The install-time security scanner scans the whole plugin directory and
flagged the test/dev fixtures (hardcoded tokens, /tmp paths, and the
~/.hermes/.env literal in setup.py) as DANGEROUS, blocking installs with
"19 findings".
- Move gateway-plugin/tests/ to top-level tests/ so the installable
gateway-plugin/ tree contains only production code.
- Update _plugin_dir() in the tests and REPO in e2e.py for the new
location (both still resolve the live gateway-plugin/ package).
- Update all references: docs, CI-SETUP.md, Gitea workflows, .pi-lens.json.
- Build the hermes .env path at runtime in setup.py via get_hermes_home()
so the scanner no longer matches the literal ~/.hermes/.env.
Scanner verdict on gateway-plugin/ is now SAFE (0 findings); a fresh
install with scan enabled succeeds and iris appears in the setup menu.
The server (gitea.zephyre.one) exposes a Forgejo-compatible API:
- release attachments live at POST /releases/{id}/assets, not /attachments
- tag deletion is DELETE /tags/{tag}, not DELETE /git/refs/tags/{tag}
(verified against the live API: /attachments 404s, /assets and /tags exist)
- Gitea's DELETE /releases/:id does not remove the tag, so re-running the
workflow for the same version failed with 409 (curl exit 22). The
re-run safety block now also deletes the tag via git/refs/tags.
- Replace curl -sf with an api() wrapper that prints Gitea's error body
on HTTP >= 400 instead of failing silently.
- The workflow_dispatch changelog input is single-line (Gitea has no
multiline input type); convert literal \\n to real newlines and
document it in the input description.
- upload-artifact@v4+ fails on Gitea/act_runner (GHESNotSupportedError —
the GitHub artifacts API is not implemented), so merge the android,
desktop and release jobs into one: build APK+AAB + desktop zip/deb,
then create the release and upload attachments from the workspace
- jpackage --type deb needs fakeroot, which the runner image lacks —
install it via apt
- sync CI-SETUP.md §3 with the restructured workflow
- pytest lives in hermes-agent's dev extra; plain uv sync left the CI venv
without it and run_tests.sh refused to run (gateway job)
- 'yes | sdkmanager --licenses' dies with SIGPIPE (exit 141) under Gitea's
bash -e -o pipefail; feed a finite number of y's from a file instead
(kotlin + android jobs)
- release.yml android job: build APK + AAB (bundleRelease/bundleDebug)
- androidApp: versionCode overridable via -PappVersionCode (Play requires
an incrementing versionCode per upload)
- make_release_keystore.sh: PKCS12 has no separate key password (keytool
ignores -keypass) — print the store password for ANDROID_KEY_PASSWORD