Files
msd-core/sdk
Tom Boucher 3c2c56b9e8 fix(ci): skip install + slow lanes on Windows in main test matrix (#3710)
* fix(ci): skip install + slow lanes on Windows in main test matrix

Gates the `Run install tests` and `Run slow tests` steps in
`.github/workflows/test.yml` to `matrix.os != 'windows-latest'`.

The install lane performs `npm install -g <tarball>` 7× per invocation
of release-tarball-smoke.install.test.cjs (1× in the shared before()
hook + 1× per of the 6 test cases). On windows-latest each install
costs 60–90 s (NTFS + Defender) so the lane alone consumes ~8–9 min
on top of the ~7 min already spent on npm ci + build:sdk + unit +
integration + security — overflowing the 15-min `timeout-minutes` cap
and cancelling the job mid-install.

The dedicated install-smoke.yml workflow already excludes Windows from
its matrix (ubuntu + macOS only); the weekly windows-compat workflow
provides Windows-specific regression coverage. Linux + macOS install
and slow lanes remain on main push for parity.

Refs #3709

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(deps): bump ws 8.20.0 → 8.20.1 to clear GHSA-58qx-3vcg-4xpx

The bug-3588 `npm audit --omit=dev reports zero advisories` test
(tests/bug-3588-npm-audit-clean.test.cjs) is failing on main after a
new advisory dropped against ws@8.20.0:

  GHSA-58qx-3vcg-4xpx — Uninitialized memory disclosure
  ws: range >=8.0.0 <8.20.1 (CVSS 4.4, moderate, CWE-908)

Fix: `npm audit fix --omit=dev` at both root and sdk/. Lockfile-only
bump to ws@8.20.1; package.json untouched (ws is transitive).

`npm audit --omit=dev` reports `found 0 vulnerabilities` in both
workspaces after the bump.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-18 16:08:57 -04:00
..

@gsd-build/sdk

TypeScript SDK for Get Shit Done: deterministic query/mutation handlers, plan execution, and event-stream telemetry so agents focus on judgment, not shell plumbing.

Install

npm install @gsd-build/sdk

Quickstart — programmatic

import { GSD, createRegistry } from '@gsd-build/sdk';

const gsd = new GSD({ projectDir: process.cwd(), sessionId: 'my-run' });
const tools = gsd.createTools();

const registry = createRegistry(gsd.eventStream, 'my-run');
const { data } = await registry.dispatch('state.json', [], process.cwd());

Quickstart — CLI

From a project that depends on this package, invoke the CLI with Node (recommended in CI and local dev):

node ./node_modules/@gsd-build/sdk/dist/cli.js query state.json
node ./node_modules/@gsd-build/sdk/dist/cli.js query roadmap.analyze

If no native handler is registered for a command, the CLI can transparently shell out to get-shit-done/bin/gsd-tools.cjs (see stderr warning), unless GSD_QUERY_FALLBACK=off.

What ships

Area Entry
Query registry createRegistry() in src/query/index.ts — same handlers as gsd-sdk query
Tools bridge GSDTools — native dispatch with optional CJS subprocess fallback
Orchestrators PhaseRunner, InitRunner, GSD
CLI gsd-sdk — query, run, init, auto

Guides

  • Handler registry & contracts: src/query/QUERY-HANDLERS.md
  • Repository docs (when present): docs/ARCHITECTURE.md, docs/CLI-TOOLS.md at repo root

Environment

Variable Purpose
GSD_QUERY_FALLBACK off / never disables CLI fallback to gsd-tools.cjs for unknown commands
GSD_AGENTS_DIR Override directory scanned for installed GSD agents (~/.claude/agents by default)