The Add operation exposed app_id, includes, and excludes in Additional
Fields and forwarded them to POST /v3/memories/add/. None of the three
are declared on that endpoint's schema (they belong to MemoryInput, used
by POST /v1/memories/), so they were silently dropped by the server.
app_id was worse than a no-op: the entity-id guard accepted it as
satisfying "at least one entity id", so filling only App ID passed local
validation and then sent a v3 request carrying no scope v3 recognises.
The guard now requires User ID, Agent ID, or Run ID.
Docs corrections alongside it:
- Add: document Custom Instructions and Custom Categories, which the
node has always supported but the docs never mentioned
- Get Many: document Return All, which the docs omitted entirely
- README: Infer and Wait for Completion are independent controls; the
README claimed infer=false returns synchronously, contradicting the
node's own field description and its actual behaviour
Every other publishable integration (@mem0/pi-agent-plugin,
@mem0/openclaw-mem0, @mem0/vercel-ai-provider) and the repo root ship
Apache-2.0. The n8n node carried MIT from the n8n starter template.
LICENSE is now byte-identical to integrations/pi-agent-plugin/LICENSE.
eslint-plugin-n8n-nodes-base hard-codes MIT in
community-package-json-license-not-default, so that rule is disabled.
It is a starter-template convention, not a functional requirement: n8n
resolves and loads community packages without reading the license field,
and n8n's own node packages (n8n-nodes-base, @n8n/n8n-nodes-langchain)
publish as "SEE LICENSE IN LICENSE.md" rather than MIT.
The n8n node was the only integration without a `pnpm.overrides` block,
so its tree carried 9 advisories (7 high, 2 moderate) that
pi-agent-plugin, openclaw, and vercel-ai-sdk already pin out. Adds the
same block, scoped to the packages actually present in this tree
(`esbuild` and `undici` are not, so their sibling entries are omitted
rather than carried over as dead config).
Down to 2 from 9. Both remaining are GHSA-mh99-v99m-4gvg on the 1.x and
2.x brace-expansion lines, whose fix shipped only in 5.0.8 with no
backport. Forcing those lines to 5.x does clear the audit but breaks
`gulp build`: rimraf -> glob -> minimatch@9 imports brace-expansion as a
default export, which the 5.x ESM build does not provide.
Replacement ranges are capped per major rather than left open like the
siblings'. An unbounded `uuid >=11.1.1` resolves to 14.x, which is
pure ESM and cannot be required by n8n-workflow under Jest's CJS
runtime.
All dev-only: the published package still declares zero runtime
dependencies, so none of this reaches an installed node. lint, build,
and the 5 tests pass; `pnpm install --frozen-lockfile` is clean.
The unscoped `n8n-nodes-mem0` name is already taken on npm by an
unrelated publisher, so the CD workflow could never publish it. Move to
the `@mem0` scope, matching `@mem0/pi-agent-plugin` and
`@mem0/openclaw-mem0`, and add `publishConfig.access: public` since
scoped packages default to restricted.
n8n accepts scoped community packages: it strips the scope before
enforcing the `n8n-nodes-` prefix, the same shape as n8n's own
`@n8n/n8n-nodes-langchain`. Verified end to end on n8n 2.22.6 by
installing the packed tarball into the community-packages directory and
executing a workflow against node type `@mem0/n8n-nodes-mem0.mem0`.
The directory, workflow filenames, and the `n8n-nodes-mem0-v*` tag
prefix are unchanged. pnpm-lock.yaml needs no update: the pnpm v9 root
importer is anonymous and never recorded the package name.
- Telemetry: replace client-side PostHog (which read process.env, banned in
verified nodes) with first-party `source: "N8N"` attribution on API requests,
mirroring OpenClaw. Removes the undisclosed-collection concern entirely.
- Verification-scanner fixes: add credential icon, use NodeConnectionTypes.Main
instead of the 'main' literal, wrap error paths in NodeApiError, stop shipping
.d.ts / tsbuildinfo, and align the local eslint config with the scanner.
- Add offline unit tests (jest): entity-id guard, JSON-parse errors, poll-timeout
loop, source attribution, and Return All pagination.
- Get Many: add a Return All option that pages through all memories.
- Docs: README telemetry note and an AGENTS.md Key Directories row.
Verified: build + tsc + eslint + 5 unit tests + live E2E against api.mem0.ai, and
the packed tarball passes @n8n/scan-community-package with zero violations.