$ the-wire · showcase
App Security checks arrive in Shopify CLI, injection checks changeset pulled
By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology
Shopify/cli added agentic SQL injection and XSS checks to app security while removing the changesets that would have shipped the earlier App Doctor and injection work, and narrowed secret findings to Shopify tokens only.
Merge pull request #8659 from Shopify/app-security-injection-prompts Shopify/cli
Agentic SQL injection and XSS checks landed in app security, giving the CLI a scanner that reasons about injection flaws rather than pattern-matching them. Treat this as the feature of the day if you run app security checks in CI.
Merge pull request #8697 from lopez-mar/fix/shopify-only-secret-prefixes Shopify/cli
Secret findings are now limited to Shopify tokens, so credentials from other providers no longer surface as app security secrets. Expect fewer false positives, and expect non-Shopify secrets to go unreported.
Add optional OWASP references to injection prompts Shopify/cli
Injection prompts can now carry optional OWASP references, pointing the checks at a published taxonomy when the guidance is emitted. This is additive: nothing changes for callers that leave the references off.
Remove App Doctor and App Security changesets Shopify/cli
The App Doctor and App Security changesets were removed. If you were tracking those entries in the release notes to anticipate what lands next, they are gone from the queue.
Remove injection checks changeset Shopify/cli
The injection checks changeset was removed along with it, folding the remaining long tail of app security housekeeping into this batch.