Skip to content

ContractGuard v1.1.0 — Multi-LLM Profiles, Policy-as-Code, and Audit Fingerprints

Latest

Choose a tag to compare

@mingxian233 mingxian233 released this 23 Sep 08:43
· 1 commit to main since this release

What's new

ContractGuard 1.1.0 adds configurable model profiles and auditable policy controls while keeping compatibility decisions deterministic and local-first.

Highlights

  • Server-owned multi-LLM profiles: configure DeepSeek, OpenAI, Gemini, Ollama, or another allowlisted OpenAI-compatible endpoint through strict JSON profiles. The browser receives only sanitized profile metadata and cannot provide arbitrary endpoints, headers, or credentials.
  • Policy as code: enable, suppress, or reclassify known rules and customize scoring weights through validated JSON policies in the CLI and API.
  • Reproducible audit metadata: JSON, Markdown, and HTML reports now include SHA-256 fingerprints for the baseline, candidate, and normalized applied policy.
  • Improved Windows launcher: adds install, build, no-AI, and non-interactive check modes, local-profile discovery, stale-build detection, and secure secret prompting.

Security and compatibility

  • Credentials remain server-side; profile files store only environment-variable names.
  • Remote endpoints require HTTPS, while HTTP is restricted to explicitly declared loopback profiles.
  • Automatic cross-provider fallback remains disabled.
  • Existing DEEPSEEK_* configuration remains supported.
  • LLM output cannot alter deterministic findings, scores, release gates, or CLI exit codes.

Verification

Recorded local verification passed 40 core tests, 31 API tests, 3 CLI formatter/security tests, 8 frontend tests, and 2 end-to-end fixture cases, plus a complete Web → API → OpenAI-compatible adapter flow against a local mock endpoint. No real cloud provider was called during verification.

See the changelog, verification record, and full comparison.