Skip to content

Unhide shopify app security commands - #8766

Merged
nickwesselman merged 2 commits into
app-security/no-jsonfrom
unhide-app-security-commands
Oct 6, 2026
Merged

nickwesselman merged 2 commits into
app-security/no-jsonfrom
unhide-app-security-commands

Conversation

@nickwesselman

Copy link
Copy Markdown
Contributor

Replaces #8742, which GitHub closed when its stacked base branch was deleted after the App Security stack merged. This is the same change, rebased onto main. It touches the same generated files and command tests as #8765 (generic "app security check" wording), so whichever merges second needs a quick rebase.

WHY are these changes introduced?

The shopify app security commands (check, clean, instructions, record, review) were hidden while in development. They're ready to be discoverable.

WHAT is this pull request doing?

Removes hidden = true from the app security commands so they appear in help output, the CLI README, and shopify.dev docs. Regenerates the manifest, README, dev docs, and commands snapshot.

How to manually test your changes?

  • pnpm shopify app --help — app security commands are listed
  • pnpm shopify app security check --help

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

🤖 Generated with Claude Code

@nickwesselman
nickwesselman requested review from a team as code owners October 5, 2026 21:42
@nickwesselman nickwesselman mentioned this pull request Oct 5, 2026
1 of 4 tasks
@github-actions github-actions Bot added shopify.dev preview Area: @shopify/cli @shopify/cli package issues labels Oct 5, 2026
@nickwesselman
nickwesselman force-pushed the unhide-app-security-commands branch from 8a59a65 to a627752 Compare October 5, 2026 21:44
@nickwesselman
nickwesselman force-pushed the unhide-app-security-commands branch from a627752 to 74b3d61 Compare October 5, 2026 22:28
@nickwesselman

Copy link
Copy Markdown
Contributor Author

/snapit

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🫰✨ Thanks @nickwesselman! Your snapshot has been published to npm.

Built from 74b3d6187c4a0a075cd59578f4a8812b0adc1c7b. Workflow run.

Test the snapshot by installing your package globally:

pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261005222923

Caution

After installing, validate the version by running shopify version in your terminal.
If the versions don't match, you might have multiple global instances installed.
Use which shopify to find out which one you are running and uninstall it.

@nickwesselman
nickwesselman force-pushed the unhide-app-security-commands branch from 74b3d61 to 8eb5385 Compare October 5, 2026 22:39
@nickwesselman

Copy link
Copy Markdown
Contributor Author

/snapit

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🫰✨ Thanks @nickwesselman! Your snapshot has been published to npm.

Built from 8eb5385437819fedfed1d5798a56a096268e63e8. Workflow run.

Test the snapshot by installing your package globally:

pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261005224042

Caution

After installing, validate the version by running shopify version in your terminal.
If the versions don't match, you might have multiple global instances installed.
Use which shopify to find out which one you are running and uninstall it.

@gonzaloriestra gonzaloriestra left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We will need to wait for the JSON fixes, but LGTM

@nickwesselman

Copy link
Copy Markdown
Contributor Author

/snapit

@nickwesselman
nickwesselman force-pushed the unhide-app-security-commands branch from 8eb5385 to 14e9f05 Compare October 6, 2026 18:29
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🫰✨ Thanks @nickwesselman! Your snapshot has been published to npm.

Built from 14e9f0576b487444c0c5cea824b7f443a2216ce3. Workflow run.

Test the snapshot by installing your package globally:

pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261006183023

Caution

After installing, validate the version by running shopify version in your terminal.
If the versions don't match, you might have multiple global instances installed.
Use which shopify to find out which one you are running and uninstall it.

nickwesselman and others added 2 commits October 6, 2026 16:02
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Visibility is already covered by the generated oclif manifest and the e2e
command tree snapshot, so the unit tests no longer assert on `hidden`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@nickwesselman
nickwesselman force-pushed the unhide-app-security-commands branch 2 times, most recently from 23e5c34 to 14e9f05 Compare October 6, 2026 20:03
@nickwesselman
nickwesselman disabled the stack merge October 6, 2026 20:04
@nickwesselman
nickwesselman force-pushed the unhide-app-security-commands branch from 14e9f05 to 23e5c34 Compare October 6, 2026 20:04
@nickwesselman
nickwesselman changed the base branch from main to app-security/no-json October 6, 2026 20:04
@nickwesselman
nickwesselman added this pull request to stack #8809 October 6, 2026 20:04
@nickwesselman

Copy link
Copy Markdown
Contributor Author

/snapit

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

⚠️ Potential Breaking Changes Detected

This PR contains changes that may break the existing contract.

@shopify/dev_experience — this PR contains breaking changes that require coordination for the next major release.

🏳️ Removed Flags

The following flags were removed from existing commands:

Command Flag
app:security:check --json
app:security:clean --json
app:security:record --json
app:security:review --json

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🫰✨ Thanks @nickwesselman! Your snapshot has been published to npm.

Built from 23e5c34a27bff37981dc68ea19fb0f40ee69eac5. Workflow run.

Test the snapshot by installing your package globally:

pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261006200604

Caution

After installing, validate the version by running shopify version in your terminal.
If the versions don't match, you might have multiple global instances installed.
Use which shopify to find out which one you are running and uninstall it.

@nickwesselman
nickwesselman added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 6696ce9 Oct 6, 2026
35 of 60 checks passed
@nickwesselman
nickwesselman deleted the unhide-app-security-commands branch October 6, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants