Skip to content

Releases: Knowledge-Forge-AI/theme-forge-stellar-burst

Theme Forge Stellar Burst 0.5.0

Choose a tag to compare

@lair001 lair001 released this 14 Sep 22:00
6efe98f

Theme Forge Stellar Burst 0.5.0 adds the versioned Vector Scene compiler, deterministic SVG output, safe SVG import, accessibility metadata and bounded service protocol. The 0.4 library, CLI and directory-snapshot contracts remain supported.

The 0.5.0 Homebrew Formula is SVG-only. PNG/raster distribution is not claimed. Clip/mask expansion and embedded or external resource ingestion remain deferred. Homebrew availability is separate and must only be announced after the tap is published and authenticated.

The attached package/application and composed source archive are the qualified release bytes. SHA256SUMS binds the attached assets; the SBOMs describe their scanned surfaces and do not establish exhaustive native component discovery. No intermediate 0.1.1 publication is required.

Theme Forge Stellar Burst v0.4.0

Choose a tag to compare

@lair001 lair001 released this 06 Sep 04:20

Theme Forge Stellar Burst v0.4.0

Theme Forge Stellar Burst v0.4.0 provides a brand system engine and design-evidence workbench, featuring typed protocol adapters, deterministic rendering transformations, and verified distribution artifacts.

Coordinated Products

  • Core Package: Theme Forge Stellar Burst v0.4.0 (Published to npm registry; distribution package attached)
  • Desktop Companion: Theme Forge Nebular Fusion v0.1.0 (Knowledge-Forge-AI/theme-forge-nebular-fusion, macOS Apple Silicon aarch64-apple-darwin developer distribution)

Distribution Assets & Package Differentiation

This release distinguishes the staging source composition archive from the npm distribution package:

Asset Type Size SHA-256
theme-forge-stellar-burst-0.4.0.tgz Staging Source Composition Archive 1,299,876 bytes 90863cc5f0fb0de193ab89ef7730e875349b4ccc2a154753aaa8d0af3f975bad
knowledge-forge-ai-theme-forge-stellar-burst-0.4.0.tgz npm Distribution Package 548,758 bytes baac6608c91bf52fbdd5b84a41a9af3a074866d0e29700a03410b87575925263
SHA256SUMS-stellar-v0.4.0.txt Source & Staging Manifest 658 bytes 548cacd3a0df9a3affdd5454bdf867fd7759dd7cbb64262433646f5988e940f2
SHA256SUMS-npm-package-v0.4.0.txt Supplemental npm Package Manifest 121 bytes 558172772870fc63ca2940814ae8d75e807d1f0d07f43bdd439a343c2de81fe5

npm Package Details

  • Package Name: @knowledge-forge-ai/theme-forge-stellar-burst
  • Version: 0.4.0
  • SHA-256: baac6608c91bf52fbdd5b84a41a9af3a074866d0e29700a03410b87575925263
  • Integrity: sha512-Lo8LryYHsGTwGJF9WtdywzuEdkq4KdjGhDfDZ0c11zYrsjiThpsGrsSKS/uN0mqkQGIve5LbgIprwuJVrLpF6A==
  • Tarball Entries: 302 entries (under package/)
  • Binaries: tfsb (./dist/cli.js), tfsb-studio-service (./dist/service-protocol/server-cli.js)
  • Native Prebuilds Included: darwin-arm64, darwin-x64, linux-x64-gnu (fail-closed loader architecture)
  • Licensing: AGPL-3.0-or-later + separate commercial licensing (COMMERCIAL-LICENSE.md); third-party notices (NOTICE)

Verification & Source Binding

  • Composed Tree SHA-256: 2743d0ba09ee22e33c3d0ffd55cad9607745ce055ab55844aba043c6f08c5521
  • Public Merge Tree: a5deea96cfec03b565e205fcd6d9bbc1e6a752d1
  • Public Merge Commit: 4f6d7720204c895517b544ce706624776cefb6a0

Installation & Distribution Status

Install from the public npm registry:

npm install --global @knowledge-forge-ai/theme-forge-stellar-burst@0.4.0

To install directly from the verified release asset:

npm install --global https://github.com/Knowledge-Forge-AI/theme-forge-stellar-burst/releases/download/v0.4.0/knowledge-forge-ai-theme-forge-stellar-burst-0.4.0.tgz

Requires Node.js >=22.0.0.

Signing & Provenance Boundaries

  • npm Package: Local CLI publish channel; does not carry npm hosted provenance attestations (dist.attestations absent).
  • Desktop Application (nebular-fusion.app.tar.gz): macOS developer distribution with ad-hoc signing (Signature=adhoc). Apple Developer ID and Apple Notarization are not present as designed.

Measured Security & Supply Chain Coverage

  • CodeQL Security Analysis: 0 open security alerts under GitHub CodeQL (/code-scanning/alerts). Analyses evaluated JavaScript/TypeScript (103 rules, 45 SARIF results), C/C++ (95 rules, 0 results), and GitHub Actions workflows (23 rules, 0 results).
  • Software Bill of Materials (SBOM): Syft v1.51.1 cataloged 12 package entries across 6 distinct npm packages (@knowledge-forge-ai/theme-forge-stellar-burst, @knowledge-forge-ai/tfsb-raster-resvg, @resvg/resvg-wasm, @xmldom/xmldom, fflate, smol-toml) from the root package release payload. Available in SPDX (root-package.spdx.json), CycloneDX (root-package.cdx.json), and Syft JSON (root-package.syft.json).
  • Vulnerability Scanning: Grype CLI 0.118.0 scanned cataloged packages against vulnerability database schema v6.1.9 (built 2026-09-05T06:27:00Z) with 0 reported vulnerabilities (root-package.grype.json).

v0.3.0

Choose a tag to compare

@lair001 lair001 released this 24 Aug 13:37

Theme Forge Stellar Burst v0.3.0

Theme Forge Stellar Burst (TFSB) v0.3.0 advances the vector asset compiler and lifecycle system with productized archive analysis, Schema 2 TOML/SVG representation, typed primitive shapes and transformations, granular accessibility modes, explicit exact-common normalization, paired provenance schema 2, deterministic schema 1 to schema 2 migration, schema-2 reconciliation, raw versus normalized archive diffing, deterministic bundle/manifest compatibility, offline scriptless preview galleries, and frozen backward compatibility for schema 1 projects.

Highlights

  • Productized Pre-Import Analysis (tfsb analyze):
    Inspects upstream SVG archives and directory trees prior to import, classifying each entry into directly_importable, importable_with_normalization, unsupported, or unsafe. Provides per-asset and aggregate scan evidence, omission reporting, and deterministic single-envelope machine JSON (--json).

  • Schema 2 Vector Model & Typed Primitives:
    Introduces Schema 2 project and asset formats (schema_version = 2) supporting typed geometric primitives (circle, ellipse, rect, line, polyline, polygon), root and element-level presentation attributes, currentColor tokens, typed transforms (translate, scale, rotate), mixed and nested groups (up to depth 8), and typed local definitions and <use> references.

  • Granular Accessibility Modes:
    Provides structured accessibility modeling with three distinct modes:

    • labelled: Authored <title> and <desc> metadata.
    • decorative: Pure visual elements with explicit aria-hidden="true".
    • consumer_labelled: Reusable glyphs where accessibility is deferred to consumer context.
  • Direct Canonical Schema-2 Import & Exact-Common Normalization:
    Supports direct transactional import of canonical Schema 2 SVG archives (--schema 2), as well as explicit, deterministic normalization of common web SVGs (--normalize exact-common) backed by normalization map schema 1 (--normalization-map <file.toml>) and cryptographic tfsb-normalization-policy-v1 policy digests.

  • Provenance Schema 2 & Deterministic Migration (tfsb migrate):
    Maintains complete cryptographic paired-checkpoint provenance for both Schema 1 and Schema 2 assets (.tfsb/provenance.json schema 2). Provides safe, deterministic, whole-project migration from Schema 1 to Schema 2 (tfsb migrate) with non-destructive dry-run planning (--check), rollback safety, and verified byte-for-byte SVG and companion equivalence.

  • Schema-2 Reconciliation & Multi-Baseline Archive Diffing:
    Reconciles upstream archive revisions against Schema 2 canonical models and provenance records. Supports granular diffing (tfsb diff) against raw archive sources (--archive) and normalized canonical baselines.

  • Deterministic Bundling, Manifest Compatibility & Offline Previews:
    Exports and imports store-only deterministic ZIP bundles (tfsb bundle) with tfsb-manifest.json metadata. Generates offline, scriptless, fully escaped static HTML/CSS visual preview galleries (tfsb preview) across multi-size responsive grids.

  • Schema-1 Frozen Compatibility:
    Maintains complete backward compatibility for existing Schema 1 projects, preserving exact historical SVG compilation, build, install, check, list, format, and diff semantics.

Limits and Operational Boundaries

  • Archive Entries: Maximum 1,024 entries per archive.
  • Selected SVG Assets: Maximum 128 selected/mutating SVGs per project.
  • Per-Entry Size: Maximum 8 MiB per selected archive entry.
  • Selected Aggregate Size: Maximum 32 MiB aggregate selected uncompressed bytes.
  • Raw Archive Size: Maximum 128 MiB raw ZIP archive size.
  • Modeled Elements: Maximum 1,024 modeled element nodes per asset.
  • Group Nesting Depth: Maximum group nesting depth of 8.

Explicit Exclusions

  • No arbitrary XML or non-SVG namespaces.
  • No arbitrary CSS styling, inline <style> tags, or style attributes.
  • No embedded scripts (<script>), event handlers, <image> raster references, <foreignObject>, animations, or external URL references (http://, https://, data:, //).
  • No full external warehouse lifecycle claim.
  • No path-derived collection or directory identity.
  • No directory import or directory reconciliation.
  • No mutation limits above the established boundaries.
  • No Studio / GUI application.

Upgrading from v0.2.0

  1. Schema 1 Projects: Existing Schema 1 projects continue to function without modification.
  2. Migrating to Schema 2: Run tfsb migrate --check to preview migration changes, then tfsb migrate to atomically upgrade .tfsb/project.toml, .tfsb/assets/*.toml, and .tfsb/provenance.json to Schema 2.
  3. Receipts: Run tfsb build to ensure build receipts are synchronized with the current toolchain.

Installation

npm install --global @knowledge-forge-ai/theme-forge-stellar-burst@0.3.0

License

GNU Affero General Public License v3.0 or later (AGPL-3.0-or-later). Commercial licensing options are available for proprietary terms (COMMERCIAL-LICENSE.md).

v0.2.0

Choose a tag to compare

@lair001 lair001 released this 23 Aug 00:19

Theme Forge Stellar Burst v0.2.0

Theme Forge Stellar Burst (TFSB) v0.2.0 expands from an initial compiler into a complete lifecycle management system for vector assets. It introduces safe upstream archive reconciliation with paired-checkpoint provenance, deterministic bundle export/import, semantic multi-baseline diffing, canonical formatting, static offline visual preview galleries, versioned JSON machine automation, and relocatable v3 build receipts.

Highlights

  • Safe Incremental Reconciliation (tfsb reconcile):
    Reconcile upstream ZIP archives safely against paired-checkpoint provenance (.tfsb/provenance.json). Reconcile is read-only by default (--dry-run), never deletes omitted assets silently (turning them into accepted tombstones), and requires explicit per-record authority (--resolve, --rename, --rename-companion, --remove, --remove-companion) for conflicts, renames, and deletions. Commits via atomic transactional swap (--apply).

  • Deterministic Bundle Export & Manifest Import (tfsb bundle, tfsb import --manifest):
    Export canonical vector assets and companions as store-only (level 0), deterministic ZIP bundles containing tfsb-manifest.json with cryptographic SHA-256 digests. Manifest-assisted import preserves declared asset IDs and file names across environments without leaking private install destinations or provenance history.

  • Semantic Multi-Baseline Diffing (tfsb diff):
    Compare canonical .tfsb semantics against four operational baselines: --provenance (default), --archive <file.zip>, --build, and --install. Uses the frozen tfsb-path-text-v1 digest for granular path comparisons and exits 0 (clean), 2 (valid semantic difference), or 1 (invalid/unavailable baseline).

  • Canonical Formatter (tfsb fmt):
    Canonically format .tfsb/project.toml and .tfsb/assets/*.toml with deterministic whitespace and key layout in a single whole-tree transaction. Non-destructive --check mode exits 2 when formatting differences exist.

  • Offline Static Preview Gallery (tfsb preview):
    Generate an offline, scriptless, fully escaped HTML/CSS asset gallery in .tfsb-preview. Renders directly from canonical TOML models across multiple responsive sizes (16px to 256px) and displays build/install drift badges without requiring an HTTP server or JavaScript.

  • Versioned JSON Machine Results (--json):
    All inspection and lifecycle query commands (check, list, reconcile, diff, bundle, fmt, preview) emit a single schema-version-1 JSON envelope with deterministic key order for script and CI/CD integration.

  • Relocatable v3 Build Receipts:
    Emits tfsb-build-v3 receipts tracking normalized project install policy evidence alongside build output hashes. Transparently accepts existing tfsb-build-v2 receipts for check, build, and install, upgrading them on the next build.

  • Terminal Nova Qualification:
    Fully qualified against the production asset corpus of Theme Forge Terminal Nova across multi-browser visual baselines (Chromium, Firefox, WebKit).

Upgrading from v0.1.0

Upgrading from v0.1.0 is seamless and backward-compatible:

  1. Provenance Bootstrap:
    To establish paired-checkpoint provenance for an existing project, run tfsb reconcile <matching-archive.zip> --apply using an archive that matches your current canonical assets. If the archive differs, provide explicit resolution flags (--resolve, --rename, --remove).

  2. Build Receipt Upgrade:
    Existing tfsb-build-v2 receipts continue to serve as valid build ownership evidence for tfsb check, tfsb build, and tfsb install. Run tfsb build once to upgrade to a tfsb-build-v3 receipt with project policy evidence, which unlocks tfsb diff --build.

  3. Preview Directory:
    The .tfsb-preview gallery directory is generated output and should be added to .gitignore.

Scope and Boundaries

  • Runtime: Requires Node.js >=22.0.0.
  • Bounded SVG Profile: Supports a safe declarative subset (paths, groups, linear gradients, use references, accessibility tags). Arbitrary scripts, CSS <style> blocks, external resources, foreign objects, animations, and non-linear gradients fail closed.
  • Local Archives Only: All import, reconcile, diff, and bundle operations operate strictly on local filesystem ZIP archives; remote network downloads are excluded.
  • Companion Documents: Preserves explicitly selected text documentation (*.md, *.markdown, *.txt) and well-known legal documents (LICENSE, NOTICE, COPYING, COPYRIGHT) byte-for-byte. Executable scripts and code files fail closed.
  • Limits: Max 1,024 archive entries, max 128 selected/mutating SVG assets, 8 MiB per selected entry, 32 MiB aggregate selected bytes, and 128 MiB raw archive size. Full external icon warehouses are not a v0.2 lifecycle target.

Installation

npm install --global @knowledge-forge-ai/theme-forge-stellar-burst@0.2.0

License

GNU Affero General Public License v3.0 or later (AGPL-3.0-or-later). Commercial licensing options are available for proprietary terms (COMMERCIAL-LICENSE.md).

v0.1.0

Choose a tag to compare

@lair001 lair001 released this 22 Aug 11:42

Theme Forge Stellar Burst v0.1.0

Theme Forge Stellar Burst (TFSB) is a deterministic declarative SVG compiler, transactional installer, and drift checker. It brings software-engineering discipline to vector asset pipelines by turning human-editable TOML into the canonical single source of truth for SVGs.

Highlights

  • Declarative SVG TOML Schema (schema_version = 1): Define SVGs in clean, human-editable TOML (.tfsb/project.toml and .tfsb/assets/*.toml) with full support for canvases (with optional width/height), accessibility (<title>, <desc>, focusable), linear gradients, groups, stroked/filled paths, presentation attributes (opacity, aria_hidden), and transformed <use> references.
  • Safe In-Memory Archive Import (tfsb import): Import local SVG ZIP archives with fail-closed security: rejects path traversal (..), symlinks, and invalid constructs before writing TOML. Ignores ordinary safe non-SVG entries by default and supports explicit --companion <path> selection.
  • Deterministic Rebuild (tfsb build): Rebuild exact, standards-compliant SVG files from TOML source with deterministic attribute order and byte-for-byte reproducibility, emitting cryptographic .tfsb-build.json receipts.
  • Transactional Installation (tfsb install): Distribute compiled SVGs and companion documents across repository target destinations with atomic writes, backup, and rollback.
  • Cryptographic Drift Detection (tfsb check): Verify that source TOML, build output, and installed target SVGs and companion documents remain perfectly synchronized (exit 0 clean, 1 invalid schema, 2 drift detected).
  • CLI Inspection & Ergonomics (tfsb list, --help, --version): Inspect managed assets, companion documents, target paths, and project structure with ancestor root discovery.
  • Browser Visual Parity Qualified: Tested across Chromium, Firefox, and WebKit to guarantee pixel-equivalent rendering between original imports and rebuilt artifacts.

Scope and Boundaries

  • Bounded Declarative Language: TFSB compiles a bounded SVG declarative language and can carry explicitly selected opaque text companion documents with an SVG bundle. Companion documents are copied byte-for-byte; they are never parsed as SVG, transformed, executed, or generalized into arbitrary package installation.
  • Runtime: Requires Node.js >=22.0.0.
  • Format: SVG-only and opaque text companion documents. Does not process raster images or font packages.
  • Bounded Subset: Bounded declarative SVG profile. Scripts, CSS stylesheets, animations, filter effects, and foreign XML elements fail closed rather than guessing or silently degrading.
  • Local Confinement: Operates strictly on local file archives and strictly confines all write operations to the project directory boundary.

Installation

npm install --global @knowledge-forge-ai/theme-forge-stellar-burst

Quick Start

# 1. Import local SVG zip (optionally selecting companion documents)
tfsb import path/to/assets.zip --root . --companion README.md

# 2. Build canonical SVGs
tfsb build

# 3. Install to configured project locations
tfsb install

# 4. Check for any source/build/install drift
tfsb check

License

GNU Affero General Public License v3.0 or later (AGPL-3.0-or-later). Commercial licensing options are available for proprietary terms (COMMERCIAL-LICENSE.md).