Skip to content

Theme Proof 1.0.0

Latest

Choose a tag to compare

@BillyNoyes BillyNoyes released this 22 Sep 09:33
e577ac0

Theme Proof 1.0.0

Theme Proof creates automatic pull request previews for Shopify Liquid themes. It builds PR code without store credentials, deploys only validated theme files as a Shopify development preview, maintains one GitHub comment with storefront and Theme Editor links, and removes the preview when the PR closes.

Setup

Use the reusable workflow rather than a single build-and-deploy job:

BillyNoyes/Proof/.github/workflows/preview.yml@v1.0.0

Create a GitHub environment named theme-preview with:

  • Secret SHOPIFY_CLI_THEME_TOKEN: a dedicated Theme Access password.
  • Variable SHOPIFY_FLAG_STORE: the full myshopify.com store domain.

No project config is required for a complete no-build theme at the repository root. Optional setup, install, build, nested working-directory, and output-directory settings are available through theme-proof.config.json.

Read the setup guide and README.

Stable v1 scope

  • Separate read-only build and credentialed deployment/cleanup jobs.
  • Same-repository pull requests only; forks are skipped.
  • Per-PR Shopify development contexts only; live and existing themes are never valid targets.
  • Strict Theme Check and Shopify upload-result validation.
  • Theme-only artifact allowlist with path, symlink, type, file-count, and size checks.
  • Current PR state/SHA checks and serialized remote mutations.
  • Safe cleanup with remote role/context verification, repeated-cleanup support, stale-run protection, and recovery for preview uploads whose comment state was not recorded.
  • SHA-pinned internal and third-party Actions, Node.js 24, and Shopify CLI 4.8.0.

Validation

The exact release commit passed:

  • 73 Action/core tests and 24 site interaction/animation tests.
  • Linux, macOS, and Windows CI on Node.js 22.12/24.
  • Workflow linting and a real build-Action smoke test.
  • Reproducible self-contained Action bundles and dependency license notices.
  • Root and project-path site builds plus light/dark, desktop/mobile, reduced-motion, keyboard, no-JavaScript, and link checks.
  • Public npm registry audit with no known vulnerabilities at release time.

Private development-store testing covered creation, updates, context reuse, comments, manual deletion/recreation, repeated cleanup, close/reopen and stale-run behavior, cancellation, invalid credentials, and actual partial-upload errors. All test themes were removed and the original theme inventory was unchanged. See the sanitized integration report.

Operational limits

  • GitHub.com and the documented GitHub-hosted Ubuntu deployment workflow are supported.
  • Existing-theme and unpublished-theme target modes are not implemented.
  • Protected storefronts still require their storefront password; Theme Editor links require an authorized Shopify admin session.
  • Natural seven-day development-theme expiration and authenticated UI interactions were not exercised.
  • A failed or manually canceled cleanup may need to be rerun; scheduled stale-preview reconciliation is not implemented.

Proof is independently developed and has no Shopify sponsorship or endorsement.