* fix(data): regenerate stale catalog-summary snapshot hashes
catalog-summary.json was not regenerated after google-fonts.csv,
google-font-licenses.json, icons.csv and phosphor-icons-upstream.json
changed, so `npm --prefix cli run verify:data` fails on a clean
checkout of main:
validate:semantic 4 stale snapshot errors
validate:catalog-summary "catalog-summary.json is stale"
test:python 1 failure / 153
check:assets 2 files out of sync
Regenerated with the existing --verified-at 2026-08-26: only the four
sha256 fields change. The date is a human attestation that the font
catalog was checked against the upstream google/fonts repository, so it
is deliberately left untouched -- no such verification was performed
here.
verify:data now exits 0.
Note: prepublishOnly runs sync:assets before verify:data, which
regenerates the snapshot at publish time. That is why released packages
are unaffected and the drift stayed invisible on main.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015UidECV1wVBD8SW6Abuj71
* fix(data): make catalog snapshot hashes line-ending independent
Root cause of the stale snapshot restored in the previous commit.
bd19ab9 (#462) regenerated catalog-summary.json from a CRLF checkout.
Every recorded sha256 was the CRLF hash of its source file, so the
check failed on every LF platform. The four committed values are
exactly sha256(crlf_bytes):
google-fonts.csv committed d03194d2… = CRLF hash
google-font-licenses.json committed 7c35e410… = CRLF hash
icons.csv committed 272ccf0e… = CRLF hash
phosphor-icons-upstream.json committed 81c37fb3… = CRLF hash
Two conditions had to combine: the digest hashed raw bytes, and no
.gitattributes pinned these files to LF, so Windows checkouts get CRLF
by default. Restoring the hashes alone would let the next contributor
on Windows reproduce the same commit.
Three changes:
- normalize line endings in generate-catalog-summary.py's digest(), so
the snapshot no longer depends on the checkout
- apply the same normalization in validate_data.py, which independently
recomputes the hashes and has to agree with the generator
- add .gitattributes pinning src/ui-ux-pro-max/data/*.{csv,json} to LF,
so a Windows checkout matches the committed bytes in the first place
sync-assets.mjs already normalizes to LF, so this only extends an
existing project convention to the two places that were missing it.
Adds test_catalog_summary_line_endings.py: LF and CRLF inputs must
digest identically, the committed snapshot must match the normalized
sources, and a simulated CRLF checkout must still produce the recorded
hashes. The third case fails against the pre-fix digest.
verify:data exits 0; the Python suite goes from 153 to 156 tests.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015UidECV1wVBD8SW6Abuj71
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>