Files
mem0/mem0-ts
harshgupta-mem0 d3d9cc9e26 fix(security): patch 8 HIGH + 18 MEDIUM Vanta vulnerabilities
Bumps three transitive packages across four pnpm workspaces via overrides.
Manifests and lockfiles only; no source changes.

  undici           7.28.0 -> 7.29.0   mem0-ts, openclaw, pi-agent-plugin
                   8.5.0  -> 8.10.0   pi-agent-plugin      (GHSA-4cwx-7wf7-3272 +4)
  ip-address       10.2.0 -> 10.4.0   mem0-ts              (GHSA-mwp4-54f8-5fhr +2)
  brace-expansion  2.1.2  -> 2.1.4    mem0-ts              (GHSA-rgw5-rvv9-x895,
                                                            GHSA-mh99-v99m-4gvg)
                   1.1.15 -> 1.1.18   zapier-mem0          (GHSA-3jxr-9vmj-r5cp)

Existing override keys were replaced in place rather than added alongside:
pnpm applies only the first override matching a bare package name, so a
stale broader key (e.g. undici@<6.27.0) would have shadowed a new narrower
one and silently held the vulnerable version.

Overrides are written to both package.json and pnpm-workspace.yaml because
openclaw, pi-agent-plugin and zapier-mem0 run pnpm 9 in CI, which reads
overrides only from package.json.

Verified: 26/41 open alerts clear against the regenerated lockfiles;
frozen-lockfile passes under each workspace's CI pnpm major; runtime API
smoke 7/7; mem0-ts 1505/1505, openclaw 446/446, pi-agent 100/100, zapier 17/17.

Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-critical?tab=results
Fixes: https://app.vanta.com/c/mem0.ai/tests/packages-checked-for-vulnerabilities-v2-records-closed-github-dependabot-high?tab=results
2026-08-07 17:22:49 +05:30
..
2025-02-27 15:19:17 -08:00
2025-02-27 15:19:17 -08:00

Mem0 - The Memory Layer for Your AI Apps

Mem0 is a self-improving memory layer for LLM applications, enabling personalized AI experiences that save costs and delight users. We offer both cloud and open-source solutions to cater to different needs.

See the complete OSS Docs. See the complete Platform API Reference.

1. Installation

For the open-source version, you can install the Mem0 package using npm:

npm i mem0ai

2. API Key Setup

For the cloud offering, sign in to Mem0 Platform to obtain your API Key.

3. Client Features

Cloud Offering

The cloud version provides a comprehensive set of features, including:

  • Memory Operations: Perform CRUD operations on memories.
  • Search Capabilities: Search for relevant memories using advanced filters.
  • Memory History: Track changes to memories over time.
  • Error Handling: Robust error handling for API-related issues.
  • Async/Await Support: All methods return promises for easy integration.

Open-Source Offering

The open-source version includes the following top features:

  • Memory Management: Add, update, delete, and retrieve memories.
  • Vector Store Integration: Supports various vector store providers for efficient memory retrieval.
  • LLM Support: Integrates with multiple LLM providers for generating responses.
  • Customizable Configuration: Easily configure memory settings and providers.
  • SQLite Storage: Use SQLite for memory history management.

4. Memory Operations

Mem0 provides a simple and customizable interface for performing memory operations. You can create long-term and short-term memories, search for relevant memories, and manage memory history.

5. Error Handling

The MemoryClient throws errors for any API-related issues. You can catch and handle these errors effectively.

6. Using with async/await

All methods of the MemoryClient return promises, allowing for seamless integration with async/await syntax.

7. Testing the Client

To test the MemoryClient in a Node.js environment, you can create a simple script to verify the functionality of memory operations.

Getting Help

If you have any questions or need assistance, please reach out to us: