You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
After the replacement App is available, remove bundled OpenVSCode from default Agent Server images and the automatic VSCodeService startup path. Remove or deprecate built-in editor-specific API/config/ports coherently with consumers; never advertise a dead editor URL. Keep generic app backend management in Agent Server.
Acceptance criteria:
Default images contain no OpenVSCode install tree/bundled Node dependencies, no automatic editor process and no unconditional editor capability.
Existing users receive migration instructions to the released/pinned vscode App. Stage deprecated API/config behavior with actionable response if needed; do not silently break downstream Cloud consumers.
Inventory Canvas launcher, Docker runtime, sandbox-server and runtime-api consumers before deleting compatibility paths. If migration needs code in another repo, split a dependency issue/PR there first.
Real image build plus targeted SBOM/scan confirms OpenVSCode tree absent; do not suppress CVEs to pass. Installing App remains scanned/maintained separately: moving it does not fix its CVEs.
Repeat real frontend click-through on the stripped image, file save and terminal operation, with .pr/ GIF evidence and green CI.
Removal is release-gated on replacement availability; no merges/release tags authorized by this issue.
Dependencies and sequencing
Implementation/merge prerequisites (cross-repository links are authoritative):
Readiness means design/scope accepted; implementation must wait for the triage automation to apply ready-for-dev. Dependent PRs may stack on tested prerequisite branches; they must not merge before prerequisite PRs. No issue should be closed just to bypass sequencing. One issue per PR.
This issue was created by an AI agent (OpenHands) on behalf of Graham Neubig.
OpenHands AI triage
The following comments and acceptance criteria were added by the OpenHands AI agent.
Triage
Bounded to this repository's Agent Server, workspace packages, Docker images, and TypeScript client, which all carry the built-in editor surface: openhands-agent-server/openhands/agent_server/vscode_service.py (auto-start path) and vscode_router.py, Configuration.enable_vscode/vscode_port/vscode_base_path, GET /api/vscode/url and /api/vscode/status, the runtime /conversations/{id}/vscode/url route, the INSTALL_CAPABILITIES=vscode Dockerfile block plus vscode_extensions/, DockerWorkspace/ApptainerWorkspace.extra_ports, clients/typescriptVSCodeClient and generated schema, and examples/02_remote_agent_server/05_vscode_with_docker_sandboxed_server.py. The replacement editor is owned elsewhere — canvas-apps#23 ships the pinned vscode App, and SDK #5264/#5265 provide the generic app backend lifecycle and authenticated HTTP/WS bridge — so this issue is deliberately release-gated on that availability. The repo has one authoritative compatibility mechanism, so deprecation is expected to use it rather than an ad-hoc shim: REST surfaces follow openhands-agent-server/AGENTS.md (deprecated=True plus the exact Deprecated since vX and scheduled for removal in vY docstring shape and 5-minor-release runway, enforced by .github/workflows/agent-server-rest-api-breakage.yml), and Python surfaces follow openhands-sdk/openhands/sdk/AGENTS.md deprecation metadata before removal.
Non-goals: implementing the replacement App or its HTTP/WS bridge (canvas-apps#23, SDK #5264/#5265); removing or redesigning generic app backend management in Agent Server; deleting unused frozen vscode_base_path/vscode_port config without the deprecation runway; any release/merge action (this issue authorizes none).
Desired Behavior
Once the replacement vscode App in canvas-apps#23 is released and pinned, default Agent Server images no longer bundle or auto-start OpenVSCode, the server no longer advertises an editor URL that points at something that is not running, and existing editor-specific REST/config surfaces are deprecated with an actionable response for their 5-minor-release runway so downstream Cloud consumers are not silently broken. Generic app backend lifecycle management in Agent Server is retained.
Acceptance Criteria
Default agent-server images built via openhands-agent-server/openhands/agent_server/docker/build.py with default capabilities contain no /openhands/.openvscode-server tree, no OpenVSCode bin/openvscode-server binary or bin/remote-cli/code shim, and no bundled Node runtime for the editor; verified against the real built image and a targeted SBOM/scan, not by suppressing CVEs.
Starting a default image spawns no editor process and the server does not log editor startup; no capability or endpoint reports an unconditionally enabled editor.
GET /api/vscode/url, GET /api/vscode/status, and the runtime /conversations/{runtime_conversation_id}/vscode/url route never return a URL for a non-running editor, and any retained endpoint is marked deprecated=True with the exact repo deprecation docstring shape required by the REST breakage check and returns an actionable migration message.
Configuration.enable_vscode, vscode_port, and vscode_base_path (and OH_ENABLE_VSCODE handling) remain accepted for at least the 5-minor-release runway, or are removed only after conforming deprecation metadata; setting them does not crash or silently change unrelated behavior.
A documented consumer inventory covers Agent Canvas launcher, DockerWorkspace/ApptainerWorkspaceextra_ports and port 8001, sandbox-server, runtime-api, clients/typescriptVSCodeClient/generated schema, and the vscode example, with any required cross-repo migration split into a linked dependency issue before compatibility paths are deleted.
clients/typescript checked out with the server change regenerates and builds cleanly (npm ci && npm run lint && npm run build && npm test) with the deprecated/removed endpoints reflected coherently in the typed client.
Real frontend click-through on the stripped image with the pinned replacement App installed opens the editor, saves a file edit, and runs a terminal command in the same workspace/tool environment, with GIF evidence committed under .pr/ and embedded in the PR description, and green CI.
User-facing migration documentation directs existing users to the released/pinned vscode App and no longer instructs using bundled OpenVSCode.
After the replacement App is available, remove bundled OpenVSCode from default Agent Server images and the automatic VSCodeService startup path. Remove or deprecate built-in editor-specific API/config/ports coherently with consumers; never advertise a dead editor URL. Keep generic app backend management in Agent Server.
Acceptance criteria:
Dependencies and sequencing
Implementation/merge prerequisites (cross-repository links are authoritative):
Readiness means design/scope accepted; implementation must wait for the triage automation to apply ready-for-dev. Dependent PRs may stack on tested prerequisite branches; they must not merge before prerequisite PRs. No issue should be closed just to bypass sequencing. One issue per PR.
This issue was created by an AI agent (OpenHands) on behalf of Graham Neubig.
OpenHands AI triage
The following comments and acceptance criteria were added by the OpenHands AI agent.
Triage
Bounded to this repository's Agent Server, workspace packages, Docker images, and TypeScript client, which all carry the built-in editor surface:
openhands-agent-server/openhands/agent_server/vscode_service.py(auto-start path) andvscode_router.py,Configuration.enable_vscode/vscode_port/vscode_base_path,GET /api/vscode/urland/api/vscode/status, the runtime/conversations/{id}/vscode/urlroute, theINSTALL_CAPABILITIES=vscodeDockerfile block plusvscode_extensions/,DockerWorkspace/ApptainerWorkspace.extra_ports,clients/typescriptVSCodeClientand generated schema, andexamples/02_remote_agent_server/05_vscode_with_docker_sandboxed_server.py. The replacement editor is owned elsewhere — canvas-apps#23 ships the pinned vscode App, and SDK #5264/#5265 provide the generic app backend lifecycle and authenticated HTTP/WS bridge — so this issue is deliberately release-gated on that availability. The repo has one authoritative compatibility mechanism, so deprecation is expected to use it rather than an ad-hoc shim: REST surfaces followopenhands-agent-server/AGENTS.md(deprecated=Trueplus the exactDeprecated since vX and scheduled for removal in vYdocstring shape and 5-minor-release runway, enforced by.github/workflows/agent-server-rest-api-breakage.yml), and Python surfaces followopenhands-sdk/openhands/sdk/AGENTS.mddeprecation metadata before removal.Non-goals: implementing the replacement App or its HTTP/WS bridge (canvas-apps#23, SDK #5264/#5265); removing or redesigning generic app backend management in Agent Server; deleting unused frozen
vscode_base_path/vscode_portconfig without the deprecation runway; any release/merge action (this issue authorizes none).Desired Behavior
Once the replacement vscode App in canvas-apps#23 is released and pinned, default Agent Server images no longer bundle or auto-start OpenVSCode, the server no longer advertises an editor URL that points at something that is not running, and existing editor-specific REST/config surfaces are deprecated with an actionable response for their 5-minor-release runway so downstream Cloud consumers are not silently broken. Generic app backend lifecycle management in Agent Server is retained.
Acceptance Criteria
openhands-agent-server/openhands/agent_server/docker/build.pywith default capabilities contain no/openhands/.openvscode-servertree, no OpenVSCodebin/openvscode-serverbinary orbin/remote-cli/codeshim, and no bundled Node runtime for the editor; verified against the real built image and a targeted SBOM/scan, not by suppressing CVEs.GET /api/vscode/url,GET /api/vscode/status, and the runtime/conversations/{runtime_conversation_id}/vscode/urlroute never return a URL for a non-running editor, and any retained endpoint is markeddeprecated=Truewith the exact repo deprecation docstring shape required by the REST breakage check and returns an actionable migration message.Configuration.enable_vscode,vscode_port, andvscode_base_path(andOH_ENABLE_VSCODEhandling) remain accepted for at least the 5-minor-release runway, or are removed only after conforming deprecation metadata; setting them does not crash or silently change unrelated behavior.DockerWorkspace/ApptainerWorkspaceextra_portsand port8001, sandbox-server, runtime-api,clients/typescriptVSCodeClient/generated schema, and the vscode example, with any required cross-repo migration split into a linked dependency issue before compatibility paths are deleted.clients/typescriptchecked out with the server change regenerates and builds cleanly (npm ci && npm run lint && npm run build && npm test) with the deprecated/removed endpoints reflected coherently in the typed client..pr/and embedded in the PR description, and green CI.