anomalyco / anomalyco/opencode
[FEATURE]: Support post-quantum TLS (X25519MLKEM768) for provider API connections
@rekram1-node is already working on this.
Since Aug 3, 2026.
- Dominant language
- TypeScript
- Stars
- 209k
- Forks
- 27.5k
- PR merge metrics
- PR metrics pending
Description
Feature hasn't been suggested before.
- I have verified this feature I'm about to request hasn't been suggested before.
Describe the enhancement you want to request
When using OpenCode Desktop to connect to API providers (e.g. Fireworks.ai), the TLS Client Hello currently advertises only traditional key exchange groups.
Using Wireshark, I observed:
supported_groups:
x25519
secp256r1
secp384r1
key_share:
x25519
There is no X25519MLKEM768 (hybrid ML-KEM) offered.
This means provider connections are not protected against the "harvest now, decrypt later" threat if the server supports post-quantum TLS.
Would it be possible for OpenCode Desktop to support hybrid post-quantum TLS for outbound provider connections?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.