chore(deps): Update dependency shell-quote@<1.8.4 to v1.10.0 #36
No reviewers
Labels
No labels
dependencies
major
security-pin
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
trails-cool/trails!36
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/shell-quote-1.8.4-1.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
1.8.4→1.10.0Release Notes
ljharb/shell-quote (shell-quote@<1.8.4)
v1.10.0Compare Source
Merged
parse: add opt-insplitUnquotedoption for shell field-splitting of unquoted expansions#1Commits
parse: match nested${...}braces so nested parameter expansion is consumed as one substitutionc0842c8parse: pin single-quote literalness and unmatched-quote handlinga0d03e32116fa3quote: pin conservative escaping of=,@,^,,,:,!(#11)1c36f3fquoteoutputs POSIX quoting, notcmd.exe/PowerShell100e96eparse's supported parameter-expansion subsete1c75cdparse: a backslash inside single quotes must not escape the closing quote5d460a32de86f5quote: pin that a backslash with whitespace is not doubled in single quotes (#14)190e236quote: use output verbatim; do not re-quote it (#11)1b36468parse: fix swappedSINGLE_QUOTE/DOUBLE_QUOTEvariable names801af5c59bbf8b@arethetypeswrong/cli,evalmda04d475@arethetypeswrong/ci,eslintd390f9aquote: the tilde test escapes every~, not just a leading one (#9)617d119v1.9.0Compare Source
Commits
dca6e21eslint9aa9e8fparse: finalize tokens in linear time (GHSA-395f-4hp3-45gv)7ff548875e8497@types/esrecurse3fb739dnpm installon Windows to survive npm 2/3 staging-rename flakeabe0163b4bafa2quote: escape leading~to prevent shell tilde-expansion7a76c1aauto-changelog,tape7184b44jackspeakis no longer in the graph9ba368aConfiguration
📅 Schedule: (in timezone Europe/Copenhagen)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
ec4ca7783c4b1bbc89354b1bbc893514a55996fd14a55996fdcad84875fecad84875fe961e9438d9961e9438d96c32739eaeClosing: superseded by #56, which freezes the version line of `pnpm.overrides` security pins (minor and major disabled, patch still flows).
This entry is a CVE floor, not a dependency — the correct value is the minimum patched version inside the range its consumers expect, not the newest release. No current advisory requires leaving the pinned line, so this change is risk without benefit. Renovate will no longer raise it.
If a future advisory can only be satisfied by crossing a minor or major, that becomes a deliberate manual change (ideally driven by
osvVulnerabilityAlertsonce configured).Renovate Ignore Notification
Because you closed this PR without merging, Renovate will ignore this update (
1.10.0). You will get a PR once a newer version is released. To ignore this dependency forever, add it to theignoreDepsarray of your Renovate config.If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.
Pull request closed