Conversation
`review` counts skipped files with the same helper the submission payload uses. Move it next to the other display helpers so `review` no longer depends on the submission module. Co-authored-by: AI <noreply@pi.dev>
jek
added this pull request to stack #8694
October 1, 2026 02:46
Drop the submit step from the agent instructions and the `review` next steps, and say "record" where the instructions meant recording findings. `review` now leaves out the next steps section when there is nothing to suggest, instead of showing an empty heading. Co-authored-by: AI <noreply@pi.dev>
Delete the hidden, unreleased `submit` command, its services, and the engine's submission payload. `review` keeps the shared loader and combination. `clean` no longer removes submission.json, and the combination comments describe the rules for `review` alone now that no server recomputes them. Co-authored-by: AI <noreply@pi.dev>
`app security submit` was the only caller of the source scan upload URL and create mutations. Drop them from the developer platform client, the App Management client, and the test client. Co-authored-by: AI <noreply@pi.dev>
`app security submit` was the only caller that uploaded in-memory bytes, needed a Content-Type on the signed URL, or labeled the artifact in errors. Return to the file path signature that deploy and dev use. Co-authored-by: AI <noreply@pi.dev>
jek
force-pushed
the
app-security/remove-submit
branch
from
October 1, 2026 03:07
628fbd1 to
ecab28c
Compare
jek
marked this pull request as ready for review
October 1, 2026 03:08
Contributor
|
| Command | Flag |
|---|---|
app:security:check |
--clean |
app:security:check |
--findings |
🔧 Removed Environment Variables
The following env vars are no longer referenced in command flags:
| Env Var | Previously Used By |
|---|---|
SHOPIFY_FLAG_APP_SECURITY_FINDINGS |
app:security:check --findings |
SHOPIFY_FLAG_APP_SECURITY_DRY_RUN |
app:security:submit --dry-run |
SHOPIFY_FLAG_APP_SECURITY_FEEDBACK |
app:security:submit --feedback |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WHY are these changes introduced?
app security submitis hidden and has never been released. Removing it before release leaves the CLI with no upload path or payload contract to maintain.WHAT is this pull request doing?
Removes
app security submitand everything only it used, keeping the shared results loader and combination thatreviewrenders.reviewand the agent instructions no longer point atsubmit. When there's nothing left to suggest,reviewleaves out the next steps section instead of showing an empty heading.cleanno longer removessubmission.json.uploadToGCSgoes back to the file path signature that deploy and dev use.All App Security commands stay hidden, so there's no changeset.
How to manually test your changes?
Checklist
patchfor bug fixes ·minorfor new features ·majorfor breaking changes) and added a changeset withpnpm changeset add