Skip to content

v1.18.40

Choose a tag to compare

@github-actions github-actions released this 26 Sep 13:08
· 0 commits to c550fc2707d95ed9385523fbbf4434d8f163f2ab since this release

Warning

Desktop app (removed from this release): it updates itself to upstream opencode.

This release included desktop installers named opencode-desktop-*. Those builds install as "OpenCode" (app ID ai.opencode.desktop) and check upstream opencode's GitHub releases for updates, not Lunos's. On start, and every 10 minutes after, they download upstream opencode's latest desktop build and offer to restart into it, even when it is an older version. If you accept, you are running upstream opencode, without Lunos's data-residency enforcement or audit log.

The CLI is not affected. lunos-ai from npm, the install script and the lunos-* archives never had this problem.

If you installed the desktop app from this or another release up to v1.18.40, uninstall it:

  • macOS: delete OpenCode.app from Applications.
  • Windows: uninstall "OpenCode" in Settings → Apps.
  • Linux: sudo apt remove opencode or sudo dnf remove opencode, or delete the AppImage. The package is named opencode, the same as upstream's, so if you also installed upstream opencode's desktop app this removes that too.

Its settings live under ai.opencode.desktop, the same folder upstream opencode's desktop app uses, so they may be shared with upstream.

Fixed on dev in #64: the desktop app installs as "Lunos" (tech.lunos.desktop), updates only from Lunos releases, and never offers a downgrade. It ships as lunos-desktop-* from the next release. The desktop files and update feeds have been removed from v1.18.34 to v1.18.40. SHA256SUMS still lists them; verify with --ignore-missing, as the deployment guide shows.


Last release: v1.18.39
Target ref: c550fc2

Core

Improvements

  • e2e6509 feat(memory): TUI memory browser (XCOD-94) (@pminev1)
  • 837c825 feat(memory): lunos memory review commands, and project memory outside git (XCOD-94, part 3 of 3) (@pminev1)
  • c1e0ce8 feat(memory): remember and recall with the section 5 bounds (XCOD-94, part 2 of 3) (@pminev1)
  • 62c9751 feat(memory): Cognee memory backend, config and off switches (XCOD-94, part 1 of 3) (@pminev1)
  • 7b4a7d6 feat(XCOD-108): CI check that documents agree with the sovereignty claim table (@pminev1)
  • fd83451 feat(XCOD-108): licence data in the release SBOM (the XCOD-64 gap) (@pminev1)
  • da38e32 docs(XCOD-105): marketplace review criteria, submission and removal, first review log; spec fields (@pminev1)
  • 5f9a1e0 feat(XCOD-105): curate lunos-community — review blocks, licences, pinned versions, integrity (@pminev1)
  • dbff912 feat(XCOD-105): review status, pinned versions and integrity checks at install (@pminev1)
  • b1a525b test(XCOD-103): audit trail end to end through the real CLI (@pminev1)
  • f8301df feat(XCOD-103): emit tool, permission, MCP, marketplace, policy and upgrade events; audit CLI; SIEM forwarding (stages 2-3) (@pminev1)
  • 5e8ac61 docs(XCOD-102): sample managed policy, macOS profile, Windows/Linux deployment notes (stage 5) (@pminev1)
  • 267a76b feat(XCOD-102): lunos debug config --sources (stage 4) (@pminev1)
  • 81dadbd feat(XCOD-102): marketplace policy from managed config; locked allow list (stage 3) (@pminev1)
  • d44022c style(XCOD-102): prettier (@pminev1)
  • e1cdc17 feat(XCOD-102): enforce locked keys where the action happens (stage 2) (@pminev1)
  • bfb6abe feat(XCOD-102): Lunos managed-config paths and locked keys (stage 1: paths and the lock pass) (@pminev1)
  • bdf4f37 feat(XCOD-106): sign release checksums and the SBOM with Sigstore; document how to verify (@pminev1)
  • 21444d0 docs(XCOD-104): admin console and SSO decision document; recommends defer (@pminev1)
  • d72e90a feat(XCOD-98): keep a dismissed question's drafts on its rejected tool part (@pminev1)
  • 65d2901 docs(XCOD-89): npm 12 needs --allow-scripts=lunos-ai to install a working CLI (@pminev1)
  • 04c8df4 sync release versions for v1.18.39

Bugfixes

  • 9772eb8 fix(memory): ask before remembering by default, and guard memory files from edits (XCOD-94) (@pminev1)
  • 27eab5e fix(XCOD-102): keep Schema class instances when applying locks (@pminev1)
  • 6c02efa fix(XCOD-112): refuse a second marketplace under a name already in use; make ambiguity choices distinguishable (@pminev1)
  • 3cb300f fix(XCOD-100): check paths in their on-disk case, so a wrong-case project path isn't external (@pminev1)
  • 4bb2b44 fix(XCOD-99): send one research/dev-cycle reminder per step instead of saving a copy each step (@pminev1)
  • 7c41978 fix(XCOD-111): allow lunos-ai's postinstall in the upgrade hint and npm auto-upgrade (@pminev1)
  • 77865cb fix(XCOD-95): make the seed manifest match what lunos.tech publishes (@pminev1)
  • d449384 fix(XCOD-96): v1 plugin loader logs v2 plugin files at DEBUG, not ERROR; XCOD-86 exit report (@pminev1)

SDK

  • 1dbf1d6 chore(XCOD-98): regenerate the OpenAPI spec for question.reject's optional drafts body (@pminev1)

Community Contributors Input

Thank you to 2 community contributors:

  • @pminev1:
    • docs: residency policy is enforced from v1.18.39
    • Merge pull request #33 from AxsionDev/docs-residency-fixed-1-18-39
    • fix(XCOD-96): v1 plugin loader logs v2 plugin files at DEBUG, not ERROR; XCOD-86 exit report
    • Merge pull request #34 from AxsionDev/xcod-96-v2-plugin-log
    • docs(XCOD-89): npm 12 needs --allow-scripts=lunos-ai to install a working CLI
    • Merge pull request #35 from AxsionDev/xcod-89-npm12-install
    • fix(XCOD-95): make the seed manifest match what lunos.tech publishes
    • Merge pull request #36 from AxsionDev/xcod-95-reconcile-manifest
    • docs: CHANGELOG by release, and name the one Lunos host the CLI contacts
    • fix(XCOD-111): allow lunos-ai's postinstall in the upgrade hint and npm auto-upgrade
    • fix(XCOD-99): send one research/dev-cycle reminder per step instead of saving a copy each step
    • fix(XCOD-100): check paths in their on-disk case, so a wrong-case project path isn't external
    • fix(XCOD-112): refuse a second marketplace under a name already in use; make ambiguity choices distinguishable
    • test(XCOD-100): scope the onDiskCase unit tests to POSIX; Windows defers to normalizePath
    • feat(XCOD-98): keep a dismissed question's drafts on its rejected tool part
    • feat(XCOD-98): double-Esc to dismiss a question, undo with ctrl+z, answer it later
    • fix(XCOD-98): create the dismissal state before the memos that read it; restore drafts on every read
    • chore(XCOD-98): regenerate the OpenAPI spec for question.reject's optional drafts body
    • docs(XCOD-104): admin console and SSO decision document; recommends defer
    • feat(XCOD-106): sign release checksums and the SBOM with Sigstore; document how to verify
    • feat(XCOD-102): Lunos managed-config paths and locked keys (stage 1: paths and the lock pass)
    • feat(XCOD-102): enforce locked keys where the action happens (stage 2)
    • style(XCOD-102): prettier
    • feat(XCOD-102): marketplace policy from managed config; locked allow list (stage 3)
    • feat(XCOD-102): lunos debug config --sources (stage 4)
    • docs(XCOD-102): sample managed policy, macOS profile, Windows/Linux deployment notes (stage 5)
    • fix(XCOD-102): keep Schema class instances when applying locks
    • feat(XCOD-103): one hash-chained audit stream with a versioned schema (stage 1: the writer)
    • feat(XCOD-103): emit tool, permission, MCP, marketplace, policy and upgrade events; audit CLI; SIEM forwarding (stages 2-3)
    • test(XCOD-103): audit trail end to end through the real CLI
    • docs(XCOD-103): audit log reference, v1 format note, SIEM recipe (stage 4)
    • fix(XCOD-103): CSV export carries every event field (kind, marketplace, patterns, transport, method, …)
    • Merge origin/dev into xcod-102-org-policy
    • feat(XCOD-105): review status, pinned versions and integrity checks at install
    • feat(XCOD-105): curate lunos-community — review blocks, licences, pinned versions, integrity
    • fix(XCOD-105): drop two entries that fail the open-source licence criterion
    • docs(XCOD-105): marketplace review criteria, submission and removal, first review log; spec fields
    • feat(XCOD-105): seed skill source — research-mode, bug-investigation, code-review-methodology
    • feat(XCOD-105): list the seed skill source and a whitespace-check hook
    • feat(XCOD-108): licence data in the release SBOM (the XCOD-64 gap)
    • feat(XCOD-108): CI check that documents agree with the sovereignty claim table
    • feat(XCOD-107): high-contrast theme and reduced-motion setting for the TUI
    • fix(XCOD-107): status that relied on colour alone gets a distinct glyph
    • fix(XCOD-105): state exactly what the whitespace-check hook covers
    • Merge origin/dev into xcod-105-curated-catalog
    • fix(XCOD-103): read only the log's tail per event; rotated files never overwrite each other
    • docs(trust): add the Trust pack and pre-filled CAIQ v3.0.1 answers (XCOD-108)
    • style(trust): prettier (XCOD-108)
    • fix(trust): extract all 295 CAIQ v3.0.1 questions and tighten three answers (XCOD-108)
    • docs: link the Trust pack from the README and the deployment guide (XCOD-108)
    • docs: label unreleased audit and policy features, and state the audit log path (XCOD-110)
    • feat(memory): Cognee memory backend, config and off switches (XCOD-94, part 1 of 3)
    • feat(memory): remember and recall with the section 5 bounds (XCOD-94, part 2 of 3)
    • feat(memory): lunos memory review commands, and project memory outside git (XCOD-94, part 3 of 3)
    • fix(memory): ask before remembering by default, and guard memory files from edits (XCOD-94)
    • Merge branch 'xcod-94-memory-tools' into xcod-94-memory-review
    • feat(memory): TUI memory browser (XCOD-94)
    • Merge origin/dev into xcod-94-memory-tools
    • Merge branch 'xcod-94-memory-review' into xcod-94-memory-tui
    • docs(trust): describe long-term memory's mitigations in the threat model (XCOD-94)
  • @pminevp:
    • Merge pull request #37 from AxsionDev/docs-sprint6-accuracy
    • Merge pull request #38 from AxsionDev/xcod-111-upgrade-allow-scripts
    • Merge pull request #39 from AxsionDev/xcod-99-reminder-dedupe
    • Merge pull request #40 from AxsionDev/xcod-100-path-case
    • Merge pull request #41 from AxsionDev/xcod-112-marketplace-name-clash
    • Merge pull request #42 from AxsionDev/xcod-98-question-recover
    • Merge pull request #43 from AxsionDev/xcod-104-admin-sso-decision
    • Merge pull request #44 from AxsionDev/xcod-106-verifiable-releases
    • Merge pull request #46 from AxsionDev/xcod-103-audit-trail
    • Merge pull request #45 from AxsionDev/xcod-102-org-policy
    • Merge pull request #48 from AxsionDev/xcod-108-trust-engineering
    • Merge pull request #49 from AxsionDev/xcod-107-tui-a11y
    • Merge pull request #50 from AxsionDev/xcod-105-curated-catalog
    • Merge pull request #51 from AxsionDev/xcod-103-audit-tail
    • Merge pull request #52 from AxsionDev/xcod-108-trust-pack
    • Merge pull request #53 from AxsionDev/xcod-110-rehearsal-doc-gaps
    • Merge pull request #54 from AxsionDev/xcod-94-memory-backend
    • Merge pull request #55 from AxsionDev/xcod-94-memory-tools
    • Merge pull request #57 from AxsionDev/xcod-94-memory-tui
    • Merge pull request #58 from AxsionDev/xcod-94-trust-memory