anomalyco / anomalyco/opencode

[FEATURE]: Support post-quantum TLS (X25519MLKEM768) for provider API connections

Open
#40,328 0 comments 0 reactions 1 assignee View on GitHub

@rekram1-node is already working on this.

Since Aug 3, 2026.

Dominant language
TypeScript
Stars
209k
Forks
27.5k
PR merge metrics
PR metrics pending

Description

Feature hasn't been suggested before.
  • I have verified this feature I'm about to request hasn't been suggested before.
Describe the enhancement you want to request

When using OpenCode Desktop to connect to API providers (e.g. Fireworks.ai), the TLS Client Hello currently advertises only traditional key exchange groups.

Using Wireshark, I observed:

supported_groups:
x25519
secp256r1
secp384r1

key_share:
x25519

There is no X25519MLKEM768 (hybrid ML-KEM) offered.

This means provider connections are not protected against the "harvest now, decrypt later" threat if the server supports post-quantum TLS.

Would it be possible for OpenCode Desktop to support hybrid post-quantum TLS for outbound provider connections?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.