Skip to content

v1.1.3

Choose a tag to compare

@CoderLuii CoderLuii released this 21 Jul 21:05

07/21/2026

Changed

  • Refresh OpenCode to 1.18.4, Claude Code to 2.1.216, s6-overlay to 3.2.3.2, fzf to 0.74.1, pnpm to 11.15.1, Vite to 8.1.5, Prettier to 3.9.6, Wrangler to 4.112.0, Prisma to 7.9.0, Lighthouse to 13.4.1, and oh-my-openagent to 4.19.0.
  • Refresh the supported Python packages, including Requests 2.34.2 and Pillow 12.3.0.
  • Keep Paperclip at 2026.707.0 while its newer destructive migration chain receives separate persistence testing.
  • Run Chromium as opencode with its sandbox enabled through the shipped config/chromium-seccomp.json profile.

Removed

  • Temporarily remove bundled Hermes while its current release line requires vulnerable dependencies. Existing /home/opencode/.hermes data is left untouched.
  • Remove Vercel CLI, sharp-cli, concurrently, and LHCI because their current dependency trees contain fixable critical or high findings.

Fixed

  • Rebuild GitHub CLI 2.96.0 from its exact upstream tag with Go 1.26.5 to remove CVE-2026-39822 from the bundled binary.
  • Replace Paperclip's vulnerable nested Undici 5.29.0 with Undici 6.27.0 and validate the Cursor adapter contract.
  • Install the PostgreSQL 17 client directly instead of its empty compatibility metapackage.
  • Validate npm lifecycle scripts by exact version, integrity, architecture, and script body before approved scripts run.
  • Promote the exact multi-architecture image built and scanned by protected validation instead of rebuilding during publication.

Before upgrading from a release earlier than v1.1.3, add the Chromium seccomp profile described in the README. Then update with:

docker compose pull
docker compose up -d

Rollback requires untouched pre-upgrade volume snapshots with image 1.1.2; in-place database downgrades are not supported.