Main (7537de9e7) moved most of the vulnerable locked versions, but some fixes live only in the lockfiles and some advisories stayed open. This commit closes the rest: website/package.json gets durable overrides for js-yaml 4.3.1, dompurify 3.4.13, mermaid 11.16.1, and tar 7.5.22. The root workspace gets the same tar override, which moves the tar 6.2.1 copies under get-windows and @mapbox/node-pre-gyp past twelve open advisories. Without an override, a reinstall can pull an old transitive copy back in. image-size <=2.0.2 has two infinite-loop DoS advisories and no fixed release upstream. An override points it at @nous-research/image-size 2.0.3, our maintained fork of the real repo. The OSV scanner resolves the aliased fork cleanly, so no ignore entries are needed. The photon sidecar moves @opentelemetry/core to 2.10.0. The whatsapp-bridge gets a body-parser 1.20.6 override, so the lockfile-only fix from main cannot regress on reinstall. website/.npmrc gets matching min-release-age exclusions for the fix releases that are less than two weeks old. electron stays at 40.10.2. The 41.x fix for GHSA-9f4c-93c8-jc8g brings back the install failure thatbb8280b75reverted: install.js in 40.10.3+ extracts with an MSVC native binding, which fails on Windows machines without the VC++ Redistributable. Upstream tracks this in electron/electron#52481, with no fix released.
Photon sidecar
Small Node helper that bridges Hermes Agent to Photon's Spectrum SDK
(spectrum-ts). Hermes is Python; Photon has no public HTTP
send-message endpoint today; replies therefore go through this sidecar.
The sidecar:
- runs
Spectrum({ projectId, projectSecret, providers: [imessage.config()] }) - exposes a loopback-only HTTP control channel for the Python adapter
to push send/typing requests (auth via
X-Hermes-Sidecar-Token) - drains the inbound message stream so
spectrum-tskeeps its reconnect/heartbeat machinery alive and Hermes can receive inbound messages over the adapter's loopbackGET /inboundstream
Install
cd plugins/platforms/photon/sidecar
npm install
The Hermes plugin's hermes photon setup command runs npm install
here automatically.
Run standalone
For debugging:
PHOTON_PROJECT_ID=... PHOTON_PROJECT_SECRET=... \
PHOTON_SIDECAR_PORT=8789 PHOTON_SIDECAR_TOKEN=$(openssl rand -hex 16) \
node index.mjs
In normal use, the Python adapter supervises this process — start, restart on crash, kill on shutdown — and never asks the user to run it by hand.
Why a sidecar at all?
Photon's Spectrum send path is exposed through the TypeScript SDK's
Space.send(...) API. Hermes is Python, so replies go through this sidecar
until Photon ships a public HTTP send endpoint.
When Photon ships an HTTP send endpoint, the plan is to retire this
sidecar entirely and call it directly from Python. The plugin's
outbound code path is already isolated behind small helpers
(_sidecar_send, _sidecar_send_richlink, and _sidecar_send_attachment in
adapter.py) to make that swap localized.