Prefer the adaptive SVG favicon so browsers can switch colors in dark mode. Exclude package sources from the app TypeScript project so production builds do not type-check standalone package code.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The OIDC and OAuth test files (added in #1056) inspect the dynamic
NextAuth provider object and use `any` for ergonomic property access.
That trips @typescript-eslint/no-explicit-any (error level), which has
been failing CI on main since 2026-05-02.
Add a file-level eslint-disable for that rule in both test files.
This is the standard pattern for tests that poke runtime-shaped
objects, and keeps the rule strict everywhere else.
Local: npm run lint -> 0 errors, npm test -> 709/709 passing.
Co-authored-by: Cursor <cursoragent@cursor.com>
- Add JohnPhamous as a core contributor for performance work (Vercel)
- Introduce a new Security section between Core Contributors and Ideation
- Credit Mehmet Ince (@mdisec) for security fixes
- Add securityTitle translation across all 17 supported locales
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat(home): replace industries grid with Open Source Friday video
Replaces the rotating industries section under the hero search bar with
an embed of the GitHub Open Source Friday episode (starting at 6:12).
Also widens the hero's right column and tightens the left text column
so the video sits comfortably without overflowing on standard laptop
viewports.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chore(i18n): remove unused heroIndustries keys
The industries grid was replaced by a YouTube embed; only
'searchPlaceholder' is still referenced. Drop the prefix,
clickToExplore, and 36 industry labels across all 17 locales.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* fix(home): i18n iframe title, lazy load, nocookie, width parity
Addresses PR review feedback on the YouTube embed:
- Translate iframe title via next-intl (new heroIndustries.videoTitle key)
- Add loading="lazy" to defer ~1MB of player JS
- Switch embed to youtube-nocookie.com for better cookie/privacy hygiene
- Restore max-w-lg so the video matches the search bar width
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chore: stop tracking local .env.docker
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This page has no auth() dependency and gets high traffic with
0% cache hit rate. ISR with 60s revalidation serves most
requests from cache while keeping content fresh.
- Remove content field from prompts/list DB query (was fetching
2-10KB per prompt just to extract variables, never returned)
- Drop arguments from prompts/list response (optional per spec,
clients get variables when they call GetPrompt)
- Replace 500-row slug fallback scan with indexed title query
- Reduce search_prompts contentPreview from 1000 to 300 chars
- Add in-memory auth cache (5-min TTL) for warm function instances
The MCP Streamable HTTP spec requires servers to return either
text/event-stream (SSE) or 405 on GET requests. The previous
200 application/json response violated the spec and caused MCP
clients to enter SSE reconnection loops.
This server is stateless (no sessions, listChanged: false) and
never pushes notifications. Returning 405 tells clients no SSE
support and they stop retrying.
Ref: https://modelcontextprotocol.io/specification/2025-03-26/basic/transports
The ??= operator already guarantees that `ez` is non-null by the time
it is assigned, so the subsequent non-null assertions (!.) on `ez.cmd`
are redundant and can be safely removed.
Before:
ez!.cmd = ez!.cmd || [];
ez!.cmd.push(fn);
After:
ez.cmd = ez.cmd || [];
ez.cmd.push(fn);