Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
5750 commits
Select commit Hold shift + click to select a range
dd9e753
fix(gateway): skip port-conflicting multiplex profiles
Jun 30, 2026
8191f62
fix(gateway): preserve multiplex profile in model picker
Jul 12, 2026
f7d6f09
fix(gateway): /profile reports the profile serving the source, not th…
Jul 10, 2026
6b1267c
fix(gateway): gate /profile source scoping on multiplex_profiles
Jul 11, 2026
9cb3569
fix(gateway): allow Feishu websocket mode in multiplex profiles
Jun 25, 2026
0cc9426
test: feishu port-binding report expects webhook mode after #52563 in…
Jul 16, 2026
fef0b2d
fix(gateway): scope secondary-adapter auth callback to its own profile
Jul 16, 2026
6ff65c4
fix(gateway): scope default-listener api_server requests under multiplex
Jul 16, 2026
bb853b2
chore(release): map rlaehddus302's email in AUTHOR_MAP (PR #61985 sal…
Jul 16, 2026
c3b2af9
test: accept profile_name kwarg in auth-check stubs
Jul 16, 2026
998e353
fix(auth): honor per-entry key_env when resolving fallback providers
Jul 16, 2026
3990bdf
fix(state): repair duplicate session titles without data loss on star…
Jul 16, 2026
9fc8fe2
fix(state): guard the duplicate-title repair so it can never abort DB…
Jul 16, 2026
fbf5005
fix(gateway): stop truncate_message hanging on a pathologically small…
Jul 16, 2026
27b31bb
fix(relay): normalize a 0/negative max_message_length at the descript…
Jul 16, 2026
efb6c21
fix(api-server): reject a non-ASCII bearer token with 401 instead of …
Jul 16, 2026
1b69c47
fix(webhook): reject a non-ASCII signature header instead of crashing…
Jul 16, 2026
4ccb232
test(webhook): cover the Svix v1 branch in the non-ASCII signature re…
Jul 16, 2026
a6d9d1d
fix(security): widen non-ASCII compare_digest crash fix to all siblin…
Jul 16, 2026
367d375
fix(auxiliary): route custom:<name> through named-provider arm + Pala…
May 31, 2026
adb6472
fix(auxiliary): apply review fixes to #36043 — guard named-custom rou…
Jul 16, 2026
2fba721
chore(release): map antydizajn's commit email for PR #36043 salvage a…
Jul 16, 2026
72562be
fix(dashboard): inline critical-CSS bootstrap for user themes to miti…
May 31, 2026
01bab39
fix(dashboard): theme bootstrap emits real bundle CSS vars; canvas ru…
Jul 16, 2026
558fcb6
test(dashboard): cover theme bootstrap CSS render + _serve_index inje…
Jul 16, 2026
7edaaf4
chore: map nnnet noreply email in release AUTHOR_MAP (PR #36024 salvage)
Jul 16, 2026
03c0b00
fix(usage): read DeepSeek's native prompt_cache_hit_tokens cache fiel…
Jul 16, 2026
1305a69
feat(gateway): route platform HTTP event callbacks
May 31, 2026
a7ec1b6
fix(google-chat): cache callback token cert fetches
Jun 2, 2026
14f023c
fix(api_server): run platform event verifiers off-loop and fail closed
Jul 16, 2026
3fccd69
feat(kanban): attachment toolset + CLI to match the dashboard surface
Jun 1, 2026
f3cbe45
refactor(kanban): unify attachment size cap on KANBAN_ATTACHMENT_MAX_…
Jul 16, 2026
c2e11bf
fix(kanban): guard kanban_attach_url against SSRF via tools.url_safety
Jul 16, 2026
6cc4691
chore(release): map otsune's noreply email in AUTHOR_MAP (PR #36019 s…
Jul 16, 2026
b5bd0ef
docs(kanban): port attachment guidance into KANBAN_GUIDANCE
Jul 16, 2026
58010c8
fix(mcp): reuse cached oauth redirect port
Jun 10, 2026
8091c44
fix(gateway): install _profile_runtime_scope in _run_background_task …
Jul 8, 2026
d79f75e
test: use object.__new__ runner pattern for background-task scope tests
Jul 16, 2026
9078a83
fix(lmstudio): clamp max/ultra reasoning effort to LM Studio's ceiling
Jul 15, 2026
4759362
chore(release): add briandevans to AUTHOR_MAP for PR #64951 salvage
Jul 16, 2026
5d9a72b
fix(ollama-cloud): capability-gate reasoning_effort + correct disable…
Jun 23, 2026
9298099
fix(gateway): strip /queue prefix when no agent is running
May 20, 2026
007cd15
chore(release): map focusedmiqa@gmail.com to m1qaweb in AUTHOR_MAP (P…
Jul 16, 2026
0678f8f
fix(desktop): force npm --include=dev so self-update rebuild can't be…
Jul 16, 2026
633fc7a
fix: don't downgrade xhigh reasoning effort when provider supports it
Apr 15, 2026
cf73b3d
fix(copilot): clamp reasoning effort to the nearest supported level, …
Jun 23, 2026
b099652
test(copilot): cover supported xhigh request paths
Jul 10, 2026
8462764
chore(release): map bare-noreply test-commit identity for PR #62028 s…
Jul 16, 2026
d0dcb9a
fix(update): consolidate pre-update backups into one gated mechanism …
Jul 16, 2026
fdbfae8
fix(tui): fall back to config terminal.backend when TERMINAL_ENV is u…
Jun 29, 2026
2352614
fix(terminal): bridge terminal.backend config in serve/desktop proces…
Jul 16, 2026
bfca45b
fix(discord): expose /reasoning reset|show|hide as slash choices
Jun 29, 2026
6cd5a2c
chore(release): add sam7894604 to AUTHOR_MAP; widen /reasoning choice…
Jul 16, 2026
659d112
fix(desktop): model picker reverts in existing threads (#65777)
Jul 16, 2026
bd37ff9
feat(gateway): inline choice pickers for /reasoning and /fast (Telegr…
Jul 16, 2026
f0ff8d5
fix(desktop): preserve routed session on profile rebind (#65283)
Jul 16, 2026
7830031
fix(desktop): ignore stale backend exits
Jul 10, 2026
71fa56e
fix(desktop): restore cloud reconnect action
Jul 10, 2026
ee8275a
test(desktop): port backend-connection-state test to vitest
Jul 16, 2026
bed46fc
Merge pull request #65885 from NousResearch/bb/salvage-62308-stale-ba…
Jul 16, 2026
c387be0
fix(desktop): serialize git status refreshes (#65341)
Jul 16, 2026
0f6abc7
fix(desktop): refresh default-derived composer model
Jul 4, 2026
bcf0d74
fix(desktop): preserve zoom across display moves (#65874)
Jul 16, 2026
2655c72
fix(desktop): refresh default-derived composer model (#65896)
Jul 16, 2026
91ed8e4
Merge pull request #65893 from NousResearch/bb/salvage-63082-sessiond…
Jul 16, 2026
7d27a31
feat(dashboard): isolate turns in compute host (#65895)
Jul 16, 2026
b0ca121
fix(desktop): restore closed main window on second launch (#64800)
Jul 16, 2026
f1af945
fix(desktop): slow session switch (#65890)
Jul 16, 2026
31a3822
fix(title): contain auto-title thread exceptions instead of dumping t…
Jul 16, 2026
c1c59e3
fix(honcho): make honcho_search do real cross-session message search
Jun 25, 2026
a35bc81
fix(honcho): honest, non-overlapping tool descriptions + drop dead param
Jun 25, 2026
bef9eea
fix(honcho): inject base context on the first message of a session
Jun 25, 2026
63288f1
fix(honcho): stop dropping dialectic results on trivial turns
Jun 25, 2026
111ca88
fix(honcho): honor per-host timeout in config resolution
Jun 25, 2026
d2b6c21
fix(honcho): resolve cost-awareness config from host block
Jun 25, 2026
3e4e3db
fix(honcho): don't let first-turn injection suppress dialectic
Jun 25, 2026
01d1a66
fix(honcho): ground dialectic queries in latest user message
Jul 10, 2026
f4669f3
feat(honcho): add list mode to honcho_conclude so delete can resolve …
Jul 6, 2026
1c051d1
fix(honcho): preserve delayed and rewritten recall context
Jul 10, 2026
29e0471
fix(honcho): update SDK and restore CI coverage
Jul 10, 2026
56816f4
fix(honcho): stop clipping honcho_reasoning tool results to the injec…
Jul 6, 2026
8ab4cb9
fix(honcho): gate the stalled-init prefetch wait to the first turn
Jul 13, 2026
e7fb51d
refactor(memory): make query rewrite provider-agnostic
Jul 16, 2026
e8957ba
feat(honcho): make latency-adding paths configurable
Jul 16, 2026
ef68ae7
docs(honcho): document latency flags and updated tool contracts
Jul 16, 2026
2ad6ab1
fix(honcho): enforce recall latency and budget contracts
Jul 16, 2026
d77c455
fix(memory): fail fast on stuck external prefetch
Jul 12, 2026
8d1c96f
fix(memory): align external prefetch guard with fail-open contracts
Jul 16, 2026
0022261
fix(ci): use autofix-bot PAT
Jul 16, 2026
74fc222
fmt(js): `npm run fix` on merge (#65912)
Jul 16, 2026
75ca29f
feat(models): add moonshotai/kimi-k3 to Nous Portal and OpenRouter cu…
Jul 16, 2026
dc7a20c
ci(js-autofix): skip apply-patch job when no fixes found
Jul 16, 2026
311a5b0
feat(kimi): discover K3 on coding endpoint
Jul 16, 2026
42bd436
fix(desktop): sidebar status indicators lag for background sessions
Jul 16, 2026
0f05aaa
perf(desktop): make session switching snappy on large transcripts (#6…
Jul 16, 2026
f1315ae
fmt(js): `npm run fix` on merge (#65971)
Jul 16, 2026
f08b1f3
feat(desktop): button tooltip keybind hints + keybinds settings tab +…
Jul 16, 2026
7546799
fmt(js): `npm run fix` on merge (#65974)
Jul 16, 2026
39a93dc
fix(desktop): follow compression's stored-id rotation to prevent thre…
Jul 16, 2026
10b6d1a
fmt(js): `npm run fix` on merge (#65986)
Jul 16, 2026
921c17a
fix(dashboard): scope chat attach tokens by session (#60745)
Jul 16, 2026
d4c3f98
fix(dashboard): unblock basic auth plugin when setting password inter…
Jul 16, 2026
bd00212
fix(dashboard): drop _HERMES_GATEWAY when spawning hermes actions (#5…
Jul 16, 2026
432fca5
fix(desktop): drain queued prompts for background sessions (#66001)
Jul 17, 2026
dfb76d3
fix(desktop): put Hermes-managed Node on PATH for install/rebuild (#6…
Jul 17, 2026
3f199f5
fix(desktop): don't latch remote backend boot failures so remote gate…
Jul 17, 2026
36bf3c2
fmt(js): `npm run fix` on merge (#66010)
Jul 17, 2026
56e2ba5
fmt(js): `npm run fix` on merge (#66013)
Jul 17, 2026
dc58758
perf(desktop): kill the layout-thrash cascade on session switch
Jul 17, 2026
f6edcb3
test(desktop): cover the review store (refresh, selection, mutations,…
Jul 17, 2026
a8b81c5
feat(optional-skills): add unreal-mcp companion skill for the unreal-…
Jul 16, 2026
d24ab20
feat(unreal-mcp): live-verify skill against a running UE 5.8 server; …
Jul 16, 2026
ab81849
fix(unreal-mcp): dedupe pitfall numbering (two sections numbered 4)
Jul 16, 2026
18694e9
feat(unreal-mcp): advanced-workflows layer, live-verified against UE 5.8
Jul 16, 2026
665eaf1
feat(unreal-mcp): video/frame-sequence pitfalls from live orbit produ…
Jul 17, 2026
d57531b
fix(unreal-mcp): pitfall 21b rewritten from live video production — h…
Jul 17, 2026
3951d76
fix(models): add kimi-for-coding-highspeed to kimi-coding provider list
Jul 10, 2026
c856f36
perf(desktop): kill the layout-thrash cascade on session switch (#66033)
Jul 17, 2026
1f7d2be
fix(install): detect Git Bash Mandatory ASLR failures (#64651)
Jul 17, 2026
531e576
fix(desktop): hide Windows updater console during handoff (#66040)
Jul 17, 2026
629aeee
docs(developer-guide): document htui/hgui worktree UI dev helpers (#6…
Jul 17, 2026
7cb2d2c
fix(auth): detect configured providers absent from registry (#66017)
Jul 17, 2026
e20c3c1
fix: honor disabled title generation config
Jun 2, 2026
8222b16
fix(title): follow-ups for salvaged #37349 — lazy config import, guar…
Jul 17, 2026
af550a7
fix(honcho): reject whitespace-only search/reasoning queries
Apr 16, 2026
9a887e7
fix(honcho): use _resolve_observer_target for user context in session…
Jul 12, 2026
b08a13c
test: add prefetch_context observer-resolution test for ai_observe_ot…
Jul 12, 2026
602998b
fix(honcho): warn model away from minimal reasoning_level on multi-fa…
Jul 6, 2026
cd268c1
fix(honcho): read base_url and defaultHost from honcho.json host blocks
Jul 9, 2026
73a4574
fix(honcho): preserve profiles for local IP config
Jul 10, 2026
e5bebe2
fix(plugins): rebuild Honcho client when timeout config changes
Jul 3, 2026
04d84df
fix(honcho): memoize timeout staleness check + host-aware status cadence
Jul 17, 2026
b170f52
test(honcho): align observer-resolution test with post-#62290 call shape
Jul 17, 2026
46d16f4
fix(tui): recover mouse tracking without a resize via DECRQM watchdog…
Jul 17, 2026
f725cf8
fix(agent): avoid overwriting manual session titles
Jun 23, 2026
d05cd7c
fix(agent): make auto-title write atomic
Jul 15, 2026
9bf5822
fix(cron): robust session title generation (#50535, #50536, #50537)
Jun 22, 2026
7facf63
fix(title): reconcile atomic auto-title writes with collision dedup r…
Jul 17, 2026
ed2f48b
fix(titles): use active runtime for gateway sessions
Jul 12, 2026
61be8b3
chore(release): map seagpt noreply identity for PR #62983 salvage
Jul 17, 2026
ef1c622
fix(title): prevent stale background title generation from reloading …
Jul 17, 2026
3483759
fix(auth): make xAI OAuth pools multi-account resilient
Jul 10, 2026
73ad913
refactor(credentials): consolidate single-use OAuth refresh lock scaf…
Jul 17, 2026
136ade2
fix(agent): surface Codex commentary items as interim messages
Jul 7, 2026
a15397d
fix(agent): redact Codex interim commentary
Jul 14, 2026
b008131
fix(agent): harden Codex commentary interim delivery
Jul 16, 2026
7041c56
feat(agent): stream Codex commentary separately
Jul 16, 2026
779019e
feat(agent): add display.show_commentary toggle for Codex commentary …
Jul 17, 2026
0f102fa
feat(browser): store full snapshots on truncation; make eval denylist…
Jul 17, 2026
5c121f1
fix(cron): resolve the no-override store fallback lazily so late env …
Jul 16, 2026
65d6bd2
fix(cron): patched compatibility constants take precedence over a rep…
Jul 16, 2026
bd208a6
test(cron): public save_jobs()/load_jobs() post-import HERMES_HOME re…
Jul 16, 2026
ebc32bf
chore: add MaartenDMT to AUTHOR_MAP for PR #65637 salvage
Jul 17, 2026
e840cca
feat(codex): add app-server event bridge for Hermes UI callbacks
May 27, 2026
7b63c49
fix(codex): surface live tool-progress + commentary on app-server run…
May 27, 2026
68d5368
test(codex): regression coverage for app-server event bridge (#33200)
May 27, 2026
60419df
fix(codex): reconcile app-server bridge with #38835, gate commentary …
Jul 17, 2026
6dcbcd0
refactor(console): remove hosted-context command blocking from Hermes…
Jul 17, 2026
1a5d2a1
fix: handle infinite Codex wait deadlines
Jul 16, 2026
14ea8de
fix(agent): harden non-finite wait recovery
Jul 17, 2026
05dea7b
fix(mcp): complete OAuth through hosted dashboards
Jul 17, 2026
b09f1ba
fix(mcp): reject invalid dashboard oauth callbacks
Jul 17, 2026
11eaa77
fix(mcp): serialize hosted oauth reauthorization
Jul 17, 2026
6045529
fix(mcp): harden hosted OAuth across profiles and clients
Jul 17, 2026
ebd737f
fix(mcp): close hosted OAuth lifecycle gaps
Jul 17, 2026
cf3ae7c
fix(mcp): preserve live OAuth state during reauth
Jul 17, 2026
4dc2b7b
fix(mcp): preserve concurrent OAuth manager refresh
Jul 17, 2026
78b9d98
fix(codex): surface nested error envelope in Responses type=error SSE…
Jul 17, 2026
e701cdc
fix(gateway): end finalized expired sessions as reset
Jul 12, 2026
3305dce
fix: conditional promote + real SessionDB tests
Jul 15, 2026
4b12b7a
fix(session): check reset policy in self-healing recovery path (#54878)
Jul 9, 2026
039f6b2
test(gateway): add overdue-policy guard for stale-agent-close recover…
Jul 13, 2026
3c7bab9
fix(gateway): notify user and log correct end_reason for resume_pendi…
Jul 5, 2026
cecf276
fix(gateway): preserve lazy reset after session expiry
Jul 4, 2026
f5b6112
fix(gateway): fail closed on active-process check errors
Jul 14, 2026
d17daf0
fix(gateway): keep stale route when recovery lookup fails
Jul 12, 2026
9fc0074
fix(gateway): unify reset boundaries vs recovery — promote accidental…
Jul 16, 2026
f28248c
test: update lock-io auto-reset assertion to the promote write-path
Jul 16, 2026
a4ecb3d
fix(skills): strip UTF-8 BOM before parsing SKILL.md frontmatter
Jun 11, 2026
780e098
fix: widen UTF-8 BOM tolerance to all sibling frontmatter parsers
Jul 16, 2026
b90dbac
fix(approval): unify execution-bearing option detection
Jul 13, 2026
17485cb
fix(cli): sanitize terminal escapes when replaying stored history (/r…
Jul 15, 2026
b78ff50
fix(gemini): prune required entries missing from properties in tool s…
Jul 14, 2026
b4221c6
Inspired by Claude Code: protect session transcripts
Jul 11, 2026
332fbad
fix(backup): fail closed on sqlite snapshot errors
Jul 10, 2026
c356752
fix(memory): drain queued writes on shutdown
Jul 10, 2026
6030ca8
fix(mcp): follow nextCursor pagination in tools/resources/prompts dis…
Jul 10, 2026
a8ec415
fix(mcp): treat non-string nextCursor as end of pagination
Jul 10, 2026
174fc95
fix(errors): classify Z.AI GLM token-limit message as context overflow
Jul 10, 2026
d9dd05b
feat(cron): add truthful execution ledger
Jul 10, 2026
abc22cd
fix(cron): harden execution attempt ledger
Jul 13, 2026
b41b4b3
test(file-safety): unbreak session-snapshot suite; de-flake fixture t…
Jul 17, 2026
f32191f
Merge pull request #66254 from kshitijk4poor/chore/author-map-maartendmt
Jul 17, 2026
53d3588
fix(gateway): retry transcript appends
Jul 16, 2026
a9cc17f
fix: harden transcript append retry — lock, matcher, encapsulation, cap
Jul 17, 2026
348e991
fix(agent): execute valid tool calls in mixed batches with invalid na…
Jul 17, 2026
c66891d
fix(cli): arm exit watchdog on shutdown signal, not at chat startup (…
Jul 17, 2026
0c9ac09
fix(streaming): fence superseded streams out of the delta sink (singl…
Jul 17, 2026
35cbffd
test(streaming): cover the single-writer invariant for superseded str…
Jul 17, 2026
d32a6d4
fix(codex): claim the stream-writer token on the codex_responses path…
Jul 17, 2026
c720504
fix(compression): affirm tool use stays active in the compaction hand…
Jul 17, 2026
11a91a6
fix(codex): forward drained notifications to on_event during approval…
Jul 17, 2026
ec3d958
feat(codex): webSearch bubbles + bare hermes-tools names in app-serve…
Jul 17, 2026
4579f26
fix(state): heal alternation at the ACP / CLI-resume / TUI-resume res…
Jul 16, 2026
7ada946
test(tui_gateway): accept repair_alternation in resume-path DB doubles
Jul 16, 2026
bebcf95
test(delegate): assert copilot probe with assert_any_call to de-flake…
Jul 16, 2026
95cc3f7
fix(tui): heal alternation at the remaining live-replay resume sites
Jul 17, 2026
c49ed09
test(tui): accept repair_alternation in the top-level server test dou…
Jul 17, 2026
71252f0
fix(terminal): fall back when the configured cwd is unenterable, not …
Jul 17, 2026
e0390c0
perf(desktop): pre-warm profile pool backends on hover intent
Jul 17, 2026
e4f8755
feat(kanban): modal create-task dialog, editable board project direct…
Jul 17, 2026
0bf44d5
fmt(js): `npm run fix` on merge (#66348)
Jul 17, 2026
9e1b1d7
fix(state): self-heal FTS corruption on the SessionDB write path (#66…
Jul 17, 2026
fdc6c32
fix(auxiliary): isolate runtime cache by live context
Jul 17, 2026
c201b72
fix(auxiliary): sync runtime after fallback restoration
Jul 17, 2026
bcce700
fix(compression): reset failure cooldown on runtime switch
Jul 17, 2026
ef9a983
fix(tui): route images with the live switched model
Jul 17, 2026
89130bf
chore(release): map auxiliary runtime contributors
Jul 17, 2026
73057ed
fix(auxiliary): scope runtime state to each turn
Jul 17, 2026
ef9e0c9
test(compression): expect complete runtime tuple
Jul 17, 2026
594308d
fix(credential-pool): throttle "no available entries" log to stop Win…
Jul 17, 2026
81a1402
perf(desktop): pre-warm opens the gateway socket too, not just the spawn
Jul 17, 2026
2f00cca
feat(desktop): promote Fireworks AI to #2 in onboarding provider pick…
Jul 17, 2026
75b300f
fmt(js): `npm run fix` on merge (#66445)
Jul 17, 2026
cfb9459
ci: add 2 minute timeout to osv scan (#66410)
Jul 17, 2026
41fdcae
fix(streaming): make the single-writer fence best-effort so a missing…
Jul 17, 2026
ba54233
fix(desktop): session-scope fast mode, surface profile ownership + pi…
Jul 17, 2026
a75a8ed
refactor(desktop): derive working/attention session sets from $sessio…
Jul 17, 2026
2704862
Merge pull request #66347 from NousResearch/bb/profile-switch-prewarm
Jul 17, 2026
3e7c563
Merge pull request #66449 from NousResearch/audit/desktop-model-picker
Jul 17, 2026
9930c2b
Merge pull request #66034 from NousResearch/bb/review-store-tests
Jul 17, 2026
29e3983
fmt(js): `npm run fix` on merge (#66457)
Jul 17, 2026
cf52edb
Merge pull request #66454 from NousResearch/ethie/session-status-sync
Jul 17, 2026
29dac61
fmt(js): `npm run fix` on merge (#66460)
Jul 17, 2026
bcea537
fmt(js): `npm run fix` on merge (#66465)
Jul 17, 2026
11d3623
fix(desktop): stop button sends interrupt to wrong session + stale ev…
Jul 17, 2026
19bc02f
feat(dev-sandbox): add --from DIR to seed sandbox HERMES_HOME (#66486)
Jul 17, 2026
9769fac
fix(honcho): resolve the timeout staleness check from honcho.json lik…
Jul 17, 2026
e4cdd8d
fix(honcho): delegate the config.yaml timeout read to load_config_rea…
Jul 17, 2026
7f76fc0
Merge pull request #64576 from joelbrilliant/fix/desktop-update-strea…
Jul 17, 2026
8702e6a
fmt(js): `npm run fix` on merge (#66505)
Jul 17, 2026
18331b9
feat(codex): stream live app-server events to TUI/desktop tool cards
Jul 17, 2026
05b5e2b
docs(codex): document live app-server display; AUTHOR_MAP entries
Jul 17, 2026
8051eba
fix: cap cache-scope headers at 64 chars to avoid Codex 400 error (#6…
Jul 17, 2026
81496a8
test(codex): cover overlength cache-scope headers
Jul 17, 2026
61bbc39
fix(codex): harden final cache-key boundaries
Jul 17, 2026
4c0546c
fix(moa): surface stale presets without retries
Jul 17, 2026
07f07c7
fix(mem0): migrate legacy OSS base URL aliases
Jul 17, 2026
597615a
fix(ci): make tests, workflows, and attribution reliable under load (…
Jul 17, 2026
d9ee342
fmt(js): `npm run fix` on merge (#66527)
Jul 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
71 changes: 71 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,21 @@
.gitignore
.gitmodules

# Python
__pycache__
*.py[cod]
*$py.class
*.so
.Python
*.egg-info/
dist/
build/

# Virtual environments
venv/
env/
ENV/

# Dependencies
node_modules
**/node_modules
Expand All @@ -24,7 +39,20 @@ ui-tui/packages/hermes-ink/dist/

# Environment files
.env
.env.*

# IDE
.vscode/
.idea/
*.swp
*.swo

# Testing
.pytest_cache/
.coverage
htmlcov/

# Documentation
*.md

# Runtime data (bind-mounted at /opt/data; must not leak into build context)
Expand All @@ -35,3 +63,46 @@ data/
# Compose/profile runtime state (bind-mounted; avoid ownership/secret issues)
hermes-config/
runtime/

# ---------- Not needed inside the Docker image ----------

# Desktop app source (Tauri/Electron); never installed in the container.
# apps/shared is the dashboard↔desktop websocket helper and is linked from
# web/package.json as a file: workspace dep — keep it in the build context.
apps/
!apps/shared/
!apps/shared/**

# Test suite — not shipped in production images
tests/

# Documentation site (Docusaurus) and supplementary docs
website/
docs/

# Assets only used by the GitHub README
assets/
infographic/

# Plugin-level docs (hermes-achievements ships docs/ but the runtime doesn't read them)
plugins/hermes-achievements/docs/

# Nix / Homebrew / AUR packaging metadata — irrelevant to Docker
nix/
flake.nix
flake.lock
packaging/

# Design and planning documents
plans/
.plans/

# ACP registry manifest (icon + agent.json) — not consumed at runtime
acp_registry/

# Repo-level dotfiles that are git-only or dev-tooling config
.env.example
.envrc
.gitattributes
.hadolint.yaml
.mailmap
24 changes: 24 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
@@ -1,6 +1,13 @@
# Hermes Agent Environment Configuration
# Copy this file to .env and fill in your API keys

# =============================================================================
# LLM PROVIDER (Fireworks AI)
# =============================================================================
# Get your key at: https://app.fireworks.ai/settings/users/api-keys
# Address models directly by catalog ID, e.g.
# accounts/fireworks/models/kimi-k2p6, accounts/fireworks/models/glm-5p2
# FIREWORKS_API_KEY=
# =============================================================================
# LLM PROVIDER (OpenRouter)
# =============================================================================
Expand Down Expand Up @@ -105,8 +112,13 @@
# Get your token at: https://huggingface.co/settings/tokens
# Required permission: "Make calls to Inference Providers"
# HF_TOKEN=
# HF_BASE_URL=https://router.huggingface.co/v1 # Override default base URL
# OPENCODE_GO_BASE_URL=https://opencode.ai/zen/go/v1 # Override default base URL

# DeepInfra — 100+ top open models, pay-per-use.
# Get your key at: https://deepinfra.com/dash/api_keys
# DEEPINFRA_API_KEY=

# =============================================================================
# LLM PROVIDER (Qwen OAuth)
# =============================================================================
Expand All @@ -124,6 +136,15 @@
# Optional base URL override:
# XIAOMI_BASE_URL=https://api.xiaomimimo.com/v1

# =============================================================================
# LLM PROVIDER (Upstage Solar)
# =============================================================================
# Upstage provides access to Upstage Solar models.
# Get your key at: https://console.upstage.ai/api-keys
# UPSTAGE_API_KEY=your_key_here
# Optional base URL override:
# UPSTAGE_BASE_URL=https://api.upstage.ai/v1

# =============================================================================
# TOOL API KEYS
# =============================================================================
Expand Down Expand Up @@ -411,6 +432,9 @@ IMAGE_TOOLS_DEBUG=false
# Groq API key (free tier — used for Whisper STT in voice mode)
# GROQ_API_KEY=

# ElevenLabs API key (cloud STT/TTS — Scribe transcription)
# ELEVENLABS_API_KEY=

# =============================================================================
# STT PROVIDER SELECTION
# =============================================================================
Expand Down
6 changes: 3 additions & 3 deletions .envrc
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
watch_file pyproject.toml uv.lock
watch_file ui-tui/package-lock.json ui-tui/package.json
watch_file flake.nix flake.lock nix/devShell.nix nix/tui.nix nix/package.nix nix/python.nix
watch_file pyproject.toml uv.lock hermes
watch_file package-lock.json package.json web/package.json ui-tui/package.json website/package.json apps/shared/package.json apps/desktop/package.json ui-tui/packages/hermes-ink/package.json
watch_file flake.nix flake.lock nix/devShell.nix nix/tui.nix nix/package.nix nix/python.nix nix/hermes-agent.nix nix/desktop.nix

use flake
8 changes: 8 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1,2 +1,10 @@
# Auto-generated files — collapse diffs and exclude from language stats
web/package-lock.json linguist-generated=true

# Enforce LF for scripts that run inside Linux containers.
# Without this, Windows checkout converts to CRLF and breaks `exec` in the
# container entrypoint with "no such file or directory".
*.sh text eol=lf
Dockerfile text eol=lf
*.dockerfile text eol=lf
docker/entrypoint.sh text eol=lf
90 changes: 90 additions & 0 deletions .github/actions/detect-changes/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
name: Detect affected areas
description: >-
Classify a PR's changed files into CI work lanes (python, frontend, site,
scan, deps, mcp_catalog) so the orchestrator can conditionally call only
the sub-workflows a PR can affect. Outputs are always "true" on push/dispatch
events and fail open (everything "true") when the diff cannot be computed.

inputs:
github-token:
description: Token for the GitHub API (gh CLI). Pass secrets.AUTOFIX_BOT_PAT from the calling workflow.
required: false
default: ${{ github.token }}

outputs:
python:
description: Run Python tests / ruff / ty / windows-footguns.
value: ${{ steps.classify.outputs.python }}
frontend:
description: Run the TypeScript testing matrix + desktop build.
value: ${{ steps.classify.outputs.frontend }}
docker_meta:
description: Docker setup and meta files have changed.
value: ${{ steps.classify.outputs.docker_meta }}
site:
description: Build the Docusaurus docs site.
value: ${{ steps.classify.outputs.site }}
scan:
description: Run the supply-chain critical-pattern scanner.
value: ${{ steps.classify.outputs.scan }}
deps:
description: Check pyproject.toml dependency upper bounds.
value: ${{ steps.classify.outputs.deps }}
npm_lock:
description: Post/update the semantic package-lock.json diff PR comment.
value: ${{ steps.classify.outputs.npm_lock }}
mcp_catalog:
description: Require MCP catalog security review label.
value: ${{ steps.classify.outputs.mcp_catalog }}
ci_review:
description: Require CI-sensitive file review label.
value: ${{ steps.classify.outputs.ci_review }}

runs:
using: composite
steps:
- name: Classify changed files
id: classify
shell: bash
env:
GH_TOKEN: ${{ inputs.github-token }}
REPO: ${{ github.repository }}
EVENT_NAME: ${{ github.event_name }}
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail

# Only pull_request events are gated. Other events (push, release,
# dispatch) leave CHANGED empty, so the classifier fails open and every
# lane runs. Post-merge / on-demand validation is never weakened.
if [ "$EVENT_NAME" = "pull_request" ]; then
# Use the compare endpoint with the pinned base/head SHAs from the
# event payload instead of the "current PR files" endpoint. The SHAs
# are frozen at trigger time, so the file list is deterministic even
# if the PR receives a new push between trigger and detect.
#
# Retried: a rate-limit blip or eventual-consistency 404 on a
# freshly-pushed HEAD would otherwise silently fall open (all lanes
# run — safe, but wasteful and it masks the API failure).
CHANGED=""
for i in 1 2 3; do
if CHANGED="$(gh api \
--paginate \
"repos/${REPO}/compare/${BASE_SHA}...${HEAD_SHA}" \
--jq '.files[].filename')"; then
break
fi
if [ "$i" = 3 ]; then
echo "::warning::compare API failed after 3 attempts — failing open (all lanes run)"
CHANGED=""
break
fi
echo "::warning::compare API failed (attempt $i); retrying in 10s"
sleep 10
done
fi

echo "Changed files:"
printf '%s\n' "${CHANGED:-(none)}"
printf '%s\n' "${CHANGED:-}" | python3 scripts/ci/classify_changes.py
50 changes: 0 additions & 50 deletions .github/actions/hermes-smoke-test/action.yml

This file was deleted.

70 changes: 70 additions & 0 deletions .github/actions/retry/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
name: Retry a flaky command
description: >-
Run a shell command, retrying on non-zero exit. For dependency installs
(npm ci, uv sync) whose only failures are transient network/toolchain
flakes — a node-gyp header fetch, a registry blip — so CI self-heals
instead of needing a manual re-run. Can also capture stdout as a step
output for commands whose result must be consumed by later steps.

inputs:
command:
description: Shell command to run (and retry).
required: true
attempts:
description: Max attempts before giving up.
default: "3"
delay:
description: Seconds to wait between attempts.
default: "10"
working-directory:
description: Directory to run in.
default: "."

outputs:
stdout:
description: Captured stdout from the successful attempt (empty if not needed).
value: ${{ steps.retry.outputs.stdout }}

runs:
using: composite
steps:
- id: retry
shell: bash
working-directory: ${{ inputs.working-directory }}
# command goes through env, never interpolated into the script body, so
# a command with quotes/specials can't break or inject into the runner.
env:
_CMD: ${{ inputs.command }}
_ATTEMPTS: ${{ inputs.attempts }}
_DELAY: ${{ inputs.delay }}
run: |
set -uo pipefail
_OUTFILE="$(mktemp)"
trap 'rm -f "$_OUTFILE"' EXIT
n=0
while :; do
n=$((n + 1))
echo "::group::attempt $n/$_ATTEMPTS: $_CMD"
# Run the command, capturing stdout to a temp file while still
# streaming to the log. We redirect first, then tee the file to
# stdout — this avoids pipefail + tee exit-code interactions that
# can cause the if-branch to be skipped under set -e.
if bash -c "$_CMD" > "$_OUTFILE"; then
cat "$_OUTFILE"
echo "::endgroup::"
# Preserve newlines in the output via heredoc delimiter.
{
echo 'stdout<<__RETRY_STDOUT_EOF__'
cat "$_OUTFILE"
echo '__RETRY_STDOUT_EOF__'
} >> "$GITHUB_OUTPUT"
exit 0
fi
echo "::endgroup::"
if [ "$n" -ge "$_ATTEMPTS" ]; then
echo "::error::failed after $n attempts: $_CMD"
exit 1
fi
echo "::warning::attempt $n failed; retrying in ${_DELAY}s: $_CMD"
sleep "$_DELAY"
done
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .github/pr-screenshots/39327/tools-collapsed.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .github/pr-screenshots/39327/tools-expanded.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .github/pr-screenshots/45449/billing-confirm.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading