Bumps sha to a6cf35afc3ca607271284844ee79c60ee4083296 (tag v0.4.5),
which carries the review fix: catch-all allow patterns refused at YAML
load and in `add --type allow` unless forced interactively.
🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
Drops gui/ from the pinned tree per review (a catalog entry may not ship an app patch); the patch stays
on the plugin repo's gui-rows branch. Both gates re-checked at the new sha.
Adds the per-model voice catalogs (361 voices), the refreshed model lists (21 STT / 18 TTS) and
the CLI listing. Both gates re-checked locally at the new sha.
The entry now carries the GUI-row patch and the audio tests, so the pin moves with them
(README rule 4 — a new PR, re-reviewed as a SHA bump). Both CI gates re-checked locally:
the structural validator passes and the plugin at the new sha passes
`hermes plugins validate`.
Adds the OpenRouter voice plugin: speech-to-text and text-to-speech providers for
stt.provider / tts.provider = openrouter, reusing OPENROUTER_API_KEY. Stdlib only.
Owner submission (README rule 5): the plugin repository's owner is opening this PR.
Pinned to a1b01810cdd6be15be61f2c6f6e05e24dafbba14 (rule 2) — exact 40-hex, no
branch or tag.
Policy compliance:
- rule 3 (no self-updating code): pure Python; the plugin never fetches GitHub and
never rewrites its own distribution. Updates reach users only through
`hermes plugins update` and a SHA-bump PR here.
- rule 6 (declared capabilities match reality): registers no tools, hooks or
middleware; requires OPENROUTER_API_KEY, which is the only env var it reads.
Both CI gates checked locally before opening: scripts/validate_plugin_catalog.py
passes on the whole directory, and an anonymous clone at the pinned sha followed by
`hermes plugins validate` passes.
Pins the localsend catalog entry to 28dfd30ccd — the revision that merges
the catalog security review's hardening (teknium1's review on this PR:
share-root allowlist with realpath checks on send and receive, LAN-only
peer gate, mandatory PIN with crypto-safe generation, 2 GiB transfer cap),
plus bumps the entry to v1.19.0.
The receiver can now serve TLS for peers that force encryption, announcing the
certificate fingerprint a peer pins. Sender certificates are not validated -
stdlib Python cannot accept arbitrary self-signed client certificates - which is
documented next to the limit rather than implied.
Pins the reviewed commit for v1.17.0 and fills in the entry contract the rest of
the catalog uses: tier, category, docs_url, requires_hermes, version, and the
capability declarations (three tools, no hooks, no middleware, no env vars).
Card image rebuilt from a real capture of the plugin's desktop pane.
Stop now reports a genuinely stopped receiver (the payload previously said
stopped=true and running=true at once), plus a contract test pinning the
desktop pane's ctx.rest paths to the backend routes.
Repins to the v1.16.0 commit: the plugin can now send to peers in LocalSend's
default HTTPS mode, presenting a persistent device certificate, announcing its
SHA-256 fingerprint in LocalSend's uppercase-hex format, and pinning the peer's
certificate against the fingerprint it advertised.
Repins to the v1.15.0 commit, which adds the desktop half — a LOCALSEND pane,
status-bar chip and three palette commands — and a dashboard backend at
/api/plugins/localsend/. The agent tools are unchanged.
LocalSend (open-source AirDrop alternative) peer-to-peer transfer for Hermes:
localsend_discover, localsend_send and localsend_receive. Standard-library
implementation of LocalSend Protocol v2.2 with no runtime dependencies.
Owner submission of https://github.com/tylerbrevard/hermes-localsend, pinned to
49dcb1f0c18ff2a25a2f3c9d89fa021307afbcde (tag v1.12.2).