Releases: chriswritescode-dev/opencode-forge
Release list
v0.9.1
Highlights
- Live session view in the dashboard: loop sessions stream in real time over SSE, with the live model summary rendered at primary text strength
- Change loop models from the dashboard: pick the execution and auditor models (and variants) per loop and apply them; changes persist to the loop configuration
- Plan amendment diffs: amendments are diffed and rendered in the dashboard
- Sandbox image pins the pnpm store via
PNPM_CONFIG_STORE_DIR(pnpm 11 ignoresnpm_config_*), so the store no longer lands inside the project directory and gets committed by loop teardown - Dashboard hardening: guarded loop POST routes, released SSE streams, stricter loopback host checks
What's Changed
- feat(dashboard): live session view and plan amendment diffs (#96)
- fix(dashboard): guard loop POST routes and release SSE streams
- fix(sandbox): pin pnpm store via PNPM_CONFIG_STORE_DIR
- fix(dashboard): harden loopback host checks and live view interactions
- chore: bump version to 0.9.1
- fix(dashboard): render live model summary at primary text strength
v0.9.0
Highlights
- msb sandbox driver replaces the sbx runtime: in-VM Docker, opt-in egress, and a plugin-dir installer (refactor(sandbox): replace sbx runtime with msb driver, #95)
- Sandbox images mount
allowExternalDirectoriesread-only and shipbuild-essential - Passwordless sudo for runtime package installs inside the sandbox
- Auditor persisted findings now require implementation-ready detailed solutions
- Indeterminate sandbox template checks are deferred and treated as non-fatal; keep-alive sentinel execs removed
What's Changed
- refactor(sandbox): replace sbx runtime with msb driver (#95)
- feat(sandbox): mount allowExternalDirectories read-only and ship build-essential
- feat(sandbox): grant passwordless sudo for runtime package installs
- feat(auditor): require implementation-ready detailed solutions in persisted findings
- fix(sandbox): defer indeterminate template checks
- fix(sandbox): remove keep-alive sentinel execs
- fix(sandbox): treat indeterminate availability probes as non-fatal
v0.8.8
What changed
- feat(sandbox): mount git metadata read-write and disable git hooks
- chore(prompts): keep code agent from calling destructive forge tools proactively
Sandboxed loops now mount the worktree and its git metadata directory read-write, so in-sandbox git (status, log, diff, commits) resolves against the real repository. Two guards keep that from becoming a path out of the sandbox: the git hooks directory is re-mounted read-only, and every git command Forge runs on the host disables core.hooksPath, so a sandboxed agent cannot plant a hook that the user's own git would execute.
The code-agent prompt now forbids calling execute-goal, execute-plan, launch-group, or loop-cancel proactively.
Full Changelog: v0.8.7...v0.8.8
v0.8.7
What's Changed
- chore(agents): rework auditor/architect prompts and drop impact-reviewer subagent (#93)
The dedicated impact-reviewer subagent is removed and whole-change impact analysis is folded directly into the auditor-loop audit workflow. Auditor and architect agent prompts are tightened around the minimal-design ladder and single-source-of-truth planning:
- Auditor-loop final audit rules now require a direct "Whole-Change Impact Analysis" covering duplication, parallel implementations, missed callers/companion updates, and unreachable/superseded code — no separate impact agent.
- The auditor findings lifecycle is simplified (read → manifest → reconcile → inspect → validate → persist) with
review-writefields documented. - Architect research/design steps mandate reusing existing code, the standard library, native platforms, or installed dependencies before new code; plans must name a single owner for shared behavior, prohibit parallel implementations, and demand explicit caller migrations and removal of obsolete code paths.
Full Changelog: v0.8.6...v0.8.7
v0.8.6
What's Changed
- feat(sandbox): keep active sandboxes warm with sentinel keep-alive exec (#91)
Active sandboxed loops now stay warm through a sentinel keep-alive exec, fixing SBX containers going stale. The forge scratch temp directory (/tmp/oc-forge / loop.tmpDir) is dropped in favor of opencode's advertised temp directory, which is now granted to loop sessions and bind-mounted at the same host path in both modes.
Also bundled in this release:
- The architect agent concludes after the plan summary with no auto-execution;
execute-plandefaults to loop mode without a mode picker. - Project docs refreshed and pnpm installed via npm in the sandbox image.
Full Changelog: v0.8.5...v0.8.6
v0.8.5
What's Changed
- refactor(sandbox): drive sandbox context note from unified resolver (#90)
The sandbox context note that tells sessions their bash tool calls run inside a container is now sourced from the single shared SandboxContext in src/sandbox/context.ts instead of being appended to loop prompt bodies. The unified sandbox message hook (src/hooks/sandbox-message.ts) injects it into every session whose tool calls are routed into a container — sandbox loops, their Task-tool subagents, and sessions with the host sandbox toggled on — so subagents that never see a loop prompt body still receive the container context from one point of truth.
v0.8.4
What's Changed
- feat(agents): add read-only impact-reviewer subagent for audit consolidation checks
The loop auditor now launches an impact-reviewer subagent during section and final audits to scan the scoped change set for duplication of existing helpers, parallel implementations, missed callers of changed shared code, and dead code. It is read-only (no edit, write, review-write, plan-adjust, or task tools), hidden from the agent picker, and returns a text report of blocking/advisory findings that the auditor verifies before writing them as review findings.
v0.8.3
What's Changed
- feat(sandbox): make Browser Control an opt-in sandbox image feature (#89)
Chromium and Browser Control are now an opt-in feature of the bundled sandbox image instead of being baked into every build. The Dockerfile gains an INSTALL_BROWSER_CONTROL build arg, the plugin exposes sandbox.imageFeatures.browserControl config that is threaded through the build dialog and missing-template hints, and the docs describe the opt-in build/load flow.
v0.8.2
What's Changed
- feat(dashboard): redesign dashboard app shell and loop rendering (#88)
- feat(loop): gate supervision to the owning worktree instance
- feat: make plan tools file-like and fix plan-launch TUI workspace navigation (#87)
The dashboard app shell and loop detail views were redesigned around a unified visual language: 1-based section numbering throughout, a shared legend/cell component system, phase colors resolved through a --phase-color token, findings severity carried on the Findings metric cell, and responsive app-bar fixes. Loop supervision is now bound to the plugin instance whose directory matches the loop's worktree, so the watchdog and the session-abort handler never act on loops another instance is observing. Plan tooling was polished as well: plan-read gained a count argument for recent listings and a truncation notice with the next offset to continue reading, plan-edit reports only the sections it touched, and plan-launch now forwards the created session's workspace to the TUI.
v0.8.1
What's Changed
- feat(loop): route wedged auditor sessions through the fallback chain
A watchdog-detected wedged (busy-stalled, no streamed content) auditing session is now aborted and re-dispatched on the next configured fallback auditor model instead of receiving a generic continue nudge. The fallback advancement loop was extracted into a shared advanceAuditorFallback helper used by both the provider-limit path and the watchdog, so all detection paths advance the fallback chain exactly once per failure.