Skip to content

Repair dependency security and strengthen memory acquisition - #143

Open
varun369 wants to merge 2 commits into
mainfrom
codex/slm-growth-acquisition
Open

varun369 wants to merge 2 commits into
mainfrom
codex/slm-growth-acquisition

Conversation

@varun369

@varun369 varun369 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

SuperLocalMemory now leads with a reproducible store/recall proof, installation and current research/source links. The governance and mathematical research remain below that acquisition layer; star links are optional.

Repair the existing dependency-security blocker instead of bypassing it. Update affected runtime and ingestion pins, adopt a compatible patched Torch/setuptools combination, and remove both old audit exceptions. Temporarily omit the unpatched NLTK/LLMLingua dependency pair while preserving backend source and safe/lossless fallback. Existing unsafe/unknown backend versions are blocked before loading; readiness does not suggest reinstalling them.

Validation: independent unfiltered all-extras audit143entries/zero known vulnerabilities; high/high Bandit and secrets/IP scan pass. Actual local embedding and reranker compatibility checks pass. Full local default suite ran11,321passed,37skipped,330deselected,one obsolete77floor assertion failed; strengthened83floor and other repaired contract assertions pass targeted reruns. Remote platform CI is the remaining merge gate. Independent code/Python/security/prose reviewers approve source changes.

The published PyPI/npm package remains4.1.17; source repairs do not claim that already installed/published artifacts changed. New package publication is a separate release action. Merge proof docs before dependent website deployments. User approved the necessary repairs and website deployment; no social posting is in scope.

@varun369 varun369 changed the title Lead with a reproducible local memory proof Repair dependency security and strengthen memory acquisition Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant