YeonGyu-Kim
2f5fc7c4e9
fix(rules-core): block symlinked rule directory escapes
2026-05-20 18:19:17 +09:00
YeonGyu-Kim
330e437f08
docs(agents): regenerate hierarchical AGENTS.md for 2026-05-20
...
Sync the AGENTS.md hierarchy to current code state:
Drift fixes in 11 existing files
- Root: 2026-05-20 commit 39aadbf9f , ~2167 TS files, 120 barrel index.ts,
57 src/hooks dirs, 297 (179 non-test) src/shared files, 11 OpenCode hook
handlers in plugin-interface.ts, packages list adds ast-grep-mcp + rules-core,
first-prompt-watchdog 206 LOC, parent-wake-notifier 587 LOC
- src/AGENTS.md: file counts, plugin-interface handler count
- src/shared/AGENTS.md: title + counts 278/170 -> 297/179
- src/hooks/AGENTS.md: 57 dirs, note unwired WIP (task-reminder,
hashline-edit-diff-enhancer)
- src/features/AGENTS.md: module map with NON-TEST counts + sub-AGENTS.md
column, 7 modules without sub-doc
- src/features/background-agent/AGENTS.md: add 12 newer files (parent-wake-
notifier 587 LOC, loop-detector, error-classifier, fallback-retry-handler,
process-cleanup, subagent-spawn-limits, session-status-classifier,
compaction-aware-message-resolver, etc.)
- src/plugin/AGENTS.md: 11 handlers, add system-transform.ts + command-
execute-before.ts + build-team-idle-wake-hint-client.ts
- src/config/AGENTS.md: note schema/internal/permission.ts
- src/cli/AGENTS.md: 8 commands including 'version'
- src/plugin-handlers/AGENTS.md, packages/web/AGENTS.md: date bump
New AGENTS.md in 4 directories
- packages/AGENTS.md: index of 15 packages (11 platform binaries + 2 MCP
packages + rules-core + web), role map, conventions
- docs/AGENTS.md: WHERE TO LOOK table for 19 docs across 6 subdirs
- .opencode/AGENTS.md: 5 skills + 4 slash commands + relationship to .agents/
- .agents/AGENTS.md: superset migration target (9 skills + 4 commands)
2026-05-20 17:18:44 +09:00
YeonGyu-Kim
b24dc6eeb8
fix(rules-core): isolate package + block symlink escape from rule sources
...
- Drop the back-import of src/shared/logger so @oh-my-opencode/rules-core
stays free of host-adapter dependencies (ROADMAP package layering
invariant). Expose setSisyphusRuleDeprecationLogger(logger) for hosts to
inject their own logger; default is a noop.
- Wire the host injection in src/hooks/rules-injector/rule-file-finder.ts
as a module-level side effect so existing behavior is preserved.
- Add realpath boundary check to findRuleFilesRecursive and
validFileRealPath. Project rule scanners now refuse entries whose
realpath escapes the rule-source root, closing the symlink-escape
vector where a malicious repo could point .github/copilot-instructions.md
(or any .omo/rules/* entry) at ~/.ssh/id_rsa and have the rule injector
pull the secret into model context.
2026-05-20 15:29:16 +09:00
YeonGyu-Kim
6fd5e7c9ec
fix(web): switch OG image from next/og to static PNG file convention
...
PR #4202 introduced dynamic OG via app/opengraph-image.tsx + app/twitter-image.tsx
using next/og ImageResponse. Build succeeds, but deploy to Cloudflare Workers
fails:
✘ [ERROR] Unable to extract npm package name from
.open-next/server-functions/default/node_modules/next/dist/compiled/
@vercel/og/yoga.wasm?module
[plugin wrangler-module-collector]
##[error]The process '/home/runner/.bun/bin/bunx' failed with exit code 1
Root cause: wrangler-module-collector can't resolve @vercel/og's bundled
yoga.wasm import from the OpenNext server-functions output. Known regression
in @opennextjs/cloudflare interop with @vercel/og (related to issue #1163 +
PRs #1169/#1176 in opennextjs/opennextjs-cloudflare, plus newer bundling
discussion in #1221 ).
Fix: switch to Next.js file convention static OG images. Place
app/opengraph-image.png + app/twitter-image.png (the same 1200x630
PNG that was being rendered dynamically). Next.js auto-emits og:image +
twitter:image metadata pointing at these routes, with correct
og:image:width/height/type tags. No @vercel/og, no WASM, no edge runtime.
The static PNGs were generated from PR #4202 's dynamic ImageResponse during
local QA - identical visual output: dark #0a0a0a background, cyan
#00d4ff brand wordmark, headline, install command pill, terminal cursor.
Build verified: /opengraph-image.png and /twitter-image.png now show as
static routes (0 B route handler size). First-load JS unchanged.
Future-revisit: re-enable dynamic OG when @opennextjs/cloudflare ships the
fixes from PRs #1169/#1176/#1221 stable for Next 15.x deploys.
2026-05-20 15:16:02 +09:00
YeonGyu-Kim
5154ab4c6f
Merge pull request #4202 from code-yeongyu/feature/web-portfolio-refinement-20260520
...
feat(web): designer-portfolio refinement + dynamic OG + perf -46%
2026-05-20 15:10:13 +09:00
YeonGyu-Kim
e9c44ddb1b
fix(web): drop nested <main> on manifesto (WCAG 1.3.1)
...
LocalizedPageShell at app/_components/localized-page-shell.tsx:34
already renders <main className='flex-1'>{children}</main> as the
page landmark. The manifesto/page.tsx shell was wrapping that with
its own <main>, producing nested main landmarks (axe-core:
landmark-no-duplicate-main + landmark-main-is-top-level).
Switch outer wrapper to <div>; keep styling (bg-background,
text-foreground, min-h-screen, overflow-x-hidden) intact. The
inner <main> from the shell remains the canonical landmark.
Pre-existing on origin/dev (the pre-decomposition manifesto/page.tsx
also had a top-level <main>), surfaced by PR #4202 hands-on QA
via axe-core run on /ko/manifesto.
2026-05-20 15:00:22 +09:00
YeonGyu-Kim
f5d5e9801b
fix(web): hero Get Started CTA -> /docs#installation ( closes #3848 )
...
Get Started button previously linked to /docs (root), landing users on
Overview. Issue #3848 reporter and concurrent PR #3948 asked for a
deeper link straight to Installation.
lib/docs-sections.ts declares 'installation' as a stable section id
rendered via <section id={section.id}> in app/[locale]/docs/page.tsx,
so /docs#installation is a valid deep link.
This also supersedes the in-flight PR #3948 (which targets the
pre-decomposition landing-page.tsx).
2026-05-20 14:40:24 +09:00
YeonGyu-Kim
64997d5e81
test(web): responsive matrix — 6 viewports x 4 locales x 2 pages
...
e2e/responsive.spec.ts (new):
- 6 viewports: iPhone SE (375x667), iPhone 14 Pro (390x844),
iPad mini (768x1024), iPad Pro (1024x1366), laptop (1280x800),
desktop (1920x1080)
- 4 locales: en, ko, ja, zh
- 2 pages: landing /, manifesto /manifesto
- Checks: no horizontal scroll, no overflow-x, primary CTA visible,
hero headline visible, nav button hit target (44x44 mobile / 32x32
desktop)
48 tests total. All pass against current build.
/docs has pre-existing horizontal overflow at 1024px viewport
(fixed-width sidebar interacting with code blocks). Intentionally
out of scope for this PR — commented in the spec, tracked as
follow-up.
2026-05-20 14:27:02 +09:00
YeonGyu-Kim
623af75962
feat(web): dynamic OG + Twitter card images via next/og
...
app/opengraph-image.tsx (new):
- next/og ImageResponse, 1200x630 PNG
- Dark #0a0a0a background + cyan #00d4ff brand wordmark + headline
+ install command pill + terminal cursor
- Google Fonts loadGoogleFont helper for Geist 400/700 +
Geist Mono 500 (runtime fetch, Cloudflare Workers compatible)
- Cache-Control: public, immutable, max-age=31536000
app/twitter-image.tsx (new):
- Same shape as OG with Twitter-card alt text
- Inherits twitter:card=summary_large_image from layout
app/layout.tsx:
- metadata.alternates.languages: explicit canonical URLs for en/ko/
ja/zh so search engines pick up hreflang
- metadata.openGraph.alternateLocale: ko_KR, ja_JP, zh_CN
- Drop manual openGraph.images / twitter.images: file-based metadata
convention now auto-emits og:image:width, og:image:height,
og:image:type, twitter:image:width, twitter:image:height
- metadata.robots: max-image-preview=large, max-snippet=-1
(richer SERP previews)
Verified: curl /opengraph-image returns 200, content-type image/png,
1200x630 PNG body. All 4 hreflang links present in <head>.
2026-05-20 14:27:02 +09:00
YeonGyu-Kim
022eb78440
refactor(web): decompose 358-LOC manifesto into 9 section components
...
app/[locale]/manifesto/page.tsx: 358 LOC -> 22-LOC composition shell.
components/manifesto/sections/:
- hero.tsx
- pain-points.tsx
- indistinguishable.tsx (the 'AI vs senior engineer' argument)
- token-cost.tsx
- cognitive-load.tsx
- principles.tsx
- core-loop.tsx
- future.tsx
- final-cta.tsx
Each section 26-68 LOC. Copy unchanged; section order unchanged.
Same i18n namespace ('manifesto'). Renders identically to baseline
in all 4 locales (en/ko/ja/zh).
2026-05-20 14:27:02 +09:00
YeonGyu-Kim
4d5f58f0c3
refactor(web): decompose 832-LOC landing into 10 section components
...
app/_components/landing-page.tsx: 832 LOC -> 33-LOC composition shell.
Each section becomes a focused, named component under
components/landing/sections/:
- hero.tsx: terminal headline + install command + primary CTA
- ultrawork.tsx: ultrawork mode pitch
- sisyphus.tsx: Sisyphus orchestrator showcase
- prometheus-atlas.tsx: planner + executor pair (was amber+indigo,
now violet — single secondary accent)
- hephaestus.tsx: code surgeon (was orange, now cyan)
- team-mode.tsx: parallel team coordination (was fuchsia/purple/cyan
gradient, now solid cyan headline + violet skills accent)
- sub-agents.tsx: explore/librarian/oracle/multimodal etc.
- architecture.tsx: 4-tier diagram
- reviews.tsx: testimonials (Star kept text-cyan-500 / fill-cyan-500,
on-brand)
- cta.tsx: final call-to-action
components/landing/constants.ts (new):
- SUB_AGENT_KEYS, AGENT_STYLES, PRINCIPLE_KEYS, PRINCIPLE_ICONS,
REVIEW_KEYS, CATEGORY_ROUTING, SKILL_INJECTIONS
- Single source of truth for agent/principle/review metadata used
across sections
components/icons/github-icon.tsx (new):
- Extracted inline SVG into a typed component with default
aria-hidden and overridable size/className
Color consolidation: 9-color rainbow per-section -> cyan (primary)
+ violet (secondary, agent identity) + neutral grays + status colors
only. 'Evolution not revolution': dark + cyan brand soul intact.
2026-05-20 14:27:02 +09:00
YeonGyu-Kim
78ca837e82
style(web): extract design system tokens + DESIGN.md
...
DESIGN.md: 7-section design system (palette, typography, spacing,
motion, components, sections, banned patterns). Documents existing
dark + cyan brand to enforce 'evolution not revolution'.
globals.css: add design tokens — --surface-{0..3}, --text-{primary,
secondary,tertiary}, --accent-primary{,-soft,-border}, --border-
{default,subtle}, status tokens (success/warning/danger/info).
Add .reveal-on-enter utility: opacity 0 → 1, translateY(8px) → 0
over 600ms cubic-bezier(0.16, 1, 0.3, 1). Triggered via
'data-revealed' attribute set by IntersectionObserver upstream.
Respects 'prefers-reduced-motion: reduce' — falls back to instant
opacity transition.
Add .ring-cyan focus utility consolidating focus-visible rings
across components (was ad-hoc per-component).
2026-05-20 14:26:09 +09:00
YeonGyu-Kim
7e0406f4ec
fix(web): UX/a11y polish + middleware metadata route fix
...
- footer.tsx: Discord link → canonical discord.gg/PUwSMR9XNk
(was outdated invite that 404'd).
- [locale]/layout.tsx: hooks count 40 → 54 (matches AGENTS.md).
- lib/stats.ts:88: drop '!' non-null assertion; use '??' fallback.
Removes the only '!' in packages/web (project rule).
- nav-header.tsx: hamburger Button size='icon' → explicit h-11 w-11;
mobile drawer links min-h-11 px-3 rounded-md. WCAG 2.5.5 tap
target 44x44 minimum.
- install-command.tsx: copy button h-8 w-8 → h-11 w-11 (was 32px,
below WCAG). Icon stays 16x16; padding fills to 44.
- middleware.ts: matcher excludes opengraph-image, twitter-image,
icon, apple-icon, manifest.webmanifest, robots.txt, sitemap.xml.
Previously next-intl redirected /opengraph-image → /en/opengraph-image
breaking OG previews for crawlers that hit the unlocalized path.
2026-05-20 14:26:09 +09:00
YeonGyu-Kim
68b80e0343
perf(web): optimize CI + build pipeline
...
- web-ci.yml: cache .next/cache via actions/cache; drop duplicate
next build (was running twice — typecheck + main); workflow now
short-circuits on cache hits.
- scripts/prepare-build.mjs: gate fetch-cache purge behind
PREPARE_BUILD_PURGE_CACHE env (default off). preview/deploy npm
scripts no longer invoke it.
- scripts/generate-docs-content.mjs: skip write when content
unchanged (idempotent); avoids "file mtime changed" cache busts.
- eslint.config.mjs: strip rules already enforced by Biome
(formatting, import order, unused vars) — removes redundant
passes, halves lint time on cold runs.
- playwright.config.ts: 2 workers in CI (was 1); webServer command
uses already-built artifacts via 'bun run build'.
Cold build: 16.2s → 8.7s (-46%). Recompile 1.45s.
2026-05-20 14:26:08 +09:00
YeonGyu-Kim
9799c54a92
chore(web): remove dead deps + safe version bumps
...
Removed motion v12.38 (zero imports) and @radix-ui/react-accordion
(unused) from runtime deps. Removed 4 dead components: code-block,
option-table, accordion, mdx-components — all had zero references.
Bumped safe caret deps via bun update:
- marked 18.0.3 → 18.0.4
- @opennextjs/cloudflare 1.19.10 → 1.19.11
- wrangler 4.92.0 → 4.93.0
- postcss override 8.5.14 → 8.5.15 (closes GHSA-qx2v-qp2m-jg93)
- @types/node 25.8.0 → 25.9.1
- @types/react 19.2.14 → 19.2.15
- typescript-eslint 8.59.3 → 8.59.4
Bundle shrinks by removing motion (≈ 60 KB) from node_modules even
though it had no runtime usage.
2026-05-20 14:22:58 +09:00
YeonGyu-Kim
faf2b02163
fix(lsp): update lsp-tools-mcp cleanup
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 14:19:05 +09:00
YeonGyu-Kim
12aaff28b5
test(rules-core): isolate sisyphus deprecation warning assertion
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 13:24:24 +09:00
YeonGyu-Kim
1bab6ec412
fix(rules-core): restore .sisyphus/rules discovery with deprecation warning (planned removal v4.3.0)
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 13:24:24 +09:00
YeonGyu-Kim
7ffe823fa9
test(rules-core): add red tests for restored .sisyphus/rules discovery + deprecation warning (BUG-G)
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 13:24:24 +09:00
YeonGyu-Kim
1f9a581e70
fix(rules-core): fall back to workspace directory when no project root marker is found
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 13:20:47 +09:00
YeonGyu-Kim
2c62e7297b
test(rules-core): add red test for project rule discovery in markerless workspaces (BUG-F)
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 13:20:47 +09:00
YeonGyu-Kim
2ea2159d80
fix(ast-grep-mcp): allow absolute paths whose realpath is inside the workspace
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 13:12:34 +09:00
YeonGyu-Kim
b2e42e1b2c
test(ast-grep-mcp): add red test for absolute paths inside workspace
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 13:12:34 +09:00
YeonGyu-Kim
3dd414226b
fix(rules): drop legacy sisyphus rule sources
2026-05-19 14:27:48 +09:00
YeonGyu-Kim
499aff011a
feat(mcp): add package-backed ast-grep MCP
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-18 21:27:36 +09:00
YeonGyu-Kim
fb7d47f1b7
feat(rules): add shared rules-core package
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-18 21:27:36 +09:00
YeonGyu-Kim
a6f1950d41
fix(web): restore navigation smoke coverage
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-18 20:56:13 +09:00
YeonGyu-Kim
9a9d9bd5a1
fix(web): adapt build tooling
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-18 20:55:59 +09:00
YeonGyu-Kim
92a5a44218
chore(web): update web dependencies
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-18 20:55:44 +09:00
github-actions[bot]
751f969fac
release: v4.2.0
2026-05-18 08:10:56 +00:00
YeonGyu-Kim
bf96794599
chore(web): move site under packages
2026-05-18 16:44:02 +09:00
YeonGyu-Kim
5e9a26c1c5
chore(packages): align platform package dirs
2026-05-18 16:43:26 +09:00
YeonGyu-Kim
7187db6ede
chore(mcp): move lsp submodule under packages
2026-05-18 16:00:40 +09:00
github-actions[bot]
c75deee54c
release: v4.1.2
2026-05-14 06:38:21 +00:00
github-actions[bot]
f44d94413c
release: v4.1.1
2026-05-13 08:15:11 +00:00
github-actions[bot]
9edaa6e90b
release: v4.1.0
2026-05-13 02:32:42 +00:00
github-actions[bot]
44f8e28055
release: v4.0.0
2026-05-07 10:13:09 +00:00
github-actions[bot]
60dfac871f
release: v3.17.15
2026-05-06 04:52:53 +00:00
github-actions[bot]
f6e9fadf01
release: v3.17.14
2026-05-05 10:31:32 +00:00
github-actions[bot]
6b9731923d
release: v3.17.13
2026-05-04 07:42:32 +00:00
github-actions[bot]
1a91967311
release: v3.17.12
2026-04-30 17:23:26 +00:00
github-actions[bot]
a663562dbe
release: v3.17.11
2026-04-30 13:06:06 +00:00
github-actions[bot]
1347d7ffad
release: v3.17.10
2026-04-30 07:47:13 +00:00
github-actions[bot]
938b609a91
release: v3.17.6
2026-04-28 06:21:01 +00:00
github-actions[bot]
c9350c67fe
release: v3.17.4
2026-04-16 06:27:22 +00:00
github-actions[bot]
1bb59c3e21
release: v3.17.2
2026-04-13 18:03:21 +00:00
github-actions[bot]
f9f71f6832
release: v3.17.0
2026-04-11 13:30:34 +00:00
github-actions[bot]
fbd3e7aabe
release: v3.16.0
2026-04-08 10:04:19 +00:00
github-actions[bot]
abda3c52f0
release: v3.15.3
2026-04-06 03:59:11 +00:00
github-actions[bot]
1562b7d148
release: v3.15.1
2026-04-05 00:54:58 +00:00