apps/site/public/ holds a hand-copied set of brand material — assets/tokens/themes.css, assets/logos/*.svg, assets/fonts/*, assets/art/* and assets/LICENSE.md — added in 60007af and not referenced since. The app imports these from @origin89/brand directly, so nothing in index.html, ops.html, the site sources or the Worker reads them. Vite still copies public/ into dist/, so they are published under data.origin89.com/assets/.
The copies now disagree with the package. apps/site/public/assets/tokens/themes.css is the 0.3.1 snapshot and has no --color-signal; the site was moved to @origin89/brand 0.4.0, which defines it in all three theme blocks. The logo, font and art files are still byte-identical, so the drift is confined to the token sheet today and will widen at the next upgrade.
Nothing renders wrong: the stylesheets load the package, not the copy. What is published is a stale palette at a public URL under the dataset's own origin, with no build step or manifest recording which package version it came from. The brand skill asks for a deterministic, manifest-based step with recorded versions and hashes where a consumer cannot bundle npm assets, and this consumer can bundle them.
To reproduce:
diff apps/site/public/assets/tokens/themes.css apps/site/node_modules/@origin89/brand/tokens/themes.css
Expected: either no copy, or one a build step regenerates from the installed package. Actual: a hand-maintained 0.3.1 copy that no code reads.
Next step: decide whether anything outside this repository links to data.origin89.com/assets/*. If not, delete apps/site/public/assets/; the package's own licence notices travel with the package. If those URLs must keep working, add a build step that copies them from the installed package with an explicit allowlist and records the version and hashes.
apps/site/public/holds a hand-copied set of brand material —assets/tokens/themes.css,assets/logos/*.svg,assets/fonts/*,assets/art/*andassets/LICENSE.md— added in 60007af and not referenced since. The app imports these from@origin89/branddirectly, so nothing inindex.html,ops.html, the site sources or the Worker reads them. Vite still copiespublic/intodist/, so they are published underdata.origin89.com/assets/.The copies now disagree with the package.
apps/site/public/assets/tokens/themes.cssis the 0.3.1 snapshot and has no--color-signal; the site was moved to@origin89/brand0.4.0, which defines it in all three theme blocks. The logo, font and art files are still byte-identical, so the drift is confined to the token sheet today and will widen at the next upgrade.Nothing renders wrong: the stylesheets load the package, not the copy. What is published is a stale palette at a public URL under the dataset's own origin, with no build step or manifest recording which package version it came from. The brand skill asks for a deterministic, manifest-based step with recorded versions and hashes where a consumer cannot bundle npm assets, and this consumer can bundle them.
To reproduce:
Expected: either no copy, or one a build step regenerates from the installed package. Actual: a hand-maintained 0.3.1 copy that no code reads.
Next step: decide whether anything outside this repository links to
data.origin89.com/assets/*. If not, deleteapps/site/public/assets/; the package's own licence notices travel with the package. If those URLs must keep working, add a build step that copies them from the installed package with an explicit allowlist and records the version and hashes.