Repository navigation
feat(hermes): bump Hermes Agent to v2026.6.19 - #5594
Conversation
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
…arts Hermes v0.16.0+ guards its OpenAI-compatible API server with a bearer token read from API_SERVER_KEY. Without it the gateway refuses to start, so the install health check fails. - Generate a per-sandbox API_SERVER_KEY into the Hermes .env. - Allow that single raw key past the secret-boundary validator (env-file and runtime-env), mirroring OPENCLAW_GATEWAY_TOKEN: it is a self-minted, loopback-only token, not an egress credential, so it legitimately lives raw in .env rather than as an openshell:resolve placeholder. - Accept HTTP 401 (not just 200) as "gateway alive" in the in-sandbox health wait, since the probe is unauthenticated and v0.16 may 401 it. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The v0.16 gateway's bearer token was minted but not retrievable, so users
had no way to call the OpenAI-compatible API.
- Add an agent web-auth model (AgentWebAuth { method, env }) read from the
manifest; Hermes is bearer_token/API_SERVER_KEY, OpenClaw stays none.
- Make `gateway-token` agent-aware: it now returns a bearer_token agent's
web-auth key (Hermes' API_SERVER_KEY) as well as OpenClaw's gateway token,
reading it group-readably from the sandbox .env without ever logging it.
- Onboard prints the OpenAI-compatible API endpoint and the retrieval
command for bearer_token agents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Three independent v0.16 install/runtime regressions: - Vendor python-multipart (pinned + hash-verified to the release's uv.lock) so the bundled kanban dashboard plugin's file-upload route mounts. It is not a dependency of hermes core or the `web` extra (only of mcp/daytona), so a slim extras install omits it; FastAPI then fails the Form/File route. Vendored directly rather than pulling the MCP client or the Daytona SDK. - Grant /dev/pts in both Hermes sandbox policies. The TUI, the dashboard chat pty bridge, and terminal.backend: local allocate a pty via openpty(); without the grant landlock denies /dev/ptmx with EACCES, surfaced as "out of pty devices". Mirrors the existing OpenClaw grant (#4513). - Fix the bump script's post-rebuild verify to use `exec` not `connect`: connect is a strict interactive shell that ignores a trailing `-- <cmd>` and just prints its usage, so the version check always failed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The model picker (CLI `hermes model` and the dashboard Models page via /api/model/options) showed zero models even though inference worked: it enumerates providers through get_compatible_custom_providers(), which only reads custom_providers/providers — never the inline `model:` block NemoClaw writes for routing. Emit a custom_providers entry mirroring the proxied endpoint (inference.local/v1) with discover_models: true, so the picker live-lists /v1/models (already served by the proxy and allowlisted in policy). Verified live: the picker then lists the routed models with is_current set. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…routed model The Hermes dashboard runs as the sandbox user under its own isolated HERMES_HOME (/tmp/hermes-dashboard-home) for privilege separation from the gateway user, so it never sees the model/custom_providers block NemoClaw writes to the gateway's /sandbox/.hermes/config.yaml. Its load_config() reads a Hermes-default config with model: '' and no providers, so the dashboard Models page (/api/model/options -> inventory.build_models_payload) listed zero models and the kanban specifier/dispatcher (get_text_auxiliary_client) resolved no client — even though the TUI/CLI on the gateway home worked. Verified live. Add seed-dashboard-config.py, invoked from start.sh::seed_hermes_dashboard_config before the dashboard launches, mirroring model/custom_providers/_nemoclaw_upstream into the dashboard home config while preserving its other keys. custom_providers carries discover_models: true so the model list stays live-discovered from /v1/models rather than pinned. Idempotent, symlink-guarded, best-effort (a seed failure never blocks startup). Confirmed end-to-end in a live sandbox: the dashboard then lists the 3 routed models and kanban resolves nvidia-routed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
generate-hermes-config.test.ts's findRawSecretEnvEntries flagged the raw API_SERVER_KEY messaging-config.ts writes to .env, but the production validator (validate-env-secret-boundary.py) already exempts it via ENV_FILE_ALLOWED_RAW_SECRET_KEYS — it is Hermes' self-generated api_server bearer token (v0.16.0+) that never transits the OpenShell proxy, so it has no resolver placeholder. Mirror that allowlist in the test helper. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Seed the Hermes dashboard's config so the Models page and kanban see the routed model, mirror the routed provider, and align Dockerfile.base/start.sh with the v0.16 dashboard launch path.
start.sh invoked seed-dashboard-config.py with bare `python3`, which at
container boot is the base-image interpreter without PyYAML (an interactive
login shell activates the venv, masking this). The seeder then hit its
"PyYAML unavailable; skipping model seed" branch and returned 0, so the
gateway's model routing was silently never mirrored into the dashboard
HERMES_HOME — leaving model:'' / providers:{} and an empty Models page after
a rebuild. Resolve the Hermes venv interpreter explicitly
(/opt/hermes/.venv/bin/python, fallback python3) and run the seeder with it.
That binary is already an allowlisted blueprint binary and the prefer-venv
fallback idiom is used elsewhere in the repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… add hermes doctor --fix Agent-Logs-Url: https://github.com/tyeth-ai-assisted/NemoClaw/sessions/cc04407b-b2a0-4a6b-8625-2512fab13384 Co-authored-by: tyeth-ai-assisted <259968460+tyeth-ai-assisted@users.noreply.github.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughThis PR upgrades Hermes to v2026.6.19 with Node 24, introduces bearer-token web auth with auto-generated ChangesHermes v16 runtime, auth, and packaging updates
Sequence DiagramssequenceDiagram
participant CLI as GatewayTokenCliCommand
participant CMD as runGatewayTokenCommand
participant Bridge as GatewayTokenRuntimeBridge
participant FetchBT as fetchAgentWebAuthTokenFromSandbox
participant FetchOC as fetchGatewayAuthTokenFromSandbox
CLI->>Bridge: getSandboxAgent(sandboxName)
Bridge-->>CMD: agentName
CMD->>Bridge: agentExposesToken(agentName)
alt bearer_token agent (e.g. hermes)
Bridge->>FetchBT: runCaptureOpenshell grep API_SERVER_KEY
FetchBT-->>Bridge: token string
else openclaw or null
Bridge->>FetchOC: fetchGatewayAuthTokenFromSandbox(sandboxName)
FetchOC-->>Bridge: gateway token
end
Bridge-->>CMD: fetchToken result
CMD->>CLI: print token to stdout
sequenceDiagram
participant StartSH as start.sh
participant Seeder as seed-dashboard-config.py
participant GWConfig as gateway config.yaml
participant GWEnv as gateway .env
participant DashYAML as dashboard config.yaml
participant DashEnv as dashboard .env
StartSH->>Seeder: python seed-dashboard-config.py
Seeder->>GWConfig: yaml.safe_load gateway config
Seeder->>Seeder: normalize routing, synthesize providers
Seeder->>DashYAML: atomic write with symlink guard
Seeder->>GWEnv: read and filter
Seeder->>DashEnv: atomic mirror at 0600 with symlink guard
Seeder-->>StartSH: exit 0 or 1
StartSH->>DashYAML: chown + chmod 600
StartSH->>DashEnv: chown + chmod 600
Estimated code review effort🎯 4 (Complex) | ⏱️ ~75 minutes Possibly related PRs
Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in the Show a code coverage summary of the most covered files.
TypeScript / code-coverage/cliThe overall coverage in the Show a code coverage summary of the most covered files.
Updated |
E2E Advisor RecommendationRequired E2E: Dispatch hint: Auto-dispatched E2E: Full advisor summaryE2E Recommendation AdvisorBase: Required E2E
Optional E2E
New E2E recommendations
Dispatch hint
|
Vitest E2E Scenario RecommendationRequired Vitest E2E scenarios: Dispatch required Vitest E2E scenarios:
Full Vitest E2E advisor summaryVitest E2E Scenario AdvisorBase: Required Vitest E2E scenarios
Optional Vitest E2E scenarios
Relevant changed files
|
There was a problem hiding this comment.
Actionable comments posted: 5
🧹 Nitpick comments (1)
agents/hermes/seed-dashboard-config.py (1)
323-334: 🧹 Nitpick | 🔵 Trivial | 💤 Low valueConsider setting restrictive permissions on config.yaml before atomic replace.
The
.envfile getschmod 0o600on the temp file beforeos.replace()(line 249), but the config.yaml write doesn't. Whilestart.shapplieschmod 600after seeding (line 708), the config file could briefly exist with default umask permissions betweenos.replace()and the caller'schmod. This is a minor inconsistency since the dashboard home dir is alreadychmod 700.Suggested fix for consistency
try: with open(tmp, "w", encoding="utf-8") as handle: yaml.safe_dump(dashboard, handle, sort_keys=False) + os.chmod(tmp, 0o600) os.replace(tmp, dst)🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@agents/hermes/seed-dashboard-config.py` around lines 323 - 334, The temporary file written in the dashboard config seeding block does not have restrictive permissions set before the atomic replace operation, creating a brief window where the file could exist with default umask permissions. In the try block where the YAML is dumped to the tmp file and before the os.replace(tmp, dst) call, add an os.chmod(tmp, 0o600) call to set restrictive permissions on the temporary file, matching the pattern used for the .env file seeding mentioned in the review comment, ensuring consistency and security of the configuration file.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@agents/hermes/start.sh`:
- Line 724: The function seed_hermes_dashboard_config is being called
redundantly in the start.sh script. Since prepare_hermes_dashboard_home already
calls seed_hermes_dashboard_config with the owner argument internally, the
additional calls to seed_hermes_dashboard_config at lines 724 and 738 are
unnecessary and should be removed entirely. This will eliminate duplicate work
on every dashboard launch while maintaining the same functionality, as the
seeding is still handled by the prepare_hermes_dashboard_home invocation.
In `@scripts/update-hermes-agent.sh`:
- Around line 84-89: The prerequisite tool check in the for loop iterating
through curl, python3, npm, sha256sum, tar, and sed does not include realpath,
which is required by the discover_installed_dockerfiles function but will only
fail later with an unclear error message. Add realpath to the list of tools
being validated in the for loop to ensure this dependency is checked upfront
with a clear error message.
- Around line 336-339: The parameter expansion ${BASE_REF%:*} in the pin_tag
assignment incorrectly strips everything after the last colon regardless of
whether it is a registry port or an image tag. For references like
localhost:5000/hermes-base without an explicit tag, this strips the port number
leaving only localhost. Fix this by checking whether BASE_REF contains an image
tag (a colon that appears after the last forward slash) before stripping it.
Only apply the %:* pattern if a tag actually exists in BASE_REF, otherwise
append the new tag directly to the full BASE_REF value.
In `@src/lib/agent/defs.ts`:
- Around line 317-334: In the readWebAuth function, the env variable is not
being normalized to null when the method is normalized to "none". Currently, if
web_auth_method is not "bearer_token", the method is set to "none", but env
retains whatever value was assigned from the rawEnv validation check. To fix
this, after determining that method is "none" (meaning web_auth_method is not
"bearer_token"), explicitly set env to null before returning the object to
ensure the AgentWebAuth contract is honored where env should only be non-null
when method is "bearer_token".
In `@test/cli/snapshot-shields.test.ts`:
- Line 52: The `it()` function on line 52 is being called with a fourth
positional argument `15_000`, which exceeds Vitest's API that only accepts up to
3 arguments. Since the timeout is already configured via
`testTimeoutOptions(30_000)` passed as the second argument, remove the trailing
`15_000` argument from the `it()` call to match the correct API signature.
---
Nitpick comments:
In `@agents/hermes/seed-dashboard-config.py`:
- Around line 323-334: The temporary file written in the dashboard config
seeding block does not have restrictive permissions set before the atomic
replace operation, creating a brief window where the file could exist with
default umask permissions. In the try block where the YAML is dumped to the tmp
file and before the os.replace(tmp, dst) call, add an os.chmod(tmp, 0o600) call
to set restrictive permissions on the temporary file, matching the pattern used
for the .env file seeding mentioned in the review comment, ensuring consistency
and security of the configuration file.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 2ffc0b1a-1213-451c-aa69-d390fe38af23
📒 Files selected for processing (34)
agents/hermes/Dockerfileagents/hermes/Dockerfile.baseagents/hermes/config/hermes-config.tsagents/hermes/config/hermes-env.tsagents/hermes/config/yaml.tsagents/hermes/manifest.yamlagents/hermes/policy-additions.yamlagents/hermes/policy-permissive.yamlagents/hermes/seed-dashboard-config.pyagents/hermes/start.shagents/hermes/validate-env-secret-boundary.pyscripts/update-hermes-agent.shsrc/commands/sandbox/gateway/token.tssrc/commands/simple-global-oclif-adapters.test.tssrc/lib/agent/base-image.test.tssrc/lib/agent/defs.test.tssrc/lib/agent/defs.tssrc/lib/agent/hermes-recovery-boundary-fixtures.tssrc/lib/agent/onboard.test.tssrc/lib/agent/onboard.tssrc/lib/agent/runtime.test.tssrc/lib/gateway-token-command.test.tssrc/lib/gateway-token-command.tssrc/lib/onboard.tssrc/lib/onboard/dashboard-web-auth-token.test.tssrc/lib/onboard/dashboard.tstest/cli/doctor-gateway-token.test.tstest/cli/snapshot-shields.test.tstest/generate-hermes-config.test.tstest/hermes-share-mount-deps.test.tstest/hermes-start.test.tstest/onboard-gateway-runtime.test.tstest/sandbox-provisioning.test.tstest/seed-hermes-dashboard-config.test.ts
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Selective E2E Results — ❌ Some jobs failedRun: 27973065752
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Selective E2E Results — ❌ Some jobs failedRun: 27973695448
|
PR Review Advisor — No blocking findingsMerge posture: No blocking advisor findings Action checklist
Test follow-ups to resolve or justifyIf these cover changed behavior, prefer adding them in this PR; otherwise state why existing coverage is enough or link the follow-up.
This is an automated, non-binding review; it still expects maintainers and agents to respond to each required or warning item. Treat suggestions as current-PR improvements when they touch changed code; defer only with maintainer rationale or a linked follow-up. A human maintainer must make the final merge decision. |
Selective E2E Results — ❌ Some jobs failedRun: 27974261930
|
Selective E2E Results — ✅ All requested jobs passedRun: 28194483287
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
|
Processed PR Review Advisor follow-ups for head Required advisor items handled in code:
Runtime-validation follow-ups:
Acceptance-clause follow-up:
Local validation run before pushing this head:
|
Selective E2E Results — ✅ All requested jobs passedRun: 28195533141
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Selective E2E Results — ✅ All requested jobs passedRun: 28196107154
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Selective E2E Results — ✅ All requested jobs passedRun: 28197637423
|
## Summary Adds the v0.0.69 release notes to the published release-notes page so users can see the shipped sandbox recovery, Deep Agents Code, Hermes, inference, policy, and release-validation changes. The section is based on the v0.0.69 announcement and links each user-facing theme to the deeper docs pages that already cover the behavior. ## Changes - Added a new `v0.0.69` section to `docs/about/release-notes.mdx`. - Linked release-note themes to lifecycle, backup, troubleshooting, Deep Agents Code, commands, workspace, messaging, Hermes, inference, security, monitoring, and network-policy docs. Source summary: - #5455 -> `docs/about/release-notes.mdx`: Summarized persistent workspace and state cleanup during sandbox destroy. - #5738 -> `docs/about/release-notes.mdx`: Summarized nonzero exit status preservation for failed hosted endpoint validation. - #5786 -> `docs/about/release-notes.mdx`: Summarized live sandbox rediscovery when local registry state is missing. - #5881 -> `docs/about/release-notes.mdx`: Summarized the `nemo-deepagents` alias command surface. - #5594 -> `docs/about/release-notes.mdx`: Summarized the Hermes Agent 2026.6.19 update. - #5777 -> `docs/about/release-notes.mdx`: Summarized manifest-derived messaging channel support. - #5825 -> `docs/about/release-notes.mdx`: Summarized DeepSeek V4 Flash managed-vLLM defaults for DGX Station. - #5877 -> `docs/about/release-notes.mdx`: Summarized provider switch metadata preservation. - #5932 -> `docs/about/release-notes.mdx`: Summarized transient inference smoke retry behavior. - #5934 -> `docs/about/release-notes.mdx`: Summarized constrained inference smoke retry boundaries. - #5681 -> `docs/about/release-notes.mdx`: Summarized Shields config-hash sealing during auto-restore. - #5682 -> `docs/about/release-notes.mdx`: Summarized sandbox connect process-limit enforcement. - #5683 -> `docs/about/release-notes.mdx`: Summarized JSON agent failure provenance warnings. - #5711 -> `docs/about/release-notes.mdx`: Summarized sparse-source log breadcrumbs. - #5838 -> `docs/about/release-notes.mdx`: Summarized host-authoritative Shields status. - #5880 -> `docs/about/release-notes.mdx`: Summarized policy round-trip documentation updates. - #5886 -> `docs/about/release-notes.mdx`: Summarized network request approval-flow documentation updates. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [x] Tests not applicable — justification: doc-only release-notes prose; no runtime behavior changed. - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Verification - [x] PR description includes the DCO sign-off declaration and every commit appears as `Verified` in GitHub - [x] Git hooks passed during commit and push, or `npx prek run --from-ref main --to-ref HEAD` passes - [ ] Targeted tests pass for changed behavior - [ ] Full `npm test` passes (broad runtime changes only) - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) `npm run docs` passed with 0 errors and the existing Fern light-mode accent contrast warning. `fern check --warnings` reported the same accent-color warning. --- Signed-off-by: Miyoung Choi <miyoungc@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added release notes for **v0.0.69**, covering improved sandbox lifecycle recovery (state preservation across destroy/recreate/rebuild/recovery/validation failures), clearer Deep Agents Code terminal/CLI behavior, and safer Hermes messaging/provider switching with manifest-driven channels. * Improved inference setup validation guidance, including handling of local/compatible endpoints and redaction of sensitive validation errors. * Refreshed release-gate documentation with clearer approval examples and validation behavior for NVIDIA API keys vs hosted inference keys. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Summary Refs NVIDIA#5591 for the Hermes dependency-upgrade slice. - Bumps Hermes to `v2026.6.19` / `hermes-agent@0.17.0`. - Pins the Hermes release tarball SHA256 and npm integrity, with `scripts/update-hermes-agent.sh` check support. - Carries the Hermes v0.16+ integration work needed for the current runtime shape: bearer-token API access, dashboard/model-picker config, dashboard-home seeding, npm workspace build handling, `/dev/pts` access, `python-multipart`, and Hermes secret-boundary updates. - Updates NemoClaw CLI/dashboard token plumbing so `gateway-token` can retrieve a bearer-token agent key when the manifest declares one. ## Validation - `npm install --ignore-scripts` - `npm run build:cli` - `npm run typecheck` - `scripts/update-hermes-agent.sh --check --tag v2026.6.19` - `python3 -m py_compile agents/hermes/seed-dashboard-config.py agents/hermes/runtime-config-guard.py agents/hermes/validate-env-secret-boundary.py` - `bash -n agents/hermes/start.sh scripts/update-hermes-agent.sh test/e2e/test-hermes-sandbox-secret-boundary.sh test/e2e/test-hermes-root-entrypoint-smoke.sh` - `npx vitest run --project cli test/hermes-runtime-api-key.test.ts test/hermes-start.test.ts src/lib/agent/defs.test.ts test/cli/snapshot-shields.test.ts test/update-hermes-agent-script.test.ts test/seed-hermes-dashboard-config.test.ts test/hermes-share-mount-deps.test.ts test/sandbox-provisioning.test.ts` - `npm run test-conditionals:scan -- --top 25` - `npx prek run --all-files --stage pre-push --skip tsc-plugin --skip tsc-js --skip tsc-cli --skip version-tag-sync --skip test-cli --skip test-plugin --skip source-shape-test-budget --skip test-file-size-budget --skip test-skills-yaml` - `npm run source-shape:check` - `npm run test-size:check` - `npx vitest run test/skills-frontmatter.test.ts` - `python3 scripts/generate-platform-docs.py --check` - `git diff --check` - GitHub PR checks on head `ff03680e4c3c24fe04df3631331380aaa0e8e9cb`: PR Review Advisor, E2E recommendation, CodeQL, ShellCheck, sandbox image builds, required static/CLI checks, and PR-gated E2E smoke jobs all passing. ## Review Notes - PR Review Advisor is green on head `ff03680e4c3c24fe04df3631331380aaa0e8e9cb` with no blocking findings; the prior `API_SERVER_KEY`/runtime-config and workspace-lockfile findings are resolved by code and focused regression coverage. - The remaining `PRA-T1` acceptance-clause follow-up is justified against NVIDIA#5591, which is a broad design/dependency proposal without concrete acceptance clauses; the changed Hermes behavior is covered by the validation above and the passing PR checks. - Earlier broad Vitest E2E result comments are historical for older heads/all-job dispatches. The latest required PR checks and E2E recommendation are green on the current head. - Docker was not run locally, but GitHub `build-sandbox-images` and `build-sandbox-images-arm64` both passed on the current head. Signed-off-by: Aaron Erickson <aerickson@nvidia.com> --------- Signed-off-by: Aaron Erickson <aerickson@nvidia.com> Co-authored-by: tyeth <tyethgundry@googlemail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: anthropic-code-agent[bot] <242468646+Claude@users.noreply.github.com> Co-authored-by: tyeth-ai-assisted <259968460+tyeth-ai-assisted@users.noreply.github.com> Co-authored-by: Carlos Villela <cvillela@nvidia.com>
## Summary Adds the v0.0.69 release notes to the published release-notes page so users can see the shipped sandbox recovery, Deep Agents Code, Hermes, inference, policy, and release-validation changes. The section is based on the v0.0.69 announcement and links each user-facing theme to the deeper docs pages that already cover the behavior. ## Changes - Added a new `v0.0.69` section to `docs/about/release-notes.mdx`. - Linked release-note themes to lifecycle, backup, troubleshooting, Deep Agents Code, commands, workspace, messaging, Hermes, inference, security, monitoring, and network-policy docs. Source summary: - NVIDIA#5455 -> `docs/about/release-notes.mdx`: Summarized persistent workspace and state cleanup during sandbox destroy. - NVIDIA#5738 -> `docs/about/release-notes.mdx`: Summarized nonzero exit status preservation for failed hosted endpoint validation. - NVIDIA#5786 -> `docs/about/release-notes.mdx`: Summarized live sandbox rediscovery when local registry state is missing. - NVIDIA#5881 -> `docs/about/release-notes.mdx`: Summarized the `nemo-deepagents` alias command surface. - NVIDIA#5594 -> `docs/about/release-notes.mdx`: Summarized the Hermes Agent 2026.6.19 update. - NVIDIA#5777 -> `docs/about/release-notes.mdx`: Summarized manifest-derived messaging channel support. - NVIDIA#5825 -> `docs/about/release-notes.mdx`: Summarized DeepSeek V4 Flash managed-vLLM defaults for DGX Station. - NVIDIA#5877 -> `docs/about/release-notes.mdx`: Summarized provider switch metadata preservation. - NVIDIA#5932 -> `docs/about/release-notes.mdx`: Summarized transient inference smoke retry behavior. - NVIDIA#5934 -> `docs/about/release-notes.mdx`: Summarized constrained inference smoke retry boundaries. - NVIDIA#5681 -> `docs/about/release-notes.mdx`: Summarized Shields config-hash sealing during auto-restore. - NVIDIA#5682 -> `docs/about/release-notes.mdx`: Summarized sandbox connect process-limit enforcement. - NVIDIA#5683 -> `docs/about/release-notes.mdx`: Summarized JSON agent failure provenance warnings. - NVIDIA#5711 -> `docs/about/release-notes.mdx`: Summarized sparse-source log breadcrumbs. - NVIDIA#5838 -> `docs/about/release-notes.mdx`: Summarized host-authoritative Shields status. - NVIDIA#5880 -> `docs/about/release-notes.mdx`: Summarized policy round-trip documentation updates. - NVIDIA#5886 -> `docs/about/release-notes.mdx`: Summarized network request approval-flow documentation updates. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [x] Tests not applicable — justification: doc-only release-notes prose; no runtime behavior changed. - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Verification - [x] PR description includes the DCO sign-off declaration and every commit appears as `Verified` in GitHub - [x] Git hooks passed during commit and push, or `npx prek run --from-ref main --to-ref HEAD` passes - [ ] Targeted tests pass for changed behavior - [ ] Full `npm test` passes (broad runtime changes only) - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) `npm run docs` passed with 0 errors and the existing Fern light-mode accent contrast warning. `fern check --warnings` reported the same accent-color warning. --- Signed-off-by: Miyoung Choi <miyoungc@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added release notes for **v0.0.69**, covering improved sandbox lifecycle recovery (state preservation across destroy/recreate/rebuild/recovery/validation failures), clearer Deep Agents Code terminal/CLI behavior, and safer Hermes messaging/provider switching with manifest-driven channels. * Improved inference setup validation guidance, including handling of local/compatible endpoints and redaction of sensitive validation errors. * Refreshed release-gate documentation with clearer approval examples and validation behavior for NVIDIA API keys vs hosted inference keys. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Summary
Refs #5591 for the Hermes dependency-upgrade slice.
v2026.6.19/hermes-agent@0.17.0.scripts/update-hermes-agent.shcheck support./dev/ptsaccess,python-multipart, and Hermes secret-boundary updates.gateway-tokencan retrieve a bearer-token agent key when the manifest declares one.Validation
npm install --ignore-scriptsnpm run build:clinpm run typecheckscripts/update-hermes-agent.sh --check --tag v2026.6.19python3 -m py_compile agents/hermes/seed-dashboard-config.py agents/hermes/runtime-config-guard.py agents/hermes/validate-env-secret-boundary.pybash -n agents/hermes/start.sh scripts/update-hermes-agent.sh test/e2e/test-hermes-sandbox-secret-boundary.sh test/e2e/test-hermes-root-entrypoint-smoke.shnpx vitest run --project cli test/hermes-runtime-api-key.test.ts test/hermes-start.test.ts src/lib/agent/defs.test.ts test/cli/snapshot-shields.test.ts test/update-hermes-agent-script.test.ts test/seed-hermes-dashboard-config.test.ts test/hermes-share-mount-deps.test.ts test/sandbox-provisioning.test.tsnpm run test-conditionals:scan -- --top 25npx prek run --all-files --stage pre-push --skip tsc-plugin --skip tsc-js --skip tsc-cli --skip version-tag-sync --skip test-cli --skip test-plugin --skip source-shape-test-budget --skip test-file-size-budget --skip test-skills-yamlnpm run source-shape:checknpm run test-size:checknpx vitest run test/skills-frontmatter.test.tspython3 scripts/generate-platform-docs.py --checkgit diff --checkff03680e4c3c24fe04df3631331380aaa0e8e9cb: PR Review Advisor, E2E recommendation, CodeQL, ShellCheck, sandbox image builds, required static/CLI checks, and PR-gated E2E smoke jobs all passing.Review Notes
ff03680e4c3c24fe04df3631331380aaa0e8e9cbwith no blocking findings; the priorAPI_SERVER_KEY/runtime-config and workspace-lockfile findings are resolved by code and focused regression coverage.PRA-T1acceptance-clause follow-up is justified against [NemoClaw] Dependency Updates (Hermes, OpenShell, OpenClaw) #5591, which is a broad design/dependency proposal without concrete acceptance clauses; the changed Hermes behavior is covered by the validation above and the passing PR checks.build-sandbox-imagesandbuild-sandbox-images-arm64both passed on the current head.Signed-off-by: Aaron Erickson aerickson@nvidia.com