Skip to content

chore(brand): vendor the hardened sync-brand-numbers.mjs - #68

Merged
VickyXAI merged 1 commit into
mainfrom
chore/brand-sync-script-hardening
Sep 15, 2026
Merged

VickyXAI merged 1 commit into
mainfrom
chore/brand-sync-script-hardening

Conversation

@VickyXAI

Copy link
Copy Markdown
Contributor

Vendored copy of sync-brand-numbers.mjs, verbatim from blockrun-mcp f9480ad2 (sha256 0c44bf15…).

The source of truth moves consumer → source this time, on purpose: the blockrun-mcp copy carries assertRenderable + escAttr (a value fetched from the mirror is refused, and attribute-escaped, before an unattended brand-sync bot pushes it into a README with contents: write — a quote or angle bracket in one value used to close the attribute and inject markup into every consuming README), keyOf() on the keys-in-use count, and a --check summary that does not print "up to date" under a list of stale markers. --check output is unchanged for this repo (verified locally on three consumers). Lockstep: all 14 consumers land first, then blockrun/brand, so brand-script-sync goes green again.

…rable/escAttr)

Verbatim from blockrun-mcp f9480ad2. A brand value fetched from the mirror
is now refused, and attribute-escaped, before the unattended brand-sync bot
writes it into this repo's markdown. --check output unchanged here.
@VickyXAI
VickyXAI merged commit 98525df into main Sep 15, 2026
4 checks passed
@VickyXAI
VickyXAI deleted the chore/brand-sync-script-hardening branch September 15, 2026 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant