$ the-wire · showcase
App Doctor becomes App Security, version gains --json
By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology
The Shopify CLI's App Doctor command family is renamed to App Security while its secret scanning gets a false-positive fix and its OAuth scope findings now require evidence, and shopify version gains a typed machine-readable contract.
Merge pull request #8593 from Shopify/joshlarson/rename-app-doctor-to-app-security Shopify/cli
The CLI's App Doctor commands are now App Security commands, so any scripts, CI steps, or docs referencing the old command names need renaming. This is a breaking change to the command surface; the paired work renames the whole family rather than aliasing it.
Merge pull request #8592 from Shopify/joshlarson/app-doctor-secret-false-positives Shopify/cli
Secret scanning under the renamed App Security command was reporting false positives; this change tightens the detection so real findings are not buried in noise. If you had learned to ignore secret warnings from this command, that assumption is now stale.
Merge pull request #8595 from Shopify/lopez-mar/app-doctor-scope-evidence Shopify/cli
OAuth scope findings from App Security now require supporting evidence before they are reported, meaning scope warnings are held to a higher bar before they surface. Expect fewer unsubstantiated scope hits in your CLI scan output.
Add JSON output to version command Shopify/cli
shopify version can now emit a closed JSON object with a required string version property, exposed through --json-schema, so scripts no longer have to parse the human-readable text. Normal mode still prints the bare version string such as 4.8.0, so existing parsing keeps working.
Remove app log sources field inventory document Shopify/cli
The app log sources field inventory document was removed from the repository, cleaning up documentation that no longer described the code.
Action items