bread-ecosystem/registry/bread-ecosystem.toml
Breadway 394a252f9e Fix audit findings: bakery index signing, artifact checksums, stale theme docs
- Add minisign-based signing/verification for the bakery index:
  scripts/gen-index.sh signs index.json (MINISIGN_SEC_KEY env var, dormant
  no-op with a loud warning until a key is provisioned); bakery/src/manifest.rs
  fetches index.json.minisig and verifies it with minisign-verify against a
  hardcoded PUBKEY before parsing/caching, and re-verifies the cached copy
  on every load (falls back to one re-fetch if the cache predates signing
  or fails verification; a fresh fetch that fails verification is a hard
  error).
- Close the previously-unchecksummed config-example and systemd-unit
  downloads in bakery/src/install.rs (scaffold_config, install_service):
  index.json now carries `sha256`/`example_sha256` for these artifacts
  (computed in gen-index.sh), verified via the same download::verify_sha256
  used for binaries. Downloads without a matching sha256 in the index are
  refused rather than installed unverified.
- scripts/get.sh now verifies the bakery release binary itself against a
  pinned minisign public key before installing it (falls back to the
  existing sha256-only check with a loud warning if no .minisig is
  published yet or minisign isn't installed; a present-but-invalid
  signature is a hard failure).
- Add dormant "sign release binary" steps to the bakery and bread-theme
  release workflows (.github/workflows/release.yml,
  .forgejo/workflows/release-bread-theme.yml), gated on secrets that are
  not yet configured — binaries ship unsigned exactly as before until the
  owner wires up the secret.
- .gitignore: add *.minisign-sec / minisign.key so the signing key can
  never be committed by accident.
- bread-theme: fix stale docs describing a "Catppuccin Mocha fallback"
  (BREAD_DESIGN_SYSTEM.md, README.md, Cargo.toml/bakery.toml/registry
  descriptions) — the actual implementation (palette.rs) uses a fixed BOS
  dark base with only accent colors from pywal.
- bread-theme: fix the legacy css_vars() path, which had its own
  hand-written @define-color block that predated the `accent` and computed
  `on-*` ink colors used by the rest of the stylesheet — any caller whose
  CSS referenced those names against css_vars()'s output would hit
  undefined colors (the illegible-text bug). css_vars() now delegates to
  the same define_colors() the full stylesheet uses, so the two can't
  drift apart again.
2026-07-17 03:37:51 +08:00

68 lines
1.8 KiB
TOML

# Human-authored product registry.
# gen-index.sh reads this + each product's bakery.toml to produce index.json.
[ecosystem]
name = "bread"
description = "Reactive desktop automation ecosystem for Arch Linux / Hyprland"
homepage = "https://breadway.dev"
dl_base = "https://dl.breadway.dev"
[[products]]
name = "bakery"
repo = "Breadway/bread-ecosystem"
description = "Bread ecosystem package manager"
[[products]]
name = "bread-theme"
repo = "Breadway/bread-ecosystem"
description = "Shared pywal-accented, fixed-dark-base theming CLI for the bread ecosystem"
[[products]]
name = "bread"
repo = "Breadway/bread"
description = "Reactive automation daemon and CLI for Linux desktops"
[[products]]
name = "breadbar"
repo = "Breadway/breadbar"
description = "Minimal status bar and notification daemon for Hyprland"
[[products]]
name = "breadbox"
repo = "Breadway/breadbox"
description = "App launcher for Hyprland / Wayland"
[[products]]
name = "breadcrumbs"
repo = "Breadway/breadcrumbs"
description = "Profile-aware Wi-Fi state machine with Tailscale integration"
[[products]]
name = "breadpad"
repo = "Breadway/breadpad"
description = "Quick-capture scratchpad and note viewer with AI classification"
[[products]]
name = "breadpaper"
repo = "Breadway/breadpaper"
description = "Wallpaper manager for the bread desktop"
[[products]]
name = "breadmon"
repo = "Breadway/breadmon"
description = "Terminal UI monitor manager for Hyprland"
[[products]]
name = "breadsearch"
repo = "Breadway/breadsearch"
description = "Semantic system-wide search for BOS"
[[products]]
name = "breadclip"
repo = "Breadway/breadclip"
description = "Wayland clipboard history manager for Hyprland"
[[products]]
name = "breadshot"
repo = "Breadway/breadshot"
description = "Screenshot utility for the bread ecosystem"