Security-motivated migration of all stale repository and npm-scope references. Three categories of changes (58 files, 174 substitutions): 1. gsd-build → open-gsd (security-critical): - .github/workflows/release-sdk.yml — npm token comment, tarball filename pattern - .github/workflows/hotfix.yml — same - .changeset/fix-3406-detect-stale-sdk-shadow.md — @gsd-build/sdk → @open-gsd/sdk - .changeset/sharp-quails-leap.md — same - get-shit-done/workflows/update.md — CHANGELOG raw GitHub URL 2. GSD-redux org slug → open-gsd (canonical rename): - package.json + sdk/package.json — repository/homepage/bugs metadata - All README.*.md — live badge and link sections - CONTRIBUTING.md, CONTEXT.md, QUICK-WINS-CONFIRMED-BUGS.md - .coderabbit.yaml, .release-monitor.sh, scripts/sync-rulesets.sh - docs/** — all live agent/ADR/user-facing documentation - tests/** — repo slug assertions and test fixtures - scripts/changeset/cli.cjs + github-release-notes.cjs - .github/ISSUE_TEMPLATE/*, .github/pull_request_template.md - bin/install.js, get-shit-done/bin/lib/model-catalog.cjs - sdk/HANDOVER-*.md, sdk/src/*.test.ts 3. CLAUDE.md (gitignored local file — not in this commit): Updated separately outside git: --repo gsd-build/get-shit-done → --repo open-gsd/get-shit-done-redux with security warning. Intentionally unchanged: CHANGELOG.md, docs/RELEASE-*.md, .changeset/README.md, .changeset/build-hooks-atomic-write.md, README.md migration table (historical fork record), tests/changeset-serialize.test.cjs line 78 (serialization fixture). The gsd-build/get-shit-done repo is compromised (rug-pull documented in README.md). Do not push to or interact with that repo. Closes #120
37 lines
1.6 KiB
YAML
37 lines
1.6 KiB
YAML
# CodeRabbit configuration — open-gsd/get-shit-done-redux
|
|
#
|
|
# Schema: https://docs.coderabbit.ai/reference/yaml-template/
|
|
#
|
|
# Project context: GSD ships a CLI tool + an agent runtime, not a documented
|
|
# public library. We carry rich JSDoc on internal helpers that warrant it
|
|
# (see bin/install.js, get-shit-done/bin/lib/*.cjs) but we do not enforce a
|
|
# blanket docstring coverage bar — see issue #2932 for rationale.
|
|
|
|
reviews:
|
|
pre_merge_checks:
|
|
# Disable docstring coverage check.
|
|
#
|
|
# The check produces false-positive warnings on PRs whose new code is
|
|
# entirely test files: it counts test(...) / beforeEach / afterEach
|
|
# arrow-function callbacks as functions and then reports 0% coverage
|
|
# because nothing has JSDoc. There is no per-check path filter in CR's
|
|
# documented schema that would let us exclude tests/** while keeping
|
|
# the check active elsewhere, and the top-level path_filters approach
|
|
# would silence ALL CR review on tests (security scans, out-of-scope
|
|
# checks, line-level findings) which we want to keep.
|
|
#
|
|
# All other CR pre-merge checks (out-of-scope, security, title) remain
|
|
# at their defaults.
|
|
docstrings:
|
|
mode: off
|
|
|
|
tools:
|
|
# Disable ESLint. The repo intentionally does not use ESLint — it ships
|
|
# its own targeted lint scripts (scripts/lint-no-source-grep.cjs, plus
|
|
# the `lint:tests` npm script) that enforce repo-specific test-quality
|
|
# invariants. Adding ESLint config purely to satisfy CR would add an
|
|
# external dependency (CONTRIBUTING.md: "No external dependencies in
|
|
# core") and overlap with the existing custom lint surface.
|
|
eslint:
|
|
enabled: false
|