Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
33 commits
Select commit Hold shift + click to select a range
8944f73
feat: consolidate governed recall and release hardening
Coding-Dev-Tools Aug 2, 2026
e5ec34a
fix: isolate conflicting sqlite native backends
Coding-Dev-Tools Aug 2, 2026
2bfdb86
test: approve encrypted recall fixture
Coding-Dev-Tools Aug 2, 2026
7435c97
On codex/v2-trust-boundary-release: transfer primary readiness change…
Coding-Dev-Tools Aug 2, 2026
377be3c
test: align ingress approval boundary
Coding-Dev-Tools Aug 2, 2026
e8b1eed
fix: enforce governed prompt boundaries
Coding-Dev-Tools Aug 2, 2026
470eebf
chore: harden LAN release packaging
Coding-Dev-Tools Aug 2, 2026
cbca12a
docs: keep post-release notes unreleased
Coding-Dev-Tools Aug 2, 2026
d601930
fix: preserve governed graph and claim boundaries
Coding-Dev-Tools Aug 2, 2026
210910d
fix: close governed review gaps
Coding-Dev-Tools Aug 2, 2026
f5772c8
fix: enforce eligibility before bounded public scans
Coding-Dev-Tools Aug 2, 2026
68e595b
fix: remove build-only pip from runtime image
Coding-Dev-Tools Aug 2, 2026
7938964
docs: streamline README detail
Coding-Dev-Tools Aug 2, 2026
b78a5e7
fix: audit stripped production image
Coding-Dev-Tools Aug 2, 2026
e38bdfe
fix: address remaining PR review findings
Coding-Dev-Tools Aug 2, 2026
98a3142
fix: harden memory retirement and offline recall
Coding-Dev-Tools Aug 2, 2026
8315970
fix: audit stripped release image
Coding-Dev-Tools Aug 2, 2026
0f52e0f
test: expect retirement control in ledger smoke
Coding-Dev-Tools Aug 2, 2026
5c96eb1
feat: harden smart MCP gateway and Pi integration
Coding-Dev-Tools Aug 3, 2026
c88462b
fix: reject all MCP server error envelopes
Coding-Dev-Tools Aug 3, 2026
c0e5470
docs: restore Pro conversion callout
Coding-Dev-Tools Aug 3, 2026
97904bb
docs: make full install the default
Coding-Dev-Tools Aug 3, 2026
c5ac56e
docs: move Compose details out of README
Coding-Dev-Tools Aug 3, 2026
2389f96
docs: restore 1.3 README intro
Coding-Dev-Tools Aug 3, 2026
68581e8
docs: move LAN setup out of README
Coding-Dev-Tools Aug 3, 2026
3df05d5
docs: preserve support badge
Coding-Dev-Tools Aug 3, 2026
fe26c4f
docs: move vector backend detail out of README
Coding-Dev-Tools Aug 3, 2026
93bca59
docs: move public review guidance out of README
Coding-Dev-Tools Aug 3, 2026
40fc297
docs: move query planning details out of README
Coding-Dev-Tools Aug 3, 2026
9ec46b3
fix: address review regressions and core test floor
Coding-Dev-Tools Aug 3, 2026
f6e3e40
fix: filter prompt graph edges before frontier cap
Coding-Dev-Tools Aug 3, 2026
899c872
fix: preserve review and prompt graph boundaries
Coding-Dev-Tools Aug 3, 2026
3bf34ef
fix: honor type caps and MCP restarts
Coding-Dev-Tools Aug 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
"name": "engraphis-memory",
"source": "./",
"description": "Discipline for giving agents durable, scoped, explainable memory across sessions and repos with the Engraphis MCP tools.",
"version": "1.3.0"
"version": "1.4.0"
}
]
}
2 changes: 1 addition & 1 deletion .claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "engraphis-memory",
"version": "1.3.0",
"version": "1.4.0",
"description": "Give agents durable, scoped, explainable memory across sessions and repos via the Engraphis MCP tools. Use when you learn something worth keeping, need prior context before acting, or ask why/how a fact changed. Covers remember/recall, why/timeline, forget/pin/correct, sessions, and code search.",
"author": {
"name": "The Engraphis Authors",
Expand Down
12 changes: 6 additions & 6 deletions .claude-plugin/skill-assets.sha256
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
24cc8bbcd2ba6055df75178c710542fb6e3e6428e63952ba51cc17d3d6d41a07 .claude-plugin/marketplace.json
6099aa7f5268a34bf1633c1f50c5e59f419b9dcc54ac5d553007fa40f28258ac .claude-plugin/plugin.json
018364f63e2181d83ba8d9532c50a41bd30e65eaa8358a721538c297dd063084 skills/engraphis-memory/SKILL.md
7ee71fb5ff9bd2b02f50b3ee8dc62f390a0e1bcd849a55739c4a376ac03d9784 skills/engraphis-memory/references/CONVENTIONS.md
8aafd2daba872be38ec8d42377e886d795d8941bf7c6a39795937ffc1d1f0d88 skills/engraphis-memory/references/SCOPING.md
6b0bbb97db4bfa4b1682f9f195bd823f05a2950384ea5c5b261b446b9461d1f1 skills/engraphis-memory/references/TOOLS.md
b3122186525b688060558721dadf8ca4a20e192097556adb1daecca0649a4e28 .claude-plugin/marketplace.json
5a870fabc9814e177a570a8878371d1c4c50a5b245076c2cfbb7ca659e41ebf6 .claude-plugin/plugin.json
911c70ead2c5aa3de24a6c645a9e921382a149aba52b0a9582ecd5b560e5b8a8 skills/engraphis-memory/SKILL.md
45dd73ca6afdd9e12ecd38c48e4a612b7646c25a07a75a80ca0e68d0e0b85f0e skills/engraphis-memory/references/CONVENTIONS.md
529fff3bdbe73f83209087fd10055fad77c5e5224ad8a9e6b0254052aa50e109 skills/engraphis-memory/references/SCOPING.md
eecd861f0f8cc2a9def07a53387ca66d8cb68d8b62d9b048dcd1b0b250fa3fee skills/engraphis-memory/references/TOOLS.md
35 changes: 22 additions & 13 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,13 @@ ENGRAPHIS_SERVICE_MODE=customer
# Set ENGRAPHIS_DASHBOARD_URL for a canonical public HTTPS URL behind a reverse proxy;
# it extends the dashboard MCP origin allow-list and drives legacy-inspector redirects.
# ENGRAPHIS_DASHBOARD_URL=https://engraphis.example.com
# Docker Compose stays loopback-only by default. For LAN MCP-over-HTTP, set a strong
# ENGRAPHIS_API_TOKEN, then run the token-required `docker-compose.lan.yml` overlay (Docker
# Compose v2.24.4+). Set this to the exact client URL:
# ENGRAPHIS_API_TOKEN=<a-long-random-secret>
# ENGRAPHIS_DASHBOARD_URL=http://192.168.10.151:8700
# Behind Traefik, use its LAN hostname instead:
# ENGRAPHIS_DASHBOARD_URL=http://engraphis.local

# Update reminder. When on (default), the server checks for a newer Engraphis release
# once a day and surfaces it in the dashboard banner, the startup log, and over MCP.
Expand Down Expand Up @@ -207,17 +214,19 @@ ENGRAPHIS_LLM_API_KEY=sk-your-key-here
# Locally defaults to ~/.engraphis; in a container use a private persistent volume.
# ENGRAPHIS_STATE_DIR=/data/.engraphis

# Hosted entitlements may report a separate local-only write grace capped at 24 hours.
# It never extends the exact 3-day trial, subscription expiry, or any cloud access.
# The private control plane may report ``workspace_write_grace`` for already-authorized
# hosted-account continuity, capped at 24 hours. It never extends the exact 3-day trial,
# subscription expiry, or cloud access, and it never restricts the free local core.

# Managed compute consent is decided automatically and needs no customer action: a
# local-only installation (no cloud session) is never allowed to upload workspace
# snapshots, while an installation connected to Engraphis Cloud is allowed by default,
# because connecting already accepts the terms covering managed analytics, dreaming, and
# consolidation. This variable is an explicit operator override, not a customer-facing
# setting: set it to 0 to opt a connected installation back out, or to 1 to force
# managed compute on regardless of session state. The cloud service remains authoritative
# for all paid computation.
# setting: set it to 0 to opt a connected installation back out, or to 1 to allow local
# snapshot preparation for a non-interactive deployment. ``1`` does not establish a cloud
# credential or authorize an upload; the cloud service remains authoritative for all paid
# computation.
# ENGRAPHIS_MANAGED_COMPUTE_CONSENT=0

# Optional credential-redacted JSON logs for hosted customer deployments.
Expand Down Expand Up @@ -256,18 +265,18 @@ ENGRAPHIS_LLM_API_KEY=sk-your-key-here
# directories allowed as import sources.
# ENGRAPHIS_IMPORT_ROOTS=/srv/docs:/home/user/notes

# Memory engine tuning: decay halflife (days), chunk sizing (tokens),
# proactive context loop, and reranker model.
# ENGRAPHIS_DECAY_HALFLIFE_DAYS=30
# ENGRAPHIS_CHUNK_TOKENS=512
# ENGRAPHIS_CHUNK_MAX=2048
# ENGRAPHIS_CHUNK_OVERLAP=64
# Memory engine tuning: runtime defaults for decay, chunk sizing, and the
# proactive context loop. CHUNK_MAX is a chunk-count limit, not a token limit.
# ENGRAPHIS_DECAY_HALFLIFE_DAYS=7
# ENGRAPHIS_CHUNK_TOKENS=256
# ENGRAPHIS_CHUNK_MAX=200
# ENGRAPHIS_CHUNK_OVERLAP=32
# Optional reader-tokenizer parity for chunk sizes (requires transformers).
# Pin the revision when the resulting memories support reproducible evidence.
# ENGRAPHIS_CHUNK_TOKENIZER_MODEL=Qwen/Qwen3.5-9B
# ENGRAPHIS_CHUNK_TOKENIZER_REVISION=<immutable model commit>
# ENGRAPHIS_LOOP_INTERVAL=300
# ENGRAPHIS_LOOP_TOP_K=10
# ENGRAPHIS_LOOP_INTERVAL=60
# ENGRAPHIS_LOOP_TOP_K=20
# ENGRAPHIS_RERANK_MODEL=cross-encoder/ms-marco-MiniLM-L-6-v2

# Workspace allow-list: comma-separated names. Empty = all allowed.
Expand Down
95 changes: 89 additions & 6 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}
- name: Install (core + server/mcp/code extras; no torch — the offline gate)
- name: Install (core + server/mcp/code extras; no torch or SQLCipher)
run: |
python -m pip install --upgrade pip
pip install -e ".[test]"
Expand All @@ -42,6 +42,28 @@ jobs:
- name: Ablation (vector-only vs hybrid)
run: python -m eval.ablation

encryption:
name: encryption driver gate (Python ${{ matrix.python-version }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}
- name: Install encryption integration gate
run: |
python -m pip install --upgrade pip
pip install -e ".[test,encryption]"
# sqlcipher3-binary currently cannot coexist safely with the stdlib sqlite
# extension during the long general suite. Keep its real driver contract in
# this dedicated, short-lived process rather than skipping encryption coverage.
- name: Encryption at-rest integration tests
run: python -m pytest -o addopts="" tests/test_encrypted_store.py -q -rs

core-py39:
name: core floor (numpy-only, Python 3.9)
runs-on: ubuntu-latest
Expand All @@ -61,6 +83,43 @@ jobs:
- name: Ablation
run: python -m eval.ablation

pi-extension:
name: Pi extension (${{ matrix.os }}, Python ${{ matrix.python-version }}, Node ${{ matrix.node-version }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
python-version: "3.10"
node-version: "22.19.0"
- os: windows-latest
python-version: "3.11"
node-version: "24"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ matrix.node-version }}
cache: npm
cache-dependency-path: integrations/pi/npm-shrinkwrap.json
- name: Install the current Smart MCP server
run: |
python -m pip install --upgrade pip
python -m pip install -e ".[test]"
- name: Install and verify the Pi package
working-directory: integrations/pi
env:
ENGRAPHIS_PI_TEST_COMMAND: engraphis-mcp
run: |
npm ci --ignore-scripts
npm run verify
npm run test:integration
npm audit --omit=dev

browser-accessibility:
name: browser accessibility smoke
runs-on: ubuntu-latest
Expand Down Expand Up @@ -98,7 +157,7 @@ jobs:
if [ "${{ github.event_name }}" != "pull_request" ]; then
echo "run=true" >> "$GITHUB_OUTPUT"
elif git diff --name-only "${{ github.event.pull_request.base.sha }}" "${{ github.sha }}" \
| grep -qE '^(Dockerfile|docker-entrypoint\.sh|docker-compose\.yml|railway\.json|deploy/|\.dockerignore|engraphis/|scripts/|pyproject\.toml|\.github/workflows/ci\.yml)'; then
| grep -qE '^(Dockerfile|docker-entrypoint\.sh|docker-compose(\.lan)?\.yml|railway\.json|deploy/|\.dockerignore|engraphis/|scripts/|pyproject\.toml|\.github/workflows/ci\.yml)'; then
echo "run=true" >> "$GITHUB_OUTPUT"
else
echo "run=false" >> "$GITHUB_OUTPUT"
Expand All @@ -111,6 +170,18 @@ jobs:
if: needs.docker-gate.outputs.run == 'true'
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Validate Compose configuration
run: docker compose config --quiet
- name: Reject unauthenticated LAN Compose overlay
run: |
if env -u ENGRAPHIS_API_TOKEN docker compose -f docker-compose.yml -f docker-compose.lan.yml config --quiet; then
echo "LAN overlay must require ENGRAPHIS_API_TOKEN"
exit 1
fi
- name: Validate token-protected LAN Compose overlay
env:
ENGRAPHIS_API_TOKEN: ci-lan-overlay-token
run: docker compose -f docker-compose.yml -f docker-compose.lan.yml config --quiet
- name: Build image
run: docker build -t engraphis:ci .
- name: Verify production image OCR runtime
Expand All @@ -119,10 +190,22 @@ jobs:
'python -c "import PIL, pytesseract" && command -v tesseract >/dev/null &&
tesseract --version | head -n 1'
- name: Audit the exact production image dependency set
run: >-
docker run --rm --entrypoint sh engraphis:ci -c
'python -m pip install --no-cache-dir pip-audit &&
python -m pip_audit --local'
# The runtime image intentionally has no pip: it is a build tool whose vendored
# dependency snapshot would otherwise remain an unnecessary attack surface. Copy the
# exact installed distributions to the runner and audit that set instead of mutating
# the production image just to run the audit.
run: |
audit_dir="$(mktemp -d)"
container="engraphis-audit-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}"
cleanup() {
docker rm -f "$container" >/dev/null 2>&1 || true
rm -rf "$audit_dir"
}
trap cleanup EXIT
python -m pip install --disable-pip-version-check --no-cache-dir pip-audit
docker create --name "$container" engraphis:ci >/dev/null
docker cp "$container":/usr/local/lib/python3.11/site-packages/. "$audit_dir"
python -m pip_audit --path "$audit_dir"
- name: Run container (offline deterministic embedder — no model downloads)
run: |
docker run -d --name engraphis -p 8700:8700 \
Expand Down
104 changes: 104 additions & 0 deletions .github/workflows/release-pi.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,104 @@
name: Publish Pi extension to npm

on:
push:
tags:
- "pi-v*.*.*"
workflow_dispatch:

permissions:
contents: read

jobs:
build:
name: Verify and pack Pi extension
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.11"
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24"
cache: npm
cache-dependency-path: integrations/pi/npm-shrinkwrap.json
registry-url: https://registry.npmjs.org

- name: Require Pi tag and npm package version to match
if: github.event_name == 'push'
shell: bash
run: |
expected="${GITHUB_REF_NAME#pi-v}"
actual="$(node -p 'require("./integrations/pi/package.json").version')"
test "$GITHUB_REF_NAME" = "pi-v$actual"
test "$expected" = "$actual"

- name: Require release tag commit to be on protected main
if: github.event_name == 'push'
shell: bash
run: |
git fetch --no-tags origin main:refs/remotes/origin/main
git merge-base --is-ancestor "$GITHUB_SHA" origin/main

- name: Install the current Smart MCP server
run: |
python -m pip install --upgrade pip
python -m pip install -e ".[test]"

- name: Verify package, live MCP bridge, and production dependencies
working-directory: integrations/pi
env:
ENGRAPHIS_PI_TEST_COMMAND: engraphis-mcp
run: |
npm ci --ignore-scripts
npm run verify
npm run test:integration
npm audit --omit=dev

- name: Build npm tarball
working-directory: integrations/pi
run: npm pack --ignore-scripts

- name: Store npm tarball
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: pi-npm-package
path: integrations/pi/engraphis-pi-*.tgz
if-no-files-found: error

publish:
name: Publish @engraphis/pi
needs: build
# A manual dispatch is intentionally verification-only. Publishing requires a
# protected pi-v* tag and npm Trusted Publishing configured for this workflow.
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/pi-v')
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24"
registry-url: https://registry.npmjs.org
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
name: pi-npm-package
path: dist
- name: Publish with npm provenance
run: npm publish dist/engraphis-pi-*.tgz --access public --provenance
- name: Verify the published version
shell: bash
run: |
version="${GITHUB_REF_NAME#pi-v}"
for attempt in $(seq 1 12); do
if [ "$(npm view "@engraphis/pi@$version" version 2>/dev/null)" = "$version" ]; then
exit 0
fi
sleep 10
done
echo "@engraphis/pi@$version did not become visible on npm"
exit 1
Loading