Re-pins to eb1ac9b, which declares fastapi and httpx2 in
[project].dependencies. pyproject previously had dependencies = [], and
Hermes' installer gives pyproject precedence over plugin.yaml's
python_dependencies, so a catalog install resolved no deps at all and the
dashboard half failed to import.
Verified with upstream hermes_cli.plugin_python_deps.read_declaration at
the new sha: specs=('fastapi>=0.104,<1', 'httpx2>=2.7,<3'), source='pyproject'
(it reported specs=() before). doctor_plugin against main: ok, no findings.
Upstream suite: 453 passed, 6 skipped; uv lock --check clean.
Durable project ownership and bounded initiative management for Hermes fleets.
Validated at the pinned sha with hermes plugins validate --install-deps
and scripts/validate_plugin_catalog.py.
Catalog entry for ajensenwaud/hermes-jev-plugin pinned at v0.1.0
(b3d29f71770a3447ad0b3db00658f64a8edc7dd3): TypeSafe Jev System One
decision tools (jev_evaluate / jev_check / jev_route / jev_score) with a
bundled usage skill. Owner-submitted; validates clean at the pin.
The plugin was renamed and restructured since the original entry, so the old
filename, name, version, category and pin are all stale.
name jev-approval-provider -> jev-approvals
sha 980b3d84 -> a19e332f (plugin-catalog/README rule 4: re-reviewed bump)
version 0.1.0 -> 0.2.0
category tools -> models (matches the other model-provider entries)
Upstream changes adopted in this range:
- Approvals-only provider `typesafe-jev` (single alias `jev`); the plugin id and the
provider name are deliberately different and both covered by tests.
- Second route: OpenRouter's decisions endpoint, selected by base_url alone, returning
the identical typed answers. Model lists are fetched live from whichever upstream is
configured instead of a hardcoded tuple.
- A `pre_tool_call` hook that existed briefly in the range was removed before this pin;
capabilities below are empty because the plugin registers no tools, hooks or
middleware at a19e332 (doctor: "0 tool(s), 0 hook(s)").
- Hardening: answer validation, egress redaction, bounded retries, a size-capped
decision log.
Verified at the pinned SHA on a fresh clone:
scripts/validate_plugin_catalog.py -> OK: 1 file(s) valid
hermes plugins validate plugin -> Validation passed (security scan: caution)
hermes plugins doctor plugin --ci -> OK, jev-approvals 0.2.0 (model-provider)
The caution findings are the self-test's hostile fixtures (recursive root delete, raw
block-device write, credential paths) living under plugin/tests/, plus the policy
comments in __init__.py that quote the same shapes. They are what the suite asserts the
guardian DENIES.
Still labelled a proof of concept in the description, the README header and the manifest.
A desktop/plugin.js is evaluated in the Electron renderer with the app's
full authority; the runtime loader documents itself as error isolation
only and says a remote source must not reuse it without a boundary. The
catalog is that remote source, so admission now fails a plugin whose
desktop code patches prototypes, uses eval/new Function, dynamically
imports anything but the SDK (app chunks, blob/http URLs), or injects
script tags. Against the 18 desktop plugins in the current sweep the lint
passes 17 and fails the one the security review flagged for exactly these
moves. Policy written down in plugin-catalog/README.md rule 8 and the
user-facing catalog doc.
Updates the catalog pin from 345ef9d5 (v0.1.1) to 16c870f9 (v0.2.0).
Repo changes since the previous pin:
- provider identity table moved out of plugin_api.py into identity.yaml
- backend/ renamed to dashboard/ (the layout Hermes mounts dashboard routes from)
- version bumped to 0.2.0 in plugin.yaml and dashboard/manifest.json
Upstream: 16c870f9c7
Community entry for ai-usage-tracker (lvabarajithan/hermes-ai-usage-tracker),
pinned to tag v1.0.1 (98010ea3fb2ce037cc5889bc4787e0152da69745).
Shows live subscription-quota windows for every provider Hermes can route to as a
desktop page, a status-bar chip and a per-profile picker. Declares no tools, hooks,
middleware or env vars — it reads credentials the user already configured.
Also maps the commit-author email so the attribution check passes.