This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summarySession diary reads are now client-neutral and filter automated/minimal diaries by default.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Credential metadata labels DB vs BYOK local backends, rejects secret-like notes on write and redacts existing secret-like notes in public metadata. Credential metadata labels DB vs BYOK local backends, rejects secret-like notes on write and redacts existing secret-like notes in public metadata. Source: granite4.1:8b-q6_K@2026-05-20 Confidence: high |
— |
| Feature | Medium |
Goals and workflow endpoints exposed on the core MCP server surface. Goals and workflow endpoints exposed on the core MCP server surface. Source: granite4.1:8b-q6_K@2026-05-20 Confidence: high |
— |
| Feature | Medium |
Email diagnostics expose account config and monitor event stores as separate layers. Email diagnostics expose account config and monitor event stores as separate layers. Source: granite4.1:8b-q6_K@2026-05-20 Confidence: low |
— |
| Feature | Medium |
Change-log retention is explicit via NEXO_CHANGE_LOG_RETENTION_DAYS and visible through the dashboard. Change-log retention is explicit via NEXO_CHANGE_LOG_RETENTION_DAYS and visible through the dashboard. Source: granite4.1:8b-q6_K@2026-05-20 Confidence: low |
— |
| Bugfix | Medium |
Session diary reads are client-neutral across Codex, Desktop, Claude Code and future clients. Session diary reads are client-neutral across Codex, Desktop, Claude Code and future clients. Source: granite4.1:8b-q6_K@2026-05-20 Confidence: high |
— |
Full changelog
Fixed
- Session diary reads are client-neutral across Codex, Desktop, Claude Code and future clients while filtering automated/minimal diaries by default.
- Goals and workflow get/list/handoff/compensation/resume/replay are exposed on the core MCP server surface.
- Credential metadata labels DB vs BYOK local backends, rejects secret-like notes on write and redacts existing secret-like notes in public metadata.
- Email diagnostics expose account config and monitor event stores as separate layers.
- Change-log retention is explicit via NEXO_CHANGE_LOG_RETENTION_DAYS and visible through the dashboard.
Verification
- python3 -m py_compile src/db/_episodic.py src/tools_credentials.py src/email_contract.py src/dashboard/app.py src/server.py
- python3 scripts/sync_release_artifacts.py --release-version 7.23.7 --check
- python3 -m pytest tests/test_episodic_memory.py tests/test_fase_b_r02_r09.py tests/test_email_contract.py tests/test_server_protocol_exports.py -q
- npm pack --dry-run --json
- npm view [email protected] version
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About wazionapps/nexo
Cognitive memory for AI agents with Atkinson-Shiffrin memory model (STM/LTM/sensory register), semantic RAG, Ebbinghaus decay, trust scoring, and 76+ MCP tools.
Related context
Beta — feedback welcome: [email protected]