OSV weekly scan reported 50 known vulnerabilities in pinned deps. This bumps everything with a released, semver-compatible fix: Python (uv.lock): - aiohttp 3.14.1 -> 3.14.3 (GHSA-cq5v-8q36-5273, GHSA-mfx4-hv73-q22v, GHSA-mq44-7p77-q5h7) - h2 4.3.0 -> 4.4.1 (CVE-2026-71554 request smuggling; exclude-newer exception documented in pyproject, remove after 2026-08-17) npm (root workspace): - brace-expansion 5.0.8 -> 5.0.9, undici 6.27->6.28 / 7.28->7.29, js-yaml 4.3.1, nanoid 3.3.17/3.3.18, ip-address 10.4.0, mermaid 11.16.1 + dompurify 3.4.13 (root overrides so the streamdown transitive copy is pinned too) - electron 40.10.2 -> 40.10.6 (GHSA-r4w5-6pfg-jxp5; the 41.x major for GHSA-9f4c-93c8-jc8g is deferred to its own PR) npm (website): mermaid, dompurify, js-yaml, nanoid, fast-uri 3.1.5, postcss 8.5.23, undici 7.29.0 npm (photon sidecar): @opentelemetry/core 2.8.0 via override, undici npm (whatsapp-bridge): body-parser 1.20.6 min-release-age excludes added to .npmrc/website/.npmrc for the sub-2wk CVE-fix releases, each with a removal date. Remaining findings are blocked upstream: cryptography <49 cap (alibabacloud-tea-openapi), image-size (no fixed release), tar 6.x transitive majors, electron 41. Local rescan: 50 -> 19 known vulns, 0 introduced.
72 lines
2.1 KiB
JSON
72 lines
2.1 KiB
JSON
{
|
|
"name": "hermes-agent",
|
|
"version": "1.0.0",
|
|
"description": "An AI agent with advanced tool-calling capabilities, featuring a flexible toolsets system for organizing and managing tools.",
|
|
"private": true,
|
|
"workspaces": [
|
|
"apps/*",
|
|
"ui-tui",
|
|
"ui-tui/packages/*",
|
|
"web",
|
|
"tests-js"
|
|
],
|
|
"scripts": {
|
|
"postinstall": "echo '✅ Browser tools ready. Run: python run_agent.py --help'",
|
|
"install:root": "npm install --workspaces=false",
|
|
"install:web": "npm install --workspace web",
|
|
"install:tui": "npm install --workspace ui-tui",
|
|
"install:desktop": "npm install --workspace apps/desktop",
|
|
"audit:root": "npm audit --workspaces=false",
|
|
"audit:web": "npm audit --workspace web",
|
|
"audit:tui": "npm audit --workspace ui-tui",
|
|
"audit:fix:root": "npm audit fix --workspaces=false",
|
|
"audit:fix:web": "npm audit fix --workspace web",
|
|
"audit:fix:tui": "npm audit fix --workspace ui-tui",
|
|
"check": "npm run --ws check",
|
|
"fix": "npm run --ws fix"
|
|
},
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "git+https://github.com/NousResearch/Hermes-Agent.git"
|
|
},
|
|
"license": "MIT",
|
|
"bugs": {
|
|
"url": "https://github.com/NousResearch/Hermes-Agent/issues"
|
|
},
|
|
"homepage": "https://github.com/NousResearch/Hermes-Agent#readme",
|
|
"dependencies": {
|
|
"@streamdown/math": "1.0.2",
|
|
"agent-browser": "0.26.0"
|
|
},
|
|
"devDependencies": {
|
|
"@eslint/js": "9.39.5",
|
|
"typescript-eslint": "8.64.0",
|
|
"eslint-plugin-perfectionist": "5.10.0",
|
|
"eslint-plugin-react-hooks": "7.1.1",
|
|
"eslint-plugin-unused-imports": "4.4.1",
|
|
"globals": "17.7.0"
|
|
},
|
|
"overrides": {
|
|
"lodash": "4.18.1",
|
|
"yauzl": "^3.3.1",
|
|
"protobufjs": "^8.7.1",
|
|
"brace-expansion": "5.0.9",
|
|
"mermaid": "11.16.1",
|
|
"dompurify": "3.4.13"
|
|
},
|
|
"engines": {
|
|
"node": ">=22.22.0",
|
|
"npm": "<11.10.0 || >=11.17.0"
|
|
},
|
|
"allowScripts": {
|
|
"unicode-animations": false,
|
|
"esbuild@0.28.1": true,
|
|
"node-pty@1.1.0": true,
|
|
"electron-winstaller@5.4.0": true,
|
|
"agent-browser@0.26.0": true,
|
|
"electron@40.10.2": true,
|
|
"fsevents@2.3.2": true,
|
|
"fsevents@2.3.3": true
|
|
}
|
|
}
|