Bumps three transitive packages across four pnpm workspaces via overrides.
Manifests and lockfiles only; no source changes.
undici 7.28.0 -> 7.29.0 mem0-ts, openclaw, pi-agent-plugin
8.5.0 -> 8.10.0 pi-agent-plugin (GHSA-4cwx-7wf7-3272 +4)
ip-address 10.2.0 -> 10.4.0 mem0-ts (GHSA-mwp4-54f8-5fhr +2)
brace-expansion 2.1.2 -> 2.1.4 mem0-ts (GHSA-rgw5-rvv9-x895,
GHSA-mh99-v99m-4gvg)
1.1.15 -> 1.1.18 zapier-mem0 (GHSA-3jxr-9vmj-r5cp)
Existing override keys were replaced in place rather than added alongside:
pnpm applies only the first override matching a bare package name, so a
stale broader key (e.g. undici@<6.27.0) would have shadowed a new narrower
one and silently held the vulnerable version.
Overrides are written to both package.json and pnpm-workspace.yaml because
openclaw, pi-agent-plugin and zapier-mem0 run pnpm 9 in CI, which reads
overrides only from package.json.
Verified: 26/41 open alerts clear against the regenerated lockfiles;
frozen-lockfile passes under each workspace's CI pnpm major; runtime API
smoke 7/7; mem0-ts 1505/1505, openclaw 446/446, pi-agent 100/100, zapier 17/17.
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-critical?tab=results
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-high?tab=results
Mem0 - The Memory Layer for Your AI Apps
Mem0 is a self-improving memory layer for LLM applications, enabling personalized AI experiences that save costs and delight users. We offer both cloud and open-source solutions to cater to different needs.
See the complete OSS Docs. See the complete Platform API Reference.
1. Installation
For the open-source version, you can install the Mem0 package using npm:
npm i mem0ai
2. API Key Setup
For the cloud offering, sign in to Mem0 Platform to obtain your API Key.
3. Client Features
Cloud Offering
The cloud version provides a comprehensive set of features, including:
- Memory Operations: Perform CRUD operations on memories.
- Search Capabilities: Search for relevant memories using advanced filters.
- Memory History: Track changes to memories over time.
- Error Handling: Robust error handling for API-related issues.
- Async/Await Support: All methods return promises for easy integration.
Open-Source Offering
The open-source version includes the following top features:
- Memory Management: Add, update, delete, and retrieve memories.
- Vector Store Integration: Supports various vector store providers for efficient memory retrieval.
- LLM Support: Integrates with multiple LLM providers for generating responses.
- Customizable Configuration: Easily configure memory settings and providers.
- SQLite Storage: Use SQLite for memory history management.
4. Memory Operations
Mem0 provides a simple and customizable interface for performing memory operations. You can create long-term and short-term memories, search for relevant memories, and manage memory history.
5. Error Handling
The MemoryClient throws errors for any API-related issues. You can catch and handle these errors effectively.
6. Using with async/await
All methods of the MemoryClient return promises, allowing for seamless integration with async/await syntax.
7. Testing the Client
To test the MemoryClient in a Node.js environment, you can create a simple script to verify the functionality of memory operations.
Getting Help
If you have any questions or need assistance, please reach out to us:
- Email: founders@mem0.ai
- Join our discord community
- GitHub Issues: Report bugs or request features