changelog: dependency audit 2026-09-19 — mempalace 3.10.0 measured and deliberately deferred
Every row by direct command: npm/PyPI/GitHub release APIs, git ls-remote, the v1.9.2 config labels via the registry API, and binaries in a running v1.9.2 container for the floating tools. Only pin with a newer upstream is mempalace 3.9.0 -> 3.10.0, and it is NOT a small bump: new installs move to ~/.config/mempalace (entrypoint-user.sh tests ~/.mempalace/palace and entrypoint.sh persists ~/.mempalace, so a fresh container would initialise outside the volume), and mempalace_event_list flips to newest-first by default (the toolkit's deriveClosed passes no order, deriveOwed on 2 of 3 calls — server-default-dependent). Deferred to its own release with the three measured preconditions listed.
This commit is contained in:
@@ -13,6 +13,56 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
|
|||||||
|
|
||||||
## Unreleased
|
## Unreleased
|
||||||
|
|
||||||
|
### Dependency audit (2026-09-19)
|
||||||
|
|
||||||
|
Every component checked against upstream by direct command, not assumed. "Baked"
|
||||||
|
is v1.9.2's published amd64 config labels (read through the registry API) or,
|
||||||
|
for the floating `*_VERSION=latest` tools, the binaries in a running v1.9.2
|
||||||
|
container.
|
||||||
|
|
||||||
|
| Component | Baked in v1.9.2 | Upstream now | Action |
|
||||||
|
|---|---|---|---|
|
||||||
|
| pi | `0.85.1` (pinned) | `0.85.1` is npm latest (2026-09-05) | none |
|
||||||
|
| pi-atelier | `v0.10.1` (pinned) | `v0.10.1` highest tag | none |
|
||||||
|
| **mempalace** | `3.9.0` (pinned) | **`3.10.0`** (2026-09-16) | **not adopted — see below** |
|
||||||
|
| skillset (mempalace fallback snapshot) | `e9e45f7` | `--check` OK: `skills/mempalace/SKILL.md` byte-identical at skillset `debc8f6` | none |
|
||||||
|
| **mempalace-toolkit** | `dab989b` | **`817b3a8`** | ships the mine-deadline fix (above) |
|
||||||
|
| **pi-toolkit** | `adfb553` | **`9c87ee8`** | ships the `task`-first AGENTS.md (above) |
|
||||||
|
| **pi-extensions** | `2610545` | **`25c1265`** | ships `task.ts` + `fork-gate.ts` (above) |
|
||||||
|
| pi-fork | `e69725c` | `e69725c` | none |
|
||||||
|
| **pi-observational-memory** | `7b397f4` (3.1.1) | **`cba0334`** (3.1.3) | adopted implicitly via `master` (above); peerDeps still `*`, no pi floor to clear |
|
||||||
|
| pi-studio (studio variant) | `e04fc7a` | `e04fc7a` highest semver tag | none |
|
||||||
|
| floating `*_VERSION=latest` tools | — | 14 of 16 already at latest; `uv` `0.12.13`→`0.12.17` (four patch releases, none with a Breaking section), `agent-browser` `0.37.1`→`0.38.1` (minor: `screenshot --if-changed`, `snapshot --delta`, persistent refs; `.1` is a recording-timing fix) | adopted implicitly by the rebuild; named here per this repo's floating-ref rule |
|
||||||
|
| node | major pin `24`, installed `v24.21.0` | `v24.21.0` newest 24.x | none |
|
||||||
|
|
||||||
|
**mempalace 3.10.0 is deliberately not in this release.** It is not a small
|
||||||
|
bump: a Rust exact-vector engine, four modules split into packages, and three
|
||||||
|
agent-facing contract changes, two of which touch this image directly —
|
||||||
|
|
||||||
|
- **New installs put config and palace under `~/.config/mempalace`.**
|
||||||
|
`entrypoint-user.sh` decides "first run" by `[ ! -d ~/.mempalace/palace ]`
|
||||||
|
and `entrypoint.sh` provisions `~/.mempalace` as the persisted path. On
|
||||||
|
3.10.0 a fresh container would initialise into `~/.config/mempalace` —
|
||||||
|
outside the volume — and the entrypoint's test would stay true on every
|
||||||
|
start. Whether `MEMPALACE_HOME`/config resolution honours the old path on a
|
||||||
|
*pre-existing* `~/.mempalace` is stated ("unchanged") but unmeasured here.
|
||||||
|
- **`mempalace_event_list` defaults to newest-first when no cursor or `order`
|
||||||
|
is given.** The toolkit's `deriveOwed` passes `order: "desc"` on two of its
|
||||||
|
three queries and `deriveClosed` on neither, so their windows are
|
||||||
|
server-default-dependent. That is a server-side skew (the hub is synlig's
|
||||||
|
stack, whose default image is `joakimp/pi-devbox:latest` — so this pin *is*
|
||||||
|
the server's next version), and the right fix is in the toolkit: pass
|
||||||
|
`order` explicitly on every `event_list` call so the derivation is the same
|
||||||
|
on 3.9 and 3.10 servers. Filed as follow-up; not a blocker for this tag.
|
||||||
|
- `mempalace rules` dropped `--agent`; `get_collection()` refuses unknown
|
||||||
|
names — no caller of either in this repo or the toolkit (grepped).
|
||||||
|
|
||||||
|
Adopting it needs its own release: the entrypoint path test, a measured
|
||||||
|
upgrade of an existing `~/.mempalace`, the toolkit `order` hardening, and the
|
||||||
|
synlig redeploy sequencing the pin comment in `Dockerfile.base` describes.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
**New check 9 in `scripts/check-doc-drift.sh`: anything the next build would bake
|
**New check 9 in `scripts/check-doc-drift.sh`: anything the next build would bake
|
||||||
differently from the last *published* release must be named in the CHANGELOG text
|
differently from the last *published* release must be named in the CHANGELOG text
|
||||||
above that release's heading.** The two entries below this one are why. The
|
above that release's heading.** The two entries below this one are why. The
|
||||||
|
|||||||
Reference in New Issue
Block a user