Repository navigation
Conversation
keygen is a top-level command but was only mentioned in the federation event-signing prose; add it to the command table next to the federation block so it's discoverable when scanning the command list. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
chore: reconcile next with released history
…orrectness feat: preserve federation state and add dynamic listeners
* feat: add experimental Rust rewrite and comparison suite * fix: fail closed for unsupported Rust HTTP security * feat: validate persistent MCP and signed federation replay * feat: add mixed Rust federation experiments * feat(rust): add background federation experiments * feat(rust): add authenticated TLS federation * feat(rust): add consolidation election foundation * feat(rust): add consolidation pass coordination * feat(rust): add heuristic promotion pass * feat(rust): add consolidation cadence and graduation * feat(rust): add model-driven consolidation * feat(rust): add consolidate CLI parity * test(rust): compare real-model consolidation * feat(rust): add watcher parity * feat(rust): add semantic search parity * feat(rust): tighten MCP contract parity * feat(rust): add plugin lifecycle parity * feat(rust): complete advanced MCP parity * feat(rust): add functional TUI parity * feat(rust): add TLS certificate lifecycle parity * feat(rust): reconcile live federation workers * test(rust): add lock and I/O fault gates * fix(rust): roll back failed trace transactions * fix(rust): recover interrupted trace mutations * fix(rust): recover interrupted trace deletion * fix(recovery): guard mixed-runtime takeover * feat(rust): add safe cortex restore * feat(rust): expose safe recovery status * feat(rust): recover interrupted cortex restore * fix(rust): persist configuration atomically * test(rust): validate live TUI lifecycle * feat(rust): complete recovery and verification parity * feat(rust): complete migration and operational parity * test(rust): add blinded qualitative comparison * fix(consolidation): align model quality across runtimes * fix(tui): match Go visual hierarchy * feat(rust): qualify standard profile at scale * test(rust): qualify APFS storage recovery * docs: clarify Rust workload comparison * docs: align Rust report charts * feat: make Rust the production implementation * docs: remove unreleased durability terminology * docs: add Rust source-size comparison * docs: refine source-size comparison * fix(backup): preserve Obsidian trash alias compatibility * fix(http): separate listener and Host allowlists * docs: record Rust deployment qualification * fix(ci): satisfy Rust 1.88 clippy
Reconcile next with the released v0.21.7 source tree and apply the validated v0.21.8 retrieval and compatibility patch. Rust, plugin, repository, and optimized-build checks pass.
* release: v0.20.0 — Rust implementation Replace the Go runtime with the qualified Rust implementation, preserve established storage and protocol contracts, and retain the migration evidence. Includes final watcher and Obsidian Streamable HTTP fixes. * fix(release): authenticate Homebrew tap pushes (#143) * docs: separate public Rust rationale from maintenance (#144) * release: v0.21.0 — tag management (#146) * feat(tags): add cortex-wide tag management * release: v0.21.0 — tag management * fix(release): eliminate Windows build warning (#147) * fix(mcp): emit portable schema version metadata (#148) * fix(federation): ignore retired clock keys during causal replay (#149) * release: v0.21.3 — integrations and service durability (#150) * fix(integrate): preserve Rust 1.88 compatibility * fix(integrate): satisfy Rust 1.88 linting * feat(integrate): add managed agent client integrations * fix(http): harden local service connectivity * release: v0.21.3 — integrations and service durability * release: v0.21.4 — safe sync reconciliation Add actionable invalid-file sync diagnostics, event-backed long-tier reconciliation, legacy reference normalization, accurate sync accounting, safe recovery behavior, private reconciliation artifacts, and focused regression coverage. * fix(watch): preserve clipped frontmatter fields (#152) Parse onboarding metadata independently so one incompatible field cannot erase valid neighbors. Preserve non-conflicting properties and accept scalar or list forms for authors and tags. * feat(obsidian): show trace tiers in file explorer (#153) * release: v0.21.6 (#154) * Release/v0.21.6 (#155) * release: v0.21.6 * feat(memory): add safe Obsidian tag normalization * feat(memory): add bounded cross-agent continuity (#156) Add bounded continuity retrieval and capture sessions, benchmark regression coverage, and qualified cross-harness evaluation documentation. * fix(obsidian): preserve trace identity during title edits (#157) Add semantic title editing and canonical filename restoration. Prepare v0.21.7 with Obsidian plugin v0.5.2. * release: v0.21.8 Add opt-in bounded Hermes retrieval and fix MCP metadata, legacy event recovery, and managed JSONC formatting. Full local validation and hosted Rust/plugin checks passed. * Create dependabot.yml
* Next (#161) * docs: list `noema keygen` in the command reference table keygen is a top-level command but was only mentioned in the federation event-signing prose; add it to the command table next to the federation block so it's discoverable when scanning the command list. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(federation): allow same-name pinned peer events * feat(obsidian): add Noema-backed trace search * fix(federation): normalize vector clocks and tighten promotion scoring (#130) * fix(federation): preserve tier state across reordered events * feat(serve): add conditional dynamic listeners * fix(db): apply migrations atomically * chore: correct brand asset path resolution * test(hermes): run integration coverage in CI * test(hermes): isolate provider binary discovery * feat(plugin): add embedded install and drift checks * fix(release): limit Hermes plugin archive contents * chore: normalize example identifiers in fixtures * feat: replace Noema with the Rust implementation (#139) * feat: add experimental Rust rewrite and comparison suite * fix: fail closed for unsupported Rust HTTP security * feat: validate persistent MCP and signed federation replay * feat: add mixed Rust federation experiments * feat(rust): add background federation experiments * feat(rust): add authenticated TLS federation * feat(rust): add consolidation election foundation * feat(rust): add consolidation pass coordination * feat(rust): add heuristic promotion pass * feat(rust): add consolidation cadence and graduation * feat(rust): add model-driven consolidation * feat(rust): add consolidate CLI parity * test(rust): compare real-model consolidation * feat(rust): add watcher parity * feat(rust): add semantic search parity * feat(rust): tighten MCP contract parity * feat(rust): add plugin lifecycle parity * feat(rust): complete advanced MCP parity * feat(rust): add functional TUI parity * feat(rust): add TLS certificate lifecycle parity * feat(rust): reconcile live federation workers * test(rust): add lock and I/O fault gates * fix(rust): roll back failed trace transactions * fix(rust): recover interrupted trace mutations * fix(rust): recover interrupted trace deletion * fix(recovery): guard mixed-runtime takeover * feat(rust): add safe cortex restore * feat(rust): expose safe recovery status * feat(rust): recover interrupted cortex restore * fix(rust): persist configuration atomically * test(rust): validate live TUI lifecycle * feat(rust): complete recovery and verification parity * feat(rust): complete migration and operational parity * test(rust): add blinded qualitative comparison * fix(consolidation): align model quality across runtimes * fix(tui): match Go visual hierarchy * feat(rust): qualify standard profile at scale * test(rust): qualify APFS storage recovery * docs: clarify Rust workload comparison * docs: align Rust report charts * feat: make Rust the production implementation * docs: remove unreleased durability terminology * docs: add Rust source-size comparison * docs: refine source-size comparison * fix(backup): preserve Obsidian trash alias compatibility * fix(http): separate listener and Host allowlists * docs: record Rust deployment qualification * fix(ci): satisfy Rust 1.88 clippy * docs: prepare README for Rust release (#140) * fix(obsidian): support Streamable HTTP responses * chore: remove Go runtime remnants (#141) * fix(watch): ignore non-mutating filesystem events * feat(tags): add cortex-wide tag management (#145) * fix(release): authenticate Homebrew tap pushes (#143) * docs: separate public Rust rationale from maintenance (#144) * feat(tags): add cortex-wide tag management * chore: reconcile next and prepare v0.21.8 Reconcile next with the released v0.21.7 source tree and apply the validated v0.21.8 retrieval and compatibility patch. Rust, plugin, repository, and optimized-build checks pass. * Create dependabot.yml (#160) * release: v0.20.0 — Rust implementation Replace the Go runtime with the qualified Rust implementation, preserve established storage and protocol contracts, and retain the migration evidence. Includes final watcher and Obsidian Streamable HTTP fixes. * fix(release): authenticate Homebrew tap pushes (#143) * docs: separate public Rust rationale from maintenance (#144) * release: v0.21.0 — tag management (#146) * feat(tags): add cortex-wide tag management * release: v0.21.0 — tag management * fix(release): eliminate Windows build warning (#147) * fix(mcp): emit portable schema version metadata (#148) * fix(federation): ignore retired clock keys during causal replay (#149) * release: v0.21.3 — integrations and service durability (#150) * fix(integrate): preserve Rust 1.88 compatibility * fix(integrate): satisfy Rust 1.88 linting * feat(integrate): add managed agent client integrations * fix(http): harden local service connectivity * release: v0.21.3 — integrations and service durability * release: v0.21.4 — safe sync reconciliation Add actionable invalid-file sync diagnostics, event-backed long-tier reconciliation, legacy reference normalization, accurate sync accounting, safe recovery behavior, private reconciliation artifacts, and focused regression coverage. * fix(watch): preserve clipped frontmatter fields (#152) Parse onboarding metadata independently so one incompatible field cannot erase valid neighbors. Preserve non-conflicting properties and accept scalar or list forms for authors and tags. * feat(obsidian): show trace tiers in file explorer (#153) * release: v0.21.6 (#154) * Release/v0.21.6 (#155) * release: v0.21.6 * feat(memory): add safe Obsidian tag normalization * feat(memory): add bounded cross-agent continuity (#156) Add bounded continuity retrieval and capture sessions, benchmark regression coverage, and qualified cross-harness evaluation documentation. * fix(obsidian): preserve trace identity during title edits (#157) Add semantic title editing and canonical filename restoration. Prepare v0.21.7 with Obsidian plugin v0.5.2. * release: v0.21.8 Add opt-in bounded Hermes retrieval and fix MCP metadata, legacy event recovery, and managed JSONC formatting. Full local validation and hosted Rust/plugin checks passed. * Create dependabot.yml --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * build(deps): bump clap_complete from 4.6.9 to 4.6.11 (#169) Bumps [clap_complete](https://github.com/clap-rs/clap) from 4.6.9 to 4.6.11. - [Release notes](https://github.com/clap-rs/clap/releases) - [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md) - [Commits](clap-rs/clap@clap_complete-v4.6.9...clap_complete-v4.6.11) --- updated-dependencies: - dependency-name: clap_complete dependency-version: 4.6.11 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump reqwest from 0.13.4 to 0.13.5 (#174) Bumps [reqwest](https://github.com/seanmonstar/reqwest) from 0.13.4 to 0.13.5. - [Release notes](https://github.com/seanmonstar/reqwest/releases) - [Changelog](https://github.com/seanmonstar/reqwest/blob/master/CHANGELOG.md) - [Commits](seanmonstar/reqwest@v0.13.4...v0.13.5) --- updated-dependencies: - dependency-name: reqwest dependency-version: 0.13.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump actions/setup-node from 4 to 7 (#162) Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4...v7) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump esbuild from 0.21.5 to 0.28.2 in /plugins/obsidian (#172) Bumps [esbuild](https://github.com/evanw/esbuild) from 0.21.5 to 0.28.2. - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2024.md) - [Commits](evanw/esbuild@v0.21.5...v0.28.2) --- updated-dependencies: - dependency-name: esbuild dependency-version: 0.28.2 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump ed25519-dalek from 2.2.0 to 3.0.0 (#165) Bumps [ed25519-dalek](https://github.com/dalek-cryptography/curve25519-dalek) from 2.2.0 to 3.0.0. - [Release notes](https://github.com/dalek-cryptography/curve25519-dalek/releases) - [Changelog](https://github.com/dalek-cryptography/curve25519-dalek/blob/3.0.0/CHANGELOG.md) - [Commits](dalek-cryptography/curve25519-dalek@ed25519-2.2.0...3.0.0) --- updated-dependencies: - dependency-name: ed25519-dalek dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump builtin-modules in /plugins/obsidian (#175) Bumps [builtin-modules](https://github.com/sindresorhus/builtin-modules) from 3.3.0 to 5.3.0. - [Release notes](https://github.com/sindresorhus/builtin-modules/releases) - [Commits](sindresorhus/builtin-modules@v3.3.0...v5.3.0) --- updated-dependencies: - dependency-name: builtin-modules dependency-version: 5.3.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump @types/node in /plugins/obsidian (#166) Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 20.19.39 to 26.6.1. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.6.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump actions/download-artifact from 4 to 8 (#164) Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump actions/upload-artifact from 4 to 7 (#167) Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump actions/checkout from 6 to 7 (#170) Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump actions/cache from 4 to 6 (#173) Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v4...v6) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Require https or loopback http when an embedding API key is present so bearer tokens are not sent to remote http endpoints.
Prepare the embedding API-key transport protection and dependency maintenance patch release.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When an embedding API key is configured, Noema now rejects remote cleartext HTTP endpoints before sending a request. HTTPS and loopback HTTP remain supported; unkeyed HTTP behavior is unchanged. Prepare v0.21.9 with the dependency maintenance already merged since v0.21.8.
Users with keyed remote HTTP embedding endpoints must switch to HTTPS, including endpoints on private networks. No database migration is added; the Obsidian plugin remains at v0.5.2.
Validation:
make testpassed (223 Rust unit tests plus integration coverage, formatting, strict Clippy, and 60 continuity benchmark tests); 121 Hermes tests passed; Obsidian tests, build, TypeScript checks, and bundle consistency passed; Homebrew metadata and repository-script tests passed.The optimized host build and version smoke test passed. Hosted Rust/plugin CI and all CodeQL analyses passed. The release excludes unfinished local macOS service-management changes.