Preflight Shopify App Store and production-readiness risks before submission.
Shopify App Review Guard is an offline, deterministic, read-only CLI and GitHub Action. It checks repository evidence for configuration, compliance webhooks, webhook security, authentication, credentials, protected-data signals, billing, API usage, and listing items that need Partner Dashboard verification.
No Shopify credentials. No telemetry. No source upload. No repository code execution. No AI API. Unofficial open-source tooling; not affiliated with or endorsed by Shopify.
Maintained by RexCode Digital Ltd.
Part of the RexCode Shopify developer tools suite. Requires Node.js 20 or later for the CLI. Releases · npm · Marketplace
npx shopify-app-review-guard check
npx shopify-app-review-guard check --format json
npx shopify-app-review-guard check --format sarifExit codes are 0 when the selected policy passes, 1 when findings meet --fail-on, and 2 for scanner or configuration errors.
name: Shopify App Review Guard
on: [pull_request]
permissions:
contents: read
jobs:
review-guard:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: RexCode-Digital/shopify-app-review-guard@83881ee8dd8428f56850b657ef01f1c30951da19 # v0.1.2
with:
fail-on: highRules report deterministic signals with explicit confidence. Repository-wide heuristics need human review and cannot prove runtime compliance. The result model distinguishes PASS, FAIL, WARN, NEEDS_REVIEW, UNKNOWN, and SKIPPED; absence of a recognizable pattern is not silently treated as proof of compliance.
- Shopify app configuration and production URL signals
customers/data_request,customers/redact, andshop/redactconfiguration- raw-body HMAC verification, timing-safe comparisons, and duplicate delivery handling
- embedded authentication and Admin API credential handling
- potential hardcoded credentials, environment files, and dynamic execution signals
- protected customer-data and billing signals
- lightweight listing manifest and manual-check tracking
- JSON and SARIF 2.1.0 output with stable rule IDs
This complements, rather than duplicates, the other RexCode tools:
- ChangeGuard reviews meaningful configuration changes.
- Scope Guard audits declared access scopes against repository evidence.
- Upgrade Guard detects API and platform migration risks.
- App Review Guard preflights App Store and production-readiness requirements.
GitHub Marketplace: Shopify App Review Guard
A configuration mistake or missing compliance subscription can delay submission. Other requirements live in Shopify dashboards or need runtime tests. Review Guard separates deterministic repository findings from items requiring manual verification.
npm install --save-dev shopify-app-review-guard
npx shopify-app-review-guard check --path apps/my-app --config shopify.app.production.toml
npx shopify-app-review-guard check --fail-on medium --strict
npx shopify-app-review-guard check --format sarif --output review.sarif
npx shopify-app-review-guard --help--config selects a TOML file relative to --path. --fail-on accepts none, low, medium, or high; --strict includes NEEDS_REVIEW findings at that threshold. Unknown flags, malformed configuration, and invalid policies exit 2. TOML comments and strings in unrelated tables do not satisfy configured compliance subscriptions.
The Action supports path, config, format, fail-on, strict, and show-unmapped. Outputs are outcome, finding-count, fail-count, warning-count, review-count, unknown-count, report, and rule-ids. report is the rendered multiline report, usable as JSON when format: json. The bundled Action runs on Node 24 without installing dependencies in the consumer job.
Human output includes status, rationale, remediation, and official evidence. JSON includes findings, counts, manual checks, and skipped files. SARIF is version 2.1.0. Reads are bounded to 2,000 files and 1 MiB per file; symlinks are not followed. Missing/unreadable roots and unsafe explicit inputs exit 2. Skipped files require manual review. .env variants are review signals; the scanner cannot determine whether they are committed or contain live secrets.
Configuration checks parse TOML. Authentication, billing, data and webhook implementation checks recognize source patterns; documentation is not accepted as runtime verification evidence. Matching a helper name cannot prove that every route uses it correctly.
External listing and Partner Dashboard requirements cannot be proven from source. An optional .app-review-guard.yml records which items still need human verification. False or unspecified required values become NEEDS_REVIEW, never FAIL. A malformed manifest reports a warning and preserves all manual checks. Values set to true are your declaration of verification, not a scanner-certified pass.
listing:
privacyPolicyUrl: true
supportUrl: true
testInstructions: true
emergencyContact: trueShopify-specific findings carry an official source URL and bundled evidence version. See the evidence model, rule reference, and limitations. Current source references include Shopify's App Store requirements, submission checklist, privacy requirements, access tokens, and webhook verification.
The tool is a preflight assistant. It cannot guarantee App Store approval, prove live behaviour, inspect Partner Dashboard state, measure latency, or replace Shopify review, runtime testing, CodeQL, or legal advice.
npm ci
npm test
npm run lint
npm run typecheck
npm run build
npm pack --dry-runContributions are welcome. See CONTRIBUTING.md for the project workflow and open issues for current work.
Report vulnerabilities privately using SECURITY.md. Never include credentials, customer data, or private keys in issues. MIT licensed. Shopify trademarks belong to their owners.
The Action example pins the reviewed v0.1.2 release commit. Verify the release reference with:
gh api repos/RexCode-Digital/shopify-app-review-guard/git/ref/tags/v0.1.2 --jq .object.shaPublished patch tags are retained; existing minor aliases are movable. A reviewed full commit SHA is the immutable execution reference.