Skip to content

release: v0.6.0 — owner-scoped memory security hardening - #4

Open
Pash10g wants to merge 4 commits into
mainfrom
release/0.6.0
Open

Pash10g wants to merge 4 commits into
mainfrom
release/0.6.0

Conversation

@Pash10g

@Pash10g Pash10g commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Harden memory operations with trusted owner scopes and fail-closed defaults.
  • Document breaking API changes and migration guidance.
  • Fix package declaration exports and validate built artifacts before publication.

Validation

  • 145 unit tests passed.
  • Type-check and build passed.
  • Package exports and ESM/CommonJS smoke checks passed.
  • Atlas integration tests NOT run: MONGODB_URI unavailable. Release requested with this limitation acknowledged.

Merging triggers the existing v0.6.0 tag and npm publishing workflow.

@caseyclements caseyclements left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need to have integration tests run. This should be added to MongoDB's ai-ml-pipeline-testing CI project.

Comment thread package.json
Comment on lines +33 to +37
"types": "./dist/index.d.mts",
"default": "./dist/index.js"
},
"require": {
"types": "./dist/index.d.cts",
"types": "./dist/index.d.ts",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great catch. This fixes a real bug on main, as there's no top-level "type" field. Not caused by this PR, but worth fixing in a follow-up: ./dist/index.js contains ESM code, and the package has no "type": "module", so Node treats .js files as CommonJS. Node falls back to re-parsing it as ESM and prints a "Masquerading as ESM" warning.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks. Agreed that adding "type": "module" (or renaming the ESM output to .mjs) should be a follow-up, since it changes how every .js file resolves and needs its own compatibility check.

Comment thread src/store.ts
Comment thread src/store.ts Outdated
@Pash10g

Pash10g commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@caseyclements On it :)

@Pash10g

Pash10g commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@caseyclements Fixes done

@Pash10g
Pash10g requested a review from caseyclements October 7, 2026 12:58
@caseyclements

Copy link
Copy Markdown

@Pash10g - Were you able to run the integration tests against a running mongodb?

@Pash10g

Pash10g commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor Author

@caseyclements Better! I have placed a whole CI with an Atlas container: https://github.com/mongodb-developer/vercel-ai-memory/actions/runs/37600975386

However , I am fixing a blocker I found with AI sdk 7:

A real issue: v7 replaced experimental_context with runtimeContext, breaking your package's "context mode" hook (which still reads event.experimental_context at src/session-hooks.ts:152), so it silently saves no transcript. The alternative "closure mode" hook works fine on v7 but requires building the agent per-request.

@@ -0,0 +1,43 @@
# `ai-ml-pipeline-testing` integration

Files for MongoDB's [`ai-ml-pipeline-testing`](https://github.com/mongodb-labs/ai-ml-pipeline-testing)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did you get this working? If so, awesome. Could you please send a link to a passing evergreen build?

We'll need to organize a time to demonstrate the ai-ml-pipeline-testing project, and after anyone can add their new work to it so that they can run integration tests with secrets, keys, access to the needed tools that github doesn't provide.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

evergreen? I am not familiar on how this works. There is a CI in the github ... Can you help looking if anything was added to evergreen..

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since there is a blocking bug covered in this release maybe we can leave evergreen to a later point?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants