Commit Graph

2631 Commits

Author SHA1 Message Date
Saket Aryan 7710a4e180 fix(plugins): publish the salt atomically, and omit the hash when there is none
Review finding from @kartik-mem0 on this PR.

O_CREAT|O_EXCL then write leaves a window where the salt file exists and is
empty. Hooks are short-lived processes firing on every tool call and people run
several agent windows, so a concurrent reader lands in that window, reads
nothing, and falls back to a digest of the salt file's own path, memoized for
its whole run. That path is guessable, so the race silently replaced the privacy
control with something an attacker can compute, and hashed the same repository
two ways depending on timing.

The value is now written to a private temp file, fsynced, and published with
os.link, which is atomic and fails if another process already published one.
Link rather than replace, so losing the race adopts their salt instead of
clobbering it. The temp file is removed either way.

The derived fallback is gone rather than fixed. _scoped_digest returns "" when
there is no salt and record() omits the property, because an unsalted digest
over a git remote or a home-directory path is close to plaintext, and shipping
one under a name that says hash is worse than sending nothing.

Three tests: the racing reader never sees the name half-written, a second writer
adopts the first's salt and leaves no temp file, and an unwritable data
directory drops the property instead of emitting a weak one. The old test
asserted the fallback behaviour and is replaced.

265 passed, 8 skipped.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-16 20:33:54 +05:30
Saket Aryan f8a9d524be docs(openclaw): correct the anonymity claim to match how it identifies events
The sweep in aa770aa6 deliberately left this page alone, reasoning that
hashing the email is materially different from sending it. Reading
integrations/openclaw/telemetry.ts does not support that: distinctId() is an
unsalted sha256 of the account email, and Mem0 holds the emails it is derived
from, so recovering the account is a table join. resolveEmail() also rewrites
already-queued events onto that id, and identifyAnonymous() fires a PostHog
$identify that merges the prior random id into it for good.

That is pseudonymous, not anonymous, and it is the same mismatch between the
stated privacy posture and the wire format that this stack exists to close.
The opt-out is unchanged and still correct.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-15 22:44:17 +05:30
Saket Aryan aa770aa652 docs(plugins): finish the telemetry sweep across the remaining surfaces
The first pass fixed the plugin README and the module docstring but left the
same claim standing everywhere else.

- docs/integrations/deepseek-plugin.mdx still said "Anonymous usage events".
  The TS SDK's telemetryId is the raw account email, so it is not anonymous.
- The pause skill told users a "minimal anonymous telemetry ping" fires while
  paused. Same ping, same email. Corrected in the template, which regenerates
  into all six hosts.
- integrations/zapier-mem0/README.md advertised telemetry the app does not have:
  there is no telemetry code in it at all. It now says what is actually true,
  that its requests carry source="ZAPIER".
- The data directory listing is presented as exhaustive and had gone stale
  against this stack's two new files, telemetry-salt and install-state.json.

Also replaced the property enumeration in both the README and the docs page.
Review pointed out it omitted the configured model name among others — writing
a fresh exhaustive list in a PR whose whole purpose is making docs match code
reproduces the defect being fixed. It now describes the shape and points at
where the rule is actually enforced, so it cannot drift again.

Deliberately unchanged: docs/integrations/openclaw.mdx. OpenClaw hashes the
email rather than sending it, which is materially different from the plugin and
the SDK, so its claim is not wrong in the same way.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-15 00:37:33 +05:30
Saket Aryan 95d4fc27e2 fix(plugins): make the telemetry salt stable, its own file, and memoized
Review found three ways the first cut produced worse data than no salt at all.
All three came from keeping the salt as a key in the identity dict and doing an
unlocked read-modify-write.

Hooks are short-lived separate processes firing on every tool call, and people
run more than one agent window, so several processes would read {}, each mint
its own uuid4, and each hash with it. One repository hashed several ways in the
window before a writer won.

resolve_distinct_id holds a copy of that same dict across a network call to
/v1/ping/ with a 5s timeout, so whichever write landed second erased the other's
key: losing the salt changes repo_hash mid-stream, losing the email fires a
second $identify and splits the person.

_write_identity swallows OSError, and nothing memoized, so on a read-only or
full data directory every single event got a brand-new random salt — unbounded
cardinality in PostHog, which is strictly worse than the unsalted value it
replaced.

The salt now lives in its own file claimed with O_CREAT|O_EXCL, so exactly one
process wins and the losers read the winner's value, and it is memoized per
process. When it cannot be persisted the fallback is derived from the data
directory path: stable for the machine rather than random per call.

Its own file also means record() no longer creates telemetry-identity.json as a
side effect. is_first_run keys off that file, so the first cut would have
silently suppressed the install event — a production metric change hidden in a
docs PR.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-15 00:25:12 +05:30
Saket Aryan 0d37619f24 fix(plugins): say what telemetry actually sends, and salt the hashes
The plugin README promises "anonymous usage events" and the telemetry module's
docstring says it sends only "salted hashes". Neither is true.

resolve_distinct_id() exchanges the API key for the account email and sends that
as the distinct_id on every event. Installing the plugin requires an API key, so
this is nearly every user. That is probably the behaviour we want — the Python
SDK and the CLI attribute the same way — but the description has to match it.

repo_hash and session_hash were unsalted SHA-256 cut to 16 hex characters.
repo.identity is a git remote URL, or `local:<absolute path>` when there is no
remote, which normally contains the account username. Sixteen unsalted hex
characters over that input space is enumerable, so the hash was not a privacy
control at all.

Salted per install, with the salt kept in the identity file. That preserves
every within-account join the analytics actually use and gives up only
cross-machine joins on the same repository, which nothing computes. Since the
distinct_id is already the email, the hash was never buying privacy from us —
only from whoever obtains the data later, which is exactly what the salt fixes.

Also corrects deepseek-plugin's README and source comment, which told readers
ZAPIER and STRANDS were already in the backend's KNOWN_EVENT_SOURCES allowlist.
Neither was.

Adds a Telemetry section to docs/integrations/claude-code.mdx, which had none.

Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
2026-09-15 00:17:26 +05:30
Harsh Vardhan Gupta c7ee362aff fix(security): resolve 12 Vanta/Dependabot vulnerabilities across 6 pnpm workspaces + poetry.lock (#7280)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-09-11 16:07:57 +05:30
Kartik d873892dad feat(plugins)!: make Sidekick exclusive to Claude Code (#7278) 2026-09-10 20:51:50 +05:30
Kartik 02f7a9b2c4 docs: align agent plugin guides with shared runtime behavior (#7269) opencode-v0.3.0 deepseek-plugin-v0.3.0 openclaw-v1.1.0 pi-agent-v0.3.0 2026-09-09 01:03:26 +05:30
Kartik 73e7b8763a refactor(integrations): shared agent plugin runtimes and native adapters (#7203) 2026-09-08 23:32:25 +05:30
Kartik dae67f74f5 fix(docs): SEO improvements for page titles, internal links, and URL structure (#7224) 2026-09-04 20:32:23 +05:30
Kartik 9a7924befd chore(release): bump Python and TypeScript SDK patch versions (#7210) v2.0.20 ts-v3.1.8 2026-09-02 18:44:55 +05:30
Kartik 3cf41878ea fix: replace PostHog evaluate_flags with static config for OSS notices (#7185) 2026-09-02 18:00:01 +05:30
Elif Sema Balcioglu c33ca27f5e docs: fix Oracle vector store setup and search examples (#7111) 2026-09-01 19:19:48 +05:30
Kartik 71fba8d464 feat(claude-code-plugin): move the Claude Code plugin to its own integration and ship it as 0.3.0 (#7106) 2026-09-01 02:34:45 +05:30
Kartik 19cb89aff4 docs: add 301 redirects for 49 legacy 404 pages (#7161) 2026-08-28 17:44:10 +05:30
Karthik fdfb763d6e docs(api-reference): add Dream (memory synthesis) endpoints (#7109)
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-27 22:12:04 +05:30
Kartik 0070e08e01 feat(deepseek-plugin,mem0-strands): add usage telemetry (#7110) mem0-strands-v0.1.1 deepseek-plugin-v0.1.1 2026-08-27 13:48:30 +05:30
Himanshu 39bc023305 docs(integrations): add Vercel Marketplace (managed) integration page (#7100) mem0-strands-v0.1.0 2026-08-24 22:22:04 +05:30
krishna soni b1342a3408 refactor: replace custom validator with Pydantic extra="forbid" config (#7089) 2026-08-24 21:17:57 +05:30
Kartik b717e38785 refactor(integrations): rename dsh-mem0 to deepseek-plugin, strands-mem0 to mem0-strands (#7098) deepseek-plugin-v0.1.0 2026-08-24 19:21:23 +05:30
Indian-boult dc82354e14 docs(skills): fix dead links in skills READMEs (#7092) vercel-ai-v3.0.2 n8n-nodes-mem0-v0.1.4 cli-node-v0.2.13 cli-v0.2.12 v2.0.19 ts-v3.1.7 openclaw-v1.0.16 pi-agent-v0.1.5 2026-08-24 18:25:33 +05:30
Kartik 4ddee9c51d chore(release): bump SDK, CLI, and plugin versions; add Strands, DeepSeek Harness, and Kimi changelogs (#7097) 2026-08-24 18:10:44 +05:30
Himanshu 7e09615571 feat(integrations): dsh-mem0 — Mem0 as a native DeepSeek Harness plugin (#7027)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-08-24 14:03:50 +05:30
Kartik d18e751dec docs: redirect five dead api-reference paths to their real pages (#7094) 2026-08-24 13:53:04 +05:30
Himanshu 8d5b7865bd feat(integrations): strands-mem0 | Mem0 as a native Strands MemoryStore (#7021) 2026-08-22 19:04:24 +05:30
Abhinav Singh 9b565da8e3 docs(embedders): document api_key on the Hugging Face Python config table (#7045) 2026-08-22 13:51:50 +05:30
Yiheng Zhao 48d0d0cd9c fix(docs): balance code fences in cookbook_template.mdx (#7054) 2026-08-22 13:50:49 +05:30
Kartik feb12852c0 fix(docs): redirect the eight 404 paths and repair dead wildcard rules (#7053) 2026-08-21 19:31:37 +05:30
Harsh Vardhan Gupta 5af797834c fix(security): resolve 17 Vanta/Dependabot HIGH+CRITICAL vulnerabilities across 5 pnpm workspaces (#7032) 2026-08-21 17:41:41 +05:30
Kartik 4fa4839077 fix(ci): make the vouch check speak, unblock list updates, widen the docs exemption (#6974) 2026-08-20 23:13:42 +05:30
Kartik 3599aa75ed docs: document the real search filter grammar (#6906) 2026-08-20 21:33:21 +05:30
Himanshu 1de6499b8a fix(integrations/zapier): address Zapier publishing review (#6985) 2026-08-20 18:53:06 +05:30
Kartik ed38ddf873 fix(python): huggingface TEI auth, procedural-memory content handling, and proxy pip auto-install (#6947) 2026-08-20 15:56:55 +05:30
Kartik 530d802b55 fix(plugins): bug-bash fixes for Cursor, Codex, Antigravity, and a Claude.ai docs page (#6948) 2026-08-20 15:56:17 +05:30
Kartik d3334fa5f1 docs: ground the platform/OSS comparison and memory-type status in reality (#6908) 2026-08-20 15:26:22 +05:30
Kartik 52b02c7cc1 docs: fix Claude Desktop MCP setup, CrewAI guide, and missing contributor docs (#6945) 2026-08-20 15:24:05 +05:30
mintlify[bot] 001c235229 Fix broken links: remove duplicate reranking redirect (#6975)
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
2026-08-14 12:47:17 +00:00
Kartik bf2d591b27 docs: remove Controlling Memory Ingestion cookbook, redirect to Custom Instructions (#6955) 2026-08-14 18:16:36 +05:30
Kartik b4c50550bf docs: correct client call shape and stale v1 response examples (#6901) 2026-08-14 18:13:37 +05:30
Kartik 290de24bb8 feat(ci): gate pull requests on an accepted issue (#6894) 2026-08-14 17:05:27 +05:30
Ratish jain ef6f51d977 fix(tests): check for RediSearch module availability in Redis tests (#6687) 2026-08-14 17:00:56 +05:30
Kartik a10c0cd030 fix(mem0-plugin): stop search errors from looking like empty results (#6898) 2026-08-14 16:57:01 +05:30
Kartik 956bf4f88e fix(ts-oss): return snake_case entity ids from the redis and valkey stores (#6902) 2026-08-14 16:56:27 +05:30
Kartik 0f172c2890 fix(ts-oss): stop prototype keys from short-circuiting embedding lookup (#6903) 2026-08-14 16:56:03 +05:30
Kartik 696455fd62 docs: contrast the advanced retrieval modes with distinct examples (#6904) 2026-08-14 16:55:44 +05:30
Kartik 9e99eaadbc docs: correct memory decay claims that contradict the SDK (#6905) 2026-08-14 16:55:26 +05:30
Kartik 02ff6c5595 feat(cli): add a version subcommand and document the --filter JSON shape (#6907) 2026-08-14 16:55:12 +05:30
Kartik a0329f047b docs(cookbooks): repair dead references and label OSS vs Platform support (#6909) 2026-08-14 16:50:46 +05:30
Kartik c50a2bfb8f docs(llms): fix wrong read snippets, dead reranking link, and 24 mis-scoped integration tags (#6950) 2026-08-14 16:50:23 +05:30
Kartik bfb51c6b93 fix(client): honor page_size in get_all when page is not passed (#6900) 2026-08-14 16:49:58 +05:30