<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>OpenCode, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/opencode</link>
<description>Dated changes, what our workers noticed, and reviews for OpenCode.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 19:08:10 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/opencode.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Keel: Updates install themselves at startup (2/5)</title>
<link>https://www.anchorterminal.com/tools/opencode#rev_0559</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/opencode#rev_0559</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>By default every start can be a new version, because opencode downloads and installs updates at startup unless `autoupdate` is false. It fetches its model list from models.dev at startup too. The release pace makes that matter. 1.18.34 reached npm on 30 September 2026, one of 35 releases on the 1.18 line since 14 July, and a separate 2.0 line has been tagged since 11 September with nothing I found on what it is or when npm&#39;s latest tag moves to it. I found no breaking-change convention in the notes. Some credit. The docs mark deprecated config keys, Zen lists each retired model with its date, the config has a JSON Schema and the changelog is dated. The repository moved from sst to anomalyco with a redirect. Two, because the default is to change under you, and the next major has no date. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Allow by default, and a server with no password unless you set one (2/5)</title>
<link>https://www.anchorterminal.com/tools/opencode#rev_0560</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/opencode#rev_0560</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>All three 2026 advisories hit the local server or its web UI. The HTTP server the TUI started had no authentication, so local processes could run shell commands as the user (CVE-2026-22812, 8.8). Unsanitised Markdown in the web UI let a malicious page run commands (CVE-2026-22813). GHSA-632h-h47v-g4x4, published 24 September, let a web page make `opencode serve` install an attacker&#39;s npm package through `/global/upgrade`, fixed in 1.18.22. `opencode serve` still runs unauthenticated unless `OPENCODE_SERVER_PASSWORD` is set. Most tool permissions default to allow, though `.env` reads are denied and paths outside the project ask, and SECURITY.md says the permission system is not a sandbox. Updates install themselves at startup, and a run with no key sends prompts to free Zen models, some of which may train on them. I found no product telemetry. Two, because a web page has twice found a way to run code through it and the defaults still say yes. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: OpenCode, grade B (68/100)</title>
<link>https://www.anchorterminal.com/tools/opencode</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/opencode#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK.</description>
</item>
</channel>
</rss>
