feat(desktop): wire macOS bundle updates and guarded feed publication

Route packaged macOS bundles and Light through the updater strategy.
Use electron-updater 6.8.9 and wait for native signature acceptance before
backend teardown. Keep checkout and Store ownership separate.

Share Darwin feed paths between packaging, runtime and publication.
Validate both native feeds, verify streamed artifact hashes, prevent
same-tag artifact replacement, and conditionally update the channel
pointer. Protect live feed references during canary retention.

Use one notarization owner. Require publishing credentials and validate
the stapled app. Keep Windows, Linux and Termux jobs unchanged.

Verified with updater/feed unit and transport tests, release-helper tests,
desktop typechecks, the desktop JS build, and workflow lint. No E2E,
native macOS install, release dispatch or public publication was run.
This commit is contained in:
ethernet
2026-09-06 21:27:58 -04:00
parent ff91ff0d5a
commit da236308fd
29 changed files with 1034 additions and 555 deletions

View File

@@ -11,7 +11,7 @@
"tests-js"
],
"scripts": {
"postinstall": "echo '\u2705 Node dependencies installed. Run: python run_agent.py --help'",
"postinstall": "echo '✅ Node dependencies installed. Run: python run_agent.py --help'",
"install:root": "npm install --workspaces=false",
"install:web": "npm install --workspace web",
"install:tui": "npm install --workspace ui-tui",
@@ -36,11 +36,11 @@
"homepage": "https://github.com/NousResearch/Hermes-Agent#readme",
"devDependencies": {
"@eslint/js": "9.39.5",
"typescript-eslint": "8.64.0",
"eslint-plugin-perfectionist": "5.10.0",
"eslint-plugin-react-hooks": "7.1.1",
"eslint-plugin-unused-imports": "4.4.1",
"globals": "17.7.0"
"globals": "17.7.0",
"typescript-eslint": "8.64.0"
},
"overrides": {
"lodash": "4.18.1",
@@ -71,5 +71,9 @@
"fsevents@2.3.2": true,
"fsevents@2.3.3": true,
"get-windows@9.3.0": true
},
"dependencies": {
"js-yaml": "4.3.1",
"semver": "7.7.4"
}
}