Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -7,9 +7,9 @@
/SECURITY.md @Codewriter90x
/LICENSING.md @Codewriter90x
/FUNDING.md @Codewriter90x
/.github/FUNDING.yml.example @Codewriter90x
/.github/workflows/pages.yml.example @Codewriter90x
/.github/workflows/source-release.yml.example @Codewriter90x
/.github/FUNDING.yml @Codewriter90x
/.github/workflows/pages.yml @Codewriter90x
/.github/workflows/source-release.yml @Codewriter90x
/GOVERNANCE.md @Codewriter90x
/PUBLICATION_STATUS @Codewriter90x
/docs/legal/ @Codewriter90x
Expand Down
9 changes: 9 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -64,3 +64,12 @@ jobs:
persist-credentials: false
- run: bash tests/scripts/macos-signing-foundation-tests.sh
- run: bash tests/scripts/windows-packaging-contract-tests.sh

native-coremidi:
runs-on: macos-15
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- name: Build and test the macOS arm64 CoreMIDI plug-in
run: ./scripts/build-coremidi-plugin-macos-arm64.sh
9 changes: 5 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -259,10 +259,11 @@ for schema, timing boundaries, validation rules, and test instructions.
`GameplayPrototype` now turns the chart, DSP clock, and deterministic matcher
into a complete rhythm-game highway. Eight readable targets cover Hi-Hat,
Snare, two rack toms, Floor Tom, Crash, Ride, and a separate full-width
Kick / Grancassa track. The same live gameplay can be viewed as Arcade Neon,
Concert Stage, or Precision Grid; use the on-screen selector or keys `1`–`3`
without restarting the song. All three directions are original HitTheKit art
and UI, not copied assets from another rhythm game. See the
Kick / Grancassa track. The same gameplay is available as Arcade Neon,
Concert Stage, or Precision Grid. Choose the theme under **Settings** before
starting a session; gameplay does not bind the `1`–`3` keys to presentation
changes. All three directions are original HitTheKit art and UI, not copied
assets from another rhythm game. See the
[gameplay highway design](docs/design/gameplay-highway-themes.md).

The playable vertical slice now includes a countdown, keyboard and CoreMIDI
Expand Down
6 changes: 3 additions & 3 deletions SUPPORT.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,9 @@ support contract.
- **Commercial licensing:** the route is not active until legal review and a
dedicated private contact are complete; see [LICENSING.md](LICENSING.md).

General troubleshooting discussions will be enabled when the clean public
repository is launched. Until then, use only the structured issue forms that
match the categories above.
Use GitHub Discussions for general troubleshooting and community questions.
Use the structured issue forms for reproducible bugs, hardware evidence, and
proposals so that actionable reports retain the information needed for review.

## Supported versions

Expand Down
10 changes: 6 additions & 4 deletions THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,11 @@ provenance is recorded separately in
| Unity Test Framework | 1.7.0 | Unity Companion License v1.4 | EditMode and PlayMode testing | Package source is resolved by Unity Package Manager, not tracked or intended for player distribution | Preserve the package license and copyright notice if substantial package portions are redistributed. |
| Unity Custom NUnit (`com.unity.ext.nunit`) | 2.1.0, based on NUnit 3.5 | Unity Package Distribution License v2.1; bundled NUnit portions under MIT | Transitive Unity test dependency | Resolved by Unity Package Manager, not tracked or intended for player distribution | Preserve Unity package terms and the bundled NUnit MIT notice when applicable. |
| .NET SDK | 8.0.411 requested by `global.json` | MIT plus the distribution's third-party notices | Build tooling | No | Build tool only; follow the license and notices of the installed distribution. |
| Microsoft.NET.Test.Sdk | 17.11.1 | MIT | Core and MIDI-tool test tooling | NuGet package is restored, not tracked; not a runtime dependency | Preserve MIT notices if redistributed. |
| xUnit.net / Visual Studio runner | xUnit 2.9.2; runner 2.8.2 | Apache License 2.0 / MIT as declared by the packages | Core and MIDI-tool test tooling | NuGet packages are restored, not tracked; not runtime dependencies | Preserve the applicable notices if redistributed. |
| Microsoft.NET.Test.Sdk | 18.9.0 | MIT | Core and MIDI-tool test tooling | NuGet package is restored, not tracked; not a runtime dependency | Preserve MIT notices if redistributed. |
| xUnit.net / Visual Studio runner | xUnit 2.9.3; runner 4.0.0 | Apache License 2.0 / MIT as declared by the packages | Core and MIDI-tool test tooling | NuGet packages are restored, not tracked; not runtime dependencies | Preserve the applicable notices if redistributed. |
| Melanchall.DryWetMidi | 8.0.3 | MIT | MIDI-file parsing in the standalone `HitTheKit.MidiCapture` developer tool | Present on `main` as a restored NuGet dependency of the tool; it is not linked into the Unity runtime | Preserve the MIT notice and audit the exact packaged dependency set before distributing the tool. A HitTheKit commercial license does not relicense DryWetMIDI. |
| Universal Render Pipeline and rendering packages | URP/Core/Shader Graph/URP Config 17.5.0; Searcher 4.9.4 | Package-specific Unity license files and Unity Package Manager terms | Unity rendering and shader authoring | Resolved by Unity Package Manager; package source is not tracked | Preserve the license and notice shipped with each exact resolved package when redistribution makes it applicable. |
| Unity resolved support packages | Burst 1.8.29; Collections 6.5.0; Mathematics 1.4.0; Performance Testing 3.5.0; Mono.Cecil 1.11.6 | Package-specific license files; Mono.Cecil is MIT | Transitive compilation, collections, mathematics, testing and assembly-inspection support | Resolved by Unity Package Manager; package source is not tracked | Regenerate this list from `Packages/packages-lock.json` for a release candidate and preserve every applicable package notice. |
| GitHub Unity `.gitignore` template | upstream `github/gitignore` template, revision not recorded | CC0-1.0 | Repository ignore rules | The adapted text is tracked in `.gitignore` | No attribution required by CC0; provenance is retained in the file header and this inventory. |

## Verified sources
Expand All @@ -26,9 +28,9 @@ provenance is recorded separately in
<https://unity.com/legal/licenses/unity-package-distribution-license>
- Microsoft .NET SDK: <https://github.com/dotnet/sdk>
- Microsoft test platform: <https://github.com/microsoft/vstest>
- xUnit.net: <https://www.nuget.org/packages/xunit/2.9.2>
- xUnit.net: <https://www.nuget.org/packages/xunit/2.9.3>
- xUnit.net Visual Studio runner:
<https://www.nuget.org/packages/xunit.runner.visualstudio/2.8.2>
<https://www.nuget.org/packages/xunit.runner.visualstudio/4.0.0>
- DryWetMIDI 8.0.3:
<https://www.nuget.org/packages/Melanchall.DryWetMidi/8.0.3>
- GitHub gitignore templates: <https://github.com/github/gitignore>
Expand Down
4 changes: 2 additions & 2 deletions docs/launch-kit/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,9 +16,9 @@ brand asset.

| Format | Asset | Recommended use |
| --- | --- | --- |
| Landscape, 1200 × 628 | [`website/assets/images/hitthekit-social-preview.jpg`](../../website/assets/images/hitthekit-social-preview.jpg) | LinkedIn link preview, repository and website sharing |
| Landscape, 1280 × 640 | [`website/assets/images/hitthekit-social-preview.jpg`](../../website/assets/images/hitthekit-social-preview.jpg) | LinkedIn link preview, repository and website sharing |
| Square, 1254 × 1254 | [`website/assets/images/hitthekit-launch-square.png`](../../website/assets/images/hitthekit-launch-square.png) | LinkedIn image post, community post, profile update |
| Wide hero, 1600 × 800 | [`website/assets/images/hitthekit-readme-hero.jpg`](../../website/assets/images/hitthekit-readme-hero.jpg) | Long-form post, README, project introduction |
| Wide hero, 1600 × 686 | [`website/assets/images/hitthekit-readme-hero.jpg`](../../website/assets/images/hitthekit-readme-hero.jpg) | Long-form post, README, project introduction |

The square image was generated specifically for HitTheKit from project-authored
direction: a fictional modern electronic drum kit, an original cyan/magenta
Expand Down
32 changes: 16 additions & 16 deletions docs/release/PUBLICATION_RUNBOOK.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
# Clean public repository runbook

Status: **source-readiness preparation authorized; publication execution still pending exact-SHA approval**.
Status: **clean source-only repository published on 2026-08-18**. This document
is retained as the historical runbook and as a verification checklist. Public
Unity binaries remain out of scope pending their separate legal and release
gates; the first attested source-snapshot workflow run is also still pending.

The existing private repository contains historical playtest tags and releases.
The preferred non-destructive publication path is a new repository initialized
Expand All @@ -15,11 +18,10 @@ Because the website and documentation already use the canonical
- repoint the local remotes deliberately, preserving a clearly named private
archive remote when still needed.

The maintainer has selected this topology and authorized its preparation. The
rename, public-repository creation, visibility change, remote rewiring and
workflow activation remain publication actions: execute them only in a later
turn after review of this readiness PR and fresh authorization tied to the
exact source SHA.
The maintainer selected this topology. The private history is now retained in
`HitTheKit-private-archive`, while `Codewriter90x/HitTheKit` is the clean public
source repository. Do not repeat the rename or repository-creation steps below;
they remain documented to explain and audit the publication boundary.

GitHub warns that redirects can stop working when a new repository reuses the
old name. Immediately after the archive rename and public repository creation,
Expand Down Expand Up @@ -75,18 +77,16 @@ Before opening access, configure:
- GitHub Sponsors only after its profile is approved and the funding link is
confirmed from a logged-out session.

After the public repository exists, rename
`.github/workflows/pages.yml.example` to `.github/workflows/pages.yml`, enable
Pages with GitHub Actions as the source, and verify the deployment before
setting the repository homepage URL. Do not activate this workflow in the
private historical archive.
The public repository uses `.github/workflows/pages.yml`; Pages is enabled with
GitHub Actions as the source and the repository homepage points to the verified
deployment. The private historical archive must not activate this workflow.

Also rename `.github/workflows/source-release.yml.example` to
`.github/workflows/source-release.yml` in the public repository. Run it only
for an approved exact version, then verify the downloaded source snapshot's
SHA-256 and GitHub artifact attestation before attaching it to a release.
The public repository also contains `.github/workflows/source-release.yml`.
Run it only for an approved exact version, then verify the downloaded source
snapshot's SHA-256 and GitHub artifact attestation before attaching it to a
release.

In the same reviewed publication commit, change `PUBLICATION_STATUS` from
The reviewed publication commit changed `PUBLICATION_STATUS` from
`private-preparation` to `public`. The public-readiness contract deliberately
fails if active deployment workflows appear in the private state or if the
public state is missing them.
Expand Down
10 changes: 5 additions & 5 deletions docs/release/PUBLIC_RELEASE_CHECKLIST.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,13 +53,13 @@ non modifica né riscrive quello privato.
- [x] Template issue/PR e scansione automatica presenti.
- [x] Roadmap, supporto, governance, maintainer e CODEOWNERS documentati.
- [x] Processo release, bozza note 0.5.0 e runbook del nuovo repository preparati.
- [x] Workflow GitHub Pages preparato come template inattivo.
- [x] Workflow snapshot sorgente con attestazione preparato come template inattivo.
- [ ] Protezione di `main`, required checks e private vulnerability reporting abilitati su GitHub.
- [x] Workflow GitHub Pages attivo nel repository pubblico.
- [x] Workflow snapshot sorgente con attestazione attivo e vincolato alla versione richiesta.
- [x] Protezione di `main`, required checks e private vulnerability reporting abilitati su GitHub.
- [ ] Screenshot e video finali acquisiti dalla build candidata, senza asset di terzi.
- [ ] Release notes coerenti con limiti reali e piattaforme testate.
- [ ] Workflow Pages attivato solo nel nuovo repository e sito verificato da sessione non autenticata.
- [ ] Workflow snapshot attivato nel nuovo repository e attestazione verificata con `gh`.
- [x] Workflow Pages attivato solo nel nuovo repository e sito verificato da sessione non autenticata.
- [ ] Prima esecuzione del workflow snapshot completata e attestazione verificata con `gh`.

## Sostenibilità

Expand Down
16 changes: 8 additions & 8 deletions docs/release/RELEASE_PROCESS.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,9 +95,9 @@ The release record must include:
- refreshed notices and provenance; and
- screenshots or video captured from the candidate itself.

In the approved public repository, activate
`.github/workflows/source-release.yml.example` and use it to create an
attested, rights-clean source snapshot. Verify the downloaded artifact with:
In the public repository, dispatch `.github/workflows/source-release.yml` for
the approved exact version to create an attested, rights-clean source snapshot.
Verify the downloaded artifact with:

```sh
gh attestation verify HitTheKit-source-0.5.0.tar.gz -R Codewriter90x/HitTheKit
Expand All @@ -108,11 +108,11 @@ legal, content, or binary validation.

## 8. Publish only after approval

The clean public repository is intentionally the final step. Follow
[PUBLICATION_RUNBOOK.md](PUBLICATION_RUNBOOK.md), publish the source snapshot
and approved binaries, mark `0.5.0` as a pre-release, and immediately verify
links, checksums, issue forms, security reporting, and branch protection from
an unauthenticated session.
The clean public repository and source-only preview are already active. Follow
[PUBLICATION_RUNBOOK.md](PUBLICATION_RUNBOOK.md), publish the approved source
snapshot, and immediately verify links, checksums, issue forms, security
reporting, and branch protection from an unauthenticated session. Public Unity
binaries remain a separate, later gate.

If any claim cannot be supported by evidence, weaken or remove the claim; do
not waive the gate silently.
7 changes: 3 additions & 4 deletions website/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,6 @@ Then open `http://127.0.0.1:4173/`.
Before publishing under a custom domain, update the canonical URL, Open Graph
image URL, `robots.txt`, and `sitemap.xml`.

The future GitHub Pages workflow is intentionally stored as
`.github/workflows/pages.yml.example`. Activate it only in the approved public
repository after Pages is configured to use GitHub Actions. The private
historical repository must not deploy the site accidentally.
The public repository deploys this directory through
`.github/workflows/pages.yml`. The private historical archive must keep public
deployment disabled.
7 changes: 5 additions & 2 deletions website/assets/js/site.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions website/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -99,7 +99,7 @@ <h1 id="hero-title"><span data-i18n="heroLine1">SALI SUL PALCO,</span><strong da
</ul>
</div>
<figure class="hero-media">
<img src="assets/images/hero-drum-kit.jpg" width="1600" height="901" alt="Batteria completa illuminata da luci blu e ambra" fetchpriority="high">
<img src="assets/images/hero-drum-kit.jpg" width="1600" height="900" alt="Batteria completa illuminata da luci blu e ambra" fetchpriority="high">
<figcaption data-i18n="heroCaption">Otto elementi leggibili, una sola timeline musicale.</figcaption>
</figure>
</div>
Expand Down Expand Up @@ -138,7 +138,7 @@ <h1 id="hero-title"><span data-i18n="heroLine1">SALI SUL PALCO,</span><strong da
<article class="theme theme-steel reveal"><p>THEME 03</p><h3>Precision Grid</h3><span data-i18n="themeGrid">Geometria tecnica, prospettiva piatta e massima leggibilità.</span></article>
</div>
<figure class="stage-preview reveal">
<img src="assets/images/stage-command.jpg" width="1600" height="901" loading="lazy" alt="Schermata Stage Command di HitTheKit su un palco neon">
<img src="assets/images/stage-command.jpg" width="1600" height="900" loading="lazy" alt="Schermata Stage Command di HitTheKit su un palco neon">
</figure>
</div>
</section>
Expand Down
Loading