Skip to content

chore(deps): bump @opengsd/gsd-core from 1.12.0 to 1.14.0 - #69

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/opengsd/gsd-core-1.14.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/opengsd/gsd-core-1.14.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @opengsd/gsd-core from 1.12.0 to 1.14.0.

Release notes

Sourced from @​opengsd/gsd-core's releases.

v1.14.0

Install

npm i @opengsd/gsd-core@1.14.0
# or
npm i @opengsd/gsd-core@latest

What's Changed

Feature

Enhancement

Fix

... (truncated)

Changelog

Sourced from @​opengsd/gsd-core's changelog.

[1.14.0] - 2026-09-14

Added

  • The phase-directory membership seam threads the phase ID convention through the completion chain — the #3511 seam (isPhaseArtifact / scopeToPhase) now takes the same optional convention every other read-path helper does, and the completion chain threads it: state json / state sync's completed-phase counting, the planning snapshot, roadmap analysis, state validate's drift scan, the verification-report resolver, and phase complete's actual completion gate. A bracket directory therefore scopes its listing by its real phase token instead of the include-everything ambiguity fail-safe, so a cross-phase stray (01-VERIFICATION.md misfiled into phase 03's directory) can no longer supply the pass/fail verdict for a bracket phase — the same protection #3511 already gives legacy directories, on the call sites this PR threads.

    Call sites that do not yet resolve a convention keep the documented include-everything fail-safe on bracket directories, and this PR changes nothing for them: the aggregate scans (uat, audit, init's projections, gap-checker, phase-locator); phase complete's advisory pre-scan (cmdPhaseComplete, src/phase.cts), whose UAT and VERIFICATION warning sweeps still call the seam convention-lessly and can therefore surface a spurious warning for a cross-phase stray, although that scan cannot pass or block completion; and the workstream inventory's per-phase completion projection (src/workstream-inventory.cts), which calls the now-convention-aware isPhaseComplete without resolving a convention to pass it and can therefore still project a bracket phase complete or incomplete from a cross-phase stray. Threading those readers is follow-up-slice work alongside the epic's other convention-less readers. A project on any convention other than "bracket" is unaffected. (#4142) (#3644)

  • workflow.compact_content now actually does something: plan-phase is the first workflow split into a spine + detail file. With the key off (default), nothing changes — the spine reads the deferred elaboration back in before continuing, so the instruction set is identical to today. With it on, that read is skipped and the orchestrator runs on the terser spine alone, which is complete enough to plan a phase correctly on its own. The check and the resolution rule live in one shared reference (gsd-core/references/compact-content-gate.md) that future splits reference instead of restating. (#4402) (#4471)

  • A new offline benchmark reports the token savings from compact-content splits — npm run benchmark:compact-content measures, per registered workflow.compact_content spine/detail split, the token count with and without the split active using a pinned tokenizer, and prints the reduction against a committed baseline without ever failing CI. (#4404) (#4502)

  • Broken-windows ledger entries now record which milestone they belong to — windows append stamps a new milestone field from the workstream's resolved milestone version. Phase numbers are unique only within one active phases directory, so two milestones routinely produced entries sharing the same phase number with nothing to distinguish them; /gsd-ship's open-count gate could be silently blocked by another, already-shipped milestone's entries. Absence (an entry recorded before this field existed) reads as null — existing ledgers keep working with no migration. (#4583)

  • Five more workflow spines split into a terser form under workflow.compact_content — execute-phase, docs-update, new-project, verify-work, and complete-milestone join plan-phase (#4402), bringing the total to six, each moving genuinely optional or rare content (interactive-mode flows, off-by-default features, gap-closure loops, cross-AI delegation, branch-merge mechanics) into a deferred <workflow>/detail/*.md elaboration read only when the key is off; several pre-existing structural drift guards pin exact wording in specific spine steps (crash-resume detection, checkpoint auto-approval, learnings extraction, revision-conflict handling), so those sections keep their full text in the spine rather than deferring it. The refreshed benchmark reports a 15.66% aggregate token reduction across the six splits. The remaining eagerly-included workflows were reviewed and recorded as not worth splitting, with reasons, in docs/PARTITION-RULES.md. (#4405) (#4536)

  • Compact content mode is now discoverable, not just settable. /gsd-new-project asks about it at init time and /gsd-settings//gsd-config toggle it on an already-initialized project, closing out the #4139 compact-content epic. (#4408) (#4587)

  • workflow.compact_content now also covers lazily-read workflow fragments and planning-artifact templates. With the key on, help --full's reference doc and generated SUMMARY.md/USER-SETUP.md templates resolve to a terser .compact.md sibling at the point of their existing Read — two independent, complete files, picked per the same shared gate Phase 5 introduced (gsd-core/references/compact-content-gate.md). With the key off (default), nothing changes. (#4540)

  • workflow.compact_content splits now have a real CI guard. Any workflow spine + detail/*.md split is enforced forever: completeness once at split time, disjointness and registration on every PR, and protected content (guardrails, output-format contracts, few-shot examples, security language, machine-parsed headings) that can never leave the spine, moved or not. Ordinary content moves between spine and detail need a Boundary-Move-Declared commit trailer naming the spine, mirroring ADR-3942's emitted-drift-ack trailers. The partition rule and the protected-content list live in one place, docs/PARTITION-RULES.md. (#4403) (#4497)

  • /gsd:code-review can now optionally corroborate its internal review with registered external reviewer lanes — new roster-derived flags dispatch a bounded, read-only source review through each selected lane; findings are re-verified against real source and folded into the existing REVIEW.md. Bare /gsd:code-review (no flag) is unchanged. (#4323)

  • check decision-coverage-plan accepts --context — same convention as sibling check verbs. (#4130) (#4374)

  • workflow.compact_content is now a registered, validated, documented project config key. It resolves to false when absent and is readable via config-get; no content branches on it yet. (#4401) (#4441)

  • Compact agent-persona payloads for non-Claude runtime dispatch, selected by workflow.compact_content. When the key is on, the AGENTS-native persona fallback (kimi-code, opencode, kilo, and similar runtimes without named-subagent dispatch) now serves a token-minimized .compact.md variant of the agent's persona instead of the full file, chosen by the same CLI seam (gsd_run query agent-skills) that already resolves this content in code rather than prose. An agent with no compact variant registered falls back to the canonical persona and discloses the fallback in the payload itself, so nothing is ever served silently or left empty. (#4407) (#4553)

Changed

  • Planning guidance now prefers the first sufficient implementation option — existing project behavior, standard-library or native platform capability, installed dependencies, and only then minimum new implementation, without reducing required scope or verification. (#4118)
  • 21 GSD skills now declare Grep in allowed-tools — cleanup, complete-milestone, config, debug, graphify, health, mempalace-capture, mempalace-recall, new-milestone, new-project, next, pause-work, phase, pr-branch, resume-work, review-backlog, settings, stats, thread, workspace, and workstreams can now use the dedicated structured-search tool instead of shelling out through Bash grep. (#4397)
  • Context-monitor WARNING/CRITICAL fire-points are now readable from .planning/config.json — hooks.context_warning_threshold (default 35) and hooks.context_critical_threshold (default 25) move the two rungs per project, so a tuned fire-point survives an update instead of being re-staged away with the managed hook file. Absent keys resolve to today's 35/25, so existing projects are unchanged. An unusable value falls back per key; both revert to their defaults only when the resolved pair violates critical < warning. The keys are root-project settings — the hook reads <cwd>/.planning/config.json only, and they are read by that hook and nothing else, so on a runtime where it is not installed (Codex, per #2586) both keys are stored and validated but inert. config-set refuses the two endpoints that can never take effect — a warning of 0 and a critical of 100 — because critical < warning has no legal partner for either, and an absent key now reports the shipped default (35/25) instead of "Key not found". (#4285) (#4366)
  • The path-containment predicate is now a single exported seam — security.cjs no longer exports validatePath. Containment is decided in exactly one place and resolved two ways: assertWithinRoot (throws) and tryWithinRoot (returns null) resolve symlinks, while assertWithinRootLexical and tryWithinRootLexical use string resolution alone and never touch the filesystem, for the few callers that must preserve a symlink rather than resolve it or that validate a destination before it exists. requireSafePath is preserved as an alias of the throwing form. All of them return a branded ContainedPath so a validated path cannot be silently swapped for an unvalidated one. The per-call-site { allowAbsolute: true } flag is replaced by the named PathAcceptance policy, which states what it actually permits: an absolute path outside the root was always rejected and still is. The traversal rejection text Path escapes allowed directory: <resolved> is outside <base> is preserved verbatim, and no command changes what it accepts or rejects. Three rejection MESSAGES are reworded, none of which now reveals a host path it previously hid: state.cts's <label> path rejected: … becomes <label> path validation failed: …, and the sub-repo and agent-skills warnings name the condition instead of echoing the predicate's error string. (#4653) (#4672)
  • Pending todos now render as one bounded bullet per todo in STATE.md. Each capture used to append to a single run-on sentence in "### Pending Todos", growing unbounded and wrecking git diff readability; captures now produce one bullet per todo, capped at 240 characters, with a fail-safe refresh that leaves the section untouched on a malformed lookup. (#2618) (#4384)
  • Codex no longer installs a context-monitor hook that could never fire. gsd-context-monitor.js read a remaining-context bridge file only Claude Code's statusline hook writes, so every one of its Codex hook-event registrations was a guaranteed silent no-op. Fresh Codex installs no longer copy or register it; a reinstall over an older install now removes the stale registrations and the orphaned script. Agent-facing context warnings and phase/lifecycle display are documented as unsupported on Codex until a real metrics producer exists for that runtime. (#2586) (#4367)
  • The codebase drift check now reports real drift instead of flagging every file in the repository on every run. Mapping a codebase records the point it was mapped at, so the check compares against that point, and it skips with a reason when no such record exists. (#4124)
  • Size-cap checks expose pressure before the hard limit — workflow and agent suites report every capped file's remaining headroom and flag files past the 95% reserved margin. (#4261) (#4418)
  • Every path-containment check in the tree now routes through one predicate, enforced by lint — around two dozen hand-rolled containment comparisons were still scattered across installers, capability lifecycle, research storage and command routing; each now takes its decision from the canonical predicate while keeping its own behavior. A new lint rule bans the hand-rolled shape and a discarded containment answer, so a reintroduced copy fails the build. Two rejection messages in capability module loading collapse into one, and a missing module now reports as a module-resolution failure rather than a file-not-found. (#4654) (#4674)

Removed

  • Removed 8 unreferenced planning-artifact scaffolding templates under gsd-core/templates/ (claude-md.md, four of the seven codebase/ brownfield-mapping templates — concerns.md, conventions.md, integrations.md, structure.md — plus debug-subagent-prompt.md and discovery.md) — confirmed, file by file, to have zero references anywhere in workflow prose, agent/command definitions, compiled source, or tests, and (for the deleted set specifically) no surviving basename reference anywhere in the tree either. codebase/architecture.md, codebase/stack.md, and continue-here.md were kept: their basenames collide with unrelated, genuinely live concepts documented across many files (a user's generated .planning/codebase/*.md output, and the real .continue-here.md pause-work artifact), so deleting them would have required rewording numerous translated docs to describe something else entirely. (#4540)

Fixed

  • gsd-tools state begin-phase without --phase now exits non-zero and writes nothing — previously a missing, empty, or flag-shaped phase argument was silently accepted and wrote a null-phase STATE.md (removing current_phase/current_phase_name from frontmatter and serialising the literal Phase null into three body locations), and took a milestone claim for the phase "null". (#4138) (#4380)
  • /gsd-update --reapply no longer re-grafts customizations that upstream already adopted — the documented Incorporated per-file status is now computed by a deterministic pre-flight classifier (hash-validated pristine baseline + every significant user-added line already present verbatim in the new version), so superseded patches are reported as already upstream instead of being silently re-applied on every future update cycle. (#4136) (#4373)
  • The decision-coverage gate now reads phase-prefixed decision IDs — a CONTEXT.md whose decisions use D4-01-style IDs (a digit-run phase prefix) no longer reports could-not-parse for the whole file; its decisions are counted and coverage-checked like any other, and a typo'd prefix (D4x-01) still fails loud. (#4130) (#4357)
  • /gsd:update no longer misreports a global install as LOCAL when the shell sits in $HOME — running the update from a home-directory shell drove the installer's --local arm (settings.local.json + the #338 relocation) against a global install; the preferred-config-dir fast path now applies the same same-path dedup the rest of the detection cascade always has. (#4197) (#4413)
  • A progress bar is full only at 100% — every bar-drawing surface (progress in table and bar format, stats, state update-progress, the STATE.md progress line written by state sync, and the gsd2 import writer) now draws through one render kernel, renderProgressBar, beside the completion-ratio kernel in phase-lifecycle. The six inline copies of Math.round((percent / 100) * width) each rounded to a full bar before the percent reached 100: at the 10-cell width every percent from 95 up drew [██████████], at the 20-cell width every percent from 98 up, so a project at 19/20 plans was visually indistinguishable from a shipped one beside a number that said otherwise. Below 100 the fill is now held one cell short; only those percents move (95-99 at width 10, 98-99 at width 20), every other value in 0-100 renders exactly as before. A null or non-finite percent still renders an empty bar, and an out-of-range percent is clamped instead of throwing RangeError from '░'.repeat as the inline form did at 120%. (#4473)
  • roadmap update-plan-progress no longer false-greens on checklist-form ROADMAPs — a phase whose entry is a - [ ] **Phase N: …** checklist bullet with no writable Progress-table row or detail section now declines with updated: false and a typed missing_phase_details reason, leaving ROADMAP.md byte-identical, instead of reporting success off an unrelated checkbox mark while the phase row stayed untouched and blank lines were injected mid-sentence in other phases' entries. (#4247) (#4468)
  • validate.health no longer flags .planning/PATTERNS.md as an unrecognized file. The graduation workflow (/gsd-extract-learnings) writes this file on gsd-core's own instruction, but the artifact registry was never updated to recognize it -- every repo that had run the graduation scan sat permanently at status: degraded. (#4282) (#4618)
  • state begin-phase no longer rewrites prose that merely quotes a bold field label — a **Status:** (or any served field label) quoted mid-sentence inside prose captured the field rewrite and silently destroyed the rest of its line; the bold form is now anchored to line start, so only the real field updates. Frontmatter round-trip through begin-phase (custom keys, progress subkeys, milestone identity without a ROADMAP) is pinned with regression tests. (#4243) (#4453)
  • The reapply verifier now headlines its baseline coverage instead of reading as fully verified when most files were skipped — after a multi-version update, /gsd-update --reapply reports 'Baseline coverage: N of M file(s)' in the verifier summary, the reapply output, and the installer's update log; on git-managed config dirs the verifier additionally recovers pristine baselines from history by recorded hash, so files upstream heavily changed are diff-verified instead of skipped; an opt-in --min-baseline-coverage <0..1> flag lets cautious operators fail the gate (exit 3) below a coverage threshold. (#4135) (#4376)
  • /gsd-pr-branch no longer silently drops a planning-only commit that mixes a structural .planning/ path (STATE.md, ROADMAP.md, etc.) with a transient or other planning path — such a commit matched none of the classification's four arms and was excluded, which could break STATE.md's per-commit revision chain in default mode. A fifth arm now covers this shape and includes it, same as a mixed code+planning commit. (#4447) (#4537)
  • milestone_name no longer corrupts to ")" for a first-milestone ROADMAP whose H1 puts the version after the name — a punctuation-only heading remainder (e.g. the closing paren of # Roadmap: Project — Name (v1.13)) is refused as a name, so init.* output reports null instead of garbage, and the roadmapper agent now templates the canonical version-free H1. (#4134) (#4358)
  • The catastrophic-shrink write-guard now protects workstream- and project-scoped planning files — hooks/gsd-write-guard.js's curated-file patterns only matched root-level .planning/STATE.md/ROADMAP.md/milestone archives, so a large-shrink Write to a workstream-scoped (.planning/[<project>/]workstreams/<ws>/...) or project-only-scoped (.planning/<project>/...) copy of the same files was never blocked. Found while fixing #4455's workstream-scoped path resolution, which makes such writes reachable via /gsd-complete-milestone's own instructions. (#4542)
  • restore-custom-files no longer re-offers a file that is already byte-identical to its backup — such an entry is reported as already_present, excluded from eligible_count and restored_count, and never rewritten under --apply, so the update workflow's restore prompt settles after one successful restore instead of asking again on every update. (#4558) (#4599)

... (truncated)

Commits
  • f8542fe chore: promote CHANGELOG for v1.14.0
  • 4b402b0 chore: bump version to 1.14.0 for release
  • c0b2a05 fix(#4594): one canonical dispatch-identity owner — the emitted format and th...
  • a155ff4 fix(#4055): verify a phase branch is genuinely new before create-and-switch (...
  • 4f487e4 fix(#3929): seed install-time capability validation with the merged registry ...
  • 0763326 fix(#3780): serialize WINDOWS.md ledger mutations on a cross-process lock (#4...
  • ccb39ae test(#4528): migrate final seam-dispatch batch and retire the timeout-literal...
  • a841575 test(#4527): migrate planning/review-lane batch to named timeout constants (#...
  • 2a5d919 test(#4526): migrate gate/predicate evaluators batch to named timeout constan...
  • 0cee0ee test(#4525): migrate statusline/teams batch to named timeout constants (#4677)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@opengsd/gsd-core](https://github.com/open-gsd/gsd-core) from 1.12.0 to 1.14.0.
- [Release notes](https://github.com/open-gsd/gsd-core/releases)
- [Changelog](https://github.com/open-gsd/gsd-core/blob/next/CHANGELOG.md)
- [Commits](open-gsd/gsd-core@v1.12.0...v1.14.0)

---
updated-dependencies:
- dependency-name: "@opengsd/gsd-core"
  dependency-version: 1.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Looks like @opengsd/gsd-core is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 30, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/opengsd/gsd-core-1.14.0 branch September 30, 2026 07:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants