* chore(#604): rename get-shit-done/ runtime directory to gsd-core/ Renames the installed runtime directory `get-shit-done/` to `gsd-core/` so the on-disk name matches the package (`@opengsd/gsd-core`), repo, and binary (`gsd-tools`). The npm package name and binary are unchanged; npx/npm consumers are unaffected. Mechanical (bulk, ~90% of the diff): - `git mv get-shit-done gsd-core` - Swept path/identifier references across the repo via `perl -pe 's/get-shit-done(?!-\w)/gsd-core/g'`. The negative lookahead preserves the five legitimate slug variants that are NOT the directory: get-shit-done-{OLD,cc,classic,cli,redux} (old package/repo names). - Build/manifest wiring: package.json (bin, files, coverage globs), tsconfig.build.json (outDir), ~86 .gitignore build-output entries, stryker.config.mjs, scan-ignore files, install.js path strings. - Frozen (not rewritten): CHANGELOG.md history; translated docs (README.<locale>.md and docs/{ja-JP,ko-KR,pt-BR,zh-CN}/). New logic (review here): - src/installer-migrations/003-rename-get-shit-done-to-gsd-core.cts: a proper ADR-0008 installer migration. On upgrade it walks the legacy `~/.claude/get-shit-done/` tree, classifies each file via the prior install manifest, and emits remove-managed / backup-and-remove for managed files while PRESERVING unknown user-added files. Symlink-safe (skips a symlinked root and symlinked entries; bounds-checks every path under configDir). The framework rolls back on install failure. Emptied dirs may remain (framework has no recursive dir-removal primitive) — documented. - scripts/lint-legacy-dir-name.cjs: CI regression guard forbidding the bare `get-shit-done` directory token (split token to avoid self-match; case- insensitive; `(?!-\w)` lookahead allows the slug variants; allowlists CHANGELOG, translated docs, and `gsd-allow-legacy-name` marker lines). Wired into the lint-tests CI job. - Restored scripts/lint-package-identity-drift.cjs detection regexes (the mechanical sweep had wrongly rewritten the old-name patterns it exists to detect) and marked them as intentional legacy references. - TDD tests for the migration and the guard; do.md slash-command guard regex tightened so a `/gsd-core/bin` path segment is not mistaken for a command; changeset + docs/installer-migrations.md row added. Breaking: the installed runtime path moves `~/.claude/get-shit-done/` -> `~/.claude/gsd-core/`. Migration 003 removes the stale legacy dir's managed files (preserving user files) on upgrade. Users with custom hooks/configs hardcoding the old path must update them. Closes #604 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): unsweep pending changesets + allowlist injection-example docs CI fixes for the rename PR: - Do not sweep pending .changeset/*.md (ephemeral release-note fragments, like CHANGELOG); reverted those body edits so 5 pre-existing malformed fragments (missing type/pr) no longer enter the PR diff and trip docs-lint. Allowlisted .changeset/ in the legacy-name guard accordingly. - Allowlisted TEST-EXAMPLES.md and docs/explanation/security-model.md in prompt-injection-scan.sh: they contain intentional injection examples / security-model prose; the path-reference rewrites are kept. CodeQL alerts on this PR are pre-existing (alert lines unchanged by this PR; none in the new migration/guard) and are out of scope for the rename. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): resolve CodeQL alerts surfaced on this PR The rename diff touched files carrying pre-existing CodeQL findings; per the no-pre-existing-dismissal rule, fixing every surfaced alert rather than waving them off. All behavior-preserving: - scripts/ci-test-scope.cjs: build the config-path match from string .includes() instead of a RegExp over an arg-derived value (js/regex-injection). - src/profile-output.cts: escape backslashes before pipe-escaping desc/safeName so the table-cell escape is complete (js/incomplete-sanitization). - tests/{bug-2643,bug-2808,docs-parity-live-registry}: two-pass HTML-comment strip so a bare/unclosed `<!--` cannot survive (js/incomplete-multi-character-sanitization). - tests/inline-plan-threshold: drop the no-op `\s`->`\s` identity replace, keep the meaningful POSIX-class conversion (js/identity-replacement). Verified: build:lib green; the touched test files + ci-test-scope + profile-output suites pass; lint:legacy-name clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): correctly resolve remaining CodeQL alerts (regex-injection + sanitization) The prior commit's fixes for two alerts were ineffective: - ci-test-scope.cjs js/regex-injection: the alert is the CLI-arg-derived `file` reaching static regex `.test(file)` calls (not the config rule). Removed ALL regex over file/t — startsWith/includes/=== string checks + an isWindowsHint helper — so there is no regex sink for the tainted value. - js/incomplete-multi-character-sanitization (3 test files): a single `.replace(/<!--...-->/g,'')` can let `<!--` re-form. Replaced with a fixpoint loop (replace until stable) plus a final bare-opener strip. Verified: no regex over file/t remains; ci-test-scope + the 3 test suites pass; lint:legacy-name clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): make ci-test-scope + comment-strippers regex-free to clear CodeQL CodeQL flags the regex PATTERNS syntactically (regex-injection on the --files arg split; incomplete-multi-character-sanitization on the <!--...--> replace), so loop fixes do not satisfy it. Made these paths regex-free: - ci-test-scope.cjs splitFiles: char-by-char separator tokenizer (no /[,\\s]+/). - 3 test files: indexOf/slice HTML-comment stripper (no .replace(/<!--/)). Behavior preserved; ci-test-scope + the 3 suites pass; guard clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): unblock security base64 scan on the large rename diff The security job hit its 10m timeout: base64-scan.sh choked on the binary test fixture tests/feat-3594-parser-property-style.test.cjs (embedded NUL/ non-UTF8 bytes -> thousands of bogus blobs + "ignored null byte" warnings), and the ~800-file rename diff is slow to scan regardless. - scripts/base64-scan.sh: skip binary-by-content files (grep -Iq .) — they can't carry base64-obfuscated *text* and feeding NUL bytes through the per-line scanner is pathologically slow. collect_files already filtered binary *extensions*; this catches binary *content* in text extensions. - .github/workflows/security-scan.yml: raise the security job timeout 10m->30m to accommodate very large diffs (the scan itself is unchanged). Verified locally: scan skips the fixture, 0 "ignored null byte" warnings, 0 findings, exit 0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): sweep get-shit-done refs introduced by merging next The branch was updated with next (#614/#384/#618 etc.), which reference the get-shit-done/ dir (still named that on next). Swept the stale references in the merged files to gsd-core so the rename stays consistent and lint:legacy-name passes: - commands/gsd/discuss-phase.md (runtime-launcher shim paths) - src/core.cts (getAgentsDir layout comments) - tests/bug-384-agents-runtime-aware.test.cjs (require path to runtime lib) Verified: guard 0 violations; build green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): exclude gsd-core/ path segments from bug-3683 command cross-ref invariant The #614 runtime-launcher shim added to discuss-phase.md references `${_GSD_RUNTIME_ROOT}/gsd-core/bin/...`. bug-3683's REF_PATTERN excluded path-y refs only via lookbehind, but `}` precedes `/gsd-core/` in the shim, so it mis-read the directory path as a dangling `/gsd-core` command ref (same class as the #604 bug-2954 fix). Added a trailing `(?![\w-]*\/)` so `/gsd-<x>/...` path segments are not treated as slash-command references. Verified locally on BOTH platforms before pushing: - mac (node 26) full suite: 0 failures - gsd-test-runner (linux, node22 image) full suite: 0 failures - bug-3683 + bug-2954 pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): lazily resolve findProjectRoot in gsd-tools (harden flaky CI) CI intermittently failed state.test's gsd-tools subprocess with "findProjectRoot is not a function" (flip-flopping across legs; not reproducible on mac full suite, gsd-test linux full suite, test:unit, or state.test x8). findProjectRoot is a re-export from core.cjs (sourced from project-root.cjs); binding it via destructure at module-load can be undefined under a load-ordering edge. Resolve it lazily at call time via a small wrapper so the lookup happens after core.cjs is fully initialized. Verified green on BOTH platforms before pushing: - mac (node 26) full suite: 0 failures - gsd-test-runner (linux, node22) full suite: 0 failures - state.test.cjs: 106/106; gsd-tools loads cleanly. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#604): allowlist verification-patterns.md placeholder examples in secret scan The rename git-mv'd references/verification-patterns.md into gsd-core/, pulling it into the secret-scan diff. It documents stub/placeholder RED-FLAG env-var examples (illustrative Stripe test-key / database-URL / API-key placeholders) — not real credentials. Added it to .secretscanignore with the strict annotation, mirroring the existing gsd-core/workflows/plan-phase.md exception. Verified locally: secret-scan-lint --strict OK; secret-scan --diff origin/next exits 0 with 0 findings. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
14 KiB
<required_reading> Read all files referenced by the invoking prompt's execution_context before starting. </required_reading>
Read project state to determine current position:_GSD_SHIM_NAME="gsd-tools.cjs"; _GSD_RUNTIME_ROOT="${RUNTIME_DIR:-$(git rev-parse --show-toplevel 2>/dev/null || pwd)}"; GSD_TOOLS="${_GSD_RUNTIME_ROOT}/gsd-core/bin/${_GSD_SHIM_NAME}"; if [ -f "$GSD_TOOLS" ]; then gsd_run() { node "$GSD_TOOLS" "$@"; }; elif [ -f "${_GSD_RUNTIME_ROOT}/.claude/gsd-core/bin/${_GSD_SHIM_NAME}" ]; then GSD_TOOLS="${_GSD_RUNTIME_ROOT}/.claude/gsd-core/bin/${_GSD_SHIM_NAME}"; gsd_run() { node "$GSD_TOOLS" "$@"; }; elif command -v gsd-tools >/dev/null 2>&1; then GSD_TOOLS="$(command -v gsd-tools)"; gsd_run() { "$GSD_TOOLS" "$@"; }; elif [ -f "$HOME/.claude/gsd-core/bin/${_GSD_SHIM_NAME}" ]; then GSD_TOOLS="$HOME/.claude/gsd-core/bin/${_GSD_SHIM_NAME}"; gsd_run() { node "$GSD_TOOLS" "$@"; }; else echo "ERROR: gsd-tools.cjs not found at $GSD_TOOLS and gsd-tools is not on PATH. Run: npx -y @opengsd/gsd-core@latest --claude --local" >&2; exit 1; fi
# Get state snapshot
gsd_run query state.json 2>/dev/null || echo "{}"
Also read:
.planning/STATE.md— current phase, progress, plan counts.planning/ROADMAP.md— milestone structure and phase list
Extract:
current_phase— which phase is activeplan_of/plans_total— plan execution progressprogress— overall percentagestatus— active, paused, etc.
If no .planning/ directory exists:
No GSD project detected. Run `/gsd:new-project` to get started.
Exit.
Run hard-stop checks before routing. Exit on first hit unless `--force` was passed.If --force flag was passed, skip all gates, Route 0, and the prior-phase completeness prompt.
Print a one-line warning: ⚠ --force: skipping safety gates
Then proceed directly to determine_next_action. (Route 0 and prior_phase_completeness are NOT reached under --force.)
Gate 1: Unresolved checkpoint
Check if .planning/.continue-here.md exists:
[ -f .planning/.continue-here.md ]
If found:
⛔ Hard stop: Unresolved checkpoint
`.planning/.continue-here.md` exists — a previous session left
unfinished work that needs manual review before advancing.
Read the file, resolve the issue, then delete it to continue.
Use `--force` to bypass this check.
Exit (do not route).
Gate 2: Error state
Check if STATE.md contains status: error or status: failed:
If found:
⛔ Hard stop: Project in error state
STATE.md shows status: {status}. Resolve the error before advancing.
Run `/gsd:health` to diagnose, or manually fix STATE.md.
Use `--force` to bypass this check.
Exit.
Gate 3: Unchecked verification
Check if the current phase has a VERIFICATION.md with any FAIL items that don't have overrides:
If found:
⛔ Hard stop: Unchecked verification failures
VERIFICATION.md for phase {N} has {count} unresolved FAIL items.
Address the failures or add overrides before advancing to the next phase.
Use `--force` to bypass this check.
Exit.
After all three hard-stop gates pass, continue to resume_incomplete_phase.
This catches the common failure mode where a session died mid-execution (hang, token exhaustion, API connection drop) and STATE.md's current_phase got advanced past the phase that actually has unfinished work. Without this gate, /gsd:progress --next would route by current_phase and silently skip the partially-executed phase.
Skip if --no-resume was passed (fall through to prior_phase_completeness). (--force already bypassed all gates and Route 0 at safety_gates — it never reaches this step.)
Why Route 0 runs here (after Gates 1-3, before the prior-phase defer prompt): This step is a hard invariant independent of current_phase's value — it must run before any routing rule that reads current_phase. Gates 1-3 are cheap repo/state validity checks that must always run — skipping them on the resume path would risk advancing into a broken-state project. The prior-phase completeness-scan DEFER PROMPT, however, must NOT run in the default (no-flag) case when Route 0 is about to resume the phase automatically: that would force a double-decision (prompt first, then resume anyway), overriding the user's choice. Route 0 placed here means: default = resume silently (no defer prompt); --no-resume = skip Route 0 and fall through to the prior-phase defer prompt in prior_phase_completeness; --force = jump straight to determine_next_action at safety_gates (never reaches Route 0 or prior_phase_completeness at all).
Scan ALL phases in ROADMAP order (lowest-numbered to highest) for incomplete-execution state. Use gsd_run query roadmap.analyze to get the phase list, then for each phase number N query gsd_run query find-phase <N> JSON and inspect its plans and summaries arrays. A phase is incomplete-execution when plans.length > summaries.length (at least one PLAN.md has no matching SUMMARY.md).
Stop at the first such phase. Record its phase number as INCOMPLETE_PHASE. This is the lowest-numbered phase that needs continued execution.
Illustrative bash:
INCOMPLETE_PHASE=""
ROADMAP_JSON=$(gsd_run query roadmap.analyze)
if [ $? -ne 0 ] || [ -z "$ROADMAP_JSON" ]; then
echo "⚠ WARNING: resume-incomplete-phase scan could not run (roadmap.analyze failed)." >&2
echo " The incomplete-phase invariant (#160) could not be verified." >&2
echo " Proceeding to prior-phase completeness check — review project state carefully." >&2
# Fall through to prior_phase_completeness rather than silently skipping
else
for PHASE_NUM in $(echo "$ROADMAP_JSON" | jq -r '.phases[] | (.number // .phase_number // empty)'); do
PHASE_JSON=$(gsd_run query find-phase "$PHASE_NUM")
if [ $? -ne 0 ] || [ -z "$PHASE_JSON" ]; then
echo "⚠ WARNING: Could not query phase $PHASE_NUM — skipping in resume scan." >&2
continue
fi
PLAN_COUNT=$(echo "$PHASE_JSON" | jq '(.plans // []) | length')
SUMMARY_COUNT=$(echo "$PHASE_JSON" | jq '(.summaries // []) | length')
if [ "${PLAN_COUNT:-0}" -gt "${SUMMARY_COUNT:-0}" ]; then
INCOMPLETE_PHASE="$PHASE_NUM"
break
fi
done
fi
If INCOMPLETE_PHASE is non-empty: route to /gsd:execute-phase $INCOMPLETE_PHASE and exit. Display a one-line notice before invoking:
▶ Resuming incomplete Phase ${INCOMPLETE_PHASE} (plans without summaries detected)
/gsd:execute-phase ${INCOMPLETE_PHASE}
(use --no-resume to skip this check and defer via the prior-phase prompt)
Then invoke via SlashCommand. Do not continue to subsequent steps.
If INCOMPLETE_PHASE is empty: continue to prior_phase_completeness.
Prior-phase completeness scan:
Scan all phases that precede the current phase in ROADMAP.md order for incomplete work. For each prior phase number N, use gsd_run query find-phase <N> JSON (plans, summaries, incomplete_plans, etc.) to inspect that phase.
Detect three categories of incomplete work:
- Plans without summaries — a PLAN.md exists in a prior phase directory but no matching SUMMARY.md exists (execution started but not completed).
- Verification failures not overridden — a prior phase has a VERIFICATION.md with
FAILitems that have no override annotation. - CONTEXT.md without plans — a prior phase directory has a CONTEXT.md but no PLAN.md files (discussion happened, planning never ran).
If no incomplete prior work is found, continue to determine_next_action silently with no interruption.
If incomplete prior work is found, show a structured completeness report:
⚠ Prior phase has incomplete work
Phase {N} — "{name}" has unresolved items:
• Plan {N}-{M} ({slug}): executed but no SUMMARY.md
[... additional items ...]
Advancing before resolving these may cause:
• Verification gaps — future phase verification won't have visibility into what prior phases shipped
• Context loss — plans that ran without summaries leave no record for future agents
Options:
[C] Continue and defer these items to backlog
[S] Stop and resolve manually (recommended)
[F] Force advance without recording deferral
Choice [S]:
If the user chooses "Stop" (S or Enter/default): Exit without routing.
If the user chooses "Continue and defer" (C):
- For each incomplete item, create a backlog entry in
ROADMAP.mdunder## Backlogusing the existing999.xnumbering scheme:
### Phase 999.{N}: Follow-up — Phase {src} incomplete plans (BACKLOG)
**Goal:** Resolve plans that ran without producing summaries during Phase {src} execution
**Source phase:** {src}
**Deferred at:** {date} during /gsd:progress --next advancement to Phase {dest}
**Plans:**
- [ ] {N}-{M}: {slug} (ran, no SUMMARY.md)
- Commit the deferral record:
gsd_run query commit "docs: defer incomplete Phase {src} items to backlog"
- Continue routing to
determine_next_actionimmediately — no second prompt.
If the user chooses "Force" (F): Continue to determine_next_action without recording deferral.
# Check for pending spikes (verdict: PENDING in any README)
PENDING_SPIKES=$(grep -rl 'verdict: PENDING' .planning/spikes/*/README.md 2>/dev/null | wc -l | tr -d ' ')
# Check for pending sketches (winner: null in any README)
PENDING_SKETCHES=$(grep -rl 'winner: null' .planning/sketches/*/README.md 2>/dev/null | wc -l | tr -d ' ')
If either count is > 0, display before routing:
⚠ Pending exploratory work:
{PENDING_SPIKES} spike(s) with unresolved verdicts in .planning/spikes/
{PENDING_SKETCHES} sketch(es) without a winning variant in .planning/sketches/
Resume with `/gsd:spike` or `/gsd:sketch`, or continue with phase work below.
Only show lines for non-zero counts. If both are 0, skip this notice entirely.
Apply routing rules based on state:Route 1: No phases exist yet → discuss
If ROADMAP has phases but no phase directories exist on disk:
→ Next action: /gsd:discuss-phase <first-phase>
Route 2: Phase exists but has no CONTEXT.md or RESEARCH.md → discuss
If the current phase directory exists but has neither CONTEXT.md nor RESEARCH.md:
→ Next action: /gsd:discuss-phase <current-phase>
Route 3: Phase has context but no plans → plan
If the current phase has CONTEXT.md (or RESEARCH.md) but no PLAN.md files:
→ Next action: /gsd:plan-phase <current-phase>
Route 4: Phase has plans but incomplete summaries → execute
If plans exist but not all have matching summaries:
→ Next action: /gsd:execute-phase <current-phase>
Route 5: All plans have summaries → verify and complete
If all plans in the current phase have summaries:
→ Next action: /gsd:verify-work
Route 6: Phase complete, next phase exists → advance
If the current phase is complete and the next phase exists in ROADMAP:
→ Next action: /gsd:discuss-phase <next-phase>
Route 7: All phases complete → complete milestone
If all phases are complete:
→ Next action: /gsd:complete-milestone
Route 8: Paused → resume
If STATE.md shows paused_at:
→ Next action: /gsd:resume-work
## GSD Next
**Current:** Phase [N] — [name] | [progress]%
**Status:** [status description]
▶ **Next step:** `/gsd-[command] [args]`
[One-line explanation of why this is the next step]
Then immediately invoke the determined command via SlashCommand.
Do not ask for confirmation — the whole point of /gsd:progress --next is zero-friction advancement.
If --auto was passed: after the determined command completes, automatically re-invoke /gsd:progress --next --auto to continue chaining to the next step. Repeat until one of:
- A milestone completes (
/gsd:complete-milestoneis reached) - A blocking decision is required (safety gate triggers, prior-phase completeness prompt, user input needed)
- An error or paused state is detected
When stopping due to a blocker, display:
⛔ Auto-chain stopped: [reason — e.g. safety gate, blocking decision required]
Resume with: `/gsd:progress --next --auto` once resolved.
<success_criteria>
- Project state correctly detected
- Gates 1-3 (repo/state validity) run first — always, even on the resume path
- Route 0 (resume_incomplete_phase) runs AFTER Gates 1-3 and BEFORE the prior-phase defer prompt — no double-decision in the default (no-flag) case
- Default (no flag): Route 0 resumes incomplete phase silently, exits — user never sees the prior-phase defer prompt
--no-resume: Route 0 skipped, prior_phase_completeness defer prompt runs as before--force: everything skipped (Gates, Route 0, prior_phase_completeness) → straight todetermine_next_action- Scan uses
gsd_run(canonical resolver form); errors are surfaced rather than suppressed - Predicate is plans-without-summaries (
plans.length > summaries.length) — consistent withdetermine_next_actionRoute 4 - Next action correctly determined from routing rules
- Command invoked immediately without user confirmation
- Clear status shown before invoking </success_criteria>