Skip to content

v0.6.0 — Team & Multi-Repo Workflows

Choose a tag to compare

@neil-data neil-data released this 14 Sep 10:31
· 12 commits to main since this release

Highlights

EnvGuard extends beyond single-repo, single-developer use for the first time — while staying fully local-first, with no accounts, no cloud sync, and no new backend. Team policy and multi-repo scanning are both built on version-controlled files, the same way .gitignore works.

Added

  • Org policy file (.envguard-org.yml) — a shared, git-committed policy that sits alongside .envguard.yml. Lets a team set a security floor that individual repos can extend but not weaken: a block_on minimum that local config can only add to, and a list of rules that cannot be disabled at the local level no matter what an individual .envguard.yml says.
  • Multi-repo scanning — envguard scan --repos <paths> (or --repos-file) scans multiple local repository checkouts in one run and produces a single combined report, with each finding attributed to its source repository. A broken or inaccessible repo in the list is reported clearly and skipped without aborting the scan of the others.
  • Org policy visibility in diagnostics — doctor and status now report whether an org policy is present, valid, and being honored, and clearly attribute any policy violation to its source (org vs. local) rather than reporting an ambiguous failure.

Design notes

  • Org policy and local config are evaluated independently for most settings — an org policy cannot silently override a repo's local exclusions or custom rules, only enforce a floor on block_on severities and lock specific rules from being disabled.
  • All new path/reference handling in this release follows the same strict validation introduced in v0.5.4 after the Git reference injection fix — no new field in this release accepts unsanitized input that reaches a subprocess or filesystem write.
  • Existing single-repo, no-org-policy usage is completely unchanged — this release is purely additive.

Deferred to a future release

Team-committed baselines (shared suppression with audit trail), directory-walking org policy discovery, and role-based enforcement beyond the block_on/disabled_rules floor are intentionally out of scope for v0.6.0 and planned for a later release, to keep this release's enforcement logic small enough to audit thoroughly.


Recommendation: Teams managing more than one EnvGuard-protected repository should adopt a shared .envguard-org.yml to prevent individual repos from silently weakening security gates.