Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
723 commits
Select commit Hold shift + click to select a range
291d89b
fix(egress): classify source diff presentations
mrkillbob Sep 5, 2026
ce1806f
chore(update): reconcile local upgrades with NousResearch main
Sep 5, 2026
48f751d
fix(egress): preserve source provenance after upstream merge
Sep 5, 2026
48d0735
fix(kanban): preserve worker reasoning flag compatibility
Sep 5, 2026
3b9944b
fix(desktop): restore kanban dispatcher readiness
mrkillbob Sep 5, 2026
8b98b3d
fix(kanban): restore worker lifecycle guardrails
mrkillbob Sep 5, 2026
7417d7c
fix(egress): mask numbered source receipt statistics
mrkillbob Sep 5, 2026
fd70651
fix(update): ignore superseded restart receipts
mrkillbob Sep 5, 2026
140949c
fix(cli): restore startup config guard wiring
mrkillbob Sep 5, 2026
dcd23ca
fix(cli): restore fast-chat backend import
mrkillbob Sep 5, 2026
d05f61a
fix(skills): repair preloaded skill resolution
mrkillbob Sep 5, 2026
7b2ebc8
fix: restore worker environments and protected CI handoffs
mrkillbob Sep 5, 2026
ede329c
test: run systemd process probes on Linux
mrkillbob Sep 5, 2026
abde996
fix: preserve authorization identifiers during credential redaction
mrkillbob Sep 5, 2026
05d7cce
fix: handle Unicode source lines in Base64 classification
mrkillbob Sep 5, 2026
a3dfa3a
fix: retain parent worktree leases for dependent review tasks
mrkillbob Sep 5, 2026
e75a0ce
fix: preserve dirty worktree pool slots and use overflow
mrkillbob Sep 5, 2026
3275941
fix: keep Codex review requests out of repair intake
mrkillbob Sep 5, 2026
f4d0682
fix: distinguish source type annotations from credential values
mrkillbob Sep 5, 2026
f87f677
fix: restore board attribution and worker reclamation wiring
mrkillbob Sep 5, 2026
0d33d14
fix: restore local worker routing and fallback confinement
mrkillbob Sep 5, 2026
2323616
fix: restore federation capacity, child context and worktree bootstrap
mrkillbob Sep 5, 2026
bdc7d1d
fix: preserve owned-run recovery and unacknowledged receipts
mrkillbob Sep 5, 2026
aeede9c
fix: honor runtime priority and fail closed on missing dispatch config
mrkillbob Sep 5, 2026
82233b9
fix: retain triage intent and lease notifications until delivery
mrkillbob Sep 5, 2026
9c8df7b
fix: reconnect worker supervision and review lifecycle controls
mrkillbob Sep 5, 2026
787e484
fix: preserve worker ownership across scheduling and recovery
mrkillbob Sep 5, 2026
76e16cd
fix: wire cooperative gateway drain and truthful budget notifications
mrkillbob Sep 5, 2026
bee7709
fix: connect worker drain and lease fencing to real runtime gates
mrkillbob Sep 5, 2026
8c51c9e
chore: preserve existing feedback WIP as isolated repair baseline
mrkillbob Sep 5, 2026
e6e693b
fix: serialize repair scans and bind conflicts to live base refs
mrkillbob Sep 5, 2026
83edd61
feat: admit native Hermes local CI through governed receipt contracts
mrkillbob Sep 5, 2026
98c9f8f
fix: retain native CI evidence when platform coverage is incomplete
mrkillbob Sep 5, 2026
a3c4a66
fix feedback conflict scheduling during required CI backlog
mrkillbob Sep 5, 2026
fede160
fix federation CLI registration and exercise real audit entrypoint
mrkillbob Sep 5, 2026
a4752a7
select governed worktree environments by checkout Python pin
mrkillbob Sep 5, 2026
d4f674d
add bounded recurring departmental discovery through Kanban
mrkillbob Sep 5, 2026
07e039d
bind discovery to the carried federation and Lunar City source
mrkillbob Sep 5, 2026
1d24d18
honor npm workspace locks and release inactive conflict slots
mrkillbob Sep 5, 2026
c2cf9c7
isolate plugin tests from inherited live Kanban worker identity
mrkillbob Sep 5, 2026
41665dc
fix: defer workspace contention and reconcile recovered roster sources
mrkillbob Sep 5, 2026
7327e88
fix(ci): retain private hash-bound process output for diagnosis
mrkillbob Sep 5, 2026
82f4c6d
fix: prefer prepared CI environments and route Revenue evidence disco…
mrkillbob Sep 5, 2026
3c3f181
refactor(kanban): extract project ownership resolution
mrkillbob Sep 5, 2026
40b0ae8
fix(kanban): preserve parent project identity across worker profiles
mrkillbob Sep 5, 2026
f74d789
fix(federation): count active descendants in discovery capacity
mrkillbob Sep 5, 2026
5ad2a43
Validate full CI environments and retry exact failed repair receipts
mrkillbob Sep 5, 2026
6a241a1
Expose Codex connector authorization failures without repeat requests
mrkillbob Sep 5, 2026
5d6bdde
Generate bounded provenance-bound Vault role navigation
mrkillbob Sep 5, 2026
24bdfac
Fetch immutable repair base objects after branch movement
mrkillbob Sep 5, 2026
d87e63e
Normalize repair regression file ending
mrkillbob Sep 5, 2026
fc97177
Bind carried project worktrees to explicit shared source refs
mrkillbob Sep 5, 2026
c909f92
Preserve complete goal contracts and distinguish egress deferrals
mrkillbob Sep 5, 2026
43e3b92
fix(kanban): require pending dependencies before automatic retry
mrkillbob Sep 5, 2026
70085f9
feat(pr-feedback): dispatch a single exact-head conflict repair
mrkillbob Sep 5, 2026
004c4c0
fix(pr-feedback): identify pending cards on duplicate dispatch
mrkillbob Sep 5, 2026
c16d4fb
fix(ci): remove obsolete reusable OSV job and retain pinned scan
mrkillbob Sep 5, 2026
a124270
fix required local CI handoff without Actions admin access
mrkillbob Sep 5, 2026
365097c
validate worker task assignees and preserve requested failure limits
mrkillbob Sep 5, 2026
08e4de5
bind audit worker completion to its exact local CI dispatch
mrkillbob Sep 5, 2026
575c5d6
preserve audit result transport and let dispatcher own worker shutdown
mrkillbob Sep 5, 2026
e10283e
keep exact conflict dispatch from creating independent escalation cards
mrkillbob Sep 5, 2026
12ff7ee
defer same-PR CI behind repairs and suppress governed completion feed…
mrkillbob Sep 5, 2026
4802fd7
defer queued audit execution until same-PR repair handoff completes
mrkillbob Sep 5, 2026
427443c
require passed control-ledger evidence for model CI completion
mrkillbob Sep 5, 2026
40d1f42
keep completion guard compatible with CLI-only hosts
mrkillbob Sep 6, 2026
5c0095f
fix: enforce CI receipts at kanban completion
mrkillbob Sep 6, 2026
56718a9
fix(ci): inherit benchmark-qualified worker profile routes
mrkillbob Sep 6, 2026
24bab85
fix(ci): retire inactive superseded conflict dispatches
mrkillbob Sep 6, 2026
a1820b8
clarify observed base versus immutable repair target
mrkillbob Sep 6, 2026
3220539
fix(pr): schedule older prerequisites and rotate repair coverage
mrkillbob Sep 6, 2026
12bc575
fix(pr): bind repair pushes to canonical head repository
mrkillbob Sep 6, 2026
0e24079
fix(ci): preserve handoff causes and expose durable receipts
mrkillbob Sep 6, 2026
f753397
test(ci): align audit policy fixture with current handoff
mrkillbob Sep 6, 2026
8eebd9d
fix(ci): defer mergeability lag without publishing failed evidence
mrkillbob Sep 6, 2026
1f8704b
feat(labels): reconcile all configured PR type and area labels
mrkillbob Sep 6, 2026
23065f8
fix(labels): preserve existing definitions and cache label setup
mrkillbob Sep 6, 2026
41609ab
feat(labels): allow bounded full repository taxonomy rules
mrkillbob Sep 6, 2026
fb61c20
fix(labels): report the exact PR and cause when reconciliation stops
mrkillbob Sep 6, 2026
5b0d14d
fix(labels): verify repository labeling permission before writes
mrkillbob Sep 6, 2026
f36fb0b
fix(labels): isolate incomplete file listings to their own PR
mrkillbob Sep 6, 2026
307895c
fix(feedback): expose PR state and retire closed feedback tasks
mrkillbob Sep 6, 2026
6d5e6de
fix(feedback): durably retire closed PR dispatches
mrkillbob Sep 6, 2026
a39acc6
fix(kanban): count failed retries since the last actual edit
mrkillbob Sep 6, 2026
ab8d77a
fix(feedback): recover CI after acknowledged duplicate dispatches
mrkillbob Sep 6, 2026
a6985db
fix(kanban): enforce durable repair completion contracts
mrkillbob Sep 6, 2026
c0144d3
fix: report completion policy failures correctly
mrkillbob Sep 6, 2026
ec84a63
fix(kanban): enforce feedback contract before review handoff
mrkillbob Sep 6, 2026
6eb3de7
fix(feedback): verify worker completion policy discovery
mrkillbob Sep 6, 2026
d756732
fix(plugins): preserve raw profile settings on enablement
mrkillbob Sep 6, 2026
a6024cd
fix(compression): retain current Kanban assignment contract
mrkillbob Sep 6, 2026
0cd2f2d
fix(kanban): enforce feedback policy for workers
mrkillbob Sep 6, 2026
43d447a
fix(kanban): redact review summaries before policy hooks
mrkillbob Sep 6, 2026
fb4e3ef
fix(feedback): validate resolved worker hooks
mrkillbob Sep 6, 2026
1bb87fd
fix(plugins): preserve config during capability mutations
mrkillbob Sep 6, 2026
51ece50
fix(compression): retain implicit Kanban assignment
mrkillbob Sep 6, 2026
efedabc
fix(feedback): avoid worker plugin imports in doctor
mrkillbob Sep 6, 2026
12c67b4
fix(config): retain fallback after raw writes
mrkillbob Sep 6, 2026
11702d8
Merge commit '0cd2f2d79d6e5d994e44d83402a963226d8c8115' into hermes/g…
mrkillbob Sep 6, 2026
958ec73
fix(feedback): resolve worker project plugin overrides
mrkillbob Sep 6, 2026
08bbaea
fix(compression): demote noncurrent kanban projections
mrkillbob Sep 6, 2026
f4c3c75
fix(feedback): bind ledger before dispatch
mrkillbob Sep 6, 2026
e48d37c
fix: preserve dashboard review policy reasons
mrkillbob Sep 6, 2026
87e6008
fix(plugins): reject managed toggle mutations safely
mrkillbob Sep 6, 2026
e49da8c
fix(config): preserve plugin list environment templates
mrkillbob Sep 6, 2026
8b29109
fix(feedback): reject worker plugin entrypoint overrides
mrkillbob Sep 6, 2026
aa30d67
fix(compression): preserve current kanban tail projection
mrkillbob Sep 6, 2026
bed3b2c
fix: preserve invalid shell completion decisions
mrkillbob Sep 6, 2026
3f90ac6
fix(feedback): reject portable hook manifests
mrkillbob Sep 6, 2026
daca8a6
fix(compression): retain assignment in handoff
mrkillbob Sep 6, 2026
1befd38
fix(kanban): keep rejected statuses as bad requests
mrkillbob Sep 6, 2026
a33fe32
fix(feedback): accept categorized worker plugin keys
mrkillbob Sep 6, 2026
76c6a20
fix(compression): honor empty task id default
mrkillbob Sep 6, 2026
444e77b
fix(plugins): persist consent atomically
mrkillbob Sep 6, 2026
b433788
fix(feedback): reject untrusted worker hook manifests
mrkillbob Sep 6, 2026
2e0e724
fix: gate project plugin worker discovery
mrkillbob Sep 6, 2026
374d9a4
fix(compression): retain assignment during pressure demotion
mrkillbob Sep 6, 2026
2289a9e
test: exercise real managed plugin toggle
mrkillbob Sep 6, 2026
68b5539
fix: keep optional feedback policy out of core
mrkillbob Sep 7, 2026
d7fb2c5
fix(feedback): expand worker plugin config
mrkillbob Sep 7, 2026
783b5ea
fix(config): preserve templates in modified list entries
mrkillbob Sep 7, 2026
8d1ae4d
fix: fail closed on completion shell hook failures
mrkillbob Sep 7, 2026
191c7bc
fix(compression): bound stale assignment projection
mrkillbob Sep 7, 2026
b06cd9f
fix(plugins): preflight plugin list writes atomically
mrkillbob Sep 7, 2026
6d755f4
fix(compression): re-pin assignment from prior handoff
mrkillbob Sep 7, 2026
9193f0f
fix(feedback): honor expanded worker plugin config
mrkillbob Sep 7, 2026
b702e4a
fix(feedback): honor dispatch opt-in when promoting cards
mrkillbob Sep 7, 2026
064cbce
fix(feedback): bind local CI cards before promotion
mrkillbob Sep 7, 2026
1f2ecab
fix-github-feedback-completion-policy-registration
mrkillbob Sep 7, 2026
58be8c6
fix-redact-kanban-completion-policy-summary
mrkillbob Sep 7, 2026
8e0e5a7
fix(profiles): persist config sections atomically
mrkillbob Sep 7, 2026
2b53315
fix(feedback): ignore malformed worker override manifests
mrkillbob Sep 7, 2026
272cb6c
fix(feedback): detect categorized project overrides
mrkillbob Sep 7, 2026
c6db7f6
fix(compression): retain assignments from later handoffs
mrkillbob Sep 7, 2026
9b9efb6
fix(feedback): match entrypoint override to selected key
mrkillbob Sep 7, 2026
7a7a38f
fix(feedback): recover blocked auto-dispatch repairs
mrkillbob Sep 7, 2026
c4a95d0
fix(compression): redact kanban assignment handoffs
mrkillbob Sep 7, 2026
a8ca3d2
test: cover redacted completion policy summary
mrkillbob Sep 7, 2026
2ee03ae
fix: reconcile Hermes Kanban and PR feedback lifecycle (#56)
mrkillbob Sep 7, 2026
49af5d4
Restore conversation worktree ownership across CLI gateway and TUI (#30)
mrkillbob Sep 7, 2026
9852801
Merge feedback completion contract into review contract
mrkillbob Sep 8, 2026
ebe2ae5
fix: repair PR45 CI portability gates
mrkillbob Sep 8, 2026
52d6814
fix: reuse cross-platform CI gate repairs
mrkillbob Sep 8, 2026
d0d1932
fix: clear extracted-stack portability findings
mrkillbob Sep 8, 2026
fac2462
fix: clear PR45 audit and CI contract failures
mrkillbob Sep 8, 2026
853f1fe
fix(kanban): preserve review policy contracts
mrkillbob Sep 8, 2026
9bd0efb
Merge pull request #47 from mrkillbob/codex/hermes-worker-contract-di…
mrkillbob Sep 9, 2026
9bea7d8
Merge pull request #48 from mrkillbob/codex/hermes-plugin-config-pres…
mrkillbob Sep 9, 2026
8d03e84
Merge pull request #49 from mrkillbob/codex/hermes-preserve-task-assi…
mrkillbob Sep 9, 2026
d7aec84
fix: address 6 P1 findings from merged PR review threads
mrkillbob Sep 9, 2026
6e9f33a
Merge remote-tracking branch 'origin/main' into fix/p1-review-finding…
mrkillbob Sep 9, 2026
69f3225
fix: address remaining P1 findings (dispatch generation, completion g…
mrkillbob Sep 9, 2026
4ecd1f0
Merge remote-tracking branch 'fork/main' into rebase-pr76
mrkillbob Sep 9, 2026
3245bbd
fix(worktree-gc): remove dead duplicate loop, fix continue-outside-lo…
mrkillbob Sep 9, 2026
11bd670
fix: restore rebased worktree and egress seams
mrkillbob Sep 9, 2026
50e8bc1
fix(worktree-gc): classify manager-owned conversation worktrees as ke…
mrkillbob Sep 9, 2026
781f487
fix(error-classifier): restore egress_policy_blocked and unsupported_…
mrkillbob Sep 9, 2026
4235107
fix(packaging): restore version and exclude-newer-package exemptions …
mrkillbob Sep 9, 2026
1677972
fix(prompt): remove hardcoded personal machine path from shared kanba…
mrkillbob Sep 9, 2026
8777662
wip: session-store conversation-worktree wiring + get_conversation_ro…
mrkillbob Sep 9, 2026
5e6ef16
Merge commit '49af5d4791' into rebase-pr76
mrkillbob Sep 9, 2026
cfb1417
fix(state): remove duplicate ConversationWorktree classes/methods, fi…
mrkillbob Sep 9, 2026
6c913f4
fix(discord): wire specialist routing and progress-query gates into i…
mrkillbob Sep 9, 2026
bffb9fa
fix(discord): load voice auto-join settings during adapter initializa…
mrkillbob Sep 9, 2026
73e209e
fix(providers): invoke sanitize_request_kwargs after request override…
mrkillbob Sep 9, 2026
6afdba3
Revert "fix(prompt): remove hardcoded personal machine path from shar…
mrkillbob Sep 9, 2026
d5ea9e9
fix(source-provenance): activate trusted-read tracking during real to…
mrkillbob Sep 9, 2026
20f2ba3
fix(terminal): preserve explicit in-container workdir for container b…
mrkillbob Sep 9, 2026
3f72c51
fix(egress): resolve receipt state dir under the active profile
mrkillbob Sep 9, 2026
6338cbf
fix(lint): add encoding=utf-8 to bare Path.read_text()/write_text() c…
mrkillbob Sep 9, 2026
f480c1c
fix(lint): add missing braces for eslint curly rule in bot-row.tsx
mrkillbob Sep 9, 2026
dbe0cec
fix(docker): complete isolate_host_data wiring in DockerEnvironment
mrkillbob Sep 9, 2026
8eb8a9a
fix(paths): restore _resolve_path rename, kanban-workspace priority, …
mrkillbob Sep 9, 2026
ea0ca3e
fix: restore missing upgrade implementations
mrkillbob Sep 8, 2026
c54aedb
fix(code-execution): restore _tool_call_limit_reached and _configured…
mrkillbob Sep 9, 2026
c90d064
fix(subagent-lifecycle): validate workforce contracts and preserve go…
mrkillbob Sep 9, 2026
ea1582c
fix(providers): guard sanitize_request_kwargs call against test-doubl…
mrkillbob Sep 9, 2026
1511d26
fix(test): create profile directories the assignee-existence check re…
mrkillbob Sep 9, 2026
c179836
fix(agent): wire tool-guardrail halt into kanban run finalization
mrkillbob Sep 9, 2026
7946e25
fix: three more dead/broken code paths from PR70 review triage
mrkillbob Sep 9, 2026
c62b522
fix(gateway): honor negation before deterministic burndown-patch routing
mrkillbob Sep 9, 2026
b7192e6
fix(worktree-env): recognize native Windows virtualenv interpreter la…
mrkillbob Sep 9, 2026
8173fbe
fix: five more pre-existing failures from CI slice triage
mrkillbob Sep 9, 2026
bbf36f6
fix(reasoning): recognize local Ollama by its default port, not just …
mrkillbob Sep 9, 2026
d55a36a
fix(security): restore kanban worker GitHub Actions/PR-creation guard…
mrkillbob Sep 9, 2026
fae82ce
fix(auxiliary): wire mandatory-reasoning gate into summary path; fix …
mrkillbob Sep 9, 2026
f846a80
fix(context-refs): wire source-provenance grant issuance into @file: …
mrkillbob Sep 9, 2026
e4beed3
feat(prompt): implement guarded local prompt mode and remote-kanban p…
mrkillbob Sep 9, 2026
5fc3f73
fix: propagate docker isolate_host_data config, missing agent.reasoni…
mrkillbob Sep 9, 2026
24b3bf3
fix: wire gateway stop --all --drain, restore ImportError partial-upd…
mrkillbob Sep 9, 2026
ee39240
fix(deps): clear npm audit --audit-level=high (electron-builder, js-y…
mrkillbob Sep 9, 2026
bc5bdc2
fix(ci): honor upload-sarif input on OSV scanner PR runs
mrkillbob Sep 9, 2026
81b7036
fix: revert get_conversation_root branch-stopping (wrong function), s…
mrkillbob Sep 9, 2026
485f550
fix: record credential preflight failures for kanban supervisor, stop…
mrkillbob Sep 9, 2026
fa7fe38
fix(security): Tier-1 secret strip list unenforced on terminal spawn …
mrkillbob Sep 9, 2026
5873aa7
feat(skills): support shared ~/.agents/skills dir and .codex/.claude …
mrkillbob Sep 10, 2026
e6d7154
fix(guardrails): key same-tool-failure accumulation on failure cause,…
mrkillbob Sep 10, 2026
7dbc0d9
fix(agent): resolve the kanban PR-intake hermes command per-worker, n…
mrkillbob Sep 10, 2026
20e1ff1
fix(agent): honor the same protected-remote predicate for auxiliary e…
mrkillbob Sep 10, 2026
b5e5420
fix(agent): route the max-iterations summary request through the egre…
mrkillbob Sep 10, 2026
c647562
fix(cli): stop worktree base resolution from trusting an unrelated fe…
mrkillbob Sep 10, 2026
9821ebd
fix(ci): restore the automatic triggers these workflows document but …
mrkillbob Sep 10, 2026
b53e5d5
fix(tools): accept negative max_tool_calls, drop stale kernel_mode do…
mrkillbob Sep 10, 2026
adbe1b5
fix(providers): register ollama-launch as a custom-profile alias, gat…
mrkillbob Sep 10, 2026
32c2043
fix(config): route raw profile config.yaml reads through the canonica…
mrkillbob Sep 10, 2026
e737a3a
fix(tests): stop reading pyproject.toml's removed static py-modules list
mrkillbob Sep 10, 2026
96bad30
fix(gateway): release the old session's worktree root lease on compre…
mrkillbob Sep 10, 2026
722b956
fix(config): reserve exact list-item matches before any structural/po…
mrkillbob Sep 10, 2026
0a114ff
fix(tools): name the stray command_class argument in terminal's schem…
mrkillbob Sep 10, 2026
e494962
fix(tools): make transcription's force-CPU check overridable from the…
mrkillbob Sep 10, 2026
f5fb89b
fix(tests): pin WAL mode for the progress-snapshot WAL-sidecar test
mrkillbob Sep 10, 2026
9b18cc1
fix(cli): key the update-check cache on the local checkout's HEAD, no…
mrkillbob Sep 10, 2026
95886fd
fix(cli): recognize a Desktop-embedded ticker's heartbeat in cron sta…
mrkillbob Sep 10, 2026
07e06fd
fix(tests): pin update-check cache-key resolution in the passive opt-…
mrkillbob Sep 10, 2026
353a95d
fix(cli): never auto-install a gateway service for a non-default-home…
mrkillbob Sep 10, 2026
7460da0
fix(tests): route codex_ttfb_watchdog fixtures through the egress fir…
mrkillbob Sep 10, 2026
805e7bd
fix(tests): set request identity for openai-codex client-lifecycle tests
mrkillbob Sep 10, 2026
d4f9300
fix(tests): add provider/base_url to the bare-__new__ AIAgent fixture
mrkillbob Sep 10, 2026
9f0c360
fix(gateway): release the displaced session's worktree root lease on …
mrkillbob Sep 10, 2026
fa76608
fix(gateway): exempt voice fast-lane follow-ups from busy-interrupt
mrkillbob Sep 10, 2026
c38c76d
fix(tools): wire resolve_worktree_base into create_subagent_worktree,…
mrkillbob Sep 10, 2026
b5ec378
fix(tests): add conversation_worktree to the WS orphan-race resume co…
mrkillbob Sep 10, 2026
1c8d59c
fix(tui_gateway): wire find_gateway_approval_session and add stored-k…
mrkillbob Sep 10, 2026
2a1e86f
feat(tui_gateway): expose federation_role identity on profiles.list rows
mrkillbob Sep 10, 2026
18e306a
fix(tui_gateway): advance the kanban notify cursor after delivery in …
mrkillbob Sep 10, 2026
27cdac2
fix(cli): route venv bin-dir resolution through the canonical hermes_…
mrkillbob Sep 10, 2026
a5643c2
feat(photon): add read_receipts behavioral config, pass through to si…
mrkillbob Sep 10, 2026
5606772
fix(tools): detect delete/passive-voice agent-config mutation instruc…
mrkillbob Sep 10, 2026
3733ece
fix(tests): make the encode_fingerprint literal pin correct across th…
mrkillbob Sep 10, 2026
6695dfd
fix(gateway): media delivery allowlist follows the active profile hom…
mrkillbob Sep 10, 2026
d99a64a
fix(bootstrap): apply harden_import_path() on import, like every othe…
mrkillbob Sep 10, 2026
adbfb64
fix(tests): update switch_session kwargs to the current signature in …
mrkillbob Sep 10, 2026
84f2f65
fix(kanban): baseline a fresh event-stream socket at the current max …
mrkillbob Sep 10, 2026
1a9824e
fix(state): consolidate duplicate WAL-holder scan implementations
mrkillbob Sep 10, 2026
d88f91a
fix(kanban): route recoverable github-pr-feedback needs_input blocks …
mrkillbob Sep 10, 2026
8eabca2
fix(agent): skip remote candidates and disable fallback per FailoverR…
mrkillbob Sep 10, 2026
25b332b
test(worktree): pin repo_with_remote's bare origin to main, not ambie…
mrkillbob Sep 10, 2026
cff2f96
fix(cron,backup): reject future heartbeat stamps; stream automatic ba…
mrkillbob Sep 10, 2026
1c5230a
fix(gateway): keep voice fast-lane turns tool-free only for real conv…
mrkillbob Sep 10, 2026
fbaa791
fix(agent): stop a completed kanban worker from making another provid…
mrkillbob Sep 10, 2026
37d28a7
fix(deps): sync website/package-lock.json with the js-yaml 4.3.2 over…
mrkillbob Sep 10, 2026
0478d5e
fix(kanban): swallow a second CancelledError raised during stream_eve…
mrkillbob Sep 10, 2026
574236c
fix(kanban): make _EventTail.shutdown() immune to task cancellation
mrkillbob Sep 10, 2026
7a2af07
fix(desktop): cap vitest worker threads for the memory-heavy jsdom UI…
mrkillbob Sep 10, 2026
290238e
fix(desktop): use Vitest 4's top-level worker options, not removed po…
mrkillbob Sep 10, 2026
aed86fe
fix(bots): remove pointer-entry pre-warming from BotRow
mrkillbob Sep 10, 2026
588a345
fix: address all reviewer threads for PR76 bot-integration fixes
mrkillbob Sep 10, 2026
5159be1
fix: address remaining reviewer threads for PR76 bot-integration review
mrkillbob Sep 10, 2026
eb2e2f1
fix(gateway): indent resolve() method body in CapabilityRegistry
mrkillbob Sep 10, 2026
563299f
fix(gateway): promote resolve() to class-level method in CapabilityRe…
mrkillbob Sep 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
23 changes: 23 additions & 0 deletions .audit-tool-lock.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
{
"schema_version": 1,
"tools": {
"zizmor": {
"version": "1.30.0",
"sha256": "sha256:98c426d9668ba03d7444acdb8a5f0eb44ba187ddffeba15833b605a384d50879"
},
"import-linter": {
"version": "2.14",
"sha256": "sha256:a6558ea7f4f0fea70cf21f63eac9d37018882f8ed529bb3313ba28e1a2bf279e",
"distribution_sha256": "sha256:de0858c9dc7eeca513b6daa31dec7099939addfb1f089536ec806a0b1611bddb"
},
"pip-audit": {
"version": "2.10.1",
"sha256": "sha256:ade9c86ba46074ca0224526121f061c67fadafabf00294c7d52d6436221604de",
"distribution_sha256": "sha256:5691c79b88f4c5c5b9f8f7642c9708d12275998fe7e523144b5c132807ac135c"
}
},
"uv": {
"version": "0.12.6",
"sha256": "sha256:e8929237934c8679686428f5a7736c7ae7a5fe7a33b0504d1b03446cdbc43c94"
}
}
2 changes: 1 addition & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
# Default model is configured in ~/.hermes/config.yaml (model.default).
# Use 'hermes model' or 'hermes setup' to change it.
# LLM_MODEL is no longer read from .env — this line is kept for reference only.
# LLM_MODEL=anthropic/claude-opus-4.6
# LLM_MODEL=openai-codex/gpt-5.5

# =============================================================================
# LLM PROVIDER (NovitaAI)
Expand Down
36 changes: 34 additions & 2 deletions .github/actions/get-app-token/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,8 @@ description: >-

Composite actions cannot access contexts directly, so callers pass the
public vars.APP_CLIENT_ID and protected secrets.APP_PRIVATE_KEY as inputs.
When the private key is empty, the fallback fires.
When either credential is empty, the fallback fires rather than attempting
to mint with a partial credential pair.

inputs:
client-id:
Expand All @@ -31,6 +32,30 @@ inputs:
description: Comma- or newline-separated repositories to scope within the installation owner.
required: false
default: ''
permission-actions:
description: Actions API permission requested for the token (read or write).
required: false
default: ''
permission-checks:
description: Checks API permission requested for the token (read or write).
required: false
default: ''
permission-contents:
description: Repository contents permission requested for the token (read or write).
required: false
default: ''
permission-issues:
description: Issues permission requested for the token (read or write).
required: false
default: ''
permission-pull-requests:
description: Pull request permission requested for the token (read or write).
required: false
default: ''
permission-statuses:
description: Commit status permission requested for the token (read or write).
required: false
default: ''

outputs:
token:
Expand All @@ -45,8 +70,9 @@ runs:
shell: bash
env:
CLIENT_ID: ${{ inputs.client-id }}
PRIVATE_KEY: ${{ inputs.private-key }}
run: |
if [ -n "$CLIENT_ID" ]; then
if [ -n "$CLIENT_ID" ] && [ -n "$PRIVATE_KEY" ]; then
echo "has_app=true" >> "$GITHUB_OUTPUT"
else
echo "has_app=false" >> "$GITHUB_OUTPUT"
Expand All @@ -61,6 +87,12 @@ runs:
private-key: ${{ inputs.private-key }}
owner: ${{ inputs.owner }}
repositories: ${{ inputs.repositories }}
permission-actions: ${{ inputs.permission-actions }}
permission-checks: ${{ inputs.permission-checks }}
permission-contents: ${{ inputs.permission-contents }}
permission-issues: ${{ inputs.permission-issues }}
permission-pull-requests: ${{ inputs.permission-pull-requests }}
permission-statuses: ${{ inputs.permission-statuses }}

- name: Fall back to GITHUB_TOKEN
id: fallback
Expand Down
17 changes: 13 additions & 4 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,12 +18,10 @@ on:
pull_request:
push:
branches: [main]
workflow_dispatch:

permissions:
contents: read
pull-requests: write # needed by lint (PR comment) + supply-chain review_status
actions: read # needed by osv-scanner (SARIF upload)
security-events: write # needed by osv-scanner (SARIF upload)

concurrency:
group: ci-${{ github.ref }}
Expand Down Expand Up @@ -197,17 +195,24 @@ jobs:
supply-chain:
name: Supply-chain scan
needs: detect
if: needs.detect.outputs.event_name == 'pull_request' && (needs.detect.outputs.scan == 'true' || needs.detect.outputs.deps == 'true')
if: needs.detect.outputs.event_name == 'pull_request' && (needs.detect.outputs.scan == 'true' || needs.detect.outputs.deps == 'true' || needs.detect.outputs.npm_lock == 'true')
permissions:
contents: read
pull-requests: read
uses: ./.github/workflows/supply-chain-audit.yml
with:
event_name: ${{ needs.detect.outputs.event_name }}
scan: ${{ needs.detect.outputs.scan == 'true' }}
deps: ${{ needs.detect.outputs.deps == 'true' }}
npm_lock: ${{ needs.detect.outputs.npm_lock == 'true' }}

review-labels:
name: Review label gate
needs: [detect, supply-chain]
if: always() && needs.detect.outputs.event_name == 'pull_request' && (needs.detect.outputs.ci_review == 'true' || needs.detect.outputs.mcp_catalog == 'true' || needs.supply-chain.outputs.critical_findings == 'true')
permissions:
contents: read
pull-requests: read
uses: ./.github/workflows/review-labels.yml
with:
ci_review: ${{ needs.detect.outputs.ci_review == 'true' }}
Expand All @@ -217,6 +222,10 @@ jobs:

osv-scanner:
name: OSV scan
permissions:
actions: read
contents: read
security-events: write
# PR scans use the artifact/review-status path below. Direct main pushes
# are scanned by osv-scanner.yml's push trigger so they can publish SARIF.
if: github.event_name == 'pull_request'
Expand Down
10 changes: 7 additions & 3 deletions .github/workflows/deploy-site.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,6 @@ on:

permissions:
contents: read
actions: read
pages: write
id-token: write

concurrency:
group: pages
Expand All @@ -48,6 +45,11 @@ jobs:

deploy-docs:
if: github.repository == 'NousResearch/hermes-agent'
permissions:
actions: read
contents: read
id-token: write
pages: write
runs-on: ubuntu-latest
timeout-minutes: 30
environment:
Expand All @@ -62,6 +64,8 @@ jobs:
with:
client-id: ${{ vars.APP_CLIENT_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
permission-actions: read
permission-contents: read

- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
name: Docker Build, Test, and Publish

on:
push:
branches: [main]
Comment thread
mrkillbob marked this conversation as resolved.
# This workflow owns its own triggers. ci.yml does not call it.
# A reusable-workflow call eeps the caller run in progress for that full time.
# GitHub refuses ``gh run rerun`` on a run that is still in progress.
Expand All @@ -10,10 +12,9 @@ on:
# Trusted main pushes resolve the environment-scoped Docker Hub secrets in
# this same workflow, never across a workflow boundary.
pull_request:
push:
branches: [main]
release:
types: [published]
workflow_dispatch:

permissions:
contents: read
Expand Down
15 changes: 8 additions & 7 deletions .github/workflows/e2e-desktop.yml
Original file line number Diff line number Diff line change
Expand Up @@ -107,8 +107,15 @@ jobs:
# is always fresh — no separate build step needed.
- name: Run Playwright E2E tests
working-directory: apps/desktop
env:
GITHUB_REF_NAME_SAFE: ${{ github.ref_name }}
CI: 'true'
# Ensure no real API keys leak into the test env.
OPENROUTER_API_KEY: ''
OPENAI_API_KEY: ''
NOUS_API_KEY: ''
run: |
if [ "${{ github.ref_name }}" = "main" ]; then
if [ "$GITHUB_REF_NAME_SAFE" = "main" ]; then
echo "On main — generating/updating baseline screenshots"
npm run build && xvfb-run -a --server-args="-screen 0 1280x1024x24" \
npx playwright test --reporter=list --update-snapshots
Expand All @@ -117,12 +124,6 @@ jobs:
npm run build && xvfb-run -a --server-args="-screen 0 1280x1024x24" \
npx playwright test --reporter=list
fi
env:
CI: 'true'
# Ensure no real API keys leak into the test env.
OPENROUTER_API_KEY: ''
OPENAI_API_KEY: ''
NOUS_API_KEY: ''

# ── Save updated baselines to cache (main only) ───────────────────
- name: Save updated baselines to cache
Expand Down
16 changes: 6 additions & 10 deletions .github/workflows/js-autofix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,16 +35,6 @@ name: auto-fix lint issues & formatting
# on the current state.

on:
push:
branches: [main]
paths:
- '**/*.js'
- '**/*.cjs'
- '**/*.mjs'
- '**/*.ts'
- '**/*.tsx'
- 'package.json'
- 'package-lock.json'
workflow_dispatch:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Restore automatic JavaScript autofixes

With this workflow reduced to workflow_dispatch, JavaScript and TypeScript changes merged to main no longer start the documented npm run fix and bot-PR loop, and a repository-wide search finds no caller that dispatches this workflow automatically. Fixable lint and formatting issues can therefore remain on main indefinitely unless an operator manually starts the workflow; restore the existing path-filtered push trigger.

Useful? React with 👍 / 👎.


permissions:
Expand Down Expand Up @@ -141,8 +131,10 @@ jobs:
timeout-minutes: 15
environment: trusted-automation
permissions:
checks: read # gh pr checks reads CheckRun entries
contents: write # needed to push to bot/js-autofix
pull-requests: write # needed for PR creation + auto-merge
statuses: read # gh pr checks also reads commit StatusContext entries
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

Expand All @@ -152,6 +144,10 @@ jobs:
with:
client-id: ${{ vars.APP_CLIENT_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
permission-checks: read
permission-contents: write
permission-pull-requests: write
permission-statuses: read

- name: Download patch
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
Expand Down
9 changes: 6 additions & 3 deletions .github/workflows/lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,12 +53,15 @@ jobs:

- name: Determine base ref
id: base
env:
BASE_BRANCH: ${{ github.base_ref }}
EVENT_NAME: ${{ inputs.event_name }}
run: |
# For PRs, diff against the merge base with the target branch.
# For pushes to main, diff against the previous commit on main.
if [ "${{ inputs.event_name }}" = "pull_request" ]; then
BASE_SHA=$(git merge-base "origin/${{ github.base_ref }}" HEAD)
BASE_REF="origin/${{ github.base_ref }}"
if [ "$EVENT_NAME" = "pull_request" ]; then
BASE_SHA=$(git merge-base "origin/$BASE_BRANCH" HEAD)
BASE_REF="origin/$BASE_BRANCH"
else
BASE_SHA=$(git rev-parse HEAD~1 2>/dev/null || git rev-parse HEAD)
BASE_REF="HEAD~1"
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/lockfile-diff.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,12 +47,14 @@ jobs:

- name: Generate semantic lockfile diff
id: diff
env:
BASE_BRANCH: ${{ github.base_ref }}
run: |
set -euo pipefail
# Three-dot semantics by hand: diff from the merge base with the
# target branch to the PR head, so changes that landed on main
# after the branch point don't show up as this PR's doing.
BASE_SHA=$(git merge-base "origin/${{ github.base_ref }}" HEAD)
BASE_SHA=$(git merge-base "origin/$BASE_BRANCH" HEAD)
echo "Merge base: ${BASE_SHA}"
python3 scripts/ci/lockfile_diff.py \
--base "$BASE_SHA" \
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/nix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,9 @@ name: Nix flake check
on:
pull_request:
push:
branches: [main]
branches:
- main
workflow_dispatch:
Comment thread
mrkillbob marked this conversation as resolved.

permissions:
contents: read
Expand Down
Loading
Loading