Skip to content

cdeust/Cortex

v3.18.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1d MCP Data & Storage
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent-memory-system anthropic artificial-intelligence causal-inference claude claude-code
+14 more
claude-code-plugin cognitive-architecture cognitive-science episodic-memory hopfield-network llm-memory long-term-memory mcp-server model-context-protocol neuroscience persistent-memory predictive-coding retrieval-augmented-generation vector-db

Affected surfaces

auth

Summary

AI summary

Updates viz, zera, and test across a mixed release.

Full changelog
  • fix(security): escape quotes in HTML attrs + mark node-id hash non-security
  • feat(viz): surface AP all-file edges — doc References + File→File imports
  • style(viz): ruff format _git_versions + impact rollup (CI lint)
  • feat(viz): full AP direction/versioning/causal in trace + bump 3.18.0
  • fix(test): I2 heat_base allow-list line numbers after viz merge
  • feat(viz): galaxy-style cluster separation + type-banded session disks
  • fix(lint): ruff format + remove dead locals/imports in viz files
  • Merge remote-tracking branch 'origin/main' into viz-to-main
  • feat(viz): live execution-trace graph — domain→session→chain, impact diagram, unified panel
  • feat(viz): server-side streaming pipeline for the graph data layer
  • Merge remote-tracking branch 'origin/main'
  • fix: silent-truncation zips in paper-critical paths + dangling asyncio task
  • fix(pg_store): atexit-close pool — stops hook process leak (~3-6 conn/leak)
  • ci(pypi): restore PyPI publish into release.yml as a deprecated channel
  • fix(viz): page the phase endpoint — default loader no longer dies on L5
  • tune(zera): chunk at 60K items (~100 MB/chunk) for V8 headroom
  • feat(zera): chunked payload frames — defeat the V8 max-string-length wall
  • fix(viz): phase-buffer race (L5 truncated JSON) + quadtree ERR_EMPTY_RESPONSE
  • fix(zera): TypeError on live graph (non-JSON values) + on-demand zstd level
  • fix(viz): ZERA endpoint shipped empty bundle + wire JS decoder into viz
  • feat(viz): /api/graph.zera — ZERA bundle transport for the neural graph
  • fix(viz): race in /api/graph — Content-Length set, body truncated/empty

What's Changed

  • feat(viz): server-side streaming pipeline for the graph data layer by @cdeust in https://github.com/cdeust/Cortex/pull/50

Full Changelog: https://github.com/cdeust/Cortex/compare/v3.17.2...v3.18.0

Security Fixes

  • fix(security): escape quotes in HTML attributes

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track cdeust/Cortex

Get notified when new releases ship.

Sign up free

About cdeust/Cortex

Persistent memory for Claude Code grounded in computational neuroscience (41 cited papers)

All releases →

Beta — feedback welcome: [email protected]