95 wires and counting

$ follow Shopify

Keep up with Shopify in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-02
stories 33

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

App Security renames its artifacts, Hydrogen stops interrupting hydration

By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology

Shopify's App Security tooling lands a coordinated breaking rename and a new record command, while Hydrogen fixes a deferred-state update that was tearing down streamed server HTML.

fix(hydrogen): prevent Analytics.Provider from interrupting hydration Shopify/hydrogen

by andguy95

Analytics.Provider sits above every route-level Suspense boundary, and its cart, shop, and consent updates were applied as urgent updates, so React discarded already-streamed server HTML and client-rendered instead (error #418). Publishing through useAnalytics() now re-checks consent at call time, which closes the window where a revocation React had not yet committed could still leak events to ...

App Security: combined review and submit v2 Shopify/cli

by Jason Kirtland

scan.json becomes deterministic-findings.json and now shares one schema with agent-findings.json, with versioned translation between stored versions and a single loader for both. The engine combines the two sources honoring per-check precedence, falling back to union when the agent result is older, and submit moves to a v2 payload projected from both. The merges pull request body text, so brief...

Add record and agent-findings.json Shopify/cli

by Jason Kirtland

Agents submit investigation results through a new hidden app security record command that reads one findings document from stdin and validates it all-or-nothing, redacting agent text and snapshotting check metadata before replacing agent-findings.json. Check output, instructions, and agent-checks text now point agents at record instead of the previous path.

Replace check --clean with the clean command Shopify/cli

by Jason Kirtland

check --clean is gone; a dedicated app security clean command now removes every current and legacy artifact (scan, agent checks, agent findings, submission, and the trace/review/findings.json files) without asking. Check is narrowed to replacing deterministic-findings.json and agent-checks.json only, so running it repeatedly is always safe. This is a breaking change for any script or CI step st...

Replace review.json with agent-checks.json Shopify/cli

by Jason Kirtland

review.json is renamed agent-checks.json and carries an engine {name, version} block instead of the bare security_version, with check --json returning an agent_checks_path rather than embedding the whole pack. Prompt fixes for SQL injection, XSS, and unsafe innerHTML drop their references to a review pack and prompt hashes, which matters if you grep that output for the old field names.

Quick answers

What shipped in Shopify on October 2, 2026?
Shopify's App Security tooling lands a coordinated breaking rename and a new record command, while Hydrogen fixes a deferred-state update that was tearing down streamed server HTML. In total, 26 commits and 7 pull requests landed.
Who contributed to Shopify on October 2, 2026?
2 developers shipped this update, including Jason Kirtland and andguy95.
What were the notable Shopify updates?
fix(hydrogen): prevent Analytics.Provider from interrupting hydration, App Security: combined review and submit v2, and Add record and agent-findings.json.