Skip to content

Port app security flag descriptions from the shopify.dev docs - #8853

Merged
jplhomer merged 1 commit into
mainfrom
joshlarson/app-security-docs-backport-2090077
Oct 9, 2026
Merged

jplhomer merged 1 commit into
mainfrom
joshlarson/app-security-docs-backport-2090077

Conversation

@jplhomer

@jplhomer jplhomer commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

The shopify.dev docs change for shopify app security (World PR 2090077) hand-edits two flag descriptions in its copy of generated_docs_data_v2.json. The next docs generation from this repo would overwrite those edits, so the source needs to say the same thing.

WHAT is this pull request doing?

Ports those two descriptions to the flag definitions and regenerates the manifest, README and shopify.dev docs data:

  • --blocking (app security check and review): lists the levels and the none default.
  • --skip-instructions (app security check): says when to use it.

After regeneration, the five appsecurity* entries in docs-shopify.dev/generated/generated_docs_data_v2.json match the World PR's copy exactly. The World PR's other JSON changes are \u escaping and a trailing newline, with no content difference, so there's nothing to port for them.

How to manually test your changes?

pnpm shopify app security check --help
pnpm shopify app security review --help

Check the --blocking and --skip-instructions descriptions.

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

Copilot AI balanced review requested due to automatic review settings October 9, 2026 14:10
@jplhomer
jplhomer requested review from a team as code owners October 9, 2026 14:10
@github-actions github-actions Bot added shopify.dev preview Area: @shopify/cli @shopify/cli package issues labels Oct 9, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The source descriptions, test assertion, changeset, and generated documentation are consistent.

0 open findings

What changed in this PR

Clarifies App Security flag help text and keeps generated CLI and Shopify.dev documentation synchronized.

Changes:

  • Documents --blocking levels and default behavior.
  • Clarifies when to use --skip-instructions.
  • Updates tests, generated artifacts, and patch changesets.
File Description
packages/​app/​src/​cli/​commands/​app/​security/​blocking-flag.ts Updates shared --blocking help.
packages/​app/​src/​cli/​commands/​app/​security/​check.ts Updates --skip-instructions help.
packages/​app/​src/​cli/​commands/​app/​security/​check.test.ts Updates the description assertion.
packages/​cli/​oclif.manifest.json Regenerates command metadata.
packages/​cli/​README.md Regenerates CLI reference text.
docs-shopify.dev/​generated/​generated_docs_data_v2.json Regenerates Shopify.dev command data.
.changeset/​app-security-flag-descriptions.md Adds patch release entries.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@jplhomer
jplhomer added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 87b806e Oct 9, 2026
46 of 59 checks passed
@jplhomer
jplhomer deleted the joshlarson/app-security-docs-backport-2090077 branch October 9, 2026 14:56
dmerand added a commit that referenced this pull request Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants