Repository navigation
chore: refresh tools branding and patch CI dependencies - #17
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe README displays a project logo based on the user's color scheme. The branding README describes logo variants, social-card assets, source files, and committed local copies. The workspace configuration updates overrides for ChangesProject branding
Dependency overrides
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to The README uses committed logo assets, and the dependency lockfile matches the new overrides; no concrete merge-blocking risk is established. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6f12018711
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| Canonical SVG source: [generate-brand.mjs](https://github.com/btravstack/btravstack.github.io/blob/main/scripts/generate-brand.mjs). | ||
| Social source: [social-card.html](https://github.com/btravstack/btravstack.github.io/blob/main/branding/social-card.html), with `?project=tools`. |
There was a problem hiding this comment.
Point branding source links at existing files
Both newly documented canonical-source links return 404: the linked repository's main tree has neither scripts/generate-brand.mjs nor branding/social-card.html. Anyone trying to regenerate or audit these committed assets therefore cannot reach the claimed sources; update these URLs to the current source locations or commit the source files here.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Changes are documentation and static brand assets only; referenced paths, SVG validity, and the social-card dimensions all check out, leaving only one optional documentation nit.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
This PR applies the shared btravstack brand identity to the tools monorepo. It adds a branding/ directory containing the logo in several variants (light, dark, mono, favicon) plus a 1200 × 630 social-preview PNG, a short branding manifest, and wires the light/dark logo into the top of the root README.md via a <picture> element. It is documentation/assets only, with no changes to package behavior or configuration.
Changes:
- Add a theme-aware logo to
README.mdusing<picture>with aprefers-color-scheme: darksource and a light fallback. - Add
branding/assets:logo-light.svg,logo-dark.svg,logo-mono.svg,logo-favicon.svg, andsocial-card.png. - Add
branding/README.mddocumenting asset usage and linking to the canonical artwork sources.
| File | Description |
|---|---|
| README.md | Adds a light/dark adaptive logo via a <picture> element referencing the new branding assets. |
| branding/README.md | New asset manifest describing each logo variant and the social preview, with links to canonical sources. |
| branding/logo-light.svg | Color logo for light surfaces (green leaf / slate body, white wrench stroke). |
| branding/logo-dark.svg | Logo tuned for dark surfaces with lightened colors. |
| branding/logo-mono.svg | Single-color variant for black-on-white print. |
| branding/logo-favicon.svg | Color logo with a thicker stroke intended as a browser tab icon (not referenced in docs). |
Verification performed: the referenced asset paths resolve correctly, all SVGs are well-formed XML, and social-card.png is exactly 1200 × 630 as documented. The only finding is a minor documentation omission (the committed logo-favicon.svg is not mentioned in the asset manifest).
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| identifies the shared build and release toolchain. Use `logo-light.svg` on light | ||
| surfaces, `logo-dark.svg` on dark surfaces, and `logo-mono.svg` for black-on-white | ||
| print. `social-card.png` is the 1200 × 630 repository preview asset. |

Refresh the tools mascot and restore the failing Security Audit job by patching development dependencies. The illustrated mascot holds a silver open-end wrench with a straight handle and clear jaws, preserving the approved pink beetroot, green leaves, expressive face, and soft shading.
Validation:
pnpm format --check,pnpm lint, andpnpm testpass. The rendered logo and social card were visually checked. Published configuration packages are unchanged. The social-preview PNG is included for repository settings; this PR does not change those settings.The Security Audit failure is fixed by resolving
shell-quote1.11.0, raising the existingfast-urisecurity floor to 3.1.8, and overriding oxfmt’s exact vulnerabletinypoolpin with 2.1.2. All selected releases satisfy the existing seven-day maturity policy. The high-severity audit threshold, maturity policy, and direct package versions are unchanged. Frozen installation andpnpm audit --audit-level=highpass; the audit reports zero known vulnerabilities.CI: all jobs pass on the audit-fix commit, including Security Audit, Format, Lint, and Validate configs.