What changed in each version of jevmem?
jevmem 0.6.0 (2026-09-30) added the guard, dead ends, better recall and saving that waits for background subagents; 0.6.1 to 0.6.3 brought a guard fix for if [ … ] in a command and a clearer jevmem doctor; and 0.6.4 (2026-10-01), the current release, changed the docs only.
The guard, the largest addition in 0.6, caught 66 of 68 rule breaks with 3–4 false asks in 206 fine calls on a held-out set of 274 tool calls (run once on 0.6.0 and once on 0.6.1, on 2026-09-30: 0.6.0, 0.6.1). To upgrade: npm install -g jevmem@latest (every install path).
The rest of this page is the repository's docs/whats-new.md, then every version in the CHANGELOG.
What's new in 0.6 (0.6.0, 2026-09-30; CHANGELOG)
Dead ends. jevmem saves an approach that was tried and failed, with the reason, and puts it in front of Claude as "Already tried: …" when a prompt comes back to it. A later turn that shows it works now supersedes it (docs/dead-ends.md). Decide's held-out v3 set, 100 turns in five new projects, run on the release build on 2026-09-30 (first run 2026-09-27, before the writer changed): dead ends saved 25 of 25, every one with its reason (25 of 25); reversals of a saved line superseded 10 of 10 (results). In the outcome A/B below, Claude never repeated an approach recorded as failed (0 of 15 sessions), against 3 of 15 with no memory; the same lines in
CLAUDE.md: also 0 of 15.Recall that finds the lines a prompt needs, and nothing for a prompt that needs none. Every live line is asked about, each on its own. Retrieval held-out v2: 90 prompts over three new projects of 20, 80 and 250 lines, run once on 2026-09-28, 0.6 (
48cc67d, the recall code that ships) against 0.5.9: recall 75/78 against 55/78 (18 of the 78 wanted lines are dead ends, which 0.5.9 cannot read; on the other 60, 0.6 found 57 and 0.5.9 found 55); lines injected that were wanted or fine 96/97 against 88/104; unrelated prompts that got a line 1/18 against 5/18; superseded lines injected 0 of 90 in both. Prompts that need two lines got both in 3 of 6. Cost per prompt $0.000578 against $0.000267, and $0.001002 against $0.000320 on the 250-line file. Above 250 live lines, only the 250 sharing the most words with the prompt are asked about (a 500-line dev file: recall 37/46).A slow or failed Jev call no longer means no memory. Past one second, the prompt gets the lines that share the most words with it. On held-out v2 no call ran late (hook p95 596 ms; 0.5.9's, in the same run, 491 ms), so this served no prompt there. Word match finds lines that share the prompt's words (on dev, as if every prompt had fallen back, 25 of 32 for prompts that name what they need) and seldom the others (3 of 33).
Claude acts on the saved line about as often as with
CLAUDE.md. "With jevmem, Claude followed the project's saved line in 66 of 72 sessions; with the same lines inCLAUDE.md, in 67 of 72; with no memory, in 28 of 72." 24 tasks in three small projects of 34 to 42 saved lines, 3 runs each, real Claude Code 2.1.281 sessions withclaude-sonnet-5; the jevmem arm on 0.6 (48cc67d, 2026-09-29, the same 66 of 72 as on part 3's build; the recall code that ships), the other two arms in part 3's run (2026-09-28).CLAUDE.mddid better where nothing in the prompt points at the line (a convention for every user-facing string: 3 of 3 against 0 of 3); rules every task must follow belong there.The guard, a backstop. A
PreToolUsehook checks each Bash, Edit and Write call against your saved rules, and has Claude Code ask you (or blocks the call) when Jev says it may break one (docs/guardrails.md). In the A/B's 6 constraint tasks (18 sessions, rerun on the release build on 2026-09-30 with Claude Code 2.1.284), recall kept Claude from ever attempting the forbidden change (0 of 18; 10 of 18 with no memory in the 2026-09-28 run), and the guard checked all 78 of those sessions' Bash, Edit and Write calls and asked once: an edit to the output formatter that put a new format behind a new flag, as its rule allows (Jev 0.89); inclaude -pthat ask refused the edit, and the session finished the task another way, 18 of 18 followed the rule and 17 of 18 did the task (results). On the guard's second held-out set (274 calls in five new projects, written after a day's trial in jevmem's own repository; run once on the 0.6.0 build on 2026-09-30 and once on 0.6.1 the same day): violations caught 66/68 and the check that guards jevmem's own files right on 274/274 calls in both runs, and false asks 3–4 of 206 across the two (the one call that differs isgit add token.secret.example, which breaks no rule: 0.52 in the 0.6.0 run, then 0.47, either side of the 0.5 threshold; the command has no bracket, so that is Jev's variation between runs, not the fix) (docs/guardrails.md).Background subagents. A turn that hands work to a subagent in the background is decided once, when it is over, not while the subagent works, and the subagent's report is never read as your message. Decide held-out v4: 30 real Claude Code 2.1.281 sessions, 14 with a background subagent, replayed through the release build and 0.5.9 in one run on 2026-09-30 (first run 2026-09-28): lines saved while a turn was still running 0 (0.5.9: 9), lines decided from a subagent's report read as your message 0 (0.5.9: 13), turns saved or skipped right 32 of 33 (0.5.9: 27 of 33) (results, 0.5.9). The line is the sentence that states the memory, not the request or hand-off next to it: on a line-text held-out set of 64 saved turns in four new projects (16 of them a memory next to a request or a hand-off to a subagent), run once on 2026-09-29 on the writer that ships, the saved lines stated the fact in 62 of 63 (0.5.9: 41 of 59), kept the reason in 29 of 30 (0.5.9: 5 of 25), and none was a request or a hand-off (0.5.9: 13 of 59).
0.6.1 and 0.6.2 fixed the guard skipping a Bash call with
if [ … ]orwhile [ … ]in it (0.6.0's check threw on the[and the hook stayed silent, so the call ran unchecked; 0.6.2 is 0.6.1's code, published again): docs/guardrails.md, CHANGELOG: 0.6.1, 0.6.2.0.6.3 fixes what you see, not what is saved, recalled or checked:
jevmem doctorshows the plugin synced from claude.ai once, its newest copy, where an update had left the previous copy beside it and doctor listed both; the limits and the upgrade notes say what an open session loses when that plugin updates, and what to do;scripts/eval.mjsrecords the version of the build it measured (CHANGELOG).0.6.4 is docs only: the README is rewritten short, with graphics, and what moved out of it is on this page, install.md, upgrading.md and limits.md; nothing changes in what jevmem saves, recalls or checks (CHANGELOG).
Earlier releases #
- In the Claude plugin directory (2026-09-29): add jevmem from the Claude app. The plugin runs the
jevmemCLI from npm, so setup takes three commands. - 0.5.10, clearer setup for installs from the Claude plugin directory (
jevmem@synced):jevmem keysaves your key, the first prompt says when no key is found and how to fix it,jevmem doctorsees the directory's plugin, andjevmem enablegives one next step. No change to what is saved or recalled. Upgrade withnpm install -g jevmem@latest(plugin users too: the plugin runs this CLI) (CHANGELOG). - 0.5.8, a security fix: secrets named like
PGPASSWORD=weren't scrubbed in 0.5.7 and earlier. A prompt or turn withPGPASSWORD=…,MYSQLPWD=…or"password": "…"in it was sent to TypeSafe with the value as written. Upgrade withnpm install -g jevmem@latest(plugin users too: the plugin runs this CLI), and rotate any such secrets that were in your chats in an enabled project (advisory GHSA-2r3p-5hmg-46p5, CHANGELOG). - Install as a Claude Code plugin (0.5.0), opt-in per project since 0.5.1: it does nothing until you run
jevmem enablein a repo. - A memory-poisoning check on recall (0.5.0): lines that jevmem did not write on your machine (a teammate's, a pull request's, your own hand edits) are checked by Jev before they're added to Claude's context. In our 44-line test set (2026-09-25) it blocked 20 of 22 planted lines, with 0 of 22 false blocks on legitimate rules (SECURITY.md).
- Turns queued during Jev outages (0.5.0) and retried later, in order, instead of being dropped.
jevmem import(0.5.0) for an existingCLAUDE.md,AGENTS.mdor Cursor rules.- Saving runs in the background (0.5.0): the
Stophook is async, so Claude doesn't wait for it. On v0.5.6 its process exited in 12–14 ms, and the decision was recorded 0.26–0.28 s after it started (results). - No calls to OpenAI or Anthropic unless you set
writerinjevmem.config.json(0.5.4). A key in your environment is not enough on its own. - PRIVACY.md (0.5.7): no telemetry, and exactly what goes where, with the third parties' privacy policies and how to delete your data.
Upgrading, for every install path: upgrading.md. Every release: CHANGELOG.
Every version #
- 0.6.4, 2026-10-01
- 0.6.3, 2026-09-30
- 0.6.2, 2026-09-30
- 0.6.1, 2026-09-30
- 0.6.0, 2026-09-30
- 0.5.10, 2026-09-29
- 0.5.9, 2026-09-28
- 0.5.8, 2026-09-28
- 0.5.7, 2026-09-26
- 0.5.6, 2026-09-26
- 0.5.5, 2026-09-26
- 0.5.4, 2026-09-26
- 0.5.3, 2026-09-25
- 0.5.2, 2026-09-25
- 0.5.1, 2026-09-25
- 0.5.0, 2026-09-25
- 0.4.5, 2026-09-25
- 0.4.4, 2026-09-24
- 0.4.3, 2026-09-23
- 0.4.2, 2026-09-23
- 0.4.1, 2026-09-23
- 0.4.0, 2026-09-23
- 0.3.8, 2026-09-23
- 0.3.7, 2026-09-23
- 0.3.6, 2026-09-23
- 0.3.5, 2026-09-23
- 0.3.4, 2026-09-23
- 0.3.3, 2026-09-22
- 0.3.2, 2026-09-22
- 0.3.1, 2026-09-22
- 0.3.0, 2026-09-22
- 0.2.0, 2026-09-22
- 0.1.1, 2026-09-22
- 0.1.0, 2026-09-22
The limits, in short #
- jevmem needs a TypeSafe API key (where to get one, and the install steps).
- Message text is sent to TypeSafe to be scored, with common secrets scrubbed first (what leaves your machine).
- It is automatic in Claude Code, automatic in Codex while
jevmem watchruns, and in Cursor only when the agent calls it (what each tool does). - Rules every task must follow still belong in
CLAUDE.md(jevmem next to CLAUDE.md). - The guard is a backstop, not a sandbox (what it misses).
Every limit, with the numbers: the FAQ.