What's new
ContractGuard 1.1.0 adds configurable model profiles and auditable policy controls while keeping compatibility decisions deterministic and local-first.
Highlights
- Server-owned multi-LLM profiles: configure DeepSeek, OpenAI, Gemini, Ollama, or another allowlisted OpenAI-compatible endpoint through strict JSON profiles. The browser receives only sanitized profile metadata and cannot provide arbitrary endpoints, headers, or credentials.
- Policy as code: enable, suppress, or reclassify known rules and customize scoring weights through validated JSON policies in the CLI and API.
- Reproducible audit metadata: JSON, Markdown, and HTML reports now include SHA-256 fingerprints for the baseline, candidate, and normalized applied policy.
- Improved Windows launcher: adds install, build, no-AI, and non-interactive check modes, local-profile discovery, stale-build detection, and secure secret prompting.
Security and compatibility
- Credentials remain server-side; profile files store only environment-variable names.
- Remote endpoints require HTTPS, while HTTP is restricted to explicitly declared loopback profiles.
- Automatic cross-provider fallback remains disabled.
- Existing
DEEPSEEK_*configuration remains supported. - LLM output cannot alter deterministic findings, scores, release gates, or CLI exit codes.
Verification
Recorded local verification passed 40 core tests, 31 API tests, 3 CLI formatter/security tests, 8 frontend tests, and 2 end-to-end fixture cases, plus a complete Web → API → OpenAI-compatible adapter flow against a local mock endpoint. No real cloud provider was called during verification.
See the changelog, verification record, and full comparison.