* fix(#3726): require --confirm before milestone complete mutates `milestone complete <version>` is a one-way door — ROADMAP.md and REQUIREMENTS.md archived, every phase directory in the milestone MOVED, STATE.md rewritten — and ran unconditionally on first invocation through every invocation path, including `query milestone.complete <version>`, whose `query` meta-prefix reads as a read-only namespace but performs no filtering (#167's invocation-compatibility shim + #3243's dotted-form normalization). The gate lives on the destructive command itself, not on the `query` prefix (the prefix is an intentional invocation mechanism, not a permission boundary — restricting it would break dozens of shipped workflow callers). Without --confirm and without --dry-run the command now refuses via error() before reading anything beyond its arg checks, so an unconfirmed invocation is a guaranteed no-op on disk. --dry-run still previews with no confirmation needed and is now documented in the usage block (it was only documented for the sibling archive-quick). --force keeps its narrow meaning — bypassing the TRUNCATED-scope and unstarted-phase guards — and does not double as the mutation opt-in. --confirm follows the existing `phases clear --confirm` idiom in the same module. complete-milestone.md's two invocations pass --confirm (the workflow has gathered explicit user intent by that step). Existing tests get --confirm appended — pre-change behavior is exactly confirmed behavior — and a #3726 regression block covers: refusal + full-tree byte-identity on both invocation forms, --force not satisfying the gate, --dry-run still passing without confirmation, and --confirm proceeding. The refusal tests fail against pre-fix code (negative control run). Fixes #3726 * docs(#3726): document the --confirm requirement in CLI-TOOLS and COMMANDS Cross-AI review of the fix diff (codex, pre-create) caught three shipped doc sites still instructing the now-refused bare invocation: the CLI-TOOLS.md milestone-complete synopsis + flag table, and COMMANDS.md's two guard-override instructions (`--force` alone now refuses without --confirm). Localized CLI-TOOLS copies already lag the English synopsis (no --force/--dry-run either) and follow the translation pipeline, not this fix. * chore(#3726): set changeset fragment pr to 3774 * test(#3726): confirm-gate CI repairs — QA scenario caller + growth ack Two CI reds from the --confirm gate, both this branch's own misses: - tests/qa/scenarios/milestone-rollover.json invoked `milestone complete 1.0 --force` as a JSON arg-array fixture — a caller shape the test sweep (which grepped runGsdTools/runSdkQuery in tests/*.cjs) never enumerated. Adds --confirm; the scenario's boundary-crossing contract is otherwise untouched. - complete-milestone.md's +420-byte --confirm note trips the emitted-attribution growth ratchet. Acknowledged as a #3726 append to the existing complete-milestone.md entry in 3409-unreachable-guard-arms.json (two ack sources may never name the same path, per that fragment's own precedent). Local: lint-emitted-drift-ack ok; loop-walk.qa 115/115 green sandboxed. * docs(#3726): CLI-TOOLS.md guard-override sentences say --force --confirm Review Major 1: the truncated-window and unstarted-phase guard paragraphs still told the reader to "Pass `--force` to override", which now refuses (--force alone does not satisfy the confirmation gate), while the flag table 470 lines later said the opposite. Mirror the docs/COMMANDS.md pair so the file no longer contradicts itself. * docs(#3726): synopsis renders --confirm and --dry-run as alternatives Review Nit 1: `milestone complete <version> --confirm [--dry-run]` read as "a dry run still needs --confirm", the opposite of AC 3. Render the pair as `(--confirm | --dry-run)` in the CLI-TOOLS.md synopsis and the usage docblock, and let the flag rows carry the rule. * test(#3726): pass --confirm in base-added milestone fixtures; re-file the growth ack Rebase onto next (26 commits) surfaced three tests the gate now refuses: the #3685 write-flag contract pair in tests/milestone.test.cjs and the `milestone complete` boundary fixture in tests/state-contract.test.cjs all invoke the command bare. Each now passes --confirm (a mutating run is exactly what they assert on). The +420 byte complete-milestone.md growth ack rode on 3409-unreachable-guard-arms.json, which #3078 swept from next as fully spent — hence the modify/delete conflict. Re-filed under a fresh fragment named for this issue, never resurrecting the swept one. * test(#3726): pin the present-but-falsy arm of the confirmation gate Review Minor 1: the boundary triple covered absent and present but not present-but-falsy. The gate is an exact-token match, so --confirm=false and --confirm=0 refuse today — pinned (canonical + query forms, whole .planning/ tree byte-identical) so a future `=`-aware or prefix-matching parser cannot silently turn --confirm=false into a confirmed run of an irreversible command. * test(#3726): drop --confirm from dry-run-only invocations Review Nit 2: --confirm was mass-appended to 14 pre-existing --dry-run invocations that never needed it, so each stopped standing as incidental proof that a preview needs no confirmation. Reverted to the pre-PR form; the dedicated AC-3 test carries the explicit assertion. * docs(#3726): sync the localized CLI-TOOLS synopsis with the confirm gate REQ-I18N-02 (docs/features/internationalized-documentation.md) requires translations to stay synchronized with the English source. The four localized CLI-TOOLS.md guides still advertised a bare `milestone complete <version>`, which now exits 1. Render the English synopsis verbatim — `(--confirm | --dry-run)` plus the `[--force]` and `[--archive-quick]` flags the translations had also fallen behind on. * test(#3726): drop --confirm from the remaining preview-only invocations Round 2 reverted the --confirm appends on --dry-run-only invocations in tests/milestone.test.cjs, but four more sat in two files the sweep missed: tests/milestone-archive.test.cjs (three) and tests/milestone-window-single-owner.test.cjs (one). Each is a preview run whose whole purpose is to document that a preview mutates nothing, so `--dry-run ... --confirm` contradicted the semantics the test exists to pin. Dropping the token restores each as incidental proof that a preview needs no confirmation; the dedicated AC-3 test keeps the explicit assertion. No assertion added, relaxed, or removed — the change is four tokens. * chore(#3726): migrate the emitted-drift ack from a fragment to a commit trailer #3954 (ADR-3942) moved emitted-drift acknowledgments out of tests/emitted-drift-acks/ and into git commit trailers, and the fragment directory no longer exists on next. The reason this PR's fragment carried moves verbatim into the Emitted-Drift-Ack-Growth trailer on this commit; the fragment file is removed rather than resurrected. Emitted-Drift-Ack-Growth: complete-milestone.md — #3726: +420 bytes (40186 -> 40606). The archive_milestone step's two `milestone complete` invocations now pass the required --confirm flag (the command refuses to mutate without it — the archive is irreversible), with a note explaining the flag and pointing at --dry-run for previews. Deliberate runtime-loaded workflow text for the new gate, not converter drift. * fix(#3726): name --confirm in the version-required refusal The documented arg-discovery path (gsd-tools.cjs top-level usage: invoke the command without args and the error lists what is required) stopped at `version required for milestone complete (e.g., v1.0)` — one required argument short. Discovering --confirm took a second round trip through the gate. The refusal now reads `… — and --confirm to mutate`, pinned by a test that also asserts the version-less invocation leaves .planning/ untouched. * test(#3726): pin the milestone complete docs against a silent regression The changeset is `type: Fixed`, which the docs-required lint exempts, so nothing in CI would notice a later edit that reinstated the bare-`--force` override prose or dropped `--confirm` from the synopsis. Four tests in tests/milestone.test.cjs now pin: the synopsis line in docs/CLI-TOOLS.md and its four localized mirrors; the `--confirm` flag row; both guard-override instructions in docs/CLI-TOOLS.md and docs/COMMANDS.md, by guard name (a substring match on each instruction's `--force --confirm` text); and — as an identity ratchet over the milestone-complete sections — every `--force` sentence or clause that lacks `--confirm`, so a new bare instruction in its own sentence or clause fails whatever its wording. Named residual: a bare instruction spliced into the same clause as a compliant one coalesces with it and passes the ratchet; the by-name pins are what keep the four known instructions from losing the pairing that way. The file is registered in scripts/docs-guard-registry.cjs so the pin runs on the PR that changes those docs, not only after merge. --------- Co-authored-by: CI Rebase Check <ci@gsd-redux> Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
GSD Core 문서
문서는 네 가지 유형으로 구성됩니다. 튜토리얼은 직접 해보며 배우고, how-to 가이드는 특정 작업을 해결하며, 레퍼런스는 권위 있는 사실을 제시하고, 설명은 개념과 설계 결정을 탐구합니다.
언어 버전: English · Português (pt-BR) · 日本語 · 简体中文 · 한국어
튜토리얼
- 첫 번째 프로젝트 — 설치부터 첫 단계 출시까지, 확실한 한 가지 경로
- 기존 코드베이스 온보딩 — 기존 저장소에 GSD Core 적용하기
How-to guides
- 런타임에 설치하기 — 지원하는 15개 런타임 각각의 설치 단계
- 단계 논의하기 — 기획 시작 전 구현 결정 사항 정리
- 단계 기획하기 — 리서치 실행, 작업 분해, 플랜 품질 검증
- 단계 실행하기 — 새 컨텍스트 서브에이전트로 병렬 웨이브 실행
- 검증 및 출시 — 완료된 작업 검토, 오류 진단, PR 생성
- 단계 자율 실행하기 — 무인 단계 실행을 위한 자율 모드 사용
- 빠른 임시 작업 처리 — 단계 루프 외 임시 작업에
/gsd-quick과/gsd-fast활용 - 모델 프로필 설정 — 고품질, 균형, 예산 모델 티어 전환
- 크로스 AI 리뷰 설정 — 주 에이전트가 생성한 코드를 두 번째 AI가 검토하도록 설정
- 워크스트림으로 병렬 작업 — 워크스트림을 사용해 독립적인 작업 라인 동시 실행
- 워크스페이스로 작업 격리 — 워크스페이스로 실험적이거나 위험한 변경 사항 샌드박스 처리
- 실패한 실행 디버깅 — 깨지거나 불완전한 단계 실행 진단 및 복구
- 스파이크와 스케치 — 플랜 확정 전 탐색 작업에
/gsd-spike와/gsd-sketch활용 - UI 단계 설계 — 프론트엔드 및 시각적 작업에 UI 단계 루프 활용
- 트래커 이슈로 GSD 구동 — GitHub, Linear, Jira 이슈에서 단계 시작
- GSD 2에서 마이그레이션 — 기존 GSD 2 프로젝트를 GSD Core로 업그레이드
- GSD 업데이트 — 설치 프로그램을 재실행해 최신 릴리스 적용
- 복구 및 문제 해결 — 일반적인 문제 해결, 컨텍스트 재구축, 제거
레퍼런스
- 명령어 — 플래그와 예제가 포함된 모든 명령어
- 설정 — 전체 설정 스키마, 모델 프로필, git 브랜칭 전략
- CLI 도구 — 워크플로우와 에이전트를 위한
gsd-tools.cjs프로그래밍 API - 기능 — 전체 기능 색인
- 인벤토리 — 설치된 스킬과 서피스 맵
- STATE.md 스키마 —
.planning/STATE.md필드별 레퍼런스 - CONTEXT.md 스키마 —
.planning/phases/<N>/CONTEXT.md필드별 레퍼런스 - PLAN.md 스키마 —
.planning/phases/<N>/PLAN.md필드별 레퍼런스 - 기획 아티팩트 — 모든
.planning/파일과 역할
설명
- 컨텍스트 엔지니어링 — 컨텍스트 rot가 형성되는 방식과 GSD Core의 방지 방법
- 단계 루프 — 논의 → 기획 → 실행 → 검증 → 출시 사이클의 설계 근거
- 멀티 에이전트 오케스트레이션 — 서브에이전트의 생성, 범위 지정, 조율 방식
- 보안 모델 — 신뢰 경계, 권한, 안전한 자동화
- 아키텍처 — 시스템 아키텍처, 에이전트 모델, 데이터 흐름
- 논의 모드 —
/gsd-discuss-phase의 가정 모드와 인터뷰 모드 - 컨텍스트 모니터링 — 컨텍스트 창 모니터링 훅 아키텍처
- 이슈 기반 오케스트레이션 — 기존 프리미티브를 사용해 트래커 이슈로 GSD를 구동하는 레시피