Repository navigation
v1.1.3
07/21/2026
Changed
- Refresh OpenCode to 1.18.4, Claude Code to 2.1.216, s6-overlay to 3.2.3.2, fzf to 0.74.1, pnpm to 11.15.1, Vite to 8.1.5, Prettier to 3.9.6, Wrangler to 4.112.0, Prisma to 7.9.0, Lighthouse to 13.4.1, and
oh-my-openagentto 4.19.0. - Refresh the supported Python packages, including Requests 2.34.2 and Pillow 12.3.0.
- Keep Paperclip at 2026.707.0 while its newer destructive migration chain receives separate persistence testing.
- Run Chromium as
opencodewith its sandbox enabled through the shippedconfig/chromium-seccomp.jsonprofile.
Removed
- Temporarily remove bundled Hermes while its current release line requires vulnerable dependencies. Existing
/home/opencode/.hermesdata is left untouched. - Remove Vercel CLI, sharp-cli, concurrently, and LHCI because their current dependency trees contain fixable critical or high findings.
Fixed
- Rebuild GitHub CLI 2.96.0 from its exact upstream tag with Go 1.26.5 to remove
CVE-2026-39822from the bundled binary. - Replace Paperclip's vulnerable nested Undici 5.29.0 with Undici 6.27.0 and validate the Cursor adapter contract.
- Install the PostgreSQL 17 client directly instead of its empty compatibility metapackage.
- Validate npm lifecycle scripts by exact version, integrity, architecture, and script body before approved scripts run.
- Promote the exact multi-architecture image built and scanned by protected validation instead of rebuilding during publication.
Before upgrading from a release earlier than v1.1.3, add the Chromium seccomp profile described in the README. Then update with:
docker compose pull
docker compose up -dRollback requires untouched pre-upgrade volume snapshots with image 1.1.2; in-place database downgrades are not supported.