CHANGE CONTROL RECORD 21 CFR Part 11 Compliant

System Changelog

Authoritative record of all system changes with validation impact classifications. Each release includes GxP assessment data for change control and impact analysis.

High impact
Medium impact
Low impact
No validation impact
v1.0.1 No Validation Impact

Removes the last latest image-tag fallback from the deployment compose template. The live production compose and the release workflow were corrected in v1.0.0; this template carried the same construct under a different variable name and was missed. No application code changes — the running system is functionally identical to v1.0.0.

v1.0.0 High Validation Impact

First validated release of GxPSign. This entry is the baseline for change control: it establishes the qualified state of the system rather than describing a change to it. Development history before this release predates validation and is not part of the controlled record — it remains available in the repository's git history, but no pre-1.0 version was released under change control and none should be cited as a qualified state.

Everything in scope is therefore qualified as a whole, not as a set of increments: PDF e-signature workflows with 21 CFR Part 11 aligned signature manifestations, an append-only signature audit trail, PostgreSQL row-level security for tenant isolation, OIDC/SAML single sign-on with re-authentication at signing, and the release pipeline that deploys it.

GxP Use: This changelog is the authoritative record for Change Control and Impact Assessment in regulated environments. Validation impact classifications follow GAMP5 Category 4 software guidelines. Each "High" impact release requires OQ/PQ re-execution for affected functionality.

Ready to start your GxP qualification?

Every release ships with updated qualification documentation.