* fix(3588)(security): clear production npm-audit advisories Before: 6 production advisories (1 high, 5 moderate) reported by `npm audit --omit=dev` — fast-uri (high), @anthropic-ai/sdk, express-rate-limit, hono, ip-address (moderate), all pulled in through @anthropic-ai/claude-agent-sdk and @modelcontextprotocol/sdk. After: `npm audit fix` bumped the lockfile-pinned transitive versions to patched releases. No package.json edits — only package-lock.json and sdk/package-lock.json. Production audit is clean on both: `npm audit --omit=dev` → 0 vulnerabilities. Regression test `tests/bug-3588-npm-audit-clean.test.cjs` runs `npm audit --omit=dev --json` against root and sdk/ and asserts the metadata vulnerability counts are zero across info/low/moderate/high/ critical. RED on origin/main (1 high + 5 moderate at root), GREEN after the lockfile bumps. Skips gracefully when node_modules/ is absent so fresh checkouts mid-`npm install` don't false-fail. Fixes #3588 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(3588): npm audit harness throws on unexpected JSON shape CodeRabbit caught that auditProductionVulns returned null both for "node_modules missing → skip" AND for "unexpected JSON shape" — and callers interpret null uniformly as skip, so a real audit harness failure (npm changed output format, audit aborted before metadata section, etc.) would silently no-op instead of failing the test. null is now reserved for the skip signal only. Any other unexpected shape throws with the cwd in the message so the test fails loudly. Local: docker gsd-test-summary 11204/0 on plex2. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@gsd-build/sdk
TypeScript SDK for Get Shit Done: deterministic query/mutation handlers, plan execution, and event-stream telemetry so agents focus on judgment, not shell plumbing.
Install
npm install @gsd-build/sdk
Quickstart — programmatic
import { GSD, createRegistry } from '@gsd-build/sdk';
const gsd = new GSD({ projectDir: process.cwd(), sessionId: 'my-run' });
const tools = gsd.createTools();
const registry = createRegistry(gsd.eventStream, 'my-run');
const { data } = await registry.dispatch('state.json', [], process.cwd());
Quickstart — CLI
From a project that depends on this package, invoke the CLI with Node (recommended in CI and local dev):
node ./node_modules/@gsd-build/sdk/dist/cli.js query state.json
node ./node_modules/@gsd-build/sdk/dist/cli.js query roadmap.analyze
If no native handler is registered for a command, the CLI can transparently shell out to get-shit-done/bin/gsd-tools.cjs (see stderr warning), unless GSD_QUERY_FALLBACK=off.
What ships
| Area | Entry |
|---|---|
| Query registry | createRegistry() in src/query/index.ts — same handlers as gsd-sdk query |
| Tools bridge | GSDTools — native dispatch with optional CJS subprocess fallback |
| Orchestrators | PhaseRunner, InitRunner, GSD |
| CLI | gsd-sdk — query, run, init, auto |
Guides
- Handler registry & contracts:
src/query/QUERY-HANDLERS.md - Repository docs (when present):
docs/ARCHITECTURE.md,docs/CLI-TOOLS.mdat repo root
Environment
| Variable | Purpose |
|---|---|
GSD_QUERY_FALLBACK |
off / never disables CLI fallback to gsd-tools.cjs for unknown commands |
GSD_AGENTS_DIR |
Override directory scanned for installed GSD agents (~/.claude/agents by default) |