Tasks 1 to 3 record their commits, Deviation: body lines and a
state.record-session line naming PLAN_BASE, so Tasks 4 and 5 can resume
in a fresh context. Their read_first lists now name only the symbols and
helpers they use. The plan stays single and autonomous.
- every per-task row of plans 01 to 06 ran green on 2026-10-01
- status validated, nyquist_compliant and wave_0_complete true
- search and dark mode stay as manual UAT rows for /gsd-verify-work
Six plans (tracer generator, site UX and checkers, content A, content B,
acme/blog walkthrough, unit tests). SC4/DOCS-04 narrowed to docs/ pages per
D-18; README Go fence conversion logged as a todo.
- 11-SECURITY-REVIEW.md: T-11-01..T-11-30 and T-11-SC with each plan's
severity and disposition, mitigation, test and result; RC-01..RC-13
removal checks for every high mitigated threat; the three defects fixed
in 11-07
- 11-VALIDATION.md: task ids, plans and waves per row, commands run,
status validated, nyquist_compliant and wave_0_complete true
- 10.1-SECURITY-REVIEW.md: T-10.1-01 to T-10.1-22 and T-10.1-SC with
mitigation, test or gate stage, observed result and 23 removal checks
- 10.1-VALIDATION.md: every plan task mapped to its command, all green
under check-phase10.1.sh --all; nyquist_compliant and wave 0 complete
- Phase 10 deferred item for the parity failures marked resolved
Four repos (sm-summercms-app, vue-summercms-app, sm-summercms-plugin,
sm-newsletter-plugin), Nuxt 4 static site in EN and PL embedded in the
binary, double opt-in signup with honeypot, consent and neutral
responses, and a standalone sending-ready subscribers table.
Adds Phase 11.2 after 11.1: the sm-summercms-app root with a
vue-summercms-app website, an sm-newsletter-plugin stub ported from
Golem15.Newsletter with double opt-in signup, and the 11.1 docs served
at /docs. Records the sm- repo naming convention.