* fix(#663): resolve open CodeQL/Dependabot security alerts - ReDoS: collapse ambiguous nested quantifiers in phase-heading regexes (verify/validate/commands) and the plan-filename lookahead (phase) to provably-equivalent non-backtracking forms - prototype pollution: guard __proto__/constructor/prototype in setConfigValue - remove dead no-op .replace(/-/g,'-') in phase.cts - escape all regex metachars in bug-2839 test - add contents:read permissions to security-scan + install-smoke workflows - pin qs >= 6.15.2 via overrides (DoS GHSA) - broaden prompt-injection allowlist to translated security-model docs Closes #663 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(#663): regression tests for prototype-pollution guard and roadmap-phase ReDoS Behavioral test that config-set rejects __proto__/constructor/prototype keys without polluting Object.prototype, plus a ReDoS guard (timing-bound) and behavior-preservation assertions for the collapsed phase-heading regexes. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(#663): make ReDoS regression assert structured result, not elapsed time Replace elapsed-time assertions (which tripped local/no-elapsed-assertion ESLint rule and were unsound for synchronous ReDoS) with structured-result assertions on adversarial inputs: assert that malformed phase headings/ unchecked-item lines without a terminating colon/space yield an empty Set, which is both the correct behavior and an exercise of the fixed linear regex on the catastrophic-backtracking input shape. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore(#663): add Security changeset fragment for #665 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(#663): fold prototype-pollution regression into config.test.cjs The standalone bug-663-config-prototype-pollution.test.cjs was a 9th config-module test file, tripping lint-test-file-count (the allowlist is ratcheted and must not grow). Consolidated into config.test.cjs instead. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
112 lines
4.0 KiB
JSON
112 lines
4.0 KiB
JSON
{
|
|
"name": "@opengsd/gsd-core",
|
|
"version": "1.2.0",
|
|
"description": "GSD Core is a meta-prompting, context engineering, and spec-driven development system for AI coding agents.",
|
|
"bin": {
|
|
"gsd-core": "bin/install.js",
|
|
"gsd-tools": "gsd-core/bin/gsd-tools.cjs"
|
|
},
|
|
"files": [
|
|
"bin",
|
|
"commands",
|
|
"gsd-core",
|
|
"assets",
|
|
"agents",
|
|
"hooks",
|
|
"scripts"
|
|
],
|
|
"keywords": [
|
|
"claude",
|
|
"claude-code",
|
|
"ai",
|
|
"meta-prompting",
|
|
"context-engineering",
|
|
"spec-driven-development",
|
|
"gemini",
|
|
"gemini-cli",
|
|
"codex",
|
|
"codex-cli"
|
|
],
|
|
"author": "OpenGSD",
|
|
"license": "MIT",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "git+https://github.com/open-gsd/gsd-core.git"
|
|
},
|
|
"homepage": "https://github.com/open-gsd/gsd-core",
|
|
"bugs": {
|
|
"url": "https://github.com/open-gsd/gsd-core/issues"
|
|
},
|
|
"publishConfig": {
|
|
"access": "public"
|
|
},
|
|
"engines": {
|
|
"node": ">=22.0.0",
|
|
"npm": ">=10.0.0"
|
|
},
|
|
"dependencies": {
|
|
"@anthropic-ai/claude-agent-sdk": "^0.2.84",
|
|
"ws": "8.20.1"
|
|
},
|
|
"devDependencies": {
|
|
"@eslint/js": "^9.39.4",
|
|
"@stryker-mutator/core": "^9.6.1",
|
|
"@types/node": "^22.19.19",
|
|
"c8": "^11.0.0",
|
|
"eslint": "^9.39.4",
|
|
"eslint-plugin-n": "^17.24.0",
|
|
"eslint-plugin-no-only-tests": "^3.4.0",
|
|
"fast-check": "^4.8.0",
|
|
"globals": "^16.5.0",
|
|
"js-yaml": "^4.1.1",
|
|
"typescript": "^6.0.3",
|
|
"typescript-eslint": "^8.60.0"
|
|
},
|
|
"overrides": {
|
|
"qs": ">=6.15.2"
|
|
},
|
|
"optionalDependencies": {
|
|
"fallow": "^2.70.0"
|
|
},
|
|
"scripts": {
|
|
"sync:launcher": "node scripts/sync-runtime-launcher.cjs",
|
|
"check:env": "node scripts/check-env.cjs",
|
|
"check:alias-drift": "node scripts/check-alias-drift.cjs",
|
|
"check:identity-drift": "node scripts/lint-package-identity-drift.cjs",
|
|
"check:integrity": "node scripts/check-npm-integrity.cjs",
|
|
"build": "npm run generate:identity && npm run build:lib && npm run build:hooks",
|
|
"build:hooks": "node scripts/build-hooks.js",
|
|
"build:lib": "tsc -p tsconfig.build.json",
|
|
"generate:identity": "node scripts/generate-package-identity.cjs",
|
|
"prepack": "npm run build:lib",
|
|
"prepare": "npm run build:lib",
|
|
"prepublishOnly": "npm run build:lib && npm run build:hooks",
|
|
"pretest": "npm run build:lib && npm run lint:skill-deps",
|
|
"pretest:coverage": "npm run build:lib && npm run lint:skill-deps",
|
|
"lint": "eslint . --cache --cache-location node_modules/.cache/eslint/",
|
|
"lint:fix": "eslint . --fix",
|
|
"lint:descriptions": "node scripts/lint-descriptions.cjs",
|
|
"lint:skill-deps": "node scripts/lint-skill-deps.cjs",
|
|
"lint:test-file-count": "node scripts/lint-test-file-count.cjs",
|
|
"lint:pr-checks": "node scripts/lint-pr-check-project-dir.cjs",
|
|
"lint:changeset": "node scripts/changeset/lint.cjs",
|
|
"lint:docs": "node scripts/lint-docs-required.cjs",
|
|
"lint:legacy-name": "node scripts/lint-legacy-dir-name.cjs",
|
|
"ci:test-scope": "node scripts/ci-test-scope.cjs",
|
|
"changeset": "node scripts/changeset/new.cjs",
|
|
"changelog:render": "node scripts/changeset/cli.cjs render",
|
|
"test": "node scripts/run-tests.cjs",
|
|
"test:unit": "node scripts/run-tests.cjs --suite unit",
|
|
"test:integration": "node scripts/run-tests.cjs --suite integration",
|
|
"test:install": "node scripts/run-tests.cjs --suite install",
|
|
"test:security": "node scripts/run-tests.cjs --suite security",
|
|
"test:slow": "node scripts/run-tests.cjs --suite slow",
|
|
"test:affected": "node scripts/run-affected-tests.cjs",
|
|
"test:coverage": "c8 --check-coverage --lines 70 --reporter text --include 'gsd-core/bin/lib/*.cjs' --exclude 'tests/**' --all node scripts/run-tests.cjs",
|
|
"test:coverage:unit": "c8 --check-coverage --lines 70 --reporter text --include 'gsd-core/bin/lib/*.cjs' --exclude 'tests/**' --all node scripts/run-tests.cjs --suite unit",
|
|
"test:coverage:all": "npm run test:coverage",
|
|
"test:mutation": "stryker run",
|
|
"test:mutation:since": "stryker run --incremental --since origin/next"
|
|
}
|
|
}
|