Skip to content

v0.2.0

Choose a tag to compare

@dvhsh dvhsh released this 28 Sep 10:18
a64e34f

Added

  • Skill packs, for building, sharing and downloading osu! mappool packs with packs.haruhime.moe: its pages (the owner's /p/<slug>/edit and /brand too), pack keys, the "Add to osu! collection" card (osu!stable's collection.db, the osu!lazer zip for the setup wizard, and the file staying in the browser), downloads through the hinai mirror, and the API with its keys, pack stats, pinned packs and the search index. packs/api.md is a copy of the live API docs. It says pools.haruhime.moe is in beta, and that its packs are pools built there and past pools from tournament hosts, community submissions and sources like otdb.
  • Skill pools, for building an osu! tournament mappool on pools.haruhime.moe (in beta), editor v2.1 included: osu! sign-in for anyone, /new and its templates (Qualifiers, Group stage, Knockout, Finals), which set slot counts only, slot targets (0 to 16 maps and an optional star range), built-in and custom slots with forced mods, paste, drag and drop with keyboard buttons, slot notes that public pages show, covers and preview clips from osu!'s servers, undo (20 steps, no redo), export (IDs with slot labels, !mp map <id> 0 and !mp mods lines, CSV), Recent changes for the owner and editors, the map browser's mod lens with its filters, sort and Add, the summary, co-editors, visibility, the synced pack with Download on packs, and Start from this pool. Past pools from otdb, tournament hosts and community submissions stay as reference: pool search by type (past, built or both), every osu! map (Check first, Unranked and explicit maps), map history, the check and sending a pool. Mod values come from the hinai mirror, and there's no public API. pools/editor.md has the editor's detail and pools/search-links.md every link param; eval cases cover links, export and undo.
  • Skill haruhime-ui, for building a haruhime.moe tool's pages with @haruhimemoe/ui 0.4.0: setup, the theme and --hue, which component fits a job (haruhime-ui/components.md, with 0.4.0's confirms, tables, link tabs, header menu, badges, text links, disclosure, radio group, choice chips, osu! display pieces and cx), client and server components, and accessibility. Eval cases cover setup and the confirms.
  • Skill haruhime-next-kit, for building a haruhime.moe-style Next.js app's server side with @haruhimemoe/next-kit 0.1.0: the subpaths and their peers, wiring env, MongoDB, rate limits and osu! sign-in, a route handler, the osu! budget, bearer-auth routes and the test helpers. An eval case covers it.
  • llms.txt, listing every skill and reference file with a link to it.
  • A README banner, and the haruhime.moe Discord server wherever the docs list help (README, CONTRIBUTING, SECURITY and llms.txt).
  • Issue templates (a wrong or broken skill, a skill request, and links to the Discord server and private vulnerability reporting), a pull request checklist and CODEOWNERS.

Changed

  • The plugin description, README and llms.txt cover the pools.haruhime.moe pool builder, the UI components and the Next.js server kit, and the no-trigger-* evals fail if any skill loads.
  • haruhimemoe-packages covers every package at its npm version (pool 0.2.0, osu 0.3.0, hinai 0.3.0, compliance 0.1.1, ui 0.4.0, brand 0.4.0) and the new @haruhimemoe/next-kit 0.1.0: each entry point (/shapes, /collections, /format, /testing, /palette, /content-filter, /service), where each runs, which versions go together, and that every version is published with npm provenance from a GitHub release. It no longer names sheets.haruhime.moe, which isn't live. The packages-map eval accepts next-kit for sign-in.
  • osu-api-v2 covers osu 0.3.0: the browser-safe /collections (osu!stable's collection.db and the osu!lazer import) and /format entry points, a userAgent that must be printable ASCII, retryAfterMs null for a malformed Retry-After, and OSU_BEATMAPSET_FALLBACK_LIMIT.
  • hinai-mirror covers hinai 0.3.0: it needs osu 0.3.x, the /testing msw mocks, a server userAgent or baseUrl that throws RangeError, an already-aborted signal and a safe forensicsUrl. Client details moved to hinai-mirror/client.md.
  • osu-mappool-data covers pool 0.2.0: the clash and digits code rules, changesStarRating, ratingMods, speedRate, displayPoolName for untrusted key names, and the /content-filter and /service entry points. pack-key-format.md checked against 0.2.0 (the spec is unchanged).
  • haruhime-brand covers brand 0.4.0: the parent haruhime brand, README banners, the 11 files the CLI writes, the browser-safe /palette entry, favicon.ico counted as a conflict, and the CLI stopping at symlinks that lead outside --root. Sites take the palette tokens from @haruhimemoe/ui's theme.css. The brand-edge eval allows /palette in an edge runtime.
  • osu-mappool-content-rules covers compliance 0.1.1: hand-built facts without moreInformation need 0.1.1, and label tracks match by substring, so short track names flag unrelated titles.
  • scripts/validate.mjs also checks that llms.txt lists exactly the skills and reference files there are, that both manifests carry the same description, that every eval case with a skill-fired grader also grades the answer, and that the no-trigger-* patterns catch every skill.
  • CONTRIBUTING and AGENTS.md say skill changes reach existing installs only when a release bumps the plugin's version.

Fixed

  • hinai-mirror: download one or two sets at a time, as the mirror asks (it said four). What an abort rejects with, which failures aren't a HinaiError, and what the shed and budget errors mean.
  • osu-api-v2: getBeatmapsets keys its sets by difficulty id, any error status on a /beatmaps call throws (not only 429 and 5xx), and bad ids given to the batch lookups never throw.
  • osu-mappool-content-rules: the Mlumìn // SoundWarper and MEGAREX gaps in the compliance data, and disallowed verdicts without a reason.
  • haruhime-brand: adding a product no longer tells you to release a version. Releases are cut by the maintainers.
  • haruhime-brand: brandFiles and previewHtml load the native PNG renderer too, not only svgToPng and the CLI.
  • haruhime-brand: sheets.haruhime.moe isn't live yet, so the product table no longer links it.

Security

  • CI runs its actions from pinned commit SHAs, and Dependabot groups their updates. SECURITY.md lists GitHub private vulnerability reporting first, then email.