Commit Graph

64 Commits

Author SHA1 Message Date
Saket Aryan 3fd4949040 fix(plugins): keep the salt working where hardlinks are not supported
Self-review of the atomic-publish fix. Some network mounts and container volumes
reject os.link, and the outer handler swallowed that into "no salt", which meant
repo_hash and session_hash were dropped on every run for that whole cohort. The
race being closed is narrow; losing the hashes for an entire filesystem is not a
fair trade.

Falls back to claiming the name with O_CREAT|O_EXCL and writing, which is what
this did before. The empty-file window reopens there, but it is benign now: a
reader landing in it gets "" and omits the hash for that process rather than
caching a guessable path digest, which was the actual defect.

266 passed, 8 skipped.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-16 21:08:43 +05:30
Saket Aryan 7710a4e180 fix(plugins): publish the salt atomically, and omit the hash when there is none
Review finding from @kartik-mem0 on this PR.

O_CREAT|O_EXCL then write leaves a window where the salt file exists and is
empty. Hooks are short-lived processes firing on every tool call and people run
several agent windows, so a concurrent reader lands in that window, reads
nothing, and falls back to a digest of the salt file's own path, memoized for
its whole run. That path is guessable, so the race silently replaced the privacy
control with something an attacker can compute, and hashed the same repository
two ways depending on timing.

The value is now written to a private temp file, fsynced, and published with
os.link, which is atomic and fails if another process already published one.
Link rather than replace, so losing the race adopts their salt instead of
clobbering it. The temp file is removed either way.

The derived fallback is gone rather than fixed. _scoped_digest returns "" when
there is no salt and record() omits the property, because an unsalted digest
over a git remote or a home-directory path is close to plaintext, and shipping
one under a name that says hash is worse than sending nothing.

Three tests: the racing reader never sees the name half-written, a second writer
adopts the first's salt and leaves no temp file, and an unwritable data
directory drops the property instead of emitting a weak one. The old test
asserted the fallback behaviour and is replaced.

265 passed, 8 skipped.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-16 20:33:54 +05:30
Saket Aryan aa770aa652 docs(plugins): finish the telemetry sweep across the remaining surfaces
The first pass fixed the plugin README and the module docstring but left the
same claim standing everywhere else.

- docs/integrations/deepseek-plugin.mdx still said "Anonymous usage events".
  The TS SDK's telemetryId is the raw account email, so it is not anonymous.
- The pause skill told users a "minimal anonymous telemetry ping" fires while
  paused. Same ping, same email. Corrected in the template, which regenerates
  into all six hosts.
- integrations/zapier-mem0/README.md advertised telemetry the app does not have:
  there is no telemetry code in it at all. It now says what is actually true,
  that its requests carry source="ZAPIER".
- The data directory listing is presented as exhaustive and had gone stale
  against this stack's two new files, telemetry-salt and install-state.json.

Also replaced the property enumeration in both the README and the docs page.
Review pointed out it omitted the configured model name among others — writing
a fresh exhaustive list in a PR whose whole purpose is making docs match code
reproduces the defect being fixed. It now describes the shape and points at
where the rule is actually enforced, so it cannot drift again.

Deliberately unchanged: docs/integrations/openclaw.mdx. OpenClaw hashes the
email rather than sending it, which is materially different from the plugin and
the SDK, so its claim is not wrong in the same way.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-15 00:37:33 +05:30
Saket Aryan 95d4fc27e2 fix(plugins): make the telemetry salt stable, its own file, and memoized
Review found three ways the first cut produced worse data than no salt at all.
All three came from keeping the salt as a key in the identity dict and doing an
unlocked read-modify-write.

Hooks are short-lived separate processes firing on every tool call, and people
run more than one agent window, so several processes would read {}, each mint
its own uuid4, and each hash with it. One repository hashed several ways in the
window before a writer won.

resolve_distinct_id holds a copy of that same dict across a network call to
/v1/ping/ with a 5s timeout, so whichever write landed second erased the other's
key: losing the salt changes repo_hash mid-stream, losing the email fires a
second $identify and splits the person.

_write_identity swallows OSError, and nothing memoized, so on a read-only or
full data directory every single event got a brand-new random salt — unbounded
cardinality in PostHog, which is strictly worse than the unsalted value it
replaced.

The salt now lives in its own file claimed with O_CREAT|O_EXCL, so exactly one
process wins and the losers read the winner's value, and it is memoized per
process. When it cannot be persisted the fallback is derived from the data
directory path: stable for the machine rather than random per call.

Its own file also means record() no longer creates telemetry-identity.json as a
side effect. is_first_run keys off that file, so the first cut would have
silently suppressed the install event — a production metric change hidden in a
docs PR.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-15 00:25:12 +05:30
Saket Aryan 0d37619f24 fix(plugins): say what telemetry actually sends, and salt the hashes
The plugin README promises "anonymous usage events" and the telemetry module's
docstring says it sends only "salted hashes". Neither is true.

resolve_distinct_id() exchanges the API key for the account email and sends that
as the distinct_id on every event. Installing the plugin requires an API key, so
this is nearly every user. That is probably the behaviour we want — the Python
SDK and the CLI attribute the same way — but the description has to match it.

repo_hash and session_hash were unsalted SHA-256 cut to 16 hex characters.
repo.identity is a git remote URL, or `local:<absolute path>` when there is no
remote, which normally contains the account username. Sixteen unsalted hex
characters over that input space is enumerable, so the hash was not a privacy
control at all.

Salted per install, with the salt kept in the identity file. That preserves
every within-account join the analytics actually use and gives up only
cross-machine joins on the same repository, which nothing computes. Since the
distinct_id is already the email, the hash was never buying privacy from us —
only from whoever obtains the data later, which is exactly what the salt fixes.

Also corrects deepseek-plugin's README and source comment, which told readers
ZAPIER and STRANDS were already in the backend's KNOWN_EVENT_SOURCES allowlist.
Neither was.

Adds a Telemetry section to docs/integrations/claude-code.mdx, which had none.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-15 00:17:26 +05:30
Harsh Vardhan Gupta c7ee362aff fix(security): resolve 12 Vanta/Dependabot vulnerabilities across 6 pnpm workspaces + poetry.lock (#7280)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-09-11 16:07:57 +05:30
Kartik d873892dad feat(plugins)!: make Sidekick exclusive to Claude Code (#7278) 2026-09-10 20:51:50 +05:30
Kartik 02f7a9b2c4 docs: align agent plugin guides with shared runtime behavior (#7269) 2026-09-09 01:03:26 +05:30
Kartik 73e7b8763a refactor(integrations): shared agent plugin runtimes and native adapters (#7203) 2026-09-08 23:32:25 +05:30
Kartik 71fba8d464 feat(claude-code-plugin): move the Claude Code plugin to its own integration and ship it as 0.3.0 (#7106) 2026-09-01 02:34:45 +05:30
Kartik 0070e08e01 feat(deepseek-plugin,mem0-strands): add usage telemetry (#7110) 2026-08-27 13:48:30 +05:30
Kartik b717e38785 refactor(integrations): rename dsh-mem0 to deepseek-plugin, strands-mem0 to mem0-strands (#7098) 2026-08-24 19:21:23 +05:30
Kartik 4ddee9c51d chore(release): bump SDK, CLI, and plugin versions; add Strands, DeepSeek Harness, and Kimi changelogs (#7097) 2026-08-24 18:10:44 +05:30
Himanshu 7e09615571 feat(integrations): dsh-mem0 — Mem0 as a native DeepSeek Harness plugin (#7027)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-08-24 14:03:50 +05:30
Himanshu 8d5b7865bd feat(integrations): strands-mem0 | Mem0 as a native Strands MemoryStore (#7021) 2026-08-22 19:04:24 +05:30
Harsh Vardhan Gupta 5af797834c fix(security): resolve 17 Vanta/Dependabot HIGH+CRITICAL vulnerabilities across 5 pnpm workspaces (#7032) 2026-08-21 17:41:41 +05:30
Himanshu 1de6499b8a fix(integrations/zapier): address Zapier publishing review (#6985) 2026-08-20 18:53:06 +05:30
Kartik 530d802b55 fix(plugins): bug-bash fixes for Cursor, Codex, Antigravity, and a Claude.ai docs page (#6948) 2026-08-20 15:56:17 +05:30
Kartik 290de24bb8 feat(ci): gate pull requests on an accepted issue (#6894) 2026-08-14 17:05:27 +05:30
Kartik a10c0cd030 fix(mem0-plugin): stop search errors from looking like empty results (#6898) 2026-08-14 16:57:01 +05:30
Kartik 96d45b78c7 fix(mem0-plugin): drop unused pytest import breaking make lint on main (#6937) 2026-08-13 16:51:01 +05:30
Himanshu ba2fb9f4c3 feat(kimi): Mem0 plugin for Kimi Code (MCP + skills + auto-capture) (#6919) 2026-08-13 16:15:04 +05:30
Harsh Vardhan Gupta 4debc58a83 fix(security): patch 8 HIGH + 18 MEDIUM Vanta vulnerabilities across 4 pnpm workspaces (#6847) 2026-08-07 19:04:33 +05:30
Himanshu 3f39fba28f fix(n8n): MIT license + themed icons for verified-node vetting (#6804)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-08-06 00:00:13 +05:30
Kartik 1112be3e5e chore(release): bump SDK, CLI, and plugin versions (#6800) 2026-08-05 00:16:26 +05:30
Himanshu b54710a3c3 fix(zapier): require user_id on Add Memory (#6790) 2026-08-04 18:49:35 +05:30
Himanshu 4cfa98f626 chore(n8n): route package contact to integrations@mem0.ai (#6791) 2026-08-04 17:39:20 +05:30
Himanshu 965140eb19 fix(zapier): add root index.js entry shim so deployed app resolves (#6789) 2026-08-04 12:48:46 +05:30
Kartik c90bdbdce0 feat(cli): Platform option parity across Python and Node CLIs (MEM-5893) (#6696) 2026-08-03 17:10:44 +05:30
Kartik 50bdaaea0c chore: bump versions and update changelog for Python 2.0.15, TypeScript 3.1.3, and plugin releases (#6715) 2026-08-01 20:26:31 +05:30
Kartik 07e58c54ae fix: align default model names with SDK defaults (#6704) 2026-08-01 01:30:57 +05:30
Harsh Vardhan Gupta 9c2d6222ce fix(security): patch 32 HIGH + 57 MEDIUM Vanta vulnerabilities across 6 pnpm workspaces (#6639)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-07-30 15:20:13 +05:30
Kartik 790e190486 chore(n8n): release 0.1.1 via CD for npm provenance (#6685) 2026-07-30 13:54:37 +05:30
Himanshu d4869d24ec feat(integrations): n8n community node for Mem0 (#6517)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-07-29 23:03:03 +05:30
Kartik 1ac3aa7256 fix(zapier): raise the add_memory poll budget past the real API latency tail (#6680) 2026-07-29 21:32:22 +05:30
Himanshu e168d48e04 feat(integrations): Zapier app for Mem0 (#6518)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-07-29 20:56:44 +05:30
Kartik ea2ee07586 chore: remove OpenMemory from the monorepo (#6530) 2026-07-29 15:10:32 +05:30
Kartik 5e7adc4d12 chore: update changelog, bump versions to Python 2.0.13, TypeScript 3.1.1, OpenCode plugin 0.2.2 (#6504) 2026-07-22 23:27:47 +05:30
Rod Boev b05cce581b fix(opencode-plugin): recover MEM0_API_KEY from shell profiles (#6404) 2026-07-20 20:41:41 +05:30
Kartik ccbe5861a1 docs: remove criteria retrieval docs for non-existent feature (#6282) 2026-07-14 20:06:05 +05:30
Kartik d6d2588ef5 fix(mem0-plugin): store assistant-authored summaries with role="assistant" (#6316) 2026-07-14 20:03:36 +05:30
Kartik 8488abe603 docs: correct custom categories, per-call custom_categories is supported (#6218) 2026-07-10 20:08:32 +05:30
Kartik 41c8f00851 chore(integrations): plugin updates, pi-agent auto-recall, and version bumps (#6011) 2026-07-01 20:57:32 +05:30
Kartik c325bd3b8e docs(changelog): consolidate per-package changelogs into the SDK changelog page (#6007) 2026-06-30 14:09:41 +05:30
Terrasse cc59d122db docs: remove instructions for unavailable Cursor marketplace plugin (#5971) 2026-06-29 20:35:07 +05:30
Harsh Vardhan Gupta bbbfcfea07 fix(deps): bump undici to >=6.27.0 (CVE-2026-12151) (#5861) 2026-06-26 15:32:09 +05:30
Rod Boev 1f66aadfa3 fix(openclaw): normalize Windows skill-loader URLs before fileURLToPath (#5679) 2026-06-25 16:36:11 +05:30
Kartik ac8f862ff7 fix(mem0-plugin): store files_touched as a list to stop double JSON-encoding (#5806) 2026-06-25 09:06:11 +05:30
Bartok ced4af681f fix(claude-plugin): rerank auto-injected memory context by default (#5690) 2026-06-23 16:52:35 +05:30
Harsh Vardhan Gupta ca86a164bd fix(pi-agent-plugin): resolve undici CVE-2026-9697 / CVE-2026-9678 (#5669) 2026-06-19 16:21:18 +05:30