Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
# The maintainer owns review responsibility without requiring CODEOWNERS approval.
* @efegokdemir
# The RexCode maintainers team owns current review routing.
* @RexCode-Digital/maintainers
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: false
contact_links:
- name: Report a security vulnerability privately
url: https://github.com/efegokdemir/shopify-app-changeguard/security/advisories/new
url: https://github.com/RexCode-Digital/shopify-app-changeguard/security/advisories/new
about: Do not disclose secrets or suspected vulnerabilities in a public issue.
8 changes: 5 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ ChangeGuard is an offline, read-only semantic reviewer for `shopify.app*.toml` c

> Unofficial open-source developer tooling. Not affiliated with, endorsed by, or certified by Shopify.

Maintained by RexCode Digital Ltd.

Part of the **RexCode Shopify developer tools** suite. Requires Node.js 20 or later for the CLI. [Releases](https://github.com/RexCode-Digital/shopify-app-changeguard/releases) · [npm](https://www.npmjs.com/package/shopify-app-changeguard) · [Marketplace](https://github.com/marketplace/actions/changeguard-shopify-app-config-review)

## Quick start
Expand Down Expand Up @@ -202,9 +204,9 @@ It highlights changes that deserve human review.

Building or maintaining Shopify apps?

- **[Shopify Upgrade Guard](https://github.com/efegokdemir/shopify-upgrade-guard)** — Catch documented Shopify API and platform upgrade risks before production migrations.
- **[Shopify Scope Guard](https://github.com/efegokdemir/shopify-scope-guard)** — Audit whether declared Shopify access scopes are supported by offline code evidence.
- **[Shopify App Review Guard](https://github.com/efegokdemir/shopify-app-review-guard)** — Run deterministic preflight checks for Shopify App Store and production readiness.
- **[Shopify Upgrade Guard](https://github.com/RexCode-Digital/shopify-upgrade-guard)** — Catch documented Shopify API and platform upgrade risks before production migrations.
- **[Shopify Scope Guard](https://github.com/RexCode-Digital/shopify-scope-guard)** — Audit whether declared Shopify access scopes are supported by offline code evidence.
- **[Shopify App Review Guard](https://github.com/RexCode-Digital/shopify-app-review-guard)** — Run deterministic preflight checks for Shopify App Store and production readiness.

All four tools run offline and require no Shopify credentials.

Expand Down
2 changes: 1 addition & 1 deletion action.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: ChangeGuard — Shopify App Config Review
description: Review Shopify app configuration changes in pull requests before deployment.
author: Efe Gökdemir
author: RexCode Digital Ltd (Efe Gökdemir)
branding:
icon: shield
color: blue
Expand Down
2 changes: 1 addition & 1 deletion docs/maintainers.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,6 @@

This one-off publication may require interactive npm authentication and 2FA. It must use the `bootstrap` dist-tag, never `latest`, and the version in the repository must remain unchanged. Removing `publishConfig.provenance` is disposable-copy-only because local npm is not a GitHub Actions OIDC provider; the real release keeps that setting and uses GitHub OIDC provenance.

Confirm that the package exists on npm and that `latest` was not changed. Then configure the package's Trusted Publisher with GitHub Actions: user/organization `efegokdemir`, repository `shopify-app-changeguard`, workflow filename `release.yml`, blank environment, and direct `npm publish` allowed. Verify that `package.json.repository.url` exactly matches the GitHub repository before creating the stable release tag. The initial bootstrap and Trusted Publisher configuration are complete for this repository; future releases should verify the existing publisher and use the normal tag workflow without repeating the bootstrap publication.
Confirm that the package exists on npm and that `latest` was not changed. Then configure the package's Trusted Publisher with GitHub Actions: user/organization `RexCode-Digital`, repository `shopify-app-changeguard`, workflow filename `release.yml`, blank environment, and direct `npm publish` allowed. Verify that `package.json.repository.url` exactly matches the GitHub repository before creating the stable release tag. After the repository transfer, verify the npm Trusted Publisher is configured for the `RexCode-Digital` organization, this repository, and `release.yml`. Before the next justified release, verify npm Trusted Publisher configuration and canonical package metadata together. Metadata-only maintenance does not require a publication.
6. For the Action, regenerate `dist/action`, verify the source/distribution check, and update a major tag only after a real stable 1.x release.
7. Roll back by moving consumers to a previously reviewed full commit SHA and, if needed, deprecating the affected npm version. Never delete evidence or rewrite released tags.
Loading