Releases: Ando-Corporation/hermes-ando
Release list
Ando Hermes v0.2.0-beta.5 — local sender authorization
Restricts Hermes host turns to explicit local authorization, addressing the two blocking catalog review findings.
New invitation connections and existing profiles without a local allowlist default to the member who connected the agent. Other workspace members and agents cannot start host turns by default. role_authorized is asserted only for an explicit local grant. The platform registers ANDO_ALLOWED_USERS and ANDO_ALLOW_ALL_USERS; widening access is an explicit operator choice documented in the README. An empty allowlist denies everyone. Reconnect preserves operator sender/channel restrictions. Invitation deduplication now depends on credential mode rather than the absence of a sender allowlist.
hermes plugins install Ando-Corporation/hermes-ando --ref 32d4c6bce36382b9f6367c0874784a57d671d99e
hermes plugins enable ando-platformFor an upgrade, stop the gateway first, retain the private profile and SQLite state, and reinstall with --force. No backend/schema changes or new credentials are required. Prior betas admitted arbitrary authorized workspace senders; upgrade before exposing a host with powerful tools to untrusted workspace members.
Validation: all 52 source and exported-artifact tests pass against actual Hermes 38d3dbce4adbb9074a34214eb330237a129e5904. Security regressions exercise installer-only defaults, explicit widening, unknown-agent rejection before host execution, false delegation for unchecked sources, CLI configuration and live/recovery deduplication. Current upstream validator passes all 14 checks without warnings. Every one of the 29 manifest hashes matches, exported from clean source 4146134159d2f95021f5fc034367a565a20f0d0f.
This authorization delta has automated runtime evidence; the prior live pilot is not claimed as a fresh live model run of this delta. Source review/CI and Hermes catalog admission remain external gates. Linux and a minimum Hermes release version remain unverified.
Ando Hermes v0.2.0-beta.4
Superseded by v0.2.0-beta.5: earlier betas admitted every authorized workspace sender to host turns. Upgrade to beta.5 for installer-only local defaults and explicit authorization controls.
Includes the regression-test file omitted from beta.3. All 29 exported file hashes now match release-manifest.json. Runtime files are byte-for-byte identical to the live-tested beta.3 implementation.
Also preserves acknowledgement of inaccessible inbox rows without fetching unavailable source messages. Includes a regression for revoked-access recovery.
Fixes replies to mentions inside an existing Ando thread. Conversation-level inbox groups can omit a thread root; Hermes now reads the source message and uses its root for context recovery and reply placement.
Install the immutable public beta artifact:
hermes plugins install Ando-Corporation/hermes-ando --ref ad05be3aa74cd31987e30721c66f950aa3390af4
hermes plugins enable ando-platformFor an existing installation, stop the gateway first, retain the private profile and delivery database, and reinstall this SHA with --force. The state format is unchanged.
Verified in an isolated profile on macOS arm64 / Python 3.14.7 against Hermes 38d3dbce4adbb9074a34214eb330237a129e5904: invitation connection, actual gpt-6.1-sol idle DM replies, followup context, authorized channel mention, corrected original-thread reply, startup recovery, and durable receiver claim conflict for both competing and legacy callers. Current upstream plugin validator passes all 14 checks without warnings. Connector suite passes 48 tests.
Public artifact ad05be3 was exported from clean committed Ando source f362f810d1aa0adb3aab10d84fb025f70b815728. Source/public fix PRs remain under review; this is a prerelease, not a production rollout or completed catalog admission. Linux and the remaining live release matrix are not yet certified. Source CI passes; local exact-SHA verification has unrelated Knip findings.
The Sara Tester pilot uses only synthetic messages. No credentials, invitation codes, or private message dumps are included.
Ando Hermes v0.2.0-beta.3
Superseded by v0.2.0-beta.4, which includes the missing regression-test file and matches every release-manifest hash. Runtime files are unchanged.
Also preserves acknowledgement of inaccessible inbox rows without fetching unavailable source messages. Includes a regression for revoked-access recovery.
Fixes replies to mentions inside an existing Ando thread. Conversation-level inbox groups can omit a thread root; Hermes now reads the source message and uses its root for context recovery and reply placement.
Install the immutable public beta artifact:
hermes plugins install Ando-Corporation/hermes-ando --ref ed118b37b5c5c8b598c518cdcd94480ac5eb8a15
hermes plugins enable ando-platformFor an existing installation, stop the gateway first, retain the private profile and delivery database, and reinstall this SHA with --force. The state format is unchanged.
Verified in an isolated profile on macOS arm64 / Python 3.14.7 against Hermes 38d3dbce4adbb9074a34214eb330237a129e5904: invitation connection, actual gpt-6.1-sol idle DM replies, followup context, authorized channel mention, corrected original-thread reply, startup recovery, and durable receiver claim conflict for both competing and legacy callers. Current upstream plugin validator passes all 14 checks without warnings. Connector suite passes 48 tests.
Public artifact ed118b3 was exported from clean committed Ando source f362f810d1aa0adb3aab10d84fb025f70b815728. Source/public fix PRs remain under review; this is a prerelease, not a production rollout or completed catalog admission. Linux and the remaining live release matrix are not yet certified. Source CI passes; local exact-SHA verification has unrelated Knip findings.
The Sara Tester pilot uses only synthetic messages. No credentials, invitation codes, or private message dumps are included.
Ando Hermes v0.2.0-beta.2
Superseded by v0.2.0-beta.3, which also preserves acknowledgement of inaccessible inbox rows. Use the beta.3 release and its immutable commit instead.
Fixes replies to mentions inside an existing Ando thread. Conversation-level inbox groups can omit a thread root; Hermes now reads the source message and uses its root for context recovery and reply placement.
Install the immutable public beta artifact:
hermes plugins install Ando-Corporation/hermes-ando --ref a96494ba68c36b6914c473e8288e4cd92f5775f0
hermes plugins enable ando-platformFor an existing installation, stop the gateway first, retain the private profile and delivery database, and reinstall this SHA with --force. The state format is unchanged.
Verified in an isolated profile on macOS arm64 / Python 3.14.7 against Hermes 38d3dbce4adbb9074a34214eb330237a129e5904: invitation connection, actual gpt-6.1-sol idle DM replies, followup context, authorized channel mention, corrected original-thread reply, startup recovery, and durable receiver claim conflict for both competing and legacy callers. Current upstream plugin validator passes all 14 checks without warnings. Connector suite passes 47 tests.
Public artifact a96494b was exported from clean committed Ando source e89d24c95bd255dea505af3702a90ac8d74e7909. Source/public fix PRs remain under review; this is a prerelease, not a production rollout or completed catalog admission. Linux and the remaining live release matrix are not yet certified. Source CI passes; local exact-SHA verification has unrelated Knip findings.
The Sara Tester pilot uses only synthetic messages. No credentials, invitation codes, or private message dumps are included.
Ando Hermes 0.2.0 beta 1
Ando's first Hermes plugin beta connects an existing Hermes agent through Invite members > Agent and receives messages through a persistent Hermes gateway.
Install this exact beta
hermes plugins install Ando-Corporation/hermes-ando --ref ae015d9360d5e1b5467cee9c847acdd63eab4086
hermes plugins enable ando-platformUse Hermes's normal dependency approval flow. Follow the runtime setup guide to connect privately using the existing agent invitation. Installing and enabling alone do not grant Ando access. The backend must support durable execution claims before generation can proceed.
Verified release artifact
- Public plugin commit:
ae015d9360d5e1b5467cee9c847acdd63eab4086. - Ando source commit:
c7e6a4356af12317d3e100a22c19a728f4746b32(provenance, not the install ref). - Reproduced the allowlisted export from the clean committed Ando source using the MIT license in this public repository. All 29 manifest file hashes match;
source_dirty=false,license_supplied=true. - 46 tests passed with no skips, including real Hermes lifecycle compatibility tests with controlled model and HTTP responses.
- Fresh public-SHA install in an isolated Hermes profile, enable, enabled-plugin discovery, exact installed SHA, and
hermes ando --helpCLI loading passed. hermes plugins validate /path/to/public-checkout --install-deps --json: all 13 checks passed, no warnings.- Verified environment: macOS / Darwin arm64, Python 3.14.7, Hermes source
38d3dbce4adbb9074a34214eb330237a129e5904, MCP 2.0.0, httpx2 2.7.0, httpx 0.28.1, websockets 15.0.1.
Beta limits and remaining evidence
This beta is text-focused and sequential. No live staging or external-company workspace pilot, actual model/provider round trip, or deployed Ando backend revision was verified in this release run. Hermes catalog admission and production invitation/documentation promotion remain separate gates. The private-file lock implementation targets macOS/Linux; this run verified macOS only.
See RELEASING.md for pilot evidence and rollout requirements.
Rollback
Stop the gateway, disable ando-platform, and retain the private Hermes profile and delivery database. Review and finish unfinished claims before changing receivers. Reinstall a previously tested public SHA only if its state format is compatible. This release did not deploy backend changes or alter production invitation instructions.