Skip to content

Release: merge development into beta - #45

Open
github-actions[bot] wants to merge 442 commits into
betafrom
development
Open

Release: merge development into beta#45
github-actions[bot] wants to merge 442 commits into
betafrom
development

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated PR to sync development changes to beta for beta release.

Merging this PR will trigger the beta release workflow.

Reminder: Add a major, minor, or patch label to this PR to control the version bump. Default is patch.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report

Repository ConductionNL/nldesign
Commit 796c4ee
Branch 45/merge
Event pull_request
Generated 2026-03-19 19:05 UTC
Workflow Run https://github.com/ConductionNL/nldesign/actions/runs/23312024709

Summary

Group Result
PHP Quality PASS
Vue Quality PASS
Security PASS
License PASS
PHPUnit PASS
Newman SKIP

PHP Quality

Tool Result
lint PASS
phpcs PASS
phpmd PASS
psalm PASS
phpstan PASS
phpmetrics PASS

Vue Quality

Tool Result
eslint PASS
stylelint PASS

Security

Ecosystem Result
composer PASS
npm PASS

License Compliance

Ecosystem Result
composer PASS
npm PASS

composer dependencies (100 total)

Metric Count
Approved (allowlist) 100
Approved (override) 0
Denied 0

npm dependencies (7 total)

Metric Count
Approved (allowlist) 5
Approved (override) 2
Denied 0

PHPUnit Tests

PHP Nextcloud Result
Overall PASS

Code coverage: 0% (0 / 24 statements)

Integration Tests (Newman)

Newman integration tests were not enabled for this run.


Generated automatically by the Quality workflow.

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report

Repository ConductionNL/nldesign
Commit 452ede8
Branch 45/merge
Event pull_request
Generated 2026-03-19 21:37 UTC
Workflow Run https://github.com/ConductionNL/nldesign/actions/runs/23318045149

Summary

Group Result
PHP Quality PASS
Vue Quality PASS
Security PASS
License PASS
PHPUnit PASS
Newman SKIP

PHP Quality

Tool Result
lint PASS
phpcs PASS
phpmd PASS
psalm PASS
phpstan PASS
phpmetrics PASS

Vue Quality

Tool Result
eslint PASS
stylelint PASS

Security

Ecosystem Result
composer PASS
npm PASS

License Compliance

Ecosystem Result
composer PASS
npm PASS

composer dependencies (100 total)

Metric Count
Approved (allowlist) 100
Approved (override) 0
Denied 0

npm dependencies (7 total)

Metric Count
Approved (allowlist) 5
Approved (override) 2
Denied 0

PHPUnit Tests

PHP Nextcloud Result
Overall PASS

Code coverage: 0% (0 / 24 statements)

Integration Tests (Newman)

Newman integration tests were not enabled for this run.


Generated automatically by the Quality workflow.

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report

Repository ConductionNL/nldesign
Commit 1652e7f
Branch 45/merge
Event pull_request
Generated 2026-03-23 21:38 UTC
Workflow Run https://github.com/ConductionNL/nldesign/actions/runs/23461372774

Summary

Group Result
PHP Quality PASS
Vue Quality PASS
Security PASS
License PASS
PHPUnit PASS
Newman SKIP

PHP Quality

Tool Result
lint PASS
phpcs PASS
phpmd PASS
psalm PASS
phpstan PASS
phpmetrics PASS

Vue Quality

Tool Result
eslint PASS
stylelint PASS

Security

Ecosystem Result
composer PASS
npm PASS

License Compliance

Ecosystem Result
composer PASS
npm PASS

composer dependencies (100 total)

Metric Count
Approved (allowlist) 100
Approved (override) 0
Denied 0

npm dependencies (7 total)

Metric Count
Approved (allowlist) 5
Approved (override) 2
Denied 0

PHPUnit Tests

PHP Nextcloud Result
Overall PASS

Code coverage: 0% (0 / 24 statements)

Integration Tests (Newman)

Newman integration tests were not enabled for this run.


Generated automatically by the Quality workflow.

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report

Repository ConductionNL/nldesign
Commit acbb095
Branch 45/merge
Event pull_request
Generated 2026-04-09 09:48 UTC
Workflow Run https://github.com/ConductionNL/nldesign/actions/runs/24183659733

Summary

Group Result
PHP Quality PASS
Vue Quality PASS
Security PASS
License PASS
PHPUnit PASS
Newman SKIP
Playwright SKIP

PHP Quality

Tool Result
lint PASS
phpcs PASS
phpmd PASS
psalm PASS
phpstan PASS
phpmetrics PASS

Vue Quality

Tool Result
eslint PASS
stylelint PASS

Security

Ecosystem Result
composer PASS
npm PASS

License Compliance

Ecosystem Result
composer PASS
npm PASS

composer dependencies (100 total)

Metric Count
Approved (allowlist) 100
Approved (override) 0
Denied 0

npm dependencies (7 total)

Metric Count
Approved (allowlist) 5
Approved (override) 2
Denied 0

PHPUnit Tests

PHP Nextcloud Result
Overall PASS

Code coverage: 0% (0 / 24 statements)

Integration Tests (Newman)

Newman integration tests were not enabled for this run.

E2E Tests (Playwright)

Playwright E2E tests were not enabled for this run.


Generated automatically by the Quality workflow.

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented May 1, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e0b6c18

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-01 11:51 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 33bfd61

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-07 20:51 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e5323e2

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-07 21:25 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 13c6474

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-12 22:09 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ b568281

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-12 22:29 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 6622f07

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-13 09:26 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 9aca552

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-17 07:45 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ f546205

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 18:09 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 772217c

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 18:54 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ b606ba3

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 19:16 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ b935b19

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 20:47 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 8ccab3a

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 20:59 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 7cc0b80

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 21:17 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 6caa0b5

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 02:56 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ ec8228b

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 03:08 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 6d9de7e

Check PHP Vue Security License Tests
lint ⏭️
phpcs ⏭️
phpmd ⏭️
psalm ⏭️
phpstan ⏭️
phpmetrics ⏭️
eslint ⏭️
stylelint ⏭️
composer ⏭️ ⏭️
npm ⏭️ ⏭️
PHPUnit
Newman
Playwright

Quality workflow — 2026-05-19 05:05 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 9d39dfa

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 05:07 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ d0a0f90

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Quality workflow — 2026-05-19 05:21 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e4f5c54

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 05:24 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 0d0d51a

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 07:42 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ fd9e665

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 08:13 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ c4f612c

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 08:23 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e222d87

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 08:35 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ f369153

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit ⏭️
Newman ⏭️
Playwright ⏭️

Quality workflow — 2026-05-21 20:32 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 503fc89

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer
npm ✅ 7/7
PHPUnit ⏭️
Newman ⏭️
Playwright ⏭️

Quality workflow — 2026-05-22 07:13 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 84a13c0

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer
npm ✅ 7/7
PHPUnit ⏭️
Newman ⏭️
Playwright ⏭️

Quality workflow — 2026-05-23 07:26 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ f661956

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-13 11:21 UTC

Download the full PDF report from the workflow artifacts.

nldesign's three unthrottled #[PublicPage] endpoints -- the webfont file
server, its @font-face stylesheet, and the health probe. nldesign now reports
ZERO.

This app was recorded as having ZERO public endpoints in the original sweep
and was therefore never looked at again. That entry came from the same
inflated grep that produced the 223 figure: it counted docblock mentions, and
for nldesign it happened to land on nothing. A number can be wrong in the
reassuring direction too.

No brute-force counters: a font id names a published asset and a liveness
probe takes nothing at all.

480/60 on the fonts -- the loosest ceilings in this sweep, deliberately.
Self-hosting these exists so a themed page loads without a third-party
request; a page pulls several at once, and a tight limit would break the
thing the app is for. 120/60 on health.

NOT verified locally: nldesign has no vendor/bin/phpunit in this environment.
Lint-clean only; CI is the first real run.
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ bce9662

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-14 15:53 UTC

Download the full PDF report from the workflow artifacts.

* ci: fast structural checks on every branch

* ci: close the branch-trigger gap
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e018d2a

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-14 18:14 UTC

Download the full PDF report from the workflow artifacts.

Conduction Release Bot and others added 2 commits August 15, 2026 09:51
Specifies the rename to `themiq` under the fleet's -iq product convention
(pipelinq, shillinq, scholiq, portaliq, hermiq). Spec only — no code moves in
this change.

The app manages corporate themes: token sets, per-app and per-group theming,
custom fonts, dark mode, theme preview, email theming — 32 capability specs.
Its name says "NL Design System", which is one of the token sets it ships, not
what it does.

Written down rather than done informally because the blast radius is not the
code. A Nextcloud app id is the directory under custom_apps, the appstore
identity, the oc_appconfig key prefix, the asset prefix on every addScript
call, and the l10n domain across 37 files. An installed instance therefore does
not get renamed — it gets a new app installed beside the old one, unless a
repair step moves the configuration across.

468 files outside this repo name the app id (measured 2026-08-15). Every one is
a caller that fails silently if missed: addScript for an id that no longer
exists is a 404 on the asset with no PHP error, so the page renders unstyled
and reads as a CSS bug.

Related: ADR-086 §6, which makes Portaliq depend on this app for corporate
themes and states that until this lands, "themiq" and "nldesign" denote the
same app.
The app pinned the exact prerelease 2.2.0-vue3.16, which is now deprecated:
the Vue 3 line was folded into the mainline 2.x release series and ships as
2.3.0 on the `latest` dist-tag. A caret range replaces the exact pin so
future 2.x releases roll out without a per-app edit.

Drops the `overrides.@conduction/nextcloud-vue.eslint` entry. That override
existed only because the old prerelease declared `eslint: ^8.56.0 || ^9.0.0`
and could not see the app's eslint 10; 2.3.0 declares `|| ^10.0.0` itself,
so the peer resolves without help.

No API change: 252 components in and 252 out, no export removed, one added
(the BSN validators). Peer ranges are otherwise identical.
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 6b0be31

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-15 20:05 UTC

Download the full PDF report from the workflow artifacts.

* chore(security): enable the npm supply-chain cooldown on npm 11

Sets `min-release-age=2` and `min-release-age-exclude[]=@conduction/*`, raises
`engines.npm` to ^11.0.0, and regenerates the lockfile under npm 11.

The .npmrc comment here has described a cooldown for months and it has never
been in effect. `min-release-age` does not exist in npm 10 — `npm config get
min-release-age` answers `undefined` — and every Node 22 release bundles npm
10, so the setting was read by nothing. Most repos also had it at 0, which
disables it outright.

@conduction/* is exempt because without the exemption the cooldown does not
fail loudly, it silently resolves backwards: measured 2026-08-15, an install of
@conduction/nextcloud-vue on release day picked 2.0.7 instead of 2.3.0 and
exited 0.

The lock is regenerated under npm 11 and iterated to a fixed point. Where the
tree changed rather than its metadata, that is npm 10 -> 11 reconciling a lock
shaped by the older resolver, not the cooldown — verified by regenerating with
the cooldown enabled and disabled and getting identical trees.

Verified: npm ci exit 0 under npm 11.19.0, @conduction/nextcloud-vue resolves
to 2.3.0, gate-84 conformance passes.

* ci: re-run against the merged shared workflow

`gh run rerun` replays the workflow version resolved when the run was created,
so a reusable workflow referenced as @main is NOT re-resolved — every re-run
after ConductionNL/.github#469 merged still executed Node 22 with npm 10.9.8,
where `min-release-age` does not exist and `npm ci` cannot read an npm-11
lockfile. Only a new run picks up the merged workflow. This empty commit is
that trigger.
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ fefc405

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-16 01:08 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e602cfa

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-16 09:11 UTC

Download the full PDF report from the workflow artifacts.

…349)

Adopts the canonical script from ConductionNL/.github (quality-config/coverage-guard.php).

The whole-project comparison fires on measurement noise. doriath#240 was a PR
whose entire diff was `webpack.config.js` — no PHP at all — and the guard failed
it: identical denominator (13723), both runs reporting exactly
`Tests: 948, Assertions: 3051, Skipped: 1`, and six covered statements of
run-to-run xdebug variance between them.

The measured `--against` floor cancels driver variance (xdebug vs pcov), as its
header says. It does not cancel run-to-run variance within one driver, and the
ratchet has no tolerance. Scoping the comparison to the PHP a change actually
touches keeps full strength where a regression matters and makes the noise
unreachable by construction — a diff with no PHP cannot fail.

New `changed-files` capability; the shared workflow PROBES for it rather than
assuming, so an un-updated copy keeps the previous behaviour instead of silently
accepting and ignoring the flag.

Script only — no behaviour change until the workflow passes `--changed-files`.
Byte-identical to the canonical copy (md5 5be122aad209da030c79b22a133232fb).

Co-authored-by: Conduction Release Bot <release-bot@conduction.nl>
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ a25bc40

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-16 11:08 UTC

Download the full PDF report from the workflow artifacts.

… proves them

gate-19 asks for browser proof of every scenario in the development-to-beta
delta. For a token/theming app most of that delta is not browser behaviour:
colour arithmetic, an occ command's file writes, a TimedJob's interval, and
outbound HTTP counted at the IClientService boundary.

Each exclusion here names the PHPUnit test that actually proves the scenario,
so the waiver is a pointer to the evidence rather than a way of not having
any. Verified with the gate's own checker (check_e2e_coverage.py --mode
report): 126 uncovered before, 103 after.

Deliberately NOT excluded, because they are real browser behaviour and should
get real tests:
  - upstream-freshness / Admin Notice Surface With Per-Version Dismissal (2)
  - dark-mode / Dark Scope Selectors (4) — auto theme following a dark OS,
    and not restyling a body carrying data-theme-light
…oves them

Same rule as the previous commit — a waiver must point at the evidence.

config-portability: bundle serialisation, all-or-nothing import and the occ
commands are document shape and CLI, not pages (ConfigBundleServiceTest,
ConfigBundleControllerTest).

theming-audit: entry content, JSONL rotation, per-controller call-site
coverage and endpoint response shape (ThemingAuditServiceTest,
AuditControllerTest and the four *ControllerAuditTest files).

email-theming: an email is never rendered in the browser session Playwright
drives (NLDesignEMailTemplateTest, EmailThemingServiceTest).

Measured with the gate's own checker: 103 uncovered before, 72 after.
…cenarios

docs(spec): gate-19 — exclude service-level scenarios, naming what proves them
v1.7.3's runner stops at gate-64, so gate-66 openregister-dependency-shape --
which this repo's Code Quality run reports on -- could not be executed from
the vendored copy. v1.8.0 also ships OCA\OpenRegister\Contract\ (the ADR-084
interfaces), which v1.7.3 does not carry at all.

Lock-only: the constraint is already ^1.0 and no other package moved.
chore(deps): raise hydra-gates to v1.8.0 so gates 65-84 exist locally
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 8f6d1c1

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-16 11:35 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 92a0afc

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-16 12:13 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 92a0afc

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-16 14:38 UTC

Download the full PDF report from the workflow artifacts.

Conduction Release Bot and others added 3 commits August 16, 2026 19:58
`css/tokens/vng.css` gains the 600 `--utrecht-*` and 254 `--tilburg-*`
component tokens for VNG, alongside the palette and `--nldesign-*` mappings it
already had.

WHY: THE BRIDGE HAD NOTHING TO READ

`systems/nldesign/utrecht-bridge.css` maps every Nextcloud-facing
`--nldesign-component-*` FROM an `--utrecht-*`:

    --nldesign-component-X: var(--utrecht-Y, <fallback from defaults.css>)

It defines none itself. Measured before this change, it consumed 88
`--utrecht-*` and this token set supplied ZERO of them — so all 88 resolved to
the Rijkshuisstijl-flavoured fallbacks, exactly the silent degradation the
bridge's own header warns about. A Nextcloud instance on VNG was VNG in palette
and Rijkshuisstijl in component styling, and nothing said so.

    bridge consumes --utrecht-*   88
    supplied by vng, before        0
    supplied by vng, after        74
    still on defaults             13   (badge, form-input, separator, table)

The 13 are listed rather than left to be discovered: they are a real gap in the
upstream VNG set, now visible instead of silently absorbed.

WHERE THESE CAME FROM, AND WHY THEY BELONG HERE

They were living in `portaliq/css/themes/vng.css`, vendored to style its public
portal. That made two derivations of one upstream source — this file's own
header records it was "manually converted from
tilburg-woo-ui/src/styles/nlds/_tokens-vng.scss", which is where those came
from too — maintained separately and already drifted. Measured, the two halves
had ZERO tokens in common: the portal was styled entirely by the copy, the
Nextcloud UI entirely by fallbacks, and neither knew about the other.

One set here styles both ends: the Nextcloud UI through the bridge, and a
public portal by reading `--utrecht-*` / `--tilburg-*` directly. portaliq now
ships no tokens of its own.

SCOPED `:root, .vng-theme`. `:root` is this app's convention and what a themed
instance needs; `.vng-theme` is what a host applying the theme to one element
tree needs, because a portal renderer serving several portals cannot theme the
document. One block, both hosts.

ON `--tilburg-*`: it is the reference implementation's internal component
naming and its stylesheet reads 244 of them. Renaming would be a data migration
across every consumer, so they are carried as vendor detail rather than
something this app invented.
`TokenCssShapeTest` rejected the first shape, and it was right to. The tokens
went in as a SECOND `:root` block, then as `:root, .vng-theme`; both break a
contract this app already depends on.

A shared applier in `nextcloud-vue` scopes a token set by rewriting `:root` to
`[data-nldesign-theme-scope="<id>"]` — a pure selector-prefix substitution. A
second selector in the block, or a second block, silently defeats that rewrite
and the scoped theme quietly stops being scoped.

So scoped application already exists here and is engineered; the bespoke class
would have been a weaker mechanism sitting beside it. The declarations now live
inside the single existing `:root` block.

Verified: one selector block, zero at-rules, 600 `--utrecht-*` / 254
`--tilburg-*` / 109 `--conduction-*` present, and the portal renders
identically — 11 of 11 measured properties against the reference, checked in a
browser and looked at.
feat(tokens): VNG carries its NL Design System component tokens
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 0fcc295

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-16 20:04 UTC

Download the full PDF report from the workflow artifacts.

… generator version (#353)

A portal's dark variant was measured on a live page and changed 0 of
1,152,000 pixels. Three defects, each of which reads as a working run:

ALIASES WERE NEVER DARKENED. `--utrecht-document-color:
var(--tilburg-color-black-txt)` is declared on `:root`, so the browser
substitutes it AT `:root` with the light value. The generated block scopes
to `body`, a descendant, so darkening the target there cannot reach an
alias already resolved one level up. Only literal declarations survived —
13 of the 600 `--utrecht-*` tokens in the VNG set. Aliases are now
flattened to literals at generation time, with a bounded hop count and
browser-compatible `var(--x, fallback)` handling.

TEXT WAS CLASSIFIED AS SURFACE. Text-class detection looked for the word
"text", which the `--nldesign-*` family uses and the utrecht and municipal
families do not: there, `-background-color` is the surface and the bare
`-color` is the glyphs on it. Every heading and body-copy token was
therefore darkened towards black exactly like the surface behind it.

THE VERSION STAMP WAS READ BY NOTHING. `GENERATOR_VERSION` was written
into every header and `isFresh()` compared only the source hash, so an
algorithm fix arriving at an installation whose token files had not
changed found all 41 sets "fresh" and regenerated none of them — the
artefacts left on disk being exactly the ones the fix was written to
replace. Freshness now requires both.

Verified by running the new tests against the unfixed service: 5 of them
fail there and pass here. Regenerating produced 41 written on the first
run and 0 on the second, so the version check invalidates without looping.

Artefacts regenerated; `cunningham` gains the variant it never had.

Co-authored-by: Conduction Release Bot <release-bot@conduction.nl>
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 2d2b431

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-16 21:42 UTC

Download the full PDF report from the workflow artifacts.

…354)

The shared Code Quality workflow maps `phpcs` exit 1 to success, so these
have been shipping unnoticed on `development`. Errors 17 -> 0; the raw
`phpcs` exit code goes 1 -> 0.

- 13x Generic.Files.LineLength (>150). Twelve are `@return` description
  continuation lines indented to the width of a long array-shape type;
  re-indented to a fixed 9-space continuation, no wording changed. The
  thirteenth wraps a string concatenation in
  ComplianceReportService::renderMarkdown() across three lines - the
  token sequence, and so the emitted string, is unchanged.
- 3x PEAR.Commenting.FunctionComment.WrongStyle on
  HealthController::index(), FontController::serve() and ::css(). A `//`
  prose block sat between the real docblock and the `#[AnonRateLimit]`
  attribute, which made it "the function comment". The prose is folded
  into the docblock verbatim, not deleted.
- 1x Generic.Commenting.DocComment.LongNotCapital: "v2 resolves..." ->
  "Version 2 resolves...".

Side effect, measured rather than assumed: three
CustomSniffs.Commenting.SpecTag.MissingMethodSpec warnings disappear.
They were false - all three methods always carried `@spec` tags, and the
stray `//` block was hiding them from the sniff. Warnings 3 -> 0, with
zero NEW warnings (diffed by file+source against `development`).

No behaviour change. lint, phpmd (both rulesets), psalm and phpstan
produce identical output before and after. PHPUnit run against the
server's lib/private is 592 tests / 4568 assertions / 4 errors on both
sides with an identical failing-test-name set; those 4 are a pre-existing
`Symfony\Component\HttpFoundation\HeaderUtils` absence in the runner, not
introduced here.
@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 50db4f3

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
composer ✅ 104/104
npm ✅ 2/2
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-17 04:26 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants