docs: add README overview hero image (#211) - #212
Conversation
|
Implementation for #211 is complete at exact HEAD Asset verification:
README verification:
Exact-head CI:
#211 still requires the explicit exact-head Human Gate after independent Review and before Integration merges. Any later HEAD change invalidates that Human Gate. Implementation has not merged this PR. |
miso-develop
left a comment
There was a problem hiding this comment.
Review disposition: HUMAN_GATE_REQUIRED
Reviewed exact PR head 6de536c9be8c2327473295f4357dd9d98c9c0a69 against Issue #211 and the #192 product-facing README baseline.
No blocking implementation finding identified.
Approved asset identity — independently verified from the committed repository blob:
- Path:
docs/assets/m5authenticator-overview.jpg. - Git blob SHA:
6737e4d5a2a9e7a79f770477c1185597e5344b35. - Decoded byte size: exactly 122,915 bytes.
- JPEG SOI/EOI structure: valid.
- Dimensions parsed from the JPEG frame: exactly 840 × 420.
- Independently recomputed SHA-256:
215ed9c6ffe29ec7ba302dc830569286b188bcfb3c9885f4e4b8b48be3556b42. - These values exactly match the Human-approved source-asset identity recorded in #211.
- Therefore the committed binary is byte-for-byte the approved asset; no crop, redraw, regeneration, re-encoding, recoloring, or substitution occurred.
- The JPEG contains only a small EXIF APP1 block with three numeric TIFF entries; there is no EXIF ASCII/string field, JPEG COM segment, or APP13 metadata carrying a local path/comment/private filesystem string.
- Repository Security scan is green with this binary addition.
README placement/content:
README.mdinserts exactly:

immediately after the language selector.README.ja.mdinserts exactly:

at the same structural location.- Both READMEs reference the same single committed repository-relative image file.
- No remote host, Issue attachment URL, CDN, data URI, clickable wrapper, hard-coded width, extra heading, or caption is introduced.
- In both languages the image is the first content after the language switcher, with ordinary blank-line Markdown separation.
- The README patches contain no other copy/content changes.
Scope/security boundary:
- Effective diff is exactly:
README.md;README.ja.md;docs/assets/m5authenticator-overview.jpg.
SECURITY.md,AGENTS.md, Web/runtime code, firmware, release workflows, and repository About metadata are unchanged.- No Product, Protocol, Vault, TOTP, credential, Recovery, Device, or release behavior changes.
- Exact binary identity plus the approved Human-source record establishes that the visible example is the intended synthetic/non-secret asset rather than a regenerated substitute.
Exact-head CI:
- Security #940: SUCCESS.
- repository scanner and existing release/security contracts passed with the JPEG tracked.
- Foundation #937: SUCCESS.
- Web and Windows Chrome jobs passed;
- firmware regression/security contracts passed;
- isolated ESP-IDF build/package validation and dependency-lock verification passed.
Staleness/collision:
- Handoff HEAD matches current PR HEAD.
- PR is open, non-draft, and mergeable.
- Current
mainremains exact PR based575e70fd7e07e9f2774762b5636cb74e94ed42d. - Compare is 1 commit ahead / 0 behind.
- PR #212 is the only open PR at final Review check.
- No ownership/collision issue exists.
Outstanding mandatory gate:
- #211 explicitly requires an exact-head Human Gate after independent Review and before merge.
- Integration must stop before merge and obtain Human confirmation on this exact head
6de536c9be8c2327473295f4357dd9d98c9c0a69. - Human must verify GitHub-rendered
README.mdandREADME.ja.md:- image appears immediately below the language selector in both;
- both show the same intended approved image;
- repository-relative rendering is not broken;
- presentation is visually acceptable at normal GitHub README width;
- surrounding README structure/content remains correct.
- Any PR-head change after that Human Gate makes the gate stale and requires re-validation.
No additional Security-role review is required for this documentation/binary presentation change.
READY_TO_MERGEHEAD: Integration reconstruction:
STATE: READY_TO_MERGE |
INTEGRATEDPR: #212 Integration evidence:
STATE: INTEGRATED |
Closes #211
Related: #192
Implementation
docs/assets/m5authenticator-overview.jpgimmediately below the language selector inREADME.mdat the same structural location inREADME.ja.mdApproved asset identity
Source verification before commit:
215ed9c6ffe29ec7ba302dc830569286b188bcfb3c9885f4e4b8b48be3556b426737e4d5a2a9e7a79f770477c1185597e5344b35The committed GitHub blob SHA is exactly
6737e4d5a2a9e7a79f770477c1185597e5344b35, proving the repository asset is byte-for-byte the approved upload. No crop, redraw, regeneration, re-encoding, recoloring, or metadata transformation was performed.Scope
Effective diff is limited to:
docs/assets/m5authenticator-overview.jpgREADME.mdREADME.ja.mdNo
SECURITY.md,AGENTS.md, product code, Web runtime, firmware, release workflow, or repository About metadata changes.Human Gate
#211 requires an exact-head Human Gate after independent Review and before Integration merges.
The Human Gate must verify GitHub-rendered EN/JA README views on the exact candidate HEAD. Any subsequent HEAD change invalidates the prior Human Gate and requires re-validation.
Exact-head verification
HEAD:
6de536c9be8c2327473295f4357dd9d98c9c0a696737e4d5a2a9e7a79f770477c1185597e5344b35, matching the approved upload byte-for-byte; repository fetch confirms 122,915 bytes.215ed9c6ffe29ec7ba302dc830569286b188bcfb3c9885f4e4b8b48be3556b42.README.mdandREADME.ja.mdeach place the required image immediately after the language selector with the required alt text.docs/assets/m5authenticator-overview.jpg.mainremainsd575e70fd7e07e9f2774762b5636cb74e94ed42d; branch is behind 0 and PR is mergeable.Integration gate
Independent Review is next. After Review passes, Integration must stop for the exact-head Human Gate required by #211 before merge. Human validation applies only to this exact HEAD; any later head change invalidates it.