Hermes Vault · Update Log
v0.21.3 · 64a9b432 installed
Full rollback ZIP verified
Gateway and Telegram live

Last updated: 17 September 2026, 10:20 AEST

Hermes Update Log, Boyd's System
v0.21.3 controlled update and custom-safeguards review

Hermes updated from v0.20.6 to v0.21.3 with a verified full backup. The gateway is running current code, Telegram is healthy, all eight configs are schema 45, six customised bundled skills and all seven worker links were preserved, and the main custom integrations passed. The custom-safeguards review found nothing that should be removed. The static publish vault move, paid auxiliary-model decision, role-skill cleanup and cron delivery-proof migration are complete. Connections remains the open decision.

Current Hermes state
v0.21.3 · 64a9b432 · config 45 · gateway current · rollback verified
Overall verdict
Operational and verified. No rollback required. Follow-up changes remain approval-gated.
64a9b432installed main commit
8/8configs on schema 45
7/7worker skill links intact
3/3external-worker wrapper tests passed

Executive Summary

The update is operationally successful. Hermes, launchd, Telegram, Photon, Camofox, Computer Use, Context7, memory-gate, Kanban handlers, cron inventory and the session database all passed their named checks. The automatic updater restart failed because its old process mixed old and new Python modules, but a fresh process loaded correctly and BB restarted the gateway. The old updater emitted no native receipt, so the verified full ZIP and direct runtime evidence are the rollback and completion proof for this run. One later Desktop-only cosmetic commit remains for the next normal update.

Core runtime healthy

Gateway PID 86501 is stable; Telegram and Photon connect; config schema 45 passes across the fleet.

Custom setup preserved

Six customised bundled skills, seven worker symlinks, Camofox, Context7, memory-gate and the external Claude/Codex work-verification wrapper remain functional.

Post-update decisions

Static vault relocation, paid auxiliary routing, role-skill lifecycle cleanup and exact cron delivery proof are complete. Connections remains open.

Claude and Anthropic were untouched. No paid-provider generation smoke ran. Curator remains disabled and no cleanup, delete, prune or automatic replacement ran.

Decisions Needed

Top Maintenance Changes

2026-09-16 v0.21.3 controlled mainline updateInstalled and operational. Full rollback ZIP passed integrity; gateway, configs and critical integrations are verified.better

Installed: v0.20.6 at 10b38830 moved to v0.21.3 at 64a9b432. The checkout is clean; one later Desktop-only cosmetic commit is parked for the next normal update.

Rollback: Full backup /Users/boydbowker/.hermes/backups/pre-update-2026-09-16-170022.zip is 3,635,175,036 bytes and passed unzip -t with no compressed-data errors.

Gateway: The updater restart failed from mixed old/new modules. A fresh Hermes process worked, BB restarted the gateway, launchd became current, and PID 86501 remained stable with Telegram and Photon connected.

Configuration: Default profile migrated 39 to 45; seven worker profiles migrated 38 to 45. Exact default-profile change count: six.

Receipt limitation: No update_receipts/latest.json was written by the old updater process. Verified backup plus direct runtime evidence are the completion proof for this run.

Camofox live proof: After a separate session logged one malformed 400 request, a direct post-update browser_navigate to https://example.com succeeded and returned the expected page snapshot. The integration is functional.

Result: No rollback required. Normal Hermes use can continue.
Custom safeguards compared with built-in HermesNo safeguard was removed. Two approved simplifications are complete without changing native Kanban behavior or cron schedules.done

What was checked: We compared Boyd's custom safeguards and workflows with the new built-in Hermes features to see whether any custom piece had become redundant.

Monitored worker, in English: It is a wrapper for external Claude Code or Codex jobs. Native Hermes tracks whether the process started, finished, failed or disappeared. The wrapper also checks whether the promised files or Git changes appeared and whether verification passed. Process completion is not work completion.

What changed on 17 September: Seven role manuals stopped repeating native Kanban lifecycle mechanics. B1, B2 and B4 delivery verifiers now require an exact delivered cron execution row. The custom safeguards and Obsidian marker repair remain.

Native Kanban: No Kanban default, config, dispatcher, database, task state or source code changed. Normal sessions still do not receive Kanban tools unless explicitly configured, and dispatched workers continue using Hermes's native behavior.

Curator: Skill housekeeping remains disabled. If considered later, run a dry-run and inspect every candidate before enabling.

Evidence: Full audit: 80-Logs/hermes-updates/2026-09-16-v0.21.3-native-replacement-audit.md. SHA-256 a0685301c3c55ef8572c23a20000769862ae3c1011b030d7261afeb9b582c94e.

Result: Keep the custom safeguards. Both approved simplifications are complete and verified.
Static publish vault relocatedThe report pipeline now lives at ~/Documents/ClaudeCode/Hermes_Vault, outside Hermes's protected credential-vault namespace.done

What changed: The full 32 MB publish vault was copied with 53 file hashes verified, then live skills, cron prompts, report tooling and system references were moved to the new path.

Verification: The report passed 18 of 18 checks and deployed successfully from the new directory. Both the immutable Cloudflare preview and stable URL returned the updated content.

Result: Resolved. The old local copy is in macOS Trash and remains recoverable until Trash is emptied.
2026-09-05 to 06 skill modernisation runSix high-use skills were reviewed from the whole-system view, simplified only where evidence supported it, installed with approval and verified against their live routes.done

Obsidian Vault: The 424-line umbrella became a 133-line Vault OS router with specialist detail behind references. Live v2.1.0 SHA-256: 1e7da2d7c769161b3f1e73402b834266af0399242d0da365551818c5eb14b55d.

External writing checks: anti-ai-writing-checklist now activates at the external boundary rather than during ordinary chat, internal notes, plans or AI handoffs. Live v2.0.0 SHA-256: 6abfe77ddf574d3d752d9b2c8dd7720846ce7c36bfd437431a9f75ceb1b07049.

Claude Code execution: autonomous-coding-agents is now a 75-line local Claude Code execution adapter. SOUL and native Hermes own general routing and delegation. Live v2.0.0 SHA-256: afb6f9f3c70bf1a4130e9fbc219b6a48e21278e586d2b70b65c75ef88813d04c.

Model route resolution: model-routing is now a 61-line compatibility adapter for model-tier resolution. Direct-versus-delegate judgement remains in SOUL. Live v2.0.0 SHA-256: d66044526ffb8e85eaa66de5cc2989614aa719b136159ce74cd7ab6b634459bb.

Communication boundaries: communicating-with-bb was reduced from 296 lines to a 44-line boundary skill. Ordinary plain-English style remains in SOUL, USER and MEMORY; MEDIA delivery and wait-state rules now live in SOUL. Live v3.1.0 SHA-256: 00df457dee197e2d0829af29cab02a9baff66fec3c7b30ba9530b4f7783ff349.

Project audits: forensic-project-audit was reduced from a compulsory 408-line investigation to a 91-line project-truth router. All 20 specialist references remain available on demand. Live v2.0.0 SHA-256: 4659a6aa9ec14d4be4cb1fe00e78ceca08ab2c83af0661d281b0dd4d82a4f9ea.

Review discipline: Each review now starts with a whole-system verdict: unique job, removal impact, existing owner, evidenced failures and smallest valid form. Clause mapping follows as an intent-loss check, not a rule-replication exercise.

Verification and scope: All six live hashes were re-read on 6 September. Named mechanical, routing and post-install checks passed for each closeout. No unapproved provider, config, cron, deployment or gateway change was included.

Evidence and rollback: Canonical review evidence lives under 20-Knowledge/Prompts/model-knowledge/skill-modernisation/. Each live replacement has a dated backup and closeout receipt.

Current queue: Six reviews are closed and verified. vault-update-reflex is next and has not started.
2026-08-31 Google Workspace generated cache cleanupMoved only the regenerated Python bytecode cache to Trash. Google Workspace now matches bundled stock.done

Cause: Normal Google Workspace use imported `_hermes_home.py`, causing Python 3.11 to regenerate a `.pyc` file that Hermes counted as source drift.

Action: Moved only `_hermes_home.cpython-311.pyc` to `~/.Trash/hermes-google-workspace-pycache-item7-20260831-074804/`.

Verification: Google Workspace matches stock by CLI diff and full file-hash comparison. Weekly Review Planning and the bundled manifest are unchanged.

Result: False modified-skill warning cleared. No skill source changed.
2026-08-31 unexpected v0.20.6 update remediation closeoutItems 1 to 7, the approved Google Workspace cache cleanup and the X/Twitter credential rotation are complete locally.done

What changed: Updated the canonical Infra record, remediation handoff, dated closeout log, structured report and rendered local HTML. No runtime, skill or manifest change ran during Item 7.

Verification: Hermes v0.20.6 at 10b38830; clean source tree; config schema 39; quick backups; built-in memory; current gateway definition; Telegram and Photon connected; Context7, Camofox and Computer Use healthy; 7 profile skill links intact.

Google Workspace: All source and reference files match stock. BB approved moving the regenerated Python bytecode cache to Trash; Google Workspace no longer appears modified.

Excluded: No Hermes update, model or provider smoke, credential file inspection, credential change, skill reset, gateway restart, report deployment or MemPalace work.

Security follow-up: Stopping the temporary loopback verifier unexpectedly echoed inherited environment values into internal tool output. BB confirmed the affected X/Twitter credentials were manually rotated on 1 September 2026. No values are stored in this report.

Decision: Google Workspace cleanup and X/Twitter credential rotation are complete. The report is deployed and live verified.
Daily system names changed to plain EnglishEleven cron display names and matching user-facing prompt labels now describe their jobs without B1, B2, B4 or Proof Wall shorthand.done

What changed: Renamed the morning, midday, evening, weekly, follow-up, safety-net, learning-review and delivery-check cron surfaces. Updated the three delivery-verifier fallback names.

What stayed unchanged: Stable job IDs, schedules, delivery targets, providers, models, filenames and JSON keys did not change. Necessary Condition keeps its existing name.

Verification: Read-back confirmed all 11 live names and prompts. The three verifier scripts compiled and passed synthetic successful-delivery dry runs. No gateway restart was required.

Result: Live cron labels are clearer. Daily Dashboard labels are locally verified but not published; the frozen Project Dashboard source remains untouched.
Kimi K3 and DeepSeek V4 Pro fallback chainSol now fails over to Kimi K3, then DeepSeek V4 Pro; Luna remains the delegation primary.done

What changed: Main fallback order is kimi-coding / kimi-k3, then opencode-go / deepseek-v4-pro. Sol and Luna remain unchanged.

Delegation limit: Hermes delegates inherit the shared main fallback chain. A separate Luna to MiniMax M3 fallback is not supported, so MiniMax was left parked.

Verification: Config schema 39, typed YAML read-back and hermes fallback list passed. No model calls and no gateway restart were performed.

Active route: gpt-5.6-sol -> kimi-k3 -> deepseek-v4-pro. Delegation remains gpt-5.6-luna and inherits that shared fallback chain.
2026-08-23 v0.20.5 maintenance bundleCompleted and verified. Config, hooks, providers, cron, skills, storage, launchd and Computer Use are reconciled.better

Rollback: Dated rollback bundle: `~/.hermes/backups/v0205-maintenance-20260823-200339`.

Config and security: Default schema 33 and 7 profile schema 23 configs migrated to 38. Concurrency re-pinned to 3. Destructive permanent approvals stripped. Disk cleanup, curator and lazy installs disabled.

Memory and compression: Memory-gate v3 plus fail-closed passed 28 durable tests across all configs. Duplicate memory/skill reviews are off. Compression is in-place, uses the 5,000-message safety threshold and routes to verified OpenAI Codex GPT-5.6.

Providers and cron: Blank, self, Kimi and unused GLM routes removed without deleting credentials or Ollama models. Linear MCP removed while API-key capability remains. Three cron prompts use canonical Vault OS paths; Matt sweep is pinned to GPT-5.6.

Skills: Stock Hermes, Google Workspace, OCR and coder Claude skills restored after BB overlays were verified. Orchestrator and Ops lifecycle drift fixed.

Storage: `state.db` reduced from 5,537.0 MB to 1,922.5 MB, reclaiming 3,614.5 MB. SQLite quick-check returned `ok`.

Runtime closeout: Launchd service definition matches. Wrapper PID 20572 supervises gateway child PID 20578 at v0.20.5 / 8804e783. Telegram and Photon connected, cron ticks, Camofox returns HTTP 200 and Computer Use performs live app discovery.

Result: No required maintenance action remains. Rollback bundle is preserved.
2026-08-23 v0.20.5 mainline updateHermes installed 6,379 commits with a verified full backup. Update and maintenance closeout are complete.better

What changed: Ran `hermes update --backup --yes` from d71033a4 to 8804e783. Hermes reports v0.20.5. Two later Desktop-only commits remain for the next normal update.

Backup proof: The updater printed the full-backup banner before mutation. `/Users/boydbowker/.hermes/backups/pre-update-2026-08-23-174745.zip` is 5.3 GB and passed full compressed-data integrity.

Maintenance result: All 8 configs are schema 38 with concurrency 3. Memory-gate v3, stock skills, cron routes, compact session storage, launchd supervision, Camofox and Computer Use passed.

Result: Complete. No required update maintenance remains.
Session full-text index optimiserCompleted. Reclaimed 3,614.5 MB with no conversation deletion; SQLite quick-check passed.better

Result: Rebuilt the external-content search index and vacuumed the database. Size fell from 5,537.0 MB to 1,922.5 MB.

Integrity: No conversation data was deleted. SQLite `PRAGMA quick_check` returned `ok`.

Result: Database is 1,922.5 MB. No further index action.
Preserved bundled-skill overrides need reconciliationResolved. BB policy moved to overlays and Google Workspace now matches stock after its generated cache moved to Trash.better

Google Workspace: BB service-account and read-only scope policy lives in `workspace-api-operations`; bundled Google Workspace matches stock v1.2. The later generated bytecode cache moved to Trash with BB approval.

Hermes Agent: BB operations policy now lives in `bb-hermes-ops`; bundled Hermes Agent matches stock v3.2.

OCR and coder Claude: Stock OCR is restored in root plus all 7 profiles. Coder Claude policy moved to `autonomous-coding-agents`; coder `claude-code` matches stock.

Result: Stock tracking is restored for Google Workspace, OCR and coder Claude. Intentional Hermes Agent and Weekly Review Planning modifications remain visible.
Orchestrator and worker lifecycle driftResolved. Orchestrator blocks only its own task at the revision cap; Ops uses native `running` status.better

Ownership: Orchestrator 2.1.2 comments the worker target, blocks only its own task at the revision cap and escalates.

Status: Ops SKILL, anomaly catalog, examples and starter prompt use native `running` status.

Review choice: BB downstream reviewer cards remain supported. Native same-card review is optional.

Result: Deterministic scans found no foreign worker block or stale active-status references.
2026-07-27 v0.19.0 mainline updateHermes moved 3,145 commits to d71033a4 with a full backup. Core checks passed; one gateway service repair remains.watch

What changed: Ran hermes update --backup --yes from b9b463f3 to d71033a4. Hermes now reports v0.19.0 and up to date.

Validation: Repo clean; Camofox localhost-only and healthy; all seven role-skill symlinks intact; Context7 and Linear MCP connected; Computer Use doctor passed; Telegram and Photon reached ready state.

Open maintenance: The launchd plist is stale relative to v0.19.0. Updating it requires a separately approved gateway restart.

Decision: Approve hermes gateway start during a quiet window to install the new launchd safety settings.
v0.19 reviewer ownership drift repairedA stale custom review flow contradicted Hermes' permanent worker ownership guard. The skills and audit template now match the runtime.better

Problem: The reviewer skill instructed a dispatcher-spawned reviewer to complete or block the producer's task. v0.19.0 rejects foreign lifecycle mutations and has no reviewer exception.

Fix: Orchestrator 2.1.1, reviewer 2.2.0, linked role guidance and coder success exits now use cross-task comments for evidence and the reviewer's own task as the gate. Revise creates a correction card and blocks the reviewer's own gate.

Proof: Temporary real Kanban databases confirmed foreign complete/block are rejected, foreign comment succeeds, approve completes the reviewer gate, and revise creates a ready correction card while leaving the producer done.

Remaining proof: Run one paid model-driven approve and revise smoke on the live board after separate approval.
Late memory-gate security findingsResolved in memory-gate v3 with V4A coverage, source-based session classification, content-bound tokens and fail-closed registration.better

Path gate: Memory-gate v3 parses V4A Add, Update, Delete and both Move endpoints and gates the full patch when any protected target appears.

Session gate: Interactive CLI and Telegram lineage is allowed; cron, subagent, missing and unknown sources block.

Approval gate: One-shot approval is bound to exact content via `yes save <scope> <sha12>`. Changed content cannot reuse old approval.

Proof: `fail_closed: true` is active across all 8 configs. Every hook doctor and the durable 28-test verifier pass.

Proof: Durable verifier passed 28 tests; all 8 hook doctors pass.
2026-07-10 update and DB maintenanceHermes main updated to b9b463f3; DB optimize and integrity check completed.better

What changed: Ran hermes update --backup from 449706cb to b9b463f3 after precheck found 183 upstream commits.

Validation: Repo clean, gateway launchd-supervised, Context7 and Linear MCP connected, Camofox health OK on 127.0.0.1, worker skill symlinks OK.

DB maintenance: hermes sessions optimize completed and SQLite PRAGMA quick_check returned ok; database stayed around 3.28 GB.

Action: No rollback needed from current evidence.
Generated Desktop JS cleanupUpdate/build produced 697 untracked .js files beside tracked TS/TSX source; they were moved to Trash.better

Evidence: Files appeared under apps/desktop/src and apps/shared/src around update time and matched generated JavaScript output.

Cleanup: Moved to ~/.Trash/hermes-generated-js-post-update-20260710-191358; git status is clean afterward.

Rollback handle: Trash folder can be restored if needed.
Previous Telegram model and delivery risks changedThe old gpt-5.5 route is gone and v0.19.0 adds durable delivery protection. Monitor normal restarts only.better

Delivery protection: v0.19.0 adds a durable delivery-obligation ledger so finished replies can survive a gateway restart. This run did not perform a destructive crash test.

Current model: Default model is now openai-codex gpt-5.6-sol. The configured fallback entries are blank, so Hermes reports no active fallback providers.

Action: No Boyd action. Mikey should monitor ordinary restart evidence and only escalate if a finished reply is lost again.
Speed and prompt-build reliabilitySkill snapshot prompt builds are faster and CLI/runtime responsiveness improved.better

What changed: The update includes perf(skills): speed up snapshot prompt builds, dashboard/session query offloading, and state-query compact rows.

What this means: Less waiting around the parts of Hermes that build prompts, list sessions, and render dashboard/status surfaces.

Recommended use: No behaviour change. Treat it as background speed.

Action: None.
Gateway and session hardeningGateway restart and live-session routing got safer; local gateway is healthy after restart.better

What changed: Fallback providers reload for live sessions, fallback-chain refresh hardening, delegation completion/session-boundary fixes, webhook route scripts off the event loop, and webhook payload filters.

Local check: Gateway is supervised by launchd at PID 4420. Fresh logs show Telegram connected, Photon sidecar listening on 127.0.0.1:8789, and gateway running with 2 platforms.

Action: None unless gateway logs start repeating errors.
Compression and long-session hygieneThe update includes a fix for compaction thrash and session-message pagination.better

What changed: Compression now has a 75% trigger floor under 512K, no summary output cap, and reasoning-trace exclusion. Session message API pagination and offset handling were fixed.

What this means: Long chats should be less likely to churn or lose useful shape during compaction.

Action: No immediate action. Watch only if long Telegram sessions behave oddly.
Matrix lazy backend refresh warningOne optional backend failed to refresh; active Telegram/Photon routes are fine.watch

What happened: During lazy backend refresh, platform.matrix failed its pip install/build refresh. Hermes kept the previous installed version.

What this means: Not a blocker for Boyd’s active Telegram/Photon setup. It matters only if Matrix is used.

Next step: If Matrix becomes relevant, rerun hermes update or test the Matrix platform backend directly.

Useful Improvements, No Decision Needed

Computer Use 0.28.2Cua Driver upgraded from 0.22.2 to 0.28.2 and retained Accessibility, Screen Recording and active MCP health.better

Action: No action. Broad Terminal Full Disk Access was not granted and is not recommended under BB security policy.

Result: Current permissions and driver health pass.
Native delivery, topic handoff and background completionv0.21.3 has stronger durable routing and delivery mechanics. Use them instead of building duplicate watchdogs.better

What remains custom: BB-specific message content, Obsidian delivery markers and policy checks still sit above the native ledger.

Action: Modernise the verifier evidence source after approval; do not delete document-specific behavior.
Config and integration validationAll eight configs are schema 45; six customised bundled skills and seven role links survived; Camofox, Context7, Kanban and session DB integrity passed.better

Action: No repair required.

Result: Critical custom setup remains compatible.
Update plans, receipts and fleet version checksHigh fit. The read-only fleet plan works now. The legacy updater could not emit the new receipt for this bootstrap run, so the next update should prove the full receipt and live gateway matrix.better

Why it fits: This Mac runs a launchd gateway plus seven profiles. `hermes update --plan` now inventories the install, running supervisor and intended restart path before mutation.

Current proof: The plan detected the launchd gateway and named `launchctl kickstart` as the intended restart route. No receipt exists for this run because the command started on v0.19 code before the receipt feature was installed.

Action: Use `hermes update --plan` before future updates and verify `logs/update_receipts/latest.json` afterward.
Cron continuity and per-job reasoning effortHigh fit later. Nineteen jobs can keep their own context and thinking level without changing the chat model.better

Why it fits: Scheduled research and verification jobs have different cost and reasoning needs. Per-job reasoning can keep simple checks cheap and reserve higher effort for analysis.

Safety boundary: Inference pins and reasoning levels are user-owned. Review jobs individually rather than changing all 19 at once.

Action: Audit the jobs first. No cron definitions changed during this update.
Mid-turn redirect and busy input modesActive on the verified v0.20.5 gateway. Corrections can steer or queue active work.better

Current state: Gateway v0.20.5 is live under current launchd supervision. Test through ordinary use.

Action: No setup change.
Native same-card Kanban reviewUseful selectively. v0.20 adds `kanban_request_review` and `kanban_request_changes`; BB’s downstream reviewer-card graph remains supported.better
Compression tuning comparisonResolved conservatively. In-place compression is enabled, safety limit is 5,000 messages and tail mode remains legacy.better
Skill evaluator on future installsGood fit. Future hub installs get a safety and quality screen before trust is granted.better

Why it fits: This setup has many local and modified skills. Install-time evaluation reduces the chance that a weak or unsafe skill enters the active prompt.

Action: No migration needed. Use the audit command before trusting optional skills.
Worktree cleanupNo immediate benefit. The live Hermes repository has no `.worktrees` inventory to reclaim.better

Current proof: `hermes worktree list --repo ~/.hermes/hermes-agent` returned nothing to reclaim.

Action: Leave it alone until worktrees accumulate.
Bot Mode and desktop UI additionsNot a current priority. The installation is Telegram and CLI led, so group-room and desktop avatar work does not solve an active problem.better

Fit: Useful only if BB deliberately moves specialist profiles into Bot Mode or the Desktop app.

Action: No setup change.
Grok 4.5 catalog supportModel catalog gained Grok 4.5 context/reasoning metadata. No route change recommended.better

What changed: The update adds grok-4.5 GA to the model catalog, with context lengths and reasoning-effort allowlist.

Action: No provider switch.
Webhook payload filtersUseful for integrations later; not needed today.better

What changed: Gateway gained webhook payload filters and docs coverage for filters plus route scripts.

Action: Park until a webhook integration needs it.

What Was Done

v0.21.3 update and validation logUpdated, recovered the failed automatic restart, migrated all profiles, tested critical integrations, audited replacements and prepared the deployed report.passed
  • Ran the full update gate from v0.20.6 at 10b38830 to v0.21.3 at 64a9b432.
  • Created and integrity-tested the full 3.4 GB rollback ZIP.
  • Migrated default plus seven worker configs to schema 45.
  • Verified current launchd gateway PID 86501, Telegram polling, Photon connection and Telegram topic message 24134.
  • Verified six customised bundled skills and all seven worker symlinks were preserved.
  • Passed memory-gate behavior tests and three external-worker wrapper regression tests.
  • Passed Camofox health and localhost binding, Computer Use 0.28.2, Context7, isolated Kanban handlers and SQLite quick_check.
  • Confirmed active cron schedules and last-run states remain intact.
  • Completed a source-backed comparison of custom safeguards against new built-in Hermes features. Nothing was automatically replaced or removed.
  • Simplified seven role manuals so native KANBAN_GUIDANCE remains the sole lifecycle authority; no Kanban runtime behavior changed.
  • Migrated B1, B2 and B4 delivery-marker proof to cron/executions.db; nine fixture tests, including all three CLI wrappers, and a real B4 repair passed.
  • Moved the static publish vault to /Users/boydbowker/Documents/ClaudeCode/Hermes_Vault and updated live skills, cron prompts, report tooling and system references.
  • Boyd chose to retain paid auxiliary-model routing. Recorded the remaining Connections decision, Photon notification limitation, orphan aliases, storage size and build-tool advisories.
  • Skipped Claude, Anthropic and paid-provider generation smokes.
  • Passed a real post-update Camofox browser navigation to example.com after investigating a separate malformed 400 request.

Historical Update Reports

2026-09-16v0.21.3 controlled update and replacement review 10b38830 to 64a9b432, 9919 commits Hermes is updated and healthy. The custom setup stays. The static report-vault move, paid auxiliary decision, role-skill cleanup and cron delivery-proof migration are complete. Connections remains open. outstanding
What Changed

Installed v0.21.3, upgraded Computer Use, migrated all eight configs to schema 45, refreshed gateway launchd state and enabled schema-default Connections entries.

Impact

Telegram, Photon, Camofox, Context7, memory-gate, worker profiles, cron inventory, Kanban mechanics and session DB integrity passed. No rollback is needed.

Decisions and Actions
  • resolved Static report vault moved to ~/Documents/ClaudeCode/Hermes_Vault and verified.
  • resolved Paid auxiliary routing retained by Boyd; no config change required.
  • resolved Seven role manuals now defer lifecycle mechanics to native KANBAN_GUIDANCE; native Kanban behavior is unchanged.
  • resolved B1, B2 and B4 marker proof now requires an exact delivered row from cron/executions.db.
  • outstanding Keep or disable the currently unavailable Connections toolset for managed app-account and local MCP connection flows.
  • monitor Leave Curator disabled until a reviewed dry-run.
Update Log
  • Full backup pre-update-2026-09-16-170022.zip passed compressed-data integrity.
  • Automatic updater restart failed from mixed modules; BB manually restarted and live gateway checks passed.
  • No native update receipt was emitted by the old updater process.
  • Default config 39 to 45; seven worker profiles 38 to 45.
  • Six customised bundled skills and seven role links preserved.
  • One later Desktop-only cosmetic commit left for the next normal update.
  • Real Camofox browser navigation to example.com passed after the final render gate.
2026-08-31Unexpected v0.20.6 update remediation closeout 8804e783 to 10b38830 Remediation Items 1 to 7, the approved Google Workspace cache cleanup and X/Twitter credential rotation are complete. The report is deployed and live verified. resolved
What Changed

Restored safe automatic update backups, repaired the gateway service definition, removed stale Stitch current-state documentation, disabled unavailable Hindsight, reconciled the native memory proposal, reviewed modified bundled skills, and completed live closeout checks.

Impact

Hermes is v0.20.6 at 10b38830. Config, gateway state, Telegram, Photon, Context7, Camofox, Computer Use and the required profile skill links passed. No update ran during remediation.

Decisions and Actions
  • resolved The v0.20.6 report is deployed and live verified at the stable URL.
  • monitor Do not start MemPalace investigation without separate approval.
Update Log
  • Automatic update backup mode is quick.
  • Gateway service definition is current and runtime reports v0.20.6 at 10b38830.
  • Telegram and Photon connected; Context7, Camofox and Computer Use passed.
  • All 7 required profile skill links are symlinks.
  • Weekly Review Planning remains intentionally customised and unchanged.
  • Google Workspace matches stock after the generated .pyc file moved to Trash.
  • Report deployed and live verified at the stable URL with v0.20.6 and 10b38830 markers.
  • Temporary verifier shutdown echoed inherited environment values into internal tool output; BB confirmed the affected X/Twitter credentials were manually rotated on 1 September 2026.
  • Moved only the regenerated Google Workspace .pyc file to Trash; CLI diff and complete hash comparison now match stock.
2026-08-23v0.19.0 to v0.20.5 mainline update d71033a4 to 8804e783, 6379 commits Large mainline update and full maintenance reconciliation completed with verified rollback, current launchd runtime and no required action remaining. resolved
What Changed

6,379 commits installed. The release includes safer update planning and receipts, mid-turn steering, session storage compaction, per-job cron reasoning, worktree cleanup, install-time skill evaluation, Bot Mode improvements and broad runtime reliability work.

Impact

Hermes is v0.20.5 at 8804e783. Config fleet schema 38, concurrency 3, memory-gate v3, stock-tracking bundled skills, compact session storage, current launchd supervision, Telegram, Photon, cron, Camofox and Computer Use all passed.

Decisions and Actions
  • outstanding Optional full-agent Kanban approve/revise proof remains separately provider-gated.
  • monitor Monitor 2 Desktop-only upstream commits and npm build-tool advisories.
  • resolved No required maintenance action remains.
Update Log
  • Preflight found v0.19.0 at d71033a4, clean tree and 6,377 commits behind.
  • Update installed 6,379 commits at 8804e783 after a verified 5.3 GB full backup.
  • Default plus 7 worker configs migrated to schema 38; concurrency remains 3.
  • Memory-gate v3 and all 8 hook registrations passed 28 durable tests.
  • BB policy moved to overlays; all affected bundled skills match stock.
  • Session storage reclaimed 3,614.5 MB and SQLite quick-check returned ok.
  • Launchd wrapper supervises the current gateway child at v0.20.5; Telegram and Photon connected.
  • Camofox HTTP 200, cron active, Context7 and Computer Use passed.
  • Claude and Anthropic checks stayed excluded. One approved Codex compression proof passed.
2026-07-27v0.18.2 to v0.19.0 mainline update b9b463f3 to d71033a4, 3145 commits Large mainline update completed with a full backup. Core services are healthy and the P0 reviewer-flow conflict was repaired. A late audit found two unresolved memory-gate defects. Security-hook repair approval and one gateway restart remain open. outstanding
What Changed

3,145 commits installed across the Quicksilver release and 1,712 later mainline commits. Major areas include startup speed, durable delivery, delegation lifecycle, multi-profile gateways, provider routing, secret sources, approvals, security and desktop/TUI performance.

Impact

Hermes is v0.19.0 at d71033a4 with a clean repo. Camofox, role-skill symlinks, Context7, Linear, Computer Use, Telegram and Photon passed. Orchestrator 2.1.1, reviewer 2.2.0 and linked guidance now match the v0.19 ownership guard; direct approve and revise runtime tests passed. Memory-gate still has an unpatched V4A bypass and session-lineage false block. The gateway service definition needs a quiet-window refresh.

Decisions and Actions
  • blocked Approve the exact memory-gate V4A path and session-lineage patch.
  • outstanding Approve hermes gateway start during a quiet window to install the new launchd safety settings.
  • monitor Watch cold-start skill scanning only if the gateway run count rises again. No Boyd action now.
  • outstanding Approve paid model calls later for one full-agent approve and revise Kanban smoke.
  • no action Do not run the suggested curl-to-shell cua-driver installer. Installed 0.7.1 is healthy.
Update Log
  • Pre-update: v0.18.2 at b9b463f3, clean tree, 3,145 commits behind d71033a4.
  • Backup completed before mutation at ~/.hermes/backups/pre-update-2026-07-27-120649.zip, 5.8 GB.
  • Update exited 0. Hermes reports v0.19.0 at d71033a4 and up to date.
  • Config version 33 passed. Repo remained clean.
  • Camofox localhost bind and health passed. The original seven role-skill symlinks passed, and the new reviewer anti-AI link makes eight.
  • Custom drift found: reviewer instructions attempted foreign task complete/block, which v0.19 rejects.
  • Orchestrator 2.1.1, reviewer 2.2.0 and linked reviewer/orchestrator guidance patched; coder success exits no longer block planned review.
  • Direct approve and revise runtime tests passed against temporary real Kanban databases.
  • Late audit found memory-gate V4A path bypass and parent-lineage false blocking; hook change remains approval-gated and unapplied.
  • Context7 and Linear MCP connected. Computer Use doctor passed.
  • Automatic cua-driver refresh failed on an incomplete upstream archive; installed 0.7.1 remained healthy.
  • Gateway hit two watchdog exits during cold-start skill scanning, then stabilised at one PID with Telegram and Photon ready.
  • Launchd definition is stale. Repair was not run because the separate restart approval timed out.
  • Hindsight live recall passed; its CLI status still misreads the local mode.
  • Claude/Anthropic and paid provider smokes were skipped by design.
2026-07-08v0.18.0 to v0.18.2 30e947e0 to 449706cb, 716 commits Reliability/speed update. Hermes is now v0.18.2; local gates passed. Matrix lazy backend refresh warned but did not block active Telegram/Photon use. monitor
What Changed

716 commits pulled. Notable changes include faster skill snapshot prompt builds, fallback-provider reload hardening, dashboard/session DB responsiveness, compression-thrash protection, webhook payload filters, session-message pagination fixes, Grok 4.5 catalog support, and broad gateway/MCP/runtime hardening.

Impact

Local system is healthy after update: repo clean, gateway supervised and freshly restarted, Telegram and Photon connected, Camofox localhost-only and healthy, all worker profile symlinks intact, Context7 and Linear MCP enabled. Matrix backend refresh warning is the only watch item.

Decisions and Actions
  • no action No workflow redesign from this update. Use the reliability improvements in place.
  • monitor Matrix lazy backend refresh warning: monitor only if Matrix is used.
  • resolved Report closeout contract: resolved for this run; report source/HTML/deploy path updated.
Update Log
  • Pre-update state: Hermes v0.18.0 at upstream 30e947e0; repo clean; update available.
  • Manual backup forced because incoming diff touched custom-risk files agent/anthropic_adapter.py and agent/prompt_caching.py.
  • Backup created: ~/.hermes/backups/pre-update-2026-07-08-222918.zip (4.6 GB). Restore command: hermes import /Users/boydbowker/.hermes/backups/pre-update-2026-07-08-222918.zip.
  • Update pulled 716 commits and installed hermes-agent==0.18.2 at upstream 449706cb.
  • Config migrated v31 to v33 with no new settings to configure.
  • CuaDriver upgraded from 0.7.0 to 0.7.1.
  • Web UI rebuilt successfully; desktop app reported up to date.
  • Warning: platform.matrix lazy backend failed to refresh; Hermes kept previous installed backend version.
  • Gateway drain timed out after 60s, then launchd restart succeeded.
  • Post-update: Hermes reports v0.18.2 (2026.7.7.2), upstream 449706cb, up to date, repo clean.
  • Gateway validation: launchd supervised PID 4420, service definition matches current install, fresh logs show Telegram connected and Photon connected.
  • Camofox validation: server.js listens on 127.0.0.1; launchd state running; health returned ok with browserConnected=true and browserRunning=true.
  • Profile symlinks: researcher, ops, coder, reviewer, writer, specifier, and orchestrator all point to shared productivity skills.
  • MCP validation: context7 and linear enabled; Dropbox MCP disabled by config.
  • Modified bundled skills kept by update: google-workspace, hermes-agent, ocr-and-documents.
  • Claude/Anthropic checks skipped by SOP because BB did not explicitly request Claude validation.
  • Live paid provider smokes and delegation smoke not run in this closeout; separate approval remains required for paid/API smokes.
2026-07-02v0.17.0 to v0.18.0 2ecca1e7d to 30e947e0, 1029 commits Major version bump. Local install is already v0.18.0 and core checks passed. The report was stale and is now being refreshed to match reality. outstanding
What Changed

v0.18.0 is the Judgment Release: P0/P1 cleanup, first-class Mixture-of-Agents, completion contracts and verification evidence, /learn and /journey, background delegation fan-out, desktop coding Projects, gateway scale-to-zero and drain coordination, Vertex AI support, and a broad security hardening round.

Impact

The local system is on v0.18.0 at upstream 30e947e0. Repo is clean. Gateway is supervised by launchd and Telegram is live. Camofox remains bound to 127.0.0.1. All seven worker profile skill symlinks survived. OpenAI Codex and Kimi smokes returned OK. The practical work now is to decide which new v0.18 capabilities are worth piloting, without turning the tool into the mission.

Decisions and Actions
  • outstanding Pilot /goal completion contracts and verification evidence on one real project before changing default workflows.
  • monitor Review first-class MoA and background delegation later as leverage tools, not as an excuse for more orchestration.
  • no action Keep current provider route: openai-codex / gpt-5.5 with Kimi fallback. No provider switch needed from this update alone.
  • outstanding Report lag incident logged as H-I-021. The process fix is to include the live update-report URL and version in every update closeout.
Update Log
  • Current local Hermes: v0.18.0 (2026.7.1) at upstream 30e947e0.
  • Deployed report was stale: it still described v0.17.0 at 2ecca1e7d.
  • Delta from deployed report head to current local head: 1029 commits.
  • Pre-check: git repo clean; origin/main delta 0; release tag v2026.7.1 present.
  • Camofox: server.js listen line still binds 127.0.0.1 and health endpoint returned ok.
  • Gateway: launchd supervised, current service definition matches install, Telegram receiving this thread.
  • Profile skills: researcher, ops, coder, reviewer, writer, specifier, and orchestrator are symlinks to shared productivity skills.
  • Provider smokes: openai-codex / gpt-5.5 returned OK; kimi-coding / kimi-k2.6 returned OK.
  • Claude/Anthropic checks skipped by SOP because Claude is not active and BB did not explicitly request Claude validation.
  • CuaDriver reports 0.7.0.
2026-06-27v0.17.0 to v0.17.0 mainline update 3e99ec0ff to 2ecca1e7d, 261 commits 261 commits, same public version. Kanban patch kept and verified. Review is complete; upstream PR package is now in progress. in progress
What Changed

Upstream Kanban added typed block reasons and loop protection. Backups now include project databases, Kanban boards, sibling stores, response store, memory store, and verification evidence. Gateway model-switching no longer blocks the event loop. Security redaction expanded. CuaDriver upgraded from 0.6.5 to 0.6.8.

Impact

Kanban patch kept and verified. Rollback coverage is now more complete. No other process changes.

Decisions and Actions
  • in progress Kanban patch formal review: complete. Recommended path is upstream PR first; local extension is fallback.
  • resolved Report template: JSON source and renderer now exist. Future reports should be generated, not hand-authored.
Update Log
  • 261 commits from 3e99ec0ff to 2ecca1e7d. Public version remains v0.17.0.
  • Pre-update: two dirty Kanban files. Local patch backed up at ~/.hermes/backups/hermes-update-20260627-225918/local-kanban-diff.patch.
  • Backup: ~/.hermes/backups/pre-update-2026-06-27-225937.zip, 3.9 GB. Snapshot 20260627-220547-pre-update.
  • Update: Python dependencies refreshed, web UI built, desktop packaged app rebuilt, CuaDriver upgraded to 0.6.8, bundled skills synced, gateway restarted.
  • Post-update verified: Hermes v0.17.0 at upstream 2ecca1e7d, Camofox localhost bind intact, profile symlinks intact, gateway launchd supervision healthy, Telegram connected, Context7 MCP passed, Linear MCP passed, Kanban patch compiles and imports.
  • Clean-up: desktop build dirtied apps/desktop/electron/main.cjs with bundled output. That source file was reverted. The desktop packaged app remains built.
  • Skipped by design: Claude/Anthropic checks and live provider smokes. Separate approval required for paid/API smokes.
2026-06-23v0.17.0 to v0.17.0 mainline update 5a53e0f0f to 5ecf3bf0e, 361 commits 361 commits, same version. Cron timeout watch carried from before this update. No Boyd decisions needed. monitor
What Changed

361 commits pulled. Package-lock.json was dirty pre-update. Incoming changes touched the Anthropic adapter. CuaDriver upgraded to 0.6.5. Python dependencies refreshed, web UI and desktop app rebuilt.

Impact

No local patches affected. Cron runs from before this update showed network timeouts. Reassessment scheduled after next cron runs.

Decisions and Actions
  • monitor Cron and network timeout watch: Mikey monitors after next scheduled runs. Not a Boyd action.
Update Log
  • 361 commits from 5a53e0f0f to 5ecf3bf0e. Public version remains v0.17.0.
  • Pre-update: one dirty file, package-lock.json. Incoming touched agent/anthropic_adapter.py, so manual backup was forced.
  • Backup: ~/.hermes/backups/pre-update-2026-06-23-160840.zip, 2.7 GB. Snapshot 20260623-151120-pre-update.
  • Update: Python dependencies refreshed, web UI built, desktop packaged app rebuilt, CuaDriver upgraded to 0.6.5, bundled skills synced.
  • Post-update verified: Hermes v0.17.0 at upstream 5ecf3bf0, repo clean, Camofox localhost bind intact, Camofox health OK, profile symlinks intact, gateway restarted under launchd, Telegram connected, Context7 MCP lookup passed, local MCP list passed.
  • Skipped by design: Claude/Anthropic checks and live provider smokes.
  • Watch: cron jobs active, but multiple last runs show network/timeouts from before this update. Reassess after next scheduled runs.
2026-06-19v0.16.0 to v0.17.0 509 commits Version bump to v0.17.0 via 509 commits. All provider checks passed. Follow-up fixes done same session. No open items. resolved
What Changed

Released hermes-agent==0.17.0. 509 commits pulled. Web UI rebuilt. Desktop packaged app rebuilt. CuaDriver upgraded to 0.5.7. SOP hook-table drift found and fixed. SOP updated to exclude Claude/Anthropic unless BB explicitly requests.

Impact

Major version jump. No breaking changes to Boyd's setup. OpenAI Codex and Kimi provider checks passed. Follow-up fixes completed in the same session.

Decisions and Actions
  • resolved CuaDriver daemon started and permissions verified.
  • resolved Cron jobs checked active.
  • resolved SOP hook-table drift fixed. Hermes update SOP now excludes Claude/Anthropic unless BB explicitly asks.
Update Log
  • 509 commits pulled locally, release v2026.6.19.
  • Pre-update: clean repo. Active provider openai-codex / gpt-5.5. Manual snapshot 20260619-215158-pre-update.
  • Backup: ~/.hermes/backups/pre-update-2026-06-19-225453.zip.
  • Update: Python package installed as hermes-agent==0.17.0, web UI built, desktop packaged app rebuilt, CuaDriver upgraded to 0.5.7, gateway restarted.
  • Post-update verified: Hermes v0.17.0, repo clean, Camofox localhost bind intact, profile symlinks intact, gateway loaded and Telegram connected, delegation smoke passed, Context7 MCP lookup passed, Kanban schema scan clean.
  • Provider checks: OpenAI Codex gpt-5.5 returned OK. Kimi kimi-k2.6 returned OK. OpenRouter smoke skipped (per-token, not required by SOP).
  • Excluded: Claude/Anthropic live checks and auth work. BB does not want Claude touched during ordinary Hermes updates.
  • Follow-up fixes done: CuaDriver daemon started and permissions verified. Cron jobs checked active. SOP hook-table drift fixed. Audit logged.
2026-06-14v0.16.0 to v0.16.0, 416 commits 6110aed9b to 4e6d05c6a, 416 commits 416 commits, same version. All checks passed. Three follow-up items all resolved later in the same period. resolved
What Changed

416 commits, same version tag, fast-forward from 6110aed9b to 4e6d05c6a. Pre-update zip backup created.

Impact

Camofox localhost patch intact, 7 profile symlinks intact, gateway service loaded, Telegram connected. Stitch MCP was not configured at this point.

Decisions and Actions
  • resolved Gateway launchd plist: now current.
  • resolved Telegram retry patch: absorbed upstream, no longer a local concern.
  • resolved Orchestrator merge: not needed. Boyd's overlay loads the stock playbook correctly.
Update Log
  • 416 commits, same version tag, fast-forward from 6110aed9b to 4e6d05c6a.
  • Pre-update: clean repo. Pre-update zip backup created at ~/.hermes/backups/pre-update-2026-06-14-202134.zip.
  • Post-update verified: Camofox localhost patch intact, 7 profile symlinks intact, gateway service loaded, Telegram connected.
  • Provider checks: OpenAI Codex, Kimi, delegation, and Context7 passed. Stitch MCP was not configured.
  • Resolved later: gateway launchd plist is now current. Telegram retry patch was absorbed upstream. Orchestrator merge is no longer needed because Boyd's overlay loads the stock playbook.
2026-06-10v0.16.0 to v0.16.0, 530 commits 5af899c7c to 6110aed9b, 530 commits 530 commits, same version. Gateway fell back to background process due to launchd bootstrap exit 5. Telegram reconnected. Drift items found and all resolved by 2026-06-14. resolved
What Changed

530 commits between 5af899c7c and 6110aed9b. Gateway fell back to background process because launchd bootstrap hit exit 5. Telegram reconnected and cron ticker ran.

Impact

Drift discovered: launchd plist stale, Telegram pause patch clobbered, degraded-send-path patch absorbed upstream. All resolved by the 2026-06-14 update session. SOP changed to make Claude smokes opt-in.

Decisions and Actions
  • resolved launchd plist stale: resolved by 2026-06-14.
  • resolved Telegram pause patch clobbered: absorbed upstream, resolved.
  • resolved Degraded-send-path patch: absorbed upstream, resolved.
  • resolved Claude Code CLI smoke and Hermes Anthropic smoke: opted out by SOP change.
Update Log
  • 530 commits between 5af899c7c and 6110aed9b.
  • Pre-update: clean repo. Auth had healthy Keychain and file credentials. Snapshot 20260610-191100-pre-update2 saved.
  • Update: gateway fell back to background process because launchd bootstrap hit exit 5. Telegram reconnected and cron ticker ran.
  • Post-update verified: Camofox localhost patch intact, 7 profile symlinks intact, gateway and Telegram reconnected.
  • Skipped per BB: Claude Code CLI smoke and Hermes Anthropic smoke. SOP changed to make Claude smokes opt-in by default.
  • Drift found: launchd plist stale, Telegram pause patch clobbered, degraded-send-path patch absorbed upstream. All resolved by 2026-06-14.
2026-06-06v0.15.1 to v0.16.0 227 commits Version bump to v0.16.0. Claude OAuth was expired; fixed during the update. All items resolved. resolved
What Changed

227 commits, tag v2026.6.5. Claude OAuth expired, only env-var credential active. Dirty repo had prompt_caching.py and package-lock noise.

Impact

Interactive Claude login ran during update. SOP-001 rewritten to use interactive login path and drop setup-token. Kanban orchestrator drift found but resolved: stock playbook load was correct, no full merge needed.

Decisions and Actions
  • resolved Claude OAuth expired: fixed. Interactive login ran, SOP-001 rewritten to use that path.
  • resolved Kanban orchestrator drift: stock playbook load resolves it. No full merge needed.
  • resolved launchd plist refreshed.
Update Log
  • 227 commits, tag v2026.6.5.
  • Pre-update: Claude OAuth expired, only env-var credential active. Dirty repo had prompt_caching.py and package-lock noise.
  • Auth fix: ran interactive Claude login, mirror, reset. SOP-001 rewritten to use that path and drop setup-token.
  • Update: clean pull after auto-stash. Pre-update zip backup created.
  • Post-update verified: Camofox localhost bind, 7 profile symlinks, gateway plus Telegram, Claude Code CLI smoke, launchd plist refresh.
  • Drift found: kanban orchestrator stock version moved ahead of Boyd's overlay. Later review found the overlay correctly loads the stock playbook, so no full merge was needed.
SOP reference: This report is generated as part of 40-Projects/claude-oauth-safety-guardrails/sops/update-gate.md. The stable URL is https://hermes-vault.pages.dev/briefs/hermes-update/.