d3d9cc9e26
Bumps three transitive packages across four pnpm workspaces via overrides.
Manifests and lockfiles only; no source changes.
undici 7.28.0 -> 7.29.0 mem0-ts, openclaw, pi-agent-plugin
8.5.0 -> 8.10.0 pi-agent-plugin (GHSA-4cwx-7wf7-3272 +4)
ip-address 10.2.0 -> 10.4.0 mem0-ts (GHSA-mwp4-54f8-5fhr +2)
brace-expansion 2.1.2 -> 2.1.4 mem0-ts (GHSA-rgw5-rvv9-x895,
GHSA-mh99-v99m-4gvg)
1.1.15 -> 1.1.18 zapier-mem0 (GHSA-3jxr-9vmj-r5cp)
Existing override keys were replaced in place rather than added alongside:
pnpm applies only the first override matching a bare package name, so a
stale broader key (e.g. undici@<6.27.0) would have shadowed a new narrower
one and silently held the vulnerable version.
Overrides are written to both package.json and pnpm-workspace.yaml because
openclaw, pi-agent-plugin and zapier-mem0 run pnpm 9 in CI, which reads
overrides only from package.json.
Verified: 26/41 open alerts clear against the regenerated lockfiles;
frozen-lockfile passes under each workspace's CI pnpm major; runtime API
smoke 7/7; mem0-ts 1505/1505, openclaw 446/446, pi-agent 100/100, zapier 17/17.
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-critical?tab=results
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-high?tab=results
82 lines
1.8 KiB
JSON
82 lines
1.8 KiB
JSON
{
|
|
"name": "@mem0/openclaw-mem0",
|
|
"version": "1.0.15",
|
|
"type": "module",
|
|
"description": "Mem0 memory backend for OpenClaw — platform or self-hosted open-source",
|
|
"license": "Apache-2.0",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "https://github.com/mem0ai/mem0",
|
|
"directory": "integrations/openclaw"
|
|
},
|
|
"keywords": [
|
|
"openclaw",
|
|
"plugin",
|
|
"memory",
|
|
"mem0",
|
|
"long-term-memory"
|
|
],
|
|
"main": "./dist/index.js",
|
|
"types": "./dist/index.d.ts",
|
|
"exports": {
|
|
".": {
|
|
"types": "./dist/index.d.ts",
|
|
"import": "./dist/index.js"
|
|
}
|
|
},
|
|
"files": [
|
|
"dist",
|
|
"openclaw.plugin.json",
|
|
"skills"
|
|
],
|
|
"scripts": {
|
|
"build": "tsup",
|
|
"test": "vitest run"
|
|
},
|
|
"dependencies": {
|
|
"@sinclair/typebox": "0.34.47",
|
|
"mem0ai": "3.0.7"
|
|
},
|
|
"openclaw": {
|
|
"extensions": [
|
|
"./dist/index.js"
|
|
],
|
|
"compat": {
|
|
"pluginApi": ">=2026.4.24",
|
|
"minGatewayVersion": ">=2026.4.24"
|
|
},
|
|
"build": {
|
|
"openclawVersion": "2026.4.24",
|
|
"pluginSdkVersion": "2026.4.24"
|
|
},
|
|
"install": {
|
|
"npmSpec": "@mem0/openclaw-mem0"
|
|
}
|
|
},
|
|
"devDependencies": {
|
|
"@qdrant/js-client-rest": "^1.18.0",
|
|
"@types/node": "^22.15.0",
|
|
"@vitest/coverage-v8": "^4.1.7",
|
|
"tsup": "^8.5.0",
|
|
"typescript": "^5.8.3",
|
|
"vite": "^8.0.5",
|
|
"vitest": "^4.1.7"
|
|
},
|
|
"pnpm": {
|
|
"overrides": {
|
|
"form-data@<4.0.6": ">=4.0.6",
|
|
"protobufjs@<7.6.5": ">=7.6.5 <8.0.0",
|
|
"vite": "^8.0.5",
|
|
"langsmith@<0.6.0": "^0.6.0",
|
|
"picomatch@<2.3.2": "^2.3.2",
|
|
"@qdrant/js-client-rest": "^1.18.0",
|
|
"uuid@<11.1.1": ">=11.1.1",
|
|
"esbuild": ">=0.28.1",
|
|
"undici@<7.29.0": ">=7.29.0 <8.0.0",
|
|
"axios@<1.18.0": ">=1.18.0 <2.0.0",
|
|
"postcss@<8.5.18": ">=8.5.18 <9.0.0",
|
|
"mongoose@>=9.0.0 <9.7.2": ">=9.7.2 <10.0.0"
|
|
}
|
|
}
|
|
}
|