Contributions are welcome around evidence-backed scope mappings, official Shopify documentation references, false-positive reduction, parser improvements, scanner hardening, and privacy-safe fixtures.
You retain copyright in your contributions. By submitting a contribution, you agree that it is provided under the same MIT licence that applies to this project. You confirm that you have the right to submit the contribution. Disclose any third-party code or assets and identify their applicable licences before including them.
Use Node.js 20 or newer, then install the locked dependencies:
npm ci
npm test
npm run lint
npm run typecheck
npm run buildBefore opening a pull request, also run npm run coverage, npm audit --omit=dev --audit-level=high, and git diff --check.
- Add a regression test for every bug or rule change.
- Link every new Shopify scope mapping to an official Shopify source.
- Record the evidence version and confidence honestly.
- Keep UNKNOWN distinct from NOT EVIDENCED; static analysis must not claim that a scope is unused.
- Use privacy-safe fixtures with no credentials, tokens, or merchant data.
See the open issues for current opportunities.