Files
cloud-ip-validator/internal/dashboard/static/vendor/VENDOR.md
T

41 lines
2.3 KiB
Markdown
Raw Normal View History

2026-08-23 20:39:22 +03:00
# Vendored frontend assets
Downloaded once and committed as-is — the dashboard binary must work fully
offline, with no runtime CDN dependency (see `docs/PLAN_ADMIN_DASHBOARD.md`).
Do not "update" these files casually; bump deliberately, in their own
commit, if a newer version is actually needed.
| File | Source | Version | Fetched |
|---|---|---|---|
| `htmx.min.js` | https://unpkg.com/htmx.org@2.0.10/dist/htmx.min.js | 2.0.10 | 2026-08-23 |
| `alpine.min.js` | https://unpkg.com/alpinejs@3.16.2/dist/cdn.min.js | 3.16.2 | 2026-08-23 |
2026-08-23 21:58:19 +03:00
| `fonts.css` + `fonts/*.woff2` | Google Fonts CSS2 API (`family=Manrope:wght@500;600;700;800\|family=IBM+Plex+Mono:wght@400;500`) | Manrope v20, IBM Plex Mono v20 | 2026-08-23 |
2026-08-23 20:39:22 +03:00
2026-08-23 21:58:19 +03:00
## Fonts
2026-08-23 21:15:31 +03:00
2026-08-23 21:58:19 +03:00
The dashboard's design system (`../dashboard.css`) uses **Manrope**
(UI chrome/headings — a variable font, so one file per subset covers all
four vendored weights) and **IBM Plex Mono** (tabular data: IP addresses,
timestamps, ports — one file per weight per subset). Only the `latin`,
`latin-ext`, `cyrillic`, and `cyrillic-ext` subsets are vendored (the UI
is Russian/English only) — `greek` and `vietnamese` from the upstream CSS
were dropped. `fonts.css` was hand-rewritten from the fetched Google Fonts
CSS to point at the local `fonts/*.woff2` files instead of
`fonts.gstatic.com`, keeping the original `unicode-range` subsetting so
browsers still only fetch the subset(s) actually used.
2026-08-23 21:15:31 +03:00
2026-08-23 21:58:19 +03:00
No CSS framework is vendored: the design system in `dashboard.css` is
hand-written (sidebar shell, panels, tables, pills, forms, buttons,
alerts) rather than built on Bootstrap/Pico/etc — see
`docs/PLAN_ADMIN_DASHBOARD.md` for why (a framework's default look kept
fighting the "modern, compact, rounded" brief; a small hand-rolled system
gave full control for less code than fighting one).
Only htmx's and Alpine's CSS-adjacent-nothing JS is vendored — no
`bootstrap.bundle.min.js`/Popper equivalent is needed since the dashboard
doesn't use any component that requires JS beyond htmx/Alpine themselves
(the mobile sidebar toggle is a pure-CSS checkbox trick, not JS;
confirmations use the browser's native dialog via htmx's `hx-confirm`).
Licenses: htmx (BSD 2-Clause), Alpine.js (MIT), Manrope (OFL-1.1), IBM Plex
Mono (OFL-1.1) — all permit vendoring/redistribution unmodified.