OSV weekly scan reported 50 known vulnerabilities in pinned deps. This bumps everything with a released, semver-compatible fix: Python (uv.lock): - aiohttp 3.14.1 -> 3.14.3 (GHSA-cq5v-8q36-5273, GHSA-mfx4-hv73-q22v, GHSA-mq44-7p77-q5h7) - h2 4.3.0 -> 4.4.1 (CVE-2026-71554 request smuggling; exclude-newer exception documented in pyproject, remove after 2026-08-17) npm (root workspace): - brace-expansion 5.0.8 -> 5.0.9, undici 6.27->6.28 / 7.28->7.29, js-yaml 4.3.1, nanoid 3.3.17/3.3.18, ip-address 10.4.0, mermaid 11.16.1 + dompurify 3.4.13 (root overrides so the streamdown transitive copy is pinned too) - electron 40.10.2 -> 40.10.6 (GHSA-r4w5-6pfg-jxp5; the 41.x major for GHSA-9f4c-93c8-jc8g is deferred to its own PR) npm (website): mermaid, dompurify, js-yaml, nanoid, fast-uri 3.1.5, postcss 8.5.23, undici 7.29.0 npm (photon sidecar): @opentelemetry/core 2.8.0 via override, undici npm (whatsapp-bridge): body-parser 1.20.6 min-release-age excludes added to .npmrc/website/.npmrc for the sub-2wk CVE-fix releases, each with a removal date. Remaining findings are blocked upstream: cryptography <49 cap (alibabacloud-tea-openapi), image-size (no fixed release), tar 6.x transitive majors, electron 41. Local rescan: 50 -> 19 known vulns, 0 introduced. |
||
|---|---|---|
| .. | ||
| .gitignore | ||
| README.md | ||
| index.mjs | ||
| package-lock.json | ||
| package.json | ||
| patch-spectrum-mixed-attachments.mjs | ||
| send-format.mjs | ||
| stream-staleness.mjs | ||
README.md
Photon sidecar
Small Node helper that bridges Hermes Agent to Photon's Spectrum SDK
(spectrum-ts). Hermes is Python; Photon has no public HTTP
send-message endpoint today; replies therefore go through this sidecar.
The sidecar:
- runs
Spectrum({ projectId, projectSecret, providers: [imessage.config()] }) - exposes a loopback-only HTTP control channel for the Python adapter
to push send/typing requests (auth via
X-Hermes-Sidecar-Token) - drains the inbound message stream so
spectrum-tskeeps its reconnect/heartbeat machinery alive and Hermes can receive inbound messages over the adapter's loopbackGET /inboundstream
Install
cd plugins/platforms/photon/sidecar
npm install
The Hermes plugin's hermes photon setup command runs npm install
here automatically.
Run standalone
For debugging:
PHOTON_PROJECT_ID=... PHOTON_PROJECT_SECRET=... \
PHOTON_SIDECAR_PORT=8789 PHOTON_SIDECAR_TOKEN=$(openssl rand -hex 16) \
node index.mjs
In normal use, the Python adapter supervises this process — start, restart on crash, kill on shutdown — and never asks the user to run it by hand.
Why a sidecar at all?
Photon's Spectrum send path is exposed through the TypeScript SDK's
Space.send(...) API. Hermes is Python, so replies go through this sidecar
until Photon ships a public HTTP send endpoint.
When Photon ships an HTTP send endpoint, the plan is to retire this
sidecar entirely and call it directly from Python. The plugin's
outbound code path is already isolated behind small helpers
(_sidecar_send, _sidecar_send_richlink, and _sidecar_send_attachment in
adapter.py) to make that swap localized.