From a4a0e96832362bf93d15052247c62435e4bcfebc Mon Sep 17 00:00:00 2001 From: Cansin Yildiz Date: Thu, 10 Sep 2026 00:21:46 +0200 Subject: [PATCH 1/2] Stop calling the org profile the company homepage yellowpine.com is the homepage now. It serves the site from yellow-pine/yellow-pine.github.io rather than redirecting to github.com/yellow-pine, so the premise these files reason from is no longer true. The profile still matters -- it is what every visitor to github.com/yellow-pine lands on, and the invariants that keep it publishable are unchanged. It is just not the homepage any more, and a comment saying otherwise will mislead whoever next decides where a change belongs. Every remaining use of "homepage" in these files now means yellowpine.com, the actual homepage; the ones that meant the profile say profile. That includes the publish rule and two assertion messages, which read as claims about the homepage and were really about the profile all along. Prose, comments and assertion messages only. No behaviour changes; 23/23 with network checks enabled. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01Q5nJ8eKEb1wm5tCzxipXHS --- .github/workflows/ci.yml | 3 ++- README.md | 17 +++++++++-------- tests/profile.test.mjs | 14 +++++++------- 3 files changed, 18 insertions(+), 16 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8a39baf..a61ba3f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,6 +1,7 @@ name: ci -# The org profile README is the company homepage (yellowpine.com redirects here), so its +# The org profile README is the org's front page on GitHub — the company homepage itself +# is yellowpine.com — so its # invariants are tested: assets resolve, brand SVGs are real vectors, and — because the # tests fetch without credentials — every linked repo is publicly visible and every # product link is live. The weekly cron catches links that die between pushes. diff --git a/README.md b/README.md index 4662eed..cc7f0c8 100644 --- a/README.md +++ b/README.md @@ -1,23 +1,24 @@ -# .github — the Yellow Pine homepage +# .github — the Yellow Pine org profile -Organization-wide GitHub configuration for **Yellow Pine**. Because yellowpine.com -redirects to [github.com/yellow-pine](https://github.com/yellow-pine), the org profile -rendered from this repository **is** the company homepage. +Organization-wide GitHub configuration for **Yellow Pine**. The company homepage is +[yellowpine.com](https://yellowpine.com). The org profile rendered from this repository is +what every visitor to [github.com/yellow-pine](https://github.com/yellow-pine) lands on, so +it is held to the same standard — but it is no longer the homepage itself. ## Contents -- [`profile/README.md`](profile/README.md) — the public org profile / homepage. +- [`profile/README.md`](profile/README.md) — the public org profile. - [`brand/`](brand/) — the canonical public brand library: hand-cleaned SVG masters (logo, dark variant, tile icon, bare mark), palette, and usage rules. The full Brandmark export archive and raster generators live in the private `yellow-pine/brand-assets` repo. -- [`tests/`](tests/) — homepage invariants, run by [CI](.github/workflows/ci.yml) on every +- [`tests/`](tests/) — profile invariants, run by [CI](.github/workflows/ci.yml) on every push and weekly: every referenced asset exists, brand SVGs are real vectors, every linked repo is publicly visible **without auth** (nothing private can leak onto the - homepage), and every product link is live. + profile), and every product link is live. ## The publish rule -A project appears on the homepage only if it is a public repo, or a private repo with a +A project appears on the profile only if it is a public repo, or a private repo with a live public website. The tests enforce the mechanical half of this: they fetch every `github.com/yellow-pine/*` link anonymously and fail on anything not public. diff --git a/tests/profile.test.mjs b/tests/profile.test.mjs index 94b5ff4..9be1754 100644 --- a/tests/profile.test.mjs +++ b/tests/profile.test.mjs @@ -1,13 +1,13 @@ -// Invariants for the Yellow Pine org homepage (profile/README.md) and the brand library. +// Invariants for the Yellow Pine org profile (profile/README.md) and the brand library. // -// yellowpine.com redirects to github.com/yellow-pine, so profile/README.md IS the company -// homepage — these tests are the gate that keeps it publishable: +// The company homepage is yellowpine.com. profile/README.md is what every visitor to +// github.com/yellow-pine lands on — these tests are the gate that keeps it publishable: // // 1. Every relative asset a README references must exist in the repo. // 2. Every github.com/yellow-pine/* link must be reachable WITHOUT auth — the publish // rule expressed without naming any repo: a link to a private repo 404s for the // anonymous public and fails here. -// 3. Every external product link must be live (a dead product link on the homepage is +// 3. Every external product link must be live (a dead product link on the profile is // worse than no link). // 4. brand/ must hold real vector SVGs (light + dark logo, icon) — no raster embeds. // @@ -84,7 +84,7 @@ const skipNetwork = process.env.SKIP_NETWORK === '1'; test('profile/README.md exists and is substantial', () => { assert.ok(existsSync(join(repoRoot, PROFILE)), 'profile/README.md missing'); - assert.ok(read(PROFILE).length > 500, 'profile/README.md is too thin to be the homepage'); + assert.ok(read(PROFILE).length > 500, 'profile/README.md is too thin to be the org profile'); }); test('every local asset referenced by a README exists', () => { @@ -119,11 +119,11 @@ test('brand SVGs are real vectors', () => { } }); -// --- the homepage's links must hold up for the anonymous public -------------------- +// --- the profile's links must hold up for the anonymous public --------------------- test('every yellow-pine GitHub link is publicly reachable without auth', { skip: skipNetwork }, async () => { const orgLinks = externalLinks().filter((u) => u.startsWith('https://github.com/yellow-pine')); - assert.ok(orgLinks.length >= 1, 'homepage should link at least one yellow-pine repo'); + assert.ok(orgLinks.length >= 1, 'the profile should link at least one yellow-pine repo'); for (const url of orgLinks) { const status = await fetchStatus(url); assert.equal(status, 200, `${url} is not publicly visible without auth (HTTP ${status})`); From bdb88fea47b2ec9eb3069fffa7c881dad97a0d97 Mon Sep 17 00:00:00 2001 From: Cansin Yildiz Date: Thu, 10 Sep 2026 00:39:02 +0200 Subject: [PATCH 2/2] Finish the sweep the first pass stopped short of A review caught that the previous commit fixed the three files it set out to fix and left the same false premise standing in four other places -- including the two highest-visibility ones. package.json still described this repo as "the public Yellow Pine profile (the company homepage)", directly contradicting the README beside it. The GitHub repo description said the same thing, and that string is not decoration: the Applications brand board mocks `gh repo view yellow-pine/.github` and prints it verbatim, so the claim was being presented in the brand deck to people with no way to know it was stale. Fixed the generator, not the generated file, and re-ran design:build -- tests/design.test.mjs byte-compares the two. The live description is updated to match, so the mock and the reality it imitates agree. Two of my own edits were also wrong: The publish rule said "appears on the homepage"; swapping that to "profile" quietly narrowed a company-wide rule to one surface, and left nothing stating any rule for yellowpine.com -- the surface that actually is the homepage now. It reads as company-wide again, with the enforcement scoped instead. The ci.yml comment put "so its invariants are tested" directly after "yellowpine.com", binding "its" to the website, which this workflow does not test at all. That is exactly the misdirection the last commit message said it wanted to prevent. The subject is explicit now, and the block is rewrapped. Also gave "held to the same standard" the antecedent it never had. 23/23 with network checks enabled. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01Q5nJ8eKEb1wm5tCzxipXHS --- .github/workflows/ci.yml | 10 +++++----- README.md | 12 ++++++++---- brand/design/build-boards.mjs | 2 +- brand/design/canvas/Applications.dc.html | 2 +- package.json | 2 +- 5 files changed, 16 insertions(+), 12 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a61ba3f..2b48ea6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,10 +1,10 @@ name: ci -# The org profile README is the org's front page on GitHub — the company homepage itself -# is yellowpine.com — so its -# invariants are tested: assets resolve, brand SVGs are real vectors, and — because the -# tests fetch without credentials — every linked repo is publicly visible and every -# product link is live. The weekly cron catches links that die between pushes. +# The org profile README is the org's front page on GitHub (the company homepage itself is +# yellowpine.com, built from yellow-pine/yellow-pine.github.io, not from here). The README's +# invariants are what this workflow tests: assets resolve, brand SVGs are real vectors, and — +# because the tests fetch without credentials — every linked repo is publicly visible and +# every product link is live. The weekly cron catches links that die between pushes. on: push: branches: [main] diff --git a/README.md b/README.md index cc7f0c8..b2ffc80 100644 --- a/README.md +++ b/README.md @@ -3,7 +3,8 @@ Organization-wide GitHub configuration for **Yellow Pine**. The company homepage is [yellowpine.com](https://yellowpine.com). The org profile rendered from this repository is what every visitor to [github.com/yellow-pine](https://github.com/yellow-pine) lands on, so -it is held to the same standard — but it is no longer the homepage itself. +it is held to the publish rule below and to the invariants in [`tests/`](tests/) — but it is +not the homepage itself. ## Contents @@ -18,9 +19,12 @@ it is held to the same standard — but it is no longer the homepage itself. ## The publish rule -A project appears on the profile only if it is a public repo, or a private repo with a -live public website. The tests enforce the mechanical half of this: they fetch every -`github.com/yellow-pine/*` link anonymously and fail on anything not public. +A project is publishable — on the profile, on yellowpine.com, anywhere Yellow Pine speaks +publicly — only if it is a public repo, or a private repo with a live public website. The +rule is company-wide; what is scoped is the enforcement. The tests here cover the mechanical +half **for the profile**: they fetch every `github.com/yellow-pine/*` link anonymously and +fail on anything not public. The website repo inherits the rule and enforces it the same way +against its own page. ```sh npm test # run the invariants locally diff --git a/brand/design/build-boards.mjs b/brand/design/build-boards.mjs index 8dda3e2..42abe7f 100644 --- a/brand/design/build-boards.mjs +++ b/brand/design/build-boards.mjs @@ -304,7 +304,7 @@ ${FOOT}`);

Terminal

➜ ~/code gh repo view yellow-pine/.github
-
The Yellow Pine homepage — org profile, public brand library, and org-wide config.
+
The Yellow Pine org profile, public brand library, and org-wide config.
➜ ~/code git push # built with 💛 by a tiny human team and a fleet of agents
diff --git a/brand/design/canvas/Applications.dc.html b/brand/design/canvas/Applications.dc.html index 2c541ee..2a32722 100644 --- a/brand/design/canvas/Applications.dc.html +++ b/brand/design/canvas/Applications.dc.html @@ -39,7 +39,7 @@

Browser tabs

Terminal

➜ ~/code gh repo view yellow-pine/.github
-
The Yellow Pine homepage — org profile, public brand library, and org-wide config.
+
The Yellow Pine org profile, public brand library, and org-wide config.
➜ ~/code git push # built with 💛 by a tiny human team and a fleet of agents
diff --git a/package.json b/package.json index 88239ae..0a2be8e 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "@yellow-pine/dot-github", "private": true, - "description": "Org-wide GitHub configuration + the public Yellow Pine profile (the company homepage).", + "description": "Org-wide GitHub configuration + the public Yellow Pine profile and brand library.", "type": "module", "scripts": { "test": "node --test tests/profile.test.mjs tests/design.test.mjs",