Skip to content

Allow app security instructions before results exist - #8808

Merged
jek merged 1 commit into
mainfrom
app-security/instructions-without-results
Oct 6, 2026
Merged

jek merged 1 commit into
mainfrom
app-security/instructions-without-results

Conversation

@jek

@jek jek commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

shopify app security instructions aborts in a fresh app because it requires a results directory, even though the generated standalone workflow starts by running shopify app security check. This prevents the instructions from initiating the workflow they describe.

WHAT is this pull request doing?

Removes the results-directory precondition from instructions and verifies that instructions are delivered before any check results exist. record, review, and clean keep their existing results checks.

Known trade-off: instructions does not validate --client-id; the generated check command validates it when run.

How to manually test your changes?

  1. Create a fresh app directory containing shopify.app.toml and no .shopify/app-security/ directory.
  2. Run pnpm shopify app security instructions --path <app>.
  3. Verify the command exits successfully and prints instructions containing ### 1. Run the scan.

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

@jek
jek requested a review from a team as a code owner October 6, 2026 19:32
@github-actions github-actions Bot added the no-changelog This PR doesn't include a changeset entry. Is an internal only change not relevant to end users. label Oct 6, 2026
@jek
jek requested a review from jplhomer October 6, 2026 20:13
@jek
jek added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 735a82e Oct 6, 2026
30 of 31 checks passed
@jek
jek deleted the app-security/instructions-without-results branch October 6, 2026 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog This PR doesn't include a changeset entry. Is an internal only change not relevant to end users.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants