Files
msd-core/.changeset/archived/3589-planning-paths-workstream-validation.md
Tom Boucher 8616839cab chore: archive 463 shipped changeset fragments before wiring render (#714)
CHANGELOG promotion was a manual operator step that was never run, so 463
fragments for work already shipped in <=1.3.1 accumulated in .changeset/.
Their notes were already hand-curated into the dated [1.2.0]/[1.3.0]/[1.3.1]
CHANGELOG sections (#690 backfill, PR #694). Rendering them now would
duplicate and mis-attribute shipped work.

Move them to .changeset/archived/ (read non-recursively by all changeset
tooling, so never rendered), keeping only the 3 genuinely-unreleased
fragments at the top level. Prep for wiring `render` into the release
finalize job (#690 follow-up).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-05 14:53:17 -04:00

750 B

type, issue
type issue
Security 3589

relPlanningPath() now validates explicit workstream names — direct SDK callers passing a workstream argument to relPlanningPath, planningPaths, or ContextEngine previously had no path-traversal gate. A value like '../../../outside' flowed through posix.join('.planning', 'workstreams', name) and routed planning operations outside the intended .planning/workstreams/<name> subtree. The fix runs the shared validateWorkstreamName policy inside relPlanningPath so every consumer fails closed at the same seam. Env-sourced workstreams continue to fall back silently to root .planning/ per the #2791 contract (they are filtered to null by planningPaths before reaching relPlanningPath).