3ngram 1.0.2
3ngram v1.0.2
Security-hardened public release of 3ngram: persistent, typed memory for AI
agents. This patch is intended as the first complete cross-package release after
the v1.0.1 publication run was halted during code-scanning review.
Security hardening
- A coarse per-IP rate limit now covers every non-health HTTP surface before
body parsing, backed by Redis across replicas and in-memory for self-hosting. - Login, signup, OAuth, MCP, and API-key traffic retain their narrower dedicated
rate-limit buckets in addition to the coarse edge limit. - Core, LLM, and SDK URL normalization now runs in linear time for arbitrary
trailing-slash input. - Documentation generators, evaluation tests, and CI permissions were tightened
in response to the public CodeQL baseline.
Release artifacts
@3ngram/server@1.0.2,@3ngram/sdk@1.0.2, and3ngram@1.0.2on npm@3ngram/core@0.5.1and@3ngram/llm@0.2.2on npm- The existing exact config, schema, and database packages that complete the
server dependency closure ghcr.io/b3dmar/3ngram:1.0.2for Linux amd64 and arm64- BuildKit SBOM plus provenance and GitHub-signed SLSA attestations
The hosted 3ngram dashboard and cloud-operations code are proprietary and are
not included in this repository. The MCP server, REST API, SDK, CLI, and memory
engine do not depend on that dashboard.
Immutable container reference
ghcr.io/b3dmar/3ngram@sha256:b57db7aa61558364fdb7fe8ea5d75a5bfa382f56496d0111996621b19fc61945