ci(hermes): cover shared native fixture inputs

Trigger credential-free Linux native fixtures for shared Runner sources, Rust and build manifests, dependency patches, and workspace inputs. Verify actual glob matching for attachment, backend, transport and dependency changes. Paid workflow authority is unchanged.

Validation: 15 workflow security tests and actionlint passed. Also record 26 passing real-database authority tests, the expected old-lock negative proof, and 143 passing ACPX lifecycle regressions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
DottaandPaperclip committed 2026-10-08 12:28:11 -05:00
1 parent d8453bf775
commit 6f87ea523b
3 files changed
+46 -6

No files matched your search

+10 -6
View File
@@ -4,13 +4,17 @@ on:
pull_request:
paths:
- .github/workflows/runner-hermes-native.yml
- packages/paperclip-runner/src/providers/hermes/**
- packages/paperclip-runner/src/drivers/acpx/**
- packages/paperclip-runner/src/live/runnerd-*.ts
- packages/paperclip-runner/runner/crates/runner-core/src/acpx_*.rs
- packages/paperclip-runner/scripts/*hermes*
- packages/paperclip-runner/acpx-profiles.json
- packages/paperclip-runner/**
- packages/paperclip-eval-kernel/**
- packages/adapter-utils/**
- packages/shared/**
- patches/**
- package.json
- pnpm-lock.yaml
- pnpm-workspace.yaml
- tsconfig*.json
- tests/runner-e2e/provision-hermes-linux.sh
- tests/runner-e2e/workflow-security.test.ts
workflow_dispatch:
permissions: