Repository navigation
v1.18.43
·
0 commits
to 0a254eb46e9d2dc3a03ed2fa31a7fb81c1ead3ec
since this release
Last release: v1.18.42
Target ref: 0a254eb
Core
Improvements
8926280XCOD-177: publish takes THIRD_PARTY_NOTICES from dist/, not the build runner's working tree (@pminev1)4ff04fbXCOD-198: judgement step works in CI; weekly report branch unique per run (@pminev1)dca1e46XCOD-200, XCOD-198: run the eval and the marketplace judgement on OpenAI's gpt-5.3-codex (@pminev1)b25a13fXCOD-198: judgement step on an EU model, and Petar as the marketplace approver (@pminev1)080bb49XCOD-198: marketplace maintainer agent (fact layer), weekly and on manifest PRs (@pminev1)36d936aXCOD-177: licence notices in the desktop app (Help → Third-Party Licences) and the VS Code extension (@pminev1)9e45364XCOD-174: Lunos JSON Schemas for config, tui and themes; the CLI writes lunos.tech URLs (@pminev1)c271d09XCOD-174: tests that expected upstream's referer, or reached upstream's hosted UI (@pminev1)5955faeXCOD-177: third-party licence notices in the CLI, its packages and offline bundles; licence gate (@pminev1)a3d3a66XCOD-174: no request to upstream's services on any default path, and a CI guard (@pminev1)060490fXCOD-174: model catalogue from models.dev; no console sign-in or free opencode tier; GitHub agent with your own token (@pminev1)3d3f14atest(XCOD-150): print the directory portably, PowerShell rejects pwd -P (@pminev1)42b915bfeat(XCOD-167): an unknown tool names the nearest real ones; show an agent's tool count; document dropping an MCP server's tools (@pminev1)f0c2940feat(XCOD-164): the default agent asks before commands that publish or reach outside the project (@pminev1)4414cc0feat(XCOD-158): the sandbox's pinned digest in the session header; every sandbox.* setting in /settings (@pminev1)428d84ffeat(XCOD-158): the project's devcontainer as the sandbox's toolchain (@pminev1)9cfc6d7feat(XCOD-158): workspace "mount" and read-only sandbox.mounts (@pminev1)07e2630test(XCOD-158): sandbox-e2e covers /sandbox and /sandbox end through the same server calls as the TUI (@pminev1)0602dc3test(XCOD-158): a Windows verification script, sandbox-e2e.ps1 (@pminev1)cda18a9feat(XCOD-158): /sandbox and /sandbox end in the TUI (@pminev1)4ad7f36test(XCOD-158): sandbox-e2e links rootless Podman's real store into the throwaway XDG dirs (@pminev1)37096d6test(XCOD-158): sandbox-e2e keeps rootless Podman's real image store under its throwaway HOME (@pminev1)510a36fci(XCOD-158): sandboxed runs end to end on Linux, with Docker Engine and rootless Podman (@pminev1)875a4e6test(XCOD-158): compare the applied patch without the user's line endings (@pminev1)c9e2e15feat(XCOD-158): Podman, results as a patch or not at all, and sandboxes in the Status tab (@pminev1)c9f5a53feat(XCOD-157): sandbox network policy, enforced by an egress proxy outside the container (@pminev1)f965ea9feat(XCOD-157): sandbox.required, lockable in managed config (@pminev1)17016datest(XCOD-135): restore the preload's managed-config dir after the trusted-source test (@pminev1)8719dc7feat(XCOD-135): external memory sources, read-only and untrusted (@pminev1)5c41986feat(XCOD-134): store memory in an external Neo4j database, with residency checks and migration (@pminev1)78f2227test(XCOD-129): relaunch test asserts exec on POSIX and spawn-and-wait on win32 (@pminev1)8da4e7ffeat(XCOD-128): /settings screen with Status | Settings | Usage tabs (@pminev1)acb5e4ffeat(XCOD-128): GET/PATCH /config/settings for the settings screen (@pminev1)a1ba47efeat(XCOD-128): settings registry generated from the config schema, and lunos settings list/get/set (@pminev1)fc9619dfeat(XCOD-136): outdate in the TUI memory browser, the memory approval prompt, lifecycle tests (@pminev1)447732efeat(XCOD-136): memory lifecycle: outdated facts, expiry, ledger integrity, encryption at rest, audit events (@pminev1)a47ed53test(XCOD-129): app_restart keybind is unbound by default and binds from tui.json (@pminev1)ed423e2feat(XCOD-129): /restart stops Lunos and starts it again, back in the same session (@pminev1)ce96274feat(XCOD-129): relaunch module for /restart (exec in place, Windows spawn-and-wait, handoff) (@pminev1)d0c20cafeat(XCOD-133): import preview and approval in the TUI memory browser, over the HTTP API (@pminev1)aeb2f4ffeat(XCOD-133): import memory from bundles, Markdown and other agents' files, with preview and the write guard (@pminev1)fb33ca0test(XCOD-137): pin the real-run project with PWD, and require the deny to come from the rule (@pminev1)7479809feat(XCOD-147): check for a new version on every start, show it bottom-right, addlunos update(@pminev1)017f0dbfeat(XCOD-144): sandboxed runs in Docker, slice 1 (@pminev1)01e3e47feat(XCOD-132): export all memory as a lossless, versioned bundle (@pminev1)4011864test(XCOD-137): show a failed read's state in the real-run external_directory test (@pminev1)f0dbf0afeat(XCOD-130): rename /connect to /providers, with a configured-providers dialog (@pminev1)f96fedfsync release versions for v1.18.4290e6520sync release versions for v1.18.33
Bugfixes
39ec684fix(XCOD-149): keep the rule as written and add its long form only when it differs (@pminev1)06b04f0fix(XCOD-149): Windows path rules written with 8.3 short names match long-form request paths (@pminev1)9a2bf23fix(XCOD-150): CLI test harness runslunosin the fixture directory, not the repo checkout (@pminev1)bc32a16fix(XCOD-151): a secret with a quote no longer breaks config, and parse errors never print substituted values (@pminev1)c238932fix(XCOD-166): an unknown model says "Model not found", not "Unexpected server error" (@pminev1)67093cdfix(XCOD-168): the built-in config skill is customize-lunos, and points at lunos settings, not upstream's schema (@pminev1)3e3b2e4fix(XCOD-165): loading a config file never writes $schema into it (@pminev1)ec8dcc3fix(XCOD-169): lunos stats totals keep four decimals under a cent, like the per-model rows (@pminev1)25277c8fix(XCOD-158): sandbox.mounts target checks on Windows; mount mode in a linked worktree there (@pminev1)d5f3fcefix(XCOD-158): devcontainer image assembly works on Podman (@pminev1)4edd152fix(XCOD-158): reach a model on this machine from a sandbox on Docker Engine (Linux) (@pminev1)6ba0326fix(XCOD-159): build release binaries without code splitting, so Bun 1.3.14 can build them (@pminev1)feb3b32fix(XCOD-158): warping a session into a docker workspace works (@pminev1)328dfbbfix(XCOD-157): say where sandbox.image must be set when the default image can't be pulled (@pminev1)c70e52cfix(XCOD-157): audit what happens inside a sandbox; keep refreshed credentials off the volume (@pminev1)7348392fix(XCOD-157): carry global and managed config into sandboxes; secrets at runtime; lifecycle, prune and audit (@pminev1)0f4abc7fix(XCOD-135): keep source facts only with the source as provenance; don't kill slow-starting sources (@pminev1)c17c4e4fix(XCOD-134): re-remembering an outdated fact's text stores it again; docs say namespaces aren't access control (@pminev1)b0ad7cffix(XCOD-136): TUI outdate sent no body; take the replacement as a query parameter (@pminev1)ff0293efix(XCOD-128): show OPENCODE_DISABLE_SHARE / OPENCODE_AUTO_SHARE as env overrides of share (@pminev1)72a89f2fix(XCOD-137): resolve the lsp tool's path like the other file tools (@pminev1)0c75590fix(XCOD-136): ask replace-or-keep through the question tool, and only where questions can be answered; document lifecycle, integrity, encryption and audit events (@pminev1)51a3f3efix(XCOD-133): audit approved imports that wrote nothing; tolerate Finder junk in bundle folders (@pminev1)08c8da9fix(XCOD-144): no Docker call on workspace sync; LF checkout in the seed (@pminev1)eff5f32fix(XCOD-147): show the update dialog once per version, and never hold up a finished command (@pminev1)1643aa3fix(XCOD-144): keep the hand-back guarantee on every path (@pminev1)5a2547cfix(XCOD-132): keep index exports honest and TUI bundles out of the worktree (@pminev1)f772ea9fix(XCOD-139): cap concurrent CLI children in the subprocess test harness (@pminev1)f1b5b0dfix(XCOD-137): resolve driveless Windows paths against the project, and make Lunos tests pass on Windows (@pminev1)35fc7a7fix(opencode): apply provider timeouts to Cloudflare AI Gateway models (anomalyco#51549) (@danlapid)
TUI
Improvements
79ca8d0XCOD-174: prettier (@pminev1)b9d93b7XCOD-174: with your own token, push with it and commit as github-actions[bot] (@pminev1)
Bugfixes
06b4a5cfix(XCOD-148): lunos run --format json writes at most one error record (@pminev1)17fffe4fix(XCOD-147): start the TUI update check once the app listens for its event (@pminev1)
Desktop
Improvements
544c561XCOD-177: Third-Party Licences works from the Windows/Linux menu too, and opens a .txt (@pminev1)
Bugfixes
ed23a0ffix(XCOD-141): closable tabs keep a valid tablist; Delete closes the focused tab (@pminev1)974af14feat(XCOD-141): axe-core CI job for the web app, fix its serious/critical findings, TUI status glyphs (@pminev1)
Community Contributors Input
Thank you to 3 community contributors:
- @danlapid:
- fix(opencode): apply provider timeouts to Cloudflare AI Gateway models (anomalyco#51549)
- @pminev1:
- docs(XCOD-124): point DEPLOY.md at the lunos-web build.ps1/deploy.ps1
- Merge remote-tracking branch 'origin/dev' into upstream-sync/2026-09-28
- fix(XCOD-137): resolve driveless Windows paths against the project, and make Lunos tests pass on Windows
- fix(XCOD-139): cap concurrent CLI children in the subprocess test harness
- feat(XCOD-130): rename /connect to /providers, with a configured-providers dialog
- feat(XCOD-141): axe-core CI job for the web app, fix its serious/critical findings, TUI status glyphs
- test(XCOD-137): show a failed read's state in the real-run external_directory test
- feat(XCOD-132): export all memory as a lossless, versioned bundle
- fix(XCOD-141): closable tabs keep a valid tablist; Delete closes the focused tab
- feat(XCOD-144): sandboxed runs in Docker, slice 1
- feat(XCOD-147): check for a new version on every start, show it bottom-right, add
lunos update - fix(XCOD-132): keep index exports honest and TUI bundles out of the worktree
- fix(XCOD-144): keep the hand-back guarantee on every path
- fix(XCOD-147): start the TUI update check once the app listens for its event
- test(XCOD-137): pin the real-run project with PWD, and require the deny to come from the rule
- fix(XCOD-147): show the update dialog once per version, and never hold up a finished command
- feat(XCOD-133): import memory from bundles, Markdown and other agents' files, with preview and the write guard
- feat(XCOD-133): import preview and approval in the TUI memory browser, over the HTTP API
- fix(XCOD-144): no Docker call on workspace sync; LF checkout in the seed
- Merge remote-tracking branch 'origin/dev' into xcod-141-axe-ci
- feat(XCOD-129): relaunch module for /restart (exec in place, Windows spawn-and-wait, handoff)
- feat(XCOD-133): document lunos memory import and the instruction screen
- fix(XCOD-133): audit approved imports that wrote nothing; tolerate Finder junk in bundle folders
- feat(XCOD-129): /restart stops Lunos and starts it again, back in the same session
- test(XCOD-129): app_restart keybind is unbound by default and binds from tui.json
- Merge remote-tracking branch 'origin/dev' into xcod-129-restart
- fix(XCOD-129): read the draft when the restart happens, not when it was asked for
- fix(XCOD-129): count a background job's own session as the job, not as a mid-turn session
- feat(XCOD-136): memory lifecycle: outdated facts, expiry, ledger integrity, encryption at rest, audit events
- feat(XCOD-136): outdate in the TUI memory browser, the memory approval prompt, lifecycle tests
- Merge remote-tracking branch 'origin/dev' into xcod-132-memory-export
- fix(XCOD-136): ask replace-or-keep through the question tool, and only where questions can be answered; document lifecycle, integrity, encryption and audit events
- docs(XCOD-136): threat model and self-hosted guide cover retention, encryption at rest and memory audit events
- feat(XCOD-128): settings registry generated from the config schema, and lunos settings list/get/set
- feat(XCOD-128): GET/PATCH /config/settings for the settings screen
- fix(XCOD-137): resolve the lsp tool's path like the other file tools
- feat(XCOD-128): /settings screen with Status | Settings | Usage tabs
- docs(XCOD-128): Settings sections in tui.mdx and config.mdx, lunos settings in cli.mdx
- fix(XCOD-128): show OPENCODE_DISABLE_SHARE / OPENCODE_AUTO_SHARE as env overrides of share
- Merge remote-tracking branch 'origin/xcod-129-restart' into xcod-128-settings
- Merge remote-tracking branch 'origin/dev' into xcod-133-memory-import
- Merge remote-tracking branch 'origin/xcod-133-memory-import' into xcod-136-memory-lifecycle
- docs(XCOD-136): say when memory.verify_failed is emitted
- test(XCOD-129): relaunch test asserts exec on POSIX and spawn-and-wait on win32
- docs(XCOD-136): list the engine files measured to hold fact text unencrypted
- Merge remote-tracking branch 'origin/dev' into xcod-128-settings
- fix(XCOD-136): TUI outdate sent no body; take the replacement as a query parameter
- Merge remote-tracking branch 'origin/dev' into xcod-136-memory-lifecycle
- feat(XCOD-134): store memory in an external Neo4j database, with residency checks and migration
- Merge remote-tracking branch 'origin/xcod-136-memory-lifecycle' into xcod-134-memory-neo4j
- Merge remote-tracking branch 'origin/dev' into xcod-134-memory-neo4j
- Merge origin/dev into xcod-144-sandbox-slice1; list sandbox in /settings
- fix(XCOD-134): re-remembering an outdated fact's text stores it again; docs say namespaces aren't access control
- feat(XCOD-135): external memory sources, read-only and untrusted
- fix(XCOD-135): keep source facts only with the source as provenance; don't kill slow-starting sources
- Merge remote-tracking branch 'origin/dev' into xcod-135-memory-sources
- test(XCOD-135): restore the preload's managed-config dir after the trusted-source test
- fix(XCOD-157): carry global and managed config into sandboxes; secrets at runtime; lifecycle, prune and audit
- feat(XCOD-157): sandbox.required, lockable in managed config
- feat(XCOD-157): sandbox network policy, enforced by an egress proxy outside the container
- Merge branch 'xcod-157a-config-secrets-lifecycle' into xcod-157b-sandbox-required
- Merge branch 'xcod-157b-sandbox-required' into xcod-157c-network-policy
- fix(XCOD-157): audit what happens inside a sandbox; keep refreshed credentials off the volume
- fix(XCOD-157): say where sandbox.image must be set when the default image can't be pulled
- feat(XCOD-158): Podman, results as a patch or not at all, and sandboxes in the Status tab
- Merge remote-tracking branch 'origin/dev' into xcod-158-sandbox-slice3
- test(XCOD-158): compare the applied patch without the user's line endings
- ci(XCOD-158): sandboxed runs end to end on Linux, with Docker Engine and rootless Podman
- fix(XCOD-158): warping a session into a docker workspace works
- fix(XCOD-159): build release binaries without code splitting, so Bun 1.3.14 can build them
- Merge remote-tracking branch 'origin/dev' into xcod-158-linux-e2e
- ci(XCOD-158): run sandbox-e2e on build.ts changes; it's the only CI that builds a release binary
- fix(XCOD-158): reach a model on this machine from a sandbox on Docker Engine (Linux)
- test(XCOD-158): sandbox-e2e keeps rootless Podman's real image store under its throwaway HOME
- test(XCOD-158): sandbox-e2e links rootless Podman's real store into the throwaway XDG dirs
- feat(XCOD-158): /sandbox and /sandbox end in the TUI
- test(XCOD-158): a Windows verification script, sandbox-e2e.ps1
- Merge remote-tracking branch 'origin/xcod-158-linux-e2e' into xcod-158-sandbox-warp
- test(XCOD-158): sandbox-e2e covers /sandbox and /sandbox end through the same server calls as the TUI
- Merge remote-tracking branch 'origin/dev' into xcod-158-sandbox-warp
- feat(XCOD-158): workspace "mount" and read-only sandbox.mounts
- feat(XCOD-158): the project's devcontainer as the sandbox's toolchain
- fix(XCOD-158): devcontainer image assembly works on Podman
- feat(XCOD-158): the sandbox's pinned digest in the session header; every sandbox.* setting in /settings
- fix(XCOD-158): sandbox.mounts target checks on Windows; mount mode in a linked worktree there
- fix(XCOD-169): lunos stats totals keep four decimals under a cent, like the per-model rows
- fix(XCOD-165): loading a config file never writes $schema into it
- fix(XCOD-168): the built-in config skill is customize-lunos, and points at lunos settings, not upstream's schema
- fix(XCOD-161): /tasks shows each background job's model in full, beside its status and time
- fix(XCOD-166): an unknown model says "Model not found", not "Unexpected server error"
- fix(XCOD-151): a secret with a quote no longer breaks config, and parse errors never print substituted values
- fix(XCOD-148): lunos run --format json writes at most one error record
- fix(XCOD-150): CLI test harness runs
lunosin the fixture directory, not the repo checkout - fix(XCOD-149): Windows path rules written with 8.3 short names match long-form request paths
- feat(XCOD-164): the default agent asks before commands that publish or reach outside the project
- feat(XCOD-167): an unknown tool names the nearest real ones; show an agent's tool count; document dropping an MCP server's tools
- test(XCOD-150): print the directory portably, PowerShell rejects pwd -P
- fix(XCOD-149): keep the rule as written and add its long form only when it differs
- XCOD-200: eval builds each Polyglot task with its own solution; oracle runs report as pipeline checks
- XCOD-174: model catalogue from models.dev; no console sign-in or free opencode tier; GitHub agent with your own token
- XCOD-174: no request to upstream's services on any default path, and a CI guard
- XCOD-174: offline-egress proves a default run and a github dry run never reach upstream
- XCOD-174: with your own token, push with it and commit as github-actions[bot]
- XCOD-174: prettier
- XCOD-177: third-party licence notices in the CLI, its packages and offline bundles; licence gate
- XCOD-200: the eval copies a verified Lunos binary into each container instead of npm-installing it
- XCOD-179: publish the 6-month security support period and the recorded sign-offs
- XCOD-174: tests that expected upstream's referer, or reached upstream's hosted UI
- XCOD-174: Lunos JSON Schemas for config, tui and themes; the CLI writes lunos.tech URLs
- XCOD-174: lunos.tech schema URL in the deployment guide and example configs
- XCOD-177: licence notices in the desktop app (Help → Third-Party Licences) and the VS Code extension
- XCOD-177: Third-Party Licences works from the Windows/Linux menu too, and opens a .txt
- XCOD-200: a task that never got a fair attempt makes the model INCOMPLETE, not a failure
- XCOD-198: marketplace maintainer agent (fact layer), weekly and on manifest PRs
- XCOD-174: schemas.ts writes prettier-formatted JSON, so generate's format step doesn't fight it
- XCOD-198: judgement step on an EU model, and Petar as the marketplace approver
- XCOD-198: remove the two archived plugins; disclose AGPL and the conductor install step
- XCOD-200, XCOD-198: run the eval and the marketplace judgement on OpenAI's gpt-5.3-codex
- XCOD-200: publish the 2026-10-04 eval (gpt-5.3-codex, 21 of 33) and a "Models we tested" page
- XCOD-200: /run-eval, the repeatable eval command (AC5)
- XCOD-200: prettier
- XCOD-198: judgement step works in CI; weekly report branch unique per run
- XCOD-171: CHANGELOG [Unreleased] covers everything merged since v1.18.42
- XCOD-196: worksheet for the 89 organisational CAIQ answers
- XCOD-174: keep schemas/*.json LF on every OS so schemas --check passes on Windows
- XCOD-171: CHANGELOG [Unreleased] becomes [1.18.43]; link references up to date
- XCOD-177: publish takes THIRD_PARTY_NOTICES from dist/, not the build runner's working tree
- @pminevp:
- Merge pull request #79 from AxsionDev/docs-deploy-pointer
- Merge pull request #78 from AxsionDev/upstream-sync/2026-09-28
- Merge pull request #93 from AxsionDev/xcod-139-run-process-flake
- Merge pull request #94 from AxsionDev/xcod-130-providers
- Merge pull request #98 from AxsionDev/xcod-147-update-notice
- Merge pull request #96 from AxsionDev/xcod-132-memory-export
- Merge pull request #92 from AxsionDev/xcod-137-windows-tests
- Merge pull request #100 from AxsionDev/xcod-129-restart
- Merge pull request #99 from AxsionDev/xcod-133-memory-import
- Merge pull request #102 from AxsionDev/xcod-136-memory-lifecycle
- Merge pull request #101 from AxsionDev/xcod-128-settings
- Merge pull request #97 from AxsionDev/xcod-144-sandbox-slice1
- Merge pull request #103 from AxsionDev/xcod-134-memory-neo4j
- Merge pull request #95 from AxsionDev/xcod-141-axe-ci
- Merge pull request #104 from AxsionDev/xcod-135-memory-sources
- Merge pull request #105 from AxsionDev/xcod-157a-config-secrets-lifecycle
- Merge pull request #108 from AxsionDev/xcod-157c-network-policy
- Merge pull request #109 from AxsionDev/xcod-158-sandbox-slice3
- Merge pull request #111 from AxsionDev/xcod-159-bun-chunk-names
- Merge pull request #110 from AxsionDev/xcod-158-linux-e2e
- Merge pull request #112 from AxsionDev/xcod-158-sandbox-warp
- Merge pull request #113 from AxsionDev/xcod-158-mount-mode
- Merge pull request #114 from AxsionDev/xcod-158-devcontainer
- Merge pull request #115 from AxsionDev/xcod-158-settings-header
- Merge pull request #116 from AxsionDev/xcod-158-mount-windows
- Merge pull request #117 from AxsionDev/xcod-169-stats-cost
- Merge pull request #118 from AxsionDev/xcod-165-no-schema-writeback
- Merge pull request #119 from AxsionDev/xcod-168-customize-lunos-skill
- Merge pull request #120 from AxsionDev/xcod-161-tasks-model-column
- Merge pull request #121 from AxsionDev/xcod-166-model-not-found
- Merge pull request #122 from AxsionDev/xcod-151-secret-substitution
- Merge pull request #123 from AxsionDev/xcod-148-one-error-record
- Merge pull request #126 from AxsionDev/xcod-164-ask-before-publish
- Merge pull request #127 from AxsionDev/xcod-167-mcp-tool-scope
- Merge pull request #124 from AxsionDev/xcod-150-harness-pwd
- Merge pull request #125 from AxsionDev/xcod-149-shortname-rules
- Merge pull request #128 from AxsionDev/xcod-200-eval-oracle-fix
- Merge pull request #129 from AxsionDev/xcod-174-no-opencode-ai
- Merge pull request #130 from AxsionDev/xcod-174-lunos-schemas
- Merge pull request #131 from AxsionDev/xcod-177-licence-notices
- Merge pull request #133 from AxsionDev/xcod-198-marketplace-agent
- Merge pull request #132 from AxsionDev/xcod-179-trust-signoffs
- Merge pull request #134 from AxsionDev/xcod-174-schemas-prettier
- Merge pull request #135 from AxsionDev/marketplace-check/2026-10-04
- Merge pull request #136 from AxsionDev/xcod-198-judge-approver
- Merge pull request #137 from AxsionDev/xcod-198-plugin-verdicts
- Merge pull request #138 from AxsionDev/xcod-200-codex
- Merge pull request #139 from AxsionDev/xcod-200-codex-report
- Merge pull request #140 from AxsionDev/xcod-200-run-eval-command
- Merge pull request #141 from AxsionDev/xcod-198-judge-ci-fix
- Merge pull request #142 from AxsionDev/marketplace-check/2026-10-04-37185019076
- Merge pull request #143 from AxsionDev/xcod-171-changelog
- Merge pull request #144 from AxsionDev/xcod-196-caiq-worksheet
- Merge pull request #145 from AxsionDev/xcod-174-schemas-eol
- Merge pull request #146 from AxsionDev/xcod-171-changelog-1.18.43
- Merge pull request #147 from AxsionDev/xcod-177-publish-notices