mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
Address review findings on the ARC migration: - docker.yml: WIF auth (and therefore Artifact Registry cache WRITES) now only runs on non-PR events. The build job runs PR-controlled code and the publish job reads the same buildcache ref, so a PR-writable cache was a layer-poisoning vector. PRs of any origin keep cache READS via the runner pod's GKE Workload Identity — that's where the 15min -> 2-3min win comes from; main pushes repopulate writes. - docker.yml: profile label is now docker-tests-<arch>. Both matrix legs uploaded resource-profile-docker-tests; upload-artifact v4+ rejects the duplicate and continue-on-error swallowed it, silently dropping one arch's profile. - actions/profile: run the wrapped command with bash -eo pipefail to match normal `run:` step semantics (a failing `source .venv/...` must fail the step, not fall through). - js/e2e/site workflows: bake node22 into the node_modules cache keys so a future node-version bump can't restore stale native builds (node-pty, electron postinstall) against an unchanged lockfile. - test_container_restart_stale_pid: forward deadline_s/interval_s to wait_for_log instead of silently dropping them. - doctor.py: refresh a stale comment on the in-container docker branch.
59 lines
1.7 KiB
YAML
59 lines
1.7 KiB
YAML
name: Docs Site Checks
|
|
|
|
on:
|
|
workflow_call:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
docs-site-checks:
|
|
runs-on: arc-runner-set
|
|
timeout-minutes: 20
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: 22
|
|
|
|
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
|
id: npm-cache
|
|
with:
|
|
path: website/node_modules
|
|
# node22: native builds + engine checks are node-major-specific;
|
|
# keep the key in sync with setup-node's node-version above.
|
|
key: node-modules-cache-node22-${{ hashFiles('website/package-lock.json') }}
|
|
|
|
- name: Install website dependencies
|
|
uses: ./.github/actions/retry
|
|
with:
|
|
command: npm ci
|
|
working-directory: website
|
|
if: steps.npm-cache.outputs.cache-hit != 'true'
|
|
|
|
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
|
with:
|
|
python-version: '3.11'
|
|
|
|
- name: Install ascii-guard
|
|
uses: ./.github/actions/retry
|
|
with:
|
|
command: python3 -m pip install ascii-guard==2.3.0 pyyaml==6.0.3
|
|
|
|
- name: Extract skill metadata for dashboard
|
|
run: python3 website/scripts/extract-skills.py
|
|
|
|
- name: Regenerate per-skill docs pages + catalogs
|
|
run: python3 website/scripts/generate-skill-docs.py
|
|
|
|
- name: Lint docs diagrams
|
|
run: npm run lint:diagrams
|
|
working-directory: website
|
|
|
|
- name: Build Docusaurus
|
|
uses: ./.github/actions/profile
|
|
with:
|
|
label: docs-site-build
|
|
working-directory: website
|
|
command: npm run build
|