Opt-in idle/daily gateway conversation resets, now that core no longer rotates conversations on timers (1d5d059410). Reads the existing session_reset block; #126244 points users with that block at this plugin. Pinned to bb618e08, which declares its pre_gateway_dispatch hook (fastfinge/hermes-session-reset-policy#1).
- Bump pin ae81c5b -> f5a880c (docs-only commit: refreshed screenshot,
new 1280x640 social preview, HOW_TO_USE.md guide linked from README)
- Add image: raw.githubusercontent URL of the social preview (2:1, 1280x640)
- hermes plugins validate passes at the pinned commit
restore now holds the memory tool's own lock while it writes MEMORY.md/USER.md and
refuses when a file changed after its plan, so it never replaces a running agent's
memory write. The plan lists the memory entries it brings back and removes.
Importing a Hermes backup put the backup's copy of the history back and cut off
every version recorded after it, the state right before the import included.
Those versions now stay, and the import is recorded as one change restore can undo.
Re-pins AhmetArif0/hermes-memory-rewind to 5f935c2 (1.3.0). A change made outside the
agent's turns was credited to whatever came next: a write approved with /memory approve
showed up as the agent's next memory call, a curator archive as the next session's. Each
turn now starts with a baseline (pre_llm_call, which declares only session_id and
platform), and the session-start baseline names no session. Adds pre_llm_call to hooks.
Re-pins AhmetArif0/hermes-memory-rewind from b747327 to e5b139b, which only redraws
docs/card.png. The plugin page header crops the 2:1 image to rows 110-490, which cut off
the card's title and last line. The plugin directory and version 1.2.0 are unchanged.
Maintenance follow-up to v1.1.2. Re-pin to d7cab7df (v1.1.3) and correct
the egress disclosure: CLI, Desktop and eligible gateway platforms are
forwarded; Telegram-origin lifecycle, approval-prompt, and (when enabled)
approval-response copies are suppressed because the core Telegram gateway
already delivers them in that chat.
Adopts upstream fix T-099: adapter dropped its pyyaml import in favor of
core-dep hermes_yaml (gateway venv runs with python -I, pyyaml absent);
plugin __init__ fallback hardened to only catch the no-parent-package
case so dependency errors surface unmasked.
Commit range 073f2e8..8de6264 touches only adapter.py (import + one
call site) and __init__.py (fallback guard) in the plugin repo.
## Thinking Path
`plugin-catalog/hindsight.yaml` already documented in prose that
`local_embedded` mode is unsupported on PM-managed Hermes with the current
pin — it still calls the retired lazy-install path for `hindsight-all` and
loops update takeover on every conversation — yet `hermes plugins install`
and the dashboard install path accepted the entry with no gate at all. Users
only discovered the trap after the death loop started. The catalog knew;
the installers didn't act on it.
## What Changed
- `hermes_cli/plugin_catalog.py`: new `known_issues: List[str]` field on
`PluginCatalogEntry` (parsed from `known_issues` in each `plugin-catalog/*.yaml`,
serialized into `to_dict()`, defaults to empty for backward compatibility).
- `plugin-catalog/hindsight.yaml`: declares the documented local-embedded trap
as machine-readable `known_issues`.
- `hermes_cli/plugins_cmd_install.py`:
- `cmd_install`: for catalog entries with `known_issues`, prints each issue
and a bold-red notice, then requires explicit confirmation. Non-interactive
(non-TTY) runs fail closed; interactive `y/N` runs require `y`.
- `dashboard_install_plugin`: non-interactive path refuses the entry outright
(no GUI bypass, mirroring the existing kill-list posture) and returns the
issue list in the error payload.
## Why This Shape
The trap is machine-readable in the catalog, so the enforcement lives in the
install entry points rather than in hindsight-specific code — any future
catalog entry that documents a known trap gets the same gate for free. The
non-interactive path fails closed because it cannot ask for the confirmation
the interactive path requires.
## Verification
- RED/GREEN double proof via git stash: pre-fix 7 failed / 3 passed, post-fix
10/10 passed (catalog parsing round-trip, hindsight.yaml declares the trap,
non-TTY refuse, TTY yes proceeds, TTY no cancels, custom-source install not
gated, dashboard refuse + unaffected path).
- Adjacent suites: test_plugin_catalog.py, test_plugin_validate.py,
test_plugins_hub_live_catalog.py all green (36 passed). 9 errors in
test_plugins_cmd_catalog.py reproduce identically with the fix stashed
(existing local `pm` / uv-sync environment limitation, unrelated).
- ruff clean on all changed files.
## Contract Change
New optional catalog field `known_issues` (list of strings). Entries without
it behave exactly as before. Install behavior changes only for entries that
declare `known_issues`.
## Risks
- Catalog entries that declare `known_issues` become gated installs. Authors
of future entries should only declare issues they want surfaced — this is
the intended trade (a documented trap must not install silently).
- `cmd_install` non-TTY automation installing hindsight by name now fails.
That is intentional: the trap cannot be confirmed non-interactively.
## Model Used
jd-deepseek-v4-flash-0731 (main session); pytest + ruff in the isolated
worktree.
## Related
#124037 (issue). Related: #122326 (resulting takeover loop), #7718
(`local_embedded` needs `hindsight-all`).
Adds Ex8-ca/memex8 as a community-tier memory backend.
Pinned to commit b5e87b7b, which:
- opts into pre-compress checkpoint API v2 (fail-closed durable
archive of the transcript before lossy rewrite)
- uses spawn_context_thread for all background work, so writes
bind to the correct profile under multiplex
- Repo: https://github.com/Ex8-ca/memex8
- Subdir: plugins/memex8
- MemoryProvider ABC + on_session_end + on_memory_write +
on_pre_compress hooks
- Standalone repo per third-party-product policy
Standalone community plugin at duyetbot/hermes-provider-anyrouter,
pinned to d5820c1. Registers the anyrouter provider over its
OpenAI-compatible /v1 surface: tool-capable picker filtering,
session/routing/reasoning passthrough, opt-in app attribution.
Resubmission per in-tree-provider-integration policy: the previous
in-tree PR (#54714) was closed under 'no third-party products in-tree';
this ships the integration as a catalog-pinned standalone plugin, which
is the path that policy points to.
Adds the card image (docs/card.png, 2:1, real /memory-history output) and re-pins to
b747327, the 1.2.0 commit plus that image; the plugin directory is unchanged.