Skip to content

Extract App Security checks behind a replaceable package contract - #8714

Draft
nickwesselman wants to merge 1 commit into
mainfrom
poc/app-security-check-set
Draft

nickwesselman wants to merge 1 commit into
mainfrom
poc/app-security-check-set

Conversation

@nickwesselman

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

Prove that App Security checks can be amended or replaced by another compatible package without replacing shopify app security check or its review/findings workflow.

WHAT is this pull request doing?

Consume the check set extracted in the paired package PR. Keep discovery, capability detection, scheduling, review-pack generation, findings validation/merge, trace compilation, redaction enforcement, artifacts, command UX and uploads in CLI.

Thread the selected check set explicitly through the existing engine; createAppSecurityEngine(checkSet) binds an alternative set without global mutation. The integration fixture exercises a complete replacement through scan, review, registry, findings compilation and trace. Default detector code and prompt bytes are preserved in the package.

Draft POC only: dependency uses a local .poc/app-security-checks link. Public CI cannot install it without the documented local checkout/build. No npm publishing or production dependency is introduced; resolve distribution/versioning before merging. See local setup and boundary.

How to manually test your changes?

Follow the linked local setup, then run against a Shopify app:

pnpm shopify app security check --path /path/to/app --json
pnpm shopify app security check --path /path/to/app --findings /path/to/findings.json --json

Validation

  • Packed-package App Security suite: 526 passed, 2 skipped across 36 files.
  • Standalone package: 57 tests passed, build and typecheck passed.
  • CLI app build and typecheck passed. Targeted ESLint for changed engine/tests passed.
  • No full-repository test or public-CI success claim. No changeset: internal draft extraction POC, no intended user-facing change.

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact

PR authored by Qlaw

…ge contract

Co-authored-by: Qlaw <noreply@qlaw.quick.shopify.io>
@github-actions github-actions Bot added the no-changelog This PR doesn't include a changeset entry. Is an internal only change not relevant to end users. label Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog This PR doesn't include a changeset entry. Is an internal only change not relevant to end users.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant