Skip to content

Migrate to Supermemory v5 with legacy server compatibility - #109

Merged
Dhravya merged 2 commits into
mainfrom
capy/migrate-to-supermemory-v5
Oct 9, 2026
Merged

Dhravya merged 2 commits into
mainfrom
capy/migrate-to-supermemory-v5

Conversation

@Dhravya

@Dhravya Dhravya commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Hosted content now uses the pinned official supermemory@5.0.1 SDK. Existing custom endpoints keep the bundled official 4.0.0 SDK by default, including the v3/v4 compatibility path needed by older local servers. apiVersion and SUPERMEMORY_API_VERSION select the protocol explicitly; URL identity normalizes hosted case/default ports/root paths, and failures never trigger version switching or hosted rerouting.

Preserve lifecycle and resource identity

  • Keep namespace strings, config/key/URL precedence, legacy read fanout, metadata, batch IDs, capture cadence, privacy and approvals unchanged.
  • Map document ingestion to namespace-scoped POST append/diff with explicit dynamic processing, validating IDs and processing acceptance before recording capture success. No instant processing, PATCH replacement, retry ledger or duplicate-suppression policy change.
  • Normalize profile facts and search/system envelopes. Query-free profiles stay query-free; optional query-ranked results use a separate search. Recall retains hybrid / 0.55 / five, no reranking or query rewriting, and the existing local floor/dedup.
  • List documents—not formed memories—and hydrate canonical content per item without replacing listed identity/metadata/system/pagination. Failed, invalid, mismatched-scope or stalled GETs retain healthy/base rows; hydration aborts within the remaining list budget with a 250-ms return grace. Exact forgetting validates count/ID/errors, and document fallback uses only namespaces with a confirmed memory miss, never retained authorization or inconsistent outcomes.
  • Keep the best-effort legacy filter settings and account/auth boundaries. Do not replace organization context or broaden administrator permissions; unsupported legacy settings remain documented rather than silently discarded.

Deliver 2.0.16 artifacts

Pin both SDKs in the lockfile, rebuild the existing V1/server/V2/CLI bundles, include both SDK license texts, retain all exports and optional TUI peers, and use frozen dependency installation in the release build. Generated distribution remains ignored as before; the current release workflow builds it before publication. No publish/tag/merge was performed.

Verification and limits

  • Typecheck/build and all 33 unchanged tests pass; no test files added or modified.
  • Credential-free loopback SDK probes cover v5, normalized hosted routing, legacy custom-prefix routing, exact request fields/headers, scoped filters, profile/search separation, document content/timestamps, acceptance failures, partial/ambiguous deletion, mixed authorization/not-found fallback, partial/malformed/wrong-ID/content/scope hydration, a real 30-second stalled-GET deadline, capture retry IDs/privacy and retry counts.
  • Nineteen isolated config fixtures cover URL identity/overrides, credentials/env/file precedence, cadence and byte-preserving reads of existing JSONC/credentials.
  • A clean packed install without development dependencies runs V1, server and V2 alias fixtures on Node 24; V1/V2 also run on Node 18 and Bun. Cold consumer declarations resolve without either SDK package; CLI/RPC and TUI-with-host-peers import successfully. Two fresh builds are byte-identical.

No hosted data/ranking/deletion/append-diff/billing parity, actual local-server storage upgrade, real OpenCode UI or Windows/macOS host was tested. Dynamic memory formation can take minutes. Content-inclusive lists add scoped document GETs under the existing wrapper budget. Official SDK5 retryable statuses/backoff differ from SDK4 (notably no automatic 409 retry); stable IDs are not an exactly-once billing guarantee. Existing overlapping product fixes remain outside this PR.

Open in Capy

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
@socket-security

socket-security Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedsupermemory@​5.0.16610010095100

View full report

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
@Dhravya
Dhravya merged commit 7c65138 into main Oct 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant