Skip to content

Unreferenced brand assets in apps/site/public are published and drifting from the package #208

Description

@lemarier

apps/site/public/ holds a hand-copied set of brand material — assets/tokens/themes.css, assets/logos/*.svg, assets/fonts/*, assets/art/* and assets/LICENSE.md — added in 60007af and not referenced since. The app imports these from @origin89/brand directly, so nothing in index.html, ops.html, the site sources or the Worker reads them. Vite still copies public/ into dist/, so they are published under data.origin89.com/assets/.

The copies now disagree with the package. apps/site/public/assets/tokens/themes.css is the 0.3.1 snapshot and has no --color-signal; the site was moved to @origin89/brand 0.4.0, which defines it in all three theme blocks. The logo, font and art files are still byte-identical, so the drift is confined to the token sheet today and will widen at the next upgrade.

Nothing renders wrong: the stylesheets load the package, not the copy. What is published is a stale palette at a public URL under the dataset's own origin, with no build step or manifest recording which package version it came from. The brand skill asks for a deterministic, manifest-based step with recorded versions and hashes where a consumer cannot bundle npm assets, and this consumer can bundle them.

To reproduce:

diff apps/site/public/assets/tokens/themes.css apps/site/node_modules/@origin89/brand/tokens/themes.css

Expected: either no copy, or one a build step regenerates from the installed package. Actual: a hand-maintained 0.3.1 copy that no code reads.

Next step: decide whether anything outside this repository links to data.origin89.com/assets/*. If not, delete apps/site/public/assets/; the package's own licence notices travel with the package. If those URLs must keep working, add a build step that copies them from the installed package with an explicit allowlist and records the version and hashes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions