Repository navigation
fix(security): never persist the OAuth access token (v0.2.1) #20
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: ci | |
| on: | |
| push: | |
| pull_request: | |
| permissions: | |
| contents: read | |
| jobs: | |
| unit: | |
| runs-on: ubuntu-latest | |
| steps: | |
| # pinned: actions/checkout@v4 | |
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 | |
| # pinned: actions/setup-python@v5 | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 | |
| with: | |
| python-version: "3.11" | |
| - run: pip install pytest | |
| - run: python -m pytest -q | |
| validate: | |
| runs-on: ubuntu-latest | |
| # Local equivalent of the upstream plugin-validate action. The official | |
| # action pip-installs hermes-agent from git, which hermes-agent's own | |
| # setup.py build guard rejects (pip/PyPI are unsupported distribution | |
| # methods upstream), and the action has a single revision in history so | |
| # there is no last-good version to pin. This job runs the same admission | |
| # checks (manifest schema, stdlib-only imports, capability probe) via a | |
| # checked-in script instead, with no hermes-agent install and no | |
| # dependency on an upstream fix. | |
| steps: | |
| # pinned: actions/checkout@v4 | |
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 | |
| # pinned: actions/setup-python@v5 | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 | |
| with: | |
| python-version: "3.11" | |
| - run: pip install pyyaml | |
| - run: python .github/scripts/validate-plugin.py --path . |