Skip to content

Releases: Avinash-jetwani/jevmem

v0.6.3

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 01 Oct 07:55

Fixes to what you see on the pages and in jevmem doctor. Nothing changes in what is saved, recalled or checked.

  • jevmem doctor shows the plugin synced from claude.ai once, its newest copy. Claude Code lands a plugin update beside the copy a session runs (<id>~g<N>/ next to <id>/) and moves the older one aside soon after; while both were there, doctor showed 0.5.7 and 0.6.2, which read as two plugins. One line per plugin now: the copy Claude Code loads.
  • A known limit, stated (Honest limits, docs/guardrails.md): when the plugin synced from claude.ai updates, Claude Code moves the previous copy aside, and a session that was already open with it loses jevmem's hooks, the guard included, until you run /reload-plugins there or start a new session (anthropics/claude-code#97847). Claude Code shows a hook error and goes on without them.
  • Upgrade notes for the directory's plugin: Claude Code downloads plugin updates in the background each time it starts, and an open session says Plugins changed. Run /reload-plugins to activate.; jevmem doctor shows which plugin version is on disk. If it still shows the old one, start claude once in a terminal, signed in with the same Claude account as the app.
  • scripts/eval.mjs records the version of the build it measured, not the checkout's. results/eval-heldout-2026-09-30-v059.json, the npm 0.5.9 package run from the 0.6.0 checkout, says 0.6.0; the old files and the note in results/README.md stay as they are.
  • README "What's new" leads with 0.6's features, then the 0.6.1 and 0.6.2 guard fix and this patch.
  • Measured: end to end with Claude Code 2.1.284 and the real Jev on this build, scripts/e2e.sh --runs 3 --scenario full: linkguard (automemory=keep) 3/3; handwrite (automemory=keep) 3/3; plugin (automemory=keep) 3/3; dormant 3/3; nocli 3/3; nokey (init hooks) 3/3; nokey (plugin hooks) 3/3; nokey 3/3; outage 3/3; guard 3/3; guardgit 3/3; deadend 3/3; supersede 3/3 (results/e2e-2026-09-30-v063-full.txt).

Upgrade: npm install -g jevmem@latest. Plugin users too: the plugin runs this CLI, and the 0.6.3 plugin warns once about an older one. From 0.6.0, 0.6.1 or 0.6.2 that is the whole upgrade; from 0.5.x, the 0.6 upgrade notes.

Full notes: CHANGELOG, 0.6.3

v0.6.2

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 30 Sep 15:15

The same code as 0.6.1, published again. npm didn't list 0.6.1 for a time after its release, and a second publish was refused, so 0.6.2 went out. npm lists both now.

  • 0.6.0's guard skipped a Bash call with if [ … ], while [ … ] or until [ … ] in it. The check threw on the [ and the hook stayed silent, so such a call ran unchecked: if [ -f x ]; then git push origin directory; fi got no ask under a rule against pushing to that branch, where true && git push origin directory was asked about (Jev 0.97). [ as the command itself ([ -f x ] && …) was never affected. jevmem doctor listed each such failed check; nothing else said anything.
  • The shell reader knows the shell's reserved words, so [ and [[ after if, while or until are the test command; a glob becomes a regular expression through one function that escapes everything and never throws; and a part of the check that fails (the tamper check, the prefilter, the git expansion) is logged while the other parts still decide.
  • Measured (docs/guardrails.md): the guard's held-out v2 set (274 calls) on this code: violations caught 66/68 and the tamper check right 274/274, as on 0.6.0; false asks 3–4 of 206 across the two runs (one call, git add token.secret.example, went from 0.52 to 0.47: Jev's variation between runs, not the fix). The dev sets: row for row as on 0.6.0. The three unchecked calls and if [ -f x ]; then git push origin directory; fi are in the shell dev set now, the last asked about at 0.94. End to end with Claude Code 2.1.284 and the real Jev, on the 0.6.1 build and again on this one: linkguard (automemory=keep) 3/3; handwrite (automemory=keep) 3/3; plugin (automemory=keep) 3/3; dormant 3/3; nocli 3/3; nokey (init hooks) 3/3; nokey (plugin hooks) 3/3; nokey 3/3; outage 3/3; guard 3/3; guardgit 3/3; deadend 3/3; supersede 3/3.
  • The release checklist now waits for npm: a release is not done until npm view shows the new version, and no npm write from anywhere until then.

Upgrade: npm install -g jevmem@latest. Plugin users too: the plugin runs this CLI. From 0.6.0 that is the whole upgrade; from 0.5.x, the 0.6 upgrade notes.

Full notes: CHANGELOG, 0.6.2 and 0.6.1

v0.6.1

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 30 Sep 13:26

A guard fix. 0.6.0's guard let a Bash call through unchecked when the command had if [ … ], while [ … ] or until [ … ] in it: the check threw on the [ and the hook stayed silent. Found in 0.6.0's own release session, three calls in.

  • A call with if [ … ], while [ … ] or until [ … ] in it ran unchecked. if [ -f x ]; then git push origin directory; fi got no ask under a rule against pushing to that branch, where true && git push origin directory was asked about (Jev 0.97). [ as the command itself ([ -f x ] && …) was never affected. jevmem doctor listed each such failed check; nothing else said anything.
  • The shell reader knows the shell's reserved words, so [ and [[ after if, while or until are the test command; a glob becomes a regular expression through one function that escapes everything and never throws; and a part of the check that fails (the tamper check, the prefilter, the git expansion) is logged while the other parts still decide.
  • Measured (docs/guardrails.md): the guard's held-out v2 set (274 calls) on this build: violations caught 66/68 and the tamper check right 274/274, as on 0.6.0; false asks 3–4 of 206 across the two runs (one call, git add token.secret.example, went from 0.52 to 0.47: Jev's variation between runs, not the fix). The dev sets: row for row as on 0.6.0. The three unchecked calls and if [ -f x ]; then git push origin directory; fi are in the shell dev set now, the last asked about at 0.94. End to end with Claude Code 2.1.284 and the real Jev: linkguard (automemory=keep) 3/3; handwrite (automemory=keep) 3/3; plugin (automemory=keep) 3/3; dormant 3/3; nocli 3/3; nokey (init hooks) 3/3; nokey (plugin hooks) 3/3; nokey 3/3; outage 3/3; guard 3/3; guardgit 3/3; deadend 3/3; supersede 3/3.

Upgrade: npm install -g jevmem@latest. Plugin users too: the plugin runs this CLI. From 0.6.0 that is the whole upgrade; from 0.5.x, the 0.6 upgrade notes.

Full notes: CHANGELOG, 0.6.1

v0.6.0

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 30 Sep 13:26

Superseded by 0.6.1 the same day: 0.6.0's guard skipped a Bash call with if [ … ], while [ … ] or until [ … ] in it. Install 0.6.1 (npm install -g jevmem@latest); this entry is kept for the record.

What 0.6.0 brought:

  • The guard. A PreToolUse hook checks each Bash, Edit and Write call against your saved [constraint] rules before it runs, and has Claude Code ask you (or blocks the call) when Jev says one may be broken; it reads a command line the way the shell does (docs/guardrails.md).
  • Dead ends. An approach that was tried and failed is saved with its reason and put in front of Claude as "Already tried: …"; a later turn that shows it works now supersedes it (docs/dead-ends.md).
  • Recall measured and changed. Every live line is asked about, each on its own; a slow or failed Jev call means word-match lines, not no memory.
  • Background subagents. A turn with a subagent in the background is decided once, when it is over, and the subagent's report is never read as your message.
  • The line. A saved line is made from the sentences Jev picks, the one that states the memory and the one that gives its reason; a genuine rule is no longer skipped as an injection.
  • Also: the message when jevmem saves its first line in a project, the MCP Registry entry (server.json), and the fixes in the CHANGELOG. The 66-turn benchmark in every mode: auto 98.5% save/skip, as 0.5.9 and v0.4.2, at $0.000157 per decision.

Upgrade: for each install path, README: What's new in 0.6; then npm install -g jevmem@latest for 0.6.1.

Full notes: CHANGELOG, 0.6.0

v0.5.10

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 29 Sep 15:54

Clearer setup for installs from the Claude plugin directory (jevmem@synced); no change to what is saved or recalled.

  • jevmem key saves your TypeSafe key to ~/.jevmem/env. It asks for the key without showing it, makes the folder and the file readable only by you, and asks before replacing a saved key. It works for every install: the plugin from the Claude plugin directory, one from a marketplace, and the hooks jevmem init registers.
  • A missing key is no longer silent. In an enabled project with no key, the first prompt says what is missing, where jevmem looks, and the fix, jevmem key. jevmem stats and jevmem doctor now say how many prompts and finished turns were skipped for want of a key, instead of "2 call(s), 0 ok".
  • jevmem doctor sees the plugin from the Claude plugin directory, and jevmem enable gives one next step. The key advice offers /plugin configure jevmem only for a plugin installed from a marketplace: the directory's jevmem@synced has no key setting.
  • A key saved or replaced while the warm daemon runs is used from the next prompt.

Setting up from the Claude plugin directory: the steps.

Upgrade: npm install -g jevmem@latest. Plugin users too: the plugin runs this CLI.

Full notes: CHANGELOG, 0.5.10

v0.5.9

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 28 Sep 11:58

Docs only: README, SECURITY and PRIVACY brought up to date; no code changes. npm's page now shows the current README, including 0.5.8's security fix (advisory GHSA-2r3p-5hmg-46p5).

Upgrade: npm install -g jevmem@latest

Full notes: CHANGELOG, 0.5.9

v0.5.8

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 28 Sep 10:51
  • Secrets with names like PGPASSWORD= were not scrubbed. In 0.5.7 and earlier, a prompt or turn with PGPASSWORD=…, MYSQLPWD=… or "password": "…" in it was sent to TypeSafe with the value as written. If you used jevmem in an enabled project and your chats contained such lines, rotate those credentials.
  • Some turns ending in KEY=value were dropped without a message. From v0.1.0 to 0.5.7 the request failed before it was sent, so nothing was sent and the turn was not saved.
  • The MCP server didn't read the key files (~/.jevmem/env, <project>/.jevmem/.env), which affected Codex setups: search, add and audit answered "TYPESAFE_API_KEY is not set".

Upgrade: npm install -g jevmem@latest. Plugin users too: the plugin runs this CLI.

Full notes: CHANGELOG, 0.5.8

v0.5.7

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 26 Sep 13:29

A privacy page for the directory listing. No change to the CLI's or the plugin's behaviour.

Added

  • PRIVACY.md. Who makes jevmem (no server, nothing sent to the author, no telemetry), what leaves the machine and where (TypeSafe AI's https://api.typesafe.ai/v1/systemone; OpenAI or Anthropic only when writer in jevmem.config.json chooses them), the best-effort secret scrubbing, links to TypeSafe's, OpenAI's and Anthropic's privacy policies and terms, what is stored where, how to delete it, and how to get in touch. The directory portal warned "No privacy policy URL found".
  • plugin/README.md has a "Privacy" link to it; the main README and SECURITY.md link to it too. The link check and check-claims now cover PRIVACY.md, and the npm package includes it.
  • test/network.test.ts checks the source for any network call other than the TypeSafe client and the OpenAI or Anthropic writer: no HTTP, socket or fetch library, node:net only for the daemon's local socket, the global fetch only in the writer, the MCP server on stdio only, and a TypeSafe SDK that names only https://api.typesafe.ai.

Not added

  • privacyPolicyUrl in plugin.json. claude plugin validate --strict plugin with Claude Code 2.1.274 rejects it ("Unknown field 'privacyPolicyUrl'"). Claude Code 2.1.281 accepts it, and also supportUrl, documentationUrl and termsOfServiceUrl, which the manifest reference doesn't list yet. The README link is the portal's other accepted form.

v0.5.6

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 26 Sep 13:06

The plugin finds the jevmem CLI in the usual places again, and in an enabled project it tells you when it can't. No change to the CLI's behaviour.

Fixed

  • The CLI is found in the usual places again. v0.5.5 found the CLI only with command -v jevmem or its cached path, so a desktop-app session whose PATH lacked jevmem did nothing and said nothing. The launcher now looks, in order: command -v jevmem, the cached path, /opt/homebrew/bin, /usr/local/bin, ~/.local/bin, ~/.volta/bin, then the newest Node version under ~/.nvm/versions/node that has jevmem. It caches what it finds and still runs no package manager. ~/.bun/bin is left out: its name reads as a package manager to scripts/check-plugin.mjs. Choosing the newest nvm version now compares version numbers (v22 above v9); the old text sort, also used to find Node, did not.
  • A message instead of silence. In an enabled project with no CLI, the UserPromptSubmit hook shows "jevmem: CLI not found, so memory is off in this project. See the jevmem README to set it up" (a systemMessage, with a link), once per session. The Stop hook stays silent. A CLI with no Node 20+ to run it gets the same, with "Node.js 20 or newer not found". A project that isn't enabled still gets no output at all (tested).

Changed

  • As a process, the plugin's Stop launcher took 14 ms p50 against 12 ms for the init launcher in the same run, and 15 ms on a bare PATH with the CLI found in ~/.local/bin and then cached (results/ops-2026-09-26-v056.json).
  • plugin.json sets displayName to jevmem, so the directory shows the lowercase name. The manifest has no field for support, issues or privacy links; homepage (the manifest's documentation URL) already points at the README.
  • The READMEs and docs/hooks.md no longer say to start Claude Code once from a terminal, and say what happens when the CLI is missing.

v0.5.5

Choose a tag to compare

@Avinash-jetwani Avinash-jetwani released this 26 Sep 12:29

The plugin folder no longer contains an install command or any package-manager wording, and jevmem has its icon and brand files. No change to the CLI's behaviour.

Changed

  • No install text in plugin/. The directory's validation read an npm install in the plugin (most likely the npm install -g jevmem line in plugin/README.md) and held the repository's package.json and pnpm files as a possible custom registry. plugin/README.md now links to the install command in the main README and names the npm registry page (https://www.npmjs.com/package/jevmem, published with provenance). scripts/check-plugin.mjs fails CI on install or launcher text anywhere in plugin/.
  • The plugin launcher finds the CLI with command -v jevmem, or the path it cached the last time it found one. It no longer searches Homebrew, /usr/local, ~/.npm-global, Volta, nvm, fnm, asdf, mise or n, and it names no package manager. If Claude Code gives hooks a PATH without jevmem (the desktop app can), start Claude Code once from a terminal so the launcher caches the path. As a process, the Stop launcher took 17 ms p50, against 14 ms for the init launcher in the same run (results/ops-2026-09-26-v055.json).

Added

  • Icon and brand files. plugin/.claude-plugin/icon.svg is the plugin's icon in the directory. brand/ holds the brand kit's SVGs (icon, lockup, mark, wordmark) and its README, and the README header is the horizontal lockup, with a dark-mode version.
  • The link check also follows HTML src/srcset and absolute links into this repository, and covers plugin/README.md and brand/README.md.