Releases: PCIRCLE-AI/memesh
Release list
v4.10.11
Includes the changes documented under 4.10.10 and 4.10.9 below; neither was published to npm.
Fixed
- Under Codex, a message already delivered into the thread is no longer announced again as "waiting" at the next prompt or session start, which made the agent fetch and record it a second time.
v4.10.8
Includes the changes documented under 4.10.7 and 4.10.6 below; neither was
published to npm. The previous public release is 4.10.5.
Fixed
- The Project tab's view toggle wraps on a phone-width screen; in German it made the page 12px wider than a 375px screen.
4.10.7 (not published to npm)
Includes the changes documented under 4.10.6 below; 4.10.6 was not published
to npm. The previous public release is 4.10.5.
Changed
- The README is kept in English and Traditional Chinese only; the German translation was removed.
Fixed
- Dashboard Settings no longer scrolls sideways on a phone-width screen: the briefing select added in 4.10.5 made the page 584px wide at 375px, and every Settings select now stays inside its card (#473).
- The dashboard header no longer overflows a phone-width screen in German: the version and memory count wrap inside it in every language (#475).
- A Claude Code session and a Codex thread in the same directory now land in the same routing project and see each other in
message discover: every managed host derives its project from its own working directory or--workspaceinstead of a typed--projectvalue that could never match; SessionStart also states a resolved session's own messaging address in one line (#474). - The Codex plugin's MCP server now receives
MEMESH_DIRandMEMESH_DB_PATH. With a custom data directory or database it used the default one, so Codex saw different memories and messages from the CLI and hooks (#482).
Notes
- The Claude channel host (
memesh-host-claude) runs from the global npm install, not the plugin, so updating only the Claude Code plugin does not deliver the cross-host discovery fix — update the globalmemeshpackage too.
4.10.6 (not published to npm)
Added
- Claude Code learns about a waiting agent message without polling. When
MEMESH_RECIPIENTis unset, the hooks take the recipient from the owner-private Claude channel config (not on Windows); a Stop hook blocks the turn once per unfetched message; SessionStart warns when the channel flag was mistyped, for example a dash autocorrected to an em dash (#468). memesh importreports how many imported memories are untrusted.memesh import --trust, after a confirmation, marks them trusted for restoring your own backup (#407)..gitleaks.tomlfor running gitleaks from the repository root: default rules plus allowlists for documentation checksums, synthetic test credentials and test idempotency keys. No CI job runs gitleaks.
Changed
- Promotion from
nexttolatestruns through the release workflow (#452).
Fixed
- Codex: a MeMesh message left in the thread queue after an interrupted turn is now started. The router asks Codex to start exactly that submission every 20 seconds, for up to 10 minutes and until intake, never while other input is queued, and records the outcome as a
host_activationreceipt; without the app-server daemon it reportsunsupported, and the message waits until you send a prompt (#468). - Injected memory and
briefingindex lines replace each run of control characters (including the ESC that starts an ANSI sequence, so colour codes no longer take effect), DEL and bidi overrides with a space, so a control byte can no longer rejoin split text (#374). Recent activityno longer shows the routing hash that session-summary and pre-compact titles carry after the project label (#409).- A path-like or over-long
MEMESH_RECIPIENTis refused at session start, with a hint for a never-seen recipient (#402). The router prints a one-line startup error, andmemesh doctor's opt-in router probe (MEMESH_DOCTOR_PROBE_MESSAGE_ROUTER=1) names a socket path that is too long (#404). - Lessons use one type:
lessonandmistakeare stored aslesson_learned, existing ones are renamed once on upgrade, and?type=lessonstill finds them (#443, #451). memesh config set sessionLimitaccepts 1–100; a larger stored value is used as 100, and the dashboard Settings tab opens again (#431).- Hook runs from the Codex plugin are recorded as host
codex. With no Claude Code signal, aPLUGIN_ROOTthat is not the running plugin's root is recorded asunknown, andmemesh doctornames the hosts behind each capture-liveness result (#447; other host signals: #325). - Agent guidance: the remember hint names the plugin's
remembertool (#442); project tags point at theprojectfield ofbriefing, while the HTTP connector guides are unchanged (#408);briefinganduser_patternsno longer ask to be called at session start (#444); the Channel instructions no longer say no reply is required: message content still authorizes nothing on its own, and an agent acts on a request only under its normal permission rules and the user's authorization, then replies (#445); Codex SessionStart, which the 4.10.5 notes said needed a manualbriefingcall, and recall matching are described correctly (#405, #446).
Notes
- If you wired Claude Code hooks with
memesh install-hooksormemesh setuprather than the plugin, runmemesh install-hooksagain after upgrading to add the new Stop hook;memesh doctordoes not report a missing one. Plugin installs pick it up on their own. - Restart a
memesh-routeryou run yourself so the Codex queue fix takes effect.
v4.10.5
v4.10.5
- Claude Code keeps a short per-project handoff and shows it first in the next session when auto-capture is enabled.
- Briefings put recent decisions first and share one 4000-character memory-block budget.
- Doctor and the Dashboard provide recovery guidance for a forgotten handoff.
- Clearer CLI help, diagnostics, and MCP descriptions.
Upgrade note: memesh delegation record now requires --source <name>.
This is a staged release on npm next; latest remains unchanged during dogfooding. Codex lease-renewal comparison and stopped-recipient fallback retain disclosed independent-observation limitations.
v4.10.4
Changed
-
The default briefing level is now
minimal. A new session, and a call to
thebriefingtool ormemesh briefing, gets only what belongs to the
project it is in — its decisions, lessons, known facts and recent activity,
with the live repository state in front of them — where the default used to
bestandard. Two things a new session no longer receives unless it asks
for them: the fresh task state (goal / next / blocked / done) and the capped
index of the project's durable memories. To get them back, runmemesh config set briefing standard, or start the session with
MEMESH_BRIEFING=standard.fullis unchanged: it still adds other
projects' memory and global memory. Only the default moved. Abriefing
value you already set inconfig.json, or aMEMESH_BRIEFINGin the
environment, is honoured exactly as before, the order is still env >
config > default, and an unset value — or an invalid one — now resolves to
minimalinstead ofstandard. A stale or unknown-age task state still
gets its one-line flag at every level,memesh taskand thetask_state
tool still show the whole stored state, andmemesh briefing --indexstill
prints the index on its own. The dashboard's Project tab no longer says the
index is what an agent receives "by default": it names the levels that
include it. -
Headings name a project by its label, not its 32-character hash (#409). A
project's id is<label>~<32 hex>, and every heading of the briefing — the
session-start block, thebriefingtool andmemesh briefing— used to print
all of it:Task state for "memesh~2c0fe491888c8efb9a4894828bbc2733",
Decisions and direction for …,Recent activity in …, the index heading, the
empty-state lines, the terminal banner a project with no memories greets you
with, and the linesmemesh taskprints. They now say"memesh". The full id
is unchanged wherever it identifies data: theprojectfield of the JSON and
MCP results,project:tags, entity names (memesh learnnames lessons as
before),--project, and the unread-message line, which tells an agent which
project to poll.projectLabelinsrc/core/work-topology.tsis the one rule:
one trailing~plus exactly 32 lowercase hex characters is removed, anything
else is left as it is. The titles the session-summary and pre-compact hooks
stored (2026-09-22 memesh~…: edited 12 file(s)) still contain the whole id and
are printed as stored, so it can still appear in the lines underRecent activity. -
memesh config listshows the briefing level in effect (#412). With the
default nowminimal, a config with nobriefingkey told you nothing about
what a session would get.listnow always prints one line for it —briefing: minimal (default),briefing: standard (config.json)orbriefing: full (env MEMESH_BRIEFING)— decided by the same resolver the hook and the tool use
(env, then config, then the default). A storedbriefingis that line, not a
second one; a stored or env value that is not a level is said to be invalid and
shows the level it resolved to.
Fixed
- The ja Settings update-freshness label no longer duplicates its Check now
button (#420). Both read 今すぐ確認; the status label now reads 最新の結果を使用. qa:live-journey --host codexworks with codex-cli 0.155.1'sCODEX_HOME
rule and reports codex's real failure reason on error (#422).--codex-home
no longer requires (or refuses) a path under the OS temp dir, and a startup
failure now shows stdout, where codex's real error actually prints, not just
stderr. An end-to-end pass is still blocked by the QA account's own usage
limit, unrelated to this code.- A new session is no longer shown the oldest of a group of equally scored
memories (#401). The SessionStart hook ranks a project's memories by
confidence, use and recency and keeps the top few (sessionLimit). The daily
decay multiplies the confidence of never-accessed memories by 0.9, so the
memories captured since its last run carry one confidence value and, never
accessed, score exactly alike (so do old ones that have sunk to the decay
floor), and SQLite hands equal scores back in ascending id order (measured):
the cut kept the OLDEST of them. The lesson query, whose pool is claimed
first, had no ORDER BY at all and kept the five oldest lessons. On a real
graph, in the hours after a decay run, a new session was given the same two
old commit lines every time and never the decision made an hour earlier,
whilememesh briefingon the same data (which reads a newest-first window)
showed the right memories. Equal scores now resolve newest first ("newest" is
creation order, the key the briefing sorts by too), in both the exp/log and
the legacy ranking forms and in the global and recent pools thatfulladds,
and the lesson query orders newest first; a higher score still beats a newer
memory.tests/core/briefing.test.tspins the hook and the briefing together
on a graph in which every memory ties, lessons included. memesh briefing --json'shasTaskStateno longer counts the unread-message
reminder. It was true whenever any state line was present, and the reminder
is listed with the task-state lines, so a project with a message waiting and no
task state reported one. It is now true exactly when a task-state line leads the
block: the fresh state, the one-line stale flag, or the unreadable-record line.
The CLI's "set the task state" hint, which reads it, now appears beside the
reminder on such a project.memesh config get <key>exists (#410). It printedunknown command 'get'
and suggestedset. It now prints the stored value asconfig listshows it
(forbriefing, what is stored, not the level in effect thatlistprints),
or<key> is not set in config.json(exit 0); an unknown key gets the same
two-line refusal assetandunsetand exits 1.memesh statusno longer calls a newer install "up to date" (#410). On
4.10.2, a trial build on thenexttag while npmlatestwas 4.9.4, it printed
Update check: up to date (fresh; latest 4.9.4)and then anUpdate path:for
@latest, a downgrade. It now saysrunning pre-release version (4.10.2), npm latest is 4.9.4, asmemesh doctoralready did, and prints no update path. A
newer install that is also deprecated, whose check only partly succeeded, or
whose check could not run keeps its update path: only the "running pre-release
version" line withholds it.
v4.10.2
This is a trial release on the npm next tag. latest stays at 4.9.4 until the trial has been observed for at least one working day.
npm install -g @pcircle/memesh@next4.10.2 includes everything in 4.10.1 (also a trial release) and the fixes listed here.
New
- A Claude Code session can now be told that a message is waiting for it. Start the session with
MEMESH_RECIPIENT=<its recipient id>and it is reminded at the start and at every prompt, until it records theintakeaction for those messages. Without the variable nothing changes. - A
briefingsetting with three levels for how much MeMesh puts into a new session:minimal,standard(the new default) andfull(what earlier versions did). Set it withmemesh config set briefing <level>.
Changed
- The default session briefing is smaller. It now leaves out the parts the host already carries itself and injects this project's own recent memory and the live repository state.
memesh config set briefing fullbrings the old behaviour back. importno longer brings back a memory you archived (#363).
Fixed
- Imported bundles can no longer grant themselves behavioural authority (#359, #361): fields that change how MeMesh behaves (guards, the demo marker, task state and similar) are refused, or accepted only after validation.
- Pre-edit recall no longer injects unrelated memories or session bookkeeping in place of what is relevant to the file being edited (#358).
- The prompt reminder hook works when MeMesh is installed under a symlinked path (#372); before, it exited having done nothing.
- A guard warning is no longer lost to a slow lock: the counter that tallies guard fires now waits at most 200 ms for the database (#366).
- A failed memory read is reported as a failure, not as an empty project, and an unreadable message inbox is recorded instead of looking like a clean run (#386, #394).
- Stale task state (older than 72 hours, or of unknown age) is flagged instead of being presented as current.
For contributors
- The tests with tight time limits that failed at random on slow Windows runners have generous limits now.
Full detail: CHANGELOG.md.
v4.10.1
This is a trial release on the npm next tag. latest stays at 4.9.4 until the trial has been observed for at least one working day.
npm install -g @pcircle/memesh@next4.10.1 includes everything listed under 4.10.0 in the changelog; 4.10.0 was never published to npm.
Fixed
- Quiet commits are now remembered (#321).
git commit -q, redirected output, merges, cherry-picks and reverts were invisible to MeMesh because it read the command's text output. It now reads the repository's state instead, and records a reason whenever it skips. - A forgotten observation stays forgotten (#346). Removing one sentence from a session summary used to be silently undone at the end of the next turn. It now stays removed;
rememberbrings it back if you change your mind. - Session memories keep up with a long session (#322). They were frozen at the first turn. They now reflect the latest state, and an entity you archived with
forgetis left alone. - Dashboard tells the truth when it cannot read your settings. It shows "unknown" with a reload hint instead of claiming automatic updates are off. Update-check failures explain how to retry, and permission failures in auto-repair say what to do next — in every supported language.
memesh doctorno longer reports a failed first update check as "never attempted", or an unpublished local build as npm's latest.
For contributors
qa:live-journeynow runs five core memory journeys before every real Codex or Claude host check;--core-onlyruns them without credentials.- Releases go to npm
nextfirst; promotion tolatestis a separate, later step.
Full detail, with links to the incident write-ups: CHANGELOG.md.
v4.9.4
Fixed
- Plugin upgrades now fail closed before cache replacement when the staged
artifact is incomplete. Before an upgrade can swap the live cache, the
updater validates every hook, plugin manifest, and MCP entrypoint in the
staged copy; missing or swapped targets leave the existing cache and
registry unchanged. The release gate runs the same checker and additionally
confirms every target is present in the npm-packed artifact. - Release audits no longer inherit an unsafe or unbounded npm cache. The
consumer audit uses a private temporary cache and bounded subprocess
lifetimes, reporting a controlled failure instead of hanging or being
affected by root-owned cache state. - Pre-release coverage now protects the updater's own checker. A copied
or incomplete updater refuses to install a plugin archive when its trusted
artifact-integrity checker is absent. - The npm package ships the checker's one dependency. The
artifact-integrity checker importsscripts/lib/npm-bin.mjs, which the
package did not include, so the checker could not load from an npm install
andmemesh upgrade-plugin— which prefers the npm-installed copy of the
updater — would have refused every upgrade. A test now unpacks the real
tarball and runs the checker from it. The checker also rejects a symlinked
directory above a hook target, not only a symlinked file.
v4.9.3
Fixed
- Codex SessionEnd no longer requests an unsupported hook timeout. The
lifecycle hook now declares the host-compatible three-second ceiling, so
Codex does not clamp the packaged manifest at load time.
v4.9.1
Fixed
- First-use update guidance is now channel-aware and session-safe. Only
supported npm-global installs can record consent for the Stop-hook updater;
project-local, source-checkout, and plugin-marketplace installs receive the
correct foreground action instead of a misleading upgrade prompt. - Concurrent and interrupted first-use prompts no longer lose the notice.
Session-scoped claims are atomic, finalize only after output is emitted, and
reclaim a pending claim only when its owner process is confirmed gone. - Post-release dogfood regressions are closed. Recall matching, router
failure reporting, bundled server startup, dashboard navigation, doctor
repairs, and release-surface contracts now have focused regression coverage.
v4.9.0
v4.9.0
MeMesh now uses one local memory path, with bounded work packages for agents and clearer live-message delivery states.
What users will notice
- Recall uses SQLite FTS5, and capture uses deterministic hooks. Built-in LLM providers, embedding/vector configuration, and model probes are removed.
- An already-running agent can prepare a bounded digest or Claude transcript work package and submit a proposal for human review. The Dashboard reviews staged proposals; it does not launch agents.
- Eligible Codex plugin sessions automatically register their exact session, renew their lease, and replace the prior generation on resume. Native acceptance, recipient intake, acknowledgement, and disposition remain separate states.
Quality improvements
- Observation removal and FTS maintenance are atomic. Index failures roll back, and archived entities stay out of the keyword index.
- Transcript packages require an unambiguous MCP workspace root and retain bounded redacted evidence for proposal review.
- Transcript rereads reject content changes even when file size and timestamps stay the same.
- Dashboard text is larger and higher-contrast, localized proposal labels are consistent, and update notices only recommend genuinely newer versions.
- Installation, API, architecture, and agent documentation are synchronized with the FTS-only behavior.
Upgrade notes
- Update your installed package/plugin through its existing installation channel, then run
memesh doctor. - Retired provider-related settings may remain on disk. Doctor names those keys without printing their values or deleting them.
- Live messaging requires the host's supported native channel and trusted lifecycle hooks. Use project-scoped
message discoverto check current registrations; queue acceptance alone is not proof the model read a message.
Verification
- Full artifact verification, fresh-consumer package smoke, and upgrades from 4.5.1 and 4.8.5.
- Real Codex and Claude model-visible journeys, including lease renewal, disconnect, and offline durable readback.
- Claude isolation and trusted-intake checks include explicit operator attestation.