diff --git a/.changeset/2198-security-dead-scan-exports.md b/.changeset/2198-security-dead-scan-exports.md new file mode 100644 index 000000000..a28eb2c42 --- /dev/null +++ b/.changeset/2198-security-dead-scan-exports.md @@ -0,0 +1,5 @@ +--- +type: Fixed +pr: 2211 +--- +**Dead security scan exports removed; injection-scan docs corrected to match reality** — `scanEntropyAnomalies` and `shannonEntropy` were dead code with zero production callers (live hooks inline their own patterns for independence). REQ-SCAN-INJ-02/-03 now accurately describe what runs live (injection patterns, invisible Unicode) vs CI-only (base64-decode, codebase scan). (#2198) diff --git a/.changeset/witty-dogs-hop.md b/.changeset/witty-dogs-hop.md new file mode 100644 index 000000000..98c5f1d13 --- /dev/null +++ b/.changeset/witty-dogs-hop.md @@ -0,0 +1,5 @@ +--- +type: Fixed +pr: 2209 +--- +**Milestone audit no longer flags a not-yet-validated phase as a Nyquist failure** — a phase that was planned but never run through `validate-phase` now reports as NOT-VALIDATED (a "run validate-phase" TODO) instead of collapsing into PARTIAL alongside phases whose validation genuinely failed. (#2117) diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json index cd576bab3..6af927e23 100644 --- a/.claude-plugin/marketplace.json +++ b/.claude-plugin/marketplace.json @@ -9,7 +9,7 @@ { "name": "gsd-core", "description": "GSD Core is a meta-prompting, context engineering, and spec-driven development system for AI coding agents.", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "source": "./", "author": { "name": "open-gsd", diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index b9d958d18..8fd746b7c 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "gsd-core", "displayName": "GSD Core", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "description": "GSD Core is a meta-prompting, context engineering, and spec-driven development system for AI coding agents.", "author": { "name": "open-gsd", diff --git a/capabilities/ai-integration/capability.json b/capabilities/ai-integration/capability.json index 90ee9a738..937bb4cd8 100644 --- a/capabilities/ai-integration/capability.json +++ b/capabilities/ai-integration/capability.json @@ -1,7 +1,7 @@ { "id": "ai-integration", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "AI design contract", "description": "AI-SPEC design contract workflow for phases that build AI systems; owns the AI integration command, agents, and workflow.ai_integration_phase activation key.", "tier": "full", diff --git a/capabilities/antigravity/capability.json b/capabilities/antigravity/capability.json index c36ea0100..996fb4191 100644 --- a/capabilities/antigravity/capability.json +++ b/capabilities/antigravity/capability.json @@ -1,7 +1,7 @@ { "id": "antigravity", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Antigravity", "description": "Google Antigravity IDE — nested under ~/.gemini/antigravity; probed across 1.x and 2.x layouts; Gemini hook event dialect; flat skill layout; tier-1 support.", "tier": "core", diff --git a/capabilities/assumption-delta/capability.json b/capabilities/assumption-delta/capability.json index 72e7ed215..4634ba396 100644 --- a/capabilities/assumption-delta/capability.json +++ b/capabilities/assumption-delta/capability.json @@ -1,7 +1,7 @@ { "id": "assumption-delta", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Assumption-delta architecture checkpoint", "description": "Rarely-firing advisory checkpoint that triggers when a phase makes something plural, optional, or chosen that used to be singular, required, or derived. Surfaces one identity-model question (promote the new general representation to primary, or add it alongside?) so a silent primary-key drift does not accumulate into a later user-facing bug. Non-blocking; fires only on a detected signal.", "tier": "full", diff --git a/capabilities/audit/capability.json b/capabilities/audit/capability.json index 675781ce8..0dd08f936 100644 --- a/capabilities/audit/capability.json +++ b/capabilities/audit/capability.json @@ -1,7 +1,7 @@ { "id": "audit", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Audit", "description": "Open-artifact audit and UAT-gap audit for milestone close gates; exposes `gsd-tools audit-uat` (cross-phase UAT outstanding items) and `gsd-tools audit-open` (structured open-artifact scan across debug, tasks, threads, todos, seeds, UAT, verification, context-questions).", "tier": "full", diff --git a/capabilities/augment/capability.json b/capabilities/augment/capability.json index a712d16f2..ffa16d6a9 100644 --- a/capabilities/augment/capability.json +++ b/capabilities/augment/capability.json @@ -1,7 +1,7 @@ { "id": "augment", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Augment Code", "description": "Augment Code CLI — commands + nested-skill artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", diff --git a/capabilities/claude-orchestration/capability.json b/capabilities/claude-orchestration/capability.json index 842901594..6c9dd8f1b 100644 --- a/capabilities/claude-orchestration/capability.json +++ b/capabilities/claude-orchestration/capability.json @@ -1,7 +1,7 @@ { "id": "claude-orchestration", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Claude orchestration (Workflow backend)", "description": "Default-off, BETA, claude-only capability that adopts Claude Code's Workflow tool (the engine behind /effort ultracode) as an optional parallel-execution backend for the GSD loop. When the runtime exposes the Workflow tool and claude_orchestration.execution_backend resolves to 'workflow', execute-phase emits a generated Workflow script (waves -> parallel() barriers, plans -> agent({ agentType: 'gsd-executor', isolation: 'worktree' }), files_modified overlap -> separate sequential stages, resumeFromRunId wired to the phase run id, shared token budget) that composes the SAME gsd-executor agent and worktree isolation the inline path uses, restoring the wave parallelism the #853 backgrounded-agent nesting limitation forces inline on Claude Code. (The plan-checker and verifier remain inline until separately wired — this capability delivers the parallel-execution backend, not those gates.) Also folds the ultraplan plan-offload under one runtime gate (plan:* surface). On any runtime lacking the Workflow tool, or when the capability is disabled, behaviour is byte-identical to today (inline/manual dispatch). Detection + emission live in gsd-core/bin/lib/claude-orchestration.cjs (pure, fail-closed). Mirrors the existing gsd-ultraplan-phase BETA-isolation posture.", "tier": "full", diff --git a/capabilities/claude/capability.json b/capabilities/claude/capability.json index e21c24d70..fa1dbcfd1 100644 --- a/capabilities/claude/capability.json +++ b/capabilities/claude/capability.json @@ -1,7 +1,7 @@ { "id": "claude", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Claude Code", "description": "Anthropic Claude Code — primary development runtime; tier-1 support with full hook surface and skills-based global install.", "tier": "core", diff --git a/capabilities/cline/capability.json b/capabilities/cline/capability.json index 2483ad168..7fb53a3a7 100644 --- a/capabilities/cline/capability.json +++ b/capabilities/cline/capability.json @@ -1,7 +1,7 @@ { "id": "cline", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Cline", "description": "Cline (VS Code extension) — global-only nested-skill layout; cline-rules hook surface (.clinerules); no hook events emitted; tier-2 support.", "tier": "core", diff --git a/capabilities/code-review/capability.json b/capabilities/code-review/capability.json index 2be81796c..acdcfe088 100644 --- a/capabilities/code-review/capability.json +++ b/capabilities/code-review/capability.json @@ -1,7 +1,7 @@ { "id": "code-review", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Code review", "description": "Source-file code review and review-fix workflow support for completed execution work.", "tier": "full", diff --git a/capabilities/codebuddy/capability.json b/capabilities/codebuddy/capability.json index c8abf8601..d915d5922 100644 --- a/capabilities/codebuddy/capability.json +++ b/capabilities/codebuddy/capability.json @@ -1,7 +1,7 @@ { "id": "codebuddy", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "CodeBuddy", "description": "CodeBuddy (Tencent) — converted commands + skills artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", diff --git a/capabilities/codex/capability.json b/capabilities/codex/capability.json index 5284ce383..ab5533549 100644 --- a/capabilities/codex/capability.json +++ b/capabilities/codex/capability.json @@ -1,7 +1,7 @@ { "id": "codex", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "OpenAI Codex CLI", "description": "OpenAI Codex CLI — shell-var command style; per-agent sandbox tiers; config.toml + hooks.json hook surface; tier-1 support.", "tier": "core", diff --git a/capabilities/copilot/capability.json b/capabilities/copilot/capability.json index 2a1360752..304c46c6c 100644 --- a/capabilities/copilot/capability.json +++ b/capabilities/copilot/capability.json @@ -1,7 +1,7 @@ { "id": "copilot", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "GitHub Copilot", "description": "GitHub Copilot (VS Code) — markdown config format; copilot-inline hook surface; no hook events emitted; flat skill nesting (unconfirmed recursive loader); tier-2 support.", "tier": "core", diff --git a/capabilities/cursor/capability.json b/capabilities/cursor/capability.json index 7b62af25a..69d5a3050 100644 --- a/capabilities/cursor/capability.json +++ b/capabilities/cursor/capability.json @@ -1,7 +1,7 @@ { "id": "cursor", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Cursor", "description": "Cursor IDE — skills + converted commands artifact layout; hooks.json surface; Claude hook event dialect; recursive skill loader (flat nesting); tier-2 support.", "tier": "core", diff --git a/capabilities/drift/capability.json b/capabilities/drift/capability.json index e3fd637a4..64539626c 100644 --- a/capabilities/drift/capability.json +++ b/capabilities/drift/capability.json @@ -1,7 +1,7 @@ { "id": "drift", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Drift detection gates", "description": "Drift detection gates for the planning loop. At execute:wave:post: a blocking schema drift gate (detects schema files changed without a database push) and a non-blocking codebase drift gate (detects structural additions not reflected in STRUCTURE.md). At plan:pre: a non-blocking, warn-only codebase drift gate (gated on workflow.plan_drift_precheck) that flags a stale codebase map before planning, so plans are authored against a fresh STRUCTURE.md instead of discovering drift mid-execution.", "tier": "full", diff --git a/capabilities/external-job/capability.json b/capabilities/external-job/capability.json index 358d9246a..5541349da 100644 --- a/capabilities/external-job/capability.json +++ b/capabilities/external-job/capability.json @@ -1,7 +1,7 @@ { "id": "external-job", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Async external-job scheduler adapter", "description": "Default-off producer of the async external-job manifest (#1164). At execute:wave:post an executor can externalize long-running compute (SLURM first, scheduler-pluggable), commit a .planning/async-jobs/.json manifest, defer SUMMARY.md, and return external_job_waiting. The core loop (#1165) consumes the manifest; this capability is the only thing that writes it. NOTE on contribution point: #1164 specifies execute:wave:pre, but execute-phase.md only dispatches execute:wave:post today (wave:pre is declared in the loop host contract but not rendered); wiring wave:pre dispatch is a core-loop change #1164 explicitly puts out of scope, so this capability registers at wave:post and the executor honors the runtime_budget classification guidance before running any tagged task. The adapter (scripts/slurm-adapter.cjs) reads external_job.submit_timeout_ms / poll_timeout_ms / artifact_dir through the canonical capability-config seam (env override > config > registry default).", "tier": "full", diff --git a/capabilities/gap-analysis/capability.json b/capabilities/gap-analysis/capability.json index 6b33d2b53..05f592e4d 100644 --- a/capabilities/gap-analysis/capability.json +++ b/capabilities/gap-analysis/capability.json @@ -1,7 +1,7 @@ { "id": "gap-analysis", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Post-planning gap analysis", "description": "Proactive, non-blocking post-planning coverage report. After all PLAN.md files are generated, cross-references every REQ-ID and D-ID from REQUIREMENTS.md and CONTEXT.md against plan bodies. Emits a Source | Item | Status table. Does not block phase advancement.", "tier": "standard", diff --git a/capabilities/graphify/capability.json b/capabilities/graphify/capability.json index e05e397e6..0b4d10610 100644 --- a/capabilities/graphify/capability.json +++ b/capabilities/graphify/capability.json @@ -1,7 +1,7 @@ { "id": "graphify", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Knowledge graph", "description": "Build, query, and inspect the project knowledge graph in `.planning/graphs/`; exposes graphify CLI subcommands (build, query, status, diff) and the /gsd-graphify skill.", "tier": "full", diff --git a/capabilities/hermes/capability.json b/capabilities/hermes/capability.json index 66a38aedf..a125f6893 100644 --- a/capabilities/hermes/capability.json +++ b/capabilities/hermes/capability.json @@ -1,7 +1,7 @@ { "id": "hermes", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Hermes Agent", "description": "Hermes Agent (NousResearch) — skills nest under skills/gsd/ category bucket; nested skill layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", diff --git a/capabilities/intel/capability.json b/capabilities/intel/capability.json index 7643f8942..f3a39a7ff 100644 --- a/capabilities/intel/capability.json +++ b/capabilities/intel/capability.json @@ -1,7 +1,7 @@ { "id": "intel", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Codebase intelligence", "description": "Code-intelligence store for codebase querying, diff, snapshot, and API-surface extraction; exposes `gsd-tools intel` subcommands (query, status, update, diff, snapshot, patch-meta, validate, extract-exports, api-surface) and backs `/gsd-map-codebase` and `gsd-intel-updater`.", "tier": "full", diff --git a/capabilities/kilo/capability.json b/capabilities/kilo/capability.json index 1afc8856c..fe8b82e58 100644 --- a/capabilities/kilo/capability.json +++ b/capabilities/kilo/capability.json @@ -1,7 +1,7 @@ { "id": "kilo", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Kilo Code", "description": "Kilo Code — XDG-based config dir; global skills at ~/.kilo/skills (separate from XDG config); flat command/ + skills artifact layout; no lifecycle hook registration; tier-2 support.", "tier": "core", diff --git a/capabilities/kimi/capability.json b/capabilities/kimi/capability.json index a9c359e87..23184955d 100644 --- a/capabilities/kimi/capability.json +++ b/capabilities/kimi/capability.json @@ -1,7 +1,7 @@ { "id": "kimi", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Kimi CLI", "description": "Kimi CLI (Moonshot AI) — generic agents root at ~/.config/agents; skills + kimi-agents artifact layout; native config.toml [[hooks]] bus at ~/.kimi/config.toml; background dispatch; tier-2 support.", "tier": "core", diff --git a/capabilities/mempalace/capability.json b/capabilities/mempalace/capability.json index 7d3f4e006..63ea31e1d 100644 --- a/capabilities/mempalace/capability.json +++ b/capabilities/mempalace/capability.json @@ -1,7 +1,7 @@ { "id": "mempalace", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "MemPalace memory", "description": "Cross-session, cross-project memory: deliberate recall before discuss/plan and verbatim capture + temporal-KG sync at phase boundaries, via the MemPalace MCP server and CLI.", "tier": "full", diff --git a/capabilities/nyquist/capability.json b/capabilities/nyquist/capability.json index 0b50ac63f..c6639c4fe 100644 --- a/capabilities/nyquist/capability.json +++ b/capabilities/nyquist/capability.json @@ -1,7 +1,7 @@ { "id": "nyquist", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Nyquist validation", "description": "Validation coverage audit that maps executed work back to tests and manual-only evidence.", "tier": "full", diff --git a/capabilities/opencode/capability.json b/capabilities/opencode/capability.json index 629d128cf..f18c39c5e 100644 --- a/capabilities/opencode/capability.json +++ b/capabilities/opencode/capability.json @@ -1,7 +1,7 @@ { "id": "opencode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "OpenCode", "description": "OpenCode — XDG-based config dir; flat command/ + skills artifact layout; settings-json config format; no lifecycle hook registration; tier-2 support.", "tier": "core", diff --git a/capabilities/pattern-mapper/capability.json b/capabilities/pattern-mapper/capability.json index 4f1bb7b66..a8086a88a 100644 --- a/capabilities/pattern-mapper/capability.json +++ b/capabilities/pattern-mapper/capability.json @@ -1,7 +1,7 @@ { "id": "pattern-mapper", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Pattern mapping", "description": "Optional codebase-pattern mapping before planning; owns the pattern mapper agent and workflow.pattern_mapper activation key.", "tier": "full", diff --git a/capabilities/pi/capability.json b/capabilities/pi/capability.json index f3b0b9094..caa54b1f4 100644 --- a/capabilities/pi/capability.json +++ b/capabilities/pi/capability.json @@ -1,7 +1,7 @@ { "id": "pi", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "pi", "description": "pi (pi.dev) — bun-runtime programmatic-CLI; TS ExtensionAPI (registerCommand/registerTool/registerProvider/pi.on); single native-extension file at ~/.pi/agent/extensions/gsd.cjs; no shared-settings hook surface; tier-2 support.", "tier": "core", diff --git a/capabilities/profile-pipeline/capability.json b/capabilities/profile-pipeline/capability.json index 77128ffcf..3293d8dcf 100644 --- a/capabilities/profile-pipeline/capability.json +++ b/capabilities/profile-pipeline/capability.json @@ -1,7 +1,7 @@ { "id": "profile-pipeline", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Developer profiling pipeline", "description": "Developer behavioral profiling from Claude Code session history; scans session JSONL files, extracts and samples user messages, and generates profile artifacts (USER-PROFILE.md, dev-preferences.md, CLAUDE.md sections). Exposes eight `gsd-tools` commands: scan-sessions, extract-messages, profile-sample (pipeline phase) and write-profile, profile-questionnaire, generate-dev-preferences, generate-claude-profile, generate-claude-md (output phase). Backs the /gsd-profile-user skill and gsd-user-profiler agent.", "tier": "full", diff --git a/capabilities/qwen/capability.json b/capabilities/qwen/capability.json index 6e8910404..65bc957be 100644 --- a/capabilities/qwen/capability.json +++ b/capabilities/qwen/capability.json @@ -1,7 +1,7 @@ { "id": "qwen", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Qwen Code", "description": "Qwen Code (Alibaba) — nested-skill artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -90,7 +90,11 @@ }, "hostBehaviors": { "skillPriorityFrontmatter": true, - "brandingRewrites": { "CLAUDE.md": "QWEN.md", "Claude Code": "Qwen Code", ".claude/": ".qwen/" }, + "brandingRewrites": { + "CLAUDE.md": "QWEN.md", + "Claude Code": "Qwen Code", + ".claude/": ".qwen/" + }, "legacyCommandsGsdCleanup": true, "legacyCommandsGsdInstallMigration": true, "legacyCommandsGsdUninstall": true, diff --git a/capabilities/research/capability.json b/capabilities/research/capability.json index 0b8ff6dcd..1715811c5 100644 --- a/capabilities/research/capability.json +++ b/capabilities/research/capability.json @@ -1,7 +1,7 @@ { "id": "research", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Phase research", "description": "Optional phase research before planning; owns the phase researcher agent and workflow.research activation key.", "tier": "standard", diff --git a/capabilities/schema-gate/capability.json b/capabilities/schema-gate/capability.json index 949d56acd..f00c9feb4 100644 --- a/capabilities/schema-gate/capability.json +++ b/capabilities/schema-gate/capability.json @@ -1,7 +1,7 @@ { "id": "schema-gate", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Schema push detection gate", "description": "Detects ORM schema-relevant files in the phase scope during planning and injects a mandatory [BLOCKING] schema push task into the plan. Prevents false-positive verification where build/types pass because TypeScript types come from config, not the live database.", "tier": "full", diff --git a/capabilities/security/capability.json b/capabilities/security/capability.json index c44157dbc..268351cf3 100644 --- a/capabilities/security/capability.json +++ b/capabilities/security/capability.json @@ -1,7 +1,7 @@ { "id": "security", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Security enforcement", "description": "Threat mitigation verification and ship-time security blocking for phases with security enforcement enabled.", "tier": "full", diff --git a/capabilities/tdd/capability.json b/capabilities/tdd/capability.json index 2076ffa2e..a181bc3b4 100644 --- a/capabilities/tdd/capability.json +++ b/capabilities/tdd/capability.json @@ -1,7 +1,7 @@ { "id": "tdd", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Test-driven development", "description": "Injects TDD heuristics into the planner and enforces RED/GREEN gate compliance on type:tdd plans after execution. Owns workflow.tdd_mode; the --tdd CLI flag is the ephemeral override.", "tier": "full", diff --git a/capabilities/trae/capability.json b/capabilities/trae/capability.json index 35cf1aa42..350ff2117 100644 --- a/capabilities/trae/capability.json +++ b/capabilities/trae/capability.json @@ -1,7 +1,7 @@ { "id": "trae", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Trae IDE", "description": "Trae IDE — nested-skill artifact layout; no hook surface (profile-marker-only config); tier-2 support.", "tier": "core", diff --git a/capabilities/ui/capability.json b/capabilities/ui/capability.json index e19a961a7..a1539f2dd 100644 --- a/capabilities/ui/capability.json +++ b/capabilities/ui/capability.json @@ -1,7 +1,7 @@ { "id": "ui", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "UI design contracts", "description": "UI-SPEC design contract + retrospective UI audit for frontend phases.", "tier": "full", diff --git a/capabilities/vscode/capability.json b/capabilities/vscode/capability.json index aeccd0ee2..bad8ac769 100644 --- a/capabilities/vscode/capability.json +++ b/capabilities/vscode/capability.json @@ -1,7 +1,7 @@ { "id": "vscode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "VS Code", "description": "VS Code — Marketplace/VSIX extension; no file-projected config directory; IDE-profile reference host (active vscode.lm model, engine-owned hook bus, sandboxed globalState/workspaceState stateIO).", "tier": "core", diff --git a/capabilities/windsurf/capability.json b/capabilities/windsurf/capability.json index a887418cd..5c99b40f4 100644 --- a/capabilities/windsurf/capability.json +++ b/capabilities/windsurf/capability.json @@ -1,7 +1,7 @@ { "id": "windsurf", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Windsurf", "description": "Windsurf (Codeium) — workspace workflow artifact layout for slash commands; Cascade native hooks.json blocking hook bus (pre_write_code, pre_run_command); tier-2 support.", "tier": "core", diff --git a/capabilities/zcode/capability.json b/capabilities/zcode/capability.json index 59555b7a4..b86ee3abf 100644 --- a/capabilities/zcode/capability.json +++ b/capabilities/zcode/capability.json @@ -1,7 +1,7 @@ { "id": "zcode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "ZCode", "description": "ZCode (Z.ai) — desktop Agentic Development Environment for GLM-5.2; Claude-shaped nested skills at ~/.zcode/skills//SKILL.md, slash commands, named subagents, native MCP; declarative plugin surface; profile-marker install; tier-2 community support.", "tier": "core", diff --git a/docs/FEATURES.md b/docs/FEATURES.md index cf0c3afe6..9b7540314 100644 --- a/docs/FEATURES.md +++ b/docs/FEATURES.md @@ -2267,15 +2267,15 @@ Test suite that scans all agent, workflow, and command files for embedded inject ### 99. Improved Prompt Injection Scanner -**Hook:** `gsd-prompt-guard.js` -**Script:** `scripts/prompt-injection-scan.sh` +**Hook:** `gsd-prompt-guard.js`, `gsd-read-injection-scanner.js` +**Script:** `scripts/prompt-injection-scan.sh`, `scripts/base64-scan.sh` -**Purpose:** Enhanced detection of prompt injection attempts in planning artifacts, adding invisible Unicode character detection, encoding obfuscation patterns, and entropy-based analysis. +**Purpose:** Defense-in-depth detection of prompt injection attempts in planning artifacts and ingested content. Live hooks inline their own pattern subsets for hook independence (they do not import from `security.cts`). The CI scanner (`scanForInjection` in `security.cts`) provides a centralized engine for codebase-wide scanning in tests. **Requirements:** -- REQ-SCAN-INJ-01: Scanner MUST detect invisible Unicode characters (zero-width spaces, soft hyphens, etc.) -- REQ-SCAN-INJ-02: Scanner MUST detect encoding obfuscation patterns (base64-encoded instructions, homoglyphs) -- REQ-SCAN-INJ-03: Scanner MUST apply entropy analysis to flag high-entropy strings in unexpected positions +- REQ-SCAN-INJ-01: Live hooks MUST detect invisible Unicode characters (zero-width spaces, soft hyphens, Unicode tag block U+E0000–E007F) +- REQ-SCAN-INJ-02: Live hooks MUST detect known injection patterns (instruction override, role manipulation, system-prompt extraction, fake message boundaries). Base64-decode scanning is a CI-time control (`scripts/base64-scan.sh`), not a live hook — live hooks match a base64-exfiltration phrase regex only, they do not decode. +- REQ-SCAN-INJ-03: ~~Scanner MUST apply entropy analysis~~ — Entropy analysis (`scanEntropyAnomalies`) was removed in #2198 as dead code (zero production callers; live hooks do not perform entropy analysis). This requirement is deferred pending a maintainable live implementation. - REQ-SCAN-INJ-04: Scanner MUST remain advisory-only — detection is logged, not blocking --- diff --git a/docs/ja-JP/FEATURES.md b/docs/ja-JP/FEATURES.md index 0e65982f6..f6f2619ad 100644 --- a/docs/ja-JP/FEATURES.md +++ b/docs/ja-JP/FEATURES.md @@ -2195,15 +2195,15 @@ Claude が GSD ワークフローコンテキスト外でファイル編集を ### 99. 改善されたプロンプトインジェクションスキャナー -**フック:** `gsd-prompt-guard.js` -**スクリプト:** `scripts/prompt-injection-scan.sh` +**フック:** `gsd-prompt-guard.js`、`gsd-read-injection-scanner.js` +**スクリプト:** `scripts/prompt-injection-scan.sh`、`scripts/base64-scan.sh` -**目的:** プランニングアーティファクト内のプロンプトインジェクション試みの検出を強化し、不可視 Unicode 文字検出、エンコードの難読化パターン、エントロピーベースの分析を追加します。 +**目的:** プランニングアーティファクトおよび取り込んだコンテンツ内のプロンプトインジェクション試行の多層防御検出。ライブフックはフック独立性のために独自のパターンサブセットをインライン化します(`security.cts` からインポートしません)。CIスキャナー(`security.cts` の `scanForInjection`)は、テストでのコードベース全体スキャン用の集中エンジンを提供します。 **要件:** -- REQ-SCAN-INJ-01: スキャナーは不可視 Unicode 文字(ゼロ幅スペース、ソフトハイフンなど)を検出しなければならない -- REQ-SCAN-INJ-02: スキャナーはエンコードの難読化パターン(base64 エンコードされた命令、ホモグリフ)を検出しなければならない -- REQ-SCAN-INJ-03: スキャナーは予期しない位置の高エントロピー文字列にフラグを立てるためにエントロピー分析を適用しなければならない +- REQ-SCAN-INJ-01: ライブフックは不可視 Unicode 文字(ゼロ幅スペース、ソフトハイフン、Unicode タグブロック U+E0000–E007F)を検出しなければならない +- REQ-SCAN-INJ-02: ライブフックは既知のインジェクションパターン(命令オーバーライド、ロール操作、システムプロンプト抽出、偽のメッセージ境界)を検出しなければならない。Base64 デコードスキャンは CI 時制御(`scripts/base64-scan.sh`)であり、ライブフックではない — ライブフックは base64 持ち出しフレーズ正規表現のみを一致させ、デコードはしない。 +- REQ-SCAN-INJ-03: ~~スキャナーはエントロピー分析を適用しなければならない~~ — エントロピー分析(`scanEntropyAnomalies`)は #2198 でデッドコードとして削除された(本番呼び出し元ゼロ;ライブフックはエントロピー分析を実行しない)。この要件は保守可能なライブ実装まで保留。 - REQ-SCAN-INJ-04: スキャナーは勧告的のみでなければならない — 検出はログに記録されるが、ブロッキングではない --- diff --git a/docs/security/baseline.md b/docs/security/baseline.md index aa3dbb151..64c53cf43 100644 --- a/docs/security/baseline.md +++ b/docs/security/baseline.md @@ -133,11 +133,16 @@ file before the job passes. ### 2.4 Locale-safe text scanning -**Control:** Text output and user-facing strings are scanned for locale-unsafe -constructs (non-ASCII homoglyphs, bidirectional override characters, invisible -Unicode) that could be used to obscure malicious content in diffs or logs. +**Control:** Text output and user-facing strings are scanned for invisible +Unicode and bidirectional override characters that could be used to obscure +malicious content in diffs or logs. The live hooks +(`gsd-prompt-guard.js`, `gsd-read-injection-scanner.js`) inline their own +Unicode-detection patterns for hook independence — they do not call +`scanForInjection` from `security.cts`. The centralized `scanForInjection` +function serves as the CI codebase-scanner engine +(`tests/prompt-injection-scan.security.test.cjs`). -**Why it matters:** Unicode homoglyph and BiDi attacks are documented +**Why it matters:** Unicode invisible-character and BiDi attacks are documented supply-chain vectors (CVE-2021-42574 — "Trojan Source"). Detecting them at scan time prevents invisible payload injection in source and output files. diff --git a/docs/zh-CN/FEATURES.md b/docs/zh-CN/FEATURES.md index 3d9e87e08..cb8961f3f 100644 --- a/docs/zh-CN/FEATURES.md +++ b/docs/zh-CN/FEATURES.md @@ -2211,15 +2211,15 @@ PreToolUse 钩子,检测 Claude 在 GSD 工作流上下文之外尝试文件 ### 99. 改进的提示注入扫描器 -**钩子:** `gsd-prompt-guard.js` -**脚本:** `scripts/prompt-injection-scan.sh` +**钩子:** `gsd-prompt-guard.js`、`gsd-read-injection-scanner.js` +**脚本:** `scripts/prompt-injection-scan.sh`、`scripts/base64-scan.sh` -**目的:** 增强对规划构件中提示注入尝试的检测,添加不可见 Unicode 字符检测、编码混淆模式和基于熵的分析。 +**目的:** 对规划构件和摄入内容中提示注入尝试的深度防御检测。实时钩子为保持独立性内联了自己的模式子集(不导入 `security.cts`)。CI 扫描器(`security.cts` 中的 `scanForInjection`)为测试中的全代码库扫描提供集中引擎。 **需求:** -- REQ-SCAN-INJ-01:扫描器必须检测不可见 Unicode 字符(零宽空格、软连字符等) -- REQ-SCAN-INJ-02:扫描器必须检测编码混淆模式(base64 编码的指令、同形字) -- REQ-SCAN-INJ-03:扫描器必须应用熵分析以标记意外位置的高熵字符串 +- REQ-SCAN-INJ-01:实时钩子必须检测不可见 Unicode 字符(零宽空格、软连字符、Unicode 标签块 U+E0000–E007F) +- REQ-SCAN-INJ-02:实时钩子必须检测已知注入模式(指令覆盖、角色操纵、系统提示提取、伪造消息边界)。Base64 解码扫描是 CI 时控制(`scripts/base64-scan.sh`),不是实时钩子 — 实时钩子仅匹配 base64 外泄短语正则,不解码。 +- REQ-SCAN-INJ-03:~~扫描器必须应用熵分析~~ — 熵分析(`scanEntropyAnomalies`)在 #2198 中作为死代码被移除(零生产调用者;实时钩子不执行熵分析)。此需求推迟到有可维护的实时实现时。 - REQ-SCAN-INJ-04:扫描器必须保持仅建议性 — 检测会被记录,而不会阻止 --- diff --git a/gsd-core/bin/lib/capability-registry.cjs b/gsd-core/bin/lib/capability-registry.cjs index 80bc9001a..9bbdf5103 100644 --- a/gsd-core/bin/lib/capability-registry.cjs +++ b/gsd-core/bin/lib/capability-registry.cjs @@ -10,7 +10,7 @@ const capabilities = { "ai-integration": { "id": "ai-integration", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "AI design contract", "description": "AI-SPEC design contract workflow for phases that build AI systems; owns the AI integration command, agents, and workflow.ai_integration_phase activation key.", "tier": "full", @@ -95,7 +95,7 @@ const capabilities = { "antigravity": { "id": "antigravity", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Antigravity", "description": "Google Antigravity IDE — nested under ~/.gemini/antigravity; probed across 1.x and 2.x layouts; Gemini hook event dialect; flat skill layout; tier-1 support.", "tier": "core", @@ -196,7 +196,7 @@ const capabilities = { "assumption-delta": { "id": "assumption-delta", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Assumption-delta architecture checkpoint", "description": "Rarely-firing advisory checkpoint that triggers when a phase makes something plural, optional, or chosen that used to be singular, required, or derived. Surfaces one identity-model question (promote the new general representation to primary, or add it alongside?) so a silent primary-key drift does not accumulate into a later user-facing bug. Non-blocking; fires only on a detected signal.", "tier": "full", @@ -242,7 +242,7 @@ const capabilities = { "audit": { "id": "audit", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Audit", "description": "Open-artifact audit and UAT-gap audit for milestone close gates; exposes `gsd-tools audit-uat` (cross-phase UAT outstanding items) and `gsd-tools audit-open` (structured open-artifact scan across debug, tasks, threads, todos, seeds, UAT, verification, context-questions).", "tier": "full", @@ -279,7 +279,7 @@ const capabilities = { "augment": { "id": "augment", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Augment Code", "description": "Augment Code CLI — commands + nested-skill artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -386,7 +386,7 @@ const capabilities = { "claude": { "id": "claude", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Claude Code", "description": "Anthropic Claude Code — primary development runtime; tier-1 support with full hook surface and skills-based global install.", "tier": "core", @@ -491,7 +491,7 @@ const capabilities = { "claude-orchestration": { "id": "claude-orchestration", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Claude orchestration (Workflow backend)", "description": "Default-off, BETA, claude-only capability that adopts Claude Code's Workflow tool (the engine behind /effort ultracode) as an optional parallel-execution backend for the GSD loop. When the runtime exposes the Workflow tool and claude_orchestration.execution_backend resolves to 'workflow', execute-phase emits a generated Workflow script (waves -> parallel() barriers, plans -> agent({ agentType: 'gsd-executor', isolation: 'worktree' }), files_modified overlap -> separate sequential stages, resumeFromRunId wired to the phase run id, shared token budget) that composes the SAME gsd-executor agent and worktree isolation the inline path uses, restoring the wave parallelism the #853 backgrounded-agent nesting limitation forces inline on Claude Code. (The plan-checker and verifier remain inline until separately wired — this capability delivers the parallel-execution backend, not those gates.) Also folds the ultraplan plan-offload under one runtime gate (plan:* surface). On any runtime lacking the Workflow tool, or when the capability is disabled, behaviour is byte-identical to today (inline/manual dispatch). Detection + emission live in gsd-core/bin/lib/claude-orchestration.cjs (pure, fail-closed). Mirrors the existing gsd-ultraplan-phase BETA-isolation posture.", "tier": "full", @@ -578,7 +578,7 @@ const capabilities = { "cline": { "id": "cline", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Cline", "description": "Cline (VS Code extension) — global-only nested-skill layout; cline-rules hook surface (.clinerules); no hook events emitted; tier-2 support.", "tier": "core", @@ -647,7 +647,7 @@ const capabilities = { "code-review": { "id": "code-review", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Code review", "description": "Source-file code review and review-fix workflow support for completed execution work.", "tier": "full", @@ -708,7 +708,7 @@ const capabilities = { "codebuddy": { "id": "codebuddy", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "CodeBuddy", "description": "CodeBuddy (Tencent) — converted commands + skills artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -819,7 +819,7 @@ const capabilities = { "codex": { "id": "codex", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "OpenAI Codex CLI", "description": "OpenAI Codex CLI — shell-var command style; per-agent sandbox tiers; config.toml + hooks.json hook surface; tier-1 support.", "tier": "core", @@ -904,7 +904,7 @@ const capabilities = { "copilot": { "id": "copilot", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "GitHub Copilot", "description": "GitHub Copilot (VS Code) — markdown config format; copilot-inline hook surface; no hook events emitted; flat skill nesting (unconfirmed recursive loader); tier-2 support.", "tier": "core", @@ -997,7 +997,7 @@ const capabilities = { "cursor": { "id": "cursor", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Cursor", "description": "Cursor IDE — skills + converted commands artifact layout; hooks.json surface; Claude hook event dialect; recursive skill loader (flat nesting); tier-2 support.", "tier": "core", @@ -1118,7 +1118,7 @@ const capabilities = { "drift": { "id": "drift", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Drift detection gates", "description": "Drift detection gates for the planning loop. At execute:wave:post: a blocking schema drift gate (detects schema files changed without a database push) and a non-blocking codebase drift gate (detects structural additions not reflected in STRUCTURE.md). At plan:pre: a non-blocking, warn-only codebase drift gate (gated on workflow.plan_drift_precheck) that flags a stale codebase map before planning, so plans are authored against a fresh STRUCTURE.md instead of discovering drift mid-execution.", "tier": "full", @@ -1196,7 +1196,7 @@ const capabilities = { "external-job": { "id": "external-job", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Async external-job scheduler adapter", "description": "Default-off producer of the async external-job manifest (#1164). At execute:wave:post an executor can externalize long-running compute (SLURM first, scheduler-pluggable), commit a .planning/async-jobs/.json manifest, defer SUMMARY.md, and return external_job_waiting. The core loop (#1165) consumes the manifest; this capability is the only thing that writes it. NOTE on contribution point: #1164 specifies execute:wave:pre, but execute-phase.md only dispatches execute:wave:post today (wave:pre is declared in the loop host contract but not rendered); wiring wave:pre dispatch is a core-loop change #1164 explicitly puts out of scope, so this capability registers at wave:post and the executor honors the runtime_budget classification guidance before running any tagged task. The adapter (scripts/slurm-adapter.cjs) reads external_job.submit_timeout_ms / poll_timeout_ms / artifact_dir through the canonical capability-config seam (env override > config > registry default).", "tier": "full", @@ -1279,7 +1279,7 @@ const capabilities = { "gap-analysis": { "id": "gap-analysis", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Post-planning gap analysis", "description": "Proactive, non-blocking post-planning coverage report. After all PLAN.md files are generated, cross-references every REQ-ID and D-ID from REQUIREMENTS.md and CONTEXT.md against plan bodies. Emits a Source | Item | Status table. Does not block phase advancement.", "tier": "standard", @@ -1320,7 +1320,7 @@ const capabilities = { "graphify": { "id": "graphify", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Knowledge graph", "description": "Build, query, and inspect the project knowledge graph in `.planning/graphs/`; exposes graphify CLI subcommands (build, query, status, diff) and the /gsd-graphify skill.", "tier": "full", @@ -1361,7 +1361,7 @@ const capabilities = { "hermes": { "id": "hermes", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Hermes Agent", "description": "Hermes Agent (NousResearch) — skills nest under skills/gsd/ category bucket; nested skill layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -1450,7 +1450,7 @@ const capabilities = { "intel": { "id": "intel", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Codebase intelligence", "description": "Code-intelligence store for codebase querying, diff, snapshot, and API-surface extraction; exposes `gsd-tools intel` subcommands (query, status, update, diff, snapshot, patch-meta, validate, extract-exports, api-surface) and backs `/gsd-map-codebase` and `gsd-intel-updater`.", "tier": "full", @@ -1502,7 +1502,7 @@ const capabilities = { "kilo": { "id": "kilo", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Kilo Code", "description": "Kilo Code — XDG-based config dir; global skills at ~/.kilo/skills (separate from XDG config); flat command/ + skills artifact layout; no lifecycle hook registration; tier-2 support.", "tier": "core", @@ -1610,7 +1610,7 @@ const capabilities = { "kimi": { "id": "kimi", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Kimi CLI", "description": "Kimi CLI (Moonshot AI) — generic agents root at ~/.config/agents; skills + kimi-agents artifact layout; native config.toml [[hooks]] bus at ~/.kimi/config.toml; background dispatch; tier-2 support.", "tier": "core", @@ -1698,7 +1698,7 @@ const capabilities = { "mempalace": { "id": "mempalace", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "MemPalace memory", "description": "Cross-session, cross-project memory: deliberate recall before discuss/plan and verbatim capture + temporal-KG sync at phase boundaries, via the MemPalace MCP server and CLI.", "tier": "full", @@ -1872,7 +1872,7 @@ const capabilities = { "nyquist": { "id": "nyquist", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Nyquist validation", "description": "Validation coverage audit that maps executed work back to tests and manual-only evidence.", "tier": "full", @@ -1922,7 +1922,7 @@ const capabilities = { "opencode": { "id": "opencode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "OpenCode", "description": "OpenCode — XDG-based config dir; flat command/ + skills artifact layout; settings-json config format; no lifecycle hook registration; tier-2 support.", "tier": "core", @@ -2028,7 +2028,7 @@ const capabilities = { "pattern-mapper": { "id": "pattern-mapper", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Pattern mapping", "description": "Optional codebase-pattern mapping before planning; owns the pattern mapper agent and workflow.pattern_mapper activation key.", "tier": "full", @@ -2082,7 +2082,7 @@ const capabilities = { "pi": { "id": "pi", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "pi", "description": "pi (pi.dev) — bun-runtime programmatic-CLI; TS ExtensionAPI (registerCommand/registerTool/registerProvider/pi.on); single native-extension file at ~/.pi/agent/extensions/gsd.cjs; no shared-settings hook surface; tier-2 support.", "tier": "core", @@ -2142,7 +2142,7 @@ const capabilities = { "profile-pipeline": { "id": "profile-pipeline", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Developer profiling pipeline", "description": "Developer behavioral profiling from Claude Code session history; scans session JSONL files, extracts and samples user messages, and generates profile artifacts (USER-PROFILE.md, dev-preferences.md, CLAUDE.md sections). Exposes eight `gsd-tools` commands: scan-sessions, extract-messages, profile-sample (pipeline phase) and write-profile, profile-questionnaire, generate-dev-preferences, generate-claude-profile, generate-claude-md (output phase). Backs the /gsd-profile-user skill and gsd-user-profiler agent.", "tier": "full", @@ -2219,7 +2219,7 @@ const capabilities = { "qwen": { "id": "qwen", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Qwen Code", "description": "Qwen Code (Alibaba) — nested-skill artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -2324,7 +2324,7 @@ const capabilities = { "research": { "id": "research", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Phase research", "description": "Optional phase research before planning; owns the phase researcher agent and workflow.research activation key.", "tier": "standard", @@ -2376,7 +2376,7 @@ const capabilities = { "schema-gate": { "id": "schema-gate", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Schema push detection gate", "description": "Detects ORM schema-relevant files in the phase scope during planning and injects a mandatory [BLOCKING] schema push task into the plan. Prevents false-positive verification where build/types pass because TypeScript types come from config, not the live database.", "tier": "full", @@ -2422,7 +2422,7 @@ const capabilities = { "security": { "id": "security", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Security enforcement", "description": "Threat mitigation verification and ship-time security blocking for phases with security enforcement enabled.", "tier": "full", @@ -2521,7 +2521,7 @@ const capabilities = { "tdd": { "id": "tdd", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Test-driven development", "description": "Injects TDD heuristics into the planner and enforces RED/GREEN gate compliance on type:tdd plans after execution. Owns workflow.tdd_mode; the --tdd CLI flag is the ephemeral override.", "tier": "full", @@ -2574,7 +2574,7 @@ const capabilities = { "trae": { "id": "trae", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Trae IDE", "description": "Trae IDE — nested-skill artifact layout; no hook surface (profile-marker-only config); tier-2 support.", "tier": "core", @@ -2664,7 +2664,7 @@ const capabilities = { "ui": { "id": "ui", "role": "feature", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "UI design contracts", "description": "UI-SPEC design contract + retrospective UI audit for frontend phases.", "tier": "full", @@ -2759,7 +2759,7 @@ const capabilities = { "vscode": { "id": "vscode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "VS Code", "description": "VS Code — Marketplace/VSIX extension; no file-projected config directory; IDE-profile reference host (active vscode.lm model, engine-owned hook bus, sandboxed globalState/workspaceState stateIO).", "tier": "core", @@ -2810,7 +2810,7 @@ const capabilities = { "windsurf": { "id": "windsurf", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Windsurf", "description": "Windsurf (Codeium) — workspace workflow artifact layout for slash commands; Cascade native hooks.json blocking hook bus (pre_write_code, pre_run_command); tier-2 support.", "tier": "core", @@ -2895,7 +2895,7 @@ const capabilities = { "zcode": { "id": "zcode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "ZCode", "description": "ZCode (Z.ai) — desktop Agentic Development Environment for GLM-5.2; Claude-shaped nested skills at ~/.zcode/skills//SKILL.md, slash commands, named subagents, native MCP; declarative plugin surface; profile-marker install; tier-2 community support.", "tier": "core", @@ -3906,7 +3906,7 @@ const runtimes = { "antigravity": { "id": "antigravity", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Antigravity", "description": "Google Antigravity IDE — nested under ~/.gemini/antigravity; probed across 1.x and 2.x layouts; Gemini hook event dialect; flat skill layout; tier-1 support.", "tier": "core", @@ -4007,7 +4007,7 @@ const runtimes = { "augment": { "id": "augment", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Augment Code", "description": "Augment Code CLI — commands + nested-skill artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -4114,7 +4114,7 @@ const runtimes = { "claude": { "id": "claude", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Claude Code", "description": "Anthropic Claude Code — primary development runtime; tier-1 support with full hook surface and skills-based global install.", "tier": "core", @@ -4219,7 +4219,7 @@ const runtimes = { "cline": { "id": "cline", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Cline", "description": "Cline (VS Code extension) — global-only nested-skill layout; cline-rules hook surface (.clinerules); no hook events emitted; tier-2 support.", "tier": "core", @@ -4288,7 +4288,7 @@ const runtimes = { "codebuddy": { "id": "codebuddy", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "CodeBuddy", "description": "CodeBuddy (Tencent) — converted commands + skills artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -4399,7 +4399,7 @@ const runtimes = { "codex": { "id": "codex", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "OpenAI Codex CLI", "description": "OpenAI Codex CLI — shell-var command style; per-agent sandbox tiers; config.toml + hooks.json hook surface; tier-1 support.", "tier": "core", @@ -4484,7 +4484,7 @@ const runtimes = { "copilot": { "id": "copilot", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "GitHub Copilot", "description": "GitHub Copilot (VS Code) — markdown config format; copilot-inline hook surface; no hook events emitted; flat skill nesting (unconfirmed recursive loader); tier-2 support.", "tier": "core", @@ -4577,7 +4577,7 @@ const runtimes = { "cursor": { "id": "cursor", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Cursor", "description": "Cursor IDE — skills + converted commands artifact layout; hooks.json surface; Claude hook event dialect; recursive skill loader (flat nesting); tier-2 support.", "tier": "core", @@ -4698,7 +4698,7 @@ const runtimes = { "hermes": { "id": "hermes", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Hermes Agent", "description": "Hermes Agent (NousResearch) — skills nest under skills/gsd/ category bucket; nested skill layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -4787,7 +4787,7 @@ const runtimes = { "kilo": { "id": "kilo", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Kilo Code", "description": "Kilo Code — XDG-based config dir; global skills at ~/.kilo/skills (separate from XDG config); flat command/ + skills artifact layout; no lifecycle hook registration; tier-2 support.", "tier": "core", @@ -4895,7 +4895,7 @@ const runtimes = { "kimi": { "id": "kimi", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Kimi CLI", "description": "Kimi CLI (Moonshot AI) — generic agents root at ~/.config/agents; skills + kimi-agents artifact layout; native config.toml [[hooks]] bus at ~/.kimi/config.toml; background dispatch; tier-2 support.", "tier": "core", @@ -4983,7 +4983,7 @@ const runtimes = { "opencode": { "id": "opencode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "OpenCode", "description": "OpenCode — XDG-based config dir; flat command/ + skills artifact layout; settings-json config format; no lifecycle hook registration; tier-2 support.", "tier": "core", @@ -5089,7 +5089,7 @@ const runtimes = { "pi": { "id": "pi", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "pi", "description": "pi (pi.dev) — bun-runtime programmatic-CLI; TS ExtensionAPI (registerCommand/registerTool/registerProvider/pi.on); single native-extension file at ~/.pi/agent/extensions/gsd.cjs; no shared-settings hook surface; tier-2 support.", "tier": "core", @@ -5149,7 +5149,7 @@ const runtimes = { "qwen": { "id": "qwen", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Qwen Code", "description": "Qwen Code (Alibaba) — nested-skill artifact layout; settings-json hook surface; Claude hook event dialect; tier-2 support.", "tier": "core", @@ -5254,7 +5254,7 @@ const runtimes = { "trae": { "id": "trae", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Trae IDE", "description": "Trae IDE — nested-skill artifact layout; no hook surface (profile-marker-only config); tier-2 support.", "tier": "core", @@ -5344,7 +5344,7 @@ const runtimes = { "vscode": { "id": "vscode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "VS Code", "description": "VS Code — Marketplace/VSIX extension; no file-projected config directory; IDE-profile reference host (active vscode.lm model, engine-owned hook bus, sandboxed globalState/workspaceState stateIO).", "tier": "core", @@ -5395,7 +5395,7 @@ const runtimes = { "windsurf": { "id": "windsurf", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "Windsurf", "description": "Windsurf (Codeium) — workspace workflow artifact layout for slash commands; Cascade native hooks.json blocking hook bus (pre_write_code, pre_run_command); tier-2 support.", "tier": "core", @@ -5480,7 +5480,7 @@ const runtimes = { "zcode": { "id": "zcode", "role": "runtime", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "title": "ZCode", "description": "ZCode (Z.ai) — desktop Agentic Development Environment for GLM-5.2; Claude-shaped nested skills at ~/.zcode/skills//SKILL.md, slash commands, named subagents, native MCP; declarative plugin surface; profile-marker install; tier-2 community support.", "tier": "core", diff --git a/gsd-core/templates/VALIDATION.md b/gsd-core/templates/VALIDATION.md index 6adaf46d6..376e29e6f 100644 --- a/gsd-core/templates/VALIDATION.md +++ b/gsd-core/templates/VALIDATION.md @@ -1,6 +1,8 @@ --- phase: {N} slug: {phase-slug} +# status lifecycle: draft (seeded by plan-phase) → validated (set by validate-phase §6) +# audit-milestone §5.5 distinguishes NOT-VALIDATED (draft) from PARTIAL (validated + nyquist_compliant: false) (#2117) status: draft nyquist_compliant: false wave_0_complete: false diff --git a/gsd-core/workflows/audit-milestone.md b/gsd-core/workflows/audit-milestone.md index ce726e2db..b42cb3c31 100644 --- a/gsd-core/workflows/audit-milestone.md +++ b/gsd-core/workflows/audit-milestone.md @@ -153,17 +153,20 @@ Resolve active step hooks from `VERIFY_POST_HOOKS_JSON` where `kind == "step"` a If no active validate-phase step hook exists: skip entirely. -For each phase directory, check `*-VALIDATION.md`. If exists, parse frontmatter (`nyquist_compliant`, `wave_0_complete`). +For each phase directory, check `*-VALIDATION.md`. If exists, parse frontmatter (`status`, `nyquist_compliant`, `wave_0_complete`). Classify per phase: | Status | Condition | |--------|-----------| -| COMPLIANT | `nyquist_compliant: true` and all tasks green | -| PARTIAL | VALIDATION.md exists, `nyquist_compliant: false` or red/pending | +| COMPLIANT | `status: validated` and `nyquist_compliant: true` and all tasks green | +| PARTIAL | `status: validated` and (`nyquist_compliant: false` or red/pending) | +| NOT-VALIDATED | `status: draft` (or absent) — validate-phase has not yet reconciled this file (#2117) | | MISSING | No VALIDATION.md | -Add to audit YAML: `nyquist: { compliant_phases, partial_phases, missing_phases, overall }` +> **NOT-VALIDATED vs PARTIAL (#2117):** A phase reads `status: draft` when it was seeded by plan-phase but never reconciled by validate-phase, OR when its `VALIDATION.md` predates the `status` field (files written before #2117 stay `draft` whether or not validation ran). In both cases `nyquist_compliant` is not authoritative, so this is a coverage TODO ("run validate-phase") — not a compliance failure. Re-running validate-phase promotes the file to `status: validated` and yields the real COMPLIANT/PARTIAL verdict. Only `status: validated` + `nyquist_compliant: false` is a genuine PARTIAL. + +Add to audit YAML: `nyquist: { compliant_phases, partial_phases, not_validated_phases, missing_phases, overall }` Discovery only — never auto-calls `/gsd:validate-phase`. diff --git a/gsd-core/workflows/validate-phase.md b/gsd-core/workflows/validate-phase.md index d529c64c3..f2e817189 100644 --- a/gsd-core/workflows/validate-phase.md +++ b/gsd-core/workflows/validate-phase.md @@ -122,11 +122,11 @@ Handle return: **State B (create):** 1. Read template from `~/.claude/gsd-core/templates/VALIDATION.md` -2. Fill: frontmatter, Test Infrastructure, Per-Task Map, Manual-Only, Sign-Off +2. Fill: frontmatter (**set `status: validated`**), Test Infrastructure, Per-Task Map, Manual-Only, Sign-Off 3. Write to `${PHASE_DIR}/${PADDED_PHASE}-VALIDATION.md` **State A (update):** -1. Update Per-Task Map statuses, add escalated to Manual-Only, update frontmatter +1. Update Per-Task Map statuses, add escalated to Manual-Only, update frontmatter (**set `status: validated`**) 2. Append audit trail: ```markdown diff --git a/package-lock.json b/package-lock.json index 85ab981b0..98b85e5ea 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@opengsd/gsd-core", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@opengsd/gsd-core", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "license": "MIT", "dependencies": { "@anthropic-ai/claude-agent-sdk": "^0.2.84", diff --git a/package.json b/package.json index 6cd0b78bc..9d0353524 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@opengsd/gsd-core", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "description": "GSD Core is a meta-prompting, context engineering, and spec-driven development system for AI coding agents.", "main": ".opencode/plugins/gsd-core.js", "bin": { diff --git a/scripts/lint-test-file-count.allowlist.json b/scripts/lint-test-file-count.allowlist.json index ca863bc9c..77734cac6 100644 --- a/scripts/lint-test-file-count.allowlist.json +++ b/scripts/lint-test-file-count.allowlist.json @@ -50,11 +50,12 @@ }, "security": { "files": [ + "security-dead-exports.regression.test.cjs", "security-prompt-injection.security.test.cjs", "security-scan.security.test.cjs", "security.test.cjs" ], - "issue": "TBD" + "issue": "2198" }, "state": { "files": [ diff --git a/src/security.cts b/src/security.cts index f2200a286..fdaeee54c 100644 --- a/src/security.cts +++ b/src/security.cts @@ -477,40 +477,9 @@ export function validatePromptStructure(text: unknown, fileType: string): { vali return { valid: violations.length === 0, violations }; } -// ─── Layer 4: Paragraph-Level Entropy Anomaly Detection ───────────────────────────────────────────────────────────────────── - -function shannonEntropy(text: string): number { - if (!text || text.length === 0) return 0; - const freq: Record = {}; - for (const ch of text) { - freq[ch] = (freq[ch] || 0) + 1; - } - const len = text.length; - let entropy = 0; - for (const count of Object.values(freq)) { - const p = count / len; - entropy -= p * Math.log2(p); - } - return entropy; -} - -/** - * Scan text for paragraphs with anomalously high Shannon entropy. - */ -export function scanEntropyAnomalies(text: unknown): { clean: boolean; findings: string[] } { - if (!text || typeof text !== 'string') { - return { clean: true, findings: [] }; - } - const findings: string[] = []; - const paragraphs = text.split(/\n\n+/); - for (const para of paragraphs) { - if (para.length <= 50) continue; - const entropy = shannonEntropy(para); - if (entropy > 5.5) { - findings.push( - `High-entropy paragraph detected (${entropy.toFixed(2)} bits/char) — possible encoded payload` - ); - } - } - return { clean: findings.length === 0, findings }; -} +// NOTE (#2198): scanEntropyAnomalies + shannonEntropy were removed as dead exports. +// They had zero production callers — the live hooks (gsd-prompt-guard.js, +// gsd-read-injection-scanner.js) inline their own pattern subsets for hook +// independence and never called these functions. scanForInjection is retained +// below: it serves as the CI codebase-scanner engine +// (tests/prompt-injection-scan.security.test.cjs), not as a live hook. diff --git a/tests/fixtures/golden-install-parity/antigravity.json b/tests/fixtures/golden-install-parity/antigravity.json index 724c58fb5..7a77264da 100644 --- a/tests/fixtures/golden-install-parity/antigravity.json +++ b/tests/fixtures/golden-install-parity/antigravity.json @@ -155,7 +155,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "8797c0c7da927c8e", "gsd-core/templates/codebase/architecture.md": "282db635ba093b1a", "gsd-core/templates/codebase/concerns.md": "e66c584daa636fc5", @@ -203,7 +203,7 @@ "gsd-core/workflows/ai-integration-phase.md": "22f5466085c47c00", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "3ecffffe78021e0a", - "gsd-core/workflows/audit-milestone.md": "77089ccd7b45c0f0", + "gsd-core/workflows/audit-milestone.md": "280cd85908dd45cb", "gsd-core/workflows/audit-uat.md": "ea8ddd910ed16ba4", "gsd-core/workflows/autonomous.md": "603ce2019835f00e", "gsd-core/workflows/check-todos.md": "5a62092df800ad7c", @@ -308,7 +308,7 @@ "gsd-core/workflows/ultraplan-phase.md": "d8e92b0b7214eba6", "gsd-core/workflows/undo.md": "6ab639d1fc7e0721", "gsd-core/workflows/update.md": "2c58df5e21c41c31", - "gsd-core/workflows/validate-phase.md": "6c0ab739d15709fa", + "gsd-core/workflows/validate-phase.md": "ae3f0180a2316fcd", "gsd-core/workflows/verify-phase.md": "0eefbb6bb1b0bed6", "gsd-core/workflows/verify-work.md": "59276d94999ee022", "hooks/gsd-check-update-worker.js": "fa301e6366270d5f", diff --git a/tests/fixtures/golden-install-parity/augment.json b/tests/fixtures/golden-install-parity/augment.json index 5fb70188b..37eb97267 100644 --- a/tests/fixtures/golden-install-parity/augment.json +++ b/tests/fixtures/golden-install-parity/augment.json @@ -226,7 +226,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "9e296471b97ebcec", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "f53e0ca061d3528e", + "gsd-core/templates/VALIDATION.md": "6f0fe4214dff6dd1", "gsd-core/templates/claude-md.md": "d1d333e4b963c0d2", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -274,7 +274,7 @@ "gsd-core/workflows/ai-integration-phase.md": "40c217869a06981f", "gsd-core/workflows/analyze-dependencies.md": "52942af10f140717", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "6866ce260980c21e", + "gsd-core/workflows/audit-milestone.md": "3835762c3147a927", "gsd-core/workflows/audit-uat.md": "fcfbec501620b564", "gsd-core/workflows/autonomous.md": "7e5683728ef33707", "gsd-core/workflows/check-todos.md": "bdeaf43f9c61e0cc", @@ -379,7 +379,7 @@ "gsd-core/workflows/ultraplan-phase.md": "0fb8291153e3937d", "gsd-core/workflows/undo.md": "96d2775f008b3a85", "gsd-core/workflows/update.md": "fd160e13f8b7e83c", - "gsd-core/workflows/validate-phase.md": "2c6d7671fcaabcaa", + "gsd-core/workflows/validate-phase.md": "ce9890f21c6e5607", "gsd-core/workflows/verify-phase.md": "22f18492581f1da5", "gsd-core/workflows/verify-work.md": "63b3f680d8f0a6f3", "hooks/gsd-check-update-worker.js": "cc1ef5f840f9dfc9", diff --git a/tests/fixtures/golden-install-parity/claude-local.json b/tests/fixtures/golden-install-parity/claude-local.json index b8cf43ddd..3b873dd1a 100644 --- a/tests/fixtures/golden-install-parity/claude-local.json +++ b/tests/fixtures/golden-install-parity/claude-local.json @@ -225,7 +225,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "d8f0fe8dba3bb28a", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -273,7 +273,7 @@ "gsd-core/workflows/ai-integration-phase.md": "3503f52a7356caf0", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "816c71b0ef2d8c1d", - "gsd-core/workflows/audit-milestone.md": "a35795246b955bdb", + "gsd-core/workflows/audit-milestone.md": "ae8605b4ecc37c0b", "gsd-core/workflows/audit-uat.md": "1c4a02a8c1ab930f", "gsd-core/workflows/autonomous.md": "6adf957e64518d15", "gsd-core/workflows/check-todos.md": "8f2c6b27f18cc5e2", @@ -378,7 +378,7 @@ "gsd-core/workflows/ultraplan-phase.md": "b926ba7e4de0c76d", "gsd-core/workflows/undo.md": "d759702f84e308fa", "gsd-core/workflows/update.md": "2a59b4edf4a3c8c7", - "gsd-core/workflows/validate-phase.md": "83eeefeeca31c2b5", + "gsd-core/workflows/validate-phase.md": "3150904744b4a1bd", "gsd-core/workflows/verify-phase.md": "6ae6f159be75dcdd", "gsd-core/workflows/verify-work.md": "de14acdc8e925338", "hooks/gsd-check-update-worker.js": "a530efdb5fdc0da3", diff --git a/tests/fixtures/golden-install-parity/claude.json b/tests/fixtures/golden-install-parity/claude.json index bf2a8f2b2..ef18c8f08 100644 --- a/tests/fixtures/golden-install-parity/claude.json +++ b/tests/fixtures/golden-install-parity/claude.json @@ -154,7 +154,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "d8f0fe8dba3bb28a", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -202,7 +202,7 @@ "gsd-core/workflows/ai-integration-phase.md": "a898d99b8d844215", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "23c1e35f449933b8", + "gsd-core/workflows/audit-milestone.md": "9f8ec364e58d5710", "gsd-core/workflows/audit-uat.md": "e11db0d74c2a7405", "gsd-core/workflows/autonomous.md": "722397c04272dfaa", "gsd-core/workflows/check-todos.md": "6c2a43d1d3e86589", @@ -307,7 +307,7 @@ "gsd-core/workflows/ultraplan-phase.md": "328664400a001fd5", "gsd-core/workflows/undo.md": "791e0bf96d9a057f", "gsd-core/workflows/update.md": "f9e7d8a760d0d3c8", - "gsd-core/workflows/validate-phase.md": "2ac231dc541441c2", + "gsd-core/workflows/validate-phase.md": "7a3db6ab8ce9f380", "gsd-core/workflows/verify-phase.md": "e0957e153788a222", "gsd-core/workflows/verify-work.md": "c8ffee621e7319de", "hooks/gsd-check-update-worker.js": "a530efdb5fdc0da3", diff --git a/tests/fixtures/golden-install-parity/cline.json b/tests/fixtures/golden-install-parity/cline.json index 3584a0f48..3ebce9147 100644 --- a/tests/fixtures/golden-install-parity/cline.json +++ b/tests/fixtures/golden-install-parity/cline.json @@ -158,7 +158,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "9e296471b97ebcec", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "f53e0ca061d3528e", + "gsd-core/templates/VALIDATION.md": "6f0fe4214dff6dd1", "gsd-core/templates/claude-md.md": "c9fea2d8afa17d80", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -206,7 +206,7 @@ "gsd-core/workflows/ai-integration-phase.md": "5159c6bdf102f74b", "gsd-core/workflows/analyze-dependencies.md": "52942af10f140717", "gsd-core/workflows/audit-fix.md": "9bb427cd3b4075d5", - "gsd-core/workflows/audit-milestone.md": "2266710d0ae48932", + "gsd-core/workflows/audit-milestone.md": "202b726748604c93", "gsd-core/workflows/audit-uat.md": "1fb7b2ab9d587c8f", "gsd-core/workflows/autonomous.md": "cc5217b1b2238a4c", "gsd-core/workflows/check-todos.md": "32fdf33f5dc8bdde", @@ -311,7 +311,7 @@ "gsd-core/workflows/ultraplan-phase.md": "ceff456b1e9d94d8", "gsd-core/workflows/undo.md": "96d2775f008b3a85", "gsd-core/workflows/update.md": "165beec33490bd28", - "gsd-core/workflows/validate-phase.md": "5b4ae14c87859bd2", + "gsd-core/workflows/validate-phase.md": "706627c190ae11aa", "gsd-core/workflows/verify-phase.md": "a4f918c92c927268", "gsd-core/workflows/verify-work.md": "3fb282f2bce34a79", "scripts/changeset/README.md": "86ff89331dfd94b2", diff --git a/tests/fixtures/golden-install-parity/codebuddy.json b/tests/fixtures/golden-install-parity/codebuddy.json index 8a6c554d7..5cc7a91f2 100644 --- a/tests/fixtures/golden-install-parity/codebuddy.json +++ b/tests/fixtures/golden-install-parity/codebuddy.json @@ -226,7 +226,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "9e296471b97ebcec", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "f53e0ca061d3528e", + "gsd-core/templates/VALIDATION.md": "6f0fe4214dff6dd1", "gsd-core/templates/claude-md.md": "d1d333e4b963c0d2", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -274,7 +274,7 @@ "gsd-core/workflows/ai-integration-phase.md": "40c217869a06981f", "gsd-core/workflows/analyze-dependencies.md": "52942af10f140717", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "6866ce260980c21e", + "gsd-core/workflows/audit-milestone.md": "3835762c3147a927", "gsd-core/workflows/audit-uat.md": "fcfbec501620b564", "gsd-core/workflows/autonomous.md": "7e5683728ef33707", "gsd-core/workflows/check-todos.md": "bdeaf43f9c61e0cc", @@ -379,7 +379,7 @@ "gsd-core/workflows/ultraplan-phase.md": "0fb8291153e3937d", "gsd-core/workflows/undo.md": "96d2775f008b3a85", "gsd-core/workflows/update.md": "5ff1f77222977648", - "gsd-core/workflows/validate-phase.md": "2c6d7671fcaabcaa", + "gsd-core/workflows/validate-phase.md": "ce9890f21c6e5607", "gsd-core/workflows/verify-phase.md": "22f18492581f1da5", "gsd-core/workflows/verify-work.md": "63b3f680d8f0a6f3", "hooks/gsd-check-update-worker.js": "bdc9324a2f080ddd", diff --git a/tests/fixtures/golden-install-parity/codex.json b/tests/fixtures/golden-install-parity/codex.json index 5dca45747..ddf3d17a2 100644 --- a/tests/fixtures/golden-install-parity/codex.json +++ b/tests/fixtures/golden-install-parity/codex.json @@ -261,7 +261,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "59a3d4f6c4afbfc9", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "e3ca8ebb8d7e2cd0", + "gsd-core/templates/VALIDATION.md": "dae6246879d09d13", "gsd-core/templates/claude-md.md": "dd1a9011684f9753", "gsd-core/templates/codebase/architecture.md": "282db635ba093b1a", "gsd-core/templates/codebase/concerns.md": "e66c584daa636fc5", @@ -309,7 +309,7 @@ "gsd-core/workflows/ai-integration-phase.md": "1dfa15d8f28c022d", "gsd-core/workflows/analyze-dependencies.md": "f799abc00907377f", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "46edd152d8b63bfc", + "gsd-core/workflows/audit-milestone.md": "5f362cead97ceaca", "gsd-core/workflows/audit-uat.md": "2564078edb15b5e9", "gsd-core/workflows/autonomous.md": "92f08626d4aea668", "gsd-core/workflows/check-todos.md": "b2b103e8638e760a", @@ -414,7 +414,7 @@ "gsd-core/workflows/ultraplan-phase.md": "0bafc2af27be4591", "gsd-core/workflows/undo.md": "5ff7d63b0a2f46d5", "gsd-core/workflows/update.md": "5c35c0ec0f462ea6", - "gsd-core/workflows/validate-phase.md": "020201a41049679f", + "gsd-core/workflows/validate-phase.md": "6d6d10fe53f6b1d0", "gsd-core/workflows/verify-phase.md": "2e12c3cb97a9122a", "gsd-core/workflows/verify-work.md": "5b348e73fc0d0829", "hooks/gsd-check-update.js": "ef48957eb6ac6a10", diff --git a/tests/fixtures/golden-install-parity/copilot.json b/tests/fixtures/golden-install-parity/copilot.json index dc5e7dc29..f8b8349e3 100644 --- a/tests/fixtures/golden-install-parity/copilot.json +++ b/tests/fixtures/golden-install-parity/copilot.json @@ -156,7 +156,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "f436ae75a9c8518a", "gsd-core/templates/codebase/architecture.md": "282db635ba093b1a", "gsd-core/templates/codebase/concerns.md": "e66c584daa636fc5", @@ -204,7 +204,7 @@ "gsd-core/workflows/ai-integration-phase.md": "ef0c2474cee76b00", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "9fdfe8a7fbcd1417", - "gsd-core/workflows/audit-milestone.md": "19e03e6d34d96f38", + "gsd-core/workflows/audit-milestone.md": "258e4dfd259ab13f", "gsd-core/workflows/audit-uat.md": "5ea0e30548ed0933", "gsd-core/workflows/autonomous.md": "dd972ddde9663295", "gsd-core/workflows/check-todos.md": "be9b50b5f28d7504", @@ -309,7 +309,7 @@ "gsd-core/workflows/ultraplan-phase.md": "7217c34dc9eaf7bb", "gsd-core/workflows/undo.md": "ba1ef7aa80bef6bd", "gsd-core/workflows/update.md": "f444a7cfcd246cfb", - "gsd-core/workflows/validate-phase.md": "2f705775a4b76d42", + "gsd-core/workflows/validate-phase.md": "e7aa423ebdd6a230", "gsd-core/workflows/verify-phase.md": "5c72780e34214e27", "gsd-core/workflows/verify-work.md": "c966971a3cbd1d71", "hooks/gsd-session.json": "3382597f61e3a559", diff --git a/tests/fixtures/golden-install-parity/cursor.json b/tests/fixtures/golden-install-parity/cursor.json index 53995f645..6587f746f 100644 --- a/tests/fixtures/golden-install-parity/cursor.json +++ b/tests/fixtures/golden-install-parity/cursor.json @@ -226,7 +226,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "d6d7da8b7817a04c", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -274,7 +274,7 @@ "gsd-core/workflows/ai-integration-phase.md": "b79f320d59a68773", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "23c1e35f449933b8", + "gsd-core/workflows/audit-milestone.md": "9f8ec364e58d5710", "gsd-core/workflows/audit-uat.md": "e11db0d74c2a7405", "gsd-core/workflows/autonomous.md": "4b20eda9a0b587ce", "gsd-core/workflows/check-todos.md": "1a67337d1630848f", @@ -379,7 +379,7 @@ "gsd-core/workflows/ultraplan-phase.md": "466e01d65c350ef6", "gsd-core/workflows/undo.md": "18dec684fb1076f9", "gsd-core/workflows/update.md": "23e294ba707c3580", - "gsd-core/workflows/validate-phase.md": "2df0c6e298a5f249", + "gsd-core/workflows/validate-phase.md": "d03a94b7b807be12", "gsd-core/workflows/verify-phase.md": "e0957e153788a222", "gsd-core/workflows/verify-work.md": "e7e7e900c4874490", "hooks/gsd-cursor-post-tool.js": "019d503aee8b4a3f", diff --git a/tests/fixtures/golden-install-parity/hermes.json b/tests/fixtures/golden-install-parity/hermes.json index 1fc86716b..d0668d781 100644 --- a/tests/fixtures/golden-install-parity/hermes.json +++ b/tests/fixtures/golden-install-parity/hermes.json @@ -155,7 +155,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "7c778398f79e25a3", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -203,7 +203,7 @@ "gsd-core/workflows/ai-integration-phase.md": "ddab2912d025db65", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "2eee4a0be82ef951", - "gsd-core/workflows/audit-milestone.md": "806d346ee5bfe9f8", + "gsd-core/workflows/audit-milestone.md": "690289689e9eda7a", "gsd-core/workflows/audit-uat.md": "86d9131fccabf2ad", "gsd-core/workflows/autonomous.md": "dd572ca89862e5ec", "gsd-core/workflows/check-todos.md": "ea9a303c48a5d752", @@ -308,7 +308,7 @@ "gsd-core/workflows/ultraplan-phase.md": "0d103bf2622436f7", "gsd-core/workflows/undo.md": "791e0bf96d9a057f", "gsd-core/workflows/update.md": "7499bb4cb2a3ce6f", - "gsd-core/workflows/validate-phase.md": "75e8971d3981d06b", + "gsd-core/workflows/validate-phase.md": "88edc724568337d3", "gsd-core/workflows/verify-phase.md": "5c8d1305b47fbef4", "gsd-core/workflows/verify-work.md": "7a9c9541d2d73fdc", "hooks/gsd-check-update-worker.js": "7989cc2bedd1138d", diff --git a/tests/fixtures/golden-install-parity/kilo.json b/tests/fixtures/golden-install-parity/kilo.json index dfc8392ce..0ab265392 100644 --- a/tests/fixtures/golden-install-parity/kilo.json +++ b/tests/fixtures/golden-install-parity/kilo.json @@ -226,7 +226,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "f35856254768bf7d", "gsd-core/templates/codebase/architecture.md": "282db635ba093b1a", "gsd-core/templates/codebase/concerns.md": "e66c584daa636fc5", @@ -274,7 +274,7 @@ "gsd-core/workflows/ai-integration-phase.md": "c85c6afdc64f0da6", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "23c1e35f449933b8", + "gsd-core/workflows/audit-milestone.md": "9f8ec364e58d5710", "gsd-core/workflows/audit-uat.md": "e11db0d74c2a7405", "gsd-core/workflows/autonomous.md": "73f429f7472c9949", "gsd-core/workflows/check-todos.md": "ed4b4eb12be222d7", @@ -379,7 +379,7 @@ "gsd-core/workflows/ultraplan-phase.md": "29245758b8497fa0", "gsd-core/workflows/undo.md": "7cd2153f8b15e30d", "gsd-core/workflows/update.md": "07dc2fba78ad1865", - "gsd-core/workflows/validate-phase.md": "557e3251e3b9349a", + "gsd-core/workflows/validate-phase.md": "52b9fa8a9533b444", "gsd-core/workflows/verify-phase.md": "e0957e153788a222", "gsd-core/workflows/verify-work.md": "9fc717845828c6e3", "kilo.json": "13151e97ff23c1aa", diff --git a/tests/fixtures/golden-install-parity/kimi.json b/tests/fixtures/golden-install-parity/kimi.json index 8b7217d18..d544f8d67 100644 --- a/tests/fixtures/golden-install-parity/kimi.json +++ b/tests/fixtures/golden-install-parity/kimi.json @@ -219,7 +219,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "9e296471b97ebcec", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "f53e0ca061d3528e", + "gsd-core/templates/VALIDATION.md": "6f0fe4214dff6dd1", "gsd-core/templates/claude-md.md": "d1d333e4b963c0d2", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -267,7 +267,7 @@ "gsd-core/workflows/ai-integration-phase.md": "40c217869a06981f", "gsd-core/workflows/analyze-dependencies.md": "52942af10f140717", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "6866ce260980c21e", + "gsd-core/workflows/audit-milestone.md": "3835762c3147a927", "gsd-core/workflows/audit-uat.md": "fcfbec501620b564", "gsd-core/workflows/autonomous.md": "7e5683728ef33707", "gsd-core/workflows/check-todos.md": "bdeaf43f9c61e0cc", @@ -372,7 +372,7 @@ "gsd-core/workflows/ultraplan-phase.md": "0fb8291153e3937d", "gsd-core/workflows/undo.md": "96d2775f008b3a85", "gsd-core/workflows/update.md": "6718e0632bba26ca", - "gsd-core/workflows/validate-phase.md": "2c6d7671fcaabcaa", + "gsd-core/workflows/validate-phase.md": "ce9890f21c6e5607", "gsd-core/workflows/verify-phase.md": "22f18492581f1da5", "gsd-core/workflows/verify-work.md": "63b3f680d8f0a6f3", "scripts/changeset/README.md": "86ff89331dfd94b2", diff --git a/tests/fixtures/golden-install-parity/opencode.json b/tests/fixtures/golden-install-parity/opencode.json index 97a353868..05da0af4d 100644 --- a/tests/fixtures/golden-install-parity/opencode.json +++ b/tests/fixtures/golden-install-parity/opencode.json @@ -226,7 +226,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "a4f5e38984001194", "gsd-core/templates/codebase/architecture.md": "282db635ba093b1a", "gsd-core/templates/codebase/concerns.md": "e66c584daa636fc5", @@ -274,7 +274,7 @@ "gsd-core/workflows/ai-integration-phase.md": "90e5f97018715b18", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "2871c5d0a4b671fa", - "gsd-core/workflows/audit-milestone.md": "7aa0db364a4b67e2", + "gsd-core/workflows/audit-milestone.md": "8bd0b730de08d1a8", "gsd-core/workflows/audit-uat.md": "c800099fab1e1c1b", "gsd-core/workflows/autonomous.md": "6cb0c014f5f56965", "gsd-core/workflows/check-todos.md": "6526b64ee88c7d2e", @@ -379,7 +379,7 @@ "gsd-core/workflows/ultraplan-phase.md": "f4bad8de3fdb49fa", "gsd-core/workflows/undo.md": "0bba5e7f6196c894", "gsd-core/workflows/update.md": "71b6cd852f38b4bc", - "gsd-core/workflows/validate-phase.md": "abcdbc1b56780565", + "gsd-core/workflows/validate-phase.md": "434d9927c65f2bba", "gsd-core/workflows/verify-phase.md": "126be1d026900102", "gsd-core/workflows/verify-work.md": "ae07b3fa8b6f864e", "hooks/gsd-check-update-worker.js": "385fb7c67810baf6", diff --git a/tests/fixtures/golden-install-parity/pi.json b/tests/fixtures/golden-install-parity/pi.json index ca40d6239..9eddb6574 100644 --- a/tests/fixtures/golden-install-parity/pi.json +++ b/tests/fixtures/golden-install-parity/pi.json @@ -122,7 +122,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "9e296471b97ebcec", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "f53e0ca061d3528e", + "gsd-core/templates/VALIDATION.md": "6f0fe4214dff6dd1", "gsd-core/templates/claude-md.md": "d1d333e4b963c0d2", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -170,7 +170,7 @@ "gsd-core/workflows/ai-integration-phase.md": "40c217869a06981f", "gsd-core/workflows/analyze-dependencies.md": "52942af10f140717", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "6866ce260980c21e", + "gsd-core/workflows/audit-milestone.md": "3835762c3147a927", "gsd-core/workflows/audit-uat.md": "fcfbec501620b564", "gsd-core/workflows/autonomous.md": "7e5683728ef33707", "gsd-core/workflows/check-todos.md": "bdeaf43f9c61e0cc", @@ -275,7 +275,7 @@ "gsd-core/workflows/ultraplan-phase.md": "0fb8291153e3937d", "gsd-core/workflows/undo.md": "96d2775f008b3a85", "gsd-core/workflows/update.md": "7e69d278375a2493", - "gsd-core/workflows/validate-phase.md": "2c6d7671fcaabcaa", + "gsd-core/workflows/validate-phase.md": "ce9890f21c6e5607", "gsd-core/workflows/verify-phase.md": "22f18492581f1da5", "gsd-core/workflows/verify-work.md": "63b3f680d8f0a6f3", "hooks/gsd-check-update-worker.js": "55376b5b9335a580", diff --git a/tests/fixtures/golden-install-parity/qwen.json b/tests/fixtures/golden-install-parity/qwen.json index 1e872a296..b02b0bf45 100644 --- a/tests/fixtures/golden-install-parity/qwen.json +++ b/tests/fixtures/golden-install-parity/qwen.json @@ -155,7 +155,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "ec5972ab31c0f5d0", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -203,7 +203,7 @@ "gsd-core/workflows/ai-integration-phase.md": "afdc7c15f03a95fc", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "aaa1b74e001322b6", - "gsd-core/workflows/audit-milestone.md": "b7617cf590d92a56", + "gsd-core/workflows/audit-milestone.md": "78dbc1e8c4499d7d", "gsd-core/workflows/audit-uat.md": "97d441d07e7972b3", "gsd-core/workflows/autonomous.md": "3014ff90115f0daf", "gsd-core/workflows/check-todos.md": "ec8c22920f6b2df1", @@ -308,7 +308,7 @@ "gsd-core/workflows/ultraplan-phase.md": "49921383982474e0", "gsd-core/workflows/undo.md": "791e0bf96d9a057f", "gsd-core/workflows/update.md": "b34cb866152d4de3", - "gsd-core/workflows/validate-phase.md": "e989cbaa4228564c", + "gsd-core/workflows/validate-phase.md": "dfb9bd178ee1b67b", "gsd-core/workflows/verify-phase.md": "0dc52b9e629a5f5a", "gsd-core/workflows/verify-work.md": "3355ddc14f052fff", "hooks/gsd-check-update-worker.js": "4bb354044e0dff91", diff --git a/tests/fixtures/golden-install-parity/trae.json b/tests/fixtures/golden-install-parity/trae.json index d9009aadb..118d4f07e 100644 --- a/tests/fixtures/golden-install-parity/trae.json +++ b/tests/fixtures/golden-install-parity/trae.json @@ -155,7 +155,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "17217a07ab8a6485", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -203,7 +203,7 @@ "gsd-core/workflows/ai-integration-phase.md": "d469eb120e52de0f", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "76607add3257cb37", - "gsd-core/workflows/audit-milestone.md": "a379eda51d821bce", + "gsd-core/workflows/audit-milestone.md": "ebec95af8f68f2ed", "gsd-core/workflows/audit-uat.md": "6e768b1c208a787a", "gsd-core/workflows/autonomous.md": "c482645c5d1ead46", "gsd-core/workflows/check-todos.md": "0dda8236355e8c9c", @@ -308,7 +308,7 @@ "gsd-core/workflows/ultraplan-phase.md": "77b58ef8af5209bd", "gsd-core/workflows/undo.md": "59b8baa54efc4110", "gsd-core/workflows/update.md": "1f935251fca1f276", - "gsd-core/workflows/validate-phase.md": "1c0ebe56d96a14d1", + "gsd-core/workflows/validate-phase.md": "58fd1a0a679d7115", "gsd-core/workflows/verify-phase.md": "a151ed36eb51813b", "gsd-core/workflows/verify-work.md": "dde2a42a56c27c4e", "scripts/changeset/README.md": "86ff89331dfd94b2", diff --git a/tests/fixtures/golden-install-parity/windsurf.json b/tests/fixtures/golden-install-parity/windsurf.json index 8311cb82e..ec771fa9d 100644 --- a/tests/fixtures/golden-install-parity/windsurf.json +++ b/tests/fixtures/golden-install-parity/windsurf.json @@ -155,7 +155,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "68d32d1fea14e184", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "6144951011cdca57", + "gsd-core/templates/VALIDATION.md": "e4d0f1c48727fce3", "gsd-core/templates/claude-md.md": "20be2a0201ab92cd", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -203,7 +203,7 @@ "gsd-core/workflows/ai-integration-phase.md": "8948988717506320", "gsd-core/workflows/analyze-dependencies.md": "77aff48f97fa6f1c", "gsd-core/workflows/audit-fix.md": "aa052e15623d759d", - "gsd-core/workflows/audit-milestone.md": "ac2238ea6c11ae9e", + "gsd-core/workflows/audit-milestone.md": "868db5a8f5d55040", "gsd-core/workflows/audit-uat.md": "d496e39402e160de", "gsd-core/workflows/autonomous.md": "fe7bb7c978f305a2", "gsd-core/workflows/check-todos.md": "afc840fceb07bf99", @@ -308,7 +308,7 @@ "gsd-core/workflows/ultraplan-phase.md": "53b77a8edf60acd0", "gsd-core/workflows/undo.md": "18dec684fb1076f9", "gsd-core/workflows/update.md": "79aaf4b8f1f83045", - "gsd-core/workflows/validate-phase.md": "2db47bf5547d7b9d", + "gsd-core/workflows/validate-phase.md": "bf16fd7ff71286b2", "gsd-core/workflows/verify-phase.md": "f961cdb3ef03ff05", "gsd-core/workflows/verify-work.md": "cce8ae44b30957f1", "hooks/gsd-windsurf-pre-command.js": "7467a8a63e354aad", diff --git a/tests/fixtures/golden-install-parity/zcode.json b/tests/fixtures/golden-install-parity/zcode.json index 4997a9328..06c7fa902 100644 --- a/tests/fixtures/golden-install-parity/zcode.json +++ b/tests/fixtures/golden-install-parity/zcode.json @@ -226,7 +226,7 @@ "gsd-core/templates/SECURITY.md": "b628f7f1c6d2328f", "gsd-core/templates/UAT.md": "9e296471b97ebcec", "gsd-core/templates/UI-SPEC.md": "7dd5c7cdc7ece0ec", - "gsd-core/templates/VALIDATION.md": "f53e0ca061d3528e", + "gsd-core/templates/VALIDATION.md": "6f0fe4214dff6dd1", "gsd-core/templates/claude-md.md": "d1d333e4b963c0d2", "gsd-core/templates/codebase/architecture.md": "6be88214162fdd89", "gsd-core/templates/codebase/concerns.md": "efa26d1fb5132f25", @@ -274,7 +274,7 @@ "gsd-core/workflows/ai-integration-phase.md": "40c217869a06981f", "gsd-core/workflows/analyze-dependencies.md": "52942af10f140717", "gsd-core/workflows/audit-fix.md": "eedb2da4bffb7575", - "gsd-core/workflows/audit-milestone.md": "6866ce260980c21e", + "gsd-core/workflows/audit-milestone.md": "3835762c3147a927", "gsd-core/workflows/audit-uat.md": "fcfbec501620b564", "gsd-core/workflows/autonomous.md": "7e5683728ef33707", "gsd-core/workflows/check-todos.md": "bdeaf43f9c61e0cc", @@ -379,7 +379,7 @@ "gsd-core/workflows/ultraplan-phase.md": "0fb8291153e3937d", "gsd-core/workflows/undo.md": "96d2775f008b3a85", "gsd-core/workflows/update.md": "dc580dee13f881a6", - "gsd-core/workflows/validate-phase.md": "2c6d7671fcaabcaa", + "gsd-core/workflows/validate-phase.md": "ce9890f21c6e5607", "gsd-core/workflows/verify-phase.md": "22f18492581f1da5", "gsd-core/workflows/verify-work.md": "63b3f680d8f0a6f3", "scripts/changeset/README.md": "86ff89331dfd94b2", diff --git a/tests/policy-138-nyquist-config-default.test.cjs b/tests/policy-138-nyquist-config-default.test.cjs index 0665e1d04..72f5a11dc 100644 --- a/tests/policy-138-nyquist-config-default.test.cjs +++ b/tests/policy-138-nyquist-config-default.test.cjs @@ -1,3 +1,4 @@ +// allow-test-rule: runtime-contract-is-the-product — asserts GSD workflow/template markdown prose, the executable contract (#138, #2117) 'use strict'; // Policy regression test for issue #138: @@ -67,3 +68,59 @@ test('legacy Nyquist config helper still detects unsafe direct reads', () => { } } }); + +// ───────────────────────────────────────────────────────────────────────────── +// Issue #2117: audit-milestone could not distinguish a not-yet-validated phase +// from a validated-but-failing one — both read Nyquist PARTIAL. The fix makes the +// dead `status` field live (validate-phase §6 promotes draft → validated) and has +// audit-milestone §5.5 bucket `status: draft` as a distinct NOT-VALIDATED state. +// These assertions fail-first if either half of that two-workflow contract is +// reverted, silently re-collapsing "not validated" and "validation failed". +// ───────────────────────────────────────────────────────────────────────────── + +test('#2117 validate-phase.md promotes status: draft → validated when it reconciles VALIDATION.md', () => { + const content = readWorkflow('validate-phase.md'); + // Both the create (State B) and update (State A) paths in §6 must set the + // terminal marker, otherwise `status` stays `draft` for the life of the file + // and audit-milestone cannot tell an unvalidated phase from a failing one. + const occurrences = content.match(/status: validated/g) || []; + assert.ok( + occurrences.length >= 2, + 'validate-phase.md must set `status: validated` in both the create (State B) and update (State A) VALIDATION.md paths', + ); +}); + +test('#2117 audit-milestone.md buckets status: draft as NOT-VALIDATED, never PARTIAL', () => { + const content = readWorkflow('audit-milestone.md'); + assert.ok( + content.includes('`status`'), + 'audit-milestone.md must parse the `status` frontmatter field to detect not-yet-validated phases', + ); + assert.ok( + content.includes('| NOT-VALIDATED | `status: draft`'), + 'audit-milestone.md must define a NOT-VALIDATED bucket keyed on `status: draft`', + ); + assert.ok( + content.includes('| COMPLIANT | `status: validated`'), + 'COMPLIANT must require `status: validated` so a draft file can never be scored compliant', + ); + assert.ok( + content.includes('| PARTIAL | `status: validated`'), + 'PARTIAL must require `status: validated`; a `status: draft` file is NOT-VALIDATED, not PARTIAL', + ); + assert.ok( + content.includes('not_validated_phases'), + 'audit-milestone.md must report not_validated_phases in the nyquist audit YAML aggregate', + ); +}); + +test('#2117 VALIDATION.md template seeds status: draft (the pre-validation state)', () => { + const template = fs.readFileSync( + path.join(__dirname, '..', 'gsd-core', 'templates', 'VALIDATION.md'), + 'utf8', + ); + assert.ok( + /^status: draft$/m.test(template), + 'VALIDATION.md template must seed `status: draft`; validate-phase promotes it to validated', + ); +}); diff --git a/tests/security-dead-exports.regression.test.cjs b/tests/security-dead-exports.regression.test.cjs new file mode 100644 index 000000000..708ed0b2f --- /dev/null +++ b/tests/security-dead-exports.regression.test.cjs @@ -0,0 +1,90 @@ +/** + * Regression test for #2198 — advertised base64/entropy/homoglyph scanning + * never runs live. `scanEntropyAnomalies` + `shannonEntropy` were dead exports + * (zero callers outside their own unit tests). The live hooks inline their + * own pattern subsets "for hook independence" and never call these functions. + * + * This test asserts the chosen contract: the dead export was removed and the + * docs no longer over-claim entropy analysis as a live MUST. + * + * Contract: `scanForInjection` is retained — it serves as the CI codebase + * scanner engine (tests/prompt-injection-scan.security.test.cjs). It is NOT + * called from live hooks; hooks inline their own patterns. + */ +'use strict'; + +const { describe, test } = require('node:test'); +const assert = require('node:assert/strict'); +const fs = require('fs'); +const path = require('path'); + +const PROJECT_ROOT = path.join(__dirname, '..'); + +describe('#2198 regression: dead scan exports removed, docs corrected', () => { + test('scanEntropyAnomalies is no longer exported from security.cjs', () => { + const security = require('../gsd-core/bin/lib/security.cjs'); + assert.equal( + security.scanEntropyAnomalies, + undefined, + 'scanEntropyAnomalies should have been removed as a dead export (#2198)' + ); + }); + + test('shannonEntropy is not accessible from the security module', () => { + const security = require('../gsd-core/bin/lib/security.cjs'); + assert.equal( + security.shannonEntropy, + undefined, + 'shannonEntropy was the private helper for the removed scanEntropyAnomalies' + ); + }); + + test('scanForInjection is retained (CI codebase scanner uses it)', () => { + const security = require('../gsd-core/bin/lib/security.cjs'); + assert.equal( + typeof security.scanForInjection, + 'function', + 'scanForInjection is retained: it serves as the CI codebase scanner engine' + ); + }); + + test('FEATURES.md does not over-claim entropy analysis as a live MUST', () => { + const features = fs.readFileSync( + path.join(PROJECT_ROOT, 'docs', 'FEATURES.md'), + 'utf-8' + ); + assert.ok( + !features.includes('REQ-SCAN-INJ-03: Scanner MUST apply entropy analysis'), + 'REQ-SCAN-INJ-03 should not claim entropy analysis runs as a live MUST — ' + + 'the implementation was dead code (#2198)' + ); + }); + + test('FEATURES.md documents that base64-decode is CI-only, not live', () => { + const features = fs.readFileSync( + path.join(PROJECT_ROOT, 'docs', 'FEATURES.md'), + 'utf-8' + ); + assert.ok( + features.includes('CI-time control'), + 'FEATURES.md should note base64-decode is a CI-time control, not a live hook (#2198)' + ); + }); + + test('live hooks inline patterns independently (do not import security.cjs)', () => { + const hookFiles = [ + 'hooks/gsd-prompt-guard.js', + 'hooks/gsd-read-injection-scanner.js', + ]; + + for (const relPath of hookFiles) { + const fullPath = path.join(PROJECT_ROOT, relPath); + const source = fs.readFileSync(fullPath, 'utf-8'); + assert.ok( + !source.match(/require\s*\(\s*['"][^'"]*security\.(cjs|js)['"]\s*\)/) && + !source.match(/import\s+.*from\s+['"][^'"]*security\.(cjs|js)['"]\s*;?/), + `${relPath} must not require/import security.cjs — hooks inline patterns for independence` + ); + } + }); +}); diff --git a/tests/security.test.cjs b/tests/security.test.cjs index ab2c11be3..1d339b2f3 100644 --- a/tests/security.test.cjs +++ b/tests/security.test.cjs @@ -21,7 +21,6 @@ const { validateFieldName, validateShellArg, validatePromptStructure, - scanEntropyAnomalies, } = require('../gsd-core/bin/lib/security.cjs'); // ─── Path Traversal Prevention ────────────────────────────────────────────── @@ -765,79 +764,8 @@ describe('validatePromptStructure', () => { }); }); -// ─── Layer 4: Paragraph-Level Entropy Anomaly Detection ───────────────────── - -describe('scanEntropyAnomalies', () => { - test('is exported from security.cjs', () => { - assert.equal(typeof scanEntropyAnomalies, 'function'); - }); - - test('returns { clean, findings } shape', () => { - const result = scanEntropyAnomalies('Normal text here.'); - assert.ok(typeof result.clean === 'boolean'); - assert.ok(Array.isArray(result.findings)); - }); - - test('clean natural language text passes', () => { - const text = [ - 'Build an authentication system with JWT tokens.', - '', - 'The system should support login, logout, and token refresh.', - ].join('\n'); - const result = scanEntropyAnomalies(text); - assert.ok(result.clean, `Expected clean but got: ${result.findings.join(', ')}`); - }); - - test('detects high-entropy paragraph (random-character content)', () => { - // A string cycling through 90 distinct chars has entropy ~6.4 bits/char, well above 5.5 threshold - const highEntropyPara = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=!@#$%^&*()_-[]{}|;:,.<>?ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqr'; - const result = scanEntropyAnomalies(highEntropyPara); - assert.ok(!result.clean, 'should detect high-entropy paragraph'); - assert.ok( - result.findings.some(f => f.includes('High-entropy paragraph')), - 'finding should mention high-entropy paragraph' - ); - }); - - test('finding includes entropy value in bits/char', () => { - const highEntropyPara = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=!@#$%^&*()_-[]{}|;:,.<>?ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqr'; - const result = scanEntropyAnomalies(highEntropyPara); - assert.ok(result.findings.some(f => f.includes('bits/char'))); - }); - - test('skips paragraphs shorter than or equal to 50 chars', () => { - // Even a high-entropy short paragraph should not be flagged - const shortPara = 'SGVsbG8gV29ybGQ='; // 16 chars — under 50 - const result = scanEntropyAnomalies(shortPara); - assert.ok(result.clean, 'short paragraphs should be skipped'); - }); - - test('handles empty text gracefully', () => { - const result = scanEntropyAnomalies(''); - assert.ok(result.clean); - assert.equal(result.findings.length, 0); - }); - - test('handles null gracefully', () => { - const result = scanEntropyAnomalies(null); - assert.ok(result.clean); - assert.equal(result.findings.length, 0); - }); - - test('multiple paragraphs — flags only high-entropy ones', () => { - const highEntropyPara = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=!@#$%^&*()_-[]{}|;:,.<>?ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqr'; - const text = [ - 'This is a perfectly normal English sentence describing a feature.', - '', - highEntropyPara, - '', - 'Another clean sentence about the authentication requirements.', - ].join('\n'); - const result = scanEntropyAnomalies(text); - assert.ok(!result.clean); - assert.equal(result.findings.length, 1, 'only 1 high-entropy paragraph should be flagged'); - }); -}); +// NOTE (#2198): scanEntropyAnomalies test block removed — the function was a +// dead export (zero production callers) and has been deleted from security.cts. // ──────────────────────────────────────────────────────────────────────── diff --git a/tests/workflow-size-baseline.json b/tests/workflow-size-baseline.json index e90823c69..b478680b8 100644 --- a/tests/workflow-size-baseline.json +++ b/tests/workflow-size-baseline.json @@ -6,7 +6,7 @@ "ai-integration-phase.md": 14805, "analyze-dependencies.md": 3887, "audit-fix.md": 11717, - "audit-milestone.md": 17681, + "audit-milestone.md": 18448, "audit-uat.md": 7469, "autonomous.md": 42474, "check-todos.md": 9475, @@ -87,7 +87,7 @@ "ultraplan-phase.md": 10512, "undo.md": 10431, "update.md": 20914, - "validate-phase.md": 10789, + "validate-phase.md": 10849, "verify-phase.md": 40923, "verify-work.md": 40247 } diff --git a/vscode/package.json b/vscode/package.json index 49cacec6d..0c3991af7 100644 --- a/vscode/package.json +++ b/vscode/package.json @@ -2,7 +2,7 @@ "name": "gsd-core-vscode", "displayName": "GSD Core", "description": "GSD orchestration engine embedded in VS Code (ADR-1239 IDE profile).", - "version": "1.7.0-rc.5", + "version": "1.7.0-rc.6", "publisher": "opengsd", "engines": { "vscode": "^1.105.0" @@ -34,7 +34,10 @@ "languageModelTools": [ { "name": "gsd_progress", - "tags": ["gsd", "status"], + "tags": [ + "gsd", + "status" + ], "toolReferenceName": "gsd-progress", "displayName": "GSD Progress", "modelDescription": "Reports GSD milestone/phase progress (percent complete, plan and summary counts) for the current project.", @@ -48,7 +51,10 @@ }, { "name": "gsd_workstreams", - "tags": ["gsd", "status"], + "tags": [ + "gsd", + "status" + ], "toolReferenceName": "gsd-workstreams", "displayName": "GSD Workstreams", "modelDescription": "Lists the GSD parallel workstreams for the current project (or reports flat/single-workstream mode).", @@ -62,7 +68,10 @@ }, { "name": "gsd_plan_phase", - "tags": ["gsd", "plan"], + "tags": [ + "gsd", + "plan" + ], "toolReferenceName": "gsd-plan-phase", "displayName": "GSD Plan Phase", "modelDescription": "Looks up the plan index (plans, waves, checkpoints) for a named GSD phase. Read-only — does not create or modify a phase plan; use the /gsd-plan-phase chat workflow for full phase planning.", @@ -76,7 +85,9 @@ "description": "The GSD phase name to look up (e.g. \"01-core\")." } }, - "required": ["phase"], + "required": [ + "phase" + ], "additionalProperties": false } }