镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

Align CSP check catalog severity to medium - #8752

Merged
jplhomer merged 1 commit into
mainfrom
joshlarson/csp-severity-medium
Oct 5, 2026
Merged

jplhomer merged 1 commit into
mainfrom
joshlarson/csp-severity-medium

Conversation

@jplhomer

@jplhomer jplhomer commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

The MISSING_EMBEDDED_CSP catalog entry says high, but the agentic check, which is the only thing that emits this finding, says medium. The scan artifact snapshots the catalog's severity, so shopify app security check ended up showing two different severities for the same check.

WHAT is this pull request doing?

Changes the catalog severity to medium so it matches the check. Points stay the same (-10, which other medium entries also use).

How to manually test your changes?

  • shopify app security check on an embedded app. The MISSING_EMBEDDED_CSP catalog entry in the scan artifact now reports medium.

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

Copilot AI balanced review requested due to automatic review settings October 5, 2026 02:59
@jplhomer
jplhomer requested a review from a team as a code owner October 5, 2026 02:59
@github-actions github-actions Bot added the no-changelog This PR doesn't include a changeset entry. Is an internal only change not relevant to end users. label Oct 5, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A patch changeset and regression coverage are missing.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Aligns the CSP catalog severity with the agentic check.

Changes:

  • Changes MISSING_EMBEDDED_CSP from high to medium.
  • Keeps its score at -10.
File Description
packages/​app/​src/​cli/​services/​app-security-engine/​rules/​catalog.ts Aligns CSP severity metadata.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/app/src/cli/services/app-security-engine/rules/catalog.ts
@jplhomer
jplhomer requested review from dmerand and jek October 5, 2026 14:55
@jplhomer
jplhomer added this pull request to the merge queue Oct 5, 2026
Merged via the queue into main with commit 3073e90 Oct 5, 2026
32 checks passed
@jplhomer
jplhomer deleted the joshlarson/csp-severity-medium branch October 5, 2026 18:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog This PR doesn't include a changeset entry. Is an internal only change not relevant to end users.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants