v0.14.2 — adjacent-edge closures, SVG beacon fix, report CSP
Truth-and-security patch from adversarial review of 0.14.1.
Security
- External
url()references stripped from sanitized SVG (local#fragmentsonly) — hostile logos can no longer beacon out from brand-report.html - Restrictive CSP (
default-src 'none') on generated reports
The five 0.14.1 adjacent edges, actually closed (with edge tests)
- Publish gate keys on the open color clarification itself — on-palette-against-a-wrong-palette content can no longer earn "safe to publish"
- Preflight caps at WARN when CSS variables are unverifiable
- Token keys use the full hex (truncated suffix re-collided)
- Blog + CTA benchmark tasks gain real structural validators
- Receipt timestamps include seconds
Hygiene: SDK 1.29.0 lockfile sync • tarball 425 → 234 files (source maps excluded, pack-test enforced) • SECURITY.md "capabilities and why scanners flag them" section • two CodeQL false positives formally dismissed
Full changelog: https://github.com/Brandcode-Studio/brandsystem-mcp/blob/main/CHANGELOG.md