Releases: RexCode-Digital/shopify-scope-guard
Release list
v0.2.2
0.2.2
- Refresh published npm metadata to the canonical RexCode-Digital repository and issue tracker.
- Preserve the existing package name, license, author attribution, and runtime behavior.
What's Changed
- chore: align project metadata with RexCode by @efegokdemir in #17
- chore: prepare 0.2.2 RexCode metadata release by @efegokdemir in #18
Full Changelog: v0.2.1...v0.2.2
v0.2.1
0.2.1
-
Declare Node 24 for the GitHub Action, matching current runner support; CLI engines remain Node >=20.
-
Correct access-scope evidence against official 2026-10 documentation, including write-only analytics mutations and read alternatives.
-
Resolve local GraphQL fragments and aliases while preserving unknown evidence for unsupported patterns.
-
Reject file symlinks, invalid or ambiguous configurations, and malformed options; bound scanned files.
-
Make Action outcomes match failure policy and return actual JSON/SARIF report files.
-
Replace registry self-comparison tests with real operation fixtures and validate packaged Action contents.
-
Retain GraphQL 16 and Node >=20; GraphQL 17 requires newer Node engines.
What's Changed
- fix: use supported Node runtime for npm publishing by @efegokdemir in #11
- chore(deps): bump github/codeql-action/upload-sarif from 87ef0dc97def48aa960fbf026a2563ee9dbdb470 to 1190a975f95ce23525efb6a3fc21ea29567c1b52 in /.github/workflows by @dependabot[bot] in #7
- chore(deps): bump github/codeql-action/analyze from 87ef0dc97def48aa960fbf026a2563ee9dbdb470 to 1190a975f95ce23525efb6a3fc21ea29567c1b52 in /.github/workflows by @dependabot[bot] in #8
- chore(deps): bump github/codeql-action/init from 87ef0dc97def48aa960fbf026a2563ee9dbdb470 to 1190a975f95ce23525efb6a3fc21ea29567c1b52 in /.github/workflows by @dependabot[bot] in #9
- Correct scope evidence and harden GraphQL analysis by @efegokdemir in #12
- Declare the supported GitHub Action runtime by @efegokdemir in #13
Full Changelog: v0.2.0...v0.2.1
v0.2.0
What's Changed
- docs: align repository presentation with Shopify tooling family by @efegokdemir in #6
- chore(deps): bump actions/checkout from 4.2.2 to 7.0.1 in /.github/workflows by @dependabot[bot] in #1
- build(deps): bump ossf/scorecard-action from 2.3.1 to 2.4.4 in /.github/workflows by @dependabot[bot] in #2
- build(deps): bump actions/setup-node from 4.4.0 to 7.0.0 in /.github/workflows by @dependabot[bot] in #5
- feat: add Shopify 2026-10 scope evidence by @efegokdemir in #10
New Contributors
- @dependabot[bot] made their first contribution in #1
Full Changelog: v0.1.0...v0.2.0
Shopify Scope Guard v0.1.0
Initial public release of Shopify Scope Guard: an offline, deterministic CLI and GitHub Action for evidence-backed Shopify Admin GraphQL access-scope audits. Includes human, JSON, and SARIF output, versioned evidence, documented limitations, and no runtime Shopify access.