59 Commits
Author SHA1 Message Date
tt-a1i 0e90bc0601 ci: use shared browser regression gate once 2026-09-22 20:40:10 +08:00
tt-a1i 564c2e5293 Merge remote-tracking branch 'origin/main' into codex/dev-stability-repair-20260922
# Conflicts:
#	.github/workflows/ci.yml
#	README.md
#	README_EN.md
#	README_ZH.md
#	archify/test/release-package-gates.test.mjs
2026-09-22 20:22:37 +08:00
tt-a1i 5289f6867f feat: migrate website to Astro while preserving visual parity (#495)
* feat: migrate website to Astro with exact visual parity

* test: preserve deployment gates for verified website artifact

* test: anchor workflow job lookup at top-level job boundary

* fix(website): normalize whitespace in guide searches
2026-09-21 16:38:50 +08:00
tt-a1i 1aa1db9f9c ci: add conservative README-only fast path (#490) 2026-09-20 21:03:51 +08:00
sunsunsun 85dea36952 fix: harden Windows path publication contracts 2026-09-18 23:47:26 +08:00
sunsunsun b0b62c0ec5 fix: unify cross-platform path contracts 2026-09-18 20:44:14 +08:00
sunsunsun 9d2fbb7957 fix: complete viewer CSS and Windows watcher coverage 2026-09-18 12:01:51 +08:00
sunsunsun 8c13104209 Merge dev and address PR 403 review 2026-09-18 11:32:07 +08:00
548f3b9e0e fix(delivery): reject stale artifacts after failed deliver (#380)
* fix(delivery): reject stale artifacts after failed deliver

* fix(delivery): make provenance commit recoverable

* build: refresh skill archive for delivery provenance

* fix(delivery): reject stale artifacts after failed deliver

* fix(delivery): make provenance commit recoverable

* build: refresh skill archive for delivery provenance

* fix(delivery): fail closed across interrupted delivery and evidence checks

* fix(delivery): preserve recovery backups and path boundaries

* fix(delivery): serialize concurrent output attempts

* fix(delivery): preserve input and unknown files at lock paths

* build: regenerate delivery archive with official Node 22

* fix(delivery): fail closed while lock state is unresolved

* fix(delivery): retain backups after recovery probe failures

* fix(delivery): serialize failure evidence

* test(delivery): pin failed provenance diagnostics

* test(browser): reject empty Chrome override

* docs(delivery): require strict check before visual proof

* test(delivery): enforce strict check ordering

* test(delivery): scope strict workflow assertion

* fix(delivery): preserve locks and verify ownership

* fix(delivery): close ownership recovery edge cases

* fix(delivery): preserve primary cleanup failures

---------

Co-authored-by: DragonFruit <16000773+dragonfruitcgk@user.noreply.gitee.com>
Co-authored-by: sunsunsun <fromzerobegin@gmail.com>
Co-authored-by: tt-a1i <2801884530@qq.com>
2026-09-17 12:12:14 +08:00
tt-a1i 7d0770d015 Refresh shared browser gate with current dev regressions 2026-09-17 02:11:27 +08:00
tt-a1i afe593ab68 Require the lifecycle rail browser regression in CI 2026-09-17 02:05:41 +08:00
tt-a1i b26b4da0eb Validate Hermes adapter and clarify community installation instructions 2026-09-17 01:39:25 +08:00
tt-a1i 4b021058a7 chore(ci): pin newly added Windows job actions 2026-09-17 01:01:32 +08:00
tt-a1i ecd2b579ff Merge remote-tracking branch 'origin/dev' into codex/pr163-dev-integration 2026-09-17 00:59:36 +08:00
tt-a1i 65d8de66ca Merge pull request #412 from tt-a1i/codex/contributor-cards
feat: generate and deliver contributor cards for merged PRs
2026-09-17 00:42:13 +08:00
tt-a1i de9a160df0 fix: validate display titles and pin contributor card actions 2026-09-17 00:30:16 +08:00
tt-a1i 57b32bb22d ci: run sequence header checks with the provisioned browser 2026-09-17 00:27:11 +08:00
tt-a1i 9464f6816f ci: verify contributor cards on dev before production activation 2026-09-17 00:20:52 +08:00
tt-a1i c472bb58e5 Merge remote-tracking branch 'origin/dev' into codex/pr412-dev-integration 2026-09-17 00:19:38 +08:00
tt-a1i 60e3af98f4 test(ci): verify Windows-sensitive fixtures on Windows 2026-09-16 23:27:42 +08:00
tt-a1i 72e5ea2e85 chore: establish dev-first integration and CI 2026-09-16 23:17:40 +08:00
tt-a1i 39d66d9bd2 fix(ci): share required browser regressions with releases 2026-09-16 18:13:27 +08:00
astsandsunsunsun 64b1ba0c1e fix(viewer): handle Object.prototype names as semantic IDs (#424)
Co-authored-by: sunsunsun <fromzerobegin@gmail.com>
2026-09-16 16:21:05 +08:00
tt-a1i bc8cdc854c docs: add Archify review skill and streamline review guidance (#435) 2026-09-16 15:15:35 +08:00
Yunyue Li cf2fa9597b feat: generate and deliver contributor cards for merged PRs 2026-09-14 15:15:45 +08:00
bb71ccdd64 refactor(viewer): modularize source while preserving standalone HTML (#381)
* refactor(viewer): extract Reader Layout source (#343)

* refactor(viewer): isolate SVG export cleanup (#343)

* refactor(viewer): extract Chrome Layout source (#343)

* refactor(viewer): extract Camera source (#343)

* test(viewer): stabilize camera observations and cancellation checks

* refactor(viewer): extract Semantic Radar source (#343)

* test(viewer): cover Radar viewport and activity synchronization

* refactor(viewer): extract Motion Governor source (#343)

* refactor(viewer): extract Node Finder source (#343)

* refactor(viewer): extract Intent Trace source (#343)

* refactor(viewer): extract Semantic Lens source (#343)

* refactor(viewer): extract Route Probe source (#343)

* refactor(viewer): extract Guided Views source (#343)

* fix(viewer): keep selected chapters and story stops in view

* refactor(viewer): extract Focus and shared flow tokens source

* refactor(viewer): extract complete export module with owned cleanup

* test(viewer): enforce synchronous clipboard construction

* test(viewer): establish mouse capabilities after browser navigation

* test(viewer): configure desktop pointer capabilities in browser fixtures

* test(viewer): verify desktop input and stabilize native clicks

* test(viewer): verify motion reload identity and bound browser concurrency

* test(viewer): diagnose native Linux storage without viewer scripts

* test(viewer): trace startup injection identity in isolated Linux motion check

* test(viewer): scope motion fixture injection to its navigation

---------

Co-authored-by: tt-a1i <53142663+tt-a1i@users.noreply.github.com>
Co-authored-by: tt-a1i <2801884530@qq.com>
2026-09-11 10:56:57 +08:00
10722002bb fix(viewer): embed the viewer font so delivered pages stay self-contained (#256)
* fix(viewer): embed the viewer font so delivered pages stay self-contained

A delivered page linked fonts.googleapis.com and fonts.gstatic.com, so every
viewer's browser reached a third party to render the artifact as designed.

The consequence is larger than the reported typography loss. The adaptive
reader measures real font metrics rather than assuming them, so the resolved
column width depends on that request succeeding: the same file resolves a
960px reader column with the face loaded and 987px without it, and the diagram
repaints at the matching scale. Both states report readability: pass, so
nothing flags it. The producer sees one page and the receiver sees another.

Embed the woff2 subsets Google Fonts serves for JetBrains Mono as data: URIs,
one @font-face per unicode range over the variable wght 400-800 axis. The
bytes are identical to what the linked stylesheet resolved to, so typography
and geometry are unchanged and now reproducible offline. No local() source is
declared first on purpose: resolving an installed copy of unknown version puts
the metrics, and so the column width, back at the mercy of the viewer's
machine. The template comment publishes a sha256 per subset and a test
enforces that those digests match what ships.

Add test/offline-self-containment.test.mjs. It selects artifacts by the
presence of Archify.readerLayout rather than a generator meta match, because
readerLayout is the code that measures font metrics: the compare artifact
carries no generator meta yet is delivered like any other page, while the
site pages declare one and link a stylesheet on purpose. Each artifact is
scanned both as-is and with entities decoded, since compare embeds each side
as an escaped srcdoc whose subresources would otherwise read as clean. Both
artifact cases assert the six faces are present, because reaching no third
party by dropping the typography satisfies the offline check and still hands
the receiver a different page.

JetBrains Mono is under the SIL Open Font License 1.1; the notice and full
license text ship at assets/JetBrainsMono-OFL.txt rather than in the template
comment, so a grep over a delivered page reports zero external hosts.

Closes #242

* fix(viewer): share offline font bytes across delivery and exports

* chore: retrigger stalled PR update processing

* build: preserve showcase quality for the checkout comparison

* fix(packaging): check embedded fonts across the staged payload

---------

Co-authored-by: sunsunsun <fromzerobegin@gmail.com>
Co-authored-by: tt-a1i <2801884530@qq.com>
2026-09-08 19:41:35 +08:00
7ce87eff8e fix: keep packaged examples within desktop reader (#325)
Co-authored-by: sunsunsun <fromzerobegin@gmail.com>
Co-authored-by: Friend A <55621390+sunsunsun-java@users.noreply.github.com>
2026-09-08 15:57:06 +08:00
tt-a1i daced37a66 docs: align contribution and bot review with change impact (#346)
* docs: bound review scope and evidence by change impact

* docs: align advisory bot review with impact-based contribution rules
2026-09-08 14:22:14 +08:00
UNGETSUandtt-a1i 2ead014aa8 fix(dsh): prepare reproducible 0.2.0 adapter with current Skill snapshot (#345)
* fix(dsh): refresh plugin payload and pin release source

* fix(dsh): resolve Windows pnpm script installations

* fix(dsh): stage adapter inputs from committed Git blobs

* test(dsh): make hostile path fixture portable and keep public docs compact

---------

Co-authored-by: tt-a1i <2801884530@qq.com>
2026-09-08 09:22:23 +08:00
Friend A 60080fbbe5 docs: clarify visual evidence requirements (#300)
* docs: clarify visual evidence requirements

* docs: make visual evidence outcome-oriented
2026-09-04 23:42:35 +08:00
Sima Bagheri a8ce5251b9 Merge current main and update action-pin contract tests 2026-09-01 14:50:41 +08:00
09cc2a04af chore(ci): migrate GitHub Actions off deprecated Node 20 runtime (fixes #217) (#224)
* chore(ci): migrate GitHub Actions off deprecated Node 20 runtime

- bump actions/checkout@v4 -> v5 (node24)
- bump actions/setup-node@v4 -> v5 (node24, requires runner >=2.327.1)
- bump actions/configure-pages@v5 -> v6 (node24)
- bump actions/deploy-pages@v4 -> v5 (node24)
- bump pnpm/action-setup@v4 -> v5 (node24, still supports pnpm 10)
- bump star-history checkout to v5, keep SHA-pinned narayann7/star-history-action (composite)
- keep softprops/action-gh-release@v2 as-is: latest v2.4.1 still node20, node24 only on unreleased master
- preserve SHA-pinning policy and Node 18/20/22/24 test matrix

Fixes #217

* fix(tests): update Pages deploy gates for Node 24 action versions

- configure-pages@v5 -> v6, deploy-pages@v4 -> v5 to match workflow
  migration off deprecated Node 20 runtime (fixes #217)
- Keeps CI gate validation aligned with chore(migrate-node20-runtime)

Signed-off-by: Yunare Maia <yunare@gmail.com>

* fix(ci): close remaining Node 20 action runtime paths

---------

Signed-off-by: Yunare Maia <yunare@gmail.com>
Co-authored-by: Yunare Maia <yunaremaia@users.noreply.github.com>
Co-authored-by: tt-a1i <tt-a1i@users.noreply.github.com>
Co-authored-by: Friend A <55621390+sunsunsun-java@users.noreply.github.com>
2026-09-01 11:53:15 +08:00
Sima Bagheri e0c6525697 Merge upstream main and resolve workflow pinning conflicts 2026-08-31 16:41:04 +08:00
tt-a1i 5122bb67e5 fix(release): fetch the exact annotated tag object
GitHub's default shallow checkout maps the pushed commit SHA directly onto the tag ref. Refetch the exact remote tag before enforcing the annotated-tag gate and cover the failure mode with a local Git fixture.
2026-08-30 19:05:18 +08:00
Sima Bagheriandtt-a1i 4ac500a498 chore(security): add vulnerability reporting policy (#164)
Co-authored-by: tt-a1i <53142663+tt-a1i@users.noreply.github.com>
2026-08-30 14:09:55 +08:00
Friend A b36d79fdbc feat(skill): add notification-only update awareness (#181)
* feat: add optional skill update awareness

Add the fail-silent, notification-only update checker and stable release contract, harden packaging and publication gates, keep the DSH 0.1.0 snapshot immutable, and fold in the reviewed codebase simplifications.

* test: accept platform-safe staging rejection

Linux can reject an ancestor swap while preflighting the leaf, while macOS detects the changed ancestor during snapshot validation. Both paths fail closed before staging, so assert the two exact safe outcomes instead of one platform-specific phase.

* test: guard staging swap hook against reentry

On Linux, recursive rm can re-enter the monkeypatched lstatSync before the swap flag was set. Fence the hook before mutating the fixture so the intended ancestor-swap attack runs exactly once.
2026-08-30 01:13:30 +08:00
Sima Bagheri c9579f1235 chore(security): require immutable workflow dependencies 2026-08-28 09:29:13 +00:00
tt-a1i 12106be58b docs: use official-style Star History chart (#156) 2026-08-28 14:01:38 +08:00
tt-a1i 49a7821d19 fix(ci): create Star History output directory (#155) 2026-08-28 12:53:00 +08:00
tt-a1iandUNGETSU 316a18456e docs: add self-hosted Star History chart (#153)
* docs: add self-hosted Star History chart

* test(ci): cover linear star history publishing

* fix(ci): publish star history with linear commits

Replace the force-pushed orphan data branch with normal fast-forward commits so the repository-wide non-fast-forward ruleset remains enforced.

---------

Co-authored-by: UNGETSU <44204222+YunyueLi@users.noreply.github.com>
2026-08-28 12:45:48 +08:00
sunsunsun eed82c9ebd build(zip): protect canonical archive publication 2026-08-26 20:55:44 +08:00
sunsunsun 99564e0c8d build(zip): make canonical archive reproducible 2026-08-26 20:13:07 +08:00
sunsunsun-java 4be6da578b feat(i18n): localize Viewer UI from meta.locale (#108)
* feat(i18n): localize viewer content by locale

* fix(i18n): address review feedback for #106
2026-08-26 11:32:22 +08:00
tt-a1i af45e517fb chore(security): require owner review for automation (#109) 2026-08-26 01:19:01 +08:00
sunsunsun-java 4293061d81 Fix Semantic Radar collision handling and dragging (#100)
* Fix semantic radar placement and dragging (#98)

* Harden radar placement fallback (#98)

* Complete radar collision recovery (#98)
2026-08-22 01:38:38 +08:00
sunsunsun-java c784542eec fix(viewer): keep navigation dock clear of legends (#101)
Prevent the Viewer navigation dock from covering canonical SVG legends by adding a collision-activated safe rail, browser regression coverage, and visual-check enforcement.\n\nCloses #99.
2026-08-22 00:30:23 +08:00
sunsunsun-java 98648ce928 fix(renderers): keep automatic routes clear and boundary composition readable (#96)
* fix(renderers): prevent routes from overlapping node borders

* fix(architecture): enforce readable boundary composition

* fix(renderers): preserve routing and layout compatibility

* fix(renderers): close review readability gaps

Include stable reader settling, projected boundary-title checks, delta mask z-ordering, and authored lifecycle-via compatibility. Refresh affected generated artifacts and regression coverage.

* chore(examples): drop Maka artifact refresh

* fix(visual-check): harden Chrome CI launch
2026-08-21 14:30:47 +08:00
tt-a1i 5a4d853981 feat: add opt-in DeepSeek Harness bundle (#69)
Adds the explicitly installed @tt-a1i/archify-dsh Skill-only bundle with isolated packaging, cross-platform command handling, portable acceptance gates, and zero changes to the default non-DSH runtime.\n\nCloses #68.
2026-08-14 14:54:11 +08:00
tt-a1i a097c2d63e fix: harden output and release stability (#53)
* [verified] Harden output and release stability

* docs: align Node support guidance

* test: make opener fixture Node 18 compatible
2026-08-02 17:38:05 +08:00