Commit graph

1955 commits

Author SHA1 Message Date
Aditya kumar singh
e3d32b7d52 fix(tools): resolve openai-middleware and voltagent test type errors (#1689) 2026-10-02 18:35:07 -07:00
rajashidattapy
b5db9a725b refactor(tools): narrow memory tool input with a type guard
Replace the bare `block.input as MemoryCommand` assertions in the
Anthropic example with an isMemoryCommand type guard, so unexpected
tool input is skipped instead of silently mistyped.
2026-10-02 18:35:07 -07:00
rajashidattapy
81f1f5ccf1 fix(tools): clear every type error under packages/tools/test
`claude-memory.ts` moved to src/ and five files in test/ kept importing
`./claude-memory`; the Mastra and AI-SDK fixtures drifted behind their
installed types. Together these left `bunx tsc --noEmit` unusable for the
package.

- repoint the five `./claude-memory` imports at `../src/claude-memory`
- add the `state` property Mastra now requires on ProcessInputArgs and
  ProcessOutputResultArgs (35 fixtures)
- add `totalTokens` to the two LanguageModelV2Usage fixtures and drop the
  `rawCall` property the type no longer has
- iterate with `.entries()` instead of indexing, which was tripping
  noUncheckedIndexedAccess once the files started resolving
- pass containerTag/customId through options in test-supermemory.ts, matching
  the current `withSupermemory` signature
- exclude test/chatapp: a standalone Next.js demo with its own package.json,
  lockfile and tsconfig that has no business in this package's program

Repointing the import also made test/claude-memory.test.ts loadable again, and
it turned out to be a live-API suite: gate it behind SUPERMEMORY_API_KEY the
same way the other integration suites are, so `vitest run` no longer collects
a dozen 401s.
2026-10-02 18:35:07 -07:00
Aditya kumar singh
f7e5bf2f77 fix(tools): handle trailing slashes and whitespace in normalizeBaseUrl and addConversation 2026-10-02 18:35:07 -07:00
Agnik47
b89ed824a6 fix(tools): accept zero-argument OpenAI tool calls and reject non-object args
`getProfile`, `documentList` and `memoryForget` all declare `required: []`,
so a model may legitimately call them with no arguments at all. The OpenAI
API serialises that as `arguments: ""`, and `parseToolArguments` handed the
empty string straight to `JSON.parse`, so every no-argument call came back as

    {"success":false,"error":"Invalid JSON arguments for getProfile"}

Those three tools were unreachable in their documented no-argument form.

The same gate also lets non-object JSON through. `"null"` parses cleanly and
then rejects in the destructuring parameter of every tool function --
`TypeError: Cannot destructure property 'containerTag' of 'object null'` --
which escapes `executeToolCall`, since it has no catch, and fails the whole
request. That is precisely the throw #1488 added this gate to contain. `"5"`
and `"\"text\""` are quieter but worse: they destructure to `undefined` and
call the API with no container tag at all.

Treat blank arguments as `{}`, and require the parsed value to be a non-null,
non-array object. Malformed JSON still returns the tool error #1488 added.

Adds eight regression tests. Six of them fail against the current
implementation -- two on the blank-argument path and four on the non-object
path, one carrying the raw TypeError. The two guard tests, malformed JSON and
an ordinary well-formed call, pass both before and after, so the behaviour
2026-10-02 18:35:07 -07:00
abhinav7x94
44869502b1 test(tools): remove redundant result assertions 2026-10-02 18:35:07 -07:00
shamAnimates
8a1cf31af8 test(tools): type scoped operation results 2026-10-02 18:35:07 -07:00
shamAnimates
977b2fcd0a fix(tools): enforce configured container scope 2026-10-02 18:35:07 -07:00
Aditya kumar singh
17ced72233 fix(tools): escape delimiters in makeTurnKey to prevent cache collision 2026-10-02 18:35:07 -07:00
therahul-yo
274e6b6e6a fix(tools): bound and harden the shared /v4/profile request
`supermemoryProfileSearch` in `shared/memory-client.ts` is the only
Supermemory HTTP call in this package with neither a request timeout nor
redirect handling. The identical `/v4/profile` call in
`openai/middleware.ts` sets both, and `/v4/conversations`
(`conversations-client.ts`) and `/v4/memories` (`shared/forget-memory.ts`)
each set a 30s budget.

Two consequences:

- **Unbounded request.** A timeout only applied when the caller supplied a
  signal. `withSupermemory` passes one (5s), but `buildMemoriesText` is
  called with no signal by the Mastra processor and the VoltAgent
  middleware, and by the exported `buildMemoriesText` / `addSystemPrompt`
  helpers. `fetch` has no default deadline, so a stalled connection blocks
  the agent turn indefinitely — the failure both integrations' surrounding
  try/catch is written to absorb, but which never surfaces as an error.
- **Redirects followed.** The request carries `Authorization: Bearer
  <apiKey>`; a 3xx from a misconfigured or attacker-influenced `baseUrl`
  was followed silently rather than refused.

Apply a 30s `PROFILE_REQUEST_TIMEOUT_MS` unconditionally and set
`redirect: "error"`. A caller signal is composed with the timeout via
`AbortSignal.any` rather than replacing it, so a caller-side budget can
only shorten the request, never leave it unbounded — the wrapper is kept
separate so the composition is stated once rather than re-derived at the
call site.

`src/shared/memory-client.test.ts` existed but was absent from the
`test:unit` file list CI runs, so its assertions never ran on a pull
request; add it alongside the new coverage.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L7GkmUn6skD6dCzKtcHDbe
2026-10-02 18:35:07 -07:00
Agnik47
8233cfb99d fix(mcp): keep the getDocuments timeout when a caller passes a signal
Same pattern as forgetMemoryRequest: `options?.signal ?? AbortSignal.timeout(...)`
dropped the 30s bound whenever a caller supplied its own signal. Compose the
two with AbortSignal.any so the caller signal adds cancellation instead of
replacing the timeout.
2026-10-02 18:35:07 -07:00
Agnik47
444b4f1698 fix(tools): keep the forget-memory timeout when a caller passes a signal
`forgetMemoryRequest` combined the caller's signal and the 30s abort with
`??`, making them mutually exclusive. Passing a cancellation signal removed
the timeout, so a hung `DELETE /v4/memories` could wedge the tool call again
— the exact condition #1451 set out to remove. There was also no way for a
caller to ask for both cancellation and a timeout.

Compose the two with `AbortSignal.any` instead of choosing between them.
`AbortSignal.any` is available in Node 20.3+, Bun and workerd.

No production call site passes `options` today (`ai-sdk.ts` and
`openai/tools.ts` both omit it), so this was latent rather than live.

The existing test asserted the buggy behaviour (`init.signal` being the
caller's own signal), so it is replaced by two tests that pin the composed
semantics: aborting the caller aborts the request, and the timeout leg still
aborts the request on its own. Both fail against the previous implementation.

Fixes #1549
2026-10-02 18:35:07 -07:00
Rikinshah787
0d90a15100 fix(tools): handle the memory tool commands Claude actually sends
Three places where ClaudeMemoryTool diverges from the documented
memory_20250818 wire format:

- rename sends old_path/new_path, not path. handleCommand validated
  command.path, so every rename coming from a real model died with
  "Cannot read properties of undefined (reading 'startsWith')".
  path is still accepted as the source for existing callers.
- insert_line means "insert after this line" (0 = top of file), but we
  spliced at insertLine - 1 and rejected 0, so every insert landed one
  line above where Claude asked and inserting at the top was impossible.
- str_replace with new_str omitted is a deletion per the spec; we
  rejected it.

The new tests mock the supermemory client so they run without an API
key. Also fixed the rename example in the docs, which showed the same
path shape the code expected.
2026-10-02 18:35:07 -07:00
Aditya kumar singh
4929603cb4 fix(tools): clean up legacy customId documents during mutations to prevent path ambiguity 2026-10-02 18:35:07 -07:00
Aditya kumar singh
d110df8ad2 fix(tools): handle legacy customIds during document verification 2026-10-02 18:35:07 -07:00
Aditya kumar singh
db64d1369c fix(tools): prevent customId collisions in claude memory tool (#1547) 2026-10-02 18:35:07 -07:00
Aniruddha Adak
b8b95112af fix(tools): reject parent-directory segments in Claude memory paths 2026-10-02 18:35:07 -07:00
Rohit
76470610ff fix(tools): align claude-memory insert with memory_20250818 line semantics
Anthropic's memory_20250818 spec defines insert as: insert_text is inserted
AFTER line insert_line, 0 inserts at the beginning of the file, and the valid
range is [0, n_lines]. The implementation treated insert_line as a 1-based
insert-BEFORE index with range [1, n_lines + 1].

Since the caller of this tool is Claude itself, which is trained on the spec
semantics, every model-driven insert landed one line earlier than intended,
insert_line: 0 (insert at top of file) was rejected as invalid, and
insert_line: n_lines (append) inserted before the last line instead of after
it.

Fix the validation range to [0, n_lines], splice at insert_line directly
(0-based insert-after), and update the error and success messages to match.
One existing tool-operations test encoded the old insert-before behavior; its
insert_line is adjusted so its expected output is unchanged under spec
semantics. Adds four regression tests covering top-of-file, middle,
append, and both out-of-range directions.
2026-10-02 18:35:07 -07:00
abhinav7x94
0d77c8f759 fix(tools): isolate OpenAI middleware clients 2026-10-02 18:35:07 -07:00
Dhravya Shah
62cc57eda6
fix(auth): upgrade Better Auth to patched 1.7.6 (#1719)
Some checks failed
Publish AI SDK / publish (push) Has been cancelled
Publish Memory Graph / publish (push) Has been cancelled
Publish Tools / publish (push) Has been cancelled
Co-authored-by: Mahesh Sanikommu <maheshthedev@gmail.com>
2026-10-02 17:05:13 -07:00
MaheshtheDev
1245d73b6b fix(mcp): clear out-of-credits error and keep it out of error rate (#1753)
- 402 now tells the agent the org is out of credits and links to console.supermemory.ai/billing (the old message said "memory limit" and pointed at the retired app).

- PostHog MCP analytics tags these calls `$mcp_error_type: out_of_credits` with `$mcp_is_error: false`, so an empty balance no longer inflates the MCP error rate.
2026-10-03 00:02:10 +00:00
Dhravya Shah
7187b538cc
docs: add team invitation guide with console screenshots (#1754) 2026-10-02 16:59:55 -07:00
Anirudh Parmar
b85a1bf9bf
fix(CI): add missing read permission and force color (#1750) 2026-10-02 12:08:14 -07:00
dependabot[bot]
bce2d0dc16
chore(deps): bump better-auth from 1.3.3 to 1.6.22 in /packages/lib (#1741)
Some checks failed
Publish LiveKit SDK Python / publish (push) Has been cancelled
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Dhravya <dhravya@supermemory.com>
2026-10-01 17:06:40 -07:00
Dhravya Shah
b36b225375
feat(livekit): add persistent memory for LiveKit Agents (#1702)
Co-authored-by: Ishaan Gupta <ishaankone@gmail.com>
2026-10-01 15:26:35 -07:00
Prasanna
66ce7f8c78
fix docs icons in dark mode (#1735) 2026-09-30 22:00:27 +00:00
Dhravya Shah
79c74f9438
docs: shorten connector sidebar labels (#1734) 2026-09-30 14:45:36 -07:00
Dhravya Shah
ce4facf662
docs: branded OG thumbnails with photo background (#1729)
Some checks failed
Publish OpenAI SDK Python / publish (push) Has been cancelled
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 18:01:29 -07:00
Dhravya Shah
1b958f48c8
docs: explain advanced PDF extraction availability (#1728) 2026-09-29 17:40:50 -07:00
Parthiv
640eeaa8e8
docs: refresh the documentation design (#1715)
Co-authored-by: Dhravya Shah <dhravya@supermemory.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 17:26:13 -07:00
Dhravya Shah
0c74b55693
fix(docs): remove vulnerable ZIP extractor and patch tar via Mintlify (#1727) 2026-09-29 16:59:39 -07:00
Dhravya Shah
83f315fc17
fix(chatapp): patch high severity transitive dependencies (#1723) 2026-09-29 15:28:16 -07:00
Dhravya Shah
e7d7b78d90
fix(mcp): override vulnerable image and HTTP dependencies (#1722) 2026-09-29 15:28:02 -07:00
Dhravya Shah
cf4436bf4b
fix(raycast): patch high severity lockfile vulnerabilities (#1721) 2026-09-29 15:27:27 -07:00
Dhravya Shah
c4382f5ffc
fix(python-sdk): patch vulnerable async and tooling dependencies (#1720) 2026-09-29 15:26:59 -07:00
MaheshtheDev
10e464aac7 feat(mcp): group PostHog MCP tool calls by conversation id (#1718)
The server is stateless HTTP, so every tool call landed in its own PostHog session. Enable conversation ids and let $mcp_conversation_id and $session_id through the metadata filter so echoed handles group calls.
2026-09-29 20:32:36 +00:00
MaheshtheDev
b392bc7d1b Instrument MCP server with metadata-only PostHog analytics (#1712)
## Summary
- Instrument the MCP v2 server with the pinned PostHog MCP Analytics SDK and replace the custom `mcp_tool_executed` wrapper with standard `$mcp_*` events.
- Send only allowlisted metadata, disable schema injection and exception autocapture, and use personless user IDs with person-profile processing disabled.
- Deliver events through immediate capture guarded by Cloudflare `waitUntil`.

## Verification
- The initial implementation passed the MCP typecheck, existing unit suite, Biome, and Wrangler dry-run bundle.
- A local `who_am_i` MCP call returned successfully and emitted a metadata-only `$mcp_tool_call` on the initial implementation.
- All five checks passed on the final `54a2384` head, including the Cloudflare MCP build.

Actual PostHog ingestion is not verified yet; this workspace still needs a PostHog project token and authenticated Supermemory MCP credential.
2026-09-29 06:08:45 +00:00
sohamd22
cfa6c7cb17 fix(memory-graph): distinguish document links from derives relations (#1701)
Document-to-memory links and actual `derives` relations were both emitted as `derives`, so they shared the same color and legend entry.

This separates structural document links into a `document` edge type, adds a dedicated theme color with `--graph-edge-document` support, and updates force-layout and level-of-detail handling to preserve existing structural behavior. The package and MCP widget legends/themes now distinguish document links from derived-memory relations.

Adds regression coverage for edge classification and validates the package plus its MCP consumer.

<!-- capy-badge:start -->
<a href="https://capy.ai/thread/jam_01M36F4MPFXZCA8J14T53YY029"><picture><source media="(prefers-color-scheme: dark)" srcset="https://capy.ai/badge/accent-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://capy.ai/badge/accent-light.svg"><img alt="Open in Capy" src="https://capy.ai/badge/accent-light.svg"></picture></a>
<!-- capy-badge:end -->
2026-09-25 22:00:12 +00:00
Dhravya
0e12f0b3a6 fix(mcp): treat full-scope read grants as read-only 2026-09-22 18:22:26 -07:00
shardulmane10
57b430b5b6 Align billing and Gmail docs with current plan entitlements (#1685)
Some checks failed
Publish Memory Graph / publish (push) Has been cancelled
## Summary

The billing guide omits Max and contradicts the pricing page about Gmail access. Add Max ($100/month with $130 in monthly credits), correct the plan feature matrix, list all six current coding plugins as available on Free with credit-consuming usage, and update both remaining Scale-only requirements on the Gmail connector page to Max or above.

Clarify that paid-plan automatic top-up limits cap automatic credit purchases, not the total invoice, and correct the documented auto-topup update endpoint from PATCH to POST.

Companion website changes: https://github.com/supermemoryai/landing-2/pull/32

## Validation

- Compared prices, credit inclusions, connector gates, and top-up behavior with the console and API source on main. Verified that all six coding plugins are on FREE_TIER_PLUGIN_IDS and the authentication route bypasses the generic Pro gate for them. Usage still consumes plan credits.
- Checked Markdown table column counts and required Max entries; `git diff --check` passed.
- Confirmed the Gmail introduction, prerequisite, and troubleshooting requirement consistently say Max or above.
- Documentation-only change. A full Mintlify build was not run.

Crawler-access verification, AI-search benchmarking, and analytics/measurement work are excluded from this PR.
2026-09-18 22:01:05 +00:00
Prasanna721
8a4d9d76ae release memory graph 0.2.4 (#1686)
Before: npm serves 0.2.3 without the merged fixes.

After: merging publishes 0.2.4 with the theme, initial fit, and node settling fixes.

Validation: package typecheck and build passed.
2026-09-18 21:44:52 +00:00
Prasanna721
2a6dcda7f6 fix graph styling and initial layout (#1684)
**Before:** Console lost its theme and dots. Incoming nodes needed a drag to reorganize, fit missed later pages, and clicks or drag release could leave the layout moving.

**After:** Restore themed rendering with configurable dots. Automatically settle and fit incoming nodes, keep clicks from reheating forces, and cool the layout after drag release.

**Checked:** Package types/build and Console build linked to this package.

Console companion: [mono#3295](https://github.com/supermemoryai/mono/pull/3295).
2026-09-18 21:18:33 +00:00
polylane
b26e917a83 fix(ci): restore bun.lock so frozen dependency install passes (#1680)
**Fixes:** [supermemoryai/supermemory publishes SDKs to npm and PyPI on merge to main with no approval or CI gate](https://console.polylane.com/supermemory/threads/thrd_0b2312a59001ty7ozbknhwen?ref=github.autofix-pr)

The dependency lockfile on this branch had been regenerated by a different Bun version than the one CI pins, so the frozen-install step aborted and took down the quality gate and both Worker builds. Restoring the lockfile to the revision already on main lets those checks install dependencies and run again.

## What caused this

**Affected:** `int_ecd270c87001rlz8v4a308n0`

## Why this fix

Quality Checks (`CI - Type Check, Format & Lint`, run 35297979197) failed on commit f9aeae8 in 16 seconds: steps ran through checkout and bun setup, then step 4 `Install dependencies` failed at 02:05:55Z. Both Cloudflare builds, `Workers Builds: supermemory-app` and `Workers Builds: supermemory-mcp`, failed at the same second, before producing a build, so all three checks died on the same step rather than on any source change.

That commit also carried a regenerated `bun.lock` (401 insertions, 21 deletions) with no accompanying manifest edit, written by the sandbox's Bun 1.2.14 while CI pins `bun@1.3.6`. The regenerated file added `apps/raycast-extension` as a workspace even though the root manifest excludes it, and dropped the `configVersion` marker the pinned release expects. With the lockfile in that state, `bun install --frozen-lockfile` refuses to proceed.

I reproduced both directions with the CI-pinned release: Bun 1.3.6 against the commit's lockfile exits 1 with `lockfile had changes, but lockfile is frozen`, while Bun 1.3.6 against the restored lockfile succeeds (`15 packages installed`). The failing step is the install, and this change removes the mismatch it reads, so the install proceeds and the downstream checks can run.

The workflow edit itself is untouched and still pins the three third-party actions to the same commit SHAs the sibling Python publish workflows use. Reverting the lockfile removes an unrelated dependency-graph rewrite, so the published-artifact behaviour this pull request targets is unchanged.

<details>
<summary>1 file changed (+6/-4)</summary>

- `.github/workflows/publish-openai-sdk-python.yml`: modified, +6/-4

</details>

Repository lint: `bun run lint` (declared in CLAUDE.md) could not run in the sandbox because its tool is not installed there; run it before merging.

<a href="https://console.polylane.com/pages/page_0b2431438001t1tqtbrria8659s7c1o9lb9icrt4?token=eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ0aHJkXzBiMjMxMmE1OTAwMXR5N296YmtuaHdlbiIsIndvcmtzcGFjZV9pZCI6IndzX2VjZDI2NGZlNjAwMTc0MG1mYXF3MHB2eTFiOXV3MnBpIiwicmVwb3NpdG9yeV9pZCI6InJlcG9fZWNkMjc0YTZjMDAxejJrNDJlbXBudGhpIiwib3duZXIiOiJzdXBlcm1lbW9yeWFpIiwicmVwbyI6InN1cGVybWVtb3J5IiwicHJfbnVtYmVyIjoxNjgwLCJpYXQiOjE3ODk2OTcyNzEsImF1ZCI6InBvbHlsYW5lOnByLXRocmVhZC1ndWVzdCIsImV4cCI6MTc5MjI4OTI3MSwiaXNzIjoiaHR0cHM6Ly9hcGkucG9seWxhbmUuY29tIn0.MVY_F-H8-bt2BXF7w4iN9d0HgfB6c_L0zeShWelJq1U&amp;ref=github.autofix-pr"><picture><source media="(prefers-color-scheme: dark)" srcset="https://badges.polylane.com/view-autofix/dark.svg?v=6&amp;face=1"><source media="(prefers-color-scheme: light)" srcset="https://badges.polylane.com/view-autofix/light.svg?v=6&amp;face=1"><img alt="View autofix" src="https://badges.polylane.com/view-autofix/light.svg?v=6&amp;face=1"></picture></a> <a href="https://console.polylane.com/supermemory/threads/thrd_0b2312a59001ty7ozbknhwen?ref=github.autofix-pr"><picture><source media="(prefers-color-scheme: dark)" srcset="https://badges.polylane.com/view-investigation/dark.svg?v=6"><source media="(prefers-color-scheme: light)" srcset="https://badges.polylane.com/view-investigation/light.svg?v=6"><img alt="View thread" src="https://badges.polylane.com/view-investigation/light.svg?v=6"></picture></a>

---

Generated by [Polylane](https://polylane.com/?ref=github.autofix-pr). You can ask follow-ups by mentioning @polylane in a comment.
2026-09-18 20:14:12 +00:00
Dhravya
bf2db3dc79
fix(ci): gate auto-fix to same-repo human runs (#1663)
## Summary

The `workflow_run` auto-fix job has write permissions and checks out the triggering PR branch. It now runs only when all three conditions hold:

- the tracked CI workflow failed on a pull request;
- the pull request branch belongs to this repository, not a fork;
- the triggering actor is not a bot account.

The same-repository check closes the privileged fork boundary. The generic `[bot]` suffix check covers Polylane, Graphite, Dependabot, and other GitHub App bot users without maintaining a name list.

## Validation

- `go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 .github/workflows/claude-auto-fix-ci.yml`
- YAML parse with the repository's installed parser
- Final diff audit: one workflow, +3/-1, no added comments

Human-triggered same-repository pull requests keep the existing auto-fix behavior.
2026-09-18 05:46:34 +00:00
Dhravya Shah
69327ca1c6
Add Muse Code plugin docs (#1674) 2026-09-17 09:36:04 -07:00
Dhravya Shah
c927c98f2c
feat(mcp): add get_profile and use snake_case for public tools (#1665) 2026-09-16 23:37:34 -07:00
Dhravya Shah
a92c21b2dc
chore(ci): disable Claude Code Review on pull requests (#1666) 2026-09-16 23:36:00 -07:00
Dhravya Shah
814f92731a
docs.json: 35 redirects for stale docs IA slugs (GSC Pages report) (#1673) 2026-09-16 20:46:20 -07:00
Prasanna
8652a0e5ea
add eve docs and refresh integrations (#1671) 2026-09-16 15:24:08 -07:00
karthik rajan
2415a5c796
fix(memory-graph): add aria-labels to zoom controls (#1662)
Signed-off-by: Karthik Rajan <karthikrajanmr@gmail.com>
2026-09-11 11:23:37 -07:00