* chore(npm): rebrand packages to @opengsd scope Rename: - get-shit-done-redux → @opengsd/get-shit-done-redux - @gsd-redux/sdk → @opengsd/gsd-sdk Add publishConfig.access=public for first-time scoped publish. CLI binary names (get-shit-done-redux, gsd-sdk, gsd-tools) unchanged. Sweeps install commands, npx invocations, CI publish/version-check workflows, tests, docs, READMEs (all translations), and the PACKAGE_NAME constant in check-latest-version. Bumps qs 6.15.1 → 6.15.2 to clear a moderate advisory surfaced by the audit-clean test (GHSA-q8mj-m7cp-5q26). Closes #126 * chore: pin 2.0.0 release + remove canary workflow - Bump both packages 1.50.0-canary.0 → 2.0.0 for first @opengsd publish - Remove .github/workflows/canary.yml and canary dist-tag handling in release.yml / release-sdk.yml - Drop canary section from VERSIONING.md Refs #126 * chore: address review findings + harden tarball-smoke timeout - .changeset/opengsd-org-rename.md: match project's custom parse.cjs frontmatter (type: Changed / pr: 127); the scoped @changesets/cli keys were silently rejected. - CONTEXT.md: drop two canary-stream policy lines and a dangling DEFECT.CANARY-VERSION-LEAK.cross-ref now that canary.yml is gone. - tests/release-tarball-smoke.install.test.cjs: pass timeout: 600_000 for npm pack + global install; the 3-minute runNpm default was timing out on slower Docker hosts (cartographer). Refs #126 * fix(sdk): add missing type/runtime devDependencies for build prepublishOnly invokes tsc which couldn't resolve @types/node, @types/ws, or synckit. They had been hoisted from root but were not declared in sdk/'s own package.json — first publish from a clean SDK tree failed. Refs #126 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(ci): use npm pack stdout instead of glob to find tarball `npm pack --silent` for a scoped package (@opengsd/get-shit-done-redux) produces `opengsd-get-shit-done-redux-*.tgz`, not `get-shit-done-redux-*.tgz`. Capture the filename from stdout instead of a hardcoded glob so the step works regardless of package name format. Fixes smoke (ubuntu-latest, 22, false) CI failure. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * ci: treat workflow-file changes as test-skip eligible `.github/workflows/install-smoke.yml` (and other workflow files) were in neither `test.yml` paths nor `test-skip.yml` paths-ignore, so neither workflow ran on a workflow-only commit — leaving the required test-skip check perpetually missing. Refs #126 * chore: reset version to 1.0.0 for first @opengsd publish Nothing has been published yet under the @opengsd scope, so the inaugural release uses 1.0.0 rather than 2.0.0. The "major bump" in the changeset reflects the breaking install-command change for users migrating from the prior unscoped `get-shit-done-redux`, not a numeric continuation from a 1.x line under the new identity. Refs #126 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
7.0 KiB
v1.42.0-rc.1 Release Notes
First release candidate for the 1.42.0 train. Published to npm under the next dist-tag.
npx @opengsd/get-shit-done-redux@next
# or pin exact:
npm install -g @opengsd/get-shit-done-redux@1.42.0-rc1
Release-candidate stream caveat. RCs come from
mainand are the staging stream for the next stablelatest. They are stable enough for everyday use but may carry bake items resolved before the matchingvX.Y.0is published. See CANARY.md for the stream policy.
What's in this release
1.42.0-rc.1 is the first cut of the 1.42 train. The headline addition is a package legitimacy gate against slopsquatting — a three-layer defense across the research → plan → execute pipeline that prevents AI-hallucinated package names from flowing undetected into npm install. Underneath that, two structural refactors deepen the SDK package seam and the phase lifecycle seams so future work has cleaner module boundaries.
This RC also rolls up every fix that shipped in v1.41.1. Those fixes are listed in the v1.41.1 notes and on the GitHub release page; this document is scoped to the new features in 1.42.0.
Added
Security
Package legitimacy gate against slopsquatting (#3215)
A three-layer defense across the research → plan → execute pipeline. Before this release, a hallucinated package name that passed npm view could flow undetected into gsd-executor running npm install <malicious-pkg> with no human gate. The gate closes that path:
- Layer 1 — Researcher (
agents/gsd-phase-researcher.md). A new<package_legitimacy_protocol>block runsslopcheck install <pkgs> --jsonover every recommended package, performs ecosystem-specific verification (pip index versions/npm view/cargo search), and emits a## Package Legitimacy Audittable toRESEARCH.mdwith Package, Registry, Age, Downloads, Source Repo, slopcheck, and Disposition columns. Packages discovered solely through WebSearch are tagged[ASSUMED]— never[VERIFIED].[SLOP]packages are removed from RESEARCH.md and listed under "Packages removed due to slopcheck." - Layer 2 — Planner (
agents/gsd-planner.md). Reads the Audit table and inserts acheckpoint:human-verifytask before any install whose package is tagged[ASSUMED]or[SUS]. Plans that introduce installs gain aT-{phase}-SCTampering / supply-chain row in their<threat_model>template. - Layer 3 — Executor (
agents/gsd-executor.md). RULE 3 amended: package installs (npm/pip/cargo) are excluded from auto-fix scope. Failed installs becomecheckpoint:human-verifywith a slopsquatting-risk rationale instead of being silently retried.
Hardening. Every npx --yes <pkg>@latest invocation across the three agent files is replaced with a command -v <bin> guard pattern — this closes the same fetch-and-execute hole npx --yes opens.
Graceful degradation. When slopcheck is unavailable at research time, every recommended package is tagged [ASSUMED] and gated with a checkpoint, so the protective behavior degrades safely instead of bypassing the gate.
Documentation. docs/USER-GUIDE.md has a new "Package Legitimacy Gate" subsection in the Security section; docs/COMMANDS.md notes the gate on /gsd-plan-phase; docs/ARCHITECTURE.md documents the gate before the Security Hooks section and updates the plan-phase pipeline diagram with the gate steps.
Closes #2827.
Changed
Architecture
SDK package seam deepened; runtime-global skills policy converged (#3238)
Concentrates two areas that were previously scattered across the codebase:
- SDK Package Seam Module. Legacy package and install-layout compatibility — previously leaked across
state-project-load,verify,roadmap, prompt-loading paths,agent-skills,skill-manifest, andgenerateDevPreferences— is now centralized behind a single Module. Callers consume legacy-asset discovery and install-layout probing through a thin Adapter; transition-only error messaging lives in one place. - Runtime-Global Skills Policy Module. A single runtime-aware global-skills directory policy is now shared by SDK and CJS callers. Resolves runtime-global skills bases and skill paths from the runtime + env precedence chain, renders display paths for warnings/manifests, and reports unsupported runtimes that lack a skills directory.
The CONTEXT.md domain glossary is updated with both Module entries so future work points at the canonical seams instead of re-deriving the boundaries.
Phase lifecycle seams deepened (#3267)
phase-lifecycle.ts becomes a thin public orchestrator. Three new modules are extracted:
- Phase Numbering Policy Module. Phase-name and project-code validation, slug/ID generation, sequential and decimal phase progression, and roadmap-entry construction.
- Phase Filesystem Adapter Module. Directory listing, gitkeep creation, and archive operations for phase directories.
- Phase Roadmap Mutation Module.
replaceInCurrentMilestoneand atomic ROADMAP.md read-modify-write under planning lock.
Backward-compatible re-exports are preserved on phase-lifecycle.ts so existing callers continue to work; new callers should import from the dedicated modules.
Closes #3270.
What was in 1.41.x
- v1.41.1 — 14-fix hotfix: phase-plan-index DAG correctness, state-snapshot YAML frontmatter precedence, code-review SUMMARY parser hardening (
BL-/blocker:accepted as Critical-tier), Codex install TOML floats + idempotent rollback, persistent SDK reachability probe, shared model-catalog source of truth (ADR-0003), and more. - v1.41.0 — six namespace meta-skills,
/gsd-health --contextutilization guard,--minimalinstall flag,/gsd-edit-phase, post-merge build & test gate, manual canary release workflow, and 25+ correctness fixes. SeeRELEASE-v1.41.0.md.
Installing
# npm (global, RC channel)
npm install -g @opengsd/get-shit-done-redux@next
# npx (one-shot)
npx @opengsd/get-shit-done-redux@next
# Pin to this exact RC
npm install -g @opengsd/get-shit-done-redux@1.42.0-rc1
The installer is idempotent — re-running on an existing install updates in-place, preserving your .planning/ directory and local patches.
To roll back to the latest stable, install with @latest:
npx @opengsd/get-shit-done-redux@latest