Ports the base additions from pi-devbox v1.4.0 + v1.5.0 that opencode-devbox lacked (opencode-devbox already tracks pi-devbox for CLI-toolset parity, v2.6.0): - typst PDF engine for pandoc (v1.4.0) + the pandoc typst-template default-font patch (v1.5.0) so 'pandoc --pdf-engine=typst' works without -V mainfont. pandoc shipped since v2.6.0 as a front-end only (no PDF back-end). +xz-utils. Tracks latest; --build-arg TYPST_VERSION escape hatch. - Terminal support (v1.5.0): ncurses-term + kitty-terminfo + a compiled xterm-ghostty alias (tic -x, use=ghostty), so wezterm/alacritty/foot/ghostty/ kitty resolve TERM over SSH instead of degrading to a dumb fallback. - Readable Neovim colours (v1.5.0): system-wide /etc/xdg/nvim/sysinit.vim with termguicolors. - Host SSH reachability check at shell startup (v1.4.0): one-time probe in .bash_aliases warning (with fix steps + inline pubkey) when the Mac host is unreachable. The rest of the LAN stack was already present. - .claude/settings.local.json added to the gitignore_global seed (v1.5.0). - Repo hygiene (v1.5.0): LICENSE (MIT), THIRD_PARTY.md, hadolint CI job (pinned v2.14.0) + .hadolint.yaml, IDEAS.md backlog. Base-affecting (Dockerfile.base + rootfs) → base-<hash> advances, base rebuilds. smoke-test gains typst/PDF, terminfo, and nvim-tgc assertions. Validated: hadolint clean on both Dockerfiles, bash -n OK, base-hash guard OK, workflow guard OK. CHANGELOG v2.7.0.
2.9 KiB
Ideas & backlog
A living list of potential improvements for opencode-devbox that are not yet
scheduled. This is intentionally lightweight — a place to park ideas so they
aren't lost between sessions. When an item ships, describe it in
CHANGELOG.md and remove it from here.
Rough effort tags: 🟢 small · 🟡 medium · 🔴 large. Status: idea (unvetted) ·
planned (agreed, not started).
Supply-chain hardening
-
🟡
planned— Pin CI actions to commit SHAs. The workflows use floating major tags (actions/checkout@v4,docker/build-push-action@v7,docker/setup-buildx-action@v4,docker/login-action@v3,docker/setup-qemu-action@v3). This is inconsistent with the project's own philosophy of SHA-pinning content refs to defeat floating refs. Pin each action to a SHA with a trailing# vX.Y.Zcomment. Pairs naturally with the renovate item below to keep the pins fresh. -
🟡
planned— Vulnerability scanning in CI. No CVE scan runs on the published images today. Add atrivy image(or grype) job todocker-publish-split.ymlaftersmoke. Start non-blocking (report only), then tighten to fail onHIGH/CRITICALwith an available fix. -
🟢🟡
planned— Standardize build provenance → buildx SBOM + attestations. The image already carries hand-rolled provenance (OCI labels +build-manifest).docker/build-push-actioncan emit a standard SBOM and SLSA provenance attestation nearly for free (provenance: mode=max,sbom: true). Makes provenance machine-consumable and pairs well with the trivy item (scan the SBOM).
Dockerfile hardening
- 🟡
idea— Address hadolint DL4006 properly. Currently ignored in.hadolint.yaml. The clean fix isSHELL ["/bin/bash", "-o", "pipefail", "-c"]so pipedRUNs fail on the first non-zero stage. This changes the defaultRUNshell fromshtobashfor all subsequent layers, so it is base-affecting and needs a careful pass over existingRUNs before removing the ignore.
Developer experience
-
🟢
idea—Makefile/justfilefor local iteration. Reproducing a CI build locally means hand-assembling many--build-args. Thin targets (make build-base,make build-variant,make smoke,make lint) would make local testing painless and document the canonical invocations. -
🟡
idea— Dependency-update automation (renovate). With CI actions SHA-pinned (above), arenovate.jsonkeeps those pins — plus the pinned tool versions (ACTIONLINT_VERSION,HADOLINT_VERSION, gosu, etc.) — current via automated PRs. Requires a renovate runner against the Gitea instance.
Housekeeping
- 🟢
idea— Registry retention forbase-<hash>tags. The base-hash caching scheme accumulatesbase-<hash>tags over time. Confirm whether the registry prunes old ones, and add a retention/cleanup step if not.