Releases: Knowledge-Forge-AI/theme-forge-stellar-burst
Release list
Theme Forge Stellar Burst 0.5.0
Theme Forge Stellar Burst 0.5.0 adds the versioned Vector Scene compiler, deterministic SVG output, safe SVG import, accessibility metadata and bounded service protocol. The 0.4 library, CLI and directory-snapshot contracts remain supported.
The 0.5.0 Homebrew Formula is SVG-only. PNG/raster distribution is not claimed. Clip/mask expansion and embedded or external resource ingestion remain deferred. Homebrew availability is separate and must only be announced after the tap is published and authenticated.
The attached package/application and composed source archive are the qualified release bytes. SHA256SUMS binds the attached assets; the SBOMs describe their scanned surfaces and do not establish exhaustive native component discovery. No intermediate 0.1.1 publication is required.
Theme Forge Stellar Burst v0.4.0
Theme Forge Stellar Burst v0.4.0
Theme Forge Stellar Burst v0.4.0 provides a brand system engine and design-evidence workbench, featuring typed protocol adapters, deterministic rendering transformations, and verified distribution artifacts.
Coordinated Products
- Core Package: Theme Forge Stellar Burst v0.4.0 (Published to npm registry; distribution package attached)
- Desktop Companion: Theme Forge Nebular Fusion v0.1.0 (
Knowledge-Forge-AI/theme-forge-nebular-fusion, macOS Apple Siliconaarch64-apple-darwindeveloper distribution)
Distribution Assets & Package Differentiation
This release distinguishes the staging source composition archive from the npm distribution package:
| Asset | Type | Size | SHA-256 |
|---|---|---|---|
theme-forge-stellar-burst-0.4.0.tgz |
Staging Source Composition Archive | 1,299,876 bytes | 90863cc5f0fb0de193ab89ef7730e875349b4ccc2a154753aaa8d0af3f975bad |
knowledge-forge-ai-theme-forge-stellar-burst-0.4.0.tgz |
npm Distribution Package | 548,758 bytes | baac6608c91bf52fbdd5b84a41a9af3a074866d0e29700a03410b87575925263 |
SHA256SUMS-stellar-v0.4.0.txt |
Source & Staging Manifest | 658 bytes | 548cacd3a0df9a3affdd5454bdf867fd7759dd7cbb64262433646f5988e940f2 |
SHA256SUMS-npm-package-v0.4.0.txt |
Supplemental npm Package Manifest | 121 bytes | 558172772870fc63ca2940814ae8d75e807d1f0d07f43bdd439a343c2de81fe5 |
npm Package Details
- Package Name:
@knowledge-forge-ai/theme-forge-stellar-burst - Version:
0.4.0 - SHA-256:
baac6608c91bf52fbdd5b84a41a9af3a074866d0e29700a03410b87575925263 - Integrity:
sha512-Lo8LryYHsGTwGJF9WtdywzuEdkq4KdjGhDfDZ0c11zYrsjiThpsGrsSKS/uN0mqkQGIve5LbgIprwuJVrLpF6A== - Tarball Entries: 302 entries (under
package/) - Binaries:
tfsb(./dist/cli.js),tfsb-studio-service(./dist/service-protocol/server-cli.js) - Native Prebuilds Included:
darwin-arm64,darwin-x64,linux-x64-gnu(fail-closed loader architecture) - Licensing: AGPL-3.0-or-later + separate commercial licensing (
COMMERCIAL-LICENSE.md); third-party notices (NOTICE)
Verification & Source Binding
- Composed Tree SHA-256:
2743d0ba09ee22e33c3d0ffd55cad9607745ce055ab55844aba043c6f08c5521 - Public Merge Tree:
a5deea96cfec03b565e205fcd6d9bbc1e6a752d1 - Public Merge Commit:
4f6d7720204c895517b544ce706624776cefb6a0
Installation & Distribution Status
Install from the public npm registry:
npm install --global @knowledge-forge-ai/theme-forge-stellar-burst@0.4.0To install directly from the verified release asset:
npm install --global https://github.com/Knowledge-Forge-AI/theme-forge-stellar-burst/releases/download/v0.4.0/knowledge-forge-ai-theme-forge-stellar-burst-0.4.0.tgzRequires Node.js >=22.0.0.
Signing & Provenance Boundaries
- npm Package: Local CLI publish channel; does not carry npm hosted provenance attestations (
dist.attestationsabsent). - Desktop Application (
nebular-fusion.app.tar.gz): macOS developer distribution with ad-hoc signing (Signature=adhoc). Apple Developer ID and Apple Notarization are not present as designed.
Measured Security & Supply Chain Coverage
- CodeQL Security Analysis: 0 open security alerts under GitHub CodeQL (
/code-scanning/alerts). Analyses evaluated JavaScript/TypeScript (103 rules, 45 SARIF results), C/C++ (95 rules, 0 results), and GitHub Actions workflows (23 rules, 0 results). - Software Bill of Materials (SBOM): Syft v1.51.1 cataloged 12 package entries across 6 distinct npm packages (
@knowledge-forge-ai/theme-forge-stellar-burst,@knowledge-forge-ai/tfsb-raster-resvg,@resvg/resvg-wasm,@xmldom/xmldom,fflate,smol-toml) from the root package release payload. Available in SPDX (root-package.spdx.json), CycloneDX (root-package.cdx.json), and Syft JSON (root-package.syft.json). - Vulnerability Scanning: Grype CLI 0.118.0 scanned cataloged packages against vulnerability database schema v6.1.9 (built 2026-09-05T06:27:00Z) with 0 reported vulnerabilities (
root-package.grype.json).
v0.3.0
Theme Forge Stellar Burst v0.3.0
Theme Forge Stellar Burst (TFSB) v0.3.0 advances the vector asset compiler and lifecycle system with productized archive analysis, Schema 2 TOML/SVG representation, typed primitive shapes and transformations, granular accessibility modes, explicit exact-common normalization, paired provenance schema 2, deterministic schema 1 to schema 2 migration, schema-2 reconciliation, raw versus normalized archive diffing, deterministic bundle/manifest compatibility, offline scriptless preview galleries, and frozen backward compatibility for schema 1 projects.
Highlights
-
Productized Pre-Import Analysis (
tfsb analyze):
Inspects upstream SVG archives and directory trees prior to import, classifying each entry intodirectly_importable,importable_with_normalization,unsupported, orunsafe. Provides per-asset and aggregate scan evidence, omission reporting, and deterministic single-envelope machine JSON (--json). -
Schema 2 Vector Model & Typed Primitives:
Introduces Schema 2 project and asset formats (schema_version = 2) supporting typed geometric primitives (circle,ellipse,rect,line,polyline,polygon), root and element-level presentation attributes,currentColortokens, typed transforms (translate,scale,rotate), mixed and nested groups (up to depth 8), and typed local definitions and<use>references. -
Granular Accessibility Modes:
Provides structured accessibility modeling with three distinct modes:labelled: Authored<title>and<desc>metadata.decorative: Pure visual elements with explicitaria-hidden="true".consumer_labelled: Reusable glyphs where accessibility is deferred to consumer context.
-
Direct Canonical Schema-2 Import & Exact-Common Normalization:
Supports direct transactional import of canonical Schema 2 SVG archives (--schema 2), as well as explicit, deterministic normalization of common web SVGs (--normalize exact-common) backed by normalization map schema 1 (--normalization-map <file.toml>) and cryptographictfsb-normalization-policy-v1policy digests. -
Provenance Schema 2 & Deterministic Migration (
tfsb migrate):
Maintains complete cryptographic paired-checkpoint provenance for both Schema 1 and Schema 2 assets (.tfsb/provenance.jsonschema 2). Provides safe, deterministic, whole-project migration from Schema 1 to Schema 2 (tfsb migrate) with non-destructive dry-run planning (--check), rollback safety, and verified byte-for-byte SVG and companion equivalence. -
Schema-2 Reconciliation & Multi-Baseline Archive Diffing:
Reconciles upstream archive revisions against Schema 2 canonical models and provenance records. Supports granular diffing (tfsb diff) against raw archive sources (--archive) and normalized canonical baselines. -
Deterministic Bundling, Manifest Compatibility & Offline Previews:
Exports and imports store-only deterministic ZIP bundles (tfsb bundle) withtfsb-manifest.jsonmetadata. Generates offline, scriptless, fully escaped static HTML/CSS visual preview galleries (tfsb preview) across multi-size responsive grids. -
Schema-1 Frozen Compatibility:
Maintains complete backward compatibility for existing Schema 1 projects, preserving exact historical SVG compilation, build, install, check, list, format, and diff semantics.
Limits and Operational Boundaries
- Archive Entries: Maximum 1,024 entries per archive.
- Selected SVG Assets: Maximum 128 selected/mutating SVGs per project.
- Per-Entry Size: Maximum 8 MiB per selected archive entry.
- Selected Aggregate Size: Maximum 32 MiB aggregate selected uncompressed bytes.
- Raw Archive Size: Maximum 128 MiB raw ZIP archive size.
- Modeled Elements: Maximum 1,024 modeled element nodes per asset.
- Group Nesting Depth: Maximum group nesting depth of 8.
Explicit Exclusions
- No arbitrary XML or non-SVG namespaces.
- No arbitrary CSS styling, inline
<style>tags, or style attributes. - No embedded scripts (
<script>), event handlers,<image>raster references,<foreignObject>, animations, or external URL references (http://,https://,data:,//). - No full external warehouse lifecycle claim.
- No path-derived collection or directory identity.
- No directory import or directory reconciliation.
- No mutation limits above the established boundaries.
- No Studio / GUI application.
Upgrading from v0.2.0
- Schema 1 Projects: Existing Schema 1 projects continue to function without modification.
- Migrating to Schema 2: Run
tfsb migrate --checkto preview migration changes, thentfsb migrateto atomically upgrade.tfsb/project.toml,.tfsb/assets/*.toml, and.tfsb/provenance.jsonto Schema 2. - Receipts: Run
tfsb buildto ensure build receipts are synchronized with the current toolchain.
Installation
npm install --global @knowledge-forge-ai/theme-forge-stellar-burst@0.3.0License
GNU Affero General Public License v3.0 or later (AGPL-3.0-or-later). Commercial licensing options are available for proprietary terms (COMMERCIAL-LICENSE.md).
v0.2.0
Theme Forge Stellar Burst v0.2.0
Theme Forge Stellar Burst (TFSB) v0.2.0 expands from an initial compiler into a complete lifecycle management system for vector assets. It introduces safe upstream archive reconciliation with paired-checkpoint provenance, deterministic bundle export/import, semantic multi-baseline diffing, canonical formatting, static offline visual preview galleries, versioned JSON machine automation, and relocatable v3 build receipts.
Highlights
-
Safe Incremental Reconciliation (
tfsb reconcile):
Reconcile upstream ZIP archives safely against paired-checkpoint provenance (.tfsb/provenance.json). Reconcile is read-only by default (--dry-run), never deletes omitted assets silently (turning them into accepted tombstones), and requires explicit per-record authority (--resolve,--rename,--rename-companion,--remove,--remove-companion) for conflicts, renames, and deletions. Commits via atomic transactional swap (--apply). -
Deterministic Bundle Export & Manifest Import (
tfsb bundle,tfsb import --manifest):
Export canonical vector assets and companions as store-only (level 0), deterministic ZIP bundles containingtfsb-manifest.jsonwith cryptographic SHA-256 digests. Manifest-assisted import preserves declared asset IDs and file names across environments without leaking private install destinations or provenance history. -
Semantic Multi-Baseline Diffing (
tfsb diff):
Compare canonical.tfsbsemantics against four operational baselines:--provenance(default),--archive <file.zip>,--build, and--install. Uses the frozentfsb-path-text-v1digest for granular path comparisons and exits0(clean),2(valid semantic difference), or1(invalid/unavailable baseline). -
Canonical Formatter (
tfsb fmt):
Canonically format.tfsb/project.tomland.tfsb/assets/*.tomlwith deterministic whitespace and key layout in a single whole-tree transaction. Non-destructive--checkmode exits2when formatting differences exist. -
Offline Static Preview Gallery (
tfsb preview):
Generate an offline, scriptless, fully escaped HTML/CSS asset gallery in.tfsb-preview. Renders directly from canonical TOML models across multiple responsive sizes (16px to 256px) and displays build/install drift badges without requiring an HTTP server or JavaScript. -
Versioned JSON Machine Results (
--json):
All inspection and lifecycle query commands (check,list,reconcile,diff,bundle,fmt,preview) emit a single schema-version-1 JSON envelope with deterministic key order for script and CI/CD integration. -
Relocatable v3 Build Receipts:
Emitstfsb-build-v3receipts tracking normalized project install policy evidence alongside build output hashes. Transparently accepts existingtfsb-build-v2receipts forcheck,build, andinstall, upgrading them on the next build. -
Terminal Nova Qualification:
Fully qualified against the production asset corpus of Theme Forge Terminal Nova across multi-browser visual baselines (Chromium, Firefox, WebKit).
Upgrading from v0.1.0
Upgrading from v0.1.0 is seamless and backward-compatible:
-
Provenance Bootstrap:
To establish paired-checkpoint provenance for an existing project, runtfsb reconcile <matching-archive.zip> --applyusing an archive that matches your current canonical assets. If the archive differs, provide explicit resolution flags (--resolve,--rename,--remove). -
Build Receipt Upgrade:
Existingtfsb-build-v2receipts continue to serve as valid build ownership evidence fortfsb check,tfsb build, andtfsb install. Runtfsb buildonce to upgrade to atfsb-build-v3receipt with project policy evidence, which unlockstfsb diff --build. -
Preview Directory:
The.tfsb-previewgallery directory is generated output and should be added to.gitignore.
Scope and Boundaries
- Runtime: Requires Node.js
>=22.0.0. - Bounded SVG Profile: Supports a safe declarative subset (paths, groups, linear gradients, use references, accessibility tags). Arbitrary scripts, CSS
<style>blocks, external resources, foreign objects, animations, and non-linear gradients fail closed. - Local Archives Only: All import, reconcile, diff, and bundle operations operate strictly on local filesystem ZIP archives; remote network downloads are excluded.
- Companion Documents: Preserves explicitly selected text documentation (
*.md,*.markdown,*.txt) and well-known legal documents (LICENSE,NOTICE,COPYING,COPYRIGHT) byte-for-byte. Executable scripts and code files fail closed. - Limits: Max 1,024 archive entries, max 128 selected/mutating SVG assets, 8 MiB per selected entry, 32 MiB aggregate selected bytes, and 128 MiB raw archive size. Full external icon warehouses are not a v0.2 lifecycle target.
Installation
npm install --global @knowledge-forge-ai/theme-forge-stellar-burst@0.2.0License
GNU Affero General Public License v3.0 or later (AGPL-3.0-or-later). Commercial licensing options are available for proprietary terms (COMMERCIAL-LICENSE.md).
v0.1.0
Theme Forge Stellar Burst v0.1.0
Theme Forge Stellar Burst (TFSB) is a deterministic declarative SVG compiler, transactional installer, and drift checker. It brings software-engineering discipline to vector asset pipelines by turning human-editable TOML into the canonical single source of truth for SVGs.
Highlights
- Declarative SVG TOML Schema (
schema_version = 1): Define SVGs in clean, human-editable TOML (.tfsb/project.tomland.tfsb/assets/*.toml) with full support for canvases (with optionalwidth/height), accessibility (<title>,<desc>,focusable), linear gradients, groups, stroked/filled paths, presentation attributes (opacity,aria_hidden), and transformed<use>references. - Safe In-Memory Archive Import (
tfsb import): Import local SVG ZIP archives with fail-closed security: rejects path traversal (..), symlinks, and invalid constructs before writing TOML. Ignores ordinary safe non-SVG entries by default and supports explicit--companion <path>selection. - Deterministic Rebuild (
tfsb build): Rebuild exact, standards-compliant SVG files from TOML source with deterministic attribute order and byte-for-byte reproducibility, emitting cryptographic.tfsb-build.jsonreceipts. - Transactional Installation (
tfsb install): Distribute compiled SVGs and companion documents across repository target destinations with atomic writes, backup, and rollback. - Cryptographic Drift Detection (
tfsb check): Verify that source TOML, build output, and installed target SVGs and companion documents remain perfectly synchronized (exit0clean,1invalid schema,2drift detected). - CLI Inspection & Ergonomics (
tfsb list,--help,--version): Inspect managed assets, companion documents, target paths, and project structure with ancestor root discovery. - Browser Visual Parity Qualified: Tested across Chromium, Firefox, and WebKit to guarantee pixel-equivalent rendering between original imports and rebuilt artifacts.
Scope and Boundaries
- Bounded Declarative Language: TFSB compiles a bounded SVG declarative language and can carry explicitly selected opaque text companion documents with an SVG bundle. Companion documents are copied byte-for-byte; they are never parsed as SVG, transformed, executed, or generalized into arbitrary package installation.
- Runtime: Requires Node.js
>=22.0.0. - Format: SVG-only and opaque text companion documents. Does not process raster images or font packages.
- Bounded Subset: Bounded declarative SVG profile. Scripts, CSS stylesheets, animations, filter effects, and foreign XML elements fail closed rather than guessing or silently degrading.
- Local Confinement: Operates strictly on local file archives and strictly confines all write operations to the project directory boundary.
Installation
npm install --global @knowledge-forge-ai/theme-forge-stellar-burstQuick Start
# 1. Import local SVG zip (optionally selecting companion documents)
tfsb import path/to/assets.zip --root . --companion README.md
# 2. Build canonical SVGs
tfsb build
# 3. Install to configured project locations
tfsb install
# 4. Check for any source/build/install drift
tfsb checkLicense
GNU Affero General Public License v3.0 or later (AGPL-3.0-or-later). Commercial licensing options are available for proprietary terms (COMMERCIAL-LICENSE.md).