merge: resolve version/changelog/build conflicts with main (v0.12.8.0)

Main shipped v0.12.8.0 (Codex cwd fix for multi-workspace environments)
while this branch has v0.13.0.0 (design tools). Resolution:
- VERSION: keep 0.13.0.0 (includes main's changes via merge)
- package.json: keep our version + description with main's em-dash fix
- CHANGELOG: keep both entries, 0.13.0.0 on top, 0.12.8.0 below
- Regenerated all skill docs to pick up main's codex cwd resolver changes

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-03-27 00:09:45 -06:00
co-authored by Claude Opus 4.6
18 changed files with 197 additions and 731 deletions
+18
View File
@@ -29,6 +29,24 @@ gstack can generate real UI mockups. Not ASCII art, not text descriptions of hex
- `design/dist/` gitignored like `browse/dist/`
- Full design doc: `docs/designs/DESIGN_TOOLS_V1.md`
## [0.12.8.0] - 2026-03-27 — Codex No Longer Reviews the Wrong Project
When you run gstack in Conductor with multiple workspaces open, Codex could silently review the wrong project. The `codex exec -C` flag resolved the repo root inline via `$(git rev-parse --show-toplevel)`, which evaluates in whatever cwd the background shell inherits. In multi-workspace environments, that cwd might be a different project entirely.
### Fixed
- **Codex exec resolves repo root eagerly.** All 12 `codex exec` commands across `/codex`, `/autoplan`, and 4 resolver functions now resolve `_REPO_ROOT` at the top of each bash block and reference the stored value in `-C`. No more inline evaluation that races with other workspaces.
- **`codex review` also gets cwd protection.** `codex review` doesn't support `-C`, so it now gets `cd "$_REPO_ROOT"` before invocation. Same class of bug, different command.
- **Silent fallback replaced with hard fail.** The `|| pwd` fallback silently used whatever random cwd was available. Now it errors out with a clear message if not in a git repo.
### Removed
- **Dead resolver copies in gen-skill-docs.ts.** Six functions that were moved to `scripts/resolvers/` months ago but never deleted. They had already diverged from the live versions and contained the old vulnerable pattern.
### Added
- **Regression test** that scans all `.tmpl`, resolver `.ts`, and generated `SKILL.md` files for codex commands using inline `$(git rev-parse --show-toplevel)`. Prevents reintroduction.
## [0.12.7.0] - 2026-03-27 — Community PRs + Security Hardening
Seven community contributions merged, reviewed, and tested. Plus security hardening for telemetry and review logging, and E2E test stability fixes.