$ the-wire · showcase
Shopify CLI adds --ignore to app security check, Hydrogen fixes env pull quoting
By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology
Shopify/cli let app security checks honor .gitignore-style patterns via a new --ignore flag, while Hydrogen closed a quoting bug that corrupted escaped characters on an env pull round-trip.
Add --ignore to app security check and instructions Shopify/cli
The app security check now takes --ignore, where each value is one .gitignore line relative to the app directory, and patterns override both the defaults and git's own ignore rules, including re-including files with a leading !. Later patterns win over earlier ones, but a file can't be re-included while its parent folder is ignored, and a folder git ignores wholesale can only be re-included as ...
Fix env pull quoting so values round-trip through dotenv Shopify/hydrogen
`h2 env pull` wrapped values in double quotes and backslash-escaped `\`, `"` and tabs, but dotenv (used by `h2 dev`, `h2 env push` and `h2 deploy` through cli-kit) has no general escape syntax in quoted values, so it only expands `\n` and `\r` and the escapes landed in the parsed value. The result: values did not survive a pull-then-read round-trip, so a storefront value like `a\b` came back wi...
Remove App Security gitignore changeset Shopify/cli
The App Security gitignore changeset was pulled from public release notes, with the same done for the path filter changeset, keeping the feature out of release notes until it ships.
Trim comments in App Security path filtering Shopify/cli
Comments in the App Security path filtering code were trimmed, alongside the merge of the path-filter branch that carried the --ignore work.