Skip to content

Refresh TMCRA Local Memory for 1.0.0-rc.1 (source security gate pending) - #398

Draft
reshuibuduo wants to merge 5 commits into
hashgraph-online:mainfrom
reshuibuduo:codex/refresh-tmcra-memory-rc10
Draft

Refresh TMCRA Local Memory for 1.0.0-rc.1 (source security gate pending)#398
reshuibuduo wants to merge 5 commits into
hashgraph-online:mainfrom
reshuibuduo:codex/refresh-tmcra-memory-rc10

Conversation

@reshuibuduo

@reshuibuduo reshuibuduo commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Refresh the existing TMCRA entry for the unified 1.0.0-rc.1 candidate: visual memory workspace, chat-confirmed source corrections, session controls, local Writer/organizer settings, and account-free Windows x64 one-click local installation.

Source update: reshuibuduo/tmcra-plugin-codex#4

Validation

  • Merged current upstream/main into this branch; only the existing TMCRA README line differs from upstream.
  • python scripts/check-alphabetical.py README.md --base-ref upstream/main passes. Prerequisite Make alphabetical checks baseline-aware #399 is already merged.
  • Full source npm run verify passes; the 235-entry Codex archive includes the backend and verified runtime inventory.

Pending source security gate

The official HOL action is still blocked. Versions 3.0.17, 3.0.65 and current 3.0.94 classify PyTorch Module.eval() (inference mode) as dynamic code execution in eight bundled Python files. The source preserves the original high-severity gate and enables Cisco scanning; no runtime exclusions or broad suppressions were added. Setup now uses no placeholder API credential and rejects all authenticated memory operations.

Review with exact affected paths: https://github.com/reshuibuduo/tmcra-plugin-codex/blob/codex/memory-controls-continuity/docs/security-scanner-review.md

Please keep this refresh pending until the source gate is resolved or the maintainer explicitly adjudicates those findings. Source main/release and bot-generated marketplace bundles should be refreshed only after that point. Local deployment is a preview; higher-tier hardware and complete offline memory acceptance remain pending.

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can route each action level your way: inline, summary, both, or drop

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Refresh TMCRA Local Memory catalog description for rc.10

📝 Documentation 🕐 Less than 5 minutes

Grey Divider

AI Description

• Refreshes the TMCRA Local Memory catalog entry for release 0.3.0-rc.10.
• Describes account-scoped recall, writeback roles, lifecycle checkpoints, and local model settings.
High-Level Assessment

The focused catalog-line edit is optimal because it follows the repository's marketplace refresh workflow while avoiding unrelated source or metadata changes.

Files changed (1) +1 / -1

Documentation (1) +1 / -1
README.mdRefresh TMCRA Local Memory catalog description +1/-1

Refresh TMCRA Local Memory catalog description

• Replaces the existing TMCRA Local Memory summary with release-current capabilities, including account-scoped memory, role-separated writeback, lifecycle checkpoints, and configurable local models. The repository link remains unchanged so the marketplace sync bot can refresh its mirrored bundle.

README.md

@reshuibuduo reshuibuduo changed the title Refresh TMCRA Local Memory to 0.3.0-rc.10 Refresh TMCRA Local Memory for 1.0.0-rc.1 (source security gate pending) Sep 5, 2026
@reshuibuduo
reshuibuduo marked this pull request as draft September 5, 2026 20:06

Copy link
Copy Markdown
Contributor Author

Detector fix proposed upstream: hashgraph-online/hol-guard#2805 . It addresses the Python no-argument inference-method false positives, with 186 related tests passing on Python 3.12 and 93 code-quality tests passing on Python 3.10. Upstream Actions await maintainer approval.

This submission remains a draft while the source release's official scanner gate is unresolved. The pinned scanner Action, high-severity threshold and Cisco coverage are unchanged; synthetic test-credential findings remain a separate item. A local detector regression pass is not an official marketplace security pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant