Skip to content

Releases: madeburo/GEO-AI

release: geo-ai-nest v0.1.1 — NestJS module initial public release

Choose a tag to compare

@madeburo madeburo released this 17 Mar 12:32

First npm publish of geo-ai-nest package.

Includes: GeoAIModule (forRoot/forRootAsync), GeoAIService, GeoAIMiddleware,
GeoAIController, GeoAIGuard, GeoAIInterceptor, @isaibot(), @GeoAIMeta()

Security: UA truncation (1024 chars), generateTimeout option (30s default)

Added

  • GeoAIModule — NestJS dynamic module with forRoot (sync) and forRootAsync (async via useFactory, useClass, useExisting)
  • GeoAIService — injectable service wrapping GeoAIInstance from geo-ai-core
  • GeoAIMiddleware — HTTP middleware serving GET /llms.txt, GET /llms-full.txt, GET /.well-known/llms.txt; Express and Fastify adapter-agnostic
  • GeoAIController — auto-registered controller serving GET /robots-ai.txt
  • GeoAIGuard — route guard restricting access to verified AI bot requests
  • GeoAIInterceptor — response interceptor injecting Link header via RxJS tap
  • @IsAIBot() — parameter decorator injecting detected bot name or null
  • @GeoAIMeta() — class/method decorator attaching GEO metadata via SetMetadata
  • GEO_AI_OPTIONS, GEO_AI_ENGINE — DI injection tokens
  • Re-exports all public types and classes from geo-ai-core and geo-ai-core/ai
  • Dual ESM/CJS build (.mjs / .cjs) with full TypeScript declarations

0.2.2

Choose a tag to compare

@madeburo madeburo released this 11 Mar 19:54

Security

geo-ai-core (v0.2.2)

  • [CRITICAL] XSS fix — HTML attribute escaping in SeoGenerator — config-derived values (siteUrl, siteName, etc.) are now escaped via escapeHtmlAttr() before interpolation into <meta> and <link> attribute values. Characters ", ', <, >, & are replaced with &quot;, &#39;, &lt;, &gt;, &amp; respectively. generateJsonLd() is unaffected (returns a plain object).

Fixed

geo-ai-core (v0.2.2)

  • [HIGH] Unbounded MemoryCacheAdapter growth — when all entries were within TTL, evictExpired() found nothing to remove and the store grew past maxEntries. Added FIFO eviction pass after evictExpired(): oldest-inserted entries are deleted until store.size <= maxEntries.

geo-ai-cli (v0.1.1)

  • [MEDIUM] No fetch timeout — validateRemote and the --url branch of runInspect called fetchFn(url) without an AbortController. Introduced safeFetch(url, fetchFn, timeoutMs, maxBytes) helper that aborts after 10 s and returns { timedOut: true }.
  • [MEDIUM] No response size limit — await res.text() read the full body with no cap. safeFetch now streams via ReadableStream and returns { tooLarge: true } if the body exceeds 1 MiB (1 048 576 bytes).
  • [LOW] Direct process.cwd() calls in command functions — runGenerate and runInspect called process.cwd() inline, making them hard to test. Both now accept cwd: string as first parameter (matching runInit); cli.ts passes process.cwd() at call sites.

0.2.1

Choose a tag to compare

@madeburo madeburo released this 11 Mar 18:04

Added

geo-ai-cli (new package — v0.1.0)

A new standalone CLI package for the GEO AI ecosystem.

npm install -g geo-ai-cli
# or per-project:
npm install --save-dev geo-ai-cli

Commands:

  • geo-ai init — scaffolds a geo-ai.config.ts starter file in the current directory with placeholder values for siteName, siteUrl, siteDescription, crawlers, and a provider section. Exits safely if a config already exists.
  • geo-ai generate — loads config (auto-discovers geo-ai.config.ts → .js → .json), calls geo-ai-core to generate content, and writes llms.txt + llms-full.txt to ./public (or --out <path>). Creates the output directory if missing.
  • geo-ai validate — checks that llms.txt and llms-full.txt are present and have valid content. Supports local files (--path <dir>) and remote URLs (--url <url>). Reports pass / warn / fail / not_found per file with actionable recommendations. Exits 1 on any fail or not_found.
  • geo-ai inspect — previews your config: site name, URL, description, crawler rules, output directory, and resource sections with item counts. With --url, fetches and displays remote llms.txt / llms-full.txt content.

Flags:

  • --config <path> — override config file path
  • --out <path> — override output directory (generate)
  • --path <dir> — local directory to validate
  • --url <url> — remote base URL for validate/inspect
  • --help / -h — show help (global or per-command)
  • --version / -v — show version

Error handling:

  • Typed error classes with exit codes: ConfigNotFoundError, ConfigParseError, ConfigValidationError, FsWriteError, NetworkError → exit 1; InternalError → exit 2
  • DEBUG=geo-ai env var prints stack traces to stderr
  • No raw stack traces on stdout

Technical:

  • Zero runtime dependencies beyond geo-ai-core
  • ESM-only build (dist/cli.mjs) with #!/usr/bin/env node shebang
  • Programmatic API via dist/index.mjs with full TypeScript declarations
  • Node.js >= 20 required

Docs

  • Added geo-ai-cli to ecosystem tables and installation sections in geo-ai-core and root README
  • Added description field to geo-ai-core and geo-ai-next package.json for npm listing
  • Added README.md and CHANGELOG.md to files in all three packages
  • geo-ai-core/README.md: new Ecosystem section with package comparison table

0.2.0

Choose a tag to compare

@madeburo madeburo released this 10 Mar 16:07

Fixed

geo-ai-next

  • Production 404 on /llms.txt – middleware and route handler only served content dynamically at runtime; static hosting (Vercel, Netlify, next export) had no files to serve. generateLlmsFiles() now writes static files to public/ as a pre-build step.

geo-ai-next

  • generateLlmsFiles(config) – static file generation for public/llms.txt and public/llms-full.txt before next build
    • Creates output directory if missing
    • Atomic writes (temp file + rename) to prevent partial files
    • Configurable outDir (default: public) and locale
    • Logs progress and file sizes to stdout
    • Throws with descriptive error on failure
  • geo-ai-generate CLI binary – run via npx geo-ai-generate with optional --config flag
  • New exports: GenerateLlmsFilesConfig, GenerateLlmsFilesResult types

0.1.2

Choose a tag to compare

@madeburo madeburo released this 07 Mar 11:43

Docs

  • Updated documentation with new domain geoai.run
  • Added ecosystem overview

0.1.1

Choose a tag to compare

@madeburo madeburo released this 07 Mar 07:29

Bug fixes and improvements for memory safety, type correctness, and build tooling.

Fixed
geo-ai-core

MemoryCrawlStore - bounded memory growth with configurable maxEntries (default 10 000), auto-evicts oldest 20% on overflow
MemoryCacheAdapter - proactive expired entry eviction on set() with configurable maxEntries (default 1 000)
getPriceRange - replaced Math.min(...spread) with iterative loop to prevent stack overflow on large variant arrays
bulkGenerate - batches now run concurrently via Promise.allSettled(), batchSize controls actual parallelism
AiBulkConfig.onProgress - callback type corrected from Resource to AiContext, removed unsafe cast
geo-ai-next

geoAIMiddleware now sets Cache-Control header on llms.txt responses, consistent with createLlmsHandler
New cacheMaxAge option (seconds, default 3600) in both GeoAIMiddlewareConfig and LlmsHandlerConfig
Infrastructure

Root tsconfig.json with paths mapping for cross-package type checking (tsc --noEmit)
Fixed tsup DTS generation - removed composite: true that conflicted with tsup's declaration build

Install
npm install geo-ai-core@0.1.1

or

npm install geo-ai-next@0.1.1

0.1.0

Choose a tag to compare

@madeburo madeburo released this 06 Mar 08:03

geo-ai-core

Universal TypeScript engine for Generative Engine Optimization.

  • createGeoAI(config) — single factory function for all modules
  • llms.txt generation — standard and full format via ContentProvider interface
  • AI crawler management — 16 bots (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, DeepSeekBot, GrokBot, and more) with per-bot allow/disallow rules and robots.txt generation
  • Crawl tracking — GDPR-compliant bot visit logging with SHA-256 IP anonymization
  • AI descriptions — Claude/OpenAI integration with rate limiting and bulk generation (geo-ai-core/ai)
  • SEO signals — meta tags, Link headers, JSON-LD (WebSite/Product/Article)
  • Caching — pluggable TTL cache (in-memory + file-based adapters)
  • Encryption — AES-256-GCM for API keys
  • Zero dependencies, dual ESM/CJS, full TypeScript declarations

geo-ai-next

Thin Next.js wrapper (~200 lines):

  • geoAIMiddleware — intercepts /llms.txt and /llms-full.txt, optional Link header injection
  • createLlmsHandler — App Router route handler
  • Re-exports all public API from geo-ai-core