Skip to content

sheawinkler/ContextLattice

v3.7.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent-framework agent-orchestration ai-infra ai-interface context-engineering context-management
+4 more
go long-horizon-agents long-horizon-intelligence rust

Affected surfaces

deps

Summary

AI summary

Upgrades the Go MongoDB driver to v1.17.9 and resolves GitHub advisory GHSA-cp6g-7hqx-qxhp.

Full changelog

ContextLattice v3.7.1

Release date: 2026-07-01

v3.7.1 is a security patch for the v3.7 Token Impact Engine train. It upgrades the Go MongoDB driver past the patched advisory floor while preserving the tokenizer-exact prompt economics and bounded token-impact ledger behavior shipped in v3.7.0.

Highlights

  • Upgrades go.mongodb.org/mongo-driver to v1.17.9.
  • Resolves GitHub advisory GHSA-cp6g-7hqx-qxhp for the Go MongoDB driver.
  • Keeps v3.7.0 prompt-economics behavior unchanged: tokenizer-exact accounting, bounded token-impact ledger persistence, and exact/sampled/heuristic dashboard labels.
  • Keeps release-note hygiene in place for public release publishing.

Verification

  • Gateway Go tests passed.
  • Release-note hygiene passed for these notes.
  • Public release body hygiene was verified after publishing.

Upgrade Guidance

Use v3.7.1 wherever v3.7.0 is currently installed. This is a dependency-only security patch; no migration is required.

Security Fixes

  • GHSA-cp6g-7hqx-qxhp — upgrade go.mongodb.org/mongo-driver to v1.17.9

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track sheawinkler/ContextLattice

Get notified when new releases ship.

Sign up free

About sheawinkler/ContextLattice

Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.

All releases →

Related context

Earlier breaking changes

  • v3.17.3 Agent guidance now mandates the `/agents/tasks` route family.
  • v3.17.3 Task worker now checks approval before any execution steps.

Beta — feedback welcome: [email protected]