Prebuilt Arch Linux package for NousResearch/hermes-agent — the locally-run AI agent CLI. Nothing is compiled at install time: GitHub Actions builds the complete relocatable Python environment once per upstream release and publishes the finished .pkg.tar.zst; the AUR -bin wrapper just downloads and extracts it.
yay -S hermes-agent-binThis replaces the source package hermes-agent (they conflict). Installs to
/opt/hermes-agent with the hermes launcher in /usr/bin.
PKGBUILD— the build recipe, run in CI (archlinux container, non-root makepkg, includingcheck()). Runsnpm ci+ esbuild (TUIentry.js, webweb_dist) anduv sync --lockedinto a venv on Arch'spython3.14 (upstream supports>=3.11,<3.15since v0.21.6). A venv only works on the minor version it was built for, sodepends=()pinspython>=3.14andpython<3.15. When Arch movespythonto 3.15, pacman holds that update back (pacman -Syureports the conflict) until this package follows: to 3.15 if upstream supports it by then, otherwise to a bundled standalone CPython as up to 0.21.5.package()also writes upstream'sinstall-stamp.json, where hermes reads its version from since v0.21.6.aur/PKGBUILD— the AUR wrapper, source of truth for hermes-agent-bin on the AUR. Itssourcepoints at the GitHub Release artifact, stored under a name that differs from the package makepkg writes;package()only extracts the payload (opt/andusr/).scripts/bump-pkgbuild.py— bump automation, runs every 2 hours: detects a new upstream tag, edits both PKGBUILDs +.SRCINFO, opens an auto-merge PR, and reports drift from the AUR source packagehermes-agent.scripts/check-metadata.sh— fails the build whenPKGBUILDandaur/PKGBUILDdisagree on version, dependencies, provides or conflicts..github/workflows/build.yml—bump/build/smoke/release/aur-syncpipeline.
- New upstream release: the scheduled
bumpjob checks every 2 hours, movesPKGBUILDto the new tag (tag, commit, source checksum), updatesaur/PKGBUILDand.SRCINFO, and opens an auto-merge PR. A new version starts atpkgrel=1; a new tag with an unchanged version gets the nextpkgrel(otherwise its release tag would already exist); an older version aborts the bump. An open bump PR is updated withmainon every run, because the ruleset only merges up-to-date branches. The job authenticates with theBUMP_TOKENsecret — a fine-grained PAT (Contents + Pull requests: read/write) — because the defaultGITHUB_TOKENproduces a bot-authored PR whose checks need manual approval and whose merge never triggers the release pipeline. The job logs the token identity it used and fails if the secret is missing or rejected; its read-only calls to upstream's API use the workflow token, because unauthenticated calls hit the runners' shared rate limit. The PAT is created without an expiry date, so revocation — not rotation — is the deliberate step: delete it under Settings > Developer settings > Fine-grained tokens andgh secret delete BUMP_TOKENhere and inhermes-agent-desktop-bin. - Pipeline:
build->smoke->release->aur-sync. The first two also run on pull requests (merge gate):buildrunscheck(), validatesaur/.SRCINFOand the metadata of both PKGBUILDs, and buildsaur/PKGBUILDfrom the fresh artifact the way AUR users' makepkg does — its payload must match the artifact file for file (paths, modes, links, sha256), and a rebuild must still pass the checksum.smokeinstalls the package in a clean container with the dependencies pacman resolves from itsdepends=()and checks the import, that the venv runs on the system Python, the version and upstream commithermes --versionreports, the prebuilt TUI and web bundles andhermes --help.releaseandaur-synconly run formain;releasetags the built commit and writes notes linking the upstream release and the upstream compare view, andaur-syncinjects the released artifact's sha256 intoaur/and pushes to the AUR only while its commit is stillmain's HEAD. Upstream tag and commit are pinned inPKGBUILD(_pkgver_tag,_commit). - Pausing the bump:
gh variable set BUMP_PAUSED --body truestops the scheduled bump (for example while a packaging change is in progress),gh variable delete BUMP_PAUSEDresumes it. A manual dispatch withbumpstill runs while paused. - Copies of this repository (forks, a private CI test repository): the scheduled bump and the AUR push only run in
jabla/hermes-agent-bin. Elsewhere the bump runs on manual dispatch only andaur-syncprints the diff it would push, so pipeline changes can be tested end to end without publishing anything. - Upgrading from 0.21.5 or older (bundled CPython 3.11): pacman removes the old interpreter, but files a root run of hermes created there (bytecode, packages installed into the venv) belong to no package. If pacman warns that a
python3.11directory under/opt/hermes-agentis not empty, remove it: nothing uses it any more. - Packaging-only changes (build steps, launcher, dependencies, the wrapper): bump
pkgrelin both PKGBUILDs, or the release tag already exists and nothing new is published. - Reference package:
PKGBUILDfollows the AUR source packagehermes-agent(build steps, launcher and its environment), except for the Python version (the reference usespython311from the AUR) and the install stamp. The bump job warns ("Drift from hermes-agent", also in the bump PR) when that PKGBUILD changes beyond its version fields. Review the change in its AUR history, port what applies, then setREFERENCE_PKGBUILD_SHA256inscripts/bump-pkgbuild.pyto the value the warning prints. - AUR wrapper: only
pkgver/pkgrelare bumped there; itssha256sumsis the release artifact's, computed after the build byaur-sync(a localmakepkgyields a different hash). - hermes-agent-desktop-bin runs the desktop app on this package's runtime: its launcher points the app at
/opt/hermes-agent/venv/bin/pythonand exports the same environment as/usr/bin/hermes(HERMES_DISABLE_LAZY_INSTALLS,HERMES_LAZY_INSTALL_TARGET), and its smoke job installs a pinned release artifact of this repository by its asset name. Changing the install layout, the launcher's exports or the asset names needs the same change there. - AUR key: keep
AUR_SSH_KEYas a secret of theaurenvironment, with deployment branches limited tomain— repository secrets are readable by pull requests from branches of this repository. The same key also publisheshermes-agent-desktop-bin, and AUR keys can push to every package of the account, so both repositories need the same environment setup.
Repository content: BSD Zero Clause (0BSD). The packaged app is MIT (Nous Research).