Upstream Versions Registry Auto-generated by src/lib/version-check.sh and src/lib/99-upstream-sync.sh. Override at install with env vars (OPENCODE_VER, NODE_VER, etc.) or via bash setup.sh --update-versions.
Core CLIs & Runtimes Component Pinned Source Notes opencode 1.18.3 npm: opencode-ai Primary AI coding tool opencode-go 1.18.3 opencode.ai/auth Budget plan fallback @opencode-ai/plugin 1.17.9 npm GUI server dependency bun 1.3.14 https://bun.sh JS runtime + package mgr node 24 n version mgr Major version pinned python 3.14 uv Bleeding-edge go 1.26 go.dev Min version enforced dotnet 10.0.302 dot.net LTS channel java 25 Adoptium LTS zig 0.15.2 ziglang.org rust stable rustup Auto-tracks latest
Infrastructure Docker Images Service Image Tag Module postgres postgres:17 30-infra.sh redis redis:7 30-infra.sh qdrant qdrant/qdrant:v1.12.1 30-infra.sh kafka confluentinc/cp-kafka:7.6.0 30-infra.sh loki grafana/loki:2.9.10 34-observability.sh promtail grafana/promtail:2.9.10 34-observability.sh prometheus prom/prometheus:latest 34-observability.sh grafana grafana/grafana:latest 34-observability.sh
LLM Provider Endpoints Provider Base URL Notes MiniMax https://api.minimax.io/v1 OpenAI-compatible MiMo https://api.mimo.run/v1 OpenAI-compatible — unverified : endpoint not pinned in opencode.json/providers.json DeepSeek https://api.deepseek.com/v1 OpenAI-compatible xAI Grok https://api.x.ai/v1 OpenAI-compatible z.ai GLM https://api.z.ai/api/paas/v4 OpenAI-compatible
MCP Servers (npm global) Name Package Source filesystem @modelcontextprotocol/server-filesystem https://github.com/modelcontextprotocol/servers github @modelcontextprotocol/server-github same monorepo postgres @modelcontextprotocol/server-postgres same monorepo sequential-thinking @modelcontextprotocol/server-sequential-thinking same monorepo memory @modelcontextprotocol/server-memory same monorepo redis @modelcontextprotocol/server-redis same monorepo context7 @upstash/context7-mcp https://github.com/upstash/context7 agentic-tools @pimzino/agentic-tools-mcp https://github.com/pimzino/agentic-tools-mcp codegraph @colbymchenry/codegraph https://github.com/colbymchenry/codegraph playwright @playwright/mcp https://github.com/microsoft/playwright-mcp agent-browser agent-browser-mcp-server https://github.com/hughedward/agent_browser_mcp memorylayer @scitrera/memorylayer-mcp-server https://github.com/scitrera/memorylayer chrome-devtools chrome-devtools-mcp https://github.com/ChromeDevTools/chrome-devtools-mcp
Python MCP (via uvx/pipx) mcp-server-git, mcp-server-fetch, mcp-server-time Upstream Git Submodules (.gitmodules) Path URL Branch upstream/opencode https://github.com/opencode-ai/opencode.git dev upstream/mcp-servers https://github.com/modelcontextprotocol/servers.git main upstream/searxng https://github.com/searxng/searxng.git master upstream/superpowers https://github.com/obra/superpowers.git main upstream/skill-conductor https://github.com/smixs/skill-conductor.git main
License Audit License Components MIT opencode-ai, Bun, Node, Ollama, Open WebUI, most MCP packages Apache-2.0 @playwright/mcp, chrome-devtools, agent-browser, @scitrera/memorylayer BSD Go, Rust, Redis AGPL-3.0 SearXNG (Docker-deployed as separate service — compatible) GPL-3.0 brave-search-mcp, google-maps-mcp (copyleft; flagged in README) MIT → Apache-2.0 @modelcontextprotocol/* (transitioning; both licenses valid)
Full audit: see src/lib/40-best-practices.sh license header.
Update Mechanism # Refresh all upstream submodules
git submodule update --remote --merge
# Check for newer tool versions
bash src/lib/version-check.sh
# Update pinned versions
bash src/lib/99-upstream-sync.sh # (new module, see below)
## v3.0.0 Changes (2026-08-08)
### SDD-native AI Harness
- **Model Governance** ( 43 -governance.sh) : ` model-policy.json` with provider/model allowlist/blocklist; modes: allow-all, allowlist, corporate; audit log per call
- **PII Sanitizer** ( 45 -pii-guard.sh + scripts/pii-guard.py) : 9 detectors — email, phone, INN, SNILS, passport, credit card, IP, API key; pre-LLM-request gate
- **Audit Trail** ( 44 -audit.sh) : 7 WAL event types ( model_call, tool_call, provider_switch, pii_redacted, etc.) ; SHA-256 hash-chain; rotation >10MB → gzip+Qdrant archive
- **Constitution Generator** ( 41 -constitution.sh) : ` memory/constitution.md` auto-generation at project init; 4 deployment profile templates
- **Lifecycle Hooks** ( 42 -hooks.sh) : pre-request, post-response, pre-commit, on-error hook framework; pluggable via ` ~/.config/opencode/hooks/`
- **Air-Gap Offline Bundle** ( 46 -offline-bundle.sh) : ` dev bundle create| list| verify <path>` ; SHA-256 manifest; ` setup.sh --airgap` for fully offline installation
### Deployment Profiles
4 profiles with enforced rules: **personal** ( auto-update, telemetry: on) , **corporate** ( provider allowlist, audit: on, telemetry: off) , **air-gapped** ( no network, isolated circuit, SHA-256 verify only) , **hybrid** ( online dev + offline CI)
### Supply-Chain Hardening
6 ` curl| sh` patterns replaced with ` _download_verify() ` — download artifact → verify SHA-256 → execute. ` _download_verify() ` defined in helpers.sh with retry and checksum enforcement.
### Core Fixes
- Dry-run guard: ` _set_dns() ` now respects ` DRY_RUN` flag ( 00 -core.sh)
- ISOLATED_CIRCUIT gates: version-check, autoupdate, unattended-upgrades all gated
- Idempotency: ` rm -rf ~/.cache/opencode` removed from bootstrap ( setup.sh)
## v2.0.3 Changes (2026-08-08)
### macOS Compatibility
- All ` grep -oP` ( PCRE) patterns migrated to ` grep -oE` ( ERE) with ` sed` /` awk` fallbacks
- macOS users need: ` brew install bash grep` ( bash>= 4 + GNU grep)
- ` declare -A` ( associative arrays) documented as known limitation on macOS bash 3 .2
- See AGENTS.md "Known Limitations" for full details
August 22, 2026 July 20, 2026