chore: point MSD at git.golem15.com/golem15/msd-core
Some checks failed
Tests / PR mergeability (push) Successful in 1m37s
Tests / Base branch health (push) Successful in 11s
Tests / Detect test scope (push) Successful in 17s
Tests / lint-tests (push) Failing after 2m16s
Tests / plugin-validate (push) Successful in 1m6s
Tests / test (ubuntu-latest, 24, shard 1/3) (push) Failing after 25s
Tests / test (ubuntu-latest, 24, shard 2/3) (push) Failing after 20s
Tests / test (ubuntu-latest, 24, shard 3/3) (push) Failing after 20s
Tests / test (ubuntu-latest, 24) (push) Failing after 19s
Tests / test (inert CI) (push) Has been skipped
Tests / QA loop walk (smell ratchet) (push) Failing after 19s
Tests / Coverage gate (merged shards) (push) Has been skipped
Tests / Publish emitted-baseline artifact (push) Has been skipped
Dismiss Unauthorized PR Approvals / dismiss-unauthorized-approval (push) Successful in 9s
Close Draft PRs (sweep) / Sweep open draft PRs (push) Successful in 8s
Tests / conformance test (macos-latest, 24) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 1/3) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 2/3) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 3/3) (push) Has been cancelled
Tests / Required tests (push) Has been cancelled
Some checks failed
Tests / PR mergeability (push) Successful in 1m37s
Tests / Base branch health (push) Successful in 11s
Tests / Detect test scope (push) Successful in 17s
Tests / lint-tests (push) Failing after 2m16s
Tests / plugin-validate (push) Successful in 1m6s
Tests / test (ubuntu-latest, 24, shard 1/3) (push) Failing after 25s
Tests / test (ubuntu-latest, 24, shard 2/3) (push) Failing after 20s
Tests / test (ubuntu-latest, 24, shard 3/3) (push) Failing after 20s
Tests / test (ubuntu-latest, 24) (push) Failing after 19s
Tests / test (inert CI) (push) Has been skipped
Tests / QA loop walk (smell ratchet) (push) Failing after 19s
Tests / Coverage gate (merged shards) (push) Has been skipped
Tests / Publish emitted-baseline artifact (push) Has been skipped
Dismiss Unauthorized PR Approvals / dismiss-unauthorized-approval (push) Successful in 9s
Close Draft PRs (sweep) / Sweep open draft PRs (push) Successful in 8s
Tests / conformance test (macos-latest, 24) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 1/3) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 2/3) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 3/3) (push) Has been cancelled
Tests / Required tests (push) Has been cancelled
The fork lives on the golem15 Gitea forge, not GitHub. Package identity now parses either host and derives in-place raw URLs for Gitea; the identity-drift lint accepts the new host; README drops GitHub-only badges and the npm quickstart in favour of the checkout installer.
This commit is contained in:
@@ -2,8 +2,8 @@
|
||||
"name": "msd-core",
|
||||
"description": "Marketplace for MSD Core — meta-prompting, context engineering, and spec-driven development system for AI coding agents.",
|
||||
"owner": {
|
||||
"name": "golem15com",
|
||||
"url": "https://github.com/golem15com"
|
||||
"name": "golem15",
|
||||
"url": "https://git.golem15.com/golem15"
|
||||
},
|
||||
"plugins": [
|
||||
{
|
||||
@@ -12,8 +12,8 @@
|
||||
"version": "1.14.0",
|
||||
"source": "./",
|
||||
"author": {
|
||||
"name": "golem15com",
|
||||
"url": "https://github.com/golem15com"
|
||||
"name": "golem15",
|
||||
"url": "https://git.golem15.com/golem15"
|
||||
}
|
||||
}
|
||||
]
|
||||
|
||||
@@ -4,11 +4,11 @@
|
||||
"version": "1.14.0",
|
||||
"description": "MSD Core is a meta-prompting, context engineering, and spec-driven development system for AI coding agents.",
|
||||
"author": {
|
||||
"name": "golem15com",
|
||||
"url": "https://github.com/golem15com"
|
||||
"name": "golem15",
|
||||
"url": "https://git.golem15.com/golem15"
|
||||
},
|
||||
"homepage": "https://github.com/golem15com/msd-core",
|
||||
"repository": "https://github.com/golem15com/msd-core",
|
||||
"homepage": "https://git.golem15.com/golem15/msd-core",
|
||||
"repository": "https://git.golem15.com/golem15/msd-core",
|
||||
"license": "MIT",
|
||||
"keywords": [
|
||||
"spec-driven-development",
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# CodeRabbit configuration — golem15com/msd-core
|
||||
# CodeRabbit configuration — golem15/msd-core
|
||||
#
|
||||
# Schema: https://docs.coderabbit.ai/reference/yaml-template/
|
||||
#
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
#!/usr/bin/env bash
|
||||
# Release monitor for golem15com/msd-core
|
||||
# Release monitor for golem15/msd-core
|
||||
# Checks every 15 minutes, writes new release info to a signal file
|
||||
|
||||
REPO="golem15com/msd-core"
|
||||
REPO="golem15/msd-core"
|
||||
SIGNAL_FILE="/tmp/msd-new-release.json"
|
||||
STATE_FILE="/tmp/msd-monitor-last-tag"
|
||||
LOG_FILE="/tmp/msd-monitor.log"
|
||||
|
||||
10
CONTEXT.md
10
CONTEXT.md
@@ -303,7 +303,7 @@ Module owning install-time per-agent model-override resolution (#2256 / #2794),
|
||||
A **genuine leaf** (node builtins only) owning the typed IR for `~/.codex/agents/<agent>.toml` (#3243, ADR-2313 Phase 3). It is a **document model, not a policy** — it knows how to parse/render/strip the two keys the posture owns (`model`, `model_reasoning_effort`); it does NOT know which `model` values are illegal for Codex (that predicate, `isAnthropicFlavoredModel`, stays in the Model Catalog Module and the caller decides what to strip). `parseCodexAgentToml(content) → {ok:true,doc} | {ok:false,reason}` is the STRICT half: `PARSE_REASON.UNTERMINATED_BLOCK` when the `developer_instructions` block is opened but never closed, because a writer that proceeds on a malformed document risks rewriting it. `renderCodexAgentToml(doc)` round-trips **byte-identically** for an unmodified doc — the load-bearing property that stops a sync from silently reformatting a user's file — by keeping the original `lines` array (never re-derived) plus the detected `eol`/BOM/trailing-newline metadata, and rejoining rather than reconstructing. `stripModel`/`stripReasoningEffort` remove exactly one targeted line, re-indexing the block range and the sibling key's line index; every other line (comments, hand-added keys, the prompt block, line endings) is untouched. `scanTomlLines`/`stripBOM`/`findDeveloperInstructionsBlockRange`/`unquoteTomlValue` are the LENIENT reader primitives — moved here (not copied) from the Agent Install Check Module (#3242, Phase 2), which still imports and calls them directly, unchanged in behavior: an unterminated block falls back to "rest of file is inside the block" rather than failing, because misreading prompt prose as a pin is only a false positive. One block-range detector (`findDeveloperInstructionsBlockRange`, now carrying a `terminated` flag the strict parser reads and the lenient scanner ignores) serves both policies, so the reader and the writer can never silently diverge on where the block ends. Consumed by the Codex `.toml` sync (Commands Module's `cmdEffortSyncCodex`, ADR-2313 D7) and the Agent Install Check Module's `checkCodexModelPosture`. Source of truth: `msd-core/bin/lib/codex-agent-toml.cjs` (generated from `src/codex-agent-toml.cts`). See Agent Install Check Module, Model Catalog Module, ADR-2313.
|
||||
|
||||
### Package Identity Module [Planned]
|
||||
Single seam owning MSD's published-package coordinates so a repoint/rename is a one-line change instead of a tree-wide sweep. Source of truth is `package.json`; values are *derived*, not re-typed: `packageName` (`.name` → `@golem15/msd-core`), `binName` (`Object.keys(.bin)[0]` → `msd-core`), `repoSlug` (parsed from `.repository.url` → `golem15com/msd-core`), plus derived `changelogRawUrl` and `manualInstallCommand({ scope, runtime })`. Generated `.cjs` per ADR-457 (generated-single-source); shipped under `msd-core/bin/lib/`. Three consumer worlds: **Node** consumers `require()` it at runtime (worker, `check-latest-version.cjs`, `bin/install.js`); the **bash launcher** snippet receives the literal injected by `scripts/sync-runtime-launcher.cjs` at sync time; **prose/help** literals (`update.md`, installer help) carry a committed copy. A drift-guard lint (`scripts/lint-package-identity-drift.cjs`, sibling to `check:alias-drift`) fails CI on any raw package/repo literal outside `package.json`, the generated module, and the value-checked materialization sites — this is what keeps the seam real (`two adapters`, not one). Replaces the contradictory pair it consolidates: the runtime-broken `require('../package.json').name` in `hooks/msd-check-update-worker.js` (#378, resolves to `undefined` post-install) and the hardcoded constant in `check-latest-version.cjs` (#2992). _Avoid_: "package name string", "the npm name" (when you mean the seam). See ADR-457 and Installer Module.
|
||||
Single seam owning MSD's published-package coordinates so a repoint/rename is a one-line change instead of a tree-wide sweep. Source of truth is `package.json`; values are *derived*, not re-typed: `packageName` (`.name` → `@golem15/msd-core`), `binName` (`Object.keys(.bin)[0]` → `msd-core`), `repoSlug` (parsed from `.repository.url` → `golem15/msd-core`), plus derived `changelogRawUrl` and `manualInstallCommand({ scope, runtime })`. Generated `.cjs` per ADR-457 (generated-single-source); shipped under `msd-core/bin/lib/`. Three consumer worlds: **Node** consumers `require()` it at runtime (worker, `check-latest-version.cjs`, `bin/install.js`); the **bash launcher** snippet receives the literal injected by `scripts/sync-runtime-launcher.cjs` at sync time; **prose/help** literals (`update.md`, installer help) carry a committed copy. A drift-guard lint (`scripts/lint-package-identity-drift.cjs`, sibling to `check:alias-drift`) fails CI on any raw package/repo literal outside `package.json`, the generated module, and the value-checked materialization sites — this is what keeps the seam real (`two adapters`, not one). Replaces the contradictory pair it consolidates: the runtime-broken `require('../package.json').name` in `hooks/msd-check-update-worker.js` (#378, resolves to `undefined` post-install) and the hardcoded constant in `check-latest-version.cjs` (#2992). _Avoid_: "package name string", "the npm name" (when you mean the seam). See ADR-457 and Installer Module.
|
||||
|
||||
`SEAM.package-identity.owns=MSD's published-package coordinates (packageName, binName, repoSlug, changelogRawUrl, manualInstallCommand) — single seam so a repoint/rename is a one-line change`
|
||||
`SEAM.package-identity.enforced-by=test:tests/package-identity.test.cjs`
|
||||
@@ -702,7 +702,7 @@ The prompt-level data/instruction isolation seam for untrusted web/document ingr
|
||||
## Workspace seams (machine-oriented predicates)
|
||||
|
||||
`RULESET.GH.AUTH.DEFAULT=source .envrc GITHUB_TOKEN before gh; exception=ambient allowed only when user explicitly says machine-only fallback`
|
||||
`RULESET.CODERABBIT.GUARD.OPEN_PRS=gh pr list --repo golem15com/msd-core --author @me --state open; repeat near end because open PR set can change mid-run`
|
||||
`RULESET.CODERABBIT.GUARD.OPEN_PRS=gh pr list --repo golem15/msd-core --author @me --state open; repeat near end because open PR set can change mid-run`
|
||||
`RULESET.CODERABBIT.GUARD.COMPLETE=required_checks_green && coderabbit_check_pass && graphQL(reviewThreads.unresolved_count)==0`
|
||||
`RULESET.CODERABBIT.GUARD.GRAPHQL=reviewThreads(first:100){nodes{id isResolved comments{nodes{author body path line originalLine url}}}}; use unresolved threads as authoritative, not badge text alone`
|
||||
`RULESET.CODERABBIT.GUARD.RERUN=after every push wait for CodeRabbit completion, then re-query unresolved threads; CodeRabbit can add new findings after earlier threads were resolved`
|
||||
@@ -991,7 +991,7 @@ Dependency posture: this seam OWNS its Windows binary resolution and cmd.exe med
|
||||
|
||||
## PR fix discipline — patterns observed 2026-05-23
|
||||
|
||||
Full detail in `~/.claude/skills/msd-pr-fix-discipline/SKILL.md`. AI agents MUST check this section before pushing to `golem15com/msd-core`.
|
||||
Full detail in `~/.claude/skills/msd-pr-fix-discipline/SKILL.md`. AI agents MUST check this section before pushing to `golem15/msd-core`.
|
||||
|
||||
### INVENTORY / manifest drift
|
||||
|
||||
@@ -1009,7 +1009,7 @@ Full detail in `~/.claude/skills/msd-pr-fix-discipline/SKILL.md`. AI agents MUST
|
||||
|
||||
- **Symptom:** `gh pr checks` shows failures but the latest commit SHA's run was cancelled before Tests even started
|
||||
- **Affected this session:** #154, #136
|
||||
- **Fix:** `gh workflow run Tests --repo golem15com/msd-core --ref <branch>`; verify with `gh run list --branch <branch> --workflow Tests --limit 1 --json status,conclusion,headSha`
|
||||
- **Fix:** `gh workflow run Tests --repo golem15/msd-core --ref <branch>`; verify with `gh run list --branch <branch> --workflow Tests --limit 1 --json status,conclusion,headSha`
|
||||
|
||||
### Missing changeset fragment
|
||||
|
||||
@@ -1045,7 +1045,7 @@ Full detail in `~/.claude/skills/msd-pr-fix-discipline/SKILL.md`. AI agents MUST
|
||||
|
||||
- **Symptom:** `gh pr merge --auto` returns `GraphQL: Auto merge is not allowed for this repository`
|
||||
- **Affected this session:** All stacked PRs
|
||||
- **Fix:** Merge manually by hand in dependency order once CI greens; `gh pr merge <N> --squash --repo golem15com/msd-core`
|
||||
- **Fix:** Merge manually by hand in dependency order once CI greens; `gh pr merge <N> --squash --repo golem15/msd-core`
|
||||
|
||||
### Defect enforcement (ADR-2143 follow-on)
|
||||
Prose defect entries retired in favour of gates; the gate IS the record. `DEFECT.UNBOUNDED-SUBPROCESS` → `eslint-rules/require-subprocess-timeout.cjs` (error, `src/**`; options literal must carry `timeout` — git 5-30s, npm 60s; the rule only requires the call be bounded, not what the caller does after — 7 of the 8 sites this surfaced degrade to an empty/false/null result on failure, and the 1 that guards a destructive real-run migration (`roadmap-upgrade.cts`'s pre-mutation clean-tree check) correctly still throws rather than proceed against an unverified working tree). `DEFECT.CANARY-VERSION-LEAK` → `scripts/lint-canary-version-leak.cjs` + the `canary-version-leak` job in `.github/workflows/version-gate.yml` (PRs whose base is `main`). `DEFECT.CHANGESET-PR-FIELD-DRIFT` → `findPrFieldDrift` in `scripts/changeset/lint.cjs`. Entries whose condition no automated check can evaluate were deleted rather than kept as unenforceable prose. `DEFECT.FRONTMATTER-SCALAR-BROAD-GREP` → `scripts/lint-frontmatter-scalar-broad-grep.cjs` (in `lint:ci`; flags an unscoped `grep "^key:"` over a whole planning doc with no frontmatter slice and no `-m1`/`head -1` guard). `DEFECT.REMOVED-BUT-NEEDED` → `scripts/lint-removed-but-needed.cjs` (in `lint:ci`; a deleted file whose basename still appears in `.github/workflows/`, `msd-core/`, `docs/` or `package.json`; and since #3565, in `tests/` behind a `pins-existence` vs `asserts-absence` discriminator — `fs.existsSync`/`readFileSync`/`require`/quoted-object-key on the deleted basename fails, a negated `!…includes`/`!fs.existsSync` absence assertion is the correct post-deletion state and passes; a bare mention that is neither is not flagged, because the undiscriminated widening was tried in #3560 and reverted for firing on the very tests that prove a deletion worked). `DEFECT.DEFAULT-FLIP-DOCUMENTATION` → `scripts/lint-default-flip-documentation.cjs` + `.github/workflows/default-flip-documentation.yml`, covering `msd-core/bin/shared/config-defaults.manifest.json` only: a changed value for an EXISTING key requires a `## Breaking Changes` PR section. The six Windows-portability entries (`WINDOWS-TEST-PORTABILITY`, `WINDOWS-POSIX-MODE-BIT-ASSERT`, `WINDOWS-PATH-LEAK-IN-MARKDOWN-CONTENT`, `WINDOWS-PATH-LITERAL-IN-ASSERT`, `WINDOWS-FS-OPS`, `TEST-SHELL-PIPELINE-NONPORTABLE`) were already enforced by ADR-1703's own `local/*` AST ESLint rules (`no-posix-mode-bit-assert`, `normalize-path-in-content`, `no-path-literal-in-assert`, `require-fs-op-fallback`, `no-crlf-fragile-split`, `no-unguarded-nonportable-exec` — see `eslint.config.mjs`) before this PR; their prose duplicated the rules' own doc comments, so it was deleted rather than kept as a second copy. **Residual, deliberately unenforced:** `buildNewProjectConfig`'s hardcoded literal in `src/config.cts` has env-derived branches and `CONFIG_DEFAULTS` spreads, so no reliable resolved-value diff exists without executing the compiled module at both refs — a line-diff there false-fires on any refactor that merely moves the object, so it was left unchecked rather than shipped noisy.
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
|
||||
```bash
|
||||
# Clone the repo
|
||||
git clone https://github.com/golem15com/msd-core.git
|
||||
git clone https://git.golem15.com/golem15/msd-core.git
|
||||
cd msd-core
|
||||
|
||||
# Activate the pinned Node version from .nvmrc
|
||||
@@ -142,7 +142,7 @@ git checkout next
|
||||
git pull --ff-only origin next
|
||||
git checkout -b fix/3187-config-corruption
|
||||
# ... commit, push
|
||||
gh pr create --base next --repo golem15com/msd-core
|
||||
gh pr create --base next --repo golem15/msd-core
|
||||
```
|
||||
|
||||
If you target the wrong branch by accident, the `PR Target Validator`
|
||||
@@ -155,7 +155,7 @@ another PR to `next` lands — so in practice you rebase much less.
|
||||
|
||||
**But `next` does still require "up-to-date before merging".** Branch
|
||||
protection has `required_status_checks.strict = true`; check it yourself with
|
||||
`gh api repos/golem15com/msd-core/branches/next/protection --jq '.required_status_checks.strict'`.
|
||||
`gh api repos/golem15/msd-core/branches/next/protection --jq '.required_status_checks.strict'`.
|
||||
If another PR lands while yours is open, yours goes `BEHIND` and must be
|
||||
rebased before it can merge.
|
||||
|
||||
@@ -238,7 +238,7 @@ To re-format an existing release by hand (e.g. backfilling an older release):
|
||||
|
||||
```bash
|
||||
node scripts/release-notes/format-github-release-notes.cjs \
|
||||
--tag vX.Y.Z --repo golem15com/msd-core --apply
|
||||
--tag vX.Y.Z --repo golem15/msd-core --apply
|
||||
```
|
||||
|
||||
Omit `--apply` to print the reformatted body to stdout for review without
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
> `GEMINI.md`, inherited from the shared Gemini 3 backend).
|
||||
|
||||
This context gives Antigravity the operating context for
|
||||
[MSD Core](https://github.com/golem15com/msd-core), a meta-prompting,
|
||||
[MSD Core](https://git.golem15.com/golem15/msd-core), a meta-prompting,
|
||||
context-engineering, and spec-driven development system for AI coding agents.
|
||||
|
||||
## What MSD is
|
||||
@@ -52,4 +52,4 @@ namespace):
|
||||
- When unsure what to do next, and the msd commands are installed, `/msd-progress`
|
||||
is the situational entry point.
|
||||
|
||||
Learn more: <https://github.com/golem15com/msd-core>
|
||||
Learn more: <https://git.golem15.com/golem15/msd-core>
|
||||
|
||||
@@ -10,9 +10,9 @@
|
||||
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://discord.gg/mYgfVNfA2r)
|
||||
[](https://github.com/golem15com/msd-core)
|
||||
[](https://git.golem15.com/golem15/msd-core)
|
||||
[](LICENSE)
|
||||
|
||||
</div>
|
||||
@@ -103,11 +103,11 @@ npx @golem15/msd-core@latest
|
||||
|
||||
## スター履歴
|
||||
|
||||
<a href="https://star-history.com/#golem15com/msd-core&Date">
|
||||
<a href="https://star-history.com/#golem15/msd-core&Date">
|
||||
<picture>
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date" />
|
||||
</picture>
|
||||
</a>
|
||||
|
||||
|
||||
@@ -10,9 +10,9 @@
|
||||
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://discord.gg/mYgfVNfA2r)
|
||||
[](https://github.com/golem15com/msd-core)
|
||||
[](https://git.golem15.com/golem15/msd-core)
|
||||
[](LICENSE)
|
||||
|
||||
</div>
|
||||
@@ -103,11 +103,11 @@ npx @golem15/msd-core@latest
|
||||
|
||||
## 스타 히스토리
|
||||
|
||||
<a href="https://star-history.com/#golem15com/msd-core&Date">
|
||||
<a href="https://star-history.com/#golem15/msd-core&Date">
|
||||
<picture>
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date" />
|
||||
</picture>
|
||||
</a>
|
||||
|
||||
|
||||
25
README.md
25
README.md
@@ -8,11 +8,6 @@
|
||||
|
||||
**A light-weight meta-prompting, context engineering, and spec-driven development system for Claude Code, OpenCode, Antigravity CLI, Kimi CLI, Kilo, Codex, Copilot, Cursor, Windsurf, and more.**
|
||||
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://discord.gg/mYgfVNfA2r)
|
||||
[](https://github.com/golem15com/msd-core)
|
||||
[](LICENSE)
|
||||
|
||||
</div>
|
||||
@@ -39,11 +34,15 @@ Each milestone repeats the same five-step loop, one phase at a time:
|
||||
|
||||
## Quickstart
|
||||
|
||||
MSD Core is a private fork and is not published to npm. Install from the checkout:
|
||||
|
||||
```bash
|
||||
npx @golem15/msd-core@latest
|
||||
git clone git@git.golem15.com:golem15/msd-core.git
|
||||
cd msd-core
|
||||
scripts/install-golem15.sh # Node 24; installs for Claude Code and Codex
|
||||
```
|
||||
|
||||
The installer prompts for your runtime (Claude Code, OpenCode, Antigravity CLI, Kimi CLI, Kilo, Codex, Copilot, Cursor, Windsurf, and more) and whether to install globally or locally. The installer is required for cross-runtime compatibility — do not copy files from `agents/` or `commands/` directly.
|
||||
For any other runtime, run `node bin/install.js` directly. The installer prompts for your runtime (Claude Code, OpenCode, Antigravity CLI, Kimi CLI, Kilo, Codex, Copilot, Cursor, Windsurf, and more) and whether to install globally or locally. The installer is required for cross-runtime compatibility — do not copy files from `agents/` or `commands/` directly.
|
||||
|
||||
On another runtime or without Node.js? See [Install on your runtime](docs/how-to/install-on-your-runtime.md).
|
||||
|
||||
@@ -103,18 +102,6 @@ Troubleshooting? See [docs/how-to/recover-and-troubleshoot.md](docs/how-to/recov
|
||||
|
||||
---
|
||||
|
||||
## Star History
|
||||
|
||||
<a href="https://star-history.com/#golem15com/msd-core&Date">
|
||||
<picture>
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
</picture>
|
||||
</a>
|
||||
|
||||
---
|
||||
|
||||
## What MSD stands for
|
||||
|
||||
**Make Software Done.** The runners-up, preserved for posterity:
|
||||
|
||||
@@ -10,9 +10,9 @@
|
||||
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://discord.gg/mYgfVNfA2r)
|
||||
[](https://github.com/golem15com/msd-core)
|
||||
[](https://git.golem15.com/golem15/msd-core)
|
||||
[](LICENSE)
|
||||
|
||||
</div>
|
||||
@@ -103,11 +103,11 @@ Problemas? Consulte [docs/pt-BR/how-to/recover-and-troubleshoot.md](docs/pt-BR/h
|
||||
|
||||
## Histórico de estrelas
|
||||
|
||||
<a href="https://star-history.com/#golem15com/msd-core&Date">
|
||||
<a href="https://star-history.com/#golem15/msd-core&Date">
|
||||
<picture>
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date" />
|
||||
</picture>
|
||||
</a>
|
||||
|
||||
|
||||
@@ -10,9 +10,9 @@
|
||||
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://www.npmjs.com/package/@golem15/msd-core)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://github.com/open-gsd/gsd-core/actions/workflows/test.yml)
|
||||
[](https://discord.gg/mYgfVNfA2r)
|
||||
[](https://github.com/golem15com/msd-core)
|
||||
[](https://git.golem15.com/golem15/msd-core)
|
||||
[](LICENSE)
|
||||
|
||||
</div>
|
||||
@@ -103,11 +103,11 @@ npx @golem15/msd-core@latest
|
||||
|
||||
## Star History
|
||||
|
||||
<a href="https://star-history.com/#golem15com/msd-core&Date">
|
||||
<a href="https://star-history.com/#golem15/msd-core&Date">
|
||||
<picture>
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15com/msd-core&type=Date" />
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date&theme=dark" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=golem15/msd-core&type=Date" />
|
||||
</picture>
|
||||
</a>
|
||||
|
||||
|
||||
@@ -989,7 +989,7 @@
|
||||
{
|
||||
"id": "RULESET.CODERABBIT.GUARD.OPEN_PRS",
|
||||
"klass": "RULESET",
|
||||
"value": "gh pr list --repo golem15com/msd-core --author @me --state open; repeat near end because open PR set can change mid-run"
|
||||
"value": "gh pr list --repo golem15/msd-core --author @me --state open; repeat near end because open PR set can change mid-run"
|
||||
},
|
||||
{
|
||||
"id": "RULESET.CODERABBIT.GUARD.RERUN",
|
||||
|
||||
@@ -19,7 +19,7 @@ Ratified by explicit maintainer directive; the Status field had sat stale at "Pr
|
||||
- Four test files are present and current: `tests/review-default-reviewers-config.test.cjs`, `tests/review-default-reviewers-resolution.test.cjs`, `tests/review-default-reviewers-workflow.test.cjs`, `tests/review-reviewer-instances.test.cjs`.
|
||||
- `.changeset/archived/daring-badgers-munch.md` (type: Added, pr: 3464) is archived, confirming release tooling already processed it.
|
||||
|
||||
Governance state: the owning issue (`#3079`, referenced above) and its landing PR (`#3464`) both 404 against the current `golem15com/msd-core` tracker — their numbering belongs to a predecessor repo whose issue space predates this repo's 2026-05 range (which topped out near `#540`), consistent with known predecessor-repo numbering rather than a fabricated reference. No in-tracker close event is directly checkable; the shipped-code evidence above substitutes for it.
|
||||
Governance state: the owning issue (`#3079`, referenced above) and its landing PR (`#3464`) both 404 against the current `golem15/msd-core` tracker — their numbering belongs to a predecessor repo whose issue space predates this repo's 2026-05 range (which topped out near `#540`), consistent with known predecessor-repo numbering rather than a fabricated reference. No in-tracker close event is directly checkable; the shipped-code evidence above substitutes for it.
|
||||
|
||||
**Known gaps at ratification:** two of the ADR's own non-blocking open questions remain genuinely unresolved — Q-2 (`--no-default` flag) and Q-3 (`review.profiles.*` namespace) — exactly as the ADR itself scoped them as future/non-blocking, so this is expected rather than a regression.
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
- **Status:** Accepted — ratified 2026-07-17 (originally Proposed 2026-05-29); see "Ratification" below
|
||||
- **Date:** 2026-05-29
|
||||
- **Issue:** golem15com/msd-core#22
|
||||
- **Issue:** golem15/msd-core#22
|
||||
|
||||
## Ratification (2026-07-17): Proposed → Accepted
|
||||
|
||||
@@ -16,7 +16,7 @@ Ratified by explicit maintainer directive; the Status field sat at Proposed for
|
||||
- `msd-core/workflows/plan-phase.md` §7.9 ("Regenerate API-SURFACE.md (intel gate)") regenerates the surface only when the intel step hook is active and injects it into the planner prompt labeled "HINT ONLY... MAY BE INCOMPLETE... Never treat the surface as exhaustive" — matching Part 1 point 2 verbatim.
|
||||
- `msd-core/workflows/settings.md` and `msd-core/workflows/new-project.md` surface `plan_review.source_grounding` as a "Drift Guard" toggle/setup question; `docs/CONFIGURATION.md` documents both config keys, explicitly marking authority rungs 2-4 (treesitter/lsp/scip) as reserved with no effect in the current release.
|
||||
|
||||
Governance: owning issue golem15com/msd-core#22 — CLOSED, stateReason COMPLETED, closed 2026-05-30T21:08:13Z, labeled `enhancement` + `approved-feature`.
|
||||
Governance: owning issue golem15/msd-core#22 — CLOSED, stateReason COMPLETED, closed 2026-05-30T21:08:13Z, labeled `enhancement` + `approved-feature`.
|
||||
|
||||
## Context
|
||||
|
||||
@@ -88,7 +88,7 @@ Locked sub-decisions:
|
||||
- **Hard-block on any MISSING (as originally proposed).** Rejected for rung 0–1: false positives from dynamic/re-exported/generated symbols would block valid plans and get the default-on guard switched off. Retained only for rung >=3.
|
||||
|
||||
## References
|
||||
- Issue: golem15com/msd-core#22 (migrated from golem15com/msd-core#3813)
|
||||
- Issue: golem15/msd-core#22 (migrated from golem15/msd-core#3813)
|
||||
- Relates to #3802 (GitNexus first-class code intelligence) — rung 4 backend
|
||||
- arXiv:2409.20550 — hallucination taxonomy + RAG mitigation (modest gains)
|
||||
- arXiv:2502.05111 — grammar-constrained decoding (soft vs hard constraints)
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
## Why this is still `Proposed` (audited 2026-07-17)
|
||||
|
||||
The architectural shift is real and operating: the live default branch is
|
||||
`next` (`gh api repos/golem15com/msd-core --jq .default_branch`), `.github/workflows/auto-backmerge.yml`
|
||||
`next` (`gh api repos/golem15/msd-core --jq .default_branch`), `.github/workflows/auto-backmerge.yml`
|
||||
runs unconditionally (`if: true`, not the Phase-1 `if: false` stub) and has
|
||||
produced real, merged `main → next` back-merge PRs across multiple releases
|
||||
(#671, #1337, #1673, and others), `release.yml` cherry-picks from
|
||||
@@ -23,7 +23,7 @@ produced real, merged `main → next` back-merge PRs across multiple releases
|
||||
protection: `main` — "strict: 2 reviewer approvals, all CI green, ...
|
||||
restrict push to maintainers via PR only"; `next` — "loose: ... 'require
|
||||
branches up to date' OFF." Live settings invert this. `main`'s classic
|
||||
branch protection (verified via `gh api repos/golem15com/msd-core/branches/main/protection`
|
||||
branch protection (verified via `gh api repos/golem15/msd-core/branches/main/protection`
|
||||
and its `required_pull_request_reviews` / `required_status_checks`
|
||||
sub-resources) shows `required_approving_review_count: 1` (spec: 2),
|
||||
`required_status_checks` returns 404 "not enabled" (spec: all CI green
|
||||
@@ -65,9 +65,9 @@ corrected `ref_name` conditions or removed as redundant with classic
|
||||
protection. Verify with:
|
||||
|
||||
```
|
||||
gh api repos/golem15com/msd-core/branches/main/protection/required_pull_request_reviews --jq .required_approving_review_count # expect 2
|
||||
gh api repos/golem15com/msd-core/branches/main/protection/required_status_checks # expect 200, not 404
|
||||
gh api repos/golem15com/msd-core/branches/main/protection --jq .allow_force_pushes.enabled # expect false
|
||||
gh api repos/golem15/msd-core/branches/main/protection/required_pull_request_reviews --jq .required_approving_review_count # expect 2
|
||||
gh api repos/golem15/msd-core/branches/main/protection/required_status_checks # expect 200, not 404
|
||||
gh api repos/golem15/msd-core/branches/main/protection --jq .allow_force_pushes.enabled # expect false
|
||||
```
|
||||
|
||||
Until then, either bring `main`'s protection into line with the Decision
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Issue tracker: GitHub
|
||||
|
||||
Issues for this repo live in **GitHub Issues** at `golem15com/msd-core`.
|
||||
Issues for this repo live in **GitHub Issues** at `golem15/msd-core`.
|
||||
|
||||
## Auth
|
||||
|
||||
@@ -9,19 +9,19 @@ repo-local `.envrc` before running `gh`.
|
||||
|
||||
## Conventions
|
||||
|
||||
- **Create**: `gh issue create --repo golem15com/msd-core --title "..." --body "..."`
|
||||
- **Read**: `gh issue view <number> --repo golem15com/msd-core --comments`
|
||||
- **List**: `gh issue list --repo golem15com/msd-core --state open --json number,title,labels --jq '...'`
|
||||
- **Comment**: `gh issue comment <number> --repo golem15com/msd-core --body "..."`
|
||||
- **Label**: `gh issue edit <number> --repo golem15com/msd-core --add-label "..." --remove-label "..."`
|
||||
- **Close**: `gh issue close <number> --repo golem15com/msd-core --comment "..."`
|
||||
- **Create**: `gh issue create --repo golem15/msd-core --title "..." --body "..."`
|
||||
- **Read**: `gh issue view <number> --repo golem15/msd-core --comments`
|
||||
- **List**: `gh issue list --repo golem15/msd-core --state open --json number,title,labels --jq '...'`
|
||||
- **Comment**: `gh issue comment <number> --repo golem15/msd-core --body "..."`
|
||||
- **Label**: `gh issue edit <number> --repo golem15/msd-core --add-label "..." --remove-label "..."`
|
||||
- **Close**: `gh issue close <number> --repo golem15/msd-core --comment "..."`
|
||||
|
||||
Always pass `--repo golem15com/msd-core` explicitly — the local clone has multiple remotes and `gh` may resolve to the wrong one.
|
||||
Always pass `--repo golem15/msd-core` explicitly — the local clone has multiple remotes and `gh` may resolve to the wrong one.
|
||||
|
||||
## When a skill says "publish to the issue tracker"
|
||||
|
||||
Create a GitHub issue at `golem15com/msd-core`.
|
||||
Create a GitHub issue at `golem15/msd-core`.
|
||||
|
||||
## When a skill says "fetch the relevant ticket"
|
||||
|
||||
Run `gh issue view <number> --repo golem15com/msd-core --comments`.
|
||||
Run `gh issue view <number> --repo golem15/msd-core --comments`.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Triage Labels
|
||||
|
||||
Maps the five canonical triage roles to the actual label strings in `golem15com/msd-core`.
|
||||
Maps the five canonical triage roles to the actual label strings in `golem15/msd-core`.
|
||||
|
||||
| Canonical role | Label in this repo | Notes |
|
||||
|-------------------|--------------------------|----------------------------------------------------------------|
|
||||
|
||||
@@ -38,13 +38,13 @@ immutable once created. Tag creation is unrestricted.
|
||||
|
||||
```bash
|
||||
# Dry-run (evaluate mode — logs violations, does not block)
|
||||
REPO=golem15com/msd-core ENFORCEMENT=evaluate bash scripts/sync-rulesets.sh
|
||||
REPO=golem15/msd-core ENFORCEMENT=evaluate bash scripts/sync-rulesets.sh
|
||||
|
||||
# Activate protection
|
||||
REPO=golem15com/msd-core ENFORCEMENT=active bash scripts/sync-rulesets.sh
|
||||
REPO=golem15/msd-core ENFORCEMENT=active bash scripts/sync-rulesets.sh
|
||||
|
||||
# Roll back to disabled
|
||||
REPO=golem15com/msd-core ENFORCEMENT=disabled bash scripts/sync-rulesets.sh
|
||||
REPO=golem15/msd-core ENFORCEMENT=disabled bash scripts/sync-rulesets.sh
|
||||
```
|
||||
|
||||
The script is idempotent: running it twice with the same `ENFORCEMENT` value
|
||||
@@ -55,7 +55,7 @@ is a no-op semantically (PUT with identical body).
|
||||
After applying with `evaluate`, check which PRs/pushes would have been blocked:
|
||||
|
||||
```bash
|
||||
REPO=golem15com/msd-core
|
||||
REPO=golem15/msd-core
|
||||
RULESET_ID=$(gh api repos/$REPO/rulesets --jq '.[] | select(.name=="main-protection") | .id')
|
||||
gh api repos/$REPO/rulesets/$RULESET_ID/rule-suites
|
||||
```
|
||||
|
||||
@@ -102,7 +102,7 @@ git add -A && git commit -m "fix: harden config parse for trailing comma"
|
||||
git push -u origin fix/3187-config-corruption
|
||||
|
||||
# 4. Open a PR. Target = next. (Don't change the target.)
|
||||
gh pr create --base next --repo golem15com/msd-core
|
||||
gh pr create --base next --repo golem15/msd-core
|
||||
|
||||
# 5. CI runs. Reviewer approves. PR squash-merges into `next`.
|
||||
# Your branch auto-deletes.
|
||||
|
||||
@@ -36,7 +36,7 @@ will read it.
|
||||
|
||||
```bash
|
||||
# 1. Clone
|
||||
git clone https://github.com/golem15com/msd-core.git
|
||||
git clone https://git.golem15.com/golem15/msd-core.git
|
||||
cd msd-core
|
||||
|
||||
# 2. Activate the pinned Node version
|
||||
|
||||
@@ -100,7 +100,7 @@ Example: `docs/adr/2264-golden-parity-redesign.md`.
|
||||
|
||||
**Why:** GitHub issue numbers are server-assigned and atomic — the reservation mechanism already exists because the issue-first rule requires it. Promoting the issue# to the artifact ID eliminates the entire collision class that the `NNNN-*` local-compute scheme created (see the `0010-*` × 2 and `0011-*` × 3 duplicates on disk).
|
||||
|
||||
**Migration policy:** Legacy ADRs keep their numbers as immutable historical record — see the **[authoritative legacy-range statement in `docs/adr/README.md`](./adr/README.md#legacy-naming-is-not-legacy-status)** for exactly which zero-padded files that covers (and which zero-padded files are actually modern, mis-padded). Do not renumber legacy files. The new convention applies to all ADRs and PRDs created on or after the merge of the implementing PR (#3485 — a pre-rename number from `get-shit-done-redux`; it does not resolve in `golem15com/msd-core`, whose issue numbering restarted at the rename).
|
||||
**Migration policy:** Legacy ADRs keep their numbers as immutable historical record — see the **[authoritative legacy-range statement in `docs/adr/README.md`](./adr/README.md#legacy-naming-is-not-legacy-status)** for exactly which zero-padded files that covers (and which zero-padded files are actually modern, mis-padded). Do not renumber legacy files. The new convention applies to all ADRs and PRDs created on or after the merge of the implementing PR (#3485 — a pre-rename number from `get-shit-done-redux`; it does not resolve in `golem15/msd-core`, whose issue numbering restarted at the rename).
|
||||
|
||||
For the end-to-end workflow — opening the issue, waiting for approval, creating the file, and submitting the PR — see **[CONTRIBUTING.md — "Proposing an ADR or PRD"](../CONTRIBUTING.md#proposing-an-adr-or-prd)**.
|
||||
|
||||
|
||||
@@ -28,7 +28,7 @@ Currently, Grok Build is only supported via its Claude compatibility layer. This
|
||||
## 2. Current Multi-Runtime Setup (as of May 2026)
|
||||
|
||||
### Development Source (Single Source of Truth)
|
||||
- **Path:** `/home/cristian/bum/msd-core` (this repo — your working fork of `golem15com/msd-core`)
|
||||
- **Path:** `/home/cristian/bum/msd-core` (this repo — your working fork of `golem15/msd-core`)
|
||||
|
||||
### Installed Locations
|
||||
- `~/.agents/msd-core/` — Core workflows, references, templates, `msd-tools.cjs`, `bin/`
|
||||
|
||||
@@ -112,7 +112,7 @@ Node.js (`node`) must also be available on your `PATH`. The plugin's always-on g
|
||||
|
||||
MSD Core also ships a `.claude-plugin/marketplace.json` marketplace manifest (sibling to `plugin.json`). Runtimes that implement the Claude plugin marketplace contract — such as ZCODE — can discover and install MSD Core from a custom marketplace source without a manual clone:
|
||||
|
||||
1. In your runtime's plugin UI, add a custom marketplace source pointing at `golem15com/msd-core` (GitHub `owner/repo` form).
|
||||
1. In your runtime's plugin UI, add a custom marketplace source pointing at `golem15/msd-core` (GitHub `owner/repo` form).
|
||||
2. MSD Core appears in the catalog and can be installed directly from the UI.
|
||||
|
||||
This path is **additive** and changes nothing about the Claude Code plugin install above (`.claude-plugin/plugin.json` is unchanged). The marketplace entry's `source` is `./`, so it reuses `plugin.json`'s `commands` / `skills` / `hooks` mapping. The catalog version tracks `package.json` (it lives at `plugins[0].version` and is stamped by the release version-sync), so the version you see in the marketplace matches the npm release.
|
||||
|
||||
@@ -5,7 +5,7 @@ Use this procedure when `npx @golem15/msd-core@latest` is unavailable — e.g. d
|
||||
## Prerequisites
|
||||
|
||||
- Node.js installed
|
||||
- This repo cloned locally (`git clone https://github.com/golem15com/msd-core`)
|
||||
- This repo cloned locally (`git clone https://git.golem15.com/golem15/msd-core`)
|
||||
|
||||
## Steps
|
||||
|
||||
|
||||
@@ -41,7 +41,7 @@ The top-level README still mixes legacy transition language, personal attributio
|
||||
|
||||
## Acceptance Criteria
|
||||
|
||||
1. README contains a continuity notice naming `golem15com/msd-core` as canonical.
|
||||
1. README contains a continuity notice naming `golem15/msd-core` as canonical.
|
||||
2. README removes personal legacy attribution in origin-story prose.
|
||||
3. README strongly recommends migration away from legacy artifacts.
|
||||
4. README links to Discussions #109 and #119.
|
||||
|
||||
@@ -11,7 +11,7 @@ The ADR defines the target architecture — one source of truth per Shared Modul
|
||||
|
||||
## Problem statement
|
||||
|
||||
The CJS↔SDK boundary in `golem15com/msd-core` is structurally permeable. Multiple Shared Modules — STATE.md Document Module, Workstream Inventory Module, and several others — exist today as **hand-synced pairs** of `.cjs` and `.ts` files with character-identical implementations. Constants (`CONFIG_DEFAULTS`, `VALID_CONFIG_KEYS`) are likewise defined twice. The boundary is policed only by:
|
||||
The CJS↔SDK boundary in `golem15/msd-core` is structurally permeable. Multiple Shared Modules — STATE.md Document Module, Workstream Inventory Module, and several others — exist today as **hand-synced pairs** of `.cjs` and `.ts` files with character-identical implementations. Constants (`CONFIG_DEFAULTS`, `VALID_CONFIG_KEYS`) are likewise defined twice. The boundary is policed only by:
|
||||
|
||||
- A naming-parity test (`tests/config-schema-sdk-parity.test.cjs`)
|
||||
- Output-parity golden tests for read-only handlers (`sdk/src/golden/read-only-parity.integration.test.ts`)
|
||||
|
||||
@@ -24,7 +24,7 @@ Exit code 134 = 128 + SIGABRT (signal 6). V8 emits `FATAL ERROR: Ineffective mar
|
||||
|
||||
## 3. Runner headroom
|
||||
|
||||
`finalize` runs on plain `runs-on: ubuntu-latest` (`.github/workflows/release.yml:547`, no `runs-on:` overrides), which is `golem15com/msd-core` — a public repo — so it gets GitHub's **public-repo standard Linux runner: 4 vCPU, 16 GB RAM, 14 GB SSD** ([GitHub Docs: Supported runners and hardware resources](https://docs.github.com/en/actions/reference/github-hosted-runners-reference)). Against 16 GB physical RAM, the current `--max-old-space-size=6144` (6 GB) leaves meaningful headroom before an OS-level OOM-kill — raising the flag further (e.g. to 10-12 GB) is a viable stopgap purely on paper, but it is treating the symptom: the underlying `_loadReports()` call still holds every raw V8 file for the whole 1785-test run in memory simultaneously before merging, so the ceiling will eventually be hit again as the suite grows, same as it was hit after the *first* raise from whatever the previous default was to 6144. GitHub-hosted "larger runners" (paid, up to 64 GB) are available as a deferred escape hatch if a real fix is not shipped, but they cost money and still only delay the same unbounded-memory-shape problem.
|
||||
`finalize` runs on plain `runs-on: ubuntu-latest` (`.github/workflows/release.yml:547`, no `runs-on:` overrides), which is `golem15/msd-core` — a public repo — so it gets GitHub's **public-repo standard Linux runner: 4 vCPU, 16 GB RAM, 14 GB SSD** ([GitHub Docs: Supported runners and hardware resources](https://docs.github.com/en/actions/reference/github-hosted-runners-reference)). Against 16 GB physical RAM, the current `--max-old-space-size=6144` (6 GB) leaves meaningful headroom before an OS-level OOM-kill — raising the flag further (e.g. to 10-12 GB) is a viable stopgap purely on paper, but it is treating the symptom: the underlying `_loadReports()` call still holds every raw V8 file for the whole 1785-test run in memory simultaneously before merging, so the ceiling will eventually be hit again as the suite grows, same as it was hit after the *first* raise from whatever the previous default was to 6144. GitHub-hosted "larger runners" (paid, up to 64 GB) are available as a deferred escape hatch if a real fix is not shipped, but they cost money and still only delay the same unbounded-memory-shape problem.
|
||||
|
||||
## 4. Options considered
|
||||
|
||||
|
||||
@@ -87,11 +87,11 @@ Contrary to the initial framing, this check **passed** (`gh pr checks 3927`: `Pu
|
||||
- The sweep's PR body (`ack-fragment-sweep.yml:243-261`) is freeform prose — no `## Fix PR` / `## Enhancement PR` / `## Feature PR` heading, none of the required headings in `TEMPLATES` (`pr-template-policy.cjs:55-97`).
|
||||
- The changed-files carve-out does not apply: `tests/emitted-drift-acks/*.json` is not in `TOOLING_PATH_ALLOWLIST` (`pr-template-policy.cjs:24-43`), so `allPathsAreTooling` returns `false`.
|
||||
- `matchingTemplate()` finds no heading match → `template: null` → falls to `reason = 'PR body does not match the fix, enhancement, or feature template.'`, `valid: false` (`pr-template-policy.cjs:217-223`).
|
||||
- The consequence is gated on **author trust**, not template compliance (`pr-template-policy.cjs:226-229`): `action = trusted ? 'warn' : 'close'`. `TRUSTED_AUTHOR_ASSOCIATIONS` includes `MEMBER` (line 6-11). The PR's actual author association is `MEMBER` (`gh api repos/golem15com/msd-core/pulls/3927 --jq '.author_association'` → `MEMBER`), because the workflow authenticates `gh pr create` with `MSD_BOT_PR_TOKEN` — a personal-access token belonging to a real maintainer account (`trek-e`), not a GitHub App/bot identity. So `action: warn`: the `msd-pr-template-policy` bot comment fires (`core.warning`, `pr-template-format.yml`'s "Warn trusted contributor" step), but the workflow only `core.setFailed`s on `action == 'close'` — never reached. The template body is objectively wrong; the check is objectively green.
|
||||
- The consequence is gated on **author trust**, not template compliance (`pr-template-policy.cjs:226-229`): `action = trusted ? 'warn' : 'close'`. `TRUSTED_AUTHOR_ASSOCIATIONS` includes `MEMBER` (line 6-11). The PR's actual author association is `MEMBER` (`gh api repos/golem15/msd-core/pulls/3927 --jq '.author_association'` → `MEMBER`), because the workflow authenticates `gh pr create` with `MSD_BOT_PR_TOKEN` — a personal-access token belonging to a real maintainer account (`trek-e`), not a GitHub App/bot identity. So `action: warn`: the `msd-pr-template-policy` bot comment fires (`core.warning`, `pr-template-format.yml`'s "Warn trusted contributor" step), but the workflow only `core.setFailed`s on `action == 'close'` — never reached. The template body is objectively wrong; the check is objectively green.
|
||||
|
||||
### B8. `Required tests` / `test (ubuntu-latest, 24)` — the fast-signal lane ran the WHOLE suite and hit its own 15-minute cap
|
||||
|
||||
`gh run view 33059472019 --repo golem15com/msd-core --log-failed` and the per-job API (`jobs/98474440239`, `jobs/98478252101`) show:
|
||||
`gh run view 33059472019 --repo golem15/msd-core --log-failed` and the per-job API (`jobs/98474440239`, `jobs/98478252101`) show:
|
||||
|
||||
- `test (ubuntu-latest, 24)` — the **unsharded** matrix entry (`.github/workflows/test.yml:198-200`: `{os: ubuntu-latest, node-version: 24, scope: targeted}`, no `shard` key, hence the bare job name per the `name:` template at `test.yml:130`) — started `09:38:38Z`, its "Run scoped tests" step ran from `09:39:10Z` to `09:53:51Z` (14m41s), and the whole job was marked `cancelled` at `09:53:56Z`, total **15m18s** — exactly the job's `timeout-minutes: 15` cap (`test.yml:155`).
|
||||
- The raw log for that job shows `run-tests: suite="all" files=827` at `09:39:11Z`, and the job reached only `chunk 13/14` before being killed (`chunk 13/14 — 61 files` at `09:52:37Z`) — i.e. it was running virtually the entire test corpus (827 files) in one unsharded process, not a narrow "targeted/fast-signal" subset. The three actually-sharded ubuntu `scope: full` jobs (which exist precisely to spread this same corpus across 3 runners, per the `#2952`/`#3057` comments at `test.yml:141-164`) all finished successfully in 6-9 minutes each.
|
||||
@@ -101,7 +101,7 @@ Contrary to the initial framing, this check **passed** (`gh pr checks 3927`: `Pu
|
||||
|
||||
### B9. How #3927 was actually merged despite red required checks
|
||||
|
||||
`gh api repos/golem15com/msd-core/pulls/3927 --jq '.merged_by.login, .merge_commit_sha, .author_association'` → `trek-e`, `ad6abc896...`, `MEMBER`. The PR was opened `09:38:15Z` and merged `12:16:49Z` (2h38m later) by the same account, `trek-e` (a human maintainer, `is_bot: false` per `gh pr list ... --json mergedBy`). The timeline (`gh api .../issues/3927/timeline`) shows only `review_requested` → two bot `commented` events → `merged`/`closed`/`head_ref_deleted`, all attributed to `trek-e` or `github-actions[bot]`; no re-run or re-triggered check event appears between open and merge. `gh pr checks 3927` (queried post-merge) still reports `validate-title fail` and `Required tests fail` as the latest, final state of those checks — they were never turned green. The merge therefore landed with required checks still red: a maintainer override (admin merge / branch-protection bypass), not an automatic pass triggered by the automation.
|
||||
`gh api repos/golem15/msd-core/pulls/3927 --jq '.merged_by.login, .merge_commit_sha, .author_association'` → `trek-e`, `ad6abc896...`, `MEMBER`. The PR was opened `09:38:15Z` and merged `12:16:49Z` (2h38m later) by the same account, `trek-e` (a human maintainer, `is_bot: false` per `gh pr list ... --json mergedBy`). The timeline (`gh api .../issues/3927/timeline`) shows only `review_requested` → two bot `commented` events → `merged`/`closed`/`head_ref_deleted`, all attributed to `trek-e` or `github-actions[bot]`; no re-run or re-triggered check event appears between open and merge. `gh pr checks 3927` (queried post-merge) still reports `validate-title fail` and `Required tests fail` as the latest, final state of those checks — they were never turned green. The merge therefore landed with required checks still red: a maintainer override (admin merge / branch-protection bypass), not an automatic pass triggered by the automation.
|
||||
|
||||
### B10. No auto-merge path exists for the sweep PR
|
||||
|
||||
@@ -109,11 +109,11 @@ Contrary to the initial framing, this check **passed** (`gh pr checks 3927`: `Pu
|
||||
|
||||
### B11. `MSD_BOT_PR_TOKEN` fallback warning did NOT fire — ruled out as a cause
|
||||
|
||||
`gh run view 33059445125 --repo golem15com/msd-core --log` (the sweep workflow's own run) shows the "Open the sweep PR" step's env block: `HAS_BOT_TOKEN: 1`. The step's guard is `if [ -z "${HAS_BOT_TOKEN:-}" ]; then echo '::warning::MSD_BOT_PR_TOKEN is unset...'; fi` (`ack-fragment-sweep.yml:191-193`) — with `HAS_BOT_TOKEN=1` this branch is skipped, and indeed no such warning line appears anywhere in the run log. `MSD_BOT_PR_TOKEN` **was** configured and used. This is corroborated independently by B7/B9: the PR's `author_association` is `MEMBER` (not the unauthenticated-fallback shape) and the title/template *required* checks did run and report real verdicts (`validate-title`, `Pull request template format` both executed) — under the `GITHUB_TOKEN` fallback the workflow's own comment (`ack-fragment-sweep.yml:189`) states "no required checks will run on it," which is not what happened. **The fallback-token hypothesis is not the cause of this hang.** (Git commit authorship on the branch itself still reads `github-actions[bot]` per `git config user.name` at `ack-fragment-sweep.yml:204-205` — a separate, cosmetic identity from the `gh` API actor, which is `trek-e` via the PAT.)
|
||||
`gh run view 33059445125 --repo golem15/msd-core --log` (the sweep workflow's own run) shows the "Open the sweep PR" step's env block: `HAS_BOT_TOKEN: 1`. The step's guard is `if [ -z "${HAS_BOT_TOKEN:-}" ]; then echo '::warning::MSD_BOT_PR_TOKEN is unset...'; fi` (`ack-fragment-sweep.yml:191-193`) — with `HAS_BOT_TOKEN=1` this branch is skipped, and indeed no such warning line appears anywhere in the run log. `MSD_BOT_PR_TOKEN` **was** configured and used. This is corroborated independently by B7/B9: the PR's `author_association` is `MEMBER` (not the unauthenticated-fallback shape) and the title/template *required* checks did run and report real verdicts (`validate-title`, `Pull request template format` both executed) — under the `GITHUB_TOKEN` fallback the workflow's own comment (`ack-fragment-sweep.yml:189`) states "no required checks will run on it," which is not what happened. **The fallback-token hypothesis is not the cause of this hang.** (Git commit authorship on the branch itself still reads `github-actions[bot]` per `git config user.name` at `ack-fragment-sweep.yml:204-205` — a separate, cosmetic identity from the `gh` API actor, which is `trek-e` via the PAT.)
|
||||
|
||||
## C. Track record — is #3927 representative or a one-off?
|
||||
|
||||
`gh pr list --repo golem15com/msd-core --search "head:chore/ack-sweep" --state all --limit 30 --json number,title,state,createdAt,mergedAt,mergedBy` returns **exactly one PR**: #3927 itself (opened `09:38:15Z`, merged `12:16:49Z`, `mergedBy: trek-e`). There is no prior sweep PR to compare against — this is the automation's first (and so far only) production run that produced a non-empty plan and opened a PR. It cannot yet be called "systematically failing" by volume, but the failure mechanism identified in B8 is a property of the scope-classification table and the sweep's title-generation code, not of this specific run's data — so it will reproduce on the *next* sweep PR with high confidence, absent a fix to either `ack-fragment-sweep.yml`'s title format or `scripts/ci-test-scope.cjs`'s `RULES` table (or both).
|
||||
`gh pr list --repo golem15/msd-core --search "head:chore/ack-sweep" --state all --limit 30 --json number,title,state,createdAt,mergedAt,mergedBy` returns **exactly one PR**: #3927 itself (opened `09:38:15Z`, merged `12:16:49Z`, `mergedBy: trek-e`). There is no prior sweep PR to compare against — this is the automation's first (and so far only) production run that produced a non-empty plan and opened a PR. It cannot yet be called "systematically failing" by volume, but the failure mechanism identified in B8 is a property of the scope-classification table and the sweep's title-generation code, not of this specific run's data — so it will reproduce on the *next* sweep PR with high confidence, absent a fix to either `ack-fragment-sweep.yml`'s title format or `scripts/ci-test-scope.cjs`'s `RULES` table (or both).
|
||||
|
||||
## Open questions
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
### Repos in scope
|
||||
|
||||
All active, non-archived repositories under the `open-gsd` GitHub organization,
|
||||
beginning with the pilot repo `golem15com/msd-core`.
|
||||
beginning with the pilot repo `golem15/msd-core`.
|
||||
|
||||
### Out of scope
|
||||
|
||||
@@ -26,7 +26,7 @@ beginning with the pilot repo `golem15com/msd-core`.
|
||||
|
||||
This section defines the mandatory security controls for every in-scope repo.
|
||||
Each control links to the PR that implements it in the pilot repo
|
||||
(`golem15com/msd-core`). Sibling repos adopt the same controls during
|
||||
(`golem15/msd-core`). Sibling repos adopt the same controls during
|
||||
Phase 2 rollout (§ 6).
|
||||
|
||||
### 2.1 Dependency integrity
|
||||
@@ -299,7 +299,7 @@ If private advisory filing is unavailable, contact the open-gsd maintainers and
|
||||
|
||||
```text
|
||||
Title: [Short description, e.g., "Secret exposed in CI log for PR #NNN"]
|
||||
Affected repo: golem15com/msd-core (or sibling repo name)
|
||||
Affected repo: golem15/msd-core (or sibling repo name)
|
||||
Affected ver: [npm version range, e.g., "<=1.42.3" or "all versions"]
|
||||
Reporter: [Your name / handle, or "Anonymous"]
|
||||
Date found: YYYY-MM-DD
|
||||
@@ -388,7 +388,7 @@ Responsibilities:
|
||||
|
||||
| Step | Detail |
|
||||
|---|---|
|
||||
| 1 | Requester opens a GitHub issue in `golem15com/msd-core` tagged `security-exception` |
|
||||
| 1 | Requester opens a GitHub issue in `golem15/msd-core` tagged `security-exception` |
|
||||
| 2 | Issue describes: which control, why the exception is needed, proposed compensating control |
|
||||
| 3 | One maintainer approves the exception in the issue thread |
|
||||
| 4 | Exception is time-limited: maximum 90 days. Requester must file a renewal or close the issue. |
|
||||
@@ -398,7 +398,7 @@ Responsibilities:
|
||||
|
||||
## 6. Rollout plan
|
||||
|
||||
### Phase 1 — Pilot: `golem15com/msd-core` (in progress)
|
||||
### Phase 1 — Pilot: `golem15/msd-core` (in progress)
|
||||
|
||||
| Item | Status | Owner | Target date | Exit criteria |
|
||||
|---|---|---|---|---|
|
||||
|
||||
@@ -1181,7 +1181,7 @@
|
||||
{
|
||||
"id": "RULESET.CODERABBIT.GUARD.OPEN_PRS",
|
||||
"klass": "RULESET",
|
||||
"value": "gh pr list --repo golem15com/msd-core --author @me --state open; repeat near end because open PR set can change mid-run",
|
||||
"value": "gh pr list --repo golem15/msd-core --author @me --state open; repeat near end because open PR set can change mid-run",
|
||||
"line": 697
|
||||
},
|
||||
{
|
||||
|
||||
@@ -5,9 +5,9 @@
|
||||
|
||||
const packageName = "@golem15/msd-core";
|
||||
const binName = "msd-core";
|
||||
const repoSlug = "golem15com/msd-core";
|
||||
const repoUrl = "https://github.com/golem15com/msd-core";
|
||||
const changelogRawUrl = "https://raw.githubusercontent.com/golem15com/msd-core/main/CHANGELOG.md";
|
||||
const repoSlug = "golem15/msd-core";
|
||||
const repoUrl = "https://git.golem15.com/golem15/msd-core";
|
||||
const changelogRawUrl = "https://git.golem15.com/golem15/msd-core/raw/branch/next/CHANGELOG.md";
|
||||
const cacheSlug = "golem15-msd-core";
|
||||
const updateCacheFileName = "msd-update-check-golem15-msd-core.json";
|
||||
|
||||
|
||||
@@ -2350,7 +2350,7 @@ function dispatchOverlayCapabilityCommand({ command, args, cwd, raw, error, load
|
||||
// MSD_RUNTIME > config.runtime > 'claude' and does not consult the
|
||||
// per-install `.msd-runtime` marker, so on a non-Claude install whose
|
||||
// project config carries no `runtime` key this resolves 'claude'. That is
|
||||
// golem15com/msd-core#2395 — a pre-existing defect in the canonical
|
||||
// golem15/msd-core#2395 — a pre-existing defect in the canonical
|
||||
// resolver, not introduced here, and deliberately NOT fixed in this PR
|
||||
// (its blast radius reaches every consumer of that resolver, so it is
|
||||
// being handled on its own).
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
> `agent_skills.<agent-type>` mapping reaches the agent that actually does the work —
|
||||
> even when the orchestrator did not run bash init (e.g. a runtime whose `Skill()`
|
||||
> delegation does not reliably execute the delegated workflow's bash, such as Cursor;
|
||||
> see golem15com/msd-core#1600 / #1601). This is the durable counterpart to the
|
||||
> see golem15/msd-core#1600 / #1601). This is the durable counterpart to the
|
||||
> orchestrator-side injection documented under
|
||||
> [Agent Skills Injection](../../docs/CONFIGURATION.md#agent-skills-injection).
|
||||
|
||||
|
||||
@@ -132,7 +132,7 @@ If `INTERACTIVE` is set, display: `Mode: Interactive (discuss inline, plan+execu
|
||||
If `section_manifest` is `null` or `"converge-banner"` is in its `included` list: read and execute `msd-core/workflows/autonomous/steps/converge-banner.md`. Otherwise skip — do not read the file.
|
||||
<!-- /msd:section -->
|
||||
|
||||
**Agent skills (delegated agents self-load):** This workflow delegates plan/execute/review via flat `Skill()` invocations rather than resolving `agent_skills` itself. Each consumer agent (`msd-planner`, `msd-executor`, `msd-plan-checker`, `msd-verifier`, …) self-loads its configured `.planning/config.json` `agent_skills` in its own mandatory init step per `@~/.claude/msd-core/references/agent-skills-bootstrap.md`. This is the durable path that works on every runtime — including Cursor, where `Skill()`-delegated workflow bash init does not reliably execute. No per-delegation injection is needed here. See golem15com/msd-core#1866.
|
||||
**Agent skills (delegated agents self-load):** This workflow delegates plan/execute/review via flat `Skill()` invocations rather than resolving `agent_skills` itself. Each consumer agent (`msd-planner`, `msd-executor`, `msd-plan-checker`, `msd-verifier`, …) self-loads its configured `.planning/config.json` `agent_skills` in its own mandatory init step per `@~/.claude/msd-core/references/agent-skills-bootstrap.md`. This is the durable path that works on every runtime — including Cursor, where `Skill()`-delegated workflow bash init does not reliably execute. No per-delegation injection is needed here. See golem15/msd-core#1866.
|
||||
|
||||
</step>
|
||||
|
||||
|
||||
@@ -258,14 +258,14 @@ If actionable anomalies were found (HIGH or MEDIUM confidence):
|
||||
If confirmed:
|
||||
```bash
|
||||
# Check if "bug" label exists before using it
|
||||
BUG_LABEL=$(gh label list --repo golem15com/msd-core --search "bug" --json name -q '.[0].name' 2>/dev/null)
|
||||
BUG_LABEL=$(gh label list --repo golem15/msd-core --search "bug" --json name -q '.[0].name' 2>/dev/null)
|
||||
LABEL_FLAG=""
|
||||
if [ -n "$BUG_LABEL" ]; then
|
||||
LABEL_FLAG="--label bug"
|
||||
fi
|
||||
|
||||
gh issue create \
|
||||
--repo golem15com/msd-core \
|
||||
--repo golem15/msd-core \
|
||||
--title "bug: {concise description from anomaly}" \
|
||||
$LABEL_FLAG \
|
||||
--body "{formatted findings from report}"
|
||||
|
||||
@@ -220,8 +220,8 @@ Exit.
|
||||
|
||||
```bash
|
||||
CHANGELOG_TMP="/tmp/msd-changelog-$$.md"
|
||||
curl -fsSL "https://raw.githubusercontent.com/golem15com/msd-core/main/CHANGELOG.md" -o "$CHANGELOG_TMP" 2>/dev/null \
|
||||
|| wget -qO "$CHANGELOG_TMP" "https://raw.githubusercontent.com/golem15com/msd-core/main/CHANGELOG.md" 2>/dev/null
|
||||
curl -fsSL "https://git.golem15.com/golem15/msd-core/raw/branch/next/CHANGELOG.md" -o "$CHANGELOG_TMP" 2>/dev/null \
|
||||
|| wget -qO "$CHANGELOG_TMP" "https://git.golem15.com/golem15/msd-core/raw/branch/next/CHANGELOG.md" 2>/dev/null
|
||||
|
||||
MSD_CHANGESET_CLI="$MSD_DIR/scripts/changeset/cli.cjs"
|
||||
if [ ! -f "$MSD_CHANGESET_CLI" ]; then
|
||||
@@ -486,7 +486,7 @@ Format completion message (changelog was already shown in confirmation step):
|
||||
|
||||
⚠️ Restart your runtime to pick up the new commands.
|
||||
|
||||
[View full changelog](https://github.com/golem15com/msd-core/blob/main/CHANGELOG.md)
|
||||
[View full changelog](https://git.golem15.com/golem15/msd-core/blob/main/CHANGELOG.md)
|
||||
```
|
||||
</step>
|
||||
|
||||
|
||||
@@ -47,11 +47,11 @@
|
||||
"license": "MIT",
|
||||
"repository": {
|
||||
"type": "git",
|
||||
"url": "git+https://github.com/golem15com/msd-core.git"
|
||||
"url": "git+https://git.golem15.com/golem15/msd-core.git"
|
||||
},
|
||||
"homepage": "https://github.com/golem15com/msd-core",
|
||||
"homepage": "https://git.golem15.com/golem15/msd-core",
|
||||
"bugs": {
|
||||
"url": "https://github.com/golem15com/msd-core/issues"
|
||||
"url": "https://git.golem15.com/golem15/msd-core/issues"
|
||||
},
|
||||
"publishConfig": {
|
||||
"access": "public"
|
||||
|
||||
@@ -20,10 +20,24 @@
|
||||
* Parse `owner/name` out of a package.json `repository.url`, stripping the
|
||||
* `git+` prefix and `.git` suffix npm conventionally adds.
|
||||
*/
|
||||
function parseRepoSlug(repository) {
|
||||
function parseRepo(repository) {
|
||||
const url = typeof repository === 'string' ? repository : (repository && repository.url) || '';
|
||||
const m = url.replace(/^git\+/, '').replace(/\.git$/, '').match(/github\.com[/:]([^/]+\/[^/]+)$/);
|
||||
return m ? m[1] : '';
|
||||
const m = url.replace(/^git\+/, '').replace(/\.git$/, '').match(/(github\.com|git\.golem15\.com)[/:]([^/]+\/[^/]+)$/);
|
||||
return m ? { host: m[1], slug: m[2] } : { host: '', slug: '' };
|
||||
}
|
||||
|
||||
function parseRepoSlug(repository) {
|
||||
return parseRepo(repository).slug;
|
||||
}
|
||||
|
||||
/**
|
||||
* Raw-file URL for CHANGELOG.md on the repo's default branch. GitHub serves raw
|
||||
* files from a separate host; the golem15 Gitea forge serves them in-place.
|
||||
*/
|
||||
function changelogRawUrlFor(host, slug) {
|
||||
if (!slug) return '';
|
||||
if (host === 'github.com') return `https://raw.githubusercontent.com/${slug}/main/CHANGELOG.md`;
|
||||
return `https://${host}/${slug}/raw/branch/next/CHANGELOG.md`;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -47,11 +61,9 @@ function slugifyPackageName(name) {
|
||||
function deriveIdentity(pkg = {}) {
|
||||
const packageName = pkg.name || '';
|
||||
const binName = pkg.bin ? Object.keys(pkg.bin)[0] || '' : '';
|
||||
const repoSlug = parseRepoSlug(pkg.repository);
|
||||
const repoUrl = repoSlug ? `https://github.com/${repoSlug}` : '';
|
||||
const changelogRawUrl = repoSlug
|
||||
? `https://raw.githubusercontent.com/${repoSlug}/main/CHANGELOG.md`
|
||||
: '';
|
||||
const { host, slug: repoSlug } = parseRepo(pkg.repository);
|
||||
const repoUrl = repoSlug ? `https://${host}/${repoSlug}` : '';
|
||||
const changelogRawUrl = changelogRawUrlFor(host, repoSlug);
|
||||
const cacheSlug = slugifyPackageName(packageName);
|
||||
const updateCacheFileName = cacheSlug ? `msd-update-check-${cacheSlug}.json` : 'msd-update-check.json';
|
||||
return { packageName, binName, repoSlug, repoUrl, changelogRawUrl, cacheSlug, updateCacheFileName };
|
||||
|
||||
@@ -31,7 +31,7 @@ const path = require('node:path');
|
||||
const PACKAGE_RE = /@[A-Za-z0-9._-]+\/[A-Za-z0-9._-]*get-shit-done[A-Za-z0-9._-]*/g; // msd-allow-legacy-name
|
||||
// A MSD repo slug, only inside a GitHub URL context so it never overlaps the
|
||||
// scoped package literal above. The `.git` suffix is trimmed before compare.
|
||||
const SLUG_RE = /(?:github\.com[/:]|raw\.githubusercontent\.com\/)([A-Za-z0-9._-]+\/[A-Za-z0-9._-]*get-shit-done[A-Za-z0-9._-]*)/g; // msd-allow-legacy-name
|
||||
const SLUG_RE = /(?:github\.com[/:]|git\.golem15\.com[/:]|raw\.githubusercontent\.com\/)([A-Za-z0-9._-]+\/[A-Za-z0-9._-]*get-shit-done[A-Za-z0-9._-]*)/g; // msd-allow-legacy-name
|
||||
|
||||
function lineOf(text, index) {
|
||||
let line = 1;
|
||||
|
||||
@@ -40,16 +40,20 @@ const GSD2_FILE_RE = /gsd-?2/i;
|
||||
|
||||
// Split so the package-name single-source lint does not flag this script.
|
||||
const OURS_NPM = '@golem15/' + 'msd-core';
|
||||
const OURS_FORGE = 'https://git.golem15.com/golem15/msd-core';
|
||||
|
||||
const SPECIFIC = [
|
||||
// Regex-escaped forms (`@opengsd\/gsd-core` inside test patterns) come first.
|
||||
[/@opengsd\\\/gsd-core/g, `${OURS_NPM.replace('/', '\\/')}`],
|
||||
[/open-gsd\\\/gsd-core(?!\\\/(?:issues|pull|discussions|commit|releases|compare|security|actions)\b)/g, 'golem15com\\/msd-core'],
|
||||
[/open-gsd\\\/gsd-core(?!\\\/(?:issues|pull|discussions|commit|releases|compare|security|actions)\b)/g, 'golem15\\/msd-core'],
|
||||
[/@opengsd\/gsd-core/g, OURS_NPM],
|
||||
[/https:\/\/raw\.githubusercontent\.com\/open-gsd\/gsd-core\/main\//g, `${OURS_FORGE}/raw/branch/next/`],
|
||||
[/https:\/\/github\.com\/open-gsd\/gsd-core(?!\/(?:issues|pull|discussions|commit|releases|compare|security|actions)\b)/g, OURS_FORGE],
|
||||
[/https:\/\/github\.com\/open-gsd(?![\w./-])/g, 'https://git.golem15.com/golem15'],
|
||||
[/%40opengsd%2Fgsd-core/g, '%40golem15%2Fmsd-core'],
|
||||
[/opengsd-gsd-core/g, 'golem15-msd-core'],
|
||||
// Bare repo slug becomes ours; deep links into upstream history are protected below.
|
||||
[/open-gsd\/gsd-core(?!\/(?:issues|pull|discussions|commit|releases|compare|security|actions)\b)/g, 'golem15com/msd-core'],
|
||||
[/open-gsd\/gsd-core(?!\/(?:issues|pull|discussions|commit|releases|compare|security|actions)\b)/g, 'golem15/msd-core'],
|
||||
[/Git\. Ship\. Done\./g, 'Make Software Done.'],
|
||||
];
|
||||
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
# DRY_RUN=1 bash scripts/setup-branch-protection.sh # show payloads, don't apply
|
||||
#
|
||||
# Requirements:
|
||||
# - gh CLI authenticated against golem15com/msd-core with admin scope
|
||||
# - gh CLI authenticated against golem15/msd-core with admin scope
|
||||
# - jq installed
|
||||
#
|
||||
# What it sets:
|
||||
@@ -49,7 +49,7 @@
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
REPO="${REPO:-golem15com/msd-core}"
|
||||
REPO="${REPO:-golem15/msd-core}"
|
||||
DRY_RUN="${DRY_RUN:-0}"
|
||||
|
||||
# Required status checks. Adjust as your CI suite evolves.
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
REPO="${REPO:-golem15com/msd-core}"
|
||||
REPO="${REPO:-golem15/msd-core}"
|
||||
ENFORCEMENT="${ENFORCEMENT:-evaluate}"
|
||||
|
||||
case "$ENFORCEMENT" in
|
||||
|
||||
@@ -17,7 +17,7 @@
|
||||
*
|
||||
* References:
|
||||
* - ADR-3524 (docs/adr/3524-cjs-sdk-hard-seam.md)
|
||||
* - Issue #4 (golem15com/msd-core)
|
||||
* - Issue #4 (golem15/msd-core)
|
||||
*/
|
||||
|
||||
import { findTableWithColumns } from './markdown-table.cjs';
|
||||
|
||||
@@ -25,8 +25,8 @@
|
||||
*
|
||||
* References:
|
||||
* - ADR-3524 (docs/adr/3524-cjs-sdk-hard-seam.md)
|
||||
* - Issue #6 (golem15com/msd-core)
|
||||
* - Issue #26 (golem15com/msd-core)
|
||||
* - Issue #6 (golem15/msd-core)
|
||||
* - Issue #26 (golem15/msd-core)
|
||||
* - PR #154 (issue #4) — generator pattern precedent
|
||||
* - PR #156 (issue #6) — validate.ts generator that #26 extends
|
||||
*/
|
||||
|
||||
@@ -7398,7 +7398,7 @@ describe('enh-1055 descriptor-drive: finishPermissionWriter passthrough', () =>
|
||||
* so autonomous/CI runs can silence the plan-time advisory without disabling the execute-time gates.
|
||||
* The gate declaration conforms to ADR-857 (`plan:pre` is an enumerated, additive-only loop point).
|
||||
*
|
||||
* Issue: #1592 (golem15com/msd-core).
|
||||
* Issue: #1592 (golem15/msd-core).
|
||||
*/
|
||||
|
||||
const { describe, test, after } = require('node:test');
|
||||
|
||||
@@ -310,7 +310,7 @@ function runCli(env, { outputPath } = {}) {
|
||||
timeoutMs: PROBE_TIMEOUT_MS,
|
||||
env: {
|
||||
...process.env,
|
||||
GITHUB_REPOSITORY: 'golem15com/msd-core',
|
||||
GITHUB_REPOSITORY: 'golem15/msd-core',
|
||||
GITHUB_TOKEN: SENTINEL_TOKEN,
|
||||
GITHUB_BASE_REF: 'next',
|
||||
...(outputPath ? { GITHUB_OUTPUT: outputPath } : {}),
|
||||
@@ -327,7 +327,7 @@ function runCli(env, { outputPath } = {}) {
|
||||
// live so the stub can actually answer. Mirrors tests/ci-pr-mergeability.test.cjs.
|
||||
async function callMain(t, env, { outputPath } = {}) {
|
||||
const overrides = {
|
||||
GITHUB_REPOSITORY: 'golem15com/msd-core',
|
||||
GITHUB_REPOSITORY: 'golem15/msd-core',
|
||||
GITHUB_TOKEN: SENTINEL_TOKEN,
|
||||
GITHUB_BASE_REF: 'next',
|
||||
...(outputPath ? { GITHUB_OUTPUT: outputPath } : {}),
|
||||
|
||||
@@ -400,7 +400,7 @@ function runCli(env, { outputPath } = {}) {
|
||||
timeoutMs: PROBE_TIMEOUT_MS,
|
||||
env: {
|
||||
...process.env,
|
||||
GITHUB_REPOSITORY: 'golem15com/msd-core',
|
||||
GITHUB_REPOSITORY: 'golem15/msd-core',
|
||||
GITHUB_TOKEN: SENTINEL_TOKEN,
|
||||
GITHUB_BASE_REF: 'next',
|
||||
PR_NUMBER: String(PR.number),
|
||||
@@ -428,7 +428,7 @@ function runCli(env, { outputPath } = {}) {
|
||||
*/
|
||||
async function callMain(t, env, { outputPath } = {}) {
|
||||
const overrides = {
|
||||
GITHUB_REPOSITORY: 'golem15com/msd-core',
|
||||
GITHUB_REPOSITORY: 'golem15/msd-core',
|
||||
GITHUB_TOKEN: SENTINEL_TOKEN,
|
||||
GITHUB_BASE_REF: 'next',
|
||||
PR_NUMBER: String(PR.number),
|
||||
|
||||
@@ -160,9 +160,9 @@ const INTERNAL_COMPONENT_SLUGS = new Set([
|
||||
// an external tool repo, not a user-typable slash command in this product.
|
||||
'test-runner',
|
||||
|
||||
// msd-core — GitHub repository name: "golem15com/msd-core".
|
||||
// msd-core — GitHub repository name: "golem15/msd-core".
|
||||
// docs/adr/22-plan-drift-guard.md references it as an issue tracker link:
|
||||
// golem15com/msd-core#22
|
||||
// golem15/msd-core#22
|
||||
// The regex captures "/msd-core" from the org/repo path separator. This is
|
||||
// the canonical repo name, not a user-typable slash command in this product.
|
||||
'core',
|
||||
@@ -216,7 +216,7 @@ function extractCommandTokens(content) {
|
||||
|
||||
// Negative lookbehind: only match tokens NOT preceded by a letter, digit,
|
||||
// `/`, `_`, or `-`. This prevents matching the `/msd-core` substring inside
|
||||
// the org/repo path `golem15com/msd-core` (and similar path-embedded segments)
|
||||
// the org/repo path `golem15/msd-core` (and similar path-embedded segments)
|
||||
// while still matching real invocations preceded by BOL, space, backtick, or
|
||||
// `(`. Fixes false-positive class identified in #489.
|
||||
const allSlash = (stripped.match(/(?<![A-Za-z0-9/_-])\/msd-[a-z0-9][a-z0-9-]*/g) || []);
|
||||
@@ -508,16 +508,16 @@ describe('adversarial: polarity inversion catches drift deny-list misses', () =>
|
||||
// ─── Tokenizer regression tests (#489) ───────────────────────────────────────
|
||||
|
||||
describe('extractCommandTokens() — repo-path false-positive regression (#489)', () => {
|
||||
test('golem15com/msd-core#22 repo path does NOT produce a /msd-core token', () => {
|
||||
// Before the lookbehind fix, /msd-core inside `golem15com/msd-core#22`
|
||||
test('golem15/msd-core#22 repo path does NOT produce a /msd-core token', () => {
|
||||
// Before the lookbehind fix, /msd-core inside `golem15/msd-core#22`
|
||||
// would be matched by the slash regex — a false positive.
|
||||
const { slash, colon, dollar } = extractCommandTokens(
|
||||
'see golem15com/msd-core#22 for details'
|
||||
'see golem15/msd-core#22 for details'
|
||||
);
|
||||
const all = [...slash, ...colon, ...dollar];
|
||||
assert.ok(
|
||||
!all.includes('/msd-core'),
|
||||
'repo path golem15com/msd-core#22 must not produce a /msd-core token; got: ' + all.join(', ')
|
||||
'repo path golem15/msd-core#22 must not produce a /msd-core token; got: ' + all.join(', ')
|
||||
);
|
||||
assert.strictEqual(all.length, 0, 'expected zero tokens from a bare repo-path string; got: ' + all.join(', '));
|
||||
});
|
||||
|
||||
@@ -144,25 +144,25 @@ describe('forensics workflow', () => {
|
||||
);
|
||||
});
|
||||
|
||||
test('workflow submits issues to golem15com/msd-core, not the current repo', () => {
|
||||
test('workflow submits issues to golem15/msd-core, not the current repo', () => {
|
||||
const content = fs.readFileSync(workflowPath, 'utf-8');
|
||||
// Scope check to the gh issue create invocation — a whole-file search would
|
||||
// pass even if gh issue create lacked --repo, because gh label list also
|
||||
// contains the repo string.
|
||||
assert.match(
|
||||
content,
|
||||
/gh issue create[\s\S]{0,250}--repo\s+golem15com\/msd-core/,
|
||||
'gh issue create must use --repo golem15com/msd-core to avoid submitting to the user\'s current project repo'
|
||||
/gh issue create[\s\S]{0,250}--repo\s+golem15\/msd-core/,
|
||||
'gh issue create must use --repo golem15/msd-core to avoid submitting to the user\'s current project repo'
|
||||
);
|
||||
});
|
||||
|
||||
test('workflow checks bug label in golem15com/msd-core, not the current repo', () => {
|
||||
test('workflow checks bug label in golem15/msd-core, not the current repo', () => {
|
||||
const content = fs.readFileSync(workflowPath, 'utf-8');
|
||||
// Regex is more robust than a fixed-length slice to formatting changes
|
||||
assert.match(
|
||||
content,
|
||||
/gh label list[\s\S]{0,250}--repo\s+golem15com\/msd-core/,
|
||||
'gh label list must target golem15com/msd-core'
|
||||
/gh label list[\s\S]{0,250}--repo\s+golem15\/msd-core/,
|
||||
'gh label list must target golem15/msd-core'
|
||||
);
|
||||
});
|
||||
|
||||
|
||||
@@ -473,7 +473,7 @@ describe('stateReplaceFieldWithFallback field-miss warning', () => {
|
||||
'use strict';
|
||||
|
||||
/**
|
||||
* Regression tests for issue #6 (golem15com/msd-core):
|
||||
* Regression tests for issue #6 (golem15/msd-core):
|
||||
* Three validation behaviors present in validate.ts are missing from verify.cjs,
|
||||
* producing silent false negatives on the CJS production path.
|
||||
*
|
||||
@@ -494,7 +494,7 @@ describe('stateReplaceFieldWithFallback field-miss warning', () => {
|
||||
*
|
||||
* References:
|
||||
* - ADR-3524 (docs/adr/3524-cjs-sdk-hard-seam.md)
|
||||
* - Issue #6 (golem15com/msd-core)
|
||||
* - Issue #6 (golem15/msd-core)
|
||||
* - PR #154 (issue #4) — precedent for the generator pattern
|
||||
*/
|
||||
|
||||
@@ -787,7 +787,7 @@ describe('Drift item 3 — W006 false positive when disk has zero-padded letter
|
||||
'use strict';
|
||||
|
||||
/**
|
||||
* Regression tests for issue #416 (golem15com/msd-core).
|
||||
* Regression tests for issue #416 (golem15/msd-core).
|
||||
*
|
||||
* Bug: getActiveMilestoneArchiveDir falls back to the newest archive directory
|
||||
* when STATE.md names a milestone that has no matching archive yet, producing
|
||||
@@ -1015,7 +1015,7 @@ describe('bug #416 case 3: STATE.md v5.0 with matching v5.0-phases/ → returns
|
||||
'use strict';
|
||||
|
||||
/**
|
||||
* Regression tests for issue #26 (golem15com/msd-core).
|
||||
* Regression tests for issue #26 (golem15/msd-core).
|
||||
* Three generator-pattern drift items: W005 phaseDirNameRe,
|
||||
* W006-archived regex constants (PHASE_TOKEN_FROM_DIR_RE, MILESTONE_ARCHIVE_DIR_RE),
|
||||
* I001 canonicalPlanStem.
|
||||
@@ -1025,7 +1025,7 @@ describe('bug #416 case 3: STATE.md v5.0 with matching v5.0-phases/ → returns
|
||||
* tests go RED.
|
||||
*
|
||||
* References:
|
||||
* - Issue #26 (golem15com/msd-core) — three drift items + reproducer
|
||||
* - Issue #26 (golem15/msd-core) — three drift items + reproducer
|
||||
* - ADR-3524 (docs/adr/3524-cjs-sdk-hard-seam.md)
|
||||
* - PR #154 (issue #4) — generator pattern precedent
|
||||
* - PR #156 (issue #6) — validate.ts generator scaffolding (#26 extends this)
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
// allow-test-rule: source-text-is-the-product (see #1073) — this guard asserts the
|
||||
// ABSENCE of phantom pre-migration issue references in repo text (docs, tests,
|
||||
// workflows). The file *content* is the product surface here (#1073): dangling
|
||||
// refs that don't exist in golem15com/msd-core mislead triage and manufacture
|
||||
// refs that don't exist in golem15/msd-core mislead triage and manufacture
|
||||
// phantom blockers. This test fails CI if such a ref is reintroduced.
|
||||
//
|
||||
// MAINTENANCE — this list ROTS and must be pruned (#2653).
|
||||
@@ -27,7 +27,7 @@ const os = require('node:os');
|
||||
const ROOT = path.resolve(__dirname, '..');
|
||||
|
||||
// Phantom pre-migration (get-shit-done-redux) issue numbers with NO equivalent
|
||||
// in golem15com/msd-core. Matched only with a leading '#' or in an issues/ URL so
|
||||
// in golem15/msd-core. Matched only with a leading '#' or in an issues/ URL so
|
||||
// digit-bearing strings like an `id_ed25519` SSH key fingerprint are NOT
|
||||
// false-positives.
|
||||
//
|
||||
|
||||
@@ -173,6 +173,13 @@ describe('Issue #498: deriveIdentity (pure, package.json -> coordinates)', () =>
|
||||
assert.equal(deriveIdentity(FAKE_PKG).repoUrl, 'https://github.com/acme/example-pkg');
|
||||
});
|
||||
|
||||
test('a git.golem15.com repository yields in-place raw URLs on the next branch', () => {
|
||||
const id = deriveIdentity({ ...FAKE_PKG, repository: 'git+https://git.golem15.com/golem15/msd-core.git' });
|
||||
assert.equal(id.repoSlug, 'golem15/msd-core');
|
||||
assert.equal(id.repoUrl, 'https://git.golem15.com/golem15/msd-core');
|
||||
assert.equal(id.changelogRawUrl, 'https://git.golem15.com/golem15/msd-core/raw/branch/next/CHANGELOG.md');
|
||||
});
|
||||
|
||||
test('changelogRawUrl points at raw.githubusercontent main CHANGELOG', () => {
|
||||
assert.equal(
|
||||
deriveIdentity(FAKE_PKG).changelogRawUrl,
|
||||
@@ -185,7 +192,7 @@ describe('Issue #498: deriveIdentity (pure, package.json -> coordinates)', () =>
|
||||
const id = deriveIdentity(real);
|
||||
assert.equal(id.packageName, '@golem15/msd-core');
|
||||
assert.equal(id.binName, 'msd-core');
|
||||
assert.equal(id.repoSlug, 'golem15com/msd-core');
|
||||
assert.equal(id.repoSlug, 'golem15/msd-core');
|
||||
});
|
||||
|
||||
test('deriveIdentity returns cacheSlug for @golem15/msd-core', () => {
|
||||
@@ -245,7 +252,7 @@ describe('Issue #498: generated runtime module (baked)', () => {
|
||||
const id = require(GENERATED);
|
||||
assert.equal(id.packageName, '@golem15/msd-core');
|
||||
assert.equal(id.binName, 'msd-core');
|
||||
assert.equal(id.repoSlug, 'golem15com/msd-core');
|
||||
assert.equal(id.repoSlug, 'golem15/msd-core');
|
||||
});
|
||||
|
||||
test('generated module exports cacheSlug matching @golem15/msd-core', () => {
|
||||
|
||||
@@ -10372,7 +10372,7 @@ describe('bug #2268: parallel discuss — all undiscussed phases marked is_next_
|
||||
'use strict';
|
||||
|
||||
/**
|
||||
* Regression test for issue #4 (golem15com/msd-core):
|
||||
* Regression test for issue #4 (golem15/msd-core):
|
||||
* bin/lib/phase.cjs cmdPhaseComplete — non-idempotent and unclamped.
|
||||
*
|
||||
* Root cause (pre-fix):
|
||||
@@ -10392,7 +10392,7 @@ describe('bug #2268: parallel discuss — all undiscussed phases marked is_next_
|
||||
* References:
|
||||
* - ADR-3524 (docs/adr/3524-cjs-sdk-hard-seam.md) — architectural foundation
|
||||
* - /tmp/adr-3524-review-findings.md — architectural justification
|
||||
* - Issue #4 (golem15com/msd-core)
|
||||
* - Issue #4 (golem15/msd-core)
|
||||
*/
|
||||
|
||||
const { describe, test, beforeEach, afterEach } = require('node:test');
|
||||
|
||||
@@ -299,7 +299,7 @@ describe('pr-template-policy', () => {
|
||||
// The tooling-paths carve-out RELAXES template enforcement, so trusting a
|
||||
// possibly-truncated list would let a >100-file PR skip enforcement on the
|
||||
// strength of its first 100 (all-tooling) paths. Verified live: PR
|
||||
// golem15com/msd-core#3202 returns 100 paths for 118 changed files.
|
||||
// golem15/msd-core#3202 returns 100 paths for 118 changed files.
|
||||
describe('pr-template-policy carve-out — truncated file lists (#3211)', () => {
|
||||
const toolingPaths = (n) => Array.from({ length: n }, (_, i) => `docs/generated-${i}.md`);
|
||||
|
||||
|
||||
@@ -7,7 +7,7 @@ process.env.MSD_TEST_MODE = '1';
|
||||
* .github/workflows/*.yml file has an effective `shell:` directive that is
|
||||
* H1-policy-compliant (native shell per OS).
|
||||
*
|
||||
* H1 policy (LOCKED — golem15com/msd-core):
|
||||
* H1 policy (LOCKED — golem15/msd-core):
|
||||
* ubuntu-* → bash (runner default, no pin needed)
|
||||
* macos-* → zsh (must be pinned explicitly)
|
||||
* windows-* → pwsh (runner default, no pin needed)
|
||||
|
||||
Reference in New Issue
Block a user