* chore(npm): rebrand packages to @opengsd scope Rename: - get-shit-done-redux → @opengsd/get-shit-done-redux - @gsd-redux/sdk → @opengsd/gsd-sdk Add publishConfig.access=public for first-time scoped publish. CLI binary names (get-shit-done-redux, gsd-sdk, gsd-tools) unchanged. Sweeps install commands, npx invocations, CI publish/version-check workflows, tests, docs, READMEs (all translations), and the PACKAGE_NAME constant in check-latest-version. Bumps qs 6.15.1 → 6.15.2 to clear a moderate advisory surfaced by the audit-clean test (GHSA-q8mj-m7cp-5q26). Closes #126 * chore: pin 2.0.0 release + remove canary workflow - Bump both packages 1.50.0-canary.0 → 2.0.0 for first @opengsd publish - Remove .github/workflows/canary.yml and canary dist-tag handling in release.yml / release-sdk.yml - Drop canary section from VERSIONING.md Refs #126 * chore: address review findings + harden tarball-smoke timeout - .changeset/opengsd-org-rename.md: match project's custom parse.cjs frontmatter (type: Changed / pr: 127); the scoped @changesets/cli keys were silently rejected. - CONTEXT.md: drop two canary-stream policy lines and a dangling DEFECT.CANARY-VERSION-LEAK.cross-ref now that canary.yml is gone. - tests/release-tarball-smoke.install.test.cjs: pass timeout: 600_000 for npm pack + global install; the 3-minute runNpm default was timing out on slower Docker hosts (cartographer). Refs #126 * fix(sdk): add missing type/runtime devDependencies for build prepublishOnly invokes tsc which couldn't resolve @types/node, @types/ws, or synckit. They had been hoisted from root but were not declared in sdk/'s own package.json — first publish from a clean SDK tree failed. Refs #126 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(ci): use npm pack stdout instead of glob to find tarball `npm pack --silent` for a scoped package (@opengsd/get-shit-done-redux) produces `opengsd-get-shit-done-redux-*.tgz`, not `get-shit-done-redux-*.tgz`. Capture the filename from stdout instead of a hardcoded glob so the step works regardless of package name format. Fixes smoke (ubuntu-latest, 22, false) CI failure. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * ci: treat workflow-file changes as test-skip eligible `.github/workflows/install-smoke.yml` (and other workflow files) were in neither `test.yml` paths nor `test-skip.yml` paths-ignore, so neither workflow ran on a workflow-only commit — leaving the required test-skip check perpetually missing. Refs #126 * chore: reset version to 1.0.0 for first @opengsd publish Nothing has been published yet under the @opengsd scope, so the inaugural release uses 1.0.0 rather than 2.0.0. The "major bump" in the changeset reflects the breaking install-command change for users migrating from the prior unscoped `get-shit-done-redux`, not a numeric continuation from a 1.x line under the new identity. Refs #126 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
105 lines
3.5 KiB
JavaScript
Executable File
105 lines
3.5 KiB
JavaScript
Executable File
#!/usr/bin/env node
|
|
'use strict';
|
|
|
|
/**
|
|
* Deterministic latest-version check for /gsd-update (#2992).
|
|
*
|
|
* The /gsd-update workflow's check_latest_version step was previously
|
|
* prescribed in LLM-driven prose ("run `npm view get-shit-done-redux
|
|
* version`"). The executing model could shortcut the prescription and
|
|
* invent npm queries against wrong-shaped names (`@get-shit-done/cli`,
|
|
* `get-shit-done-cli`, `gsd`), all of which 404 or — worse — return an
|
|
* unrelated typosquat package.
|
|
*
|
|
* This script makes the package name a CONSTANT in code, not a free
|
|
* choice at execution time. The workflow calls it via `npm run
|
|
* check-latest-version -- --json` and parses the structured response.
|
|
*
|
|
* Tests assert on the typed CHECK_REASON enum and the structured result
|
|
* record, never on console prose. See CONTRIBUTING.md "Prohibited: Raw
|
|
* Text Matching on Test Outputs".
|
|
*/
|
|
|
|
const { execNpm } = require('./lib/shell-command-projection.cjs');
|
|
|
|
// Hardcoded. Do not parameterise — the whole point of this script is that
|
|
// the package name is not a runtime choice for the caller.
|
|
const PACKAGE_NAME = '@opengsd/get-shit-done-redux';
|
|
|
|
const CHECK_REASON = Object.freeze({
|
|
OK: 'ok',
|
|
FAIL_NPM_FAILED: 'fail_npm_failed',
|
|
FAIL_INVALID_OUTPUT: 'fail_invalid_output',
|
|
});
|
|
|
|
const SEMVER_RE = /^\d+\.\d+\.\d+(?:[-+][0-9A-Za-z.-]+)?$/;
|
|
|
|
/**
|
|
* Pure-ish: takes an injected spawn function so tests don't actually run npm.
|
|
* In production, defaults to execNpm() from the shell-projection seam.
|
|
*/
|
|
function checkLatestVersion(opts = {}) {
|
|
// Default path routes through the shell-projection seam (execNpm owns the
|
|
// Windows shell-flag policy and timeout default). The injection point
|
|
// remains spawnSync-shaped for test compatibility — the adapter below
|
|
// translates { exitCode } → { status } so the consumer logic is unchanged.
|
|
// Bounded at 15s so a hung registry doesn't block /gsd-update (#2993 CR).
|
|
const defaultSpawn = () => {
|
|
const r = execNpm(['view', PACKAGE_NAME, 'version'], { timeout: 15_000 });
|
|
return {
|
|
status: r.exitCode,
|
|
stdout: r.stdout,
|
|
stderr: r.stderr,
|
|
signal: r.signal,
|
|
error: r.error,
|
|
};
|
|
};
|
|
const spawn = opts.spawn || defaultSpawn;
|
|
|
|
const r = spawn();
|
|
if (!r || r.status !== 0) {
|
|
// Distinguish timeout (status null, signal set, stderr empty) from a
|
|
// genuine npm failure. Without this, both surfaced as "npm exited
|
|
// non-zero" and the operator couldn't tell which (#2993 CR).
|
|
let detail;
|
|
if (r && r.signal) {
|
|
detail = `npm timed out (signal: ${r.signal})`;
|
|
} else if (r && r.stderr) {
|
|
detail = r.stderr.trim();
|
|
} else {
|
|
detail = 'npm exited non-zero';
|
|
}
|
|
return {
|
|
ok: false,
|
|
reason: CHECK_REASON.FAIL_NPM_FAILED,
|
|
detail,
|
|
};
|
|
}
|
|
const version = (r.stdout || '').trim();
|
|
if (!SEMVER_RE.test(version)) {
|
|
return {
|
|
ok: false,
|
|
reason: CHECK_REASON.FAIL_INVALID_OUTPUT,
|
|
detail: version || '(empty)',
|
|
};
|
|
}
|
|
return { ok: true, version, reason: CHECK_REASON.OK };
|
|
}
|
|
|
|
function main() {
|
|
const json = process.argv.includes('--json');
|
|
const r = checkLatestVersion();
|
|
if (json) {
|
|
process.stdout.write(JSON.stringify(r) + '\n');
|
|
} else if (r.ok) {
|
|
process.stdout.write(r.version + '\n');
|
|
} else {
|
|
process.stderr.write(`check-latest-version: ${r.reason}: ${r.detail}\n`);
|
|
}
|
|
process.exit(r.ok ? 0 : 1);
|
|
}
|
|
|
|
if (require.main === module) main();
|
|
|
|
module.exports = { checkLatestVersion, CHECK_REASON, PACKAGE_NAME };
|