Where alerts come from
Meridian ingests Shopify’s changelog and classifies each entry with AI: a severity (critical, warning, or info), the impact areas, the APIs affected (the exact identifiers to look for in code), a recommendation, and a migration deadline where Shopify gives one. Classification is grounded against Shopify’s live developer docs and GraphQL schema, so the affected-API list is real rather than guessed.Matching your code
If your app has a connected GitHub repository, Meridian scans it for the affected-API identifiers and records where they appear (file, line range, and a snippet) on each relevant alert. Scans are incremental: only changed files are re-read, and an alert with no remaining matches is retired automatically. Tests, mocks, fixtures and translation files are skipped, since a test that mocks an API isn’t your app using it. So are generated files (GraphQL codegen types, Function input schemas, downloaded schemas) and built bundles, which contain the whole Shopify schema rather than what your app calls. If a scan can’t finish, the alerts page says why instead of showing an empty result. Only changes that ask you to do something are matched against your code: entries Shopify marks Action Required or Breaking API Change, and deprecation announcements. Announcements of new, optional capabilities stay in the changelog but never raise an alert. Some changes are skipped for your app automatically:- Changes for products apps don’t build on, such as Hydrogen and Shop Minis.
- Changes to an extension surface your app doesn’t ship. A checkout UI, POS, customer account, admin extension, Functions, theme or payments change only applies if your repository has a matching extension.
- Required change: your app breaks, loses data, or fails review if you don’t change it.
- Recommended: your app uses something deprecated that still works today. Move before Shopify removes it.
- Optional: Shopify says no change is needed if the default behavior fits your app. Optional alerts never send an email.
apiVersion: ApiVersion.October25 in shopify.server.ts), or from your own constant if you build the client yourself (such as export const SHOPIFY_API_VERSION = "2025-01"). Shopify serves each version for about a year, until the 16th of its release month the following year, then answers with the oldest version it still supports. From 90 days before that date, you get a required alert with the exact line to change and the latest stable version to move to. It needs no AI, costs nothing, and closes itself once you upgrade.
Two related checks work the same way:
- Admin API
unstablein production. Shopify saysunstablecan change at any time and isn’t meant for production, so an app pinned to it gets a recommended alert to pin the latest stable version. - UI extension API versions. Each checkout, customer account, admin and POS extension pins its own
api_versioninshopify.extension.toml. Old versions keep running, but Shopify CLI refuses to deploy an extension on a version older than 12 months, which blocks every deploy of your app. You get a recommended alert 90 days before that date and a required one once deploys are blocked, listing each extension to move.
Working an alert
For each alert you can:- View the change summary, AI analysis, impact areas, affected APIs, migration deadline, and the exact code references in your app.
- Read the AI fix: a code-aware suggestion, grounded against Shopify’s docs and your repository. It’s advisory: review before applying. Fixes are written automatically when a scan finds a match, and again when the matched code changes, so there’s no regenerate button. While a match is being checked it shows as Being checked, and it moves to Needs action or Ruled out when the check finishes. If a fix fails, Try again appears on that alert. Every GraphQL query and Polaris component in a fix is checked against Shopify’s schema on the Admin API version your app actually calls (read from where you configure the API client, such as
shopify.server.ts), before you see it. If the fix needs a newer version, upgrading is its first step. A fix that fails the check isn’t shown: the alert says so, and you can regenerate it. - Acknowledge the alert once you’ve handled it, recording who and when.
- Run a scan on demand, and set email preferences: a severity threshold, whether to notify on action-required changes, and the recipients.
Your AI coding client can read the same alerts and their fix suggestions through Meridian MCP (
shopify_alerts_list, shopify_alert_get).