Skip to content

Releases: techne-tools/zotero-hermes

Release v0.3.2

Choose a tag to compare

@github-actions github-actions released this 18 Sep 19:04

🚀 Enhancements

  • hermes: Implement metadata editing, approval gating, audit log, and runtime mode switching (a6129b6)
  • hermes: Add obsidian export bridge, comparative synthesis, bbt drafting, and active reader workflows (5a76bad)

❤️ Contributors

  • Chris Wenn

v0.3.1 — Security hardening and race condition fixes

Choose a tag to compare

@prismatic7 prismatic7 released this 11 Sep 11:42

Security Hardening & Race Condition Fixes

This release addresses high-priority security vulnerabilities (sandbox escape vectors, path traversal, dialog deadlocks) and multiple concurrency/race conditions across the Hermes agent interface.

Security Mitigations

  • Sandbox escape mitigations: Disarmed dangerous URI schemes (javascript:, file:, chrome:, data:) in MarkdownRenderer and prevented unhandled schemes in HermesChatView from invoking privileged Gecko chrome execution. Added nested parenthesis link URL support.
  • Workspace sandboxing & database protection: Sandboxed Hermes ACP agent session cwd and workdir to <profile>/zotero-hermes/workspace/ (isolated from zotero.sqlite), and disabled ACP filesystem client capabilities.
  • Path traversal prevention: Enforced strict ID validation (/^[a-zA-Z0-9_-]+$/) across all ConversationManager file access methods.
  • Modal dialog deadlock fix: Handled native cancel and close events in ApprovalDialog so pressing Escape resolves cleanly rather than deadlocking the approval queue.

Race Condition & Concurrency Fixes

  • Process spawn mutex: Added connectPromise mutex in HermesClient to prevent concurrent calls from spawning multiple hermes acp child processes.
  • Stream buffer bleed: Added abortActiveStream() and buffer clearing on chat switch, creation, or deletion; dropped reasoning chunks targeted at inactive conversations.
  • Debounced save race: Captured target conversation ID in ChatManager.scheduleSave() to prevent delayed debounced writes from clobbering switched chats.
  • Duplicate SSE stop events: Guarded against spurious duplicate stop notifications in HermesApiClient.
  • Context synchronization: Added removeAttachedItem() to ItemManager and synchronized with ContextBar.onRemoveItem.
  • Multi-window teardown: Switched to per-window WeakMap<Window, any> in hooks.ts to prevent window close from disrupting other open windows.

Install

Download hermes-agent-for-zotero.xpi and install via Zotero → Tools → Plugins → gear → Install Plugin From File.

v0.3.0 — OpenDesign 'Reading Room' redesign

Choose a tag to compare

@prismatic7 prismatic7 released this 10 Sep 19:45

OpenDesign "Reading Room" redesign

Complete visual redesign of the Hermes chat view, plus a critical identity correction.

Highlights

  • New design language — bundled Source Sans 3 / Source Serif 4 / Source Code Pro fonts, refined dark/light palette tokens
  • Input area — auto-growing textarea (up to 6 lines, then scroll) for wordy research queries; fixed-height centred send button; symmetric padding; cursor breathing room
  • Header — matched to Zotero's native toolbar (40px, zero vertical padding)
  • Identity correction — addon ID is now hermes@techne-tools.org (was hermes@nousresearch.com); author/homepage/bugs point at the techne-tools org

Notes

  • Breaking for existing installs: the addon ID change means Zotero treats this as a new plugin. Existing users must remove the old hermes@nousresearch.com install and install this release fresh. Preferences (prefs prefix extensions.zotero.hermes) carry over.
  • Zotero 7.0 – 10.x supported.

Install

Download hermes-agent-for-zotero.xpi and install via Zotero → Tools → Plugins → gear → Install Plugin From File.

Release v0.2.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 18:11

No significant changes.

Release Manifest

Release Manifest Pre-release
Pre-release

Choose a tag to compare

@prismatic7 prismatic7 released this 10 Sep 18:07

This release is used to host update.json, please do not delete or modify it!
Updated in UTC 2026-09-18T19:04:31.704Z for version 0.3.2