Skip to content

build(deps-dev): bump shell-quote from 1.8.4 to 1.10.0 - #108

Merged
mmcky merged 1 commit into
mainfrom
dependabot/npm_and_yarn/shell-quote-1.10.0
Jul 24, 2026
Merged

build(deps-dev): bump shell-quote from 1.8.4 to 1.10.0#108
mmcky merged 1 commit into
mainfrom
dependabot/npm_and_yarn/shell-quote-1.10.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps shell-quote from 1.8.4 to 1.10.0.

Changelog

Sourced from shell-quote's changelog.

v1.10.0 - 2026-07-10

Merged

Commits

  • [Fix] parse: match nested ${...} braces so nested parameter expansion is consumed as one substitution c0842c8
  • [Tests] parse: pin single-quote literalness and unmatched-quote handling a0d03e3
  • [readme] remove the space in js code fences so evalmd evaluates them 2116fa3
  • [Tests] quote: pin conservative escaping of =, @, ^, ,, :, ! (#11) 1c36f3f
  • [readme] document that quote outputs POSIX quoting, not cmd.exe/PowerShell 100e96e
  • [readme] document parse's supported parameter-expansion subset e1c75cd
  • [Fix] parse: a backslash inside single quotes must not escape the closing quote 5d460a3
  • [readme] fix stale example outputs 2de86f5
  • [Tests] quote: pin that a backslash with whitespace is not doubled in single quotes (#14) 190e236
  • [readme] quote: use output verbatim; do not re-quote it (#11) 1b36468
  • [Refactor] parse: fix swapped SINGLE_QUOTE/DOUBLE_QUOTE variable names 801af5c
  • [types] fix an error TS v6 ignores but v7 fails on 59bbf8b
  • [Dev Deps] update @arethetypeswrong/cli, evalmd a04d475
  • [Dev Deps] update @arethetypeswrong/ci, eslint d390f9a
  • [Tests] quote: the tilde test escapes every ~, not just a leading one (#9) 617d119

v1.9.0 - 2026-06-24

Commits

  • [New] add types dca6e21
  • [Dev Deps] update eslint 9aa9e8f
  • [Fix] parse: finalize tokens in linear time (GHSA-395f-4hp3-45gv) 7ff5488
  • [actions] update workflows 75e8497
  • [actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10@types/esrecurse 3fb739d
  • [actions] retry npm install on Windows to survive npm 2/3 staging-rename flake abe0163
  • [actions] Windows + node 5/7: install deps with a modern node b4bafa2
  • [Fix] quote: escape leading ~ to prevent shell tilde-expansion 7a76c1a
  • [Dev Deps] update auto-changelog, tape 7184b44
  • [Dev Deps] apparently jackspeak is no longer in the graph 9ba368a
Commits
  • 64988d9 v1.10.0
  • 617d119 [Tests] quote: the tilde test escapes every ~, not just a leading one (#9)
  • 59bbf8b [types] fix an error TS v6 ignores but v7 fails on
  • 190e236 [Tests] quote: pin that a backslash with whitespace is not doubled in singl...
  • a04d475 [Dev Deps] update @arethetypeswrong/cli, evalmd
  • b9545b3 [New] parse: add opt-in splitUnquoted option for shell field-splitting of...
  • 1b36468 [readme] quote: use output verbatim; do not re-quote it (#11)
  • 1c36f3f [Tests] quote: pin conservative escaping of =, @, ^, ,, :, ! (#11)
  • e1c75cd [readme] document parse's supported parameter-expansion subset
  • c0842c8 [Fix] parse: match nested ${...} braces so nested parameter expansion is ...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.4 to 1.10.0.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.4...v1.10.0)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.10.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 24, 2026
@github-actions

github-actions Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor
PR Preview Action v1.8.1
Preview removed because the pull request was closed.
2026-07-24 04:44 UTC

@github-actions

Copy link
Copy Markdown
Contributor

🎭 Visual regression results

passed  13 passed
skipped  1 skipped

Details

stats  14 tests across 1 suite
duration  27.7 seconds
commit  38048bb

Skipped tests

mobile-chrome › theme.spec.ts › QuantEcon theme — visual regression › launch-colab

@mmcky
mmcky merged commit ddb1f0b into main Jul 24, 2026
4 checks passed
@mmcky
mmcky deleted the dependabot/npm_and_yarn/shell-quote-1.10.0 branch July 24, 2026 04:44
mmcky added a commit that referenced this pull request Aug 6, 2026
…t set

Builds on Copilot's CVE-alias addition. Reviewing that PR surfaced that the
snapshot date was being advanced without a re-triage: measured by package,
SECURITY.md covered 13 of the 18 packages with open alerts, and four of the
five uncovered ones had backward-compatible patched releases — exactly the
case this file's own policy says to fix with an `overrides` entry rather
than defer.

Overrides added (10 alerts closed):

  brace-expansion  1.1.15 -> 1.1.18, 5.0.6 -> 5.0.9   3 high (ReDoS)
  js-yaml          3.14.2 -> 3.15.1, 4.1.1 -> 4.3.1   2 high + 2 medium
  sanitize-html    2.12.1/2.17.1 -> 2.17.6            1 medium
  @babel/core      7.29.0 -> 7.29.7                   1 low

brace-expansion and js-yaml each have two majors in the tree, so those are
version-scoped like the existing `ws@^8.0.0` entry.

The fifth, `linkify-it`, is a genuine major (4->5) with no 4.x fix, but it
reaches the tree only via markdown-it@13 — already deferred as 13->14, and
markdown-it@14 requires linkify-it ^5. Named explicitly under that deferral
rather than left to be inferred.

Also: SECURITY.md's own "Report a vulnerability" link still pointed at the
pre-rename quantecon-theme-src (as did the #63 link), and the shell-quote
row still read ^1.8.4 after #108 moved it to ^1.10.0. Both corrected, and
the snapshot date set to the day the re-triage actually happened.

Verified: all 18 packages with open alerts are now named in the file;
overrides resolve to the patched versions; typecheck, 13 unit tests and 13
visual tests pass (sanitize-html sits in MyST's render path, so the visual
suite is the meaningful check).
mmcky added a commit that referenced this pull request Aug 6, 2026
…t set (#104)

* Initial plan

* docs(security): re-evaluate GHSA-9583-h5hc-x8cw / CVE-2025-61686, update snapshot date to 2026-07-24

* fix(security): close 10 alerts via overrides; re-triage the full alert set

Builds on Copilot's CVE-alias addition. Reviewing that PR surfaced that the
snapshot date was being advanced without a re-triage: measured by package,
SECURITY.md covered 13 of the 18 packages with open alerts, and four of the
five uncovered ones had backward-compatible patched releases — exactly the
case this file's own policy says to fix with an `overrides` entry rather
than defer.

Overrides added (10 alerts closed):

  brace-expansion  1.1.15 -> 1.1.18, 5.0.6 -> 5.0.9   3 high (ReDoS)
  js-yaml          3.14.2 -> 3.15.1, 4.1.1 -> 4.3.1   2 high + 2 medium
  sanitize-html    2.12.1/2.17.1 -> 2.17.6            1 medium
  @babel/core      7.29.0 -> 7.29.7                   1 low

brace-expansion and js-yaml each have two majors in the tree, so those are
version-scoped like the existing `ws@^8.0.0` entry.

The fifth, `linkify-it`, is a genuine major (4->5) with no 4.x fix, but it
reaches the tree only via markdown-it@13 — already deferred as 13->14, and
markdown-it@14 requires linkify-it ^5. Named explicitly under that deferral
rather than left to be inferred.

Also: SECURITY.md's own "Report a vulnerability" link still pointed at the
pre-rename quantecon-theme-src (as did the #63 link), and the shell-quote
row still read ^1.8.4 after #108 moved it to ^1.10.0. Both corrected, and
the snapshot date set to the day the re-triage actually happened.

Verified: all 18 packages with open alerts are now named in the file;
overrides resolve to the patched versions; typecheck, 13 unit tests and 13
visual tests pass (sanitize-html sits in MyST's render path, so the visual
suite is the meaningful check).

* fix(security): correct two override floors caught by adversarial review

An independent review of the override set found two real defects:

- sanitize-html: the ^2.17.5 caret resolved 2.17.6, which raises
  engines.node to >=22.12.0 — contradicting this theme's declared node
  >=20 support — and swaps htmlparser2 from v8 to the ESM-only v12. CI
  never noticed because it runs node 24. Now pinned EXACTLY to 2.17.5:
  the advisory-fixed floor (GHSA-vccv-cmxp-4j9h patched at 2.17.5), no
  engines constraint, htmlparser2 v10. The tree keeps a single
  sanitize-html copy.
- brace-expansion@^5.0.0: the ^5.0.7 floor was below the 5.x patched
  versions in the GitHub advisory DB (GHSA-mh99 patched 5.0.8, GHSA-rgw5
  patched 5.0.9) — this repo's Dependabot alerts only surface the 1.x
  ranges for those two, which is what the floor was mistakenly read
  from. The installed 5.0.9 was already safe; the declared floor now
  matches it (^5.0.9).

SECURITY.md corrections from the same review:

- Both rows updated with the reasoning above; the sanitize-html row also
  notes the override knowingly forces @jupyterlab/apputils past its
  declared ~2.12.1 range.
- The "ws (7->8)" deferral was stale — ws@7 has no open alerts since
  7.5.12 (#103) covers the last patched 7.5.11. Removed from the
  deferred list; the ws@^8.0.0 override row records it.
- The tar deferral enumeration was missing two of the eight open GHSAs
  (GHSA-vmf3-w455-68vh, GHSA-w8wr-v893-vjvp) — added.
- The react-router row now records that GHSA-337j-9hxr-rhxg and
  GHSA-wrjc-x8rr-h8h6 have no 6.x fix at all (first patched in 7.18.0).

Verified: all open-alert packages named in SECURITY.md and every
override row matches package.json (both checked programmatically);
resolved tree is sanitize-html 2.17.5 / htmlparser2 10.1.0 /
brace-expansion 1.1.18 + 5.0.9; typecheck, 13 unit and 13 visual
tests pass.

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Matt McKay <mmcky@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant