mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-27 17:58:07 +00:00
PR infographics belong in the PR description, referenced from the image-provider URL. The binary never enters git history. This rule has been established twice and leaked twice. #48261 removed the first batch. #54564 removed a second batch and added `infographic/` to .gitignore — but .gitignore only stops an accidental `git add`. It does nothing against `git add -f`, and nothing for a directory that does not literally match the pattern. In the four weeks after that rule landed, nine more PNGs were force-added, and an `infograficos/` directory (#70552's loophole, never actually closed) slipped a tenth past the pattern entirely. Removes 11 tracked images (~14MB) with `git rm --cached`, so local copies survive. Adds an infographic-check CI job that matches on the IMAGE rather than on one directory spelling, so a localized or typo'd path cannot sidestep it, and extends the .gitignore pattern list as the first line of defence. Verified the guard both ways against synthetic repos: it fires on `git add -f` into `infographic/`, on the `infograficos/` spelling, and on nested `docs/pr/infographics/*.jpg`; it does not fire on legitimate product imagery under `docs/assets/` or `website/`, nor on non-image files.
187 lines
5.4 KiB
Text
187 lines
5.4 KiB
Text
.DS_Store
|
|
/venv/
|
|
/venv.old/
|
|
/venv.stale.runtime-*/
|
|
/.hermes-runtime/
|
|
/_pycache/
|
|
*.pyc*
|
|
__pycache__/
|
|
act/
|
|
.act-sandbox-agent.*
|
|
.venv/
|
|
.venv
|
|
.vscode/
|
|
.env
|
|
.op.env
|
|
.env.local
|
|
.env.development.local
|
|
.env.test.local
|
|
.env.production.local
|
|
.env.development
|
|
.env.test
|
|
.hermes-docker/
|
|
.notebooklm-home/
|
|
.notebooklm-cli-venv/
|
|
.notebooklm-playwright/
|
|
.pip-cache/
|
|
.uv-cache/
|
|
compose.hermes.local.yml
|
|
export*
|
|
__pycache__/model_tools.cpython-310.pyc
|
|
__pycache__/web_tools.cpython-310.pyc
|
|
logs/
|
|
data/
|
|
.pytest_cache/
|
|
test_durations.json
|
|
.pytest-cache/
|
|
tmp/
|
|
temp_vision_images/
|
|
hermes-*/*
|
|
examples/
|
|
tests/quick_test_dataset.jsonl
|
|
tests/sample_dataset.jsonl
|
|
run_datagen_kimik2-thinking.sh
|
|
run_datagen_megascience_glm4-6.sh
|
|
run_datagen_sonnet.sh
|
|
source-data/*
|
|
run_datagen_megascience_glm4-6.sh
|
|
data/*
|
|
# No trailing slash: also matches node_modules SYMLINKS (worktrees often
|
|
# symlink node_modules to the main checkout; the dir-only pattern let one
|
|
# slip into a commit and break `npm ci` on CI with ENOTDIR).
|
|
node_modules
|
|
browser-use/
|
|
agent-browser/
|
|
# Private keys
|
|
*.ppk
|
|
*.pem
|
|
privvy*
|
|
images/
|
|
__pycache__/
|
|
hermes_agent.egg-info/
|
|
wandb/
|
|
testlogs
|
|
playwright-report/
|
|
test-results/
|
|
# Playwright visual regression baselines — cached from main in CI, not committed
|
|
*-snapshots/
|
|
|
|
# CLI config (may contain sensitive SSH paths)
|
|
cli-config.yaml
|
|
|
|
# Skills Hub state (lives in ~/.hermes/skills/.hub/ at runtime, but just in case)
|
|
skills/.hub/
|
|
ignored/
|
|
.worktrees/
|
|
environments/benchmarks/evals/
|
|
|
|
# Web UI build output
|
|
hermes_cli/web_dist/
|
|
# Cross-process web UI build lock (flock target, always empty)
|
|
.web_ui_build.lock
|
|
apps/desktop/build/
|
|
apps/desktop/dist/
|
|
|
|
# tsc-emitted artifacts (a stray `tsc -b` compiles into src/, and vite then
|
|
# resolves the stale .js OVER the .tsx — never track these)
|
|
apps/desktop/src/**/*.js
|
|
apps/desktop/src/**/*.js.map
|
|
apps/desktop/src/**/*.d.ts
|
|
!apps/desktop/src/global.d.ts
|
|
!apps/desktop/src/vite-env.d.ts
|
|
apps/shared/src/**/*.js
|
|
apps/shared/src/**/*.js.map
|
|
apps/shared/src/**/*.d.ts
|
|
apps/desktop/release/
|
|
*.tsbuildinfo
|
|
|
|
# Web UI assets — synced from @nous-research/ui at build time via
|
|
# `npm run sync-assets` (see web/package.json).
|
|
web/public/fonts/
|
|
web/public/ds-assets/
|
|
|
|
# Release script temp files
|
|
.release_notes.md
|
|
mini-swe-agent/
|
|
|
|
# Nix
|
|
.direnv/
|
|
.nix-stamps/
|
|
result
|
|
website/static/api/skills-index.json
|
|
# skills.json + skills-meta.json are build artifacts emitted by
|
|
# website/scripts/extract-skills.py during prebuild — keep them out of
|
|
# git for the same reason as skills-index.json (large, generated, change
|
|
# every build).
|
|
website/static/api/skills.json
|
|
website/static/api/skills-meta.json
|
|
# automation-blueprints-index.json is a build artifact emitted by
|
|
# website/scripts/extract-automation-blueprints.py during prebuild.
|
|
website/static/api/automation-blueprints-index.json
|
|
models-dev-upstream/
|
|
|
|
# Local editor / agent tooling (machine-specific; keep in global config, not the repo)
|
|
.codex/
|
|
.cursor/
|
|
.gemini/
|
|
.zed/
|
|
.mcp.json
|
|
opencode.json
|
|
config/mcporter.json
|
|
|
|
hermes_cli/tui_dist/*
|
|
hermes_cli/scripts/
|
|
docs/superpowers/*
|
|
# Working directory for the Hermes Agent's session state (~/.hermes/ at runtime;
|
|
# also created in-repo when an agent operates in this checkout). Plans, audit
|
|
# logs, and per-session caches are never artifacts of the codebase.
|
|
.hermes/
|
|
|
|
# Desktop/bootstrap install marker written into the managed checkout root by the
|
|
# bootstrap installer. It is Hermes-managed runtime state, never a code change —
|
|
# ignore it so `hermes update`'s `git stash push --include-untracked` does not
|
|
# treat it as a local edit and autostash it on every run (#38529).
|
|
.hermes-bootstrap-complete
|
|
|
|
# Persistent dev sandbox dir (scripts/dev-sandbox.sh --persistent)
|
|
.hermes-sandbox/
|
|
|
|
# Interrupted-update breadcrumb + recovery lock written next to the shared venv
|
|
# by `hermes update` / launch-time self-heal. Runtime state, never a code change
|
|
# — ignore so `git status` stays clean and update's autostash skips them.
|
|
.update-incomplete
|
|
.update-incomplete.lock
|
|
|
|
# Installer-written method stamp in the managed checkout root (scripts/install.sh).
|
|
# Runtime metadata only — never a code change. Ignore so `git status` stays clean
|
|
# and `hermes update`'s untracked autostash does not treat it as a local edit (#66189 / #54855).
|
|
/.install_method
|
|
|
|
# Tool Search live-test harness output — non-deterministic model transcripts,
|
|
# regenerated by scripts/tool_search_livetest.py. Never an artifact of the repo.
|
|
scripts/out/
|
|
|
|
# Per-release changelog drafts. These exist only transiently during a release
|
|
# cut (passed to `gh release create --notes-file`); the GitHub Release itself
|
|
# stores the published notes. They are not a build artifact and must never be
|
|
# committed to the repo root. See the hermes-release skill.
|
|
RELEASE_v*.md
|
|
|
|
# Desktop demo-run scratch output (hermes writes demo/*.txt during recorded
|
|
# walkthroughs). Throwaway artifacts, never part of the app.
|
|
apps/desktop/demo/
|
|
|
|
# PR infographics are rendered locally and embedded in PR descriptions via the
|
|
# image-provider (fal.media) URL — they are NEVER committed to the repo. The
|
|
# PR body is the archive. See the hermes-agent-dev skill's
|
|
# pr-infographic-workflow reference (storage rule + lapse #8 / #COMMIT-1).
|
|
#
|
|
# Spelling variants are listed because a single `infographic/` pattern was
|
|
# sidestepped by an `infograficos/` directory (#70552). .gitignore is only
|
|
# the first line of defence and cannot stop `git add -f` at all — the
|
|
# infographic-check CI job is what actually enforces this.
|
|
infographic/
|
|
infographics/
|
|
infograficos/
|
|
infografico/
|
|
native/fts5_cjk/*.so
|