mirror of
https://github.com/daijro/camoufox.git
synced 2026-10-04 16:00:21 +00:00
scripts/data/font-bundle.json pointed at a release in JWriter20/camoufox, so merging this would have left daijro/camoufox fetching a required build input from a personal fork -- a build that breaks if that fork is renamed, made private, or has the release deleted, by someone with no obligation to keep it. The identical asset is now published at daijro/camoufox under the same font-bundle-v1 tag, so only `repo` and `url` move here; `size` and `sha256` are byte-for-byte what they were, which is the point -- the pin proves the bytes did not change when the host did. The upstream release is deliberately NOT marked latest: v152.0.4-beta.30 holds that badge, and a build input must not displace the browser download people actually come for. `font-bundle-*` tags are already excluded from build.yml, so publishing it triggered no browser build. Verified against the new host from scratch: local archive moved aside, `make fetch-fonts` pulled 843 MB from daijro/camoufox, sha256 matched the pin, a forced re-extract produced 1515 files, verify-fonts.py passed every check (1513 faces stored once; 810/780/793 reachable, each inside its own groups), and pythonlib is 316 passed, 2 skipped. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>