Built in the open

Every legend starts as a pull request

The roster is community-curated. Card art and data are licensed CC BY-SA 4.0 — fork it, print it, remix it, and send legends back upstream.

01

Nominate a legend

Open an issue with the person, project, or company and why they belong in the set. The community votes with reactions.

02

Draft the card data

Add a record to the roster for the series you are contributing to — see the spec below. Every factual claim needs a public source we can check.

03

Render the faces

Run the series pipeline to produce the front and back PNGs from your record. Card art is generated from the data, so nobody hand-edits a card image.

04

Open a pull request

Ship the roster record plus the rendered faces. Maintainers review for accuracy, sourcing, licensing, and balance.

The card spec

One legend, one record

Series Two and Series Three are both taking nominations. Each roster is hand-curated in one file — src/data/hacking.ts for Hacking Legends, src/data/security.ts for Security Professionals — and that file is the source of truth: the pipeline reads it directly, so there is no second copy to keep in sync. Series Three swaps the social and notoriety bars for defense and research, and no name may appear in two sets.

// src/data/hacking.ts
{
  number: 31,
  slug: "ada-lovelace",
  name: "Ada Lovelace",
  handle: "",                  // optional scene handle
  title: "The First Programmer",
  knownFor: "The first published algorithm",
  rarity: "iconic",            // iconic | legendary | epic | rare
  impact: 96,                  // headline score, 0-100
  technical: 97,               // the four stat bars on the card back
  social: 70,
  notoriety: 60,
  influence: 95,
  nationality: "England",
  era: "1815-1852",
  domains: ["Computing theory", "Mathematics"],
  scouting: "Wrote the first published algorithm...",
  note: "Curator's voice. Never a fabricated quote.",
  status: "draft",             // locked | draft | candidate
  sources: [                   // required — at least one public reference
    { label: "Ada Lovelace", url: "https://en.wikipedia.org/wiki/Ada_Lovelace" },
  ],
}

Then render the faces

pnpm hacking validate checks the roster and reports what art is missing. pnpm hacking all 31 generates the portrait, renders the front and back, and writes them to public/cards/hacking/. The front and back fields are written by that step — never by hand.

Series One works differently

Series One is complete and locked. Its fact-checked roster lives in data/roster.locked.json, and src/data/cards.ts is generated from it — the header of that file says so. Edit the JSON and re-run node scripts/open-source-legends.mjs all; a pull request that edits cards.ts directly will be overwritten by the next render.

Sourcing is not optional

Every historical claim on a card has to be checkable. The sourcesarray is rendered on the card page and in the roster's scouting report, so a reader can go straight to the reporting, court record, talk or primary writing behind it.