v12.3.9

thedotmack/claude-memv12.3.9Apr 22, 2026by thedotmack

AI Summary

Introduces security observation types with Telegram notifications, eliminates terminal blocking on session end with fire-and-forget summarize, and fixes Windows compatibility issues in hooks.

Key Highlights

  • New security_alert and security_note observation types
  • Fire-and-forget Telegram notifier with MarkdownV2 formatting
  • Stop hook fire-and-forget summarize - eliminates ~110s terminal block
  • Hooks resolve endpoint with same precedence as worker (env > settings.json > defaults)
  • Windows fallback to 37777 when per-uid formula doesn't apply

New Features

  • Security observation types (security_alert, security_note)
  • Telegram notifier for alerts
  • Fire-and-forget summarize on session end

Full Release Notes

## Highlights

### 🔐 Security observation types + Telegram notifier
- New observation types: `security_alert` 🚨 (high-priority, triggers notifications) and `security_note` 🔐 (low-priority).
- Fire-and-forget Telegram notifier — MarkdownV2 formatting, per-observation error isolation, no token logging.
- Five env vars control behavior. `CLAUDE_MEM_TELEGRAM_ENABLED` master toggle defaults on (no-op without bot token + chat ID).

### ⚡ Stop hook: fire-and-forget summarize
- Eliminated the ~110s terminal block when a session ended. Summarize handler now enqueues and returns immediately.
- Server-side `SessionCompletionHandler` finalizes off the hook's critical path (generator + HTTP fallback), with singleton sharing across the worker.

### 🐛 Hooks: worker-port precedence + Windows (#2086 / PR #2084)
- Hooks now resolve endpoint with the same precedence as the worker: env (`CLAUDE_MEM_WORKER_PORT`, `CLAUDE_MEM_WORKER_HOST`) > settings.json > defaults.
- Looser sed regex handles both quoted and unquoted JSON port values.
- Windows fallback to 37777 when per-uid formula doesn't apply.

### 🔧 Bug fixes (reviewer rounds on PR #2084)
- Don't remove in-memory session after a failed finalize; preserve crash-recovery state at 3 sites.
- Eliminate double-broadcast of `session_completed` on fallback path.
- Sync `DatabaseManager.getSessionById` return type.
- `TelegramNotifier` now respects `settings.json` (not just env).
- Hardcoded 🚨 emoji replaced with per-type mapping.

### 📝 Docs
- `version-bump` skill now covers `npm publish` + all 6 manifest paths so `npx claude-mem@<version>` always resolves. Adds `git grep` pre-flight for new manifests.

### ⚙️ Chores
- 🤖 Generated with [Claude Code](https://claude.com/claude-code)

**Full Changelog**: https://github.com/thedotmack/claude-mem/compare/v12.3.8...v12.3.9