This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+4 more
Affected surfaces
Summary
AI summaryUpgrades the Go MongoDB driver to v1.17.9 and resolves GitHub advisory GHSA-cp6g-7hqx-qxhp.
Full changelog
ContextLattice v3.7.1
Release date: 2026-07-01
v3.7.1 is a security patch for the v3.7 Token Impact Engine train. It upgrades the Go MongoDB driver past the patched advisory floor while preserving the tokenizer-exact prompt economics and bounded token-impact ledger behavior shipped in v3.7.0.
Highlights
- Upgrades
go.mongodb.org/mongo-drivertov1.17.9. - Resolves GitHub advisory
GHSA-cp6g-7hqx-qxhpfor the Go MongoDB driver. - Keeps v3.7.0 prompt-economics behavior unchanged: tokenizer-exact accounting, bounded token-impact ledger persistence, and exact/sampled/heuristic dashboard labels.
- Keeps release-note hygiene in place for public release publishing.
Verification
- Gateway Go tests passed.
- Release-note hygiene passed for these notes.
- Public release body hygiene was verified after publishing.
Upgrade Guidance
Use v3.7.1 wherever v3.7.0 is currently installed. This is a dependency-only security patch; no migration is required.
Security Fixes
- GHSA-cp6g-7hqx-qxhp — upgrade go.mongodb.org/mongo-driver to v1.17.9
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sheawinkler/ContextLattice
Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.
Related context
Related tools
Beta — feedback welcome: [email protected]