dependabot[bot] opened a new pull request, #45097: URL: https://github.com/apache/superset/pull/45097
Bumps the security group with 3 updates in the /superset-frontend directory: [@simple-git/argv-parser](https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser), [shell-quote](https://github.com/ljharb/shell-quote) and [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git). Updates `@simple-git/argv-parser` from 1.1.1 to 2.0.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/steveukx/git-js/releases">@simple-git/argv-parser's releases</a>.</em></p> <blockquote> <h2><code>@simple-git/argv-parser</code><a href="https://github.com/2"><code>@2</code></a>.0.1</h2> <h3>Patch Changes</h3> <ul> <li> <p>68874c2: Add <code>VISUAL</code> environment variable to set of <code>allowUnsafeEditor</code> environment variables.</p> <p>Thanks to <a href="https://github.com/oss-security-shopify"><code>@oss-security-shopify</code></a> for identifying the vulnerability.</p> </li> </ul> <h2><code>@simple-git/argv-parser</code><a href="https://github.com/2"><code>@2</code></a>.0.0</h2> <h3>Major Changes</h3> <ul> <li> <p>98864c6: Updates ahead of the v4 release for <code>simple-git</code>.</p> <ul> <li> <p>Adds support for TypeScript declaration maps</p> </li> <li> <p>Exports the <code>isGitEnvKey</code> helper to detect whether an environment variable can be used to configure a <code>git</code> operation</p> </li> <li> <p>Adds detection for <code>includeIf.<condition>.path</code>, thanks to <a href="https://github.com/NotAFlightRisk"><code>@NotAFlightRisk</code></a> for identifying the vulnerability</p> </li> </ul> </li> </ul> <h3>Patch Changes</h3> <ul> <li> <p>c427fba: Additional argument parser vulnerability checks:</p> <ul> <li>Thanks to <a href="https://github.com/mrillicit"><code>@mrillicit</code></a> for identifying <code>include.path</code>, <code>filter.*.process</code></li> <li>Thanks to <a href="https://github.com/tejas619"><code>@tejas619</code></a> for identifying <code>url.*.insteadOf</code></li> </ul> </li> <li> <p>1bb14df: Vulnerability detection expanded to include <code>pager.*</code>, <code>uploadpack.packObjectsHook</code>, <code>difftool.*.cmd</code> and use of the <code>GIT_CONFIG_PARAMETERS</code> environment variable</p> <p>Thanks to <a href="https://github.com/threalwinky"><code>@threalwinky</code></a> and <a href="https://github.com/nuc13us"><code>@nuc13us</code></a> for identifying.</p> </li> <li> <p>dfeb116: Vulnerability detection expanded to cover configuration delivered through path-taking global options, where the dangerous value is a file on disk rather than a token <code>simple-git</code> can inspect:</p> <ul> <li><code>--exec-path</code> names the directory <code>git</code> loads built-in commands and remote helpers from, and is blocked under the new <code>allowUnsafeExec</code> category along with the <code>GIT_EXEC_PATH</code> environment variable (previously grouped under <code>allowUnsafeConfigPaths</code>)</li> <li><code>--git-dir</code>, <code>--work-tree</code> and <code>-C</code> cause <code>git</code> to read the configuration of the repository they name, and are blocked under <code>allowUnsafeConfigPaths</code></li> </ul> <p>These options are only detected when supplied before the git sub-command and with a value - used as getters (<code>git.raw('rev-parse', '--git-dir')</code>) or as task options (<code>git.raw('commit', '-C', 'HEAD~1')</code>) they are unaffected.</p> </li> <li> <p>d762810: Add <code>allowUnsafeExec</code> detection to <code>rebase -x</code> and <code>rebase --exec</code>.</p> <p>Thanks to <a href="https://github.com/gdegrange"><code>@gdegrange</code></a> for the vulnerability report.</p> </li> <li> <p>d762810: Add <code>allowUnsafeCommandBinaries</code> detection to configuring <code>trailer.<token>.cmd</code> and <code>trailer.<token>.command</code>.</p> <p>Thanks to <a href="https://github.com/sec-reex"><code>@sec-reex</code></a> for the vulnerability report.</p> </li> <li> <p>Updated dependencies [98864c6]</p> <ul> <li><code>@simple-git/args-pathspec</code><a href="https://github.com/1"><code>@1</code></a>.0.4</li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/steveukx/git-js/blob/main/packages/argv-parser/CHANGELOG.md">@simple-git/argv-parser's changelog</a>.</em></p> <blockquote> <h2>2.0.1</h2> <h3>Patch Changes</h3> <ul> <li> <p>68874c2: Add <code>VISUAL</code> environment variable to set of <code>allowUnsafeEditor</code> environment variables.</p> <p>Thanks to <a href="https://github.com/oss-security-shopify"><code>@oss-security-shopify</code></a> for identifying the vulnerability.</p> </li> </ul> <h2>2.0.0</h2> <h3>Major Changes</h3> <ul> <li> <p>98864c6: Updates ahead of the v4 release for <code>simple-git</code>.</p> <ul> <li> <p>Adds support for TypeScript declaration maps</p> </li> <li> <p>Exports the <code>isGitEnvKey</code> helper to detect whether an environment variable can be used to configure a <code>git</code> operation</p> </li> <li> <p>Adds detection for <code>includeIf.<condition>.path</code>, thanks to <a href="https://github.com/bhaswanthc"><code>@bhaswanthc</code></a>, <a href="https://github.com/NotAFlightRisk"><code>@NotAFlightRisk</code></a>, <a href="https://github.com/oss-security-shopify"><code>@oss-security-shopify</code></a> for identifying the vulnerability</p> </li> </ul> </li> </ul> <h3>Patch Changes</h3> <ul> <li> <p>c427fba: Additional argument parser vulnerability checks:</p> <ul> <li>Thanks to <a href="https://github.com/bhaswanthc"><code>@bhaswanthc</code></a>, <a href="https://github.com/mrillicit"><code>@mrillicit</code></a>, <a href="https://github.com/avrlab233"><code>@avrlab233</code></a>, <a href="https://github.com/avrlab233"><code>@avrlab233</code></a> for identifying <code>include.path</code>, <code>filter.*.process</code></li> <li>Thanks to <a href="https://github.com/tejas619"><code>@tejas619</code></a> for identifying <code>url.*.insteadOf</code></li> </ul> </li> <li> <p>1bb14df: Vulnerability detection expanded to include <code>pager.*</code>, <code>uploadpack.packObjectsHook</code>, <code>difftool.*.cmd</code> and use of the <code>GIT_CONFIG_PARAMETERS</code> environment variable</p> <p>Thanks to <a href="https://github.com/threalwinky"><code>@threalwinky</code></a> and <a href="https://github.com/nuc13us"><code>@nuc13us</code></a> for identifying.</p> </li> <li> <p>dfeb116: Vulnerability detection expanded to cover configuration delivered through path-taking global options, where the dangerous value is a file on disk rather than a token <code>simple-git</code> can inspect:</p> <ul> <li><code>--exec-path</code> names the directory <code>git</code> loads built-in commands and remote helpers from, and is blocked under the new <code>allowUnsafeExec</code> category along with the <code>GIT_EXEC_PATH</code> environment variable (previously grouped under <code>allowUnsafeConfigPaths</code>)</li> <li><code>--git-dir</code>, <code>--work-tree</code> and <code>-C</code> cause <code>git</code> to read the configuration of the repository they name, and are blocked under <code>allowUnsafeConfigPaths</code></li> </ul> <p>These options are only detected when supplied before the git sub-command and with a value - used as getters (<code>git.raw('rev-parse', '--git-dir')</code>) or as task options (<code>git.raw('commit', '-C', 'HEAD~1')</code>) they are unaffected.</p> </li> <li> <p>d762810: Add <code>allowUnsafeExec</code> detection to <code>rebase -x</code> and <code>rebase --exec</code>.</p> <p>Thanks to <a href="https://github.com/gdegrange"><code>@gdegrange</code></a> for the vulnerability report.</p> </li> <li> <p>d762810: Add <code>allowUnsafeCommandBinaries</code> detection to configuring <code>trailer.<token>.cmd</code> and <code>trailer.<token>.command</code>.</p> <p>Thanks to <a href="https://github.com/sec-reex"><code>@sec-reex</code></a> for the vulnerability report.</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/steveukx/git-js/commit/f09081b793daa75e282794e92982efa9000a3514"><code>f09081b</code></a> Version Packages</li> <li><a href="https://github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4"><code>68874c2</code></a> Add <code>VISUAL</code> to tracked environment variables for <code>allowUnsafeEditor</code> (<a href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1201">#1201</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/3971917d3c3d65d9935383ed88970a3578cb462d"><code>3971917</code></a> Version Packages</li> <li><a href="https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3"><code>d762810</code></a> Fix/vulnerability rebase exec (<a href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1198">#1198</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/dfeb11648190b2d82a98c91768ec6e3a65bb401c"><code>dfeb116</code></a> Fix/exec path vulnerability (<a href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1197">#1197</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7"><code>98864c6</code></a> V4 (<a href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1193">#1193</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/c427fbad33f1f2b11341f1cf852eedecbb106400"><code>c427fba</code></a> Argument parser vulnerability checks (<a href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1167">#1167</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/1bb14df0595794a9353d28ccdaeeb06c0b9bf2a5"><code>1bb14df</code></a> Merge pull request <a href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1163">#1163</a> from steveukx/claude/add-git-config-vulnerabilities-...</li> <li>See full diff in <a href="https://github.com/steveukx/git-js/commits/@simple-git/[email protected]/packages/argv-parser">compare view</a></li> </ul> </details> <br /> Updates `shell-quote` from 1.9.0 to 1.12.0 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md">shell-quote's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/ljharb/shell-quote/compare/v1.11.0...v1.12.0">v1.12.0</a> - 2026-10-02</h2> <h3>Fixed</h3> <ul> <li>[New] <code>parse</code>: support here-documents (<code>&lt;&lt;</code>) <a href="https://redirect.github.com/ljharb/shell-quote/issues/31"><code>[#31](https://github.com/ljharb/shell-quote/issues/31)</code></a></li> </ul> <h3>Commits</h3> <ul> <li>[New] <code>parse</code>: support tab-stripping here-documents (<code>&lt;&lt;-</code>) <a href="https://github.com/ljharb/shell-quote/commit/dbfac376d4065d37539d3abdb5e76847f93797d3"><code>dbfac37</code></a></li> <li>[New] <code>parse</code>: support output process substitution (<code>&gt;(</code>) <a href="https://github.com/ljharb/shell-quote/commit/20533154bb57809c80f55318b8493aef49505f4e"><code>2053315</code></a></li> <li>[New] <code>parse</code>: support the <code>case</code> test-next terminator (<code>;;&</code>) <a href="https://github.com/ljharb/shell-quote/commit/7d688b9bec1917a22cccd4d4c887128a9c66e8a0"><code>7d688b9</code></a></li> <li>[New] <code>parse</code>: support the <code>case</code> fall-through terminator (<code>;&</code>) <a href="https://github.com/ljharb/shell-quote/commit/f27010ed04bcd925795b350afb1c49e36bbd1ba3"><code>f27010e</code></a></li> <li>[New] <code>parse</code>: support redirecting output despite <code>noclobber</code> (<code>&gt;|</code>) <a href="https://github.com/ljharb/shell-quote/commit/b78d19c14da6356cc12c46b3478203247ab8a295"><code>b78d19c</code></a></li> <li>[New] <code>parse</code>: support opening a file for reading and writing (<code>&lt;&gt;</code>) <a href="https://github.com/ljharb/shell-quote/commit/21cc333eb0ce5bf094f595b7fdc01b3447ffd4b0"><code>21cc333</code></a></li> <li>[New] <code>parse</code>: support redirecting stdout and stderr (<code>&&gt;</code>) <a href="https://github.com/ljharb/shell-quote/commit/6ad6cd215f89adcc29dd601e085fa54083c2f911"><code>6ad6cd2</code></a></li> <li>[New] <code>parse</code>: support appending stdout and stderr (<code>&&gt;&gt;</code>) <a href="https://github.com/ljharb/shell-quote/commit/90cde9cfd8af30fcb65e9fd2cb2f9e181d3f103b"><code>90cde9c</code></a></li> <li>[Dev Deps] update <code>@ljharb/eslint-config</code> <a href="https://github.com/ljharb/shell-quote/commit/3a7b4ae3960c3ff4413932e276c5b0ecb3a2b456"><code>3a7b4ae</code></a></li> </ul> <h2><a href="https://github.com/ljharb/shell-quote/compare/v1.10.0...v1.11.0">v1.11.0</a> - 2026-09-29</h2> <h3>Fixed</h3> <ul> <li>[Refactor] <code>quote</code>: drop a replace that can never match in the single-quote branch <a href="https://redirect.github.com/ljharb/shell-quote/issues/15"><code>[#15](https://github.com/ljharb/shell-quote/issues/15)</code></a></li> <li>[New] <code>parse</code>: support bash ANSI-C quoting (<code>$'...'</code>) <a href="https://redirect.github.com/ljharb/shell-quote/issues/32"><code>[#32](https://github.com/ljharb/shell-quote/issues/32)</code></a></li> </ul> <h3>Commits</h3> <ul> <li>[Fix] <code>quote</code>: reject line terminators in tokens after a <code>comment</code> <a href="https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc"><code>6002b2e</code></a></li> <li>[Fix] <code>parse</code>: preserve text after special shell parameters <a href="https://github.com/ljharb/shell-quote/commit/81b08a532e898a3627f9305fa13d643ffa82a9d3"><code>81b08a5</code></a></li> <li>[Fix] <code>parse</code>: an escaped backslash does not escape the character after it <a href="https://github.com/ljharb/shell-quote/commit/d708019016ce26e1a8a05af4b296e35ef8095c9e"><code>d708019</code></a></li> <li>[Fix] <code>quote</code>: preserve <code>!</code> in arguments that also contain <code>'</code> <a href="https://github.com/ljharb/shell-quote/commit/ad399279dbbbd086967d2040c1558b4888b074e6"><code>ad39927</code></a></li> <li>[Fix] <code>parse</code>: treat <code>$_name</code> as a variable name, not <code>$_</code> followed by text <a href="https://github.com/ljharb/shell-quote/commit/28f88cd422ae4046aca9556c4b74ca90b0ea7f6b"><code>28f88cd</code></a></li> <li>[Fix] <code>quote</code>: preserve empty glob patterns <a href="https://github.com/ljharb/shell-quote/commit/35c9b97a744211091b772f145bef0b6a5562b68e"><code>35c9b97</code></a></li> <li>[Fix] <code>quote</code>: escape <code>~</code> in glob patterns to prevent shell tilde-expansion <a href="https://github.com/ljharb/shell-quote/commit/239d49cae6d231436ea4e676850037018c790c49"><code>239d49c</code></a></li> <li>[Dev Deps] update <code>@ljharb/eslint-config</code>, <code>auto-changelog</code>, <code>eslint</code>, <code>evalmd</code> <a href="https://github.com/ljharb/shell-quote/commit/b1e406ed4287a134cc649db47b9a59e21b304472"><code>b1e406e</code></a></li> <li>[meta] npmignore some files <a href="https://github.com/ljharb/shell-quote/commit/ebfc3080cf5f68db5edfddfba49dc8c4ccacd2d5"><code>ebfc308</code></a></li> <li>[actions] add permissions <a href="https://github.com/ljharb/shell-quote/commit/3429b0d349211786765e9e68478e029d96ad44e9"><code>3429b0d</code></a></li> <li>[actions] set least-privilege <code>cache-mode</code> <a href="https://github.com/ljharb/shell-quote/commit/36f23944db50dd3f0df4da9c7cba0bb63df05f64"><code>36f2394</code></a></li> <li>[Dev Deps] update <code>eslint</code> <a href="https://github.com/ljharb/shell-quote/commit/6de9a41ecfc4fe9f9546df08866c8ead039f8909"><code>6de9a41</code></a></li> </ul> <h2><a href="https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.10.0">v1.10.0</a> - 2026-07-10</h2> <h3>Merged</h3> <ul> <li>[New] <code>parse</code>: add opt-in <code>splitUnquoted</code> option for shell field-splitting of unquoted expansions <a href="https://redirect.github.com/ljharb/shell-quote/pull/1"><code>[#1](https://github.com/ljharb/shell-quote/issues/1)</code></a></li> </ul> <h3>Commits</h3> <ul> <li>[Fix] <code>parse</code>: match nested <code>${...}</code> braces so nested parameter expansion is consumed as one substitution <a href="https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c"><code>c0842c8</code></a></li> <li>[Tests] <code>parse</code>: pin single-quote literalness and unmatched-quote handling <a href="https://github.com/ljharb/shell-quote/commit/a0d03e35c8ede24016502c4433b8f5d6b3100a62"><code>a0d03e3</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ljharb/shell-quote/commit/6ecb8aa618ba6dc6c3b087fce6d7660320d2adeb"><code>6ecb8aa</code></a> v1.12.0</li> <li><a href="https://github.com/ljharb/shell-quote/commit/3a7b4ae3960c3ff4413932e276c5b0ecb3a2b456"><code>3a7b4ae</code></a> [Dev Deps] update <code>@ljharb/eslint-config</code></li> <li><a href="https://github.com/ljharb/shell-quote/commit/7d688b9bec1917a22cccd4d4c887128a9c66e8a0"><code>7d688b9</code></a> [New] <code>parse</code>: support the <code>case</code> test-next terminator (<code>;;&</code>)</li> <li><a href="https://github.com/ljharb/shell-quote/commit/f27010ed04bcd925795b350afb1c49e36bbd1ba3"><code>f27010e</code></a> [New] <code>parse</code>: support the <code>case</code> fall-through terminator (<code>;&</code>)</li> <li><a href="https://github.com/ljharb/shell-quote/commit/90cde9cfd8af30fcb65e9fd2cb2f9e181d3f103b"><code>90cde9c</code></a> [New] <code>parse</code>: support appending stdout and stderr (<code>&>></code>)</li> <li><a href="https://github.com/ljharb/shell-quote/commit/6ad6cd215f89adcc29dd601e085fa54083c2f911"><code>6ad6cd2</code></a> [New] <code>parse</code>: support redirecting stdout and stderr (<code>&></code>)</li> <li><a href="https://github.com/ljharb/shell-quote/commit/20533154bb57809c80f55318b8493aef49505f4e"><code>2053315</code></a> [New] <code>parse</code>: support output process substitution (<code>>(</code>)</li> <li><a href="https://github.com/ljharb/shell-quote/commit/b78d19c14da6356cc12c46b3478203247ab8a295"><code>b78d19c</code></a> [New] <code>parse</code>: support redirecting output despite <code>noclobber</code> (<code>>|</code>)</li> <li><a href="https://github.com/ljharb/shell-quote/commit/21cc333eb0ce5bf094f595b7fdc01b3447ffd4b0"><code>21cc333</code></a> [New] <code>parse</code>: support opening a file for reading and writing (<code>\<></code>)</li> <li><a href="https://github.com/ljharb/shell-quote/commit/dbfac376d4065d37539d3abdb5e76847f93797d3"><code>dbfac37</code></a> [New] <code>parse</code>: support tab-stripping here-documents (<code><<-</code>)</li> <li>Additional commits viewable in <a href="https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.12.0">compare view</a></li> </ul> </details> <br /> Updates `simple-git` from 3.36.0 to 4.0.2 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/steveukx/git-js/releases">simple-git's releases</a>.</em></p> <blockquote> <h2>[email protected]</h2> <h3>Patch Changes</h3> <ul> <li> <p>68874c2: Add <code>VISUAL</code> environment variable to set of <code>allowUnsafeEditor</code> environment variables.</p> <p>Thanks to <a href="https://github.com/oss-security-shopify"><code>@oss-security-shopify</code></a> for identifying the vulnerability.</p> </li> <li> <p>Updated dependencies [68874c2]</p> <ul> <li><code>@simple-git/argv-parser</code><a href="https://github.com/2"><code>@2</code></a>.0.1</li> </ul> </li> </ul> <h2>[email protected]</h2> <h3>Patch Changes</h3> <ul> <li>365f52d: Prepare package.json before publishing.</li> </ul> <h2>[email protected]</h2> <h3>Major Changes</h3> <ul> <li> <p>98864c6: Major upgrade to v4. In this version:</p> <ul> <li>Removed previously available default export, now uses a consistently named <code>simpleGit</code> export.</li> <li>Removed previously deprecated import <code>simple-git/promise</code> (change to using the main <code>simple-git</code> import).</li> <li>Removed legacy <code>gitP</code> export (change to using the main <code>simpleGit</code> export).</li> </ul> <pre lang="typescript"><code>// v3 - previously supported imports import simpleGit from "simple-git"; import { gitP } from "simple-git"; import simpleGit from "simple-git/promise"; const simpleGit = require("simple-git"); <p>// v4 - consolidates to a single supported import import { simpleGit } from "simple-git"; const { simpleGit } = require("simple-git"); </code></pre></p> <ul> <li>Prevents the use of abbreviated long-form <code>git</code> options:</li> </ul> <pre lang="typescript"><code>// v3 - allowed the use of unambiguous long-form options git.raw("clone", "--conf=user.name=me", "..."); <p>// v4 - requires full option names, abbreviated option names will now throw a GitConfigurationError git.raw("fetch", "--config=user.name=me", "..."); </code></pre></p> <ul> <li>Ambient environment variables are filtered before passing into the <code>git</code> child process.</li> </ul> <pre lang="typescript"><code>// v3 </code></pre> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md">simple-git's changelog</a>.</em></p> <blockquote> <h2>4.0.2</h2> <h3>Patch Changes</h3> <ul> <li> <p>68874c2: Add <code>VISUAL</code> environment variable to set of <code>allowUnsafeEditor</code> environment variables.</p> <p>Thanks to <a href="https://github.com/oss-security-shopify"><code>@oss-security-shopify</code></a> for identifying the vulnerability.</p> </li> <li> <p>Updated dependencies [68874c2]</p> <ul> <li><code>@simple-git/argv-parser</code><a href="https://github.com/2"><code>@2</code></a>.0.1</li> </ul> </li> </ul> <h2>4.0.1</h2> <h3>Patch Changes</h3> <ul> <li>365f52d: Prepare package.json before publishing.</li> </ul> <h2>4.0.0</h2> <h3>Major Changes</h3> <ul> <li> <p>98864c6: Major upgrade to v4. In this version:</p> <ul> <li>Removed previously available default export, now uses a consistently named <code>simpleGit</code> export.</li> <li>Removed previously deprecated import <code>simple-git/promise</code> (change to using the main <code>simple-git</code> import).</li> <li>Removed legacy <code>gitP</code> export (change to using the main <code>simpleGit</code> export).</li> </ul> <pre lang="typescript"><code>// v3 - previously supported imports import simpleGit from "simple-git"; import { gitP } from "simple-git"; import simpleGit from "simple-git/promise"; const simpleGit = require("simple-git"); <p>// v4 - consolidates to a single supported import import { simpleGit } from "simple-git"; const { simpleGit } = require("simple-git"); </code></pre></p> <ul> <li>Prevents the use of abbreviated long-form <code>git</code> options:</li> </ul> <pre lang="typescript"><code>// v3 - allowed the use of unambiguous long-form options git.raw("clone", "--conf=user.name=me", "..."); <p>// v4 - requires full option names, abbreviated option names will now throw a GitConfigurationError git.raw("fetch", "--config=user.name=me", "..."); </code></pre></p> <p>Thanks to <a href="https://github.com/anir0y"><code>@anir0y</code></a>, <a href="https://github.com/CFionaBF"><code>@CFionaBF</code></a>, <a href="https://github.com/Leeziao"><code>@Leeziao</code></a>, <a href="https://github.com/internetteletubbie"><code>@internetteletubbie</code></a>, <a href="https://github.com/idisdi"><code>@idisdi</code></a>, <a href="https://github.com/the-vibe-dev"><code>@the-vibe-dev</code></a>,</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/steveukx/git-js/commit/f09081b793daa75e282794e92982efa9000a3514"><code>f09081b</code></a> Version Packages</li> <li><a href="https://github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4"><code>68874c2</code></a> Add <code>VISUAL</code> to tracked environment variables for <code>allowUnsafeEditor</code> (<a href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1201">#1201</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/f26086d0cd649adda54a44f6e20e3e81318c5029"><code>f26086d</code></a> Version Packages</li> <li><a href="https://github.com/steveukx/git-js/commit/365f52d4c8deaf55ac88769ca89ce160e7bb1405"><code>365f52d</code></a> Prepare the main <code>simple-git</code> <code>package.json</code> immediately before publishing.</li> <li><a href="https://github.com/steveukx/git-js/commit/3971917d3c3d65d9935383ed88970a3578cb462d"><code>3971917</code></a> Version Packages</li> <li><a href="https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3"><code>d762810</code></a> Fix/vulnerability rebase exec (<a href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1198">#1198</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/76f308ed445013d8dd973bc515e7815b59426e3e"><code>76f308e</code></a> Pr/1180 (<a href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1195">#1195</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/dfeb11648190b2d82a98c91768ec6e3a65bb401c"><code>dfeb116</code></a> Fix/exec path vulnerability (<a href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1197">#1197</a>)</li> <li><a href="https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7"><code>98864c6</code></a> V4 (<a href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1193">#1193</a>)</li> <li>See full diff in <a href="https://github.com/steveukx/git-js/commits/[email protected]/simple-git">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/apache/superset/network/alerts). </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
