Skip to content

build(deps): bump mem0ai from 2.0.0 to 2.1.0 - #1789

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/mem0ai-2.1.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/mem0ai-2.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown

Bumps mem0ai from 2.0.0 to 2.1.0.

Release notes

Sourced from mem0ai's releases.

Mem0 Python SDK (v2.1.0)

Improvements:

  • Client: Requests now carry three surface-identity headers so the platform can tell which product made a call. X-Mem0-Source names the surface and X-Application the host app it runs inside, both set-once so a wrapper that already declared its identity keeps it. X-Mem0-Client is append-only and carries name/version per layer, outermost first, so a plugin calling this SDK reports the whole chain rather than only the last speaker. MEM0_SOURCE, MEM0_APPLICATION and MEM0_CLIENT_STACK set them from the environment for wrappers that cannot pass options (#7326)
  • Client: The client stack is bounded by dropping whole entries rather than slicing characters, and this SDK's own entry is the reserved one. Truncating the joined string could sever an identifier mid-name and the platform parsed the fragment as a real client (#7326)

Mem0 Python SDK (v2.0.20)

Improvements:

  • OSS notices: Notice configuration now comes from a static, cacheable repository file with a bundled disabled fallback and deterministic rollout assignment, instead of calling PostHog's feature-flag evaluation API. This keeps notices fail-safe when the remote config is unavailable and removes the PostHog feature-flag request from notice evaluation (#7185)
  • Vector Stores: RedisDBConfig now uses Pydantic's native extra="forbid" handling for unknown fields instead of a custom model validator, preserving strict validation while returning standard Pydantic errors (#7089)

Mem0 Python SDK (v2.0.19)

Bug Fixes:

  • Embeddings: HuggingFaceEmbedding now falls back to the HUGGINGFACE_API_KEY env var, then a placeholder key, when huggingface_base_url is set and no api_key is configured. The OpenAI-compatible client used to talk to TEI endpoints raises at construction when no key resolves at all, so a TEI deployment that doesn't require a real key previously failed to initialize (#6947)
  • Core: remove_code_blocks() now accepts list-shaped content (a sequence of {"text": ...} blocks, as some agent frameworks pass) by joining each block's text before stripping code fences, instead of raising AttributeError from calling .strip() on a list (#6947)
  • Core: create_procedural_memory() (Memory and AsyncMemory) now raises a clear ValueError when the LLM returns no content for the summary, instead of continuing with empty content that surfaced as a confusing error further down the call (#6947)
  • Proxy: mem0.proxy no longer auto-installs litellm via a pip install subprocess when the import fails; it now raises ImportError with instructions to install it yourself. The auto-install could hang or fail silently in restricted environments and ran an unreviewed install on the caller's behalf (#6947)
  • Client: get_all() (sync and async) now sends page and page_size as independent query params instead of requiring both to be set before either was sent. Passing only page_size without page previously had it silently dropped, so results came back at the server's default page size (#6900)
  • LLMs: Add provider_override to AWSBedrockConfig, an explicit provider name (for example "anthropic") for when model is an application inference profile ARN whose opaque ID has no provider substring for extract_provider() to detect. Without it, those ARNs raised ValueError: Unable to determine provider (#6899)
  • LLMs: VllmConfig now falls back to the VLLM_BASE_URL env var when vllm_base_url isn't passed explicitly. The default was filled in before the env var was ever checked, so VLLM_BASE_URL was silently ignored (#6897)

Mem0 Python SDK (v2.0.18)

Bug Fixes:

  • Core: Percent-escape %, &, and = in user_id, agent_id, and run_id when building the session scope key for the recent-conversation buffer, so the key stays unambiguous for ids containing those characters. Ordinary ids keep their existing key; an id already containing %, &, or = maps to a new key, so its buffer starts empty once and refills on the next add(). Stored memories are unaffected. Reported by @​OfficialAbhinavSingh (#6892)
  • Vector Stores: Raise ValueError when a PGVector in/nin filter value is not a list. A string value was previously iterated character by character into the generated = ANY(...) array (so {"user_id": {"in": "alice"}} matched a, l, i, c, e), and a non-iterable value raised a bare TypeError from deep inside filter building (#6879)
  • Vector Stores: Reject index_accuracy=0 in the Oracle AI Vector Search config. The range check sat behind a truthiness test, so 0 skipped validation entirely and was passed through to WITH TARGET ACCURACY 0 instead of raising (#6848)
  • Vector Stores: Close the Oracle connection or pool that Mem0 opened when initialization fails. A client version check, a database version check, or a create_col() error previously propagated with the connection still open, leaking it for the life of the process. A caller-supplied client is left untouched (#6839)

Mem0 Python SDK (v2.0.17)

New Features:

  • Client: Add agent_custom_instructions to project.update()/update_project() (sync and async) and to the ProjectUpdateOptions and AddMemoryOptions typed models. It sets a second extraction instruction set that applies only to agent-scoped memories: an add passing agent_id without user_id uses it, one passing both splits by attribution, and while it is unset custom_instructions continues to apply to every memory (#6809)

Mem0 Python SDK (v2.0.16)

New Features:

  • Client: Add reference_date, latest_only, and keyword_search to SearchMemoryOptions, and latest_only to GetAllMemoryOptions, keeping the Python client's typed options in sync with the Platform API and the CLIs (#6696)

Bug Fixes:

  • Core: Stop add() metadata from setting a memory's identity scope. _build_filters_and_metadata() now strips user_id, agent_id, run_id, and actor_id from caller-supplied metadata before building the creation template, so metadata can no longer place a memory into a scope that was never passed through the entity params (#6656)
  • Vector Stores: Validate Upstash filter keys and values in search(), keyword_search(), and list(). Filter keys must match a safe identifier pattern, values must be str/int/float/bool, and string values containing a double quote or backslash are now rejected instead of being interpolated unescaped into the generated query string (#5981)
  • Embeddings: FastEmbedEmbedding.embed() now converts its result with .tolist() before returning, so callers get a plain List[float] instead of a numpy array (#6770)
  • Embeddings: HuggingFaceEmbedding now passes api_key to the OpenAI-compatible client when huggingface_base_url is set. The configured key was previously dropped, so the client fell back to OPENAI_API_KEY from the environment or raised OpenAIError at construction when that was unset (#6770)
  • Embeddings: Replace Ollama's interactive pip install prompt on import with a plain ImportError. Importing mem0.embeddings.ollama without the ollama package previously blocked on stdin and then called sys.exit(1), killing the host process instead of raising (#6770)
  • Core: remove_code_blocks() now returns an empty string for None input instead of raising AttributeError (#6770)
  • Core: parse_vision_messages() now chains the original exception (raise ... from e) when an image download fails, so the root cause is preserved in the traceback (#6770)
  • Core: process_telemetry_filters(None) now returns ([], {}), matching the two-value tuple every caller unpacks, instead of {} (#6770)
  • Core: LlmFactory.create() no longer mutates the caller's config dict in place via .update(kwargs); the merge now builds a new dict (#6770)
  • Rerankers: The Cohere, HuggingFace, SentenceTransformer, and Zero Entropy rerankers' failure-fallback path no longer mutates the caller's document dicts in place when stamping rerank_score; it now falls back on copies (#6770)
  • Vector Stores: Remove logging.basicConfig() calls from the MongoDB and Vertex AI Vector Search providers, so selecting either provider no longer reconfigures the host application's root logger as a side effect (#6770)

Mem0 Python SDK (v2.0.15)

... (truncated)

Commits
  • 19f7134 chore(release): bump every package the telemetry attribution work changed (#7...
  • a8d3634 fix(plugins): stop the TypeScript telemetry losing events and misattributing ...
  • 1a5c7ad feat(integrations): declare which surface each client is, and its version (#7...
  • 4e38b05 fix(plugins): count installs once, and re-resolve the email when the key chan...
  • 3362999 fix(plugins): stop delivering telemetry events twice, and stop losing parked ...
  • 012cd32 fix(plugins): report the plugin that produced the event, not the one that sen...
  • e4e0307 fix(plugins): say what telemetry actually sends, and salt the hashes (#7322)
  • 84bf468 docs: add practical Mem0 Copilot guide (MEM-6344) (#7337)
  • f135cb9 SEO & metadata audit: shorten hermes description (#7359)
  • f5220ff fix(security): bump next to 15.5.24, patches GHSA-p293-qw3h-jr36 (#7320)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mem0ai](https://github.com/mem0ai/mem0) from 2.0.0 to 2.1.0.
- [Release notes](https://github.com/mem0ai/mem0/releases)
- [Commits](mem0ai/mem0@v2.0.0...v2.1.0)

---
updated-dependencies:
- dependency-name: mem0ai
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 25, 2026
@dcellison dcellison closed this Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/mem0ai-2.1.0 branch October 1, 2026 18:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant