Files
hermes-agent/website
Teknium a1e4fee33d fix(deps): enforce 14-day aging + exact pins on all bumped versions
Audit of every changed version across all 4 npm locks + uv.lock
against the >=2-week supply-chain aging rule:

- ip-address: 10.4.0 (8d, and a minor feature release) -> 10.3.1
  (exactly 14d, the CVE-fix patch for GHSA-mwp4-54f8-5fhr)
- nanoid: floating resolutions pulled 3.3.18/6.0.1 (1d/5d, post-fix
  releases) -> scoped overrides nanoid@^3=3.3.17 (the CVE-fix
  version) and nanoid@^6=6.0.0 (27d)
- js-yaml/undici: scoped overrides pin the exact CVE-fix versions
  so transitive copies can't float to newer releases
- postcss: 8.5.25/8.5.26 (2d, npm update drift) -> pinned 8.5.23 (15d)
- @electron/get 5.1.0 (12d) -> 5.0.0 (108d),
  @electron-internal/extract-zip 1.0.5 (10d) -> 1.0.4 (45d) —
  electron 40.10.6's carets resolved to sub-14d releases; both were
  incidental drift, not CVE fixes
- website: nanoid override 3.3.17

Remaining sub-14d versions are exclusively documented CVE-fix
exceptions (.npmrc min-release-age-exclude entries with removal
dates): brace-expansion 5.0.9, dompurify 3.4.13, js-yaml 4.3.1,
mermaid 11.16.1, nanoid 3.3.17, fast-uri 3.1.5, h2 4.4.1 (pyproject
exclude-newer exception).

Rescan: 18 findings (blocked-upstream only). npm run check green.
2026-08-08 14:06:48 -07:00
..

Website

This website is built using Docusaurus, a modern static website generator.

Installation

yarn

Local Development

yarn start

This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.

Build

yarn build

This command generates static content into the build directory and can be served using any static contents hosting service.

Deployment

Using SSH:

USE_SSH=true yarn deploy

Not using SSH:

GIT_USER=<Your GitHub username> yarn deploy

If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.

Diagram Linting

CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.