ShiftWatch operator package / initial targeted ruleset

Requires Node.js22 or newer. No dependency installation, account, API token or source upload is needed.

1. Extract this archive into a tooling folder, outside the integration source root.
2. Single integration:
   node scan.mjs --root /absolute/path/to/integration --surface admin --target 2026-10 --output impact.json
3. Several integrations:
   Copy portfolio-example.json, then set each source root, API surface, target version, review-owner label and due date.
   node portfolio.mjs --manifest portfolio-example.json --output baseline.json --review review.md
4. A later review:
   node portfolio.mjs --manifest portfolio-example.json --previous baseline.json --output next.json --review next-review.md

Exit codes:0 no blocking matched findings;1 blocked/removed usage;2 incomplete coverage. An exit code0 is not certification of compatibility. Warnings alone do not fail the run.

Source is parsed locally, never executed. Single-integration JSON can contain source snippets. Portfolio snapshots omit source/snippets but contain filenames and finding metadata. Keep all exports private unless your organization authorizes sharing them.

Maximum100 source files per integration,500KB per file and5MB aggregate. Maximum20 configured integrations. Unsupported integration languages appear as coverage gaps. Explicit exclusions require a reviewer label. Do not put private credentials in the manifest.

Supported rules: ScriptTag writes; Customer Account lastIncompleteCheckout; DraftOrderDiscountNotAppliedWarning.priceRule; ProductVariant.barcode deprecation; POS Session currentSession.staffMemberId. See official notice links in the report.

Dynamic queries, cross-file fragments, request wrappers and unsupported POS entry points need additional review. A finding is syntactic evidence, not proof of execution. Missing findings require release verification rather than automatic closure.

This package is a working technical trial. Managed cloud monitoring, payment collection and paid service delivery are not enabled. There is no required payment or subscription contract to run it.
