Skip to content

Commit 3f7b549

Browse files
committed
Merge branch 'dev' into fix/center-selected-session
2 parents 55e80b0 + 74baae5 commit 3f7b549

File tree

108 files changed

+5898
-1229
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

108 files changed

+5898
-1229
lines changed

.opencode/command/ai-deps.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
---
2+
description: "Bump AI sdk dependencies minor / patch versions only"
3+
---
4+
5+
Please read @package.json and @packages/opencode/package.json.
6+
7+
Your job is to look into AI SDK dependencies, figure out if they have versions that can be upgraded (minor or patch versions ONLY no major ignore major changes).
8+
9+
I want a report of every dependency and the version that can be upgraded to.
10+
What would be even better is if you can give me links to the changelog for each dependency, or at least some reference info so I can see what bugs were fixed or new features were added.
11+
12+
Consider using subagents for each dep to save your context window.
13+
14+
Here is a short list of some deps (please be comprehensive tho):
15+
16+
- "ai"
17+
- "@ai-sdk/openai"
18+
- "@ai-sdk/anthropic"
19+
- "@openrouter/ai-sdk-provider"
20+
- etc, etc
21+
22+
DO NOT upgrade the dependencies yet, just make a list of all dependencies and their versions that can be upgraded to minor or patch versions only.
23+
24+
Write up your findings to ai-sdk-updates.md

.opencode/plans/1768330644696-gentle-harbor.md

Lines changed: 0 additions & 320 deletions
This file was deleted.

SECURITY.md

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,32 @@
1+
# Security
2+
3+
## Threat Model
4+
5+
### Overview
6+
7+
OpenCode is an AI-powered coding assistant that runs locally on your machine. It provides an agent system with access to powerful tools including shell execution, file operations, and web access.
8+
9+
### No Sandbox
10+
11+
OpenCode does **not** sandbox the agent. The permission system exists as a UX feature to help users stay aware of what actions the agent is taking - it prompts for confirmation before executing commands, writing files, etc. However, it is not designed to provide security isolation.
12+
13+
If you need true isolation, run OpenCode inside a Docker container or VM.
14+
15+
### Server Mode
16+
17+
Server mode is opt-in only. When enabled, set `OPENCODE_SERVER_PASSWORD` to require HTTP Basic Auth. Without this, the server runs unauthenticated (with a warning). It is the end user's responsibility to secure the server - any functionality it provides is not a vulnerability.
18+
19+
### Out of Scope
20+
21+
| Category | Rationale |
22+
| ------------------------------- | ----------------------------------------------------------------------- |
23+
| **Server access when opted-in** | If you enable server mode, API access is expected behavior |
24+
| **Sandbox escapes** | The permission system is not a sandbox (see above) |
25+
| **LLM provider data handling** | Data sent to your configured LLM provider is governed by their policies |
26+
| **MCP server behavior** | External MCP servers you configure are outside our trust boundary |
27+
28+
---
29+
130
# Reporting Security Issues
231

332
We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.

STATS.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -200,3 +200,4 @@
200200
| 2026-01-11 | 2,836,394 (+204,371) | 1,530,479 (+26,809) | 4,366,873 (+231,180) |
201201
| 2026-01-12 | 3,053,594 (+217,200) | 1,553,671 (+23,192) | 4,607,265 (+240,392) |
202202
| 2026-01-13 | 3,297,078 (+243,484) | 1,595,062 (+41,391) | 4,892,140 (+284,875) |
203+
| 2026-01-14 | 3,568,928 (+271,850) | 1,645,362 (+50,300) | 5,214,290 (+322,150) |

0 commit comments

Comments
 (0)