Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
794 commits
Select commit Hold shift + click to select a range
6fbb4ce
Merge pull request #65805 from NousResearch/ethie/e2e
ethernet8023 Jul 20, 2026
67e73ae
Merge pull request #68140 from NousResearch/bb/desktop-keep-awake
OutThisLife Jul 20, 2026
e2fd8a3
fix(desktop): refresh repo status on session switch with unchanged cw…
ethernet8023 Jul 20, 2026
d7b3607
fix(checkpoints): honor gateway config and task cwd (#68195)
helix4u Jul 20, 2026
5783746
Merge origin/main into feat/desktop-remote-ssh-current
yoniebans Jul 20, 2026
b9f82ed
ci: live-updating PR review comment with structured job statuses
ethernet8023 Jul 16, 2026
7a69b82
ci: migrate AUTOFIX_BOT_PAT to GitHub App token
ethernet8023 Jul 20, 2026
faa3bce
style(desktop): satisfy merged eslint/prettier config
yoniebans Jul 20, 2026
1f76bdc
fix(ci): pass App secrets as inputs to composite action
ethernet8023 Jul 20, 2026
5c7993e
fix(ci): add detect to all-checks-pass needs so its failure blocks merge
ethernet8023 Jul 20, 2026
d57947b
fix(desktop): bump skills test timeout to fix cold-start flake (#68235)
ethernet8023 Jul 20, 2026
a41d280
Merge pull request #65964 from NousResearch/ethie/ci-review-comment
ethernet8023 Jul 20, 2026
b586e4e
feat(desktop): open multiple full app windows (electron)
OutThisLife Jul 20, 2026
a90ca7f
feat(desktop): wire New Window to ⌘⇧N + command palette
OutThisLife Jul 20, 2026
fb0c6d9
fix(desktop): de-dupe cross-window cues so peers don't spam
OutThisLife Jul 20, 2026
a41346f
refactor(desktop): tidy the cross-window deduper
OutThisLife Jul 20, 2026
fb0ed83
Merge pull request #68259 from NousResearch/bb/multi-window
OutThisLife Jul 20, 2026
933c823
nix: add cage to devDeps
ethernet8023 Jul 21, 2026
5c4dc46
Merge pull request #68298 from NousResearch/ethie/cage-nix
ethernet8023 Jul 21, 2026
272bbaf
fix(desktop): avoid false remote gateway reauthentication (#68250)
helix4u Jul 21, 2026
f657840
fix(desktop): keep composer draft across compression tip rotation (#6…
xxxigm Jul 21, 2026
477c08b
fmt(js): `npm run fix` on merge (#68305)
hermes-seaeye[bot] Jul 21, 2026
a85df69
fix(desktop): Stop parks the queue instead of firing the next queued …
SHL0MS Jul 21, 2026
79af472
fix(cli,tui): recall real paste content on up-arrow
OutThisLife Jul 21, 2026
7651764
Merge pull request #68390 from NousResearch/bb/paste-history-recall
OutThisLife Jul 21, 2026
3f820a1
fix(cli): suppress CPR on POSIX local TTYs under load
HexLab98 Jul 19, 2026
f6d82e1
test(cli): prove local CPR leak and Application CPR-disabled wiring
HexLab98 Jul 19, 2026
2da64e7
refactor: drop platform kwarg, fix PTY test cleanup
kshitijk4poor Jul 21, 2026
693d390
docs(portal): remove retired Nous Chat references
helix4u Jul 21, 2026
21c7e49
fix(web/ddgs): isolate DuckDuckGo search in a disposable process
HexLab98 Jul 20, 2026
77ee16b
test(web/ddgs): cover GIL-hold timeout, interrupt, and worker reap
HexLab98 Jul 20, 2026
646e71a
fix: sanitize subprocess env for DDGS worker
kshitijk4poor Jul 21, 2026
0ba889d
fix(agent): pass persisted-prefix boundary when rotation flushes on c…
PRATHAMESH75 Jul 20, 2026
6c28558
fix(desktop): prevent contentEditable composer input from visually co…
x7peeps Jul 20, 2026
3a9b9d6
fix(agent): circuit-break AttributeError from commit-splice and detec…
x7peeps Jul 20, 2026
1ba0e87
fix(telegram): preserve fatal recovery handoff
Imgaojp Jul 21, 2026
087732c
fix(telegram): widen fatal handoff to heartbeat watchdog path
kshitijk4poor Jul 21, 2026
7a8852d
fix(tests): make the live-system-guard canary fail closed
PRATHAMESH75 Jul 21, 2026
b0da653
fix(billing): rename user-facing "terminal billing" copy to Remote Sp…
alt-glitch Jul 21, 2026
94c9443
feat(tui): show the plan catalog in /subscription on Free (#68357)
alt-glitch Jul 21, 2026
0155c09
fmt(js): `npm run fix` on merge (#68462)
hermes-seaeye[bot] Jul 21, 2026
f4df260
fix(relay): attach metadata.user_id on guild replies for egress fallb…
benbarclay Jul 21, 2026
b14be88
build: declare pywin32 as a direct win32 dependency
yoniebans Jul 21, 2026
25f4ba7
Merge remote-tracking branch 'origin/main' into feat/desktop-remote-s…
yoniebans Jul 21, 2026
940fd96
fix(desktop): preserve dragging with empty titlebar slots
helix4u Jul 21, 2026
279be82
Revert "fix(agent): circuit-break AttributeError from commit-splice a…
teknium1 Jul 21, 2026
8a0701c
fix(context): revalidate Codex OAuth context windows
sbe27 Jul 10, 2026
9a34cc9
test(context): document Codex cache persistence coverage
sbe27 Jul 10, 2026
60afc29
fix(context): scope Codex catalogue cache by credential
sbe27 Jul 10, 2026
0c0ec18
test(context): cover Codex context rollback
sbe27 Jul 13, 2026
64702f8
fix(compression): report live-resolved Codex window in the autoraise …
teknium1 Jul 21, 2026
c44c2fb
fix(codex): send ChatGPT-Account-Id on /models probes
Jul 15, 2026
b49b1e5
test(codex): cover ChatGPT-Account-Id header on /models probe
Jul 15, 2026
03841c9
fix(tools): make the tool-search context gate provider-aware (#68589)
teknium1 Jul 21, 2026
afb7bf6
feat(skills): bundle docx, xlsx, and pdf office skills; refresh power…
teknium1 Jul 21, 2026
a31a318
fix(approval): raise gateway approval timeout to 300s, honest stale-t…
teknium1 Jul 21, 2026
ed3c391
Merge pull request #68331 from helix4u/fix/desktop-session-titlebar
OutThisLife Jul 21, 2026
d3b0e61
feat(secrets): one-command token rotation + actionable startup errors…
teknium1 Jul 21, 2026
d355e0e
feat(desktop): configure repository discovery (supersedes #67630) (#6…
austinpickett Jul 21, 2026
d9dae17
fix(desktop): ⌘W closes visible file tab when preview selection is st…
xxxigm Jul 21, 2026
d604141
fmt(js): `npm run fix` on merge (#68681)
hermes-seaeye[bot] Jul 21, 2026
73c8d40
Merge pull request #68130 from NousResearch/feat/desktop-remote-ssh-c…
yoniebans Jul 21, 2026
11ae6bf
Merge pull request #68725 from SHL0MS/fix/desktop-stop-parks-queue
OutThisLife Jul 21, 2026
5ed7137
feat(billing): plan chips and rows deep-link their tier (#68666)
alt-glitch Jul 21, 2026
a88512b
fix(desktop): drop the decorative top-up credits bar (#68649)
alt-glitch Jul 21, 2026
4dd535c
fix(ci): route critical supply-chain findings through review gate (#6…
ethernet8023 Jul 21, 2026
6b54582
fix: `tool_calls` double-encoding on import (#68856)
ethernet8023 Jul 21, 2026
625687f
feat(status-bar): add /battery toggle for a color-coded battery read-out
OutThisLife Jul 21, 2026
a3297bd
fix(approval): restore session approval for Tirith-flagged commands
Jul 21, 2026
02d8cba
fix(approval): honor allow_session across all button adapters
teknium1 Jul 21, 2026
9cc475c
test(approval): cover allow_session tiers in Matrix reaction seeding …
teknium1 Jul 21, 2026
0c33db0
fix(desktop): wrap missing sidebar icon-button tooltips (#67500)
alelpoan Jul 21, 2026
0008868
fmt(js): `npm run fix` on merge (#68867)
hermes-seaeye[bot] Jul 21, 2026
2b72e06
fix(gateway): detect stale lock when macOS psutil returns valid start…
liuhao1024 Jun 27, 2026
6f50c56
fix(gateway): handle PermissionError on stale root-owned lock file
liuhao1024 Jun 9, 2026
35fb2e4
fix(gateway): guard acquire_gateway_runtime_lock against root-owned l…
teknium1 Jul 21, 2026
3fc0cfb
fix(gateway): make stale scoped-lock removal atomic via tombstone rename
teknium1 Jul 21, 2026
e54723a
fix(gateway): detect stale gateway_state.json in `gateway status` (TT…
Cossackx Jun 23, 2026
ad7b4c7
test(gateway): cover stale gateway_state.json detection (TTL + PID li…
Cossackx Jun 23, 2026
155fdd5
fix(gateway): take over live platform-lock token holders once
jbbottoms Jul 16, 2026
50fdf13
chore(contributors): map jaretbottoms@gmail.com -> jbbottoms (PR #651…
teknium1 Jul 21, 2026
ab76cf8
fix(gateway): reap the replaced gateway's orphaned children on POSIX
teknium1 Jul 21, 2026
5e4529c
chore(contributors): map emails for PRs #66906, #66420, #63398 salvage
teknium1 Jul 21, 2026
11e76f4
fix(state): probe FTS5 read path in _db_opens_cleanly so partial inde…
Jul 18, 2026
57b3c47
fix(state): also catch sqlite3.DatabaseError in FTS5 read probe (#66724)
Jul 18, 2026
96c1511
fix(state): preserve degraded-runtime read probe + use canonical FTS5…
Jul 19, 2026
11710c5
fix(state): self-heal FTS corruption on the SessionDB search path too
Frowtek Jul 17, 2026
373ec23
fix(state): extend search-path FTS self-heal to the CJK/trigram branch
teknium1 Jul 21, 2026
505fb58
fix(state): add REINDEX strategy to repair stale B-tree indexes (#63386)
liuhao1024 Jul 12, 2026
2d6b95c
test(state): exercise REINDEX repair against a REAL stale B-tree index
teknium1 Jul 21, 2026
8995131
fix(kanban): auto-repair index-only kanban.db corruption via REINDEX
teknium1 Jul 21, 2026
8fb3cc1
fix(kanban): cap corrupt-backup retention at 10 files per board DB
teknium1 Jul 21, 2026
49828a3
feat(kanban): periodic WAL checkpoint (TRUNCATE) on the dispatcher tick
teknium1 Jul 21, 2026
60cfa11
feat(kanban): add `hermes kanban repair` CLI verb
teknium1 Jul 21, 2026
26fb0c5
fix(packaging): graft web_dist in MANIFEST.in and add sdist regressio…
aniruddhaadak80 Jul 21, 2026
18a3fa5
fix(dashboard): attempt one recovery build when --skip-build finds no…
teknium1 Jul 21, 2026
ad235d9
fix(web): guard _serve_index against a missing or unreadable index.html
teknium1 Jul 21, 2026
e404d6c
fix(dashboard): content-hash web UI freshness check
eazye19 Jun 8, 2026
3a9b2f2
fix(cli): serialize concurrent web-UI builds with an exclusive flock
frohsinnllc Jul 12, 2026
37396fc
refactor(cli): run the web-UI staleness walk once, under the build lock
frohsinnllc Jul 13, 2026
cca2276
chore(git): ignore the web UI build lock file
teknium1 Jul 21, 2026
9adb5a3
test(cli): cover the web UI build flock contention paths
teknium1 Jul 21, 2026
7ae4da2
style(cli): open the build lock file with explicit encoding (ruff PLW…
teknium1 Jul 21, 2026
fb5b8e4
chore(contributors): map eazye19@users.noreply.github.com -> eazye19 …
teknium1 Jul 21, 2026
a8a93b6
fix(mcp): reconnect immediately on transport TaskGroup drop instead o…
hanyu1212 Jul 17, 2026
48be106
fix(mcp): charge immediate reconnects against a rapid-drop budget (#6…
teknium1 Jul 21, 2026
3e6b437
fix(mcp): unwrap exception groups and park permanent failures immedia…
teknium1 Jul 21, 2026
da8b89c
fix(mcp): one WARNING per state transition, DEBUG retry chatter, jitt…
teknium1 Jul 21, 2026
106d182
fix(mcp): re-register tools during parked revival
yungchentang Jul 19, 2026
2c3aa3f
fix(mcp): isolate a single failing stdio server from the bridge (#50394)
trevorgordon981 Jun 22, 2026
ee23bff
fix(mcp): clear connect-cooldown state on every shutdown path
teknium1 Jul 21, 2026
c4e8ff4
chore(contributors): map diffen77 + fazerluga-creator emails
teknium1 Jul 21, 2026
f26fb90
fix(mcp): reconnect message-less closed transports
Jul 17, 2026
80209e5
test(mcp): isolate resource error breaker state
Jul 17, 2026
1ae1dd8
fix(mcp): harden nested interruption detection
Jul 17, 2026
4735454
fix(mcp): make transport classification cycle safe
Jul 17, 2026
fbe086f
fix(mcp): cycle-guard cause/context traversal in transport classifier
teknium1 Jul 21, 2026
4fda7ef
fix(mcp): allow background discovery retry after a run that connected…
fazerluga-creator Jul 18, 2026
8b6e92a
fix(tui): centralize stdio TUI MCP discovery on the shared owner
fazerluga-creator Jul 19, 2026
c54b568
fix(tui): give the stdio TUI discovery a retry-after-zero-connected path
teknium1 Jul 21, 2026
f218474
fix(tui): gate the shared-owner MCP discovery wait on the stdio TUI flag
teknium1 Jul 21, 2026
3c2903a
fix(status-bar): address Copilot review on /battery
OutThisLife Jul 21, 2026
87e31cb
fix(dashboard): cap gateway health probe timeout
tianma-if Jul 2, 2026
eff2931
fix(gateway): report runtime source version in /health, not stale dis…
Jul 8, 2026
0d5982d
fix(api-server): count "stopping" runs as active in readiness work co…
pierrenode Jul 15, 2026
e2e8823
chore(contributors): map yingwaizhiying@gmail.com -> tianma-if (super…
teknium1 Jul 21, 2026
8fd5b25
feat(dashboard): component-level health rollup on /api/status (#68662)
teknium1 Jul 21, 2026
a2c2ec6
fix(status): make gateway_updated_at a stable RFC3339-or-null contrac…
teknium1 Jul 21, 2026
413ed6b
Merge pull request #68860 from NousResearch/bb/battery-status
OutThisLife Jul 21, 2026
a1a406f
feat(desktop): type-to-focus the composer from empty chat chrome
OutThisLife Jul 21, 2026
81f4095
Merge pull request #68918 from NousResearch/bb/composer-focus-keys
OutThisLife Jul 21, 2026
58d75ec
feat(ui-tui): widget-grid 2-axis layout engine + overlay primitives (…
OutThisLife Jul 20, 2026
4a129af
refactor(ui-tui): route production surfaces through the widget-grid e…
OutThisLife Jul 20, 2026
cd05498
feat(ui-tui): background-aware theme adaptation + paired palettes + /…
OutThisLife Jul 20, 2026
c0763bd
feat(ui-tui): theme engine — seeds to derived-tone ladder + flash-fre…
OutThisLife Jul 20, 2026
2963033
perf(tui): skin switches stay hot — MCP gating, pooled reload, swap r…
OutThisLife Jul 20, 2026
28e05a3
fix(ui-tui): light mode renders the vivid palette RAW, not WCAG-darkened
OutThisLife Jul 20, 2026
6929f5f
fix(ui-tui): eradicate every transparent-terminal black-slab trigger
OutThisLife Jul 20, 2026
3c135ab
fix(ui-tui): session-panel hierarchy + polarity-proof placeholder tone
OutThisLife Jul 20, 2026
4426d57
feat(ui-tui): OSC-10 foreground polarity tiebreaker for transparent t…
OutThisLife Jul 20, 2026
e594e11
fix(ui-tui): session-panel fade anchors on muted, not the surface — r…
OutThisLife Jul 20, 2026
505b2de
style(skins): default light overlay = goldenrod ladder, not neon or m…
OutThisLife Jul 20, 2026
a0a9aaf
refactor(ui-tui): DRY the chrome primitives — shared scrollbarColors …
OutThisLife Jul 20, 2026
ce8c2c9
fix(ui-tui): completions popover — aligned name track + neutral descr…
OutThisLife Jul 20, 2026
5bfffcd
refactor(ui-tui): every selectable list rides the shared selection ch…
OutThisLife Jul 20, 2026
11f2e54
fix(ui-tui): overlay width caps are absolute — clampOverlayWidth (Cop…
OutThisLife Jul 21, 2026
fdac23b
fix(tui): reload.mcp lock scope + coalesced refresh + macOS polarity …
OutThisLife Jul 21, 2026
6982c61
fix(tui): mcp_rev includes mcp_servers; reload survives leader failur…
OutThisLife Jul 21, 2026
4bb9e6c
fix(ui-tui): first-swap repaint + config-auto respects shell theme pi…
OutThisLife Jul 21, 2026
2fb0dc6
fix: restore package-lock.json @esbuild platform entries (Bugbot r4)
OutThisLife Jul 21, 2026
9be9a91
fix(ui-tui): seed mcp_rev baseline at startup so first cosmetic write…
OutThisLife Jul 21, 2026
c543c69
fix(ui-tui): record config theme pin even when env already matches (B…
OutThisLife Jul 21, 2026
0ada783
feat(ui-tui): shimmer skeleton for the lazy tools section
OutThisLife Jul 21, 2026
146f4ed
fmt(js): `npm run fix` on merge (#68938)
hermes-seaeye[bot] Jul 21, 2026
e0e1543
Merge pull request #20379 from NousResearch/bb/widget-grid-slots
OutThisLife Jul 21, 2026
96ba7ec
fmt(js): `npm run fix` on merge (#68976)
hermes-seaeye[bot] Jul 21, 2026
8208fc5
fmt(js): `npm run fix` on merge (#68977)
hermes-seaeye[bot] Jul 21, 2026
75be8fb
test(mcp): stamp breaker-open time on the monotonic clock, not a lite…
OutThisLife Jul 22, 2026
967e078
fix(windows): share one bounded, tree-killing git probe across both c…
OutThisLife Jul 22, 2026
b11b5ec
fix(tui): revision-aware reload.mcp — an ack now means the revision w…
OutThisLife Jul 22, 2026
e6cc561
fix(ui-tui): boot theme cache gets provenance — a stale hint can't pi…
OutThisLife Jul 22, 2026
c25e08a
fix(ui-tui): stacked dialog gets input before the grid under it
OutThisLife Jul 22, 2026
9fb2a63
fix(ui-tui): make `npm run visual` portable off POSIX — zero new deps
OutThisLife Jul 22, 2026
cd24efe
perf(ui-tui): shimmer loaders share one clock and stop after a bounde…
OutThisLife Jul 22, 2026
7d757cf
fmt(js): prettier pass on the new review tests
OutThisLife Jul 22, 2026
502939e
chore: gitignore node_modules symlinks, not just directories
OutThisLife Jul 22, 2026
3de91c6
fix(desktop): stop long-session transcript from drifting to old turns…
OutThisLife Jul 22, 2026
5c714be
ci: retrigger (transient setup-uv manifest fetch flake)
OutThisLife Jul 22, 2026
32a9f2a
Merge pull request #68999 from NousResearch/bb/widget-grid-hardening
OutThisLife Jul 22, 2026
d8fcab4
feat(ui-tui): widget-app SDK — registry, host, dispatch; demos become…
OutThisLife Jul 21, 2026
fc3be32
feat(ui-tui): weather reference app — the async-data contract, themed…
OutThisLife Jul 21, 2026
76b58d6
feat(ui-tui): ambient widget mode — registry-driven slash catalog + i…
OutThisLife Jul 21, 2026
ca0b1b1
feat(ui-tui): self-authored widgets — user-widget loader, hot-load, s…
OutThisLife Jul 21, 2026
ed93d6a
feat(ui-tui): widget primitives — charts, accordion, shimmer, stable …
OutThisLife Jul 21, 2026
a7e2671
docs(skill): tui-widgets — auto-open recipe (openWidget at end of reg…
OutThisLife Jul 21, 2026
9627d4f
feat(ui-tui): ambient zone system + widget crash boundary
OutThisLife Jul 21, 2026
2ed61d4
refactor(ui-tui): host placement router + grid-test width-floor fix
OutThisLife Jul 21, 2026
a8444fb
feat(themes): cross-surface theme SDK — one skin themes CLI, TUI, and…
OutThisLife Jul 21, 2026
91c5c0c
fix(themes): activate skins via `hermes config set`, never a config.y…
OutThisLife Jul 21, 2026
eb45491
feat(themes): agent-authored skins switch live via a gateway skin wat…
OutThisLife Jul 21, 2026
727f670
feat(themes): TUI paints its own background from the skin (OSC 11)
OutThisLife Jul 22, 2026
30ee6f7
feat(themes): element tokens (ui_tool, ui_thinking) + skinnable diffs
OutThisLife Jul 22, 2026
2a4e5fa
fix(themes): tweak the ACTIVE skin in place, never fork default
OutThisLife Jul 22, 2026
4f4f938
feat(themes): `hermes skin set` — deterministic one-color tweak, bg u…
OutThisLife Jul 22, 2026
3ba6eeb
feat(themes): dedicated code-syntax palette keys
OutThisLife Jul 22, 2026
428a053
test(themes): E2E live skin switch — config write → skin.changed broa…
OutThisLife Jul 22, 2026
50170fd
fix(themes): reconcile element/syntax tokens with main's derive+adapt…
OutThisLife Jul 22, 2026
300a0f1
fix(themes): apply a runtime switch back to default on the desktop
OutThisLife Jul 22, 2026
850b8da
fix(tui_gateway): serve candidate-inclusive display on warm/live resume
OutThisLife Jul 22, 2026
77855ce
fix(tui_gateway): candidate-inclusive display on child-watch resume +…
OutThisLife Jul 22, 2026
ef81d9d
fix(cli): add skin to _BUILTIN_SUBCOMMANDS for plugin gating
OutThisLife Jul 22, 2026
8f51376
Merge pull request #69040 from NousResearch/bb/fix-verify-candidate-w…
OutThisLife Jul 22, 2026
7dc535a
Merge pull request #68306 from NousResearch/bb/tui-widget-sdk
OutThisLife Jul 22, 2026
367810a
Merge pull request #68857 from NousResearch/bb/theme-sdk
OutThisLife Jul 22, 2026
5c4c419
fmt(js): `npm run fix` on merge (#69048)
hermes-seaeye[bot] Jul 22, 2026
7c68b4e
feat(desktop): Billing page revamp — current-plan card, in-app plans …
alt-glitch Jul 22, 2026
14f8441
fmt(js): `npm run fix` on merge (#69050)
hermes-seaeye[bot] Jul 22, 2026
9baad4e
feat(cli): plan catalog on Free + plan= deep link + top-up/auto-refil…
alt-glitch Jul 22, 2026
60ec6a3
feat(desktop): native in-app downgrade — chargeless preview → schedul…
alt-glitch Jul 22, 2026
d8bf3df
fmt(js): `npm run fix` on merge (#69067)
hermes-seaeye[bot] Jul 22, 2026
fd96e13
fix(gateway): hard-exit CLI runner after graceful teardown
web3blind Jul 21, 2026
c9ab8ba
test: update gateway run stub for hard-exit helper
web3blind Jul 21, 2026
4425ddd
fix(gateway): hard-exit on KeyboardInterrupt path too
kshitijk4poor Jul 21, 2026
1c0a578
fix(cli): pass conversation_history on /new /resume /branch flush
Bartok9 Jul 21, 2026
a46fbaf
test: drop source-grep change-detector from #68480
kshitijk4poor Jul 21, 2026
e57918a
test: update mock assertions for conversation_history kwarg
kshitijk4poor Jul 22, 2026
2ab1532
fix(gateway): make adapter fatal-error handoff cancellation-proof; ex…
anoopmehendale-cue Jul 21, 2026
4999de8
chore: map anoop.mehendale@gmail.com -> anoopmehendale-cue
kshitijk4poor Jul 22, 2026
e99882c
fix(update): isolate systemctl timeouts per gateway unit during fleet…
HexLab98 Jul 21, 2026
b7b0c37
test(update): cover fleet restart timeout isolation (#68523)
HexLab98 Jul 21, 2026
52d219b
fix: refresh vulnerable npm lockfile entries
Jul 21, 2026
3e953ed
chore: AUTHOR_MAP for tinetwork
kshitijk4poor Jul 22, 2026
377244f
fix(compression): prevent stale-budget retry loops
cucurigoo Jul 21, 2026
97499d7
fix(compression): harden startup route scoping
cucurigoo Jul 21, 2026
cb785e6
fix(providers): align custom route scoping
cucurigoo Jul 22, 2026
ca6b8cd
test(compression): cover overflow after blocked preflight
cucurigoo Jul 22, 2026
fcae6fb
test(providers): cover route URL identity boundaries
cucurigoo Jul 22, 2026
2507af2
test(providers): cover query path slash identity
cucurigoo Jul 22, 2026
639cee5
test(providers): complete hermetic route coverage
cucurigoo Jul 22, 2026
ddd6675
test(providers): cover URL whitespace route identity
cucurigoo Jul 22, 2026
f3f0135
fix(providers): fail closed on missing active route
cucurigoo Jul 22, 2026
63dd651
fix(providers): scope route-owned runtime settings
cucurigoo Jul 22, 2026
9fa2906
fix: restore base_url rstrip, extract should_clear_context_pin helper
kshitijk4poor Jul 22, 2026
f489601
fix(compression): ignore assistant handoff summaries in tail anchor
McHersheys Jul 21, 2026
9eb7b1a
chore: AUTHOR_MAP for McHermes
kshitijk4poor Jul 22, 2026
45fce38
fix(telegram): group authz fallback + command sender identity
Jul 20, 2026
7078430
fix(telegram): address review findings from PR #67816
kshitijk4poor Jul 22, 2026
9ecacd6
fix(telegram): update auth check tests for group_allow_from split
kshitijk4poor Jul 22, 2026
323e9ba
fix(openviking): recover pending session commits
ehz0ah Jul 5, 2026
f7c198d
docs: clarify OpenViking local setup
NPFernando Jun 2, 2026
3fd9658
fix(openviking): serialize orphan session recovery
ehz0ah Jul 18, 2026
81fc424
fix(openviking): chunk structured session sync
ckorhonen Jul 18, 2026
c3c80e1
refactor: cleanup follow-up for salvaged PR #58871
kshitijk4poor Jul 22, 2026
11c1ca0
fix(openviking): inject session-start memory context
itsflownium Jun 30, 2026
8af2133
fix(openviking): align session context with shared profile contract
ehz0ah Jul 17, 2026
0c76cc6
fix: discard both session IDs on compression for profile re-injection
Jul 22, 2026
7de5542
chore: add kshitij@kshitij.dev to AUTHOR_MAP
Jul 22, 2026
77f3b3e
fix(secrets): fall back to stale disk cache when bws live fetch fails
jackjin1997 Jun 8, 2026
7db521a
fix(secrets): port stale-cache fallback to current DiskCache API + ga…
jackjin1997 Jul 14, 2026
a616b9f
fix(secrets): fold OP_CONNECT_HOST/OP_CONNECT_TOKEN into 1Password au…
briandevans Jul 7, 2026
fe8c0f7
fix(secrets): pass OP_LOAD_DESKTOP_APP_SETTINGS through to the op chi…
menhguin Jul 11, 2026
2beed8b
fix(mcp): pass secret-source-injected env vars to stdio servers
westkite1201 Jul 22, 2026
fe5d0be
fix(env): stop printing Bitwarden secret names
andrexibiza Jul 7, 2026
8e089db
fix(secrets): validate bitwarden status token
izumi0uu Jun 6, 2026
c7b0c0d
fix(secrets): mark _APPLIED_HOMES only after a real fetch attempt (#4…
teknium1 Jul 22, 2026
c758ded
fix(secrets): fall back to os.environ on scope miss when multiplexing…
Soju06 Jul 20, 2026
e66e02d
test(gateway): activate multiplex flag in cross-profile env isolation…
teknium1 Jul 22, 2026
86fb046
feat(secrets): orchestrator-level preserve_existing + profile aliasin…
teknium1 Jul 22, 2026
bd9123d
Merge PR #65798 branch onto current main
teknium1 Jul 22, 2026
15d69db
test(state): accept FTS5-specific corruption message in read-probe test
teknium1 Jul 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
18 changes: 15 additions & 3 deletions .github/actions/detect-changes/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ description: >-

inputs:
github-token:
description: Token for the GitHub API (gh CLI). Pass secrets.AUTOFIX_BOT_PAT from the calling workflow.
description: Token for the GitHub API (gh CLI). Pass steps.app-token.outputs.token from the calling workflow.
required: false
default: ${{ github.token }}

Expand Down Expand Up @@ -47,7 +47,12 @@ runs:
id: classify
shell: bash
env:
GH_TOKEN: ${{ inputs.github-token }}
# Fall back to the built-in read-only token when the caller passes an
# empty value. Fork PRs get no repo secrets, so AUTOFIX_BOT_PAT is ""
# there, and an input `default:` only applies when the input is omitted,
# not when it's passed empty. Without this fallback the compare API
# fails on forks and the classifier fails open (every lane forced on).
GH_TOKEN: ${{ inputs.github-token || github.token }}
REPO: ${{ github.repository }}
EVENT_NAME: ${{ github.event_name }}
BASE_SHA: ${{ github.event.pull_request.base.sha }}
Expand All @@ -67,12 +72,19 @@ runs:
# Retried: a rate-limit blip or eventual-consistency 404 on a
# freshly-pushed HEAD would otherwise silently fall open (all lanes
# run — safe, but wasteful and it masks the API failure).
#
# `.files[]?` (null-safe): with --paginate, a PR more than 100
# commits ahead of its merge-base paginates the compare, and pages
# after the first carry `files: null` — bare `.files[]` makes jq
# die with "cannot iterate over: null", which fails every retry
# and forces the fail-open path (seen on stacked PRs). The full
# file list (up to the API's 300-file cap) is on page one.
CHANGED=""
for i in 1 2 3; do
if CHANGED="$(gh api \
--paginate \
"repos/${REPO}/compare/${BASE_SHA}...${HEAD_SHA}" \
--jq '.files[].filename')"; then
--jq '.files[]?.filename')"; then
break
fi
if [ "$i" = 3 ]; then
Expand Down
59 changes: 59 additions & 0 deletions .github/actions/get-app-token/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
name: Get GitHub App Token
description: >-
Mint a short-lived (1-hour) installation access token from the repo's
GitHub App, replacing the long-lived AUTOFIX_BOT_PAT. App tokens get
5,000 req/hr per installation (vs 1,000 for the default GITHUB_TOKEN)
and are scoped to the App's installation permissions, not a user account.

Falls back to the built-in GITHUB_TOKEN when APP_CLIENT_ID is not set —
this happens on fork PRs where repo secrets are unavailable. The fallback
ensures classification, timings, and review comments still work on
forks (with the lower GITHUB_TOKEN rate limit).

Composite actions cannot access the secrets context directly, so the
calling workflow must pass secrets.APP_CLIENT_ID and secrets.APP_PRIVATE_KEY
as inputs. When both are empty (fork PRs), the fallback fires.

inputs:
client-id:
description: GitHub App Client ID. Pass secrets.APP_CLIENT_ID from the calling workflow.
required: false
default: ''
private-key:
description: GitHub App private key PEM. Pass secrets.APP_PRIVATE_KEY from the calling workflow.
required: false
default: ''

outputs:
token:
description: A GitHub App installation access token (1-hour TTL), or GITHUB_TOKEN on forks.
value: ${{ steps.app-token.outputs.token || steps.fallback.outputs.token }}

runs:
using: composite
steps:
- name: Check if App credentials exist
id: check
shell: bash
env:
CLIENT_ID: ${{ inputs.client-id }}
run: |
if [ -n "$CLIENT_ID" ]; then
echo "has_app=true" >> "$GITHUB_OUTPUT"
else
echo "has_app=false" >> "$GITHUB_OUTPUT"
fi

- name: Create GitHub App token
id: app-token
if: steps.check.outputs.has_app == 'true'
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ inputs.client-id }}
private-key: ${{ inputs.private-key }}

- name: Fall back to GITHUB_TOKEN
id: fallback
if: steps.check.outputs.has_app != 'true'
shell: bash
run: echo "token=${{ github.token }}" >> "$GITHUB_OUTPUT"
149 changes: 139 additions & 10 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ on:

permissions:
contents: read
pull-requests: write # needed by lint (PR comment) + supply-chain (PR comment)
pull-requests: write # needed by lint (PR comment) + supply-chain review_status
actions: read # needed by osv-scanner (SARIF upload)
security-events: write # needed by osv-scanner (SARIF upload)
packages: write # needed by docker build
Expand Down Expand Up @@ -49,11 +49,19 @@ jobs:
event_name: ${{ github.event_name }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Get GitHub App token
id: app-token
uses: ./.github/actions/get-app-token
with:
client-id: ${{ secrets.APP_CLIENT_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Detect affected areas
id: classify
uses: ./.github/actions/detect-changes
with:
github-token: ${{ secrets.AUTOFIX_BOT_PAT }}
# The get-app-token composite action falls back to GITHUB_TOKEN
# on fork PRs where APP_ID is unavailable.
github-token: ${{ steps.app-token.outputs.token }}

# ─────────────────────────────────────────────────────────────────────
# Lane-gated sub-workflows. Each runs in parallel after detect finishes.
Expand All @@ -71,11 +79,10 @@ jobs:
lint:
name: Python lints
needs: detect
if: needs.detect.outputs.python == 'true' || needs.detect.outputs.ci_review == 'true'
if: needs.detect.outputs.python == 'true'
uses: ./.github/workflows/lint.yml
with:
event_name: ${{ needs.detect.outputs.event_name }}
ci_review: ${{ needs.detect.outputs.ci_review == 'true' }}
secrets: inherit

js-tests:
Expand All @@ -85,6 +92,12 @@ jobs:
uses: ./.github/workflows/js-tests.yml
secrets: inherit

e2e-desktop:
name: Desktop E2E
needs: detect
if: needs.detect.outputs.python == 'true' || needs.detect.outputs.frontend == 'true'
uses: ./.github/workflows/e2e-desktop.yml

docs-site:
name: Docs Site
needs: detect
Expand Down Expand Up @@ -136,54 +149,153 @@ jobs:
supply-chain:
name: Supply-chain scan
needs: detect
if: needs.detect.outputs.event_name == 'pull_request' && (needs.detect.outputs.scan == 'true' || needs.detect.outputs.deps == 'true' || needs.detect.outputs.mcp_catalog == 'true')
if: needs.detect.outputs.event_name == 'pull_request' && (needs.detect.outputs.scan == 'true' || needs.detect.outputs.deps == 'true')
uses: ./.github/workflows/supply-chain-audit.yml
with:
event_name: ${{ needs.detect.outputs.event_name }}
scan: ${{ needs.detect.outputs.scan == 'true' }}
deps: ${{ needs.detect.outputs.deps == 'true' }}

review-labels:
name: Review label gate
needs: [detect, supply-chain]
if: always() && needs.detect.outputs.event_name == 'pull_request' && (needs.detect.outputs.ci_review == 'true' || needs.detect.outputs.mcp_catalog == 'true' || needs.supply-chain.outputs.critical_findings == 'true')
uses: ./.github/workflows/review-labels.yml
with:
ci_review: ${{ needs.detect.outputs.ci_review == 'true' }}
mcp_catalog: ${{ needs.detect.outputs.mcp_catalog == 'true' }}
supply_chain: ${{ needs.supply-chain.outputs.critical_findings == 'true' }}
secrets: inherit

osv-scanner:
name: OSV scan
uses: ./.github/workflows/osv-scanner.yml
secrets: inherit

# ─────────────────────────────────────────────────────────────────────
# Live-updating PR review comment.
#
# A single ``comment-live`` job polls the GitHub Actions API every 15s
# for job statuses in this run, re-assembles the review comment from
# whatever results are available, and upserts it via the
# ``<!-- hermes-ci-review-bot -->`` marker.
#
# The poller exits when all non-infra jobs are completed (or on
# timeout). ci-timings' review_status is picked up automatically when
# its artifact becomes available — the poller downloads and merges it.
# ─────────────────────────────────────────────────────────────────────
comment-live:
name: CI review comment (live)
needs: [detect, review-labels, lockfile-diff, supply-chain, osv-scanner, uv-lockfile, history-check, contributor-check]
if: always() && github.event_name == 'pull_request' && github.event.pull_request.head.repo.fork != true
runs-on: ubuntu-latest
timeout-minutes: 40
steps:
- name: Checkout code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- name: Run live comment poller
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
GITHUB_RUN_ID: ${{ github.run_id }}
PR_NUMBER: ${{ github.event.pull_request.number }}
RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
# Commit info for the review comment header.
COMMIT_SHA: ${{ github.event.pull_request.head.sha }}
COMMIT_MESSAGE: ${{ github.event.pull_request.head.commit.message }}
COMMIT_URL: ${{ github.server_url }}/${{ github.repository }}/pull/${{ github.event.pull_request.number }}/commits/${{ github.event.pull_request.head.sha }}
# Structured review statuses from workflow_call jobs.
# Each job outputs a JSON array of {source, results: [...]} objects
# that the assembler renders directly — no hardcoded job-name
# matching. We merge all available outputs into one array.
REVIEW_STATUSES: ${{ toJSON(needs.*.outputs.review_status) }}
run: |
set -uo pipefail

# REVIEW_STATUSES is a JSON array of strings (some may be empty
# when a job was skipped). Parse each string and merge into one
# flat array for the assembler.
python3 - <<'PYEOF'
import json, os, sys

raw = os.environ.get("REVIEW_STATUSES", "")
merged = []
if raw:
try:
arr = json.loads(raw)
except (json.JSONDecodeError, TypeError):
arr = []
for item in arr:
if not item:
continue
try:
statuses = json.loads(item)
except (json.JSONDecodeError, TypeError):
continue
if isinstance(statuses, list):
merged.extend(statuses)

# Write merged array to a temp file the poller reads.
with open("/tmp/review_statuses.json", "w") as f:
json.dump(merged, f)
print(f"Merged {len(merged)} review status entries")
PYEOF

python3 scripts/ci/live_comment.py \
--interval 15 \
--timeout 2100 \
--review-statuses-file /tmp/review_statuses.json

# ─────────────────────────────────────────────────────────────────────
# Gate: runs after everything. ``if: always()`` ensures it reports a
# status even when some deps were skipped. Only actual ``failure``
# results cause it to fail; ``skipped`` is treated as success.
#
# Branch protection should require ONLY this check.
#
# Outputs ``needs-json`` — a compact ``{job_name: result}`` dict — so
# the live comment poller can list failed jobs in the PR comment.
# ─────────────────────────────────────────────────────────────────────
all-checks-pass:
name: All required checks pass
needs:
- detect
- tests
- lint
- js-tests
- e2e-desktop
- docs-site
- history-check
- contributor-check
- uv-lockfile
- lockfile-diff
- docker-lint
- supply-chain
- review-labels
- osv-scanner
# comment-live is a polling job — it doesn't block the gate.
# we don't require docker to pass rn because it's so slow lol
# - docker
if: always()
runs-on: ubuntu-latest
timeout-minutes: 10
outputs:
needs-json: ${{ steps.evaluate.outputs.needs-json }}
steps:
- name: Evaluate job results
id: evaluate
env:
NEEDS: ${{ toJSON(needs) }}
run: |
echo "$NEEDS" | python3 -c "
import json, sys
needs = json.load(sys.stdin)
# Emit compact {job_name: result} for the comment assembler.
compact = {name: info['result'] for name, info in needs.items()}
print(f'needs-json={json.dumps(compact)}')
with open('$GITHUB_OUTPUT', 'a') as f:
f.write(f'needs-json={json.dumps(compact)}\n')
failed = [name for name, info in needs.items() if info['result'] == 'failure']
for name, info in sorted(needs.items()):
result = info['result']
Expand All @@ -200,6 +312,9 @@ jobs:
# cache them on main (as a baseline), and on PRs generate an HTML diff
# report with a gantt chart + per-step breakdown. The report is uploaded
# as an artifact and a markdown summary is written to $GITHUB_STEP_SUMMARY.
#
# The live comment poller picks up ci-timings' completion automatically —
# it reads review-status.json from the artifact when the job finishes.
# ─────────────────────────────────────────────────────────────────────
ci-timings:
name: CI timing report
Expand All @@ -211,6 +326,13 @@ jobs:
- name: Checkout code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- name: Get GitHub App token
id: app-token
uses: ./.github/actions/get-app-token
with:
client-id: ${{ secrets.APP_CLIENT_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}

- name: Restore baseline cache (PR only)
if: github.event_name == 'pull_request'
uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
Expand All @@ -224,24 +346,31 @@ jobs:

- name: Collect timings and generate report
env:
GITHUB_TOKEN: ${{ secrets.AUTOFIX_BOT_PAT }}
# Forks get no repo secrets (AUTOFIX_BOT_PAT is empty); fall back to
# the built-in read-only token so the timings API read still works
# there instead of hard-failing this advisory job on every fork PR.
# The get-app-token composite action falls back to GITHUB_TOKEN
# on fork PRs where APP_ID is unavailable.
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
python3 scripts/ci/timings_report.py \
--baseline ci-timings-baseline.json \
--output ci-timings-report.html \
--json-out ci-timings.json \
--summary-out ci-timings-summary.md
--summary-out ci-timings-summary.md \
--review-status-out review-status.json

- name: Upload HTML report
- name: Upload HTML report + review status
# Advisory report — artifact-service blips must not fail the job.
continue-on-error: true
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
id: ci-timings-artifact
with:
name: ci-timings-report
path: ci-timings-report.html
path: |
ci-timings-report.html
review-status.json
retention-days: 14
archive: false

- name: Output summary
env:
Expand Down
Loading
Loading