diff --git a/cli/node/CHANGELOG.md b/cli/node/CHANGELOG.md index 713ce451d..0f223e737 100644 --- a/cli/node/CHANGELOG.md +++ b/cli/node/CHANGELOG.md @@ -5,6 +5,21 @@ All notable changes to `@mem0/cli` are documented here. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [0.2.8] — 2026-06-01 + +### Security + +- Pinned transitive dependencies via pnpm overrides to remediate high-severity CVEs: + - `jws` → 4.0.1 (CVE-2025-65945) + - `langsmith` → ^0.6.0 (CVE-2026-45134) + - `tar-fs` → ^2.1.4 (CVE-2025-48387, CVE-2025-59343) + - `picomatch` → ^2.3.2 (CVE-2026-33671) + - `minimatch` → ^3.1.3 / ^5.1.8 / ^9.0.7 (CVE-2026-27903, CVE-2026-27904, CVE-2026-26996) + - `path-to-regexp` → ^8.4.0 (CVE-2026-4926) + - `rollup` → ^4.59.0 (CVE-2026-27606) + - `glob` → ^10.5.0 (CVE-2025-64756) + - `@modelcontextprotocol/sdk` → ^1.25.4 (CVE-2025-66414, CVE-2026-0621) + ## [0.2.7] — 2026-05-20 ### Added diff --git a/cli/node/package.json b/cli/node/package.json index b3abdd480..41335220b 100644 --- a/cli/node/package.json +++ b/cli/node/package.json @@ -1,6 +1,6 @@ { "name": "@mem0/cli", - "version": "0.2.7", + "version": "0.2.8", "description": "The official CLI for mem0 — the memory layer for AI agents", "type": "module", "bin": { diff --git a/docs/changelog/sdk.mdx b/docs/changelog/sdk.mdx index 566ce2415..9cf797a27 100644 --- a/docs/changelog/sdk.mdx +++ b/docs/changelog/sdk.mdx @@ -939,6 +939,13 @@ See the [OSS v1 to v2 migration guide](https://docs.mem0.ai/migration/oss-v1-to- + + +**Security:** +- **Dependencies:** Bumped `axios` to `^1.16.0` to remediate high-severity prototype-pollution CVEs (credential theft, MITM, DoS). Pinned transitive dependencies via pnpm overrides: `jws` → 4.0.1 (CVE-2025-65945), `langsmith` → ^0.6.0 (CVE-2026-45134), `tar-fs` → ^2.1.4 (CVE-2025-48387, CVE-2025-59343), `picomatch` → ^2.3.2 (CVE-2026-33671), `minimatch` → ^3.1.3 / ^5.1.8 / ^9.0.7 (CVE-2026-27903, CVE-2026-27904, CVE-2026-26996), `path-to-regexp` → ^8.4.0 (CVE-2026-4926), `rollup` → ^4.59.0 (CVE-2026-27606), `glob` → ^10.5.0 (CVE-2025-64756), `@modelcontextprotocol/sdk` → ^1.25.4 (CVE-2025-66414, CVE-2026-0621) + + + **New Features:** @@ -1352,6 +1359,13 @@ See the [TypeScript SDK migration guide](https://docs.mem0.ai/migration/ts-v2-to + + +**Security:** +- **Dependencies:** Pinned transitive dependencies via pnpm overrides to remediate high-severity CVEs: `jws` → 4.0.1 (CVE-2025-65945), `langsmith` → ^0.6.0 (CVE-2026-45134), `tar-fs` → ^2.1.4 (CVE-2025-48387, CVE-2025-59343), `picomatch` → ^2.3.2 (CVE-2026-33671), `minimatch` → ^3.1.3 / ^5.1.8 / ^9.0.7 (CVE-2026-27903, CVE-2026-27904, CVE-2026-26996), `path-to-regexp` → ^8.4.0 (CVE-2026-4926), `rollup` → ^4.59.0 (CVE-2026-27606), `glob` → ^10.5.0 (CVE-2025-64756), `@modelcontextprotocol/sdk` → ^1.25.4 (CVE-2025-66414, CVE-2026-0621) + + + **Bug Fixes:** @@ -1468,6 +1482,20 @@ A full-featured command-line interface for Mem0, available in both Python and No + + +**Security:** +- **Dependencies:** Pinned transitive dependencies via pnpm overrides to remediate high-severity CVEs: `protobufjs` → ^7.5.5, `vite` → ^8.0.5, `langsmith` → ^0.6.0 (CVE-2026-45134), `picomatch` → ^2.3.2 (CVE-2026-33671), `@qdrant/js-client-rest` → ^1.18.0 + + + + + +**Security:** +- **Dependencies:** Pinned transitive dependencies via pnpm overrides to remediate high-severity CVEs: `glob` → ^10.5.0 (CVE-2025-64756), `minimatch` → ^3.1.3 / ^5.1.8 / ^9.0.7 (CVE-2026-27903, CVE-2026-27904, CVE-2026-26996), `picomatch` → ^2.3.2 (CVE-2026-33671), `rollup` → ^4.59.0 (CVE-2026-27606) + + + **Mem0 Plugin for Claude Code, Cursor, and Codex** diff --git a/mem0-ts/package.json b/mem0-ts/package.json index 4a19b4f7c..a9ed7b521 100644 --- a/mem0-ts/package.json +++ b/mem0-ts/package.json @@ -1,6 +1,6 @@ { "name": "mem0ai", - "version": "3.0.5", + "version": "3.0.6", "description": "The Memory Layer For Your AI Apps", "main": "./dist/index.js", "module": "./dist/index.mjs", diff --git a/mem0-ts/src/community/package.json b/mem0-ts/src/community/package.json index afb663dd7..36c5ca8b2 100644 --- a/mem0-ts/src/community/package.json +++ b/mem0-ts/src/community/package.json @@ -1,6 +1,6 @@ { "name": "@mem0/community", - "version": "0.0.1", + "version": "0.0.2", "description": "Community features for Mem0", "main": "./dist/index.js", "module": "./dist/index.mjs", diff --git a/openclaw/package.json b/openclaw/package.json index 81a4e6664..13e15b6d9 100644 --- a/openclaw/package.json +++ b/openclaw/package.json @@ -1,6 +1,6 @@ { "name": "@mem0/openclaw-mem0", - "version": "1.0.11", + "version": "1.0.12", "type": "module", "description": "Mem0 memory backend for OpenClaw — platform or self-hosted open-source", "license": "Apache-2.0", diff --git a/vercel-ai-sdk/package.json b/vercel-ai-sdk/package.json index 597f56871..a6c6f72f1 100644 --- a/vercel-ai-sdk/package.json +++ b/vercel-ai-sdk/package.json @@ -1,6 +1,6 @@ { "name": "@mem0/vercel-ai-provider", - "version": "2.0.5", + "version": "2.0.6", "description": "Vercel AI Provider for providing memory to LLMs", "main": "./dist/index.js", "module": "./dist/index.mjs",