94 wires and counting

$ follow Shopify

Keep up with Shopify in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-22
stories 44

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

App Doctor becomes App Security, version gains --json

By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology

The Shopify CLI's App Doctor command family is renamed to App Security while its secret scanning gets a false-positive fix and its OAuth scope findings now require evidence, and shopify version gains a typed machine-readable contract.

Merge pull request #8593 from Shopify/joshlarson/rename-app-doctor-to-app-security Shopify/cli

by jason kirtland

The CLI's App Doctor commands are now App Security commands, so any scripts, CI steps, or docs referencing the old command names need renaming. This is a breaking change to the command surface; the paired work renames the whole family rather than aliasing it.

Merge pull request #8592 from Shopify/joshlarson/app-doctor-secret-false-positives Shopify/cli

by Mar Lopez

Secret scanning under the renamed App Security command was reporting false positives; this change tightens the detection so real findings are not buried in noise. If you had learned to ignore secret warnings from this command, that assumption is now stale.

Merge pull request #8595 from Shopify/lopez-mar/app-doctor-scope-evidence Shopify/cli

by Mar Lopez

OAuth scope findings from App Security now require supporting evidence before they are reported, meaning scope warnings are held to a higher bar before they surface. Expect fewer unsubstantiated scope hits in your CLI scan output.

Add JSON output to version command Shopify/cli

by dmerand

shopify version can now emit a closed JSON object with a required string version property, exposed through --json-schema, so scripts no longer have to parse the human-readable text. Normal mode still prints the bare version string such as 4.8.0, so existing parsing keeps working.

Remove app log sources field inventory document Shopify/cli

by Gonzalo Riestra

The app log sources field inventory document was removed from the repository, cleaning up documentation that no longer described the code.

Quick answers

What shipped in Shopify on September 22, 2026?
The Shopify CLI's App Doctor command family is renamed to App Security while its secret scanning gets a false-positive fix and its OAuth scope findings now require evidence, and shopify version gains a typed machine-readable contract. In total, 29 commits and 15 pull requests landed.
Who contributed to Shopify on September 22, 2026?
4 developers shipped this update, including jason kirtland, Mar Lopez, Gonzalo Riestra, and dmerand.
What were the notable Shopify updates?
Merge pull request #8593 from Shopify/joshlarson/rename-app-doctor-to-app-security, Merge pull request #8592 from Shopify/joshlarson/app-doctor-secret-false-positives, and Merge pull request #8595 from Shopify/lopez-mar/app-doctor-scope-evidence.