RepoJournal

$ cat shopify/month/2026-09-01.log

Shopify

Shopify

the month in review · September 2026

Shopify CLI closes credential leaks, ships 4.8.0

By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology

♥

Hydrogen moves consent to async initialization and keeps https origin in MiniOxygen local dev.

278 commits 136 PRs merged 12 releases 26 briefings covered

all shopify reviews →

Prevent GitHub credentials from being logged locally Shopify/cli

by gonzaloriestra

GitHub helper scripts had been printing authentication tokens and signed download URLs to command output, and the change notes state CI stays safe because it uses secrets rather than `dev` commands. If you have agent transcripts or shell history from local CLI runs, treat those credentials as exposed.

Merge pull request #8435 from Shopify/security-validate-git-author-7844826945563519319 Shopify/cli

by Gonzalo Riestra

Git commit author arguments now go through validation before the CLI uses them. This is the breaking half of the period's credential work, so scripts that shell out through the dev commands are the ones to re-test.

Redact store signup JWTs from analytics payloads Shopify/cli

by craigmichaelmartin

The signup JWT accepted by `shopify store stripe-auth --signup` is a bearer credential for the target store, and it was flowing into analytics payloads. The accompanying change reads the JWT from stdin when the flag is omitted, so interactive and scripted auth flows can stop putting it on the command line.

Add app subscription migration commands Shopify/cli

by tyler-eon

Four commands land for Partners moving legacy manual-billing subscriptions to Shopify-managed app pricing: schedule, unschedule, and two more for scripting the migration. The stated goal is a safe, scriptable workflow, so migration state can now be driven from CI instead of the dashboard.

@shopify/hydrogen@2026.4.6 Shopify/hydrogen

by shopify-github-actions-access[bot]

Shopify's consent API now returns visitor tracking values in the `consentManagement` response, and Hydrogen initializes consent asynchronously so the Customer Privacy API fetches and caches them before analytics starts. If you wired up Hydrogen's separate consent mechanism, this replaces it.

@shopify/mini-oxygen@4.2.3 Shopify/hydrogen

by shopify-github-actions-access[bot]

MiniOxygen previously always passed an `http:` URL to the worker even when the Vite dev server ran over HTTPS, so code reading `new URL(request.url).origin` saw the wrong origin. That broke Customer Account OAuth in local dev; the scheme is now preserved.

Show `store list` context in an info banner Shopify/cli

by nickwesselman

The organization line used to sit flush on top of the table header and the `shopify store auth list` hint ran into the last row. Context now renders in a banner, which matters most when the command output is being read by a script or an agent.

Ask about demo data when creating a dev store interactively Shopify/cli

by nickwesselman

`shopify store create dev` could already populate a store with demo data, but nothing ever asked. A shared prompt now runs after the name and plan questions, and along the way `--with-demo-data` became `--demo-data`; update any scripts still passing the old flag.

$ ls shopify/month/ # the briefings behind this review

Tue Sep 1 Validate git author args, stop leaking GitHub credentials Wed Sep 2 Redact store signup JWTs from analytics and terminal output Thu Sep 3 Shopify CLI starts asking for demo data on dev store creation Fri Sep 4 Two Shopify CLI prompts make their unexpected appearances visible Sat Sep 5 Shopify CLI adds subscription migration list command Sun Sep 6 Filter store list by type, server-side Mon Sep 7 shopify store list gains server-side type filtering Tue Sep 8 Shopify CLI unhides store create dev and store delete Wed Sep 9 Dasherize `client_transfer` in Shopify CLI Thu Sep 10 Shopify CLI 4.8.0 ships store create, pnpm install recovery, and honest upgrade messaging Fri Sep 11 App Doctor reuses Shopify CLI app identity, engine internals go behind operations Sat Sep 12 Shopify CLI now syncs config/styles.css and AGENTS.md Mon Sep 14 Scheduled maintenance runs fixed in Shopify CLI Tue Sep 15 App doctor drops the lax Shopify API key check Wed Sep 16 Shopify CLI starts detecting AI agents in analytics Thu Sep 17 Shopify CLI drops CVE audit from app doctor, adds typed command events Fri Sep 18 App Doctor gains a dependency automation check, organization list gets a JSON schema Sat Sep 19 Per-target function input variables, optional owner_type for UI extension metafields Mon Sep 21 Shopify CLI recovers from storage permission errors and versions in JSON Tue Sep 22 App Doctor becomes App Security, version gains --json Wed Sep 23 Shopify CLI groups App Security findings and guards agent scans Thu Sep 24 Shopify CLI drops App Security score, Hydrogen enforces typed JSON output Fri Sep 25 Subscription migration commands go visible, MiniOxygen keeps https in local dev Mon Sep 28 Shopify CLI bumps theme-tools and puts flaky tests first Tue Sep 29 Hydrogen moves consent to CTA async, dropping Server-Timing and legacy cookies Wed Sep 30 App Security checks arrive in Shopify CLI, injection checks changeset pulled

Keep up with Shopify in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

all shopify reviews →