Repository navigation
Remove --json from the app security commands until they follow the JSON output contract - #8807
Conversation
The output doesn't follow docs/cli/json-output.md yet, and adding --json later is non-breaking where changing a released shape isn't. The services keep returning typed results separately from their presenters, and the commands are exempt from the typed JSON output lint rule until they adopt it.
The agent instructions no longer suggest --json, so agents following them don't fail on a nonexistent flag.
|
/snapit |
1 similar comment
|
/snapit |
|
🫰✨ Thanks @jek! Your snapshot has been published to npm. Built from Test the snapshot by installing your package globally: pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261006184401Caution After installing, validate the version by running |
Without --json, review's output is the only combined view of the results. The agent instructions now say so, warn that its boxes wrap long paths and commands, and explain what --blocking does.
|
/snapit |
agent-checks.json told agents to pipe their findings to a bare `shopify app security record`. When check ran with --config, --client-id, --without-app-config or from another directory, that wrote the findings to the wrong results directory without warning.
Review's next steps said running check "also updates" agent-findings.json, which check never does. Agents now report from review, so say that the agent runs check and records its findings again.
|
/snapit |
|
🫰✨ Thanks @jek! Your snapshot has been published to npm. Built from Test the snapshot by installing your package globally: pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261006193249Caution After installing, validate the version by running |
With findings, review now asks for a deeper review when the agent hasn't recorded findings, leaves refreshing to the older-results step when its findings are older than the scan, and otherwise says how to refresh them.
|
/snapit |
|
🫰✨ Thanks @jek! Your snapshot has been published to npm. Built from Test the snapshot by installing your package globally: pnpm i -g --@shopify:registry=https://registry.npmjs.org @shopify/cli@0.0.0-snapshot-20261006195249Caution After installing, validate the version by running |
|
| Command | Flag |
|---|---|
app:security:check |
--json |
app:security:clean |
--json |
app:security:record |
--json |
app:security:review |
--json |
WHY are these changes introduced?
The
--jsonoutput of theshopify app securitycommands doesn't followdocs/cli/json-output.md. For example, its fields are snake_case andcheckandreviewreuse the result file schemas. Converting it is too big a change for launch. Releasing the current shape and converting later would break a public contract, but adding--jsonlater only adds output. So this removes--jsonfor launch. The commands are exempt from the typed JSON output requirement until they're converted.WHAT is this pull request doing?
--jsonandjsonOutputSchemafromcheck,record,reviewandclean, along with their JSON encoders, fixtures and tests. The services still return typed results separately from the terminal presenters, so the conversion can add new encoders on top of them.app securitycommands, includinginstructions, to a new section ofjson-output-command-exceptions.js, so unhiding them doesn't fail thecommand-json-outputlint rule.error.detailsfromrecordrejections and from invalid results file errors, since only JSON error documents read it. The terminal still lists every error. Without thedetailsassignment,no-error-factory-functionsrejected the error factories, so they're nowabort…(): neverhelpers like the ones inapp-security-selection.ts.--jsonfrom the coding-agent instructions and the command descriptions, so agents following them don't pass a nonexistent flag. The instructions now tell agents to report fromreview, the only combined view of the results, instead of combining the results files themselves, and explain--blockingas the pass/fail gate.agent-checks.jsontold agents to pipe their findings to a bareshopify app security record, which records to the default configuration's results whencheckran with--config,--client-id,--without-app-configor from another directory. It now points them at the exact command from their instructions.review's next steps said runningcheck"also updates"agent-findings.json, which it never does. With findings, the agent step now depends on the agent findings: a deeper review when there are none, the existing older-results step when they're older than the scan, and how to refresh them otherwise.Machine-readable results are still in
deterministic-findings.json,agent-checks.jsonandagent-findings.jsonin the results directory.The first commit is the removal. The second updates the agent instructions, the descriptions and
oclif.manifest.json. The third tells agents to report fromreview. The rest fix the directions above.How to manually test your changes?
In a local app:
pnpm shopify app security check --path <app> --jsonexits 2 with aNonexistent flag: --jsonerror document on stdout, like other commands without--json, such asapp env show.--helpdoesn't list--json.pnpm shopify app security check --path <app> --skip-instructionsshows the report and writes the result files to<app>/.shopify/app-security/shopify.app/.pnpm shopify app security check --path <app> --list-filesprints one path per line.echo '{}' | pnpm shopify app security record --path <app>rejects the document and lists every error.pnpm shopify app security review --path <app>shows the combined results.pnpm shopify app security instructions --path <app>prints instructions that don't mention--jsonand tell the agent to report fromreview.Checklist
patchfor bug fixes ·minorfor new features ·majorfor breaking changes) and added a changeset withpnpm changeset add