Skip to content

refactor(skills): fold Hermes upgrade guidance - #8179

Merged
cv merged 3 commits into
codex/reduce-contributor-skill-driftfrom
codex/fold-hermes-upgrade-variant
Aug 4, 2026
Merged

refactor(skills): fold Hermes upgrade guidance#8179
cv merged 3 commits into
codex/reduce-contributor-skill-driftfrom
codex/fold-hermes-upgrade-variant

Conversation

@jyaunches

@jyaunches jyaunches commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Summary

Remove the dedicated Hermes implementation skill and route Hermes release work through the general dependency-upgrade workflow. Keep only the Hermes-specific CalVer collection and base-image publication gates in a conditional reference so implementation details continue to come from source and tests.

This PR is stacked on #8159 and should be reviewed and merged after it. Once #8159 merges, this PR can target main without carrying duplicate skill-refactor changes.

Changes

  • Remove the dedicated Hermes skill, agent metadata, catalog entry, and obsolete skill test while preserving narrow update, review, and publication triggers in the dependency skill.
  • Move the Hermes CalVer helper beneath the dependency skill and use its ordered release endpoints as adjacent audit boundaries only when the generic collector does not cover the selected range.
  • Keep concise, process-level Hermes base-image publication guidance without maintaining code-derived path or contract inventories.
  • Bring the moved helper under the parent collector's private-output contract with descriptor-anchored mode-0600 writes, no replacement or symlink following, unsafe-directory rejection, and failure cleanup.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification: No user-facing product behavior changes. Contributor-agent routing is documented by the updated checked-in skills catalog, and the exact-head documentation review passed.
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Codex Desktop independently reviewed exact head 89e75241b with the repository's nine-category security checklist. All categories passed with no remaining findings; evidence covers descriptor anchoring, ownership and mode checks, files and symlinks, hostile directories, permissive umask, and injected fsync failure cleanup.
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: docs-updated
  • Evidence: Reviewed the full PR diff and final descriptor-anchored output-security follow-up against current writing and documentation rules. Affected tests passed 103/103; final focused tests passed 10/10; repository checks, Biome, git diff checks, forward testing, pre-commit, commit-msg, skill YAML, markdownlint, and gitleaks passed. Independent nine-category security review passed. No user-facing docs/ change is needed because this changes contributor-agent routing, documented in the skills catalog.
  • Agent: Codex Desktop

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit:
  • Station profile/scenario:
  • Result:
  • Supporting evidence:

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run validate:pr passed after refreshing origin/main when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: Affected integration selection passed 103/103; final variant and helper tests passed 10/10.
  • Applicable broad gate passed — npm test for broad runtime/test-harness changes; npm run check for repo-wide validation/coverage changes — command/result: Not applicable to this narrow agent-skill and standalone-helper refactor; npm run checks:repository passed.
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only)
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: Julie Yaunches jyaunches@nvidia.com

@jyaunches jyaunches self-assigned this Aug 3, 2026
@coderabbitai

coderabbitai Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 8b1dd451-453f-44f6-a8d0-689d86af14d8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in commit e444c33 in the codex/fold-hermes-up... branch remains at 96%, unchanged from commit a37c0c9 in the codex/reduce-contrib... branch.

TypeScript / code-coverage/cli

The overall coverage in commit e444c33 in the codex/fold-hermes-up... branch remains at 81%, unchanged from commit 643a4ab in the codex/reduce-contrib... branch.

Show a code coverage summary of the most impacted files.
File codex/reduce-contrib... 643a4ab codex/fold-hermes-up... e444c33 +/-
src/lib/platform.ts 89% 84% -5%
src/lib/policy/...ne-exclusion.ts 96% 92% -4%
src/lib/private-networks.ts 93% 90% -3%
src/lib/shields/index.ts 70% 69% -1%
src/lib/shields...nsition-lock.ts 88% 87% -1%
src/lib/policy/index.ts 59% 59% 0%
src/lib/actions...licy-channel.ts 80% 81% +1%
src/lib/actions...ess-recovery.ts 82% 84% +2%
src/lib/domain/.../connect-env.ts 89% 97% +8%
src/lib/onboard...ization-deps.ts 58% 83% +25%

Updated August 04, 2026 06:56 UTC

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — No blocking findings reported

Advisor assessment: No blocking advisor findings reported
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions

Model lanes

  • GPT-5.6 Terra (primary): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Model comparison: normalized findings match; normalized terminology decisions differ; normalized E2E selections match; severity counts match.
3 terminology differences from the second opinion

Advisory only. These are normalized differences from the primary terminology receipt.

  • adjacent audit boundaries at .agents/skills/nemoclaw-contributor-update-dependencies/references/hermes.md:15: primary classified it as justified; the second opinion classified it as define.
  • upgrade variant at .agents/skills/nemoclaw-contributor-update-dependencies/SKILL.md:60: selected only by the second-opinion lane as define.
  • parent collector trust controls at .agents/skills/nemoclaw-contributor-update-dependencies/references/hermes.md:17: selected only by the second-opinion lane as define.

Second-opinion terminology and E2E selections are advisory. They do not change the primary assessment or E2E / PR Gate.

3 semantic terminology decisions

Terminology decisions are advisory. They affect the assessment only when a separate finding identifies concrete semantic impact.

  • established — Hermes CalVer at .agents/skills/nemoclaw-contributor-update-dependencies/references/hermes.md:13: Retain `Hermes CalVer`; the collector and tests already use this established release-format term.
  • justified — adjacent audit boundaries at .agents/skills/nemoclaw-contributor-update-dependencies/references/hermes.md:15: Retain `adjacent audit boundaries`; the modifier identifies the release-range evidence required by the parent workflow.
  • established — private report at .agents/skills/nemoclaw-contributor-update-dependencies/scripts/collect-hermes-release-supplement.py:455: Retain `private report`; the parent skill already uses it for collector outputs with mode 0600 permissions.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: None

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@apurvvkumaria apurvvkumaria left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the exact stacked delta at head ec7a804. Hermes trigger routing now lands in the general dependency workflow; the conditional variant preserves the CalVer collection and immutable base-image publication gates, while the parent contract audit retains the removed security, lifecycle, state, provenance, platform, and E2E coverage. No stale old-skill references remain. The moved collector now publishes through a mode-0600 temporary file with fsync, atomic no-clobber linking, and cleanup. Focused validation passed 36 tests across the variant, collector, and frontmatter suites, and the diff check is clean. Current red image and npm-audit checks concern unchanged runtime advisories; the aggregate CodeQL annotation is on a test-fixture permission assertion, not production behavior. No blocking correctness, security, compatibility, or regression defect found.

if created and not complete:
try:
os.unlink(output.name, dir_fd=directory)
except FileNotFoundError:

@apurvvkumaria apurvvkumaria left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed exact head 89e7524. The follow-up opens and validates the output directory once, creates the report with exclusive no-follow semantics and private permissions, flushes file and directory state, and removes partial output on failure. This closes directory and leaf race paths without weakening the stacked skill refactor. Focused validation passes 40 of 40 tests on macOS. The CodeQL empty-except note is an intentional missing-file cleanup case, and current red audit and image checks concern unchanged stacked-base runtime dependencies. No blocking defect found.

@cv
cv merged commit 56845f3 into codex/reduce-contributor-skill-drift Aug 4, 2026
52 of 53 checks passed
@cv
cv deleted the codex/fold-hermes-upgrade-variant branch August 4, 2026 07:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants