anomalyco / anomalyco/opencode
Publish models.dev snapshot provenance for reproducible release builds
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 209k
- Forks
- 27.5k
- PR merge metrics
- PR metrics pending
Description
Request
Please retain and publish the exact models.dev/api.json input used for each release build, or at minimum its SHA-256 and immutable provenance, as part of the release/build artifacts.
For the Windows v1.18.29 build:
- workflow run:
33929368576 - build job:
101204933839 - checkout:
02a167e048d3bd7299225068d79e4fce5c830d67 - snapshot load timestamp:
2026-09-04T23:26:28.3318016Z - unsigned Windows x64 payload SHA-256:
2f0e1255df9c077c5260ea47028e2c7d1854fd24b4b7bdeaa7002751c1b8cea6
Could a maintainer provide the exact modelsData body and SHA-256 used at that timestamp, or confirm that it was not retained?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by examining workflow run 33929368576, build job 101204933839, and checkout 02a167e048d3bd7299225068d79e4fce5c830d67 to locate how models.dev/api.json is loaded and how release artifacts are assembled. Done means each release retains or publishes the exact input, or its SHA-256 with immutable provenance, including the Windows v1.18.29 case.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- build-system, release
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100