Commit Graph

42 Commits

Author SHA1 Message Date
harshgupta-mem0 d3d9cc9e26 fix(security): patch 8 HIGH + 18 MEDIUM Vanta vulnerabilities
Bumps three transitive packages across four pnpm workspaces via overrides.
Manifests and lockfiles only; no source changes.

  undici           7.28.0 -> 7.29.0   mem0-ts, openclaw, pi-agent-plugin
                   8.5.0  -> 8.10.0   pi-agent-plugin      (GHSA-4cwx-7wf7-3272 +4)
  ip-address       10.2.0 -> 10.4.0   mem0-ts              (GHSA-mwp4-54f8-5fhr +2)
  brace-expansion  2.1.2  -> 2.1.4    mem0-ts              (GHSA-rgw5-rvv9-x895,
                                                            GHSA-mh99-v99m-4gvg)
                   1.1.15 -> 1.1.18   zapier-mem0          (GHSA-3jxr-9vmj-r5cp)

Existing override keys were replaced in place rather than added alongside:
pnpm applies only the first override matching a bare package name, so a
stale broader key (e.g. undici@<6.27.0) would have shadowed a new narrower
one and silently held the vulnerable version.

Overrides are written to both package.json and pnpm-workspace.yaml because
openclaw, pi-agent-plugin and zapier-mem0 run pnpm 9 in CI, which reads
overrides only from package.json.

Verified: 26/41 open alerts clear against the regenerated lockfiles;
frozen-lockfile passes under each workspace's CI pnpm major; runtime API
smoke 7/7; mem0-ts 1505/1505, openclaw 446/446, pi-agent 100/100, zapier 17/17.

Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-critical?tab=results
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-high?tab=results
2026-08-07 17:22:49 +05:30
Himanshu 3f39fba28f fix(n8n): MIT license + themed icons for verified-node vetting (#6804)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-08-06 00:00:13 +05:30
Kartik 1112be3e5e chore(release): bump SDK, CLI, and plugin versions (#6800) 2026-08-05 00:16:26 +05:30
Himanshu b54710a3c3 fix(zapier): require user_id on Add Memory (#6790) 2026-08-04 18:49:35 +05:30
Himanshu 4cfa98f626 chore(n8n): route package contact to integrations@mem0.ai (#6791) 2026-08-04 17:39:20 +05:30
Himanshu 965140eb19 fix(zapier): add root index.js entry shim so deployed app resolves (#6789) 2026-08-04 12:48:46 +05:30
Kartik c90bdbdce0 feat(cli): Platform option parity across Python and Node CLIs (MEM-5893) (#6696) 2026-08-03 17:10:44 +05:30
Kartik 50bdaaea0c chore: bump versions and update changelog for Python 2.0.15, TypeScript 3.1.3, and plugin releases (#6715) 2026-08-01 20:26:31 +05:30
Kartik 07e58c54ae fix: align default model names with SDK defaults (#6704) 2026-08-01 01:30:57 +05:30
Harsh Vardhan Gupta 9c2d6222ce fix(security): patch 32 HIGH + 57 MEDIUM Vanta vulnerabilities across 6 pnpm workspaces (#6639)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-07-30 15:20:13 +05:30
Kartik 790e190486 chore(n8n): release 0.1.1 via CD for npm provenance (#6685) 2026-07-30 13:54:37 +05:30
Himanshu d4869d24ec feat(integrations): n8n community node for Mem0 (#6517)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-07-29 23:03:03 +05:30
Kartik 1ac3aa7256 fix(zapier): raise the add_memory poll budget past the real API latency tail (#6680) 2026-07-29 21:32:22 +05:30
Himanshu e168d48e04 feat(integrations): Zapier app for Mem0 (#6518)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-07-29 20:56:44 +05:30
Kartik ea2ee07586 chore: remove OpenMemory from the monorepo (#6530) 2026-07-29 15:10:32 +05:30
Kartik 5e7adc4d12 chore: update changelog, bump versions to Python 2.0.13, TypeScript 3.1.1, OpenCode plugin 0.2.2 (#6504) 2026-07-22 23:27:47 +05:30
Rod Boev b05cce581b fix(opencode-plugin): recover MEM0_API_KEY from shell profiles (#6404) 2026-07-20 20:41:41 +05:30
Kartik ccbe5861a1 docs: remove criteria retrieval docs for non-existent feature (#6282) 2026-07-14 20:06:05 +05:30
Kartik d6d2588ef5 fix(mem0-plugin): store assistant-authored summaries with role="assistant" (#6316) 2026-07-14 20:03:36 +05:30
Kartik 8488abe603 docs: correct custom categories, per-call custom_categories is supported (#6218) 2026-07-10 20:08:32 +05:30
Kartik 41c8f00851 chore(integrations): plugin updates, pi-agent auto-recall, and version bumps (#6011) 2026-07-01 20:57:32 +05:30
Kartik c325bd3b8e docs(changelog): consolidate per-package changelogs into the SDK changelog page (#6007) 2026-06-30 14:09:41 +05:30
Terrasse cc59d122db docs: remove instructions for unavailable Cursor marketplace plugin (#5971) 2026-06-29 20:35:07 +05:30
Harsh Vardhan Gupta bbbfcfea07 fix(deps): bump undici to >=6.27.0 (CVE-2026-12151) (#5861) 2026-06-26 15:32:09 +05:30
Rod Boev 1f66aadfa3 fix(openclaw): normalize Windows skill-loader URLs before fileURLToPath (#5679) 2026-06-25 16:36:11 +05:30
Kartik ac8f862ff7 fix(mem0-plugin): store files_touched as a list to stop double JSON-encoding (#5806) 2026-06-25 09:06:11 +05:30
Bartok ced4af681f fix(claude-plugin): rerank auto-injected memory context by default (#5690) 2026-06-23 16:52:35 +05:30
Harsh Vardhan Gupta ca86a164bd fix(pi-agent-plugin): resolve undici CVE-2026-9697 / CVE-2026-9678 (#5669) 2026-06-19 16:21:18 +05:30
Harsh Vardhan Gupta 1dcee153b9 fix(deps): patch js-yaml, ai, python-dotenv vulnerabilities (CVE-2026-53550, CVE-2025-48985, CVE-2026-28684) (#5641)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-18 17:13:15 +05:30
Harsh Vardhan Gupta 96b31c4bc0 fix(form-data): upgrade to >=4.0.6 across pnpm workspaces (CVE-2026-12143) (#5618)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-18 13:44:05 +05:30
ChrisFloofyKitsune 9ed1983b85 refactor(opencode): use existing mem0 SDK instead of delegating to MCP, load skills properly instead of dumping them in .opencode (#5323)
Co-authored-by: kartik-mem0 <kartik.labhshetwar@mem0.ai>
2026-06-17 21:18:39 +05:30
Harsh Vardhan Gupta 4492e75d04 fix(deps): bump esbuild >=0.28.1 across all npm packages (#5563)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-15 17:04:11 +05:30
Rod Boev 3951ad4705 fix(openclaw): reduce skills-mode triage prompt footprint (#5502) 2026-06-15 11:18:39 +05:30
Kartik 73c975ba68 chore: bump version to 0.1.3, update mem0ai to ^3.0.7, and adjust CHANGELOG (#5521) 2026-06-13 18:10:50 +05:30
Kartik 931d579ba5 chore(openclaw): release v1.0.13 and backfill v1.0.12 changelog (#5519) 2026-06-13 17:59:04 +05:30
Kartik f4773a0baf fix(mem0-plugin): accurate per-editor telemetry attribution + OpenCode telemetry (#5518) 2026-06-13 16:48:29 +05:30
mjzcng 821152bd14 Fix OpenClaw Mem0 custom categories payload (#5345)
Co-authored-by: Kartik <kartik.labhshetwar@mem0.ai>
2026-06-12 19:48:53 +05:30
Yufeng He b9ad8fa8b2 fix(openclaw): skip runtime setup during metadata registration (#5383) 2026-06-12 19:32:59 +05:30
Kartik f681889b14 fix(pi-agent-plugin): make command results visible and relevance-filtered (#5504) 2026-06-12 19:13:31 +05:30
Kartik b5ec46be5b fix(plugin): guard bare $USER refs in on_session_start.sh for Windows (#5492) 2026-06-12 19:13:19 +05:30
Harsh Vardhan Gupta 168ad358d5 fix(deps): resolve all open MEDIUM Dependabot alerts (npm overrides + Python pins) (#5489)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-12 15:15:26 +05:30
Kartik 2c796d144f refactor: consolidate agent/editor plugins under integrations/ (#5491)
Co-authored-by: Claude <noreply@anthropic.com>
2026-06-12 10:31:35 +05:30