Skip to content

claude-flow

v3.22.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agentic-ai agentic-framework agentic-workflow agents ai-agents ai-assistant
+14 more
ai-coding ai-skills autonomous-agents claude-code codex harness mcp-server multi-agent multi-agent-systems npm skills swarm swarm-intelligence typescript

Summary

AI summary

Adds a self‑learning memory distillation loop, real failure‑signal capture, and natural‑language browser intents.

Full changelog

Highlights

  • ADR-174 — Memory distillation self-learning loop. The daemon's consolidate worker was a stub writing zeros; it now really mines memory_entries → episodes → reasoning_patterns (+embeddings) → weak relational edges. $0 default, incremental, non-destructive, provenance-gated (ADR-171). memory distill run|status|config CLI + self-optimization (distill-tuning). Trains the local SONA/MoE model on your own memory.
  • Failure-signal capture. Hooks recorded a hardcoded success:true (898/898, 0 failures) — now they read Claude Code's PostToolUse outcome and record real failures, so the oracle tier finally has negative examples.
  • ADR-175 — page-agent browser intent. New browser_act MCP tool: natural-language intents on top of the selector tools. Strips page-agent's demo auto-connect to Alibaba's sandbox (fail-closed firewall) and proxies the LLM key so it never enters page context.
  • Version-stamped helper auto-refresh (secured). Hook fixes now propagate to every project on the next ruflo command — no re-init — gated by an Ed25519 signed manifest (key in GCP Secret Manager); a tampered helper is refused, not propagated.

Also: statusline vector-count + corruption auto-recovery (#2569), memory-search recall (#2558), agenticow/memory perf.

All backward-compatible additions. 3-package train (@claude-flow/cli, claude-flow, ruflo) at 3.22.0.

🤖 Generated with RuFlo

Security Fixes

  • Version‑stamped helper auto‑refresh guarded by Ed25519 signed manifest prevents tampered helper propagation

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track claude-flow

Get notified when new releases ship.

Sign up free

About claude-flow

Deploy multi-agent swarms with coordinated workflows.

All releases →

Related context

Beta — feedback welcome: [email protected]