Repository navigation
v1.1.4
07/30/2026
Changed
- Update OpenCode to 1.18.9, Claude Code to 2.1.220, Paperclip to 2026.722.0, npm to 12.0.2, pnpm to 11.18.0, ESLint to 10.8.0, Wrangler to 4.115.0, and Prisma to 7.9.1.
- Refresh the Python 3.13 package set, including pip 26.2, pandas 3.0.5, tqdm 4.70.0, FastAPI 0.141.1, and Uvicorn 0.52.0.
- Bundle
opencode-claude-auth2.1.5 as an integrity-checked offline package so container startup no longer downloads it from npm. - Upgrade Paperclip's database through migration
0183. Back up your volumes before updating, and restore untouched pre-upgrade volumes if you roll back to1.1.3. - Suspend HolyCode-managed oh-my-openagent installation. Once you remove the legacy enable flag, the first v1.1.4 start disables its old active entry while preserving settings, skills, and cached package data.
Security
- Rebuild GitHub CLI, fzf, and lazygit from their exact release sources with reviewed dependency updates.
- Replace pip's vulnerable internal msgpack and pkg_resources copies with hash-verified fixed sources.
- Remove the root npm lifecycle cache from the final image after the reviewed package scripts finish.
- Remove Netlify CLI and
serve. Hermes stays unbundled, CLIProxyAPI stays external-only, and HolyCode-managed oh-my-openagent installation remains suspended while their accessible dependency trees retain unresolved findings. - Run Chromium as the unprivileged
opencodeuser with Debian's setuid sandbox and the constrained HolyCode seccomp profile. - Record the four Chromium fixes that Debian Trixie has not published yet as narrow exceptions expiring on August 28, 2026. The release audit lists the affected CVEs, controls, and removal trigger.
Fixed
- Validate both hash-locked Python package sets, npm lifecycle scripts, release metadata, exact scanner exceptions, plugin modes, and Renovate extraction in protected release checks.
- Promote the exact multi-architecture image that passed protected validation instead of rebuilding after validation.
See the v1.1.4 dependency audit for adopted, held, removed, and unavailable updates.