Skip to main content

Changelog

What's new in commercebuild. Stay up to date with our latest features, performance improvements, and ecosystem updates.

Show dates for
Mon 21 Sep 2026
v5.148

✨Key Enhancements

πŸ‘€
Admin-created account welcome email with password activation link

Store administrators can now create user accounts that automatically trigger a branded welcome email to the new user, including a secure activation link to set their password (valid for 7 days). The email follows the same notification pipeline as password reset emails, ensuring consistent delivery and branding.

Read documentation β†’
πŸ’³
Admin email alerts for failed payment captures

Store administrators now receive an automated email notification when a payment capture fails at the gateway, enabling timely follow-up on problematic orders before fulfillment. The alert includes diagnostic details such as invoice number, amount, gateway error message, and retry attempts.

Read documentation β†’
πŸ“Š
Users import/export on the generic spreadsheet framework

Store users can now be exported with filters and column selection, and imported via spreadsheet with immediate validation and detailed per-row reporting, replacing the legacy PHP import. This is the first entity on the new generic import/export flow (PDECOM-6130), with email as the match key; imports create new users or update existing ones while protecting site administrators from bulk changes.

Read documentation β†’
πŸ—‚οΈ
Item attribute values import and export

Users can now export and import item attribute values in bulk via CSV or Excel, using the shared import/export flow with instant validation, per-row error reporting, and activity logging. The column schema is dynamically generated based on the store's configured attributes, and imports are limited to store-managed attributes only.

Read documentation β†’
πŸ—‚οΈ
Rich content custom field with TipTap editor and JSON storage

Product custom fields now support a new "richContent" type that provides a TipTap editor in the V5 admin, stores content as ProseMirror JSON, and renders styled HTML on the storefront. The editor supports headings (levels 2-6), bold, italic, lists, and links, with paste operations preserving structure while removing inline styles.

🏷️
URL custom field type for products

Products now support a new URL custom field type that stores absolute http(s) links to external resources such as spec sheets, videos, or documents. The platform validates URL format and length on save, and exposes the type to themes via the API for custom rendering.

Read documentation β†’
πŸ—‚οΈ
Rich content custom fields: JSON schema endpoint and validation

Product custom fields now support a richContent type that stores versioned ProseMirror documents as JSON. A new schema endpoint (`GET /admin/product-custom-fields/rich-content/schema`) serves the JSON Schema contract, and all writes are validated against it to reject documents with unsupported nodes, marks, or attributes before storage.

Read documentation β†’
πŸ—‚οΈ
Asset usage tracking shows where images and files are referenced

The Asset Manager now displays everywhere an asset is used across products, categories, CMS pages, and theme settings, preventing accidental deletion of referenced files. Admins can view usage details before modifying or deleting any asset, and can identify unused files for cleanup.

🏷️
Item attributes can now generate storefront category filters

Merchants can flag an item attribute (product custom field) to automatically generate category-page filters from its values, eliminating the need to maintain separate filter definitions and mappings. The catalog indexer reads flagged attributes and builds Elasticsearch filters that stay synchronized with ERP data changes.

Read documentation β†’
πŸ”—
Marketing platform integrations screen (Klaviyo, Mailchimp, HubSpot)

Store admins can now connect, update, and remove marketing platforms (Klaviyo, Mailchimp, HubSpot) directly from the V5 admin under Notification β†’ Integrations, with masked credentials, live customer sync progress, and last sync time. Previously these connections could only be set up by calling the notification API directly.

Read documentation β†’
πŸ””
Event workflows admin screen (V5)

A new V5 admin screen at /settings/event-workflows lets store admins create and manage notification rules that trigger integrations (Klaviyo, HubSpot, Mailchimp, Mailgun) when store events fire, replacing legacy admin screens with a visual flow builder backed by the existing notification-service API.

Read documentation β†’
🏷️
Product attributes can now select images via tagged assets

Brand logos, certification badges, and other attribute-driven images can now appear on product pages without custom code. An admin sets a custom field value on items, uploads one image per value and tags it, then adds an Assets Display block that matches the attributeβ€”the correct image appears on every product automatically.

Read documentation β†’
πŸ—‚οΈ
Image usage lookup API for Asset Manager "Used In" panel

Added GET /admin/products/image-usage and GET /admin/categories/image-usage endpoints that answer "which catalog rows reference this image file?" by querying the store database directly, replacing the client-side approach that required hundreds of detail API calls per check. The new endpoints cover product main and support images, variant images, swatches, custom fields, category images, and background images from legacy tables.

Read documentation β†’
✏️
Adobe Fonts support in CMS theme editor

Merchants can now add Adobe Fonts to their storefronts by entering their Adobe Fonts web project Kit ID in the theme editor. All font pickers across the CMSβ€”including typography settings, rich text toolbar, product cards, element designer, and carousel layersβ€”now display Adobe families in a grouped, searchable list alongside system and Google fonts, with the merchant's own Adobe license applying to the storefront.

Read documentation β†’
πŸͺ
App Store authoring API for advert management and catalog views

Adds a staff-facing authoring API in store-manager for managing app adverts (create, update, publish, link/unlink to catalog apps) with visibility controls, image/video uploads to GCS, and catalog views showing all apps and their advertised status. Includes an installed-sites endpoint with searchable, paginated results joining across the appstore and store-manager databases.

πŸ—‚οΈ
StoreManager Manage Apps navigation and catalog curation tabs

Staff can now access the Manage Apps area via the left navigation to curate the app catalog across two tabs: Manage App Adverts (with search, status badges, install counts, and edit/delete actions) and All Apps (showing author, type, and advert filter options). The UI surfaces audit metadata including last-updated-by attribution for adverts.

πŸ—‚οΈ
App Store Manager advert editing and installed-sites tracking

Store managers can now edit full app adverts (name, description, pricing, ERP targeting, visibility, and linked modules) with live preview, placement rules derived from the app's source, and a drill-down modal showing which stores have installed each app. Unlisted adverts remain installable via shared UUID, and system-published installs are tracked separately from user installs.

πŸ—‚οΈ
App Store catalog sync infrastructure with region-aware tombstoning

Introduces the catalog sync plane that ingests app metadata from multiple sources (payments, shipping, PIM, notifications, settings) across regions, with region-aware tombstoning that only hides apps when they're absent from all active regions' latest reports. Includes staleness monitoring, sync audit trails, and staff-facing "Sync now" triggers to diagnose and repair catalog freshness issues.

πŸ“¦
App Store installation command pipeline and event projection

Introduces the message-driven installation plane core in settings, including command publishing endpoints for install/uninstall operations, event projection with state machine tracking (PENDING_INSTALL through UNINSTALLED), reconciliation against installation reports, and dead-letter protection for all install-plane subscriptions. The ledger keyed on (appUuid, storeId) provides the authoritative installation state that fans out to store-manager and supports installer execution.

πŸͺ
App Store consumer API with read and install authorities

Introduces store-admin-facing read endpoints at `/appstore/**` for listing published adverts (with filtering, optional pagination, and per-store install state), retrieving individual advert details (including unlisted adverts via share-by-uuid), and querying installation status. Two new authorities, `APP_STORE_READ` and `APP_STORE_INSTALL`, are provisioned for store admin user groups with per-store rate limiting on command operations.

Read documentation β†’
πŸ“¦
App Store shipping integrations with safe concurrent carrier operations

Shipping carriers can now be installed and uninstalled through the App Store with row-scoped operations that prevent app changes from overwriting concurrent admin edits. ERP mappings for carriers and payment methods are now soft-deleted on uninstall and automatically restored on reinstall, preserving merchant configuration across app lifecycle operations.

Read documentation β†’
πŸ””
App Store integration for marketing notifications (Klaviyo)

Marketing notification integrations can now be installed from the App Store, with Klaviyo as the first validated provider. The installation creates a pending-config integration row that awaits admin configuration before activating gateway connections.

Read documentation β†’
πŸ—‚οΈ
Plytix PIM integration support in App Store

Added Plytix as a fifth integration source in the App Store catalog, enabling automated installation and reporting of PIM (Product Information Management) integrations through the product service. The implementation includes catalog reporting, installation state tracking via gateway integrations, and install/uninstall command handling with idempotent redelivery protection.

Read documentation β†’
πŸ—‚οΈ
Module installer and reporter for phase-1 add-on features

Introduces module installation infrastructure for Marketing, Promotions, PIMM, and Product Configurator add-ons, including manifest definition, catalog/installation reporters that fan out across store databases, and an installer that manages gate flags through the settings service. The implementation includes an in-flight guard with configurable wait time, throttled scanning, and proper rejection handling for stores where migrations are behind or the store is not provisioned in the region.

πŸͺ
App Store consumer API integration with platform SDK and cb-store

The App Store settings page in cb-store now consumes the new regional consumer API for listing adverts and managing installations, with SDK methods for app discovery, install/uninstall commands, and polling. Feature-flagged for safe rollback, phase 1 covers curated app listings and installed apps while extension authoring remains on the legacy CloudFlare surface.

πŸ”‘
Role-aware Firestore access for extensions via OIDC identity bridge

Extensions can now access Firestore with role-aware security rules that enforce store, user role, customer group, and B2B/B2C scope boundaries without code changes. The platform federates signed-in session identity to Firebase through OIDC, exposing claims like cb_store_id, cb_user_role, cb_user_scope, and cb_user_group_id in Firestore Security Rules for fine-grained data access control.

πŸ”
Search Results Page Designer

Merchants can now design a dedicated search results page in the CMS editor alongside the Category Page Designer. The new `/search` route displays products matching a shopper's query using a customizable layout built from search-specific content blocks (Search Header, Search Toolbar, and Search Listing).

Read documentation β†’
πŸ”‘
Default strong password policy for new stores

New stores now enforce an 8-character minimum password policy requiring at least one uppercase letter, one number, and one special character for all user groups. Registration and password reset forms expose the applicable policy via new API endpoints so storefronts can display requirements before users submit credentials.

Read documentation β†’
πŸ“±
App Store adverts now support screenshot galleries and preview videos

Adverts can now include multiple screenshots and a preview video (MP4 or WebM) in addition to the icon image, displayed in an app-store-style detail view. The authoring form supports uploading image assets up to 5 MB and video assets up to 50 MB, with content validation to ensure uploaded files match their declared media types.


🧩Customer-Focused Improvements

πŸ—„οΈ
Store Manager backup retention and cleanup policy

Implemented automated deletion of store backups older than 6 months (18 months for pinned backups) to manage storage costs, with support for manual deletion, pinning important backups with notes, and full audit logging of all deletion activity.

πŸ’³
Enhanced DLL decline messages with dealer code and status details

DLL Commercial Finance decline messages now include the dealer code, approval status code, and approval comment from the provider's response, enabling webstore users to efficiently resolve issues when contacting DLL support.

Read documentation β†’
🏷️
Google Merchant Center image size validation warnings

The product image upload interface now warns merchants when images are below Google Merchant Center's 500Γ—500px minimum requirement (effective January 31, 2027). Undersized images are still allowed but trigger a toast notification so merchants can replace them before feed disapproval.

πŸ’³
Payment lifecycle drawer now shows failure timestamps

The payment management drawer now displays when a capture or ERP write-back last failed, not just that it failed, enabling admins to prioritise queue work by recency. Failure timestamps clear automatically once the corresponding step succeeds, so resolved payments never show stale failure times.

Read documentation β†’
πŸ”‘
Enhanced session security with absolute timeout and ID rotation

Sessions now enforce a hard maximum lifetime (default 12 hours) regardless of activity, periodically rotate session IDs during use, and regenerate IDs on login/logout to prevent session fixation and limit the window of a stolen token. The client ID cookie is now marked Secure and SameSite=Lax in production to prevent transmission over plaintext connections.

Read documentation β†’
🏷️
Product page enhancements and CMS picker improvements

Enhanced product page display with breadcrumbs that follow menu structure, stacked thumbnail layout with show-more controls, auto-height accordions, and removed auto-scroll behavior. CMS product pickers now find variant products in search mode, and category navigation clears facet filters to prevent empty results.

Read documentation β†’

πŸ”§Top Resolved Issues

Mon 7 Sep 2026
v5.147

✨Key Enhancements

πŸ’³
Payment lifecycle timeline with per-leg timestamps and ERP metadata

The V5 Admin payment management screen now exposes timestamped history for each payment leg (authorization, capture, ERP write-back) including retry attempts and real gateway expiry times, replacing client-side derivation with platform-sourced data. This enables admins to diagnose reconciliation issues by seeing exactly when charges succeeded and when ERP sync attempts failed, without correlating against API Gateway logs.

πŸ—‚οΈ
Category assignment bulk import and export

Merchandisers can now export product-to-category assignments and import them in bulk via spreadsheet, enabling efficient management of hundreds of items at once including ordering and primary category designation. The import framework now supports composite match keys (Category ID + Item Code pairs) and reports all rows involved in duplicate key conflicts rather than silently accepting the first occurrence.

Read documentation β†’
🏷️
Item attribute values import/export in V5 admin

Store administrators can now export item attribute values to CSV or Excel for bulk editing and re-import them using the unified import/export framework with validation, per-row reporting, and activity tracking. This extends the generic import/export capability to handle dynamic column sets based on each store's custom attribute definitions.

πŸ“Š
Promotion performance report now displays real analytics data

The promotion performance report now displays actual redemption data, discount values, order revenue, and per-promotion usage statistics instead of sample figures. The report includes a drill-down view showing individual orders where each promotion was applied, with filtering by date range and customer group.

Read documentation β†’
πŸ—‚οΈ
Documents block β€” tag-driven asset lists in the CMS

Store admins can now configure a CMS block that displays assets filtered by product, region, category, or document type without writing custom JavaScript. The block supports multiple match sets with AND/OR logic, enabling use cases like per-region compliance documents and category-scoped resource libraries.

Read documentation β†’
πŸ’³
ACH saved payment methods with optional account naming

Customers can now save their ACH bank account details in the Spreedly vault for future purchases, with the option to assign a custom name to distinguish between multiple accounts at the same bank.

Read documentation β†’
🏷️
Guided tag picker with domain groups and catalogue bindings

The asset tag editor now offers a guided picker that searches products, categories, customers, warehouses, locations, and countries by name and writes the correct tag automatically, replacing free-text entry. System tags written by the platform are now visibly separated from author-controlled tags, and all domain prefixes align with the Documents block's lookup vocabulary.

Read documentation β†’
🏷️
Bulk tag editing for assets with guided tag picker

Admins can now select multiple assets and add or remove tags in one action, using a guided picker that offers existing tags, products, warehouses, and regions to prevent typos and streamline compliance workflows. The feature includes collision handling, partial-failure retry, and protects system tags from accidental modification.

Read documentation β†’
πŸ”§
Admin screens in app extensions

App developers can now build custom admin interfaces within their app extensions by adding an `src/admin/` folder that compiles to a separate bundle and renders at `/v5-admin/{locale}/extension/{appId}/page/{PageName}`. The admin area includes authentication layers, live preview during development, and isolated build pipelines to prevent cross-contamination between storefront and admin code.

πŸ—οΈ
App Store foundation: project structure and database schema

Created the new app-store library project with dedicated database schemas for both authoring (store-manager) and consumer (settings) halves, establishing the foundation for Phase 1 app domain functionality. The library modules are embedded in their respective host services via one-way dependencies and remain disabled by default until configured per region.

🏷️
CMS Page Banner section and Page Banners manager

Store administrators can now create single banners and carousels in the V5 CMS editor, target them to categories using rules (including schedules and defaults), or pin dedicated banners to specific category templates. The manager includes optimistic concurrency control to prevent concurrent edits from overwriting each other.

Read documentation β†’
πŸ—‚οΈ
CMS Product Page ID assignment in admin

Administrators can now assign a specific CMS page layout to individual products via a searchable dropdown in the product admin screen; the selected page ID is stored and automatically applied when rendering that product on the storefront. This completes the CMS page override feature (UN-2975) by adding the authoring UI and save workflow, gated to V5 stores.

Read documentation β†’

🧩Customer-Focused Improvements

πŸ—‚οΈ
Product modification timestamp for efficient catalog sync

Admin product list and detail endpoints now return a `modifiedAt` timestamp that reflects when the product record, detail record, or any custom field value last changed. External integrators can store the newest timestamp seen and re-fetch only products that changed since their last sync, eliminating the need to poll all product details on every run.

Read documentation β†’
πŸ”—
Firebase named database support for data connections

Firebase data connections now support an optional `databaseId` field to target named Firestore databases within a project, instead of only the default database. The field appears in the Configure-data form, editor dialogs, and all code templates, with updated documentation and examples across the extension starter and AI agent prompts.

🏷️
Product page UX enhancements and CMS accordion improvements

Enhanced the product page with breadcrumb navigation that follows menu structure, optional stacked thumbnail layout with show-more controls, removal of disruptive autoscroll behavior, and accordion blocks that now auto-size and remain stable when expanding. Also fixed variant product visibility in CMS banner pickers and improved filter persistence when navigating between categories.

Read documentation β†’

πŸ”§Top Resolved Issues

Mon 24 Aug 2026
v5.146

✨Key Enhancements

πŸ›’
V2 promotions can now be edited after creation

Admins can now edit live promotions (fixing typos, extending dates, adjusting discount values) without deleting and recreating them. The platform preserves historical redemption accuracy and cart stability by snapshotting promotion criteria at the moment of application, so edits never rewrite past discounts or silently change active customer sessions.

Read documentation β†’
🚚
Shipping V2 now supports pre-tax order totals in Drools rules

Shipping rules can now reference the order subtotal and tax amounts separately via `$order.subTotal` and `$order.tax` variables, in addition to the existing `$order.totalAmount`. This enables more flexible shipping calculations based on pre-tax order values.

Read documentation β†’
πŸ’³
Authorize.Net payment gateway integration

Added support for Authorize.Net as a payment gateway, enabling merchants to accept credit card and ACH bank debit payments through Accept.js tokenization with full support for authorization, capture, partial capture, and void operations.

Read documentation β†’
πŸ—‚οΈ
Item dimensions import/export with new generic flow

Adds bulk import and export for item dimensions (weight, length, width, height) in V5 admin, replacing the legacy PHP process with a reusable Java implementation that supports filtering, column selection, and detailed validation. This is the first entity migrated to the new generic import/export architecture that will be shared across all remaining sheet services.

🏷️
Item attribute values import/export (V5 admin)

Store-managed item attribute values can now be exported to and imported from spreadsheets using the shared import/export flow, with per-row validation, activity tracking, and ownership gating. This extends the generic framework to handle dynamic column sets based on each store's configured attributes.

Read documentation β†’
πŸ›’
Abandoned cart report for store administrators

Store administrators can now view a report of carts that shoppers filled but did not convert to orders, filtered by idle time threshold (default 24 hours). The report includes cart details and last activity date to enable follow-up on potential lost sales.

Read documentation β†’
πŸ“Š
Promotion performance report (demo with sample data)

A new promotion performance report in Store Admin shows which promotions are being used, what they cost, and whether to keep them running. This release ships the report screen with placeholder data to enable demonstration and design approval while the backend aggregation endpoint is developed.

Read documentation β†’
🎠
Carousel block for CMS editor with unified media and animation

Adds a hero carousel block to the CMS editor with configurable slides, each supporting layered content (headings, text, buttons, badges) over image, video, or color backgrounds. Includes new unified media controls for focal-point framing and opacity, plus structured animation presets with triggers and travel origins that apply to carousel layers, blocks, and sections.

Read documentation β†’
🎨
Button Designer enhancements and storefront-wide application

Merchants can now control button fill colors, hover states with customizable fade transitions, and per-variant typography (weight, size, letter spacing, uppercase) directly in the Button Designer panel. The default button scheme now applies to all customer-facing CTAs across the storefront, including product pages, cart, checkout, and account actions, unless a section or block explicitly selects its own scheme.

Read documentation β†’
πŸ”₯
Firebase/Firestore direct access from custom apps

Custom apps can now import and use Firebase/Firestore directly from the browser, enabling real-time data features without routing through the platform backend. A new package registry makes adding future libraries (state management, additional Firebase products) a single-entry change, and a "Firestore data demo" starter template demonstrates live CRUD operations.

🎨
Streamlined colour panel with four core swatches and advanced overrides

The theme editor's Colours panel now displays four primary swatchesβ€”Background, Text, Brand, and Brand textβ€”with an Advanced disclosure for fine-grained overrides (Link, Link hover, Icons, Icon hover, Supporting icons, Muted text, Borders). Saved legacy Link and Icon values automatically migrate to overrides when they differ from Brand, preserving all existing customizations.

🎨
Storefront theme engine now uses merchant color scheme roles

Header, cart, and storefront content now read the merchant's configured color scheme roles (link, icon, borders, backgrounds) end-to-end, replacing hardcoded grays and bespoke hover formulas. Legacy color codes are automatically folded on read and stripped on write, so saved themes continue to paint the merchant's chosen colors without component edits.

πŸ—‚οΈ
Category Page Designer for V5 CMS

Store administrators can now design category pages through the CMS editor, controlling page width, breadcrumbs, filter rail configuration, product display (tile/list view switcher), grid columns, and pagination behavior (page numbers or auto-scroll). The designer organizes settings across Default, Filters, and Cards tabs, with automatic page sizes that align to grid rows and configurable list-view column layouts.

Read documentation β†’

🧩Customer-Focused Improvements

🏷️
Group inherited products by subcategory order in parent categories

Parent categories now display products grouped by subcategory in the configured order, rather than interleaving products across all subcategories by position. This depth-first ordering makes product listings visually follow the admin-configured category hierarchy.

Read documentation β†’
πŸ”
API Gateway exchange resend capability

Added a new endpoint allowing support teams to replay failed API Gateway exchanges with optional payload editing, eliminating the need for manual URL adjustments to avoid CORS errors. Exchanges now track replay attribution and support both synchronous and asynchronous resend modes.

πŸ—‚οΈ
Reorganised V5 Admin sidebar navigation

Promotions and Apps are now top-level menu items for easier access, while Synchronisation and API Gateway have been moved under a new Settings > Integration group. All existing page URLs remain unchanged.

πŸ’³
Customizable checkout payment button styling via CSS variables

Payment form buttons now accept CSS variables for color, font, border radius, and other visual properties, allowing storefronts to match payment buttons to their brand without hardcoded purple styling. The storefront passes resolved `--cb-payment-*` values on the iframe URL, which are declared server-side before processor scripts run to ensure compatibility with SDKs that read styles at load time.

Read documentation β†’
πŸ”
Role-based authentication spike for App Builder and Firestore

Completed proof-of-concept verifying that CB Store user sessions can federate into Firebase via OpenID Connect, allowing Firestore Security Rules to read shopper role, store ID, user ID, and group claims through `request.auth.token.firebase.sign_in_attributes`. Extensions now automatically sign in using the store's identity when configured, enabling role-aware data access without requiring changes to extension code.

Read documentation β†’

πŸ”§Top Resolved Issues