Reverify the full stack catalog against Nuxt UI 4.11.1 and correct stale API examples. Add Splitter, ProgressGroup, motion, Vite detection, and CommandPalette security guidance.
Co-authored-by: Ray <ray.tien@cloudeep.com.tw>
Squash-merged by github-maintain cron after maintainer approval (review 2026-06-20 by @mrgoonie) and conflict resolution (rebase to head 4bd45ba5, all checks green).
Refs #474 (finding 1 follow-up to #476, which rewrote design/SKILL.md
and added a contract that grepped only */SKILL.md; the same defect one
level down survived).
- 29 home-rooted paths (~/.claude/skills/design/scripts/...) in
design/references/{cip,icon,logo}-design.md -> scripts/... (27 at
review time, two more added by #470); the printed
hint in design/scripts/cip/generate.py now derives the absolute path
from __file__
- 19 project-rooted invocations (.claude/skills/<skill>/scripts/...) in
brand/, slides/ and design/ references -> scripts/... (own skill) or
../<skill>/scripts/... (sibling sub-skill; sub-skills are installed
side by side in every layout)
- brand/scripts/sync-brand-to-tokens.cjs resolved its sibling script from
process.cwd(), silently skipping CSS regeneration under plugin and
--global installs; now resolved from __dirname, with a warning when
the sibling skill is missing; regression test asserts the regeneration
- brand/scripts/extract-colors.cjs: tool-neutral hint instead of a
project-rooted path into a skill this plugin does not ship
- "Script Paths" section in the five sub-skills that invoke scripts:
script path from the skill directory, working directory at the
project root
- new test_skill_script_paths.py (src, mirrored to both scripts/tests
copies): every python/node/bash invocation in every shipped skill
markdown must be skill-relative and name a file that ships
- check-asset-sync.yml: contract covers every file under both skill
trees and home-/project-/variable-rooted forms; ${CLAUDE_PLUGIN_ROOT}
allowed only in the plugin-only core SKILL.md; LC_ALL=C + -I for the tracked
.coverage binary; grep errors fail instead of passing; push filter
includes the workflow and sync-assets.mjs
- CLI copy regenerated via sync-assets.mjs
Co-authored-by: notbucki <daniel@buckenmaier.xyz>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* fix(data): regenerate stale catalog-summary snapshot hashes
catalog-summary.json was not regenerated after google-fonts.csv,
google-font-licenses.json, icons.csv and phosphor-icons-upstream.json
changed, so `npm --prefix cli run verify:data` fails on a clean
checkout of main:
validate:semantic 4 stale snapshot errors
validate:catalog-summary "catalog-summary.json is stale"
test:python 1 failure / 153
check:assets 2 files out of sync
Regenerated with the existing --verified-at 2026-08-26: only the four
sha256 fields change. The date is a human attestation that the font
catalog was checked against the upstream google/fonts repository, so it
is deliberately left untouched -- no such verification was performed
here.
verify:data now exits 0.
Note: prepublishOnly runs sync:assets before verify:data, which
regenerates the snapshot at publish time. That is why released packages
are unaffected and the drift stayed invisible on main.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015UidECV1wVBD8SW6Abuj71
* fix(data): make catalog snapshot hashes line-ending independent
Root cause of the stale snapshot restored in the previous commit.
bd19ab9 (#462) regenerated catalog-summary.json from a CRLF checkout.
Every recorded sha256 was the CRLF hash of its source file, so the
check failed on every LF platform. The four committed values are
exactly sha256(crlf_bytes):
google-fonts.csv committed d03194d2… = CRLF hash
google-font-licenses.json committed 7c35e410… = CRLF hash
icons.csv committed 272ccf0e… = CRLF hash
phosphor-icons-upstream.json committed 81c37fb3… = CRLF hash
Two conditions had to combine: the digest hashed raw bytes, and no
.gitattributes pinned these files to LF, so Windows checkouts get CRLF
by default. Restoring the hashes alone would let the next contributor
on Windows reproduce the same commit.
Three changes:
- normalize line endings in generate-catalog-summary.py's digest(), so
the snapshot no longer depends on the checkout
- apply the same normalization in validate_data.py, which independently
recomputes the hashes and has to agree with the generator
- add .gitattributes pinning src/ui-ux-pro-max/data/*.{csv,json} to LF,
so a Windows checkout matches the committed bytes in the first place
sync-assets.mjs already normalizes to LF, so this only extends an
existing project convention to the two places that were missing it.
Adds test_catalog_summary_line_endings.py: LF and CRLF inputs must
digest identically, the committed snapshot must match the normalized
sources, and a simulated CRLF checkout must still produce the recorded
hashes. The third case fails against the pre-fix digest.
verify:data exits 0; the Python suite goes from 153 to 156 tests.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015UidECV1wVBD8SW6Abuj71
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
generate() ranked style, palette and anti-patterns independently, so a
dark-primary style could come back with a light palette and a
"Dark mode by default" anti-pattern in the same output. The palette is
what users copy into CSS variables, so the output shipped a light theme
with dark-theme styling instructions attached.
Resolve the mode first -- from the query keywords and the style's own
Light/Dark Mode columns -- then pick a palette whose Background matches
it and drop mode-contradicting anti-pattern clauses.
Only the dark case filters palettes. Light keeps the existing top-hit
behaviour so queries that never mention a mode are untouched, and dark
falls back to the top hit when colors.csv has no dark ramp for the
product type.
Adds scripts/tests/test_design_system_mode.py (stdlib unittest, matching
test_core.py) and syncs cli/assets + .claude/skills via sync-assets.mjs.
Merged by github-maintain cron. Approved by @clark-cant and @jizc. Pre-existing pytest failure on main (ui-styling/shadcn test) is unrelated to PR scope.