This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
Summary
AI summaryFixed stdio fallback to spawn local credential form instead of remote relay.
Full changelog
v1.20.4 (2026-04-21)
This release is published under the MIT License.
Bug Fixes
-
Accept SubjectContext arg on save_credentials (
45b9095) -
Cache environment checks with functools.lru_cache to eliminate repetitive import overhead (
d188282) -
Stdio fallback spawns local credential form, not remote relay (
7dd1d59) -
deps: Bump mcp-core to 1.4.3 (
43799d8) -
deps: Lock file maintenance (authlib 1.6.11->1.7.0 security align) (
f14ee2e)
Performance Improvements
- config: Cache environment checks for significant speedup (
d188282)
Detailed Changes: v1.20.3...v1.20.4
Security Fixes
- Dependency authlib upgraded from 1.6.11 to 1.7.0 for security alignment
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About n24q02m/mnemo-mcp
Persistent AI memory with SQLite hybrid search (FTS5 + semantic). Built-in Qwen3 embedding, rclone sync across machines. Zero config, no cloud, no limits.
Related context
Beta — feedback welcome: [email protected]