
- fix(XCOD-73): await debug skill stdout, retract G10/G11 as artifacts
- Merge pull request #7 from AxsionDev/xcod-73-debug-stdout-fix
- feat(XCOD-71): port research-mode onto Lunos, fixing two hooks defects
- Merge pull request #8 from AxsionDev/xcod-71-skill-hook-port
- feat(marketplace): discover MCP servers across added marketplaces
- fix(marketplace): test MCP discovery through the real deps surface
- fix(marketplace): make MCP discovery tests actually load their manifests
- feat(marketplace): resolve an entry name across added marketplaces
- feat(marketplace): convert a manifest MCP entry into config
- feat(marketplace): install MCP servers by name from a marketplace
- fix(marketplace): refuse to overwrite an existing MCP server entry
- fix(marketplace): close the overwrite-guard hole and make the secret test real
- @pminevp: