
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
openchronicle-mcp
Advanced tools
Memory database for LLM agents — persistent semantic + keyword memory, project namespacing, served over HTTP REST and MCP.
A memory database for LLM agents. Persistent semantic + keyword memory, project namespacing, git-onboard, served over HTTP REST and MCP from a single ASGI process. Runs on your hardware.
/api/v1/*) and the MCP streamable-HTTP transport (/mcp) on the
same port. Single container, single port mapping, single
healthcheck./health. Backfill catches up when the provider
returns..sql migrations with
savepoint atomicity. Re-runs are idempotent. Future schema changes
drop in as NNN_<slug>.sql files.OC_API_KEY
is supported but optional — disabled by default for trusted-LAN
deployments. See docs/configuration/security_posture.md for the
when-to-enable guidance.By design.
From source:
pip install -e ".[mcp,openai]"
oc init
oc serve
The default oc serve binds 127.0.0.1:8000. Override with
--host/--port or OC_API_HOST/OC_API_PORT.
Docker (single container, NAS-friendly):
docker run --rm \
-p 8000:8000 \
-v $(pwd)/data:/app/data \
-v $(pwd)/config:/app/config \
ghcr.io/carldog/openchronicle-mcp:latest
For a Portainer stack on a NAS, use the docker-compose.nas.yml at
the repo root.
# Bootstrap the runtime tree
oc init
oc init-config
# Create a project
PROJECT_ID=$(oc init-project "my-project")
# Save your first memory
oc memory add "Decision: SQLite for storage; AGPL for license" \
--project-id $PROJECT_ID --tags decision
# Search it
oc memory search "storage decision" --project-id $PROJECT_ID
Or do the same via MCP — register the server with Claude Code:
claude mcp add --scope user --transport http openchronicle \
http://127.0.0.1:8000/mcp
Then ask Claude to call memory_save and memory_search.
Hexagonal: domain/ (pure types + ports) → application/ (use cases,
services) → infrastructure/ (SQLite, embedding adapters, the
maintenance loop). Driver-side adapters in interfaces/ host the
HTTP, MCP, and CLI surfaces.
See docs/architecture/ARCHITECTURE.md for the full layout.
docs/architecture/ARCHITECTURE.md — layout, schema, ASGI designdocs/architecture/MAINTENANCE.md — maintenance loop + degradation policydocs/cli/commands.md — oc subcommand referencedocs/configuration/env_vars.md — environment variablesdocs/configuration/config_files.md — core.json schemadocs/configuration/security_posture.md — security modeldocs/integrations/mcp_client_setup.md — register the MCP serverdocs/integrations/mcp_server_spec.md — MCP tool surfacedocs/api/STABILITY.md — versioning + deprecation policypip install -e ".[dev,mcp,openai,ollama]"
pre-commit install
pytest
The architecture is enforced by tests:
tests/test_hexagonal_boundaries.py — domain/application/infrastructure layeringtests/test_architectural_posture.py — core agnostic of MCP SDKtests/test_no_secrets_committed.py, tests/test_no_soft_deprecation.py — repo hygienemcp-name: io.github.CSOAI-ORG/openchronicle-mcp
FAQs
Memory database for LLM agents — persistent semantic + keyword memory, project namespacing, served over HTTP REST and MCP.
We found that openchronicle-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.