94 wires and counting

$ follow Shopify

Keep up with Shopify in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-01
stories 24

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

Shopify CLI adds --ignore to app security check, Hydrogen fixes env pull quoting

By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology

Shopify/cli let app security checks honor .gitignore-style patterns via a new --ignore flag, while Hydrogen closed a quoting bug that corrupted escaped characters on an env pull round-trip.

Add --ignore to app security check and instructions Shopify/cli

by Jason Kirtland

The app security check now takes --ignore, where each value is one .gitignore line relative to the app directory, and patterns override both the defaults and git's own ignore rules, including re-including files with a leading !. Later patterns win over earlier ones, but a file can't be re-included while its parent folder is ignored, and a folder git ignores wholesale can only be re-included as ...

Fix env pull quoting so values round-trip through dotenv Shopify/hydrogen

by stephanie-shopify

`h2 env pull` wrapped values in double quotes and backslash-escaped `\`, `"` and tabs, but dotenv (used by `h2 dev`, `h2 env push` and `h2 deploy` through cli-kit) has no general escape syntax in quoted values, so it only expands `\n` and `\r` and the escapes landed in the parsed value. The result: values did not survive a pull-then-read round-trip, so a storefront value like `a\b` came back wi...

Remove App Security gitignore changeset Shopify/cli

by Jason Kirtland

The App Security gitignore changeset was pulled from public release notes, with the same done for the path filter changeset, keeping the feature out of release notes until it ships.

Trim comments in App Security path filtering Shopify/cli

by Jason Kirtland

Comments in the App Security path filtering code were trimmed, alongside the merge of the path-filter branch that carried the --ignore work.

Quick answers

What shipped in Shopify on October 1, 2026?
Shopify/cli let app security checks honor .gitignore-style patterns via a new --ignore flag, while Hydrogen closed a quoting bug that corrupted escaped characters on an env pull round-trip. In total, 18 commits and 6 pull requests landed.
Who contributed to Shopify on October 1, 2026?
2 developers shipped this update, including Jason Kirtland and stephanie-shopify.
What were the notable Shopify updates?
Add --ignore to app security check and instructions, Fix env pull quoting so values round-trip through dotenv, and Remove App Security gitignore changeset.