anomalyco / anomalyco/opencode

Publish models.dev snapshot provenance for reproducible release builds

Open
#49,949 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
209k
Forks
27.5k
PR merge metrics
PR metrics pending

Description

Request

Please retain and publish the exact models.dev/api.json input used for each release build, or at minimum its SHA-256 and immutable provenance, as part of the release/build artifacts.

For the Windows v1.18.29 build:

  • workflow run: 33929368576
  • build job: 101204933839
  • checkout: 02a167e048d3bd7299225068d79e4fce5c830d67
  • snapshot load timestamp: 2026-09-04T23:26:28.3318016Z
  • unsigned Windows x64 payload SHA-256: 2f0e1255df9c077c5260ea47028e2c7d1854fd24b4b7bdeaa7002751c1b8cea6

Could a maintainer provide the exact modelsData body and SHA-256 used at that timestamp, or confirm that it was not retained?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by examining workflow run 33929368576, build job 101204933839, and checkout 02a167e048d3bd7299225068d79e4fce5c830d67 to locate how models.dev/api.json is loaded and how release artifacts are assembled. Done means each release retains or publishes the exact input, or its SHA-256 with immutable provenance, including the Windows v1.18.29 case.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
build-system, release
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.