Files
mem0/integrations/openclaw/package.json
T
harshgupta-mem0 d3d9cc9e26 fix(security): patch 8 HIGH + 18 MEDIUM Vanta vulnerabilities
Bumps three transitive packages across four pnpm workspaces via overrides.
Manifests and lockfiles only; no source changes.

  undici           7.28.0 -> 7.29.0   mem0-ts, openclaw, pi-agent-plugin
                   8.5.0  -> 8.10.0   pi-agent-plugin      (GHSA-4cwx-7wf7-3272 +4)
  ip-address       10.2.0 -> 10.4.0   mem0-ts              (GHSA-mwp4-54f8-5fhr +2)
  brace-expansion  2.1.2  -> 2.1.4    mem0-ts              (GHSA-rgw5-rvv9-x895,
                                                            GHSA-mh99-v99m-4gvg)
                   1.1.15 -> 1.1.18   zapier-mem0          (GHSA-3jxr-9vmj-r5cp)

Existing override keys were replaced in place rather than added alongside:
pnpm applies only the first override matching a bare package name, so a
stale broader key (e.g. undici@<6.27.0) would have shadowed a new narrower
one and silently held the vulnerable version.

Overrides are written to both package.json and pnpm-workspace.yaml because
openclaw, pi-agent-plugin and zapier-mem0 run pnpm 9 in CI, which reads
overrides only from package.json.

Verified: 26/41 open alerts clear against the regenerated lockfiles;
frozen-lockfile passes under each workspace's CI pnpm major; runtime API
smoke 7/7; mem0-ts 1505/1505, openclaw 446/446, pi-agent 100/100, zapier 17/17.

Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-critical?tab=results
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-high?tab=results
2026-08-07 17:22:49 +05:30

82 lines
1.8 KiB
JSON

{
"name": "@mem0/openclaw-mem0",
"version": "1.0.15",
"type": "module",
"description": "Mem0 memory backend for OpenClaw — platform or self-hosted open-source",
"license": "Apache-2.0",
"repository": {
"type": "git",
"url": "https://github.com/mem0ai/mem0",
"directory": "integrations/openclaw"
},
"keywords": [
"openclaw",
"plugin",
"memory",
"mem0",
"long-term-memory"
],
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
"exports": {
".": {
"types": "./dist/index.d.ts",
"import": "./dist/index.js"
}
},
"files": [
"dist",
"openclaw.plugin.json",
"skills"
],
"scripts": {
"build": "tsup",
"test": "vitest run"
},
"dependencies": {
"@sinclair/typebox": "0.34.47",
"mem0ai": "3.0.7"
},
"openclaw": {
"extensions": [
"./dist/index.js"
],
"compat": {
"pluginApi": ">=2026.4.24",
"minGatewayVersion": ">=2026.4.24"
},
"build": {
"openclawVersion": "2026.4.24",
"pluginSdkVersion": "2026.4.24"
},
"install": {
"npmSpec": "@mem0/openclaw-mem0"
}
},
"devDependencies": {
"@qdrant/js-client-rest": "^1.18.0",
"@types/node": "^22.15.0",
"@vitest/coverage-v8": "^4.1.7",
"tsup": "^8.5.0",
"typescript": "^5.8.3",
"vite": "^8.0.5",
"vitest": "^4.1.7"
},
"pnpm": {
"overrides": {
"form-data@<4.0.6": ">=4.0.6",
"protobufjs@<7.6.5": ">=7.6.5 <8.0.0",
"vite": "^8.0.5",
"langsmith@<0.6.0": "^0.6.0",
"picomatch@<2.3.2": "^2.3.2",
"@qdrant/js-client-rest": "^1.18.0",
"uuid@<11.1.1": ">=11.1.1",
"esbuild": ">=0.28.1",
"undici@<7.29.0": ">=7.29.0 <8.0.0",
"axios@<1.18.0": ">=1.18.0 <2.0.0",
"postcss@<8.5.18": ">=8.5.18 <9.0.0",
"mongoose@>=9.0.0 <9.7.2": ">=9.7.2 <10.0.0"
}
}
}