Commit Graph

213 Commits

Author SHA1 Message Date
jinli.yl
e834ee8971 feat(plugins): list ReMe and align manifest install support 2026-09-19 11:58:06 -07:00
chenfeijiang95-ui
ec5cee7e4c catalog: update live-time (pin refresh + card image) 2026-09-19 11:57:11 -07:00
GoldenLoaf24h
a8262bcce0 chore: re-pin browserclaw to v2.8.2 (c4b8d14) 2026-09-19 11:56:28 -07:00
GoldenLoaf24h
78bf8c7e75 Update browserclaw catalog pin SHA to 302e5df (token auth fix) 2026-09-19 11:56:28 -07:00
GoldenLoaf24h
4383f1cdba feat(plugin-catalog): add browserclaw plugin 2026-09-19 11:56:28 -07:00
Sahil-SS9
7ef193088e fix(plugin-catalog): re-pin hermes-project-stewardship after dependency fix
Re-pins to eb1ac9b, which declares fastapi and httpx2 in
[project].dependencies. pyproject previously had dependencies = [], and
Hermes' installer gives pyproject precedence over plugin.yaml's
python_dependencies, so a catalog install resolved no deps at all and the
dashboard half failed to import.

Verified with upstream hermes_cli.plugin_python_deps.read_declaration at
the new sha: specs=('fastapi>=0.104,<1', 'httpx2>=2.7,<3'), source='pyproject'
(it reported specs=() before). doctor_plugin against main: ok, no findings.
Upstream suite: 453 passed, 6 skipped; uv lock --check clean.
2026-09-19 11:55:49 -07:00
Sahil-SS9
5db3298a5e feat(plugin-catalog): add hermes-project-stewardship
Durable project ownership and bounded initiative management for Hermes fleets.

Validated at the pinned sha with hermes plugins validate --install-deps
and scripts/validate_plugin_catalog.py.
2026-09-19 11:55:49 -07:00
Jordan @ BoredSexy
55ae8b6cf2 plugin-catalog: bump fusion sha to edab6a6 (relative-import + category fix) and drop empty subdir 2026-09-19 11:55:11 -07:00
Jordan Rosenberg
08dfeb0d59 plugin-catalog: add fusion router (community) 2026-09-19 11:55:11 -07:00
Emir Ibrahimbegovic
f978d1aad5 plugin-catalog: add tailgate 2026-09-19 11:54:25 -07:00
Denis Skripnik
ea14d6c8f5 fix(catalog): pin VK v0.2.3 profile isolation fixes 2026-09-19 11:53:46 -07:00
Denis Skripnik
5a5c3aec07 fix(catalog): require verified Hermes 0.21.3 for VK v0.2.2 2026-09-19 11:53:46 -07:00
Denis Skripnik
e07f0221ae fix(catalog): pin VK plugin v0.2.1 registration compatibility 2026-09-19 11:53:46 -07:00
web3blind
da1d38dde6 feat(catalog): add VK Messenger platform plugin 2026-09-19 11:53:46 -07:00
teknium1
6330e6b213 chore(plugin-catalog): disclosure line, contributor map (catalog review) 2026-09-19 11:53:09 -07:00
Aners Jensen-Waud
2b2512d0cf feat(plugin-catalog): add jev-typesafe entry
Catalog entry for ajensenwaud/hermes-jev-plugin pinned at v0.1.0
(b3d29f71770a3447ad0b3db00658f64a8edc7dd3): TypeSafe Jev System One
decision tools (jev_evaluate / jev_check / jev_route / jev_score) with a
bundled usage skill. Owner-submitted; validates clean at the pin.
2026-09-19 11:53:09 -07:00
Apostol Apostolov
10eb860733 feat(plugin-catalog): pin opaque-composer catalog card 2026-09-19 11:49:47 -07:00
Apostol Apostolov
bf9f57e2a4 feat(plugin-catalog): add opaque-composer 2026-09-19 11:49:47 -07:00
teknium1
158f53e3eb plugin-catalog: jev-approvals — disclosure line (commands + approval policy go to a third-party AI) 2026-09-19 11:21:46 -07:00
anpicasso
a9e18c4090 catalog: description + env — TYPESAFE_API_KEY is route-conditional (OpenRouter supported) 2026-09-19 11:21:46 -07:00
anpicasso
6a91e1be2d catalog: pin jev-approvals v0.2.0 (d323921); quote description, drop PoC wording 2026-09-19 11:21:46 -07:00
anpicasso
ce43890e77 catalog: pin jev-approvals v0.2.0 (d323921); update description 2026-09-19 11:21:46 -07:00
anpicasso
1fb4b89130 catalog: rename jev-approval-provider -> jev-approvals, bump sha
The plugin was renamed and restructured since the original entry, so the old
filename, name, version, category and pin are all stale.

  name      jev-approval-provider -> jev-approvals
  sha       980b3d84 -> a19e332f (plugin-catalog/README rule 4: re-reviewed bump)
  version   0.1.0 -> 0.2.0
  category  tools -> models (matches the other model-provider entries)

Upstream changes adopted in this range:
- Approvals-only provider `typesafe-jev` (single alias `jev`); the plugin id and the
  provider name are deliberately different and both covered by tests.
- Second route: OpenRouter's decisions endpoint, selected by base_url alone, returning
  the identical typed answers. Model lists are fetched live from whichever upstream is
  configured instead of a hardcoded tuple.
- A `pre_tool_call` hook that existed briefly in the range was removed before this pin;
  capabilities below are empty because the plugin registers no tools, hooks or
  middleware at a19e332 (doctor: "0 tool(s), 0 hook(s)").
- Hardening: answer validation, egress redaction, bounded retries, a size-capped
  decision log.

Verified at the pinned SHA on a fresh clone:
  scripts/validate_plugin_catalog.py  -> OK: 1 file(s) valid
  hermes plugins validate plugin      -> Validation passed (security scan: caution)
  hermes plugins doctor plugin --ci   -> OK, jev-approvals 0.2.0 (model-provider)

The caution findings are the self-test's hostile fixtures (recursive root delete, raw
block-device write, credential paths) living under plugin/tests/, plus the policy
comments in __init__.py that quote the same shapes. They are what the suite asserts the
guardian DENIES.

Still labelled a proof of concept in the description, the README header and the manifest.
2026-09-19 11:21:46 -07:00
anpicasso
b87da48999 catalog: add jev-approval-provider (PoC smart-approval reviewer) 2026-09-19 11:21:46 -07:00
xyzCruzl
236689b9b4 Add crypto-prices to the plugin catalog 2026-09-19 03:34:16 -07:00
teknium1
72f55062d2 feat(plugin-catalog): refuse desktop plugins that step outside the SDK surface
A desktop/plugin.js is evaluated in the Electron renderer with the app's
full authority; the runtime loader documents itself as error isolation
only and says a remote source must not reuse it without a boundary. The
catalog is that remote source, so admission now fails a plugin whose
desktop code patches prototypes, uses eval/new Function, dynamically
imports anything but the SDK (app chunks, blob/http URLs), or injects
script tags. Against the 18 desktop plugins in the current sweep the lint
passes 17 and fails the one the security review flagged for exactly these
moves. Policy written down in plugin-catalog/README.md rule 8 and the
user-facing catalog doc.
2026-09-19 03:19:18 -07:00
nero
0cc69b7964 bump hermes-live-voice to 0.2.3 2026-09-19 03:08:02 -07:00
nero
0f4cf40c5b plugin-catalog: bump hermes-live-voice to 0.2.2 (privacy + language) 2026-09-19 03:08:02 -07:00
anpicasso
a1b8631baf catalog: bump hermes-plugin-chrome-profiles to v2.0.0 2026-09-19 03:05:50 -07:00
Chris Mish
b8390ee2e5 feat(catalog): add Pixel Worlds desktop realms 2026-09-19 03:03:35 -07:00
JanHranicky
8bb3496d2e fix: re-pin apify plugin to the git-clone loader fix
Bumps the catalog pin to apify/apify-hermes-agent-plugin@07b2146, which
fixes the shim's ImportError under Hermes' git-clone plugin loader
(NousResearch/hermes-agent#114254).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-19 02:57:46 -07:00
JanHranicky
fafcddbca4 feat: added apify plugin entry 2026-09-19 02:57:46 -07:00
Teknium
53403f150f Merge pull request #113921 from Sahil-SS9/catalog/sahil-clean-plugins
feat(plugin-catalog): add prompt-optimizer and spectator plugins
2026-09-19 02:48:58 -07:00
Neal
ebfe522a4e plugin-catalog: bump hermes-subscription-meter pinned sha to v0.2.0
Updates the catalog pin from 345ef9d5 (v0.1.1) to 16c870f9 (v0.2.0).

Repo changes since the previous pin:
- provider identity table moved out of plugin_api.py into identity.yaml
- backend/ renamed to dashboard/ (the layout Hermes mounts dashboard routes from)
- version bumped to 0.2.0 in plugin.yaml and dashboard/manifest.json

Upstream: 16c870f9c7
2026-09-19 02:48:39 -07:00
Spiritsong
00f279fdab fix(plugin-catalog): configure subdir and update pinned sha to e025217 2026-09-19 02:48:17 -07:00
badiyee85
255cb3d992 chore(plugin-catalog): pin release commit SHA and banner image for v0.3.0 2026-09-19 02:48:17 -07:00
badiyee85
c97f50f59e chore(plugin-catalog): bump ha-sidebar-navigator to v0.3.0 2026-09-19 02:48:17 -07:00
Spiritsong
708911f951 chore(plugin-catalog): update ha-sidebar-navigator to v0.2.0 2026-09-19 02:48:17 -07:00
badiyee85
efc9a4458f feat(plugin-catalog): add ha-sidebar-navigator 2026-09-19 02:48:17 -07:00
kama-dev
ecd560c17d plugin-catalog: add session-ref (community, desktop) 2026-09-19 02:46:55 -07:00
teknium1
0873194e52 catalog: add review disclosure line for hermes-loadout (review #112742) 2026-09-19 02:46:19 -07:00
qwertyuiop97
fc32ca7974 feat(plugin-catalog): add hermes-loadout community plugin
Owner-submitted catalog entry for qwertyuiop97/hermes-loadout, pinned
to the published v0.1.0-alpha.1 commit.
2026-09-19 02:46:19 -07:00
Abarajithan
37a0977d7a plugin-catalog: pin ai-usage-tracker to v1.0.2 2026-09-19 02:45:41 -07:00
Abarajithan
d23d05b7e0 plugin-catalog: add ai-usage-tracker
Community entry for ai-usage-tracker (lvabarajithan/hermes-ai-usage-tracker),
pinned to tag v1.0.1 (98010ea3fb2ce037cc5889bc4787e0152da69745).

Shows live subscription-quota windows for every provider Hermes can route to as a
desktop page, a status-bar chip and a per-profile picker. Declares no tools, hooks,
middleware or env vars — it reads credentials the user already configured.

Also maps the commit-author email so the attribution check passes.
2026-09-19 02:45:41 -07:00
teknium1
24a6e0e362 catalog: add review disclosure line for hermes-resetwatch (review #113835) 2026-09-19 02:43:21 -07:00
Adolanium
fa024b9fb4 catalog: update Resetwatch to 0.2.19 2026-09-19 02:43:21 -07:00
Adolanium
910d8ae722 catalog: update Resetwatch to 0.2.18 2026-09-19 02:43:21 -07:00
Markgatcha
0171faec1a fix(catalog): rename memos entry to mem-os and re-pin both entries 2026-09-19 02:41:45 -07:00
Mark Gatcha
d3f6e525f0 catalog: add memos.yaml plugin entry 2026-09-19 02:41:45 -07:00
Mark Gatcha
26dfa869d0 catalog: add umt.yaml plugin entry 2026-09-19 02:41:45 -07:00