Skip to content

feat: migrate PentestCode to OpenCode V2 - #17

Open
acak1221 wants to merge 1 commit into
s0ld13rr:mainfrom
acak1221:v2-migration
Open

acak1221 wants to merge 1 commit into
s0ld13rr:mainfrom
acak1221:v2-migration

Conversation

@acak1221

Copy link
Copy Markdown

Issue for this PR

 Closes #13.

 ### Type of change

 - [x] Bug fix
 - [x] New feature
 - [x] Refactor / code improvement
 - [x] Documentation

 ### What does this PR do?

 Migrates PentestCode 0.2.6 to OpenCode 2.0.18, with product version `0.3.0-v2.1`.

 - Upgrades the runtime, CLI/TUI, web app, client/SDK, build, installer and CI.
 - Ports all 21 pentest tools, 16 agent roles, 12 commands, bundled skills and engagement context to native V2 plugins.
 - Implements task DAG execution through V2 child sessions, permissions, cancellation and durable completion notifications.
 - Preserves existing engagement/knowledge data and configuration; migrates V1 transcripts and credentials.
 - Restores PentestCode branding and engagement creation, selection and sidebar flows.
 - Fixes #13 by sending the current session’s `x-opencode-session` on Go/Zen primary and auxiliary requests, with regression coverage.

Architecture and validation details: specs/v2/pentestcode-migration.md.

 ### How did you verify your code works?

 Locally on Linux x64 with Bun 1.4.2:

 - Workspace typecheck: 22 tasks passed.
 - Core: 5,697 passed, 11 skipped, 0 failed.
 - TUI: 1,434 passed, 2 skipped.
 - Web: 930 unit, 157 browser-unit, 7 icon, 4 boundary and 3 production Chromium E2E tests passed.
 - Shared session UI: 193 passed.
 - Built the Linux executable with embedded web UI and skills.
 - Verified compiled service authentication, persistence/restart, plugin activation and service election.
 - Verified interactive TUI engagement creation/selection and clean exit.
 - Validated the Node 26.4.0 bundle.
 - Repeated client generation with identical output hashes.

 Native Windows/macOS execution and Node SEA remain unverified locally.

 ### Screenshots / recordings

 Compiled TUI terminal capture excerpt after engagement creation and selection:

 ```text
 Final compiled TUI smoke
 Final smoke alpha
 recon · auto
 0 hosts · 0 findings · 0 credentials
 ```

 ### Checklist

 - [x] I have tested my changes locally
 - [x] I have not included unrelated changes in this PR

Upgrade the active runtime, CLI, TUI, web app, SDK and build pipeline to OpenCode 2.0.18 while retaining PentestCode agents, tools, commands and persisted engagement data.

Port native task orchestration, engagement RPC, V1 config and credential migration, and Go/Zen session routing compatibility. Document architecture and local validation for 0.3.0-v2.1.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant