build(deps): bump @shopify/hydrogen-react from 2026.1.2 to 2026.4.4 in /skills/shopify-hydrogen #6

Closed
xixu-me wants to merge 0 commits from dependabot/npm_and_yarn/skills/shopify-hydrogen/shopify/hydrogen-react-2026.4.4 into main
pull from: dependabot/npm_and_yarn/skills/shopify-hydrogen/shopify/hydrogen-react-2026.4.4
Owner

Bumps @shopify/hydrogen-react from 2026.1.2 to 2026.4.4.

Release notes

Sourced from @​shopify/hydrogen-react's releases.

@​shopify/hydrogen-react@​2026.4.4

Patch Changes

  • Shopify's consent API now returns visitor tracking values in the consentManagement response. Hydrogen now enables asynchronous consent initialization so the Customer Privacy API fetches and caches these values before analytics starts. This replaces Hydrogen's separate consent query and cache writes, as well as Server-Timing headers, which are no longer collected or forwarded for tracking. The deprecated JavaScript-visible _shopify_y and _shopify_s cookies are no longer created. Hydrogen leaves migration and expiration of legacy analytics and consent cookies to the Customer Privacy API. Upgrade to keep visitor analytics and session continuity working as Shopify retires the deprecated cookies. (#4085) by @​frandiox

    Initial consent readiness also releases analytics for returning visitors when the privacy banner is enabled. Later consent changes refresh tracking permissions, and the Customer Privacy API can renew expired session tokens.

    Consent and analytics now require the same-origin Storefront API proxy that Hydrogen's createRequestHandler (from @shopify/hydrogen or @shopify/hydrogen/oxygen) includes, and consent requests always use it, notice. The consent.sameDomainForStorefrontApi option is deprecated and ignored, as if it were true; setting it to false logs a warning. If your server.ts still uses the deprecated createRequestHandler from @shopify/remix-oxygen, or a custom server without the proxy, switch to Hydrogen's createRequestHandler: without the proxy, consent can't load, so analytics stay off and the privacy banner doesn't show.

    useCustomerPrivacy's onReady callback now waits for consent as well as the selected APIs. If initial consent fails to load, analytics and PerfKit stay blocked until a successful consent update. Custom consent interfaces should use the returned customerPrivacy API when available to allow recovery, rather than relying only on onReady to display their controls.

    Analytics.Provider's cookieDomain prop and useShopifyCookies's hasUserConsent, domain, and ignoreDeprecatedCookies options are now deprecated no-ops. The Customer Privacy API manages Shopify cookies and expires deprecated ones. Standalone hydrogen-react integrations that passed hasUserConsent: false to clear cookies should remove the option; cookie lifecycle is handled automatically.

    For standalone hydrogen-react apps, <ShopifyProvider> still sends cart requests to your store domain when sameDomainForStorefrontApi is off or can't be detected, so the cart keeps working. Visitor analytics and session attribution require a same-origin Storefront API proxy: proxy /api/{version}/graphql.json on your storefront domain to your store and set sameDomainForStorefrontApi: true. Client-side analytics also require the Customer Privacy API to be loaded and initialized on the page so getTrackingValues() can obtain current tracking values. Configuring the proxy alone does not initialize the Customer Privacy API. See the tracking-cookie deprecation notice.

@​shopify/hydrogen-react@​2026.4.3

Patch Changes

  • Fix Image component generating 1x/2x/3x density descriptors instead of w descriptors for fluid (responsive) images whose source dimensions cap the srcset to exactly 3 entries. (#3756) by @​z0n

    What was happening: When a product image stored in Shopify was small enough that the default srcset ladder (200px, 400px, 600px, 800px, …) was filtered down to exactly 3 entries by the source-dimension cap, the Image component incorrectly switched to density descriptors (1x/2x/3x) and silently ignored the sizes attribute. On a DPR-1 screen this caused the smallest srcset entry (200px) to be used regardless of the rendered image size, resulting in blurry images.

    The fix: Descriptor type (density vs width) is now determined by whether the image is in fixed or fluid mode — not by how many srcset entries happen to survive source-dimension filtering.

@​shopify/hydrogen-react@​2026.4.2

Minor Changes

  • Add support for Vite 7 and Vite 8. Hydrogen remains backwards-compatible with Vite 5+. (#3617) by @​frandiox

    Mini Oxygen's dev server has been refactored to use the Vite Environment API, which is the standard way to run non-browser runtimes in Vite. This replaces the previous custom middleware approach with a first-class FetchableDevEnvironment, improving compatibility with Vite's built-in HMR and module invalidation.

    New Hydrogen projects created with npm create @shopify/hydrogen will default to Vite 8. The vite-tsconfig-paths plugin is no longer needed in the skeleton template since Vite 8 supports resolve.tsconfigPaths natively.

Patch Changes

  • Fixed the CartProvider example code (both TS and JS) to include the missing return statement in the App component. (#3685) by @​J8118

  • Fixed the ProductProvider example code (both TS and JS): restored the missing return in the .map() callback so option buttons render, and removed a stray semicolon that rendered as visible text. (#3680) by @​J8118

@​shopify/hydrogen-react@​2026.4.1

Patch Changes

  • Fix cart operations failing on stores without VisitorConsent type (#3720) by @​itsjustriley

    Cart operations (like cart.setMetafields()) were unconditionally including the visitorConsent parameter in GraphQL operations, even when not being used. This caused failures on stores whose Storefront API schema doesn't include the VisitorConsent type (older API versions or certain store configurations).

    The visitorConsent parameter is now only included in cart GraphQL operations when explicitly provided. This restores compatibility with stores that don't support the VisitorConsent type while preserving the feature for users who need it.

@​shopify/hydrogen-react@​2026.4.0

Major Changes

... (truncated)

Changelog

Sourced from @​shopify/hydrogen-react's changelog.

2026.4.4

Patch Changes

  • Shopify's consent API now returns visitor tracking values in the consentManagement response. Hydrogen now enables asynchronous consent initialization so the Customer Privacy API fetches and caches these values before analytics starts. This replaces Hydrogen's separate consent query and cache writes, as well as Server-Timing headers, which are no longer collected or forwarded for tracking. The deprecated JavaScript-visible _shopify_y and _shopify_s cookies are no longer created. Hydrogen leaves migration and expiration of legacy analytics and consent cookies to the Customer Privacy API. Upgrade to keep visitor analytics and session continuity working as Shopify retires the deprecated cookies. (#4085) by @​frandiox

    Initial consent readiness also releases analytics for returning visitors when the privacy banner is enabled. Later consent changes refresh tracking permissions, and the Customer Privacy API can renew expired session tokens.

    Consent and analytics now require the same-origin Storefront API proxy that Hydrogen's createRequestHandler (from @shopify/hydrogen or @shopify/hydrogen/oxygen) includes, and consent requests always use it, notice. The consent.sameDomainForStorefrontApi option is deprecated and ignored, as if it were true; setting it to false logs a warning. If your server.ts still uses the deprecated createRequestHandler from @shopify/remix-oxygen, or a custom server without the proxy, switch to Hydrogen's createRequestHandler: without the proxy, consent can't load, so analytics stay off and the privacy banner doesn't show.

    useCustomerPrivacy's onReady callback now waits for consent as well as the selected APIs. If initial consent fails to load, analytics and PerfKit stay blocked until a successful consent update. Custom consent interfaces should use the returned customerPrivacy API when available to allow recovery, rather than relying only on onReady to display their controls.

    Analytics.Provider's cookieDomain prop and useShopifyCookies's hasUserConsent, domain, and ignoreDeprecatedCookies options are now deprecated no-ops. The Customer Privacy API manages Shopify cookies and expires deprecated ones. Standalone hydrogen-react integrations that passed hasUserConsent: false to clear cookies should remove the option; cookie lifecycle is handled automatically.

    For standalone hydrogen-react apps, <ShopifyProvider> still sends cart requests to your store domain when sameDomainForStorefrontApi is off or can't be detected, so the cart keeps working. Visitor analytics and session attribution require a same-origin Storefront API proxy: proxy /api/{version}/graphql.json on your storefront domain to your store and set sameDomainForStorefrontApi: true. Client-side analytics also require the Customer Privacy API to be loaded and initialized on the page so getTrackingValues() can obtain current tracking values. Configuring the proxy alone does not initialize the Customer Privacy API. See the tracking-cookie deprecation notice.

2026.4.3

Patch Changes

  • Fix Image component generating 1x/2x/3x density descriptors instead of w descriptors for fluid (responsive) images whose source dimensions cap the srcset to exactly 3 entries. (#3756) by @​z0n

    What was happening: When a product image stored in Shopify was small enough that the default srcset ladder (200px, 400px, 600px, 800px, …) was filtered down to exactly 3 entries by the source-dimension cap, the Image component incorrectly switched to density descriptors (1x/2x/3x) and silently ignored the sizes attribute. On a DPR-1 screen this caused the smallest srcset entry (200px) to be used regardless of the rendered image size, resulting in blurry images.

    The fix: Descriptor type (density vs width) is now determined by whether the image is in fixed or fluid mode — not by how many srcset entries happen to survive source-dimension filtering.

2026.4.2

Minor Changes

  • Add support for Vite 7 and Vite 8. Hydrogen remains backwards-compatible with Vite 5+. (#3617) by @​frandiox

    Mini Oxygen's dev server has been refactored to use the Vite Environment API, which is the standard way to run non-browser runtimes in Vite. This replaces the previous custom middleware approach with a first-class FetchableDevEnvironment, improving compatibility with Vite's built-in HMR and module invalidation.

    New Hydrogen projects created with npm create @shopify/hydrogen will default to Vite 8. The vite-tsconfig-paths plugin is no longer needed in the skeleton template since Vite 8 supports resolve.tsconfigPaths natively.

Patch Changes

  • Fixed the CartProvider example code (both TS and JS) to include the missing return statement in the App component. (#3685) by @​J8118

  • Fixed the ProductProvider example code (both TS and JS): restored the missing return in the .map() callback so option buttons render, and removed a stray semicolon that rendered as visible text. (#3680) by @​J8118

2026.4.1

Patch Changes

  • Fix cart operations failing on stores without VisitorConsent type (#3720) by @​itsjustriley

    Cart operations (like cart.setMetafields()) were unconditionally including the visitorConsent parameter in GraphQL operations, even when not being used. This caused failures on stores whose Storefront API schema doesn't include the VisitorConsent type (older API versions or certain store configurations).

... (truncated)

Commits


GitHub 来源:https://github.com/xixu-me/scps/pull/17
作者:dependabot[bot] · 创建时间:2026-10-08T07:31:27Z
GitHub PR 状态:已合并,合并提交 b13fd7bb5e

Bumps [@shopify/hydrogen-react](https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react) from 2026.1.2 to 2026.4.4. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Shopify/hydrogen/releases">@​shopify/hydrogen-react's releases</a>.</em></p> <blockquote> <h2><code>@​shopify/hydrogen-react</code><a href="https://github.com/2026"><code>@​2026</code></a>.4.4</h2> <h3>Patch Changes</h3> <ul> <li> <p>Shopify's consent API now returns visitor tracking values in the <code>consentManagement</code> response. Hydrogen now enables asynchronous consent initialization so the Customer Privacy API fetches and caches these values before analytics starts. This replaces Hydrogen's separate consent query and cache writes, as well as <code>Server-Timing</code> headers, which are no longer collected or forwarded for tracking. The deprecated JavaScript-visible <code>_shopify_y</code> and <code>_shopify_s</code> cookies are no longer created. Hydrogen leaves migration and expiration of legacy analytics and consent cookies to the Customer Privacy API. Upgrade to keep visitor analytics and session continuity working as Shopify retires the deprecated cookies. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/4085">#4085</a>) by <a href="https://github.com/frandiox"><code>@​frandiox</code></a></p> <p>Initial consent readiness also releases analytics for returning visitors when the privacy banner is enabled. Later consent changes refresh tracking permissions, and the Customer Privacy API can renew expired session tokens.</p> <p>Consent and analytics now require the same-origin Storefront API proxy that Hydrogen's <code>createRequestHandler</code> (from <code>@shopify/hydrogen</code> or <code>@shopify/hydrogen/oxygen</code>) includes, and consent requests always use it, <a href="https://shopify.dev/changelog/posts/tracking-cookie-deprecation-hydrogen">notice</a>. The <code>consent.sameDomainForStorefrontApi</code> option is deprecated and ignored, as if it were <code>true</code>; setting it to <code>false</code> logs a warning. If your <code>server.ts</code> still uses the deprecated <code>createRequestHandler</code> from <code>@shopify/remix-oxygen</code>, or a custom server without the proxy, switch to Hydrogen's <code>createRequestHandler</code>: without the proxy, consent can't load, so analytics stay off and the privacy banner doesn't show.</p> <p><code>useCustomerPrivacy</code>'s <code>onReady</code> callback now waits for consent as well as the selected APIs. If initial consent fails to load, analytics and PerfKit stay blocked until a successful consent update. Custom consent interfaces should use the returned <code>customerPrivacy</code> API when available to allow recovery, rather than relying only on <code>onReady</code> to display their controls.</p> <p><code>Analytics.Provider</code>'s <code>cookieDomain</code> prop and <code>useShopifyCookies</code>'s <code>hasUserConsent</code>, <code>domain</code>, and <code>ignoreDeprecatedCookies</code> options are now deprecated no-ops. The Customer Privacy API manages Shopify cookies and expires deprecated ones. Standalone <code>hydrogen-react</code> integrations that passed <code>hasUserConsent: false</code> to clear cookies should remove the option; cookie lifecycle is handled automatically.</p> <p>For standalone <code>hydrogen-react</code> apps, <code>&lt;ShopifyProvider&gt;</code> still sends cart requests to your store domain when <code>sameDomainForStorefrontApi</code> is off or can't be detected, so the cart keeps working. Visitor analytics and session attribution require a same-origin Storefront API proxy: proxy <code>/api/{version}/graphql.json</code> on your storefront domain to your store and set <code>sameDomainForStorefrontApi: true</code>. Client-side analytics also require the Customer Privacy API to be loaded and initialized on the page so <code>getTrackingValues()</code> can obtain current tracking values. Configuring the proxy alone does not initialize the Customer Privacy API. See the <a href="https://shopify.dev/changelog/posts/tracking-cookie-deprecation-hydrogen">tracking-cookie deprecation notice</a>.</p> </li> </ul> <h2><code>@​shopify/hydrogen-react</code><a href="https://github.com/2026"><code>@​2026</code></a>.4.3</h2> <h3>Patch Changes</h3> <ul> <li> <p>Fix <code>Image</code> component generating <code>1x/2x/3x</code> density descriptors instead of <code>w</code> descriptors for fluid (responsive) images whose source dimensions cap the srcset to exactly 3 entries. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3756">#3756</a>) by <a href="https://github.com/z0n"><code>@​z0n</code></a></p> <p><strong>What was happening:</strong> When a product image stored in Shopify was small enough that the default srcset ladder (200px, 400px, 600px, 800px, …) was filtered down to exactly 3 entries by the source-dimension cap, the <code>Image</code> component incorrectly switched to density descriptors (<code>1x</code>/<code>2x</code>/<code>3x</code>) and silently ignored the <code>sizes</code> attribute. On a DPR-1 screen this caused the smallest srcset entry (200px) to be used regardless of the rendered image size, resulting in blurry images.</p> <p><strong>The fix:</strong> Descriptor type (density vs width) is now determined by whether the image is in fixed or fluid mode — not by how many srcset entries happen to survive source-dimension filtering.</p> </li> </ul> <h2><code>@​shopify/hydrogen-react</code><a href="https://github.com/2026"><code>@​2026</code></a>.4.2</h2> <h3>Minor Changes</h3> <ul> <li> <p>Add support for Vite 7 and Vite 8. Hydrogen remains backwards-compatible with Vite 5+. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3617">#3617</a>) by <a href="https://github.com/frandiox"><code>@​frandiox</code></a></p> <p>Mini Oxygen's dev server has been refactored to use the <a href="https://vite.dev/guide/api-environment">Vite Environment API</a>, which is the standard way to run non-browser runtimes in Vite. This replaces the previous custom middleware approach with a first-class <code>FetchableDevEnvironment</code>, improving compatibility with Vite's built-in HMR and module invalidation.</p> <p>New Hydrogen projects created with <code>npm create @shopify/hydrogen</code> will default to Vite 8. The <code>vite-tsconfig-paths</code> plugin is no longer needed in the skeleton template since Vite 8 supports <code>resolve.tsconfigPaths</code> natively.</p> </li> </ul> <h3>Patch Changes</h3> <ul> <li> <p>Fixed the <code>CartProvider</code> example code (both TS and JS) to include the missing <code>return</code> statement in the <code>App</code> component. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3685">#3685</a>) by <a href="https://github.com/J8118"><code>@​J8118</code></a></p> </li> <li> <p>Fixed the <code>ProductProvider</code> example code (both TS and JS): restored the missing <code>return</code> in the <code>.map()</code> callback so option buttons render, and removed a stray semicolon that rendered as visible text. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3680">#3680</a>) by <a href="https://github.com/J8118"><code>@​J8118</code></a></p> </li> </ul> <h2><code>@​shopify/hydrogen-react</code><a href="https://github.com/2026"><code>@​2026</code></a>.4.1</h2> <h3>Patch Changes</h3> <ul> <li> <p>Fix cart operations failing on stores without <code>VisitorConsent</code> type (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3720">#3720</a>) by <a href="https://github.com/itsjustriley"><code>@​itsjustriley</code></a></p> <p>Cart operations (like <code>cart.setMetafields()</code>) were unconditionally including the <code>visitorConsent</code> parameter in GraphQL operations, even when not being used. This caused failures on stores whose Storefront API schema doesn't include the <code>VisitorConsent</code> type (older API versions or certain store configurations).</p> <p>The <code>visitorConsent</code> parameter is now only included in cart GraphQL operations when explicitly provided. This restores compatibility with stores that don't support the <code>VisitorConsent</code> type while preserving the feature for users who need it.</p> </li> </ul> <h2><code>@​shopify/hydrogen-react</code><a href="https://github.com/2026"><code>@​2026</code></a>.4.0</h2> <h3>Major Changes</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Shopify/hydrogen/blob/main/packages/hydrogen-react/CHANGELOG.md">@​shopify/hydrogen-react's changelog</a>.</em></p> <blockquote> <h2>2026.4.4</h2> <h3>Patch Changes</h3> <ul> <li> <p>Shopify's consent API now returns visitor tracking values in the <code>consentManagement</code> response. Hydrogen now enables asynchronous consent initialization so the Customer Privacy API fetches and caches these values before analytics starts. This replaces Hydrogen's separate consent query and cache writes, as well as <code>Server-Timing</code> headers, which are no longer collected or forwarded for tracking. The deprecated JavaScript-visible <code>_shopify_y</code> and <code>_shopify_s</code> cookies are no longer created. Hydrogen leaves migration and expiration of legacy analytics and consent cookies to the Customer Privacy API. Upgrade to keep visitor analytics and session continuity working as Shopify retires the deprecated cookies. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/4085">#4085</a>) by <a href="https://github.com/frandiox"><code>@​frandiox</code></a></p> <p>Initial consent readiness also releases analytics for returning visitors when the privacy banner is enabled. Later consent changes refresh tracking permissions, and the Customer Privacy API can renew expired session tokens.</p> <p>Consent and analytics now require the same-origin Storefront API proxy that Hydrogen's <code>createRequestHandler</code> (from <code>@shopify/hydrogen</code> or <code>@shopify/hydrogen/oxygen</code>) includes, and consent requests always use it, <a href="https://shopify.dev/changelog/posts/tracking-cookie-deprecation-hydrogen">notice</a>. The <code>consent.sameDomainForStorefrontApi</code> option is deprecated and ignored, as if it were <code>true</code>; setting it to <code>false</code> logs a warning. If your <code>server.ts</code> still uses the deprecated <code>createRequestHandler</code> from <code>@shopify/remix-oxygen</code>, or a custom server without the proxy, switch to Hydrogen's <code>createRequestHandler</code>: without the proxy, consent can't load, so analytics stay off and the privacy banner doesn't show.</p> <p><code>useCustomerPrivacy</code>'s <code>onReady</code> callback now waits for consent as well as the selected APIs. If initial consent fails to load, analytics and PerfKit stay blocked until a successful consent update. Custom consent interfaces should use the returned <code>customerPrivacy</code> API when available to allow recovery, rather than relying only on <code>onReady</code> to display their controls.</p> <p><code>Analytics.Provider</code>'s <code>cookieDomain</code> prop and <code>useShopifyCookies</code>'s <code>hasUserConsent</code>, <code>domain</code>, and <code>ignoreDeprecatedCookies</code> options are now deprecated no-ops. The Customer Privacy API manages Shopify cookies and expires deprecated ones. Standalone <code>hydrogen-react</code> integrations that passed <code>hasUserConsent: false</code> to clear cookies should remove the option; cookie lifecycle is handled automatically.</p> <p>For standalone <code>hydrogen-react</code> apps, <code>&lt;ShopifyProvider&gt;</code> still sends cart requests to your store domain when <code>sameDomainForStorefrontApi</code> is off or can't be detected, so the cart keeps working. Visitor analytics and session attribution require a same-origin Storefront API proxy: proxy <code>/api/{version}/graphql.json</code> on your storefront domain to your store and set <code>sameDomainForStorefrontApi: true</code>. Client-side analytics also require the Customer Privacy API to be loaded and initialized on the page so <code>getTrackingValues()</code> can obtain current tracking values. Configuring the proxy alone does not initialize the Customer Privacy API. See the <a href="https://shopify.dev/changelog/posts/tracking-cookie-deprecation-hydrogen">tracking-cookie deprecation notice</a>.</p> </li> </ul> <h2>2026.4.3</h2> <h3>Patch Changes</h3> <ul> <li> <p>Fix <code>Image</code> component generating <code>1x/2x/3x</code> density descriptors instead of <code>w</code> descriptors for fluid (responsive) images whose source dimensions cap the srcset to exactly 3 entries. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3756">#3756</a>) by <a href="https://github.com/z0n"><code>@​z0n</code></a></p> <p><strong>What was happening:</strong> When a product image stored in Shopify was small enough that the default srcset ladder (200px, 400px, 600px, 800px, …) was filtered down to exactly 3 entries by the source-dimension cap, the <code>Image</code> component incorrectly switched to density descriptors (<code>1x</code>/<code>2x</code>/<code>3x</code>) and silently ignored the <code>sizes</code> attribute. On a DPR-1 screen this caused the smallest srcset entry (200px) to be used regardless of the rendered image size, resulting in blurry images.</p> <p><strong>The fix:</strong> Descriptor type (density vs width) is now determined by whether the image is in fixed or fluid mode — not by how many srcset entries happen to survive source-dimension filtering.</p> </li> </ul> <h2>2026.4.2</h2> <h3>Minor Changes</h3> <ul> <li> <p>Add support for Vite 7 and Vite 8. Hydrogen remains backwards-compatible with Vite 5+. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3617">#3617</a>) by <a href="https://github.com/frandiox"><code>@​frandiox</code></a></p> <p>Mini Oxygen's dev server has been refactored to use the <a href="https://vite.dev/guide/api-environment">Vite Environment API</a>, which is the standard way to run non-browser runtimes in Vite. This replaces the previous custom middleware approach with a first-class <code>FetchableDevEnvironment</code>, improving compatibility with Vite's built-in HMR and module invalidation.</p> <p>New Hydrogen projects created with <code>npm create @shopify/hydrogen</code> will default to Vite 8. The <code>vite-tsconfig-paths</code> plugin is no longer needed in the skeleton template since Vite 8 supports <code>resolve.tsconfigPaths</code> natively.</p> </li> </ul> <h3>Patch Changes</h3> <ul> <li> <p>Fixed the <code>CartProvider</code> example code (both TS and JS) to include the missing <code>return</code> statement in the <code>App</code> component. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3685">#3685</a>) by <a href="https://github.com/J8118"><code>@​J8118</code></a></p> </li> <li> <p>Fixed the <code>ProductProvider</code> example code (both TS and JS): restored the missing <code>return</code> in the <code>.map()</code> callback so option buttons render, and removed a stray semicolon that rendered as visible text. (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3680">#3680</a>) by <a href="https://github.com/J8118"><code>@​J8118</code></a></p> </li> </ul> <h2>2026.4.1</h2> <h3>Patch Changes</h3> <ul> <li> <p>Fix cart operations failing on stores without <code>VisitorConsent</code> type (<a href="https://redirect.github.com/Shopify/hydrogen/pull/3720">#3720</a>) by <a href="https://github.com/itsjustriley"><code>@​itsjustriley</code></a></p> <p>Cart operations (like <code>cart.setMetafields()</code>) were unconditionally including the <code>visitorConsent</code> parameter in GraphQL operations, even when not being used. This caused failures on stores whose Storefront API schema doesn't include the <code>VisitorConsent</code> type (older API versions or certain store configurations).</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Shopify/hydrogen/commit/0d0f2662df8e9245d23fc24f5fb7168caeb27c1c"><code>0d0f266</code></a> [ci] release 2026.4.6 (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/4072">#4072</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/76cdc6c538dc680a3f1ce96a6d704d463afde0ce"><code>76cdc6c</code></a> Use CTA async consent for classic Hydrogen (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/4085">#4085</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/253bb275c48835a2307b13b4c64e42ff1ac22e4a"><code>253bb27</code></a> [ci] release 2026.4.3 (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/3760">#3760</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/a810db483c108ac8bbeaac45595b130ed95a2ec7"><code>a810db4</code></a> fix: correct Image component descriptor handling for fluid images (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/3756">#3756</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/97b7248cbf4e2016a49fa8a094c37316231a722b"><code>97b7248</code></a> docs: cleanup old docs information (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/3758">#3758</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/6fed75f8034933ee1d1a38f66ee32d186a37b074"><code>6fed75f</code></a> [ci] release 2026.4.2 (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/3732">#3732</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/51f1e77fe63be5e5ded4ef0c91942bc304f1abc4"><code>51f1e77</code></a> feat: use vite environment API (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/3617">#3617</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/32ce6adfe60458e2aadeb902b34263f25d86d638"><code>32ce6ad</code></a> update gen docs to 1.1.4 and rebuild docs (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/3737">#3737</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/dc49699c799997d5893bc06e444f888e86a3bc29"><code>dc49699</code></a> fix: missing return statement in CartProvider example code (<a href="https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react/issues/3685">#3685</a>)</li> <li><a href="https://github.com/Shopify/hydrogen/commit/50df825c57159757529f5f9f62c258d4de2a4b97"><code>50df825</code></a> fix: missing return in map callback and stray semicolon in ProductProvider (#...</li> <li>Additional commits viewable in <a href="https://github.com/Shopify/hydrogen/commits/@shopify/hydrogen-react@2026.4.4/packages/hydrogen-react">compare view</a></li> </ul> </details> <br /> --- GitHub 来源:https://github.com/xixu-me/scps/pull/17 作者:dependabot[bot] · 创建时间:2026-10-08T07:31:27Z GitHub PR 状态:已合并,合并提交 b13fd7bb5eb1ebdf759df2f676bc1e2b5538b446 <!-- github-archive:4783436489 -->
xixu-me added the dependenciesjavascript labels 2026-10-08 07:50:45 +00:00
Author
Owner

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​shopify/​hydrogen-react@​2026.4.4991009797100

View full report


GitHub 来源:https://github.com/xixu-me/scps/pull/17#issuecomment-6054969344
作者:socket-security[bot] · 创建时间:2026-10-08T07:32:03Z

**Review the following changes in direct dependencies.** Learn more about [Socket for GitHub](https://socket.dev?utm_medium=gh). <table> <thead> <tr> <th>Diff</th> <th width="200px">Package</th> <th align="center" width="100px">Supply Chain<br/>Security</th> <th align="center" width="100px">Vulnerability</th> <th align="center" width="100px">Quality</th> <th align="center" width="100px">Maintenance</th> <th align="center" width="100px">License</th> </tr> </thead> <tbody> <tr><td align="center"><a href="https://socket.dev/dashboard/org/default-4lfzp/diff-scan/891e148d-de8a-4e21-a684-2e62f6c7ae7b?tab=dependencies&dependency_item_key=101954440339"><img src="https://github-app-statics.socket.dev/diff-added.svg" title="Added" alt="Added" width="20" height="20"></a></td><td><a href="https://socket.dev/dashboard/org/default-4lfzp/diff-scan/891e148d-de8a-4e21-a684-2e62f6c7ae7b?tab=dependencies&dependency_item_key=101954440339">npm/​@​shopify/​hydrogen-react@​2026.4.4</a></td><td align="center"><a href="https://socket.dev/dashboard/org/default-4lfzp/diff-scan/891e148d-de8a-4e21-a684-2e62f6c7ae7b?tab=dependencies&dependency_item_key=101954440339"><img src="https://github-app-statics.socket.dev/score-99.svg" title="Supply Chain Security" width="40" height="40" alt="99"></a></td><td align="center"><a href="https://socket.dev/dashboard/org/default-4lfzp/diff-scan/891e148d-de8a-4e21-a684-2e62f6c7ae7b?tab=dependencies&dependency_item_key=101954440339"><img src="https://github-app-statics.socket.dev/score-100.svg" title="Vulnerability" width="40" height="40" alt="100"></a></td><td align="center"><a href="https://socket.dev/dashboard/org/default-4lfzp/diff-scan/891e148d-de8a-4e21-a684-2e62f6c7ae7b?tab=dependencies&dependency_item_key=101954440339"><img src="https://github-app-statics.socket.dev/score-97.svg" title="Quality" width="40" height="40" alt="97"></a></td><td align="center"><a href="https://socket.dev/dashboard/org/default-4lfzp/diff-scan/891e148d-de8a-4e21-a684-2e62f6c7ae7b?tab=dependencies&dependency_item_key=101954440339"><img src="https://github-app-statics.socket.dev/score-97.svg" title="Maintenance" width="40" height="40" alt="97"></a></td><td align="center"><a href="https://socket.dev/dashboard/org/default-4lfzp/diff-scan/891e148d-de8a-4e21-a684-2e62f6c7ae7b?tab=dependencies&dependency_item_key=101954440339"><img src="https://github-app-statics.socket.dev/score-100.svg" title="License" width="40" height="40" alt="100"></a></td></tr> </tbody> </table> [View full report](https://socket.dev/dashboard/org/default-4lfzp/diff-scan/891e148d-de8a-4e21-a684-2e62f6c7ae7b?tab=dependencies) <!-- overview-comment --> --- GitHub 来源:https://github.com/xixu-me/scps/pull/17#issuecomment-6054969344 作者:socket-security[bot] · 创建时间:2026-10-08T07:32:03Z <!-- github-archive:6054969344 -->
xixu-me added 1 commit 2026-10-08 07:50:51 +00:00
Bumps [@shopify/hydrogen-react](https://github.com/Shopify/hydrogen/tree/HEAD/packages/hydrogen-react) from 2026.1.2 to 2026.4.4.
- [Release notes](https://github.com/Shopify/hydrogen/releases)
- [Changelog](https://github.com/Shopify/hydrogen/blob/main/packages/hydrogen-react/CHANGELOG.md)
- [Commits](https://github.com/Shopify/hydrogen/commits/@shopify/hydrogen-react@2026.4.4/packages/hydrogen-react)

---
updated-dependencies:
- dependency-name: "@shopify/hydrogen-react"
  dependency-version: 2026.4.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
xixu-me force-pushed dependabot/npm_and_yarn/skills/shopify-hydrogen/shopify/hydrogen-react-2026.4.4 from b66e144a3c to 250a4aa320 2026-10-08 07:50:51 +00:00 Compare
xixu-me closed this pull request 2026-10-08 07:56:12 +00:00
xixu-me deleted branch dependabot/npm_and_yarn/skills/shopify-hydrogen/shopify/hydrogen-react-2026.4.4 2026-10-08 07:56:12 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.