Files
msd-core/.changeset/archived/3628-bundled-hook-whitelist.md
Tom Boucher 8616839cab chore: archive 463 shipped changeset fragments before wiring render (#714)
CHANGELOG promotion was a manual operator step that was never run, so 463
fragments for work already shipped in <=1.3.1 accumulated in .changeset/.
Their notes were already hand-curated into the dated [1.2.0]/[1.3.0]/[1.3.1]
CHANGELOG sections (#690 backfill, PR #694). Rendering them now would
duplicate and mis-attribute shipped work.

Move them to .changeset/archived/ (read non-recursively by all changeset
tooling, so never rendered), keeping only the 3 genuinely-unreleased
fragments at the top level. Prep for wiring `render` into the release
finalize job (#690 follow-up).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-05 14:53:17 -04:00

901 B

type, issue
type issue
Security 3628

Installer no longer auto-removes user-authored or retired hooks/gsd-* files — the bundled-gsd-hook classifier added in #3610 used a shape regex (/^hooks\/gsd-[^/]+\.(?:js|sh|cjs|mjs)$/) that matched any file with that naming shape, not only the 13 hooks actually shipped in the npm package. User-authored custom hooks (e.g. hooks/gsd-personal-experiment.js) and retired bundled hooks from prior versions were silently auto-classified and removed on first-time-baseline scan. The classifier now whitelists the explicit set of shipped hook filenames (BUNDLED_GSD_HOOK_FILES); files outside the whitelist fall through to the existing block-or-prompt flow so the user retains control. A drift guard in tests/bug-3628-bundled-hook-classifier-whitelist.test.cjs fails CI if the whitelist diverges from the on-disk hooks/ directory in either direction.