Consolidate all pre-rename release notes (the retired get-shit-done-cc / get-shit-done-redux lineage, 1.0.0 -> 1.50.0-canary.1) into one condensed, read-only archive so the legacy 1.x version numbers no longer collide with the current @opengsd/gsd-core line. - Add docs/RELEASE-NOTES-LEGACY.md: rename banner, master version-index table, condensed per-version sections (1.42.3 -> 1.0.0), and a separate pre-release & canary builds section. Stale install commands stripped. - Trim CHANGELOG.md to the current @opengsd/gsd-core line only; replace the Legacy Release History block with a pointer to the archive and drop the orphaned numbered legacy reference-link definitions. - Remove the 10 standalone docs/RELEASE-v*.md files. - Repoint docs/CANARY.md and docs/FEATURES.md links to the new archive. Closes #658 Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2936
CHANGELOG.md
2936
CHANGELOG.md
File diff suppressed because it is too large
Load Diff
@@ -61,6 +61,6 @@ File against the [issue tracker](https://github.com/open-gsd/gsd-core/issues) wi
|
||||
|
||||
## Where to look next
|
||||
|
||||
- Active canary release notes: [`docs/RELEASE-v1.50.0-canary.1.md`](RELEASE-v1.50.0-canary.1.md)
|
||||
- Active canary release notes: [`v1.50.0-canary.1` (now in the legacy release-notes archive)](RELEASE-NOTES-LEGACY.md)
|
||||
- Stable release notes: [`CHANGELOG.md`](../CHANGELOG.md)
|
||||
- Stream architecture rationale: discussed across [#2727](https://github.com/open-gsd/gsd-core/issues/2727), [#2773](https://github.com/open-gsd/gsd-core/issues/2773) (codex schema-break and the resulting promotion bottleneck that motivated explicit stream isolation)
|
||||
|
||||
@@ -2817,7 +2817,7 @@ Source commit: abc1234 (3 commits behind HEAD)
|
||||
- REQ-PKG-GATE-02: Planner MUST gate unverified or suspicious package installs before execution.
|
||||
- REQ-PKG-GATE-03: Executor MUST NOT auto-substitute package names after failed package-manager installs.
|
||||
|
||||
**Reference:** [v1.42.1 Release Notes](RELEASE-v1.42.1.md)
|
||||
**Reference:** [v1.42.1 Release Notes](RELEASE-NOTES-LEGACY.md)
|
||||
|
||||
---
|
||||
|
||||
|
||||
1030
docs/RELEASE-NOTES-LEGACY.md
Normal file
1030
docs/RELEASE-NOTES-LEGACY.md
Normal file
File diff suppressed because it is too large
Load Diff
@@ -1,84 +0,0 @@
|
||||
# v1.39.0-rc.4 Release Notes
|
||||
|
||||
Pre-release candidate. Published to npm under the `next` tag.
|
||||
|
||||
```
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
### Added
|
||||
|
||||
**`--minimal` install flag** (alias `--core-only`) (#2762)
|
||||
|
||||
Writes only the six core skills needed to run the main workflow loop:
|
||||
`new-project`, `discuss-phase`, `plan-phase`, `execute-phase`, `help`, `update`.
|
||||
No `gsd-*` subagents are installed.
|
||||
|
||||
| Mode | Cold-start system-prompt overhead |
|
||||
|------|-----------------------------------|
|
||||
| full (default) | ~12k tokens |
|
||||
| minimal | ~700 tokens |
|
||||
|
||||
Useful for local LLMs with 32K–128K context windows. Sonnet 4.6 / Opus 4.7 users
|
||||
don't need it — the full surface is the right default for cloud models.
|
||||
|
||||
The install manifest records `mode: "minimal" | "full"`. Run `gsd update` without
|
||||
`--minimal` at any time to expand to the full skill set.
|
||||
|
||||
---
|
||||
|
||||
### Fixed
|
||||
|
||||
**Codex install no longer corrupts `~/.codex/config.toml`** (#2760)
|
||||
|
||||
Four users confirmed the same breakage: the previous installer left
|
||||
`~/.codex/config.toml` in a state that Codex rejected on launch, with manual file
|
||||
cleanup as the only workaround.
|
||||
|
||||
The installer now:
|
||||
|
||||
- Strips legacy `[agents]` (single-bracket) and `[[agents]]` (sequence) blocks
|
||||
unconditionally — both are invalid in the current Codex TOML schema, regardless of
|
||||
whether a GSD marker is present.
|
||||
- Emits the GSD-managed hook in the shape the user's config already uses:
|
||||
`[[hooks.<Event>]]` namespaced AoT if any existing hook uses that form, otherwise
|
||||
top-level `[[hooks]]`.
|
||||
- Migrates any legacy `[hooks.<Event>]` (map format) to `[[hooks.<Event>]]` (array
|
||||
format) during write.
|
||||
- Writes atomically via a temp file + `renameSync` — no partial writes.
|
||||
- Validates the post-write bytes with a strict TOML parser that rejects duplicate
|
||||
keys, repeated table headers, trailing bytes after values, and unsupported value
|
||||
types.
|
||||
- On any pre-write or write-time failure, restores the pre-install snapshot and aborts
|
||||
with a clear error instead of warn-and-continue.
|
||||
|
||||
---
|
||||
|
||||
## Installing the pre-release
|
||||
|
||||
```bash
|
||||
# npm
|
||||
npm install -g @opengsd/get-shit-done-redux@next
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
To pin to this exact RC:
|
||||
|
||||
```bash
|
||||
npm install -g @opengsd/get-shit-done-redux@1.39.0-rc.4
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's next
|
||||
|
||||
- Run `rc` again on the release branch to publish rc.5 if further fixes land before
|
||||
finalization.
|
||||
- Run `finalize` on the release workflow to promote `1.39.0` to `latest` when the RC
|
||||
is stable.
|
||||
@@ -1,99 +0,0 @@
|
||||
# v1.39.0-rc.5 Release Notes
|
||||
|
||||
Pre-release candidate. Published to npm under the `next` tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
All fixes from rc.4, plus:
|
||||
|
||||
### Fixed
|
||||
|
||||
**Codex hooks migrator correctness hardening** (#2809)
|
||||
|
||||
Five edge-cases in the `[[hooks.<Event>]]` → `[[hooks.<Event>.hooks]]` two-level nested
|
||||
schema migration path, discovered across five rounds of code review:
|
||||
|
||||
| Finding | Fix |
|
||||
|---------|-----|
|
||||
| `parseHooksBody` used a bare regex (`/^([\w.]+)\s*=/`) that silently dropped hyphenated keys such as `status-message` and any quoted TOML key | Replaced with `parseTomlKey()`, the existing full TOML key parser |
|
||||
| `buildNestedBlock` unconditionally emitted `[[hooks.TYPE.hooks]]` even when no handler fields were present, producing an entry with `type = "command"` but no `command` | Added guard: matcher-only / handler-field-free sections emit only the event-entry block |
|
||||
| `legacyMapSections` filter used `section.path.startsWith('hooks.')` without checking the segment count, so three-segment tables like `[hooks.SessionStart.hooks]` were misclassified as event entries and re-emitted as bogus nested events | Now uses `section.segments.length === 2` (same fix previously applied to `staleNamespacedAotSections`) |
|
||||
| No regression test for quoted event names containing dots — `[[hooks."before.tool"]]` has a 2-segment path but 3 dot-parts, and a `split('.')` check would misclassify it | Regression test added; quoted-dot names are correctly treated as a single two-segment namespace |
|
||||
| Handler command path assertion in install tests used a regex (`/gsd-check-update\.js/`) rather than the exact absolute path | Strengthened to `assert.strictEqual` with `path.join(codexHome, 'hooks', 'gsd-check-update.js')` |
|
||||
|
||||
---
|
||||
|
||||
## What was in rc.4
|
||||
|
||||
### Added
|
||||
|
||||
**`--minimal` install flag** (alias `--core-only`) (#2762)
|
||||
|
||||
Writes only the six core skills needed to run the main workflow loop:
|
||||
`new-project`, `discuss-phase`, `plan-phase`, `execute-phase`, `help`, `update`.
|
||||
No `gsd-*` subagents are installed.
|
||||
|
||||
| Mode | Cold-start system-prompt overhead |
|
||||
|------|-----------------------------------|
|
||||
| full (default) | ~12k tokens |
|
||||
| minimal | ~700 tokens |
|
||||
|
||||
Useful for local LLMs with 32K–128K context windows. Sonnet 4.6 / Opus 4.7 users
|
||||
don't need it — the full surface is the right default for cloud models.
|
||||
|
||||
The install manifest records `mode: "minimal" | "full"`. Run `gsd update` without
|
||||
`--minimal` at any time to expand to the full skill set.
|
||||
|
||||
### Fixed (rc.4)
|
||||
|
||||
**Codex install no longer corrupts `~/.codex/config.toml`** (#2760)
|
||||
|
||||
The installer now:
|
||||
|
||||
- Strips legacy `[agents]` (single-bracket) and `[[agents]]` (sequence) blocks
|
||||
unconditionally — both are invalid in the current Codex TOML schema, regardless of
|
||||
whether a GSD marker is present.
|
||||
- Emits the GSD-managed hook in the shape the user's config already uses:
|
||||
`[[hooks.<Event>]]` namespaced AoT if any existing hook uses that form, otherwise
|
||||
top-level `[[hooks]]`.
|
||||
- Migrates any legacy `[hooks.<Event>]` (map format) to `[[hooks.<Event>]]` (array
|
||||
format) during write.
|
||||
- Writes atomically via a temp file + `renameSync` — no partial writes.
|
||||
- Validates the post-write bytes with a strict TOML parser that rejects duplicate
|
||||
keys, repeated table headers, trailing bytes after values, and unsupported value
|
||||
types.
|
||||
- On any pre-write or write-time failure, restores the pre-install snapshot and aborts
|
||||
with a clear error instead of warn-and-continue.
|
||||
|
||||
---
|
||||
|
||||
## Installing the pre-release
|
||||
|
||||
```bash
|
||||
# npm
|
||||
npm install -g @opengsd/get-shit-done-redux@next
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
To pin to this exact RC:
|
||||
|
||||
```bash
|
||||
npm install -g @opengsd/get-shit-done-redux@1.39.0-rc.5
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's next
|
||||
|
||||
- Run `rc` again on the release branch to publish rc.6 if further fixes land before
|
||||
finalization.
|
||||
- Run `finalize` on the release workflow to promote `1.39.0` to `latest` when the RC
|
||||
is stable.
|
||||
@@ -1,116 +0,0 @@
|
||||
# v1.39.0-rc.6 Release Notes
|
||||
|
||||
Pre-release candidate. Published to npm under the `next` tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
**rc.6 is a republish of rc.5.** No new fixes were rolled in — `release/1.39.0`
|
||||
was bumped from `1.39.0-rc.5` to `1.39.0-rc.6` without first being merged with
|
||||
`main`, so the branch contents at the time of tag are byte-for-byte equivalent
|
||||
to rc.5 plus the version-bump commit.
|
||||
|
||||
```bash
|
||||
$ git log v1.39.0-rc.5..v1.39.0-rc.6 --pretty='%h %s'
|
||||
388118d8 chore: bump to 1.39.0-rc.6
|
||||
```
|
||||
|
||||
If you are already on `1.39.0-rc.5`, there is nothing new to install in rc.6.
|
||||
The expected next step is an rc.7 cut that first merges `main` into
|
||||
`release/1.39.0` so the eight fixes that landed after rc.5 reach the registry.
|
||||
|
||||
---
|
||||
|
||||
## What was in rc.5
|
||||
|
||||
### Fixed
|
||||
|
||||
**Codex hooks migrator correctness hardening** (#2809)
|
||||
|
||||
Five edge-cases in the `[[hooks.<Event>]]` → `[[hooks.<Event>.hooks]]` two-level
|
||||
nested schema migration path, discovered across five rounds of code review:
|
||||
|
||||
| Finding | Fix |
|
||||
|---------|-----|
|
||||
| `parseHooksBody` used a bare regex (`/^([\w.]+)\s*=/`) that silently dropped hyphenated keys such as `status-message` and any quoted TOML key | Replaced with `parseTomlKey()`, the existing full TOML key parser |
|
||||
| `buildNestedBlock` unconditionally emitted `[[hooks.TYPE.hooks]]` even when no handler fields were present, producing an entry with `type = "command"` but no `command` | Added guard: matcher-only / handler-field-free sections emit only the event-entry block |
|
||||
| `legacyMapSections` filter used `section.path.startsWith('hooks.')` without checking the segment count, so three-segment tables like `[hooks.SessionStart.hooks]` were misclassified as event entries and re-emitted as bogus nested events | Now uses `section.segments.length === 2` (same fix previously applied to `staleNamespacedAotSections`) |
|
||||
| No regression test for quoted event names containing dots — `[[hooks."before.tool"]]` has a 2-segment path but 3 dot-parts, and a `split('.')` check would misclassify it | Regression test added; quoted-dot names are correctly treated as a single two-segment namespace |
|
||||
| Handler command path assertion in install tests used a regex (`/gsd-check-update\.js/`) rather than the exact absolute path | Strengthened to `assert.strictEqual` with `path.join(codexHome, 'hooks', 'gsd-check-update.js')` |
|
||||
|
||||
---
|
||||
|
||||
## What was in rc.4
|
||||
|
||||
### Added
|
||||
|
||||
**`--minimal` install flag** (alias `--core-only`) (#2762)
|
||||
|
||||
Writes only the six core skills needed to run the main workflow loop:
|
||||
`new-project`, `discuss-phase`, `plan-phase`, `execute-phase`, `help`, `update`.
|
||||
No `gsd-*` subagents are installed.
|
||||
|
||||
| Mode | Cold-start system-prompt overhead |
|
||||
|------|-----------------------------------|
|
||||
| full (default) | ~12k tokens |
|
||||
| minimal | ~700 tokens |
|
||||
|
||||
Useful for local LLMs with 32K–128K context windows. Sonnet 4.6 / Opus 4.7 users
|
||||
don't need it — the full surface is the right default for cloud models.
|
||||
|
||||
The install manifest records `mode: "minimal" | "full"`. Run `gsd update` without
|
||||
`--minimal` at any time to expand to the full skill set.
|
||||
|
||||
### Fixed (rc.4)
|
||||
|
||||
**Codex install no longer corrupts `~/.codex/config.toml`** (#2760)
|
||||
|
||||
The installer now:
|
||||
|
||||
- Strips legacy `[agents]` (single-bracket) and `[[agents]]` (sequence) blocks
|
||||
unconditionally — both are invalid in the current Codex TOML schema, regardless of
|
||||
whether a GSD marker is present.
|
||||
- Emits the GSD-managed hook in the shape the user's config already uses:
|
||||
`[[hooks.<Event>]]` namespaced AoT if any existing hook uses that form, otherwise
|
||||
top-level `[[hooks]]`.
|
||||
- Migrates any legacy `[hooks.<Event>]` (map format) to `[[hooks.<Event>]]` (array
|
||||
format) during write.
|
||||
- Writes atomically via a temp file + `renameSync` — no partial writes.
|
||||
- Validates the post-write bytes with a strict TOML parser that rejects duplicate
|
||||
keys, repeated table headers, trailing bytes after values, and unsupported value
|
||||
types.
|
||||
- On any pre-write or write-time failure, restores the pre-install snapshot and aborts
|
||||
with a clear error instead of warn-and-continue.
|
||||
|
||||
---
|
||||
|
||||
## Installing the pre-release
|
||||
|
||||
```bash
|
||||
# npm
|
||||
npm install -g @opengsd/get-shit-done-redux@next
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
To pin to this exact RC:
|
||||
|
||||
```bash
|
||||
npm install -g @opengsd/get-shit-done-redux@1.39.0-rc.6
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's next
|
||||
|
||||
- **rc.7** — cut from `release/1.39.0` after merging `main` into the release branch,
|
||||
so the eight fixes that landed after rc.5 (#2828, #2829, #2831, #2832, #2835,
|
||||
#2836, #2838, #2839) actually reach the registry.
|
||||
- Run `finalize` on the release workflow to promote `1.39.0` to `latest` once an RC
|
||||
with the full main-branch contents is stable.
|
||||
@@ -1,185 +0,0 @@
|
||||
# v1.39.0-rc.7 Release Notes
|
||||
|
||||
Pre-release candidate. Published to npm under the `next` tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
rc.7 is the first RC in the 1.39.0 train that rolls in the post-rc.5 fixes from
|
||||
`main`. rc.6 was content-identical to rc.5 (`release/1.39.0` was bumped without
|
||||
first being merged with `main` — see [#2856](https://github.com/GSD-redux/get-shit-done-redux/issues/2856)).
|
||||
rc.7 syncs the release branch with `main` so all of the work below actually
|
||||
reaches the registry.
|
||||
|
||||
### Added
|
||||
|
||||
- **Manual canary release workflow** — `.github/workflows/canary.yml` publishes
|
||||
`{base}-canary.{N}` builds of `@opengsd/get-shit-done-redux` under the `canary` dist-tag on
|
||||
demand via `workflow_dispatch` (manual trigger only). Optional `dry_run` boolean.
|
||||
([#2828](https://github.com/GSD-redux/get-shit-done-redux/issues/2828))
|
||||
|
||||
### Fixed
|
||||
|
||||
- **`extractCurrentMilestone` no longer truncates ROADMAP.md at heading-like lines
|
||||
inside fenced code blocks** — the milestone-end search now scans line-by-line while
|
||||
tracking ` ``` ` / `~~~` fence state, so a line like `# Ops runbook (v1.0 compat)`
|
||||
inside a code block no longer acts as a milestone boundary.
|
||||
([#2787](https://github.com/GSD-redux/get-shit-done-redux/issues/2787))
|
||||
- **`audit-uat` parser reads `human_verification:` from frontmatter array** — the
|
||||
previous body-only regex was too strict and missed valid UAT items declared in
|
||||
YAML frontmatter, surfacing false-positive open gaps at every milestone-completion
|
||||
audit. ([#2788](https://github.com/GSD-redux/get-shit-done-redux/issues/2788))
|
||||
- **Skill description anti-patterns trimmed; ≤ 100-char budget enforced** — three
|
||||
anti-patterns eliminated across `commands/gsd/*.md`: flag documentation already in
|
||||
`argument-hint:`, `Triggers:` keyword-stuffing lists, and numbered enumeration. New
|
||||
CI lint gate `npm run lint:descriptions` fails if any description exceeds 100
|
||||
chars. ([#2789](https://github.com/GSD-redux/get-shit-done-redux/issues/2789))
|
||||
- **`gsd-sdk` binary collision with `@opengsd/gsd-sdk` resolved** — workstream-aware
|
||||
query registry now respects the `GSD_WORKSTREAM` env var; `gsd-tools` bin alias
|
||||
added. ([#2791](https://github.com/GSD-redux/get-shit-done-redux/issues/2791))
|
||||
- **`OpenCode` agents embed `model_profile_overrides.opencode.<tier>`** — per-tier
|
||||
model overrides set via `/gsd-settings-advanced` are now propagated into generated
|
||||
agent files. ([#2794](https://github.com/GSD-redux/get-shit-done-redux/issues/2794))
|
||||
- **`roadmap update-plan-progress` accepts `--phase` flag form** — SDK arg-parsing
|
||||
regression in v0.1.0 silently dropped `--phase`/`--name`/`--plans` flags, causing
|
||||
STATE.md corruption. ([#2796](https://github.com/GSD-redux/get-shit-done-redux/issues/2796))
|
||||
- **`context_window` added to `VALID_CONFIG_KEYS` allowlist** —
|
||||
`/gsd-settings-advanced` could not set `context_window` because the key was missing
|
||||
from the allowlist used by `config-set` validation.
|
||||
([#2798](https://github.com/GSD-redux/get-shit-done-redux/issues/2798))
|
||||
- **`gsd-tools init` dispatches `ingest-docs` handler** — `/gsd-ingest-docs` was
|
||||
broken in v1.38.5 because the workflow called the new tool but no `ingest-docs`
|
||||
init handler was registered. ([#2801](https://github.com/GSD-redux/get-shit-done-redux/issues/2801))
|
||||
- **`config-get` honors `--default <value>` flag** — fallback for missing keys
|
||||
ported from CJS into the SDK. ([#2803](https://github.com/GSD-redux/get-shit-done-redux/issues/2803))
|
||||
- **`find-phase` returns `null` for archived phases** — when the current-milestone
|
||||
phase had no directory yet, `init.plan-phase` / `init.execute-phase` returned the
|
||||
archived prior-milestone directory instead of `null`, causing wrong-phase work.
|
||||
([#2805](https://github.com/GSD-redux/get-shit-done-redux/issues/2805))
|
||||
- **SKILL.md frontmatter `name:` migrated to hyphen form** — files that still used
|
||||
the deprecated colon form (`gsd:cmd`) caused autocomplete to suggest `/gsd:command`.
|
||||
([#2808](https://github.com/GSD-redux/get-shit-done-redux/issues/2808))
|
||||
- **`gsd-sdk` resolvable in local-mode installs** — the previous `isLocal`
|
||||
short-circuit returned before the PATH probe + self-link could run. When
|
||||
`sdk/dist/cli.js` is present, local installs now run the same probe-and-link flow
|
||||
as global installs. ([#2829](https://github.com/GSD-redux/get-shit-done-redux/issues/2829))
|
||||
- **OpenCode `@file` references use absolute paths on all platforms** — OpenCode
|
||||
does not shell-expand `$HOME` in `@file` references on any platform; the
|
||||
Windows-only guard from #2376 left macOS/Linux producing literal `@$HOME/...`
|
||||
strings. Guard now applies unconditionally for OpenCode.
|
||||
([#2831](https://github.com/GSD-redux/get-shit-done-redux/issues/2831))
|
||||
- **`gsd-sdk auto` detects Codex runtime correctly** — `auto` mode ignored
|
||||
`runtime: codex` and routed through `@anthropic-ai/claude-agent-sdk`, producing
|
||||
the `[FAILED] $0.00 0.1s` symptom on autonomous runs. New `runtime-gate` raises a
|
||||
clear error for non-Claude runtimes; `resolveModel()` honours `GSD_RUNTIME` env
|
||||
precedence and never injects a Claude profile id under non-Claude runtimes.
|
||||
([#2832](https://github.com/GSD-redux/get-shit-done-redux/issues/2832))
|
||||
- **CR-INTEGRATION tests aligned with hyphen-form skill names** — tests now parse
|
||||
`Skill(skill="...")` invocations structurally and reject the legacy colon form.
|
||||
([#2835](https://github.com/GSD-redux/get-shit-done-redux/issues/2835))
|
||||
- **`audit-open` quick-task scanner accepts `${quick_id}-SUMMARY.md`** — the
|
||||
bare-`SUMMARY.md` check produced false-positive `status: missing` for every
|
||||
documented quick task. UAT terminal-status enum also adds `resolved` (matches
|
||||
`execute-phase.md`'s post-gap-closure terminal).
|
||||
([#2836](https://github.com/GSD-redux/get-shit-done-redux/issues/2836))
|
||||
- **`quick.md` / `execute-phase.md` SUMMARY rescue handles gitignored `.planning/`** —
|
||||
rescue blocks used `git ls-files --exclude-standard`, silently no-op'ing when
|
||||
`.planning/` was excluded; the worktree was then deleted with the SUMMARY.
|
||||
Replaced with filesystem-level `find` + idempotent `cp`.
|
||||
([#2838](https://github.com/GSD-redux/get-shit-done-redux/issues/2838))
|
||||
- **`/gsd-code-review-fix` cleanup tail is transactional** — JSON recovery sentinel
|
||||
at `${phase_dir}/.review-fix-recovery-pending.json` is written after `git worktree
|
||||
add` succeeds and removed only after `git worktree remove` returns. New runs that
|
||||
find a pre-existing sentinel force-remove the orphan worktree, making the agent
|
||||
self-healing across crashes. ([#2839](https://github.com/GSD-redux/get-shit-done-redux/issues/2839))
|
||||
|
||||
---
|
||||
|
||||
## What was in rc.6
|
||||
|
||||
```bash
|
||||
$ git log v1.39.0-rc.5..v1.39.0-rc.6 --pretty='%h %s'
|
||||
388118d8 chore: bump to 1.39.0-rc.6
|
||||
```
|
||||
|
||||
rc.6 was a republish of rc.5 with no new content — `release/1.39.0` was bumped
|
||||
without first being merged with `main`. See
|
||||
[`RELEASE-v1.39.0-rc.6.md`](RELEASE-v1.39.0-rc.6.md) for the full context.
|
||||
|
||||
---
|
||||
|
||||
## What was in rc.5
|
||||
|
||||
### Fixed
|
||||
|
||||
**Codex hooks migrator correctness hardening** ([#2809](https://github.com/GSD-redux/get-shit-done-redux/issues/2809))
|
||||
|
||||
Five edge-cases in the `[[hooks.<Event>]]` → `[[hooks.<Event>.hooks]]` two-level
|
||||
nested schema migration path, discovered across five rounds of code review:
|
||||
|
||||
| Finding | Fix |
|
||||
|---------|-----|
|
||||
| `parseHooksBody` used a bare regex (`/^([\w.]+)\s*=/`) that silently dropped hyphenated keys such as `status-message` and any quoted TOML key | Replaced with `parseTomlKey()`, the existing full TOML key parser |
|
||||
| `buildNestedBlock` unconditionally emitted `[[hooks.TYPE.hooks]]` even when no handler fields were present, producing an entry with `type = "command"` but no `command` | Added guard: matcher-only / handler-field-free sections emit only the event-entry block |
|
||||
| `legacyMapSections` filter used `section.path.startsWith('hooks.')` without checking the segment count, so three-segment tables like `[hooks.SessionStart.hooks]` were misclassified as event entries and re-emitted as bogus nested events | Now uses `section.segments.length === 2` (same fix previously applied to `staleNamespacedAotSections`) |
|
||||
| No regression test for quoted event names containing dots — `[[hooks."before.tool"]]` has a 2-segment path but 3 dot-parts, and a `split('.')` check would misclassify it | Regression test added; quoted-dot names are correctly treated as a single two-segment namespace |
|
||||
| Handler command path assertion in install tests used a regex (`/gsd-check-update\.js/`) rather than the exact absolute path | Strengthened to `assert.strictEqual` with `path.join(codexHome, 'hooks', 'gsd-check-update.js')` |
|
||||
|
||||
---
|
||||
|
||||
## What was in rc.4
|
||||
|
||||
### Added
|
||||
|
||||
**`--minimal` install flag** (alias `--core-only`) ([#2762](https://github.com/GSD-redux/get-shit-done-redux/issues/2762))
|
||||
|
||||
Writes only the six core skills needed to run the main workflow loop:
|
||||
`new-project`, `discuss-phase`, `plan-phase`, `execute-phase`, `help`, `update`.
|
||||
No `gsd-*` subagents are installed.
|
||||
|
||||
| Mode | Cold-start system-prompt overhead |
|
||||
|------|-----------------------------------|
|
||||
| full (default) | ~12k tokens |
|
||||
| minimal | ~700 tokens |
|
||||
|
||||
The install manifest records `mode: "minimal" | "full"`. Run `gsd update` without
|
||||
`--minimal` at any time to expand to the full skill set.
|
||||
|
||||
### Fixed (rc.4)
|
||||
|
||||
**Codex install no longer corrupts `~/.codex/config.toml`** ([#2760](https://github.com/GSD-redux/get-shit-done-redux/issues/2760))
|
||||
|
||||
The installer now strips legacy `[agents]` blocks, emits hooks in the user's
|
||||
existing shape, migrates legacy `[hooks.<Event>]` map format to `[[hooks.<Event>]]`,
|
||||
writes atomically via temp-file + `renameSync`, and validates post-write bytes
|
||||
with a strict TOML parser.
|
||||
|
||||
---
|
||||
|
||||
## Installing the pre-release
|
||||
|
||||
```bash
|
||||
# npm
|
||||
npm install -g @opengsd/get-shit-done-redux@next
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
To pin to this exact RC:
|
||||
|
||||
```bash
|
||||
npm install -g @opengsd/get-shit-done-redux@1.39.0-rc.7
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's next
|
||||
|
||||
- Run `finalize` on the release workflow to promote `1.39.0` to `latest` once
|
||||
rc.7 has soaked.
|
||||
@@ -1,136 +0,0 @@
|
||||
# v1.40.0-rc.1 Release Notes
|
||||
|
||||
Pre-release candidate. Published to npm under the `next` tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
rc.1 opens the 1.40.0 train. The headline change is the **skill-surface
|
||||
consolidation** ([#2790](https://github.com/GSD-redux/get-shit-done-redux/issues/2790))
|
||||
and the new **two-stage hierarchical namespace routing** that sits on top of it
|
||||
([#2792](https://github.com/GSD-redux/get-shit-done-redux/issues/2792)) — together
|
||||
they drop the cold-start system-prompt overhead from ~2,150 tokens (86 flat skills)
|
||||
to ~120 tokens (6 namespace routers). The release also adds the read-side of the
|
||||
phase-lifecycle status-line, hardens multi-runtime installs, and clears a backlog of
|
||||
correctness fixes for Gemini, Copilot, Codex, and the canary publish workflow.
|
||||
|
||||
### Added
|
||||
|
||||
- **Six namespace meta-skills with keyword-tag descriptions** — replace the flat
|
||||
86-skill listing with a two-stage hierarchical routing layer. The model sees 6
|
||||
namespace routers (`gsd:workflow`, `gsd:project`, `gsd:review`, `gsd:context`,
|
||||
`gsd:manage`, `gsd:ideate`) instead of 86 entries; selects a namespace, then routes
|
||||
to the sub-skill. Existing sub-skills are unchanged and still invocable directly.
|
||||
([#2792](https://github.com/GSD-redux/get-shit-done-redux/issues/2792))
|
||||
|
||||
- **`/gsd-health --context` utilization guard** — context-window quality guard with
|
||||
two thresholds: 60 % warns ("consider `/gsd-thread`"), 70 % is critical ("reasoning
|
||||
quality may degrade"). Also exposed as `gsd-tools validate context`.
|
||||
([#2792](https://github.com/GSD-redux/get-shit-done-redux/issues/2792))
|
||||
|
||||
- **Phase-lifecycle status-line — read-side** — `parseStateMd()` now reads four new
|
||||
STATE.md frontmatter fields: `active_phase`, `next_action`, `next_phases`, and
|
||||
`progress`. `formatGsdState()` gains scenes for in-flight, idle, and progress
|
||||
display. Write-side wiring follows in a later RC.
|
||||
([#2833](https://github.com/GSD-redux/get-shit-done-redux/issues/2833))
|
||||
|
||||
- **`--minimal` install flag** (alias `--core-only`) — writes only the six core
|
||||
skills needed for the main workflow loop; no `gsd-*` subagents. Drops cold-start
|
||||
overhead from ~12k tokens to ~700. Useful for local LLMs with 32K–128K context.
|
||||
([#2762](https://github.com/GSD-redux/get-shit-done-redux/issues/2762))
|
||||
|
||||
### Changed
|
||||
|
||||
- **Skill surface consolidated 86 → 59 `commands/gsd/*.md` entries** — four new
|
||||
grouped skills replace clusters of micro-skills (`capture`, `phase`, `config`,
|
||||
`workspace`); six existing parents absorb wrap-up and sub-operations as flags
|
||||
(`update --sync/--reapply`, `sketch --wrap-up`, `spike --wrap-up`,
|
||||
`map-codebase --fast/--query`, `code-review --fix`, `progress --do/--next`).
|
||||
Zero functional loss — 31 micro-skills deleted, all behavior preserved via flags.
|
||||
([#2790](https://github.com/GSD-redux/get-shit-done-redux/issues/2790))
|
||||
|
||||
- **Canary release workflow now publishes from `dev` branch only** — aligns with
|
||||
the branch→dist-tag policy (`dev` → `@canary`, `main` → `@next`/`@latest`).
|
||||
`workflow_dispatch` on `main` now completes build/test/dry-run validation but
|
||||
skips publish and tag.
|
||||
([#2868](https://github.com/GSD-redux/get-shit-done-redux/issues/2868))
|
||||
|
||||
- **PRs missing `Closes #NNN` are auto-closed** — the `Issue link required`
|
||||
workflow now auto-closes any PR opened without a closing keyword, posting a
|
||||
comment that points to the contribution guide.
|
||||
([#2872](https://github.com/GSD-redux/get-shit-done-redux/issues/2872))
|
||||
|
||||
### Fixed
|
||||
|
||||
- **Gemini slash commands now namespaced as `/gsd:<cmd>` instead of `/gsd-<cmd>`** —
|
||||
Gemini CLI namespaces commands under `gsd:` so `/gsd-plan-phase` was unexecutable.
|
||||
The install path now converts every body-text reference via a roster-checked regex,
|
||||
consistently rewriting command files, agent bodies, and banners.
|
||||
([#2768](https://github.com/GSD-redux/get-shit-done-redux/issues/2768),
|
||||
[#2783](https://github.com/GSD-redux/get-shit-done-redux/issues/2783))
|
||||
|
||||
- **GSD slash-command namespace drift cleaned up across docs, workflows, and
|
||||
autocomplete** — remaining stale `/gsd:<cmd>` references now use canonical
|
||||
`/gsd-<cmd>`; `scripts/fix-slash-commands.cjs` rewrites retired colon syntax.
|
||||
([#2858](https://github.com/GSD-redux/get-shit-done-redux/pull/2858))
|
||||
|
||||
- **`SKILL.md` description quoted for Copilot / Antigravity / Trae / CodeBuddy** —
|
||||
descriptions starting with a YAML 1.2 flow indicator crashed gh-copilot's strict
|
||||
YAML loader. Six emission sites now wrap descriptions in `yamlQuote(...)`.
|
||||
([#2876](https://github.com/GSD-redux/get-shit-done-redux/issues/2876))
|
||||
|
||||
- **`gsd-tools` invocations use the absolute installed path** — bare `gsd-tools …`
|
||||
calls inside skill bodies relied on PATH resolution not guaranteed in every runtime;
|
||||
replaced with the absolute path emitted at install time.
|
||||
([#2851](https://github.com/GSD-redux/get-shit-done-redux/issues/2851))
|
||||
|
||||
- **Codex installer preserves trailing newline when stripping legacy hooks** — the
|
||||
legacy-hook strip ran against files with no terminating newline at EOF, breaking
|
||||
downstream parsers.
|
||||
([#2866](https://github.com/GSD-redux/get-shit-done-redux/issues/2866))
|
||||
|
||||
---
|
||||
|
||||
## What was in rc.7
|
||||
|
||||
[`RELEASE-v1.39.0-rc.7.md`](RELEASE-v1.39.0-rc.7.md) — first 1.39.0 RC to roll in
|
||||
post-rc.5 fixes from `main`. Includes the `extractCurrentMilestone` fenced-code-block
|
||||
fix ([#2787](https://github.com/GSD-redux/get-shit-done-redux/issues/2787)), `audit-uat`
|
||||
frontmatter parse fix ([#2788](https://github.com/GSD-redux/get-shit-done-redux/issues/2788)),
|
||||
skill description budget + lint gate ([#2789](https://github.com/GSD-redux/get-shit-done-redux/issues/2789)),
|
||||
`gsd-sdk` workstream + binary-collision fixes ([#2791](https://github.com/GSD-redux/get-shit-done-redux/issues/2791)),
|
||||
and nine additional correctness fixes across OpenCode, Codex, and Gemini runtimes.
|
||||
|
||||
---
|
||||
|
||||
## Installing the pre-release
|
||||
|
||||
```bash
|
||||
# npm
|
||||
npm install -g @opengsd/get-shit-done-redux@next
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
```
|
||||
|
||||
To pin to this exact RC:
|
||||
|
||||
```bash
|
||||
npm install -g @opengsd/get-shit-done-redux@1.40.0-rc.1
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's next
|
||||
|
||||
- Soak rc.1 against real installs across Claude Code, Codex, Copilot, Gemini,
|
||||
OpenCode, and Antigravity runtimes.
|
||||
- Wire write-side phase-lifecycle status-line on top of the
|
||||
[#2833](https://github.com/GSD-redux/get-shit-done-redux/issues/2833) read-side.
|
||||
- Run `finalize` on the release workflow to promote `1.40.0` to `latest` once
|
||||
the train has soaked.
|
||||
@@ -1,199 +0,0 @@
|
||||
# v1.41.0 Release Notes
|
||||
|
||||
Stable release. Published to npm under the `latest` tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@latest
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
1.41.0 is a quality and infrastructure release. The headline additions are **per-phase-type model selection** and **dynamic routing** — two new config blocks that give you granular cost control without learning the agent taxonomy. The release also ships the **MVP mode SDK resolution layer** (three canonical query verbs replacing per-workflow bash duplication), the **optional update banner** for non-statusline users, and the **issue-driven orchestration guide**. Underneath that, 25+ correctness fixes cover Homebrew node path stability, planner directive fidelity, secure-phase retroactive audit, cross-runtime installs, and statusline parsing.
|
||||
|
||||
### Added
|
||||
|
||||
- **Per-phase-type model selection (`models` block)** — express "Opus for planning,
|
||||
Sonnet for the rest" in two config lines without learning the agent taxonomy. Six
|
||||
named slots (`planning` / `discuss` / `research` / `execution` / `verification` /
|
||||
`completion`) accept tier aliases (`opus` / `sonnet` / `haiku` / `inherit`). Fully
|
||||
backward compatible.
|
||||
([#3023](https://github.com/GSD-redux/get-shit-done-redux/pull/3030))
|
||||
|
||||
- **Dynamic routing with failure-tier escalation (`dynamic_routing` block)** — start
|
||||
cheap, escalate only when the orchestrator detects a soft failure (inconclusive
|
||||
verification, plan-check FLAG). Disabled by default; composes with `model_overrides`
|
||||
and `models.<phase_type>` via the same precedence chain.
|
||||
([#3024](https://github.com/GSD-redux/get-shit-done-redux/pull/3031))
|
||||
|
||||
- **Optional update banner for non-GSD statusline users** — when the installer detects
|
||||
no GSD statusline, it offers an opt-in `SessionStart` hook that surfaces update
|
||||
availability via the existing `~/.cache/gsd/gsd-update-check.json` cache. Silent when
|
||||
up-to-date; removed cleanly by `--uninstall`.
|
||||
([#2795](https://github.com/GSD-redux/get-shit-done-redux/pull/2795))
|
||||
|
||||
- **Issue-driven orchestration guide** — new
|
||||
[`docs/issue-driven-orchestration.md`](issue-driven-orchestration.md) recipe that maps
|
||||
tracker issues (GitHub / Linear / Jira) onto existing GSD primitives: workspace →
|
||||
discuss → plan → execute → verify → review → ship.
|
||||
([#2840](https://github.com/GSD-redux/get-shit-done-redux/pull/2840))
|
||||
|
||||
### Changed
|
||||
|
||||
- **MVP mode SDK resolution layer — three canonical query verbs** — three new verbs
|
||||
centralize the MVP-mode predicates previously duplicated across workflows:
|
||||
`gsd-sdk query phase.mvp-mode <N>` (precedence resolver), `task.is-behavior-adding`
|
||||
(Behavior-Adding Task predicate), and `user-story.validate` (User Story regex). All
|
||||
consuming workflows now call the verb instead of inlining 4–8 bash lines each. Also
|
||||
fixes a silent SDK bug where `roadmap.get-phase --pick mode` returned `null` for
|
||||
phases with `**Mode:** mvp` set.
|
||||
([#3178](https://github.com/GSD-redux/get-shit-done-redux/pull/3178))
|
||||
|
||||
- **`/gsd-graphify status` surfaces commit-based staleness** — reads `built_at_commit`
|
||||
from graphify v0.7+ graphs, compares against `git HEAD`, and adds four new fields
|
||||
(`built_at_commit`, `current_commit`, `commits_behind`, `commit_stale`). Pre-v0.7
|
||||
graphs return `commit_stale: null` and fall back to the existing mtime-based signal.
|
||||
([#3170](https://github.com/GSD-redux/get-shit-done-redux/issues/3170))
|
||||
|
||||
- **MVP concept index and domain glossary** — seven MVP-related terms added to
|
||||
`CONTEXT.md`; new `references/mvp-concepts.md` indexes the six MVP reference files.
|
||||
No behavior change.
|
||||
([#3176](https://github.com/GSD-redux/get-shit-done-redux/pull/3176))
|
||||
|
||||
### Fixed
|
||||
|
||||
- **Stable node path on Homebrew** — `resolveNodeRunner()` now maps versioned Cellar
|
||||
paths to the stable Homebrew symlinks. Prevents `dyld: Library not loaded` errors
|
||||
after `brew upgrade node`.
|
||||
([#3181](https://github.com/GSD-redux/get-shit-done-redux/issues/3181))
|
||||
|
||||
- **Milestone-archive layout support** — `validate consistency`, `validate health`, and
|
||||
`find-phase` now scan `.planning/milestones/v*-phases/` in addition to the flat
|
||||
`.planning/phases/` layout, eliminating spurious W006 warnings.
|
||||
([#3164](https://github.com/GSD-redux/get-shit-done-redux/issues/3164))
|
||||
|
||||
- **`/gsd-graphify build` runs inline instead of spawning a sub-agent** — the
|
||||
post-extraction clustering phase was SIGTERM'd when the sub-agent exited, leaving no
|
||||
`graph.json` / `graph.html` / `GRAPH_REPORT.md` artifacts.
|
||||
([#3166](https://github.com/GSD-redux/get-shit-done-redux/issues/3166))
|
||||
|
||||
- **Planner directive language restored** — 10 `CRITICAL`/`MANDATORY`/`MUST` emphasis
|
||||
markers were silently removed from `gsd-planner.md` in v1.38.4, weakening planner
|
||||
adherence to user decisions and requirement coverage. All restored.
|
||||
([#3138](https://github.com/GSD-redux/get-shit-done-redux/issues/3087))
|
||||
|
||||
- **`secure-phase` retroactive-STRIDE mode for legacy phases** — phases with no
|
||||
`<threat_model>` blocks no longer rubber-stamp a clean `SECURITY.md`; the auditor
|
||||
now builds a register from implementation files before verifying mitigations.
|
||||
([#3142](https://github.com/GSD-redux/get-shit-done-redux/issues/3120))
|
||||
|
||||
- **Global skills resolution now uses the correct runtime home directory** —
|
||||
`buildAgentSkillsBlock()` hardcoded `~/.claude/skills` for all runtimes. The new
|
||||
`runtime-homes.cjs` module maps all 15 supported runtimes to their canonical skills
|
||||
directory.
|
||||
([#3126](https://github.com/GSD-redux/get-shit-done-redux/issues/3126))
|
||||
|
||||
- **`state.begin-phase` is now idempotent** — wave-resume calls no longer overwrite
|
||||
`Current Plan`, `stopped_at`, or `Last Activity Description` with stale values from
|
||||
the last `plan-phase` run.
|
||||
([#3127](https://github.com/GSD-redux/get-shit-done-redux/issues/3127))
|
||||
|
||||
- **`gsd-validate-commit.sh` hook catches all git commit forms** — the previous bash
|
||||
regex missed `git -C /path commit`, `GIT_AUTHOR_NAME=x git commit`, and
|
||||
`/usr/bin/git commit`. New `hooks/lib/git-cmd.js` token-walk classifier handles all
|
||||
forms correctly.
|
||||
([#3141](https://github.com/GSD-redux/get-shit-done-redux/issues/3129))
|
||||
|
||||
- **`/gsd-plan-phase` no longer auto-dispatches to a subagent on OpenCode** — the
|
||||
`agent: gsd-planner` frontmatter directive caused OpenCode to run the orchestrator in
|
||||
a context where the `Agent` tool is unavailable. Directive removed.
|
||||
([#3156](https://github.com/GSD-redux/get-shit-done-redux/issues/3156))
|
||||
|
||||
- **`/gsd-quick` worktree-merge resurrection guard** — the inverted `PRE_MERGE_FILES`
|
||||
grep that deleted freshly-created files (including `SUMMARY.md`) is replaced with the
|
||||
git-history check used by `execute-phase.md`.
|
||||
([#3195](https://github.com/GSD-redux/get-shit-done-redux/issues/3195))
|
||||
|
||||
- **`gsd-health` no longer raises W019 for `RETROSPECTIVE.md`** — registered in
|
||||
`CANONICAL_EXACT` in `artifacts.cjs` to match its established status as a milestone
|
||||
completion artifact.
|
||||
([#3200](https://github.com/GSD-redux/get-shit-done-redux/issues/3198))
|
||||
|
||||
- **`--sdk` flag now wired into SDK deployment** — `hasSdk` was parsed but never
|
||||
passed to `installSdkIfNeeded`, so `--sdk` silently skipped deployment.
|
||||
([#3033](https://github.com/GSD-redux/get-shit-done-redux/issues/3033))
|
||||
|
||||
- **Installer shell-path probe for SDK shim** — no longer prints "✓ GSD SDK ready"
|
||||
when the shim is unreachable from the user's interactive shells; probes
|
||||
`$SHELL -lc 'printf %s "$PATH"'` instead of the installer subprocess PATH.
|
||||
([#3028](https://github.com/GSD-redux/get-shit-done-redux/issues/3020))
|
||||
|
||||
- **Windows update-check no longer silently fails** — passes `shell: true` on Windows
|
||||
so `npm.cmd` resolves via PATHEXT; without this the statusline "⬆ /gsd-update"
|
||||
indicator never rendered on Windows.
|
||||
([#3102](https://github.com/GSD-redux/get-shit-done-redux/issues/3103))
|
||||
|
||||
- **Community `.sh` hooks use `#!/usr/bin/env bash`** — the previous `#!/bin/bash`
|
||||
shebang fails on NixOS, minimal Alpine images, and some container runtimes.
|
||||
([#3194](https://github.com/GSD-redux/get-shit-done-redux/issues/3194))
|
||||
|
||||
- **Gemini local install no longer duplicates `/gsd:*` commands** — when GSD is
|
||||
already installed at user scope, a subsequent `--gemini --local` install skips the
|
||||
workspace scope. Previously both scopes received all 65 command files and Gemini's
|
||||
conflict detector renamed everything.
|
||||
([#3037](https://github.com/GSD-redux/get-shit-done-redux/issues/3037))
|
||||
|
||||
- **Workstream resolution in `init.milestone-op` and `roadmap.analyze`** — both
|
||||
handlers now respect `--ws`, `GSD_WORKSTREAM`, and `.planning/active-workstream`.
|
||||
Workstream-scoped repos no longer exit with "Nothing left to do" from reading the
|
||||
root `.planning/` directory.
|
||||
([#3196](https://github.com/GSD-redux/get-shit-done-redux/issues/3196),
|
||||
[#3207](https://github.com/GSD-redux/get-shit-done-redux/pull/3207))
|
||||
|
||||
- **`gsd-tools config-set workflow._auto_chain_active` no longer rejected** — the key
|
||||
was added to the SDK schema but not mirrored to `config-schema.cjs`; users routed
|
||||
through `gsd-tools` saw "Unknown config key."
|
||||
([#3197](https://github.com/GSD-redux/get-shit-done-redux/issues/3197))
|
||||
|
||||
- **Statusline state rendering is type-robust and YAML-list compatible** — milestone
|
||||
completion renders for numeric and string `percent` values; `next_phases` parses both
|
||||
flow-array and block-list YAML.
|
||||
([#3153](https://github.com/GSD-redux/get-shit-done-redux/issues/3153))
|
||||
|
||||
- **Codex SessionStart hook uses absolute Node binary path** — bare `node` in
|
||||
`config.toml` failed with exit 127 under GUI/minimal-PATH runtimes.
|
||||
([#3022](https://github.com/GSD-redux/get-shit-done-redux/issues/3017))
|
||||
|
||||
- **`config-set resolve_model_ids` and `workflow._auto_chain_active` accepted** — both
|
||||
keys were documented or written by internal workflows but missing from the allowlists.
|
||||
([#3162](https://github.com/GSD-redux/get-shit-done-redux/issues/3162))
|
||||
|
||||
---
|
||||
|
||||
## What was in 1.40.0
|
||||
|
||||
[`RELEASE-v1.40.0-rc.1.md`](RELEASE-v1.40.0-rc.1.md) — skill-surface consolidation
|
||||
(86 → 59, [#2790](https://github.com/GSD-redux/get-shit-done-redux/issues/2790)), six
|
||||
namespace meta-skills ([#2792](https://github.com/GSD-redux/get-shit-done-redux/issues/2792)),
|
||||
`/gsd-health --context` utilization guard, phase-lifecycle status-line read-side
|
||||
([#2833](https://github.com/GSD-redux/get-shit-done-redux/issues/2833)), and Gemini
|
||||
colon-form slash-command conversion.
|
||||
|
||||
---
|
||||
|
||||
## Installing
|
||||
|
||||
```bash
|
||||
# npm (global)
|
||||
npm install -g @opengsd/get-shit-done-redux@latest
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@latest
|
||||
|
||||
# Pin to this exact version
|
||||
npm install -g @opengsd/get-shit-done-redux@1.41.0
|
||||
```
|
||||
|
||||
The installer is idempotent — re-running on an existing install updates in-place,
|
||||
preserving your `.planning/` directory and local patches.
|
||||
@@ -1,100 +0,0 @@
|
||||
# v1.42.0-rc.1 Release Notes
|
||||
|
||||
First release candidate for the **1.42.0** train. Published to npm under the `next` dist-tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
# or pin exact:
|
||||
npm install -g @opengsd/get-shit-done-redux@1.42.0-rc1
|
||||
```
|
||||
|
||||
> **Release-candidate stream caveat.** RCs come from `main` and are the staging stream for the next stable `latest`. They are stable enough for everyday use but may carry bake items resolved before the matching `vX.Y.0` is published. See [CANARY.md](CANARY.md) for the stream policy.
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
1.42.0-rc.1 is the first cut of the 1.42 train. The headline addition is a **package legitimacy gate against slopsquatting** — a three-layer defense across the research → plan → execute pipeline that prevents AI-hallucinated package names from flowing undetected into `npm install`. Underneath that, two structural refactors deepen the **SDK package seam** and the **phase lifecycle seams** so future work has cleaner module boundaries.
|
||||
|
||||
This RC also rolls up every fix that shipped in [v1.41.1](https://github.com/GSD-redux/get-shit-done-redux/releases/tag/v1.41.1). Those fixes are listed in the v1.41.1 notes and on the GitHub release page; this document is scoped to the **new features** in 1.42.0.
|
||||
|
||||
---
|
||||
|
||||
## Added
|
||||
|
||||
### Security
|
||||
|
||||
#### Package legitimacy gate against slopsquatting ([#3215](https://github.com/GSD-redux/get-shit-done-redux/pull/3215))
|
||||
|
||||
A three-layer defense across the research → plan → execute pipeline. Before this release, a hallucinated package name that passed `npm view` could flow undetected into `gsd-executor` running `npm install <malicious-pkg>` with no human gate. The gate closes that path:
|
||||
|
||||
- **Layer 1 — Researcher (`agents/gsd-phase-researcher.md`).** A new `<package_legitimacy_protocol>` block runs `slopcheck install <pkgs> --json` over every recommended package, performs ecosystem-specific verification (`pip index versions` / `npm view` / `cargo search`), and emits a `## Package Legitimacy Audit` table to `RESEARCH.md` with Package, Registry, Age, Downloads, Source Repo, slopcheck, and Disposition columns. Packages discovered solely through WebSearch are tagged `[ASSUMED]` — never `[VERIFIED]`. `[SLOP]` packages are removed from RESEARCH.md and listed under "Packages removed due to slopcheck."
|
||||
- **Layer 2 — Planner (`agents/gsd-planner.md`).** Reads the Audit table and inserts a `checkpoint:human-verify` task before any install whose package is tagged `[ASSUMED]` or `[SUS]`. Plans that introduce installs gain a `T-{phase}-SC` Tampering / supply-chain row in their `<threat_model>` template.
|
||||
- **Layer 3 — Executor (`agents/gsd-executor.md`).** RULE 3 amended: package installs (`npm`/`pip`/`cargo`) are excluded from auto-fix scope. Failed installs become `checkpoint:human-verify` with a slopsquatting-risk rationale instead of being silently retried.
|
||||
|
||||
**Hardening.** Every `npx --yes <pkg>@latest` invocation across the three agent files is replaced with a `command -v <bin>` guard pattern — this closes the same fetch-and-execute hole `npx --yes` opens.
|
||||
|
||||
**Graceful degradation.** When `slopcheck` is unavailable at research time, every recommended package is tagged `[ASSUMED]` and gated with a checkpoint, so the protective behavior degrades safely instead of bypassing the gate.
|
||||
|
||||
**Documentation.** `docs/USER-GUIDE.md` has a new "Package Legitimacy Gate" subsection in the Security section; `docs/COMMANDS.md` notes the gate on `/gsd-plan-phase`; `docs/ARCHITECTURE.md` documents the gate before the Security Hooks section and updates the plan-phase pipeline diagram with the gate steps.
|
||||
|
||||
Closes [#2827](https://github.com/GSD-redux/get-shit-done-redux/issues/2827).
|
||||
|
||||
---
|
||||
|
||||
## Changed
|
||||
|
||||
### Architecture
|
||||
|
||||
#### SDK package seam deepened; runtime-global skills policy converged ([#3238](https://github.com/GSD-redux/get-shit-done-redux/pull/3238))
|
||||
|
||||
Concentrates two areas that were previously scattered across the codebase:
|
||||
|
||||
- **SDK Package Seam Module.** Legacy package and install-layout compatibility — previously leaked across `state-project-load`, `verify`, `roadmap`, prompt-loading paths, `agent-skills`, `skill-manifest`, and `generateDevPreferences` — is now centralized behind a single Module. Callers consume legacy-asset discovery and install-layout probing through a thin Adapter; transition-only error messaging lives in one place.
|
||||
- **Runtime-Global Skills Policy Module.** A single runtime-aware global-skills directory policy is now shared by SDK and CJS callers. Resolves runtime-global skills bases and skill paths from the runtime + env precedence chain, renders display paths for warnings/manifests, and reports unsupported runtimes that lack a skills directory.
|
||||
|
||||
The CONTEXT.md domain glossary is updated with both Module entries so future work points at the canonical seams instead of re-deriving the boundaries.
|
||||
|
||||
Closes [#3237](https://github.com/GSD-redux/get-shit-done-redux/issues/3237). Refs [#3234](https://github.com/GSD-redux/get-shit-done-redux/issues/3234).
|
||||
|
||||
#### Phase lifecycle seams deepened ([#3267](https://github.com/GSD-redux/get-shit-done-redux/pull/3267))
|
||||
|
||||
`phase-lifecycle.ts` becomes a thin public orchestrator. Three new modules are extracted:
|
||||
|
||||
- **Phase Numbering Policy Module.** Phase-name and project-code validation, slug/ID generation, sequential and decimal phase progression, and roadmap-entry construction.
|
||||
- **Phase Filesystem Adapter Module.** Directory listing, gitkeep creation, and archive operations for phase directories.
|
||||
- **Phase Roadmap Mutation Module.** `replaceInCurrentMilestone` and atomic ROADMAP.md read-modify-write under planning lock.
|
||||
|
||||
Backward-compatible re-exports are preserved on `phase-lifecycle.ts` so existing callers continue to work; new callers should import from the dedicated modules.
|
||||
|
||||
Closes [#3270](https://github.com/GSD-redux/get-shit-done-redux/issues/3270).
|
||||
|
||||
---
|
||||
|
||||
## What was in 1.41.x
|
||||
|
||||
- **[v1.41.1](https://github.com/GSD-redux/get-shit-done-redux/releases/tag/v1.41.1)** — 14-fix hotfix: phase-plan-index DAG correctness, state-snapshot YAML frontmatter precedence, code-review SUMMARY parser hardening (`BL-` / `blocker:` accepted as Critical-tier), Codex install TOML floats + idempotent rollback, persistent SDK reachability probe, shared model-catalog source of truth (ADR-0003), and more.
|
||||
- **[v1.41.0](https://github.com/GSD-redux/get-shit-done-redux/releases/tag/v1.41.0)** — six namespace meta-skills, `/gsd-health --context` utilization guard, `--minimal` install flag, `/gsd-edit-phase`, post-merge build & test gate, manual canary release workflow, and 25+ correctness fixes. See [`RELEASE-v1.41.0.md`](RELEASE-v1.41.0.md).
|
||||
|
||||
---
|
||||
|
||||
## Installing
|
||||
|
||||
```bash
|
||||
# npm (global, RC channel)
|
||||
npm install -g @opengsd/get-shit-done-redux@next
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@next
|
||||
|
||||
# Pin to this exact RC
|
||||
npm install -g @opengsd/get-shit-done-redux@1.42.0-rc1
|
||||
```
|
||||
|
||||
The installer is idempotent — re-running on an existing install updates in-place, preserving your `.planning/` directory and local patches.
|
||||
|
||||
To roll back to the latest stable, install with `@latest`:
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@latest
|
||||
```
|
||||
@@ -1,178 +0,0 @@
|
||||
# v1.42.1 Release Notes
|
||||
|
||||
Stable release. Published to npm under the `latest` tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@latest
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
1.42.1 is a safety and control-surface release. The headline additions are the
|
||||
**package legitimacy gate**, **skill-surface budgeting**, and the **installer migration
|
||||
framework** — three changes that make GSD safer to install, safer to update, and easier
|
||||
to run in constrained contexts. The release also ships configurable `/gsd-ship` PR body
|
||||
sections, `/gsd-review` reviewer defaults, optional fallow structural review, and
|
||||
quota-aware execution recovery. Underneath that, 30+ correctness fixes cover
|
||||
`project_code` phase directories, phase completion, nested git detection, Codex
|
||||
install migration, SDK readiness, and decimal-phase dependencies.
|
||||
|
||||
### Added
|
||||
|
||||
- **Package legitimacy gate against slopsquatting** — researchers audit external
|
||||
packages with `slopcheck`, planners add human verification for unverified packages,
|
||||
and executors stop on package install failures instead of trying similarly named
|
||||
alternatives. This closes the path where AI-hallucinated package names could flow
|
||||
from research into `npm install` / `pip install` / `cargo add`.
|
||||
([#3215](https://github.com/GSD-redux/get-shit-done-redux/pull/3215))
|
||||
|
||||
- **Skill surface budgeting** — install with `--profile=core`, `--profile=standard`,
|
||||
or the default `full`; profiles persist in `.gsd-profile`. Use `/gsd:surface` to
|
||||
list, enable, disable, reset, or switch skill clusters without reinstalling.
|
||||
`--minimal` and `--core-only` remain aliases for `--profile=core`.
|
||||
([#3408](https://github.com/GSD-redux/get-shit-done-redux/pull/3456))
|
||||
|
||||
- **Installer migration framework** — install now has explicit migration records,
|
||||
baseline scanning, legacy cleanup, user-owned artifact preservation, dry-run
|
||||
reporting, rollback protection, and ambiguous stale-file guardrails.
|
||||
([#3398](https://github.com/GSD-redux/get-shit-done-redux/pull/3398),
|
||||
[#3399](https://github.com/GSD-redux/get-shit-done-redux/pull/3399),
|
||||
[#3400](https://github.com/GSD-redux/get-shit-done-redux/pull/3400),
|
||||
[#3402](https://github.com/GSD-redux/get-shit-done-redux/pull/3402),
|
||||
[#3404](https://github.com/GSD-redux/get-shit-done-redux/pull/3404))
|
||||
|
||||
- **Configurable `/gsd-ship` PR body sections** — `ship.pr_body_sections` appends
|
||||
project-specific PRD-style sections while preserving the required `Summary`,
|
||||
`Changes`, `Requirements Addressed`, `Verification`, and `Key Decisions` sections.
|
||||
([#3391](https://github.com/GSD-redux/get-shit-done-redux/pull/3391))
|
||||
|
||||
- **`review.default_reviewers`** — no-flag `/gsd-review` can default to a configured
|
||||
reviewer subset. Explicit reviewer flags and `--all` still take precedence.
|
||||
([#3464](https://github.com/GSD-redux/get-shit-done-redux/pull/3464))
|
||||
|
||||
- **Optional fallow structural review pre-pass** — `code_quality.fallow.*` runs a
|
||||
structural pass before `/gsd-code-review`, writes `FALLOW.json`, and embeds
|
||||
structural findings in `REVIEW.md`.
|
||||
([#3424](https://github.com/GSD-redux/get-shit-done-redux/pull/3486))
|
||||
|
||||
- **Structured CLI error mode** — `gsd-tools --json-errors` returns machine-readable
|
||||
error envelopes for automation and SDK callers while preserving human-readable output
|
||||
by default.
|
||||
([#3255](https://github.com/GSD-redux/get-shit-done-redux/pull/3304))
|
||||
|
||||
### Changed
|
||||
|
||||
- **Human verification defaults to end-of-phase** — `workflow.human_verify_mode:
|
||||
"end-of-phase"` keeps human checks in verification blocks instead of scattering
|
||||
mid-flight checkpoint tasks. Set `"mid-flight"` to restore the previous blocking
|
||||
checkpoint behavior.
|
||||
([#3309](https://github.com/GSD-redux/get-shit-done-redux/pull/3325))
|
||||
|
||||
- **Quota and rate-limit failures get a distinct recovery path** — execute-phase
|
||||
classifies provider quota failures (`429`, `rate limit`, `usage limit`,
|
||||
`RESOURCE_EXHAUSTED`, etc.) and guides wait-and-resume instead of retry-now.
|
||||
([#3095](https://github.com/GSD-redux/get-shit-done-redux/pull/3490))
|
||||
|
||||
- **Milestone tags can be disabled** — `git.create_tag: false` lets projects with
|
||||
external release automation complete milestones without creating local tags.
|
||||
Existing tag collisions now fail clearly instead of overwriting tags.
|
||||
([#3086](https://github.com/GSD-redux/get-shit-done-redux/pull/3508))
|
||||
|
||||
- **Statusline context meter can move to the front** — `statusline.context_position:
|
||||
"front"` renders the context meter after the model name so it stays visible in narrow
|
||||
terminals.
|
||||
([#2937](https://github.com/GSD-redux/get-shit-done-redux/pull/3515))
|
||||
|
||||
- **Reasoning effort is transported with resolved model IDs** — runtime-aware model
|
||||
resolution now carries `reasoning_effort` where supported, including Codex config
|
||||
output and SDK query paths.
|
||||
([#3474](https://github.com/GSD-redux/get-shit-done-redux/pull/3483))
|
||||
|
||||
- **Shell command projection and SDK architecture seams deepened** — hook commands,
|
||||
path actions, subprocess execution, platform file I/O, SDK compatibility policy, and
|
||||
runtime skill policy now flow through narrower typed modules.
|
||||
([#3238](https://github.com/GSD-redux/get-shit-done-redux/pull/3238),
|
||||
[#3316](https://github.com/GSD-redux/get-shit-done-redux/pull/3316),
|
||||
[#3470](https://github.com/GSD-redux/get-shit-done-redux/pull/3470),
|
||||
[#3476](https://github.com/GSD-redux/get-shit-done-redux/pull/3476),
|
||||
[#3481](https://github.com/GSD-redux/get-shit-done-redux/pull/3481),
|
||||
[#3484](https://github.com/GSD-redux/get-shit-done-redux/pull/3484))
|
||||
|
||||
### Fixed
|
||||
|
||||
- **`project_code` phase directory prefixes apply consistently** — first-touch
|
||||
`/gsd-discuss-phase`, `/gsd-plan-phase`, import, gap-planning, and backlog creation
|
||||
paths now create prefixed phase directories consistently.
|
||||
([#3287](https://github.com/GSD-redux/get-shit-done-redux/pull/3292),
|
||||
[#3298](https://github.com/GSD-redux/get-shit-done-redux/pull/3306))
|
||||
|
||||
- **Phase completion is idempotent and refreshes state** — `state complete-phase` and
|
||||
`phase.complete` no longer leave stale `STATE.md` progress, focus, or body
|
||||
frontmatter fields behind.
|
||||
([#3489](https://github.com/GSD-redux/get-shit-done-redux/pull/3499),
|
||||
[#3517](https://github.com/GSD-redux/get-shit-done-redux/pull/3520))
|
||||
|
||||
- **Nested git worktrees are detected** — `/gsd-new-project` and ingest flows avoid
|
||||
creating nested `.git` directories when run inside an existing repository or
|
||||
worktree.
|
||||
([#3491](https://github.com/GSD-redux/get-shit-done-redux/pull/3502))
|
||||
|
||||
- **Codex install and hook migration are safer** — AoT hooks use event-name leaf keys,
|
||||
duplicate legacy `hooks.json` entries are removed, user hooks are preserved, and
|
||||
unsupported execute-phase worktrees are blocked.
|
||||
([#3346](https://github.com/GSD-redux/get-shit-done-redux/pull/3505),
|
||||
[#3357](https://github.com/GSD-redux/get-shit-done-redux/pull/3380),
|
||||
[#3360](https://github.com/GSD-redux/get-shit-done-redux/pull/3380))
|
||||
|
||||
- **SDK install readiness is durable** — `--sdk` now forces SDK deployment, stale shims
|
||||
are detected, Windows PATH probing is hardened, and "GSD SDK ready" only prints when
|
||||
the shim is reachable.
|
||||
([#3033](https://github.com/GSD-redux/get-shit-done-redux/issues/3033),
|
||||
[#3211](https://github.com/GSD-redux/get-shit-done-redux/pull/3282),
|
||||
[#3231](https://github.com/GSD-redux/get-shit-done-redux/pull/3249),
|
||||
[#3359](https://github.com/GSD-redux/get-shit-done-redux/pull/3380))
|
||||
|
||||
- **User custom skills are preserved during update detection** — `detect-custom-files`
|
||||
now scans `skills/`, preventing user-added skill files from being missed during
|
||||
patch preservation.
|
||||
([#3317](https://github.com/GSD-redux/get-shit-done-redux/pull/3318))
|
||||
|
||||
- **Decimal-phase `depends_on` references resolve correctly** — SDK phase indexing now
|
||||
expands same-phase short forms such as `depends_on: [01]` and warns on unresolved
|
||||
references.
|
||||
([#3488](https://github.com/GSD-redux/get-shit-done-redux/pull/3501))
|
||||
|
||||
- **`gsd-sdk query commit --files --respect-staged` preserves interactive staging** —
|
||||
respect-staged mode now avoids restaging pathspecs and commits only the already
|
||||
staged hunks within the requested file scope.
|
||||
([#3522](https://github.com/GSD-redux/get-shit-done-redux/pull/3528))
|
||||
|
||||
---
|
||||
|
||||
## What was in 1.41.0
|
||||
|
||||
[`RELEASE-v1.41.0.md`](RELEASE-v1.41.0.md) — per-phase-type model selection,
|
||||
dynamic routing with failure-tier escalation, the optional update banner,
|
||||
issue-driven orchestration, MVP mode SDK query verbs, graphify commit-based
|
||||
staleness, and 25+ correctness fixes across Homebrew node paths, milestone archives,
|
||||
secure-phase audits, cross-runtime installs, and statusline parsing.
|
||||
|
||||
---
|
||||
|
||||
## Installing
|
||||
|
||||
```bash
|
||||
# npm (global)
|
||||
npm install -g @opengsd/get-shit-done-redux@latest
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@latest
|
||||
|
||||
# Pin to this exact version
|
||||
npm install -g @opengsd/get-shit-done-redux@1.42.1
|
||||
```
|
||||
|
||||
The installer is idempotent — re-running on an existing install updates in-place,
|
||||
preserving your `.planning/` directory and local patches.
|
||||
@@ -1,157 +0,0 @@
|
||||
# v1.42.3 Release Notes
|
||||
|
||||
Hotfix release. Published to npm under the `latest` tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@latest
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## What's in this release
|
||||
|
||||
1.42.3 is a stability hotfix on top of 1.42.2. The headline is **Codex
|
||||
CLI 0.130.0 install routability** — after `npx @opengsd/get-shit-done-redux@latest
|
||||
--codex`, `$gsd-*` skills now resolve correctly under Codex 0.130.0 and
|
||||
later, where the previous build left users with zero routable
|
||||
entrypoints. The release also ships **runtime-aware slash formatting**
|
||||
so emitted commands match the install's routing shape (Claude → `/gsd-*`,
|
||||
Codex → `$gsd-*`) instead of the deprecated colon form, an **argv-based
|
||||
subprocess** fix for `check.ship-ready` that closes a shell-injection
|
||||
class through git refnames, the **`phase_status` field on
|
||||
init.plan-phase** that gates `/gsd:plan-phase` on closed phases, plus
|
||||
correctness fixes for archived-phase warnings, future-phase warnings,
|
||||
canonical Codex hooks, and the SDK bridge load path.
|
||||
|
||||
### Fixed
|
||||
|
||||
- **Codex CLI 0.130.0 install now materializes routable skills** —
|
||||
`bin/install.js` writes `~/.codex/skills/gsd-<name>/SKILL.md` for every
|
||||
shipped command so `$gsd-*` skills resolve after install. Codex 0.130.0
|
||||
dropped the extra-skills-roots discovery the previous build relied on,
|
||||
leaving users with a successful-looking install and zero usable
|
||||
commands. Documented minimum Codex CLI version (0.130.0) inline in the
|
||||
Codex sections of `USER-GUIDE.md` and `CONFIGURATION.md`.
|
||||
([#3562](https://github.com/GSD-redux/get-shit-done-redux/pull/3568),
|
||||
[#3582](https://github.com/GSD-redux/get-shit-done-redux/pull/3609))
|
||||
|
||||
- **Runtime-aware slash formatter for user-facing emissions** —
|
||||
`runtime-slash.cjs` produces `/gsd-<cmd>` for skills-based runtimes
|
||||
(Claude, Cursor, OpenCode, Kilo, etc.) and `$gsd-<cmd>` for Codex.
|
||||
The deprecated colon form `/gsd:<cmd>` is no longer emitted at
|
||||
runtime, so the recommendations from `init`, `phase`, `verify`,
|
||||
`milestone`, `validate-command-router`, `workstream`, `profile-output`,
|
||||
`drift`, `gsd2-import`, and `commands` now paste cleanly into the
|
||||
active runtime.
|
||||
([#3584](https://github.com/GSD-redux/get-shit-done-redux/pull/3606))
|
||||
|
||||
- **Argv-based subprocess for `check.ship-ready`** — every git/gh probe
|
||||
in `sdk/src/query/check-ship-ready.ts` now uses `execFileSync` with an
|
||||
argv array instead of `execSync` with shell-interpolated strings.
|
||||
Closes a shell-injection class where a malicious branch name (e.g.
|
||||
`foo;touch INJ;bar`) interpolated into `git config --get
|
||||
branch.<name>.merge` triggered arbitrary code execution.
|
||||
([#3587](https://github.com/GSD-redux/get-shit-done-redux/pull/3611))
|
||||
|
||||
- **`init.plan-phase` surfaces `phase_status`; `/gsd:plan-phase` gates
|
||||
on closed phases** — `init.plan-phase` payload now carries the
|
||||
authoritative phase status (`Pending` / `Planned` / `Executed` /
|
||||
`Complete`) from `determinePhaseStatus`. The plan-phase workflow
|
||||
short-circuits on `Complete` (with `--force` override), and
|
||||
`--reviews` against a closed phase hard-errors with no override.
|
||||
Prevents accidental re-planning over shipped code.
|
||||
([#3569](https://github.com/GSD-redux/get-shit-done-redux/pull/3581))
|
||||
|
||||
- **Canonical `[features].hooks` for Codex configs, legacy alias
|
||||
recognized** — Codex config emission uses the canonical
|
||||
`features.hooks` key while still accepting the legacy `codex_hooks`
|
||||
shape on read. Fixes the install where the previous key drift left
|
||||
Codex unable to find managed hooks.
|
||||
([#3566](https://github.com/GSD-redux/get-shit-done-redux/pull/3573))
|
||||
|
||||
- **SDK bridge loads via the public package export** — fixes a stale
|
||||
internal path that broke SDK dispatch after install on some package
|
||||
layouts.
|
||||
([#3567](https://github.com/GSD-redux/get-shit-done-redux/pull/3574))
|
||||
|
||||
- **W006/W007 health warnings skip archived and future phases** —
|
||||
`/gsd:health` no longer flags phases that are intentionally
|
||||
unimplemented (future) or archived as missing-on-disk or
|
||||
missing-from-roadmap.
|
||||
([#3559](https://github.com/GSD-redux/get-shit-done-redux/pull/3565),
|
||||
[#3560](https://github.com/GSD-redux/get-shit-done-redux/pull/3564))
|
||||
|
||||
- **Ultraplan runtime gates on Claude Code markers** — `/gsd:ultraplan`
|
||||
detects the runtime via Claude Code markers and fails closed when
|
||||
the version is unavailable, instead of running against an unknown
|
||||
runtime.
|
||||
([#3561](https://github.com/GSD-redux/get-shit-done-redux/pull/3563))
|
||||
|
||||
- **Padded phase IDs match unpadded ROADMAP prose** — phase routing
|
||||
through `phaseMarkdownRegexSource` handles `02.7` ↔ `2.7` and
|
||||
similar padding mismatches so `/gsd:phase complete 02` updates a
|
||||
ROADMAP that uses the short `### Phase 2:` form.
|
||||
([#3537](https://github.com/GSD-redux/get-shit-done-redux/pull/3538))
|
||||
|
||||
- **W007 ignores archived phase directories** — phases under
|
||||
`.planning/milestones/v*/` no longer trigger
|
||||
"exists on disk but not in roadmap" warnings against the active
|
||||
roadmap.
|
||||
([#3560](https://github.com/GSD-redux/get-shit-done-redux/pull/3564))
|
||||
|
||||
- **Prompt-user migration actions resolve in non-TTY runs** —
|
||||
`installer-migration-authoring` flows complete cleanly under CI /
|
||||
non-interactive shells; error grouping clarified.
|
||||
([#3541](https://github.com/GSD-redux/get-shit-done-redux/pull/3547))
|
||||
|
||||
- **Executor agents forbidden from `git stash`** — execution agents
|
||||
no longer use shared stash storage, which violated worktree
|
||||
isolation when multiple agents ran in parallel.
|
||||
([#3542](https://github.com/GSD-redux/get-shit-done-redux/pull/3546))
|
||||
|
||||
- **Configuration manifests load from the installed payload** —
|
||||
`configuration.generated.cjs` looks in the installed
|
||||
`gsd-core/bin/shared/` path first, then falls back to
|
||||
source-checkout `sdk/shared/`. Fixes the install where the manifest
|
||||
loader failed on the runtime layout because the source-tree path
|
||||
doesn't exist after install.
|
||||
([#3571](https://github.com/GSD-redux/get-shit-done-redux/pull/3572))
|
||||
|
||||
---
|
||||
|
||||
## What was in 1.42.1
|
||||
|
||||
[`RELEASE-v1.42.1.md`](RELEASE-v1.42.1.md) — package legitimacy gate
|
||||
against slopsquatting, skill-surface budgeting (`--profile=core` /
|
||||
`standard` / `full`), installer migration framework, configurable
|
||||
`/gsd-ship` PR body sections, `review.default_reviewers`, optional
|
||||
fallow structural review, structured `--json-errors` CLI mode, plus
|
||||
30+ correctness fixes across `project_code` phase prefixes, phase
|
||||
completion idempotency, nested git detection, Codex install migration,
|
||||
SDK install readiness, and decimal-phase dependencies.
|
||||
|
||||
---
|
||||
|
||||
## Installing
|
||||
|
||||
```bash
|
||||
# npm (global)
|
||||
npm install -g @opengsd/get-shit-done-redux@latest
|
||||
|
||||
# npx (one-shot)
|
||||
npx @opengsd/get-shit-done-redux@latest
|
||||
|
||||
# Pin to this exact version
|
||||
npm install -g @opengsd/get-shit-done-redux@1.42.3
|
||||
```
|
||||
|
||||
The installer is idempotent — re-running on an existing install
|
||||
updates in-place, preserving your `.planning/` directory and local
|
||||
patches.
|
||||
|
||||
### Codex CLI requirement
|
||||
|
||||
Codex installs (`--codex`) require **Codex CLI 0.130.0 or later**.
|
||||
Earlier Codex versions used a discovery mechanism that the current
|
||||
install layout does not target; upgrade Codex first, then re-run the
|
||||
GSD installer.
|
||||
@@ -1,94 +0,0 @@
|
||||
# v1.50.0-canary.1 Release Notes
|
||||
|
||||
First canary cut for the **1.50.0** train. Published to npm under the `canary` dist-tag.
|
||||
|
||||
```bash
|
||||
npx @opengsd/get-shit-done-redux@canary
|
||||
# or pin exact:
|
||||
npm install -g @opengsd/get-shit-done-redux@1.50.0-canary.1
|
||||
```
|
||||
|
||||
> **Canary stream caveat.** Canary builds come from the long-lived `dev` integration branch and may carry rough edges that the `next` (RC) and `latest` (stable) channels never see. Use canary when you want to exercise in-flight features early and report findings; do NOT pin production projects to it. See [CANARY.md](CANARY.md) for the stream policy and rollback path.
|
||||
|
||||
---
|
||||
|
||||
## Headline: Vertical MVP / TDD / UAT planning track
|
||||
|
||||
The 1.50.0 train opens with a four-phase vertical slice that adds an end-to-end "MVP mode" to the GSD planning pipeline — from project kickoff, through phase planning, through execution, through verification. Issue [#2826](https://github.com/GSD-redux/get-shit-done-redux/issues/2826) is the umbrella PRD.
|
||||
|
||||
### What's new
|
||||
|
||||
#### `/gsd plan-phase --mvp` — vertical-slice planning ([#2867](https://github.com/GSD-redux/get-shit-done-redux/pull/2867))
|
||||
|
||||
`/gsd plan-phase` learns a `--mvp` flag that flips the planner into vertical-slice mode. The planner reads `**Mode:** mvp` from a phase's ROADMAP entry, an explicit `--mvp` CLI override, or `workflow.mvp_mode` in `.planning/config.json` (precedence in that order, with the CLI flag winning). Under MVP mode the planner:
|
||||
|
||||
- Surfaces a "Walking Skeleton" template for the very first phase of a new project — a thin end-to-end vertical slice that proves the wiring before any horizontal layer is built
|
||||
- Suppresses horizontal-layer language ("data layer first, then business logic, then UI") in favor of user-flow-driven decomposition
|
||||
- Emits the user story as a header at the top of `PLAN.md`
|
||||
|
||||
New required-reading injection: `references/planner-mvp-mode.md`. New parser surface: `roadmap.cjs` extracts a `mode` field on every phase lookup.
|
||||
|
||||
#### `/gsd mvp-phase <N>` — guided user-story phase framing ([#2874](https://github.com/GSD-redux/get-shit-done-redux/pull/2874))
|
||||
|
||||
A new top-level command that walks the user through framing a phase as a vertical MVP slice before planning. Three structured prompts capture an "As a / I want to / So that" user story. If the story is too large, an interactive SPIDR (Spike / Path / Interface / Data / Rule) splitting flow surfaces a list of `/gsd add-phase` invocations to break the work apart. The command then:
|
||||
|
||||
- Mutates the ROADMAP entry to set `**Mode:** mvp` and replaces `**Goal:**` with the assembled user story
|
||||
- Delegates to `/gsd plan-phase --mvp <N>` to produce the plan
|
||||
|
||||
Two new references: [`spidr-splitting.md`](../gsd-core/references/spidr-splitting.md), [`user-story-template.md`](../gsd-core/references/user-story-template.md).
|
||||
|
||||
#### Execute-phase MVP+TDD runtime gate ([#2878](https://github.com/GSD-redux/get-shit-done-redux/pull/2878))
|
||||
|
||||
When `MVP_MODE` and `TDD_MODE` are both true at execution time, `execute-phase` adds a per-task gate that requires a `test(<phase>-<plan>):` commit to exist before the corresponding `feat(...)` commit. The reference [`execute-mvp-tdd.md`](../gsd-core/references/execute-mvp-tdd.md) documents the contract; the executor agent (`agents/gsd-executor.md`) gains an MVP+TDD Gate section that explains when the gate trips, what evidence it expects, and how to escalate via the documented escape hatch.
|
||||
|
||||
> **Known canary-bake item.** The current bash gate snippet uses some workflow variables that aren't fully wired (`${PLAN_ID}`, `${TASK_TDD}`) and the documented `--force-mvp-gate` escape hatch is referenced in the user-facing error message but not yet implemented in the argument parser. These are tracked as canary-bake follow-ups; the gate itself is functional for the dominant code path.
|
||||
|
||||
#### Verify-work MVP-mode UAT framing ([#2880](https://github.com/GSD-redux/get-shit-done-redux/pull/2880))
|
||||
|
||||
Under MVP mode, `verify-work` flips the UAT script's framing so user-flow steps come **before** technical correctness checks — the inverse of the default order. The verifier agent gains a `mvp_mode_verification` section. New reference: [`verify-mvp-mode.md`](../gsd-core/references/verify-mvp-mode.md).
|
||||
|
||||
A user-story format guard at the top of `extract_tests` will halt verification if a phase claims `**Mode:** mvp` but its `**Goal:**` doesn't parse as `As a … I want to … so that …` — pointing the user at `/gsd mvp-phase <N>` to repair.
|
||||
|
||||
#### Discovery & progress surfaces ([#2883](https://github.com/GSD-redux/get-shit-done-redux/pull/2883))
|
||||
|
||||
The MVP slice closes out with read-side surfaces:
|
||||
|
||||
- **`/gsd new-project`** prompts up front for **Vertical MVP** vs **Horizontal Layers** mode and seeds the milestone accordingly
|
||||
- **`/gsd-progress`** emits a "User-flow next up" panel for MVP-mode phases, surfacing user-visible task names ahead of internal scaffolding
|
||||
- **`/gsd-stats`** adds an "MVP phases: N" summary line when the roadmap contains any
|
||||
- **`/gsd-graphify`** visually differentiates MVP-mode phase nodes from horizontal-layer phases in the rendered graph
|
||||
|
||||
---
|
||||
|
||||
## Bonus fixes also in this canary
|
||||
|
||||
- **`/gsd-progress` no longer cites stale CLAUDE.md project blocks** as the source for the "Next Up" section ([#2912](https://github.com/GSD-redux/get-shit-done-redux/issues/2912)) — explicit context-authority directive added to the report step.
|
||||
|
||||
(Other recent main-stream fixes — agent-skills CLI JSON wrap, audit-open ReferenceError, execute-phase branching, Hermes runtime — target the `next` stream and will arrive in the canary when they land in `dev`.)
|
||||
|
||||
---
|
||||
|
||||
## Install / upgrade
|
||||
|
||||
```bash
|
||||
# Try the canary
|
||||
npx @opengsd/get-shit-done-redux@canary
|
||||
|
||||
# Or pin exact
|
||||
npm install -g @opengsd/get-shit-done-redux@1.50.0-canary.1
|
||||
```
|
||||
|
||||
The installer's defensive purge will rewrite stale config blocks left by older GSD versions on first run. No manual cleanup needed.
|
||||
|
||||
## Reporting issues
|
||||
|
||||
If something breaks on canary, file against [the issue tracker](https://github.com/GSD-redux/get-shit-done-redux/issues) with the `bug` template and mention `1.50.0-canary.1` so it gets routed back into the dev stream rather than the stable stream.
|
||||
|
||||
## What ships next in this train
|
||||
|
||||
Pending dev-stream merges that should land before promotion to `next`:
|
||||
- Resolve canary-bake items in the MVP+TDD gate (variable wiring + `--force-mvp-gate` parser)
|
||||
- Sync recent main-stream fixes (`#2918`, `#2919`, `#2921`, `#2917`, `#2920`) into dev
|
||||
- Ride a few canary cycles for real-user MVP/TDD/UAT feedback
|
||||
|
||||
When the dev stream stabilizes, the train promotes to `main` as `v1.50.0-rc.1` (the `next` channel).
|
||||
Reference in New Issue
Block a user