Skip to content

3ngram 1.0.2

Choose a tag to compare

@github-actions github-actions released this 14 Jul 15:17
v1.0.2
edb3ec4

3ngram v1.0.2

Security-hardened public release of 3ngram: persistent, typed memory for AI
agents. This patch is intended as the first complete cross-package release after
the v1.0.1 publication run was halted during code-scanning review.

Security hardening

  • A coarse per-IP rate limit now covers every non-health HTTP surface before
    body parsing, backed by Redis across replicas and in-memory for self-hosting.
  • Login, signup, OAuth, MCP, and API-key traffic retain their narrower dedicated
    rate-limit buckets in addition to the coarse edge limit.
  • Core, LLM, and SDK URL normalization now runs in linear time for arbitrary
    trailing-slash input.
  • Documentation generators, evaluation tests, and CI permissions were tightened
    in response to the public CodeQL baseline.

Release artifacts

  • @3ngram/server@1.0.2, @3ngram/sdk@1.0.2, and 3ngram@1.0.2 on npm
  • @3ngram/core@0.5.1 and @3ngram/llm@0.2.2 on npm
  • The existing exact config, schema, and database packages that complete the
    server dependency closure
  • ghcr.io/b3dmar/3ngram:1.0.2 for Linux amd64 and arm64
  • BuildKit SBOM plus provenance and GitHub-signed SLSA attestations

The hosted 3ngram dashboard and cloud-operations code are proprietary and are
not included in this repository. The MCP server, REST API, SDK, CLI, and memory
engine do not depend on that dashboard.

Immutable container reference

ghcr.io/b3dmar/3ngram@sha256:b57db7aa61558364fdb7fe8ea5d75a5bfa382f56496d0111996621b19fc61945