diff --git a/.github/workflows/close-draft-prs.yml b/.github/workflows/close-draft-prs.yml index 690ae5fbf..f2d361e89 100644 --- a/.github/workflows/close-draft-prs.yml +++ b/.github/workflows/close-draft-prs.yml @@ -14,7 +14,10 @@ permissions: jobs: close-if-draft: name: Reject draft PRs - if: github.event.pull_request.draft == true + # Maintainers may use draft PRs for internal coordination. + if: >- + github.event.pull_request.draft == true && + contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.pull_request.author_association) == false runs-on: ubuntu-latest steps: - name: Comment and close draft PR diff --git a/.github/workflows/pr-target-validator.yml b/.github/workflows/pr-target-validator.yml index 18b59d6cf..ade2c8fea 100644 --- a/.github/workflows/pr-target-validator.yml +++ b/.github/workflows/pr-target-validator.yml @@ -22,6 +22,9 @@ permissions: jobs: validate-target: + # Maintainers may open internal release/backport coordination PRs against main. + if: >- + contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.pull_request.author_association) == false runs-on: ubuntu-latest timeout-minutes: 2 env: diff --git a/README.md b/README.md index 179dffffa..3d3944604 100644 --- a/README.md +++ b/README.md @@ -1,28 +1,3 @@ -> # Project Continuity Notice -> -> GSD Core is maintained by the **open-gsd** team at: -> **`open-gsd/gsd-core`** -> -> Use only these package names: -> -> - npm (main): `@opengsd/gsd-core` -> - npm (sdk): `@opengsd/gsd-sdk` -> -> The legacy upstream is outside open-gsd control. Based on public transition announcements and repository ownership reality, we strongly recommend removing legacy packages and migrating to `@opengsd/*`. -> -> Security status: -> -> - maintainers completed an internal security audit -> - maintainers report an independent review pass -> - no known active exploit was found in tracked source during those passes -> -> See: -> -> - continuity announcement: https://github.com/open-gsd/gsd-core/discussions/109 -> - audit transparency report: https://github.com/open-gsd/gsd-core/discussions/119 -> -> --- -
# GSD Core @@ -77,18 +52,6 @@ npx @opengsd/gsd-core@latest --- -## Why We Continue Building GSD Core - -GSD Core exists to help solo builders and small teams ship reliably with AI: clear specs, controlled context, and verification before release. - -In May 2026, maintainers published a continuity announcement and migrated active development to `open-gsd/gsd-core` after trust and ownership concerns around the former upstream, including a meme-coin rug-pull incident publicly associated with that ecosystem. - -The former creator and legacy lineage are no longer part of this program. This repository is the maintained continuation under open-gsd governance. - -The current team continues release operations, triage, and security hardening in public. Audit status and follow-up security work are documented in Discussion #119 and linked issues. - ---- - ## How It Works The loop is six commands. Each one does exactly one thing. diff --git a/tests/workflow-maintainer-skip.test.cjs b/tests/workflow-maintainer-skip.test.cjs new file mode 100644 index 000000000..64233d25c --- /dev/null +++ b/tests/workflow-maintainer-skip.test.cjs @@ -0,0 +1,37 @@ +// allow-test-rule: source-text-is-the-product +// These workflow files are deployed policy; the tests lock the maintainer +// carve-out so future edits do not accidentally re-enable enforcement. +'use strict'; + +const { describe, test } = require('node:test'); +const assert = require('node:assert/strict'); +const fs = require('node:fs'); +const path = require('node:path'); + +const MAINTAINER_SKIP_EXPR = 'contains(fromJSON(\'["OWNER","MEMBER","COLLABORATOR"]\'), github.event.pull_request.author_association) == false'; + +function readWorkflow(relativePath) { + return fs.readFileSync(path.join(process.cwd(), relativePath), 'utf8'); +} + +function assertMaintainerSkip(source) { + assert.ok( + source.includes(MAINTAINER_SKIP_EXPR), + `Expected workflow to include maintainer skip expression: ${MAINTAINER_SKIP_EXPR}` + ); +} + +describe('PR policy workflow maintainer carve-outs', () => { + test('draft PR auto-close does not run for maintainer-authored PRs', () => { + const workflow = readWorkflow('.github/workflows/close-draft-prs.yml'); + + assert.match(workflow, /github\.event\.pull_request\.draft == true/); + assertMaintainerSkip(workflow); + }); + + test('PR target validator does not run for maintainer-authored PRs', () => { + const workflow = readWorkflow('.github/workflows/pr-target-validator.yml'); + + assertMaintainerSkip(workflow); + }); +});