Part 1 of 2 of the n/no-process-exit cleanup (umbrella #738): convert every
process.exit() call in standalone scripts/** CLIs to the rule-compliant pattern.
- New shared helper scripts/lib/cli-exit.cjs: ExitError(code,message) + runMain()
which translates a thrown ExitError / returned number into process.exitCode
(never process.exit()), flushing output and still firing process.on('exit').
- main()-based entrypoints: throw new ExitError(code) for errors, return <code>
for verdicts; invoked via runMain(main). Child exit codes preserved via return.
- top-level-only scripts: imperative body extracted into main() so mid-flow
aborts (throw ExitError) actually halt; pure consts/helpers stay at module scope.
- diff-touches-shipped-paths.cjs: stdin event handling restructured to an async
read so the whole flow runs under runMain; uncaughtException/unhandledRejection
nets replaced by an in-band catch that preserves EXIT_ERROR=2.
Exit codes verified unchanged for every converted script (success/error/help and
the 0/1/2 semantic codes in diff-touches). Rule stays warn here; flipped to error
in part 2 (#738) once gsd-core/bin/** is also clean.
Refs #739
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#706): skip rescueSummaryArtifacts when SUMMARY is already committed
rescueSummaryArtifacts now probes `git cat-file -e HEAD:<path>` before
copying a SUMMARY.md into the main checkout. When the file is already
committed on the worktree branch, copying it as an untracked file causes
`git merge --no-ff` to abort with "untracked working tree files would be
overwritten by merge" — a permanent merge_failed cleanup-wave failure.
Fail-closed on timeout: if cat-file is unreliable we skip rescue (the
merge will surface the collision as it did before, which is recoverable).
Adds 4 new test cases in worktree-safety.test.cjs covering:
- committed SUMMARY skipped, merge succeeds (#706 regression case)
- committed SUMMARY skipped even when timeout (fail-closed)
- uncommitted SUMMARY still rescued (existing contract preserved)
- rescue failure on ENOSPC still propagates (unchanged)
Closes#706
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* chore: add changeset for #706
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(#706): treat cat-file exit 128 as uncertain — skip rescue (fail-closed)
The previous guard skipped rescue only when `exitCode === 0` (committed) or
`timedOut`. Any other non-zero exit, including `128` (fatal git error: corrupt
object store, unborn HEAD, missing repo), fell through and PROCEEDED with
rescue — potentially re-creating the #706 untracked-file merge collision.
Fix: rescue ONLY when `exitCode === 1` (cat-file definitively reports the
object absent). All other outcomes — 0 (committed), 128 (fatal), null/SIGTERM
(timeout), or any other code — are treated as "uncertain → skip rescue".
Also corrects the JSDoc bullet that still referenced `git ls-files
--error-unmatch` (the old mechanism); updated to `git cat-file -e HEAD:<relPath>`.
Regression test added: asserts rescue is SKIPPED when cat-file returns exit 128,
leaving the merge to surface the issue safely rather than silently copying an
already-committed file.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* chore: link changeset to PR #709
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(#704): exclude } and ) from Codex path-rewrite lookbehind
Shell variable expressions like \${VAR}/gsd-core/ and command-substitution
paths like \$(cmd)/gsd-local-patches were being rewritten to \$gsd-core and
\$gsd-local-patches respectively because the negative lookbehind in
convertSlashCommandsToCodexSkillMentions did not include } or ).
Add both characters to the lookbehind set:
(?<![a-zA-Z0-9./})])
Also adds regression test:
tests/bug-704-codex-launcher-path-corruption.test.cjs
Closes#704
* chore: add changeset for #704
* test: use RUNTIME_ROOT_PATH in assertion to eliminate dead-code lint warning
Replace the partial hard-coded fragment '}/gsd-core/bin/' with the
existing RUNTIME_ROOT_PATH const so the assertion both compiles clean
(no unused variable) and self-documents which canonical launcher path
must survive Codex conversion intact (#704).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* chore: link changeset to PR #710
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Replace raw setTimeout/Atomics.wait synchronization sleeps in 4 test files
with a shared async delay()/waitFor() poll-for-condition helper in
tests/helpers.cjs, then flip local/no-magic-sleep-in-tests and
no-restricted-syntax from warn to error so the debt can't regrow.
- tests/helpers.cjs: add delay(ms) + waitFor(predicate, opts), exported
- bug-1974: setTimeout backoff -> await delay()
- config.test: drop Atomics.wait sleep(); async retry via await delay()
- graphify: waitForBuildStatus/cleanupHookRepo async via await delay()
- locking-bugs: 3 Atomics.wait poll loops -> await waitFor()
- eslint.config.mjs: ratchet both rules warn -> error
Refs #733
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
The 5 no-control-regex warnings are all the same intentional ANSI-color-strip
pattern /\x1b\[[0-9;]*m/g across 5 test files. The \x1b (ESC) control char is
the required leading byte of an ANSI SGR sequence, so matching it is the whole
point of stripping color codes from captured CLI/console output. Add an inline
eslint-disable-next-line with justification at each site (not a refactor — the
control char is essential, not accidental), then flip no-control-regex from
warn to error so the debt can't regrow.
Refs #736
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Pay down pre-existing error→warn lint debt. Removes dead imports/vars, unused functions, redundant regex/string escapes, and stale eslint-disable directives; converts unused `catch (_e)` to optional catch binding (src/*.cts).
No behavior change. Lint 345→125 warnings (0 errors); deferred categories (n/no-process-exit, test-sleeps, control-regex) tracked in #732 for follow-up. Full test suite green (0 failures); code-review verified all removals unused and all escape fixes semantics-preserving.
Closes#732
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* feat(#159): auto-use existing RESEARCH.md in /gsd:plan-phase --research-phase
When RESEARCH.md already exists in research-only mode and neither --research
nor --view is passed, emit a one-line notice and exit cleanly instead of
prompting update/view/skip. This matches the promptless auto-use of standard
/gsd:plan-phase <N> (§5.1) and removes the §5.0/§5.1 inconsistency, making
AI-agent and CLI invocations non-interactive in the common case. The two
explicit-flag escape hatches (--research to refresh, --view to print) cover
any deviation.
Closes#159
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(#159): point changeset fragment at PR #718
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* docs(#159): tighten research-phase reference register (Diataxis)
Make the 'no modifier' research-phase entries descriptive rather than
imperative and drop the trailing 'pass --research/--view' clauses, which
duplicated the adjacent --research/--view documentation. Reference docs
describe; the recovery flags are documented in their own entries. The
emitted runtime notice in the workflow keeps naming the flags (in-band
recovery), unchanged.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* feat(#717): re-base workflow size budget on bytes + document quality rationale
Re-base tests/workflow-size-budget.test.cjs from line counts to byte
counts (matches Codex's 32,768-byte project_doc_max_bytes cap; deterministic,
no tokenizer). Tier ceilings: XL=90000, LARGE=54000, DEFAULT=38000, GRACE=3000;
discuss-phase target re-expressed as <30 KB. The #597 tighten-only ratchet and
per-file budget semantics are preserved unchanged — only the unit swaps.
byteCount() uses fs.statSync().size to match `wc -c` (includes trailing
newline), deliberately not lineCount()'s newline-stripping.
Document the context-rot / attention-budget QUALITY rationale (independent of
prompt caching) in the test JSDoc and docs/ARCHITECTURE.md, plus the
Goodhart caveat: the byte budget measures one file, so the real goal is
bounded *loaded* context — eager @-imports game the proxy; legitimate
extraction is lazy. Update CONTEXT.md RULESET.WORKFLOW_SIZE_BUDGET to bytes and
remove a stale duplicate ruleset entry that still said "1800 lines".
Defers the #3182 MVP-mode split (tracked separately): MVP is a cross-cutting
concern woven through plan-phase/execute-phase, not a discrete extractable mode.
Closes#717
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* docs(#717): add changeset fragment for byte-budget re-base
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* feat(#656): add Research Store module (content-addressed cache, TTL staleness)
Content-addressed research cache behind a clock seam: researchKey (sha256, deterministic), putResearch/getResearch ({hit,stale}, never throws), ttlForSource (curated HIGH 30d / MED 7d / web LOW 1d), two-tier resolveStorePath (curated -> ~/.gsd/research-cache, web/synthesis -> project .planning/research/.cache). 28 behavioral + property tests; boundary coverage at ttl-1/ttl/ttl+1.
Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(#656): add Research Provider module (waterfall + confidence + plan)
Single source of truth for the Balanced provider waterfall (docs Context7->Ref->Jina, web Exa+Tavily, fallback Perplexity/Brave, Firecrawl scrape-only). classifyConfidence stamps HIGH|MEDIUM|LOW by provider (never throws). providerAvailability maps config flags to usable providers. planResearch checks the Research Store (injected seam) and returns cache-hits + a per-question fetch plan, falling through the waterfall to the always-available websearch terminal. 22 behavioral + property tests.
Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(#656): add Package Legitimacy module (registry-API verdicts, slopcheck optional)
Replaces the pip-install-or-degrade slopcheck prose gate with code: classifyPackage (pure, never throws) computes OK|SUS|SLOP from tunable thresholds (minAgeDays 30, minWeeklyDownloads 1000, requireRepo). checkPackages queries injectable npm/PyPI/crates registry adapters (real https with 5s timeout, degraded-not-thrown on failure); slopcheck is one optional adapter that can only escalate severity, never degrade to [ASSUMED]. 34 behavioral + property tests; boundary coverage on age and downloads (limit-1/limit/limit+1).
Known follow-up: real npm adapter must add api.npmjs.org last-week downloads fetch (currently null -> unknown-downloads). Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(#656): detect Tavily/Ref/Perplexity/Jina provider keys; complete npm downloads adapter
config: add tavily_search/ref_search/perplexity/jina availability flags (env var or ~/.gsd/<x>_api_key), mirroring brave_search/exa_search/firecrawl, so the Research Provider waterfall can gate them. package-legitimacy: real npm adapter now fetches api.npmjs.org last-week downloads (bounded, degraded-not-thrown) so weeklyDownloads is populated. +12 config tests; 34 legitimacy tests unchanged.
Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(#656): expose Research seam via gsd-tools query (research-plan, research-store, package-legitimacy)
Routes the L2-hybrid surface so agents reach it as CLI: 'query research-store get/put' (cache, HOME-sandboxable), 'query research-plan --input' (cache-hits + fetch plan from planResearch), 'query package-legitimacy check --ecosystem' (async registry verdicts). Commands skip .planning root resolution and appear in top-level usage. 5 behavioral runGsdTools tests; command-contract unchanged (335).
Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* docs(#656): document Research module (CONTEXT predicates, ADR-0656, architecture, changeset)
Adds GSD-RESEARCH.* + DEFECT.RESEARCH-PROVIDER-PROSE-DRIFT predicates to CONTEXT.md, ADR-0656 recording the L2-hybrid seam decision, a docs/ARCHITECTURE.md Research Module subsection, and an Added changeset fragment (pr:0, backfill on PR). Notes the #657 deferrals (agent collapse + install.js MCP mapping).
Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(#656): sync inventory for research modules
Regenerate INVENTORY-MANIFEST.json and bump docs/INVENTORY.md CLI Modules count 82->85 with rows for research-store/research-provider/package-legitimacy (DEFECT.INVENTORY-DRIFT).
Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(#656): eslint-ignore generated research .cjs artifacts (ADR-457)
research-store/research-provider/package-legitimacy .cjs are tsc-generated from src/*.cts, so they belong in the ESLint ignore block (lint the .cts source, not the emitted .cjs). Fixes tests/551-eslint-bin-lib-coverage.
Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(#656): backfill changeset pr number to #664
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(#656): satisfy eslint lint-tests gate
Fix 20 eslint errors in the new research files: use helpers.cleanup() instead of raw fs.rmSync() in tests (local/no-raw-rmsync-in-tests, Windows-EBUSY retry budget); drop redundant '| string' union members and unnecessary type assertions; deterministic object normalization in researchKey (no-base-to-string). Logic unchanged; 6180 tests still green.
Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#656): harden package legitimacy per review (W1/W2/I3/I4)
W1: httpsGet now reads statusCode; npm/PyPI/crates map 404 -> exists:false -> SLOP (registry-existence is the #1 slopsquatting defense; previously only npm caught it). Transport made injectable (_setHttpGet) for hermetic 404 tests. W2: suspicious-postinstall is now terminal SLOP independent of the optional slopcheck adapter, and the regex drops the bare https?:// arm (over-fired on esbuild/sharp/node-gyp) for shell-exec/download-exec signatures only. I3: checkPackages now threads version to registry.lookup and adapters verify that specific version exists. I4: moreServerVerdict -> moreSevereVerdict. +11 regression tests (all RED-first); 45 total green.
Addresses review by @davesienkowski on #664. Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#656): research-store tier coherence + freshness + version TTL (W4/I1/I2/I4)
I1: tier now derives from source (curated -> user ~/.gsd, else -> project .planning), not kind, so put-tier and get-tier can't diverge; kind is a key component only. W4: getResearch searches both tiers and returns the freshest (non-stale preferred), never letting a stale curated entry shadow a fresh web one; blank version caps TTL at 1 day (no 30d on version-blind keys). I2: atomic platformWriteSync instead of raw fs.writeFileSync on the shared global path. I4: dropped the dead ttlForSource arm. CLI get now searches both tiers. +5 RED-first regression tests; 38 green.
Addresses review by @davesienkowski on #664. Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#656): expose classifyConfidence as a CLI route, killing dead code (W3)
Adds 'gsd-tools query classify-confidence --provider X [--verified]' so research agents get the confidence tier FROM CODE (provider waterfall + verification lever) instead of asserting it in prose. classifyConfidence previously had no runtime caller. HIGH means 'trusted provider'; --verified raises web results to MEDIUM (verification semantics documented in ADR-0656). +4 behavioral tests.
Addresses review by @davesienkowski on #664 (W3). Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#656): close Codex adversarial-review findings (path-traversal, version-age, malformed-cache)
HIGH: research key must be 64-hex sha256 (isValidResearchKey) + resolved-path containment check in put/get + CLI validation -> blocks '../../x' arbitrary-file-write. HIGH: package legitimacy now derives publishedAt from the REQUESTED version (npm time[version], PyPI releases[version] upload_time, crates versions[].created_at) so a new malicious version of an old package can't inherit old age and evade 'too-new'. MEDIUM: getResearch validates entry shape (finite fetched_at + positive ttl + required fields) -> malformed cache entry is a miss, not fresh-forever. +regression tests (RED-first); 111 green.
Codex adversarial review (required pre-PR gate). Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#656): close code-review correctness findings
(1) package-legitimacy CLI now rejects unknown --flags instead of silently consuming the following package as a flag value; only --ecosystem takes a value. (2) crates recent_downloads (90-day) normalized to a weekly figure before the minWeeklyDownloads threshold (was ~13x too lenient). (3) research-plan --input validates parsed JSON is an object with an Array questions before destructuring -> clean usage error instead of an uncaught TypeError on null/bad input. (4) research-store put rejects a flag value that is itself a --flag (no more storing '--source' as content). (5) planResearch skips questions whose text is not a non-empty string instead of emitting question:undefined. +13 RED-first regression tests; 143 green.
Code-review gate. Issue #656. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(#657): extract researcher documentation_lookup to shared @-reference
6 researcher agents carried a near-duplicate <documentation_lookup> block; consolidate into gsd-core/references/research-documentation-lookup.md (@-included). Unifies the ctx7 CLI fallback to the safer 'command -v ctx7' guard (drops silent 'npx --yes ctx7@latest' execution in 5 agents). Behavior-preserving dedup; inventory 63->64 references. Phase A of the agent collapse.
Issue #657. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(#657): extract researcher philosophy + verification-protocol to shared @-references
philosophy and the pitfalls+pre-submission-checklist common-core were near-duplicated in project/phase researchers; consolidate into gsd-core/references/research-{philosophy,verification-protocol}.md (@-included). phase-researcher keeps its 3 extra checklist items inline. Pre-submission domains checklist made agent-agnostic so project-researcher doesn't lose features/architecture coverage. Write-contract intentionally left inline (bug-214 tests assert it verbatim). Inventory 64->66 refs. Behavior-preserving. Phase A.
Issue #657. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(#657): wire gsd-phase-researcher to the Research seam (Phase B / S1)
The phase researcher now CALLS the code seam instead of carrying inline mechanics: provider waterfall -> 'gsd-tools query research-plan' (+ research-store put to cache digests); confidence-tier prose -> 'gsd-tools query classify-confidence'; slopcheck pip-install protocol -> 'gsd-tools query package-legitimacy check'. This makes the Research module a real runtime consumer (validates the seam end-to-end, addresses reviewer S1) and removes the duplicated waterfall/confidence/slopcheck prose. RESEARCH.md output contract, commit step, structured returns, and Phase-A @-includes unchanged. package-legitimacy-gate.test.cjs rewritten prose-grep -> behavioral (asserts the seam invocation).
Issue #657. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(#657): wire gsd-project-researcher to the seam + add tavily/ref/jina MCP tools (Phase C.1)
project-researcher now calls gsd-tools query research-plan / classify-confidence (+ research-store put) instead of the inline provider waterfall + confidence-tier prose (mirrors the phase-researcher rewire; no package-legitimacy — phase-only). Output contract (STACK/FEATURES/ARCHITECTURE/PITFALLS/SUMMARY.md + sections, no-commit, structured returns, Phase-A @-includes) unchanged. Adds mcp__tavily/ref/jina__* to the project/phase/ui researcher tools frontmatter (Balanced provider set) so install.js MCP mapping (C.2) has a consumer.
Issue #657. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(#657): cover tavily/ref/jina MCP install handling + frontmatter parity guard (Phase C.2)
Investigation: exa/firecrawl have no explicit per-runtime tool-mapping — every mcp__<server>__* except context7 rides the generic passthrough (Copilot lowercases; OpenCode/Cursor/Windsurf/Augment keep as-is; Gemini auto-discovers). tavily/ref/jina are handled identically, no install path broken. Added 12 copilot-install passthrough tests + a mcp-tool-inheritance parity guard (tavily co-declared with exa, jina with firecrawl, ref present across the 3 web researchers) so the MCP set can't drift. No io.github registry ids invented (none sourceable in-repo); documented as a follow-up. 488 tests green.
Issue #657. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(#657): profiles as source of truth for researcher agents + drift-guard (Phase C.3)
scripts/research-profiles.cjs declares each of the 7 researcher agents' identity + contract (name, description, color, tools, required @-includes, required gsd-tools seam calls, output-contract markers). scripts/gen-research-agents.cjs --check validates every committed agent against its profile; --write regenerates ONLY the frontmatter from profiles (body untouched) and is a verified no-op against the current agents (zero diff = fidelity). tests/research-agent-profiles.test.cjs is the DEFECT.GENERATIVE-FIX drift guard. Design note: profiles govern the generatable/contract surface rather than destructively regenerating the disparate operational prose bodies (those were deduped via @-includes in Phase A). scripts/ is not inventoried (no inventory change).
Issue #657. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#657): complete agent provider-dispatch + parity guard; align legitimacy field; validate profiles
Adversarial-review findings: (HIGH) the seam-wired agents' Step-C dispatch only mapped 6 providers, so a planResearch result of jina/ref/perplexity/brave (reachable via the waterfall fallbacks) had no handling -> agent stall; completed both agents' dispatch to all 9 PROVIDER_WATERFALL ids + a catch-all, and added a parity test asserting agent dispatch stays in sync with research-provider PROVIDER_WATERFALL (DEFECT.GENERATIVE-FIX). (MEDIUM) phase-researcher package-legitimacy JSON example used 'package' but the module returns 'name' -> aligned. (LOW) gen-research-agents checkAgent now returns a clear failure for a malformed profile instead of throwing. +parity/validation tests (RED-first).
Issue #657. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#656): make classifyConfidence verification-evidence-driven (W3)
Confidence conflated provider authority with claim verification — context7/ref
stamped HIGH purely by provider identity, and the only verification lever was a
self-set --verified flag. Split into two axes: provider authority (static) +
verification evidence (code-computed). HIGH now requires ground-truth
corroboration (legitimacyVerdict OK), independent of provider; authority alone
caps at MEDIUM; SLOP caps at LOW; the self-reported --verified is demoted to a
MEDIUM-only web lever. HIGH = corroborated-against-authoritative-source, not a
correctness guarantee. Adds --legitimacy-verdict to the classify-confidence CLI;
updates CONTEXT.md predicate + ADR-0656 (tier set unchanged, ADR-consistent).
Addresses davesienkowski's W3 review on #664.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#656): bind classify-confidence verdict to code, closing CLI self-grading
Adversarial review found the new --legitimacy-verdict flag was caller-supplied,
so an agent could self-assert OK->HIGH without any real legitimacy check —
reintroducing the exact self-grading hole W3 closes. Remove the free flag; the
CLI now computes the verdict via checkPackages only when --package/--ecosystem
is given (code-computed, not agent-asserted). Update the stale CLI test
(context7 alone -> MEDIUM) and extend the property test to vary legitimacyVerdict.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds --only N and --text to the COMMANDS.md reference table and the
run-phases-autonomously how-to guide, revised to fit the Diataxis
framework (reference: factual/parallel rows; how-to: goal-framed sections).
* feat(#690): wire CHANGELOG render into release finalize job
CHANGELOG promotion has always been a manual operator step, which is why
1.3.0/1.3.1 shipped unpromoted (#690). PR #694 added a `verify` latch that
fails a release lacking a dated heading, but nothing performed the promotion.
Wire `changeset render` into the finalize job, after build/test and before
the verify gate, committing the promoted CHANGELOG so it ships with the
release. Add a `--allow-empty` flag to cmdRender so a zero-fragment release
still emits a dated heading (with a '_No notable changes._' placeholder)
instead of writing nothing and tripping the verify gate.
Note: requires the changeset-archive cleanup (separate PR) to land first, so
the first render consumes only genuinely-unreleased fragments.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(#713): set changeset pr number to 715
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
CHANGELOG promotion was a manual operator step that was never run, so 463
fragments for work already shipped in <=1.3.1 accumulated in .changeset/.
Their notes were already hand-curated into the dated [1.2.0]/[1.3.0]/[1.3.1]
CHANGELOG sections (#690 backfill, PR #694). Rendering them now would
duplicate and mis-attribute shipped work.
Move them to .changeset/archived/ (read non-recursively by all changeset
tooling, so never rendered), keeping only the 3 genuinely-unreleased
fragments at the top level. Prep for wiring `render` into the release
finalize job (#690 follow-up).
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#669): /gsd-review --cursor actually invokes cursor-agent
The Cursor reviewer branch in review.md never ran the agent:
- detection probed `cursor` (the IDE launcher) instead of the headless
`cursor-agent` binary
- the invocation used the two-token `cursor agent` (the IDE treats `agent`
as a file-path argument, so the agent never starts)
- the prompt was piped via stdin, but `cursor-agent -p` reads the prompt
from a command-line argument, and `2>/dev/null` hid the empty result
Probe `cursor-agent`; invoke `cursor-agent -p --mode ask --trust
--output-format text` with the prompt passed as a file-path-reference
argument (avoids the OS arg-length limit on large prompts); capture stderr
so failures are diagnosable. Invert tests/cursor-reviewer.test.cjs to assert
the corrected contract, with negative guards against the two-token form and
the stdin pipe. The sibling `agy` reviewer already used the argument form.
Closes#669
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(#669): set changeset pr number to 686
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
`/gsd-review --agy` hung indefinitely on large prompts. agy's print mode runs the
full tool-enabled agent, and on a big, file-path-rich prompt its agentic Cascade
loops on the code_search/grep tool and never converges; the transcript fallback
only runs after agy exits, so it can't recover a run that never exits.
The agy CLI exposes no per-tool deny (that lives in the Antigravity SDK), but it
does expose --print-timeout — agy's native print-mode cap. Pass it explicitly so a
stalled run self-terminates through the tool's own mechanism; a non-zero exit
discards any partial output so the existing transcript fallback / "review failed"
stub take over. Adds a regression test.
Closes#687
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#685): set windowsHide on all Windows child-process spawns
A visible "gsd-core" console window flashed on Windows whenever a gsd-core
child process spawned without `windowsHide: true`. The most visible offenders
fire on every SessionStart / `/clear` (execNpm's `shell:true` npm view via the
update-check worker) and on every Edit/Write/MultiEdit in a worktree (the
worktree-path guard's git probe).
Add `windowsHide: true` to every external-binary spawn in the runtime source:
- hooks/gsd-context-monitor.js (record-session spawn)
- hooks/gsd-worktree-path-guard.js (SPAWNOPT)
- hooks/gsd-workflow-guard.js (git branch --show-current)
- src/shell-command-projection.cts (execGit / execNpm / execTool)
- src/check-command-router.cts (git log execFileSync)
- src/roadmap-upgrade.cts (git status/rev-parse/reset/clean execSync)
gsd-check-update.js already had it (the precedent). probeTty's tty call is
POSIX-only and intentionally untouched. Adds a regression test that asserts
each site plus a repo-wide completeness guard so a future external-binary
spawn that omits windowsHide fails CI. No behavior change off-Windows.
Closes#685
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(#685): set changeset pr number to 688
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#705): route hardcoded $HOME gsd-tools invocations in agents/commands through gsd_run
The hardcoded `node "$HOME/.claude/gsd-core/bin/gsd-tools.cjs" <cmd>` form
(fixed for workflows in #621/#637) survived in agent/command surfaces and
misresolves on global/shim-only installs. Route every agent-executed
invocation through the resolved `gsd_run` launcher in gsd-phase-researcher,
gsd-planner (load_graph_context extracted to a shared reference to stay under
the planner size budget), import, and graphify. Add a regression guard over
agents/ + commands/ + gsd-core/references/ bash blocks. User-facing display
messages and docs are intentionally left untouched.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#705): use repo changeset fragment format (type: Fixed, pr: 707)
The hand-written fragment used the standard changesets package format
(package: bump) which lacks the type:/pr: frontmatter the repo's
docs-required lint consumes (fail_malformed_fragment / missing_type).
Regenerated via scripts/changeset/new.cjs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#637): route 3 more workflows through gsd_run launcher (hardcoded $HOME sweep)
The hardcoded `node "$HOME/.claude/gsd-core/bin/gsd-tools.cjs"` invocation form
fixed in plan-phase.md (#621) survived in three more workflows. Same bug class:
on a global/shim-only install with no project-local runtime, the hardcoded path
can miss a working install, so the step reports the tool "not found" instead of
resolving it via the launcher. #3668 introduced gsd_run resolution; these sites
were missed.
- plan-review-convergence.md: convert the 3 hardcoded invocations (init,
roadmap get-phase, state planned-phase) to gsd_run. File already carried the
canonical preamble (first gsd_run is the earlier convergence-enabled check).
- ingest-docs.md, spec-phase.md: convert their hardcoded invocations to gsd_run
and inject the canonical launcher preamble via
`node scripts/sync-runtime-launcher.cjs` (these files previously had no
gsd_run and no preamble). The injected preamble is byte-equal to
_runtime-launcher.snippet.sh and precedes the first gsd_run call, per
runtime-launcher-parity invariant (B).
- Add tests/bug-637-workflow-no-hardcoded-home-tool.test.cjs: repo-wide
regression guard asserting NO workflow .md invokes gsd-tools via a hardcoded
$HOME path. Generalizes the plan-phase-only guard from #621 — the parity test
guards retired $GSD_SDK / bare /gsd-tools tokens but not this form, which is
how it survived across four files. Fails on the pre-fix files, passes after.
runtime-launcher-parity 7/7; full unit suite green (3477 pass / 0 fail).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(#637): add changeset fragment for PR #642
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(#637): update stale bug-2801 assertion to expect gsd_run
bug-2801 pinned ingest-docs.md to the hardcoded node "$HOME/.../gsd-tools.cjs" init form, which #637 replaces with the gsd_run launcher. Flip the assertion to expect gsd_run init ingest-docs; the bare-gsd-tools rejection and CLI-handler tests are unchanged, and bug-637's repo-wide guard now owns the no-hardcoded-$HOME invariant.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
`push: [main]` workflows execute from main's copy of the file, so the hardened
auto-backmerge.yml must live on main to govern real back-merges. This brings
main's copy in line with next, carrying:
- #673: scoped GSD_BOT_PR_TOKEN in the branch / open-PR steps.
- #698/#699: admin-merge via the PAT, force-push guarded to
chore/backmerge-main-to-next-* branches, `--jq '.[0].number // empty'` +
capture-from-create-URL, non-fatal labels, no greenwashing, and loud failure
on a genuine conflict.
Identical content to next's auto-backmerge.yml (already reviewed/merged in #699).
Merging this to main triggers the hardened workflow to back-merge main → next
autonomously — the end-to-end validation.
Closes#698
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
The Auto Back-Merge workflow could open a back-merge PR but never landed it,
and silently reported success on failure. Fixes:
- Merge via admin bypass using GSD_BOT_PR_TOKEN (the PAT) instead of auto-merge,
since back-merge PRs structurally can't satisfy next's required checks
(Issue-link / PR-template / changeset-lint).
- Stop swallowing create/merge failures with "|| echo ::warning" — real
failures now fail the job. (That greenwashing hid the whole bug.)
- Resolve the PR number with `--jq '.[0].number // empty'` (a no-match returns
the string "null", not empty) and capture a freshly-created PR's number from
the create URL to avoid GitHub API eventual-consistency races.
- Merge the exact PR number (env-bound) rather than by branch name.
- Force-push the disposable SHA-named bot branch, guarded by a
chore/backmerge-main-to-next-* name check so a mislabeled PR can't redirect
the force-push.
- Apply labels non-fatally so a missing label can't abort PR creation.
- On a genuine merge conflict, fail loudly (::error + exit 1) instead of
pushing an empty branch and opening a PR with no diff.
Closes#698
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Fast-track of the CHANGELOG.md backfill from #694 directly to `main` so the
live `/gsd:update` "What's New" preview (which fetches main's CHANGELOG.md)
immediately shows the 1.3.0/1.3.1 release notes instead of the empty message.
CHANGELOG-only; identical content to the dated [1.3.0]/[1.3.1] sections merged
to `next` in #694. The code-side fixes (verify gate, update.md, tests) reach
main on the next release. Uses the fix/critical-* lane because it is the
sanctioned main-target path and auto-back-merges to next.
Closes#690
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#690): promote CHANGELOG 1.3.x + gate release-notes promotion
/gsd:update showed an empty "What's New" preview after updating to 1.3.1
because CHANGELOG.md's 1.3.x content was never promoted out of [Unreleased]
into dated sections, so `scripts/changeset/cli.cjs extract` returned exit 2
("no releases in range").
- CHANGELOG.md: split [Unreleased] into dated [1.3.0] and [1.3.1] sections
(1.3.1 = hono advisory bump + installer-migration checksum self-heal, #670;
1.3.0 = the feature release), restoring an empty [Unreleased].
- scripts/changeset/cli.cjs: new `verify` subcommand that exits non-zero when
CHANGELOG has no dated `## [x.y.z]` heading for a version; hoist shared
stripV/resolveChangelogPath helpers used by extract + verify.
- .github/workflows/release.yml: gate the finalize job on `verify` (after the
build, before tag/publish) so an unpromoted CHANGELOG can never ship again.
- gsd-core/workflows/update.md: move `rm -f $CHANGELOG_TMP` after the
human-readable extract re-run so the preview no longer degrades to
"(changelog unavailable)".
- tests: regression guard for the 1.3.x headings + extract range + verify
command coverage (present/absent/undated/v-prefixed/--json/prerelease).
Closes#690
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(#690): add changeset fragment for #694
Fixed-type fragment for the user-facing /gsd:update preview fix and the
release-notes promotion gate.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Same moderate hono advisory (GHSA-3hrh-pfw6-9m5x et al.) that blocked the 1.3.1
hotfix is present on next (was 4.12.19); bump to keep the npm-audit gate green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
hotfix.yml was deleted (folded into release.yml). Remove the now-broken
release-coverage-scope and policy-release-no-npm-self-upgrade assertions that
readFileSync'd hotfix.yml (release.yml equivalents retained), drop the dead
install-smoke.yml path trigger, and update VERSIONING.md / docs/branching.md
prose to describe hotfixes via the Release workflow with a patch version.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
v1.3.0's production tree carries a moderate hono advisory (GHSA-3hrh-pfw6-9m5x
et al.) disclosed after release; the npm-audit unit gate blocked the hotfix
finalize. npm audit fix bumps hono to 4.12.23 (lockfile only).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#676): consolidate hotfix into release.yml; delete standalone hotfix workflow
npm allows only one trusted publisher per package and it is release.yml, so the
standalone hotfix.yml (token-auth) could never publish via OIDC (ENEEDAUTH on the
v1.3.1 finalize). Fold the patch/hotfix path into release.yml — the sole OIDC
trusted publisher — and delete hotfix.yml.
- validate-version accepts X.Y.Z (Z>0) → hotfix/X.Y.Z + base_tag; rejects rc for
hotfixes; X.Y.0 still → release/X.Y.0.
- create branches hotfix/X.Y.Z from the base tag with optional auto-cherry-pick
(default on) of fix:/chore: from next; release path unchanged.
- finalize is branch-agnostic already and publishes @latest via the existing
OIDC trusted publisher (no NODE_AUTH_TOKEN).
- CONTRIBUTING branching table updated; hotfix.yml removed.
Fixes#676
Supersedes #677.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#676): add hotfix/patch path to release.yml (OIDC trusted publisher)
The companion to the hotfix.yml deletion: release.yml now handles patch
versions (X.Y.Z) via hotfix/X.Y.Z branches and publishes @latest through the
existing OIDC trusted publisher. CONTRIBUTING branching table updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Backport of #675 to the 1.3.1 hotfix. An already-applied installer migration
whose recorded checksum drifted (e.g. a shipped body was edited in #615) is now
detected and reconciled on the next install instead of hard-aborting the
upgrade ("applied migration checksum changed"). Adds a CI baseline lock that
fails on any shipped-migration body drift.
Fixes#670
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Editing the body of an already-released installer migration drifts its computed
checksum (it hashes plan.toString()). The integrity guard then hard-aborted
every prior install on upgrade with "applied migration checksum changed" — a
100% reproducible blocker (v1.3.0, all platforms).
Already-applied migrations are filtered out of `pending` and never re-run, so
a drifted checksum is functionally inert. ADR-0008 anticipates checksum-mismatch
state as something the install-state layer must handle gracefully (plan -> apply
-> recover/report), not abort on.
This supersedes the published-checksum allowlist merged in #674 (per-release
maintenance debt — every historical checksum hand-pinned, still throws for any
unregistered value) with a general, self-healing recovery:
- Replace the throwing guard with non-fatal `collectAppliedChecksumDrift`,
surfaced on `plan.checksumDrift`.
- Reconcile drifted stored checksums durably on the next state write
(`reconcileDriftedChecksums`), idempotently (no perpetual writes).
- Relocate the "shipped migration bodies are immutable" rule to a CI baseline
test that locks every shipped migration's checksum and fails on body drift —
where #615 should have been caught, instead of blocking users.
Removes #674's legacyChecksums field, per-migration checksum pins,
published-checksums.json fixture, and compat test.
Fixes#670
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
The open-gsd org blocks the Actions GITHUB_TOKEN from creating PRs, so
auto-backmerge and the release finalize merge-back PR steps can't open
their PRs (must be done manually). Point those two steps at a scoped
secret (pull-requests:write + contents:write), falling back to
GITHUB_TOKEN so behavior is unchanged until the secret is added.
Refs #660
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
After the 1.3.0 release, next moves onto the -dev prerelease stream so the
trunk self-identifies as unreleased (floor = next patch). First manual
exercise of the ADR-660 release model.
Refs #660
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* fix(#663): resolve open CodeQL/Dependabot security alerts
- ReDoS: collapse ambiguous nested quantifiers in phase-heading regexes
(verify/validate/commands) and the plan-filename lookahead (phase) to
provably-equivalent non-backtracking forms
- prototype pollution: guard __proto__/constructor/prototype in setConfigValue
- remove dead no-op .replace(/-/g,'-') in phase.cts
- escape all regex metachars in bug-2839 test
- add contents:read permissions to security-scan + install-smoke workflows
- pin qs >= 6.15.2 via overrides (DoS GHSA)
- broaden prompt-injection allowlist to translated security-model docs
Closes#663
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test(#663): regression tests for prototype-pollution guard and roadmap-phase ReDoS
Behavioral test that config-set rejects __proto__/constructor/prototype keys
without polluting Object.prototype, plus a ReDoS guard (timing-bound) and
behavior-preservation assertions for the collapsed phase-heading regexes.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test(#663): make ReDoS regression assert structured result, not elapsed time
Replace elapsed-time assertions (which tripped local/no-elapsed-assertion
ESLint rule and were unsound for synchronous ReDoS) with structured-result
assertions on adversarial inputs: assert that malformed phase headings/
unchecked-item lines without a terminating colon/space yield an empty Set,
which is both the correct behavior and an exercise of the fixed linear regex
on the catastrophic-backtracking input shape.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(#663): add Security changeset fragment for #665
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test(#663): fold prototype-pollution regression into config.test.cjs
The standalone bug-663-config-prototype-pollution.test.cjs was a 9th
config-module test file, tripping lint-test-file-count (the allowlist is
ratcheted and must not grow). Consolidated into config.test.cjs instead.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Override stale main-only docs (README/translations/CHANGELOG #540/#542/#546/#548)
with the cleaned-up release content from next — these were old data confusing
users and were intentionally removed on next. Strategy 'ours' keeps the release
tree verbatim and records main as a parent so the merge-back is conflict-free.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replaces the persistent/frozen release branch + hand-moved tag with:
release always cut from next's head, immutable tags minted once at
finalize, next on a -dev stream, and @next dist-tag as the RC surface.
Closes#660
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Consolidate all pre-rename release notes (the retired get-shit-done-cc /
get-shit-done-redux lineage, 1.0.0 -> 1.50.0-canary.1) into one condensed,
read-only archive so the legacy 1.x version numbers no longer collide with
the current @opengsd/gsd-core line.
- Add docs/RELEASE-NOTES-LEGACY.md: rename banner, master version-index
table, condensed per-version sections (1.42.3 -> 1.0.0), and a separate
pre-release & canary builds section. Stale install commands stripped.
- Trim CHANGELOG.md to the current @opengsd/gsd-core line only; replace the
Legacy Release History block with a pointer to the archive and drop the
orphaned numbered legacy reference-link definitions.
- Remove the 10 standalone docs/RELEASE-v*.md files.
- Repoint docs/CANARY.md and docs/FEATURES.md links to the new archive.
Closes#658
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
The package author was still the legacy personal credit "TÂCHES", which npm
renders on the package page (issue #653). Set it to the org name OpenGSD,
matching the @opengsd scope / open-gsd org. The installer banner's "by TÂCHES"
was already removed in the #523 rebrand; this clears the last in-repo reference.
Closes#653
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#586): make ship PHASE_VERIFICATION_INCOMPLETE actionable, drop dead `pass` arm
The ship preflight gate blocked with PHASE_VERIFICATION_INCOMPLETE but named no
next step, and accepted a `pass` status the verifier never emits. Capture the
verification status and route per value (gaps_found / human_needed / missing),
mirroring execute-phase's status table; accept only `passed`.
Closes#586
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(#586): backfill changeset PR number 650
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(#586): scope ship verification status to frontmatter only
Codex adversarial review of PR #650 flagged that the status gate grepped
`^status:` over the entire VERIFICATION.md, so a `status:` line in the report
body (a code block / copied artifact) concatenates into a non-matching value and
blocks a genuinely-passed phase with the wrong next action. Restrict extraction
to the leading YAML frontmatter block, first match only. Adds a behavioral
regression test that runs the gate's own bash pipeline against a passing report
whose body contains decoy `status:` lines.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(#586): drop manual PR ref from changeset body
The changelog renderer auto-appends `(#<pr>)` from the fragment's pr: field
(scripts/changeset/serialize.cjs, github-release-notes.cjs). The manual trailing
`(#586)` produced a double, mismatched ref (issue #586 + auto PR #650); remove it
to match the sibling-fragment convention.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(#586): make ship-586 bash-fence regex Windows-safe (CRLF)
The behavioral test extracted the gate's bash block with /```bash\n.../ — a
literal \n that fails to match Windows CRLF checkouts and trips the
windows-test-parity-guard (fenceRegexLiteralNewline). Use ```bash\r?\n and
normalize the captured block to LF before running it. Full unit suite: 0 fail.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(#586): run ship-586 bash-pipeline tests on POSIX only
On Windows CI the behavioral tests failed: git-bash is present (so the old
hasBash guard ran them) but receives a Windows-style tmpdir path it cannot glob,
so extraction returned empty. The extraction logic is platform-independent and
the gate's bash only runs in a POSIX workflow context, so skip the pipeline
execution on win32. POSIX (macOS/Linux) still runs and asserts it.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The #452 ESLint migration replaced the homegrown source-grep regex linters
with the local/no-source-grep AST rule (eslint-rules/no-source-grep.cjs, wired
in eslint.config.mjs) but left the old scripts on disk, wired to nothing.
Removed:
- scripts/lint-no-source-grep.cjs — CLI linter; no module.exports, never
required, not referenced by package.json / CI / eslint. Superseded by the rule.
- scripts/lint-no-source-grep-extras.cjs — var-binding + wrapped-assert-ok
regex detectors; the ESLint rule covers both forms via AST
(VariableDeclarator/AssignmentExpression tracking + member-call checks).
- tests/bug-2982-lint-var-binding.test.cjs — exercised only the deleted extras
module; the #2982 var-binding scenario is already covered against the live
rule by tests/eslint-rules.test.cjs.
Also dropped the now-dangling 'scripts/lint-no-source-grep.cjs' entry from
DEFAULT_RELATIVE_FILES in scripts/lint-pr-check-project-dir.cjs (the list is
existsSync-filtered, so this is tidy-up, not a behavior change).
No functional change: source-grep enforcement remains intact via the ESLint
rule, and the full unit suite stays green. Three surviving comment-only mentions
of "lint-no-source-grep" refer to the rule concept (which lives on in ESLint),
not the deleted files.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
When ci-test-scope falls back to the 'unit' sentinel (#408 intent) and
ci-prepare-test-scope writes it verbatim, run-tests --files-from received
a bare 'unit' token that was not a filename, causing exit 2 with
"requested test file(s) not found: unit".
selectExplicitFiles() now recognises any SUITES member and delegates to
the existing selectFiles() resolver before the path-existence check,
reusing the suite expansion logic rather than reimplementing it.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>