94 wires and counting

$ follow Shopify

Keep up with Shopify in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-25
stories 23

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

Subscription migration commands go visible, MiniOxygen keeps https in local dev

By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology

Shopify's CLI surfaces subscription migration commands in help as that work goes GA, while Hydrogen fixes an HTTPS origin bug that broke Customer Account OAuth during local Vite development.

@shopify/mini-oxygen@4.2.3 Shopify/hydrogen

by shopify-github-actions-access[bot]

MiniOxygen now keeps the `https:` scheme in the request URL your worker receives when the Vite dev server runs over HTTPS; it previously always handed over an `http:` URL, so anything reading `new URL(request.url).origin` (Customer Account OAuth is the named case) saw the wrong origin locally. The release notes state MiniOxygen "always passed an `http:` URL," which is now corrected.

Show subscription migration commands in CLI help Shopify/cli

by tyler-eon

The `hidden` flag comes off the `cancel`, `list`, `schedule`, `status`, and `unschedule` subscription migration commands, and the shipped oclif manifest entries were refreshed to match. Since migration is going GA, these commands now show up in help and command discovery paths instead of existing only for those who already knew the names.

Resolve `store list --organization-id` without listing every organization Shopify/cli

by amcaplan

`shopify store list --organization-id <id>` no longer fetches the account's entire organization list just to validate the flag, since `ListAccessibleShops` already returns the organization name. That pre-check query passed no `first` and selected no `pageInfo`, so for accounts in enough organizations a valid `--organization-id` could be reported as invalid.

Ignore query string when inferring SEO media type Shopify/hydrogen

by kwy404

`inferMimeType` no longer reads the extension from everything after the last `.`, query string included; it strips the query string and hash first. Shopify CDN URLs typically end in `?v=<timestamp>`, which meant a `.png` image was getting `og:image:type` set to `image/jpeg` in both `generateSeoTags` and `getSeoMeta`.

Revert SCOPE_OVER_REQUEST prompt changes from #8595 Shopify/cli

by lopez-mar

The `SCOPE_OVER_REQUEST` check prompt is back at version 1, along with the embedded source copy and catalog entry, undoing the prompt changes from #8595 while the patch changeset stays in place so the version bump still ships. A companion commit dropped a redundant changeset on the CLI side, and the migration help snapshot and test types were updated.

Quick answers

What shipped in Shopify on September 25, 2026?
Shopify's CLI surfaces subscription migration commands in help as that work goes GA, while Hydrogen fixes an HTTPS origin bug that broke Customer Account OAuth during local Vite development. In total, 13 commits, 8 pull requests, and 2 releases landed.
Who contributed to Shopify on September 25, 2026?
7 developers shipped this update, including tyler-eon, lopez-mar, amcaplan, shopify-github-actions-access[bot], kwy404, majd-shopify, and fredericoo.
What were the notable Shopify updates?
@shopify/mini-oxygen@4.2.3, Show subscription migration commands in CLI help, and Resolve `store list --organization-id` without listing every organization.