[1.152.0] — 2026-08-12
Hermes provider — completed wiring + docs actualization. A detailed code review of the v1.151.0 Hermes integration surfaced two real gaps and four completeness items; all are fixed here, and the whole app's LLM-provider roster is brought up to the full seven (Anthropic → Gemini → OpenAI → Qwen → OpenRouter → GitHub Models → Hermes) across every doc surface and all 17 locales.
Fixed
#/configcould not force Hermes — theLLM_PROVIDERdropdown listed only six providers (GitHub was the last), so a user with both a cloud key and a local Hermes could setHERMES_API_KEYbut had no way to force Hermes from the UI (only by hand-editing.env).hermesis now the 8th option (auto+ 7 providers), and the field hint (config.llmProviderHint× 17 + the JS fallback) names the full seven-provider order. Newprovider-selector.test.mjsguard asserts the dropdown can never drift fromLLM_PROVIDERSagain.- Short self-hosted keys were silently rejected —
isUsableKey's 20-char floor was calibrated for cloud keys, but ahermes gateway'sAPI_SERVER_KEYis user-chosen and may be short (the Hermes docs' own examplechange-me-local-devis 19 chars).hasHermesKeynow uses a relaxed 8-char floor (still rejects empty/placeholder junk), so a legitimate short local key is no longer dropped to manual-mode without a diagnostic.
Changed
hermesChatUrlcompletes a bare host —HERMES_BASE_URL=http://127.0.0.1:8642(a mis-paste that drops the/v1) now resolves to…/v1/chat/completionsinstead of a/v1-less 404.- Manual-fallback copy in
routes/llm.mjsnow names Hermes in the "execute via …" provider list. - Provider-roster actualization — the six-provider chain/force-list strings were normalized to the full seven across README (× 17), the in-app help (× 17), the
config.llmProviderHintdict (× 17), anddocs/sdd.CONVENTIONS.mdcorrected to "all 16 non-EN locales". Assembled-dict snapshot regenerated (1214 keys).
Notes
- Security unchanged — no new route, no SSRF/CSP/sanitizer change. The relaxed key floor only affects the local-loopback Hermes gateway; the provider endpoint stays trusted config (not a scanned job URL).
HERMES_API_KEYremains aSECRET_KEY. - Health/doctor now carries a
HERMES_API_KEYrow (was omitted in v1.151.0), so#/healthandcareer-ops-ui doctorlist all seven providers. - Suite: 2392 tests (+2: the
isUsableKeyminLen guard + the dropdown-vs-LLM_PROVIDERSparity guard).