build(deps-dev): bump shell-quote from 1.8.4 to 1.10.0 - #108
Merged
Conversation
Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.4 to 1.10.0. - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.8.4...v1.10.0) --- updated-dependencies: - dependency-name: shell-quote dependency-version: 1.10.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Contributor
🎭 Visual regression resultsDetails
Skipped testsmobile-chrome › theme.spec.ts › QuantEcon theme — visual regression › launch-colab |
mmcky
added a commit
that referenced
this pull request
Aug 6, 2026
…t set Builds on Copilot's CVE-alias addition. Reviewing that PR surfaced that the snapshot date was being advanced without a re-triage: measured by package, SECURITY.md covered 13 of the 18 packages with open alerts, and four of the five uncovered ones had backward-compatible patched releases — exactly the case this file's own policy says to fix with an `overrides` entry rather than defer. Overrides added (10 alerts closed): brace-expansion 1.1.15 -> 1.1.18, 5.0.6 -> 5.0.9 3 high (ReDoS) js-yaml 3.14.2 -> 3.15.1, 4.1.1 -> 4.3.1 2 high + 2 medium sanitize-html 2.12.1/2.17.1 -> 2.17.6 1 medium @babel/core 7.29.0 -> 7.29.7 1 low brace-expansion and js-yaml each have two majors in the tree, so those are version-scoped like the existing `ws@^8.0.0` entry. The fifth, `linkify-it`, is a genuine major (4->5) with no 4.x fix, but it reaches the tree only via markdown-it@13 — already deferred as 13->14, and markdown-it@14 requires linkify-it ^5. Named explicitly under that deferral rather than left to be inferred. Also: SECURITY.md's own "Report a vulnerability" link still pointed at the pre-rename quantecon-theme-src (as did the #63 link), and the shell-quote row still read ^1.8.4 after #108 moved it to ^1.10.0. Both corrected, and the snapshot date set to the day the re-triage actually happened. Verified: all 18 packages with open alerts are now named in the file; overrides resolve to the patched versions; typecheck, 13 unit tests and 13 visual tests pass (sanitize-html sits in MyST's render path, so the visual suite is the meaningful check).
mmcky
added a commit
that referenced
this pull request
Aug 6, 2026
…t set (#104) * Initial plan * docs(security): re-evaluate GHSA-9583-h5hc-x8cw / CVE-2025-61686, update snapshot date to 2026-07-24 * fix(security): close 10 alerts via overrides; re-triage the full alert set Builds on Copilot's CVE-alias addition. Reviewing that PR surfaced that the snapshot date was being advanced without a re-triage: measured by package, SECURITY.md covered 13 of the 18 packages with open alerts, and four of the five uncovered ones had backward-compatible patched releases — exactly the case this file's own policy says to fix with an `overrides` entry rather than defer. Overrides added (10 alerts closed): brace-expansion 1.1.15 -> 1.1.18, 5.0.6 -> 5.0.9 3 high (ReDoS) js-yaml 3.14.2 -> 3.15.1, 4.1.1 -> 4.3.1 2 high + 2 medium sanitize-html 2.12.1/2.17.1 -> 2.17.6 1 medium @babel/core 7.29.0 -> 7.29.7 1 low brace-expansion and js-yaml each have two majors in the tree, so those are version-scoped like the existing `ws@^8.0.0` entry. The fifth, `linkify-it`, is a genuine major (4->5) with no 4.x fix, but it reaches the tree only via markdown-it@13 — already deferred as 13->14, and markdown-it@14 requires linkify-it ^5. Named explicitly under that deferral rather than left to be inferred. Also: SECURITY.md's own "Report a vulnerability" link still pointed at the pre-rename quantecon-theme-src (as did the #63 link), and the shell-quote row still read ^1.8.4 after #108 moved it to ^1.10.0. Both corrected, and the snapshot date set to the day the re-triage actually happened. Verified: all 18 packages with open alerts are now named in the file; overrides resolve to the patched versions; typecheck, 13 unit tests and 13 visual tests pass (sanitize-html sits in MyST's render path, so the visual suite is the meaningful check). * fix(security): correct two override floors caught by adversarial review An independent review of the override set found two real defects: - sanitize-html: the ^2.17.5 caret resolved 2.17.6, which raises engines.node to >=22.12.0 — contradicting this theme's declared node >=20 support — and swaps htmlparser2 from v8 to the ESM-only v12. CI never noticed because it runs node 24. Now pinned EXACTLY to 2.17.5: the advisory-fixed floor (GHSA-vccv-cmxp-4j9h patched at 2.17.5), no engines constraint, htmlparser2 v10. The tree keeps a single sanitize-html copy. - brace-expansion@^5.0.0: the ^5.0.7 floor was below the 5.x patched versions in the GitHub advisory DB (GHSA-mh99 patched 5.0.8, GHSA-rgw5 patched 5.0.9) — this repo's Dependabot alerts only surface the 1.x ranges for those two, which is what the floor was mistakenly read from. The installed 5.0.9 was already safe; the declared floor now matches it (^5.0.9). SECURITY.md corrections from the same review: - Both rows updated with the reasoning above; the sanitize-html row also notes the override knowingly forces @jupyterlab/apputils past its declared ~2.12.1 range. - The "ws (7->8)" deferral was stale — ws@7 has no open alerts since 7.5.12 (#103) covers the last patched 7.5.11. Removed from the deferred list; the ws@^8.0.0 override row records it. - The tar deferral enumeration was missing two of the eight open GHSAs (GHSA-vmf3-w455-68vh, GHSA-w8wr-v893-vjvp) — added. - The react-router row now records that GHSA-337j-9hxr-rhxg and GHSA-wrjc-x8rr-h8h6 have no 6.x fix at all (first patched in 7.18.0). Verified: all open-alert packages named in SECURITY.md and every override row matches package.json (both checked programmatically); resolved tree is sanitize-html 2.17.5 / htmlparser2 10.1.0 / brace-expansion 1.1.18 + 5.0.9; typecheck, 13 unit and 13 visual tests pass. --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: Matt McKay <mmcky@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps shell-quote from 1.8.4 to 1.10.0.
Changelog
Sourced from shell-quote's changelog.
Commits
64988d9v1.10.0617d119[Tests]quote: the tilde test escapes every~, not just a leading one (#9)59bbf8b[types] fix an error TS v6 ignores but v7 fails on190e236[Tests]quote: pin that a backslash with whitespace is not doubled in singl...a04d475[Dev Deps] update@arethetypeswrong/cli,evalmdb9545b3[New]parse: add opt-insplitUnquotedoption for shell field-splitting of...1b36468[readme]quote: use output verbatim; do not re-quote it (#11)1c36f3f[Tests]quote: pin conservative escaping of=,@,^,,,:,!(#11)e1c75cd[readme] documentparse's supported parameter-expansion subsetc0842c8[Fix]parse: match nested${...}braces so nested parameter expansion is ...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.