Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
b9cf23a
fix(animator): gate a timeline step's animation on its own at
LeadcodeDev Sep 25, 2026
5bda143
feat(svg): add a fill-reveal draw-on mode via `reveal: fill`
LeadcodeDev Sep 25, 2026
8afc4c1
fix(css): default flex-direction to column when unset
LeadcodeDev Sep 25, 2026
83f7ca6
fix(animator): rebase a start_at'ed node's animation clock on its own…
LeadcodeDev Sep 25, 2026
3ba6f76
fix(geometry): clamp content-overflow checks to the containing block'…
LeadcodeDev Sep 25, 2026
f99224b
docs(skills): document the svg reveal modes and how they compose
LeadcodeDev Sep 25, 2026
2ee05c1
docs(skills): teach the schema the binary actually accepts
LeadcodeDev Sep 25, 2026
4cce2e1
fix(encode): keep the incremental encoder's slot indices aligned
LeadcodeDev Sep 25, 2026
2cd2c98
fix(render): refuse flags the bundled encoder cannot honour
LeadcodeDev Sep 25, 2026
5d17cfe
fix(encode): make the ffmpeg path produce what the flags asked for
LeadcodeDev Sep 25, 2026
baee884
fix(security): close the file reads a scenario could reach
LeadcodeDev Sep 25, 2026
08aaace
feat(cli): validate in still the way render already does
LeadcodeDev Sep 25, 2026
a650157
fix(studio): stop writing scenarios the engine refuses
LeadcodeDev Sep 25, 2026
70bbf52
fix(components): paint inside the box layout assigned, not a self-com…
LeadcodeDev Sep 25, 2026
74b0f59
fix(geometry): measure against the real viewport and the real camera
LeadcodeDev Sep 25, 2026
ed5e1cf
feat(css): make mix-blend-mode, clip-path and visibility do something
LeadcodeDev Sep 25, 2026
72b74b3
fix(schema): describe the shapes the parser actually accepts
LeadcodeDev Sep 25, 2026
9ffb064
fix(cli,studio): drop the references text-decoration left behind
LeadcodeDev Sep 25, 2026
0915bea
fix(badge): stop overriding the alignment its parent asked for
LeadcodeDev Sep 25, 2026
de86870
fix(examples): make the corpus pass its own validator again
LeadcodeDev Sep 25, 2026
2e12aae
style(studio): reflow the line left by the text-decoration removal
LeadcodeDev Sep 25, 2026
2faca28
fix(layout): stop the taffy bridge from swallowing what it cannot tra…
LeadcodeDev Sep 25, 2026
6028508
fix(animator): stop the timing layer from failing quietly
LeadcodeDev Sep 25, 2026
2ae09e2
fix(schema): refuse the keys it used to swallow, and name them
LeadcodeDev Sep 25, 2026
5b81cd3
perf(renderer): cache text measurement instead of narrowing the threa…
LeadcodeDev Sep 25, 2026
e7b8b80
perf(encode): save frames on the threads that rendered them
LeadcodeDev Sep 25, 2026
4d2ca43
fix(encode): stop --watch from trusting a hash that ignores the files
LeadcodeDev Sep 25, 2026
09a33c3
fix(encode): check what the container and the codec can actually hold
LeadcodeDev Sep 25, 2026
8739c37
fix(expand): give each iteration its own scope instead of one flat pass
LeadcodeDev Sep 25, 2026
781b98f
fix(include): resolve directives before rebasing, and clone a repeate…
LeadcodeDev Sep 25, 2026
46d814b
fix(engine): make the scroll wrap, the camera stack and the world clo…
LeadcodeDev Sep 25, 2026
b12801c
fix(core,studio): let the paint pass and the studio use what the engi…
LeadcodeDev Sep 25, 2026
d9bcb33
style(expand): reflow the type-mismatch error construction
LeadcodeDev Sep 25, 2026
59d93e5
fix(ci): gate publishing on main, and take the fixes that were alread…
LeadcodeDev Sep 25, 2026
f1d5d37
fix(html): refuse what the dialect cannot express, and reach what it …
LeadcodeDev Sep 25, 2026
9b47e8e
docs(skills): update the dialect reference to what it now does
LeadcodeDev Sep 25, 2026
a7c814a
fix(chart): stop the charts from drawing a plausible wrong answer
LeadcodeDev Sep 25, 2026
3da2f01
docs(skills): document the radial bar's explicit maximum
LeadcodeDev Sep 25, 2026
ba9b361
fix(security): guard every ffmpeg input, not one of four
LeadcodeDev Sep 25, 2026
ee173f6
fix(paint): stop the paint pass from clipping, dropping and double-pa…
LeadcodeDev Sep 25, 2026
1233e80
fix(studio,cli): make the editor and the validator report what they see
LeadcodeDev Sep 25, 2026
0ef48b9
fix(components): spend the typewriter budget in characters, and stop …
LeadcodeDev Sep 25, 2026
347c609
fix(cli): keep key order through --fix, and refuse transparency befor…
LeadcodeDev Sep 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
51 changes: 30 additions & 21 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ on:
env:
CARGO_TERM_COLOR: always

permissions:
contents: read

jobs:
fmt:
runs-on: ubuntu-latest
Expand Down Expand Up @@ -56,42 +59,48 @@ jobs:
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable channel, 2026-09-22
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
- name: Install cargo-audit
run: cargo install cargo-audit --locked
run: cargo install cargo-audit --version 0.22.2 --locked
# Blocking on any advisory not listed below — a newly introduced
# vulnerability fails this job. Every `--ignore` is a pre-existing
# transitive-dependency advisory tolerated today because the fix is a
# dependency version bump, and version bumps for the published
# `rustmotion` crate are being handled separately from this workstream
# (crates/rustmotion/Cargo.toml, orchestrator-owned). Unmaintained/
# unsound/yanked advisories (17 as of 2026-09-22) print but do not fail
# unsound/yanked advisories (13 as of 2026-09-25) print but do not fail
# the job — that's `cargo audit`'s own default, left unchanged here.
#
# rustls/rustls-webpki (RUSTSEC-2026-0285, -0104, -0098, -0099, -0049) and
# crossbeam-epoch (RUSTSEC-2026-0204) were closed 2026-09-25 by a plain
# `cargo update -p <crate>` — their consumers (ureq; rayon-core <- exr <-
# image) already accepted the patched semver range, so no Cargo.toml edit
# was needed. Only the two advisories below have no such path today:
#
# Review by 2026-12-22, or sooner once the dependency bumps land:
# RUSTSEC-2025-0008 — openh264-sys2 0.6.6, heap overflow in decoding.
# Direct dependency of the published `rustmotion` crate. Fix: openh264 >=0.8.0.
# RUSTSEC-2026-0204 — crossbeam-epoch 0.9.18, invalid pointer deref in `fmt::Pointer`.
# Via rayon-core <- exr <- image, reaches rustmotion-core/-components. Fix: >=0.9.20.
# RUSTSEC-2025-0008 — openh264-sys2 0.6.6, heap overflow in the DECODING path.
# `h264.rs` only imports Encoder/YUVBuffer/OpenH264API — no decoder type is ever
# constructed, and Cargo.lock's openh264-sys2 pulls in cc/nasm-rs/walkdir, not
# libloading, so it is the source-compiled build the advisory itself calls safe at
# >=0.6.6 ("if you rely on our `source` feature only, >=0.6.6 should be safe").
# `cargo audit` still flags it because its patched-version range (>=0.8.0) only
# covers the libloading/prebuilt-DLL path we don't use. Bumping past 0.8.0 would
# touch `h264.rs`'s API usage for no reachable fix; left ignored on that basis.
# RUSTSEC-2026-0195, RUSTSEC-2026-0194 — quick-xml 0.38.4 / 0.39.4, DoS + quadratic runtime.
# 0.38.4 via syntect reaches the published crates; 0.39.4 via dioxus-desktop/rfd is
# rustmotion-studio-only (Linux/Wayland file dialogs). Fix: >=0.41.0.
# RUSTSEC-2026-0285 — rustls 0.23.37, TLS 1.3 handshake level-boundary bug.
# Via ureq, used by rustmotion/rustmotion-core for Google Fonts + Iconify fetches. Fix: >=0.23.45.
# RUSTSEC-2026-0104, RUSTSEC-2026-0098, RUSTSEC-2026-0099, RUSTSEC-2026-0049 — rustls-webpki
# 0.103.9, four CRL/name-constraint parsing bugs. Same ureq path as rustls above.
# Fix: >=0.103.13,<0.104.0-alpha.1 (or the matching 0.104 alpha per advisory).
# 0.38.4 reaches the published crates via syntect -> plist. 0.39.4 is
# rustmotion-studio-only (Linux/Wayland), via wayland-client/wayland-protocols* ->
# wayland-scanner, themselves pulled in by rfd (file dialogs) and gpui-pre-linux
# (window backend) — not dioxus-desktop, which is no longer a dependency since the
# gpui-kit migration. Fix: >=0.41.0. `cargo update -p quick-xml` has no candidate
# today — syntect/plist and wayland-scanner both pin narrower ranges than that, so
# closing this needs a Cargo.toml bump in those third-party crates, not just a lock
# update (a third, already-fixed instance is in the tree today via `xcb`).
# RUSTSEC-2026-0257 — webbrowser 1.2.1, BROWSER env argument injection on Unix.
# Via dioxus-desktop, rustmotion-studio only (`publish = false`, never reaches a published
# crate). Fix: >=1.2.2.
# `webbrowser` is no longer in Cargo.lock at all (it left with dioxus-desktop during the
# gpui-kit migration) — this --ignore is currently inert. Left in rather than dropped
# silently: re-verify before removing, in case something reintroduces the crate.
- name: Audit dependencies
run: >
cargo audit
--ignore RUSTSEC-2025-0008
--ignore RUSTSEC-2026-0204
--ignore RUSTSEC-2026-0195
--ignore RUSTSEC-2026-0194
--ignore RUSTSEC-2026-0285
--ignore RUSTSEC-2026-0104
--ignore RUSTSEC-2026-0098
--ignore RUSTSEC-2026-0099
--ignore RUSTSEC-2026-0049
--ignore RUSTSEC-2026-0257
29 changes: 29 additions & 0 deletions .github/workflows/publish.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,40 @@ on:
tags:
- "[0-9]+.[0-9]+.[0-9]+"

permissions:
contents: read
checks: read

jobs:
publish:
runs-on: ubuntu-latest
environment: release
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
fetch-depth: 0

- name: Verify tag is reachable from main
run: |
git fetch --no-tags origin main
if ! git merge-base --is-ancestor "$GITHUB_SHA" origin/main; then
echo "::error::Tag $GITHUB_REF_NAME (commit $GITHUB_SHA) is not an ancestor of origin/main; refusing to publish from a commit that was never merged."
exit 1
fi

- name: Verify CI passed on the tagged commit
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
runs=$(gh api "repos/${GITHUB_REPOSITORY}/commits/${GITHUB_SHA}/check-runs" \
--jq '.check_runs[] | select(.app.slug == "github-actions") | "\(.name)=\(.conclusion)"')
echo "$runs"
for job in fmt clippy test audit; do
if ! echo "$runs" | grep -qx "${job}=success"; then
echo "::error::CI job '$job' has not succeeded on $GITHUB_SHA; refusing to publish."
exit 1
fi
done

- name: Install system dependencies
# Doit rester identique à ci.yaml : l'étape « Run tests » ci-dessous lance
Expand Down
20 changes: 10 additions & 10 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading