diff --git a/CHANGELOG.md b/CHANGELOG.md index d2e88055b..2beff3d29 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,8 +6,48 @@ Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). ## [Unreleased] +## [1.31.0] - 2026-04-01 + +### Added +- **Claude Code 2.1.88+ skills migration** — Commands now install as `skills/gsd-*/SKILL.md` instead of deprecated `commands/gsd/`. Auto-cleans legacy directory on install +- **`/gsd:docs-update` command** — Verified documentation generation with doc-writer and doc-verifier agents +- **`--chain` flag for discuss-phase** — Interactive discuss that auto-chains into plan+execute +- **`--only N` flag for autonomous** — Execute a single phase instead of all remaining +- **Schema drift detection** — Prevents false-positive verification when ORM schema files change without migration +- **`/gsd:secure-phase` command** — Security enforcement layer with threat-model-anchored verification +- **Claim provenance tagging** — Researcher marks claims with source evidence +- **Scope reduction detection** — Planner blocked from silently dropping requirements +- **`workflow.use_worktrees` config** — Toggle to disable worktree isolation +- **`project_code` config** — Prefix phase directories with project code +- **Project skills discovery** — CLAUDE.md generation now includes project-specific skills section +- **CodeRabbit integration** — Added to cross-AI review workflow +- **GSD SDK enhancements** — Auto `--init` flag, headless prompts, prompt sanitizer + ### Changed -- **`/gsd:quick --full` flag** — Now enables all phases (discussion + research + plan-checking + verification). New `--validate` flag covers previous `--full` behavior (plan-checking + verification only) (#1498) +- **`/gsd:quick --full` flag** — Now enables all phases (discussion + research + plan-checking + verification). New `--validate` flag covers previous `--full` behavior (plan-checking + verification only) + +### Fixed +- **Gemini CLI agent loading** — Removed `permissionMode` that broke agent frontmatter parsing +- **Phase count display** — Clarified misleading N/T banner in autonomous mode +- **Workstream `set` command** — Now requires name arg, added `--clear` flag +- **Infinite self-discuss loop** — Fixed in auto/headless mode with `max_discuss_passes` config +- **Orphan worktree cleanup** — Post-execution cleanup added +- **JSONC settings.json** — Comments no longer cause data loss +- **Incremental checkpoint saves** — Discuss answers preserved on interrupt +- **Stats accuracy** — Verification required for Complete status, added Executed state +- **Three-way merge for reapply-patches** — Never-skip invariant for backed-up files +- **SDK verify gates advance** — Skip advance when verification finds gaps +- **Manager delegates to Skill pipeline** — Instead of raw Task prompts +- **ROADMAP.md Plans column** — cmdPhaseComplete now updates correctly +- **Decimal phase numbers** — Commit regex captures decimal phases +- **Codex path replacement** — Added .claude path replacement +- **Verifier loads all ROADMAP SCs** — Regardless of PLAN must_haves +- **Verifier human_needed status** — Enforced when human verification items exist +- **Hooks shared cache dir** — Correct stale hooks path +- **Plan file naming** — Convention enforced in gsd-planner agent +- **Copilot path replacement** — Fixed ~/.claude to ~/.github +- **Windsurf trailing slash** — Removed from .windsurf/rules path +- **Slug sanitization** — Added --raw flag, capped length to 60 chars ## [1.30.0] - 2026-03-26 diff --git a/README.ja-JP.md b/README.ja-JP.md index 60ca891c9..db5329396 100644 --- a/README.ja-JP.md +++ b/README.ja-JP.md @@ -75,6 +75,8 @@ GSDはそれを解決します。Claude Codeを信頼性の高いものにする やりたいことを説明するだけで正しく構築してほしい人 — 50人のエンジニア組織を運営しているふりをせずに。 +ビルトインの品質ゲートが本当の問題を検出します:スキーマドリフト検出はマイグレーション漏れのORM変更をフラグし、セキュリティ強制は検証を脅威モデルに紐付け、スコープ削減検出はプランナーが要件を暗黙的に落とすのを防止します。 + --- ## はじめに @@ -371,7 +373,7 @@ claude --dangerously-skip-permissions **discuss → plan → execute → verify → ship** のループをマイルストーン完了まで繰り返します。 -ディスカッション中のインプットを速くしたい場合は、`/gsd:discuss-phase --batch` で1つずつではなく小さなグループにまとめた質問に一括で回答できます。 +ディスカッション中のインプットを速くしたい場合は、`/gsd:discuss-phase --batch` で1つずつではなく小さなグループにまとめた質問に一括で回答できます。`--chain` を使うと、ディスカッションからプラン+実行まで途中で止まらずに自動チェインできます。 各フェーズであなたのインプット(discuss)、適切なリサーチ(plan)、クリーンな実行(execute)、人間による検証(verify)が行われます。コンテキストは常にフレッシュ。品質は常に高い。 @@ -399,9 +401,11 @@ claude --dangerously-skip-permissions **`--research` フラグ:** 計画前にフォーカスされたリサーチャーを起動。実装アプローチ、ライブラリの選択肢、落とし穴を調査します。タスクへのアプローチが不明な場合に使用してください。 -**`--full` フラグ:** プランチェック(最大2回のイテレーション)と実行後の検証を有効にします。 +**`--full` フラグ:** 全フェーズを有効化 — ディスカッション + リサーチ + プランチェック + 検証。クイックタスク形式のフルGSDパイプライン。 -フラグは組み合わせ可能:`--discuss --research --full` でディスカッション + リサーチ + プランチェック + 検証が行われます。 +**`--validate` フラグ:** プランチェック + 実行後の検証のみを有効化(以前の `--full` の動作)。 + +フラグは組み合わせ可能:`--discuss --research --validate` でディスカッション + リサーチ + プランチェック + 検証が行われます。 ``` /gsd:quick @@ -507,7 +511,7 @@ lmn012o feat(08-02): create registration endpoint | コマンド | 説明 | |---------|--------------| | `/gsd:new-project [--auto]` | フル初期化:質問 → リサーチ → 要件定義 → ロードマップ | -| `/gsd:discuss-phase [N] [--auto] [--analyze]` | 計画前に実装の決定事項をキャプチャ(`--analyze` でトレードオフ分析を追加) | +| `/gsd:discuss-phase [N] [--auto] [--analyze] [--chain]` | 計画前に実装の決定事項をキャプチャ(`--analyze` でトレードオフ分析を追加、`--chain` でプラン+実行へ自動チェイン) | | `/gsd:plan-phase [N] [--auto] [--reviews]` | フェーズのリサーチ + プラン + 検証(`--reviews` でコードベースレビューの発見事項を読み込み) | | `/gsd:execute-phase ` | 全プランを並列ウェーブで実行し、完了時に検証 | | `/gsd:verify-work [N]` | 手動ユーザー受入テスト ¹ | @@ -613,7 +617,7 @@ lmn012o feat(08-02): create registration endpoint | `/gsd:debug [desc]` | 永続状態を持つ体系的デバッグ | | `/gsd:do ` | フリーフォームテキストを適切なGSDコマンドに自動ルーティング | | `/gsd:note ` | ゼロフリクションのアイデアキャプチャ — ノートの追加、一覧、todoへの昇格 | -| `/gsd:quick [--full] [--discuss] [--research]` | GSDの保証付きでアドホックタスクを実行(`--full` でプランチェックと検証を追加、`--discuss` で事前にコンテキストを収集、`--research` で計画前にアプローチを調査) | +| `/gsd:quick [--full] [--discuss] [--research]` | GSDの保証付きでアドホックタスクを実行(`--full` で全フェーズを有効化、`--discuss` で事前にコンテキストを収集、`--research` で計画前にアプローチを調査) | | `/gsd:health [--repair]` | `.planning/` ディレクトリの整合性を検証、`--repair` で自動修復 | | `/gsd:stats` | プロジェクト統計を表示 — フェーズ、プラン、要件、gitメトリクス | | `/gsd:profile-user [--questionnaire] [--refresh]` | セッション分析から開発者行動プロファイルを生成し、パーソナライズされた応答を提供 | diff --git a/README.ko-KR.md b/README.ko-KR.md index f6cd53a06..23419e7ec 100644 --- a/README.ko-KR.md +++ b/README.ko-KR.md @@ -73,6 +73,8 @@ GSD가 그걸 고칩니다. Claude Code를 신뢰할 수 있게 만드는 컨텍 원하는 걸 설명하면 제대로 만들어지길 바라는 사람들 — 50인 규모 엔지니어링 조직인 척하지 않아도 되는. +내장 품질 게이트가 실제 문제를 잡아냅니다: 스키마 드리프트 감지는 마이그레이션 누락된 ORM 변경을 플래그하고, 보안 강제는 검증을 위협 모델에 고정시키고, 스코프 축소 감지는 플래너가 요구사항을 몰래 빠뜨리는 걸 방지합니다. + --- ## 시작하기 @@ -369,7 +371,7 @@ claude --dangerously-skip-permissions 마일스톤이 완료될 때까지 **논의 → 기획 → 실행 → 검증 → 출시** 반복. -논의 중에 더 빠르게 진행하고 싶다면 `/gsd:discuss-phase --batch`를 사용해 하나씩이 아닌 소그룹으로 한 번에 답할 수 있습니다. +논의 중에 더 빠르게 진행하고 싶다면 `/gsd:discuss-phase --batch`를 사용해 하나씩이 아닌 소그룹으로 한 번에 답할 수 있습니다. `--chain`을 사용하면 논의에서 기획+실행까지 중간에 멈추지 않고 자동 체이닝됩니다. 각 단계는 사용자 입력(논의), 적절한 리서치(기획), 깔끔한 실행(실행), 사람의 검증(검증)을 거칩니다. 컨텍스트는 새롭게 유지됩니다. 품질도 높게 유지됩니다. @@ -397,9 +399,11 @@ claude --dangerously-skip-permissions **`--research` 플래그:** 기획 전 집중 리서처를 생성합니다. 구현 접근법, 라이브러리 옵션, 주의사항을 조사합니다. 접근 방식이 불확실할 때 사용하세요. -**`--full` 플래그:** 계획 확인 (최대 2회 반복)과 실행 후 검증을 활성화합니다. +**`--full` 플래그:** 모든 단계를 활성화 — 논의 + 리서치 + 계획 확인 + 검증. 빠른 작업 형태의 전체 GSD 파이프라인. -플래그는 조합 가능합니다: `--discuss --research --full`은 논의 + 리서치 + 계획 확인 + 검증을 제공합니다. +**`--validate` 플래그:** 계획 확인 + 실행 후 검증만 활성화 (이전 `--full`의 동작). + +플래그는 조합 가능합니다: `--discuss --research --validate`은 논의 + 리서치 + 계획 확인 + 검증을 제공합니다. ``` /gsd:quick @@ -502,7 +506,7 @@ lmn012o feat(08-02): create registration endpoint | 명령어 | 역할 | |---------|------------| | `/gsd:new-project [--auto]` | 전체 초기화: 질문 → 리서치 → 요구사항 → 로드맵 | -| `/gsd:discuss-phase [N] [--auto] [--analyze]` | 기획 전 구현 결정 캡처 (`--analyze`는 트레이드오프 분석 추가) | +| `/gsd:discuss-phase [N] [--auto] [--analyze] [--chain]` | 기획 전 구현 결정 캡처 (`--analyze`는 트레이드오프 분석 추가, `--chain`은 기획+실행으로 자동 체이닝) | | `/gsd:plan-phase [N] [--auto] [--reviews]` | 단계에 대한 리서치 + 기획 + 검증 (`--reviews`는 코드베이스 리뷰 결과 로드) | | `/gsd:execute-phase ` | 병렬 웨이브로 모든 계획 실행, 완료 시 검증 | | `/gsd:verify-work [N]` | 수동 사용자 인수 테스트 ¹ | @@ -602,7 +606,7 @@ lmn012o feat(08-02): create registration endpoint | `/gsd:debug [desc]` | 지속적 상태를 이용한 체계적 디버깅 | | `/gsd:do ` | 자유 형식 텍스트를 적절한 GSD 명령어로 자동 라우팅 | | `/gsd:note ` | 마찰 없는 아이디어 캡처 — 추가, 목록, 또는 할 일로 승격 | -| `/gsd:quick [--full] [--discuss] [--research]` | GSD 보장과 함께 임시 작업 실행 (`--full`은 계획 확인 및 검증 추가, `--discuss`는 먼저 컨텍스트 수집, `--research`는 기획 전 접근법 조사) | +| `/gsd:quick [--full] [--discuss] [--research]` | GSD 보장과 함께 임시 작업 실행 (`--full`은 전체 단계 활성화, `--discuss`는 먼저 컨텍스트 수집, `--research`는 기획 전 접근법 조사) | | `/gsd:health [--repair]` | `.planning/` 디렉터리 무결성 검증, `--repair`로 자동 복구 | | `/gsd:stats` | 프로젝트 통계 표시 — 단계, 계획, 요구사항, git 지표 | | `/gsd:profile-user [--questionnaire] [--refresh]` | 개인화된 응답을 위해 세션 분석에서 개발자 행동 프로필 생성 | diff --git a/README.md b/README.md index 4f83a7ebf..ea29635e9 100644 --- a/README.md +++ b/README.md @@ -73,6 +73,8 @@ GSD fixes that. It's the context engineering layer that makes Claude Code reliab People who want to describe what they want and have it built correctly — without pretending they're running a 50-person engineering org. +Built-in quality gates catch real problems: schema drift detection flags ORM changes missing migrations, security enforcement anchors verification to threat models, and scope reduction detection prevents the planner from silently dropping your requirements. + --- ## Getting Started @@ -93,7 +95,7 @@ Verify with: - Antigravity: `/gsd:help` > [!NOTE] -> Codex installation uses skills (`skills/gsd-*/SKILL.md`) rather than custom prompts. +> Claude Code 2.1.88+ and Codex install as skills (`skills/gsd-*/SKILL.md`). Older Claude Code versions use `commands/gsd/`. The installer handles this automatically. ### Staying Updated @@ -374,7 +376,7 @@ Or let GSD figure out the next step automatically: Loop **discuss → plan → execute → verify → ship** until milestone complete. -If you want faster intake during discussion, use `/gsd:discuss-phase --batch` to answer a small grouped set of questions at once instead of one-by-one. +If you want faster intake during discussion, use `/gsd:discuss-phase --batch` to answer a small grouped set of questions at once instead of one-by-one. Use `--chain` to auto-chain discuss into plan+execute without stopping between steps. Each phase gets your input (discuss), proper research (plan), clean execution (execute), and human verification (verify). Context stays fresh. Quality stays high. @@ -402,9 +404,11 @@ Quick mode gives you GSD guarantees (atomic commits, state tracking) with a fast **`--research` flag:** Spawns a focused researcher before planning. Investigates implementation approaches, library options, and pitfalls. Use when you're unsure how to approach a task. -**`--full` flag:** Enables plan-checking (max 2 iterations) and post-execution verification. +**`--full` flag:** Enables all phases — discussion + research + plan-checking + verification. The full GSD pipeline in quick-task form. -Flags are composable: `--discuss --research --full` gives discussion + research + plan-checking + verification. +**`--validate` flag:** Enables plan-checking + post-execution verification only (the previous `--full` behavior). + +Flags are composable: `--discuss --research --validate` gives discussion + research + plan-checking + verification. ``` /gsd:quick @@ -507,7 +511,7 @@ You're never locked in. The system adapts. | Command | What it does | |---------|--------------| | `/gsd:new-project [--auto]` | Full initialization: questions → research → requirements → roadmap | -| `/gsd:discuss-phase [N] [--auto] [--analyze]` | Capture implementation decisions before planning (`--analyze` adds trade-off analysis) | +| `/gsd:discuss-phase [N] [--auto] [--analyze] [--chain]` | Capture implementation decisions before planning (`--analyze` adds trade-off analysis, `--chain` auto-chains into plan+execute) | | `/gsd:plan-phase [N] [--auto] [--reviews]` | Research + plan + verify for a phase (`--reviews` loads codebase review findings) | | `/gsd:execute-phase ` | Execute all plans in parallel waves, verify when complete | | `/gsd:verify-work [N]` | Manual user acceptance testing ¹ | @@ -590,8 +594,10 @@ You're never locked in. The system adapts. | Command | What it does | |---------|--------------| | `/gsd:review` | Cross-AI peer review of current phase or branch | +| `/gsd:secure-phase [N]` | Security enforcement with threat-model-anchored verification | | `/gsd:pr-branch` | Create clean PR branch filtering `.planning/` commits | | `/gsd:audit-uat` | Audit verification debt — find phases missing UAT | +| `/gsd:docs-update` | Verified documentation generation with doc-writer and doc-verifier agents | ### Backlog & Threads @@ -613,7 +619,7 @@ You're never locked in. The system adapts. | `/gsd:debug [desc]` | Systematic debugging with persistent state | | `/gsd:do ` | Route freeform text to the right GSD command automatically | | `/gsd:note ` | Zero-friction idea capture — append, list, or promote notes to todos | -| `/gsd:quick [--full] [--discuss] [--research]` | Execute ad-hoc task with GSD guarantees (`--full` adds plan-checking and verification, `--discuss` gathers context first, `--research` investigates approaches before planning) | +| `/gsd:quick [--full] [--validate] [--discuss] [--research]` | Execute ad-hoc task with GSD guarantees (`--full` enables all phases, `--validate` adds plan-checking and verification, `--discuss` gathers context first, `--research` investigates approaches before planning) | | `/gsd:health [--repair]` | Validate `.planning/` directory integrity, auto-repair with `--repair` | | `/gsd:stats` | Display project statistics — phases, plans, requirements, git metrics | | `/gsd:profile-user [--questionnaire] [--refresh]` | Generate developer behavioral profile from session analysis for personalized responses | @@ -632,6 +638,7 @@ GSD stores project settings in `.planning/config.json`. Configure during `/gsd:n |---------|---------|---------|------------------| | `mode` | `yolo`, `interactive` | `interactive` | Auto-approve vs confirm at each step | | `granularity` | `coarse`, `standard`, `fine` | `standard` | Phase granularity — how finely scope is sliced (phases × plans) | +| `project_code` | string | `""` | Prefix phase directories with a project code | ### Model Profiles @@ -667,6 +674,7 @@ These spawn additional agents during planning/execution. They improve quality bu | `workflow.discuss_mode` | `'discuss'` | Discussion mode: `discuss` (interview), `assumptions` (codebase-first) | | `workflow.skip_discuss` | `false` | Skip discuss-phase in autonomous mode | | `workflow.text_mode` | `false` | Text-only mode for remote sessions (no TUI menus) | +| `workflow.use_worktrees` | `true` | Toggle worktree isolation for execution | Use `/gsd:settings` to toggle these, or override per-invocation: - `/gsd:plan-phase --skip-research` @@ -758,7 +766,7 @@ This prevents Claude from reading these files entirely, regardless of what comma **Commands not found after install?** - Restart your runtime to reload commands/skills -- Verify files exist in `~/.claude/commands/gsd/` (global) or `./.claude/commands/gsd/` (local) +- Verify files exist in `~/.claude/skills/gsd-*/SKILL.md` (Claude Code 2.1.88+) or `~/.claude/commands/gsd/` (legacy) - For Codex, verify skills exist in `~/.codex/skills/gsd-*/SKILL.md` (global) or `./.codex/skills/gsd-*/SKILL.md` (local) **Commands not working as expected?** diff --git a/README.pt-BR.md b/README.pt-BR.md index f1d5b14f0..bd2603b8a 100644 --- a/README.pt-BR.md +++ b/README.pt-BR.md @@ -71,6 +71,8 @@ O GSD corrige isso. É a camada de engenharia de contexto que torna o Claude Cod Para quem quer descrever o que precisa e receber isso construído do jeito certo — sem fingir que está rodando uma engenharia de 50 pessoas. +Quality gates embutidos capturam problemas reais: detecção de schema drift sinaliza mudanças ORM sem migrations, segurança ancora verificação a modelos de ameaça, e detecção de redução de escopo impede o planner de descartar requisitos silenciosamente. + --- ## Primeiros passos @@ -290,7 +292,7 @@ Cada tarefa gera commit próprio, facilitando `git bisect`, rollback e rastreabi | Comando | O que faz | |---------|-----------| | `/gsd:new-project [--auto]` | Inicializa projeto completo | -| `/gsd:discuss-phase [N] [--auto] [--analyze]` | Captura decisões antes do plano | +| `/gsd:discuss-phase [N] [--auto] [--analyze] [--chain]` | Captura decisões antes do plano (`--chain` encadeia automaticamente em plan+execute) | | `/gsd:plan-phase [N] [--auto] [--reviews]` | Pesquisa + plano + validação | | `/gsd:execute-phase ` | Executa planos em ondas paralelas | | `/gsd:verify-work [N]` | UAT manual | @@ -308,7 +310,7 @@ Cada tarefa gera commit próprio, facilitando `git bisect`, rollback e rastreabi | `/gsd:pr-branch` | Cria branch limpa para PR | | `/gsd:settings` | Configura perfis e agentes | | `/gsd:set-profile ` | Troca perfil (quality/balanced/budget/inherit) | -| `/gsd:quick [--full] [--discuss] [--research]` | Execução rápida com garantias do GSD | +| `/gsd:quick [--full] [--discuss] [--research]` | Execução rápida com garantias do GSD (`--full` ativa todas as etapas, `--validate` ativa apenas verificação) | | `/gsd:health [--repair]` | Verifica e repara `.planning/` | > Para a lista completa de comandos e opções, use `/gsd:help`. diff --git a/docs/CONFIGURATION.md b/docs/CONFIGURATION.md index 5c4491d74..517822c47 100644 --- a/docs/CONFIGURATION.md +++ b/docs/CONFIGURATION.md @@ -33,7 +33,8 @@ GSD stores project settings in `.planning/config.json`. Created during `/gsd:new "research_before_questions": false, "discuss_mode": "discuss", "skip_discuss": false, - "text_mode": false + "text_mode": false, + "use_worktrees": true }, "hooks": { "context_warnings": true, @@ -67,6 +68,10 @@ GSD stores project settings in `.planning/config.json`. Created during `/gsd:new "always_confirm_destructive": true, "always_confirm_external_services": true }, + "project_code": null, + "security_enforcement": true, + "security_asvs_level": 1, + "security_block_on": "high", "agent_skills": {} } ``` @@ -80,6 +85,7 @@ GSD stores project settings in `.planning/config.json`. Created during `/gsd:new | `mode` | enum | `interactive`, `yolo` | `interactive` | `yolo` auto-approves decisions; `interactive` confirms at each step | | `granularity` | enum | `coarse`, `standard`, `fine` | `standard` | Controls phase count: `coarse` (3-5), `standard` (5-8), `fine` (8-12) | | `model_profile` | enum | `quality`, `balanced`, `budget`, `inherit` | `balanced` | Model tier for each agent (see [Model Profiles](#model-profiles)) | +| `project_code` | string | any short string | (none) | Prefix for phase directory names (e.g., `"ABC"` produces `ABC-01-setup/`). Added in v1.31 | > **Note:** `granularity` was renamed from `depth` in v1.22.3. Existing configs are auto-migrated. @@ -104,6 +110,7 @@ All workflow toggles follow the **absent = enabled** pattern. If a key is missin | `workflow.discuss_mode` | string | `'discuss'` | Controls how `/gsd:discuss-phase` gathers context. `'discuss'` (default) asks questions one-by-one. `'assumptions'` reads the codebase first, generates structured assumptions with confidence levels, and only asks you to correct what's wrong. Added in v1.28 | | `workflow.skip_discuss` | boolean | `false` | When `true`, `/gsd:autonomous` bypasses the discuss-phase entirely, writing minimal CONTEXT.md from the ROADMAP phase goal. Useful for projects where developer preferences are fully captured in PROJECT.md/REQUIREMENTS.md. Added in v1.28 | | `workflow.text_mode` | boolean | `false` | Replaces AskUserQuestion TUI menus with plain-text numbered lists. Required for Claude Code remote sessions (`/rc` mode) where TUI menus don't render. Can also be set per-session with `--text` flag on discuss-phase. Added in v1.28 | +| `workflow.use_worktrees` | boolean | `true` | When `false`, disables git worktree isolation for parallel execution. Users who prefer sequential execution or whose environment does not support worktrees can disable this. Added in v1.31 | ### Recommended Presets @@ -299,6 +306,18 @@ Control confirmation prompts during workflows. --- +## Security Settings + +Settings for the security enforcement feature (v1.31). All follow the **absent = enabled** pattern. + +| Setting | Type | Default | Description | +|---------|------|---------|-------------| +| `security_enforcement` | boolean | `true` | Enable threat-model-anchored security verification via `/gsd:secure-phase`. When `false`, security checks are skipped entirely | +| `security_asvs_level` | number (1-3) | `1` | OWASP ASVS verification level. Level 1 = opportunistic, Level 2 = standard, Level 3 = comprehensive | +| `security_block_on` | string | `"high"` | Minimum severity that blocks phase advancement. Options: `"high"`, `"medium"`, `"low"` | + +--- + ## Hook Settings | Setting | Type | Default | Description | @@ -397,6 +416,7 @@ The intent is the same as the Claude profile tiers -- use a stronger model for p | `CLAUDE_CONFIG_DIR` | Override default config directory (`~/.claude/`) | | `GEMINI_API_KEY` | Detected by context monitor to switch hook event name | | `WSL_DISTRO_NAME` | Detected by installer for WSL path handling | +| `GSD_SKIP_SCHEMA_CHECK` | Skip schema drift detection during execute-phase (v1.31) | --- diff --git a/docs/FEATURES.md b/docs/FEATURES.md index 14b08a884..debfe1a9f 100644 --- a/docs/FEATURES.md +++ b/docs/FEATURES.md @@ -70,6 +70,22 @@ - [Assumptions Discussion Mode](#53-assumptions-discussion-mode) - [UI Phase Auto-Detection](#54-ui-phase-auto-detection) - [Multi-Runtime Installer Selection](#55-multi-runtime-installer-selection) +- [v1.29 Features](#v129-features) + - [Windsurf Runtime Support](#56-windsurf-runtime-support) + - [Internationalized Documentation](#57-internationalized-documentation) +- [v1.30 Features](#v130-features) + - [GSD SDK](#58-gsd-sdk) +- [v1.31 Features](#v131-features) + - [Schema Drift Detection](#59-schema-drift-detection) + - [Security Enforcement](#60-security-enforcement) + - [Documentation Generation](#61-documentation-generation) + - [Discuss Chain Mode](#62-discuss-chain-mode) + - [Single-Phase Autonomous](#63-single-phase-autonomous) + - [Scope Reduction Detection](#64-scope-reduction-detection) + - [Claim Provenance Tagging](#65-claim-provenance-tagging) + - [Worktree Toggle](#66-worktree-toggle) + - [Project Code Prefixing](#67-project-code-prefixing) + - [Claude Code Skills Migration](#68-claude-code-skills-migration) --- @@ -1288,3 +1304,264 @@ Test suite that scans all agent, workflow, and command files for embedded inject 1. **Detect** — Identify available AI CLI runtimes on the system 2. **Prompt** — Present multi-select interface for runtime selection 3. **Install** — Configure GSD for all selected runtimes in a single session + +--- + +## v1.29 Features + +### 56. Windsurf Runtime Support + +**Part of:** `npx get-shit-done-cc` + +**Purpose:** Add Windsurf as a supported AI CLI runtime for GSD installation and execution. + +**Requirements:** +- REQ-WINDSURF-01: Installer MUST detect Windsurf runtime and offer it as a target +- REQ-WINDSURF-02: GSD commands MUST function correctly within Windsurf sessions + +**Process:** +1. **Detect** — Identify Windsurf runtime availability on the system +2. **Install** — Configure GSD skills and hooks for the Windsurf environment + +--- + +### 57. Internationalized Documentation + +**Part of:** `docs/` + +**Purpose:** Provide GSD documentation in Portuguese, Korean, and Japanese. + +**Requirements:** +- REQ-I18N-01: Documentation MUST be available in Portuguese (pt), Korean (ko), and Japanese (ja) +- REQ-I18N-02: Translations MUST stay synchronized with English source documents + +**Process:** +1. **Translate** — Convert core documentation into target languages +2. **Publish** — Make translated documentation accessible alongside English originals + +--- + +## v1.30 Features + +### 58. GSD SDK + +**Command:** Programmatic API (headless) + +**Purpose:** Headless TypeScript SDK for running GSD workflows programmatically without a CLI session. + +**Requirements:** +- REQ-SDK-01: SDK MUST expose GSD workflow operations as TypeScript functions +- REQ-SDK-02: SDK MUST support headless execution without interactive prompts +- REQ-SDK-03: SDK MUST produce the same artifacts as CLI-driven workflows + +**Process:** +1. **Import** — Import GSD SDK into a TypeScript/JavaScript project +2. **Configure** — Set project path and workflow options programmatically +3. **Execute** — Run GSD phases (discuss, plan, execute) via API calls + +--- + +## v1.31 Features + +### 59. Schema Drift Detection + +**Command:** Automatic during `/gsd:execute-phase` + +**Purpose:** Detect when ORM schema files are modified without corresponding migration or push commands, preventing false-positive verification. + +**Requirements:** +- REQ-SCHEMA-01: System MUST detect modifications to ORM schema files (Prisma, Drizzle, Payload, Sanity, Mongoose) +- REQ-SCHEMA-02: System MUST verify corresponding migration/push commands exist when schema changes are detected +- REQ-SCHEMA-03: System MUST implement two-layer defense: plan-time injection and execute-time gate +- REQ-SCHEMA-04: System MUST support `GSD_SKIP_SCHEMA_CHECK` env var to override detection +- REQ-SCHEMA-05: System MUST prevent false-positive verification when schema is modified without migration + +**Process:** +1. **Detect** — Monitor ORM schema file modifications during plan execution +2. **Verify** — Check that corresponding migration/push commands are present in the plan +3. **Gate** — Block execution if schema drift is detected without migration (execute-time gate) +4. **Inject** — Add migration reminders during plan generation (plan-time injection) + +**Config:** `GSD_SKIP_SCHEMA_CHECK` environment variable to bypass detection. + +--- + +### 60. Security Enforcement + +**Command:** `/gsd:secure-phase ` + +**Purpose:** Threat-model-anchored security verification for phase implementations. + +**Requirements:** +- REQ-SEC-01: System MUST perform threat-model-anchored verification (not blind scanning) +- REQ-SEC-02: System MUST support configurable OWASP ASVS verification levels (1-3) +- REQ-SEC-03: System MUST block phase advancement based on configurable severity threshold +- REQ-SEC-04: System MUST spawn `gsd-security-auditor` agent for analysis + +**Produces:** +| Artifact | Description | +|----------|-------------| +| Security audit report | Threat-model-anchored findings with severity classification | + +**Process:** +1. **Model** — Build threat model from phase implementation context +2. **Audit** — Spawn `gsd-security-auditor` to verify against threat model +3. **Gate** — Block phase advancement if findings meet or exceed `security_block_on` severity + +**Config:** +| Setting | Type | Default | Description | +|---------|------|---------|-------------| +| `security_enforcement` | boolean | `true` | Enable threat-model security verification | +| `security_asvs_level` | number (1-3) | `1` | OWASP ASVS verification level | +| `security_block_on` | string | `"high"` | Minimum severity to block phase advancement | + +--- + +### 61. Documentation Generation + +**Command:** `/gsd:docs-update` + +**Purpose:** Generate and verify project documentation with accuracy checks. + +**Requirements:** +- REQ-DOCS-01: System MUST spawn `gsd-doc-writer` agent to generate documentation +- REQ-DOCS-02: System MUST spawn `gsd-doc-verifier` agent to check accuracy +- REQ-DOCS-03: System MUST verify generated documentation against actual implementation + +**Produces:** +| Artifact | Description | +|----------|-------------| +| Updated project documentation | Generated and verified documentation files | + +**Process:** +1. **Generate** — Spawn `gsd-doc-writer` to create or update documentation from implementation +2. **Verify** — Spawn `gsd-doc-verifier` to check documentation accuracy against codebase +3. **Output** — Produce verified documentation with accuracy annotations + +--- + +### 62. Discuss Chain Mode + +**Flag:** `/gsd:discuss-phase --chain` + +**Purpose:** Auto-chain discuss, plan, and execute phases in one flow to reduce manual command sequencing. + +**Requirements:** +- REQ-CHAIN-01: System MUST auto-chain discuss → plan → execute when `--chain` flag is provided +- REQ-CHAIN-02: System MUST respect all gate settings between chained phases +- REQ-CHAIN-03: System MUST halt the chain if any phase fails + +**Process:** +1. **Discuss** — Run discuss-phase to gather context +2. **Plan** — Automatically invoke plan-phase with gathered context +3. **Execute** — Automatically invoke execute-phase with generated plan + +--- + +### 63. Single-Phase Autonomous + +**Flag:** `/gsd:autonomous --only N` + +**Purpose:** Execute just one phase autonomously instead of all remaining phases. + +**Requirements:** +- REQ-ONLY-01: System MUST execute only the specified phase number when `--only N` is provided +- REQ-ONLY-02: System MUST follow the same discuss → plan → execute flow as full autonomous mode +- REQ-ONLY-03: System MUST stop after the specified phase completes + +**Process:** +1. **Select** — Identify the target phase from `--only N` argument +2. **Execute** — Run full autonomous flow (discuss → plan → execute) for that single phase +3. **Stop** — Halt after the phase completes instead of advancing to the next + +--- + +### 64. Scope Reduction Detection + +**Part of:** `/gsd:plan-phase` + +**Purpose:** Prevent silent requirement dropping during plan generation with three-layer defense. + +**Requirements:** +- REQ-SCOPE-01: System MUST prohibit planners from reducing scope without explicit justification +- REQ-SCOPE-02: System MUST have plan-checker verify requirement dimension coverage +- REQ-SCOPE-03: System MUST have orchestrator recover dropped requirements and re-inject them +- REQ-SCOPE-04: System MUST implement three-layer defense: planner prohibition, checker dimension, orchestrator recovery + +**Process:** +1. **Prohibit** — Planner instructions explicitly forbid scope reduction +2. **Check** — Plan-checker verifies all phase requirements are covered in the plan +3. **Recover** — Orchestrator detects dropped requirements and re-injects them into the planning loop + +--- + +### 65. Claim Provenance Tagging + +**Part of:** `/gsd:research-phase` + +**Purpose:** Ensure research claims are tagged with source evidence and assumptions are logged separately. + +**Requirements:** +- REQ-PROVENANCE-01: Researcher MUST mark claims with source evidence references +- REQ-PROVENANCE-02: Assumptions MUST be logged separately from sourced claims +- REQ-PROVENANCE-03: System MUST distinguish between evidenced facts and inferred assumptions + +**Process:** +1. **Research** — Researcher gathers information from codebase and domain sources +2. **Tag** — Each claim is annotated with its source (file path, documentation, API response) +3. **Separate** — Assumptions without direct evidence are logged in a distinct section + +--- + +### 66. Worktree Toggle + +**Config:** `workflow.use_worktrees: false` + +**Purpose:** Disable git worktree isolation for users who prefer sequential execution. + +**Requirements:** +- REQ-WORKTREE-01: System MUST respect `workflow.use_worktrees` setting when deciding isolation strategy +- REQ-WORKTREE-02: System MUST default to `true` (worktrees enabled) for backward compatibility +- REQ-WORKTREE-03: System MUST fall back to sequential execution when worktrees are disabled + +**Config:** +| Setting | Type | Default | Description | +|---------|------|---------|-------------| +| `workflow.use_worktrees` | boolean | `true` | When `false`, disables git worktree isolation | + +--- + +### 67. Project Code Prefixing + +**Config:** `project_code: "ABC"` + +**Purpose:** Prefix phase directory names with a project code for multi-project disambiguation. + +**Requirements:** +- REQ-PREFIX-01: System MUST prefix phase directories with project code when configured (e.g., `ABC-01-setup/`) +- REQ-PREFIX-02: System MUST use standard naming when `project_code` is not set +- REQ-PREFIX-03: System MUST apply prefix consistently across all phase operations + +**Config:** +| Setting | Type | Default | Description | +|---------|------|---------|-------------| +| `project_code` | string | (none) | Prefix for phase directory names | + +--- + +### 68. Claude Code Skills Migration + +**Part of:** `npx get-shit-done-cc` + +**Purpose:** Migrate GSD commands to Claude Code 2.1.88+ skills format with backward compatibility. + +**Requirements:** +- REQ-SKILLS-01: Installer MUST write `skills/gsd-*/SKILL.md` for Claude Code 2.1.88+ +- REQ-SKILLS-02: Installer MUST auto-clean legacy `commands/gsd/` directory +- REQ-SKILLS-03: Installer MUST maintain backward compatibility with older Claude Code versions via Gemini path + +**Process:** +1. **Detect** — Check Claude Code version to determine skills support +2. **Migrate** — Write `skills/gsd-*/SKILL.md` files for each GSD command +3. **Clean** — Remove legacy `commands/gsd/` directory if skills are installed +4. **Fallback** — Maintain Gemini path compatibility for older Claude Code versions diff --git a/docs/zh-CN/README.md b/docs/zh-CN/README.md index f7f377731..e8ca6f118 100644 --- a/docs/zh-CN/README.md +++ b/docs/zh-CN/README.md @@ -71,6 +71,8 @@ GSD 解决了这个问题。它是让 Claude Code 变得可靠的上下文工程 想要描述需求然后正确构建出来的人 —— 不用假装自己在运营一个 50 人的工程组织。 +内置的质量门禁能捕获真正的问题:模式漂移检测会标记缺少迁移的 ORM 变更,安全强制将验证锚定到威胁模型,范围缩减检测防止规划器默默丢弃你的需求。 + --- ## 快速开始 @@ -344,7 +346,7 @@ claude --dangerously-skip-permissions 循环 **讨论 → 规划 → 执行 → 验证** 直到里程碑完成。 -如果你想在讨论期间更快速地输入,使用 `/gsd:discuss-phase --batch` 一次回答一组小问题,而不是一个一个来。 +如果你想在讨论期间更快速地输入,使用 `/gsd:discuss-phase --batch` 一次回答一组小问题,而不是一个一个来。使用 `--chain` 可以自动链式执行从讨论到规划+执行,中间不停顿。 每个阶段都会获得你的输入(讨论)、适当的研究(规划)、干净的执行(执行)和人工验证(验证)。上下文保持新鲜。质量保持高水平。 @@ -365,10 +367,18 @@ claude --dangerously-skip-permissions 快速模式给你 GSD 保证(原子提交、状态跟踪)和更快的路径: - **相同代理** —— 规划者 + 执行者,相同质量 -- **跳过可选步骤** —— 无研究、无计划检查器、无验证器 +- **跳过可选步骤** —— 默认无研究、无计划检查器、无验证器 - **独立跟踪** —— 存放在 `.planning/quick/`,不是阶段 -用于:bug 修复、小功能、配置更改、一次性任务。 +**`--discuss` 标志:** 规划前的轻量讨论,发现灰色地带。 + +**`--research` 标志:** 规划前启动聚焦研究员。调查实现方法、库选项和陷阱。当你不确定如何处理任务时使用。 + +**`--full` 标志:** 启用所有阶段 —— 讨论 + 研究 + 计划检查 + 验证。快速任务形式的完整 GSD 管道。 + +**`--validate` 标志:** 仅启用计划检查 + 执行后验证(之前 `--full` 的行为)。 + +标志可组合:`--discuss --research --validate` 提供讨论 + 研究 + 计划检查 + 验证。 ``` /gsd:quick @@ -469,7 +479,7 @@ lmn012o feat(08-02): 创建注册端点 | 命令 | 作用 | |---------|--------------| | `/gsd:new-project [--auto]` | 完整初始化:提问 → 研究 → 需求 → 路线图 | -| `/gsd:discuss-phase [N] [--auto]` | 在规划前捕获实现决策 | +| `/gsd:discuss-phase [N] [--auto] [--chain]` | 在规划前捕获实现决策(`--chain` 自动链式执行规划+执行) | | `/gsd:plan-phase [N] [--auto]` | 阶段的研究 + 规划 + 验证 | | `/gsd:execute-phase ` | 在并行波次中执行所有计划,完成后验证 | | `/gsd:verify-work [N]` | 手动用户验收测试 ¹ | @@ -518,7 +528,7 @@ lmn012o feat(08-02): 创建注册端点 | `/gsd:add-todo [desc]` | 捕获想法留待后用 | | `/gsd:check-todos` | 列出待处理事项 | | `/gsd:debug [desc]` | 带持久状态的系统化调试 | -| `/gsd:quick [--full] [--discuss]` | 用 GSD 保证执行临时任务(`--full` 添加计划检查和验证,`--discuss` 先收集上下文) | +| `/gsd:quick [--full] [--discuss] [--research]` | 用 GSD 保证执行临时任务(`--full` 启用全部阶段,`--discuss` 先收集上下文,`--research` 规划前调查方法) | | `/gsd:health [--repair]` | 验证 `.planning/` 目录完整性,用 `--repair` 自动修复 | ¹ 由 Reddit 用户 OracleGreyBeard 贡献