Move the design system's build and checks into this repository (no release) - #2
Merged
Merged
Conversation
A byte-for-byte copy of supergraphics.css from @mfb/shared (sha256 9e8a9630...9324), with nothing added: the build appends it unchanged to the published supergraphics.css, so any added byte would change a published file. Its origin is recorded in CONTRIBUTING.md and in the build script, not in the file. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/build-design-package.mjs is the build that used to run outside this repository, made repository-relative: - root tokens.json is the source; src/supergraphics.canon.css is the canon; - the geometry gate still runs before any file is written; - it no longer writes package.json (the version is edited by hand and a version bump is what releases); the README install pin reads it; - the emitted headers and the README template are unchanged, so all published files rebuild byte-identical to master. Usage: node scripts/build-design-package.mjs [OUT_DIR] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/brand-spec.mjs fills src/brand-spec.template.md with values read from tokens.json and writes brand-spec.md at the root. brand-spec.md is public but not in package.json's files, so consumers install nothing new. The prose is the rule set of the former generator, cleaned for a public repository: no date stamps, no machine paths, no internal system or database names, no restart or token-expiry lines, no em-dashes, and the stale lines corrected (CSS variable names, logo file names, the highlighter class). The generator refuses to write on a missing token, an unfilled placeholder, or an em-dash, machine path or date stamp in the result. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/check.mjs rebuilds the package and the spec into a temporary directory and fails when any committed output differs, when the build or the spec generator refuses, or when package.json gains scripts or dependencies (a git dependency's prepare runs on every consumer install). scripts/verify-figma.mjs checks tokens.json against the Brand Book page in Figma (colors as rendered fills, font sizes and weights as rendered text styles). It reads Figma only: the comparison with other repositories and the staleness block of the former script are left out. --summary writes a Markdown summary, --status FILE the JSON result. It is not run in GitHub Actions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
.github/workflows/design.yml runs rebuild-check on every event, version-check on pull requests, and release on pushes to master (it tags package.json's version when it has no tag yet and creates a GitHub Release). Only actions/checkout (v7.0.1, 3d3c42e5) and actions/setup-node (v7.0.0, 82076278), pinned by full SHA; workflow token read-only, write only in the release job; no workflow-level paths filter; no Figma check and no secret. CONTRIBUTING.md describes the files, the checks, the release rule, the brand-change loop, the Figma check, the supergraphics canon's origin and where the earlier history lives. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- design.yml release job: read the tag with git ls-remote --exit-code, so an unreadable remote fails closed instead of releasing; act only on the push that raised the version (a later push never tags); refuse a version that is not above the newest v* tag; warn when published files change without a bump. Full history is fetched so github.event.before is available. - check.mjs: package.json may not have peerDependencies or peerDependenciesMeta either (npm 7+ installs peer dependencies). - CONTRIBUTING: Quentin accepts the version (no approval rule yet); the release job's push rule; the canon is the origin in this repository. - brand-spec template: correct what theme.css and tailwind.js carry; replace the stale gradient rule with the deprecation. brand-spec.md regenerated. - verify-figma: the mono and gradient notes say they are deprecated. The 8 published files are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The design system's build, its checks and its written guide move into this repository, so this repository becomes the
single source of the design system. The 8 published files are unchanged byte for byte, and the version stays 1.3.0, so
no project that pins a tag sees any difference until it chooses to move.
What is added
scripts/build-design-package.mjs: the build, now readingtokens.jsonandsrc/supergraphics.canon.cssfrom thisrepository. It no longer writes
package.json; its output headers are unchanged.src/supergraphics.canon.css: an identical copy of the supergraphics source (a weekly check keeps the two in step).scripts/brand-spec.mjs,src/brand-spec.template.mdandbrand-spec.md: the written brand guide, cleaned for apublic repository. It is not part of the published package.
scripts/check.mjs: rebuilds everything into a temporary folder and fails if any committed output differs.scripts/verify-figma.mjs: the Figma comparison, run on the Monday check, not in Actions..github/workflows/design.yml:rebuild-checkon every change,version-checkon pull requests, andreleaseonmaster, which creates a tag only when a merged change raises the version. GitHub-owned actions only, pinned by SHA;
read-only by default.
CONTRIBUTING.md: how a brand change travels from Figma to a release.Checked before opening: a fresh build reproduces all 8 published files identically to master (
cmp);npm pack --dry-runlists the same 8 files;scripts/check.mjspasses and fails on every tampered case tried; theversion and release logic was exercised against the live tags.
Not in this change: no version bump, so merging releases nothing; existing tags are protected by the
design-tagsruleset.
🤖 Generated with Claude Code