* chore: rename npm package + bin to @opengsd/gsd-core (functional) - package.json: name @opengsd/get-shit-done-redux → @opengsd/gsd-core, bin key get-shit-done-redux → gsd-core, repository/homepage/bugs URLs - package-lock.json: regenerated (npm install --package-lock-only) - tests/**, scripts/**, bin/**, .github/**, agents/**, commands/**, get-shit-done/bin/**, get-shit-done/workflows/**: applied the 4-rule replacement (scoped npm ref, GitHub repo path, bin/clone invocations) per #505 single-source refactor Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs: sweep live references to @opengsd/gsd-core Update all live documentation (README.md + translations, docs/**, CONTRIBUTING.md, VERSIONING.md, SECURITY.md, CONTEXT.md, docs/CANARY.md) to reflect the renamed package and repository. Rules applied: - @opengsd/get-shit-done-redux → @opengsd/gsd-core (scoped npm name) - open-gsd/get-shit-done-redux → open-gsd/gsd-core (GitHub repo) - GSD-redux/get-shit-done-redux → open-gsd/gsd-core (stale badge org) - bare bin/clone refs → gsd-core CHANGELOG.md, docs/adr/**, docs/RELEASE-*.md, docs/research/**, and .changeset/** are preserved byte-identical. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix: add negative lookbehind to slash-command regex in bug-2954 test The extractSlashReferences regex matched /gsd-core inside npm package URLs (@opengsd/gsd-core), producing a false /gsd:core command reference. Adding a negative lookbehind (?<![a-z]) excludes matches preceded by a letter, so only standalone /gsd-<cmd> and /gsd:<cmd> tokens are found. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore(#518): add changeset for package rename Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(#518): update package-identity expectations to the renamed coordinates The rebase regenerated the seam to @opengsd/gsd-core (bin gsd-core, repo open-gsd/gsd-core). The #498 seam tests assert deriveIdentity against the REAL package.json, so their expected literals must follow the rename. The drift-lint unit test is left as-is — its SEAM is a self-consistent fixture and its stale-literal detection cases would shift if altered; the live-repo scan in it already passes. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
62 lines
2.1 KiB
Markdown
62 lines
2.1 KiB
Markdown
# PRD: README Continuity And Release Communications Update
|
|
|
|
## Linked Issue
|
|
|
|
- Closes #209
|
|
|
|
## Problem
|
|
|
|
The top-level README still mixes legacy transition language, personal attribution, and outdated migration framing. Users need one clear source of truth for:
|
|
|
|
- canonical repository and package identities
|
|
- current maintainer ownership/governance
|
|
- migration guidance away from legacy upstream artifacts
|
|
- security and audit status references
|
|
|
|
## Goals
|
|
|
|
1. Remove legacy personal maintainer attribution from README narrative sections.
|
|
2. Present open-gsd continuity messaging in concise, team-owned language.
|
|
3. Provide explicit migration guidance from legacy packages to `@opengsd/*`.
|
|
4. Reference public announcement and security-audit discussions directly.
|
|
5. Keep changes docs-only and non-behavioral.
|
|
|
|
## Non-Goals
|
|
|
|
- Any runtime, CLI, or workflow behavior changes.
|
|
- Any package publishing process changes.
|
|
- Any new security policy implementation beyond documentation updates.
|
|
|
|
## Scope
|
|
|
|
- `README.md` top continuity notice
|
|
- `README.md` "Why" narrative section rewrite
|
|
- release/continuity cross-links and wording cleanup
|
|
|
|
## User Stories
|
|
|
|
- As a new user, I can quickly identify which repo/package is canonical.
|
|
- As an existing user, I can safely migrate away from legacy package names.
|
|
- As a security-conscious user, I can find the public audit status and continuity rationale in one place.
|
|
|
|
## Acceptance Criteria
|
|
|
|
1. README contains a continuity notice naming `open-gsd/gsd-core` as canonical.
|
|
2. README removes personal legacy attribution in origin-story prose.
|
|
3. README strongly recommends migration away from legacy artifacts.
|
|
4. README links to Discussions #109 and #119.
|
|
5. README states current audit posture with "no known active exploit" language.
|
|
|
|
## Risks
|
|
|
|
- Overstating security claims beyond published evidence.
|
|
- Mitigation: keep wording scoped to publicly posted announcement text.
|
|
- Migration warning language may be interpreted as policy rather than recommendation.
|
|
- Mitigation: phrase as a strong recommendation based on ownership and governance reality.
|
|
|
|
## Rollout
|
|
|
|
1. Update README content.
|
|
2. Open docs PR linked to #209.
|
|
3. Run CI and merge once green.
|