All notable changes to Trust-Link Backend are documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
- OpenTelemetry distributed tracing with OTLP export, database spans, and workflow-level context propagation (#79)
- Security policy with vulnerability disclosure procedures (#90)
- Incident response runbook for backup restoration and container recovery (#97)
- Jaeger all-in-one service in Docker Compose for local trace visualization
GET /healthandGET /versionnow report the semver frompackage.json
1.0.0 - 2026-05-29
First stable release of the Trust-Link escrow backend.
- NestJS 11 application with escrow lifecycle management (
POST/GET/PATCH /escrow) - SEP-10 Stellar authentication with JWT challenge/verify flow
- Vendor profile management (
/vendor/profile, vendor escrow listings) - Buyer dispute flow with evidence URLs
- Stellar Horizon webhook receiver with HMAC verification and idempotent event processing
- Admin modules: statistics, dispute resolution, API key rotation, BullMQ-style queue dashboard
- Structured JSON logging with configurable
LOG_LEVEL(#81) - CORS configuration via
ALLOWED_ORIGINS(#85) - Rate limiting guard on sensitive endpoints
- Security headers middleware
- Redis response caching with graceful no-op fallback (#103)
- PostgreSQL schema via Prisma with migrations (escrow, disputes, vendor profiles, webhook cursor)
- Docker multi-stage production image with non-root user and health check
- Docker Compose stack (app, PostgreSQL 15, Redis 7)
- Auto-release worker with optimistic DB locking and exponential-backoff notifications
- Tracking poll worker for shipment status updates
- Multi-currency Stellar asset configuration (including cNGN stablecoin)
- Event replay service for Stellar contract events
- In-process audit log for admin actions (#94)
- Optional SendGrid email and Twilio SMS notifications
- Stress-test module and CLI runner
- CI workflows: unit tests with coverage threshold, ESLint on PRs
- Architecture documentation (
ARCHITECTURE.md) - Environment variable reference (
.env.example)
- Regenerated
package-lock.jsonto resolve missing@nestjs/axiosdependency entries - Idempotent auto-release via optimistic lock to prevent duplicate fund releases
- JWT secret minimum length enforcement (32 characters) via Joi validation
- Webhook signature verification when
STELLAR_WEBHOOK_SECRETis configured - Production CORS blocks all origins when
ALLOWED_ORIGINSis unset
| Version | Date | Highlights |
|---|---|---|
| 1.0.0 | 2026-05-29 | Initial stable release — escrow, SEP-10 auth, webhooks, admin, Docker |
| Unreleased | — | Distributed tracing, security policy, incident runbook |
| Bump | When |
|---|---|
| MAJOR (X.0.0) | Breaking API or database schema changes |
| MINOR (1.X.0) | New features, backward-compatible |
| PATCH (1.0.X) | Bug fixes and security patches |