Developer guide / CI compatibility

Catch breaking OpenAPI changes before they reach production.

Compare the pull request's OpenAPI specification with the base version. Fail CI on incompatible changes, manage time-limited exceptions and preserve the release evidence your team actually reviewed.

Self-hosted tool, not a paid SaaS or a runtime contract-testing service. Optional managed setup is available separately.

01 / What changes break clients?

Don't rely on a green build for an incompatible API.

An OpenAPI file can remain syntactically valid while existing callers become incompatible. These examples require deliberate review; exact severity follows the underlying oasdiff rules and your policy.

REMOVED OPERATION

Endpoint disappears

A previously supported path or HTTP method is removed from the published contract.

REQUIRED INPUT

Request becomes stricter

A parameter that existing clients never sent becomes mandatory.

RESPONSE SCHEMA

Output changes shape

A field, type, enum or response definition changes incompatibly with the previous contract.

02 / Integrate into GitHub Actions

One CI gate and a reviewable evidence trail.

STEP 01

Choose baseline and candidate

Check out the PR, materialize the OpenAPI specification from the base commit, and point the Action at the proposed specification.

STEP 02

Apply an explicit policy

Use a local JSON policy with an agreed severity threshold and fingerprint-specific, time-limited exceptions when appropriate.

STEP 03

Review the release evidence

Keep report.json, summary.md and their input hashes with the release record. Artifact upload is opt-in.

node cli.mjs \
  --base fixtures/base.yaml \
  --head fixtures/breaking.yaml \
  --out evidence/breaking

# A breaking contract returns exit code 1.
# A safe additive change returns exit code 0.
The GitHub Action provides the workflow wrapper; see the documented installation example for the exact YAML. For reproducible production workflows, pin the Action to an audited immutable commit SHA. The Action runs on Linux x86_64 and downloads a checksum-verified oasdiff engine.
03 / Optional implementation service

Free detection engine. Paid setup when you want it configured correctly.

Use the open-source Action yourself, or ask ForgeFrame Labs to set up an OpenAPI baseline, CI gate, scoped exception policy and evidence workflow. We agree the repository and specification scope in writing before any billable work.

Contract Guard checks specification compatibility, not runtime behavior, undocumented API drift, production availability or full client compatibility. API contracts and secrets remain in your own environment.

Inspect an actual breaking-change report with two blocking findings ↗

Read the product scope and limitations ↗
CONTRACT GUARD SETUP / ONE-TIME$149

Asynchronous setup for one GitHub repository with an existing OpenAPI 3.x specification, subject to a confirmed scope and delivery date. No subscription or hosted dashboard is included.

Check eligibility for $149 managed setup ↗

We agree scope, legal seller and delivery in writing before issuing a unique one-order Stripe payment link. Review the service terms and cancellation policy before purchase.

04 / Answers before you install

Scope, permissions and exceptions.

Does this detect every API-breaking change?

No. The Action analyzes documented changes to OpenAPI specifications. Runtime behavior, stale specifications and effects on individual consumers need additional tests.

Does the Action need repository write access?

No. The published Action is designed for minimal contents: read permission. Workflow artifact upload is optional.

Can I approve a breaking change temporarily?

Yes, subject to your policy. An exception must match the rule ID and finding fingerprint, contain a reason and have a valid, non-expired date. Broad hidden allowlists are not the intended workflow.

Does $149 include an unlimited CI service?

No. It is a one-time implementation of one qualifying repository. Additional requirements, ongoing maintenance, or hosting need separate terms.

Need help with this tool?Contract Guard · forgeframe.lab@gmail.com
Compose in Gmail ↗Other email app