Source for hivecommons.dev (GitHub Pages). Static site: index.html, style.css, and
assets/ — no build step.
Custom domain is pinned via CNAME. llms.txt carries a short machine-readable summary
for LLM crawlers (its integration and sponsor lists are gated against index.html by
scripts/llms-txt.test.mjs), and sitemap.xml lists the canonical top-level pages (not every
shortcut redirect) for robots.txt's Sitemap: entry — when adding a new top-level
page, add it to sitemap.xml too.
Short paths like /docs, /code, /discord are meta-refresh redirect pages. All of them
are generated by make-redirects.sh: edit the MAP at the top of the script, run
./make-redirects.sh, then commit the regenerated index.html files — don't hand-edit
them, since a future run of the script will silently overwrite any hand edit.
scripts/check-redirects.sh enforces this: it regenerates the pages into a scratch
directory and fails if any committed redirect page is missing from MAP, any MAP
entry has no committed page, or a committed page differs from what the script emits.
The Link check workflow (.github/workflows/links.yml) runs its links, test and
redirects jobs on every pull request and on every push to main, so commits pushed
straight to main are checked too and main carries a same-named baseline to compare a
red PR job against.
scripts/check-links.sh [--external-warn]— resolves every internal link/anchor and probes external URLs (CI runs it with--external-warnon PRs and pushes; the weekly scheduled run and manual dispatch hard-fail on broken external links).scripts/check-links.test.sh— fixture-based self-test of the link checker; runs offline (fakecurl).node --test scripts/story-dialog.test.mjs— runs the Share-your-story dialog script fromstories/index.htmlagainst a stub DOM and checks the prefilled-issue URL, validation, 1500-char trim, and popup-blocked fallback. Zero dependencies.node --test scripts/acmm-levels.test.mjs— runs the ACMM levels tablist script fromindex.htmlagainst a stub DOM with deterministic timers and checks tab activation, roving tabindex, arrow/Home/End keys, auto-rotation, and every pause condition (hover, focus, hidden tab, reduced motion, out of view). Zero dependencies.node --test scripts/carousels.test.mjs— runs the hero carousel and projects carousel scripts fromindex.htmlagainst a stub DOM with deterministic timers and checks dot generation, slide/aria-currentstate, live-region announcements, keyboard/swipe/hash navigation, auto-rotate and every pause condition, hero height measurement (clones, resize debounce), and projects scroll-sync (debounced scroll,scrollend, IntersectionObserver). Zero dependencies.node --test scripts/page-scripts.test.mjs— static gate over every committed HTML page: each inline<script>parses, each JSON-LD block is valid schema.org JSON, no external<script src>is introduced, andsitemap.xmllists exactly the canonical top-level pages (redirect shortcuts excluded, new pages required). Zero dependencies.node --test scripts/page-markup.test.mjs— static markup gate over every committed non-redirect HTML page:ids are unique, every ARIA idref (aria-controls,aria-labelledby,aria-describedby, …) andlabel forresolves to anidon the page, every<img>hasalt,<html>declareslang,role="tab"/"tabpanel"carry their ARIA pair, and every[data-*]selector an inline script queries exists in the markup (so a dropped attribute cannot make a carousel silently no-op). Each rule has a fixture self-test. Zero dependencies.node --test scripts/style-contract.test.mjs— static gate overstyle.css(every local stylesheet the pages link) and the pages' inline<style>blocks: comments, strings, braces and parens balance and every declaration isname: value; everyvar(--x)without a fallback names a custom property defined somewhere (stylesheet, inlinestyle=, or a scriptsetProperty); every[data-*]selector in CSS matches an element on some page; every class an inline script adds/toggles is styled by a rule (or read back by the script); every custom property a script sets (--hero-h) is read by CSS; every localurl()(self-hosted@font-facefiles, images) names a committed file whose magic bytes match itsformat()hint or extension; and every font file underassets/fonts/is referenced by someurl(). Each rule has a fixture self-test. Zero dependencies.node --test scripts/page-images.test.mjs— static gate over every local image the pages embed (<img src>/srcset, icon andpreload as="image"<link>s,og:image): each is a committed, non-empty file whose magic bytes match its extension (a PNG re-exported as SVG under the old.pngname fails); every<img>withwidth/heightdeclares the file's intrinsic aspect ratio (PNG IHDR, JPEG SOF, GIF header, SVGviewBox) and is not drawn larger than a raster's pixels; every<img>SVG has a rootviewBox; and every image file underassets/is referenced by some page or stylesheeturl(). Each rule has a fixture self-test. Zero dependencies.node --test scripts/page-meta.test.mjs— static gate over every page's<head>and the Markdown/llms.txtdocuments: each canonical page has exactly one<title>, a description,charset/viewport, acanonicalthat matches the path the page is served at,og:urlequal to it, the full Open Graph + Twitter card set withog:*/twitter:*pairs in agreement, no duplicated meta, nonoindex;og:imageis a committed file whose PNG header matches any declaredog:image:width/height; each redirect page isnoindexwith acanonicalequal to its refresh target; and every relative Markdown link andhivecommons.devURL inREADME.md,runbooks/*.mdandllms.txtresolves to a committed file. Each rule has a fixture self-test. Zero dependencies.node --test scripts/page-404.test.mjs— static gate over the custom error page, whichpage-meta.test.mjsdeliberately skips. GitHub Pages serves/404.htmlfor every unknown path at any depth, so the page must live at the repository root and nowhere else, keep exactly onenoindexrobots meta, carry nocanonical/og:*/twitter:*identity and no meta-refresh, use only root-absolute or externalhref/src(a relativestyle.cssbreaks under/some/deep/path), link back to/, resolve every root-absolute reference to a committed file, and keep body text thatscripts/check-links.sh'sSOFT_404_REmatches (so a misrouted URL serving the page with HTTP 200 is still flagged); no other page may match that regex. Each rule has a fixture self-test. Zero dependencies.node --test scripts/story-cards.test.mjs— static gate over every<article class="story-card">instories/index.html, which are hand-copied per PR: the avatarsrc, itsalt, the handle linkhrefand its text all name the same GitHub handle; the avatar keepsloading="lazy",referrerpolicy="no-referrer", width/height and theonerrorhide; exactly one<h3>; at least one<a class="inline-link">pointing at a GitHub pull/issue/commit; every link in the card ishttps://github.com/…(the page promises public GitHub evidence only); everyMonth D, YYYYis a real date; no handle has two cards. Each rule has a fixture self-test. Zero dependencies.node --test scripts/page-csp.test.mjs— static gate over the<meta http-equiv="Content-Security-Policy">on every non-redirect page. GitHub Pages cannot send response headers, so the policy ships as a<meta>tag and inline scripts are allow-listed bysha256-hash: the test recomputes the hash of every inline<script>body andon*=handler and fails when the policy is missing one or carries a stale one (a drifted hash silently disables that script in every browser — after editing any inline script, update its hash in the page's CSP meta). It also requiresdefault-src 'none', rejects'unsafe-inline'/'unsafe-eval'inscript-src, requires the meta to precede every<script>/<link>in<head>, and requires every external<img>origin to appear inimg-src. Each rule has a fixture self-test. Zero dependencies.node --test scripts/llms-txt.test.mjs— static gate keepingllms.txtin step withindex.html: the agent CLIs it names must equal the Agent CLIs chips, the inference engines/gateways it names must equal the engine and gateway chips (classifier chips excluded), and its infrastructure thanks must equal the infra-thanks logo labels — in both directions, so adding, renaming or dropping a chip without updatingllms.txtfails CI. Also requires the "See all integrations" docs URL to appear inllms.txt. Each rule has a fixture self-test. Zero dependencies.node --test scripts/availability-probes.test.mjs— static gate over the URL list the scheduledavailabilityjob inlinks.ymlprobes: every probed URL ishttps, underhivecommons.dev, carries its trailing slash when it is a directory page (GitHub Pages answers301for/docs, whichcurlwithout-Lreports as a failure) and resolves to a committed page; every canonical page insitemap.xmland/404.htmlis probed; at least one redirect shortcut is probed; no duplicates. Fixing a failure means editing the workflow's probe list. Each rule has a fixture self-test. Zero dependencies.node --test scripts/site-origin.test.mjs— static gate tying the site origin toCNAME, the one file GitHub Pages actually reads for the host:CNAMEmust be a single bare lowercase DNS host (no scheme, path, port, trailing dot, second line or CRLF); everySITE_ORIGINconstant the other gates hardcode, everysitemap.xml<loc>, therobots.txtSitemap:URL and every canonical page's<link rel="canonical">/og:urlmust be athttps://<CNAME>; and no committed page, stylesheet or text asset may link thehivecommons.github.iofallback host (which bypasses the custom domain). Each rule has a fixture self-test. Zero dependencies.scripts/check-redirects.sh— redirect-page drift gate described above.scripts/check-redirects.test.sh— fixture-based self-test of the drift gate; runs offline against throwaway sites with a two-entry generator.
The Link check workflow runs every Monday at 09:17 UTC and can also be run
manually from the Actions tab. On those runs, its separate availability job
requests the live homepage, /stories/, a sample of the shortcut redirects and
/404.html over HTTPS and fails unless every one returns HTTP 200 (the list is
kept in step with the committed pages by scripts/availability-probes.test.mjs).
Connection/TLS errors and timeouts also fail the job. Requests
have bounded retries for transient failures. PR and push-to-main runs only check
the checkout; they do not probe the production site.
Review failed runs in Actions and configure GitHub Actions notifications for the
workflow if you operate the site. See the rollback runbook
for investigation and recovery. This weekly probe is a basic availability signal,
not continuous uptime monitoring or a check after every deployment. External link
failures remain warnings in the separate links job.
Traffic analytics and shortcut usage tracking are not configured. Adding them requires an operator to choose a backend/property and settle privacy and consent requirements first (see issue #73).
Hive Commons website contributors are expected to follow the CNCF Code of Conduct.