Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
116 commits
Select commit Hold shift + click to select a range
8a12a0c
docs: add public community and release guides
Obed0101 Jun 13, 2026
3af9fbc
ci: publish release supply-chain hardening
Obed0101 Jun 13, 2026
33cc1b2
ci: fix release workflow dispatch
Obed0101 Jun 13, 2026
3309898
ci: harden release dry runs
Obed0101 Jun 13, 2026
1c66371
ci: unblock release asset dry run (#60)
Obed0101 Jun 13, 2026
9433bee
ci: avoid dynamic installs during release build (#61)
Obed0101 Jun 13, 2026
339ea93
ci: stamp release binaries with version (#62)
Obed0101 Jun 13, 2026
6b03f29
fix(tui): clarify agent mode controls
Obed0101 Jun 13, 2026
9d2dfd0
feat(tui): add context usage modal
Obed0101 Jun 13, 2026
e99a22f
ci: update actions for node24 runners (#67)
Obed0101 Jun 13, 2026
ef3a579
docs: expand MendCode customization guide (#70)
Obed0101 Jun 13, 2026
0ab2e67
docs: show mascot only in README header (#72)
Obed0101 Jun 13, 2026
b55cfec
docs: remove README mascot header (#73)
Obed0101 Jun 13, 2026
72fde74
chore: sync dev into main (#78)
Obed0101 Jun 13, 2026
cba22ce
chore: promote dev for v0.1.3 (#84)
Obed0101 Jun 13, 2026
8babbb4
chore: promote dev for v0.1.4 (#87)
Obed0101 Jun 13, 2026
3c3e1e4
chore: promote dev for v0.1.5 (#90)
Obed0101 Jun 13, 2026
648d761
fix: release v0.1.6 memory injection (#91) (#93)
Obed0101 Jun 14, 2026
64752db
Promote Usage Insights dashboard to main (#97)
Obed0101 Jun 14, 2026
5220320
fix: release v0.1.7 setup memory UX (#98) (#99)
Obed0101 Jun 14, 2026
5d9dadc
fix: complete v0.1.7 memory and docs (#100) (#102)
Obed0101 Jun 14, 2026
1273284
fix: release v0.1.8 stats cache and installer
Obed0101 Jun 14, 2026
a5d6d82
chore: promote dev for v0.1.9 (#109)
Obed0101 Jun 14, 2026
41c1899
chore: promote v0.1.9 changelog to main (#111)
Obed0101 Jun 14, 2026
e793e85
chore: promote v0.1.10 to main (#114)
Obed0101 Jun 15, 2026
da25998
chore: promote v0.1.11 to main (#117)
Obed0101 Jun 15, 2026
7dbee28
chore: promote v0.1.12 to main (#120)
Obed0101 Jun 16, 2026
865f5e5
chore: promote v0.1.12 release dependency gates (#124)
Obed0101 Jun 16, 2026
4317043
chore: promote v0.1.13 to main
Obed0101 Jun 16, 2026
fd97798
fix: update hono for v0.1.13 release
Obed0101 Jun 16, 2026
42bf915
chore: promote v0.1.14 to main (#134)
Obed0101 Jun 17, 2026
a7424a8
fix: update protobufjs for v0.1.14 release (#137)
Obed0101 Jun 17, 2026
e8a0530
release: promote v0.1.15
Obed0101 Jun 20, 2026
5acdd8b
fix: refresh release dependency gates
Obed0101 Jun 20, 2026
785d02d
fix: use final OSV release dependency versions
Obed0101 Jun 20, 2026
6122ac2
fix: allow urgent OSV release versions through age gate (#145)
Obed0101 Jun 20, 2026
8e22535
Promote v0.1.15 docs to main (#148)
Obed0101 Jun 20, 2026
3d53884
docs: promote memory center guidance (#151)
Obed0101 Jun 20, 2026
3d96f5d
fix: release dream schedule recovery (#154)
Obed0101 Jun 20, 2026
21819a9
docs: update website domain (#157)
Obed0101 Jun 20, 2026
8aa8b8f
docs: remove personal release examples (#159)
Obed0101 Jun 20, 2026
8e354be
release: promote v0.1.17
Obed0101 Jun 23, 2026
588ad39
docs: add workflow screenshots (#163) (#164)
Obed0101 Jun 23, 2026
d7ae0b0
chore: promote dev for v0.1.18 (#167)
Obed0101 Jun 23, 2026
6e482fe
fix: keep loops cursor out of detail rows (#168) (#170)
Obed0101 Jun 24, 2026
fb5eab7
fix: remove loops dashboard cursor sink (#171) (#172)
Obed0101 Jun 24, 2026
efcf5f3
release: promote v0.1.18
Obed0101 Jun 24, 2026
1329d2a
release: promote v0.1.19 (#178)
Obed0101 Jun 26, 2026
c8403de
chore: promote dev for v0.1.20 (#183)
Obed0101 Jul 27, 2026
a119918
fix: harden release dependencies and binary patches (#184) (#186)
Obed0101 Jul 28, 2026
60e33cd
fix: update release dependency pins (#187) (#188)
Obed0101 Jul 28, 2026
21d2c2b
docs: sync v0.1.20 changelog metadata (#189) (#190)
Obed0101 Jul 28, 2026
a46b334
promote: v0.1.20 dev tree to main
Obed0101 Jul 28, 2026
7c6a038
fix: prevent hidden prompt leakage during questions (#196)
Obed0101 Jul 28, 2026
53b32cd
docs: refresh main README screenshots
Obed0101 Jul 29, 2026
0778597
docs: remove duplicate README screenshot
Obed0101 Jul 29, 2026
88956d2
promote: v0.1.21 to main
Obed0101 Jul 30, 2026
317f80c
fix(release): use supported Intel macOS runner
Obed0101 Jul 30, 2026
b5d74e8
fix(release): publish Darwin x64 baseline asset
Obed0101 Jul 30, 2026
d29c840
promote: v0.1.22 update notification fix (#207)
Obed0101 Jul 30, 2026
b1b332a
promote: v0.1.23 to main (#212)
Obed0101 Jul 31, 2026
166d705
promote: v0.1.23 release smoke fix (#214)
Obed0101 Jul 31, 2026
185c7e4
promote: release smoke fix into main (#217)
Obed0101 Jul 31, 2026
a436006
promote v0.1.23 to main (#220)
Obed0101 Aug 1, 2026
1b1b999
fix: repair compacted session cancellation state (#221) (#223)
Obed0101 Aug 1, 2026
8a8354f
fix(upgrade): make in-app updates transport-independent (#224) (#225)
Obed0101 Aug 2, 2026
ee7f2d2
release: promote v0.1.27 TUI reliability update (#228)
Obed0101 Aug 2, 2026
36a696c
release: promote v0.1.28 durable workflows (#231)
Obed0101 Aug 4, 2026
c78a4f7
fix: patch vulnerable release dependencies (#232) (#234)
Obed0101 Aug 4, 2026
1110f4a
fix(installer): skip setup prompt without TTY (#235) (#236)
Obed0101 Aug 4, 2026
e96615d
release: promote v0.1.29 to main
Obed0101 Aug 4, 2026
5bd5006
release: promote v0.1.30 to main (#243)
Obed0101 Aug 5, 2026
5eb6780
fix(release): build Windows assets on native architectures (#245)
Obed0101 Aug 5, 2026
f3b8c93
release: promote v0.1.30 reliability fixes (#248)
Obed0101 Aug 5, 2026
1be15e8
fix(release): finalize v0.1.30 TUI recovery and notes (#249) (#251)
Obed0101 Aug 5, 2026
c8e60d1
release: prepare MendCode v0.1.30 (#256)
Obed0101 Aug 18, 2026
3a89537
chore(deps): bump dompurify (#253)
dependabot[bot] Aug 18, 2026
86a4b0e
fix(deps): synchronize DOMPurify lockfile (#259)
Obed0101 Aug 18, 2026
4adbf24
fix(deps): patch release dependency vulnerabilities (#261)
Obed0101 Aug 18, 2026
a057d23
fix: stabilize Mermaid interaction and test isolation (#264) (#265)
Obed0101 Aug 18, 2026
f61cb26
release: prepare v0.1.31 Loop and Workflow verification (#266) (#268)
Obed0101 Aug 19, 2026
e02bcf4
release: promote v0.1.32 to main (#270)
Obed0101 Aug 20, 2026
2b026ea
fix: ship v0.1.33 reliability hotfix (#271) (#273)
Obed0101 Aug 20, 2026
0c960a0
release: prepare v0.1.34 (#276)
Obed0101 Aug 21, 2026
ed971fa
fix: preserve v prefix in release names (#278)
Obed0101 Aug 21, 2026
995fcfe
release: promote v0.1.35 to main (#280)
Obed0101 Aug 22, 2026
7251d54
release: promote v0.1.36 (#283)
Obed0101 Aug 23, 2026
f9a7c83
release: promote v0.1.37
Obed0101 Aug 24, 2026
8740155
fix: make v0.1.37 release buildable
Obed0101 Aug 24, 2026
23c13f7
release: promote v0.1.38 to main (#289)
Obed0101 Aug 25, 2026
5db2486
promote: docs navigation and Mermaid reference
Obed0101 Aug 25, 2026
1ef29f3
release: prepare v0.1.39
Obed0101 Aug 26, 2026
9b2222e
release: promote v0.1.39 to main
Obed0101 Aug 26, 2026
e984dd1
release: promote v0.1.40 to main (#298)
Obed0101 Aug 26, 2026
7ad08ea
release: promote v0.1.41 to main (#300)
Obed0101 Aug 29, 2026
9f918cd
release: promote v0.1.41 security fix to main (#302)
Obed0101 Aug 29, 2026
19cb48d
fix: harden session delivery and runtime reliability
Obed0101 Sep 3, 2026
70520de
Merge remote-tracking branch 'origin/dev' into dev
Obed0101 Sep 3, 2026
b564699
fix: preserve queued prompt delivery during interrupt
Obed0101 Sep 3, 2026
56c9fe0
release: promote v0.1.42 to main (#307)
Obed0101 Sep 3, 2026
c117f18
release: promote v0.1.42 security fix to main (#309)
Obed0101 Sep 3, 2026
8fe7e00
release: promote v0.1.42 reproducible install fix (#312)
Obed0101 Sep 3, 2026
9950607
fix: promote release attestation docs
Obed0101 Sep 4, 2026
c62b3c0
release: promote v0.1.43 to main (#317)
Obed0101 Sep 4, 2026
f667706
fix: preserve attestation loop in release notes (#318)
Obed0101 Sep 4, 2026
234d4b6
Release v0.1.44 stable startup recovery (#321)
Obed0101 Sep 5, 2026
cb14ba5
ci: enable immutable prerelease publication
Obed0101 Sep 9, 2026
9d29309
.github/workflows: Migrate workflows to Blacksmith runners (#335)
blacksmith-sh[bot] Sep 14, 2026
262c32a
feat: harden memory, workflows, and session recovery
Obed0101 Sep 14, 2026
c9895a6
feat: integrate beta reliability and session fixes
Obed0101 Sep 14, 2026
f31c9da
merge: synchronize latest main release history
Obed0101 Sep 14, 2026
a61263b
docs: prepare v0.1.44-beta.14 notes
Obed0101 Sep 14, 2026
f178dc0
ci: preserve current release runners
Obed0101 Sep 14, 2026
d0f942d
fix: keep attached CLI runs client-only
Obed0101 Sep 14, 2026
5c204c1
fix: preserve reasoning state across cache integration
Obed0101 Sep 14, 2026
f1b27ff
fix(release): run pnpm with supported Node
Obed0101 Sep 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ concurrency:
jobs:
analyze:
name: Analyze JavaScript and TypeScript
runs-on: ubuntu-latest
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 20
steps:
- name: Checkout repository
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ concurrency:
jobs:
dependency-review:
name: Dependency review
runs-on: ubuntu-latest
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 10
steps:
- name: Checkout repository
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/prerelease.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ concurrency:

jobs:
select:
runs-on: ubuntu-latest
runs-on: blacksmith-4vcpu-ubuntu-2404
outputs:
changed: ${{ steps.candidate.outputs.changed }}
version: ${{ steps.candidate.outputs.version }}
Expand Down
27 changes: 21 additions & 6 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ concurrency:
jobs:
build-release:
name: Build Linux and Windows baseline release assets
runs-on: ubuntu-latest
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 60
permissions:
attestations: write
Expand Down Expand Up @@ -125,6 +125,11 @@ jobs:
ghcr.io/google/osv-scanner:v2.3.8@sha256:64e86bec6df2466feea5137fc7c78fb3b7c21ec077f014d7130f64810e50676b \
scan --config /src/.github/osv-release.toml --lockfile /src/src/mendcode/pnpm-lock.yaml

- name: Setup Node
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: "24"

- name: Setup pnpm
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1
with:
Expand Down Expand Up @@ -159,7 +164,7 @@ jobs:
bun run --cwd packages/opencode typecheck
cd packages/opencode
for test_file in test/installation/*.test.ts test/cli/upgrade-channel.test.ts test/cli/tui/shared-server.test.ts test/cli/tui/thread.test.ts; do
bash -c 'export MENDCODE_DB=":memory:"; exec bun test --timeout 30000 "$@"' bash "$test_file"
bash -c 'export MENDCODE_DB="${TMPDIR:-/tmp}/opencode-test-data-$$/share/release.db"; exec bun test --timeout 30000 "$@"' bash "$test_file"
done

- name: Upload release artifacts to workflow
Expand All @@ -180,7 +185,7 @@ jobs:
fail-fast: false
matrix:
include:
- runner: windows-latest
- runner: blacksmith-4vcpu-windows-2025
arch: x64
build_args: --single
expected_executables: 1
Expand All @@ -204,6 +209,11 @@ jobs:
persist-credentials: false
ref: ${{ inputs.source_sha }}

- name: Setup Node
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: "24"

- name: Setup pnpm
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1
with:
Expand Down Expand Up @@ -277,7 +287,7 @@ jobs:
fail-fast: false
matrix:
include:
- runner: macos-14
- runner: blacksmith-6vcpu-macos-15
arch: arm64
- runner: macos-15-intel
arch: x64
Expand All @@ -298,6 +308,11 @@ jobs:
persist-credentials: false
ref: ${{ inputs.source_sha }}

- name: Setup Node
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: "24"

- name: Setup pnpm
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1
with:
Expand Down Expand Up @@ -349,7 +364,7 @@ jobs:
name: Assemble and attest release assets
if: ${{ always() && needs.build-release.result == 'success' && needs.build-windows.result == 'success' && needs.build-darwin.result == 'success' }}
needs: [build-release, build-windows, build-darwin]
runs-on: ubuntu-latest
runs-on: blacksmith-4vcpu-ubuntu-2404
permissions:
attestations: write
contents: read
Expand Down Expand Up @@ -440,7 +455,7 @@ jobs:
name: Create draft GitHub Release
if: ${{ inputs.dry_run == false }}
needs: assemble-release
runs-on: ubuntu-latest
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 10
environment: release
permissions:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/runtime-recovery.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,4 +71,4 @@ jobs:
test/server/usage.test.ts test/server/release-channel.test.ts test/server/upgrade-progress.test.ts; do
run_test "$test_file"
done
run_test test/session/prompt.test.ts --test-name-pattern "continuity wakes the existing executor"
run_test test/session/prompt.test.ts --test-name-pattern "wakes an async parent by default for a background task"
4 changes: 2 additions & 2 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ concurrency:
jobs:
repository-guards:
name: Repository guards
runs-on: ubuntu-latest
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 10
steps:
- name: Checkout repository
Expand Down Expand Up @@ -139,7 +139,7 @@ jobs:

deep-scanners:
name: Deep security scanners
runs-on: ubuntu-latest
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 30
permissions:
contents: read
Expand Down
38 changes: 38 additions & 0 deletions .github/workflows/stable-startup.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
name: Stable startup regression
on:
pull_request:
paths: ["src/mendcode/**", ".github/workflows/stable-startup.yml"]
workflow_dispatch:
permissions:
contents: read
jobs:
startup:
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 15
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10
with:
persist-credentials: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: "24"
- uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1
with:
version: 11.0.9
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6
with:
bun-version-file: src/mendcode/package.json
- name: Prepare frozen dependencies and test catalog
working-directory: src/mendcode
run: |
pnpm --pm-on-fail=ignore install --frozen-lockfile --ignore-scripts
cd packages/opencode
bun run script/fix-node-pty.ts
MODELS_DEV_API_JSON="$PWD/test/tool/fixtures/models-api.json" bun run script/generate.ts
- name: Typecheck and isolated startup regressions
working-directory: src/mendcode/packages/opencode
run: |
bun run typecheck
for test_file in test/installation/backend-startup.test.ts test/storage/compatibility.test.ts test/cli/tui/thread.test.ts test/plugin/auth-override.test.ts; do
bash -c 'export MENDCODE_DB="${TMPDIR:-/tmp}/opencode-test-data-$$/share/contracts.db"; exec bun test --timeout 30000 "$@"' bash "$test_file"
done
32 changes: 32 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,37 @@
# Changelog

## 0.1.44-beta.14 - 2026-09-14

### Added

- Run automatic memory learning through a persisted, bounded background worker so
completed chat turns no longer wait for the memory provider; expose extraction
outcomes, Dream maintenance, write policy, and Markdown sharing controls.
- Add recoverable memory maintenance and revision-aware Markdown import/export
with explicit opt-in scopes, validation, and visible conflicts.

### Changed

- Keep GPT-6 Astra compatible with the current Codex Responses Lite protocol and
surface normalized multi-provider cache-hit usage to prompt status integrations.
- Make the Minimal prompt preset truly compact and retain the final Arcade/Snake
board after compaction without leaving timers or input focus active.

### Fixed

- Preserve queued prompt delivery and terminal cancellation while compaction,
background extraction, reconnect recovery, or long-running shell work settles.
- Keep provider startup usable when metadata loading fails or a valid catalog is
empty, and report configuration errors without trapping Home in startup state.
- Carry forward database compatibility checks and Blacksmith-backed security and
startup regression workflows from the latest public branch.

### Tests

- Add focused regressions for memory workers, Dream and Markdown sharing, provider
startup, Astra OAuth compatibility, cache reporting, compact prompt layout,
final compaction rendering, queue delivery, and repeated cancellation.

## 0.1.44-beta.7 - 2026-09-10

### Added
Expand Down
84 changes: 59 additions & 25 deletions docs/cli-setup-configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -166,10 +166,15 @@ project or global MendCode config. The controls affect cache keys and provider
cache annotations that MendCode sends with a request; they never delete a
provider's remote cache and they never schedule refresh or keepalive requests.

This policy is separate from MendCode's local runtime/cache directories and
from the Usage Insights statistics cache. It controls request shaping and
provider annotations; it does not configure local cache size, eviction, or
statistics retention.

The public CLI is:

```bash
mendcode cache status [--format text|json|--json]
mendcode cache status [--format text|json] [--json]
mendcode cache enable [--global] [--provider <id>] [--model <id>] [--session <id>] [--project-path <path>]
mendcode cache disable [--global] [--provider <id>] [--model <id>] [--session <id>] [--project-path <path>]
```
Expand All @@ -178,13 +183,16 @@ mendcode cache disable [--global] [--provider <id>] [--model <id>] [--session <i
`--global`, mutation commands update the active project's config. With
`--global`, they update the global config. `--project-path` is only valid with
`--global` and writes an exact normalized project-path override. A model target
requires `--provider`; provider, model, session, and project targets cannot be
combined.
requires `--provider`; `--provider` and `--model` are valid together and target
one provider model. Session and project targets cannot be combined with a
provider or model target, and a project target cannot be combined with a
session target.

### Configuration

The `cache` block is optional. If it is absent, MendCode preserves existing
provider behavior (`legacy` effective mode).
The `cache` block is optional. If it is absent, MendCode uses a conservative
provider-aware default: OpenAI requests use `smart`, while other providers
preserve existing `legacy` behavior.

```jsonc
{
Expand Down Expand Up @@ -215,7 +223,8 @@ provider behavior (`legacy` effective mode).
Supported values and scopes:

- `mode`: `off` suppresses MendCode cache controls; `smart` enables only the
verified passive-key paths described below. Omit it to keep legacy behavior.
verified passive-key paths described below. Omit it to use the provider-aware
default (OpenAI `smart`; other providers `legacy`).
- `projects`: exact normalized project paths mapped to `{ "mode": "off" }` or
`{ "mode": "smart" }`. Use absolute paths for portable global config.
- `sessions.mode`: `all`, `selected`, or `none`. `include` selects session IDs
Expand All @@ -228,24 +237,35 @@ Resolution is deterministic. Disabling rules win in this order: global
`mode: off`, project `off`, session `none`/exclusion/not-selected, provider
`off`, then model exclusion or allowlist rejection. Enabling then resolves from
the global mode, project mode, provider selection, or explicitly included
session; otherwise the effective mode is `legacy`.
session; otherwise OpenAI uses `smart` and other providers use `legacy`.

### Smart-mode boundaries

`smart` is deliberately conservative. A managed passive cache key is enabled
only for a binding that has all of the following verified locally:

- API-key authentication, not ChatGPT subscription OAuth;
- a non-Responses-Lite transport;
- OpenAI's `@ai-sdk/openai` SDK at `api.openai.com`, or the OpenRouter SDK/
compatible route at `openrouter.ai`;
- the exact provider, model, endpoint, SDK, authentication, and transport match.

Other providers, custom endpoints, OAuth routes, unknown models, and incomplete
bindings do not receive a newly inferred managed key. Existing provider-specific
legacy annotations remain governed by their existing transform path unless the
policy is explicitly `off`; MendCode does not infer TTL, cache warmth, hit rate,
price savings, or provider support from a model name alone.
`smart` is deliberately conservative. A passive cache key is enabled only for
a binding that has a verified local wire contract:

- ChatGPT subscription/OAuth on OpenAI Codex Responses Lite uses the
provider-native, session-scoped key already required by that adapter. This is
not a MendCode-managed key and is not shared across sessions, projects, or
accounts;
- API-key authentication uses a managed key only for a non-Responses-Lite
binding with OpenAI's `@ai-sdk/openai` SDK at `api.openai.com`, or the
OpenRouter SDK/compatible route at `openrouter.ai`;
- in both cases, provider, endpoint, SDK, authentication, and transport must
match the verified binding.

The built-in verification is provider/SDK/endpoint based. An exact-model
restriction is applied only when `providers.<id>.models` or
`providers.<id>.exclude_models` is configured. Therefore, when a global or
provider policy is `smart`, use an allowlist if caching must be limited to
known models; a model name alone is not evidence of provider support.

Other providers, custom endpoints, and incomplete bindings do not receive a
newly inferred managed key. Existing provider-specific options and legacy
annotations remain governed by their existing transform path unless the policy
is explicitly `off`; `smart` does not overwrite an unverified provider option.
MendCode does not infer TTL, cache warmth, hit rate, price savings, weekly-limit
percentage, or provider support from a model name alone.

`off` removes recognized cache fields from request options and message/provider
annotations, including `promptCacheKey`, `prompt_cache_key`, `cacheControl`,
Expand Down Expand Up @@ -277,10 +297,24 @@ mendcode cache disable --global --project-path /Users/me/src/example
```

`cache status` reports the effective mode, the current project, the configured
block, and `activeKeeper: false`. Cache Keeper, scheduled refresh, automatic
warm-up, and provider canaries are not part of this control surface. Missing
provider cache metrics remain unknown rather than being converted to a zero or
used to claim a cache hit.
block, and `activeKeeper: false`. The reported `configured` block is the merged
policy visible to the current project; it includes any `projects`, `sessions`,
and `providers` rules. The status command does not take a session ID. To
inspect session policy, read `configured.sessions`: `none` disables all
sessions, `selected` permits only IDs in `include`, and `exclude` always wins.

Cache Keeper, scheduled refresh, automatic warm-up, and provider canaries are
not part of this control surface. A cache key may still consume request/quota/
weekly-limit usage, and missing provider cache metrics remain unknown rather
than being converted to a zero or used to claim a cache hit. The provider's
usage report or account UI is authoritative for actual token accounting and
remaining subscription quota.

If another MendCode backend currently owns the local database, a standalone
`cache status` invocation may fail with a writer-lock error. That error means
the status was not read; it is not evidence that caching is enabled or
disabled. Keep the active backend running and query through its existing
client, or retry after it releases the writer. Do not delete the lock manually.

## Prompt Draft Undo and Redo

Expand Down
Loading
Loading