Solidus v4.8

portrait of Jared Norman

Jared Norman

9 Oct 2026 - 7 mins read

Cover image of Solidus v4.8 post

I'm happy to announce that Solidus v4.8 is here! Massive thanks to everyone who contributed to this release, starting with our first-time contributors: John Mamanao, minhluuquang, owgreen-dev, Robert Silén, Siddharth Gautam, and Waqas Ahmed. Thanks as well to Adam Mueller, Alberto Vena, Alistair Norman, Benjamin Wil, Brent Wheeldon, Chris Todorov, Elia Schito, Ikraam Ghoor, Martin Meyerhoff, Noah Silvera, Sascha Karnatz, Sean Denny, Senem Soy, Sofia Besenski, and Thomas von Deyen. I snuck a few in myself.

Ruby and Rails requirements are unchanged from v4.7, so upgrading should mostly be a matter of working through the deprecations. The v4.8 upgrade guide covers the deprecations and breaking changes in detail, and the release notes list every change.

Storefront and I18n Join the Monorepo

In an effort to keep the development of Solidus's core components more centralized, we've moved the Solidus Storefront (#6468), formerly Solidus Starter Frontend, and Solidus I18n (#6537) into the monorepo. This will help us maintain compatibility and ensure they get released in lockstep with the rest of Solidus, which is exactly what happened with today's release. We used Git's subtree merge feature for both projects so their histories are preserved.

For existing stores, the storefront move changes nothing: it's an application template, and your app already owns its copy of the code. If you use solidus_i18n, the gem jumps to 4.8.0 and now tracks the Solidus version, so loosen any ~> 2.0 pin. The upgrade guide has the details.

Since the merge, I18n has already picked up fixes for missing interpolations (#6626, #6637) and a CI check that catches them going forward (#6655), all from first-time contributor owgreen-dev.

With these projects merged in, we also did a pass to ensure that all the Solidus subprojects and vendored assets are correctly licensed (#6559, #6560), which closed a long-open Remixicon licence issue (#5947). Hooray for license compliance!

Security Releases and Hardening

Since v4.7.0 was released, we've done two rounds of security patches, on September 9 and October 7. v4.8.0 includes all those fixes, as well as a variety of hardening changes that didn't warrant security advisories:

  • Refunds can no longer be created for payments that aren't in a refundable state (#6565).
  • The storefront cart update permits far fewer attributes (#6636).
  • Order customer assignment is scoped to users the current admin can read (#6659).
  • The backend's payment actions can no longer trigger payment events the admin UI doesn't offer (#6660).
  • Shipment transfers are scoped to stock locations the user can read (#6661).

If you have custom roles or payment sources, check the upgrade guide, since a few of these tighten what those roles can do.

Performance

Big thanks to Ikraam Ghoor, Martin Meyerhoff, and Thomas von Deyen for their work on improving the framework's performance. We've cut down on N+1 queries and added eager loading across the API and admin (#6504, #6500, #6525, #6497, #6612), improved loaded record reuse (#6524), dropped unnecessary model reloading (#6627), and removed unnecessary database round trips (#6493, #6494). Order recalculation also does less work now: events fire only after the order is saved, and redundant total setting and amount persistence are gone (#6447, #6450, #6451).

Long-Standing Bugs, Finally Fixed

During the development of Solidus v4.8, we undertook a significant effort to close long-standing pull requests and issues. This resulted in fixes for bugs going back as far as 2017. Highlights include:

  • Shipping calculators no longer count cancelled items (#6644), closing #1837, open since 2017.
  • Taxon touching no longer causes deadlocks (#6609), closing #3931 from 2021.
  • Customer returns can't be created for orders without shipped units (#6614), closing #3800 from 2020.
  • Static preferences fall back to their defaults correctly (#6616), closing #3718 from 2020.
  • Calculators always return BigDecimal (#6507), closing #3756 from 2020.

New in Promotions

Martin Meyerhoff was hard at work on the promotions system. A new configurable PromotionEligibilityChecker lets you check whether a promotion applies to an order without running every promotion in the system (#6430), and a new TaxonRevenue condition (#6492) gained an "exclude" match policy shortly after (#6518). Sascha Karnatz added a privilege and category to the promotion permission sets, so they show up properly in role management (#6554).

Other Changes

Besides that, we've made a variety of miscellaneous improvements. Stores can now have an address for invoicing purposes (#6649). Store operators can select their time zone in the backend (#6437). Refund logs now appear in the payment log listing (#6486), and SimpleCoordinator accepts inventory_units as a keyword argument, laying groundwork for a configurable coordinator (#6483). We also made a bunch of developer-facing improvements, including a fixed and refreshed Docker setup (#6533, #6534, #6567), idempotent sample data (#6555), Postgres 18 in CI (#6539), and a solidus:install generator that aborts when migrations or seeds fail instead of silently carrying on (#6553).

Deprecations and Upgrade Notes

A few things are deprecated in this release, including a handful of orphaned preferences (#6575), refunding payments that aren't in a refundable state (#6565), and the promotion dry-run arguments (#6430). There are also a few dependency changes: discard 2.x is now required (#6488), kt-paperclip 8 is allowed (#6571), and kaminari-activerecord is no longer pulled in by core (#6445). The v4.8 upgrade guide has the full list of deprecations and breaking changes, along with what to do about each of them.

Closing

Thanks again to everyone who contributed. For everything that happened this quarter beyond the release itself, see the Q3 2026 quarterly roundup. We'll be releasing the next version of Solidus Admin soon!