Skip to content

Releases: RexCode-Digital/shopify-app-changeguard

ChangeGuard v0.5.2

Choose a tag to compare

@github-actions github-actions released this 05 Oct 23:28
Immutable release. Only release title and notes can be modified.
67ef54c

0.5.2

  • Refine npm search metadata and align the Action listing description with configuration review in CI.
  • Include the current third-party notice inventory in the published package.

What's Changed

Full Changelog: v0.5.1...v0.5.2

ChangeGuard v0.5.1

Choose a tag to compare

@github-actions github-actions released this 03 Oct 23:08
Immutable release. Only release title and notes can be modified.

0.5.1

  • Fail closed on incomplete reviews under both review and unreviewed policies.
  • Resolve named Git refs for repository-wide comparisons and reject configuration symlinks, including Git type changes.
  • Make summaries accurately describe the selected failure policy and add focused regressions.

All notable changes to ChangeGuard are documented here. The project follows Semantic Versioning while it remains in the 0.x phase.

What's Changed

  • docs: pin Action examples to v0.5.0 by @efegokdemir in #49
  • docs: prepare ChangeGuard for public launch by @efegokdemir in #50
  • chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in the development-dependencies group by @dependabot[bot] in #56
  • maintain movable minor release aliases by @efegokdemir in #54
  • test: expand privacy-safe configuration coverage by @efegokdemir in #57
  • ci: scope workflow write permissions to release job by @efegokdemir in #58

Full Changelog: v0.5.0...v0.5.1

ChangeGuard v0.5.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 19:18
Immutable release. Only release title and notes can be modified.
1fee675

What's new

  • Added deterministic low, medium, and high risk levels to supported configuration findings.
  • Added a concise risk rationale so reviewers can prioritize authorization, identity, routing, API access, event delivery, and lifecycle changes.
  • Added risk counts to the GitHub Action summary and the highest_risk output for automation.
  • Added risk labels to Git-range CLI output.

Existing rule IDs, exit codes, redaction guarantees, and severity: "review" behaviour remain compatible.

Verification

The release passed the Node 20/22/24 CI matrix, cross-platform Action fixture matrix, CodeQL, dependency review, coverage, npm audit, package smoke, and Action bundle checks.

Full Changelog: v0.4.2...v0.5.0

ChangeGuard v0.4.2

Choose a tag to compare

@github-actions github-actions released this 27 Sep 11:28
25a4384

What's Changed

Full Changelog: v0.4.1...v0.4.2

ChangeGuard v0.4.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 11:05
471bc3f

What's Changed

Full Changelog: v0.4.0...v0.4.1

ChangeGuard v0.4.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 10:53
ddc3f54

What's Changed

Full Changelog: v0.3.0...v0.4.0

ChangeGuard v0.3.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 10:25
8d8f07e

What's Changed

Full Changelog: v0.2.1...v0.3.0

ChangeGuard v0.2.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 09:59
b78f4f8

What's Changed

Full Changelog: v0.2.0...v0.2.1

ChangeGuard v0.2.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 09:36
04bb33f

What's Changed

  • feat: harden ChangeGuard for OSS distribution by @efegokdemir in #17
  • fix: upgrade OpenSSF Scorecard action to v2.4.4 by @efegokdemir in #22
  • chore(deps): bump actions/checkout from 5.1.0 to 7.0.1 by @dependabot[bot] in #18
  • chore(deps): bump actions/setup-node from 5.0.0 to 7.0.0 by @dependabot[bot] in #20
  • chore(deps-dev): bump @types/node from 24.13.5 to 26.6.2 in the development-dependencies group by @dependabot[bot] in #21
  • chore(deps): bump github/codeql-action/upload-sarif from 87ef0dc97def48aa960fbf026a2563ee9dbdb470 to 1190a975f95ce23525efb6a3fc21ea29567c1b52 by @dependabot[bot] in #23
  • chore(deps): bump github/codeql-action/init from 87ef0dc97def48aa960fbf026a2563ee9dbdb470 to 1190a975f95ce23525efb6a3fc21ea29567c1b52 by @dependabot[bot] in #24
  • chore: align CodeQL action pins by @efegokdemir in #26
  • chore: guard release metadata integrity by @efegokdemir in #27
  • docs: prepare public launch workflow and governance by @efegokdemir in #28
  • fix: include compiled CLI in npm package by @efegokdemir in #29
  • docs: clarify local npm bootstrap publication by @efegokdemir in #30
  • chore: migrate CodeQL Action to v4 by @efegokdemir in #31
  • fix: restrict npm package to CLI runtime by @efegokdemir in #32

New Contributors

Full Changelog: v0.1.2...v0.2.0

ChangeGuard v0.1.2 — Experimental

Pre-release

Choose a tag to compare

@efegokdemir efegokdemir released this 17 Sep 22:58
fd9b267

ChangeGuard v0.1.2 — Experimental preview

This experimental update expands Shopify app configuration review,
improves redaction and clarifies GitHub Actions review outcomes.

Changes since v0.1.1

  • Added semantic detection of client ID additions, removals and changes
    without including client ID values in findings.
  • Expanded CLI regression coverage for client ID redaction and malformed
    configuration handling.
  • Added regression tests for webhook delivery destinations, filters and
    related configuration changes.
  • Improved GitHub Actions job summaries with explicit review outcomes:
    no supported-field changes, manual review recommended and review incomplete.
  • Updated the external installation guide to the independently tested
    full Action commit SHA.

Validation

  • 70 automated tests passed locally.
  • GitHub CI and ChangeGuard PR Review passed for the documentation update.
  • An external private test repository successfully detected five synthetic
    configuration changes and displayed Manual review recommended.
  • A separate external test using malformed TOML failed with exit code 2
    and displayed Review incomplete with one unreviewable configuration.

Limitations

  • Findings are informational and do not block pull requests.
  • Added, deleted or unreviewable Shopify TOML configurations fail the check.
  • ChangeGuard is an unofficial, experimental, read-only reviewer.
  • It does not access Shopify, perform a security audit or approve deployment.
  • It is not affiliated with, endorsed by or certified by Shopify.
  • The package remains private. No npm package is being published.