changelog: dependency audit 2026-09-19 — mempalace 3.10.0 measured and deliberately deferred
Lint / hadolint (push) Successful in 9s
Lint / actionlint (push) Successful in 17s
Lint / skill-floor (push) Successful in 8s
Lint / doc-drift (push) Successful in 13s

Every row by direct command: npm/PyPI/GitHub release APIs, git ls-remote,
the v1.9.2 config labels via the registry API, and binaries in a running
v1.9.2 container for the floating tools. Only pin with a newer upstream is
mempalace 3.9.0 -> 3.10.0, and it is NOT a small bump: new installs move to
~/.config/mempalace (entrypoint-user.sh tests ~/.mempalace/palace and
entrypoint.sh persists ~/.mempalace, so a fresh container would initialise
outside the volume), and mempalace_event_list flips to newest-first by
default (the toolkit's deriveClosed passes no order, deriveOwed on 2 of 3
calls — server-default-dependent). Deferred to its own release with the
three measured preconditions listed.
This commit is contained in:
Joakim Persson
2026-09-19 17:38:02 +02:00
parent b9057fdc8c
commit 960aada769
+50
View File
@@ -13,6 +13,56 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
## Unreleased ## Unreleased
### Dependency audit (2026-09-19)
Every component checked against upstream by direct command, not assumed. "Baked"
is v1.9.2's published amd64 config labels (read through the registry API) or,
for the floating `*_VERSION=latest` tools, the binaries in a running v1.9.2
container.
| Component | Baked in v1.9.2 | Upstream now | Action |
|---|---|---|---|
| pi | `0.85.1` (pinned) | `0.85.1` is npm latest (2026-09-05) | none |
| pi-atelier | `v0.10.1` (pinned) | `v0.10.1` highest tag | none |
| **mempalace** | `3.9.0` (pinned) | **`3.10.0`** (2026-09-16) | **not adopted — see below** |
| skillset (mempalace fallback snapshot) | `e9e45f7` | `--check` OK: `skills/mempalace/SKILL.md` byte-identical at skillset `debc8f6` | none |
| **mempalace-toolkit** | `dab989b` | **`817b3a8`** | ships the mine-deadline fix (above) |
| **pi-toolkit** | `adfb553` | **`9c87ee8`** | ships the `task`-first AGENTS.md (above) |
| **pi-extensions** | `2610545` | **`25c1265`** | ships `task.ts` + `fork-gate.ts` (above) |
| pi-fork | `e69725c` | `e69725c` | none |
| **pi-observational-memory** | `7b397f4` (3.1.1) | **`cba0334`** (3.1.3) | adopted implicitly via `master` (above); peerDeps still `*`, no pi floor to clear |
| pi-studio (studio variant) | `e04fc7a` | `e04fc7a` highest semver tag | none |
| floating `*_VERSION=latest` tools | — | 14 of 16 already at latest; `uv` `0.12.13`→`0.12.17` (four patch releases, none with a Breaking section), `agent-browser` `0.37.1`→`0.38.1` (minor: `screenshot --if-changed`, `snapshot --delta`, persistent refs; `.1` is a recording-timing fix) | adopted implicitly by the rebuild; named here per this repo's floating-ref rule |
| node | major pin `24`, installed `v24.21.0` | `v24.21.0` newest 24.x | none |
**mempalace 3.10.0 is deliberately not in this release.** It is not a small
bump: a Rust exact-vector engine, four modules split into packages, and three
agent-facing contract changes, two of which touch this image directly —
- **New installs put config and palace under `~/.config/mempalace`.**
`entrypoint-user.sh` decides "first run" by `[ ! -d ~/.mempalace/palace ]`
and `entrypoint.sh` provisions `~/.mempalace` as the persisted path. On
3.10.0 a fresh container would initialise into `~/.config/mempalace` —
outside the volume — and the entrypoint's test would stay true on every
start. Whether `MEMPALACE_HOME`/config resolution honours the old path on a
*pre-existing* `~/.mempalace` is stated ("unchanged") but unmeasured here.
- **`mempalace_event_list` defaults to newest-first when no cursor or `order`
is given.** The toolkit's `deriveOwed` passes `order: "desc"` on two of its
three queries and `deriveClosed` on neither, so their windows are
server-default-dependent. That is a server-side skew (the hub is synlig's
stack, whose default image is `joakimp/pi-devbox:latest` — so this pin *is*
the server's next version), and the right fix is in the toolkit: pass
`order` explicitly on every `event_list` call so the derivation is the same
on 3.9 and 3.10 servers. Filed as follow-up; not a blocker for this tag.
- `mempalace rules` dropped `--agent`; `get_collection()` refuses unknown
names — no caller of either in this repo or the toolkit (grepped).
Adopting it needs its own release: the entrypoint path test, a measured
upgrade of an existing `~/.mempalace`, the toolkit `order` hardening, and the
synlig redeploy sequencing the pin comment in `Dockerfile.base` describes.
---
**New check 9 in `scripts/check-doc-drift.sh`: anything the next build would bake **New check 9 in `scripts/check-doc-drift.sh`: anything the next build would bake
differently from the last *published* release must be named in the CHANGELOG text differently from the last *published* release must be named in the CHANGELOG text
above that release's heading.** The two entries below this one are why. The above that release's heading.** The two entries below this one are why. The