This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+5 more
Summary
AI summaryTheme-aware color governance now supports dual‑theme palettes without collapsing dark colors.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Theme-aware colors support dual-theme palettes without collapsing dark colors Theme-aware colors support dual-theme palettes without collapsing dark colors Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Preflight truth adds same-document var() resolution with cycle-guarding and fallback awareness Preflight truth adds same-document var() resolution with cycle-guarding and fallback awareness Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Poisoned‑runtime runbook exercised for the first time with scripted tamper detection and response workflow Poisoned‑runtime runbook exercised for the first time with scripted tamper detection and response workflow Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Performance | Low |
TypeScript 7.0.2 migration produces byte‑identical runtime JavaScript with only ordering changes in declarations TypeScript 7.0.2 migration produces byte‑identical runtime JavaScript with only ordering changes in declarations Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Preflight truth fixes quoted font-family capture bug in <img> logo evidence extraction Preflight truth fixes quoted font-family capture bug in <img> logo evidence extraction Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Low |
21-test malformed-input suite hardens ingestion parsers to degrade or throw controlled errors on hangs 21-test malformed-input suite hardens ingestion parsers to degrade or throw controlled errors on hangs Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
Theme-aware color governance, preflight truth, ingestion hardening, and the TypeScript 7 migration.
Theme-aware colors (#35)
- (role, theme) merge key: dual-theme palettes no longer collapse; dark colors get their own runtime lane (colors_dark), DTCG group, and synthesis section; both themes join the check palette
- Extraction tags themes only on explicit dark-scope signals — no value guessing. Fully additive.
Preflight truth (#43)
- Same-document var() resolution (cycle-guarded, fallback-aware; unresolvables are info, not violations)
- logo evidence by filename/alt; quoted font-family capture bug fixed
Hardening
- 21-test malformed-input suite across all ingestion parsers (degrade or controlled-throw; hangs fail CI); findings → #45
- Poisoned-runtime runbook exercised for the first time (scripted tamper → detect → respond → clean); live drill honestly pending
TypeScript 7.0.2
- Same-source dist-diff vs 5.9: byte-identical runtime JavaScript, ordering-only declaration changes
Full changelog: https://github.com/Brandcode-Studio/brandsystem-mcp/blob/main/CHANGELOG.md
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Brand-System/brandsystem-mcp
Make your brand machine-readable. Extract brand identity (colors, fonts, logo, voice, visual rules) from any website via static CSS + rendered-page extraction, compile into DTCG tokens, brand runtime contracts, and interaction policies. 34 tools across 4 progressive sessions. Subscribable `brand://runtime` and `brand://policy` MCP resources. Content compliance scoring (0-100), pass/fail gate, and HTML/CSS preflight. Brandcode Studio connector for hosted brand sync.
Related context
Beta — feedback welcome: [email protected]