feat: publish Toolbox 0.15.0 with Sudoku Tools 0.2.0

This commit is contained in:
2026-08-31 08:44:44 +02:00
parent 7bd34371a9
commit bc07e13e3b
12 changed files with 41 additions and 41 deletions
+2 -2
View File
@@ -5,5 +5,5 @@ TRAEFIK_NETWORK=internal
TRAEFIK_CERT_RESOLVER=netcup TRAEFIK_CERT_RESOLVER=netcup
# Keep these two values paired when deploying a newer published toolbox release. # Keep these two values paired when deploying a newer published toolbox release.
TOOLBOX_RELEASE_VERSION=0.14.0 TOOLBOX_RELEASE_VERSION=0.15.0
TOOLBOX_RELEASE_SHA256=e79f4aadfce3222855a3829805e72ebe399ce863df5e2b57ea0bd606139c2d6d TOOLBOX_RELEASE_SHA256=3e88b91cf73a5f9166ede37b9f23528824d977ed356808c050253aefea8c98d3
+2 -2
View File
@@ -2,8 +2,8 @@ ARG NGINX_IMAGE=nginxinc/nginx-unprivileged:1.31.3-alpine@sha256:18d67281256ded3
FROM ${NGINX_IMAGE} AS release FROM ${NGINX_IMAGE} AS release
ARG TOOLBOX_RELEASE_VERSION=0.14.0 ARG TOOLBOX_RELEASE_VERSION=0.15.0
ARG TOOLBOX_RELEASE_SHA256=e79f4aadfce3222855a3829805e72ebe399ce863df5e2b57ea0bd606139c2d6d ARG TOOLBOX_RELEASE_SHA256=3e88b91cf73a5f9166ede37b9f23528824d977ed356808c050253aefea8c98d3
ARG TOOLBOX_RELEASE_BASE_URL=https://git.add-ideas.de/lotobo/toolbox-portal/releases/download ARG TOOLBOX_RELEASE_BASE_URL=https://git.add-ideas.de/lotobo/toolbox-portal/releases/download
RUN set -eu; \ RUN set -eu; \
+15 -15
View File
@@ -1,7 +1,7 @@
# add·ideas Toolbox Portal # add·ideas Toolbox Portal
`toolbox-portal` is the static launcher and release assembler for the add·ideas `toolbox-portal` is the static launcher and release assembler for the add·ideas
browser toolbox. Version `0.2.16` reads one same-origin catalogue, shows each app browser toolbox. Version `0.2.17` reads one same-origin catalogue, shows each app
as a compact launch tile, and keeps personal pins, drag-and-drop ordering, as a compact launch tile, and keeps personal pins, drag-and-drop ordering,
visibility, and appearance in the current browser. Pinned tools have their own visibility, and appearance in the current browser. Pinned tools have their own
section; search, category, and clickable tag filters stay close to the tool section; search, category, and clickable tag filters stay close to the tool
@@ -69,7 +69,7 @@ privacy and executable-code warning. Light, dark, and system modes are supported
## Production deployment behind Traefik ## Production deployment behind Traefik
The committed `compose.yaml` is the shortest production path. Its release The committed `compose.yaml` is the shortest production path. Its release
container downloads the immutable Toolbox 0.14.0 ZIP during the image build, container downloads the immutable Toolbox 0.15.0 ZIP during the image build,
verifies SHA-256 before extracting it, and then copies only the verified static verifies SHA-256 before extracting it, and then copies only the verified static
files into the pinned unprivileged nginx image. Node.js and a local portal files into the pinned unprivileged nginx image. Node.js and a local portal
assembly are not required on the deployment host. assembly are not required on the deployment host.
@@ -133,10 +133,10 @@ The app release should also publish a matching `.sha256` sidecar. The manifest
must declare the pinned reverse-DNS id and version. Application and portal must declare the pinned reverse-DNS id and version. Application and portal
versions are independent. versions are independent.
`release/toolbox.lock.json` is the reviewed v0.14.0 lock. Its URLs and checksums `release/toolbox.lock.json` is the reviewed v0.15.0 lock. Its URLs and checksums
pin the published PDF Tools 0.4.4, XSLT Tools 0.4.3, OneNote Tools 0.3.4, pin the published PDF Tools 0.4.4, XSLT Tools 0.4.3, OneNote Tools 0.3.4,
Audio & Video Tools 0.3.0, Regex Tools 0.4.2, SVG Tools 0.1.0, OTP & Passkey Audio & Video Tools 0.3.0, Regex Tools 0.4.2, SVG Tools 0.1.0, OTP & Passkey
Tools 0.3.0, and Sudoku Tools 0.1.0 release bytes. Use Tools 0.3.0, and Sudoku Tools 0.2.0 release bytes. Use
`release/toolbox.lock.example.json` as the template for a future release and `release/toolbox.lock.example.json` as the template for a future release and
verify every downloaded asset before committing updated values. Artifacts may be: verify every downloaded asset before committing updated values. Artifacts may be:
@@ -157,7 +157,7 @@ npm run assemble -- \
--lock release/toolbox.lock.json \ --lock release/toolbox.lock.json \
--portal-dist dist \ --portal-dist dist \
--output build/toolbox \ --output build/toolbox \
--archive build/add-ideas-toolbox-0.14.0.zip --archive build/add-ideas-toolbox-0.15.0.zip
``` ```
Existing output is refused. Pass `--force` only when replacing those exact Existing output is refused. Pass `--force` only when replacing those exact
@@ -182,8 +182,8 @@ build/toolbox/
├── auth/ ├── auth/
└── sudoku/ └── sudoku/
build/add-ideas-toolbox-0.14.0.zip build/add-ideas-toolbox-0.15.0.zip
build/add-ideas-toolbox-0.14.0.zip.sha256 build/add-ideas-toolbox-0.15.0.zip.sha256
``` ```
The assembler verifies SHA-256 before opening an artifact, validates every app The assembler verifies SHA-256 before opening an artifact, validates every app
@@ -204,7 +204,7 @@ directory separately:
```sh ```sh
npm run package:static -- \ npm run package:static -- \
--input build/toolbox \ --input build/toolbox \
--output artifacts/add-ideas-toolbox-0.14.0.zip --output artifacts/add-ideas-toolbox-0.15.0.zip
``` ```
This also emits a `.sha256` sidecar. This also emits a `.sha256` sidecar.
@@ -232,9 +232,9 @@ normal local XML/XSLT transformations do not require that permission.
```sh ```sh
podman build -f Containerfile \ podman build -f Containerfile \
-t git.add-ideas.de/lotobo/toolbox:0.14.0 . -t git.add-ideas.de/lotobo/toolbox:0.15.0 .
podman run --rm -p 8080:8080 \ podman run --rm -p 8080:8080 \
git.add-ideas.de/lotobo/toolbox:0.14.0 git.add-ideas.de/lotobo/toolbox:0.15.0
``` ```
For a direct-port local deployment after assembly, use the separate example: For a direct-port local deployment after assembly, use the separate example:
@@ -251,8 +251,8 @@ docker login git.add-ideas.de
docker buildx build \ docker buildx build \
--platform linux/amd64,linux/arm64 \ --platform linux/amd64,linux/arm64 \
--file Containerfile.release \ --file Containerfile.release \
--tag git.add-ideas.de/lotobo/toolbox:0.14.0 \ --tag git.add-ideas.de/lotobo/toolbox:0.15.0 \
--tag git.add-ideas.de/lotobo/toolbox:0.14 \ --tag git.add-ideas.de/lotobo/toolbox:0.15 \
--push . --push .
``` ```
@@ -277,8 +277,8 @@ needs permission to push code, releases, and container packages to
all eight apps, switch between them, and confirm the encoded `toolbox` all eight apps, switch between them, and confirm the encoded `toolbox`
context. context.
5. Verify the distribution with 5. Verify the distribution with
`(cd build && sha256sum -c add-ideas-toolbox-0.14.0.zip.sha256)`. `(cd build && sha256sum -c add-ideas-toolbox-0.15.0.zip.sha256)`.
6. Commit the reviewed lock, tag the toolbox release (for example `v0.14.0`), and 6. Commit the reviewed lock, tag the toolbox release (for example `v0.15.0`), and
push the branch and tag to Gitea. push the branch and tag to Gitea.
7. In Gitea, open **Releases → New release**, select the tag, and upload the 7. In Gitea, open **Releases → New release**, select the tag, and upload the
static ZIP plus its `.sha256` file. Do not use a mutable “latest” URL in a static ZIP plus its `.sha256` file. Do not use a mutable “latest” URL in a
@@ -302,7 +302,7 @@ must not re-resolve app versions or substitute a newer release.
| **`regex-tools`** | Current local-first v0.4.2 release; dedicated repository | Develop, explain, test and apply JavaScript, PCRE2, PHP, Perl, Python, Ruby, Java, C++, Go, .NET, Rust and Scala/JVM-compatible regular expressions | Deterministic syntax trees; engine-native matching, captures and bounded replacement; stable double-buffered live results; PCRE2 tracing and C17 generation; comparison; corpus apply; tests; risk/growth/benchmark analysis; generated cases; bounded minimization; validated ECMAScript formatting; project import/export and optional local persistence | Open-source regexpp and pinned local WebAssembly runtimes for PCRE2, PHP preg, legacy Perl, CPython, CRuby, TeaVM Java/Scala compatibility, libc++ C++, Go, .NET and Rust in killable workers; explicit source/licence inventories, resource limits and engine-specific offset semantics | | **`regex-tools`** | Current local-first v0.4.2 release; dedicated repository | Develop, explain, test and apply JavaScript, PCRE2, PHP, Perl, Python, Ruby, Java, C++, Go, .NET, Rust and Scala/JVM-compatible regular expressions | Deterministic syntax trees; engine-native matching, captures and bounded replacement; stable double-buffered live results; PCRE2 tracing and C17 generation; comparison; corpus apply; tests; risk/growth/benchmark analysis; generated cases; bounded minimization; validated ECMAScript formatting; project import/export and optional local persistence | Open-source regexpp and pinned local WebAssembly runtimes for PCRE2, PHP preg, legacy Perl, CPython, CRuby, TeaVM Java/Scala compatibility, libc++ C++, Go, .NET and Rust in killable workers; explicit source/licence inventories, resource limits and engine-specific offset semantics |
| **`svg-tools`** | Initial local-first v0.1.0 release; dedicated repository | Inspect and edit SVG source, structure, geometry, references and accessibility locally | Synchronized source/tree/canvas/inspector; path and transform tools; reference analysis; optimization; CSS animation preview; exact, sanitized, raster and project export | Untrusted SVG is sanitized into an opaque-origin sandbox; bounded parsing and decompression, explicit security findings and a URI-scoped controller header exception; later milestone slices remain intentionally tracked in the app repository | | **`svg-tools`** | Initial local-first v0.1.0 release; dedicated repository | Inspect and edit SVG source, structure, geometry, references and accessibility locally | Synchronized source/tree/canvas/inspector; path and transform tools; reference analysis; optimization; CSS animation preview; exact, sanitized, raster and project export | Untrusted SVG is sanitized into an opaque-origin sandbox; bounded parsing and decompression, explicit security findings and a URI-scoped controller header exception; later milestone slices remain intentionally tracked in the app repository |
| **`auth-tools`** | Current local-first v0.3.0 release; dedicated repository | Generate, migrate and diagnose OTP credentials, and inspect, verify and test WebAuthn/passkey ceremonies locally | HOTP/TOTP/OCRA with time travel, resynchronization and rotation planning; QR, Google, Aegis and encrypted PSKC migration; WebAuthn extension experiments and replayable traces; assertion, attestation, signer-chain and historical metadata-policy evaluation | Authentication material remains memory-only unless explicitly exported; redaction is deliberate but not a secrecy guarantee; live ceremonies and camera scanning are enabled only at the exact dedicated `auth.toolbox.add-ideas.de` origin, while the shared Portal path remains inspect-only; no raw CTAP administration | | **`auth-tools`** | Current local-first v0.3.0 release; dedicated repository | Generate, migrate and diagnose OTP credentials, and inspect, verify and test WebAuthn/passkey ceremonies locally | HOTP/TOTP/OCRA with time travel, resynchronization and rotation planning; QR, Google, Aegis and encrypted PSKC migration; WebAuthn extension experiments and replayable traces; assertion, attestation, signer-chain and historical metadata-policy evaluation | Authentication material remains memory-only unless explicitly exported; redaction is deliberate but not a secrecy guarantee; live ceremonies and camera scanning are enabled only at the exact dedicated `auth.toolbox.add-ideas.de` origin, while the shared Portal path remains inspect-only; no raw CTAP administration |
| **`sudoku-tools`** | Initial local-first v0.1.0 release; dedicated repository | Set, play, generate, analyse and solve classic, Killer and common variant Sudoku locally | 4×416×16 grids; givens and custom regions; cages, diagonals, thermos, arrows, Kropki, XV, inequalities, renban and palindrome lines; notes, colours, history, timer, exact uniqueness checks, explained logic, focused calculators, local projects and bounded import/export | Worker-bounded solving and generation; IndexedDB with memory fallback; self-contained links and supported f-puzzles fields stay local; unsupported foreign rules stop explicitly instead of being silently discarded | | **`sudoku-tools`** | Current local-first v0.2.0 release; dedicated repository | Set, play, generate, analyse and solve classic, Killer and rich variant Sudoku locally | 4×416×16 grids; registry-backed constraint packs including cages, lines, dots, XV, inequalities, indexing and Fog of War; staged hints, candidate maintenance, advanced logical techniques, setter quality checks, mixed-variant generation, source-preserving f-puzzles/SudokuPad interoperability, autosave recovery and searchable local projects | Worker-bounded solving, generation and quality analysis; strict inert imported-visual validation; fog-safe play assistance; IndexedDB history with memory fallback; responsive zoom, pan, tap selection, patterned colours, accessibility controls and an offline-capable PWA shell |
## Planned tools ## Planned tools
+1 -1
View File
@@ -3,7 +3,7 @@ services:
build: build:
context: . context: .
dockerfile: Containerfile dockerfile: Containerfile
image: git.add-ideas.de/lotobo/toolbox:0.14.0 image: git.add-ideas.de/lotobo/toolbox:0.15.0
restart: unless-stopped restart: unless-stopped
read_only: true read_only: true
ports: ports:
+3 -3
View File
@@ -6,9 +6,9 @@ services:
context: . context: .
dockerfile: Containerfile.release dockerfile: Containerfile.release
args: args:
TOOLBOX_RELEASE_VERSION: "${TOOLBOX_RELEASE_VERSION:-0.14.0}" TOOLBOX_RELEASE_VERSION: "${TOOLBOX_RELEASE_VERSION:-0.15.0}"
TOOLBOX_RELEASE_SHA256: "${TOOLBOX_RELEASE_SHA256:-e79f4aadfce3222855a3829805e72ebe399ce863df5e2b57ea0bd606139c2d6d}" TOOLBOX_RELEASE_SHA256: "${TOOLBOX_RELEASE_SHA256:-3e88b91cf73a5f9166ede37b9f23528824d977ed356808c050253aefea8c98d3}"
image: "git.add-ideas.de/lotobo/toolbox:${TOOLBOX_RELEASE_VERSION:-0.14.0}" image: "git.add-ideas.de/lotobo/toolbox:${TOOLBOX_RELEASE_VERSION:-0.15.0}"
restart: unless-stopped restart: unless-stopped
read_only: true read_only: true
tmpfs: tmpfs:
+2 -2
View File
@@ -1,12 +1,12 @@
{ {
"name": "@add-ideas/toolbox-portal", "name": "@add-ideas/toolbox-portal",
"version": "0.2.16", "version": "0.2.17",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "@add-ideas/toolbox-portal", "name": "@add-ideas/toolbox-portal",
"version": "0.2.16", "version": "0.2.17",
"license": "AGPL-3.0-only", "license": "AGPL-3.0-only",
"dependencies": { "dependencies": {
"@add-ideas/toolbox-contract": "^0.2.3", "@add-ideas/toolbox-contract": "^0.2.3",
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "@add-ideas/toolbox-portal", "name": "@add-ideas/toolbox-portal",
"version": "0.2.16", "version": "0.2.17",
"license": "AGPL-3.0-only", "license": "AGPL-3.0-only",
"private": true, "private": true,
"type": "module", "type": "module",
+2 -2
View File
@@ -1,8 +1,8 @@
# Corresponding source # Corresponding source
The source code corresponding to add·ideas Toolbox Portal 0.2.16 is available at: The source code corresponding to add·ideas Toolbox Portal 0.2.17 is available at:
https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.14.0 https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.15.0
Each bundled application contains its own `SOURCE.md`, license, and third-party Each bundled application contains its own `SOURCE.md`, license, and third-party
license materials. The application sources are also linked from the portal. license materials. The application sources are also linked from the portal.
+5 -5
View File
@@ -1,8 +1,8 @@
{ {
"$schema": "./toolbox-release-lock.schema.json", "$schema": "./toolbox-release-lock.schema.json",
"schemaVersion": 1, "schemaVersion": 1,
"releaseVersion": "0.14.0", "releaseVersion": "0.15.0",
"portalVersion": "0.2.16", "portalVersion": "0.2.17",
"catalogue": { "catalogue": {
"id": "de.add-ideas.toolbox", "id": "de.add-ideas.toolbox",
"name": "add·ideas Toolbox", "name": "add·ideas Toolbox",
@@ -64,9 +64,9 @@
}, },
{ {
"id": "de.add-ideas.sudoku-tools", "id": "de.add-ideas.sudoku-tools",
"version": "0.1.0", "version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/sudoku-tools/releases/download/v0.1.0/sudoku-tools-0.1.0.zip", "artifact": "https://git.add-ideas.de/lotobo/sudoku-tools/releases/download/v0.2.0/sudoku-tools-0.2.0.zip",
"sha256": "bc277791dc50d5fdb39f5abd098d81ea7d84b8a9bc43ca86214de7ee335abf61", "sha256": "3cee275b97838d5ebb53424cceb6abdda7ca837fe667d58d30431f449a024a4f",
"target": "sudoku" "target": "sudoku"
} }
] ]
+5 -5
View File
@@ -1,8 +1,8 @@
{ {
"$schema": "./toolbox-release-lock.schema.json", "$schema": "./toolbox-release-lock.schema.json",
"schemaVersion": 1, "schemaVersion": 1,
"releaseVersion": "0.14.0", "releaseVersion": "0.15.0",
"portalVersion": "0.2.16", "portalVersion": "0.2.17",
"catalogue": { "catalogue": {
"id": "de.add-ideas.toolbox", "id": "de.add-ideas.toolbox",
"name": "add·ideas Toolbox", "name": "add·ideas Toolbox",
@@ -64,9 +64,9 @@
}, },
{ {
"id": "de.add-ideas.sudoku-tools", "id": "de.add-ideas.sudoku-tools",
"version": "0.1.0", "version": "0.2.0",
"artifact": "https://git.add-ideas.de/lotobo/sudoku-tools/releases/download/v0.1.0/sudoku-tools-0.1.0.zip", "artifact": "https://git.add-ideas.de/lotobo/sudoku-tools/releases/download/v0.2.0/sudoku-tools-0.2.0.zip",
"sha256": "bc277791dc50d5fdb39f5abd098d81ea7d84b8a9bc43ca86214de7ee335abf61", "sha256": "3cee275b97838d5ebb53424cceb6abdda7ca837fe667d58d30431f449a024a4f",
"target": "sudoku" "target": "sudoku"
} }
] ]
+1 -1
View File
@@ -83,7 +83,7 @@ function makeLock(artifact: string, sha256: string) {
return { return {
schemaVersion: 1, schemaVersion: 1,
releaseVersion: '0.1.0', releaseVersion: '0.1.0',
portalVersion: '0.2.16', portalVersion: '0.2.17',
catalogue: { catalogue: {
id: 'de.add-ideas.toolbox', id: 'de.add-ideas.toolbox',
name: 'Test Toolbox', name: 'Test Toolbox',
+2 -2
View File
@@ -489,9 +489,9 @@ export default function App() {
</span> </span>
</p> </p>
<span> <span>
Portal v0.2.16 ·{' '} Portal v0.2.17 ·{' '}
<a <a
href="https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.14.0" href="https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.15.0"
target="_blank" target="_blank"
rel="noopener noreferrer" rel="noopener noreferrer"
> >