hermes-agent/website
Eugeniusz Gilewski 64dd865912 fix(deps): repair Google transitive security floors (#72108)
Google API and authentication packages permit vulnerable httplib2 and pyasn1
transitives, while the Workspace and Google Chat runtime installers previously
treated any importable version as sufficient. Existing environments could
therefore remain vulnerable after the project dependency pins were repaired.

Carry the fixed versions through the Google and Vertex extras, lazy feature
requirements, lockfile, and both runtime installers. Route the documented
Google Chat installation path through its maintained secure requirements
instead of an unconstrained direct pip command.

Detect stale distributions, install only unsatisfied requirements, and verify
the result before continuing. Behavioral tests cover those repair invariants
without freezing manifests, lockfiles, or complete package sets.

Related #72108
Extracted from #72840
Co-authored-by: Teknium <127238744+teknium1@users.noreply.github.com>
2026-07-31 23:18:38 -07:00
..
docs fix(deps): repair Google transitive security floors (#72108) 2026-07-31 23:18:38 -07:00
i18n/zh-Hans/docusaurus-plugin-content-docs/current fix(deps): repair Google transitive security floors (#72108) 2026-07-31 23:18:38 -07:00
scripts fix(skills-hub): include owner in ClawHub source URLs and add retry on 429 (#51236) 2026-07-31 22:33:11 -07:00
src refactor: remove the claude-marketplace skill source (redundant Marketplace hub tab) 2026-07-28 23:16:27 -07:00
static feat(models): add deepseek/deepseek-v4-flash-0731 to Nous portal and OpenRouter catalogs 2026-07-31 09:43:03 -07:00
.gitignore
.npmrc fix(npm): npm 11.10-12.0 support min-release-age but NOT min-release-age-exclude. 2026-07-31 13:42:04 -04:00
README.md
docusaurus.config.ts
package-lock.json fix(sec): pin exact npm package versions in website/, lock. 2026-07-31 13:42:03 -04:00
package.json fix(npm): npm 11.10-12.0 support min-release-age but NOT min-release-age-exclude. 2026-07-31 13:42:04 -04:00
sidebars.ts docs(skills): regenerate skills catalog; fix generator sentence truncation 2026-07-29 08:48:05 -07:00
tsconfig.json

README.md

Website

This website is built using Docusaurus, a modern static website generator.

Installation

yarn

Local Development

yarn start

This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.

Build

yarn build

This command generates static content into the build directory and can be served using any static contents hosting service.

Deployment

Using SSH:

USE_SSH=true yarn deploy

Not using SSH:

GIT_USER=<Your GitHub username> yarn deploy

If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.

Diagram Linting

CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.