Files
msd-core/docs/prd/209-readme-continuity-release-update.md
Jakub Zych 12ee75a509
Some checks failed
Tests / PR mergeability (push) Successful in 1m37s
Tests / Base branch health (push) Successful in 11s
Tests / Detect test scope (push) Successful in 17s
Tests / lint-tests (push) Failing after 2m16s
Tests / plugin-validate (push) Successful in 1m6s
Tests / test (ubuntu-latest, 24, shard 1/3) (push) Failing after 25s
Tests / test (ubuntu-latest, 24, shard 2/3) (push) Failing after 20s
Tests / test (ubuntu-latest, 24, shard 3/3) (push) Failing after 20s
Tests / test (ubuntu-latest, 24) (push) Failing after 19s
Tests / test (inert CI) (push) Has been skipped
Tests / QA loop walk (smell ratchet) (push) Failing after 19s
Tests / Coverage gate (merged shards) (push) Has been skipped
Tests / Publish emitted-baseline artifact (push) Has been skipped
Dismiss Unauthorized PR Approvals / dismiss-unauthorized-approval (push) Successful in 9s
Close Draft PRs (sweep) / Sweep open draft PRs (push) Successful in 8s
Tests / conformance test (macos-latest, 24) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 1/3) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 2/3) (push) Has been cancelled
Tests / conformance test (windows-latest, 24, shard 3/3) (push) Has been cancelled
Tests / Required tests (push) Has been cancelled
chore: point MSD at git.golem15.com/golem15/msd-core
The fork lives on the golem15 Gitea forge, not GitHub. Package identity now
parses either host and derives in-place raw URLs for Gitea; the identity-drift
lint accepts the new host; README drops GitHub-only badges and the npm
quickstart in favour of the checkout installer.
2026-10-06 10:41:56 +02:00

2.1 KiB

PRD: README Continuity And Release Communications Update

Linked Issue

  • Closes #209

Problem

The top-level README still mixes legacy transition language, personal attribution, and outdated migration framing. Users need one clear source of truth for:

  • canonical repository and package identities
  • current maintainer ownership/governance
  • migration guidance away from legacy upstream artifacts
  • security and audit status references

Goals

  1. Remove legacy personal maintainer attribution from README narrative sections.
  2. Present open-gsd continuity messaging in concise, team-owned language.
  3. Provide explicit migration guidance from legacy packages to @opengsd/*.
  4. Reference public announcement and security-audit discussions directly.
  5. Keep changes docs-only and non-behavioral.

Non-Goals

  • Any runtime, CLI, or workflow behavior changes.
  • Any package publishing process changes.
  • Any new security policy implementation beyond documentation updates.

Scope

  • README.md top continuity notice
  • README.md "Why" narrative section rewrite
  • release/continuity cross-links and wording cleanup

User Stories

  • As a new user, I can quickly identify which repo/package is canonical.
  • As an existing user, I can safely migrate away from legacy package names.
  • As a security-conscious user, I can find the public audit status and continuity rationale in one place.

Acceptance Criteria

  1. README contains a continuity notice naming golem15/msd-core as canonical.
  2. README removes personal legacy attribution in origin-story prose.
  3. README strongly recommends migration away from legacy artifacts.
  4. README links to Discussions #109 and #119.
  5. README states current audit posture with "no known active exploit" language.

Risks

  • Overstating security claims beyond published evidence.
    • Mitigation: keep wording scoped to publicly posted announcement text.
  • Migration warning language may be interpreted as policy rather than recommendation.
    • Mitigation: phrase as a strong recommendation based on ownership and governance reality.

Rollout

  1. Update README content.
  2. Open docs PR linked to #209.
  3. Run CI and merge once green.