Commit Graph

307 Commits

Author SHA1 Message Date
Forkbert
2d95c42aa4 plugin-catalog: repin localsend to the security-hardened revision
Pins the localsend catalog entry to 28dfd30ccd — the revision that merges
the catalog security review's hardening (teknium1's review on this PR:
share-root allowlist with realpath checks on send and receive, LAN-only
peer gate, mandatory PIN with crypto-safe generation, 2 GiB transfer cap),
plus bumps the entry to v1.19.0.
2026-09-20 10:32:28 -07:00
Tyler Lyon
b6fde6b79b plugin-catalog: bump localsend to v1.18.0
The receiver can now serve TLS for peers that force encryption, announcing the
certificate fingerprint a peer pins. Sender certificates are not validated -
stdlib Python cannot accept arbitrary self-signed client certificates - which is
documented next to the limit rather than implied.
2026-09-20 10:32:28 -07:00
Tyler Lyon
8cdac5f23d plugin-catalog: localsend v1.17.0 - full field set
Pins the reviewed commit for v1.17.0 and fills in the entry contract the rest of
the catalog uses: tier, category, docs_url, requires_hermes, version, and the
capability declarations (three tools, no hooks, no middleware, no env vars).
Card image rebuilt from a real capture of the plugin's desktop pane.
2026-09-20 10:32:28 -07:00
Tyler Lyon
bff182d5e5 plugin-catalog: bump localsend to v1.16.1
Stop now reports a genuinely stopped receiver (the payload previously said
stopped=true and running=true at once), plus a contract test pinning the
desktop pane's ctx.rest paths to the backend routes.
2026-09-20 10:32:28 -07:00
Tyler Lyon
dc8f4f1673 plugin-catalog: bump localsend to v1.16.0 (encrypted peer support)
Repins to the v1.16.0 commit: the plugin can now send to peers in LocalSend's
default HTTPS mode, presenting a persistent device certificate, announcing its
SHA-256 fingerprint in LocalSend's uppercase-hex format, and pinning the peer's
certificate against the fingerprint it advertised.
2026-09-20 10:32:28 -07:00
Tyler Lyon
0a67efa90a plugin-catalog: bump localsend to v1.15.0 (desktop pane, chip, palette commands)
Repins to the v1.15.0 commit, which adds the desktop half — a LOCALSEND pane,
status-bar chip and three palette commands — and a dashboard backend at
/api/plugins/localsend/. The agent tools are unchanged.
2026-09-20 10:32:28 -07:00
Tyler Lyon
d30568e602 plugin-catalog: bump localsend to v1.13.0, add card image 2026-09-20 10:32:28 -07:00
Tyler Lyon
6a60e2d275 plugin-catalog: add localsend
LocalSend (open-source AirDrop alternative) peer-to-peer transfer for Hermes:
localsend_discover, localsend_send and localsend_receive. Standard-library
implementation of LocalSend Protocol v2.2 with no runtime dependencies.

Owner submission of https://github.com/tylerbrevard/hermes-localsend, pinned to
49dcb1f0c18ff2a25a2f3c9d89fa021307afbcde (tag v1.12.2).
2026-09-20 10:32:28 -07:00
Bikash Joshi
22d328dedf chore(plugin-catalog): pin bot-forge banner to the entry's commit 2026-09-20 10:31:45 -07:00
Bikash Joshi
a9d53dbdd6 chore(plugin-catalog): pin bot-forge v0.4.1 2026-09-20 10:31:45 -07:00
Bikash Joshi
9392fa1d08 feat(plugin-catalog): pin bot-forge to v0.4.0 2026-09-20 10:31:45 -07:00
Bikash Joshi
cf3be4d7df feat(plugin-catalog): pin bot-forge to v0.3.0 2026-09-20 10:31:45 -07:00
Bikash Joshi
36bad2f06f feat(plugin-catalog): pin bot-forge to v0.2.0 2026-09-20 10:31:45 -07:00
Bikash Joshi
e437be2f50 feat(plugin-catalog): add bot-forge 2026-09-20 10:31:45 -07:00
Kyle Durepos
6058ad105c catalog: repin Afterforge with external Python runtime declaration 2026-09-20 10:27:44 -07:00
mojomast
baa65cfaf4 catalog: repin Afterforge to operator-reviewed security distribution 2026-09-20 10:27:44 -07:00
mojomast
ed5e47efba catalog: add Afterforge pinned native regression workbench 2026-09-20 10:27:44 -07:00
MazenMkhinini
960864fd70 chore(plugin-catalog): pin image-utils to the three-platform commit
2cc23a9 -> c4123fbdb315137b40e4c5b4b5fd3eb2298dae66. The pinned commit runs its suite on ubuntu-latest, macos-latest and
windows-latest (actions/runs/35520540211, all green), so windows is declared in platforms instead of
being excluded without explanation, and the README now gives the manual install route that Windows
needs because install.sh is a POSIX shell script.

What CI found and fixed on the way to that green run, all of it reaching the plugin only through this
branch: an in-place overwrite of a multi-frame image failed on Windows because the input's read handle
(and the mapping Pillow uses for single-strip BMP/TIFF/PNG/P) was still open at the rename; a
read-only target is refused by Windows even with the mode restored afterwards, so the attribute is
cleared for the rename and put back either way; WinError 5/32 from an external holder is retried
briefly; release/rename/chmod hold the plugin's guard lock; and converting a JPEG with EXIF
orientation 5-8 to TIFF no longer fails its own verification (Pillow's TIFF reader applies the tag,
so the file legitimately reads back transposed).

Diff adopted: 5 commits, tools.py +158/-23, tests +366, README +5, 135 tests (134 + 1 platform skip
on Windows).
2026-09-20 10:27:04 -07:00
MazenMkhinini
9bf24e4e4d chore(plugin-catalog): bump image-utils pin to the CI-tested commit
b1eb2585 -> 2cc23a99a6df9238b25cd5dc118946563afb1bd9. The new commit adds a linux/macOS/Windows test matrix and the two platform
guards it needed, so the pinned code is now tested on every platform the entry claims plus Windows.

Diff being adopted: .github/workflows/tests.yml (new), tests/test_image_utils.py and
tests/test_competition_fixes.py (platform guards only). No plugin behaviour changes.
2026-09-20 10:27:04 -07:00
MazenMkhinini
e2978d0a81 feat(plugin-catalog): add image-utils 2026-09-20 10:27:04 -07:00
Apostol Apostolov
7335224718 feat(plugin-catalog): bump rss-reader to 1.0.6 2026-09-20 10:26:26 -07:00
teknium1
1ff92e59d5 chore(catalog): remarkable disclosure line (cloud egress, upload, sidecar setup) 2026-09-20 10:25:46 -07:00
cygnostik
db5205b870 fix(plugins): pin cross-platform CI-qualified installable release 2026-09-20 10:25:46 -07:00
cygnostik
22b72e2561 feat(plugins): add reMarkable cloud and notebook toolkit 2026-09-20 10:25:46 -07:00
aydnOktay
8c9b674622 feat(plugin-catalog): add sketch-pad community plugin 2026-09-20 10:25:09 -07:00
GoldenLoaf24h
16c5ce7d9a chore(plugin-catalog): bump browserclaw to v2.9.3 2026-09-20 10:24:31 -07:00
Ritesh Patel
9d638304dc catalog: add handflow (community) 2026-09-20 10:23:52 -07:00
teknium1
a1183a8ef9 chore(catalog): hermes-herald disclosure line (egress, ledger, credential use) 2026-09-20 10:23:11 -07:00
Ben Kamholtz
dc79c3ee82 docs(catalog): point hermes-herald entry at the multiplex limitation
Review feedback: the trust-boundary limitation lives in the PR body and the
repo README, but a catalog reader may never open either. Add an inline comment
on the entry naming the limitation and where it is documented.

Comment-only; the pinned sha is unchanged.
2026-09-20 10:23:11 -07:00
Ben Kamholtz
358cb07280 feat(catalog): add hermes-herald plugin entry
Herald lets Hermes agent profiles dispatch work to each other: async dispatch
to a target profile's API server with SSE completion, synchronous multi-turn
chat, model-selectable in-process subagents, a durable SQLite run ledger,
fail-closed per-target model-route discovery, and host-owned bare LLM
inference. 12 tools, no core tool collisions.

Pinned at v1.1.1 (1d185a9e). requires_hermes >=0.21.0: the approval-consent
gate imports tools.approval_prompt.request_elicitation_consent, which first
exists in 0.21.0.
2026-09-20 10:23:11 -07:00
chenxue
db72cb912f plugin-catalog: bump aihubmix pin to b55e916 (docs-only) 2026-09-20 10:22:25 -07:00
tobenwarrior
1095530312 fix(plugin-catalog): pin kiro-acp to the tagged COMMIT, not the tag object
The entry pinned 88e5b023, which is the annotated tag OBJECT for v0.1.2 —
40 hex, but not a commit. Git peels the ref on checkout and detaches at the
commit it points to (02c4dd06), so the installer's revision guard saw
tag-sha != HEAD and refused:

    Error: Checked-out revision '02c4dd06...' does not match requested
    commit '88e5b023...'.

The entry was therefore uninstallable: `hermes plugins install kiro-acp`
failed for everyone, at the pin, with no way through.

Pin the commit the tag points at (same tree as reviewed; the tag was created
on a commit that is also the current main tip). Verified end to end:
`--ref 88e5b023` fails with the mismatch above, `--ref 02c4dd06` installs.

Swept all 194 catalog entries for the same class: this was the only pin that
names a tag object.
2026-09-20 10:21:45 -07:00
Angello Picasso
9d24f9c91f chore(catalog): bump kiro-provider to v1.0.0 2026-09-20 13:57:00 +05:30
anpicasso
4fb18291fc catalog: bump jev-approvals to v0.2.1 2026-09-20 13:48:44 +05:30
Teknium
eeb85107f9 Merge pull request #116215 from aydnOktay/catalog/source-tray
feat(plugin-catalog): add source-tray community plugin
2026-09-19 19:33:03 -07:00
teknium1
913d409832 chore(plugin-catalog): disclosure line (catalog review) 2026-09-19 19:14:41 -07:00
trajectoire-regis[bot]
1764d01b7d feat(catalog): add hermes-structured-aux-models plugin entry
Adds one plugin-catalog entry for trajectoire-ai/hermes-structured-aux-models,
a `kind: model-provider` plugin that registers the `structured-aux` provider.

The plugin accepts the OpenAI-shaped `chat.completions.create()` call Hermes'
auxiliary client makes and translates it into a bounded Jev decision request on
OpenRouter, mapping the typed answer back — so auxiliary tasks (approval, MCP
sampling, compression) get a bounded decision instead of a free-form chat
prompt. It fails open: any request it cannot express as a decision raises, so
Hermes falls back to the operator's own auxiliary provider.

- tier: community, category: models
- pin: e5c49b081ad04adca2ee3edc601b09ede6cee4c5 (v0.1.0, repo released)
- capabilities: no tools, hooks or middleware registered; no required env vars
  (the OpenRouter credential resolves env -> profile .env -> Hermes credential
  pool, so no duplicate secret is demanded at install time)
- requires_hermes: ">=0.21" — the plugin seams were verified against v0.21.0

Verified locally against the admission gate at the pinned sha:
`python3 scripts/validate_plugin_catalog.py plugin-catalog/` -> OK: 187 files valid
`hermes plugins validate --install-deps <dir>` -> Validation passed (13/13 checks,
security scan: safe, capability probe: registered provider structured-aux)
2026-09-19 19:14:41 -07:00
apoapostolov
55f2b988f2 feat(plugin-catalog): pin rss-reader public edition 2026-09-19 19:13:44 -07:00
Apostol Apostolov
b492618163 chore(plugin-catalog): repin rss-reader 1.0.5 2026-09-19 19:13:44 -07:00
Apostol Apostolov
f7849016b3 chore(plugin-catalog): repin rss-reader 1.0.5 2026-09-19 19:13:44 -07:00
Apostol Apostolov
9c1ef6bfcf feat(plugin-catalog): pin rss-reader 1.0.5 fix 2026-09-19 19:13:44 -07:00
Apostol Apostolov
f9073eff76 feat(plugin-catalog): bump rss-reader to 1.0.5 2026-09-19 19:13:44 -07:00
Apostol Apostolov
23bb584b96 feat(plugin-catalog): pin rss-reader 1.0.4 2026-09-19 19:13:44 -07:00
Apostol Apostolov
633b065abb feat(plugin-catalog): pin rss-reader catalog card 2026-09-19 19:13:44 -07:00
Apostol Apostolov
250d8a89d1 feat(plugin-catalog): pin rss-reader 1.0.4
Bump sha to 7e39b1159a377d473bb47af1be8a3a1d42f307f5 (empty Unread view on the last post).
2026-09-19 19:13:44 -07:00
Apostol Apostolov
05e580ff62 feat(plugin-catalog): add rss-reader 2026-09-19 19:13:44 -07:00
teknium1
cdbbbfd882 chore(plugin-catalog): disclosure line (catalog review) 2026-09-19 19:13:07 -07:00
apoapostolov
a7f63109e6 feat(plugin-catalog): pin provider-status public edition 2026-09-19 19:13:07 -07:00
Apostol Apostolov
3ee2d10098 feat(plugin-catalog): pin provider-status catalog card 2026-09-19 19:13:07 -07:00
Apostol Apostolov
97f731020b feat(plugin-catalog): add provider-status 2026-09-19 19:13:07 -07:00