Skip to content

Releases: mingxian233/ContractGuard

ContractGuard v1.1.0 — Multi-LLM Profiles, Policy-as-Code, and Audit Fingerprints

Choose a tag to compare

@mingxian233 mingxian233 released this 23 Sep 08:43

What's new

ContractGuard 1.1.0 adds configurable model profiles and auditable policy controls while keeping compatibility decisions deterministic and local-first.

Highlights

  • Server-owned multi-LLM profiles: configure DeepSeek, OpenAI, Gemini, Ollama, or another allowlisted OpenAI-compatible endpoint through strict JSON profiles. The browser receives only sanitized profile metadata and cannot provide arbitrary endpoints, headers, or credentials.
  • Policy as code: enable, suppress, or reclassify known rules and customize scoring weights through validated JSON policies in the CLI and API.
  • Reproducible audit metadata: JSON, Markdown, and HTML reports now include SHA-256 fingerprints for the baseline, candidate, and normalized applied policy.
  • Improved Windows launcher: adds install, build, no-AI, and non-interactive check modes, local-profile discovery, stale-build detection, and secure secret prompting.

Security and compatibility

  • Credentials remain server-side; profile files store only environment-variable names.
  • Remote endpoints require HTTPS, while HTTP is restricted to explicitly declared loopback profiles.
  • Automatic cross-provider fallback remains disabled.
  • Existing DEEPSEEK_* configuration remains supported.
  • LLM output cannot alter deterministic findings, scores, release gates, or CLI exit codes.

Verification

Recorded local verification passed 40 core tests, 31 API tests, 3 CLI formatter/security tests, 8 frontend tests, and 2 end-to-end fixture cases, plus a complete Web → API → OpenAI-compatible adapter flow against a local mock endpoint. No real cloud provider was called during verification.

See the changelog, verification record, and full comparison.

ContractGuard v1.0.1 — Explainable OpenAPI compatibility checks

Choose a tag to compare

@mingxian233 mingxian233 released this 23 Sep 05:56
517018f

ContractGuard v1.0.1 strengthens reliability, security, documentation, and open-source usability for local-first OpenAPI compatibility analysis.

Highlights

  • Direction-aware compatibility rules with stable IDs, precise locations, evidence, and remediation.
  • Web workspace plus JSON, Markdown, and HTML exports.
  • CLI/CI gate with configurable thresholds and exit code 2 for incompatible changes.
  • Optional DeepSeek summaries that cannot alter findings, scores, compatibility decisions, or CI exit codes.
  • Bounded AI responses, runtime JSON validation, timeout handling, and grounded change IDs.
  • Safer analysis IDs, filenames, local JSON Pointer handling, and temporary-file cleanup.
  • English and Chinese documentation, structured issue forms, contributor guidance, and an inspectable sample report.

Verification

  • 67 automated tests across the core engine, API, CLI, and Web app.
  • 2 end-to-end fixture cases.
  • Documentation-link, example-configuration, and smoke checks in CI.
  • GitHub Actions CI passed on Node.js 22 for the tagged commit.

Try it

Current boundaries

Local $ref only; no external or cross-file references; composition semantics are partial; the compatibility score is a risk-ordering heuristic, not a guarantee of production safety.