chore: migrate references from gsd-build to open-gsd/get-shit-done-redux (#120) (#121)
Security-motivated migration of all stale repository and npm-scope references.
Three categories of changes (58 files, 174 substitutions):
1. gsd-build → open-gsd (security-critical):
- .github/workflows/release-sdk.yml — npm token comment, tarball filename pattern
- .github/workflows/hotfix.yml — same
- .changeset/fix-3406-detect-stale-sdk-shadow.md — @gsd-build/sdk → @open-gsd/sdk
- .changeset/sharp-quails-leap.md — same
- get-shit-done/workflows/update.md — CHANGELOG raw GitHub URL
2. GSD-redux org slug → open-gsd (canonical rename):
- package.json + sdk/package.json — repository/homepage/bugs metadata
- All README.*.md — live badge and link sections
- CONTRIBUTING.md, CONTEXT.md, QUICK-WINS-CONFIRMED-BUGS.md
- .coderabbit.yaml, .release-monitor.sh, scripts/sync-rulesets.sh
- docs/** — all live agent/ADR/user-facing documentation
- tests/** — repo slug assertions and test fixtures
- scripts/changeset/cli.cjs + github-release-notes.cjs
- .github/ISSUE_TEMPLATE/*, .github/pull_request_template.md
- bin/install.js, get-shit-done/bin/lib/model-catalog.cjs
- sdk/HANDOVER-*.md, sdk/src/*.test.ts
3. CLAUDE.md (gitignored local file — not in this commit):
Updated separately outside git: --repo gsd-build/get-shit-done →
--repo open-gsd/get-shit-done-redux with security warning.
Intentionally unchanged: CHANGELOG.md, docs/RELEASE-*.md,
.changeset/README.md, .changeset/build-hooks-atomic-write.md,
README.md migration table (historical fork record),
tests/changeset-serialize.test.cjs line 78 (serialization fixture).
The gsd-build/get-shit-done repo is compromised (rug-pull documented in
README.md). Do not push to or interact with that repo.
Closes #120