Skip to content

Upstream Versions Registry

Auto-generated by src/lib/version-check.sh and src/lib/99-upstream-sync.sh. Override at install with env vars (OPENCODE_VER, NODE_VER, etc.) or via bash setup.sh --update-versions.

Core CLIs & Runtimes

Component Pinned Source Notes
opencode 1.18.3 npm: opencode-ai Primary AI coding tool
opencode-go 1.18.3 opencode.ai/auth Budget plan fallback
@opencode-ai/plugin 1.17.9 npm GUI server dependency
bun 1.3.14 https://bun.sh JS runtime + package mgr
node 24 n version mgr Major version pinned
python 3.14 uv Bleeding-edge
go 1.26 go.dev Min version enforced
dotnet 10.0.302 dot.net LTS channel
java 25 Adoptium LTS
zig 0.15.2 ziglang.org
rust stable rustup Auto-tracks latest

Infrastructure Docker Images

Service Image Tag Module
postgres postgres:17 30-infra.sh
redis redis:7 30-infra.sh
qdrant qdrant/qdrant:v1.12.1 30-infra.sh
kafka confluentinc/cp-kafka:7.6.0 30-infra.sh
loki grafana/loki:2.9.10 34-observability.sh
promtail grafana/promtail:2.9.10 34-observability.sh
prometheus prom/prometheus:latest 34-observability.sh
grafana grafana/grafana:latest 34-observability.sh

LLM Provider Endpoints

Provider Base URL Notes
MiniMax https://api.minimax.io/v1 OpenAI-compatible
MiMo https://api.mimo.run/v1 OpenAI-compatible — unverified: endpoint not pinned in opencode.json/providers.json
DeepSeek https://api.deepseek.com/v1 OpenAI-compatible
xAI Grok https://api.x.ai/v1 OpenAI-compatible
z.ai GLM https://api.z.ai/api/paas/v4 OpenAI-compatible

MCP Servers (npm global)

Name Package Source
filesystem @modelcontextprotocol/server-filesystem https://github.com/modelcontextprotocol/servers
github @modelcontextprotocol/server-github same monorepo
postgres @modelcontextprotocol/server-postgres same monorepo
sequential-thinking @modelcontextprotocol/server-sequential-thinking same monorepo
memory @modelcontextprotocol/server-memory same monorepo
redis @modelcontextprotocol/server-redis same monorepo
context7 @upstash/context7-mcp https://github.com/upstash/context7
agentic-tools @pimzino/agentic-tools-mcp https://github.com/pimzino/agentic-tools-mcp
codegraph @colbymchenry/codegraph https://github.com/colbymchenry/codegraph
playwright @playwright/mcp https://github.com/microsoft/playwright-mcp
agent-browser agent-browser-mcp-server https://github.com/hughedward/agent_browser_mcp
memorylayer @scitrera/memorylayer-mcp-server https://github.com/scitrera/memorylayer
chrome-devtools chrome-devtools-mcp https://github.com/ChromeDevTools/chrome-devtools-mcp

Python MCP (via uvx/pipx)

  • mcp-server-git, mcp-server-fetch, mcp-server-time

Upstream Git Submodules (.gitmodules)

Path URL Branch
upstream/opencode https://github.com/opencode-ai/opencode.git dev
upstream/mcp-servers https://github.com/modelcontextprotocol/servers.git main
upstream/searxng https://github.com/searxng/searxng.git master
upstream/superpowers https://github.com/obra/superpowers.git main
upstream/skill-conductor https://github.com/smixs/skill-conductor.git main

License Audit

License Components
MIT opencode-ai, Bun, Node, Ollama, Open WebUI, most MCP packages
Apache-2.0 @playwright/mcp, chrome-devtools, agent-browser, @scitrera/memorylayer
BSD Go, Rust, Redis
AGPL-3.0 SearXNG (Docker-deployed as separate service — compatible)
GPL-3.0 brave-search-mcp, google-maps-mcp (copyleft; flagged in README)
MIT → Apache-2.0 @modelcontextprotocol/* (transitioning; both licenses valid)

Full audit: see src/lib/40-best-practices.sh license header.

Update Mechanism

# Refresh all upstream submodules
git submodule update --remote --merge

# Check for newer tool versions
bash src/lib/version-check.sh

# Update pinned versions
bash src/lib/99-upstream-sync.sh    # (new module, see below)

## v3.0.0 Changes (2026-08-08)

### SDD-native AI Harness
- **Model Governance** (43-governance.sh): `model-policy.json` with provider/model allowlist/blocklist; modes: allow-all, allowlist, corporate; audit log per call
- **PII Sanitizer** (45-pii-guard.sh + scripts/pii-guard.py): 9 detectors — email, phone, INN, SNILS, passport, credit card, IP, API key; pre-LLM-request gate
- **Audit Trail** (44-audit.sh): 7 WAL event types (model_call, tool_call, provider_switch, pii_redacted, etc.); SHA-256 hash-chain; rotation >10MB → gzip+Qdrant archive
- **Constitution Generator** (41-constitution.sh): `memory/constitution.md` auto-generation at project init; 4 deployment profile templates
- **Lifecycle Hooks** (42-hooks.sh): pre-request, post-response, pre-commit, on-error hook framework; pluggable via `~/.config/opencode/hooks/`
- **Air-Gap Offline Bundle** (46-offline-bundle.sh): `dev bundle create|list|verify <path>`; SHA-256 manifest; `setup.sh --airgap` for fully offline installation

### Deployment Profiles
4 profiles with enforced rules: **personal** (auto-update, telemetry: on), **corporate** (provider allowlist, audit: on, telemetry: off), **air-gapped** (no network, isolated circuit, SHA-256 verify only), **hybrid** (online dev + offline CI)

### Supply-Chain Hardening
6 `curl|sh` patterns replaced with `_download_verify()` — download artifact → verify SHA-256 → execute. `_download_verify()` defined in helpers.sh with retry and checksum enforcement.

### Core Fixes
- Dry-run guard: `_set_dns()` now respects `DRY_RUN` flag (00-core.sh)
- ISOLATED_CIRCUIT gates: version-check, autoupdate, unattended-upgrades all gated
- Idempotency: `rm -rf ~/.cache/opencode` removed from bootstrap (setup.sh)

## v2.0.3 Changes (2026-08-08)

### macOS Compatibility
- All `grep -oP` (PCRE) patterns migrated to `grep -oE` (ERE) with `sed`/`awk` fallbacks
- macOS users need: `brew install bash grep` (bash>=4 + GNU grep)
- `declare -A` (associative arrays) documented as known limitation on macOS bash 3.2
- See AGENTS.md "Known Limitations" for full details