Build in public
Changelog
Every published release of the Lunos CLI, newest first. Each links to its full notes on GitHub.
- A failed update now names the package manager’s error code and the path of npm’s log, instead of only an exit code.
- The licence notices include the full LGPL texts and the exact WebKit and tinycc sources that the Bun runtime links, with how to relink; the desktop app’s notices now cover the Bun runtime too.
- Sandboxed runs: lunos --sandbox runs Lunos and everything it starts in a Docker or Podman container, with your repository copied in rather than mounted, and a network policy enforced outside the container.
- Memory: export to a versioned bundle, import from bundles and other agents’ files with a preview, outdated facts and expiry, encryption at rest, and an optional shared Neo4j store.
- /settings shows every configuration option in one place; /restart restarts Lunos back into the same session; /connect is now /providers.
- Lunos checks for a new version on every start and shows it in the bottom-right corner; lunos update installs it.
- The default agent asks before commands that publish or reach outside the project.
- No request to upstream opencode’s services on any default path; the model catalogue comes from models.dev.
- Every package, release archive and offline bundle carries third-party licence notices; lunos licenses prints them.
- Offline install bundles, one per platform, for installing Lunos on a machine with no internet access. Each carries the CLI, the model catalogue, the SBOM, the signed SHA256SUMS, Sigstore’s trust root, and pinned ripgrep and cosign builds.
Security: Fixes a data-residency gap in earlier releases: an EU claim now holds only for that provider’s own API hosts. Any other endpoint is unknown, and an EU-only policy refuses it. If you run a self-hosted or proxied endpoint, declare where it runs with residency.endpoints.
- Offline mode: LUNOS_OFFLINE=1 turns off every outbound call Lunos makes on its own behalf, leaving only the endpoints you configured. lunos --version --verbose shows what is off.
- residency.endpoints declares the region of a self-hosted model or proxy, and an air-gapped deployment guide has a tested recipe for Ollama and vLLM.
- The desktop app ships again, as Lunos, updating only from Lunos releases and never offering a downgrade.
- A “Lunos” extension for VS Code, on Open VSX and the VS Code Marketplace, which starts the lunos CLI.
- Weekly upstream merges; lunos --version --verbose shows the upstream base and how far behind it is.
- The CLI no longer tells you to run opencode commands, and lunos uninstall no longer removes upstream opencode.
Security: The CLI is not affected. The desktop app once attached to this release installed as “OpenCode” and updated itself to upstream opencode, without Lunos’s residency enforcement or audit log. Its files have been removed; if you installed it, uninstall it. From v1.18.41 the desktop app ships as Lunos and updates only from Lunos releases.
Security: A residency policy judged a provider by its ID only, so an EU-tagged provider pointed at another host with baseURL still passed an EU-only policy. Fixed in v1.18.41; upgrade.
- Organisation policy: a managed.json in a location only administrators can write, or a macOS MDM profile, locks settings developers can’t change. No server is involved. lunos debug config --sources shows which layer set each key.
- One hash-chained audit log for tool runs, permission decisions, MCP and marketplace installs, policy refusals and upgrades, as well as model calls. It records no prompt or file contents. lunos audit verifies and exports it, and it can forward events to syslog.
- Reviewed marketplace entries: a verified entry installs only the version that was reviewed and, for npm plugins, only if the registry’s integrity hash matches. A community entry needs --allow-unreviewed, which an organisation’s policy can forbid.
- SHA256SUMS and the SBOM are signed with Sigstore, and the SBOM now carries licence data. Binaries are still not OS code-signed.
- Long-term memory, off by default. When on, it asks you before keeping each fact by default, and lunos memory and a TUI browser let you list, search, forget and export them. Needs uv and Python 3.10–3.13.
- A high-contrast theme and a reduced_motion setting for the TUI, and status that no longer relies on colour alone.
- One Esc no longer dismisses an agent’s question: press it twice, undo with ctrl+z, or answer it later.
- Fixes: a second marketplace under a name already in use is refused; a project path typed in the wrong case is no longer treated as outside the project; the upgrade hint and npm auto-upgrade pass --allow-scripts=lunos-ai; the built-in marketplace matches what lunos.tech publishes.
Security: The CLI is not affected. The desktop app once attached to this release installed as “OpenCode” and updated itself to upstream opencode, without Lunos’s residency enforcement or audit log. Its files have been removed; if you installed it, uninstall it. From v1.18.41 the desktop app ships as Lunos and updates only from Lunos releases.
Security: A residency policy judged a provider by its ID only, so an EU-tagged provider pointed at another host with baseURL still passed an EU-only policy. Fixed in v1.18.41; upgrade.
- Data-residency policy enforced for sessions, with every outbound model call written to the egress audit log. Earlier releases did not enforce it for sessions.
- Session sharing is off by default, and share uploads fall under the residency policy.
- Background subagents as a documented setting, with /tasks to watch and cancel them, and a configurable model per subagent.
- Skills can restrict the agent to named tools with allowed-tools, and Claude Code subagents in .claude/agents work unchanged.
- /artifacts finds and opens plans, research notes and dev-cycle records.
- lunos-community is a built-in marketplace, so install commands copied from lunos.tech work on a fresh install.
- Updates track Lunos rather than upstream opencode, and are announced rather than installed silently; /upgrade installs one.
- One version label everywhere, npm packages published with Lunos metadata, and a checked-in reference deployment config.
Security: Fixes the local file disclosure in v1.18.37: marketplace entries carrying config substitution tokens are now refused.
Security: The CLI is not affected. The desktop app once attached to this release installed as “OpenCode” and updated itself to upstream opencode, without Lunos’s residency enforcement or audit log. Its files have been removed; if you installed it, uninstall it. From v1.18.41 the desktop app ships as Lunos and updates only from Lunos releases.
- The marketplace carries all four kinds of extension: plugins, skills, hooks and MCP servers.
- Search and install every kind from the CLI, or browse them in the TUI’s tabbed Discover view.
- Community plugins now install from npm; eleven entries that could not be installed were dropped.
Security: Affected by a local file disclosure when installing MCP servers by name from a third-party marketplace. Fixed in v1.18.38; upgrade.
Security: The CLI is not affected. The desktop app once attached to this release installed as “OpenCode” and updated itself to upstream opencode, without Lunos’s residency enforcement or audit log. Its files have been removed; if you installed it, uninstall it. From v1.18.41 the desktop app ships as Lunos and updates only from Lunos releases.
- Install MCP servers by name from a marketplace.
- Config-driven lifecycle hooks, and research mode.
- Provider jurisdiction metadata and a data-residency policy with an egress audit log. Enforced for sessions only from v1.18.39.
- A self-hosted deployment guide for procurement reviewers, a release SBOM and a vulnerability-handling policy.
Security: The CLI is not affected. The desktop app once attached to this release installed as “OpenCode” and updated itself to upstream opencode, without Lunos’s residency enforcement or audit log. Its files have been removed; if you installed it, uninstall it. From v1.18.41 the desktop app ships as Lunos and updates only from Lunos releases.
- Release versions are now computed from lunos-ai rather than upstream opencode.
- The first release under the Lunos name: lunos-ai and its lunos-<os>-<arch> platform packages on npm, and lunos-* release assets.
- Rebranded terminal and desktop strings.