Files
msd-core/docs/prd/209-readme-continuity-release-update.md
Tom Boucher 79002a00cb chore(#518): rename npm package + bin to @opengsd/gsd-core (#519)
* chore: rename npm package + bin to @opengsd/gsd-core (functional)

- package.json: name @opengsd/get-shit-done-redux → @opengsd/gsd-core,
  bin key get-shit-done-redux → gsd-core, repository/homepage/bugs URLs
- package-lock.json: regenerated (npm install --package-lock-only)
- tests/**, scripts/**, bin/**, .github/**, agents/**, commands/**,
  get-shit-done/bin/**, get-shit-done/workflows/**:
  applied the 4-rule replacement (scoped npm ref, GitHub repo path,
  bin/clone invocations) per #505 single-source refactor

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs: sweep live references to @opengsd/gsd-core

Update all live documentation (README.md + translations, docs/**,
CONTRIBUTING.md, VERSIONING.md, SECURITY.md, CONTEXT.md,
docs/CANARY.md) to reflect the renamed package and repository.

Rules applied:
- @opengsd/get-shit-done-redux → @opengsd/gsd-core (scoped npm name)
- open-gsd/get-shit-done-redux → open-gsd/gsd-core (GitHub repo)
- GSD-redux/get-shit-done-redux → open-gsd/gsd-core (stale badge org)
- bare bin/clone refs → gsd-core

CHANGELOG.md, docs/adr/**, docs/RELEASE-*.md, docs/research/**,
and .changeset/** are preserved byte-identical.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix: add negative lookbehind to slash-command regex in bug-2954 test

The extractSlashReferences regex matched /gsd-core inside npm package
URLs (@opengsd/gsd-core), producing a false /gsd:core command reference.
Adding a negative lookbehind (?<![a-z]) excludes matches preceded by a
letter, so only standalone /gsd-<cmd> and /gsd:<cmd> tokens are found.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore(#518): add changeset for package rename

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#518): update package-identity expectations to the renamed coordinates

The rebase regenerated the seam to @opengsd/gsd-core (bin gsd-core, repo
open-gsd/gsd-core). The #498 seam tests assert deriveIdentity against the REAL
package.json, so their expected literals must follow the rename. The drift-lint
unit test is left as-is — its SEAM is a self-consistent fixture and its
stale-literal detection cases would shift if altered; the live-repo scan in it
already passes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-30 17:25:02 -04:00

2.1 KiB

PRD: README Continuity And Release Communications Update

Linked Issue

  • Closes #209

Problem

The top-level README still mixes legacy transition language, personal attribution, and outdated migration framing. Users need one clear source of truth for:

  • canonical repository and package identities
  • current maintainer ownership/governance
  • migration guidance away from legacy upstream artifacts
  • security and audit status references

Goals

  1. Remove legacy personal maintainer attribution from README narrative sections.
  2. Present open-gsd continuity messaging in concise, team-owned language.
  3. Provide explicit migration guidance from legacy packages to @opengsd/*.
  4. Reference public announcement and security-audit discussions directly.
  5. Keep changes docs-only and non-behavioral.

Non-Goals

  • Any runtime, CLI, or workflow behavior changes.
  • Any package publishing process changes.
  • Any new security policy implementation beyond documentation updates.

Scope

  • README.md top continuity notice
  • README.md "Why" narrative section rewrite
  • release/continuity cross-links and wording cleanup

User Stories

  • As a new user, I can quickly identify which repo/package is canonical.
  • As an existing user, I can safely migrate away from legacy package names.
  • As a security-conscious user, I can find the public audit status and continuity rationale in one place.

Acceptance Criteria

  1. README contains a continuity notice naming open-gsd/gsd-core as canonical.
  2. README removes personal legacy attribution in origin-story prose.
  3. README strongly recommends migration away from legacy artifacts.
  4. README links to Discussions #109 and #119.
  5. README states current audit posture with "no known active exploit" language.

Risks

  • Overstating security claims beyond published evidence.
    • Mitigation: keep wording scoped to publicly posted announcement text.
  • Migration warning language may be interpreted as policy rather than recommendation.
    • Mitigation: phrase as a strong recommendation based on ownership and governance reality.

Rollout

  1. Update README content.
  2. Open docs PR linked to #209.
  3. Run CI and merge once green.