$ the-wire · showcase
App Security renames its artifacts, Hydrogen stops interrupting hydration
By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology
Shopify's App Security tooling lands a coordinated breaking rename and a new record command, while Hydrogen fixes a deferred-state update that was tearing down streamed server HTML.
fix(hydrogen): prevent Analytics.Provider from interrupting hydration Shopify/hydrogen
Analytics.Provider sits above every route-level Suspense boundary, and its cart, shop, and consent updates were applied as urgent updates, so React discarded already-streamed server HTML and client-rendered instead (error #418). Publishing through useAnalytics() now re-checks consent at call time, which closes the window where a revocation React had not yet committed could still leak events to ...
App Security: combined review and submit v2 Shopify/cli
scan.json becomes deterministic-findings.json and now shares one schema with agent-findings.json, with versioned translation between stored versions and a single loader for both. The engine combines the two sources honoring per-check precedence, falling back to union when the agent result is older, and submit moves to a v2 payload projected from both. The merges pull request body text, so brief...
Add record and agent-findings.json Shopify/cli
Agents submit investigation results through a new hidden app security record command that reads one findings document from stdin and validates it all-or-nothing, redacting agent text and snapshotting check metadata before replacing agent-findings.json. Check output, instructions, and agent-checks text now point agents at record instead of the previous path.
Replace check --clean with the clean command Shopify/cli
check --clean is gone; a dedicated app security clean command now removes every current and legacy artifact (scan, agent checks, agent findings, submission, and the trace/review/findings.json files) without asking. Check is narrowed to replacing deterministic-findings.json and agent-checks.json only, so running it repeatedly is always safe. This is a breaking change for any script or CI step st...
Replace review.json with agent-checks.json Shopify/cli
review.json is renamed agent-checks.json and carries an engine {name, version} block instead of the bare security_version, with check --json returning an agent_checks_path rather than embedding the whole pack. Prompt fixes for SQL injection, XSS, and unsafe innerHTML drop their references to a review pack and prompt hashes, which matters if you grep that output for the old field names.
Action items