$ cat shopify/month/2026-09-01.log
the month in review · September 2026
Shopify CLI closes credential leaks, ships 4.8.0
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
Hydrogen moves consent to async initialization and keeps https origin in MiniOxygen local dev.
Prevent GitHub credentials from being logged locally Shopify/cli
GitHub helper scripts had been printing authentication tokens and signed download URLs to command output, and the change notes state CI stays safe because it uses secrets rather than `dev` commands. If you have agent transcripts or shell history from local CLI runs, treat those credentials as exposed.
Merge pull request #8435 from Shopify/security-validate-git-author-7844826945563519319 Shopify/cli
Git commit author arguments now go through validation before the CLI uses them. This is the breaking half of the period's credential work, so scripts that shell out through the dev commands are the ones to re-test.
Redact store signup JWTs from analytics payloads Shopify/cli
The signup JWT accepted by `shopify store stripe-auth --signup` is a bearer credential for the target store, and it was flowing into analytics payloads. The accompanying change reads the JWT from stdin when the flag is omitted, so interactive and scripted auth flows can stop putting it on the command line.
Add app subscription migration commands Shopify/cli
Four commands land for Partners moving legacy manual-billing subscriptions to Shopify-managed app pricing: schedule, unschedule, and two more for scripting the migration. The stated goal is a safe, scriptable workflow, so migration state can now be driven from CI instead of the dashboard.
@shopify/hydrogen@2026.4.6 Shopify/hydrogen
by shopify-github-actions-access[bot]
Shopify's consent API now returns visitor tracking values in the `consentManagement` response, and Hydrogen initializes consent asynchronously so the Customer Privacy API fetches and caches them before analytics starts. If you wired up Hydrogen's separate consent mechanism, this replaces it.
@shopify/mini-oxygen@4.2.3 Shopify/hydrogen
by shopify-github-actions-access[bot]
MiniOxygen previously always passed an `http:` URL to the worker even when the Vite dev server ran over HTTPS, so code reading `new URL(request.url).origin` saw the wrong origin. That broke Customer Account OAuth in local dev; the scheme is now preserved.
Show `store list` context in an info banner Shopify/cli
The organization line used to sit flush on top of the table header and the `shopify store auth list` hint ran into the last row. Context now renders in a banner, which matters most when the command output is being read by a script or an agent.
Ask about demo data when creating a dev store interactively Shopify/cli
`shopify store create dev` could already populate a store with demo data, but nothing ever asked. A shared prompt now runs after the name and plan questions, and along the way `--with-demo-data` became `--demo-data`; update any scripts still passing the old flag.
$ ls shopify/month/ # the briefings behind this review
Keep up with Shopify in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.