Gateway (gateway-plugin/): - Fix interactive_setup broken imports: print helpers were imported from the wrong hermes module (hermes_cli.config instead of hermes_cli.cli_output) plus a non-existent print_code; the try/except swallowed the ImportError so `hermes gateway setup` for android always bailed out early. - Fix release_scoped_lock type error (str | None passed where str required). - Rewrite empty `except: pass` blocks as contextlib.suppress with rationale. - Restructure two ambiguous ws_server try blocks (hello-auth, frame loop). - Ruff cleanup: type annotations, import sorting, line wrapping, magic values -> named constants, `raise ... from e`, complexity. Add gateway-plugin/ruff.toml. - Add pyrightconfig.json so the Python LSP resolves hermes-runtime imports. - Suppress verified false positives inline (parameterized SQL, column-name "secrets", hermes-generated media path). Android (app/androidApp + app/shared): - Consolidate launcher icons into a single mipmap-anydpi (minSdk 29 >= 26) with the monochrome layer; clears ObsoleteSdkInt + MonochromeLauncherIcon. - Bump core-splashscreen 1.0.1 -> 1.2.0; pin targetSdk 34 (deliberate). - Suppress verified findings inline (LAN ws:// default, correct GCM IV usage). Desktop (app/desktopApp): - Move the desktop to a Java 21 runtime (org.gradle.java.home) and set the desktop jvmTarget to 21 (Android stays JVM 17 / minSdk 29). Fixes the startup UnsupportedClassVersionError and restores Markdown renderer 0.44.0. Tooling/config: - .pi-lens.json: disable verified-noisy heuristics (documented in docs). - .gitleaks.toml: allowlist git-ignored false-positive paths. - docs/18-code-review.md: full findings + verification. Verified: ruff clean, pyright 0 errors, 64/64 gateway tests, all Kotlin tests, Android lint 0 issues, Android installed+launched on device, desktop launches on JDK 21.
20 lines
841 B
TOML
20 lines
841 B
TOML
# Gitleaks allowlist for iris_x_hermes.
|
|
#
|
|
# pi-lens runs `gitleaks detect --no-git` over the working tree, which includes
|
|
# git-ignored paths. The hits below are all false positives:
|
|
# - hermes-agent/ read-only research reference (never committed)
|
|
# - **/build/** Gradle / jpackage build artifacts (regenerated)
|
|
# - google-services.json standard Firebase config; its "API key" is a web
|
|
# client key restricted by package name + SHA-1, and
|
|
# the file is git-ignored (optional; FCM is inert
|
|
# without it).
|
|
title = "iris_x_hermes gitleaks allowlist"
|
|
|
|
[allowlist]
|
|
description = "Git-ignored reference tree, build artifacts, and Firebase config"
|
|
paths = [
|
|
'''^hermes-agent/''',
|
|
'''.*/build/''',
|
|
'''^app/androidApp/google-services\.json$''',
|
|
]
|