This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+11 more
Summary
AI summaryUpdates Release Links, Verification Standard, and Patch Changes across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Redacts Gemini/Vertex authentication failures to scalar summaries and clears ambient provider credentials in tests. Redacts Gemini/Vertex authentication failures to scalar summaries and clears ambient provider credentials in tests. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds lesson-retrieval.js, lesson-reranker.js, cross-encoder-reranker.js, and lesson-embedding-index.js to public npm package. Adds lesson-retrieval.js, lesson-reranker.js, cross-encoder-reranker.js, and lesson-embedding-index.js to public npm package. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Raises audited public-bundle ceiling from 333 to 337 files intentionally. Raises audited public-bundle ceiling from 333 to 337 files intentionally. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Reduces guardrail noise by limiting network warnings to executable egress and requiring contextual recurring-memory matches before hard denial. Reduces guardrail noise by limiting network warnings to executable egress and requiring contextual recurring-memory matches before hard denial. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Makes self-harness prompt mutation explicit opt-in instead of silently editing and committing AGENTS.md/GEMINI.md after negative feedback. Makes self-harness prompt mutation explicit opt-in instead of silently editing and committing AGENTS.md/GEMINI.md after negative feedback. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
[email protected]
Release Links
- npm: https://www.npmjs.com/package/thumbgate/v/1.28.3
- GitHub Release: https://github.com/IgorGanapolsky/ThumbGate/releases/tag/v1.28.3
- Compare: https://github.com/IgorGanapolsky/ThumbGate/compare/v1.28.2...v1.28.3
- Publish workflow: https://github.com/IgorGanapolsky/ThumbGate/actions/runs/29441789061
- npm published at: 2026-07-15T18:46:01.172Z
- npm shasum:
bbf2d445058fd4bf48a82c4368492838d2b89afa - npm tarball: https://registry.npmjs.org/thumbgate/-/thumbgate-1.28.3.tgz
- Release ref: 2f3f223e36060aee6a4b572256ae241c95e13a91
npm Email Companion
npm controls the native "Successfully published" email template, so the email itself stays short. Treat this generated artifact as the full release-note companion for that email: it carries the Changeset summaries, CHANGELOG entry, publish workflow, npm tarball, and shasum when available.
Full Changeset Release Notes
No changed .changeset/*.md entries were detected for this release range.
CHANGELOG.md Entry
1.28.3
Patch Changes
-
Capture explicit thumbs feedback in the same turn with a durable event ID, distinguish capture from reusable-memory promotion, and deduplicate repeated hook deliveries including emoji-only signals without storing raw session identifiers.
Expose only executable MCP tools for the active profile, label unavailable private-core capabilities internally, use the documented
essentialfactory profile, and fail clearly instead of returning an empty retrieval result when a required capability is missing.Ship
lesson-retrieval.js,lesson-reranker.js,cross-encoder-reranker.js, andlesson-embedding-index.jsin the public npm package soretrieve_lessonsworks after installation. This intentionally raises the audited public-bundle ceiling from 333 to 337 files.Reduce guardrail noise by limiting network warnings to executable egress, applying task scope only to mutating actions, and requiring contextual recurring-memory matches before hard denial. Self-harness prompt mutation is now explicit opt-in instead of silently editing and committing
AGENTS.md/GEMINI.mdafter negative feedback.Keep learned deny/warn policy advisory for read-only inspection, while retaining the prediction in structured diagnostics and preserving enforcement for execution-oriented actions.
Redact Gemini/Vertex authentication failures to scalar summaries and clear ambient provider credentials in tests so an accidental live authentication call cannot expose structured credential metadata.
Verification Standard
- Publish only runs from
mainafter version sync, tests, and runtime proof pass. - The npm package is smoke-tested after publish by installing
thumbgate@VERSIONin a clean runtime. - GitHub Release notes are generated from Changesets, not only GitHub auto-generated PR titles.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About IgorGanapolsky/mcp-memory-gateway
Pre-action gates that prevent AI coding agents from repeating known mistakes. Captures explicit feedback, auto-promotes failures into prevention rules, and enforces them via hooks.
Beta — feedback welcome: [email protected]