Files
msd-core/QUICK-WINS-CONFIRMED-BUGS.md
Tom Boucher 79002a00cb chore(#518): rename npm package + bin to @opengsd/gsd-core (#519)
* chore: rename npm package + bin to @opengsd/gsd-core (functional)

- package.json: name @opengsd/get-shit-done-redux → @opengsd/gsd-core,
  bin key get-shit-done-redux → gsd-core, repository/homepage/bugs URLs
- package-lock.json: regenerated (npm install --package-lock-only)
- tests/**, scripts/**, bin/**, .github/**, agents/**, commands/**,
  get-shit-done/bin/**, get-shit-done/workflows/**:
  applied the 4-rule replacement (scoped npm ref, GitHub repo path,
  bin/clone invocations) per #505 single-source refactor

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs: sweep live references to @opengsd/gsd-core

Update all live documentation (README.md + translations, docs/**,
CONTRIBUTING.md, VERSIONING.md, SECURITY.md, CONTEXT.md,
docs/CANARY.md) to reflect the renamed package and repository.

Rules applied:
- @opengsd/get-shit-done-redux → @opengsd/gsd-core (scoped npm name)
- open-gsd/get-shit-done-redux → open-gsd/gsd-core (GitHub repo)
- GSD-redux/get-shit-done-redux → open-gsd/gsd-core (stale badge org)
- bare bin/clone refs → gsd-core

CHANGELOG.md, docs/adr/**, docs/RELEASE-*.md, docs/research/**,
and .changeset/** are preserved byte-identical.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix: add negative lookbehind to slash-command regex in bug-2954 test

The extractSlashReferences regex matched /gsd-core inside npm package
URLs (@opengsd/gsd-core), producing a false /gsd:core command reference.
Adding a negative lookbehind (?<![a-z]) excludes matches preceded by a
letter, so only standalone /gsd-<cmd> and /gsd:<cmd> tokens are found.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore(#518): add changeset for package rename

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#518): update package-identity expectations to the renamed coordinates

The rebase regenerated the seam to @opengsd/gsd-core (bin gsd-core, repo
open-gsd/gsd-core). The #498 seam tests assert deriveIdentity against the REAL
package.json, so their expected literals must follow the rename. The drift-lint
unit test is left as-is — its SEAM is a self-consistent fixture and its
stale-literal detection cases would shift if altered; the live-repo scan in it
already passes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-30 17:25:02 -04:00

5.7 KiB

Quick Wins: Confirmed-Bug Fixes

Status: Active
Started: 2026-05-16
Owner: Current session (Grok + user)
Context: Follow-up to /gsd-inbox triage on 2026-05-16

Goal

Land 6 high-signal, confirmed-bug issues that currently have zero open pull requests. These are the cleanest quick-win opportunities available in the public GitHub inbox right now.

All six issues carry the confirmed-bug label, meaning the bug has been verified and a fix is explicitly welcome.

The 6 Issues (Prioritized)

# Issue Short Title Type Recommended Flow Est. Effort Status Notes
1 #3583 Claude skill install leaves /gsd:<cmd> in SKILL.md body Installer / Command namespace PR 3629 (our branch) + competing 3586 Small (1 file + test) PR opened / Review Leading PR: 3629 (cristianuibar) — reviewed + hardened with CodeRabbit feedback (left-boundary regex + body-scoped guard). Competing PR 3586 has "needs changes" + "ci: failing". Issue still carries confirmed-bug.
2 #3579 build-hooks.js + npm publish omit graphify auto-update hook Packaging / Build /gsd-quick Small Not started Classic "new feature missed in release artifact". Easy local verification.
3 #3496 /gsd:update changelog extraction skips intermediate versions Workflow / Update logic /gsd-quick or lightweight plan Medium-small Not started Needs deterministic version-range helper.
4 #3588 Production npm audit has 1 high + 5 moderate advisories Security / Dependencies Direct + careful review Medium Not started Transitive via @anthropic-ai/claude-agent-sdk. May need overrides.
5 #3584 Runtime bin/lib/*.cjs still emit /gsd:<cmd> (larger piece deferred from #3583) Runtime output / Slash formatter Short plan first, then execute Medium-Large Not started 16+ files. Design a centralized runtime-aware formatter. Do after #3583.
6 #3340 SDK publish lag — agent dir fix never shipped in @opengsd/gsd-sdk@0.1.0 Release / SDK publishing Plan + coordination Medium (release-focused) Not started Oldest. Mostly a publishing/versioning task.

Execution Rules for This Batch

  • Branch naming: fix/NNNN-short-description (enforced by CI)
  • PR template: Must use .github/PULL_REQUEST_TEMPLATE/fix.md
  • Linking: Fixes #NNNN (or Closes) in the PR body
  • Changeset: Required for all user-facing or security fixes
  • Testing: All existing tests must pass + new coverage where the issue describes a gap
  • Clean context windows: Each fix should preferably be driven from a fresh session using the prepared prompts (see session notes or ask for them)
  • GSD self-use: For the small ones (#3583, #3579, #3496), using /gsd-quick (or /gsd-fast) inside the fix session is encouraged and appropriate. For #3584, a short planning step is recommended.

Status Legend

  • Not started — Issue claimed for this batch, no work begun
  • In progress — Active work in a clean window
  • PR opened — Pull request created and linked
  • Review — Awaiting review / CI / merge fixes
  • Merged — Landed on main
  • Blocked — Needs input from maintainers or upstream

Current Status

  • #3583 — PR opened (3629 leading after CodeRabbit review + hardening push; competing 3586 needs changes + CI failing)
  • #3579 — Not started (cleanest next target — 0 PRs)
  • #3496 — PR 3497 open (changes requested)
  • #3588 — Not started
  • #3584 — Not started (larger; deferred runtime cjs colon emissions)
  • #3340 — Not started

Progress: 0 / 6 merged (1 in active review)

Process Notes

  • These issues were identified during a /gsd-inbox run on 2026-05-16.
  • At the time of creation of this file, zero of the six had open PRs.
  • 2026-05-16 Grok session: Reviewed PR 3629 (our #3583 fix) for CodeRabbit comments. 1 critical was false-positive (scripts/ is published per package.json "files" + npm pack). Applied the 2 valid suggestions (bidirectional word-boundary lookbehind in buildColonPattern + body-only scope for the colon-ref regression guard in the test). Tests pass. Pushed hardening commit to the fork branch. Competing PR 3586 exists but is behind on CI/review status.
  • Work is intended to be done in parallel clean context windows (one issue per fresh Claude/Codex/Gemini session) using dedicated prompts.
  • After each fix is complete in its window, the resulting branch + PR description should be brought back here for final review and opening.
  • This file serves as the single source of truth for the current batch while execution is in progress. It can be deleted or moved to docs/archive/ once all six PRs are merged.
  • Inbox triage report: /tmp/GSD-INBOX-TRIAGE-2026-05-16.md (from the /gsd-inbox run)
  • Full issue list with confirmed-bug label: gh issue list --state open --label confirmed-bug

Next action: #3583 now has active PR(s) under review. Next clean quick win (0 PRs, small packaging effort, high value for recently-landed graphify feature): #3579. Validated via GitHub search: no PRs mention 3579. Ready for /gsd-quick or direct fix (update scripts/build-hooks.js HOOKS_TO_COPY + ensure hooks/lib/ copy in installer + fix any publish filter).

This document will be updated as status changes.