Skip to content

Remove the App Security submit command - #8718

Open
jek wants to merge 5 commits into
app-security/reviewfrom
app-security/remove-submit
Open

jek wants to merge 5 commits into
app-security/reviewfrom
app-security/remove-submit

Conversation

@jek

@jek jek commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

app security submit is hidden and has never been released. Removing it before release leaves the CLI with no upload path or payload contract to maintain.

WHAT is this pull request doing?

Removes app security submit and everything only it used, keeping the shared results loader and combination that review renders.

  • review and the agent instructions no longer point at submit. When there's nothing left to suggest, review leaves out the next steps section instead of showing an empty heading.
  • clean no longer removes submission.json.
  • The combination rules are documented on their own terms, now that no server recomputes them from an upload.
  • The source scan upload mutations come out of the developer platform client, and uploadToGCS goes back to the file path signature that deploy and dev use.

All App Security commands stay hidden, so there's no changeset.

How to manually test your changes?

pnpm shopify app security check --path /path/to/app
pnpm shopify app security review --path /path/to/app
pnpm shopify app security instructions --path /path/to/app
pnpm shopify app security clean --path /path/to/app
pnpm shopify app security submit --path /path/to/app

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

`review` counts skipped files with the same helper the submission
payload uses. Move it next to the other display helpers so `review` no
longer depends on the submission module.

Co-authored-by: AI <noreply@pi.dev>
@jek
jek added this pull request to stack #8694 October 1, 2026 02:46
@jek jek changed the title app security/remove submit Remove the App Security submit command Oct 1, 2026
@github-actions github-actions Bot added the no-changelog This PR doesn't include a changeset entry. Is an internal only change not relevant to end users. label Oct 1, 2026
jek and others added 4 commits September 30, 2026 20:07
Drop the submit step from the agent instructions and the `review` next
steps, and say "record" where the instructions meant recording findings.
`review` now leaves out the next steps section when there is nothing to
suggest, instead of showing an empty heading.

Co-authored-by: AI <noreply@pi.dev>
Delete the hidden, unreleased `submit` command, its services, and the
engine's submission payload. `review` keeps the shared loader and
combination. `clean` no longer removes submission.json, and the
combination comments describe the rules for `review` alone now that no
server recomputes them.

Co-authored-by: AI <noreply@pi.dev>
`app security submit` was the only caller of the source scan upload URL
and create mutations. Drop them from the developer platform client, the
App Management client, and the test client.

Co-authored-by: AI <noreply@pi.dev>
`app security submit` was the only caller that uploaded in-memory bytes,
needed a Content-Type on the signed URL, or labeled the artifact in
errors. Return to the file path signature that deploy and dev use.

Co-authored-by: AI <noreply@pi.dev>
@jek
jek force-pushed the app-security/remove-submit branch from 628fbd1 to ecab28c Compare October 1, 2026 03:07
@jek
jek marked this pull request as ready for review October 1, 2026 03:08
@jek
jek requested review from a team as code owners October 1, 2026 03:08
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

⚠️ Potential Breaking Changes Detected

This PR contains changes that may break the existing contract.

@shopify/dev_experience — this PR contains breaking changes that require coordination for the next major release.

🗑️ Removed Commands

The following commands were removed from the OCLIF manifest:

  • app:security:submit

🏳️ Removed Flags

The following flags were removed from existing commands:

Command Flag
app:security:check --clean
app:security:check --findings

🔧 Removed Environment Variables

The following env vars are no longer referenced in command flags:

Env Var Previously Used By
SHOPIFY_FLAG_APP_SECURITY_FINDINGS app:security:check --findings
SHOPIFY_FLAG_APP_SECURITY_DRY_RUN app:security:submit --dry-run
SHOPIFY_FLAG_APP_SECURITY_FEEDBACK app:security:submit --feedback

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog This PR doesn't include a changeset entry. Is an internal only change not relevant to end users.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant