Skip to content
This repository was archived by the owner on Jun 4, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
109 commits
Select commit Hold shift + click to select a range
bde487c
fix(voice): honor PULSE_SERVER/PIPEWIRE_REMOTE inside Docker (#21203)
wesleysimplicio May 9, 2026
30dd554
fix(voice_mode): generalize container phrasing and use $XDG_RUNTIME_DIR
wesleysimplicio May 9, 2026
ec641d4
chore: ignore local Hermes runtime files
slowtokki0409 May 15, 2026
51689a4
feat(cli): add --branch flag to `hermes update`
jquesnelle May 21, 2026
d5b7393
fix(cli): plug silent-divergence holes in --branch flag
jquesnelle May 21, 2026
b96a1a0
fix(docker): include anthropic, bedrock, azure-identity extras in image
ilonagaja509-glitch May 22, 2026
f8695ed
feat(docker): add Windows Docker Desktop compatible compose file
Sunil123135 May 23, 2026
1579a6f
docs: clarify xurl auth HOME in Docker
yu-xin-c May 24, 2026
95cee44
docs: add Docker audio bridge notes
yu-xin-c May 25, 2026
29c71e9
fix(docker): propagate container env through s6 to cont-init and main…
jonpol01 May 26, 2026
8b69ec0
feat(mcp): Nous-approved MCP catalog with interactive picker (#30870)
teknium1 May 26, 2026
ccd3d04
chore(models): swap qwen3.6-plus → qwen3.7-max in openrouter+nous lis…
teknium1 May 26, 2026
5101326
fix(cron): clarify schedule is required for create in tool schema
ygd58 May 26, 2026
556bf7c
test(cron): guard schedule-required description text on CRONJOB_SCHEMA
teknium1 May 26, 2026
f05a473
fix(gateway): refresh cached agent tools on /reload-mcp
teknium1 May 26, 2026
bb4703c
docs(auth): replace stale 'hermes login' references with 'hermes auth…
teknium1 May 26, 2026
43a3f11
fix(agent): recover Codex streams with null output
carltonawong May 27, 2026
2a8d217
chore(release): map carltonawong noreply to GitHub login
teknium1 May 27, 2026
1e267c4
Merge pull request #29025 from slowtokki0409/codex/ignore-local-runti…
benbarclay May 27, 2026
16e86ce
chore(release): map wangpuv contributor email for #32933 (#33005)
teknium1 May 27, 2026
bba5097
fix: parse Codex image generation SSE directly
wangpuv May 27, 2026
840f79e
Merge pull request #31031 from Sunil123135/feat/windows-docker-desktop
benbarclay May 27, 2026
628aaea
Merge pull request #32412 from jonpol01/fix/docker-env-propagation
benbarclay May 27, 2026
7d94eee
Merge pull request #32122 from yu-xin-c/codex/docs-docker-audio-bridg…
benbarclay May 27, 2026
3c7f786
Merge pull request #31557 from yu-xin-c/codex/docs-xurl-docker-home-2…
benbarclay May 27, 2026
2fc77c5
feat(opencode-go): route qwen3.7-max via anthropic_messages
beardthelion May 26, 2026
0a83247
feat: add TUI session orchestrator
ticketclosed-wontfix May 17, 2026
9feadc2
chore(release): map ticketclosed-wontfix noreply to GitHub login
teknium1 May 27, 2026
81a4f28
Merge pull request #22534 from wesleysimplicio/fix/voice-mode-docker-…
benbarclay May 27, 2026
1e5884e
refactor(docker): drop build-essential from apt install (#27507)
benbarclay May 27, 2026
3d9a26a
Merge remote-tracking branch 'origin/main' into jq/hermes-update-bran…
jquesnelle May 27, 2026
9d3e931
Merge pull request #29591 from NousResearch/jq/hermes-update-branch-flag
jquesnelle May 27, 2026
b6ca56f
fix(codex-responses): gracefully recover from invalid_encrypted_conte…
teknium1 May 27, 2026
9eadb68
fix(docker): targeted chown to preserve host file ownership in HERMES…
benbarclay May 27, 2026
22eb4d1
fix(docker): chown ui-tui and node_modules on UID remap so TUI esbuil…
benbarclay May 27, 2026
27a29ee
feat(docker): upgrade Node to 22 LTS via multi-stage from node:22-boo…
benbarclay May 27, 2026
c3bdb2a
ci(docker): add shellcheck shell=sh directive to main-wrapper.sh
benbarclay May 27, 2026
fb298a9
fix(docker): mkdir HERMES_HOME as root in stage2 before chown / privi…
benbarclay May 27, 2026
cb38ce2
refactor(codex): drop SDK responses.stream() helper; consume events d…
teknium1 May 27, 2026
febc4cf
remove Vercel AI Gateway and Vercel Sandbox (#33067)
teknium1 May 27, 2026
25f43d3
feat(api-server): add GET /v1/skills and /v1/toolsets (#33016)
teknium1 May 27, 2026
9769794
feat(nix): add #messaging and #full package variants (#33108)
alt-glitch May 27, 2026
4243b6d
fix(codex): update silent-hang workaround hint
EvilHumphrey May 27, 2026
f0be322
chore(release): map EvilHumphrey noreply for #33034 salvage
teknium1 May 27, 2026
f7527b0
feat: add API server session controls
Codename-11 May 20, 2026
464b51d
Support media in session chat API
Schwartz10 May 22, 2026
9622326
chore(api-server): mark skills_api capability True now that /v1/skill…
teknium1 May 27, 2026
f0fdb5e
feat(catalog): add qwen3.7-max to alibaba + alibaba-coding-plan model…
orcool May 27, 2026
4920f84
test(codex): cover null output stream terminal events
superearn-fisher May 27, 2026
c752205
chore(release): map superearn-fisher noreply for #33122 salvage
teknium1 May 27, 2026
249534e
plugins: add security-guidance — pattern-matched warnings on dangerou…
teknium1 May 27, 2026
f2b479e
test(dashboard): pin current loopback auth behavior as regression har…
benbarclay May 21, 2026
8773bbf
feat(dashboard): add should_require_auth predicate for OAuth gate
benbarclay May 21, 2026
949ad95
feat(dashboard): stash auth_required flag on app.state
benbarclay May 21, 2026
2dc6d03
feat(dashboard-auth): define DashboardAuthProvider ABC + Session data…
benbarclay May 21, 2026
1bbfed7
test(dashboard-auth): cover registry register/get/list/clear semantics
benbarclay May 21, 2026
c32b17f
feat(plugins): add register_dashboard_auth_provider hook on PluginCon…
benbarclay May 21, 2026
865cae4
feat(dashboard-auth): json-lines audit log at $HERMES_HOME/logs/dashb…
benbarclay May 21, 2026
628a52f
test(dashboard-auth): stub auth provider for E2E gate testing
benbarclay May 21, 2026
a30c4d8
feat(dashboard-auth): cookie helpers for session_at/session_rt/pkce
benbarclay May 21, 2026
5b17eab
feat(dashboard-auth): auth gate middleware + /auth/* routes + /login …
benbarclay May 21, 2026
53736b3
feat(dashboard-auth): fail-closed on no providers; proxy_headers when…
benbarclay May 21, 2026
53999b9
docs(dashboard-auth): plan v2 — incorporate Portal OAuth contract (PR…
benbarclay May 21, 2026
848baeb
feat(dashboard-auth): plugins/dashboard_auth/nous — contract-complian…
benbarclay May 21, 2026
b69fce9
feat(dashboard-auth): single-use WS tickets + POST /api/auth/ws-ticket
benbarclay May 21, 2026
b2360ba
feat(dashboard-auth): _ws_auth_ok helper + ticket auth on all 4 WS en…
benbarclay May 21, 2026
8971e94
feat(dashboard-auth): SPA WS auth — getWsTicket() + buildWsAuthParam()
benbarclay May 21, 2026
5e9308b
feat(dashboard-auth): Phase 6 — 401 re-auth envelope + next= propagation
benbarclay May 21, 2026
2fc4615
feat(dashboard-auth): Phase 7 — SPA AuthWidget + /api/status auth fields
benbarclay May 21, 2026
7c9cdbc
docs(dashboard-auth): Phase 7 — OAuth Authentication section in web-d…
benbarclay May 21, 2026
af3d4a6
fix(dashboard-auth): ChatPage cleanup closes WS via wsRef.current
benbarclay May 21, 2026
b3dc539
feat(dashboard-auth): Nous plugin always-on; default portal URL; spec…
benbarclay May 21, 2026
4272977
fix(dashboard): trigger plugin discovery in cmd_dashboard before star…
benbarclay May 23, 2026
a498485
feat(dashboard-auth-nous): surface token iss/aud in verification-fail…
benbarclay May 23, 2026
c598076
test(dashboard-auth): strip HERMES_DASHBOARD_OAUTH_* env vars in herm…
benbarclay May 25, 2026
866cc98
fix(dashboard-auth): use fixed-length sig suffix in stub token framing
benbarclay May 25, 2026
c310419
fix(dashboard-auth): bypass loopback WS peer check in gated mode
benbarclay May 25, 2026
034ad95
fix(dashboard-auth): propagate next= through login page + PKCE cookie
benbarclay May 25, 2026
b26d81d
feat(dashboard-auth): honour X-Forwarded-Prefix + __Host-/__Secure- c…
benbarclay May 25, 2026
e2a92ce
chore: gitignore .hermes/ working directory; drop tracked plan artifact
benbarclay May 25, 2026
61dcc33
feat(dashboard-auth): config.yaml as canonical surface for dashboard.…
benbarclay May 26, 2026
0af37ff
style(dashboard-auth): redesign /login page to match Nous design system
benbarclay May 26, 2026
a890389
feat(dashboard-auth): HERMES_DASHBOARD_PUBLIC_URL / dashboard.public_…
benbarclay May 26, 2026
187cf0f
tools(terminal): nudge homebrewed CI pollers at the tool surface (#33…
teknium1 May 27, 2026
b1a46b3
fix(codex): drop transient rs_tmp reasoning replay state
kpadilha May 13, 2026
c819bc5
chore(release): map kpadilha noreply for #11038 salvage
teknium1 May 27, 2026
9c69204
fix(codex_responses_adapter): drop foreign-issuer reasoning on replay
chaconne67 May 27, 2026
581b021
chore(release): map chaconne67 noreply for #31629 salvage
teknium1 May 27, 2026
8807b1c
fix(gateway): hide telegram compaction status noise
sir-ad May 25, 2026
efa9525
fix: ignore Telegram start pings
rdasilva1016-ui May 23, 2026
60f84c6
gateway: quiet Telegram operational chatter
houenyang-momo May 23, 2026
2f7ba51
refactor(gateway): drop try/except wrappers around resolve_display_se…
teknium1 May 27, 2026
4feb181
chore(release): map sir-ad + rdasilva1016-ui in AUTHOR_MAP
teknium1 May 27, 2026
2bbd534
fix(cli): sync credential_pool on Codex re-auth
konsisumer May 27, 2026
f1422ff
fix(gateway): classify Codex 429 quota as rate-limit, not missing cre…
konsisumer May 27, 2026
0b6ace6
test(verbose): align with telegram tier-1 inbox default
teknium1 May 27, 2026
bb65beb
Merge pull request #30504 from ilonagaja509-glitch/fix/30394-docker-a…
benbarclay May 27, 2026
ea34925
fix(discord): recover Windows voice opus decoding
helix4u May 27, 2026
3e33e14
fix(docker): discover agent-browser Chromium binary at boot
benbarclay May 27, 2026
69dfcdc
fix(auth): codex chat path falls back to credential_pool when singlet…
teknium1 May 27, 2026
0325e18
fix(gateway): keep Telegram heartbeat + interim commentary on; edit h…
teknium1 May 27, 2026
a699de8
fix(xai-oauth): strip service_tier and add safety-net sanitization fo…
Nami4D May 19, 2026
b4eea18
fix(xai-oauth): gate slash-enum strip on model name + add regression …
teknium1 May 26, 2026
825948e
ci(docker): simplify tagging — push both :main and :latest on main push
ethernet8023 May 27, 2026
f0de3cd
fix(agent): roll back switch_model() state when client rebuild fails …
teknium1 May 27, 2026
458a94e
fix(cli): keep destructive slash modal on Linux
LeonSGP43 May 26, 2026
8fc55ba
chore: sync inkbox with upstream main (2026-05-27)
inkbox-on-call-agent May 27, 2026
0f22847
fix(kanban): drop orphan idx_tasks_session_id from SCHEMA_SQL
inkbox-on-call-agent May 27, 2026
f90d8d2
chore: map inkbox-on-call-agent@inkboxmail.com to dimavrem22 in AUTHO…
inkbox-on-call-agent May 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ node_modules
**/node_modules
.venv
**/.venv
.notebooklm-cli-venv/
.notebooklm-playwright/
.pip-cache/
.uv-cache/

# Built artifacts that are regenerated inside the image. Excluded so local
# rebuilds on the developer's machine don't invalidate the npm-install layer
Expand All @@ -25,6 +29,8 @@ ui-tui/packages/hermes-ink/dist/

# Runtime data (bind-mounted at /opt/data; must not leak into build context)
data/
.hermes-docker/
.notebooklm-home/

# Compose/profile runtime state (bind-mounted; avoid ownership/secret issues)
hermes-config/
Expand Down
248 changes: 19 additions & 229 deletions .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,7 @@ permissions:
contents: read

# Concurrency: push/release runs are NEVER cancelled so every merge gets
# its own :main or release-tagged image. :latest is guarded separately
# by the move-latest job. PR runs reuse a PR-scoped group with
# its own image. PR runs reuse a PR-scoped group with
# cancel-in-progress: true so rapid pushes to the same PR collapse to the
# latest commit.
concurrency:
Expand Down Expand Up @@ -140,12 +139,6 @@ jobs:
# Push amd64 by digest only (no tag). The merge job assembles the
# tagged manifest list. `push-by-digest=true` is docker's recommended
# pattern for multi-runner multi-platform builds.
#
# We apply the OCI revision label here (and again on arm64) because
# the move-latest job reads it off the linux/amd64 sub-manifest
# config of the floating tag to decide whether it's safe to advance.
# The label must be on each per-arch image — manifest lists themselves
# don't carry image config labels.
- name: Push amd64 by digest
id: push
if: github.event_name == 'push' && github.ref == 'refs/heads/main' || github.event_name == 'release'
Expand Down Expand Up @@ -258,30 +251,17 @@ jobs:
# ---------------------------------------------------------------------------
# Stitch both per-arch digests into a single tagged multi-arch manifest.
# This is a registry-side operation — no building, no layer re-push —
# so it runs in ~30 seconds. On main pushes it produces :main; on
# releases it produces :<release_tag_name>.
# so it runs in ~30 seconds.
#
# For main pushes the ancestor check runs BEFORE the manifest push so
# we never overwrite :main with an older commit. The top-level
# concurrency group (`docker-${{ github.ref }}` with
# `cancel-in-progress: false`) already serialises runs per ref; the
# ancestor check is defense-in-depth.
# On main pushes: tags both :main and :latest.
# On releases: tags :<release_tag_name>.
# ---------------------------------------------------------------------------
merge:
if: github.repository == 'NousResearch/hermes-agent' && (github.event_name == 'push' && github.ref == 'refs/heads/main' || github.event_name == 'release')
runs-on: ubuntu-latest
needs: [build-amd64, build-arm64]
timeout-minutes: 10
outputs:
pushed_release_tag: ${{ steps.mark_release_pushed.outputs.pushed }}
release_tag: ${{ steps.tag.outputs.tag }}
steps:
- name: Checkout code
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 1000

- name: Download digests
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
Expand All @@ -298,224 +278,34 @@ jobs:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

# Read the git revision label off the current :main manifest, then
# use `git merge-base --is-ancestor` to check whether our commit is
# a descendant of it. If :main doesn't exist yet, or its label is
# missing, we treat that as "safe to publish". If another run
# already advanced :main past us (or diverged), we skip and leave
# it alone.
- name: Decide whether to move :main
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
id: main_check
run: |
set -euo pipefail
image=nousresearch/hermes-agent

image_json=$(
docker buildx imagetools inspect "${image}:main" \
--format '{{ json (index .Image "linux/amd64") }}' \
2>/dev/null || true
)

if [ -z "${image_json}" ]; then
echo "No existing :main (or inspect failed) — safe to publish."
echo "push_main=true" >> "$GITHUB_OUTPUT"
exit 0
fi

current_sha=$(
printf '%s' "${image_json}" \
| jq -r '.config.Labels."org.opencontainers.image.revision" // ""'
)

if [ -z "${current_sha}" ]; then
echo "Registry :main has no revision label — safe to publish."
echo "push_main=true" >> "$GITHUB_OUTPUT"
exit 0
fi

echo "Registry :main is at ${current_sha}"
echo "This run is at ${GITHUB_SHA}"

if [ "${current_sha}" = "${GITHUB_SHA}" ]; then
echo ":main already points at our SHA — nothing to do."
echo "push_main=false" >> "$GITHUB_OUTPUT"
exit 0
fi

if ! git cat-file -e "${current_sha}^{commit}" 2>/dev/null; then
git fetch --no-tags --prune origin \
"+refs/heads/main:refs/remotes/origin/main" \
|| true
fi

if ! git cat-file -e "${current_sha}^{commit}" 2>/dev/null; then
echo "Registry :main points at an unknown commit (${current_sha}); refusing to overwrite."
echo "push_main=false" >> "$GITHUB_OUTPUT"
exit 0
fi

if git merge-base --is-ancestor "${current_sha}" "${GITHUB_SHA}"; then
echo "Our commit is a descendant of :main — safe to advance."
echo "push_main=true" >> "$GITHUB_OUTPUT"
else
echo "Another run advanced :main past us (or diverged) — leaving it alone."
echo "push_main=false" >> "$GITHUB_OUTPUT"
fi

# Compute the tag for this run. Main pushes tag directly as :main
# (no per-commit SHA tags); releases use the release tag name.
- name: Compute tag
id: tag
run: |
if [ "${{ github.event_name }}" = "release" ]; then
echo "tag=${{ github.event.release.tag_name }}" >> "$GITHUB_OUTPUT"
else
echo "tag=main" >> "$GITHUB_OUTPUT"
fi

# Gate the manifest push on the ancestor check for main pushes.
# For releases there is no gate — the check doesn't even run.
- name: Create manifest list and push
if: github.event_name != 'push' || steps.main_check.outputs.push_main == 'true'
working-directory: /tmp/digests
run: |
set -euo pipefail
args=()
for digest_file in *; do
args+=("${IMAGE_NAME}@sha256:${digest_file}")
done
docker buildx imagetools create \
-t "${IMAGE_NAME}:${TAG}" \
"${args[@]}"
if [ "${{ github.event_name }}" = "release" ]; then
TAG="${{ github.event.release.tag_name }}"
docker buildx imagetools create \
-t "${IMAGE_NAME}:${TAG}" \
"${args[@]}"
else
docker buildx imagetools create \
-t "${IMAGE_NAME}:main" \
-t "${IMAGE_NAME}:latest" \
"${args[@]}"
fi
env:
IMAGE_NAME: ${{ env.IMAGE_NAME }}
TAG: ${{ steps.tag.outputs.tag }}

- name: Inspect image
if: github.event_name != 'push' || steps.main_check.outputs.push_main == 'true'
run: |
docker buildx imagetools inspect "${IMAGE_NAME}:${TAG}"
env:
IMAGE_NAME: ${{ env.IMAGE_NAME }}
TAG: ${{ steps.tag.outputs.tag }}

# Signal to move-latest that the release tag is live.
- name: Mark release tag pushed
id: mark_release_pushed
if: github.event_name == 'release'
run: echo "pushed=true" >> "$GITHUB_OUTPUT"

# ---------------------------------------------------------------------------
# Move :latest to point at the release tag the merge job pushed.
#
# :latest is the floating tag that tracks the most recent stable release.
# Only `release: published` events advance it — never main pushes.
#
# We still run an ancestor check against the existing :latest so that a
# backport release on an older branch (e.g. patching v1.1.5 after v1.2.3
# is out) doesn't drag :latest backwards. The check is the same shape
# as the ancestor check in the merge job for :main: read the OCI
# revision label off the current :latest, look up that commit in git,
# and only advance if our release commit is a strict descendant.
# ---------------------------------------------------------------------------
move-latest:
if: |
github.repository == 'NousResearch/hermes-agent'
&& github.event_name == 'release'
&& needs.merge.outputs.pushed_release_tag == 'true'
needs: merge
runs-on: ubuntu-latest
timeout-minutes: 10
concurrency:
group: docker-move-latest
cancel-in-progress: false
steps:
- name: Checkout code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 1000

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3

- name: Log in to Docker Hub
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

- name: Decide whether to move :latest
id: latest_check
run: |
set -euo pipefail
image=nousresearch/hermes-agent

image_json=$(
docker buildx imagetools inspect "${image}:latest" \
--format '{{ json (index .Image "linux/amd64") }}' \
2>/dev/null || true
)

if [ -z "${image_json}" ]; then
echo "No existing :latest (or inspect failed) — safe to publish."
echo "push_latest=true" >> "$GITHUB_OUTPUT"
exit 0
fi

current_sha=$(
printf '%s' "${image_json}" \
| jq -r '.config.Labels."org.opencontainers.image.revision" // ""'
)

if [ -z "${current_sha}" ]; then
echo "Registry :latest has no revision label — safe to publish."
echo "push_latest=true" >> "$GITHUB_OUTPUT"
exit 0
fi

echo "Registry :latest is at ${current_sha}"
echo "This release is at ${GITHUB_SHA}"

if [ "${current_sha}" = "${GITHUB_SHA}" ]; then
echo ":latest already points at our SHA — nothing to do."
echo "push_latest=false" >> "$GITHUB_OUTPUT"
exit 0
fi

# Make sure we have the :latest commit locally for merge-base.
# Releases can be cut from any branch, so fetch broadly.
if ! git cat-file -e "${current_sha}^{commit}" 2>/dev/null; then
git fetch --no-tags --prune origin \
"+refs/heads/main:refs/remotes/origin/main" \
|| true
fi

if ! git cat-file -e "${current_sha}^{commit}" 2>/dev/null; then
echo "Registry :latest points at an unknown commit (${current_sha}); refusing to overwrite."
echo "push_latest=false" >> "$GITHUB_OUTPUT"
exit 0
fi

# Our release SHA must be a descendant of the current :latest.
# Backport releases on older branches won't satisfy this and will
# be left alone — :latest stays on the newer release.
if git merge-base --is-ancestor "${current_sha}" "${GITHUB_SHA}"; then
echo "Our release commit is a descendant of :latest — safe to advance."
echo "push_latest=true" >> "$GITHUB_OUTPUT"
if [ "${{ github.event_name }}" = "release" ]; then
docker buildx imagetools inspect "${IMAGE_NAME}:${{ github.event.release.tag_name }}"
else
echo "Existing :latest is newer than this release (likely a backport) — leaving it alone."
echo "push_latest=false" >> "$GITHUB_OUTPUT"
docker buildx imagetools inspect "${IMAGE_NAME}:main"
fi

# Retag the already-pushed release manifest as :latest.
- name: Move :latest to this release tag
if: steps.latest_check.outputs.push_latest == 'true'
env:
RELEASE_TAG: ${{ needs.merge.outputs.release_tag }}
run: |
set -euo pipefail
image=nousresearch/hermes-agent
docker buildx imagetools create \
--tag "${image}:latest" \
"${image}:${RELEASE_TAG}"
IMAGE_NAME: ${{ env.IMAGE_NAME }}
13 changes: 12 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,13 @@ __pycache__/
.env.production.local
.env.development
.env.test
.hermes-docker/
.notebooklm-home/
.notebooklm-cli-venv/
.notebooklm-playwright/
.pip-cache/
.uv-cache/
compose.hermes.local.yml
export*
__pycache__/model_tools.cpython-310.pyc
__pycache__/web_tools.cpython-310.pyc
Expand Down Expand Up @@ -74,4 +81,8 @@ website/static/api/skills-index.json
models-dev-upstream/
hermes_cli/tui_dist/*
hermes_cli/scripts/
docs/superpowers/*
docs/superpowers/*
# Working directory for the Hermes Agent's session state (~/.hermes/ at runtime;
# also created in-repo when an agent operates in this checkout). Plans, audit
# logs, and per-session caches are never artifacts of the codebase.
.hermes/
Loading
Loading