Releases: RexCode-Digital/shopify-app-changeguard
Release list
ChangeGuard v0.5.2
0.5.2
- Refine npm search metadata and align the Action listing description with configuration review in CI.
- Include the current third-party notice inventory in the published package.
What's Changed
- Harden incomplete configuration reviews and Git inputs by @efegokdemir in #59
- Fix write permission for the existing minor release alias job by @efegokdemir in #60
- fix: use canonical repository URLs by @efegokdemir in #62
- fix: use canonical security report URL by @efegokdemir in #63
- chore: align remaining RexCode metadata with current main by @efegokdemir in #64
- docs: add privacy-safe issue templates by @efegokdemir in #65
- docs: include bundled third-party notices by @efegokdemir in #66
- build: ship bundled dependency licence inventory by @efegokdemir in #67
- chore: improve discovery metadata and release by @efegokdemir in #68
Full Changelog: v0.5.1...v0.5.2
ChangeGuard v0.5.1
0.5.1
- Fail closed on incomplete reviews under both review and unreviewed policies.
- Resolve named Git refs for repository-wide comparisons and reject configuration symlinks, including Git type changes.
- Make summaries accurately describe the selected failure policy and add focused regressions.
All notable changes to ChangeGuard are documented here. The project follows Semantic Versioning while it remains in the 0.x phase.
What's Changed
- docs: pin Action examples to v0.5.0 by @efegokdemir in #49
- docs: prepare ChangeGuard for public launch by @efegokdemir in #50
- chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in the development-dependencies group by @dependabot[bot] in #56
- maintain movable minor release aliases by @efegokdemir in #54
- test: expand privacy-safe configuration coverage by @efegokdemir in #57
- ci: scope workflow write permissions to release job by @efegokdemir in #58
Full Changelog: v0.5.0...v0.5.1
ChangeGuard v0.5.0
What's new
- Added deterministic low, medium, and high risk levels to supported configuration findings.
- Added a concise risk rationale so reviewers can prioritize authorization, identity, routing, API access, event delivery, and lifecycle changes.
- Added risk counts to the GitHub Action summary and the
highest_riskoutput for automation. - Added risk labels to Git-range CLI output.
Existing rule IDs, exit codes, redaction guarantees, and severity: "review" behaviour remain compatible.
Verification
The release passed the Node 20/22/24 CI matrix, cross-platform Action fixture matrix, CodeQL, dependency review, coverage, npm audit, package smoke, and Action bundle checks.
Full Changelog: v0.4.2...v0.5.0
ChangeGuard v0.4.2
What's Changed
- fix: complete rule catalogue and refresh stable references by @efegokdemir in #44
- release: ChangeGuard v0.4.2 by @efegokdemir in #45
Full Changelog: v0.4.1...v0.4.2
ChangeGuard v0.4.1
What's Changed
- docs: refresh public v0.4.0 references by @efegokdemir in #41
- release: ChangeGuard v0.4.1 by @efegokdemir in #43
Full Changelog: v0.4.0...v0.4.1
ChangeGuard v0.4.0
What's Changed
- docs: update examples for v0.3.0 by @efegokdemir in #38
- feat: complete semantic Shopify app configuration review by @efegokdemir in #39
- release: ChangeGuard v0.4.0 by @efegokdemir in #40
Full Changelog: v0.3.0...v0.4.0
ChangeGuard v0.3.0
What's Changed
- feat: review Events configuration and test Action portability by @efegokdemir in #35
- docs: update post-release Action references by @efegokdemir in #36
- release: ChangeGuard v0.3.0 by @efegokdemir in #37
Full Changelog: v0.2.1...v0.3.0
ChangeGuard v0.2.1
What's Changed
- docs: update public installation guidance by @efegokdemir in #33
- release: publish v0.2.1 documentation patch by @efegokdemir in #34
Full Changelog: v0.2.0...v0.2.1
ChangeGuard v0.2.0
What's Changed
- feat: harden ChangeGuard for OSS distribution by @efegokdemir in #17
- fix: upgrade OpenSSF Scorecard action to v2.4.4 by @efegokdemir in #22
- chore(deps): bump actions/checkout from 5.1.0 to 7.0.1 by @dependabot[bot] in #18
- chore(deps): bump actions/setup-node from 5.0.0 to 7.0.0 by @dependabot[bot] in #20
- chore(deps-dev): bump @types/node from 24.13.5 to 26.6.2 in the development-dependencies group by @dependabot[bot] in #21
- chore(deps): bump github/codeql-action/upload-sarif from 87ef0dc97def48aa960fbf026a2563ee9dbdb470 to 1190a975f95ce23525efb6a3fc21ea29567c1b52 by @dependabot[bot] in #23
- chore(deps): bump github/codeql-action/init from 87ef0dc97def48aa960fbf026a2563ee9dbdb470 to 1190a975f95ce23525efb6a3fc21ea29567c1b52 by @dependabot[bot] in #24
- chore: align CodeQL action pins by @efegokdemir in #26
- chore: guard release metadata integrity by @efegokdemir in #27
- docs: prepare public launch workflow and governance by @efegokdemir in #28
- fix: include compiled CLI in npm package by @efegokdemir in #29
- docs: clarify local npm bootstrap publication by @efegokdemir in #30
- chore: migrate CodeQL Action to v4 by @efegokdemir in #31
- fix: restrict npm package to CLI runtime by @efegokdemir in #32
New Contributors
- @dependabot[bot] made their first contribution in #18
Full Changelog: v0.1.2...v0.2.0
ChangeGuard v0.1.2 — Experimental
ChangeGuard v0.1.2 — Experimental preview
This experimental update expands Shopify app configuration review,
improves redaction and clarifies GitHub Actions review outcomes.
Changes since v0.1.1
- Added semantic detection of client ID additions, removals and changes
without including client ID values in findings. - Expanded CLI regression coverage for client ID redaction and malformed
configuration handling. - Added regression tests for webhook delivery destinations, filters and
related configuration changes. - Improved GitHub Actions job summaries with explicit review outcomes:
no supported-field changes, manual review recommended and review incomplete. - Updated the external installation guide to the independently tested
full Action commit SHA.
Validation
- 70 automated tests passed locally.
- GitHub CI and ChangeGuard PR Review passed for the documentation update.
- An external private test repository successfully detected five synthetic
configuration changes and displayed Manual review recommended. - A separate external test using malformed TOML failed with exit code 2
and displayed Review incomplete with one unreviewable configuration.
Limitations
- Findings are informational and do not block pull requests.
- Added, deleted or unreviewable Shopify TOML configurations fail the check.
- ChangeGuard is an unofficial, experimental, read-only reviewer.
- It does not access Shopify, perform a security audit or approve deployment.
- It is not affiliated with, endorsed by or certified by Shopify.
- The package remains private. No npm package is being published.