Conversation
jek
added this pull request to stack #8694
September 29, 2026 00:23
Contributor
Author
|
/snapit |
Converge deterministic-findings.json (renamed from scan.json) and agent-findings.json on one stored schema with versioned translation. Combine both sources in the engine, honoring per-check precedence, and fall back to union when the agent result is older than the deterministic one. Load both files through one shared loader. Rewrite `review` to render or encode the combined results, and move `submit` to a v2 payload projected from both sources with privacy filtering and new copy.
jek
force-pushed
the
app-security/review
branch
from
September 30, 2026 16:33
e9fca5c to
1dd945e
Compare
Contributor
|
| Command | Flag |
|---|---|
app:security:check |
--clean |
app:security:check |
--findings |
🔧 Removed Environment Variables
The following env vars are no longer referenced in command flags:
| Env Var | Previously Used By |
|---|---|
SHOPIFY_FLAG_APP_SECURITY_FINDINGS |
app:security:check --findings |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WHY are these changes introduced?
On
main, App Security results only describe a single run.checkwrites a trace and a review pack, agent findings count only when they're attested against that exact scan, andsubmituploads one run's trace. Any rerun invalidates the agent's work, so there's no lasting record of where an app stands that deterministic and agent analysis can each update, and thatreviewand Shopify read the same way.This PR gives App Security a durable model of an app's status that can be reviewed and refreshed over time.
WHAT is this pull request doing?
deterministic-findings.json, written by everycheck, andagent-findings.json, written by everyrecord. Each records when and at which commit it was produced. Either can be refreshed without invalidating the other, and reads translate by schema version so later CLI versions can evolve the format.revieworsubmitruns, the engine combines the results that are present, per check. Agent checks declareprecedence: aprefer-agentcheck uses the agent's result when it's at least as new as the deterministic one, and keeps both when it's older, so refreshing one source never silently hides the other.reviewis the view of that status. It shows each check with active findings, then a summary with counts, coverage, each results file's age and commit, and next steps (fix, refresh the agent review, send feedback).--jsonexposes the same combined status,--check-idnarrows it, and--blockinggates on it.submitsends whatreviewshows. Upload schema version 2 carries both sources with the inputs Shopify needs to recompute the same status (per-check statuses, precedence, suppression and times). It excludes source code, file paths, snippets, evidence, finding messages, agent reasoning and reasons, suppression justifications and commit identifiers, and it encourages feedback. The server has to accept schema version 2 for uploads to succeed.All App Security commands stay hidden, so there's no changeset.
How to manually test your changes?
pnpm shopify app security check --path /path/to/app pnpm shopify app security record --path /path/to/app < findings.json pnpm shopify app security review --path /path/to/app pnpm shopify app security review --path /path/to/app --json pnpm shopify app security review --path /path/to/app --check-id CREDENTIAL_LOG_LEAKAGE --blocking high pnpm shopify app security submit --path /path/to/app --dry-runChecklist
patchfor bug fixes ·minorfor new features ·majorfor breaking changes) and added a changeset withpnpm changeset add