Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
ISC License

Copyright (c) 2026

Permission to use, copy, modify, and/or distribute this software for any
purpose with or without fee is hereby granted, provided that the above
copyright notice and this permission notice appear in all copies.

THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
30 changes: 19 additions & 11 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,22 +1,23 @@
# CubDen Game - Polar Bear Endless Runner

A browser-based 2D Phaser 3 endless runner game featuring a cybernetic polar bear running across frozen Arctic ice while avoiding holes.
A browser-based Phaser 3 endless runner where a cybernetic polar bear sprints across unstable Arctic ice, dodges sliding penguins, and survives accelerating obstacle waves.

## Game Features

- **Endless Runner Mechanics**: Polar bear auto-runs forward
- **Jump Controls**: SPACE or UP ARROW to jump over ice holes
- **Pause**: **ESC** to pause / resume (pause overlay)
- **Desktop and Touch Controls**: keyboard and on-screen controls
- **Pause Support**: ESC or on-screen pause button
- **Animated Sprite**: 10-frame walking animation
- **Procedural Obstacles**: Ice holes spawn randomly with increasing difficulty
- **Score & Distance Tracking**: Real-time HUD display
- **Arctic Theme**: Snow particles, clouds, mountains, and ice ground
- **Procedural Obstacles**: ice holes and sliding penguins
- **Progression Layer**: score, distance, milestones, best-run tracking, and difficulty tiers
- **Arctic Presentation**: snow particles, parallax clouds, mountains, and drifting ice details

## Commands

```bash
pnpm install
pnpm dev # Vite dev server
pnpm verify # Security scan + production build
pnpm build # Production build
pnpm preview # Preview production build
```
Expand All @@ -25,21 +26,28 @@ pnpm preview # Preview production build

1. Run `pnpm dev` to start the development server
2. Open `http://localhost:5173/` in your browser
3. Use **SPACE** or **UP ARROW** to jump over ice holes
4. Press **ESC** to pause; press **ESC** again to resume
5. Avoid falling into the dark holes in the ice
6. Press **R** to restart after game over
3. Use **SPACE**, **W**, or **UP ARROW** to jump on desktop
4. On mobile or narrow screens, use the on-screen **Jump** and **Pause** buttons
5. Press **ESC** to pause or resume on desktop
6. Avoid ice holes and penguins while speed increases over time
7. Press **ENTER** or **R** to restart after game over

## Project Structure

- `index.html` - Main HTML file
- `src/polar-bear-main.js` - Game entry point
- `src/scenes/PolarBearScene.js` - Main game scene
- `src/constants/polar-bear.js` - Game constants
- `src/ui/TouchControls.js` - Mobile control bindings
- `scripts/security-scan.mjs` - Lightweight repository scan for suspicious code patterns
- `assets/polarbear-game/` - Game assets (sprites, etc.)

## Tech Stack

- Phaser 3.80+
- Vite 5
- ES Modules

## Release Notes

- Current package version: `0.1.0`
- Public repo hygiene includes a pre-commit security scan, CI verification workflow, and documented security handling guidance
23 changes: 15 additions & 8 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,18 @@
# Security Notes
# Security Policy

## Immediate Remediation
## Reporting

- Remove any browser-incompatible or obfuscated payloads from tracked source files.
- Treat unexpected `createRequire`, `global[...]`, encoded payloads, and hand-obfuscated functions as a stop-ship event.
- If you find a security issue, report it privately to the maintainers instead of opening a public issue.
- Include a short description, affected files or features, reproduction steps, and impact.

## Local Controls
## Scope

- Unexpected obfuscated code in tracked source files
- Browser game code importing Node-only modules
- Supply-chain or build-script changes that introduce unsafe behavior
- Client-side behaviors that expose users to script injection or malicious redirects

## Local Verification

- Run `pnpm run security:scan` before commit or release.
- Run `pnpm run verify` before pushing.
Expand All @@ -17,8 +24,8 @@
- Reject browser game code that imports Node-only modules.
- Review unusual changes to build config, package scripts, and scene files with extra scrutiny.

## Recovery Guidance
## Response Guidance

- If suspicious code is found again, remove it from the working tree first.
- Remove suspicious code from the working tree first.
- Identify the introducing commit with `git blame` and `git log`.
- Rewrite local history so the malicious commit is no longer reachable.
- Rewrite history when needed so malicious commits are no longer reachable from active branch refs.
7 changes: 7 additions & 0 deletions changelog.txt
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
CHANGELOG — cubden-game (Polar Bear Endless Runner)

## [0.1.0] — 2026-04-05
- Added responsive layout and touch controls
- Added best-run tracking, milestones, and named difficulty tiers
- Fixed pause-state timing and animation suspension
- Hardened animation registration, collision tuning, and background motion
- Updated public repo documentation and security policy

## [0.0.4] — 2026-03-27
- Version bump

Expand Down
58 changes: 22 additions & 36 deletions docs/DEV-TASKS_04-05.md
Original file line number Diff line number Diff line change
@@ -1,28 +1,12 @@
# Development Tasklist (04-05)

This task list is based on direct codebase review and one build verification run. It focuses on clear improvement opportunities rather than forcing fixes where the game is already acceptable.

## Highest Priority

### Major Bug Fix

#### 1. Remove browser-incompatible and obfuscated code from the main scene
- Priority: Critical
- Why it matters: The game does not currently build for production.
- Evidence:
- `src/scenes/PolarBearScene.js` imports `createRequire` from Node's `module` package at lines 8-10.
- The same file has a large block of obfuscated code appended after the class at line 130.
- `pnpm build` fails with: `"createRequire" is not exported by "__vite-browser-external"`.
- Task:
- Remove the Node-specific import and any injected obfuscated payload from the scene file.
- Rebuild and confirm Vite produces a clean production bundle.
- Review the repo for any similar injected code patterns before shipping.
This task list is based on direct codebase review after the security cleanup. It focuses on practical gameplay, usability, and maintainability improvements rather than forcing unnecessary fixes.

## Feature Improvements

### Major Feature Improvement

#### 2. Add responsive layout and mobile-friendly controls
#### 1. ✅ Add responsive layout and mobile-friendly controls
- Priority: High
- Why it matters: The game is locked to a desktop-sized fixed canvas and keyboard-only input, which limits reach and usability.
- Evidence:
Expand All @@ -36,7 +20,7 @@ This task list is based on direct codebase review and one build verification run

### Minor Feature Improvement

#### 3. Add a simple progression layer: best score, milestones, and difficulty tiers
#### 2. ✅ Add a simple progression layer: best score, milestones, and difficulty tiers
- Priority: Medium
- Why it matters: The core loop works, but there is little long-term motivation beyond surviving longer.
- Evidence:
Expand All @@ -49,9 +33,23 @@ This task list is based on direct codebase review and one build verification run

## Smaller Fixes

### Major Bug Fix

#### 3. ✅ Freeze all gameplay timers and obstacle animations during pause
- Priority: High
- Why it matters: Pause should fully suspend game state. If timers or animations continue running, players can lose invincibility time or see inconsistent behavior after resuming.
- Evidence:
- `src/ui/PauseMenu.js:21-46` pauses physics and only pauses the polar bear animation.
- `src/ui/HUD.js:81-87` uses `scene.time.delayedCall(...)` for invincibility, which should not be allowed to expire while paused.
- `src/entities/Penguins.js:36` starts a looping penguin animation that is not explicitly paused.
- Task:
- Pause and resume the scene clock or equivalent timers along with physics.
- Pause active non-player animations when the game is paused.
- Verify pause behavior while invincibility is active.

### Minor Bug Fixes

#### 4. Prevent animation key re-registration issues on restart
#### 4. ✅ Prevent animation key re-registration issues on restart
- Priority: Medium
- Why it matters: Restarting the scene can re-run animation creation and cause duplicate-key warnings or unstable behavior.
- Evidence:
Expand All @@ -61,19 +59,7 @@ This task list is based on direct codebase review and one build verification run
- Task:
- Register animations once, or check whether an animation key already exists before creating it.

#### 5. Freeze all gameplay timers and obstacle animations during pause
- Priority: Medium
- Why it matters: The pause system pauses physics, but not all scene activity is guaranteed to stop.
- Evidence:
- `src/ui/PauseMenu.js:21-46` pauses physics and only pauses the polar bear animation.
- `src/ui/HUD.js:81-87` uses `scene.time.delayedCall(...)` for invincibility, which should not be allowed to expire while paused.
- `src/entities/Penguins.js:36` starts a looping penguin animation that is not explicitly paused.
- Task:
- Pause and resume the scene clock or equivalent timers along with physics.
- Pause active non-player animations when the game is paused.
- Verify pause behavior while invincibility is active.

#### 6. Tighten collision logic to reduce unfair hits
#### 5. ✅ Tighten collision logic to reduce unfair hits
- Priority: Low
- Why it matters: Collision checks are currently hand-tuned and may feel inconsistent as art sizes or speeds change.
- Evidence:
Expand All @@ -86,7 +72,7 @@ This task list is based on direct codebase review and one build verification run

## Nice-to-Have Polish

#### 7. Improve endless-runner readability with stronger world motion
#### 6. ✅ Improve endless-runner readability with stronger world motion
- Priority: Low
- Why it matters: Clouds move, but mountains, ground details, and decorative ice mostly stay static, which weakens the feeling of motion.
- Evidence:
Expand All @@ -98,5 +84,5 @@ This task list is based on direct codebase review and one build verification run

## Notes

- I did not find evidence that the overall game loop is fundamentally broken beyond the confirmed production build failure.
- Because of that, the backlog should prioritize shipping stability first, then usability and replay value.
- I did not find evidence that the overall core loop is critically broken after the recent cleanup.
- The highest-value backlog items now are pause-state correctness, responsiveness, and replay-value improvements.
Loading
Loading