name: Hermes Plugin Validate description: >- Validate a plugin's manifest and registered capabilities with Hermes at the requested ref. The caller owns its plugin checkout; Hermes and its locked runtime are prepared separately under RUNNER_TEMP. inputs: path: description: Path to the plugin directory (containing plugin.yaml). default: "." hermes-ref: description: hermes-agent git ref (branch/tag/sha) to validate with. default: "main" runs: using: composite steps: - name: Prepare an isolated Hermes checkout id: source shell: bash env: _HERMES_REF: ${{ inputs.hermes-ref }} run: | set -euo pipefail source=$(mktemp -d "$RUNNER_TEMP/hermes-plugin-validator.XXXXXX") git init "$source" git -C "$source" remote add origin https://github.com/NousResearch/hermes-agent.git git -C "$source" fetch --depth=1 -- origin "$_HERMES_REF" git -C "$source" checkout --detach FETCH_HEAD printf 'source=%s\n' "$source" >> "$GITHUB_OUTPUT" if [ "$RUNNER_OS" = Windows ]; then bootstrap=python; else bootstrap=python3; fi "$bootstrap" -S "$source/scripts/ci/setup_toolchain.py" prepare \ --toolchain python --home "$source/.build/pm" - name: Prepare the locked Python toolchain shell: bash env: _SOURCE: ${{ steps.source.outputs.source }} run: | set -euo pipefail if [ "$RUNNER_OS" = Windows ]; then bootstrap=python; else bootstrap=python3; fi "$bootstrap" -S "$_SOURCE/scripts/ci/setup_toolchain.py" install \ --toolchain python --home "$_SOURCE/.build/pm" - name: Build the isolated validator runtime id: runtime shell: bash working-directory: ${{ steps.source.outputs.source }} env: _SOURCE: ${{ steps.source.outputs.source }} run: | set -euo pipefail "$HERMES_PYTHON" - <<'PY' import os from pathlib import Path from pm import build_environment source = Path(os.environ["_SOURCE"]) python = build_environment(source=source, out=source / ".build/validator", explicit=True) with open(os.environ["GITHUB_OUTPUT"], "a", encoding="utf-8") as output: output.write(f"python={python}\n") PY - name: Validate plugin shell: bash env: _PLUGIN_PATH: ${{ inputs.path }} _VALIDATOR_PYTHON: ${{ steps.runtime.outputs.python }} run: | set -euo pipefail "$_VALIDATOR_PYTHON" -I -m hermes_cli.main plugins validate "$_PLUGIN_PATH"