ci(security): include bridge lockfiles in OSV scan - #46747
Conversation
598a58e to
89a52da
Compare
|
Thanks for identifying the uncovered runtime lockfiles. The premise still holds: Problems
Suggested changes
Automated hermes-sweeper review. |
89a52da to
54066ed
Compare
|
Updated this against current Local checks passed: workflow assertions, lockfile parsing, Prettier, and zizmor. The new CI run is waiting for maintainer approval: https://github.com/NousResearch/hermes-agent/actions/runs/29355271472 |
54066ed to
55bfae5
Compare
|
Rebased this onto current Local validation passed: YAML parsing, five-lockfile assertions, Prettier, zizmor, and |
55bfae5 to
f1e7ab9
Compare
|
Rebased onto current Local checks passed: the workflow YAML and package lockfiles parse, all five lockfile paths exist, Prettier passes, and The new CI run is waiting for maintainer approval: https://github.com/NousResearch/hermes-agent/actions/runs/30465294563 |
f1e7ab9 to
0924ffd
Compare
|
This was incorporated directly into main in f21332f, so I’m closing the superseded PR. Thanks for carrying the change forward and preserving the attribution. |
…SV scan Surgical reapply of PR NousResearch#46747 by @tank321 onto the current reusable-workflow form of osv-scanner.yml (the original targeted the old direct-action layout). Fixes NousResearch#46738.
Summary
mainFixes #46738.
Validation
.github/workflows/osv-scanner.ymlwith PyYAMLcontinue-on-error: truegit diff --checkpassed