RepoJournal

$ cat shopify/week/2026-09-21.log

Shopify

Shopify

the week in review · Sep 21 – Sep 27, 2026

App Doctor becomes App Security, scoring removed

By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology

♥

Shopify CLI retired the App Doctor name and stripped the score from App Security JSON output, breaking scripts and agents that read it.

87 commits 44 PRs merged 4 releases 5 briefings covered

all shopify reviews →

Merge pull request #8593 from Shopify/joshlarson/rename-app-doctor-to-app-security Shopify/cli

by jason kirtland

The `app doctor` command surface is now `app security`; every invocation, alias, and CI step referencing the old name needs updating. This is the period's widest-reaching change, and it lands alongside the rest of the App Security rework.

Remove score from App Security JSON output Shopify/cli

by jplhomer

The score was already hidden from human-readable output but survived in the `--json` payload, and agents reading it were reporting it, per the PR description. Both `scan.score` and `trace.score` are now gone, and the trace schema version moves to 3, so anything parsing those fields breaks rather than degrades.

Protect App security agent findings from new scans Shopify/cli

by Jason Kirtland

A new scan now refuses to start when agent findings or compiled review results already exist, so the deterministic check can no longer overwrite that work. Starting over requires `--clean` explicitly, and inherited environment values are ignored.

Group repeated App Security findings in human-readable output Shopify/cli

by Josh Larson

The terminal report collapses repeated findings by rule, optional pattern, and severity; JSON output, traces, scoring, and check counts still retain every occurrence. Expect shorter human output without a loss of data in the machine path.

Merge pull request #8592 from Shopify/joshlarson/app-doctor-secret-false-positives Shopify/cli

by Mar Lopez

Secret scanning false positives are addressed, and the companion change makes OAuth scope findings require supporting evidence before they are reported. Together they cut noise from two of the checks most likely to be wrong.

@shopify/mini-oxygen@4.2.3 Shopify/hydrogen

by shopify-github-actions-access[bot]

MiniOxygen now keeps the `https:` scheme in the request URL your worker receives when the Vite dev server runs over HTTPS; it previously always passed an `http:` URL. Code that derives its origin from `new URL(request.url).origin`, such as Customer Account OAuth, saw the wrong origin in local dev until now.

Fix local storage initialization permission errors Shopify/cli

by gonzaloriestra

Permission errors during local storage initialization were bypassing the existing recovery handler, so commands like `theme info` could fail with a raw filesystem error instead of recovering. That path is now handled.

Show subscription migration commands in CLI help Shopify/cli

by tyler-eon

Subscription migration going GA means `cancel`, `list`, `schedule`, `status`, and `unschedule` lose their `hidden` flag and appear in help and command discovery. If you scripted around their absence, that assumption no longer holds.

$ ls shopify/week/ # the briefings behind this review

Keep up with Shopify in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

all shopify reviews →