Skip to content

chore(release): memhub v0.87.0 - #278

Merged
sgonz-xtrace merged 3 commits into
mainfrom
promote/memhub-v0.87.0
Sep 25, 2026
Merged

sgonz-xtrace merged 3 commits into
mainfrom
promote/memhub-v0.87.0

Conversation

@sgonz-xtrace

Copy link
Copy Markdown
Contributor

MemHub plugin v0.87.0, built from internal main.

Source-RevId: 711c0c1a0d8f88353d4bb9e970232852576706bf
SHA256SUMS: 3c93e12af37b689d271c5ac1a41f2c5743ef62248617c0e7417865b38a685749

Built by promote run 36077808698 at XTraceAI/agent-plugins-internal@711c0c1a0d8f88353d4bb9e970232852576706bf: the plugin suites pass at that commit, and the
export is verified — named memhub, one version across all four manifests, the production
backend in .mcp.json, and nothing shaped like a credential. Every file's digest was
re-checked against SHA256SUMS in the clone this branch was pushed from, so what is here is
what that run produced.

This PR replaces plugins/memhub/ and nothing else.

Before this can merge: main requires the Real agent evidence check, which is a commit
status, not a check run — it exists only once someone dispatches it on this PR's exact head:

gh workflow run real-agent-evidence.yml -R XTraceAI/agent-plugins --ref promote/memhub-v0.87.0

Push again and the new head needs a new run.

After merge, in this order (RELEASING.md):

  1. Tag the merge commit memhub--v0.87.0 and push the tag first — the Claude pin
    cannot resolve a ref that is not there yet.
  2. Move ref and sha in .claude-plugin/marketplace.json to that tag, by PR.
  3. Smoke-test Claude, Codex and Cursor.

Codex and Cursor ship the moment this merges: their catalogs carry no pin and cache by
version string.

Promoted from XTraceAI/agent-plugins-internal by scripts/promote_ship.py.

Source-RevId: 711c0c1a0d8f88353d4bb9e970232852576706bf
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 00:38 — with GitHub Actions Active
@sgonz-xtrace
sgonz-xtrace had a problem deploying to production-plugin-release September 25, 2026 00:38 — with GitHub Actions Failure
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 00:38 — with GitHub Actions Active
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 00:38 — with GitHub Actions Active
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 00:50 — with GitHub Actions Active
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 00:50 — with GitHub Actions Active
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 00:50 — with GitHub Actions Active
…1145)

A promotion replaces plugins/memhub/ only, so public's tests/ and README
stayed at 0.76.1 while the plugin moved to 0.87.0. Six suites then failed
guard and probe-tests on #278, each on an intentional internal change:
the add_memory gate (22 hooks, #57), the companion skill (#47/#51), the
author-child guard (#58), the one-line spec reminder (#61/#63), and the
rulebook-verify and starter-rulebook wording/source_ref changes.

The six suites are internal's at 711c0c1 (the promoted commit), with
plugins/memhub-staging rewritten to plugins/memhub. The README gains the
/memhub:companion entry and the seventeen-skill count the doc test pins.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H6kYog7yKLFVuXb12AAF2m
test: bring public's suites and README up to the v0.87.0 plugin (ENG-1145)
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 02:02 — with GitHub Actions Active
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 02:03 — with GitHub Actions Active
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 02:03 — with GitHub Actions Active
@sgonz-xtrace
sgonz-xtrace deployed to production-plugin-release September 25, 2026 02:03 — with GitHub Actions Active

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f5b1eddd5f

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment on lines +698 to +700
patch = inp.get("command") if isinstance(inp, dict) else None
if not isinstance(patch, str) or "*** Begin Patch" not in patch:
return []

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Read Codex patches from their actual input field

Codex hook payloads provide an apply_patch body as tool_input.patch (as exercised in tests/codex_hooks_setup_test.py), while transcript parsing also recognizes input; neither reaches this command lookup. Consequently apply_patch_files returns no files for normal Codex edits, so the newly added synthetic edit events never run and Codex edit/ordering rules and gates remain silent for every patch.

Useful? React with 👍 / 👎.

Comment on lines +77 to +81
name = payload.get("tool_name")
if not isinstance(name, str) or not _ADD_MEMORY.match(name):
return False
args = payload.get("tool_input")
return isinstance(args, dict) and "user_message" in args

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Limit the memory gate to MemHub servers

When capture is active, this accepts any MCP tool whose name ends in __add_memory and happens to have a user_message argument. An unrelated installed MCP server can legitimately expose mcp__other_service__add_memory with that shape, and its calls will then be denied as though they were MemHub writes, removing that server's tool from Claude sessions that have this plugin enabled.

Useful? React with 👍 / 👎.

@sgonz-xtrace
sgonz-xtrace merged commit 5ac4962 into main Sep 25, 2026
12 checks passed

This branch was successfully deployed

1 active deployment
production-plugin-release — f5b1eddd Deployed Sep 25, 2026 by sgonz-xtrace via Real agent session (claude candidate) #75
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant