Repository navigation
BoundedCode v0.1.0-alpha.3 (Public Alpha, pre-release)
Pre-releaseYour model, your platform, your language.
This alpha removes the "one machine, one model" limits of the first
releases. You can use a cloud model API instead of the local model, choose a
local model that fits your hardware, and run on macOS or (experimentally)
Windows. Verification now works without configuration for Python, Rust,
Java/Kotlin, C/C++, Ruby and PHP as well as Go and JavaScript/TypeScript.
Cross-service analysis now covers gRPC, protobuf, OpenAPI and SQL contracts.
The local default, Qwen3.6-35B-A3B on Linux with an NVIDIA GPU, is still the
only validated configuration. Its validation results from
v0.1.0-alpha.1 still apply. The new features are covered
by unit, integration and container tests but have not yet been validated on
real tasks. That is what this release asks you to help with.
Highlights
-
Cloud model providers (experimental): OpenAI, Anthropic, Google Gemini
or any OpenAI-compatible service, instead of the local model.bcode provider key set anthropic # prompts for the key, no echo bcode provider use anthropic --model claude-opus-5-5 bcode provider test
API keys are kept in the OS credential store (or an owner-only file),
never inconfig.yaml, on command lines or in logs. Only the host-side
gateway uses them: the agent's sandbox still has no network and never sees
a key. With a cloud provider, the agent's conversation, including
repository content, is sent to that provider. -
A model for your hardware (experimental):
bcode model recommend
rates every model profile against this machine (GPU, unified memory on
Apple Silicon, RAM, disk) and suggests one. Five new profiles (Qwen3.5-4B
and 9B, gpt-oss-20b, Devstral Small 2, Qwen3.8-27B), all Apache-2.0 and
pinned by commit and checksum. Downloads are resumable and
checksum-verified (bcode model fetch|use|remove). -
Set-up wizard (experimental):
/setupin the interface walks you
through a local model or a cloud API. For a cloud API it has a masked key
field, the provider's live model list and a connection test. The model and
provider are set up from the interface, with no config file to edit. -
macOS and Windows (experimental): binaries for macOS (Apple Silicon
and Intel) and Windows, with prebuilt checksum-verified tools and llama.cpp
(Metal on Apple Silicon), Docker Desktop resource limits, and Windows path
handling in the Linux sandbox. Install on Windows withscripts/install.ps1. -
Verification for more languages: built-in presets for Python (pytest
or unittest), Rust (Cargo), Java and Kotlin (Maven, Gradle; JDK 11, 17 or
21 chosen per project), C/C++ (CMake + CTest, Meson, Autotools, Make), Ruby
and PHP. Any other language runs its Makefile'stest/checktarget; when
nothing applies, a skippedtestsstage says so instead of passing
silently. Dependencies stay offline: the checkout's.venvorvendor/,
and this machine's Cargo, Maven and Gradle caches, read-only. Behavioural
evidence ("a changed test fails on the original code and passes with the
change") is compared per test for pytest, unittest, Cargo, Maven, Gradle,
minitest, RSpec, PHPUnit, CTest and Meson. One project per language is
verified offline in the real sandbox image by a container test. -
gRPC, protobuf, OpenAPI and SQL contracts: cross-service analysis now
links gRPC clients to servers down to the RPC (Go, Python, Java/Kotlin, C#,
Rust, Ruby, PHP, TS/JS),.protopackages to the code using them, OpenAPI
operations to routes and calls, and SQL tables to queries in other
services. When the agent changes a.proto, a spec or a migration but not
the code depending on it, it gets one round to update it. On Google's
Online Boutique demo it finds all 21 gRPC connections between its services
and nothing else. -
Clearer failures: a missing or stopped Docker, a missing sandbox image,
model weights orllama-server, and broken tools are each reported with
thesetup --only STEPthat fixes them, before a task starts. -
Fewer false ambiguity stops: an ambiguity must be supported by the
request's own text before the task stops to ask you.
Upgrade notes
- Rebuild the sandbox image:
bcode setupdetects the image built by
alpha.2 as outdated and rebuilds it (about 5 GB instead of 2 GB, for the
new language toolchains). - Re-index: run
bcode indexto fill the new cross-service contracts. - The database migrates itself (migrations 4 and 5).
- Behaviour changes:
- A changed test that does not compile or load on the original code, or a
stage that times out there, is no longer behavioural evidence. Such a
task endstests_green, nottask_verified. - Repositories in Python, Rust, Java, C/C++, Ruby or PHP now get test
stages. A project whose dependencies are not installed in the checkout
fails verification with the command to install them, where it used to
pass with no tests run. - If codebase-memory-mcp is missing or at the wrong version,
index
fails with one message namingsetup --only tools; a task run warns
and continues without graph context.
- A changed test that does not compile or load on the original code, or a
- New Go dependencies:
anthropic-sdk-go,go-keyring,godbus/dbusand
their runtime (MIT, BSD, Apache-2.0), listed inTHIRD_PARTY_NOTICES.md.
Known limitations
- Only Qwen3.6-35B-A3B on Linux with an NVIDIA GPU is validated. Cloud
providers, the other model profiles, macOS and Windows have not been run
end to end on real tasks. - Windows: 17 of 31 test packages pass on the CI runner and the full flow
has not been run on a Windows machine. macOS: 26 of 31 pass and the full
flow has not been run on a Mac. Serena is not supported on Windows. - Verification runs offline: a project's dependencies must already be
installed in the checkout or in this machine's package caches. - HTTP routes and calls, topics and environment variables are analyzed in
Go and TS/JS only; the other languages contribute gRPC, protobuf and SQL
contracts. SQL contracts are per table, not per column. - The validation limitations of
v0.1.0-alpha.1 still apply.
Please report what you find:
issues. The
verification state a task ended in (task_verified, tests_green or
failed), and whether it was right, is the most useful thing you can tell us.
Assets
boundedcode-linux-amd64,boundedcode-linux-arm64,
boundedcode-darwin-amd64,boundedcode-darwin-arm64,
boundedcode-windows-amd64.exe,boundedcode-windows-arm64.exe: static
binaries (CGO disabled).SHA256SUMS: checksums, verified by the installers.SBOM-<os>-<arch>.spdx.json: SPDX 2.3 software bill of materials of each
binary.boundedcode-v0.1.0-alpha.3-licenses.tar.gz:LICENSE,NOTICE,
THIRD_PARTY_NOTICES.mdand the license texts of every Go module compiled
into the binaries (LICENSES/go) and of the upstream components
(LICENSES/upstream).
Model weights are not distributed. Download them with bcode setup or
bcode model fetch, from their publisher at a pinned revision, and review
their license.