Repository navigation
Releases: nail00749/opencode-agent
Release list
v0.12.4 — consistent agent contracts and Git workflows
Fixed
- Resolve Git readonly-file instructions conflicting with authorized repository operations. Normal requested staging, commit and push are allowed; force pushes, deletion refspecs and prune require exact-command approval. Remaining destructive denials and active-writer restrictions are retained.
- Add DevOps direct native claim access and align writer ask/deny, coordinator and reviewer/security guidance.
- Add all-17 agent contract tests, runtime/generated identity checks and isolated native Git/DevOps acceptance; regenerate agents and update knowledge.
Verification
679 tests, lint/typecheck/build, sync/package/release gates, 4 e2e tests and Linux/macOS CI PASS.
Both rebuilt OpenCode 2.0.24 isolated smokes PASS, including local bare push without approval, rejected force approval with no execution/retry, active-lease restrictions and DevOps claim/edit plus four denials. Cleanup PASS; no external push or production/global changes.
Deep review and Security APPROVE after remote-deletion/prune approval fix; metadata review APPROVE.
Limits
Explicit task intent remains model guidance. Wildcard permission rules are not exhaustive shell-safety enforcement; expanded-rule redundancy remains advisory. All-agent contract tests do not imply an individual live run of every agent. No dependency/compatibility or global installation changes.
PR: #17
v0.12.3 — direct native claim for strict writers
Fixed
- Expose native gvozd_claim directly with codemode:false while retaining exact permission and all lease guards.
- Cartographer and Docs can claim leases without opening execute or adding MCP grants.
- Update direct-call prompts and add host catalog, transport and native execution regression coverage.
Verified
651 tests, lint/typecheck/build, sync/package/release-tag gates, 4 e2e tests and Linux/macOS CI pass.
Actual OpenCode 2.0.24 with the rebuilt local plugin passes isolated native smoke: parent reservations, child claim/edit, strict writers without execute, readonly no-claim, and four rejections per writer (preclaim, wrong assignee, wrong parent, out-of-lease). Denied writes remain unchanged; final idle wait and cleanup pass.
Deep feature review and release metadata review: APPROVE.
No dependency/compatibility changes or global installation changes. Live smoke currently requires local macOS paths; production installation is not covered by the isolated result.
PR: #16
v0.12.2 — native claim permission fix
Fixed
- Explicitly bind the native gvozd.claim tool to the gvozd_claim permission action.
- Give Docs only the exact claim permission under its deny-all policy; Cartographer already has the grant.
- Add real-config and registration regressions preserving role, assignee, parent, unclaimed and out-of-lease guards.
No broad execute/MCP grants, dependency or compatibility changes.
Verification: 642 tests, lint/typecheck/build, sync/package/release gates, 4 package e2e tests and Linux/macOS CI passed. Deep security and release metadata reviews APPROVE.
Actual host discovery in fresh Cartographer/Docs sessions remains to be verified after installation.
PR: #15
v0.12.1 — MR evidence reporting fix
Fixed
- Separate local Git inspection from CLI discovery and forge preflight calls.
- Distinguish pending/rejected requests from executed CLI failures and unverified authentication.
- Do not infer CLI/keyring authentication failure from anonymous HTTP login pages.
- Preserve confirmed host/repository/MR identifiers in commands and suggestions.
Permissions, dependencies and OpenCode compatibility unchanged.
Verification: 638 tests, lint/typecheck, build, sync/package/release gates, 4 e2e tests and Linux/macOS CI passed. Prompt and metadata review APPROVE.
PR: #14
v0.12.0 — forge, CI and runner CLI skills
Added
- Built-in forge-workflow, ci-workflow and runner-workflow skills using git, glab and gh.
- Secure managed installation through setup and project sync, with doctor/package checks.
- Pipeline/job/runner diagnostics and explicitly confirmed supported operations.
Changed
- Default agent guidance and permissions no longer depend on GitLab MCP. Existing user MCP configurations are not automatically removed.
- Local users must provide installed and authenticated CLIs; skills are guidance, not permission enforcement.
Verification
634 unit tests + 4 package e2e tests, lint, typecheck, build, sync/package/release gates and Linux/macOS CI passed.
PR: #13
v0.11.4
v0.11.3
v0.11.2
v0.11.1
Release 0.11.0
0.11.0
Added
- Goal/extreme mode (the
extremecoordinator): every round runs
measure → improve → verify against a metric until plateau or limit,
with family-scoped auto-approval, CLI transport through a file intent,
a round log plusrecord/statusreporting, and per-layer config
limits. - Permissions tab bulk actions:
Allow allapproves every pending
request at once andReset allreturns the tab to the agent policy,
so a full grant or a clean reset no longer needs row-by-row toggling. - Mandatory
code-review-excellencein the review prompts: both review
tiers carry the shared review skill, andgvozd doctorreports a
missing review skill instead of silently running without it.
Guards, stated exactly as implemented:
- The grant is family-scoped: it covers only sessions in the goal
family, never the whole server. - Never-escalate command families and file-lease enforcement stay
denied even under an active goal. - Loop commands come only from the start input: agents run exactly the
recordedmeasureCmd/verifyCmdand cannot invent replacements
mid-loop.