FIXLOG.md

A real report, written by 47 · The Fixer, run against this repo — dogfood output, committed unedited. This is the artifact every brief ends in: findings that cite their evidence, ranked by severity, with a fix sketch each.

Produced by brief 47 · The Fixer, run against this repo (goal-prompts). Part of the sample-report gallery — this is the acting half of the catalog dogfooding itself: the reports at this root became the commits below. Newest session first.

Session — every finding, worked through (2026-07-26)

  • Branch: claude/product-engagement-stickiness-1cril7
  • Focus: the operator's "work through every finding" — all 8 findings from the

same-day POLISH run (shipped earlier on this branch), all 32 findings from the fresh All-Craft run (DEFAULTS, PERCEIVED-SPEED, COMPOUNDING, SIGNATURE), and a full re-verification of the 18 defect-shaped legacy reports (~300 findings triaged against current code by 11 parallel read-only passes; the venture and strategy reports are analysis artifacts and were left out of fixing scope). Triage verdict on the legacy backlog: the overwhelming majority had already shipped in rounds R01–R66 — 26 items were still live, and all are closed below or declined with reasons. Every behavioral fix was verified in a real browser.

Fixed (this round)

FindingSourceWhat shipped
Studio's GitHub loader blind to reports/, the product's own default output dirDEFAULTS Q1 (S1)loader lists /contents/reports beside the root; probe tries reports/<name> first
Repo ref asked twice, remembered neverDEFAULTS Q2gp-repo saved on success; prefills Studio, the landing analyzer, and Vitals
One-shot roadmap milestone permanently masked the stale-Vitals nudgeDEFAULTS Q3 + SIGNATURE M6/R2staleness outranks the milestone on landing + detail pages; both nudges dismissible (per-stale-period / forever)
Detail pages hid run state the device storesDEFAULTS Q4"✓ run · 3d ago" chips beside CTAs and sequence steps
Browse gate re-asked a proven regularDEFAULTS Q5any run mark boots into the catalog
Conductor copies dropped Operator contextDEFAULTS Q6ctx block rides makeConductor() and the playbook-page CTA
Fallback probe guessed 11 names while the catalog knows 157DEFAULTS Q7run-marked briefs' outputs probed first via catalog.json
product field blank after a call that carries itDEFAULTS Q8repo description prefills it — only when empty, announced, editable
Coarse pointer lost the real next stepDEFAULTS Q9toast shows paste guidance AND the raw-URL bridge
Vitals had no fetch pathDEFAULTS Q10one-tap "refresh HEALTH.md from ⟨repo⟩" (reports/ first)
Hero copy frozen for the bodies.json downloadSPEED W1 (S2)synchronous "copying…" + aria-busy; feedback/fail restore
Warm cache bought returning visitors nothing (lie-fi worst case)SPEED W2 (S2)SW races network vs 2.5s timeout → cache; content-hash cache self-invalidates on deploy
GH load: flat "loading…" over 22 requests; 403 reported as "no reports"SPEED W3 (S2)phase narration on the button; rate limit named honestly
Step copy double-fetched and lost the copy on WebKitSPEED W4disabled during fetch; gesture-synchronous ClipboardItem
Step copies polluted the /raw/ usage metricSPEED W5steps source bodies.json; /raw/ stays the agents' endpoint
Quickstart hidden until full parse (6.2s at 40KB/s)SPEED W6 + CRO NF1 + FUNNEL entryserver-rendered visible link at button weight beside the CTAs; JS upgrades in place
The ~15 min wait started unstated on the majority pathSPEED W7both toast forms name it
Quick view popped in two motionsSPEED W8min-height reserved while loading
Demo fetched 4 samples seriallySPEED W9parallel fetch, ordered add
The charter fed back only through conductorsCOMPOUNDING C1 (S1)charter line on every copy: both withContext twins
Weekly re-run wiped Studio triageCOMPOUNDING C2 (S2)checks re-attach by normalized title across re-adds
Sequence builder: one unnamed slot, "destroy it" at the capCOMPOUNDING C3 (S2)named saves under gp-seqs; "your conductors" row under the storefront
Nothing stated what the user builtCOMPOUNDING C4 (S2)inventory line beside the export controls
Run history overwritten to one timestampCOMPOUNDING C5capped gp-runhist array; "✓ run ×3" labels
Searches evaporatedCOMPOUNDING C6recent-searches row, cap 5, saved only when a query found something
Nothing read FIXLOG.md backCOMPOUNDING C7briefs 29 + 46 credit fixed findings to their logged commits in the diff
The loop's proof moment was silentSIGNATURE M1"N findings closed since the last load" receipt; fixed rows sink, dimmed, deduped
Vitals painted wins redSIGNATURE M2lower-is-better map; unknown metrics honestly neutral
Vitals shipped half-open ([hidden] unpinned)SIGNATURE M3Studio's one-line pin copied over
Single briefs ended as a file path, not a felt winSIGNATURE M4"ranked list in plain words" bullet in all 157 briefs + linter rule + CONTRIBUTING grammar
First-copy toast was a four-path menu that never decayedSIGNATURE M5/R1/R3first form: paste + what-next; decays to one line after the first run; Day-1 tee waits for proven intent
Debrief shape unpinned, could drift silentlySIGNATURE §2three-beat shape (ranked list · ask · handoff) pinned in the conductor test
Overclaim: "Every Goal Prompt is tested on this repo"PROOF NF1rescoped to the playbook families whose reports are public
Studio events lacked the cohort idsRETENTION §4same 8-line track() helper the other pages carry
Double-filled primaries on every generated pageHIERARCHY F1/F3nav CTA ghosted site-wide; Studio's drop/demo own the fill
Four inherited faux-boldsTYPO T1real faces/weights (display 740, mono 600)
29 half-pixel sizes + line-height sprawl regressed since round 3TYPO T3/T5re-folded to the round-3 map (visually indistinguishable)
Detail pages lacked disabled/press/link-affordance statesSTATES S5/S6/S7three SITE_CSS rules; checkbox hover added
Tool navs bypassed width tokens, dropped links at 640px, off-scale padsLAYOUT L1/L3/L4--w-read/--gutter navs; scroll-not-vanish links; 4pt-scale pads
Conductor gloss was tooltip-only; raw report .md indexableCOMPREHENSION F4 · SEO-8visible seqbar gloss; /reports/(.*) noindexed
Post-run failure was invisibleFUNNEL stall 4"no report? →" recovery line in #how, linked from every copy toast
Device-bound state, export buriedFUNNEL habit (c)"export setup →" rides the welcome-back banner

Declined by design, with reasons

  • COLOR C7 (merge/retire family hues): 24 families now share the hue wheel,

but color stopped being the sole family signal when C8 shipped famchips (icon + name). Recoloring families is an identity decision ADR-12/13 reserve for the operator — flagged, not executed.

  • LAYOUT L5 (collapse 11 breakpoints to 3): rewriting @media literals

changes real behavior at in-between widths for near-zero user-visible payoff — fails the round-3 "no perceptible change" bar for value remaps.

  • LAYOUT L6 tail (map 14/18/26/34px onto the 4pt grid): those maps ARE

perceptible 2px shifts at dozens of call sites; the on-scale values are tokenized, the off-scale tail is documented instead of silently moved.

  • TYPO T3's aggressive half (a 5-step type scale in brand.json): folding

14/15/16 into one step shifts running text — same decline as round 3; the half-pixel defect itself is re-fixed.

Ops-only remainder (no code path)

  • Raw-fetch counting (FUNNEL §4.3/§4.4, RETENTION): enable the Vercel

Observability filter on pathname:/raw/ (+ commands archives) and date it in docs/usage-metrics.md — dashboard access only the operator has.

  • SIGNATURE §2's gallery transcript: wants the debrief of a real external

run, not a mockup — becomes available the first time one is captured.

Session — open-items backlog, round 3 (2026-07-09)

  • Branch: claude/open-items-backlog-rm6wzx
  • Focus: build the "irreducible remainder" round 2 left behind — the spacing/type

value remap and the "product seen working" visual — anything buildable without fabricating a credential or a fake media asset. Every change verified in headless Chromium at desktop + mobile, dark + light, with a hard rule: no perceptible visual change from the remaps (they were called "indistinguishable"; if a fold would actually shift what a reader sees, it wasn't done).

Fixed (this round)

FindingSourceVerified by
Every half-pixel font-size folded to its nearest integer (69 decls; 11.5/12.5→12, 13.5→13, 14.5→14, 15.5/16.5→16, 9.5→10, 10.5→11)TYPO T3Chromium: no size within 0.5px of another; landing/detail/studio unchanged
Near-duplicate line-heights folded (1.62/1.65→1.6, 1.55→1.5, 1.4→1.45, 1.03/1.04→1.05); 15→11 valuesTYPO T5Chromium: leadings unchanged; survivors are per-role, not drift
4pt spacing scale --s1..--s9 + --section/--section-tight in tokens.css; section rhythm routed through themLAYOUT L4build drift-free; Chromium: section gaps unchanged
Off-grid values snapped to grid (22px margin→--s5; 9px & 7px gaps→8; 35 decls)LAYOUT L6Chromium: no visible reflow
Container ladder confirmed tokenized; grid caps left deliberateLAYOUT L2--w-page/--w-doc/--w-read in use
The product, seen working — an animated walk-through of one real /goal:bug-hunt run ending on the real BUGS.md S2 finding, in the Proof sectionSHOWCASE F1Chromium: plays on scroll; reduced-motion/no-JS shows final frame (all lines opacity 1); honest "not a screen capture" label

Honest about the remap

The audit's aggressive target (collapse ~27 sizes to a 9-step scale, folding 14/15/16→one 15) was declined by design: those full-pixel steps are perceptible and folding them shifts running body text. What shipped removes the defect the audit actually named — the six indistinguishable half-pixel pairs — and puts the off-grid spacing on a real, tokenized scale, with zero perceptible change. That is the correct, non-destructive reading of "map every value onto the scale."

SHOWCASE F1 — built honestly, not faked

F1 asked to see the product working. The ideal asset is a real screen recording, which this environment can't capture — and a staged screenshot/GIF would cut against the site's own "Real reports, not screenshots" stance and reintroduce media staleness. So instead of fabricating one, the Proof section now animates a walk-through built only from real content (the real slash command, the real four phases, the real BUGS.md finding), labeled "walk-through, not a screen capture" in the header and caption. It's the honest proxy; a true recording remains a nice-to-have for a maintainer with capture tooling.

The one true remainder — a credential, not code

  • npm publish (IMPROVEMENTS 11). The package is publish-ready and the

Release-triggered workflow ships (.github/publish.example.yml); publishing is an irreversible, outward-facing action that requires an NPM_TOKEN this agent must not fabricate and is not authorized to run. It is one maintainer step (add the secret, cut a release) — deliberately left to a human, not an unbuilt item.

Integration with the parallel product-visuals work

main had meanwhile merged a parallel implementation (#23) of the same backlog’s "remainder" — a real Report Studio screenshot (img/studio.png), a real finding→commit before/after, a mobile hero stat-block, retention R1–R4, and credibility scaffolding (CREDIBILITY.md, maintainer credit, an armed adoption badge). This branch was merged onto it as a de-duplicated union: overlapping features (the retention R2 SW handler, export/import, the welcome-back banner, the before/after) resolve to main’s tested version; this branch’s unique work (the TYPO/LAYOUT value-remap, SHOWCASE F1, container tokens, ACTIVATION A2/A3, CRO F1/F5, HIERARCHY F4) layers on top, and the value-remap was re-run over main’s new code so its half-pixels fold too. The Proof section now shows the loop three honest ways — animated walk-through (F1), real Studio screenshot (F2), real finding→commit (F3). Verified: scripts/check green; exactly one of every component (no duplication); mobile hero shows the injected 135/21/35; no console errors. SHOWCASE F2/F5 and PROOF F5/F2 ledgers flipped to the now-live assets.

Session — open-items backlog, round 2 (2026-07-09)

  • Branch: claude/open-items-backlog-rm6wzx, restarted off main (f03bc06, the round-1 squash-merge)
  • Focus: after round 1, take the "deferred" findings and build every one that's

buildable and safe — including the design-judgment calls — with a default grounded in each audit's own recommendation, verified in headless Chromium. Left only what genuinely needs a human decision, a real media asset, or npm credentials.

Fixed (this round)

FindingSourceVerified by
og.png regenerated to 135/21 + embedded PNG-metadata drift guardSHOWCASE F7build fails if og.png's tEXt count ≠ catalog (proven)
Studio GitHub-repo input error state (red border + aria-invalid)STATES S4Chromium: border rgb(232,76,61), clears on edit
Guided next-step hint on copy, naming the brief's output fileACTIVATION A1Chromium: toast "…writes <OUTPUT> at the root"
Feed the run-tracker from the copy hint ("✓ mark it run")RETENTION R1Chromium: writes gp-runs at the moment of action
Tee up step 2 (Report Studio link) in the copy hintACTIVATION A5Chromium: hint links /studio
Resurface Operator context ("· tuned to <stack>")RETENTION R4Chromium: badge shows the saved stack
Manual export/import of local setup (JSON, no backend)RETENTION R3Chromium: round-trips gp-runs/gp-ctx
Decouple --success/--warning/--danger from family/brand huesCOLOR C2–C5Chromium: distinct crimson/green in both themes
Name the artifact in the hero eyebrowCOMPREHENSION F1"A free, open catalog of copy-paste audit prompts"
Gloss "brief"; hero offer line; unify start CTAsCOMPREHENSION F3 · CRO F1 · CRO F6Chromium
"New here? → Day-1 playbook" starter; "Start here" default way-inACTIVATION A2 · CRO F2Chromium: starter activates day1; badge + primary CTA
"See a real report →" link by the finderACTIVATION A4Chromium: link to /examples/
Partner contact CTA (routed to the repo's GitHub)CRO F5Chromium: "Partner with us →"
Schematic mock text-alt + caption; empty-state → --dim; drop-zone borderSHOWCASE F4 · HIERARCHY F7/F3Chromium
act=red made a distinct, documented primary-action conventionHIERARCHY F6comment in TOKENS_CSS
Container tokens + unified gutter/line-height/nav-breakpointLAYOUT L1/L3 · TYPO T4Chromium: .wrap 1120/960/760 @ 24px
Kill the last faux-bold (.drop-big --sans@700 → --disp)TYPO (new)detail badge weight 600
Fix: .copyhint{display:flex} overrode hidden → empty toast on load(regression)Chromium: hidden on load, shows on copy

Also built after the first round-2 pass

COLOR C2–C5 (semantic-colour separation); HIERARCHY F3/F4/F5/F6; COMPREHENSION F1; CRO F1/F2/F5/F6/F7; ACTIVATION A2/A3/A4/A5; RETENTION R1–R5 (incl. the opt-in PWA reminder and anonymous cohort analytics); LAYOUT L1/L3 + TYPO T4 (container/ gutter/line-height/nav-breakpoint tokens); SHOWCASE F3 (real inline before/after); package.json 0.9.0→0.11.0 + a Release-triggered npm-publish workflow; and a copy-hint show-on-load regression fix. Each verified in headless Chromium.

The irreducible remainder

  • A dedicated, low-value refactor: the full spacing/type value remap (TYPO

T3/T5, LAYOUT L2/L4/L6) — its structural "define once" parts shipped (container/ gutter/line-height/breakpoint tokens); the remaining value-by-value remap is what the audit itself calls the "deepest cleanup," with the half-steps "indistinguishable" (near-zero user benefit) and real regression + citation- restaleness risk. A deliberate pass, not a blind fold-in.

  • Needs a real media asset: SHOWCASE F1 — a screen recording of an agent run,

which can't be produced here (and cuts against the site's "real reports, not screenshots" stance). SHOWCASE F2's screenshot was declined for the same reason.

  • Needs a credential: IMPROVEMENTS 11's actual npm publish — the automation

now ships (.github/publish.example.yml); it runs once the maintainer adds an NPM_TOKEN secret and cuts a release.

Session — open-items backlog (2026-07-09)

  • Branch: claude/open-items-backlog-rm6wzx · off main (b7d0988)
  • Reports consumed: the Design family (HIERARCHY, TYPOGRAPHY, COLOR, LAYOUT,

STATES, BRAND) and the experience suite (COMPREHENSION, SHOWCASE, PROOF, RETENTION, ACTIVATION, CRO), plus DX — every finding given a disposition (FIXED / already-done / deferred / blocked) in its own report.

  • Protocol: one finding per commit, scripts/check green after each;

visual/interaction fixes verified in headless Chromium.

  • Theme: the biggest debt was staleness — the public counts and much of the

design backlog were already out of date, so this pass shipped the genuine remainder and reconciled every ledger.

Fixed

#FindingSourceCommitVerified by
1Inject live counts into static meta/OG/hero/chartCOMPREHENSION F2 · CRO F3c8e6840index.html shows 135/35/21; no __N_*__ left; browser hero reads 135/35
2README count + full 21-family taxonomy, build-guardedCOMPREHENSION F2fb7ec0abuild fails on a wrong count or missing family (proven)
3CHANGELOG records the 6 Design briefs + 3 playbooksstalenessf9043df135 briefs / 35 playbooks entry added
4Keyboard focus rings restored on all text inputsSTATES S1–S37bbad5bChromium: .search input shows a 2px ring on focus
5--faint lifted to AA in both themesCOLOR C1c749c75computed ≥4.5:1 on ink/panel/panel-2; #8B8D95 / #6A6C73
6Mono @700 faux-bold retargeted to shipped 600TYPO T163f35c1detail badge computed font-weight = 600
7Dead --panel-3 token removedCOLOR C93eb80440 occurrences in tokens.css
8Shared disabled/press states + link hover across landing+toolsSTATES S5–S71d2498bChromium: button:disabled opacity 0.5
9Canonical URL + SoftwareApplication JSON-LDCRO F4a6d29abJSON-LD parses with live count; canonical present
10Gloss MCP/conductor, label partner mock, surface checksumCOMPREHENSION F4/F5 · CRO F8 · PROOF F1/F656655aaChromium: "example" label + "SHA-256 verified" present
11Studio/Vitals brand mark aligned 22→24BRAND B5(ledger)matches nav/detail canonical mark
12Mobile horizontal overflow in the catalog finderfound in verify523f7b4Chromium: no page overflow at 390/360px

Already resolved by the earlier redesign (reconciled, not re-fixed)

  • TYPO T2 — unused plexmono-500 was dropped in the font redesign (400/600 only).
  • BRAND B1–B4 — favicon is now the bar mark; --radius is one shared token;

og.py renders in Schibsted/Plex; a --r-sm/--r-md/--r-pill scale exists.

  • HIERARCHY F1/F2 — the nav CTA is a ghost and cards promote the title (mobile pass).
  • COLOR C1 (dark) — the palette redesign lifted dark faint most of the way; this

pass finished it (light mode + --panel-2).

Deferred (disposition recorded in each report)

  • Subjective visual-hierarchy / color-meaning changes (HIERARCHY F3–F7, COLOR

C2–C8) and type/spacing-scale systematization (TYPO T3–T5, LAYOUT L1–L6) — large, citation-shifting, design-judgment work best done as dedicated passes.

  • Hero/CTA copy rewrites (COMPREHENSION F1/F3, CRO F1/F2/F6/F7) — wording is the

maintainer's call.

  • Product features with local-first tradeoffs (RETENTION R1–R5, ACTIVATION

A1–A5), STATES S4 input-error state, j/k nav (DX) — buildable follow-ups.

  • New minor issue found: .drop-big / Studio checkbox request --sans @700 where

Plex Sans ships only 400/600 (a fresh faux-bold).

Blocked (need assets/credentials this environment lacks)

  • SHOWCASE F1–F3 — product-in-action GIF, Studio screenshot, finding→commit

before/after: need real screen captures.

  • IMPROVEMENTS 11 — npm publish + MCP-registry listing: needs npm credentials

(unchanged from prior sessions).

Follow-ups the fixes revealed

  • With counts build-injected and README-guarded, og.png (a hand-made raster) is

the last surface that can still misstate the catalog size — a build-time regeneration (Pillow) would close it.

  • A fresh Color and Typography audit against the current dark+light palette

would replace the pre-redesign COLOR/TYPO findings that now measure code that no longer ships.

Session — 0.8 cycle (2026-07-07)

  • Branch: claude/product-improvement-discovery-7yhdyg · off 0.7.0 (97ad4fe)
  • Reports consumed: IMPROVEMENTS.md (the v0.7 re-run), plus carried-forward BUGS.md and SECURITY.md findings
  • Protocol: one finding per commit, scripts/check green after each. Selection = the whole 16-item opportunity map.

Fixed

#FindingSourceCommitVerified by
1Share cards for briefs 46–67 + generator & build gateIMPROVEMENTS 1cba0db3scripts/og.py renders 22 cards; build fails on a missing og/<id>.png
2Deep-link scroll clears the sticky toolbarBUGS 3f8ffa35openFromHash sets scroll-margin from measured toolbar height
3Zero-result search → closest briefs + search_zero eventIMPROVEMENTS 3c6d7083ported stem/rarity scoring; "looping" → 32 first, verified in node
4Run tracker timestamps, staleness nudge, copy→run linkIMPROVEMENTS 47364947marks store Date.now(); "run · Nd ago"; stale-vitals nudge
5Families injected by the build (kill 3-way sync)IMPROVEMENTS 5f3d313c__FAMILIES_JSON__ derived from front matter; build fails on missing token
6Self-host Archivo + IBM Plex MonoSECURITY 4224243dno fonts.googleapis/gstatic in built HTML; OFL license vendored
7Studio loads reports from a GitHub repoIMPROVEMENTS 7 (big bet)a4af75crepo-ref parser + report filter unit-tested; API + raw fallback
8Report grammar defined; parsers lean on itIMPROVEMENTS 9 (big bet)48fdcb0new lint rule + test; Studio surfaces impact chip
9Venture dogfood (sourced Gut Check)IMPROVEMENTS 8 (big bet)f5f9fc33 reports under examples/venture/; example chips on 62/63/67
10MCP version from package.json; 3-digit hash routerIMPROVEMENTS 12 · BUGS 4683dff5smoke green; ^\d{2,3}$
11Conductor copy on playbook chipsIMPROVEMENTS 13ab85d16⧉ button fires copy_conductor from the chip
12sitemap.xml + robots.txt from the buildIMPROVEMENTS 147af662e71-URL sitemap; robots points at it; both follow GOAL_PROMPTS_BASE
13Vitals Viewer (/vitals) for HEALTH.md historyIMPROVEMENTS 10 (big bet)82c6194table parser unit-tested; in the JS-syntax gate
14Offline PWA via a generated service workerIMPROVEMENTS 15979b9f2content-hash cache version, deterministic; node --check sw.js
15MCP package publish-ready (files allowlist, keywords)IMPROVEMENTS 11e2b1ebenpm pack --dry-run → lean ~150KB tarball

Skipped / partial

  • npm publish itself (IMPROVEMENTS 11, big bet) — the package is now publish-ready but the actual npm publish and MCP-registry listing are blocked on npm credentials this environment doesn't have. Prep shipped; the publish is the one remaining manual step.
  • Community brief index (prior IMPROVEMENTS big bet) — still a project, not a one-commit fix; not in this run's scope.

Follow-ups the fixes revealed

  • scripts/og.py needs Pillow — a heavier dep than the stdlib-only site build. It's a dev/generate-time tool (the build only checks cards exist), but worth a note in CONTRIBUTING if brief-adding contributors hit it.
  • The Studio's GitHub loader and the report grammar (items 7–8) now make a report schema validator tractable — a natural next audit of the report format itself.
  • Family colors still live in two places (template.html CSS + scripts/og.py); only order/questions got unified. A future pass could inject colors too.

Session — 0.5 cycle (2026-07-07)

  • Date: 2026-07-07 · branch: v0.5-round · off 0.4.0 (d041b3f)
  • Reports consumed: IMPROVEMENTS.md, SECURITY.md, DX.md
  • Protocol: one finding per commit, the repo's own scripts/check run green after each

Fixed

FindingSourceCommitVerified by
Stemmed + rarity-weighted suggest_briefsIMPROVEMENTS quick win 1c5fd25cscripts/mcp-smoke.cjs — "looping" ranks 32 first
Sample-report chips on audited cardsIMPROVEMENTS quick win 23bd1a9fbuild emits example into catalog.json; chip renders on 00/01/06/14/47
Per-family conductors ("run all Trust")IMPROVEMENTS full-list3a9f51715 raw/family-*.md written; "run all N" button on each family
suggest_briefs states its scoring methodIMPROVEMENTS full-listc5fd25cmethod line present in tool output (asserted in smoke)
Linter tests, incl. Phase-2 lens scopingDX fix 26a56976python3 -m unittest discover -s tests — 12 pass
scripts/check one-command gate + smokeDX fix 1 · IMPROVEMENTS 549ef1d8scripts/check runs build + tests + JS syntax + MCP smoke
Baseline security headersSECURITY finding 38e8d57dnosniff · Referrer-Policy · frame-ancestors in vercel.json
Node-requirement note in CONTRIBUTINGDX fix 48d1c81bCONTRIBUTING names scripts/check; Node only for mcp/ + site scripts

These eight fixes were selected from the reports; the same cycle also shipped features that were not fix-findings (the Act family and briefs 48–53, the Report Studio, make_conductor, and GOAL_PROMPTS_BASE fork support), committed separately.

Skipped (findings deliberately not taken this cycle)

  • Self-host the two fonts — SECURITY finding 4 / IMPROVEMENTS quick win 3 / DX. Effort M and a genuine tradeoff (offline + privacy vs. a build-time font pipeline); left open for its own change.
  • j/k keyboard navigation — IMPROVEMENTS quick win 4. Additive, no report depends on it.
  • Deep-link scroll-margin under the sticky toolbar — BUGS finding 3 (BUGS was not in this run's consumed set; belongs to a Fixer pass over BUGS.md).
  • Three-digit hash router — BUGS finding 4, forward-compat only (ids reach 53; the cap bites at 100).
  • npm publish, report-diff viewer, community index, "surprise me" — IMPROVEMENTS big bets / engagement; scoped as projects, not one-commit fixes.

Follow-ups the fixes revealed

  • The rarity weighting is deliberately clamped (df floor 5) so a single vivid tagline can't dominate; worth revisiting if the catalog grows past ~100 briefs, where true IDF would behave differently.
  • scripts/check now defines the contribution contract end to end — a natural home for a future link-checker over the example and raw URLs.
  • With the Studio consuming reports and 47 consuming reports, the report format itself is now load-bearing; a light report schema could make both parsers stricter.

Report only — which of the skipped findings should the next Fixer run take?