Skip to content

v1.1.4

Choose a tag to compare

@CoderLuii CoderLuii released this 30 Jul 13:55

07/30/2026

Changed

  • Update OpenCode to 1.18.9, Claude Code to 2.1.220, Paperclip to 2026.722.0, npm to 12.0.2, pnpm to 11.18.0, ESLint to 10.8.0, Wrangler to 4.115.0, and Prisma to 7.9.1.
  • Refresh the Python 3.13 package set, including pip 26.2, pandas 3.0.5, tqdm 4.70.0, FastAPI 0.141.1, and Uvicorn 0.52.0.
  • Bundle opencode-claude-auth 2.1.5 as an integrity-checked offline package so container startup no longer downloads it from npm.
  • Upgrade Paperclip's database through migration 0183. Back up your volumes before updating, and restore untouched pre-upgrade volumes if you roll back to 1.1.3.
  • Suspend HolyCode-managed oh-my-openagent installation. Once you remove the legacy enable flag, the first v1.1.4 start disables its old active entry while preserving settings, skills, and cached package data.

Security

  • Rebuild GitHub CLI, fzf, and lazygit from their exact release sources with reviewed dependency updates.
  • Replace pip's vulnerable internal msgpack and pkg_resources copies with hash-verified fixed sources.
  • Remove the root npm lifecycle cache from the final image after the reviewed package scripts finish.
  • Remove Netlify CLI and serve. Hermes stays unbundled, CLIProxyAPI stays external-only, and HolyCode-managed oh-my-openagent installation remains suspended while their accessible dependency trees retain unresolved findings.
  • Run Chromium as the unprivileged opencode user with Debian's setuid sandbox and the constrained HolyCode seccomp profile.
  • Record the four Chromium fixes that Debian Trixie has not published yet as narrow exceptions expiring on August 28, 2026. The release audit lists the affected CVEs, controls, and removal trigger.

Fixed

  • Validate both hash-locked Python package sets, npm lifecycle scripts, release metadata, exact scanner exceptions, plugin modes, and Renovate extraction in protected release checks.
  • Promote the exact multi-architecture image that passed protected validation instead of rebuilding after validation.

See the v1.1.4 dependency audit for adopted, held, removed, and unavailable updates.