Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
7877 commits
Select commit Hold shift + click to select a range
ae80cb7
fix: import hermes_bootstrap first in the compute-host and hermes-too…
teknium1 Sep 23, 2026
1808488
fix: bootstrap the hermes-tools MCP server only when it runs as pytho…
teknium1 Sep 23, 2026
db0fe41
fix: bootstrap the compute host only as python -m; pin library import…
teknium1 Sep 24, 2026
d4212f7
fix: a nested os.environ write from an audit hook no longer drops out…
teknium1 Sep 24, 2026
37aad38
fix: an audit hook that writes os.environ on every event can no longe…
teknium1 Sep 24, 2026
a25cf4d
fix(providers): a provider registered after hermes_cli.models imports…
teknium1 Sep 24, 2026
1b7e8c4
fix(desktop): every settings row renders through one ListRow/ToggleRo…
OutThisLife Sep 24, 2026
7d63f57
feat(sdk): export ListRow/ToggleRow so plugin panes lay out like core…
OutThisLife Sep 24, 2026
0fb230b
fix(desktop): every Appearance row is a command-palette hit
OutThisLife Sep 24, 2026
686c34d
feat(bot_desktop): ship Bot Screen on hosted images (-desktop tags)
IAvecilla Sep 24, 2026
65d01a7
test: allowlist installable()'s sudo probe for the command-resolution…
teknium1 Sep 24, 2026
35b14ad
Merge pull request #120928 from NousResearch/bb/desktop-function-shor…
OutThisLife Sep 24, 2026
771eb80
fix(tests): stop tui_gateway subagent snapshot fixture forking the li…
teknium1 Sep 24, 2026
fcd6e78
Merge pull request #120925 from NousResearch/bb/session-search-titles
OutThisLife Sep 24, 2026
c22b0a2
Merge pull request #120950 from NousResearch/bb/settings-row-consistency
OutThisLife Sep 24, 2026
e7cc383
fix: TUI auth fallback no longer crashes on `model: <id>` config shor…
teknium1 Sep 24, 2026
8ae1dc1
test: tui_gateway/test_protocol stops leaking _hermes_home and a fres…
teknium1 Sep 24, 2026
5dbbc9a
fix(cli): make plugin clone timeout configurable
helix4u Sep 24, 2026
72d18ce
fix(plugins): subdirectory installs download only that folder
teknium1 Sep 24, 2026
d188a47
fix(desktop): plugin probe/install from a repo subfolder downloads on…
teknium1 Sep 24, 2026
11b0bcc
feat(desktop): index every hand-built settings row in the command pal…
OutThisLife Sep 24, 2026
7135182
Merge pull request #121039 from NousResearch/bb/settings-search-manifest
OutThisLife Sep 24, 2026
7de8728
Merge pull request #108345 from afourniernv/fix/relay-atof-cwd
jquesnelle Sep 24, 2026
9835323
fix(agent/gemini): count thinking tokens in usage and cost
Maero47 Sep 4, 2026
a980c35
test(gemini): trim salvaged thinking-token tests to the two invariants
teknium1 Sep 24, 2026
2364cde
chore(contributors): map Maero47's commit email
teknium1 Sep 24, 2026
994074c
fix(desktop): retain provider setup connection and profile ownership
BearHuddleston Sep 22, 2026
7213ebb
test(desktop): cover provider setup route lookup failures
BearHuddleston Sep 22, 2026
690813b
fix(desktop): keep the Desktop route alias when the picker opens prov…
BearHuddleston Sep 22, 2026
4340fa4
fix(desktop): pin provider setup readiness to an explicit connection
BearHuddleston Sep 22, 2026
db20d39
fix(desktop): keep provider readiness on the profile REST setup writes
teknium1 Sep 24, 2026
6fa17e8
test: trim salvage tests to invariants
teknium1 Sep 24, 2026
fec4920
test: restore picker alias handoff coverage
teknium1 Sep 24, 2026
03a7bf3
fix(gemini): wire response_format into native Gemini generationConfig
gabbyong Sep 24, 2026
b6d38fd
fix(gemini): drop JSON response_format alongside tools on pre-Gemini-…
teknium1 Sep 24, 2026
236aab3
fix(auxiliary): recognise Gemini's structured-output 400 wording
teknium1 Sep 24, 2026
04fa849
chore(contributors): map gabbyong's commit email
teknium1 Sep 24, 2026
a69f860
fix(desktop): keep image frames stable through delayed loads
BearHuddleston Sep 22, 2026
39cca5f
fix(desktop): keep the pending generated-image frame when its result …
BearHuddleston Sep 22, 2026
77bb695
fix(desktop): read explicitly local-owned media through the native br…
BearHuddleston Sep 22, 2026
99d9b62
fix(desktop): drop stale tool-output image size overrides
BearHuddleston Sep 23, 2026
81235c9
test: trim salvage tests to invariants
teknium1 Sep 24, 2026
4c6137f
fix(desktop): never upscale a cold chat image or shrink its portrait
teknium1 Sep 24, 2026
d113cfc
fix(desktop): remember the size of inline data-URL chat images
teknium1 Sep 24, 2026
06616b4
fix(desktop): collapse a broken chat image to one line
teknium1 Sep 24, 2026
51f8b7c
chore(desktop): neutral wording in the pixel_size comment
teknium1 Sep 24, 2026
ee8ffff
fix(desktop): keep a generated image visible after a remembered failure
teknium1 Sep 24, 2026
f6d0e0c
fix(desktop): restore the remote-owner image routing test
teknium1 Sep 24, 2026
6828ffa
fix(desktop): persist edit previews before tool-result flush
BearHuddleston Sep 22, 2026
caf1c38
fix(desktop): only an unresolved tool part claims a stored result
BearHuddleston Sep 22, 2026
9579930
fix: consume prepared edit previews on every completion path
teknium1 Sep 24, 2026
f27a0a9
test: trim salvage tests to invariants
teknium1 Sep 24, 2026
444066b
fix: exclude display-only message fields from token estimates
teknium1 Sep 24, 2026
37e0ac0
fix(desktop): hold history reads behind reconnect replay
BearHuddleston Sep 24, 2026
9e66418
test: trim salvage tests to invariants
teknium1 Sep 24, 2026
bb7788c
fix(desktop): let history reads proceed when the replay epoch changes
teknium1 Sep 24, 2026
32cf269
fix(desktop): settle a warm resume through activate when replay is lost
teknium1 Sep 24, 2026
1a0b6ff
fix(desktop): hold a reconnect re-resume behind its runtime's replay
teknium1 Sep 24, 2026
04b61d1
fix(desktop): ignore retired secondaries in the replay barrier
teknium1 Sep 24, 2026
4d58c3a
fix(desktop): re-check the replay barrier after a cold re-resume REST…
teknium1 Sep 24, 2026
716db85
test: restore replay-barrier fallback and background-sync coverage
teknium1 Sep 24, 2026
defb703
fix(desktop): don't let a closed secondary veto a runtime an open soc…
teknium1 Sep 24, 2026
58c896e
fmt(js): `npm run fix` on merge (#121111)
hermes-seaeye[bot] Sep 24, 2026
074349f
Merge pull request #120790 from benbarclay/feat/desktop-external-brow…
OutThisLife Sep 24, 2026
a874cee
feat(desktop): expose composer draft API to plugins (host.composer)
Heybinshao Sep 19, 2026
6b3c0de
fix(composer): gate active draft requests on isActive and acknowledge…
Heybinshao Sep 22, 2026
dcea97b
feat(desktop): add host.composer.focus(sessionId) to the plugin compo…
teknium1 Sep 24, 2026
9316197
docs(desktop-sdk): host.composer signatures, arbitration, consumer mi…
teknium1 Sep 24, 2026
ef70b36
fix(desktop): host.composer 'new' fails closed, single-owner draft re…
teknium1 Sep 24, 2026
78b1331
fix(desktop): collapse stale compression tips before nesting sidebar …
OutThisLife Sep 24, 2026
d78355c
fix(desktop): tag and preview Windows absolute paths (C:\, UNC)
OutThisLife Sep 24, 2026
2a38b29
refactor(desktop): share isWindowsAbsolutePath with the attachment up…
OutThisLife Sep 24, 2026
1bdc455
fix(desktop): keep the selected chat's workspace when entering a project
OutThisLife Sep 24, 2026
e7bcdcc
fix(cli): bound persistent_output replay to visible terminal height
Sep 23, 2026
f748481
fix(cli): refill only the viewport on redraw and erase it without CSI 2J
teknium1 Sep 23, 2026
d486536
fix(cli): a resize mid-stream repaints each transcript line once
teknium1 Sep 23, 2026
38f9764
fix(cli): size the resize replay for how the terminal re-wraps
teknium1 Sep 23, 2026
29b9d7a
fix(cli): measure the re-wrapped chrome as prompt_toolkit wrote it
teknium1 Sep 23, 2026
68b0f85
fix(cli): resize keeps each transcript row once on tmux and never los…
teknium1 Sep 24, 2026
0b8278d
fix(cli): a shrink refills the viewport on terminals that don't reflow
teknium1 Sep 24, 2026
9f288ba
fix(cli): treat GNU screen as a reflowing terminal
teknium1 Sep 24, 2026
1a36408
test: drop the _cprint hold test added for #95375
teknium1 Sep 24, 2026
6055214
test(e2e): (cli, resize_scrollback) passes plainly now that #95375 is…
teknium1 Sep 24, 2026
e389aa4
fix(cli): close resize-drag row loss and modal refill dups (#95375)
teknium1 Sep 24, 2026
9d1390f
fix(cli): settle before a mid-drag resize recovery; keep-above erase …
teknium1 Sep 24, 2026
764d5bf
fix(cli): hold resize-drag output 0.7 s before a recovery (#95375)
teknium1 Sep 24, 2026
a95242c
fix(cli): tmux with a generic TERM still counts as reflowing (#95375)
teknium1 Sep 24, 2026
0004e3a
refactor(cli): move the output-history row helpers out of the cli fac…
teknium1 Sep 24, 2026
6d57e9e
fix(cli): never aim the resize erase past chrome tmux clipped (#95375)
teknium1 Sep 24, 2026
71cca15
fix(compression): a compressor no attempt claimed is never judged stale
100yenadmin Sep 24, 2026
9ec5640
test(compression): trim unclaimed-compressor coverage to two invariants
teknium1 Sep 24, 2026
748f039
feat(desktop): expose typed plugin settings gateway
zyz619963502zyz Sep 19, 2026
21f6e35
docs(desktop): host.settings — teardown rule, declined keys, consumer…
teknium1 Sep 24, 2026
ab2c1cb
fix(desktop): host.settings refuses inherited keys instead of TypeErr…
teknium1 Sep 24, 2026
540442a
fix(desktop): label the settings sessions group 'Sessions', not 'Arch…
OutThisLife Sep 24, 2026
0e69909
fix(desktop): don't warn about lost work when quitting a remote backend
OutThisLife Sep 24, 2026
771b42e
fix(desktop): let the project folder picker create a new folder
OutThisLife Sep 24, 2026
b9b9476
fix(desktop): scroll the composer caret into view after paste and voi…
OutThisLife Sep 24, 2026
c0c7e95
fix(desktop): keep menu search focus while hovering rows
OutThisLife Sep 24, 2026
0048071
fix(desktop): don't flash the profile-default effort before a resumed…
OutThisLife Sep 24, 2026
174ea05
fix(desktop): keep popped-out pet on-screen after a monitor unplug
scottaki Aug 4, 2026
32fbb5a
fix(desktop): never let a blank pet-overlay window capture clicks
scottaki Aug 4, 2026
412d0b7
fix(desktop): keep the popped-out pet wholly inside a display work area
OutThisLife Sep 24, 2026
75fef37
fix(desktop): clamp pet overlay drags and persist the clamped spot
OutThisLife Sep 24, 2026
585e296
feat(desktop): session-list API and row-decoration slots for plugins
tobenwarrior Sep 19, 2026
9d8ae38
feat(desktop): host.sessions.pin takes a drop index; reorder([]) rese…
teknium1 Sep 24, 2026
4f3426e
fix(desktop): host.sessions.reorder writes live ids; add reorderPinne…
teknium1 Sep 24, 2026
1ad2e8b
fix(desktop): avoid deprecated ASAR stat when resolving renderer
daresan Sep 21, 2026
ee6852c
fix(desktop): resolve the app icon from the unpacked dist before any …
jonpol01 Sep 23, 2026
dcf5728
test(desktop): pin that renderer and icon probes never stat inside ap…
OutThisLife Sep 24, 2026
387298a
fix(desktop): drop the remaining stat probes on app.asar paths
OutThisLife Sep 24, 2026
d5c446e
fix(desktop): keep the bundle Dock icon in packaged macOS builds
OutThisLife Sep 24, 2026
02b07ac
fix(desktop): re-read the sidebar when a same-route activation voids …
OutThisLife Sep 24, 2026
2054ab9
fix(desktop): report failed primary session reads instead of empty sl…
OutThisLife Sep 24, 2026
14a8a77
fix(desktop-update): stop launching a Chrome instance for the macOS u…
OutThisLife Sep 24, 2026
9a2507e
fix(desktop): save hand-registered Cloud connections as oauth with a …
OutThisLife Sep 24, 2026
0f9feda
fix(web): re-measure xterm once the bundled terminal font loads
OutThisLife Sep 24, 2026
80e3063
fix(tts): keep local voices warm for tts.keep_warm_seconds after the …
OutThisLife Sep 24, 2026
0641ee1
fix(tui-gateway): never park an idle /steer on the agent
OutThisLife Sep 24, 2026
21cc8bf
fix(update): anchor discarded local commits before the diverged reset
Moep90 Sep 18, 2026
c7d2985
fix(install): keep dropped commits behind a rescue ref on the install…
OutThisLife Sep 24, 2026
db1ff59
fix(update): say how many commits the diverged reset drops and where …
OutThisLife Sep 24, 2026
511b879
docs(update): document rescue refs for local commits on the target br…
OutThisLife Sep 24, 2026
021530a
fix(delegation): re-offer completions orphaned by a dead owner while …
OutThisLife Sep 24, 2026
02ed55e
fix(delegation): hand a dropped orphan offer back to the sweep
OutThisLife Sep 24, 2026
3fa2123
fix(desktop): group messaging sidebar sections by profile when showin…
webtecnica Aug 16, 2026
bbba4d4
fix(desktop): group messaging platforms by gateway/profile owner in a…
OutThisLife Sep 24, 2026
72b8502
fix(desktop): open the Nous sign-in dialog from Billing's logged-out …
OutThisLife Sep 24, 2026
632a5cd
feat(desktop): sidebar nav visibility and order for plugins
tobenwarrior Sep 19, 2026
7fba0e6
feat(desktop): sidebar nav prefs become a `sidebarNav.prefs` contribu…
teknium1 Sep 24, 2026
2553b86
fix(desktop): sidebarNav.prefs cannot hide the Plugins row; document …
teknium1 Sep 24, 2026
826e40c
fix(desktop): trim wrapper parens from raw URL autolinks
harjothkhara Jun 13, 2026
d51727f
refactor(desktop): single-pass unbalanced-paren trim in raw-URL autol…
harjothkhara Jun 13, 2026
ef9a5f9
fix(desktop): preserve matched URL parentheses
harjothkhara Jul 11, 2026
c882636
fix(desktop): raw-URL autolinker steps over markdown links (#49822)
OutThisLife Sep 24, 2026
0c7c8b6
fix(project): keep task-scoped create/switch off the profile-global p…
Jul 16, 2026
a932f22
fix(project): report the calling session's project from desktop_proje…
OutThisLife Sep 24, 2026
2b4a5a0
feat(desktop): model-pill label providers for plugins
tobenwarrior Sep 19, 2026
eecabbe
feat(desktop): memoise model-pill providers on primitives; cover comp…
teknium1 Sep 24, 2026
1b77007
docs(desktop-sdk): model-pill label providers — signatures, arbitrati…
teknium1 Sep 24, 2026
6b2c23a
fix(desktop): model-pill provider must return a string; non-strings f…
teknium1 Sep 24, 2026
3b8c77c
fmt(js): `npm run fix` on merge (#121210)
hermes-seaeye[bot] Sep 24, 2026
bd55633
feat(desktop): typed skills/toolsets/profiles bridge for plugins
tobenwarrior Sep 19, 2026
488cd56
feat(desktop): move the capabilities bridge to sdk/bridge.ts; pluginD…
teknium1 Sep 24, 2026
7daf818
docs(desktop): capabilities bridge section; pluginDecisions documente…
teknium1 Sep 24, 2026
4cec3f8
fix(desktop): host.pluginDecisions hands out frozen copies, not the l…
teknium1 Sep 24, 2026
0717586
docs(gateway): drop the remaining whichever-home --replace claims
kshitijk4poor Sep 23, 2026
9a27bcc
docs(gateway): --replace crosses homes only for an owner serving this…
kshitijk4poor Sep 23, 2026
78fbbb0
fix(gateway): log the foreign-standalone-owner warning once per start
kshitijk4poor Sep 23, 2026
c564a85
test(gateway): make the lock-refusal tests' standalone checks real
kshitijk4poor Sep 23, 2026
fa4714c
refactor(gateway): trim the --replace ownership prose and reuse _migr…
kshitijk4poor Sep 23, 2026
8d71403
feat(desktop): appearance-settings slot and the app's swatch grid for…
tobenwarrior Sep 19, 2026
84ac69e
feat(desktop): keep ColorSwatches export as on main; document APPEARA…
teknium1 Sep 24, 2026
55c52f2
fix(desktop): appearance extras use the pane boundary and render on t…
teknium1 Sep 24, 2026
ff8c8f0
fix(desktop): rebuild a packaged app whose node-pty has no native binary
OutThisLife Sep 24, 2026
d9a44a0
fix(desktop): download Kanban attachments through authenticated gateway
jroest Sep 10, 2026
efafed5
fix(desktop): Kanban attachment download through the one gated resolver
OutThisLife Sep 24, 2026
72bc2f6
fix(desktop): flag a failed cold-start sidebar read instead of report…
OutThisLife Sep 24, 2026
620d388
fix(desktop): show retry in place of "No sessions yet" when the first…
OutThisLife Sep 24, 2026
db114c2
fix(update): diagnose SSH publickey / host-key fetch failures
OutThisLife Sep 24, 2026
edecebf
fix(bootstrap): show the update child's exit-2 refusal instead of "st…
OutThisLife Sep 24, 2026
f928860
fix(projects): CLI and pathless switches move the active project again
OutThisLife Sep 24, 2026
3804baa
fix(tts): lease release reads the requesting profile's keep-warm window
OutThisLife Sep 24, 2026
83ee4bc
fix(desktop): branches of a collapsed stale tip nest under the live tip
OutThisLife Sep 24, 2026
f003387
fix(desktop): pet overlay stays clickable on Linux and survives a rep…
OutThisLife Sep 24, 2026
d81db86
feat(desktop): sandboxed embed primitive for plugins
tobenwarrior Sep 19, 2026
a48557b
feat(desktop): trim SandboxedFrame tests to invariants; document the …
teknium1 Sep 24, 2026
8636d6a
style(desktop): blank lines before statements in sandboxed-frame test
teknium1 Sep 24, 2026
c2645ef
fix(desktop): SandboxedFrame takes an explicit prop allowlist, not if…
teknium1 Sep 24, 2026
d8814dc
fix(desktop): serve uvicorn on SelectorEventLoop on Windows despite u…
Finn763 Sep 23, 2026
355f5cb
test(desktop): run the serve loop-factory regression on the Windows lane
OutThisLife Sep 24, 2026
44812b5
fix(desktop): branch long sessions without renderer transcript load
benjaminbrumbaugh Sep 4, 2026
1c7ec93
fix(desktop): preserve branch compatibility with older gateways
benjaminbrumbaugh Sep 4, 2026
d95a6bc
fix(desktop): preserve message-level branch responses
benjaminbrumbaugh Sep 4, 2026
ecacf3d
fix(desktop): declare the branch methods in the typed gateway contract
OutThisLife Sep 24, 2026
8034d49
feat(plugins): public event bridge for plugin backends
tobenwarrior Sep 19, 2026
5fa1402
feat(plugins): plugin event names take a dotted hierarchy; ids are ca…
teknium1 Sep 24, 2026
00c9f3e
fix(plugins): desktop lint reads a new RegExp("<script…") pattern as …
teknium1 Sep 24, 2026
3593b63
docs(plugins): broadcast_plugin_event contract, delivery scope and rs…
teknium1 Sep 24, 2026
5765f8d
fix(plugins): desktop lint masks a new RegExp("<script…") only where …
teknium1 Sep 24, 2026
be59f04
fix(plugins): broadcast_plugin_event from the turn-isolation child re…
teknium1 Sep 24, 2026
d892451
fix(update): cap boot recovery retries and derive self-lock native mo…
OutThisLife Sep 24, 2026
7ba3a71
fix(desktop): closing a tool tab in the chat's zone fronts the chat
OutThisLife Sep 24, 2026
d17f519
fix(desktop): profile backend env drops the launch profile's dotenv n…
OutThisLife Sep 24, 2026
94dcb17
fix(desktop): isolate primary and pooled backend spawns from launch-p…
OutThisLife Sep 24, 2026
03add1f
fix(desktop): keep root-only project chats out of Home
OutThisLife Sep 24, 2026
0397efe
fix(desktop): every project session is reachable from the sidebar
OutThisLife Sep 24, 2026
76c5bdc
fmt(js): `npm run fix` on merge (#121304)
hermes-seaeye[bot] Sep 24, 2026
eb4f92b
fix(dashboard): reject credential preview writeback
JoaoMarcos44 Sep 24, 2026
e3ef141
test(dashboard): cover secret preview boundaries
JoaoMarcos44 Sep 24, 2026
f8b66c7
fix(dashboard): make credential previews non-reusable
JoaoMarcos44 Sep 24, 2026
af4c928
fix(dashboard): reject legacy credential masks by shape, not equality
kshitijk4poor Sep 24, 2026
a7c6803
test(dashboard): fold preview-writeback coverage into two invariant t…
kshitijk4poor Sep 24, 2026
ea478da
fix(dashboard): treat any «redacted… value as a credential preview
kshitijk4poor Sep 24, 2026
b9a50dd
refactor(dashboard): hoist /api/env preview check out of the write th…
kshitijk4poor Sep 24, 2026
a7279d6
chore: map MarkTro1969 for salvage of #120557
kshitijk4poor Sep 24, 2026
aabb7a6
fix(agent): make compression stall fallback deterministic
MarkTro1969 Sep 23, 2026
f0672a0
refactor(compression): single stall-fallback ladder for every stall exit
kshitijk4poor Sep 24, 2026
3bd93da
refactor(compression): sample the stall wait once, before the retry c…
kshitijk4poor Sep 24, 2026
3028995
fix(compression): an in-place compaction never archives turns the com…
jonpol01 Sep 23, 2026
f53c0f6
fix(compression): a trailing held row without any stamp keeps the lea…
teknium1 Sep 23, 2026
1a632c3
fix(compression): a held row a merge rewrote does not bound the archive
jonpol01 Sep 23, 2026
4d58998
fix(compression): a here-N tail copy vouches for its row id only when…
kshitijk4poor Sep 24, 2026
a702791
test(cli): stop leaking a real MCP discovery thread from the TUI laun…
teknium1 Sep 24, 2026
43d3d4e
fix(journey): route memory edit/delete through MemoryStore._mutate
OutThisLife Sep 24, 2026
a88bef9
fix(config): stop the migration ladder rewriting unversioned configs
jonpol01 Sep 24, 2026
49aaa52
fix(config): keep v41 off the unversioned ladder and drop the stamp r…
kshitijk4poor Sep 24, 2026
9232479
refactor(config): read the version stamp once and drop has_version_stamp
kshitijk4poor Sep 24, 2026
19bd20f
test(config): tie LEGACY_KEY_STEPS to the migration ladder
kshitijk4poor Sep 24, 2026
03584e4
test(docker): pin the non-mapping config.yaml boot path
kshitijk4poor Sep 24, 2026
39682e3
fix(profiles): merge distributed cron jobs safely
JoaoMarcos44 Sep 24, 2026
439e3a3
test(profiles): cover cron distribution ownership
JoaoMarcos44 Sep 24, 2026
c2063cf
refactor(cron): move job-definition merge schema into cron/job_defini…
kshitijk4poor Sep 24, 2026
0bf0e03
fix(profiles): narrow cron-merge error wrapper to the corrupt-store case
kshitijk4poor Sep 24, 2026
bb0650e
fix(profiles): reject an unschedulable shipped cron job before any fi…
kshitijk4poor Sep 24, 2026
ca1ef78
refactor(cron): own the store-import loop in cron/job_definition.py
kshitijk4poor Sep 24, 2026
b0aefcc
refactor(cron): gate imported schedule changes on is_job_runnable
kshitijk4poor Sep 24, 2026
b96e88b
fix(memory): pin a staged replace/remove to the entry the approver re…
jonpol01 Sep 24, 2026
3da1c59
fix(memory): refuse unpinned legacy replace/remove at approval
kshitijk4poor Sep 24, 2026
c013f1b
refactor(memory): dry-run the staged batch through apply_batch's own …
kshitijk4poor Sep 24, 2026
5c3afee
refactor(memory): derive a payload's destructive ops in one place
kshitijk4poor Sep 24, 2026
88dee3e
refactor(memory): derive batch receipts from the matched list
kshitijk4poor Sep 24, 2026
f97608f
chore: release v0.21.5 (2026.9.24)
teknium1 Sep 24, 2026
1320bfe
Merge upstream tag v2026.9.24 (f97608f178, Hermes 0.21.5) into main
100yenadmin Sep 25, 2026
5aaac77
r34 merge: hermes_state lockguard + split — 4 files
100yenadmin Sep 25, 2026
34c5e0a
r34 merge: profiles + config + managed scope + plugin selection — 12 …
100yenadmin Sep 25, 2026
6c6e1b8
r34 merge: MCP runtime at the tag (checkpoint, no fork semantics) — 1…
100yenadmin Sep 25, 2026
3503dba
r34 merge: MCP fleet unit (evaos_lease transport, lease config valida…
100yenadmin Sep 25, 2026
7b37029
r34 merge: MCP desktop unit (native write approval, per-profile handl…
100yenadmin Sep 25, 2026
8fdfaf1
r34 merge: tui_gateway (desktop_ui_protocol wire compat, session atta…
100yenadmin Sep 25, 2026
96c3bfc
r34 merge: gateway run_* + platforms (clarify session key, voice capt…
100yenadmin Sep 25, 2026
a96714d
r34 merge: auth_codex + shared auth file — 6 files
100yenadmin Sep 25, 2026
7073ba2
r34 merge: cron split + scheduler ownership + web_server — 5 files
100yenadmin Sep 25, 2026
600bf6c
r34 merge: session search — 2 files
100yenadmin Sep 25, 2026
0f4ecb4
r34 merge: apps/desktop (upstream desktop structure, evaOS managed-mo…
100yenadmin Sep 25, 2026
1ef5753
r34 merge: the rest (fork docs restored to docs/, CI, tools, tests, R…
100yenadmin Sep 25, 2026
b61ee8c
Merge remote-tracking branch 'origin/main' into codex/r34.0-upstream-…
100yenadmin Sep 25, 2026
0df2ea7
r34 merge: ledger (docs/r34-managed-delta.md) — 1 file
100yenadmin Sep 25, 2026
7dd3d88
chore: map contributor emails
100yenadmin Sep 25, 2026
77c71e1
r34 merge: PR CI fixes (managed boot overlay keeps support banners re…
100yenadmin Sep 25, 2026
bb3356a
ci: retrigger (GitHub internal startup error on run 36137803921, no j…
100yenadmin Sep 25, 2026
ac7cf78
r34 merge: CI load budgets for upstream's heavier agent suites (slice…
100yenadmin Sep 25, 2026
19878db
r34 merge: upstream e2e jobs on standard runners (no larger runners i…
100yenadmin Sep 25, 2026
23e1728
r34 merge: upstream e2e suites opt-in behind RUN_UPSTREAM_E2E until #…
100yenadmin Sep 25, 2026
b56c1a3
r34 merge: review round (RE-7 connection.request guard, plugin re-ent…
100yenadmin Sep 25, 2026
2efd369
r34 merge: review round 2 (RE-7 connection.request to the requesting …
100yenadmin Sep 25, 2026
d00b0fe
r34 merge: review round 3 (RE-7 routing keyed on the requester's own …
100yenadmin Sep 25, 2026
187948d
r34 merge: review round 4 (pure-TUI RE-7 test with a stale desktop se…
100yenadmin Sep 25, 2026
c348ccf
ci: retrigger (GitHub startup_failure on run 36163438185, no jobs cre…
100yenadmin Sep 25, 2026
81659bb
ci: retrigger (run 36163707303: slice-4 and footguns timeouts, then a…
100yenadmin Sep 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
3 changes: 1 addition & 2 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -80,9 +80,8 @@ apps/
# Test suite — not shipped in production images
tests/

# Documentation site (Docusaurus) and supplementary docs
# Documentation site (Docusaurus)
website/
docs/

# Assets only used by the GitHub README
assets/
Expand Down
8 changes: 0 additions & 8 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -104,14 +104,6 @@
# $10/month subscription. Get your key at: https://opencode.ai/auth
# OPENCODE_GO_API_KEY=

# =============================================================================
# LLM PROVIDER (OpenCode Free)
# =============================================================================
# OpenCode Free provides keyless free models (Ox Alpha / x-preview-f-free,
# big-pickle, etc.). NO env var and NO account needed — requests are sent
# anonymously (the free tier rejects any unrecognized Authorization header).
# Select it with `hermes model` or `/model free`.

# =============================================================================
# LLM PROVIDER (Hugging Face Inference Providers)
# =============================================================================
Expand Down
4 changes: 3 additions & 1 deletion .github/scripts/run-workspace-checks.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -133,7 +133,9 @@ async function main() {
if (failed.length > 0) {
for (const r of failed) console.error(`::error::${r.unit.pkg} :: ${r.unit.script} failed`)
console.error(`::error::${failed.length} of ${results.length} checks failed`)
process.exit(1)
// Not process.exit(): it drops what stdout still buffers, which is the failing check's output.
process.exitCode = 1
return
}
console.log(`\nall ${results.length} checks passed`)
}
Expand Down
20 changes: 13 additions & 7 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,6 @@ on:
permissions:
contents: read
pull-requests: write # needed by lint (PR comment) + supply-chain review_status
actions: read # needed by osv-scanner (SARIF upload)
security-events: write # needed by osv-scanner (SARIF upload)

concurrency:
group: ci-${{ github.ref }}
Expand Down Expand Up @@ -137,6 +135,14 @@ jobs:
if: false
uses: ./.github/workflows/e2e-desktop.yml

e2e-desktop-core:
name: Desktop core E2E
needs: detect
# The deterministic core suite (apps/desktop/e2e/core): transcript
# integrity, boot/respawn/orphans, clarify+approval. Required; retries 0.
if: ${{ needs.detect.outputs.python_prod == 'true' || needs.detect.outputs.frontend == 'true' }}
uses: ./.github/workflows/e2e-desktop-core.yml

docs-site:
name: Docs Site
needs: detect
Expand Down Expand Up @@ -220,10 +226,6 @@ jobs:
mcp_catalog: ${{ needs.detect.outputs.mcp_catalog == 'true' }}
supply_chain: ${{ needs.supply-chain.outputs.critical_findings == 'true' }}

osv-scanner:
name: OSV scan
uses: ./.github/workflows/osv-scanner.yml

# ─────────────────────────────────────────────────────────────────────
# Gate: runs after everything. ``if: always()`` ensures it reports a
# status even when some deps were skipped. Only actual ``failure``
Expand All @@ -246,6 +248,7 @@ jobs:
- rust-tests
- e2e-desktop
- e2e-desktop-managed
- e2e-desktop-core
- docs-site
- history-check
- contributor-check
Expand All @@ -257,7 +260,10 @@ jobs:
- profile-artifact-check
- supply-chain
- review-labels
- osv-scanner
# OSV runs weekly against main (osv-scanner.yml schedule), not per PR:
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
# every PR was reporting the same repo-wide baseline of pinned-dep CVEs
# in its review comment, and the SARIF upload tripped GitHub's
# per-installation API rate limit during merge trains.
# The image build runs in its own workflow (docker.yml) and reports
# its own check. It was never required here, because it is too slow
# to block a merge. A separate run also stops it from holding this
Expand Down
11 changes: 11 additions & 0 deletions .github/workflows/deploy-site.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,8 @@ jobs:
url: ${{ steps.deploy.outputs.page_url }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0 # extract-plugins.py derives each catalog entry's added/updated dates from git log

- name: Get GitHub App token
id: app-token
Expand Down Expand Up @@ -139,6 +141,8 @@ jobs:
echo "Downloading skills-index artifact from run $SKILLS_INDEX_RUN_ID"
if gh run download "$SKILLS_INDEX_RUN_ID" --name skills-index --dir "$tmpdir"; then
candidate="$(find "$tmpdir" -name skills-index.json -type f | head -n 1 || true)"
stars="$(find "$tmpdir" -name plugin-stars.json -type f | head -n 1 || true)"
[ -n "$stars" ] && cp "$stars" website/static/api/plugin-stars.json
if [ -n "$candidate" ]; then
cp "$candidate" "$INDEX_PATH"
if validate_index; then
Expand All @@ -164,6 +168,13 @@ jobs:
- name: Extract skill metadata for dashboard
run: python3 website/scripts/extract-skills.py

# Star counts drive the catalog ranking. Same rule as the skills index: GitHub is only
# probed by the scheduled skills-index run; deploys reuse its artifact (downloaded above
# into website/static/api/ when SKILLS_INDEX_RUN_ID is set) or the live site's copy.
# Never calls the GitHub API.
- name: Reuse plugin GitHub stars (no API calls)
run: python3 website/scripts/fetch-plugin-stars.py

- name: Extract plugin catalog for the Plugins page
run: python3 website/scripts/extract-plugins.py

Expand Down
65 changes: 46 additions & 19 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -74,19 +74,21 @@ jobs:
strategy:
fail-fast: false
matrix:
# Two images per arch. `slim` is what :latest has always been; `desktop`
# adds the Bot Screen packages and a headed Chromium (+1.4 GB) for the
# tier that offers a screen. Both are built on a PR so a change that only
# breaks the gated layers cannot reach publish.
arch: [amd64, arm64]
variant: [slim, desktop]
include:
- arch: amd64
runner: ubuntu-latest-32-core
platform: linux/amd64
cache-from: type=gha,scope=docker-amd64
cache-to: type=gha,mode=max,scope=docker-amd64
# arm64 builds on the native arm64 larger runner. A build of
# linux/arm64 on an x64 host uses emulation.
- arch: arm64
runner: ubuntu-latest-32-arm-core
platform: linux/arm64
cache-from: type=gha,scope=docker-arm64
cache-to: type=gha,mode=max,scope=docker-arm64

runs-on: ${{ matrix.runner }}
timeout-minutes: 45
Expand Down Expand Up @@ -124,8 +126,11 @@ jobs:
tags: ${{ env.IMAGE_NAME }}:test
build-args: |
HERMES_GIT_SHA=${{ github.sha }}
cache-from: ${{ matrix.cache-from }}
cache-to: ${{ (github.event_name != 'pull_request') && matrix.cache-to || '' }}
HERMES_BOT_DESKTOP=${{ matrix.variant == 'desktop' && '1' || '0' }}
# Slim owns the scope; desktop is slim plus two RUN steps, so it reads
# and writes nothing — a 5.5 GB mode=max scope would blow the 10 GB cap.
cache-from: type=gha,scope=docker-${{ matrix.arch }}
cache-to: ${{ (github.event_name != 'pull_request' && matrix.variant == 'slim') && format('type=gha,mode=max,scope=docker-{0}', matrix.arch) || '' }}


# Run the docker-integration test suite against the freshly-built
Expand Down Expand Up @@ -191,18 +196,16 @@ jobs:
strategy:
fail-fast: false
matrix:
arch: [amd64, arm64]
variant: [slim, desktop]
include:
- arch: amd64
runner: ubuntu-latest-32-core
platform: linux/amd64
cache-from: type=gha,scope=docker-amd64
cache-to: type=gha,mode=max,scope=docker-amd64
# Native arm64 for the same reason as the build matrix above.
- arch: arm64
runner: ubuntu-latest-32-arm-core
platform: linux/arm64
cache-from: type=gha,scope=docker-arm64
cache-to: type=gha,mode=max,scope=docker-arm64
runs-on: ${{ matrix.runner }}
timeout-minutes: 30
steps:
Expand Down Expand Up @@ -242,9 +245,10 @@ jobs:
org.opencontainers.image.revision=${{ github.sha }}
build-args: |
HERMES_GIT_SHA=${{ github.sha }}
HERMES_BOT_DESKTOP=${{ matrix.variant == 'desktop' && '1' || '0' }}
outputs: type=image,name=${{ env.IMAGE_NAME }},push-by-digest=true,name-canonical=true,push=true
cache-from: ${{ matrix.cache-from }}
cache-to: ${{ matrix.cache-to }}
cache-from: type=gha,scope=docker-${{ matrix.arch }}
cache-to: ${{ matrix.variant == 'slim' && format('type=gha,mode=max,scope=docker-{0}', matrix.arch) || '' }}

- name: Export digest
run: |
Expand All @@ -255,7 +259,7 @@ jobs:
- name: Upload digest artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: digest-${{ matrix.arch }}
name: digest-${{ matrix.variant }}-${{ matrix.arch }}
path: /tmp/digests/*
if-no-files-found: error
retention-days: 1
Expand All @@ -269,17 +273,30 @@ jobs:
# On releases: tags :<release_tag_name>.
# ---------------------------------------------------------------------------
merge:
if: github.repository == 'NousResearch/hermes-agent' && (github.event_name == 'push' && github.ref == 'refs/heads/main' || github.event_name == 'release')
# `needs` is the whole 4-leg matrix and a failed need skips the job, so a
# transient desktop push would take slim's :latest with it. Guard below.
if: ${{ !cancelled() && github.repository == 'NousResearch/hermes-agent' && (github.event_name == 'push' && github.ref == 'refs/heads/main' || github.event_name == 'release') }}
runs-on: ubuntu-latest
needs: [publish]
timeout-minutes: 10
environment: container-publish
strategy:
fail-fast: false
matrix:
# One manifest list per variant. `slim` keeps the unsuffixed tags it has
# always had, so nothing that pulls :latest today changes; `desktop`
# publishes the same digests under a -desktop suffix.
include:
- variant: slim
suffix: ""
- variant: desktop
suffix: "-desktop"
steps:
- name: Download digests
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
path: /tmp/digests
pattern: digest-*
pattern: digest-${{ matrix.variant }}-*
merge-multiple: true

# Retry once on transient Docker Hub / buildkit pull failures.
Expand All @@ -304,16 +321,25 @@ jobs:
env:
IMAGE_NAME: ${{ env.IMAGE_NAME }}
RELEASE_TAG: ${{ github.event.release.tag_name }}
SUFFIX: ${{ matrix.suffix }}
run: |
set -euo pipefail
# Without nullglob an empty dir yields the literal `*`: one bogus entry.
shopt -s nullglob
args=()
for digest_file in *; do
args+=("${IMAGE_NAME}@sha256:${digest_file}")
done
# One per arch in the publish matrix; a short set means a leg failed, and
# stitching it would publish a single-arch :latest. Keep in step with it.
if [ "${#args[@]}" -ne 2 ]; then
echo "::error::variant ${{ matrix.variant }}: want 2 digests, found ${#args[@]} (a publish leg failed)"
exit 1
fi
if [ "${{ github.event_name }}" = "release" ]; then
tags=(-t "${IMAGE_NAME}:${RELEASE_TAG}")
tags=(-t "${IMAGE_NAME}:${RELEASE_TAG}${SUFFIX}")
else
tags=(-t "${IMAGE_NAME}:main" -t "${IMAGE_NAME}:latest")
tags=(-t "${IMAGE_NAME}:main${SUFFIX}" -t "${IMAGE_NAME}:latest${SUFFIX}")
fi
# Retry: Docker Hub API + just-pushed digest eventual consistency
# can transiently fail the create; the operation is idempotent.
Expand All @@ -333,9 +359,10 @@ jobs:
env:
IMAGE_NAME: ${{ env.IMAGE_NAME }}
RELEASE_TAG: ${{ github.event.release.tag_name }}
SUFFIX: ${{ matrix.suffix }}
run: |
if [ "${{ github.event_name }}" = "release" ]; then
docker buildx imagetools inspect "${IMAGE_NAME}:${RELEASE_TAG}"
docker buildx imagetools inspect "${IMAGE_NAME}:${RELEASE_TAG}${SUFFIX}"
else
docker buildx imagetools inspect "${IMAGE_NAME}:main"
docker buildx imagetools inspect "${IMAGE_NAME}:main${SUFFIX}"
fi
13 changes: 13 additions & 0 deletions .github/workflows/docs-site-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,19 @@ jobs:
- name: Regenerate per-skill docs pages + catalogs
run: python3 website/scripts/generate-skill-docs.py

- name: Committed skill docs match the generator
# GitHub renders the committed copies, so a regeneration that changes anything
# means the published catalogs/pages are stale. Fix: run the generator and commit.
run: |
git add -N website/docs website/sidebars.ts
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
Comment thread
100yenadmin marked this conversation as resolved.
if ! git diff --exit-code --stat -- website/docs website/sidebars.ts website/i18n; then
echo "::error::website/scripts/generate-skill-docs.py output differs from the committed docs; run it and commit the result"
exit 1
fi

- name: Check cross-page links resolve on GitHub and on the site
run: python3 website/scripts/check_doc_links.py

- name: Lint docs diagrams
run: npm run lint:diagrams
working-directory: website
Expand Down
Loading
Loading