Repository navigation
Conversation
An app directory below its Git repository root left MISSING_DEPENDENCY_SECURITY_AUTOMATION unresolved, because configuration was only looked up in the app directory. Dependabot and Renovate read their configuration from the repository root, so look it up there. An app with its own repository keeps its own boundary. Refs shop/issues-develop#24160 Co-authored-by: Qlaw <noreply@qlaw.quick.shopify.io>
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The implementation safely addresses the reported nested-app behavior with comprehensive boundary and integration coverage.
0 open findings
What changed in this PR
Resolves dependency-automation detection for apps nested within Git repositories.
Changes:
- Resolves Dependabot/Renovate configuration from the nearest repository root.
- Preserves scan exclusions, bounded reads, symlink containment, and nested repository boundaries.
- Adds integration/discovery coverage and a patch changeset.
| File | Description |
|---|---|
dependency-automation.test.ts |
Adds nested-app integration tests. |
dependency-automation-discovery.test.ts |
Tests repository boundaries and safe reads. |
scanners/types.ts |
Updates discovery contract documentation. |
scanners/discover.ts |
Implements repository-root configuration discovery. |
| Changeset | Documents the user-facing fix. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Expected absolutePath used node path.join, which is backslash-separated on Windows. Build it with joinPath like discover.ts, and include ext. Refs shop/issues-develop#24160 Co-authored-by: Qlaw <noreply@qlaw.quick.shopify.io>
…y root Dependency automation configuration was read directly, contained by the repository root, whenever that root was not itself a scan directory. An included directory such as .github below the root then bypassed gathering, so --exclude and git-ignore were not applied to its configuration. Decide per configuration file: a file inside any scan directory is read only when gathered, and only a file outside every scan directory is read directly. Refs shop/issues-develop#24160 Co-authored-by: Qlaw <noreply@qlaw.quick.shopify.io>
Contributor
|
Should we check dependency automation for every repository containing a gathered package manifest with dependencies? or |
Contributor
Author
|
@jek Yeah, maybe a follow-up PR that groups package files by their nearest git root? Mainly addressing your second example. The first one looks like a submodule situation. |
dmerand
approved these changes
Oct 8, 2026
jek
approved these changes
Oct 8, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WHY are these changes introduced?
Refs shop/issues-develop#24160.
MISSING_DEPENDENCY_SECURITY_AUTOMATIONnever passes or reports for an app below its Git repository root, such asapps/fooin a monorepo. Discovery rejects the app as "nested below a parent Git repository", so the check is alwaysunresolved, even when the root has.github/dependabot.yml.WHAT is this pull request doing?
Looks for Dependabot and Renovate configuration at the root of the nearest Git repository that holds the app, which is where those bots read it.
--include-dirset to the root), only gathered paths are read, so--excludeand Git ignore rules still apply..gitkeeps its own boundary, so a parent repository's configuration can't make it pass.Includes a
@shopify/apppatch changeset (.changeset/app-security-dependency-automation-repository-root.md).How to manually test your changes?
In
deterministic-findings.json,MISSING_DEPENDENCY_SECURITY_AUTOMATIONisexecutedwith no findings, and../../.github/dependabot.ymlis among its inspected files. Before this change it'sunresolved. Delete the rootdependabot.ymland the check reports a finding.Checklist
patchfor bug fixes ·minorfor new features ·majorfor breaking changes) and added a changeset withpnpm changeset addPR authored by Qlaw