[Feature] Protect theme push and dev with Theme Airlock#8150
Draft
Codercise wants to merge 26 commits into
Draft
[Feature] Protect theme push and dev with Theme Airlock#8150Codercise wants to merge 26 commits into
Codercise wants to merge 26 commits into
Conversation
Codercise
force-pushed
the
nh/theme-airlock-push-dev
branch
2 times, most recently
from
July 22, 2026 18:44
573e852 to
972c404
Compare
Codercise
force-pushed
the
nh/theme-airlock-push-dev
branch
from
July 23, 2026 19:28
972c404 to
d270f1e
Compare
4 tasks
4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WHY are these changes introduced?
theme pushandtheme devcan target the globally remembered store when a project omits--store. A developer moving between client projects can create a theme or upload files to the wrong store before noticing.Theme Airlock makes project trust a required precondition for those workflows.
This is PR 3 of the Theme Airlock safety stack and depends on #8148 and #8149.
Incremental review
Please review only the changes introduced by this PR:
Codercise/cli@nh/theme-airlock-trust-core...nh/theme-airlock-push-dev
WHAT is this pull request doing?
theme pushandtheme devbefore authentication, theme selection, creation, checksums, services, or uploads.shopify theme airlock add <store> --environment <name>setup.@shopify/themechangeset.--forceand--yescannot add trust or bypass a trust decision. The Airlock add command exposes no force, yes, or bypass flag.The coordinator is intentionally limited to the Push and Dev safety slice. Other remote theme commands and Black Box history remain follow-up work.
Review map
theme-airlock/coordinator.tstheme-command.tscommands/theme/push.tsandcommands/theme/dev.tsservices/metafields-pull.tstheme-airlock/preflight.tscommands/theme/airlock/add.tsandservices/theme-airlock-add.tspush.test.tsanddev.test.tsMigration
Existing non-interactive scripts need a one-time project trust configuration. Add a named environment to the nearest
shopify.theme.toml:Then select it in the script:
Future runs remain non-interactive. Passing
--storeand valid credentials does not establish project trust.The upgrade guide and built Push and Dev help document this requirement. The minor bump remains pending confirmation from the Developer Platform team.
How to test your changes?
Verified locally:
Manual reviewer flow:
shopify.theme.tomltrust.pnpm shopify:run theme dev --path <theme-directory>.pnpm shopify:run theme airlock add <store> --environment review --path <theme-directory>.pnpm shopify:run theme dev --path <theme-directory>again.review, the expected store,shopify.theme.tomlas the source, and operationtheme dev.Manual proof was completed against
the-bilko-store.myshopify.com:No files were uploaded.and made zero network connections.Post-release steps
None.
Stack
Checklist
minorbump and changeset are proposed, pending Developer Platform confirmation