* Add APNG Studio canvas extension
APNG Studio is an interactive GitHub Copilot canvas extension for building
Animated PNG (APNG) files from frames: draw or upload frames, tune per-frame
timing and compositing, preview live, send the result to a phone by QR, and
export an animated .png.
Adds extensions/apng-studio/ with the required .github/plugin/plugin.json and
assets/preview.png, and regenerates .github/plugin/marketplace.json.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Address review feedback for APNG Studio
Security and robustness (extension.mjs):
- Reject "." and ".." project ids so canvas/action input cannot resolve
outside artifacts/.
- Bound request bodies (1 MiB JSON, 40 MiB frame upload); return 413 when
exceeded.
- Reject malformed JSON with 400 instead of coercing to {}, so a truncated
body cannot trigger destructive routes such as /frames/clear.
- Scope shares per project so one canvas cannot rotate or stop another's
share; the LAN server is shared and torn down once no shares remain.
- get_state treats hiddenFirst as active only with >=2 frames, matching the
encoder, so a single-frame project reports the correct duration.
Accessibility (web/):
- Expose Pen/Eraser state with aria-pressed and keep it in sync in setTool.
- Mark the toast as an aria-live status region.
Packaging:
- Add extensions/apng-studio/.gitignore with artifacts/ so the documented
runtime-data exclusion holds for this extension.
- Update the README install section to reference the committed awesome-copilot
extension path.
Regenerated .github/plugin/marketplace.json.
* Use "GitHub Copilot app" wording
Update the plugin description (and regenerated marketplace entry) to refer to
the host as the GitHub Copilot app.
* Address deeper review for APNG Studio
Security:
- Require a per-server access token on every loopback data/mutation request
(minted per canvas server, carried in the iframe URL, attached to every
renderer request). Static assets stay public. Blocks a local process or
cross-origin page from reading state or driving mutations.
Concurrency and durability:
- Serialize the load-mutate-save cycle per project; dedupe concurrent first
loads; write project.json via temp file + rename.
Lifecycle:
- Track SSE clients per instance and end them before server.close().
- Stop a project's LAN share only when no other panel references it.
Correctness:
- Report exact numerator/denominator total duration; handle pointercancel.
QR and accessibility:
- Place QR version bits least-significant-bit first (versions 7-10).
- Associate delay/fps/dispose/blend labels with their inputs via for=.
* Address deeper concurrency and validation review for APNG Studio
- Run assemble() under the project lock; add_color_frame renders and appends
within one lock.
- Validate uploaded frames (PNG chunk scan, size + dimension checks) before
writing; first frame stores real dimensions; CanvasError maps to 400.
- Validate move delta; clear frames in memory before deleting files.
- Route the open-handler rename through applySettings.
- Deduplicate LAN share startup; clean up if the canvas closes mid-start.
- End SSE streams before server.close(); skip dead streams in broadcast.
- Exact fractional duration; drawing surface stays >= 1px; refresh state before
re-seeding "start from last frame".
* Address review: PNG format validation, share bind, limits, a11y
- Validate uploaded frames are 8-bit RGBA non-interlaced PNGs (standard
compression/filter); reject formats the codec can't encode.
- Cap projects at 600 frames (add + duplicate).
- Bind the LAN share server to the private address, not 0.0.0.0; require a
private address and rebind when it changes while idle; build the URL from the
bound address.
- Align width/height inputs and clampSize to the 2048 maximum.
- Size the drawing surface by width + aspect ratio for narrow panels.
- set_frame with an unknown frameId returns a validation error.
* Address review: encoded-byte budget, timing modes, id keys, load errors
- 256 MiB aggregate encoded-byte budget (add + duplicate); per-frame size
tracked and backfilled on load, so a frame count alone no longer bounds
assembly memory.
- Frame timing is one exclusive mode (delayMs | fps | delayNum/delayDen);
combinations are rejected instead of producing hybrid delays.
- Collision-resistant project storage keys: safe ids are used verbatim (existing
projects still load) and only unsafe ids get a hash suffix, so "foo/bar" and
"foo?bar" can't share a directory.
- Load only treats a missing file as a new project; other read/parse errors
surface instead of silently overwriting real data.
- Share server binds to a real LAN interface (skips virtual/VPN/container,
prefers physical NICs and common ranges).
- Generated export names get millisecond + random suffix to avoid same-second
overwrite.
- PNG validator accepts the encoder's Uint8Array so agent solid-color frames
aren't rejected.
* Address review: crash-safe frame writes, server startup, APNG first frame
- Write the PNG before mutating project metadata on add/duplicate, and delete
after persisting, so an interrupted disk op can't dangle a reference or
advance unsaved state.
- Evict a project from the in-memory cache if its save fails, so a transient
write error can't desync the live session from disk.
- Reject on the loopback server's listen error and drop a half-initialized
instance so startup failures clean up and can retry.
- Normalize APNG dispose_op PREVIOUS to BACKGROUND on the first animated frame
(spec requirement).
- Release decoded ImageBitmaps after use so a large upload batch doesn't retain
native image memory.
- Surface otherwise-silent async UI failures via a toast; check the state
response is ok before parsing it.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add publish-to-pages agent skill
Agent skill that publishes presentations and web content to GitHub Pages.
Works with any AI coding agent (Copilot CLI, Claude Code, Gemini CLI, etc.)
Features:
- Converts PPTX and PDF with full formatting preservation
- Creates repo, enables Pages, returns live URL
- Zero config — just needs gh CLI
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* docs: update README.skills.md
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>