hermes-agent/.github/workflows
Dilek dbc11abcb6
fix(ci): pin floating GitHub Actions tags and ascii-guard to explicit versions (#3982)
* fix(ci): pin floating GitHub Actions tags and ascii-guard to explicit versions

Actions pinned to @main pull whatever is at that ref at execution time,
so a compromised upstream org could execute arbitrary code in CI.

- Pin DeterminateSystems/nix-installer-action to commit SHA (v22)
- Pin DeterminateSystems/magic-nix-cache-action to commit SHA (v13)
- Pin ascii-guard to 2.3.0 in docs-site-checks workflow

SHA comments include the version tag for human readability; Renovate or
Dependabot can keep these updated automatically.

* Add skill metadata extraction step in workflow

Add step to extract skill metadata for dashboard in CI workflow.

---------

Co-authored-by: Siddharth Balyan <52913345+alt-glitch@users.noreply.github.com>
2026-04-09 21:27:20 +05:30
..
deploy-site.yml feat(website): add skills browse and search page to docs (#4500) 2026-04-02 10:47:38 -07:00
docker-publish.yml fix(ci): build and push multi-arch Docker image (amd64 + arm64) (#6124) 2026-04-09 00:29:45 -07:00
docs-site-checks.yml fix(ci): pin floating GitHub Actions tags and ascii-guard to explicit versions (#3982) 2026-04-09 21:27:20 +05:30
nix.yml fix(ci): pin floating GitHub Actions tags and ascii-guard to explicit versions (#3982) 2026-04-09 21:27:20 +05:30
supply-chain-audit.yml ci: add supply chain audit workflow for PR scanning (#2816) 2026-03-24 08:56:04 -07:00
tests.yml refactor(tests): re-architect tests + fix CI failures (#5946) 2026-04-07 17:19:07 -07:00