Nine review angles, fourteen verified findings, all but the byte-table
generator applied. The two that mattered most were regressions of mine:
- a:hover repainted button-styled anchors, and in dark theme --accent-text
equals --accent-solid — hovering the hero CTA drew its label in its own
background colour. Verified invisible before (computed color == computed
background) and distinct after: 10.39:1 dark, 6.90:1 light. The buttons and
the skip link now re-assert their label colours on hover.
- Footer links had lost every non-hover affordance: the text-decoration:none
carve-out plus body-coloured links left a 2.37:1 shade difference as the
only cue. The carve-out is deleted — .nav-links a and .brand already
declare none themselves — and the accent rule is back on the footer.
Also on the page: #ref-filter, the one text input, moves to --border-ui (it
still had the 1.68:1 border the token's own comment calls decorative);
focusable code surfaces get the --accent-on-code ring at -2px offset, inside
the .code overflow clip; #output .out-err drops #ff8095, the last surviving
colour of the deleted indigo palette; the two rgba(255,106,126) washes become
color-mix over --err-line so a grep for the token finds them.
The theme machinery loses a whole block: the dark media query is guarded with
:not([data-theme="light"]), so an explicit light toggle falls through to the
bare :root palette and the 21-token hand-copy in [data-theme="light"] is
gone. Verified in all four system/toggle combinations.
The page stops contradicting the repo: it claimed cereale/min "cannot
tree-shake — nothing left to shake" while src/treeshake.test.ts proves the
opposite on every run. Corrected here and in FRAMEWORKS.md, with the measured
figures (1,837 vs 1,996 bytes for one decorator). The release facts the page
was hand-bumping — both tgz names, "0.4.0 lives in the repository", the
sixty-eight — now fill from meta.js/the bundle like the version badge always
has.
The workflows close three holes:
- The docs sync gate was blind to NEW untracked build outputs (git diff does
not report them; demonstrated). Both workflows now run check:docs-sync, one
shared script that fails on anything porcelain reports — which also ends
the copy-paste divergence between them.
- pages.yml deploys on CI succeeding on main (workflow_run) instead of on the
push itself, so a deploy implies green tests, not just in-sync docs. The
deploy job refuses refs other than main, closing the workflow_dispatch
any-branch deploy, and the build job drops pages/id-token — npm postinstall
scripts no longer run alongside an OIDC grant.
- The Junie action is pinned to the commit behind v1.7.4 rather than the tag,
which is the immutability the previous comment promised but a mutable ref
cannot deliver.
Verified: every fix confirmed in a rendered browser in both themes; 72
contrast pairs still pass; no overflow at 20 widths; 268 tests, build,
check:types, check:docs, actionlint all green.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
Checked against the action repo itself rather than assumed: git ls-remote
shows v1.7.4 is the newest release tag and the moving v1 tag points at the
same commit (c2ae82f), so this changes which ref is named, not which code
runs — today. What it buys is that the version running stays the version
that was reviewed here, instead of silently following wherever v1 moves.
There was never a v0 reference in this workflow, and there is no api-key
presence check to remove — the action is invoked directly and fails loudly
if JUNIE_API_KEY is absent, which is the intended behaviour.
For the record, since this commit will re-trigger the job on PR #12: the two
failures there today are neither the workflow nor the Junie balance. Both
died in under ten seconds at the action's GitHub permission pre-check with
GitHub's own 503 body ("No server is currently available to service your
request"), before any Junie API call was made.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
Runs JetBrains' Junie agent on every PR into main or develop, using the
action's built-in `code-review` prompt rather than a free-form instruction.
Details worth keeping:
- `use_single_comment` plus a `concurrency` group keyed on the PR number, so a
burst of pushes leaves one review of the final state rather than a queue of
reviews of intermediate ones.
- Skipped explicitly on fork PRs. `pull_request` does not expose secrets to
them, so the job would otherwise fail on an empty API key — a skipped job
reads as "not applicable", a failed one as "broken".
- `contents: read`. This workflow reviews; it does not push.
- Not a required check, on purpose. CI gates merges; a review that can block
one on a judgement call is a review that gets rubber-stamped.
Needs a JUNIE_API_KEY repository secret before it will do anything but fail.
Pinned to @v1, whose action.yml declares each of the three inputs used here.
actionlint clean across all three workflows.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK