fix(#2873): close review findings across fences, sanitizer and docs

Isolated security review found resolveSpecRootReference's fence tracker
toggled on any delimiter, so a backtick fence could be closed by a tilde
one and an include in the gap was rewritten inside a code block. Fixed by
reusing scanFencedBlocks - the canonical engine already behind
stripFencedCode and extractFencedBlock - rather than carrying a fourth
copy of fence detection, which also closes the duplication the standards
review flagged.

sanitizeForRender now strips combining marks and zero-width characters
alongside the ANSI, control and bidi classes it already handled.

Adds the C, E and F matrix rows the spec review found missing, including
installer-level coverage that spawns the real install rather than calling
the report builder. Ships the how-to, the reference and command docs in
five locales, the changeset, the inventory and glossary entries, and
regenerates health.md for the new W028 rule.

Refs #2873
This commit is contained in:
sim
2026-08-14 23:09:36 -04:00
parent 2641e6cb67
commit 147856040b
25 changed files with 747 additions and 34 deletions

View File

@@ -36,6 +36,8 @@ npx @opengsd/gsd-core@latest --claude --global
技能文件存放于 `~/.claude/`。下次 Claude Code 会话中,命令将以 `/gsd-*` 斜杠命令的形式出现。重启 Claude Code 以加载它们。
**同时在 `--global` 和 `--local` 两个作用域安装。** 这是受支持的配置(不同项目有时需要不同的自定义配置),但 Claude Code 自身的触发器解析规则——个人作用域覆盖项目作用域,且技能(skill)覆盖同名命令——都指向同一个方向:全局技能总是在 `/gsd-<name>` 触发器上胜过本地命令。GSD Core 会检测到这一点,并在安装完成后立即打印出哪个作用域胜出(并通过 `/gsd-health` 以诊断代码 `W028` 呈现相同的事实);这只是一条提示,不是失败——安装本身仍然会成功。在**全局**作用域下,胜出技能的工作流规范引用会在运行时优先相对于你的工作目录解析,因此即使 Claude Code 实际调用的是全局技能,拥有自己 `.claude/gsd-core/` 的项目仍然能获取到自己的规范。
**覆盖安装目录:**
```bash