fix(#343): remove legacy security contacts and org references (#351)

This commit is contained in:
Tom Boucher
2026-05-26 17:03:49 -04:00
committed by GitHub
parent ec8aaf11ea
commit 660670ef57
10 changed files with 415 additions and 415 deletions

View File

@@ -6,7 +6,7 @@ This directory holds **per-PR CHANGELOG fragments**. Every PR with user-facing c
Two PRs that both edit the `### Fixed` block of `CHANGELOG.md` always conflict on merge — git can't pick a serialization order without human input. Two PRs that each add a fresh `.changeset/<unique-name>.md` never conflict because they don't share lines.
See [#2975](https://github.com/gsd-build/get-shit-done/issues/2975) for the full rationale.
See [#2975](https://github.com/open-gsd/get-shit-done-redux/issues/2975) for the full rationale.
## Adding a fragment

View File

@@ -2,4 +2,4 @@
type: Fixed
pr: 3216
---
**Atomic writes in `scripts/build-hooks.js` to fix flaky release CI** — nine test files invoke `build-hooks.js` from their `before()` hooks, and `scripts/run-tests.cjs` runs test files with `--test-concurrency=4`, so multiple builders raced to rewrite the same files in `hooks/dist/`. `fs.copyFileSync(src, dest)` truncates `dest` then writes it; a parallel `bin/install.js` subprocess (spawned by another install test) could `fs.readFileSync` between the truncate and the write and observe an empty file. install.js then wrote that empty content into the install target, so installed `.sh` hooks lacked their `# gsd-hook-version:` header. This surfaced as the release-blocking failure in `tests/bug-2136-sh-hook-version.test.cjs` part 4 even though the same SHA passed on every other Node-22/Node-24 install-smoke matrix run. `build-hooks.js` now stages each output to a sibling `hooks/.dist-staging/` directory (same filesystem as `hooks/dist/`) and uses `fs.renameSync` to swap into place — POSIX `rename(2)` is atomic, so concurrent readers always observe a complete file. The existing `tests/bug-2136-sh-hook-version.test.cjs` part 4 already locks the post-fix invariant. (Failing run: https://github.com/gsd-build/get-shit-done/actions/runs/25472202941/job/74738276687)
**Atomic writes in `scripts/build-hooks.js` to fix flaky release CI** — nine test files invoke `build-hooks.js` from their `before()` hooks, and `scripts/run-tests.cjs` runs test files with `--test-concurrency=4`, so multiple builders raced to rewrite the same files in `hooks/dist/`. `fs.copyFileSync(src, dest)` truncates `dest` then writes it; a parallel `bin/install.js` subprocess (spawned by another install test) could `fs.readFileSync` between the truncate and the write and observe an empty file. install.js then wrote that empty content into the install target, so installed `.sh` hooks lacked their `# gsd-hook-version:` header. This surfaced as the release-blocking failure in `tests/bug-2136-sh-hook-version.test.cjs` part 4 even though the same SHA passed on every other Node-22/Node-24 install-smoke matrix run. `build-hooks.js` now stages each output to a sibling `hooks/.dist-staging/` directory (same filesystem as `hooks/dist/`) and uses `fs.renameSync` to swap into place — POSIX `rename(2)` is atomic, so concurrent readers always observe a complete file. The existing `tests/bug-2136-sh-hook-version.test.cjs` part 4 already locks the post-fix invariant. (Failing run: https://github.com/open-gsd/get-shit-done-redux/actions/runs/25472202941/job/74738276687)

View File

@@ -2,4 +2,4 @@
type: Changed
pr: 209
---
**README continuity and governance messaging refreshed** — top-level docs now standardize on open-gsd ownership, migration away from legacy gsd-build packages, and linked security/transition announcements.
**README continuity and governance messaging refreshed** — top-level docs now standardize on open-gsd ownership, migration away from legacy packages, and linked security/transition announcements.

File diff suppressed because it is too large Load Diff

View File

@@ -8,7 +8,7 @@
> - npm (main): `@opengsd/get-shit-done-redux`
> - npm (sdk): `@opengsd/gsd-sdk`
>
> The legacy upstream (`gsd-build/*`) is outside open-gsd control. Based on public transition announcements and repository ownership reality, we strongly recommend removing `gsd-build` organization packages and migrating to `@opengsd/*`.
> The legacy upstream is outside open-gsd control. Based on public transition announcements and repository ownership reality, we strongly recommend removing legacy packages and migrating to `@opengsd/*`.
>
> Security status:
>
@@ -81,7 +81,7 @@ GSD exists to help solo builders and small teams ship reliably with AI: clear sp
In May 2026, maintainers published a continuity announcement and migrated active development to `open-gsd/get-shit-done-redux` after trust and ownership concerns around the former upstream, including a meme-coin rug-pull incident publicly associated with that ecosystem.
The former creator and the `gsd-build` lineage are no longer part of this program. This repository is the maintained continuation under open-gsd governance.
The former creator and legacy lineage are no longer part of this program. This repository is the maintained continuation under open-gsd governance.
The current team continues release operations, triage, and security hardening in public. Audit status and follow-up security work are documented in Discussion #119 and linked issues.

View File

@@ -4,7 +4,9 @@
**Please do not report security vulnerabilities through public GitHub issues.**
Instead, please report them via email to: **security@gsd.build** (or DM @glittercowboy on Discord/Twitter if email bounces)
Instead, please report them via a **private GitHub security advisory**:
**https://github.com/open-gsd/get-shit-done-redux/security/advisories/new**
Include:
- Description of the vulnerability

View File

@@ -17,7 +17,7 @@ The top-level README still mixes legacy transition language, personal attributio
1. Remove legacy personal maintainer attribution from README narrative sections.
2. Present open-gsd continuity messaging in concise, team-owned language.
3. Provide explicit migration guidance from legacy `gsd-build/*` packages to `@opengsd/*`.
3. Provide explicit migration guidance from legacy packages to `@opengsd/*`.
4. Reference public announcement and security-audit discussions directly.
5. Keep changes docs-only and non-behavioral.
@@ -43,7 +43,7 @@ The top-level README still mixes legacy transition language, personal attributio
1. README contains a continuity notice naming `open-gsd/get-shit-done-redux` as canonical.
2. README removes personal legacy attribution in origin-story prose.
3. README strongly recommends migration away from `gsd-build/*` artifacts.
3. README strongly recommends migration away from legacy artifacts.
4. README links to Discussions #109 and #119.
5. README states current audit posture with "no known active exploit" language.

View File

@@ -47,7 +47,7 @@ integrity as a prerequisite.
**Implementation in pilot:** PR
[#135](https://github.com/open-gsd/get-shit-done-redux/pull/135)
(linked to issue
[#114](https://github.com/gsd-build/get-shit-done/issues/114)).
[#114](https://github.com/open-gsd/get-shit-done-redux/issues/114)).
**Verify locally:**
@@ -81,7 +81,7 @@ mechanism.
**Implementation in pilot:** PR
[#134](https://github.com/open-gsd/get-shit-done-redux/pull/134)
(linked to issue
[#115](https://github.com/gsd-build/get-shit-done/issues/115)).
[#115](https://github.com/open-gsd/get-shit-done-redux/issues/115)).
Exclusion annotation files: `.secretscanignore` (top-level) and
`.base64scanignore` (top-level, for base64-encoded values).
@@ -116,7 +116,7 @@ risks in automated pipelines.
**Implementation in pilot:** PR
[#133](https://github.com/open-gsd/get-shit-done-redux/pull/133)
(linked to issue
[#113](https://github.com/gsd-build/get-shit-done/issues/113)).
[#113](https://github.com/open-gsd/get-shit-done-redux/issues/113)).
**Verify locally:**
@@ -144,7 +144,7 @@ time prevents invisible payload injection in source and output files.
**Implementation in pilot:** PR
[#132](https://github.com/open-gsd/get-shit-done-redux/pull/132)
(linked to issue
[#116](https://github.com/gsd-build/get-shit-done/issues/116)).
[#116](https://github.com/open-gsd/get-shit-done-redux/issues/116)).
**Verify locally:**
@@ -174,7 +174,7 @@ OpenSSF Scorecard's "Pinned-Dependencies" check measures this directly.
([OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md))
**Implementation in pilot:** PR for issue
[#117](https://github.com/gsd-build/get-shit-done/issues/117)
[#117](https://github.com/open-gsd/get-shit-done-redux/issues/117)
(see PR #136).
**Verify locally:**
@@ -232,7 +232,7 @@ Post-Incident Activity.
| Phase | Action |
|---|---|
| Detection | Alert from secret scanner CI step, or external reporter via `security@gsd.build` |
| Detection | Alert from secret scanner CI step, or external reporter via a private GitHub security advisory |
| Containment | Immediately revoke the exposed credential in the issuing service (GitHub, npm, cloud, etc.) |
| Containment | Force-push or rewrite history to remove the secret from Git history (if public) |
| Containment | Rotate all credentials that shared the same scope as the exposed one |
@@ -284,8 +284,7 @@ Report security vulnerabilities via **private security advisory** on GitHub:
Do not open public issues for security vulnerabilities.
Fallback: email `security@gsd.build` (or DM `@glittercowboy` on Discord/Twitter
if email bounces).
If private advisory filing is unavailable, contact the open-gsd maintainers and include a link to this policy.
**Source:** [GitHub Security Advisories](https://docs.github.com/en/code-security/security-advisories)

View File

@@ -75,7 +75,7 @@ describe('changeset serialize: multi-line bullet parsing (#3496)', () => {
test('a multi-line bullet with linked release header is parsed correctly', () => {
const text = [
'## [1.42.1](https://github.com/gsd-build/get-shit-done/compare/v1.41.0...v1.42.1) - 2026-05-15',
'## [1.42.1](https://github.com/open-gsd/get-shit-done-redux/compare/v1.41.0...v1.42.1) - 2026-05-15',
'',
'### Fixed',
'',

View File

@@ -105,10 +105,9 @@ const INTERNAL_COMPONENT_SLUGS = new Set([
// a real command token.
'init-',
// gsd-build — GitHub organization name: "github.com/open-gsd/get-shit-done-redux".
// Every occurrence of "/gsd-build" in docs is the path component of a GitHub URL
// (e.g., "[#2792](https://github.com/open-gsd/get-shit-done-redux/issues/2792)").
// The regex captures "/gsd-build" from the URL path. Not a slash command.
// Compatibility guard for legacy doc links that may include
// legacy org path segments in migrated historical URLs.
// This is not a user-typable slash command.
'build',
// ~/gsd-workspaces/ — filesystem directory path used by /gsd-workspace.