Adopts the DNS-rebinding-pinned transport hardening (repo issues #2/#3, PR #3) and the starter-feed/settings failure-surfacing + SSRF-gated icon proxy fix (issue #6, PR #8). Full range in tony-simons-aiowa/hermes-newswire deccdc4..e6b438e (13 commits): Security-relevant highlights: - All outbound fetches (feeds, redirects, icons) now go through a pinned transport: the SSRF gate's validated address set is bound to the actual connection — no second DNS lookup, so DNS rebinding/TOCTOU has no window; the plugin fails closed if the pin seam changes. - New GET /icon.json proxies favicons through the same gate and returns base64 data URLs — the renderer's <img> no longer performs unpinned DNS resolutions of feed-controlled hostnames. 64 KB cap enforced mid-transfer; image content-type allowlist; bounded, normalized TTL cache. - Renderer surfaces backend failures (settings/sources banners, starter-feed inline errors) instead of silent no-ops. Capabilities unchanged (all empty — dashboard plugin, no tools/hooks/ env). Verification at the new pin: 129 pytest, 33 renderer interaction checks, 26 ESM render smoke, hermes plugins validate clean.
18 lines
648 B
YAML
18 lines
648 B
YAML
name: hermes-newswire
|
|
repo: https://github.com/tony-simons-aiowa/hermes-newswire
|
|
sha: e6b438ee617f9b3c1ef9fe008cce2b7291abd949
|
|
description: 'Breaking-news ticker for Hermes Desktop: a scrolling RSS/Atom/JSON-Feed strip above the
|
|
statusbar with per-source favicons, feed search + discovery, grouping modes, offline cache, and
|
|
in-app reading. Zero API keys, zero model tokens.'
|
|
maintainer: tony-simons-aiowa
|
|
tier: community
|
|
category: desktop
|
|
requires_hermes: '>=0.19'
|
|
docs_url: https://github.com/tony-simons-aiowa/hermes-newswire
|
|
platforms: []
|
|
capabilities:
|
|
provides_tools: []
|
|
provides_hooks: []
|
|
provides_middleware: []
|
|
requires_env: []
|