* chore(deps-dev): bump js-yaml Bumps the npm_and_yarn group with 1 update in the / directory: [js-yaml](https://github.com/nodeca/js-yaml). Updates `js-yaml` from 4.3.1 to 4.3.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md) - [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 4.3.2 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> * chore: refresh vendored js-yaml to 4.3.2 (#4565) lint-vendored-deps caught the drift: this PR's lockfile-only bump left gsd-core/bin/lib/vendor/js-yaml.cjs and the package.json pin behind the new js-yaml 4.3.2 resolved by package-lock.json (merge-key CPU-limit backport, GHSA for excessive merge-key processing). Refreshes the vendored copy from node_modules and bumps the manifest pin to match. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs: add Security changeset for js-yaml 4.3.2 vendor bump (#4565) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Tom Boucher <trekkie@nomorestars.com> Co-authored-by: sim <sim@local> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
vendor/
This directory holds verbatim, unmodified copies of third-party build
artifacts that gsd-core/bin/** needs at runtime.
Why
gsd-core/bin/** is copied by the installer into trees that have no
node_modules (e.g. ~/.claude/gsd-core/). Any external (non-relative,
non-builtin) require()/import under gsd-core/bin/** breaks verify
(and everything else) for every installed user, because the module simply
cannot be resolved there. The fix is to vendor the compiled artifact
in-tree instead of depending on it being installed as an npm package.
eslint-rules/no-external-require-in-bin.cjs enforces this at lint time.
Contents
re2js.cjs— verbatim copy ofnode_modules/re2js/build/index.cjs(upstream packagere2js, pinned version seepackage.jsondevDependencies.re2js). Used bysrc/pattern.cts(compiled togsd-core/bin/lib/pattern.cjs) for linear-time RE2 pattern compilation.re2js.d.cts— verbatim copy ofnode_modules/re2js/build/index.d.cts, so TypeScript resolves types for the relative import fromsrc/pattern.cts.js-yaml.cjs— verbatim copy ofnode_modules/js-yaml/dist/js-yaml.js(upstream packagejs-yaml, pinned version seepackage.jsondevDependencies.js-yaml). ADR-3473 §8.1 (#3881): the single YAML parser this repo standardizes on. ThedistUMD bundle is the vendorable artifact — js-yaml'sexports.requireentry (index.js) is not self-contained;dist/js-yaml.jsloads underrequire(), contains zerorequire()calls of its own, and exposesload/dump/FAILSAFE_SCHEMA/YAMLException.
Two kinds of type twin
Each vendored package needs a .d.cts under src/vendor/ so TypeScript can
resolve types for a relative ./vendor/<pkg>.cjs import from src/**
(module resolution for a .cts source is relative to src/, not the
compiled output dir). There are two kinds:
- upstream-verbatim (
re2js.d.cts) — a byte-for-byte copy of an upstream.d.cts/.d.tsthat ships with the package. Both thegsd-core/bin/lib/vendor/copy and thesrc/vendor/copy are checked byscripts/lint-vendored-deps.cjsagainstnode_modulesand against each other. - hand-authored (
js-yaml.d.cts) — js-yaml ships no type declarations upstream and@types/js-yamlis not installed, so there is nothing to copy verbatim.src/vendor/js-yaml.d.ctsis written by hand, declares only the symbols actually used (load,dump,FAILSAFE_SCHEMA,YAMLException), and is excluded fromlint-vendored-deps.cjs's byte-compare — there is no upstream file to compare it against. The narrowness is deliberate: anchors, aliases, custom types andloadAllare unreachable from typed code, which is a compile-time enforcement of ADR-3473 §8.1's refusal to expand them.
Do not hand-edit
These files are verbatim copies of upstream build output. Never edit
them directly — refresh them from node_modules instead:
cp node_modules/re2js/build/index.cjs gsd-core/bin/lib/vendor/re2js.cjs
cp node_modules/re2js/build/index.d.cts gsd-core/bin/lib/vendor/re2js.d.cts
cp node_modules/re2js/build/index.d.cts src/vendor/re2js.d.cts
cp node_modules/js-yaml/dist/js-yaml.js gsd-core/bin/lib/vendor/js-yaml.cjs
# js-yaml.d.cts has no upstream counterpart — update src/vendor/js-yaml.d.cts
# by hand if the js-yaml API surface this repo depends on changes.
node scripts/lint-vendored-deps.cjs fails CI if any vendored copy drifts
byte-for-byte from its node_modules upstream, from its own source-side
type twin (upstream-verbatim twins only), or from the version pinned in
package.json devDependencies. It is table-driven (VENDORED in that
script) — adding a third vendored package means adding a row, not a second
hardcoded check block (ADR-3473 §8.3, "one implementation per rule").