* test(#2721): failing-first suite for the gsd-regen driver and CONTEXT.md parity Tests precede the implementation per the TDD gate. The driver module does not exist yet, so tests/git-merge-regen-driver.test.cjs fails at require time; the contributor-standards parity assertions fail against next as it stands today, where the standards doc names two CONTEXT.md headings that have never existed. Refs #2721 * feat(#2721): add the gsd-regen merge driver and regen:derived The golden parity manifests and the two size baselines are pure functions of the source tree, so their only correct merge is "recompute" -- something git's ours/theirs interface cannot express. 140 of 143 conflicted-file instances across the open PR queue are these files. The driver deliberately does NOT regenerate. Four probes established that at merge-driver time neither the working tree nor the index reflects the merge: both hold the ours side, a file added by theirs does not exist yet, and MERGE_HEAD is unwritten. Git also invokes the driver once per conflicted path (20 here). A regenerating driver would therefore read the ours-side tree and emit a plausible-but-wrong hash manifest -- worse than a conflict, because a conflict is visible. So it accepts %A, runs zero subprocesses, records the resolved paths, and prints one notice pointing at npm run regen:derived. Staleness stays caught where it already was, by golden-install-parity in CI. Every failure path degrades toward today's behaviour (a normal conflict). install-tree is deliberately excluded per ADR-2719 section 7. Also folded in, per the no-defer rule: workflow-size.cjs claimed .md files have no eol=lf in .gitattributes; git check-attr shows eol: lf, set by .gitattributes line 2 since #1088. Refs #2721 * docs(#2721): document regen:derived and the gsd-regen merge driver Adds the how-to a contributor actually reaches for when the generated parity manifests or size baselines conflict, in both places they would look: the merge-conflict path in CONTRIBUTING.md and the full guide in TESTING-SUITES.md, including what the driver deliberately does not do (it does not clear GitHub's CONFLICTING label, and it does not regenerate mid-merge). Also scopes the new contributor-standards parity assertion to the doc's own CONTEXT.md section. Its first run flagged `## Decision`, `## Consequences` and `## Standards followed`, which the doc attributes to an ADR body and a PR body rather than to CONTEXT.md -- a doc-wide extractor would have demanded CONTEXT.md grow headings that do not belong to it. Refs #2721 * fix(#2721): stop passing %P to the merge driver — shell injection The isolated adversarial review found, and I independently reproduced, local arbitrary command execution. Git does not invoke a merge driver with an argv array. It substitutes %O %A %B %L %P textually into the configured string and runs the whole thing through a shell, and $(...) executes inside POSIX double quotes -- so quoting the placeholder does not neutralise it. %O/%A/%B are git-generated temp names and %L is an integer, but %P is the file's own path, chosen freely by any contributor. A branch renaming a covered fixture to evil$(touch PWNED_SENTINEL).json executed that command on the machine of every maintainer who merged it, and the merge still reported success. Fix removes the input rather than filtering it: %P is no longer registered, so the driver receives no attacker-controlled argument at all. The marker records a count instead of path names. A metacharacter filter would have been a guess about shell grammar; passing nothing is a property. Re-ran the identical exploit against the fixed command: nothing executed, conflict still resolved. Two regressions guard it -- a platform-independent assertion that the registered command carries no %P, and a real merge driven by the actual planInstall output with a $(...) filename. Also from review: CLI dispatch had no coverage at all (CONTRIBUTING's "CLI and command routing" matrix), which is why runInstall/runStatus now take {repoRoot} -- hardcoding REPO_ROOT was what made them untestable. Renamed planResolution to resolveAndRecord since the plan* prefix promised purity it did not have. Reconciled the eleven-vs-twelve generator count across CONTEXT.md, CONTRIBUTING.md and the changeset. Refs #2721 * test(#2721): scope safe.directory for the check-attr helper The 66f4d85a run failed 11 assertions, all in the .gitattributes scoping block, with "fatal: detected dubious ownership in repository at '/work'". The test container checks the repo out at a path its user does not own, so git refuses check-attr outright. Everything else passed (27,185). `check-attr` is a pure read of .gitattributes -- no hooks, no filters -- so the exemption is scoped to that one invocation. It is deliberately NOT applied to the driver's own production `git config` calls, which run in the user's own clone and should keep the protection. Refs #2721 * test(#2721): delete the stale assertion that the driver command carries %P The plex2 run on bdfd0856 left exactly two failures, both this test: it still asserted the pre-fix command string, i.e. the vulnerable behaviour. Deleted rather than relaxed, per RULESET.TESTS.delete-bad-tests -- its useful half is already covered, in both directions, by registeredDriverCommandNeverPassesThePlaceholderForTheFilePath. Refs #2721 * test(#2721): drive the end-to-end merges from the real planInstall output The e2e helper hand-rolled its own driver registration, and still carried %P. That meant the five real-git tests were not exercising the production command string at all -- planInstall could drift and they would keep passing. They now register exactly what a contributor gets from npm run setup:merge-driver. Refs #2721 * chore(#2721): backfill changeset pr number to 2730
141 lines
7.0 KiB
JSON
141 lines
7.0 KiB
JSON
{
|
|
"name": "@opengsd/gsd-core",
|
|
"version": "1.8.0",
|
|
"description": "GSD Core is a meta-prompting, context engineering, and spec-driven development system for AI coding agents.",
|
|
"main": ".opencode/plugins/gsd-core.js",
|
|
"bin": {
|
|
"gsd-core": "bin/install.js",
|
|
"gsd-tools": "gsd-core/bin/gsd-tools.cjs",
|
|
"gsd_run": "gsd-core/bin/gsd_run",
|
|
"gsd-mcp-server": "bin/gsd-mcp-server.js"
|
|
},
|
|
"files": [
|
|
"bin",
|
|
"commands",
|
|
"skills",
|
|
"gsd-core",
|
|
"assets",
|
|
"agents",
|
|
".claude-plugin",
|
|
".opencode",
|
|
"GEMINI.md",
|
|
"hooks",
|
|
"scripts",
|
|
"pi",
|
|
"vscode"
|
|
],
|
|
"keywords": [
|
|
"claude",
|
|
"claude-code",
|
|
"ai",
|
|
"meta-prompting",
|
|
"context-engineering",
|
|
"spec-driven-development",
|
|
"codex",
|
|
"codex-cli"
|
|
],
|
|
"author": "OpenGSD",
|
|
"license": "MIT",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "git+https://github.com/open-gsd/gsd-core.git"
|
|
},
|
|
"homepage": "https://github.com/open-gsd/gsd-core",
|
|
"bugs": {
|
|
"url": "https://github.com/open-gsd/gsd-core/issues"
|
|
},
|
|
"publishConfig": {
|
|
"access": "public"
|
|
},
|
|
"engines": {
|
|
"node": ">=22.0.0",
|
|
"npm": ">=10.0.0"
|
|
},
|
|
"dependencies": {
|
|
"@anthropic-ai/claude-agent-sdk": "^0.2.84",
|
|
"ws": "^8.21.0"
|
|
},
|
|
"devDependencies": {
|
|
"@eslint/js": "^9.39.4",
|
|
"@stryker-mutator/core": "^9.6.1",
|
|
"@types/node": "^22.19.19",
|
|
"c8": "^11.0.0",
|
|
"eslint": "^9.39.4",
|
|
"eslint-plugin-n": "^17.24.0",
|
|
"eslint-plugin-no-only-tests": "^3.4.0",
|
|
"fast-check": "^4.8.0",
|
|
"globals": "^16.5.0",
|
|
"js-yaml": "^4.2.1",
|
|
"typescript": "^6.0.3",
|
|
"typescript-eslint": "^8.60.0"
|
|
},
|
|
"overrides": {
|
|
"qs": ">=6.15.2",
|
|
"body-parser": ">=2.3.0",
|
|
"@hono/node-server": ">=2.0.5"
|
|
},
|
|
"optionalDependencies": {
|
|
"fallow": "^2.70.0"
|
|
},
|
|
"scripts": {
|
|
"sync:launcher": "node scripts/sync-runtime-launcher.cjs",
|
|
"check:env": "node scripts/check-env.cjs",
|
|
"check:alias-drift": "node scripts/check-alias-drift.cjs",
|
|
"check:identity-drift": "node scripts/lint-package-identity-drift.cjs",
|
|
"check:phase-id-drift": "node scripts/lint-phase-id-drift.cjs",
|
|
"check:integrity": "node scripts/check-npm-integrity.cjs",
|
|
"build": "npm run generate:identity && npm run build:lib && npm run gen:plugin-skills && npm run gen:loop-host-contract && npm run gen:capability-registry && npm run build:hooks",
|
|
"build:hooks": "node scripts/build-hooks.js",
|
|
"build:lib": "tsc -p tsconfig.build.json",
|
|
"generate:identity": "node scripts/generate-package-identity.cjs",
|
|
"gen:loop-host-contract": "node scripts/gen-loop-host-contract.cjs --write",
|
|
"gen:plugin-skills": "node scripts/gen-plugin-skills.cjs --write",
|
|
"gen:capability-registry": "node scripts/gen-capability-registry.cjs --write",
|
|
"gen:registry": "node scripts/gen-registry.cjs --write",
|
|
"gen:golden": "node scripts/gen-golden-install-parity-zcode.cjs && node scripts/gen-install-tree-fixtures.cjs",
|
|
"regen:derived": "npm run build && npm run gen:registry && node scripts/gen-adr-index.cjs --write && node scripts/gen-capability-matrix.cjs --write && node scripts/gen-inventory-manifest.cjs --write && node scripts/sync-manifest-versions.cjs && npm run size:baseline && npm run gen:golden",
|
|
"setup:merge-driver": "node scripts/git-merge-regen-driver.cjs --install",
|
|
"validate:registry": "node scripts/validate-registry.cjs",
|
|
"prepack": "npm run build:lib",
|
|
"prepare": "npm run build:lib",
|
|
"version": "node scripts/sync-manifest-versions.cjs --stage && node scripts/gen-capability-registry.cjs --write && git add gsd-core/bin/lib/capability-registry.cjs",
|
|
"prepublishOnly": "npm run build:lib && npm run build:hooks",
|
|
"pretest": "npm run build:lib && npm run lint:skill-deps",
|
|
"pretest:coverage": "npm run build:lib && npm run lint:skill-deps",
|
|
"lint": "eslint . --cache --cache-location node_modules/.cache/eslint/",
|
|
"lint:fix": "eslint . --fix",
|
|
"lint:table-schema-drift": "node scripts/lint-table-schema-drift.cjs",
|
|
"lint:ci": "npm run lint && npm run lint:skill-deps && npm run lint:generated-sync && node scripts/lint-test-file-count.cjs && node scripts/lint-command-contract.cjs && node scripts/lint-pr-check-project-dir.cjs && npm run lint:legacy-name && node scripts/lint-regression-test-names.cjs && node scripts/lint-allow-test-rule-refs.cjs && node scripts/lint-resolution-provenance.cjs && node scripts/lint-portable-timeout.cjs && node scripts/validate-registry.cjs && node scripts/lint-table-schema-drift.cjs && node scripts/lint-fix-has-regression-test.cjs",
|
|
"lint:allow-test-rule-refs": "node scripts/lint-allow-test-rule-refs.cjs",
|
|
"lint:regression-names": "node scripts/lint-regression-test-names.cjs",
|
|
"lint:descriptions": "node scripts/lint-descriptions.cjs",
|
|
"lint:skill-deps": "node scripts/lint-skill-deps.cjs",
|
|
"lint:test-file-count": "node scripts/lint-test-file-count.cjs",
|
|
"lint:pr-checks": "node scripts/lint-pr-check-project-dir.cjs",
|
|
"lint:changeset": "node scripts/changeset/lint.cjs",
|
|
"lint:generated-sync": "node scripts/gen-capability-registry.cjs --check && node scripts/gen-loop-host-contract.cjs --check && node scripts/gen-capability-matrix.cjs --check && node scripts/sync-manifest-versions.cjs --check && node scripts/gen-inventory-manifest.cjs --check && node scripts/generate-package-identity.cjs --check && node scripts/gen-plugin-skills.cjs --check && node scripts/gen-registry.cjs --check && node scripts/gen-adr-index.cjs --check && node scripts/check-glossary-refs.cjs --check && node scripts/lint-compiled-artifact-sync.cjs --check",
|
|
"lint:docs": "node scripts/lint-docs-required.cjs",
|
|
"lint:legacy-name": "node scripts/lint-legacy-dir-name.cjs",
|
|
"ci:test-scope": "node scripts/ci-test-scope.cjs",
|
|
"size:baseline": "node scripts/update-size-baseline.cjs",
|
|
"changeset": "node scripts/changeset/new.cjs",
|
|
"changelog:render": "node scripts/changeset/cli.cjs render",
|
|
"test": "node scripts/run-tests.cjs",
|
|
"test:unit": "node scripts/run-tests.cjs --suite unit",
|
|
"test:integration": "node scripts/run-tests.cjs --suite integration",
|
|
"test:install": "node scripts/run-tests.cjs --suite install",
|
|
"test:security": "node scripts/run-tests.cjs --suite security",
|
|
"test:slow": "node scripts/run-tests.cjs --suite slow",
|
|
"test:affected": "node scripts/run-affected-tests.cjs",
|
|
"test:coverage": "c8 --check-coverage --lines 70 --branches 60 --reporter text --include 'gsd-core/bin/lib/*.cjs' --exclude 'tests/**' --all node scripts/run-tests.cjs",
|
|
"test:coverage:scripts-floor": "c8 check-coverage --lines 55 --include 'scripts/**/*.cjs' --exclude 'tests/**' --all",
|
|
"test:coverage:unit": "c8 --reporter text --reporter json-summary --include 'gsd-core/bin/lib/*.cjs' --exclude 'tests/**' --all node scripts/run-tests.cjs --suite unit && node scripts/check-coverage-gate.cjs",
|
|
"test:coverage:all": "npm run test:coverage",
|
|
"test:mutation": "stryker run",
|
|
"test:mutation:since": "stryker run --incremental --since origin/next"
|
|
},
|
|
"allowScripts": {
|
|
"fallow@2.70.0": true
|
|
}
|
|
}
|