Skip to content

chore: pin shell-quote to 1.8.4#659

Merged
kacperzolkiewski merged 1 commit into
mainfrom
@exploif/bump-shell-quote
Jun 25, 2026
Merged

chore: pin shell-quote to 1.8.4#659
kacperzolkiewski merged 1 commit into
mainfrom
@exploif/bump-shell-quote

Conversation

@exploIF

@exploIF exploIF commented Jun 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

Fixes shell-quote vulnerability: https://security.snyk.io/package/npm/shell-quote/1.8.2
Fixes: #646

Copilot AI review requested due to automatic review settings June 24, 2026 16:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins shell-quote to a non-vulnerable version to address the Snyk-reported issue for shell-quote@1.8.2, ensuring installs consistently resolve to the patched release.

Changes:

  • Adds a Yarn resolutions override to force shell-quote@1.8.4.
  • Updates yarn.lock to reflect shell-quote resolving to 1.8.4.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
package.json Adds a resolutions entry to pin shell-quote to 1.8.4.
yarn.lock Updates the locked shell-quote package entry to 1.8.4.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@kacperzolkiewski kacperzolkiewski merged commit f871f36 into main Jun 25, 2026
8 checks passed
@kacperzolkiewski kacperzolkiewski deleted the @exploif/bump-shell-quote branch June 25, 2026 06:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants