Skip to content

BoundedCode v0.1.0-alpha.3 (Public Alpha, pre-release)

Pre-release
Pre-release

Choose a tag to compare

@akynte akynte released this 08 Oct 12:09
· 22 commits to main since this release

Your model, your platform, your language.

This alpha removes the "one machine, one model" limits of the first
releases. You can use a cloud model API instead of the local model, choose a
local model that fits your hardware, and run on macOS or (experimentally)
Windows. Verification now works without configuration for Python, Rust,
Java/Kotlin, C/C++, Ruby and PHP as well as Go and JavaScript/TypeScript.
Cross-service analysis now covers gRPC, protobuf, OpenAPI and SQL contracts.

The local default, Qwen3.6-35B-A3B on Linux with an NVIDIA GPU, is still the
only validated configuration. Its validation results from
v0.1.0-alpha.1 still apply. The new features are covered
by unit, integration and container tests but have not yet been validated on
real tasks
. That is what this release asks you to help with.

Highlights

  • Cloud model providers (experimental): OpenAI, Anthropic, Google Gemini
    or any OpenAI-compatible service, instead of the local model.

    bcode provider key set anthropic      # prompts for the key, no echo
    bcode provider use anthropic --model claude-opus-5-5
    bcode provider test

    API keys are kept in the OS credential store (or an owner-only file),
    never in config.yaml, on command lines or in logs. Only the host-side
    gateway uses them: the agent's sandbox still has no network and never sees
    a key. With a cloud provider, the agent's conversation, including
    repository content, is sent to that provider.

  • A model for your hardware (experimental): bcode model recommend
    rates every model profile against this machine (GPU, unified memory on
    Apple Silicon, RAM, disk) and suggests one. Five new profiles (Qwen3.5-4B
    and 9B, gpt-oss-20b, Devstral Small 2, Qwen3.8-27B), all Apache-2.0 and
    pinned by commit and checksum. Downloads are resumable and
    checksum-verified (bcode model fetch|use|remove).

  • Set-up wizard (experimental): /setup in the interface walks you
    through a local model or a cloud API. For a cloud API it has a masked key
    field, the provider's live model list and a connection test. The model and
    provider are set up from the interface, with no config file to edit.

  • macOS and Windows (experimental): binaries for macOS (Apple Silicon
    and Intel) and Windows, with prebuilt checksum-verified tools and llama.cpp
    (Metal on Apple Silicon), Docker Desktop resource limits, and Windows path
    handling in the Linux sandbox. Install on Windows with scripts/install.ps1.

  • Verification for more languages: built-in presets for Python (pytest
    or unittest), Rust (Cargo), Java and Kotlin (Maven, Gradle; JDK 11, 17 or
    21 chosen per project), C/C++ (CMake + CTest, Meson, Autotools, Make), Ruby
    and PHP. Any other language runs its Makefile's test/check target; when
    nothing applies, a skipped tests stage says so instead of passing
    silently. Dependencies stay offline: the checkout's .venv or vendor/,
    and this machine's Cargo, Maven and Gradle caches, read-only. Behavioural
    evidence ("a changed test fails on the original code and passes with the
    change") is compared per test for pytest, unittest, Cargo, Maven, Gradle,
    minitest, RSpec, PHPUnit, CTest and Meson. One project per language is
    verified offline in the real sandbox image by a container test.

  • gRPC, protobuf, OpenAPI and SQL contracts: cross-service analysis now
    links gRPC clients to servers down to the RPC (Go, Python, Java/Kotlin, C#,
    Rust, Ruby, PHP, TS/JS), .proto packages to the code using them, OpenAPI
    operations to routes and calls, and SQL tables to queries in other
    services. When the agent changes a .proto, a spec or a migration but not
    the code depending on it, it gets one round to update it. On Google's
    Online Boutique demo it finds all 21 gRPC connections between its services
    and nothing else.

  • Clearer failures: a missing or stopped Docker, a missing sandbox image,
    model weights or llama-server, and broken tools are each reported with
    the setup --only STEP that fixes them, before a task starts.

  • Fewer false ambiguity stops: an ambiguity must be supported by the
    request's own text before the task stops to ask you.

Upgrade notes

  • Rebuild the sandbox image: bcode setup detects the image built by
    alpha.2 as outdated and rebuilds it (about 5 GB instead of 2 GB, for the
    new language toolchains).
  • Re-index: run bcode index to fill the new cross-service contracts.
  • The database migrates itself (migrations 4 and 5).
  • Behaviour changes:
    • A changed test that does not compile or load on the original code, or a
      stage that times out there, is no longer behavioural evidence. Such a
      task ends tests_green, not task_verified.
    • Repositories in Python, Rust, Java, C/C++, Ruby or PHP now get test
      stages. A project whose dependencies are not installed in the checkout
      fails verification with the command to install them, where it used to
      pass with no tests run.
    • If codebase-memory-mcp is missing or at the wrong version, index
      fails with one message naming setup --only tools; a task run warns
      and continues without graph context.
  • New Go dependencies: anthropic-sdk-go, go-keyring, godbus/dbus and
    their runtime (MIT, BSD, Apache-2.0), listed in THIRD_PARTY_NOTICES.md.

Known limitations

  1. Only Qwen3.6-35B-A3B on Linux with an NVIDIA GPU is validated. Cloud
    providers, the other model profiles, macOS and Windows have not been run
    end to end on real tasks.
  2. Windows: 17 of 31 test packages pass on the CI runner and the full flow
    has not been run on a Windows machine. macOS: 26 of 31 pass and the full
    flow has not been run on a Mac. Serena is not supported on Windows.
  3. Verification runs offline: a project's dependencies must already be
    installed in the checkout or in this machine's package caches.
  4. HTTP routes and calls, topics and environment variables are analyzed in
    Go and TS/JS only; the other languages contribute gRPC, protobuf and SQL
    contracts. SQL contracts are per table, not per column.
  5. The validation limitations of
    v0.1.0-alpha.1 still apply.

Please report what you find:
issues. The
verification state a task ended in (task_verified, tests_green or
failed), and whether it was right, is the most useful thing you can tell us.

Assets

  • boundedcode-linux-amd64, boundedcode-linux-arm64,
    boundedcode-darwin-amd64, boundedcode-darwin-arm64,
    boundedcode-windows-amd64.exe, boundedcode-windows-arm64.exe: static
    binaries (CGO disabled).
  • SHA256SUMS: checksums, verified by the installers.
  • SBOM-<os>-<arch>.spdx.json: SPDX 2.3 software bill of materials of each
    binary.
  • boundedcode-v0.1.0-alpha.3-licenses.tar.gz: LICENSE, NOTICE,
    THIRD_PARTY_NOTICES.md and the license texts of every Go module compiled
    into the binaries (LICENSES/go) and of the upstream components
    (LICENSES/upstream).

Model weights are not distributed. Download them with bcode setup or
bcode model fetch, from their publisher at a pinned revision, and review
their license.