mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
Follow-up to the #30179 security review (maxpetrusenko). P0s 1-3 are being handled separately (kuangmi-bit); this covers the three P1s + the P2. P1 #4 — secrets replace rules now emit `require: true`. Verified replaceConfig.Require EXISTS in the pinned iron-proxy v0.39.0 secrets transform (KnownFields(true) strict decode would otherwise reject it) and is enforced in TransformRequest: a request to an allowlisted upstream that arrives WITHOUT the proxy token in a matched location is rejected (ActionReject) rather than forwarded with whatever credential it carried. Closes the leak where a real provider key sent directly to an allowed host passed the proxy boundary. P1 #5 — NODE_OPTIONS append-merge now resolves CA-mode conflicts. A docker_env `--use-bundled-ca` would previously survive alongside the egress-required `--use-openssl-ca`, leaving Node's trust behavior dependent on option order. Egress flag now wins deterministically (conflicting CA-mode flags stripped + warning); unrelated operator tuning preserved. P1 #6 — install now GPG-verifies the release. checksums.txt is verified against checksums.txt.asc using the bundled public-key.asc in an ephemeral keyring. Best-effort: degrades with a warning when gpg/sig assets are unavailable (SHA-256 still enforced); a PRESENT-but-invalid signature is a tamper signal and hard-fails the install. P2 #7 — threat-model wording scoped to the 'configured trusted proxy boundary' across the module docstring, config.py, and the egress docs, with a new security-model bullet on CA-key / endpoint-integrity loss (MITRE T1588.004 AiTM). Tests: +2 NODE_OPTIONS conflict/preserve, +5 GPG verify (skip/missing/bad/ good/install-abort), +1 require assertion. iron_proxy 94 + docker 74 green; ruff clean. |
||
|---|---|---|
| .. | ||
| docs | ||
| i18n/zh-Hans/docusaurus-plugin-content-docs/current | ||
| scripts | ||
| src | ||
| static | ||
| .gitignore | ||
| docusaurus.config.ts | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| sidebars.ts | ||
| tsconfig.json | ||
Website
This website is built using Docusaurus, a modern static website generator.
Installation
yarn
Local Development
yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
USE_SSH=true yarn deploy
Not using SSH:
GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.
Diagram Linting
CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.