Skip to content

chore: refresh tools branding and patch CI dependencies - #17

Merged
btravers merged 5 commits into
mainfrom
codex/refresh-project-brand
Oct 7, 2026
Merged

btravers merged 5 commits into
mainfrom
codex/refresh-project-brand

Conversation

@btravers

@btravers btravers commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Refresh the tools mascot and restore the failing Security Audit job by patching development dependencies. The illustrated mascot holds a silver open-end wrench with a straight handle and clear jaws, preserving the approved pink beetroot, green leaves, expressive face, and soft shading.

  • Give the mascot floating hands without arms, with a clearly separate hand gripping the wrench.
  • Apply native SVG artwork to the README and include light/dark, grayscale print, favicon, and 1200 × 630 social-preview assets.
  • Record canonical artwork sources; all displayed assets remain local to the repository. SVGs use editable paths and gradients, with no embedded bitmap.

Validation: pnpm format --check, pnpm lint, and pnpm test pass. The rendered logo and social card were visually checked. Published configuration packages are unchanged. The social-preview PNG is included for repository settings; this PR does not change those settings.

The Security Audit failure is fixed by resolving shell-quote 1.11.0, raising the existing fast-uri security floor to 3.1.8, and overriding oxfmt’s exact vulnerable tinypool pin with 2.1.2. All selected releases satisfy the existing seven-day maturity policy. The high-severity audit threshold, maturity policy, and direct package versions are unchanged. Frozen installation and pnpm audit --audit-level=high pass; the audit reports zero known vulnerabilities.

CI: all jobs pass on the audit-fix commit, including Security Audit, Format, Lint, and Validate configs.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 23:51
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T08:41:38.334610Z 79eb4a7 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: btravstack/tools/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 869a4597-fcbb-4947-8957-bad94365aa98
📥 Commits

Reviewing files that changed from the base of the PR and between e5047f1 and 79eb4a7.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml, !pnpm-lock.yaml
📒 Files selected for processing (1)
  • pnpm-workspace.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The README displays a project logo based on the user's color scheme. The branding README describes logo variants, social-card assets, source files, and committed local copies. The workspace configuration updates overrides for fast-uri and tinypool.

Changes

Project branding

Layer / File(s) Summary
Logo display and asset guidance
README.md, branding/README.md
The README selects the dark logo for dark color schemes and the light logo otherwise. The branding README documents logo variants, social-card dimensions and sources, and committed local copies.

Dependency overrides

Layer / File(s) Summary
Workspace version floors
pnpm-workspace.yaml
The fast-uri override floor changes from 3.1.6 to 3.1.8. A tinypool override now sets versions below 2.1.2 to 2.1.2.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 79eb4

The README uses committed logo assets, and the dependency lockfile matches the new overrides; no concrete merge-blocking risk is established.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes both changes: refreshing the project branding and patching CI dependencies.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6f12018711

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread branding/README.md
Comment on lines +8 to +9
Canonical SVG source: [generate-brand.mjs](https://github.com/btravstack/btravstack.github.io/blob/main/scripts/generate-brand.mjs).
Social source: [social-card.html](https://github.com/btravstack/btravstack.github.io/blob/main/branding/social-card.html), with `?project=tools`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Point branding source links at existing files

Both newly documented canonical-source links return 404: the linked repository's main tree has neither scripts/generate-brand.mjs nor branding/social-card.html. Anyone trying to regenerate or audit these committed assets therefore cannot reach the claimed sources; update these URLs to the current source locations or commit the source files here.

Useful? React with 👍 / 👎.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Changes are documentation and static brand assets only; referenced paths, SVG validity, and the social-card dimensions all check out, leaving only one optional documentation nit.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR applies the shared btravstack brand identity to the tools monorepo. It adds a branding/ directory containing the logo in several variants (light, dark, mono, favicon) plus a 1200 × 630 social-preview PNG, a short branding manifest, and wires the light/dark logo into the top of the root README.md via a <picture> element. It is documentation/assets only, with no changes to package behavior or configuration.

Changes:

  • Add a theme-aware logo to README.md using <picture> with a prefers-color-scheme: dark source and a light fallback.
  • Add branding/ assets: logo-light.svg, logo-dark.svg, logo-mono.svg, logo-favicon.svg, and social-card.png.
  • Add branding/README.md documenting asset usage and linking to the canonical artwork sources.
File Description
README.md Adds a light/dark adaptive logo via a <picture> element referencing the new branding assets.
branding/​README.md New asset manifest describing each logo variant and the social preview, with links to canonical sources.
branding/​logo-light.svg Color logo for light surfaces (green leaf / slate body, white wrench stroke).
branding/​logo-dark.svg Logo tuned for dark surfaces with lightened colors.
branding/​logo-mono.svg Single-color variant for black-on-white print.
branding/​logo-favicon.svg Color logo with a thicker stroke intended as a browser tab icon (not referenced in docs).

Verification performed: the referenced asset paths resolve correctly, all SVGs are well-formed XML, and social-card.png is exactly 1200 × 630 as documented. The only finding is a minor documentation omission (the committed logo-favicon.svg is not mentioned in the asset manifest).


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread branding/README.md Outdated
Comment on lines +4 to +6
identifies the shared build and release toolchain. Use `logo-light.svg` on light
surfaces, `logo-dark.svg` on dark surfaces, and `logo-mono.svg` for black-on-white
print. `social-card.png` is the 1200 × 630 repository preview asset.
@btravers btravers changed the title docs: apply the shared tools logo and brand assets docs: apply the illustrated tools mascot and brand assets Oct 7, 2026
@btravers btravers changed the title docs: apply the illustrated tools mascot and brand assets chore: refresh tools branding and patch CI dependencies Oct 7, 2026
@btravers
btravers merged commit 8a5eb1d into main Oct 7, 2026
5 checks passed
@btravers
btravers deleted the codex/refresh-project-brand branch October 7, 2026 08:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants