Skip to content

Releases: PCIRCLE-AI/memesh

v4.10.11

Choose a tag to compare

@kevintseng kevintseng released this 29 Sep 14:49
b599200

Includes the changes documented under 4.10.10 and 4.10.9 below; neither was published to npm.

Fixed

  • Under Codex, a message already delivered into the thread is no longer announced again as "waiting" at the next prompt or session start, which made the agent fetch and record it a second time.

v4.10.8

Choose a tag to compare

@kevintseng kevintseng released this 27 Sep 16:14
7be8d02

Includes the changes documented under 4.10.7 and 4.10.6 below; neither was
published to npm. The previous public release is 4.10.5.

Fixed

  • The Project tab's view toggle wraps on a phone-width screen; in German it made the page 12px wider than a 375px screen.

4.10.7 (not published to npm)

Includes the changes documented under 4.10.6 below; 4.10.6 was not published
to npm. The previous public release is 4.10.5.

Changed

  • The README is kept in English and Traditional Chinese only; the German translation was removed.

Fixed

  • Dashboard Settings no longer scrolls sideways on a phone-width screen: the briefing select added in 4.10.5 made the page 584px wide at 375px, and every Settings select now stays inside its card (#473).
  • The dashboard header no longer overflows a phone-width screen in German: the version and memory count wrap inside it in every language (#475).
  • A Claude Code session and a Codex thread in the same directory now land in the same routing project and see each other in message discover: every managed host derives its project from its own working directory or --workspace instead of a typed --project value that could never match; SessionStart also states a resolved session's own messaging address in one line (#474).
  • The Codex plugin's MCP server now receives MEMESH_DIR and MEMESH_DB_PATH. With a custom data directory or database it used the default one, so Codex saw different memories and messages from the CLI and hooks (#482).

Notes

  • The Claude channel host (memesh-host-claude) runs from the global npm install, not the plugin, so updating only the Claude Code plugin does not deliver the cross-host discovery fix — update the global memesh package too.

4.10.6 (not published to npm)

Added

  • Claude Code learns about a waiting agent message without polling. When MEMESH_RECIPIENT is unset, the hooks take the recipient from the owner-private Claude channel config (not on Windows); a Stop hook blocks the turn once per unfetched message; SessionStart warns when the channel flag was mistyped, for example a dash autocorrected to an em dash (#468).
  • memesh import reports how many imported memories are untrusted. memesh import --trust, after a confirmation, marks them trusted for restoring your own backup (#407).
  • .gitleaks.toml for running gitleaks from the repository root: default rules plus allowlists for documentation checksums, synthetic test credentials and test idempotency keys. No CI job runs gitleaks.

Changed

  • Promotion from next to latest runs through the release workflow (#452).

Fixed

  • Codex: a MeMesh message left in the thread queue after an interrupted turn is now started. The router asks Codex to start exactly that submission every 20 seconds, for up to 10 minutes and until intake, never while other input is queued, and records the outcome as a host_activation receipt; without the app-server daemon it reports unsupported, and the message waits until you send a prompt (#468).
  • Injected memory and briefing index lines replace each run of control characters (including the ESC that starts an ANSI sequence, so colour codes no longer take effect), DEL and bidi overrides with a space, so a control byte can no longer rejoin split text (#374).
  • Recent activity no longer shows the routing hash that session-summary and pre-compact titles carry after the project label (#409).
  • A path-like or over-long MEMESH_RECIPIENT is refused at session start, with a hint for a never-seen recipient (#402). The router prints a one-line startup error, and memesh doctor's opt-in router probe (MEMESH_DOCTOR_PROBE_MESSAGE_ROUTER=1) names a socket path that is too long (#404).
  • Lessons use one type: lesson and mistake are stored as lesson_learned, existing ones are renamed once on upgrade, and ?type=lesson still finds them (#443, #451).
  • memesh config set sessionLimit accepts 1–100; a larger stored value is used as 100, and the dashboard Settings tab opens again (#431).
  • Hook runs from the Codex plugin are recorded as host codex. With no Claude Code signal, a PLUGIN_ROOT that is not the running plugin's root is recorded as unknown, and memesh doctor names the hosts behind each capture-liveness result (#447; other host signals: #325).
  • Agent guidance: the remember hint names the plugin's remember tool (#442); project tags point at the project field of briefing, while the HTTP connector guides are unchanged (#408); briefing and user_patterns no longer ask to be called at session start (#444); the Channel instructions no longer say no reply is required: message content still authorizes nothing on its own, and an agent acts on a request only under its normal permission rules and the user's authorization, then replies (#445); Codex SessionStart, which the 4.10.5 notes said needed a manual briefing call, and recall matching are described correctly (#405, #446).

Notes

  • If you wired Claude Code hooks with memesh install-hooks or memesh setup rather than the plugin, run memesh install-hooks again after upgrading to add the new Stop hook; memesh doctor does not report a missing one. Plugin installs pick it up on their own.
  • Restart a memesh-router you run yourself so the Codex queue fix takes effect.

v4.10.5

v4.10.5 Pre-release
Pre-release

Choose a tag to compare

@kevintseng kevintseng released this 25 Sep 05:37
b6b402e

v4.10.5

  • Claude Code keeps a short per-project handoff and shows it first in the next session when auto-capture is enabled.
  • Briefings put recent decisions first and share one 4000-character memory-block budget.
  • Doctor and the Dashboard provide recovery guidance for a forgotten handoff.
  • Clearer CLI help, diagnostics, and MCP descriptions.

Upgrade note: memesh delegation record now requires --source <name>.

This is a staged release on npm next; latest remains unchanged during dogfooding. Codex lease-renewal comparison and stopped-recipient fallback retain disclosed independent-observation limitations.

v4.10.4

Choose a tag to compare

@kevintseng kevintseng released this 23 Sep 08:37
5dc966e

Changed

  • The default briefing level is now minimal. A new session, and a call to
    the briefing tool or memesh briefing, gets only what belongs to the
    project it is in — its decisions, lessons, known facts and recent activity,
    with the live repository state in front of them — where the default used to
    be standard. Two things a new session no longer receives unless it asks
    for them: the fresh task state (goal / next / blocked / done) and the capped
    index of the project's durable memories. To get them back, run memesh config set briefing standard, or start the session with
    MEMESH_BRIEFING=standard. full is unchanged: it still adds other
    projects' memory and global memory. Only the default moved. A briefing
    value you already set in config.json, or a MEMESH_BRIEFING in the
    environment, is honoured exactly as before, the order is still env >
    config > default, and an unset value — or an invalid one — now resolves to
    minimal instead of standard. A stale or unknown-age task state still
    gets its one-line flag at every level, memesh task and the task_state
    tool still show the whole stored state, and memesh briefing --index still
    prints the index on its own. The dashboard's Project tab no longer says the
    index is what an agent receives "by default": it names the levels that
    include it.

  • Headings name a project by its label, not its 32-character hash (#409). A
    project's id is <label>~<32 hex>, and every heading of the briefing — the
    session-start block, the briefing tool and memesh briefing — used to print
    all of it: Task state for "memesh~2c0fe491888c8efb9a4894828bbc2733",
    Decisions and direction for …, Recent activity in …, the index heading, the
    empty-state lines, the terminal banner a project with no memories greets you
    with, and the lines memesh task prints. They now say "memesh". The full id
    is unchanged wherever it identifies data: the project field of the JSON and
    MCP results, project: tags, entity names (memesh learn names lessons as
    before), --project, and the unread-message line, which tells an agent which
    project to poll. projectLabel in src/core/work-topology.ts is the one rule:
    one trailing ~ plus exactly 32 lowercase hex characters is removed, anything
    else is left as it is. The titles the session-summary and pre-compact hooks
    stored (2026-09-22 memesh~…: edited 12 file(s)) still contain the whole id and
    are printed as stored, so it can still appear in the lines under Recent activity.

  • memesh config list shows the briefing level in effect (#412). With the
    default now minimal, a config with no briefing key told you nothing about
    what a session would get. list now always prints one line for it — briefing: minimal (default), briefing: standard (config.json) or briefing: full (env MEMESH_BRIEFING) — decided by the same resolver the hook and the tool use
    (env, then config, then the default). A stored briefing is that line, not a
    second one; a stored or env value that is not a level is said to be invalid and
    shows the level it resolved to.

Fixed

  • The ja Settings update-freshness label no longer duplicates its Check now
    button (#420).
    Both read 今すぐ確認; the status label now reads 最新の結果を使用.
  • qa:live-journey --host codex works with codex-cli 0.155.1's CODEX_HOME
    rule and reports codex's real failure reason on error (#422).
    --codex-home
    no longer requires (or refuses) a path under the OS temp dir, and a startup
    failure now shows stdout, where codex's real error actually prints, not just
    stderr. An end-to-end pass is still blocked by the QA account's own usage
    limit, unrelated to this code.
  • A new session is no longer shown the oldest of a group of equally scored
    memories (#401).
    The SessionStart hook ranks a project's memories by
    confidence, use and recency and keeps the top few (sessionLimit). The daily
    decay multiplies the confidence of never-accessed memories by 0.9, so the
    memories captured since its last run carry one confidence value and, never
    accessed, score exactly alike (so do old ones that have sunk to the decay
    floor), and SQLite hands equal scores back in ascending id order (measured):
    the cut kept the OLDEST of them. The lesson query, whose pool is claimed
    first, had no ORDER BY at all and kept the five oldest lessons. On a real
    graph, in the hours after a decay run, a new session was given the same two
    old commit lines every time and never the decision made an hour earlier,
    while memesh briefing on the same data (which reads a newest-first window)
    showed the right memories. Equal scores now resolve newest first ("newest" is
    creation order, the key the briefing sorts by too), in both the exp/log and
    the legacy ranking forms and in the global and recent pools that full adds,
    and the lesson query orders newest first; a higher score still beats a newer
    memory. tests/core/briefing.test.ts pins the hook and the briefing together
    on a graph in which every memory ties, lessons included.
  • memesh briefing --json's hasTaskState no longer counts the unread-message
    reminder.
    It was true whenever any state line was present, and the reminder
    is listed with the task-state lines, so a project with a message waiting and no
    task state reported one. It is now true exactly when a task-state line leads the
    block: the fresh state, the one-line stale flag, or the unreadable-record line.
    The CLI's "set the task state" hint, which reads it, now appears beside the
    reminder on such a project.
  • memesh config get <key> exists (#410). It printed unknown command 'get'
    and suggested set. It now prints the stored value as config list shows it
    (for briefing, what is stored, not the level in effect that list prints),
    or <key> is not set in config.json (exit 0); an unknown key gets the same
    two-line refusal as set and unset and exits 1.
  • memesh status no longer calls a newer install "up to date" (#410). On
    4.10.2, a trial build on the next tag while npm latest was 4.9.4, it printed
    Update check: up to date (fresh; latest 4.9.4) and then an Update path: for
    @latest, a downgrade. It now says running pre-release version (4.10.2), npm latest is 4.9.4, as memesh doctor already did, and prints no update path. A
    newer install that is also deprecated, whose check only partly succeeded, or
    whose check could not run keeps its update path: only the "running pre-release
    version" line withholds it.

v4.10.2

v4.10.2 Pre-release
Pre-release

Choose a tag to compare

@kevintseng kevintseng released this 21 Sep 19:15
59863e9

This is a trial release on the npm next tag. latest stays at 4.9.4 until the trial has been observed for at least one working day.

npm install -g @pcircle/memesh@next

4.10.2 includes everything in 4.10.1 (also a trial release) and the fixes listed here.

New

  • A Claude Code session can now be told that a message is waiting for it. Start the session with MEMESH_RECIPIENT=<its recipient id> and it is reminded at the start and at every prompt, until it records the intake action for those messages. Without the variable nothing changes.
  • A briefing setting with three levels for how much MeMesh puts into a new session: minimal, standard (the new default) and full (what earlier versions did). Set it with memesh config set briefing <level>.

Changed

  • The default session briefing is smaller. It now leaves out the parts the host already carries itself and injects this project's own recent memory and the live repository state. memesh config set briefing full brings the old behaviour back.
  • import no longer brings back a memory you archived (#363).

Fixed

  • Imported bundles can no longer grant themselves behavioural authority (#359, #361): fields that change how MeMesh behaves (guards, the demo marker, task state and similar) are refused, or accepted only after validation.
  • Pre-edit recall no longer injects unrelated memories or session bookkeeping in place of what is relevant to the file being edited (#358).
  • The prompt reminder hook works when MeMesh is installed under a symlinked path (#372); before, it exited having done nothing.
  • A guard warning is no longer lost to a slow lock: the counter that tallies guard fires now waits at most 200 ms for the database (#366).
  • A failed memory read is reported as a failure, not as an empty project, and an unreadable message inbox is recorded instead of looking like a clean run (#386, #394).
  • Stale task state (older than 72 hours, or of unknown age) is flagged instead of being presented as current.

For contributors

  • The tests with tight time limits that failed at random on slow Windows runners have generous limits now.

Full detail: CHANGELOG.md.

v4.10.1

v4.10.1 Pre-release
Pre-release

Choose a tag to compare

@kevintseng kevintseng released this 19 Sep 16:24
554e714

This is a trial release on the npm next tag. latest stays at 4.9.4 until the trial has been observed for at least one working day.

npm install -g @pcircle/memesh@next

4.10.1 includes everything listed under 4.10.0 in the changelog; 4.10.0 was never published to npm.

Fixed

  • Quiet commits are now remembered (#321). git commit -q, redirected output, merges, cherry-picks and reverts were invisible to MeMesh because it read the command's text output. It now reads the repository's state instead, and records a reason whenever it skips.
  • A forgotten observation stays forgotten (#346). Removing one sentence from a session summary used to be silently undone at the end of the next turn. It now stays removed; remember brings it back if you change your mind.
  • Session memories keep up with a long session (#322). They were frozen at the first turn. They now reflect the latest state, and an entity you archived with forget is left alone.
  • Dashboard tells the truth when it cannot read your settings. It shows "unknown" with a reload hint instead of claiming automatic updates are off. Update-check failures explain how to retry, and permission failures in auto-repair say what to do next — in every supported language.
  • memesh doctor no longer reports a failed first update check as "never attempted", or an unpublished local build as npm's latest.

For contributors

  • qa:live-journey now runs five core memory journeys before every real Codex or Claude host check; --core-only runs them without credentials.
  • Releases go to npm next first; promotion to latest is a separate, later step.

Full detail, with links to the incident write-ups: CHANGELOG.md.

v4.9.4

Choose a tag to compare

@kevintseng kevintseng released this 10 Sep 06:19
ed09174

Fixed

  • Plugin upgrades now fail closed before cache replacement when the staged
    artifact is incomplete.
    Before an upgrade can swap the live cache, the
    updater validates every hook, plugin manifest, and MCP entrypoint in the
    staged copy; missing or swapped targets leave the existing cache and
    registry unchanged. The release gate runs the same checker and additionally
    confirms every target is present in the npm-packed artifact.
  • Release audits no longer inherit an unsafe or unbounded npm cache. The
    consumer audit uses a private temporary cache and bounded subprocess
    lifetimes, reporting a controlled failure instead of hanging or being
    affected by root-owned cache state.
  • Pre-release coverage now protects the updater's own checker. A copied
    or incomplete updater refuses to install a plugin archive when its trusted
    artifact-integrity checker is absent.
  • The npm package ships the checker's one dependency. The
    artifact-integrity checker imports scripts/lib/npm-bin.mjs, which the
    package did not include, so the checker could not load from an npm install
    and memesh upgrade-plugin — which prefers the npm-installed copy of the
    updater — would have refused every upgrade. A test now unpacks the real
    tarball and runs the checker from it. The checker also rejects a symlinked
    directory above a hook target, not only a symlinked file.

v4.9.3

Choose a tag to compare

@kevintseng kevintseng released this 09 Sep 13:45
3b01cf6

Fixed

  • Codex SessionEnd no longer requests an unsupported hook timeout. The
    lifecycle hook now declares the host-compatible three-second ceiling, so
    Codex does not clamp the packaged manifest at load time.

v4.9.1

Choose a tag to compare

@kevintseng kevintseng released this 09 Sep 07:13
6f9c5e4

Fixed

  • First-use update guidance is now channel-aware and session-safe. Only
    supported npm-global installs can record consent for the Stop-hook updater;
    project-local, source-checkout, and plugin-marketplace installs receive the
    correct foreground action instead of a misleading upgrade prompt.
  • Concurrent and interrupted first-use prompts no longer lose the notice.
    Session-scoped claims are atomic, finalize only after output is emitted, and
    reclaim a pending claim only when its owner process is confirmed gone.
  • Post-release dogfood regressions are closed. Recall matching, router
    failure reporting, bundled server startup, dashboard navigation, doctor
    repairs, and release-surface contracts now have focused regression coverage.

v4.9.0

Choose a tag to compare

@kevintseng kevintseng released this 08 Sep 12:37
7d55904

v4.9.0

MeMesh now uses one local memory path, with bounded work packages for agents and clearer live-message delivery states.

What users will notice

  • Recall uses SQLite FTS5, and capture uses deterministic hooks. Built-in LLM providers, embedding/vector configuration, and model probes are removed.
  • An already-running agent can prepare a bounded digest or Claude transcript work package and submit a proposal for human review. The Dashboard reviews staged proposals; it does not launch agents.
  • Eligible Codex plugin sessions automatically register their exact session, renew their lease, and replace the prior generation on resume. Native acceptance, recipient intake, acknowledgement, and disposition remain separate states.

Quality improvements

  • Observation removal and FTS maintenance are atomic. Index failures roll back, and archived entities stay out of the keyword index.
  • Transcript packages require an unambiguous MCP workspace root and retain bounded redacted evidence for proposal review.
  • Transcript rereads reject content changes even when file size and timestamps stay the same.
  • Dashboard text is larger and higher-contrast, localized proposal labels are consistent, and update notices only recommend genuinely newer versions.
  • Installation, API, architecture, and agent documentation are synchronized with the FTS-only behavior.

Upgrade notes

  • Update your installed package/plugin through its existing installation channel, then run memesh doctor.
  • Retired provider-related settings may remain on disk. Doctor names those keys without printing their values or deleting them.
  • Live messaging requires the host's supported native channel and trusted lifecycle hooks. Use project-scoped message discover to check current registrations; queue acceptance alone is not proof the model read a message.

Verification

  • Full artifact verification, fresh-consumer package smoke, and upgrades from 4.5.1 and 4.8.5.
  • Real Codex and Claude model-visible journeys, including lease renewal, disconnect, and offline durable readback.
  • Claude isolation and trusted-intake checks include explicit operator attestation.