Skip to main content

Changelog

Release history for @gentleduck/variants. Newest releases at the top.

1.0.0

Major Changes

  • 95638de: Audit-driven refactor across all 15 public packages. Closes type holes, hardens security boundaries, eliminates dead code, and dedups duplicated patterns.

    Highlights

  • duck-docs — CompiledMdxBody branded type gates new Function(body); sanitizeSvg covers SMIL, unquoted javascript: URIs, nested script, CSS url(), bare iframe; code-preview tag + attr allowlists

  • duck-registry-build — safe-path containment at every fs sink; per-phase Zod cache schemas; JSON.stringify in generated TSX; cache manifest rejection on tamper

  • duck-cli — install pipeline path containment unified across add/init/update; env-var allowlist contract reconciled with one-time warning; aliases.ui regex validation

  • duck-primitivesobserve-element-rect rAF loop guard (no leak when empty); compose-ref useCallback memo fix; popper forwardRef restored for R18 peer compat

  • duck-hooksuseDebounce is now a real hook (stable identity, unmount cleanup); useStableId delegates to React.useId (SSR-safe); scheduleTransitionTimeout rename strips two useHookAtTopLevel lint suppressions

  • duck-lazy — spread order fix restores the lazy swap; next/image moved behind /lazy-image-next subpath so non-Next consumers don't pull the peer

  • duck-vim — single document listener fans out to chord matcher + sequence manager; canonical modifier order; requireReset auto-clears for chord bindings; all three hook dep arrays corrected

  • duck-variantsProps<T, D> makes defaulted variant keys optional and non-defaulted required; bounded preludeCache LRU; second-layer filter2 set eliminates last clone in hot path

  • duck-ttestpredictates/ renamed to predicates/, twin dirs deleted, type-utility duplicates reconciled to canonical sources, IsVoid actually distinguishes void from undefined now

  • duck-calendar./* wildcard export removed; falsy-zero weekStartDay: 0 (Sunday) bug fixed; Gregorian helpers extracted; Hebrew addMonths uses Metonic cycle

  • duck-libscnMemo bounded LRU; filteredObject rejects typo keys at compile time; parseDate rejects ambiguous one-token inputs

  • duck-query — single AnyReq boundary cast replaces 14 as any; param regex escape; throws on unresolved :tokens

  • registers — schema tightened (z.any() removed); ~1000 LoC of identical block-registry boilerplate replaced with builders

  • registry-ui_audio / _upload (~1.1K LoC) deleted; motion-shell HOC + withMotion collapses simple motion clones; toDirection() narrower replaces 52 as IDirection.Kind casts; chart CSS_NAMED_COLORS finite allowlist

  • duck-motion — refcounted body pointer-events ownership; easing/blur/duration token dedup; half of public exports were unused and removed

Tests: 3133+ across the monorepo, all green. Type-checks clean across every project. No commits skipped hooks.

0.1.24

Patch Changes

  • 95dbbce: Standardize README headers across all packages: centered logo, h1, tagline, nav links, and npm badges (matching the @duck-md template). Replace per-repo *.gentleduck.org subdomain refs with path-based gentleduck.org/duck-<name> URLs. No runtime code changes.

0.1.23

Patch Changes

  • 918b34c: Strip workspace:* and catalog: protocol tokens from devDependencies/dependencies/peerDependencies of every public package before changeset publish. Previously published artifacts leaked these tokens into npm metadata, which broke strict resolvers (bun, deno) for downstream consumers. Adds scripts/clean-publish.ts and wires it into the root release script with a git checkout restore step so source remains workspace-friendly.

0.1.22

Patch Changes

  • 7d6fb7b: Align tsconfig shared configs, fix TS strict mode errors (exactOptionalPropertyTypes, verbatimModuleSyntax), align package.json deps to catalog refs, apply biome lint fixes.

0.1.21

Patch Changes

  • 6f0e067: Standardize package exports to use explicit named exports, add sideEffects field and types export entries to package.json, and annotate internal APIs with @internal JSDoc tags.

0.1.20

Patch Changes

  • 2b6e8d0: Resolve all biome lint warnings, improve type safety, and add test coverage across the monorepo.

0.1.19

Patch Changes

  • 7c2aa88: Update dependencies and publish unpublished packages

0.1.18

Patch Changes

  • c9bbef8: Documentation and style updates.

0.1.17

Patch Changes

  • ad86755: Align biome and tsconfig build info exclusions. Rebrand package metadata to gentleduck/duck-ui.

0.1.16

Patch Changes

  • Fix TypeScript type inference for variant compound conditions. Correct GitHub URLs from gentleeduck/ui to gentleeduck/gentleduck. Normalize package metadata.