Hermes Agent 0.21.6 is out for Docker, Hermes Cloud and command-line installs, bringing several security fixes and a new stable-release pipeline. It is a substantial patch, but not every Hermes user gets it yet: the desktop app, Termux packages and Microsoft Store build remain unchanged for now.
Nous/Hermes Watch analysis
What happened
NousResearch’s release notes describe 0.21.6 as a patch release rolling up roughly 2,100 merged pull requests since 0.21.5. It is the first release made with a new pipeline that the project says produces a tested Docker image and a receipt tag at publication. The release notes say users can update Docker or Hermes Cloud with the stable or latest image tag; CLI users can run hermes update or rerun the installer.
The notes list fixes for dashboard authentication, including a sign-in redirect issue that could allow session takeover, and for automatic Git operations that could run programs configured by an untrusted repository. They also describe hardening around login rate limits, audit-log writes and request-body size limits. These are issues the project says it has fixed, not an independent assessment of their severity or exposure.
Our top picks
- A tested Docker image in the release process
The new pipeline is designed to publish a tested image alongside the tag, giving operators a clearer release artefact to deploy. - A fix for a sign-in redirect flaw
The project says native sign-in could send login codes to a non-loopback redirect, enabling session takeover. - Safer automatic Git operations
The release prevents automatic Git calls from running filter programs defined in an untrusted repository’s configuration. - More controls around dashboard authentication
The listed fixes address spoofed rate-limit headers, unbounded audit-log values and missing request-body size limits. - A clear divide between delivery channels
Docker, Hermes Cloud and CLI users get this release now; desktop, Termux and Microsoft Store users do not.
Why it matters
Hermes can work with repositories and handle sign-in, so flaws in automatic Git behaviour or authentication are more than housekeeping. The release notes give affected users concrete fixes to check for, while the new pipeline makes the project’s release process easier to understand. The catch is practical: installing the newest tag will not update every supported build.
Our read
This is a worthwhile update for operators on the channels it covers. Check which Hermes build you run, then use the project’s stated update route if you are on Docker, Hermes Cloud or a Git-based CLI install. Desktop and Termux users should not assume the patch has arrived simply because the release tag exists. A release pipeline is only as useful as the builds it reaches.
What to watch
- When the next bundled release reaches the desktop app, Termux and Microsoft Store.
- Whether NousResearch publishes fuller curated notes with version 0.22.0, as promised.
- How the new stable-release pipeline handles future releases and updates.
Discussion spark: Should projects publish important security fixes in staggered releases when desktop and mobile users remain on older builds, or hold back until every channel can update together?
Sources and evidence
- Releases · open-webui/open-webui · GitHub (Publication date not supplied)
Nous/Hermes Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by Nous Research.