Security-motivated migration of all stale repository and npm-scope references. Three categories of changes (58 files, 174 substitutions): 1. gsd-build → open-gsd (security-critical): - .github/workflows/release-sdk.yml — npm token comment, tarball filename pattern - .github/workflows/hotfix.yml — same - .changeset/fix-3406-detect-stale-sdk-shadow.md — @gsd-build/sdk → @open-gsd/sdk - .changeset/sharp-quails-leap.md — same - get-shit-done/workflows/update.md — CHANGELOG raw GitHub URL 2. GSD-redux org slug → open-gsd (canonical rename): - package.json + sdk/package.json — repository/homepage/bugs metadata - All README.*.md — live badge and link sections - CONTRIBUTING.md, CONTEXT.md, QUICK-WINS-CONFIRMED-BUGS.md - .coderabbit.yaml, .release-monitor.sh, scripts/sync-rulesets.sh - docs/** — all live agent/ADR/user-facing documentation - tests/** — repo slug assertions and test fixtures - scripts/changeset/cli.cjs + github-release-notes.cjs - .github/ISSUE_TEMPLATE/*, .github/pull_request_template.md - bin/install.js, get-shit-done/bin/lib/model-catalog.cjs - sdk/HANDOVER-*.md, sdk/src/*.test.ts 3. CLAUDE.md (gitignored local file — not in this commit): Updated separately outside git: --repo gsd-build/get-shit-done → --repo open-gsd/get-shit-done-redux with security warning. Intentionally unchanged: CHANGELOG.md, docs/RELEASE-*.md, .changeset/README.md, .changeset/build-hooks-atomic-write.md, README.md migration table (historical fork record), tests/changeset-serialize.test.cjs line 78 (serialization fixture). The gsd-build/get-shit-done repo is compromised (rug-pull documented in README.md). Do not push to or interact with that repo. Closes #120
3.4 KiB
Canary Stream
The canary dist-tag is GSD's earliest preview channel. It exists so contributors and willing early adopters can exercise in-flight features against the long-lived dev integration branch before they have any expectation of stability.
Stream policy
GSD ships through three npm dist-tags, each fed by exactly one git branch. Streams do not mix.
| Branch | dist-tag | Audience | Stability |
|---|---|---|---|
dev |
canary |
Contributors, willing early adopters | Best-effort. May regress between cuts. Roll-forward only. |
main |
next |
Maintainers, RC testers | Release-candidate quality. Bug-bar enforced. |
main |
latest |
Everyone else | Production stable. The default npm install target. |
dev is the integration branch for in-flight feature work (typically multi-PR vertical slices like the MVP/TDD/UAT track in 1.50.0). When the dev work stabilizes, it promotes to main as an RC train (vX.Y.Z-rc.N published to next), and after the RC train bakes, the same train promotes again to latest.
A canary build NEVER becomes a next build directly, and a next build NEVER becomes a latest build directly — every promotion goes through a fresh tag and a fresh release.
Installing canary
# One-off invocation (npx)
npx get-shit-done-redux@canary
# Pin to the canary dist-tag globally
npm install -g get-shit-done-redux@canary
# Pin to an exact canary version
npm install -g get-shit-done-redux@1.50.0-canary.1
The CC installer's defensive purge rewrites stale config blocks left by older GSD versions, so reinstalling on top of an existing project is safe.
When to install canary
✅ Do install canary when you want to:
- Exercise in-flight planning/execution/verification features early and report findings
- Validate a fix you've contributed to
devis reachable end-to-end - Help shake out canary-bake items (rough edges that won't ship to
nextuntil resolved)
❌ Do NOT install canary on:
- Production projects you depend on for delivery
- A machine where rolling back means recreating GSD state (use a profile or a workspace instead)
- A demo or onboarding setup — pin to
@latestso audiences see the stable surface
Rolling back from canary
# Back to the current stable
npm install -g get-shit-done-redux@latest
# Or to the next/RC train
npm install -g get-shit-done-redux@next
If you have a local project that interacted with canary-only features (for instance, an MVP-mode phase planned by 1.50.0-canary), the planner artifacts in .planning/ remain valid — older GSD versions will just ignore the **Mode:** mvp field on phases.
Reporting issues against canary
File against the issue tracker with the bug template. Include the exact canary version (get-shit-done-redux --version reports it) so triage can route the report back into the dev stream rather than the stable stream.
Where to look next
- Active canary release notes:
docs/RELEASE-v1.50.0-canary.1.md - Stable release notes:
CHANGELOG.md - Stream architecture rationale: discussed across #2727, #2773 (codex schema-break and the resulting promotion bottleneck that motivated explicit stream isolation)