Merge branch 'next' into codex/tagline-punctuation-next
This commit is contained in:
5
.github/workflows/close-draft-prs.yml
vendored
5
.github/workflows/close-draft-prs.yml
vendored
@@ -14,7 +14,10 @@ permissions:
|
||||
jobs:
|
||||
close-if-draft:
|
||||
name: Reject draft PRs
|
||||
if: github.event.pull_request.draft == true
|
||||
# Maintainers may use draft PRs for internal coordination.
|
||||
if: >-
|
||||
github.event.pull_request.draft == true &&
|
||||
contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.pull_request.author_association) == false
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Comment and close draft PR
|
||||
|
||||
3
.github/workflows/pr-target-validator.yml
vendored
3
.github/workflows/pr-target-validator.yml
vendored
@@ -22,6 +22,9 @@ permissions:
|
||||
|
||||
jobs:
|
||||
validate-target:
|
||||
# Maintainers may open internal release/backport coordination PRs against main.
|
||||
if: >-
|
||||
contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.pull_request.author_association) == false
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 2
|
||||
env:
|
||||
|
||||
37
README.md
37
README.md
@@ -1,28 +1,3 @@
|
||||
> # Project Continuity Notice
|
||||
>
|
||||
> GSD Core is maintained by the **open-gsd** team at:
|
||||
> **`open-gsd/gsd-core`**
|
||||
>
|
||||
> Use only these package names:
|
||||
>
|
||||
> - npm (main): `@opengsd/gsd-core`
|
||||
> - npm (sdk): `@opengsd/gsd-sdk`
|
||||
>
|
||||
> The legacy upstream is outside open-gsd control. Based on public transition announcements and repository ownership reality, we strongly recommend removing legacy packages and migrating to `@opengsd/*`.
|
||||
>
|
||||
> Security status:
|
||||
>
|
||||
> - maintainers completed an internal security audit
|
||||
> - maintainers report an independent review pass
|
||||
> - no known active exploit was found in tracked source during those passes
|
||||
>
|
||||
> See:
|
||||
>
|
||||
> - continuity announcement: https://github.com/open-gsd/gsd-core/discussions/109
|
||||
> - audit transparency report: https://github.com/open-gsd/gsd-core/discussions/119
|
||||
>
|
||||
> ---
|
||||
|
||||
<div align="center">
|
||||
|
||||
# GSD Core
|
||||
@@ -77,18 +52,6 @@ npx @opengsd/gsd-core@latest
|
||||
|
||||
---
|
||||
|
||||
## Why We Continue Building GSD Core
|
||||
|
||||
GSD Core exists to help solo builders and small teams ship reliably with AI: clear specs, controlled context, and verification before release.
|
||||
|
||||
In May 2026, maintainers published a continuity announcement and migrated active development to `open-gsd/gsd-core` after trust and ownership concerns around the former upstream, including a meme-coin rug-pull incident publicly associated with that ecosystem.
|
||||
|
||||
The former creator and legacy lineage are no longer part of this program. This repository is the maintained continuation under open-gsd governance.
|
||||
|
||||
The current team continues release operations, triage, and security hardening in public. Audit status and follow-up security work are documented in Discussion #119 and linked issues.
|
||||
|
||||
---
|
||||
|
||||
## How It Works
|
||||
|
||||
The loop is six commands. Each one does exactly one thing.
|
||||
|
||||
37
tests/workflow-maintainer-skip.test.cjs
Normal file
37
tests/workflow-maintainer-skip.test.cjs
Normal file
@@ -0,0 +1,37 @@
|
||||
// allow-test-rule: source-text-is-the-product
|
||||
// These workflow files are deployed policy; the tests lock the maintainer
|
||||
// carve-out so future edits do not accidentally re-enable enforcement.
|
||||
'use strict';
|
||||
|
||||
const { describe, test } = require('node:test');
|
||||
const assert = require('node:assert/strict');
|
||||
const fs = require('node:fs');
|
||||
const path = require('node:path');
|
||||
|
||||
const MAINTAINER_SKIP_EXPR = 'contains(fromJSON(\'["OWNER","MEMBER","COLLABORATOR"]\'), github.event.pull_request.author_association) == false';
|
||||
|
||||
function readWorkflow(relativePath) {
|
||||
return fs.readFileSync(path.join(process.cwd(), relativePath), 'utf8');
|
||||
}
|
||||
|
||||
function assertMaintainerSkip(source) {
|
||||
assert.ok(
|
||||
source.includes(MAINTAINER_SKIP_EXPR),
|
||||
`Expected workflow to include maintainer skip expression: ${MAINTAINER_SKIP_EXPR}`
|
||||
);
|
||||
}
|
||||
|
||||
describe('PR policy workflow maintainer carve-outs', () => {
|
||||
test('draft PR auto-close does not run for maintainer-authored PRs', () => {
|
||||
const workflow = readWorkflow('.github/workflows/close-draft-prs.yml');
|
||||
|
||||
assert.match(workflow, /github\.event\.pull_request\.draft == true/);
|
||||
assertMaintainerSkip(workflow);
|
||||
});
|
||||
|
||||
test('PR target validator does not run for maintainer-authored PRs', () => {
|
||||
const workflow = readWorkflow('.github/workflows/pr-target-validator.yml');
|
||||
|
||||
assertMaintainerSkip(workflow);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user