Repository navigation
Theme Proof 1.0.0
Theme Proof creates automatic pull request previews for Shopify Liquid themes. It builds PR code without store credentials, deploys only validated theme files as a Shopify development preview, maintains one GitHub comment with storefront and Theme Editor links, and removes the preview when the PR closes.
Setup
Use the reusable workflow rather than a single build-and-deploy job:
BillyNoyes/Proof/.github/workflows/preview.yml@v1.0.0
Create a GitHub environment named theme-preview with:
- Secret
SHOPIFY_CLI_THEME_TOKEN: a dedicated Theme Access password. - Variable
SHOPIFY_FLAG_STORE: the fullmyshopify.comstore domain.
No project config is required for a complete no-build theme at the repository root. Optional setup, install, build, nested working-directory, and output-directory settings are available through theme-proof.config.json.
Read the setup guide and README.
Stable v1 scope
- Separate read-only build and credentialed deployment/cleanup jobs.
- Same-repository pull requests only; forks are skipped.
- Per-PR Shopify development contexts only; live and existing themes are never valid targets.
- Strict Theme Check and Shopify upload-result validation.
- Theme-only artifact allowlist with path, symlink, type, file-count, and size checks.
- Current PR state/SHA checks and serialized remote mutations.
- Safe cleanup with remote role/context verification, repeated-cleanup support, stale-run protection, and recovery for preview uploads whose comment state was not recorded.
- SHA-pinned internal and third-party Actions, Node.js 24, and Shopify CLI 4.8.0.
Validation
The exact release commit passed:
- 73 Action/core tests and 24 site interaction/animation tests.
- Linux, macOS, and Windows CI on Node.js 22.12/24.
- Workflow linting and a real build-Action smoke test.
- Reproducible self-contained Action bundles and dependency license notices.
- Root and project-path site builds plus light/dark, desktop/mobile, reduced-motion, keyboard, no-JavaScript, and link checks.
- Public npm registry audit with no known vulnerabilities at release time.
Private development-store testing covered creation, updates, context reuse, comments, manual deletion/recreation, repeated cleanup, close/reopen and stale-run behavior, cancellation, invalid credentials, and actual partial-upload errors. All test themes were removed and the original theme inventory was unchanged. See the sanitized integration report.
Operational limits
- GitHub.com and the documented GitHub-hosted Ubuntu deployment workflow are supported.
- Existing-theme and unpublished-theme target modes are not implemented.
- Protected storefronts still require their storefront password; Theme Editor links require an authorized Shopify admin session.
- Natural seven-day development-theme expiration and authenticated UI interactions were not exercised.
- A failed or manually canceled cleanup may need to be rerun; scheduled stale-preview reconciliation is not implemented.
Proof is independently developed and has no Shopify sponsorship or endorsement.