CodeDecay v0.3.3
CodeDecay v0.3.3
This release sharpens CodeDecay as a local-first PR red-team orchestrator for AI-assisted development.
Highlights
- Adds the reproducible
codedecay benchmarkproof command with deterministic recall, false-positive, cost, LLM, and telemetry metrics. - Adds sticky GitHub Action PR comments so CodeDecay can update one pull request report instead of spamming new comments.
- Adds benchmark-backed launch/README positioning generated from real benchmark output.
- Adds optional memory provider configuration plus safe Mem0 and Supermemory provider adapters.
- Adds
codedecay memory setupwith dry-run defaults and explicit--applybehavior. - Wires configured memory provider context into redteam/agent workflows while keeping external context untrusted.
- Adds JWT auth edge-case knowledge pack groundwork and OSS tool recommendations in doctor output.
Safety guarantees
- Local-first by default.
- No telemetry.
- No required API keys.
- No hidden LLM/model calls.
- Optional external memory providers only run when explicitly configured.
Package
- npm:
@submuxhq/codedecay@0.3.3 - CLI:
codedecay