Skip to content

Unhide shopify app security commands - #8742

Closed
nickwesselman wants to merge 4 commits into
app-security/include-dirfrom
unhide-app-security-commands
Closed

nickwesselman wants to merge 4 commits into
app-security/include-dirfrom
unhide-app-security-commands

Conversation

@nickwesselman

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

The shopify app security commands (check, clean, instructions, record, review) were hidden while in development. They're ready to be discoverable.

WHAT is this pull request doing?

Removes hidden = true from the app security commands so they appear in help output, the CLI README, and shopify.dev docs. Regenerates the manifest, README, dev docs, and commands snapshot.

How to manually test your changes?

  • pnpm shopify app --help — app security commands are listed
  • pnpm shopify app security check --help

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

🤖 Generated with Claude Code

@github-actions github-actions Bot added shopify.dev preview Area: @shopify/cli @shopify/cli package issues labels Oct 2, 2026
@nickwesselman

Copy link
Copy Markdown
Contributor Author

/snapit

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🫰✨ Thanks @nickwesselman! Your snapshot has been published to npm.

Built from be9fe2145c113130cea0c040bb954bc25d5dd39f. Workflow run.

Test the snapshot by installing your package globally:

pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261002135905

Caution

After installing, validate the version by running shopify version in your terminal.
If the versions don't match, you might have multiple global instances installed.
Use which shopify to find out which one you are running and uninstall it.

jek added 2 commits October 5, 2026 06:43
Add check --list-files, render rerun commands from the selection and the typed
scope flags, and record the scope on both sides so review can flag a mismatch.
The instructions name the working directory and have the agent settle the scope
before scanning. Cover the layout catalogue.
Run the real command with --without-app-config and --exclude, and check the
results key, the selection, the recorded scope and the unresolved config
checks. No other test scans with no app configuration file.
@nickwesselman
nickwesselman force-pushed the unhide-app-security-commands branch from be9fe21 to acaefc1 Compare October 5, 2026 15:57
@nickwesselman
nickwesselman marked this pull request as ready for review October 5, 2026 15:58
@nickwesselman
nickwesselman requested review from a team as code owners October 5, 2026 15:58
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@nickwesselman
nickwesselman force-pushed the unhide-app-security-commands branch from acaefc1 to 86f6d29 Compare October 5, 2026 16:02
@nickwesselman
nickwesselman changed the base branch from main to app-security/agent-workflow October 5, 2026 16:02
@nickwesselman

Copy link
Copy Markdown
Contributor Author

/snapit

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🫰✨ Thanks @nickwesselman! Your snapshot has been published to npm.

Built from 86f6d29ba4ef49493639de40885c27731bba4050. Workflow run.

Test the snapshot by installing your package globally:

pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261005160359

Caution

After installing, validate the version by running shopify version in your terminal.
If the versions don't match, you might have multiple global instances installed.
Use which shopify to find out which one you are running and uninstall it.

test('is hidden and does not require linked app context', () => {
expect(SecurityCheck.hidden).toBe(true)
test('is visible and does not require linked app context', () => {
expect(SecurityCheck.hidden).toBeFalsy()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

no need for these type of tests now that the command is public i guess

Visibility is already covered by the generated oclif manifest and the e2e
command tree snapshot, so the unit tests no longer assert on `hidden`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@dmerand dmerand left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Aside from Isaac's note, LGTM.

Base automatically changed from app-security/agent-workflow to app-security/include-dir October 5, 2026 18:17
@jek
jek deleted the branch app-security/include-dir October 5, 2026 18:17
@jek jek closed this Oct 5, 2026
@nickwesselman nickwesselman mentioned this pull request Oct 5, 2026
1 of 4 tasks
@nickwesselman

Copy link
Copy Markdown
Contributor Author

Superseded by #8766, the same change rebased onto main. This PR was closed automatically when its stacked base branch was deleted.

Posted by Claude Code on behalf of the PR author.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants