Six contributor PRs were shipped via the cherry-pick/absorb path but their
absorb commits never carried a `Co-authored-by:` trailer, so the contributors
received zero commit credit on their GitHub contribution graphs. Three of them
(@antoniocarlos97ss, @liuqiangweb-svg, @pix0127) were also missing from
CONTRIBUTORS.md entirely; the other three (@AJV20, @mysoul12138) were already
listed via CHANGELOG attribution but still lacked the graph credit.
This commit:
- Adds the three missing contributors to CONTRIBUTORS.md (single-PR section).
- Carries Co-authored-by trailers for all six so each gets a real commit on
their contribution graph (the non-history-rewrite way to repair this).
- Bumps the tracked totals (194 -> 197 contributors, 843 -> 846 credits).
The shipped work, by PR:
#2622 (@pix0127) WebUI dashboard plugin system w/ iframe isolation
#2931 (@liuqiangweb-svg) Edge TTS as an alternative speech engine
#3104 (@antoniocarlos97ss) workspace file upload + drag-drop w/ archive extract
#3220 (@AJV20) generated media artifact cards
#3223 (@AJV20) manual session title regeneration
#3337 (@mysoul12138) syntax highlighting in workspace file preview
Co-authored-by: pix0127 <8500500+pix0127@users.noreply.github.com>
Co-authored-by: Andy <281253538+liuqiangweb-svg@users.noreply.github.com>
Co-authored-by: antoniocarlos97ss <101895404+antoniocarlos97ss@users.noreply.github.com>
Co-authored-by: AJV20 <24819659+AJV20@users.noreply.github.com>
Co-authored-by: mysoul12138 <203929894+mysoul12138@users.noreply.github.com>
19 KiB
Contributors
Hermes WebUI is a community project. 194 people have shipped code that landed in a release tag — including the long tail of folks whose work was salvaged into batch releases or absorbed via Co-authored-by trailers. This file is the canonical credit roll.
A contributor's PR count is the number of distinct PRs they get credit for: PRs they authored that merged directly, PRs they authored that were closed-but-absorbed into a release commit (batch merges, salvage rewrites, cherry-picked-and-attributed work), and PRs where they were explicitly attributed in CHANGELOG.md. All count the same.
Total contributors tracked: 197 Total PR credits: 846 Last refreshed: v0.51.217, 2026-06-02 (attribution backfill — 3 absorbed-PR contributors that lacked CONTRIBUTORS.md entries; see PR description)
Generated by scripts/regen_contributors.py in the maintainer workspace, which unions three sources: the GitHub merged-PR list, CHANGELOG.md attribution lines, and Co-authored-by: trailers on commits that landed on master (the canonical signal for a CLOSED PR whose commits were cherry-picked in and attributed). If your name is missing or wrong, open a PR against CONTRIBUTORS.md — we cross-check against the changelog on each release.
Top contributors (5+ PRs landed)
| # | Contributor | PRs | First release | Latest release |
|---|---|---|---|---|
| 1 | @franksong2702 | 148 | v0.49.3 |
v0.51.153 |
| 2 | @Michaelyklam | 117 | v0.50.240 |
v0.51.139 |
| 3 | @bergeouss | 70 | v0.48.0 |
v0.51.46 |
| 4 | @ai-ag2026 | 67 | v0.50.279 |
v0.51.190 |
| 5 | @dso2ng | 25 | v0.50.227 |
v0.51.153 |
| 6 | @AJV20 | 24 | v0.51.93 |
v0.51.188 |
| 7 | @starship-s | 19 | v0.50.123 |
v0.51.153 |
| 8 | @jasonjcwu | 16 | v0.50.227 |
v0.51.132 |
| 9 | @dobby-d-elf | 15 | v0.51.38 |
v0.51.161 |
| 10 | @Jordan-SkyLF | 12 | v0.50.18 |
v0.51.66 |
| 11 | @aronprins | 10 | v0.44.0 |
v0.51.45 |
| 12 | @JKJameson | 10 | v0.50.198 |
v0.51.31 |
| 13 | @ccqqlo | 9 | v0.44.0 |
v0.50.270 |
| 14 | @24601 | 8 | v0.50.189 |
v0.51.5 |
| 15 | @LumenYoung | 8 | v0.51.47 |
v0.51.99 |
| 16 | @Sanjays2402 | 8 | v0.50.292 |
v0.51.158 |
| 17 | @armorbreak001 | 7 | v0.50.47 |
v0.50.50 |
| 18 | @NocGeek | 7 | v0.50.251 |
v0.50.252 |
| 19 | @Hinotoi-agent | 6 | v0.50.10 |
v0.51.44 |
| 20 | @iRonin | 6 | v0.41.0 |
v0.41.0 |
| 21 | @bsgdigital | 5 | v0.50.159 |
v0.51.31 |
| 22 | @cloudyun888 | 5 | v0.50.47 |
v0.50.140 |
| 23 | @fxd-jason | 5 | v0.50.245 |
v0.50.250 |
| 24 | @george-andraws | 5 | v0.51.139 |
v0.51.153 |
| 25 | @happy5318 | 5 | v0.50.238 |
v0.51.31 |
Sustained contributors (3–4 PRs landed)
| Contributor | PRs | First release | Latest release |
|---|---|---|---|
| @AlexeyDsov | 4 | v0.50.267 |
v0.51.139 |
| @fecolinhares | 4 | v0.50.238 |
v0.50.250 |
| @frap129 | 4 | v0.50.140 |
v0.50.233 |
| @Isla-Liu | 4 | v0.51.100 |
v0.51.142 |
| @KingBoyAndGirl | 4 | v0.50.238 |
v0.50.240 |
| @qxxaa | 4 | v0.50.210 |
v0.51.37 |
| @renheqiang | 4 | v0.50.61 |
v0.50.95 |
| @Thanatos-Z | 4 | v0.50.257 |
v0.50.278 |
| @deboste | 3 | v0.17.1 |
v0.50.297 |
| @dutchaiagency | 3 | v0.50.281 |
v0.50.286 |
| @espokaos-ops | 3 | v0.51.92 |
v0.51.94 |
| @lucasrc | 3 | v0.51.57 |
v0.51.57 |
| @mccxj | 3 | v0.51.75 |
v0.51.148 |
| @mysoul12138 | 3 | v0.51.161 |
v0.51.185 |
| @pamnard | 3 | v0.51.186 |
v0.51.191 |
| @pavolbiely | 3 | v0.50.159 |
v0.50.233 |
Two-PR contributors (17)
@aliceisjustplaying, @allenliang2022, @andrewkangkr, @Carry00, @eleboucher, @insecurejezza, @junjunjunbong, @linuxid10t, @michael-dg, @mmartial, @MrFant, @plerohellec, @renatomott, @swftwolfzyq, @vcavichini, @xz-dev, @zichen0116.
Single-PR contributors (139)
Each of these folks landed exactly one PR that shipped — a bug fix, a locale, a security hardening, a doc improvement, an infrastructure tweak. Every one moved the project forward.
@29n, @86cloudyun-afk, @AdoneyGalvan, @amlyczz, @andrewy-wizard, @antoniocarlos97ss, @Argonaut790, @arshkumarsingh, @ashbuildslife, @Asunfly, @ayushere, @bengdan, @betamod, @bjb2, @Bobby9228, @bschmidy10, @carlytwozero, @Charanis, @ChaseFlorell, @chwps, @colin-chang, @cyberdyne187, @darkopetrovic, @davidsben, @DavidSchuchert, @DelightRun, @dev-rehaann, @dotBeeps, @DrMaks22, @eba8, @emanon312, @eov128, @Fail-Safe, @FrancescoFarinola, @gabogabucho, @galvani, @gavinssr, @GeoffBao, @georgebdavis, @GiggleSamurai, @hacker1e7, @hacker2005, @halmisen, @hermes-gimmethebeans, @hi-friday, @hualong1009, @huangzt, @indigokarasu, @intellectronica, @jeffscottward, @Jellypowered, @jimdawdy-hub, @JinYue-GitHub, @joaompfp, @jundev0001, @KayZz69, @kcclaw001, @kevin-ho, @koshikai, @kowenhaoai, @lawrencel1ng, @leap233, @legeantbleu, @likawa3b, @liuqiangweb-svg, @lost9999, @lucky-yonug, @lx3133584, @MacLeodMike, @malulian, @mangodxd, @mariosam95, @MatzAgent, @mbac, @migueltavares, @MinhoJJang, @mittyok, @mslovy, @mvanhorn, @nanookclaw, @ng-technology-llc, @nickgiulioni1, @octo-patch, @OneFat3, @PINKIIILQWQ, @pix0127, @rhelmer, @rickchew, @RobertoVillegas, @ruxme, @ryan-remeo, @ryansombraio, @s905060, @Saik0s, @samuelgudi, @SaulgoodMan-C, @sbe27, @shaoxianbilly, @sheng-di, @shruggr, @sixianli, @skspade, @smurmann, @snuffxxx, @someaka, @spektro33, @Stampede, @stocky789, @suinia, @sunilkumarvalmiki, @sunnysktsang, @TaraTheStar, @tgaalman, @thadreber-web, @the-own-lab, @theh4v0c, @theseussss, @tiansiyuan, @tomaioo, @trucuit, @ts2111, @v2psv, @vansour, @vCillusion, @vikarag, @waldmanz, @wali-reheman, @watzon, @weidzhou, @weiwei83, @wind-chant, @wirtsi, @woaijiadanoo, @xingyue52077, @xolom, @yunyunyunyun-yun, @yzp12138, @zapabob, @zenc-cp.
How credit is tracked
Most PRs in this repo land via one of four paths:
- Direct merge — your PR is reviewed and merged on its own. Author shows up directly in
git logand on the PR'smerged_attimestamp. - Squash into a batch release — your PR is merged together with several other contributor PRs into a single release commit (e.g.
release: v0.51.55 — 9-PR contributor batch). The original PR closes (not merges) on GitHub but the squashed release commit carries aCo-authored-by: <you>trailer plus an entry inCHANGELOG.mdcrediting you by username and PR number. - Salvaged from a larger PR — when a PR mixes one good change with several unrelated or risky ones, we split it: the good parts ship in a clean follow-up PR, you get credit in the CHANGELOG entry, and the original PR is closed with a salvage map showing what went where.
- Auto-rebase + auto-fix — for merge-ready contributor PRs with mechanical blockers (CHANGELOG conflicts, lint, drifted tests), a maintainer rebases the contributor's branch, fixes the blockers, and force-pushes back. The
Co-authored-bytrailer preserves your authorship.
All four paths count as a contribution. GitHub's merged_at field only catches path 1; paths 2-4 show as "closed" on the contributor's PR even though the work is live in master. That's why this file consults the CHANGELOG attribution lines, not just GitHub's merged-PR list.
Special thanks
- @aronprins —
v0.50.0UI overhaul (PR #242). The CSS-only redesign that defined the design tokens, theme architecture, and three-panel layout that the rest of the app builds on. PR #242 didn't merge as-is, but it is the design language of the app. - @franksong2702 — most prolific external contributor across the project's history. 148 PRs spanning the session sidebar, mobile/responsive layout, workspace state machine, profile context, slash autocomplete, breadcrumb navigation, streaming-session exemption, cron output preservation, embedded terminal, the manual-compress async start/status endpoint pair, the worktree status surface (PR #2109) + guarded remove (PR #2156) for the lifecycle umbrella #2057, session post-render dedup (PR #2166), the
/api/sessionnative-WebUI fast path (PR #2170), tail-window response trim (PR #2171), the second-wave stale-stream guard extension (PR #2158), CSP report collector (PR #2160), and the long tail of polish. - @Michaelyklam — most prolific contributor of late-2025/early-2026. 117 PRs covering Docker hardening, profile-scoped skills, KaTeX delimiter parsing, Codex quota surfacing, Goal command, Kanban polish, auto-compression toast lifetime, the localization parity backfills, the v0.51.51 mobile Insights bucketing/layout pair (PRs #2120/#2121), the Hermes run adapter RFC (PR #2105 for #1925), the fork-from-here absolute-index fix (PR #2198 for #2184), and the opencode-go custom-provider overlap routing fix (PR #2204 for #1894).
- @bergeouss — provider-management UI, OAuth status, two-container Docker docs, profile isolation hardening, Reveal-in-Finder, the OpenRouter free-tier live fetch, and most of Settings → Providers. 70 PRs.
- @ai-ag2026 — autonomous-AI contributor (Hermes Agent-driven). 67 PRs focused on session recovery (state.db sidecar reconciliation, orphan
.bakrecovery, audit + safe-repair endpoints), workspace/run lifecycle health, the crash-safe turn-journal RFC, the append-only turn-journal helper (PR #2059), the matching lifecycle-events layer (PR #2062), theContent-Security-Policy-Report-Onlyheader (PR #2084), and the per-cron toast notification toggle (PR #2100). - @Jordan-SkyLF — Live streaming, session recovery, workspace fallback, and a recent burst of presentation polish: the manual "Refresh usage" button on the Provider quota card (PR #2150), cancelled-turn status classification (PR #2151), Firefox sidebar scroll stabilization (PR #2200), early provisional session titles (PR #2202), target-aware "What's new?" links (PR #2207), and MCP tools overflow fix in Settings (PR #2210). 12 PRs total.
- @LumenYoung — contributor focused on the streaming hot path's correctness. 8 PRs including the original stale-stream writeback guard (PR #2136 — the bug class the next two releases extended), gateway-state alive-null classification (PR #2075), compression-banner anchor alignment (PR #2182), and context-progress ring auto-refresh on compression complete (PR #2188).
- @iRonin — security hardening sprint (PRs #196–#204): session memory leak fix, CSP + Permissions-Policy headers, slow-client connection timeout, optional HTTPS/TLS, upstream branch tracking, CLI session file-browser support. Six consecutive, focused, high-quality security PRs.
- @indigokarasu — visual redesign proposal (PR #213). Icon rail sidebar, design token system, 7 themes. Didn't merge as-is but shaped the design language that landed in v0.50.0.
- @zenc-cp — anti-hallucination guard for the ReAct loop (PR #133). Three-layer approach (ephemeral prompt, live token filtering, session-history cleanup) that the streaming pipeline still uses.
- @deboste — reverse-proxy auth, mobile responsive layout, model routing (PRs #3, #4, #5). Three of the very first community PRs. Early foundation work.
- @Hinotoi-agent — security fixes spanning profile
.envisolation (PR #351), session-import workspace validation (PR #2048), and bandit B105 hardening. Subtle, high-leverage credential and path-traversal fixes. - @lucasrc — auth-hardening trilogy in v0.51.57 (PRs #2191/#2192/#2193): thread-safe login rate limiter with PBKDF2 key separation, password-hash cache invalidation on settings change, and the full 64-char HMAC-SHA256 session signature with backwards-compatible migration bridge. Three coordinated security PRs that landed together.
- @jasonjcwu — composer and transcript polish, 16 PRs. Recent: silent compress-status during session switch (PR #2185), concurrent-send loss fix (PR #2186), in-transcript steer message badge (PR #2187), plus sidebar collapse via active-rail click (PR #2054).
- @dobby-d-elf — frontend reliability and motion polish: workspace fallback on deleted directories (PR #2138), iPhone PWA bottom-scroll fix (PR #2143), the new "Activity: X tools" composer footer animation (PR #2203) and its follow-up tuning (PR #2212).
If you've contributed and aren't here, open a PR. We cross-check the CHANGELOG on every release, but if a credit fell through (a Co-authored-by trailer that didn't make it into the changelog entry, an attribution in a PR comment that should be in the release notes), this list is the right place to fix it.