Skip to content

feat: add security-first previews and extend the timeline - #11

Merged
Bots merged 2 commits into
mainfrom
feat/orange-timeline-continuation
Aug 11, 2026
Merged

feat: add security-first previews and extend the timeline#11
Bots merged 2 commits into
mainfrom
feat/orange-timeline-continuation

Conversation

@Bots

@Bots Bots commented Aug 11, 2026

Copy link
Copy Markdown
Owner

Summary

  • make exact #ff5a1f the primary action treatment across the app, including the persistent Start an idea and interest actions
  • anchor grayscale editorial imagery with unfiltered orange rules and use accessible black-on-orange category treatments
  • add six deterministic, security-first concept previews—one for every catalog category—with stable IDs, locally hosted SVGs, and complete threat, boundary, and proof cases
  • make every complete existing concept visibly security-focused in the catalog by surfacing its actual threat scenario instead of a generic badge
  • expand and rewrite the landing process as a coherent ten-stage security/evidence lifecycle
  • update public product documentation and deterministic catalog totals from 21 to 27

New security-first previews

  1. Oral History Provenance Lab — consent, edit history, provenance, withdrawal, and synthetic-audio risk
  2. Neighborhood Incident Relay — minimum-data reporting without doxxing or public accusation feeds
  3. Phishing Drill Library — inert simulations without credential capture, shaming, or worker surveillance
  4. Water Sensor Integrity Watch — signed readings, calibration evidence, tamper detection, and bounded claims
  5. Clinic Device Privacy Check — patient-controlled telemetry, deletion, offline, and fallback review
  6. Software Supply Chain Clinic — SBOM, provenance, signatures, clean rebuilds, secrets, and rollback

Each concept remains permission-first, evidence-oriented, and presentation-only until a bounded pilot earns support. Nothing introduces payments, custody, fundraising, covert surveillance, or automatic deployment.

Ten-stage timeline

  1. Shape the concept
  2. Map the threat scenario
  3. Set the control boundary
  4. Test public interest
  5. Turn signals into evidence
  6. Design a bounded pilot
  7. Challenge the security case
  8. Publish what happened
  9. Choose, repeat, or stop
  10. Leave a useful record

The timeline uses one column on mobile, two at medium widths, and five at wide widths with tested border behavior.

Catalog security treatment

  • cards with all three security fields now show a labeled Security focus panel and the concept's real threat scenario
  • cards missing any security field do not claim a security case
  • the narrow legacy-schema fallback remains unchanged and fail-closed
  • full threat scenario, control boundary, and proof required remain available on detail pages
  • interest privacy, authentication, RLS, and aggregate counts are unchanged

Palette and imagery

  • sole hue remains exact, opaque #ff5a1f
  • black text remains the foreground on orange controls and labels
  • supporting structure stays pure black, pure white, and exact neutral grays
  • all six new SVGs use only the approved palette, include <title> and <desc>, and ship locally
  • grayscale filters remain confined to image pixels; orange rules stay on unfiltered wrappers
  • profile/member avatars remain unfiltered

Database rollout

  • adds 20260811121000_seed_security_first_concepts.sql
  • preserves the original 21 UUIDs, slugs, statuses, and security cases
  • adds six stable UUIDs/slugs/media rows, bringing fresh databases to exactly 27 published demos
  • requires the existing security-column migration plus this seed migration to be deployed after merge
  • frontend compatibility for production schemas missing the security columns remains unchanged

Verification

  • 190/190 frontend tests
  • TypeScript and Biome lint/format
  • Production build (2,029 modules)
  • npm audit --omit=dev --audit-level=high — 0 vulnerabilities
  • Clean local Supabase reset through every migration
  • 227/227 pgTAP assertions
  • Supabase schema lint — no errors
  • Exact palette, accessibility structure, dimensions, XML validity, and built-copy verification for all six SVGs
  • Visual review of all six SVGs; two discovered overlaps were fixed and rechecked
  • git diff --check
  • GitHub CI and Vercel preview deployment
  • Independent exact-checksum review — PASS on 59f5c3f4b6986be1540f865bcaa6fcba0ebdecdeba2ce33051e25899c97b42aa

Existing PR scope retained

This PR also retains its previously reviewed orange primary actions, interest semantics, image-frame correction, responsive timeline foundation, pure black/white surfaces, and neutral grayscale structure. It does not weaken authentication, PostgreSQL authorization, RLS, interest persistence/privacy, error propagation, or the schema compatibility matcher.

@vercel

vercel Bot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
ideascape Ready Ready Preview Aug 11, 2026 1:49pm

@Bots Bots changed the title feat: amplify orange and extend timeline feat: add security-first previews and extend the timeline Aug 11, 2026
@Bots
Bots merged commit b6ee32d into main Aug 11, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant