Skip to content

Check dependency automation at the repository root for nested apps - #8826

Merged
jplhomer merged 4 commits into
mainfrom
jplhomer/app-security-monorepo-dependency-automation
Oct 9, 2026
Merged

jplhomer merged 4 commits into
mainfrom
jplhomer/app-security-monorepo-dependency-automation

Conversation

@jplhomer

@jplhomer jplhomer commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

Refs shop/issues-develop#24160.

MISSING_DEPENDENCY_SECURITY_AUTOMATION never passes or reports for an app below its Git repository root, such as apps/foo in a monorepo. Discovery rejects the app as "nested below a parent Git repository", so the check is always unresolved, even when the root has .github/dependabot.yml.

WHAT is this pull request doing?

Looks for Dependabot and Renovate configuration at the root of the nearest Git repository that holds the app, which is where those bots read it.

  • Flat apps, and apps outside a repository, behave as before.
  • When the repository root is inside a scan directory (for example --include-dir set to the root), only gathered paths are read, so --exclude and Git ignore rules still apply.
  • Otherwise the allowlisted paths are read directly, contained by the repository root: symbolic links can't leave it, and the size limit and skipped-file reporting still apply.
  • An app with its own .git keeps its own boundary, so a parent repository's configuration can't make it pass.
  • Configuration only inside a nested app directory isn't read by the bots, so it's now reported as missing instead of unresolved.

Includes a @shopify/app patch changeset (.changeset/app-security-dependency-automation-repository-root.md).

How to manually test your changes?

mkdir -p /tmp/mono/.github && cd /tmp/mono && git init -q
printf 'version: 2\nupdates: []\n' > .github/dependabot.yml
# Put an app in apps/foo: a shopify.app.toml and a package.json with dependencies
shopify app security check --path apps/foo

In deterministic-findings.json, MISSING_DEPENDENCY_SECURITY_AUTOMATION is executed with no findings, and ../../.github/dependabot.yml is among its inspected files. Before this change it's unresolved. Delete the root dependabot.yml and the check reports a finding.

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

PR authored by Qlaw

An app directory below its Git repository root left
MISSING_DEPENDENCY_SECURITY_AUTOMATION unresolved, because configuration was
only looked up in the app directory. Dependabot and Renovate read their
configuration from the repository root, so look it up there. An app with its
own repository keeps its own boundary.

Refs shop/issues-develop#24160

Co-authored-by: Qlaw <noreply@qlaw.quick.shopify.io>
@jplhomer
jplhomer requested a review from a team as a code owner October 7, 2026 15:18
Copilot AI balanced review requested due to automatic review settings October 7, 2026 15:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation safely addresses the reported nested-app behavior with comprehensive boundary and integration coverage.

0 open findings

What changed in this PR

Resolves dependency-automation detection for apps nested within Git repositories.

Changes:

  • Resolves Dependabot/Renovate configuration from the nearest repository root.
  • Preserves scan exclusions, bounded reads, symlink containment, and nested repository boundaries.
  • Adds integration/discovery coverage and a patch changeset.
File Description
dependency-automation.test.ts Adds nested-app integration tests.
dependency-automation-discovery.test.ts Tests repository boundaries and safe reads.
scanners/​types.ts Updates discovery contract documentation.
scanners/​discover.ts Implements repository-root configuration discovery.
Changeset Documents the user-facing fix.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions github-actions Bot added the Area: @shopify/app @shopify/app package issues label Oct 7, 2026
jplhomer and others added 2 commits October 7, 2026 10:28
Expected absolutePath used node path.join, which is backslash-separated
on Windows. Build it with joinPath like discover.ts, and include ext.

Refs shop/issues-develop#24160

Co-authored-by: Qlaw <noreply@qlaw.quick.shopify.io>
…y root

Dependency automation configuration was read directly, contained by the
repository root, whenever that root was not itself a scan directory. An
included directory such as .github below the root then bypassed gathering,
so --exclude and git-ignore were not applied to its configuration. Decide
per configuration file: a file inside any scan directory is read only when
gathered, and only a file outside every scan directory is read directly.

Refs shop/issues-develop#24160

Co-authored-by: Qlaw <noreply@qlaw.quick.shopify.io>
@jek

jek commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Should we check dependency automation for every repository containing a gathered package manifest with dependencies?

   monorepo/
   ├── .git/
   ├── renovate.json
   ├── apps/foo/package.json
   └── vendor/tool/
       ├── .git/
       └── package.json

or

  app-repo/
  ├── .git/
  └── package.json

  web-repo/
  ├── .git/
  ├── dependabot config
  └── package.json

@jplhomer

jplhomer commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@jek Yeah, maybe a follow-up PR that groups package files by their nearest git root? Mainly addressing your second example. The first one looks like a submodule situation.

@jplhomer
jplhomer added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 3e5e60c Oct 9, 2026
29 of 30 checks passed
@jplhomer
jplhomer deleted the jplhomer/app-security-monorepo-dependency-automation branch October 9, 2026 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area: @shopify/app @shopify/app package issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants