Skip to content

Exclude gitignored files from App Security discovery - #8691

Open
jek wants to merge 1 commit into
mainfrom
app-security/exclude-gitignore
Open

jek wants to merge 1 commit into
mainfrom
app-security/exclude-gitignore

Conversation

@jek

@jek jek commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

shopify app security check ran its deterministic checks on files that git ignores, such as local .env files and generated output. That produced findings, including committed-secret findings, for files that never reach the
repository.

WHAT is this pull request doing?

Discovery now walks the app root once and skips a path when a default pattern or git excludes it:

  • Git's untracked, ignored paths come from git ls-files --others --ignored --exclude-standard, so nested .gitignore files, negations, .git/info/exclude and global excludes all apply. Tracked files that match .gitignore are still scanned.
  • No git exclusions apply when the app isn't in a repository, when git fails, or when an enclosing repository ignores the app folder.
  • Dot-folders are now walked, so .github/ and .vscode/ are scanned for secrets. Generated dot-folders (.next/, .shopify/, .yarn/, …) are excluded by default.
  • Dependabot and Renovate config follows the same exclusions, so an ignored config file doesn't count as dependency automation.
  • The committed-secret check no longer skips ignored files on its own. When git ignores a file that was still scanned, the finding says why.

Exclusions are silent, like the existing hardcoded ones: they aren't recorded in the trace or submission.

How to manually test your changes?

In a git-tracked app:

  1. Add .env to .gitignore, and put a Shopify token-shaped value (shpat_ followed by 32 hex characters) in .env.
  2. pnpm shopify app security check --path /path/to/app: no committed-secret finding for .env.
  3. git -C /path/to/app add -f .env, then rerun: the finding appears, because tracked files are scanned.
  4. Put the same value in .github/workflows/deploy.yml and rerun: it's reported.

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

App Security's deterministic checks scanned files that git ignores, such
as local .env files and generated output, and reported findings for files
that never reach the repository.

Discovery now walks the app root once and skips a path when either of two
exclusion phases matches it:

- Default .gitignore-style patterns for dependencies, build output,
  caches, test and fixture trees, and CLI-generated folders.
- The untracked, ignored paths git reports, so nested .gitignore files,
  negations, .git/info/exclude and global excludes all apply. Tracked
  files that match .gitignore are still scanned.

No git exclusions apply when the app isn't in a git repository, when git
fails, or when an enclosing repository ignores the app folder or one of
its ancestors. Git's listing skips the default directories, so git doesn't
traverse trees the walker never enters.

The walker prunes excluded folders, stops at nested apps, and walks
dot-folders and dotfiles, so .github/ and .vscode/ are now scanned for
secrets. Loading the app configuration isn't subject to exclusions.
Dependabot and Renovate configuration is, so an ignored configuration file
no longer counts as dependency automation.

The committed-secret check no longer skips untracked, ignored files on its
own, because discovery decides what is scanned. When git ignores a file
that was still scanned, the finding says why: an enclosing repository
ignores the app, the file is inside a nested repository, or git couldn't
list ignored files.
@jek
jek marked this pull request as ready for review September 28, 2026 22:14
@jek
jek requested a review from a team as a code owner September 28, 2026 22:14
@github-actions github-actions Bot added the Area: @shopify/app @shopify/app package issues label Sep 28, 2026
@jek
jek requested a review from jplhomer September 28, 2026 22:14

Copy link
Copy Markdown
Contributor

Sorry to ask, but why is a change to exclude gitignored files, a +2000 line change?
I'm sure this can be simplified?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area: @shopify/app @shopify/app package issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants