Skip to content

v0.14.2 — adjacent-edge closures, SVG beacon fix, report CSP

Choose a tag to compare

@zk-xyz zk-xyz released this 18 Jul 16:33
84e758f

Truth-and-security patch from adversarial review of 0.14.1.

Security

  • External url() references stripped from sanitized SVG (local #fragments only) — hostile logos can no longer beacon out from brand-report.html
  • Restrictive CSP (default-src 'none') on generated reports

The five 0.14.1 adjacent edges, actually closed (with edge tests)

  • Publish gate keys on the open color clarification itself — on-palette-against-a-wrong-palette content can no longer earn "safe to publish"
  • Preflight caps at WARN when CSS variables are unverifiable
  • Token keys use the full hex (truncated suffix re-collided)
  • Blog + CTA benchmark tasks gain real structural validators
  • Receipt timestamps include seconds

Hygiene: SDK 1.29.0 lockfile sync • tarball 425 → 234 files (source maps excluded, pack-test enforced) • SECURITY.md "capabilities and why scanners flag them" section • two CodeQL false positives formally dismissed

Full changelog: https://github.com/Brandcode-Studio/brandsystem-mcp/blob/main/CHANGELOG.md