Skip to content
CAI
Software that uses CAICheck a score

open-gsd/gsd-core

51.5

Adequate · 2 October 2026

237.7k

lines of production code

TypeScript

with JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a security-focused orchestration engine, known as GSD (Guarded Session Director), designed to manage AI agent workflows and planning artifacts across multiple development hosts like VS Code, Cursor, and Cline. It provides a unified interface for state management, capability validation, and health diagnostics, ensuring consistent behavior and isolation across different environments. The platform supports both native plugin integrations and standard MCP server protocols, allowing external AI models to safely drive project tasks while enforcing strict security guards against prompt injection and unauthorized changes.

Features

Installable GSD extension for pi with robust hook discovery

Users can now install the GSD extension as a native pi plugin (gsd.js), enabling GSD commands to be executed directly within the pi environment. The extension resolves GSD's shared hook bundle by probing for a staged 'gsd-hooks' directory first, falling back to the legacy 'hooks' directory to prevent silent failures during upgrades or partial installs. It also suppresses spurious TypeBox fallback warnings on startup and ensures command output is correctly routed through pi's display and notification systems.

pi · high confidence

Installer migration framework rewritten in TypeScript

The installer migration logic in src/installer-migrations has been migrated from hand-written CommonJS (.cjs) to TypeScript (.cts) source files, establishing a single source of truth for migration behaviors. This change introduces a suite of new migration scripts (000 through 009) that handle specific upgrade tasks, including recording a first-time baseline, removing legacy orphan hook files, cleaning up stale pristine snapshots from the get-shit-done to gsd-core rename, baselining OpenCode's commands directory, retiring obsolete file extensions for the pi runtime, removing stale CommonJS markers from the config root, and retiring duplicate command surfaces for Cursor and legacy hook directories for pi.

src/installer-migrations · high confidence

Introduce GSD plugin adapter for OpenCode

Added a new GSD (Guardrails/Security/Debug) plugin adapter for OpenCode that bridges OpenCode plugin events to existing Claude Code hook scripts. The adapter translates OpenCode tool calls (Read, Write, Bash, etc.) into Claude Code payloads, spawns the hooks as child processes, and maps their outputs back to OpenCode semantics (blocking errors or advisory metadata). It supports two distribution modes: a file-copy installation where GSD handles command registration, and a package/git-spec mode where the plugin registers commands, agents, and skills itself, ensuring no double-registration in the installed config directory.

.opencode · high confidence

Introduces gsd-mcp-server companion bin entry

Adds a new \bin/gsd-mcp-server.js\ executable that acts as a stdio JSON-RPC 2.0 server, exposing GSD command and state I/O interface points to any MCP-consuming host (such as Claude, Codex, OpenCode, VS Code, Gemini, Cursor, Cline, or Hermes) without requiring bespoke plugins. The server delegates to the tested \mcp-server.cjs\ module, reading line-delimited JSON-RPC from stdin and writing responses to stdout, enabling external hosts to drive GSD capabilities natively.

bin · high confidence

New CI and security tooling scripts for affected-test selection and environment validation

Added several new scripts to the \scripts/\ directory to improve CI reliability and security scanning. \affected-tests-lib.cjs\ introduces a forward dependency graph and transitive reverse index to accurately select test suites based on changed source files, replacing previous heuristics. \check-env.cjs\ provides a Node.js-based environment parity validator to catch configuration mismatches early. Security scanning is enhanced with \base64-scan.sh\ to detect base64-obfuscated prompt injections, and \audit-workflow-script-paths.cjs\ validates that workflow-invoked scripts exist and are correctly installed. Additional utilities include \check-alias-drift.cjs\ for validating command alias consistency, \check-coverage-gate.cjs\ for enforcing code coverage thresholds, and \benchmark-compact-content.cjs\ for performance benchmarking.

scripts · high confidence

New CLI tooling and self-healing runtime build for GSD tools

The \gsd-core/bin\ directory now includes a comprehensive set of new scripts to support the GSD workflow. \gsd-tools.cjs\ serves as the central CLI utility, replacing repetitive inline bash patterns with a unified command interface for state management, phase operations, roadmap updates, and verification. To support plugin-marketplace installations where pre-built artifacts are missing, \ensure-runtime-build.cjs\ provides a self-healing mechanism that automatically compiles the runtime library on demand. Additionally, \check-latest-version.cjs\ offers a deterministic, safe check for the latest package version to prevent typosquatting, and \verify-reapply-patches.cjs\ implements a strict, deterministic gate to verify that user-added lines survive patch reapplication, addressing previous issues with silent content loss.

gsd-core/bin · high confidence

New ESLint rules enforce portability, reliability, and seam usage conventions

This change introduces a suite of new ESLint rules to the \eslint-rules\ directory to enforce specific code quality and portability standards. The \no-adhoc-markdown-parsing\ rule flags hand-rolled regex patterns for parsing markdown fences, sections, and tables, requiring imports from the canonical \markdown-sectionizer\ and \markdown-table\ seams. The \no-adhoc-regex-escape\ rule prevents manual regex metacharacter escaping outside the \src/pattern.cts\ seam. To improve Windows test portability, \no-bare-npm-exec\ requires \{ shell: true }\ for direct \npm\ binary invocations, and \no-crlf-fragile-split\ flags \.split('\\n')\ or regexes with bare newlines on \readFileSync\ content. Reliability is improved by \no-adhoc-timeout-literal\, which bans bare numeric timeout values in tests in favor of named constants, and \no-elapsed-assertion\, which prevents flaky timing assertions. Additionally, \no-duplicate-fold-marker\ detects duplicated consolidated test suites, and \no-exact-case-env-access\ flags case-sensitive environment variable reads from non-\process.env\ receivers to prevent Windows-specific failures.

eslint-rules · high confidence

New GSD core plugin adapter for OpenCode.ai

A new GSD (Guarded Session Director) plugin adapter has been added to the Kilo native plugin system. This adapter acts as a bridge between OpenCode plugin events and existing Claude Code hook scripts, translating tool names and arguments to ensure compatibility. It supports two distribution modes: a file-copy installation where it skips redundant command registration, and a package/tree installation where it handles full registration. The plugin also includes logic to resolve its repository root dynamically across different installation layouts and reuses existing namespace conversion scripts for slash commands.

.kilo · high confidence

New capability management CLI and hardened validation

The \gsd\ CLI now includes a dedicated \capability\ command (exposed via \capability-command-router.cjs\) for managing capability state, installation, and consent, replacing the previous inline logic in the main tools binary. This is supported by a new \capability-validator.cjs\ that enforces strict schema rules for capability manifests, including SemVer versioning, config-slice types, and enum constraints. Additionally, the \exit-code-registry.cjs\ has been updated to standardize exit codes (e.g., \HOOK\_DENY\, \NO\_INPUT\) for better error reporting, and \legacy-cleanup.cjs\ now safely removes stale artifacts from the previous \get-shit-done\ package name during upgrades.

gsd-core/bin/lib · high confidence

New changeset-fragment workflow for release notes and changelog management

The \scripts/changeset\ directory now provides a complete tooling suite for managing release notes via a fragment-based workflow. Contributors create small markdown fragments in \.changeset/\ using the \new\ subcommand, which are validated by a new \lint\ script that enforces fragment presence on user-facing changes and checks for PR number drift. The \cli\ entry point orchestrates the process: \render\ consumes fragments to update \CHANGELOG.md\ (with a new \--preview\ mode for release candidates), \extract\ pulls historical entries with strict semver validation, and \github-release-notes\ generates structured release bodies with categorized fixes. This replaces ad-hoc changelog editing with an automated, conflict-resistant pipeline.

scripts/changeset · high confidence

New health diagnostic rules for agent installation, config validation, and project consistency

The health diagnostic system now includes new rule modules for agent installation status (W010), config.json validation (W003, E005, W004, W008, W016, W012, W013), milestone archive hygiene (W018, W019), and cross-scope install shadowing (W028). Additionally, consistency checks (C001–C004) have been added to detect gaps in phase/plan numbering, orphan summaries, and missing frontmatter. These rules provide more granular feedback on project health, including warnings for missing or incomplete GSD agents, invalid configuration values, and structural inconsistencies in the planning directory.

src/health-diagnostic-rules · high confidence

New isolation guard and Cursor lifecycle hooks

Added a new PreToolUse isolation guard (gsd-agent-isolation-guard.js) that hard-blocks GSD executor dispatches when harness-worktree isolation is required but not enforced, preventing accidental commits to the primary checkout. Added a suite of Cursor-specific lifecycle hooks (sessionStart, preToolUse, postToolUse, stop, subagentStart) that inject GSD state reminders and enforce the same isolation guard for Cursor subagents. Updated the update-check mechanism to use atomic file writes and self-heal missing build artifacts.

hooks · high confidence

New reference example for dynamic context management predicate parsing

Added a non-shipping reference example under examples/dynamic-context-management that demonstrates the Option-E predicate fact-store slice of the dynamic context management platform. The example includes a self-contained parser (context-predicates.cjs) that extracts CLASS.subkey=value predicates from CONTEXT.md, a generator script (gen-context-index.cjs) to build and drift-guard a deterministic CONTEXT-INDEX.json, and a demo script. The parser uses structural validation to avoid catastrophic backtracking and rejects malformed predicates with specific reasons. The index supports querying by class, prefix, or free-text containment to select relevant predicate subsets for just-in-time task briefs.

examples · high confidence

New scripts/lib modules for CI guards, exit contracts, and test diagnostics

This change introduces several new modules in scripts/lib to improve CI reliability and CLI robustness. allowlist-ratchet.cjs replaces count-based ratchets with identity-based guards to prevent defect masking, while ci-job-timing.cjs provides arithmetic for near-cap warnings and trending. cli-exit.cjs and exit-code-registry.cjs establish a unified exit-contract system with versioned outcome projection and a centralized code registry. ndjson-reporter.cjs adds a durable, synchronous JSON reporter to capture test events even after process kills, enabling better hang diagnosis. alias-drift-families.cjs centralizes command-alias validation to fix pre-commit hook drift, and drift-scan.cjs provides a shared, symlink-aware tree-walk for drift guards. macOS-conformance-tier.generated.cjs and platform-conformance-tier.generated.cjs define platform-specific test tiers, and npm-version-check-diagnosis.cjs improves error reporting for npm version checks.

scripts/lib · high confidence

VS Code extension now supports web (vscode.dev) alongside desktop

The VS Code extension now includes a dedicated browser entry point (browser.js) that enables the GSD extension to run in web-based IDEs like vscode.dev. This web build is strictly zero-Node-API, avoiding any file-system or subprocess calls that are unavailable in the browser environment. Consequently, while the chat participant and Language Model Tools are registered and discoverable in the web UI, their handlers return a message instructing users to configure the GSD MCP server for full command dispatch, as the native engine dispatch relies on Node.js subprocesses. The desktop extension (extension.js) remains the primary entry point for full functionality, utilizing the existing host-binding and engine integration.

vscode · high confidence

Behavioural changes

987 commits (223 fixes) modifying (repo-wide)

A change to existing behaviour in (repo-wide) — 987 commits (223 fixs), 27 files.

(repo-wide) · low confidence · unverified

Introduce canonical configuration manifests and model routing catalog

This change establishes a new set of shared JSON manifests in gsd-core/bin/shared that serve as the single source of truth for the application's configuration and runtime behavior. The config-defaults.manifest.json defines the complete nested structure and default values for all configuration keys (such as workflow modes, gate settings, and security enforcement), while the config-schema.manifest.json explicitly lists every valid configuration path to enforce validation at the boundary. A new model-catalog.json centralizes the mapping of AI providers (including Codex, Claude, Qwen, and others) to specific model IDs and reasoning effort levels, replacing ad-hoc definitions. Additionally, the system introduces a standardized exit-code registry (exit-codes.json and its shell projection) to ensure consistent error reporting across tools, and a runtime-aliases.manifest.json to normalize various CLI executable names to internal runtime identifiers.

gsd-core/bin/shared · high confidence

Migrate Cline and Cursor hosts to imperative adapters with enhanced hook and model capabilities

The host-integration-adapters now use imperative adapters for both Cline and Cursor, replacing previous file-convention or hardcoded approaches. For Cline, a new SDK binding implements a \beforeTool\ planning-artifact guard that blocks write-class tools targeting \.planning/\ paths (preserving the previous fail-open cancel behavior) and resolves model overrides via \createAgentModel\ to support per-subagent model profiles. For Cursor, a descriptor-driven hook-bus adapter generalizes hook registration to a configurable set of events (session, tool, subagent, stop) instead of hardcoded pairs, allowing the host to dynamically manage which hook scripts are installed and registered in \hooks.json\.

src/host-integration-adapters · high confidence

New ESLint rules enforce cross-platform portability and prevent unsafe file-processing patterns

The \eslint-rules/lib\ directory now includes three new linting utilities that enforce stricter portability and safety standards. \platform-guard.cjs\ introduces logic to detect and flag path literals in assertions that may behave differently on Windows versus other platforms, ensuring consistent behavior across operating systems. \portability-vocab.cjs\ provides a centralized vocabulary of path-returning functions and Windows-specific environment variables, enabling rules to catch hardcoded paths and case-sensitive environment variable access that could break on Windows. Additionally, \readfilesync-trace.cjs\ extracts shared data-flow tracing logic for \readFileSync\ usage, allowing other rules to accurately identify when regular expressions are applied to file content read synchronously, thereby preventing fragile string-splitting patterns that fail with CRLF line endings.

eslint-rules/lib · high confidence

New pre-commit alias drift check and configurable pre-push author block

The repository now includes \.githooks/pre-commit\ and \.githooks/pre-push\ scripts. The pre-commit hook detects staged changes to specific command-alias source files (e.g., \src/command-aliases.cts\) and runs an alias drift check to ensure consistency. The pre-push hook adds a configurable security guard: if the \GSD\_BLOCKED\_AUTHOR\_REGEX\ environment variable is set, it blocks pushes containing commits from authors whose email addresses match the provided regex, helping prevent accidental commits from restricted domains.

.githooks · high confidence

Release notes now filter out internal commits and validate PR titles

The release-notes scripts now automatically exclude non-user-facing commits (such as docs, refactors, tests, CI, chores, perf, and reverts) from the public changelog, grouping them as 'Internal' instead. To ensure the changelog classifier and the CI gate agree on what constitutes a valid commit, a single source of truth for conventional commit parsing has been introduced, and PR titles are now validated at open time to enforce the required format (type with a linked issue reference).

scripts/release-notes · high confidence

Vendored js-yaml and re2js libraries for offline runtime use

The \gsd-core/bin/lib/vendor\ directory now contains verbatim copies of the \js-yaml\ (YAML parsing) and \re2js\ (linear-time regular expression engine) build artifacts. This change ensures that \gsd-core/bin\ functions correctly in installation trees that lack \node\_modules\, by embedding these dependencies directly in the source tree rather than relying on external npm resolution.

gsd-core/bin/lib/vendor · high confidence

Vendored js-yaml and re2js type definitions added

Hand-authored TypeScript declaration files (\.d.cts\) have been added for the vendored \js-yaml\ and \re2js\ libraries to provide type safety for the project. The \js-yaml\ types are deliberately narrowed to expose only \load\, \dump\, \FAILSAFE\_SCHEMA\, and \YAMLException\, enforcing a security posture that prevents callers from using dangerous features like \loadAll\ or custom schemas, while relying on runtime checks in \frontmatter.cts\ to refuse anchors and aliases. The \re2js\ types expose the \RE2Set\, \Matcher\, and related classes for linear-time regex matching.

src/vendor · high confidence

Fixes

1076 commits (673 fixes) fixing src

A fix in src — 1076 commits (673 fixs), 236 files.

src · medium confidence · unverified

New shared hook library for isolation, exit handling, and injection scanning

The \hooks/lib\ directory now contains a suite of shared modules that standardize hook behavior and improve security. \isolation-sentinel.js\ and \isolation-deny-reason.js\ centralize the logic for dispatch-isolation guards, ensuring that isolation decisions are based on the resolved workflow state rather than host capabilities, and providing stable reason codes for test assertions. \cli-exit.js\ and \hook-exit.js\ implement a structured exit contract with explicit crash policies (allow vs. deny) to prevent silent failures. \injection-patterns.js\ unifies prompt-injection signatures across hooks, including a filler-tolerant pattern to catch more evasion attempts. \git-cmd.js\ replaces fragile regex-based git detection with a robust token-walk classifier, and \git-probe.js\ distinguishes between genuine negative results and timeouts in git probes. \cursor-workspace.js\ fixes workspace resolution for Cursor hooks by using \workspace\_roots\ instead of \cwd\. \filename-classification.js\ closes a Windows path-alias bypass for \.env\ files, and \dispatch-identity.js\ provides a canonical parser for dispatch markers.

hooks/lib · high confidence

Standardized gsd-tools launcher and identity verification across all workflows

All workflows now use a unified, self-contained shell snippet to locate and invoke \gsd-tools.cjs\. This launcher searches standard runtime config directories (e.g., \.claude\, \.codex\, \.agents\) and the project root, verifies the tool's identity as \@opengsd/gsd-core\ via the \runtime-identity\ verb, and fails loudly if a valid, matching binary is not found. This ensures consistent tool resolution and prevents execution against foreign or outdated \gsd-tools\ versions.

gsd-core/workflows · high confidence

Test coverage

2418 commits adding/updating tests in tests; Added test fixtures for base64-locale scanning edge cases; Added test fixtures for offline-proofing, benchmarking, and host bindings; Added tests for health diagnostic rules; Added tests for observability event shape, trace correlation, and logger integration; New test helpers for CLI, fixtures, and content guards.

Dependencies

GSD Core v1.15.0: Scoped package, Node 24 requirement, and VS Code integration

The \@opengsd/gsd-core\ package is now published under the \@opengsd\ scope (previously \get-shit-done-cc\), with the minimum Node.js runtime raised to 24.0.0. This release introduces a VS Code extension (\gsd-core-vscode\) that embeds the GSD orchestration engine, exposing chat participants and model tools for progress, workstreams, and phase planning. The dependency tree has been updated to include \@anthropic-ai/claude-agent-sdk\ and \ws\, while dev tooling now uses ESLint 9, TypeScript 6, and Stryker for mutation testing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 60 → 51 (-8.1)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 49 → 49 (+0.2)
  • Architecture 69 → 67 (-1.6)
  • Maturity 78 → 78 (+0.1)
  • Readiness 63 → 43 (-19.4)
  • Security 92 → 88 (-4.0)
  • Performance 60 (new)

Resolved (118)

  • ADR lacks an enforcement field (.changeset/3638-bracket-display.md)
  • ADR lacks an enforcement field (.changeset/4668-state-write-intent-surface.md)
  • ADR lacks an enforcement field (.changeset/4685-verify-artifacts-directory.md)
  • Consequences/trade-offs are absent despite an informative title (.changeset/archived/3591-gsdtools-native-workstream.md)
  • Consequences/trade-offs are cut off by the scanner clip marker mid-summary and cannot be flagged as missing (.changeset/archived/3740-consolidate-phase-tests.md)
  • Consequences/trade-offs are not stated (e.g., the forceSdk flag may be misused to bypass real SDK install) (.changeset/archived/3033-sdk-flag-wired.md)
  • Context/problem is thin: only the decision (tighten SDK-first seams across four paths) and benefits are stated; consequences/trade-offs are absent (.changeset/archived/3312-sdk-first-architecture-seams.md)
  • Context/problem is thin: only the stabilization goal and one concrete consequence (prevent uninstall-time crashes) are stated; no motivation or alternative under consideration (.changeset/archived/3450-shell-projection-merge-repair.md)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no architecture or design documentation (docs/README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (docs/README.md)
  • FileTooLong: src/check-command-router.cts (src/check-command-router.cts)
  • FunctionTooLong: check-command-router.cmdApiCoverageVerifyPre (src/check-command-router.cts)
  • FunctionTooLong: config-loader.loadConfigResolved (src/config-loader.cts)
  • FunctionTooLong: roadmap-parser.extractCurrentMilestoneScoped (src/roadmap-parser.cts)
  • Hotspot: eslint-rules/lib/portability-vocab.cjs (eslint-rules/lib/portability-vocab.cjs)
  • Hotspot: eslint-rules/no-adhoc-regex-escape.cjs (eslint-rules/no-adhoc-regex-escape.cjs)
  • Hotspot: eslint-rules/no-crlf-fragile-split.cjs (eslint-rules/no-crlf-fragile-split.cjs)
  • Hotspot: eslint-rules/no-path-literal-in-assert.cjs (eslint-rules/no-path-literal-in-assert.cjs)
  • …and 98 more

New (192)

  • ADR lacks an enforcement field (docs/adr/4780-labeled-arguments-block.md)
  • ADR lacks an enforcement field (docs/adr/4910-planning-document-seam.md)
  • ADR lacks an enforcement field (docs/adr/5057-one-owner-per-workflow-verdict.md)
  • Assertions commented out: invalid: roadmapContent.replace(<synthesized bold-label field regex>, ...) is flagged as field-shaped (tests/eslint-rules.test.cjs)
  • Consequences/trade-offs are absent despite a solid problem statement (.changeset/archived/3033-sdk-flag-wired.md)
  • Consequences/trade-offs are absent despite a strong decision and visible results (.changeset/archived/3740-consolidate-phase-tests.md)
  • Consequences/trade-offs are not present in the visible text (.changeset/archived/3591-gsdtools-native-workstream.md)
  • Context/problem is thin and the decision/consequences fall below the clip marker; trade-offs are not visible (.changeset/archived/3450-shell-projection-merge-repair.md)
  • Context/problem is thin: only the added fixture directories and test names are named; no rationale for why adversarial input was chosen (.changeset/archived/3594-parser-adversarial-fixtures.md)
  • Context/problem is thin: only the decision (tighten SDK-first seams across planning path projection, workstream inventory, transforms, CJS command routing) and benefits ('Shared CJS/SDK helpers now reduce drift') are stated; consequences/trade-offs are absent (.changeset/archived/3312-sdk-first-architecture-seams.md)
  • Context/problem is thin: only the generated builder source and freshness guard wire is described; no problem statement or consequences (.changeset/archived/3544-workstream-inventory-builder.md)
  • Documentation: no project overview (docs/zh-CN/README.md)
  • Documentation: written for insiders (tests/fixtures/adversarial/toml/README.md)
  • FileTooLong: scripts/ci-timeout-report.cjs (scripts/ci-timeout-report.cjs)
  • FileTooLong: src/phase-id.cts (src/phase-id.cts)
  • FileTooLong: src/roadmap-upgrade.cts (src/roadmap-upgrade.cts)
  • FunctionTooLong: config-loader.loadConfigResolvedInternal (src/config-loader.cts)
  • FunctionTooLong: gate-api-coverage-verify-pre.evaluateApiCoverageVerifyPre (src/gate-api-coverage-verify-pre.cts)
  • FunctionTooLong: roadmap-upgrade.computeBracketPlan (src/roadmap-upgrade.cts)
  • Hotspot: scripts/lib/ndjson-reporter.cjs (scripts/lib/ndjson-reporter.cjs)
  • …and 172 more

Changes since last survey

  • 164 commits — 52 feature/other, 112 fixes

By area

  • (root) — 19 commits
  • gsd-core/workflows — 13 commits
  • src/phase.cts — 12 commits
  • (repo) — 11 commits
  • tests/fixtures — 9 commits
  • .github/workflows — 7 commits
  • docs/adr — 5 commits
  • scripts/lib — 5 commits
  • .changeset/eager-wolves-bark.md — 2 commits
  • .changeset/noble-ibex-swim.md — 2 commits
  • .changeset/phase6-drain-grandfather-allowlist.md — 2 commits
  • docs/features — 2 commits
  • docs/how-to — 2 commits
  • eslint-rules/no-adhoc-markdown-parsing.cjs — 2 commits
  • gsd-core/references — 2 commits
  • src/planning-document.cts — 2 commits
  • src/roadmap-parser.cts — 2 commits
  • .changeset/agile-cranes-parade.md — 1 commit
  • .changeset/bold-badgers-march.md — 1 commit
  • .changeset/bold-deer-click.md — 1 commit

Notable commits

  • fix: Merge branch 'next' into fix/5008-emitted-baseline-at-merge-base
  • fix: Merge pull request #5009 from open-gsd/fix/5008-emitted-baseline-at-merge-base
  • fix: Revert "chore(#4990): make next merge-queue-ready and gate back-merges on verified green CI (#4999)" (#5001)
  • fix: fix(#4415): treat an absent worktree as removed, not as a branch mismatch (#4612)
  • fix: fix(#4434): win32 unmeasured test files weigh the documented ~2.2x Windows-cost floor, not the Linux-measured mean (#4903)
  • fix: fix(#4588): observe fork-from-HEAD from prior harness worktrees before degrading (#4868)
  • fix: fix(#4664): preserve Codex foreground handoffs (#4695)
  • fix: fix(#4667): rewrite codex @ includes to the codex install root (#4858)
  • fix: fix(#4683): detect cross-plan threat-ID duplicates before execution (#4828)
  • fix: fix(#4699): skip already-complete phases in the next_phase cascade (#4820)
  • fix: fix(#4700): queue the headless mempalace mine on the palace lock (#4821)
  • fix: fix(#4705): emit Antigravity-native tool names as a YAML sequence (#4822)
  • fix: fix(#4717): consult the per-install runtime marker at both identity seams (#4861)
  • fix: fix(#4724): classify Surefire/Failsafe XML as RED evidence (#4825)
  • fix: fix(#4725): write normalization preserves tight paragraph-list shape (#4842)
  • fix: fix(#4731): read hard-wrapped Goal/Requirements fields past the line break (#4826)
  • fix: fix(#4734): degrade worktree isolation when the root has no git repository (#4843)
  • fix: fix(#4738): record opencode's staged skills in the install manifest (#4847)
  • fix: fix(#4741): the plan checkbox tick respects the superseded exclusion (#4851)
  • fix: fix(#4757): roadmap analyze surfaces checkbox/disk disagreement via checkbox_conflict (#5146)
  • …and 144 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

open-gsd/gsd-core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2cc432e73add46891016671d7303e10aa69eecfd — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.