Verified release history
Changelog
Every published HolyCode release through v1.2.5, kept here as a static record that works without JavaScript.
Read the tagged source changelogVerified history through v1.2.5.
202610/05/2026
Changed
- Updated Claude Code to 2.1.290, OpenSpec to 1.14.1, pnpm to 12.9.1, ESLint to 10.12.0, and Wrangler to 4.147.0 with its matching Miniflare and workerd packages.
- Switched GitHub CLI, fzf, and lazygit to official checksum-verified release archives. Updated lazygit to 0.66.0 and delta to 0.20.1.
- Kept the full Trivy and Docker Scout reports and added accepted upstream vulnerability records. Third-party findings remain visible; secrets, HolyCode-owned findings, invalid reports, unknown package provenance, and scanner failures still block delivery.
- Kept Paperclip at 2026.831.1 and Claude Auth at 2.2.1. The credential-refresh report in issue #11 remains open.
Fixed
- Updated all three Debian Chromium packages to .92 on AMD64 and ARM64, fixing the earlier v1.2.4 .57 advisory set and removing its package exception. Newer CVEs remain listed below. Pull
coderluii/holycode:1.2.5 and restart your container to apply the update. - Corrected the security-policy audit link, the contribution guide for disabled Discussions, and the missing v1.2.4 changelog entries.
Known issues
- Debian Chromium is
154.0.8037.92-1~deb13u1 on AMD64 and ARM64. It fixes the older .57 advisory set, but five newer CVEs remain accepted upstream vulnerabilities: CVE-2026-103622, CVE-2026-103624, CVE-2026-103625, CVE-2026-103626, and CVE-2026-103628. Two are Critical. Google ships the upstream fix in .97; Debian has not published that package yet. Avoid untrusted browser content and automation until the corrected Debian packages ship. See the dependency audit. - Other accepted upstream findings remain listed by dependency, installed version, and CVE in the scanner assets attached to this release. Acceptance permits delivery; it does not mean those findings are fixed.
10/01/2026
Changed
- Updated bundled OpenCode to 1.18.34, Claude Code to 2.1.286, OpenSpec to 1.14.0, npm to 12.2.0, pnpm to 12.8.1, Vite to 8.3.2, and GitHub CLI to 2.102.0.
- Updated Wrangler to 4.145.0 with its matching Miniflare and workerd packages, refreshed the Go builder image, and updated the release scanners and Renovate validator. The dependency audit lists the selected updates and compatibility holds.
- Kept Claude Auth at 2.2.1. This release does not fix the credential-refresh report in issue #11, which remains open.
Known issues
- The ARM64 image includes Chromium
154.0.8037.57-1~deb13u1. The 11 known CVEs include code-execution and sandbox-escape risks. The 33 exact package/CVE/version exceptions expire October 8, 2026. Avoid untrusted browser content and automation on ARM64. Existing sandbox and container controls do not make this safe. A follow-up release must replace the affected packages and remove the exceptions. Pull the corrected image and restart the container to apply it.
Fixed
- Removed Paperclip's obsolete Undici override after its dependency graph changed. The image now checks the current package owners and exercises jsdom's fetch path without adding an unused dependency.
- Updated npm's node-gyp and Undici packages, PM2's FTP dependency, and pip's vendored urllib3 to address the security findings in those bundled copies.
- Repaired the offline pip seed as well, so a new Python environment gets the same fixes. Source records, licenses, and the patched package metadata stay in sync.
09/24/2026
Changed
- Updated bundled OpenCode to 1.18.32, Claude Code to 2.1.281, OpenSpec to 1.13.2, npm to 12.1.0, and the selected development and inspection tools. The dependency audit lists every updated pin and compatibility hold.
- Updated the bundled Claude Auth plugin to 2.2.1. This release does not claim to resolve the credential-refresh report in issue #11, which remains open.
Fixed
- When CLIProxyAPI is enabled and no model list is set, HolyCode discovers the models offered by its
/models endpoint for OpenCode. An explicit CLIPROXYAPI_MODELS list still takes precedence; a temporary discovery failure leaves user-owned provider settings untouched.
09/18/2026
Changed
- Update GitHub CLI to 2.101.0, OpenCode to 1.18.31, Claude Code to 2.1.276, OpenSpec to 1.13.1, pnpm to 12.4.2, Prettier to 3.9.8, and Wrangler to 4.134.0 with Miniflare 5.20260917.0-alpha and workerd 1.20260917.1.
- Update Playwright to 1.63.0 and pandas to 3.0.6 with their compatible Python lock refresh.
- Update npm-owned brace-expansion to 5.0.12, ip-address to 10.7.2, and the protected Renovate validator to 44.97.6.
- Keep Paperclip at 2026.831.1 so fresh self-hosted instances do not silently enable the native runner. This release adds no Paperclip migration or default override.
- Keep
opencode-claude-auth at 2.2.0. The idle-session credential refresh reported in issue #11 remains open and is not fixed by the Claude Code update.
Fixed
- Reject malformed or cross-scanner Trivy and Docker Scout reports instead of treating them as empty findings.
09/14/2026
Changed
- Refresh Claude Code to 2.1.270, pnpm to 12.4.1, Wrangler to 4.131.2 with its owned Miniflare/workerd pair, fzf to 0.74.4, and lazygit to 0.65.1.
- Refresh Matplotlib to 3.11.2, tqdm to 4.70.1, and Uvicorn to 0.53.0 while keeping Node.js 24.21.0 LTS, Go 1.27.1, and the documented compatibility holds.
Fixed
- Keep non-root OpenSpec project initialization portable through Git Bash bind mounts and stop stubborn Uvicorn smoke processes cleanly.
09/10/2026
Changed
- Update Node.js LTS to 24.21.0, OpenCode to 1.18.30, Claude Code to 2.1.268, OpenSpec to 1.13.0, Vite to 8.3.0, and Wrangler to 4.131.0.
- Keep the bundled Claude Auth plugin and existing service defaults. Initialize OpenSpec explicitly with
openspec init --tools opencode; startup leaves your projects alone.
Fixed
- Update pip's bundled msgpack to 1.2.2 and use Wrangler's upstream Sharp dependency instead of the older custom replacement.
Upgrade
- Stop the container and back up your home, local-cache, and workspace volumes before updating. Paperclip stays on 2026.831.1. To return to image
1.1.9, restore your untouched pre-upgrade backup.
09/08/2026
Added
- Install
THIRD-PARTY-NOTICES at /usr/local/share/holycode/THIRD-PARTY-NOTICES.
Changed
- Refresh OpenCode, Claude Code, Paperclip, OpenSpec, Claude Auth, pnpm 12.4.0, Wrangler, ESLint, GitHub CLI, lazygit, and compatible Python packages.
- Keep TypeScript 6.0.3, Prisma 7.10.0, json-server 0.17.4, and Paperclip's Undici 6.28.1 replacement on their compatible stable lines.
Fixed
- Replace PM2's nested js-yaml and Miniflare's nested Sharp/libvips packages with owner-guarded fixed releases.
- Make suspended Hermes and HolyCode-managed oh-my-openagent startup errors version-neutral.
Paperclip 2026.831.1 applies migrations 0223 through 0230. Stop the container and back up your home/workspace volumes before upgrading. The retired brandColor and attachmentMaxBytes fields are removed, and in-progress login sessions reset, so restart login afterward. To roll back, restore the untouched backup with image 1.1.8; never run 1.1.8 against a database already migrated by 1.1.9.
09/01/2026
Added
- Added OpenSpec 1.11.0 for spec-driven development in OpenCode projects. Run
openspec init --tools opencode inside your project.
Changed
- Updated the bundled runtimes, CLIs, libraries, plugins, scanners, actions, and container build inputs to their latest stable releases.
08/12/2026
Fixed
- Replaced npm's bundled
ip-address 10.2.0 with 10.3.1. - Replaced PM2's bundled
js-yaml 4.3.0 with 4.3.1. - Added bounded retries to checksum-verified build and scanner downloads.
Security
- Added native AMD64 and ARM64 Docker Scout 1.24.0 and Trivy 0.73.0 checks before release tags are published.
08/12/2026
Status
- Docker tag
1.1.6 was not published because the security gate stopped promotion. - Docker tag
latest now points to 1.1.7.
Changed
- Refresh Node.js to 24.19.0, GitHub CLI to 2.97.0, fzf to 0.74.2, lazygit to 0.64.0, OpenCode to 1.18.16, Claude Code to 2.1.228, and Claude Auth to 2.1.6.
- Refresh pnpm to 11.21.0, tsx to 4.23.12, Vite to 8.2.1, Wrangler to 4.121.0, ESLint to 10.8.1, and Renovate to 44.24.2.
- Refresh the hash-locked Python set with Playwright 1.62.0, NumPy 2.5.2, Packaging 26.3, setuptools 84.0.0, Markdown 3.10.3, Uvicorn 0.52.1, and pip 26.2.1.
Security
- Validate image builds and smoke tests on native AMD64 and ARM64 runners.
- Refresh Docker Scout to 1.24.0 and Trivy to 0.73.0 while keeping fixable critical and high findings fail-closed.
08/02/2026
Changed
- Corrected the HolyCode Cloud copy in the README, moved the live hosted link beneath the product headline, and removed maintenance-only release text from public documentation.
- Rebuilt the image with current Debian Trixie security packages.
Security
- Updated Chromium to Debian Trixie's 151.0.7922.71 security package and retired the four Chromium exceptions used by v1.1.4.
07/30/2026
Changed
- Update OpenCode to 1.18.9, Claude Code to 2.1.220, Paperclip to 2026.722.0, npm to 12.0.2, pnpm to 11.18.0, ESLint to 10.8.0, Wrangler to 4.115.0, and Prisma to 7.9.1.
- Refresh the Python 3.13 package set, including pip 26.2, pandas 3.0.5, tqdm 4.70.0, FastAPI 0.141.1, and Uvicorn 0.52.0.
- Bundle
opencode-claude-auth 2.1.5 as an integrity-checked offline package so container startup no longer downloads it from npm. - Upgrade Paperclip's database through migration
0183. Back up your volumes before updating, and restore untouched pre-upgrade volumes if you roll back to 1.1.3. - Suspend HolyCode-managed oh-my-openagent installation. Once you remove the legacy enable flag, the first v1.1.4 start disables its old active entry while preserving settings, skills, and cached package data.
Security
- Rebuild GitHub CLI, fzf, and lazygit from their exact release sources with reviewed dependency updates.
- Replace pip's vulnerable internal msgpack and pkg_resources copies with hash-verified fixed sources.
- Remove the root npm lifecycle cache from the final image after the reviewed package scripts finish.
- Remove Netlify CLI and
serve. Hermes stays unbundled, CLIProxyAPI stays external-only, and HolyCode-managed oh-my-openagent installation remains suspended while their accessible dependency trees retain unresolved findings. - Run Chromium as the unprivileged
opencode user with Debian's setuid sandbox and the constrained HolyCode seccomp profile. - Record the four Chromium fixes that Debian Trixie has not published yet as narrow exceptions expiring on August 28, 2026. The release audit lists the affected CVEs, controls, and removal trigger.
Fixed
- Validate both hash-locked Python package sets, npm lifecycle scripts, release metadata, exact scanner exceptions, plugin modes, and Renovate extraction in protected release checks.
- Promote the exact multi-architecture image that passed protected validation instead of rebuilding after validation.
See the v1.1.4 dependency audit for adopted, held, removed, and unavailable updates.
07/21/2026
Changed
- Refresh OpenCode to 1.18.4, Claude Code to 2.1.216, s6-overlay to 3.2.3.2, fzf to 0.74.1, pnpm to 11.15.1, Vite to 8.1.5, Prettier to 3.9.6, Wrangler to 4.112.0, Prisma to 7.9.0, Lighthouse to 13.4.1, and
oh-my-openagent to 4.19.0. - Refresh the supported Python packages, including Requests 2.34.2 and Pillow 12.3.0.
- Keep Paperclip at 2026.707.0 while its newer destructive migration chain receives separate persistence testing.
- Run Chromium as
opencode with its sandbox enabled through the shipped config/chromium-seccomp.json profile.
Removed
- Temporarily remove bundled Hermes while its current release line requires vulnerable dependencies. Existing
/home/opencode/.hermes data is left untouched. - Remove Vercel CLI, sharp-cli, concurrently, and LHCI because their current dependency trees contain fixable critical or high findings.
Fixed
- Rebuild GitHub CLI 2.96.0 from its exact upstream tag with Go 1.26.5 to remove
CVE-2026-39822 from the bundled binary. - Replace Paperclip's vulnerable nested Undici 5.29.0 with Undici 6.27.0 and validate the Cursor adapter contract.
- Install the PostgreSQL 17 client directly instead of its empty compatibility metapackage.
- Validate npm lifecycle scripts by exact version, integrity, architecture, and script body before approved scripts run.
- Promote the exact multi-architecture image built and scanned by protected validation instead of rebuilding during publication.
Before upgrading from a release earlier than v1.1.3, add the Chromium seccomp profile described in the README. Then update with:
docker compose pull
docker compose up -d
Rollback requires untouched pre-upgrade volume snapshots with image 1.1.2; in-place database downgrades are not supported.
07/15/2026
Added
- A deny-by-default npm 12 lifecycle policy that checks each installed package's exact version and script before the image can ship.
Changed
- Moved the image to Debian Trixie with Node.js 24.18.0 LTS, Python 3.13, npm 12.0.1, and NumPy 2.5.1.
- Updated OpenCode to 1.18.2, Wrangler to 4.111.0, and lazygit to 0.63.1.
- Kept TypeScript 6.0.3 as the default compiler and Vercel 54.21.0 while their newer major versions remain compatibility holds.
- Kept Netlify CLI limited to remote build and deploy commands.
netlify dev and local functions remain unsupported.
Fixed
- Prepared Paperclip's embedded PostgreSQL library links during the image build so Paperclip can start after dropping to the unprivileged
opencode user. - Installed Hermes' Packaging 26.0 requirement without replacing Debian's package-manager-owned files.
Security
- Kept fixable critical findings as a release blocker and documented the remaining unfixed Debian findings in the v1.1.2 dependency audit.
07/15/2026
Changed
- Updated OpenCode to 1.18.1, Claude Code to 2.1.210, s6-overlay to 3.2.3.1, pnpm to 11.13.0, tsx to 4.23.1, and the default oh-my-openagent pin to 4.18.1.
- Rebuilt on the current Node 24.18.0 Bookworm digest and current Bookworm security packages.
- Kept Netlify CLI 26.2.0 for remote build and deploy commands while removing its local functions binary.
- Updated dependency, upgrade, rollback, security, Podman, Docker Hub, and translated documentation.
Fixed
- Registered OpenCode, Xvfb, Paperclip, and Hermes through the service bundle path required by s6-overlay 3.2.3.1.
- Aligned the shared Python environment with Hermes's exact Requests, Pillow, and Rich versions.
- Made release validation compare the actual current and rollback images instead of hard-coded runtime versions.
Removed
- Removed the bundled CLIProxyAPI sidecar while its published image contains fixable high-severity dependencies. External CLIProxyAPI endpoints remain supported.
- Removed Netlify local functions support until upstream publishes rebuilt platform binaries.
- Removed obsolete Trivy exceptions because the affected Netlify binaries are no longer shipped.
07/12/2026
Added
- Added native AMD64 and ARM64 release checks for upgrades, rollback, CLIProxyAPI authentication, Docker Scout, and Trivy.
- Published SPDX SBOM and SLSA provenance attestations with Docker image tags
latest and 1.1.0. - Added Renovate coverage and one-digit release version validation.
Changed
- Updated the base to Node.js 24.18.0 LTS with npm 11.16.0, OpenCode 1.17.18, Claude Code 2.1.207, Paperclip 2026.707.0, Hermes v2026.7.7.2, and CLIProxyAPI v7.2.71.
- Pinned container bases, release downloads, GitHub Actions, Docker Scout, Claude Code, and automatic OpenCode plugin updates to reviewed versions, digests, checksums, or commit SHAs.
- Corrected the release sequence at
v1.1.0 while preserving v1.0.10 through v1.0.13 as published history.
Fixed
- Run Hermes with
/home/opencode and matching XDG paths. - Keep OpenCode plugin behavior deterministic in manual, automatic, disabled, and legacy unversioned configurations.
- Removed Drizzle Kit's unused legacy loader and old nested esbuild binaries.
- Removed root npm download caches from the image layers, reducing build residue and eliminating placeholder-token secret findings.
07/07/2026
Changed
- Refresh the Docker runtime to Node.js 22.23.1 LTS while keeping npm 10.9.8.
- Refresh the pinned OpenCode, Paperclip, npm CLI, PyPI utility, GitHub-release, git-tag, and GitHub Actions versions used by the Docker image and workflows.
- Move Paperclip to its published Skills catalog package path and remove HolyCode's temporary catalog compatibility shim.
- Update the README, Docker Hub description, Podman guide, translations, and third-party notice text for the current Paperclip catalog packaging.
Fixed
- Keep pull-request validation pointed at Paperclip's current Skills catalog manifest path.
06/21/2026
Changed
- Include Paperclip's published Skills catalog package in the Docker image until stable Paperclip carries the upstream package-layout fix.
- Document the Paperclip Skills catalog compatibility shim in the README, Docker Hub description, Podman guide, translations, and third-party notices.
Fixed
- Stop Paperclip's Skills page from failing on
GET /api/skills/catalog by providing the catalog manifest at the path stable Paperclip expects. - Add pull-request validation that checks the Paperclip Skills catalog manifest and verifies a non-empty catalog can load from the built image.
06/20/2026
Changed
- Refresh Paperclip to 2026.618.0.
- Document Paperclip's OpenCode home/config paths and the supported Docker update path across the README, Docker Hub description, Podman guide, examples, security notes, and translations.
Fixed
- Start Paperclip with the same
/home/opencode HOME and XDG paths used by OpenCode so the OpenCode adapter no longer falls back to /root/.config/opencode. - Add pull-request validation that starts Paperclip and checks its runtime HOME/XDG environment.
06/18/2026
Changed
- Refreshed the Docker runtime to Node.js 22.23.0 LTS with npm 10.9.8.
- Refreshed pinned npm, PyPI, GitHub-release, and git-tag tools in the image.
- Updated GitHub Actions checkout/QEMU pins, read-only workflow permissions, and Docker Hub secret documentation.
- Migrated Renovate custom managers to
managerFilePatterns. - Updated README, Docker Hub description, Podman guide, changelog, security notes, third-party notices, and translated runtime tables.
- Documented the supported update path:
docker compose pull && docker compose up -d. - Documented that some current bundled third-party CLIs still report transitive npm advisories at their latest stable versions.
Fixed
- Removed the critical npm audit findings from the previous Dockerfile npm pin set.
- Kept shell and s6 service files on LF endings so Docker images built from Windows checkouts start correctly.
- Started Hermes in foreground mode under HolyCode's s6 supervision and documented the required
API_SERVER_KEY. - Started Paperclip with a Docker-reachable bind preset and pre-created embedded Postgres compatibility symlinks.
05/27/2026
Added
- Add a dedicated Podman guide covering env-file setup, SELinux bind mounts, rootless permissions, updates, and minimal web UI usage
05/27/2026
Fixed
- Allow Paperclip remote LAN/private hostnames to be configured with
PAPERCLIP_ALLOWED_HOSTNAMES
05/27/2026
Added
- Add optional CLIProxyAPI sidecar support in the full Docker Compose reference
- Add runtime OpenCode
cliproxyapi provider wiring behind CLIPROXYAPI_ENABLED
Changed
- Document CLIProxyAPI setup, environment variables, and isolated local-cache state paths in English docs
Fixed
- Keep CLIProxyAPI configuration isolated from
ENABLE_CLAUDE_AUTH, opencode-claude-auth, and Claude credential paths
05/27/2026
Added
- Add Renovate-only dependency automation for GitHub Actions, Dockerfile pins, Docker ARGs, npm packages, and PyPI packages with automerge disabled
Changed
- Pin Docker and runtime dependency versions for repeatable builds
- Refresh workflow action versions to current stable tags
Fixed
- Preserve user-owned
oh-my-openagent-setup skill folders while cleaning up HolyCode-managed copies when the plugin is disabled - Document local
local-cache/ guidance for quick-start setups - Repair translated README contributing links so they resolve to the source repo contribution guide
[1.0.5] - 04/10/2026
Added
- Add Hermes Agent as an optional bundled service with
ENABLE_HERMES, persistent ~/.hermes state, and an API surface on port 8642 - Add Paperclip as an optional bundled service with
ENABLE_PAPERCLIP, persistent ~/.paperclip state, and a local dashboard on port 3100 - Install Claude Code CLI in the image so the Claude Auth flow has the binary it expects
- Expand the shipped toolset with TypeScript, pnpm, Prisma, Lighthouse, database CLIs, media tools, and Python utility packages
- Add a pull-request validation workflow that builds the image and smoke-checks the OpenCode binary
Changed
- Refresh the docs, translations, Docker Hub description, and landing page to reflect the new bundled services and the larger 50+ toolset
- Extend the default compose and env examples with Hermes and Paperclip toggles
Fixed
- Resolve the
python-dotenv and dotenv-cli binary collision so the image builds cleanly - Switch Hermes to its foreground gateway runner and bootstrap Paperclip in a Docker-safe authenticated mode so both bundled services start correctly under s6-overlay
- Remove shell-expanded Python config edits from
entrypoint.sh by passing data into Python safely - Repair broken asset and LICENSE paths in the affected translated READMEs
- Remove stale Slim-variant references from the package request issue template
04/04/2026
Added
- Ship a built-in
/oh-my-openagent-setup skill for first-time setup and reruns after provider changes (only visible when ENABLE_OH_MY_OPENAGENT=true) - Copy HolyCode-managed OpenCode skills into
~/.config/opencode/skills on boot without overwriting existing user skill folders - Ensure enabled plugin packages are installed on boot if they are missing from the OpenCode cache
- Add
HOLYCODE_PLUGIN_UPDATE environment variable with two modes: manual (install if missing only) and auto (install if missing and update on boot)
Changed
- Document
/oh-my-openagent-setup as the supported path for writing oh-my-openagent.jsonc - Document the default picker policy so only Sisyphus, Hephaestus, Prometheus, and Atlas are visible by default
- Clarify that
OPENCODE_DISABLE_AUTOUPDATE only affects OpenCode itself, not plugins - Clarify that
/oh-my-openagent-setup skill only appears when the plugin is enabled
Fixed
- Add an explicit rerun + doctor + model-capability refresh path for stale visible default-model behavior after provider changes
04/04/2026
Added
- Ship a built-in
/oh-my-openagent-setup skill for first-time setup and reruns after provider changes - Copy HolyCode-managed OpenCode skills into
~/.config/opencode/skills on boot without overwriting existing user skill folders - Ensure enabled plugin packages are installed on boot if they are missing from the OpenCode cache
Changed
- Document
/oh-my-openagent-setup as the supported path for writing oh-my-openagent.jsonc - Document the default picker policy so only Sisyphus, Hephaestus, Prometheus, and Atlas are visible by default
Fixed
- Add an explicit rerun + doctor + model-capability refresh path for stale visible default-model behavior after provider changes
04/03/2026
Changed
- Clarify that
/home/opencode is the fixed container path while the host data path depends on the bind mount the user chooses - Clarify that main data can live on remote storage while the cache path should remain local
- Clarify that
ENABLE_OH_MY_OPENAGENT=true enables the plugin through opencode.json without promising a separate plugin-specific config file on the host
04/02/2026
Fixed
- Detect CIFS/SMB network mounts and warn about SQLite WAL incompatibility
- Add
nobrl,mfsymlinks mount option documentation for README Troubleshooting section
Changed
- Expand SQLite WAL note with network storage guidance
- Add startup check in entrypoint.sh for CIFS/SMB detection
- Replace the
holycode-cache named volume guidance with an explicit local-path cache bind mount for CIFS/SMB setups
03/30/2026
Added
- OpenCode AI coding agent (v1.3.6) with built-in web UI on port 4096
- s6-overlay v3 for process supervision with auto-restart and clean shutdown
- Headless browser: Chromium + Xvfb + Playwright for browser automation
- Single bind mount persistence (all state under ./data/opencode)
- UID/GID remapping via PUID/PGID environment variables
- First-boot bootstrap with default config and git identity setup
- Claude Auth plugin toggle (ENABLE_CLAUDE_AUTH) for Claude subscription users
- oh-my-openagent plugin toggle (ENABLE_OH_MY_OPENAGENT) for multi-agent orchestration
- Web UI basic auth support (OPENCODE_SERVER_PASSWORD)
- 30+ dev tools: git, ripgrep, fd, fzf, bat, eza, lazygit, delta, gh CLI, htop, tmux, and more
- Language runtimes: Node.js 22, Python 3
- 10+ AI provider support: Anthropic, OpenAI, Gemini, Groq, AWS Bedrock, Azure OpenAI, Vertex AI, GitHub Models, Ollama
- CI/CD pipeline for Docker Hub + GHCR (amd64 + arm64)
- Docker Compose quick-start and full reference configurations
- Comprehensive README with quick start, troubleshooting, and architecture docs
- Landing page at holycode.coderluii.dev