Releases: techne-tools/zotero-hermes
Releases · techne-tools/zotero-hermes
Release list
Release v0.3.2
v0.3.1 — Security hardening and race condition fixes
Security Hardening & Race Condition Fixes
This release addresses high-priority security vulnerabilities (sandbox escape vectors, path traversal, dialog deadlocks) and multiple concurrency/race conditions across the Hermes agent interface.
Security Mitigations
- Sandbox escape mitigations: Disarmed dangerous URI schemes (
javascript:,file:,chrome:,data:) inMarkdownRendererand prevented unhandled schemes inHermesChatViewfrom invoking privileged Gecko chrome execution. Added nested parenthesis link URL support. - Workspace sandboxing & database protection: Sandboxed Hermes ACP agent session
cwdandworkdirto<profile>/zotero-hermes/workspace/(isolated fromzotero.sqlite), and disabled ACP filesystem client capabilities. - Path traversal prevention: Enforced strict ID validation (
/^[a-zA-Z0-9_-]+$/) across allConversationManagerfile access methods. - Modal dialog deadlock fix: Handled native
cancelandcloseevents inApprovalDialogso pressingEscaperesolves cleanly rather than deadlocking the approval queue.
Race Condition & Concurrency Fixes
- Process spawn mutex: Added
connectPromisemutex inHermesClientto prevent concurrent calls from spawning multiplehermes acpchild processes. - Stream buffer bleed: Added
abortActiveStream()and buffer clearing on chat switch, creation, or deletion; dropped reasoning chunks targeted at inactive conversations. - Debounced save race: Captured target conversation ID in
ChatManager.scheduleSave()to prevent delayed debounced writes from clobbering switched chats. - Duplicate SSE stop events: Guarded against spurious duplicate stop notifications in
HermesApiClient. - Context synchronization: Added
removeAttachedItem()toItemManagerand synchronized withContextBar.onRemoveItem. - Multi-window teardown: Switched to per-window
WeakMap<Window, any>inhooks.tsto prevent window close from disrupting other open windows.
Install
Download hermes-agent-for-zotero.xpi and install via Zotero → Tools → Plugins → gear → Install Plugin From File.
v0.3.0 — OpenDesign 'Reading Room' redesign
OpenDesign "Reading Room" redesign
Complete visual redesign of the Hermes chat view, plus a critical identity correction.
Highlights
- New design language — bundled Source Sans 3 / Source Serif 4 / Source Code Pro fonts, refined dark/light palette tokens
- Input area — auto-growing textarea (up to 6 lines, then scroll) for wordy research queries; fixed-height centred send button; symmetric padding; cursor breathing room
- Header — matched to Zotero's native toolbar (40px, zero vertical padding)
- Identity correction — addon ID is now
hermes@techne-tools.org(washermes@nousresearch.com); author/homepage/bugs point at the techne-tools org
Notes
- Breaking for existing installs: the addon ID change means Zotero treats this as a new plugin. Existing users must remove the old
hermes@nousresearch.cominstall and install this release fresh. Preferences (prefs prefixextensions.zotero.hermes) carry over. - Zotero 7.0 – 10.x supported.
Install
Download hermes-agent-for-zotero.xpi and install via Zotero → Tools → Plugins → gear → Install Plugin From File.
Release v0.2.0
Release Manifest
This release is used to host update.json, please do not delete or modify it!
Updated in UTC 2026-09-18T19:04:31.704Z for version 0.3.2