* fix(viewer): embed the viewer font so delivered pages stay self-contained
A delivered page linked fonts.googleapis.com and fonts.gstatic.com, so every
viewer's browser reached a third party to render the artifact as designed.
The consequence is larger than the reported typography loss. The adaptive
reader measures real font metrics rather than assuming them, so the resolved
column width depends on that request succeeding: the same file resolves a
960px reader column with the face loaded and 987px without it, and the diagram
repaints at the matching scale. Both states report readability: pass, so
nothing flags it. The producer sees one page and the receiver sees another.
Embed the woff2 subsets Google Fonts serves for JetBrains Mono as data: URIs,
one @font-face per unicode range over the variable wght 400-800 axis. The
bytes are identical to what the linked stylesheet resolved to, so typography
and geometry are unchanged and now reproducible offline. No local() source is
declared first on purpose: resolving an installed copy of unknown version puts
the metrics, and so the column width, back at the mercy of the viewer's
machine. The template comment publishes a sha256 per subset and a test
enforces that those digests match what ships.
Add test/offline-self-containment.test.mjs. It selects artifacts by the
presence of Archify.readerLayout rather than a generator meta match, because
readerLayout is the code that measures font metrics: the compare artifact
carries no generator meta yet is delivered like any other page, while the
site pages declare one and link a stylesheet on purpose. Each artifact is
scanned both as-is and with entities decoded, since compare embeds each side
as an escaped srcdoc whose subresources would otherwise read as clean. Both
artifact cases assert the six faces are present, because reaching no third
party by dropping the typography satisfies the offline check and still hands
the receiver a different page.
JetBrains Mono is under the SIL Open Font License 1.1; the notice and full
license text ship at assets/JetBrainsMono-OFL.txt rather than in the template
comment, so a grep over a delivered page reports zero external hosts.
Closes#242
* fix(viewer): share offline font bytes across delivery and exports
* chore: retrigger stalled PR update processing
* build: preserve showcase quality for the checkout comparison
* fix(packaging): check embedded fonts across the staged payload
---------
Co-authored-by: sunsunsun <fromzerobegin@gmail.com>
Co-authored-by: tt-a1i <2801884530@qq.com>
GitHub's default shallow checkout maps the pushed commit SHA directly onto the tag ref. Refetch the exact remote tag before enforcing the annotated-tag gate and cover the failure mode with a local Git fixture.
* feat: add optional skill update awareness
Add the fail-silent, notification-only update checker and stable release contract, harden packaging and publication gates, keep the DSH 0.1.0 snapshot immutable, and fold in the reviewed codebase simplifications.
* test: accept platform-safe staging rejection
Linux can reject an ancestor swap while preflighting the leaf, while macOS detects the changed ancestor during snapshot validation. Both paths fail closed before staging, so assert the two exact safe outcomes instead of one platform-specific phase.
* test: guard staging swap hook against reentry
On Linux, recursive rm can re-enter the monkeypatched lstatSync before the swap flag was set. Fence the hook before mutating the fixture so the intended ancestor-swap attack runs exactly once.
* docs: add self-hosted Star History chart
* test(ci): cover linear star history publishing
* fix(ci): publish star history with linear commits
Replace the force-pushed orphan data branch with normal fast-forward commits so the repository-wide non-fast-forward ruleset remains enforced.
---------
Co-authored-by: UNGETSU <44204222+YunyueLi@users.noreply.github.com>
Prevent the Viewer navigation dock from covering canonical SVG legends by adding a collision-activated safe rail, browser regression coverage, and visual-check enforcement.\n\nCloses #99.
Adds the explicitly installed @tt-a1i/archify-dsh Skill-only bundle with isolated packaging, cross-platform command handling, portable acceptance gates, and zero changes to the default non-DSH runtime.\n\nCloses #68.