@@ -6,7 +6,7 @@ This directory holds **per-PR CHANGELOG fragments**. Every PR with user-facing c
|
||||
|
||||
Two PRs that both edit the `### Fixed` block of `CHANGELOG.md` always conflict on merge — git can't pick a serialization order without human input. Two PRs that each add a fresh `.changeset/<unique-name>.md` never conflict because they don't share lines.
|
||||
|
||||
See [#2975](https://github.com/gsd-build/get-shit-done/issues/2975) for the full rationale.
|
||||
See [#2975](https://github.com/open-gsd/get-shit-done-redux/issues/2975) for the full rationale.
|
||||
|
||||
## Adding a fragment
|
||||
|
||||
|
||||
@@ -2,4 +2,4 @@
|
||||
type: Fixed
|
||||
pr: 3216
|
||||
---
|
||||
**Atomic writes in `scripts/build-hooks.js` to fix flaky release CI** — nine test files invoke `build-hooks.js` from their `before()` hooks, and `scripts/run-tests.cjs` runs test files with `--test-concurrency=4`, so multiple builders raced to rewrite the same files in `hooks/dist/`. `fs.copyFileSync(src, dest)` truncates `dest` then writes it; a parallel `bin/install.js` subprocess (spawned by another install test) could `fs.readFileSync` between the truncate and the write and observe an empty file. install.js then wrote that empty content into the install target, so installed `.sh` hooks lacked their `# gsd-hook-version:` header. This surfaced as the release-blocking failure in `tests/bug-2136-sh-hook-version.test.cjs` part 4 even though the same SHA passed on every other Node-22/Node-24 install-smoke matrix run. `build-hooks.js` now stages each output to a sibling `hooks/.dist-staging/` directory (same filesystem as `hooks/dist/`) and uses `fs.renameSync` to swap into place — POSIX `rename(2)` is atomic, so concurrent readers always observe a complete file. The existing `tests/bug-2136-sh-hook-version.test.cjs` part 4 already locks the post-fix invariant. (Failing run: https://github.com/gsd-build/get-shit-done/actions/runs/25472202941/job/74738276687)
|
||||
**Atomic writes in `scripts/build-hooks.js` to fix flaky release CI** — nine test files invoke `build-hooks.js` from their `before()` hooks, and `scripts/run-tests.cjs` runs test files with `--test-concurrency=4`, so multiple builders raced to rewrite the same files in `hooks/dist/`. `fs.copyFileSync(src, dest)` truncates `dest` then writes it; a parallel `bin/install.js` subprocess (spawned by another install test) could `fs.readFileSync` between the truncate and the write and observe an empty file. install.js then wrote that empty content into the install target, so installed `.sh` hooks lacked their `# gsd-hook-version:` header. This surfaced as the release-blocking failure in `tests/bug-2136-sh-hook-version.test.cjs` part 4 even though the same SHA passed on every other Node-22/Node-24 install-smoke matrix run. `build-hooks.js` now stages each output to a sibling `hooks/.dist-staging/` directory (same filesystem as `hooks/dist/`) and uses `fs.renameSync` to swap into place — POSIX `rename(2)` is atomic, so concurrent readers always observe a complete file. The existing `tests/bug-2136-sh-hook-version.test.cjs` part 4 already locks the post-fix invariant. (Failing run: https://github.com/open-gsd/get-shit-done-redux/actions/runs/25472202941/job/74738276687)
|
||||
|
||||
@@ -2,4 +2,4 @@
|
||||
type: Changed
|
||||
pr: 209
|
||||
---
|
||||
**README continuity and governance messaging refreshed** — top-level docs now standardize on open-gsd ownership, migration away from legacy gsd-build packages, and linked security/transition announcements.
|
||||
**README continuity and governance messaging refreshed** — top-level docs now standardize on open-gsd ownership, migration away from legacy packages, and linked security/transition announcements.
|
||||
|
||||
788
CHANGELOG.md
788
CHANGELOG.md
File diff suppressed because it is too large
Load Diff
@@ -8,7 +8,7 @@
|
||||
> - npm (main): `@opengsd/get-shit-done-redux`
|
||||
> - npm (sdk): `@opengsd/gsd-sdk`
|
||||
>
|
||||
> The legacy upstream (`gsd-build/*`) is outside open-gsd control. Based on public transition announcements and repository ownership reality, we strongly recommend removing `gsd-build` organization packages and migrating to `@opengsd/*`.
|
||||
> The legacy upstream is outside open-gsd control. Based on public transition announcements and repository ownership reality, we strongly recommend removing legacy packages and migrating to `@opengsd/*`.
|
||||
>
|
||||
> Security status:
|
||||
>
|
||||
@@ -81,7 +81,7 @@ GSD exists to help solo builders and small teams ship reliably with AI: clear sp
|
||||
|
||||
In May 2026, maintainers published a continuity announcement and migrated active development to `open-gsd/get-shit-done-redux` after trust and ownership concerns around the former upstream, including a meme-coin rug-pull incident publicly associated with that ecosystem.
|
||||
|
||||
The former creator and the `gsd-build` lineage are no longer part of this program. This repository is the maintained continuation under open-gsd governance.
|
||||
The former creator and legacy lineage are no longer part of this program. This repository is the maintained continuation under open-gsd governance.
|
||||
|
||||
The current team continues release operations, triage, and security hardening in public. Audit status and follow-up security work are documented in Discussion #119 and linked issues.
|
||||
|
||||
|
||||
@@ -4,7 +4,9 @@
|
||||
|
||||
**Please do not report security vulnerabilities through public GitHub issues.**
|
||||
|
||||
Instead, please report them via email to: **security@gsd.build** (or DM @glittercowboy on Discord/Twitter if email bounces)
|
||||
Instead, please report them via a **private GitHub security advisory**:
|
||||
|
||||
**https://github.com/open-gsd/get-shit-done-redux/security/advisories/new**
|
||||
|
||||
Include:
|
||||
- Description of the vulnerability
|
||||
|
||||
@@ -17,7 +17,7 @@ The top-level README still mixes legacy transition language, personal attributio
|
||||
|
||||
1. Remove legacy personal maintainer attribution from README narrative sections.
|
||||
2. Present open-gsd continuity messaging in concise, team-owned language.
|
||||
3. Provide explicit migration guidance from legacy `gsd-build/*` packages to `@opengsd/*`.
|
||||
3. Provide explicit migration guidance from legacy packages to `@opengsd/*`.
|
||||
4. Reference public announcement and security-audit discussions directly.
|
||||
5. Keep changes docs-only and non-behavioral.
|
||||
|
||||
@@ -43,7 +43,7 @@ The top-level README still mixes legacy transition language, personal attributio
|
||||
|
||||
1. README contains a continuity notice naming `open-gsd/get-shit-done-redux` as canonical.
|
||||
2. README removes personal legacy attribution in origin-story prose.
|
||||
3. README strongly recommends migration away from `gsd-build/*` artifacts.
|
||||
3. README strongly recommends migration away from legacy artifacts.
|
||||
4. README links to Discussions #109 and #119.
|
||||
5. README states current audit posture with "no known active exploit" language.
|
||||
|
||||
|
||||
@@ -47,7 +47,7 @@ integrity as a prerequisite.
|
||||
**Implementation in pilot:** PR
|
||||
[#135](https://github.com/open-gsd/get-shit-done-redux/pull/135)
|
||||
(linked to issue
|
||||
[#114](https://github.com/gsd-build/get-shit-done/issues/114)).
|
||||
[#114](https://github.com/open-gsd/get-shit-done-redux/issues/114)).
|
||||
|
||||
**Verify locally:**
|
||||
|
||||
@@ -81,7 +81,7 @@ mechanism.
|
||||
**Implementation in pilot:** PR
|
||||
[#134](https://github.com/open-gsd/get-shit-done-redux/pull/134)
|
||||
(linked to issue
|
||||
[#115](https://github.com/gsd-build/get-shit-done/issues/115)).
|
||||
[#115](https://github.com/open-gsd/get-shit-done-redux/issues/115)).
|
||||
Exclusion annotation files: `.secretscanignore` (top-level) and
|
||||
`.base64scanignore` (top-level, for base64-encoded values).
|
||||
|
||||
@@ -116,7 +116,7 @@ risks in automated pipelines.
|
||||
**Implementation in pilot:** PR
|
||||
[#133](https://github.com/open-gsd/get-shit-done-redux/pull/133)
|
||||
(linked to issue
|
||||
[#113](https://github.com/gsd-build/get-shit-done/issues/113)).
|
||||
[#113](https://github.com/open-gsd/get-shit-done-redux/issues/113)).
|
||||
|
||||
**Verify locally:**
|
||||
|
||||
@@ -144,7 +144,7 @@ time prevents invisible payload injection in source and output files.
|
||||
**Implementation in pilot:** PR
|
||||
[#132](https://github.com/open-gsd/get-shit-done-redux/pull/132)
|
||||
(linked to issue
|
||||
[#116](https://github.com/gsd-build/get-shit-done/issues/116)).
|
||||
[#116](https://github.com/open-gsd/get-shit-done-redux/issues/116)).
|
||||
|
||||
**Verify locally:**
|
||||
|
||||
@@ -174,7 +174,7 @@ OpenSSF Scorecard's "Pinned-Dependencies" check measures this directly.
|
||||
([OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md))
|
||||
|
||||
**Implementation in pilot:** PR for issue
|
||||
[#117](https://github.com/gsd-build/get-shit-done/issues/117)
|
||||
[#117](https://github.com/open-gsd/get-shit-done-redux/issues/117)
|
||||
(see PR #136).
|
||||
|
||||
**Verify locally:**
|
||||
@@ -232,7 +232,7 @@ Post-Incident Activity.
|
||||
|
||||
| Phase | Action |
|
||||
|---|---|
|
||||
| Detection | Alert from secret scanner CI step, or external reporter via `security@gsd.build` |
|
||||
| Detection | Alert from secret scanner CI step, or external reporter via a private GitHub security advisory |
|
||||
| Containment | Immediately revoke the exposed credential in the issuing service (GitHub, npm, cloud, etc.) |
|
||||
| Containment | Force-push or rewrite history to remove the secret from Git history (if public) |
|
||||
| Containment | Rotate all credentials that shared the same scope as the exposed one |
|
||||
@@ -284,8 +284,7 @@ Report security vulnerabilities via **private security advisory** on GitHub:
|
||||
|
||||
Do not open public issues for security vulnerabilities.
|
||||
|
||||
Fallback: email `security@gsd.build` (or DM `@glittercowboy` on Discord/Twitter
|
||||
if email bounces).
|
||||
If private advisory filing is unavailable, contact the open-gsd maintainers and include a link to this policy.
|
||||
|
||||
**Source:** [GitHub Security Advisories](https://docs.github.com/en/code-security/security-advisories)
|
||||
|
||||
|
||||
@@ -75,7 +75,7 @@ describe('changeset serialize: multi-line bullet parsing (#3496)', () => {
|
||||
|
||||
test('a multi-line bullet with linked release header is parsed correctly', () => {
|
||||
const text = [
|
||||
'## [1.42.1](https://github.com/gsd-build/get-shit-done/compare/v1.41.0...v1.42.1) - 2026-05-15',
|
||||
'## [1.42.1](https://github.com/open-gsd/get-shit-done-redux/compare/v1.41.0...v1.42.1) - 2026-05-15',
|
||||
'',
|
||||
'### Fixed',
|
||||
'',
|
||||
|
||||
@@ -105,10 +105,9 @@ const INTERNAL_COMPONENT_SLUGS = new Set([
|
||||
// a real command token.
|
||||
'init-',
|
||||
|
||||
// gsd-build — GitHub organization name: "github.com/open-gsd/get-shit-done-redux".
|
||||
// Every occurrence of "/gsd-build" in docs is the path component of a GitHub URL
|
||||
// (e.g., "[#2792](https://github.com/open-gsd/get-shit-done-redux/issues/2792)").
|
||||
// The regex captures "/gsd-build" from the URL path. Not a slash command.
|
||||
// Compatibility guard for legacy doc links that may include
|
||||
// legacy org path segments in migrated historical URLs.
|
||||
// This is not a user-typable slash command.
|
||||
'build',
|
||||
|
||||
// ~/gsd-workspaces/ — filesystem directory path used by /gsd-workspace.
|
||||
|
||||
Reference in New Issue
Block a user