From 99ad10ff4c34d5a01d8ffaf491e622add1bead44 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Efe=20G=C3=B6kdemir?= Date: Mon, 5 Oct 2026 00:46:50 +0300 Subject: [PATCH] chore: align remaining RexCode metadata with current main --- .github/CODEOWNERS | 4 ++-- .github/ISSUE_TEMPLATE/config.yml | 2 +- README.md | 8 +++++--- action.yml | 2 +- docs/maintainers.md | 2 +- 5 files changed, 10 insertions(+), 8 deletions(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 86a96b7..fe4bc6a 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1,2 +1,2 @@ -# The maintainer owns review responsibility without requiring CODEOWNERS approval. -* @efegokdemir +# The RexCode maintainers team owns current review routing. +* @RexCode-Digital/maintainers diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml index 6404d85..d82cdc1 100644 --- a/.github/ISSUE_TEMPLATE/config.yml +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -1,5 +1,5 @@ blank_issues_enabled: false contact_links: - name: Report a security vulnerability privately - url: https://github.com/efegokdemir/shopify-app-changeguard/security/advisories/new + url: https://github.com/RexCode-Digital/shopify-app-changeguard/security/advisories/new about: Do not disclose secrets or suspected vulnerabilities in a public issue. diff --git a/README.md b/README.md index 830a05d..dc16440 100644 --- a/README.md +++ b/README.md @@ -15,6 +15,8 @@ ChangeGuard is an offline, read-only semantic reviewer for `shopify.app*.toml` c > Unofficial open-source developer tooling. Not affiliated with, endorsed by, or certified by Shopify. +Maintained by RexCode Digital Ltd. + Part of the **RexCode Shopify developer tools** suite. Requires Node.js 20 or later for the CLI. [Releases](https://github.com/RexCode-Digital/shopify-app-changeguard/releases) · [npm](https://www.npmjs.com/package/shopify-app-changeguard) · [Marketplace](https://github.com/marketplace/actions/changeguard-shopify-app-config-review) ## Quick start @@ -202,9 +204,9 @@ It highlights changes that deserve human review. Building or maintaining Shopify apps? -- **[Shopify Upgrade Guard](https://github.com/efegokdemir/shopify-upgrade-guard)** — Catch documented Shopify API and platform upgrade risks before production migrations. -- **[Shopify Scope Guard](https://github.com/efegokdemir/shopify-scope-guard)** — Audit whether declared Shopify access scopes are supported by offline code evidence. -- **[Shopify App Review Guard](https://github.com/efegokdemir/shopify-app-review-guard)** — Run deterministic preflight checks for Shopify App Store and production readiness. +- **[Shopify Upgrade Guard](https://github.com/RexCode-Digital/shopify-upgrade-guard)** — Catch documented Shopify API and platform upgrade risks before production migrations. +- **[Shopify Scope Guard](https://github.com/RexCode-Digital/shopify-scope-guard)** — Audit whether declared Shopify access scopes are supported by offline code evidence. +- **[Shopify App Review Guard](https://github.com/RexCode-Digital/shopify-app-review-guard)** — Run deterministic preflight checks for Shopify App Store and production readiness. All four tools run offline and require no Shopify credentials. diff --git a/action.yml b/action.yml index 3eca99e..8dec6a5 100644 --- a/action.yml +++ b/action.yml @@ -1,6 +1,6 @@ name: ChangeGuard — Shopify App Config Review description: Review Shopify app configuration changes in pull requests before deployment. -author: Efe Gökdemir +author: RexCode Digital Ltd (Efe Gökdemir) branding: icon: shield color: blue diff --git a/docs/maintainers.md b/docs/maintainers.md index ff3e454..af6191f 100644 --- a/docs/maintainers.md +++ b/docs/maintainers.md @@ -15,6 +15,6 @@ This one-off publication may require interactive npm authentication and 2FA. It must use the `bootstrap` dist-tag, never `latest`, and the version in the repository must remain unchanged. Removing `publishConfig.provenance` is disposable-copy-only because local npm is not a GitHub Actions OIDC provider; the real release keeps that setting and uses GitHub OIDC provenance. - Confirm that the package exists on npm and that `latest` was not changed. Then configure the package's Trusted Publisher with GitHub Actions: user/organization `efegokdemir`, repository `shopify-app-changeguard`, workflow filename `release.yml`, blank environment, and direct `npm publish` allowed. Verify that `package.json.repository.url` exactly matches the GitHub repository before creating the stable release tag. The initial bootstrap and Trusted Publisher configuration are complete for this repository; future releases should verify the existing publisher and use the normal tag workflow without repeating the bootstrap publication. + Confirm that the package exists on npm and that `latest` was not changed. Then configure the package's Trusted Publisher with GitHub Actions: user/organization `RexCode-Digital`, repository `shopify-app-changeguard`, workflow filename `release.yml`, blank environment, and direct `npm publish` allowed. Verify that `package.json.repository.url` exactly matches the GitHub repository before creating the stable release tag. After the repository transfer, verify the npm Trusted Publisher is configured for the `RexCode-Digital` organization, this repository, and `release.yml`. Before the next justified release, verify npm Trusted Publisher configuration and canonical package metadata together. Metadata-only maintenance does not require a publication. 6. For the Action, regenerate `dist/action`, verify the source/distribution check, and update a major tag only after a real stable 1.x release. 7. Roll back by moving consumers to a previously reviewed full commit SHA and, if needed, deprecating the affected npm version. Never delete evidence or rewrite released tags.