diff --git a/.gds/bundle.lock.yaml b/.gds/bundle.lock.yaml
new file mode 100644
index 0000000..21205c1
--- /dev/null
+++ b/.gds/bundle.lock.yaml
@@ -0,0 +1,16 @@
+# GENERATED FILE - DO NOT EDIT DIRECTLY
+schema_version: 1
+
+bundle:
+ version: "0.9.4-dev"
+ release_sequence: 0
+ channel: "development"
+ source_tree_digest: "sha256:b1c334df899c661304dc45ef29898df24ff4a6ddffd2a6ca4d6f1f795d585189"
+ digest: "sha256:469ac74bf934333ee1fde843ad04a26e002e5b5ec9c782fbe68ec6fe313bfac0"
+
+projection:
+ input_digest: "sha256:c87f0fc49a274ff5304a109a72ff0da4b700ecc932e6fc43f9fe96fa2dbaf9bc"
+ output_digest: "sha256:c5be6d325c9db3c058b0a06bf0144da9d648b8511ad4c99eed04855a47806ca8"
+ files:
+ - path: ".gds/compiled-policy.json"
+ digest: "sha256:ca79997d1614742bc4ccc55ba4c8118802f589b923aed3910ebe5a315b838567"
diff --git a/.gds/compiled-policy.json b/.gds/compiled-policy.json
new file mode 100644
index 0000000..f65213b
--- /dev/null
+++ b/.gds/compiled-policy.json
@@ -0,0 +1,412 @@
+{
+ "schema_version": 1,
+ "compiled_policy": {
+ "repository_id": "repo_01087WPKCEYEDP64ZFXG5YV2MB",
+ "bundle_version": "0.9.4-dev",
+ "digest": "sha256:5ee81c53905fda4d40d7f83ad2d20df10b27d794fd6086b9f8957ba5bb5fdea7"
+ },
+ "sources": [
+ {
+ "id": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "distribution": "public",
+ "path": "policies/base/repository-default.yaml",
+ "digest": "sha256:0ea560cc2653184e07c6f744455f745a34f764a5c0dcda55f2dc76fa5296f2f0"
+ },
+ {
+ "id": "opennetwork-default",
+ "tier": "owner",
+ "priority": 110,
+ "distribution": "public",
+ "path": "policies/owners/opennetwork-default.yaml",
+ "digest": "sha256:096b9781b05c37fd5b440a171a6e5599cda3ef77983db72bf9c68d3d40b34ab4"
+ }
+ ],
+ "effective": {
+ "agent": {
+ "generated_projection_edit": "forbidden",
+ "profiles": [
+ "core",
+ "drakkars"
+ ]
+ },
+ "context": {
+ "private_parent_persistence": "forbidden"
+ },
+ "git": {
+ "branch_cleanup": "merged-only",
+ "default_branch": "main",
+ "integration": "pull-request"
+ },
+ "github": {
+ "actions": {
+ "allowed_actions": {
+ "management": "observed"
+ },
+ "enabled": {
+ "management": "managed",
+ "value": true
+ },
+ "selected_actions": {
+ "management": "observed"
+ },
+ "sha_pinning_required": {
+ "management": "observed"
+ }
+ },
+ "merge": {
+ "allow_auto_merge": {
+ "management": "observed"
+ },
+ "allow_merge_commit": {
+ "management": "managed",
+ "value": true
+ },
+ "allow_rebase_merge": {
+ "management": "observed"
+ },
+ "allow_squash_merge": {
+ "management": "managed",
+ "value": false
+ },
+ "allow_update_branch": {
+ "management": "managed",
+ "value": true
+ },
+ "delete_branch_on_merge": {
+ "management": "managed",
+ "value": true
+ },
+ "merge_commit_message": {
+ "management": "observed"
+ },
+ "merge_commit_title": {
+ "management": "observed"
+ },
+ "squash_merge_commit_message": {
+ "management": "observed"
+ },
+ "squash_merge_commit_title": {
+ "management": "observed"
+ }
+ },
+ "releases": {
+ "immutable": {
+ "management": "observed"
+ }
+ },
+ "rulesets": {
+ "management": "observed"
+ },
+ "security": {
+ "management": "observed"
+ },
+ "workflow": {
+ "can_approve_pull_request_reviews": {
+ "management": "managed",
+ "value": false
+ },
+ "default_workflow_permissions": {
+ "management": "managed",
+ "value": "read"
+ }
+ }
+ },
+ "package_management": {
+ "mutable_version_resolution": "forbidden",
+ "npm_family_on_managed_path": "allowed",
+ "remote_stream_to_shell": "forbidden"
+ },
+ "rollout": {
+ "mode": "pull-request"
+ },
+ "security": {
+ "external_write_requires_approval": true,
+ "public_projection_scan": "required",
+ "secrets_in_repository": "forbidden"
+ }
+ },
+ "provenance": {
+ "/effective/agent/generated_projection_edit": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/agent/profiles/0": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "append"
+ },
+ "/effective/agent/profiles/1": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "append"
+ },
+ "/effective/context/private_parent_persistence": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/git/branch_cleanup": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/git/default_branch": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/git/integration": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/actions/allowed_actions/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/actions/enabled/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/actions/enabled/value": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/actions/selected_actions/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/actions/sha_pinning_required/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/allow_auto_merge/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/allow_merge_commit/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/allow_merge_commit/value": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/allow_rebase_merge/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/allow_squash_merge/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/allow_squash_merge/value": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/allow_update_branch/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/allow_update_branch/value": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/delete_branch_on_merge/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/delete_branch_on_merge/value": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/merge_commit_message/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/merge_commit_title/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/squash_merge_commit_message/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/merge/squash_merge_commit_title/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/releases/immutable/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/rulesets/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/security/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/workflow/can_approve_pull_request_reviews/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/workflow/can_approve_pull_request_reviews/value": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/workflow/default_workflow_permissions/management": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/github/workflow/default_workflow_permissions/value": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/package_management/mutable_version_resolution": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/package_management/npm_family_on_managed_path": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/package_management/remote_stream_to_shell": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/rollout/mode": {
+ "source": "opennetwork-default",
+ "tier": "owner",
+ "priority": 110,
+ "file": "policies/owners/opennetwork-default.yaml",
+ "operation": "set"
+ },
+ "/effective/security/external_write_requires_approval": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/security/public_projection_scan": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ },
+ "/effective/security/secrets_in_repository": {
+ "source": "repository-default",
+ "tier": "base",
+ "priority": 100,
+ "file": "policies/base/repository-default.yaml",
+ "operation": "set"
+ }
+ }
+}
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 2ac6768..4b3d68f 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -15,6 +15,31 @@ cut and that this clone does not carry.
## [Unreleased]
+## [0.0.71] - 2026-09-13
+
+nddev-builder guidance is refreshed against each harness's current native
+extension model. Codex custom agents now cover inherited session settings and
+project scope; its hook guide includes Interrupt and the limits of asynchronous
+hooks as enforcement. Antigravity plugin and subagent guidance records the
+current manifest minimum, bundled agents, workspace isolation, inherited safety
+boundaries and validation behavior observed in CLI 1.2.2.
+
+Every builder manifest now cites all vendor pages used by its generated
+component guides, including sources beyond the base permission posture. The
+provider protocol, setup ownership and software artifact pins are unchanged.
+
+## [0.0.70] - 2026-09-13
+
+Software artifacts are refreshed from verified vendor bytes: Claude Code
+2.1.270, Codex 0.154.0, Grok Build 1.0.31, OpenCode 1.18.30, Cursor
+2026.09.10-fd3934a and Antigravity CLI 1.2.2. Pi remains at 0.85.1.
+Every published platform digest and rollback pin is transcribed from the same
+verified ledger.
+
+Lifecycle integration tests remain compatible with the pinned Rust 1.98.0
+toolchain by reading Cargo's executable path at runtime. Provider behavior,
+protocol-v3 declarations and setup ownership are unchanged.
+
## [0.0.69] - 2026-09-08
Native lifecycle evidence runs every provider command in the same isolated
diff --git a/Cargo.lock b/Cargo.lock
index 9a6e867..7ad630b 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -66,7 +66,7 @@ checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f"
[[package]]
name = "harness-runtime"
-version = "0.0.69"
+version = "0.0.71"
dependencies = [
"provider-v3",
"serde",
@@ -128,7 +128,7 @@ dependencies = [
[[package]]
name = "opencode-setup-system"
-version = "0.0.69"
+version = "0.0.71"
dependencies = [
"harness-runtime",
"provider-v3",
@@ -147,7 +147,7 @@ dependencies = [
[[package]]
name = "provider-v3"
-version = "0.0.69"
+version = "0.0.71"
dependencies = [
"serde",
"serde_json",
@@ -209,7 +209,7 @@ dependencies = [
[[package]]
name = "setup-core"
-version = "0.0.69"
+version = "0.0.71"
dependencies = [
"miniz_oxide",
"serde",
diff --git a/Cargo.toml b/Cargo.toml
index 8c6650b..9b5246e 100644
--- a/Cargo.toml
+++ b/Cargo.toml
@@ -8,7 +8,7 @@ members = [
]
[workspace.package]
-version = "0.0.69"
+version = "0.0.71"
edition = "2024"
rust-version = "1.89"
license = "AGPL-3.0-or-later"
@@ -23,9 +23,9 @@ sha2 = "0.11"
# `setup-core::archive`); an inflate loop is not, because its bugs are
# memory-safety bugs and it is not improved by being hand-written here.
miniz_oxide = "0.9"
-setup-core = { path = "crates/setup-core", version = "0.0.69" }
-provider-v3 = { path = "crates/provider-v3", version = "0.0.69" }
-harness-runtime = { path = "crates/harness-runtime", version = "0.0.69" }
+setup-core = { path = "crates/setup-core", version = "0.0.71" }
+provider-v3 = { path = "crates/provider-v3", version = "0.0.71" }
+harness-runtime = { path = "crates/harness-runtime", version = "0.0.71" }
[workspace.lints.rust]
unsafe_code = "forbid"
diff --git a/README.md b/README.md
index 7165d06..0a9d9fd 100644
--- a/README.md
+++ b/README.md
@@ -179,7 +179,7 @@ release is a convenience, not the authorised copy.
```bash
docker run --rm -v "$HOME/.config:/config" \
- ghcr.io/nddev-opennetwork/opencode-setup-system:0.0.69 \
+ ghcr.io/nddev-opennetwork/opencode-setup-system:0.0.71 \
status --target /config/
--json
```
diff --git a/crates/opencode-setup-system/src/software.rs b/crates/opencode-setup-system/src/software.rs
index 39e5264..f427314 100644
--- a/crates/opencode-setup-system/src/software.rs
+++ b/crates/opencode-setup-system/src/software.rs
@@ -20,103 +20,103 @@ use harness_runtime::{Artifact, Delivery, Previous, Shape, Software};
pub(crate) const ARTIFACTS: &[Artifact] = &[
Artifact {
platform: "linux/arm64",
- url: "https://registry.npmjs.org/opencode-linux-arm64/-/opencode-linux-arm64-1.18.29.tgz",
- bytes: 59_952_206,
- sha256: "sha256:bbc655accf8263d44e5c668ef865520239e58bef515057bf8ecc27d006a6f28a",
+ url: "https://registry.npmjs.org/opencode-linux-arm64/-/opencode-linux-arm64-1.18.30.tgz",
+ bytes: 59_985_069,
+ sha256: "sha256:1e20b66e76afbb7c1e5cd9be7515d2744cb4ea3476ff57add1f7e9ad6fb3a32d",
shape: Shape::GzipTar,
member: "package/bin/opencode",
},
Artifact {
platform: "linux/x86_64",
- url: "https://registry.npmjs.org/opencode-linux-x64/-/opencode-linux-x64-1.18.29.tgz",
- bytes: 60_170_392,
- sha256: "sha256:a2df564ba242759e3ee27cbd356da786243a3d3fd911cf5aa2c417521aef3042",
+ url: "https://registry.npmjs.org/opencode-linux-x64/-/opencode-linux-x64-1.18.30.tgz",
+ bytes: 60_202_013,
+ sha256: "sha256:aa31a7e68ce5c73cba302c6a4f31c2e308398db125e49d3dbea32f61862fe6de",
shape: Shape::GzipTar,
member: "package/bin/opencode",
},
Artifact {
platform: "macos/arm64",
- url: "https://registry.npmjs.org/opencode-darwin-arm64/-/opencode-darwin-arm64-1.18.29.tgz",
- bytes: 45_944_097,
- sha256: "sha256:1fc08fee8b4984c1306c826b8c0e2c367fd9eeb4d4c3707469194e3fea047e72",
+ url: "https://registry.npmjs.org/opencode-darwin-arm64/-/opencode-darwin-arm64-1.18.30.tgz",
+ bytes: 45_975_576,
+ sha256: "sha256:25b722fcdc8c46aebcb6501e1156dc1dc5a392492cc278c65b7775311674e7f8",
shape: Shape::GzipTar,
member: "package/bin/opencode",
},
Artifact {
platform: "macos/x86_64",
- url: "https://registry.npmjs.org/opencode-darwin-x64/-/opencode-darwin-x64-1.18.29.tgz",
- bytes: 48_120_807,
- sha256: "sha256:d9e2270b9040d7ce140df629773c68f15222c7a6c882f16921d36aa4c9200ae2",
+ url: "https://registry.npmjs.org/opencode-darwin-x64/-/opencode-darwin-x64-1.18.30.tgz",
+ bytes: 48_153_052,
+ sha256: "sha256:d7119bd0adbacf86c1176f07b35d429909d1d702ca0c90dcd31415e66220f590",
shape: Shape::GzipTar,
member: "package/bin/opencode",
},
Artifact {
platform: "windows/arm64",
- url: "https://registry.npmjs.org/opencode-windows-arm64/-/opencode-windows-arm64-1.18.29.tgz",
- bytes: 58_399_395,
- sha256: "sha256:ad2f4a063a6d82578edc0b37078eff76fcb2a58f6439a33c34a50e1c795512b8",
+ url: "https://registry.npmjs.org/opencode-windows-arm64/-/opencode-windows-arm64-1.18.30.tgz",
+ bytes: 58_430_892,
+ sha256: "sha256:d26f3759e7c17754e1d6c72020853ffb153c7bb0f6b7d75efdc48466f482c4d4",
shape: Shape::GzipTar,
member: "package/bin/opencode.exe",
},
Artifact {
platform: "windows/x86_64",
- url: "https://registry.npmjs.org/opencode-windows-x64/-/opencode-windows-x64-1.18.29.tgz",
- bytes: 60_086_309,
- sha256: "sha256:19eca6cdead9c67cce26fdc2db165980318edb7318c8c964dfc2ebffe03bb472",
+ url: "https://registry.npmjs.org/opencode-windows-x64/-/opencode-windows-x64-1.18.30.tgz",
+ bytes: 60_117_264,
+ sha256: "sha256:1a5cc50f529cf359fbb6d1a1750c6ae521799f463d00a0215e6eff579a08b036",
shape: Shape::GzipTar,
member: "package/bin/opencode.exe",
},
];
-/// The artifacts 1.18.27 was published as, kept so
+/// The artifacts 1.18.29 was published as, kept so
/// `software_update` has a version to move from and `rollback` a tree to
/// return to. Measured from bytes when it was the current pin.
pub(crate) const PREVIOUS_ARTIFACTS: &[Artifact] = &[
Artifact {
platform: "linux/arm64",
- url: "https://registry.npmjs.org/opencode-linux-arm64/-/opencode-linux-arm64-1.18.27.tgz",
- bytes: 59_945_385,
- sha256: "sha256:83bf3812ecad71b3a463c5c0a7ceb0dba9db96964f3e7f8ba6bf30ca138287e8",
+ url: "https://registry.npmjs.org/opencode-linux-arm64/-/opencode-linux-arm64-1.18.29.tgz",
+ bytes: 59_952_206,
+ sha256: "sha256:bbc655accf8263d44e5c668ef865520239e58bef515057bf8ecc27d006a6f28a",
shape: Shape::GzipTar,
member: "package/bin/opencode",
},
Artifact {
platform: "linux/x86_64",
- url: "https://registry.npmjs.org/opencode-linux-x64/-/opencode-linux-x64-1.18.27.tgz",
- bytes: 60_168_253,
- sha256: "sha256:0aba86ba404f52e57bd154ec3565cd3e86d344743bf32e3004bf7fdbd3363ac4",
+ url: "https://registry.npmjs.org/opencode-linux-x64/-/opencode-linux-x64-1.18.29.tgz",
+ bytes: 60_170_392,
+ sha256: "sha256:a2df564ba242759e3ee27cbd356da786243a3d3fd911cf5aa2c417521aef3042",
shape: Shape::GzipTar,
member: "package/bin/opencode",
},
Artifact {
platform: "macos/arm64",
- url: "https://registry.npmjs.org/opencode-darwin-arm64/-/opencode-darwin-arm64-1.18.27.tgz",
- bytes: 45_940_410,
- sha256: "sha256:dba942c12128491b7c00f5d4b395bb8d36061f293b59db501ca9b0911a701680",
+ url: "https://registry.npmjs.org/opencode-darwin-arm64/-/opencode-darwin-arm64-1.18.29.tgz",
+ bytes: 45_944_097,
+ sha256: "sha256:1fc08fee8b4984c1306c826b8c0e2c367fd9eeb4d4c3707469194e3fea047e72",
shape: Shape::GzipTar,
member: "package/bin/opencode",
},
Artifact {
platform: "macos/x86_64",
- url: "https://registry.npmjs.org/opencode-darwin-x64/-/opencode-darwin-x64-1.18.27.tgz",
- bytes: 48_115_145,
- sha256: "sha256:8e379467c2f911d5a6bb14a453b8f760e093daf8c5c6b9ee1da8f3515477e8f2",
+ url: "https://registry.npmjs.org/opencode-darwin-x64/-/opencode-darwin-x64-1.18.29.tgz",
+ bytes: 48_120_807,
+ sha256: "sha256:d9e2270b9040d7ce140df629773c68f15222c7a6c882f16921d36aa4c9200ae2",
shape: Shape::GzipTar,
member: "package/bin/opencode",
},
Artifact {
platform: "windows/arm64",
- url: "https://registry.npmjs.org/opencode-windows-arm64/-/opencode-windows-arm64-1.18.27.tgz",
- bytes: 58_397_893,
- sha256: "sha256:3da5a83466c814922fc1472ef4eef1c37cae990a1cfe1530959c83d3f5b13cda",
+ url: "https://registry.npmjs.org/opencode-windows-arm64/-/opencode-windows-arm64-1.18.29.tgz",
+ bytes: 58_399_395,
+ sha256: "sha256:ad2f4a063a6d82578edc0b37078eff76fcb2a58f6439a33c34a50e1c795512b8",
shape: Shape::GzipTar,
member: "package/bin/opencode.exe",
},
Artifact {
platform: "windows/x86_64",
- url: "https://registry.npmjs.org/opencode-windows-x64/-/opencode-windows-x64-1.18.27.tgz",
- bytes: 60_079_608,
- sha256: "sha256:d940ca3115e9a87107bb666c30c3efea88bcad1c2d34212c8deb4401a3054792",
+ url: "https://registry.npmjs.org/opencode-windows-x64/-/opencode-windows-x64-1.18.29.tgz",
+ bytes: 60_086_309,
+ sha256: "sha256:19eca6cdead9c67cce26fdc2db165980318edb7318c8c964dfc2ebffe03bb472",
shape: Shape::GzipTar,
member: "package/bin/opencode.exe",
},
@@ -124,12 +124,12 @@ pub(crate) const PREVIOUS_ARTIFACTS: &[Artifact] = &[
/// Opencode's program, and where its bytes come from.
pub(crate) const SOFTWARE: Software = Software {
- version: "1.18.29",
+ version: "1.18.30",
command: "opencode",
delivery: Delivery::Artifacts(ARTIFACTS),
unsupported: &[],
previous: Some(Previous {
- version: "1.18.27",
+ version: "1.18.29",
artifacts: PREVIOUS_ARTIFACTS,
}),
};
diff --git a/crates/opencode-setup-system/tests/lifecycle.rs b/crates/opencode-setup-system/tests/lifecycle.rs
index 96c046f..62556e8 100644
--- a/crates/opencode-setup-system/tests/lifecycle.rs
+++ b/crates/opencode-setup-system/tests/lifecycle.rs
@@ -10,12 +10,15 @@
//! runs for all seven systems on all three platforms, and a crate carries only
//! the one fact that is its own: which binary to run.
+#![allow(clippy::expect_used, reason = "tests require Cargo's binary path")]
+
/// Install, select, back up, hold, restore, restore to a named slot, release,
/// remove -- and a file this provider does not own, present throughout.
#[test]
fn the_documented_round_trip_works_on_this_system() {
- let exe = std::path::Path::new(env!("CARGO_BIN_EXE_opencode-setup-system"));
- let problems = harness_runtime::probe::round_trip(exe);
+ let exe = std::env::var("CARGO_BIN_EXE_opencode-setup-system")
+ .expect("Cargo must expose the opencode setup-system binary to integration tests");
+ let problems = harness_runtime::probe::round_trip(std::path::Path::new(&exe));
assert!(
problems.is_empty(),
"the round trip disagreed with what this build documents:\n {}",
@@ -26,8 +29,9 @@ fn the_documented_round_trip_works_on_this_system() {
/// A target this provider was never pointed at is refused, never guessed at.
#[test]
fn a_target_that_is_not_one_is_refused_on_this_system() {
- let exe = std::path::Path::new(env!("CARGO_BIN_EXE_opencode-setup-system"));
- let problems = harness_runtime::probe::refuses_a_target_it_should(exe);
+ let exe = std::env::var("CARGO_BIN_EXE_opencode-setup-system")
+ .expect("Cargo must expose the opencode setup-system binary to integration tests");
+ let problems = harness_runtime::probe::refuses_a_target_it_should(std::path::Path::new(&exe));
assert!(problems.is_empty(), "{}", problems.join("\n "));
}
@@ -38,7 +42,8 @@ fn a_target_that_is_not_one_is_refused_on_this_system() {
/// test in one process cannot reach it, so this drives real ones.
#[test]
fn one_process_writes_this_target_at_a_time() {
- let exe = std::path::Path::new(env!("CARGO_BIN_EXE_opencode-setup-system"));
- let problems = harness_runtime::probe::one_writer_at_a_time(exe);
+ let exe = std::env::var("CARGO_BIN_EXE_opencode-setup-system")
+ .expect("Cargo must expose the opencode setup-system binary to integration tests");
+ let problems = harness_runtime::probe::one_writer_at_a_time(std::path::Path::new(&exe));
assert!(problems.is_empty(), "{}", problems.join("\n "));
}
diff --git a/install.ps1 b/install.ps1
index d69ef89..b92f9a6 100644
--- a/install.ps1
+++ b/install.ps1
@@ -7,7 +7,7 @@
# powershell -ExecutionPolicy Bypass -File install.ps1 -Version 0.1.0
[CmdletBinding()]
param(
- [string]$Version = "0.0.69",
+ [string]$Version = "0.0.71",
[string]$InstallDir = "$env:LOCALAPPDATA\Programs\opencode-setup-system"
)
$ErrorActionPreference = "Stop"
diff --git a/install.sh b/install.sh
index 9822926..c2fbbd2 100644
--- a/install.sh
+++ b/install.sh
@@ -14,7 +14,7 @@ set -eu
REPO="NDDev-OpenNetwork/opencode-setup-system"
BINARY="opencode-setup-system"
-VERSION="${1:-0.0.69}"
+VERSION="${1:-0.0.71}"
PREFIX="${OPENCODE_INSTALL_DIR:-$HOME/.local/bin}"
case "$(uname -s)" in
diff --git a/references/opencode-baseline.json b/references/opencode-baseline.json
index 10eaf3d..5780b58 100644
--- a/references/opencode-baseline.json
+++ b/references/opencode-baseline.json
@@ -8,9 +8,9 @@
"minimum_version_ref": "build/version.json:opencode_min"
},
"release": {
- "github_release": "https://github.com/anomalyco/opencode/releases/tag/v1.18.29",
- "github_release_api": "https://api.github.com/repos/anomalyco/opencode/releases/tags/v1.18.29",
- "tag": "v1.18.29",
+ "github_release": "https://github.com/anomalyco/opencode/releases/tag/v1.18.30",
+ "github_release_api": "https://api.github.com/repos/anomalyco/opencode/releases/tags/v1.18.30",
+ "tag": "v1.18.30",
"cli_signature": null,
"cli_signature_note": "Official CLI zip/tar assets expose GitHub release asset SHA-256 digests but no PGP/cosign signature was published for the CLI assets."
},
@@ -109,7 +109,7 @@
"OPENCODE_DISABLE_PROJECT_CONFIG",
"OPENCODE_DISABLE_SHARE"
],
- "verified_at": "2026-09-07T03:16:49+00:00",
+ "verified_at": "2026-09-13T15:18:31+00:00",
"native_surfaces": {
"verified_at": "2026-08-31",
"config_home": "~/.config/opencode",
@@ -294,44 +294,44 @@
"shape": "gzip-tar",
"platforms": {
"linux/arm64": {
- "url": "https://registry.npmjs.org/opencode-linux-arm64/-/opencode-linux-arm64-1.18.29.tgz",
- "bytes": 59952206,
- "sha256": "sha256:bbc655accf8263d44e5c668ef865520239e58bef515057bf8ecc27d006a6f28a",
+ "url": "https://registry.npmjs.org/opencode-linux-arm64/-/opencode-linux-arm64-1.18.30.tgz",
+ "bytes": 59985069,
+ "sha256": "sha256:1e20b66e76afbb7c1e5cd9be7515d2744cb4ea3476ff57add1f7e9ad6fb3a32d",
"member": "package/bin/opencode"
},
"linux/x86_64": {
- "url": "https://registry.npmjs.org/opencode-linux-x64/-/opencode-linux-x64-1.18.29.tgz",
- "bytes": 60170392,
- "sha256": "sha256:a2df564ba242759e3ee27cbd356da786243a3d3fd911cf5aa2c417521aef3042",
+ "url": "https://registry.npmjs.org/opencode-linux-x64/-/opencode-linux-x64-1.18.30.tgz",
+ "bytes": 60202013,
+ "sha256": "sha256:aa31a7e68ce5c73cba302c6a4f31c2e308398db125e49d3dbea32f61862fe6de",
"member": "package/bin/opencode"
},
"macos/arm64": {
- "url": "https://registry.npmjs.org/opencode-darwin-arm64/-/opencode-darwin-arm64-1.18.29.tgz",
- "bytes": 45944097,
- "sha256": "sha256:1fc08fee8b4984c1306c826b8c0e2c367fd9eeb4d4c3707469194e3fea047e72",
+ "url": "https://registry.npmjs.org/opencode-darwin-arm64/-/opencode-darwin-arm64-1.18.30.tgz",
+ "bytes": 45975576,
+ "sha256": "sha256:25b722fcdc8c46aebcb6501e1156dc1dc5a392492cc278c65b7775311674e7f8",
"member": "package/bin/opencode"
},
"macos/x86_64": {
- "url": "https://registry.npmjs.org/opencode-darwin-x64/-/opencode-darwin-x64-1.18.29.tgz",
- "bytes": 48120807,
- "sha256": "sha256:d9e2270b9040d7ce140df629773c68f15222c7a6c882f16921d36aa4c9200ae2",
+ "url": "https://registry.npmjs.org/opencode-darwin-x64/-/opencode-darwin-x64-1.18.30.tgz",
+ "bytes": 48153052,
+ "sha256": "sha256:d7119bd0adbacf86c1176f07b35d429909d1d702ca0c90dcd31415e66220f590",
"member": "package/bin/opencode"
},
"windows/arm64": {
- "url": "https://registry.npmjs.org/opencode-windows-arm64/-/opencode-windows-arm64-1.18.29.tgz",
- "bytes": 58399395,
- "sha256": "sha256:ad2f4a063a6d82578edc0b37078eff76fcb2a58f6439a33c34a50e1c795512b8",
+ "url": "https://registry.npmjs.org/opencode-windows-arm64/-/opencode-windows-arm64-1.18.30.tgz",
+ "bytes": 58430892,
+ "sha256": "sha256:d26f3759e7c17754e1d6c72020853ffb153c7bb0f6b7d75efdc48466f482c4d4",
"member": "package/bin/opencode.exe"
},
"windows/x86_64": {
- "url": "https://registry.npmjs.org/opencode-windows-x64/-/opencode-windows-x64-1.18.29.tgz",
- "bytes": 60086309,
- "sha256": "sha256:19eca6cdead9c67cce26fdc2db165980318edb7318c8c964dfc2ebffe03bb472",
+ "url": "https://registry.npmjs.org/opencode-windows-x64/-/opencode-windows-x64-1.18.30.tgz",
+ "bytes": 60117264,
+ "sha256": "sha256:1a5cc50f529cf359fbb6d1a1750c6ae521799f463d00a0215e6eff579a08b036",
"member": "package/bin/opencode.exe"
}
},
- "version": "1.18.29",
- "verified_at": "2026-09-07T03:16:49+00:00"
+ "version": "1.18.30",
+ "verified_at": "2026-09-13T15:18:31+00:00"
},
"setup_catalogue_digest": "sha256:637cc0372e587d7360dd8542554f59d8aa464af96475587cbecdaba7c36093ac",
"previous_software_artifacts": {
@@ -339,44 +339,44 @@
"shape": "gzip-tar",
"platforms": {
"linux/arm64": {
- "url": "https://registry.npmjs.org/opencode-linux-arm64/-/opencode-linux-arm64-1.18.27.tgz",
- "bytes": 59945385,
- "sha256": "sha256:83bf3812ecad71b3a463c5c0a7ceb0dba9db96964f3e7f8ba6bf30ca138287e8",
+ "url": "https://registry.npmjs.org/opencode-linux-arm64/-/opencode-linux-arm64-1.18.29.tgz",
+ "bytes": 59952206,
+ "sha256": "sha256:bbc655accf8263d44e5c668ef865520239e58bef515057bf8ecc27d006a6f28a",
"member": "package/bin/opencode"
},
"linux/x86_64": {
- "url": "https://registry.npmjs.org/opencode-linux-x64/-/opencode-linux-x64-1.18.27.tgz",
- "bytes": 60168253,
- "sha256": "sha256:0aba86ba404f52e57bd154ec3565cd3e86d344743bf32e3004bf7fdbd3363ac4",
+ "url": "https://registry.npmjs.org/opencode-linux-x64/-/opencode-linux-x64-1.18.29.tgz",
+ "bytes": 60170392,
+ "sha256": "sha256:a2df564ba242759e3ee27cbd356da786243a3d3fd911cf5aa2c417521aef3042",
"member": "package/bin/opencode"
},
"macos/arm64": {
- "url": "https://registry.npmjs.org/opencode-darwin-arm64/-/opencode-darwin-arm64-1.18.27.tgz",
- "bytes": 45940410,
- "sha256": "sha256:dba942c12128491b7c00f5d4b395bb8d36061f293b59db501ca9b0911a701680",
+ "url": "https://registry.npmjs.org/opencode-darwin-arm64/-/opencode-darwin-arm64-1.18.29.tgz",
+ "bytes": 45944097,
+ "sha256": "sha256:1fc08fee8b4984c1306c826b8c0e2c367fd9eeb4d4c3707469194e3fea047e72",
"member": "package/bin/opencode"
},
"macos/x86_64": {
- "url": "https://registry.npmjs.org/opencode-darwin-x64/-/opencode-darwin-x64-1.18.27.tgz",
- "bytes": 48115145,
- "sha256": "sha256:8e379467c2f911d5a6bb14a453b8f760e093daf8c5c6b9ee1da8f3515477e8f2",
+ "url": "https://registry.npmjs.org/opencode-darwin-x64/-/opencode-darwin-x64-1.18.29.tgz",
+ "bytes": 48120807,
+ "sha256": "sha256:d9e2270b9040d7ce140df629773c68f15222c7a6c882f16921d36aa4c9200ae2",
"member": "package/bin/opencode"
},
"windows/arm64": {
- "url": "https://registry.npmjs.org/opencode-windows-arm64/-/opencode-windows-arm64-1.18.27.tgz",
- "bytes": 58397893,
- "sha256": "sha256:3da5a83466c814922fc1472ef4eef1c37cae990a1cfe1530959c83d3f5b13cda",
+ "url": "https://registry.npmjs.org/opencode-windows-arm64/-/opencode-windows-arm64-1.18.29.tgz",
+ "bytes": 58399395,
+ "sha256": "sha256:ad2f4a063a6d82578edc0b37078eff76fcb2a58f6439a33c34a50e1c795512b8",
"member": "package/bin/opencode.exe"
},
"windows/x86_64": {
- "url": "https://registry.npmjs.org/opencode-windows-x64/-/opencode-windows-x64-1.18.27.tgz",
- "bytes": 60079608,
- "sha256": "sha256:d940ca3115e9a87107bb666c30c3efea88bcad1c2d34212c8deb4401a3054792",
+ "url": "https://registry.npmjs.org/opencode-windows-x64/-/opencode-windows-x64-1.18.29.tgz",
+ "bytes": 60086309,
+ "sha256": "sha256:19eca6cdead9c67cce26fdc2db165980318edb7318c8c964dfc2ebffe03bb472",
"member": "package/bin/opencode.exe"
}
},
- "version": "1.18.27",
- "verified_at": "2026-09-03T14:13:03+00:00"
+ "version": "1.18.29",
+ "verified_at": "2026-09-07T03:16:49+00:00"
},
"source_verified_runtime_flags_note": "All five read out of the 1.18.25 binary on 2026-08-31 -- the whole `OPENCODE_*` set is in its string table, and these are the five this provider has a reason to name. **Nothing in this repository read this block until now.** It is the same shape as the `windows` row that sat under `unsupported` for weeks while this provider installed Windows: a true-when-written list with no reader, which is the condition a stale fact needs. `native_declaration_names_the_switch_it_sets` now ties `updates_off_env` to this list, so the declaration and the measurement cannot drift apart in silence.",
"surface_presence": {