This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
Summary
AI summaryFixed broken npm packages 1.2.0 and 1.2.1 that caused unsupported protocol errors on install.
Full changelog
Critical fix — versions 1.2.0 and 1.2.1 on npm were broken: the published package.json retained workspace:* literal references for internal dependencies, causing EUNSUPPORTEDPROTOCOL: Unsupported URL Type "workspace:" on every external install.
Both versions are now deprecated on npm with a deprecation notice.
Upgrade
npm install @celiums/[email protected]
What v1.2.2 contains
Same code as v1.2.1 — including all P0 security fixes from the external audit (projectId='all' guard, credentials classifier in remember + journal_write, schema validation in journal_write). Only package.json was fixed.
Security Fixes
- P0 security fixes from external audit: projectId='all' guard, credentials classifier in remember + journal_write, schema validation in journal_write
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About celiums/celiums-memory
Cognitive memory engine with 5,100+ knowledge modules, circadian rhythm awareness, and emotional state tracking (PAD model). Hybrid search (PostgreSQL + Qdrant vectors + Valkey cache), per-user memory isolation, and multi-protocol support (MCP, REST, OpenAI, LangChain, A2A). `npx @celiums/memory` Website
Related context
Related tools
Earlier breaking changes
- v2.0.0 SaaS/UI/monetization framing removed.
Beta — feedback welcome: [email protected]