Repository navigation
Releases: madeburo/GEO-AI
Release list
release: geo-ai-nest v0.1.1 — NestJS module initial public release
First npm publish of geo-ai-nest package.
Includes: GeoAIModule (forRoot/forRootAsync), GeoAIService, GeoAIMiddleware,
GeoAIController, GeoAIGuard, GeoAIInterceptor, @isaibot(), @GeoAIMeta()
Security: UA truncation (1024 chars), generateTimeout option (30s default)
Added
GeoAIModule— NestJS dynamic module withforRoot(sync) andforRootAsync(async viauseFactory,useClass,useExisting)GeoAIService— injectable service wrappingGeoAIInstancefromgeo-ai-coreGeoAIMiddleware— HTTP middleware servingGET /llms.txt,GET /llms-full.txt,GET /.well-known/llms.txt; Express and Fastify adapter-agnosticGeoAIController— auto-registered controller servingGET /robots-ai.txtGeoAIGuard— route guard restricting access to verified AI bot requestsGeoAIInterceptor— response interceptor injectingLinkheader via RxJStap@IsAIBot()— parameter decorator injecting detected bot name ornull@GeoAIMeta()— class/method decorator attaching GEO metadata viaSetMetadataGEO_AI_OPTIONS,GEO_AI_ENGINE— DI injection tokens- Re-exports all public types and classes from
geo-ai-coreandgeo-ai-core/ai - Dual ESM/CJS build (
.mjs/.cjs) with full TypeScript declarations
0.2.2
Security
geo-ai-core (v0.2.2)
- [CRITICAL] XSS fix — HTML attribute escaping in
SeoGenerator— config-derived values (siteUrl,siteName, etc.) are now escaped viaescapeHtmlAttr()before interpolation into<meta>and<link>attribute values. Characters",',<,>,&are replaced with",',<,>,&respectively.generateJsonLd()is unaffected (returns a plain object).
Fixed
geo-ai-core (v0.2.2)
- [HIGH] Unbounded
MemoryCacheAdaptergrowth — when all entries were within TTL,evictExpired()found nothing to remove and the store grew pastmaxEntries. Added FIFO eviction pass afterevictExpired(): oldest-inserted entries are deleted untilstore.size <= maxEntries.
geo-ai-cli (v0.1.1)
- [MEDIUM] No fetch timeout —
validateRemoteand the--urlbranch ofrunInspectcalledfetchFn(url)without anAbortController. IntroducedsafeFetch(url, fetchFn, timeoutMs, maxBytes)helper that aborts after 10 s and returns{ timedOut: true }. - [MEDIUM] No response size limit —
await res.text()read the full body with no cap.safeFetchnow streams viaReadableStreamand returns{ tooLarge: true }if the body exceeds 1 MiB (1 048 576 bytes). - [LOW] Direct
process.cwd()calls in command functions —runGenerateandrunInspectcalledprocess.cwd()inline, making them hard to test. Both now acceptcwd: stringas first parameter (matchingrunInit);cli.tspassesprocess.cwd()at call sites.
0.2.1
Added
geo-ai-cli (new package — v0.1.0)
A new standalone CLI package for the GEO AI ecosystem.
npm install -g geo-ai-cli
# or per-project:
npm install --save-dev geo-ai-cliCommands:
geo-ai init— scaffolds ageo-ai.config.tsstarter file in the current directory with placeholder values forsiteName,siteUrl,siteDescription,crawlers, and aprovidersection. Exits safely if a config already exists.geo-ai generate— loads config (auto-discoversgeo-ai.config.ts→.js→.json), callsgeo-ai-coreto generate content, and writesllms.txt+llms-full.txtto./public(or--out <path>). Creates the output directory if missing.geo-ai validate— checks thatllms.txtandllms-full.txtare present and have valid content. Supports local files (--path <dir>) and remote URLs (--url <url>). Reportspass/warn/fail/not_foundper file with actionable recommendations. Exits1on anyfailornot_found.geo-ai inspect— previews your config: site name, URL, description, crawler rules, output directory, and resource sections with item counts. With--url, fetches and displays remotellms.txt/llms-full.txtcontent.
Flags:
--config <path>— override config file path--out <path>— override output directory (generate)--path <dir>— local directory to validate--url <url>— remote base URL for validate/inspect--help/-h— show help (global or per-command)--version/-v— show version
Error handling:
- Typed error classes with exit codes:
ConfigNotFoundError,ConfigParseError,ConfigValidationError,FsWriteError,NetworkError→ exit1;InternalError→ exit2 DEBUG=geo-aienv var prints stack traces to stderr- No raw stack traces on stdout
Technical:
- Zero runtime dependencies beyond
geo-ai-core - ESM-only build (
dist/cli.mjs) with#!/usr/bin/env nodeshebang - Programmatic API via
dist/index.mjswith full TypeScript declarations - Node.js >= 20 required
Docs
- Added
geo-ai-clito ecosystem tables and installation sections ingeo-ai-coreand root README - Added
descriptionfield togeo-ai-coreandgeo-ai-nextpackage.jsonfor npm listing - Added
README.mdandCHANGELOG.mdtofilesin all three packages geo-ai-core/README.md: new Ecosystem section with package comparison table
0.2.0
Fixed
geo-ai-next
- Production 404 on
/llms.txt– middleware and route handler only served content dynamically at runtime; static hosting (Vercel, Netlify,next export) had no files to serve.generateLlmsFiles()now writes static files topublic/as a pre-build step.
geo-ai-next
generateLlmsFiles(config)– static file generation forpublic/llms.txtandpublic/llms-full.txtbeforenext build- Creates output directory if missing
- Atomic writes (temp file + rename) to prevent partial files
- Configurable
outDir(default:public) andlocale - Logs progress and file sizes to stdout
- Throws with descriptive error on failure
geo-ai-generateCLI binary – run vianpx geo-ai-generatewith optional--configflag- New exports:
GenerateLlmsFilesConfig,GenerateLlmsFilesResulttypes
0.1.2
0.1.1
Bug fixes and improvements for memory safety, type correctness, and build tooling.
Fixed
geo-ai-core
MemoryCrawlStore - bounded memory growth with configurable maxEntries (default 10 000), auto-evicts oldest 20% on overflow
MemoryCacheAdapter - proactive expired entry eviction on set() with configurable maxEntries (default 1 000)
getPriceRange - replaced Math.min(...spread) with iterative loop to prevent stack overflow on large variant arrays
bulkGenerate - batches now run concurrently via Promise.allSettled(), batchSize controls actual parallelism
AiBulkConfig.onProgress - callback type corrected from Resource to AiContext, removed unsafe cast
geo-ai-next
geoAIMiddleware now sets Cache-Control header on llms.txt responses, consistent with createLlmsHandler
New cacheMaxAge option (seconds, default 3600) in both GeoAIMiddlewareConfig and LlmsHandlerConfig
Infrastructure
Root tsconfig.json with paths mapping for cross-package type checking (tsc --noEmit)
Fixed tsup DTS generation - removed composite: true that conflicted with tsup's declaration build
Install
npm install geo-ai-core@0.1.1
or
npm install geo-ai-next@0.1.1
0.1.0
geo-ai-core
Universal TypeScript engine for Generative Engine Optimization.
createGeoAI(config)— single factory function for all modules- llms.txt generation — standard and full format via
ContentProviderinterface - AI crawler management — 16 bots (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, DeepSeekBot, GrokBot, and more) with per-bot allow/disallow rules and robots.txt generation
- Crawl tracking — GDPR-compliant bot visit logging with SHA-256 IP anonymization
- AI descriptions — Claude/OpenAI integration with rate limiting and bulk generation (
geo-ai-core/ai) - SEO signals — meta tags, Link headers, JSON-LD (WebSite/Product/Article)
- Caching — pluggable TTL cache (in-memory + file-based adapters)
- Encryption — AES-256-GCM for API keys
- Zero dependencies, dual ESM/CJS, full TypeScript declarations
geo-ai-next
Thin Next.js wrapper (~200 lines):
geoAIMiddleware— intercepts/llms.txtand/llms-full.txt, optional Link header injectioncreateLlmsHandler— App Router route handler- Re-exports all public API from
geo-ai-core