v0.6.0 — Team & Multi-Repo Workflows
Highlights
EnvGuard extends beyond single-repo, single-developer use for the first time — while staying fully local-first, with no accounts, no cloud sync, and no new backend. Team policy and multi-repo scanning are both built on version-controlled files, the same way .gitignore works.
Added
- Org policy file (
.envguard-org.yml) — a shared, git-committed policy that sits alongside.envguard.yml. Lets a team set a security floor that individual repos can extend but not weaken: ablock_onminimum that local config can only add to, and a list of rules that cannot be disabled at the local level no matter what an individual.envguard.ymlsays. - Multi-repo scanning —
envguard scan --repos <paths>(or--repos-file) scans multiple local repository checkouts in one run and produces a single combined report, with each finding attributed to its source repository. A broken or inaccessible repo in the list is reported clearly and skipped without aborting the scan of the others. - Org policy visibility in diagnostics —
doctorandstatusnow report whether an org policy is present, valid, and being honored, and clearly attribute any policy violation to its source (org vs. local) rather than reporting an ambiguous failure.
Design notes
- Org policy and local config are evaluated independently for most settings — an org policy cannot silently override a repo's local exclusions or custom rules, only enforce a floor on
block_onseverities and lock specific rules from being disabled. - All new path/reference handling in this release follows the same strict validation introduced in v0.5.4 after the Git reference injection fix — no new field in this release accepts unsanitized input that reaches a subprocess or filesystem write.
- Existing single-repo, no-org-policy usage is completely unchanged — this release is purely additive.
Deferred to a future release
Team-committed baselines (shared suppression with audit trail), directory-walking org policy discovery, and role-based enforcement beyond the block_on/disabled_rules floor are intentionally out of scope for v0.6.0 and planned for a later release, to keep this release's enforcement logic small enough to audit thoroughly.
Recommendation: Teams managing more than one EnvGuard-protected repository should adopt a shared .envguard-org.yml to prevent individual repos from silently weakening security gates.