v1.18.39
Warning
Desktop app (removed from this release): it updates itself to upstream opencode.
This release included desktop installers named opencode-desktop-*. Those builds install as "OpenCode" (app ID ai.opencode.desktop) and check upstream opencode's GitHub releases for updates, not Lunos's. On start, and every 10 minutes after, they download upstream opencode's latest desktop build and offer to restart into it, even when it is an older version. If you accept, you are running upstream opencode, without Lunos's data-residency enforcement or audit log.
The CLI is not affected. lunos-ai from npm, the install script and the lunos-* archives never had this problem.
If you installed the desktop app from this or another release up to v1.18.40, uninstall it:
- macOS: delete
OpenCode.appfrom Applications. - Windows: uninstall "OpenCode" in Settings → Apps.
- Linux:
sudo apt remove opencodeorsudo dnf remove opencode, or delete the AppImage. The package is namedopencode, the same as upstream's, so if you also installed upstream opencode's desktop app this removes that too.
Its settings live under ai.opencode.desktop, the same folder upstream opencode's desktop app uses, so they may be shared with upstream.
Fixed on dev in #64: the desktop app installs as "Lunos" (tech.lunos.desktop), updates only from Lunos releases, and never offers a downgrade. It ships as lunos-desktop-* from the next release. The desktop files and update feeds have been removed from v1.18.34 to v1.18.40. SHA256SUMS still lists them; verify with --ignore-missing, as the deployment guide shows.
Last release: v1.18.38
Target ref: 28078c3
Core
Improvements
e5f415cfeat(XCOD-84): find and open artifacts; export as the in-perimeter share path (@pminev1)eb388a8docs(XCOD-85): memory-layer spike, recommend defer plus a zero-build convention (@pminev1)13fc765feat(XCOD-82): background subagents as a documented setting, /tasks, lifecycle (part 2) (@pminev1)4efafa9feat(XCOD-82): configurable subagent model selection (part 1 of XCOD-82) (@pminev1)926c997feat(XCOD-83): skill allowed-tools, agent/skill context for hooks, subagent parity (@pminev1)50f683bfeat(XCOD-88): make a marketplace install command copied from lunos.tech work on a fresh install (@pminev1)d4815e7feat(XCOD-75): add the tool domain to the v2 plugin API (@pminev1)d4bc293refactor(XCOD-76): delete the unreachable v2 plugin event API (@pminev1)a3a69bcfeat(XCOD-92): publish lunos-ai and platform packages with Lunos npm metadata (@pminev1)d9b0352feat(XCOD-91): Lunos update reminder, /upgrade, daily CLI notice, 24h cache (@pminev1)17782a7feat(XCOD-90): show the Lunos version clearly in the TUI and CLI (@pminev1)5a6dc6edocs(XCOD-79): ship the reference deployment config the guide walks through (@pminev1)1a2ed2ffeat(XCOD-87): turn session sharing off by default (@pminev1)0f9acdfdocs(marketplace): bring the seed-manifest mapping decisions up to date (@pminev1)a222f0csync release versions for v1.18.38
Bugfixes
4d57a25fix(XCOD-77): debug commands no longer truncate piped output (@pminev1)a8e5353fix(XCOD-80): put session-share uploads under the residency policy (@pminev1)83197f0fix(XCOD-93): enforce the residency policy on the live session path (@pminev1)0f55a12fix(XCOD-91): stop update checks and upgrades from tracking upstream opencode (@pminev1)a7c1e05fix(marketplace): name Claude Code marketplaces instead of a raw schema error (@pminev1)a8c170efix(marketplace): plain messages for refusals only; faults keep the crash banner (@pminev1)
SDK
da42f62docs(XCOD-74): retire PLAN.md as the plugin API's source of truth (@pminev1)
Community Contributors Input
Thank you to 2 community contributors:
- @pminev1:
- docs(marketplace): add the 2026-09-24 marketplace review fix plan
- fix(marketplace): plain messages for refusals only; faults keep the crash banner
- fix(marketplace): name Claude Code marketplaces instead of a raw schema error
- docs(marketplace): bring the seed-manifest mapping decisions up to date
- fix(XCOD-91): stop update checks and upgrades from tracking upstream opencode
- feat(XCOD-87): turn session sharing off by default
- fix(XCOD-93): enforce the residency policy on the live session path
- Merge branch 'fix-residency-live-path' into xcod-79-reference-config
- docs(XCOD-79): ship the reference deployment config the guide walks through
- docs(XCOD-93): correct the residency claim until the enforcement fix ships
- Merge pull request #14 from AxsionDev/docs-xcod-93-residency-correction
- Merge pull request #15 from AxsionDev/fix-residency-live-path
- Merge remote-tracking branch 'origin/dev' into xcod-87-share-off-by-default
- Merge pull request #16 from AxsionDev/xcod-87-share-off-by-default
- Merge remote-tracking branch 'origin/dev' into xcod-79-reference-config
- Merge pull request #17 from AxsionDev/xcod-79-reference-config
- feat(XCOD-90): show the Lunos version clearly in the TUI and CLI
- Merge pull request #19 from AxsionDev/xcod-90-version-label
- Merge remote-tracking branch 'origin/dev' into xcod-91-lunos-upgrade
- feat(XCOD-91): Lunos update reminder, /upgrade, daily CLI notice, 24h cache
- Merge pull request #18 from AxsionDev/xcod-91-lunos-upgrade
- feat(XCOD-92): publish lunos-ai and platform packages with Lunos npm metadata
- Merge pull request #20 from AxsionDev/xcod-92-npm-metadata
- docs(XCOD-74): retire PLAN.md as the plugin API's source of truth
- Merge pull request #21 from AxsionDev/xcod-74-retire-plan
- refactor(XCOD-76): delete the unreachable v2 plugin event API
- Merge pull request #22 from AxsionDev/xcod-76-delete-event-api
- feat(XCOD-75): add the tool domain to the v2 plugin API
- Merge pull request #23 from AxsionDev/xcod-75-tool-domain
- feat(XCOD-88): make a marketplace install command copied from lunos.tech work on a fresh install
- Merge pull request #24 from AxsionDev/xcod-88-marketplace-install
- feat(XCOD-83): skill allowed-tools, agent/skill context for hooks, subagent parity
- Merge pull request #25 from AxsionDev/xcod-83-tool-scoping
- fix(XCOD-83): make SkillV2.Info.allowedTools mutable to match the generated SDK
- Merge pull request #26 from AxsionDev/fix-skill-allowedtools-type
- feat(XCOD-82): configurable subagent model selection (part 1 of XCOD-82)
- Merge pull request #27 from AxsionDev/xcod-82-subagent-models
- feat(XCOD-82): background subagents as a documented setting, /tasks, lifecycle (part 2)
- Merge pull request #28 from AxsionDev/xcod-82-background
- fix(XCOD-80): put session-share uploads under the residency policy
- Merge pull request #29 from AxsionDev/xcod-80-share-residency
- docs(XCOD-85): memory-layer spike, recommend defer plus a zero-build convention
- Merge pull request #30 from AxsionDev/xcod-85-memory-spike
- fix(XCOD-77): debug commands no longer truncate piped output
- Merge pull request #31 from AxsionDev/xcod-77-debug-stdout
- feat(XCOD-84): find and open artifacts; export as the in-perimeter share path
- Merge pull request #32 from AxsionDev/xcod-84-artifacts
- @pminevp:
- Merge pull request #13 from AxsionDev/marketplace-refusals