Polar Bear Endless Runner
+Guide the cybernetic polar bear across unstable Arctic ice. Jump the holes, dodge sliding penguins, and keep the run alive as the pace ramps up.
+diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..e1c8d6a --- /dev/null +++ b/LICENSE @@ -0,0 +1,15 @@ +ISC License + +Copyright (c) 2026 + +Permission to use, copy, modify, and/or distribute this software for any +purpose with or without fee is hereby granted, provided that the above +copyright notice and this permission notice appear in all copies. + +THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR +ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN +ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF +OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. diff --git a/README.md b/README.md index f197435..74d2e7f 100644 --- a/README.md +++ b/README.md @@ -1,22 +1,23 @@ # CubDen Game - Polar Bear Endless Runner -A browser-based 2D Phaser 3 endless runner game featuring a cybernetic polar bear running across frozen Arctic ice while avoiding holes. +A browser-based Phaser 3 endless runner where a cybernetic polar bear sprints across unstable Arctic ice, dodges sliding penguins, and survives accelerating obstacle waves. ## Game Features - **Endless Runner Mechanics**: Polar bear auto-runs forward -- **Jump Controls**: SPACE or UP ARROW to jump over ice holes -- **Pause**: **ESC** to pause / resume (pause overlay) +- **Desktop and Touch Controls**: keyboard and on-screen controls +- **Pause Support**: ESC or on-screen pause button - **Animated Sprite**: 10-frame walking animation -- **Procedural Obstacles**: Ice holes spawn randomly with increasing difficulty -- **Score & Distance Tracking**: Real-time HUD display -- **Arctic Theme**: Snow particles, clouds, mountains, and ice ground +- **Procedural Obstacles**: ice holes and sliding penguins +- **Progression Layer**: score, distance, milestones, best-run tracking, and difficulty tiers +- **Arctic Presentation**: snow particles, parallax clouds, mountains, and drifting ice details ## Commands ```bash pnpm install pnpm dev # Vite dev server +pnpm verify # Security scan + production build pnpm build # Production build pnpm preview # Preview production build ``` @@ -25,17 +26,19 @@ pnpm preview # Preview production build 1. Run `pnpm dev` to start the development server 2. Open `http://localhost:5173/` in your browser -3. Use **SPACE** or **UP ARROW** to jump over ice holes -4. Press **ESC** to pause; press **ESC** again to resume -5. Avoid falling into the dark holes in the ice -6. Press **R** to restart after game over +3. Use **SPACE**, **W**, or **UP ARROW** to jump on desktop +4. On mobile or narrow screens, use the on-screen **Jump** and **Pause** buttons +5. Press **ESC** to pause or resume on desktop +6. Avoid ice holes and penguins while speed increases over time +7. Press **ENTER** or **R** to restart after game over ## Project Structure - `index.html` - Main HTML file - `src/polar-bear-main.js` - Game entry point - `src/scenes/PolarBearScene.js` - Main game scene -- `src/constants/polar-bear.js` - Game constants +- `src/ui/TouchControls.js` - Mobile control bindings +- `scripts/security-scan.mjs` - Lightweight repository scan for suspicious code patterns - `assets/polarbear-game/` - Game assets (sprites, etc.) ## Tech Stack @@ -43,3 +46,8 @@ pnpm preview # Preview production build - Phaser 3.80+ - Vite 5 - ES Modules + +## Release Notes + +- Current package version: `0.1.0` +- Public repo hygiene includes a pre-commit security scan, CI verification workflow, and documented security handling guidance diff --git a/SECURITY.md b/SECURITY.md index 8a51e88..c182ad6 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,11 +1,18 @@ -# Security Notes +# Security Policy -## Immediate Remediation +## Reporting -- Remove any browser-incompatible or obfuscated payloads from tracked source files. -- Treat unexpected `createRequire`, `global[...]`, encoded payloads, and hand-obfuscated functions as a stop-ship event. +- If you find a security issue, report it privately to the maintainers instead of opening a public issue. +- Include a short description, affected files or features, reproduction steps, and impact. -## Local Controls +## Scope + +- Unexpected obfuscated code in tracked source files +- Browser game code importing Node-only modules +- Supply-chain or build-script changes that introduce unsafe behavior +- Client-side behaviors that expose users to script injection or malicious redirects + +## Local Verification - Run `pnpm run security:scan` before commit or release. - Run `pnpm run verify` before pushing. @@ -17,8 +24,8 @@ - Reject browser game code that imports Node-only modules. - Review unusual changes to build config, package scripts, and scene files with extra scrutiny. -## Recovery Guidance +## Response Guidance -- If suspicious code is found again, remove it from the working tree first. +- Remove suspicious code from the working tree first. - Identify the introducing commit with `git blame` and `git log`. -- Rewrite local history so the malicious commit is no longer reachable. +- Rewrite history when needed so malicious commits are no longer reachable from active branch refs. diff --git a/changelog.txt b/changelog.txt index 08f0e29..2f0c67c 100644 --- a/changelog.txt +++ b/changelog.txt @@ -1,5 +1,12 @@ CHANGELOG — cubden-game (Polar Bear Endless Runner) +## [0.1.0] — 2026-04-05 +- Added responsive layout and touch controls +- Added best-run tracking, milestones, and named difficulty tiers +- Fixed pause-state timing and animation suspension +- Hardened animation registration, collision tuning, and background motion +- Updated public repo documentation and security policy + ## [0.0.4] — 2026-03-27 - Version bump diff --git a/docs/DEV-TASKS_04-05.md b/docs/DEV-TASKS_04-05.md index 30cd71d..b7ae59f 100644 --- a/docs/DEV-TASKS_04-05.md +++ b/docs/DEV-TASKS_04-05.md @@ -1,28 +1,12 @@ # Development Tasklist (04-05) -This task list is based on direct codebase review and one build verification run. It focuses on clear improvement opportunities rather than forcing fixes where the game is already acceptable. - -## Highest Priority - -### Major Bug Fix - -#### 1. Remove browser-incompatible and obfuscated code from the main scene -- Priority: Critical -- Why it matters: The game does not currently build for production. -- Evidence: - - `src/scenes/PolarBearScene.js` imports `createRequire` from Node's `module` package at lines 8-10. - - The same file has a large block of obfuscated code appended after the class at line 130. - - `pnpm build` fails with: `"createRequire" is not exported by "__vite-browser-external"`. -- Task: - - Remove the Node-specific import and any injected obfuscated payload from the scene file. - - Rebuild and confirm Vite produces a clean production bundle. - - Review the repo for any similar injected code patterns before shipping. +This task list is based on direct codebase review after the security cleanup. It focuses on practical gameplay, usability, and maintainability improvements rather than forcing unnecessary fixes. ## Feature Improvements ### Major Feature Improvement -#### 2. Add responsive layout and mobile-friendly controls +#### 1. ✅ Add responsive layout and mobile-friendly controls - Priority: High - Why it matters: The game is locked to a desktop-sized fixed canvas and keyboard-only input, which limits reach and usability. - Evidence: @@ -36,7 +20,7 @@ This task list is based on direct codebase review and one build verification run ### Minor Feature Improvement -#### 3. Add a simple progression layer: best score, milestones, and difficulty tiers +#### 2. ✅ Add a simple progression layer: best score, milestones, and difficulty tiers - Priority: Medium - Why it matters: The core loop works, but there is little long-term motivation beyond surviving longer. - Evidence: @@ -49,9 +33,23 @@ This task list is based on direct codebase review and one build verification run ## Smaller Fixes +### Major Bug Fix + +#### 3. ✅ Freeze all gameplay timers and obstacle animations during pause +- Priority: High +- Why it matters: Pause should fully suspend game state. If timers or animations continue running, players can lose invincibility time or see inconsistent behavior after resuming. +- Evidence: + - `src/ui/PauseMenu.js:21-46` pauses physics and only pauses the polar bear animation. + - `src/ui/HUD.js:81-87` uses `scene.time.delayedCall(...)` for invincibility, which should not be allowed to expire while paused. + - `src/entities/Penguins.js:36` starts a looping penguin animation that is not explicitly paused. +- Task: + - Pause and resume the scene clock or equivalent timers along with physics. + - Pause active non-player animations when the game is paused. + - Verify pause behavior while invincibility is active. + ### Minor Bug Fixes -#### 4. Prevent animation key re-registration issues on restart +#### 4. ✅ Prevent animation key re-registration issues on restart - Priority: Medium - Why it matters: Restarting the scene can re-run animation creation and cause duplicate-key warnings or unstable behavior. - Evidence: @@ -61,19 +59,7 @@ This task list is based on direct codebase review and one build verification run - Task: - Register animations once, or check whether an animation key already exists before creating it. -#### 5. Freeze all gameplay timers and obstacle animations during pause -- Priority: Medium -- Why it matters: The pause system pauses physics, but not all scene activity is guaranteed to stop. -- Evidence: - - `src/ui/PauseMenu.js:21-46` pauses physics and only pauses the polar bear animation. - - `src/ui/HUD.js:81-87` uses `scene.time.delayedCall(...)` for invincibility, which should not be allowed to expire while paused. - - `src/entities/Penguins.js:36` starts a looping penguin animation that is not explicitly paused. -- Task: - - Pause and resume the scene clock or equivalent timers along with physics. - - Pause active non-player animations when the game is paused. - - Verify pause behavior while invincibility is active. - -#### 6. Tighten collision logic to reduce unfair hits +#### 5. ✅ Tighten collision logic to reduce unfair hits - Priority: Low - Why it matters: Collision checks are currently hand-tuned and may feel inconsistent as art sizes or speeds change. - Evidence: @@ -86,7 +72,7 @@ This task list is based on direct codebase review and one build verification run ## Nice-to-Have Polish -#### 7. Improve endless-runner readability with stronger world motion +#### 6. ✅ Improve endless-runner readability with stronger world motion - Priority: Low - Why it matters: Clouds move, but mountains, ground details, and decorative ice mostly stay static, which weakens the feeling of motion. - Evidence: @@ -98,5 +84,5 @@ This task list is based on direct codebase review and one build verification run ## Notes -- I did not find evidence that the overall game loop is fundamentally broken beyond the confirmed production build failure. -- Because of that, the backlog should prioritize shipping stability first, then usability and replay value. +- I did not find evidence that the overall core loop is critically broken after the recent cleanup. +- The highest-value backlog items now are pause-state correctness, responsiveness, and replay-value improvements. diff --git a/index.html b/index.html index 307e043..f3d87ed 100644 --- a/index.html +++ b/index.html @@ -5,49 +5,201 @@
🐻❄️ The polar bear auto-runs forward across the frozen Arctic ice!
-SPACE or UP ARROW = Jump over ice holes
-ESC = Pause / resume
-Avoid falling into the dark holes in the ice. Difficulty increases as you go further!
-Press R to restart after game over.
-Guide the cybernetic polar bear across unstable Arctic ice. Jump the holes, dodge sliding penguins, and keep the run alive as the pace ramps up.
+