Repository navigation
Releases: felipesauer/mnema
Release list
mnema 0.1.0-beta (pre-release)
A pre-release of the rebuilt mnema. It is not on npm: install it from the four tarballs attached here, together in one command (@mnema/code depends on the other three at this exact version):
npm i -g \
https://github.com/felipesauer/mnema/releases/download/v0.1.0-beta/mnema-chain-0.1.0-beta.tgz \
https://github.com/felipesauer/mnema/releases/download/v0.1.0-beta/mnema-core-0.1.0-beta.tgz \
https://github.com/felipesauer/mnema/releases/download/v0.1.0-beta/mnema-context-0.1.0-beta.tgz \
https://github.com/felipesauer/mnema/releases/download/v0.1.0-beta/mnema-code-0.1.0-beta.tgz
mnema --version # 0.1.0-betaRequires Node ≥ 22.12.0. SHA256SUMS lists the digest of each tarball. The GitHub Action, the SDK and the editor extension are private packages of this repository and are not shipped here.
This replaces the earlier v0.15.0 pre-release: the same line, renumbered so that it does not read as a continuation of the 0.x alpha.
Changes
The first release of this line: @mnema/code, and the three packages it is built from. The
numbering starts over here: it does not continue the 0.x alpha.
Requires Node ≥ 22.12.0; the packages are ESM-only.
Added
-
A front page that says who it is for. The root README opens with the promise, honest badges and
the first-record recording, then who it is for and when not to use it; one section lists what else
the product does, each with what it does not prove. The package pages gain the log read against
the record, the inherited record,doctor, the plugin's skills and the server-only plugin. -
A guard on commit e-mails. The pull request job that keeps the tool's footer out of the record
now also refuses an author or committer outside*@users.noreply.github.com(GitHub's own
noreply@github.comis allowed as a committer), and the non-merge commits of one pull request
must share a single author address, since the squash turns any other into aCo-authored-by. -
A library door to the record (
packages/sdk, not published):openRecordrecords a decision, accepts
or rejects one, takes a note, reads the brief, the notes and the rules for a path, and verifies the
record, each by calling the function the matching command calls;mnemaHooksreturns the
Claude Agent SDK hooks that hand a session the opening document and ask the record before a write.
A test holds the command line, the MCP server and the library to the same events and the same
refusal codes.@mnema/codegains one subpath,library, which only the SDK is meant to import. -
A VS Code extension for the person who judges (
packages/vscode, not published): a lens over
each file a rule in force addresses, a panel of decisions awaiting judgment that accepts or
rejects through the command line's own decision verb with the required note, a notice when one is proposed while
the window is open, and the verify level and channel state in the status bar. Every read and
write goes through themnemacommand line. -
Decisions inherited from another repository (the
inheritverb): a project points,
in the committed.mnema/inherit.json, at a git repository that holds a record and at one commit of
it.mnema briefprints that record's decisions in force in a section of their own, naming the
repository and the commit; they are read and never signed by the project, and the project's
verifydoes not count them. A record that does not verify at the commit prints none, and the
brief says so. Moving the pointer is explicit and shows what changes first; the copy is kept
under the mnema home, outside the project. Inheriting is trusting that repository at that commit. -
A rule can carry its check (the
checkcommand): a decision in force names the program that
checks it, and a machine with a key of its own records, at a commit, whether the rule held. That
key is enrolled by a member of an identity (the--checkerform of the key request and enroll
commands) and signs check results only:mnema verifyrefuses a check result from any other key
and any other fact from that key, andmnema accountabilitylists it as a machine. Four new event
kinds, read by both verifiers. -
A GitHub Action over the record (
packages/action, not published): on a pull request it keeps
one comment saying which events the pull request adds to the record and which changed files an
accepted rule addresses, and fails the check whenmnema verify --require=signedfails. An
optional input also fails it when a rule that asks for a person addresses a changed file and only
the author has approved. It reads the record and writes nothing but the comment. -
A signed, append-only record in the repository. Decisions with their reasoning and the
options turned down, the patterns a team works by, tasks, handoffs, memories and
observations, as typed facts in.mnema/, committed with the code and handed to every
clone. Every fact is hash-chained, and every write the command line or the MCP server makes
is signed before it returns. -
Three trees to write to: the committed project record the team shares, a private one
for the machine, and a global one for what outlives a project. Every write says which tree
it landed in. -
A lifecycle for decisions. A decision enters
proposed, is in force onceaccepted,
and is changed only by a new decision that supersedes it, never by an edit. A move the gate
does not allow is refused with a typed reason, the same on the command line and over MCP. -
Two surfaces over one record in
@mnema/code: an MCP server over stdio (mnema mcp)
that an agent writes through while it works, and a command line for reading, auditing and
verifying. -
mnema verify, which needs no private key and no network, names the level it reached
instead of answering yes or no, and exits non-zero on a broken record, so it drops into CI.
--require=signedcatches checkpoints taken out from under the events they signed; a cut
that took the newest events with their checkpoint reads as a shorter honest record. -
An outside witness, opt-in.
mnema witness stamphas the public OpenTimestamps
calendars attest a checkpoint's digest, so a record rebuilt later cannot claim a history.
Only the digest leaves the machine. -
Secrets kept out by their format. A value in a shape the product recognizes never
reaches the chain; a password written out in prose does, and nothing deletes a fact
afterwards. -
A Claude Code plugin. A session opens with the decisions in force, the adopted patterns
and the notes recorded for the project — first the ones that share a word with what the
session touches (the files changed in the working tree, the tasks in progress, the branch,
the last three commits), read with no model, then the newest. At each edit, the rules addressed at that file land beside the result
of the write, and a rule recorded as asking for a person holds the write until one decides.
Each channel can be switched off, and switching one off is itself a signed fact. VS Code's
agent and Cursor's command-line agent are handed the opening. -
Reads that pay for what arrived, not for the record. The projection the command line and the
hooks read from is kept on disk beside the record, brought forward by the events that landed
since the last read, and rebuilt whole whenever it cannot be shown to be a continuation (a
sealed segment whose size or modification time changed, the active one whose size changed, a
different record, a different build). A rewrite of the active segment that keeps its size is
not seen by the projection, andverifyrefuses it. Deleting it changes no answer, only the
time. A write numbers, moves and checks who counts from that projection rather than from a
replay held under the lock; measured at 100 thousand events, 0 of 27 writes timed out waiting
for the lock with the projection warm, and 1 of 18 on the first use. -
A console.
mnemaalone at a terminal asks what you want to do here, and its first
door opens a session that reads the record and refuses to write. It needs a window at least
80 columns wide and 42 rows tall. -
@mnema/chain, the proof engine, released on its own with zero runtime dependencies.
Its tarball carries the format's specification (FORMAT.md), the published canonical
vectors and event schema, and a second verifier written from that document in
standard-library Python, importing nothing of the product. -
@mnema/coreand@mnema/context, released because@mnema/codedepends on them: the
work domain (the gate, the projections, identity) and the read-only derivations that turn
the record into the context an agent is handed. -
The read-only package is
@mnema/context. It was called the copilot layer while it was built,
and the name collided with GitHub Copilot, so it is renamed before its first release. -
Licensed under Apache-2.0 alone, with a
NOTICE. The whole repository and every package
carry the Apache License 2.0 and aNOTICEthat credits the author; each tarball ships both. -
Source maps that carry their source. Every map a package ships holds the text of the
files it names, so a debugger in an installed tree can open them. -
A read-only diagram of the state machines, and the timeline and references of one entity
(thediagram,timelineandrefsverbs): mermaid text on stdout, nothing written. -
A signed retraction for notes: a memory or an observation can be taken back by a fact
of its own, and the note stops being offered while its history stays. -
A rule that refuses a write (
refuses-a-write): the relation, the signed fact that
records a refusal at a channel, the switch that turns it off, and one decision that carries
it; the three hosts' pre-write hooks answerdenyfor a path such a rule addresses. -
**Keys compared w...