dependabot[bot] opened a new pull request, #45097:
URL: https://github.com/apache/superset/pull/45097

   Bumps the security group with 3 updates in the /superset-frontend directory: 
[@simple-git/argv-parser](https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser),
 [shell-quote](https://github.com/ljharb/shell-quote) and 
[simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git).
   
   Updates `@simple-git/argv-parser` from 1.1.1 to 2.0.1
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/steveukx/git-js/releases";>@​simple-git/argv-parser's 
releases</a>.</em></p>
   <blockquote>
   <h2><code>@​simple-git/argv-parser</code><a 
href="https://github.com/2";><code>@​2</code></a>.0.1</h2>
   <h3>Patch Changes</h3>
   <ul>
   <li>
   <p>68874c2: Add <code>VISUAL</code> environment variable to set of 
<code>allowUnsafeEditor</code> environment variables.</p>
   <p>Thanks to <a 
href="https://github.com/oss-security-shopify";><code>@​oss-security-shopify</code></a>
 for identifying the vulnerability.</p>
   </li>
   </ul>
   <h2><code>@​simple-git/argv-parser</code><a 
href="https://github.com/2";><code>@​2</code></a>.0.0</h2>
   <h3>Major Changes</h3>
   <ul>
   <li>
   <p>98864c6: Updates ahead of the v4 release for <code>simple-git</code>.</p>
   <ul>
   <li>
   <p>Adds support for TypeScript declaration maps</p>
   </li>
   <li>
   <p>Exports the <code>isGitEnvKey</code> helper to detect whether an 
environment variable can be used to configure a <code>git</code> operation</p>
   </li>
   <li>
   <p>Adds detection for <code>includeIf.&lt;condition&gt;.path</code>, thanks 
to <a 
href="https://github.com/NotAFlightRisk";><code>@​NotAFlightRisk</code></a> for 
identifying the vulnerability</p>
   </li>
   </ul>
   </li>
   </ul>
   <h3>Patch Changes</h3>
   <ul>
   <li>
   <p>c427fba: Additional argument parser vulnerability checks:</p>
   <ul>
   <li>Thanks to <a 
href="https://github.com/mrillicit";><code>@​mrillicit</code></a> for 
identifying <code>include.path</code>, <code>filter.*.process</code></li>
   <li>Thanks to <a 
href="https://github.com/tejas619";><code>@​tejas619</code></a> for identifying 
<code>url.*.insteadOf</code></li>
   </ul>
   </li>
   <li>
   <p>1bb14df: Vulnerability detection expanded to include 
<code>pager.*</code>, <code>uploadpack.packObjectsHook</code>, 
<code>difftool.*.cmd</code> and use of the <code>GIT_CONFIG_PARAMETERS</code> 
environment variable</p>
   <p>Thanks to <a 
href="https://github.com/threalwinky";><code>@​threalwinky</code></a> and <a 
href="https://github.com/nuc13us";><code>@​nuc13us</code></a> for 
identifying.</p>
   </li>
   <li>
   <p>dfeb116: Vulnerability detection expanded to cover configuration 
delivered through path-taking global options, where
   the dangerous value is a file on disk rather than a token 
<code>simple-git</code> can inspect:</p>
   <ul>
   <li><code>--exec-path</code> names the directory <code>git</code> loads 
built-in commands and remote helpers from, and is blocked
   under the new <code>allowUnsafeExec</code> category along with the 
<code>GIT_EXEC_PATH</code> environment variable (previously
   grouped under <code>allowUnsafeConfigPaths</code>)</li>
   <li><code>--git-dir</code>, <code>--work-tree</code> and <code>-C</code> 
cause <code>git</code> to read the configuration of the repository they name, 
and
   are blocked under <code>allowUnsafeConfigPaths</code></li>
   </ul>
   <p>These options are only detected when supplied before the git sub-command 
and with a value - used as getters
   (<code>git.raw('rev-parse', '--git-dir')</code>) or as task options 
(<code>git.raw('commit', '-C', 'HEAD~1')</code>) they are
   unaffected.</p>
   </li>
   <li>
   <p>d762810: Add <code>allowUnsafeExec</code> detection to <code>rebase 
-x</code> and <code>rebase --exec</code>.</p>
   <p>Thanks to <a 
href="https://github.com/gdegrange";><code>@​gdegrange</code></a> for the 
vulnerability report.</p>
   </li>
   <li>
   <p>d762810: Add <code>allowUnsafeCommandBinaries</code> detection to 
configuring <code>trailer.&lt;token&gt;.cmd</code> and 
<code>trailer.&lt;token&gt;.command</code>.</p>
   <p>Thanks to <a 
href="https://github.com/sec-reex";><code>@​sec-reex</code></a> for the 
vulnerability report.</p>
   </li>
   <li>
   <p>Updated dependencies [98864c6]</p>
   <ul>
   <li><code>@​simple-git/args-pathspec</code><a 
href="https://github.com/1";><code>@​1</code></a>.0.4</li>
   </ul>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/steveukx/git-js/blob/main/packages/argv-parser/CHANGELOG.md";>@​simple-git/argv-parser's
 changelog</a>.</em></p>
   <blockquote>
   <h2>2.0.1</h2>
   <h3>Patch Changes</h3>
   <ul>
   <li>
   <p>68874c2: Add <code>VISUAL</code> environment variable to set of 
<code>allowUnsafeEditor</code> environment variables.</p>
   <p>Thanks to <a 
href="https://github.com/oss-security-shopify";><code>@​oss-security-shopify</code></a>
 for identifying the vulnerability.</p>
   </li>
   </ul>
   <h2>2.0.0</h2>
   <h3>Major Changes</h3>
   <ul>
   <li>
   <p>98864c6: Updates ahead of the v4 release for <code>simple-git</code>.</p>
   <ul>
   <li>
   <p>Adds support for TypeScript declaration maps</p>
   </li>
   <li>
   <p>Exports the <code>isGitEnvKey</code> helper to detect whether an 
environment variable can be used to configure a <code>git</code> operation</p>
   </li>
   <li>
   <p>Adds detection for <code>includeIf.&lt;condition&gt;.path</code>, thanks 
to <a href="https://github.com/bhaswanthc";><code>@​bhaswanthc</code></a>, <a 
href="https://github.com/NotAFlightRisk";><code>@​NotAFlightRisk</code></a>, <a 
href="https://github.com/oss-security-shopify";><code>@​oss-security-shopify</code></a>
 for identifying the vulnerability</p>
   </li>
   </ul>
   </li>
   </ul>
   <h3>Patch Changes</h3>
   <ul>
   <li>
   <p>c427fba: Additional argument parser vulnerability checks:</p>
   <ul>
   <li>Thanks to <a 
href="https://github.com/bhaswanthc";><code>@​bhaswanthc</code></a>, <a 
href="https://github.com/mrillicit";><code>@​mrillicit</code></a>, <a 
href="https://github.com/avrlab233";><code>@​avrlab233</code></a>, <a 
href="https://github.com/avrlab233";><code>@​avrlab233</code></a> for 
identifying <code>include.path</code>, <code>filter.*.process</code></li>
   <li>Thanks to <a 
href="https://github.com/tejas619";><code>@​tejas619</code></a> for identifying 
<code>url.*.insteadOf</code></li>
   </ul>
   </li>
   <li>
   <p>1bb14df: Vulnerability detection expanded to include 
<code>pager.*</code>, <code>uploadpack.packObjectsHook</code>, 
<code>difftool.*.cmd</code> and use of the <code>GIT_CONFIG_PARAMETERS</code> 
environment variable</p>
   <p>Thanks to <a 
href="https://github.com/threalwinky";><code>@​threalwinky</code></a> and <a 
href="https://github.com/nuc13us";><code>@​nuc13us</code></a> for 
identifying.</p>
   </li>
   <li>
   <p>dfeb116: Vulnerability detection expanded to cover configuration 
delivered through path-taking global options, where
   the dangerous value is a file on disk rather than a token 
<code>simple-git</code> can inspect:</p>
   <ul>
   <li><code>--exec-path</code> names the directory <code>git</code> loads 
built-in commands and remote helpers from, and is blocked
   under the new <code>allowUnsafeExec</code> category along with the 
<code>GIT_EXEC_PATH</code> environment variable (previously
   grouped under <code>allowUnsafeConfigPaths</code>)</li>
   <li><code>--git-dir</code>, <code>--work-tree</code> and <code>-C</code> 
cause <code>git</code> to read the configuration of the repository they name, 
and
   are blocked under <code>allowUnsafeConfigPaths</code></li>
   </ul>
   <p>These options are only detected when supplied before the git sub-command 
and with a value - used as getters
   (<code>git.raw('rev-parse', '--git-dir')</code>) or as task options 
(<code>git.raw('commit', '-C', 'HEAD~1')</code>) they are
   unaffected.</p>
   </li>
   <li>
   <p>d762810: Add <code>allowUnsafeExec</code> detection to <code>rebase 
-x</code> and <code>rebase --exec</code>.</p>
   <p>Thanks to <a 
href="https://github.com/gdegrange";><code>@​gdegrange</code></a> for the 
vulnerability report.</p>
   </li>
   <li>
   <p>d762810: Add <code>allowUnsafeCommandBinaries</code> detection to 
configuring <code>trailer.&lt;token&gt;.cmd</code> and 
<code>trailer.&lt;token&gt;.command</code>.</p>
   <p>Thanks to <a 
href="https://github.com/sec-reex";><code>@​sec-reex</code></a> for the 
vulnerability report.</p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/steveukx/git-js/commit/f09081b793daa75e282794e92982efa9000a3514";><code>f09081b</code></a>
 Version Packages</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4";><code>68874c2</code></a>
 Add <code>VISUAL</code> to tracked environment variables for 
<code>allowUnsafeEditor</code> (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1201";>#1201</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/3971917d3c3d65d9935383ed88970a3578cb462d";><code>3971917</code></a>
 Version Packages</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3";><code>d762810</code></a>
 Fix/vulnerability rebase exec (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1198";>#1198</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/dfeb11648190b2d82a98c91768ec6e3a65bb401c";><code>dfeb116</code></a>
 Fix/exec path vulnerability (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1197";>#1197</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7";><code>98864c6</code></a>
 V4 (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1193";>#1193</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/c427fbad33f1f2b11341f1cf852eedecbb106400";><code>c427fba</code></a>
 Argument parser vulnerability checks (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1167";>#1167</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/1bb14df0595794a9353d28ccdaeeb06c0b9bf2a5";><code>1bb14df</code></a>
 Merge pull request <a 
href="https://github.com/steveukx/git-js/tree/HEAD/packages/argv-parser/issues/1163";>#1163</a>
 from steveukx/claude/add-git-config-vulnerabilities-...</li>
   <li>See full diff in <a 
href="https://github.com/steveukx/git-js/commits/@simple-git/[email protected]/packages/argv-parser";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `shell-quote` from 1.9.0 to 1.12.0
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md";>shell-quote's
 changelog</a>.</em></p>
   <blockquote>
   <h2><a 
href="https://github.com/ljharb/shell-quote/compare/v1.11.0...v1.12.0";>v1.12.0</a>
 - 2026-10-02</h2>
   <h3>Fixed</h3>
   <ul>
   <li>[New] <code>parse</code>: support here-documents 
(<code>&amp;lt;&amp;lt;</code>) <a 
href="https://redirect.github.com/ljharb/shell-quote/issues/31";><code>[#31](https://github.com/ljharb/shell-quote/issues/31)</code></a></li>
   </ul>
   <h3>Commits</h3>
   <ul>
   <li>[New] <code>parse</code>: support tab-stripping here-documents 
(<code>&amp;lt;&amp;lt;-</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/dbfac376d4065d37539d3abdb5e76847f93797d3";><code>dbfac37</code></a></li>
   <li>[New] <code>parse</code>: support output process substitution 
(<code>&amp;gt;(</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/20533154bb57809c80f55318b8493aef49505f4e";><code>2053315</code></a></li>
   <li>[New] <code>parse</code>: support the <code>case</code> test-next 
terminator (<code>;;&amp;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/7d688b9bec1917a22cccd4d4c887128a9c66e8a0";><code>7d688b9</code></a></li>
   <li>[New] <code>parse</code>: support the <code>case</code> fall-through 
terminator (<code>;&amp;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/f27010ed04bcd925795b350afb1c49e36bbd1ba3";><code>f27010e</code></a></li>
   <li>[New] <code>parse</code>: support redirecting output despite 
<code>noclobber</code> (<code>&amp;gt;|</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/b78d19c14da6356cc12c46b3478203247ab8a295";><code>b78d19c</code></a></li>
   <li>[New] <code>parse</code>: support opening a file for reading and writing 
(<code>&amp;lt;&amp;gt;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/21cc333eb0ce5bf094f595b7fdc01b3447ffd4b0";><code>21cc333</code></a></li>
   <li>[New] <code>parse</code>: support redirecting stdout and stderr 
(<code>&amp;&amp;gt;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/6ad6cd215f89adcc29dd601e085fa54083c2f911";><code>6ad6cd2</code></a></li>
   <li>[New] <code>parse</code>: support appending stdout and stderr 
(<code>&amp;&amp;gt;&amp;gt;</code>) <a 
href="https://github.com/ljharb/shell-quote/commit/90cde9cfd8af30fcb65e9fd2cb2f9e181d3f103b";><code>90cde9c</code></a></li>
   <li>[Dev Deps] update <code>@ljharb/eslint-config</code> <a 
href="https://github.com/ljharb/shell-quote/commit/3a7b4ae3960c3ff4413932e276c5b0ecb3a2b456";><code>3a7b4ae</code></a></li>
   </ul>
   <h2><a 
href="https://github.com/ljharb/shell-quote/compare/v1.10.0...v1.11.0";>v1.11.0</a>
 - 2026-09-29</h2>
   <h3>Fixed</h3>
   <ul>
   <li>[Refactor] <code>quote</code>: drop a replace that can never match in 
the single-quote branch <a 
href="https://redirect.github.com/ljharb/shell-quote/issues/15";><code>[#15](https://github.com/ljharb/shell-quote/issues/15)</code></a></li>
   <li>[New] <code>parse</code>: support bash ANSI-C quoting 
(<code>$'...'</code>) <a 
href="https://redirect.github.com/ljharb/shell-quote/issues/32";><code>[#32](https://github.com/ljharb/shell-quote/issues/32)</code></a></li>
   </ul>
   <h3>Commits</h3>
   <ul>
   <li>[Fix] <code>quote</code>: reject line terminators in tokens after a 
<code>comment</code> <a 
href="https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc";><code>6002b2e</code></a></li>
   <li>[Fix] <code>parse</code>: preserve text after special shell parameters 
<a 
href="https://github.com/ljharb/shell-quote/commit/81b08a532e898a3627f9305fa13d643ffa82a9d3";><code>81b08a5</code></a></li>
   <li>[Fix] <code>parse</code>: an escaped backslash does not escape the 
character after it <a 
href="https://github.com/ljharb/shell-quote/commit/d708019016ce26e1a8a05af4b296e35ef8095c9e";><code>d708019</code></a></li>
   <li>[Fix] <code>quote</code>: preserve <code>!</code> in arguments that also 
contain <code>'</code> <a 
href="https://github.com/ljharb/shell-quote/commit/ad399279dbbbd086967d2040c1558b4888b074e6";><code>ad39927</code></a></li>
   <li>[Fix] <code>parse</code>: treat <code>$_name</code> as a variable name, 
not <code>$_</code> followed by text <a 
href="https://github.com/ljharb/shell-quote/commit/28f88cd422ae4046aca9556c4b74ca90b0ea7f6b";><code>28f88cd</code></a></li>
   <li>[Fix] <code>quote</code>: preserve empty glob patterns <a 
href="https://github.com/ljharb/shell-quote/commit/35c9b97a744211091b772f145bef0b6a5562b68e";><code>35c9b97</code></a></li>
   <li>[Fix] <code>quote</code>: escape <code>~</code> in glob patterns to 
prevent shell tilde-expansion <a 
href="https://github.com/ljharb/shell-quote/commit/239d49cae6d231436ea4e676850037018c790c49";><code>239d49c</code></a></li>
   <li>[Dev Deps] update <code>@ljharb/eslint-config</code>, 
<code>auto-changelog</code>, <code>eslint</code>, <code>evalmd</code> <a 
href="https://github.com/ljharb/shell-quote/commit/b1e406ed4287a134cc649db47b9a59e21b304472";><code>b1e406e</code></a></li>
   <li>[meta] npmignore some files <a 
href="https://github.com/ljharb/shell-quote/commit/ebfc3080cf5f68db5edfddfba49dc8c4ccacd2d5";><code>ebfc308</code></a></li>
   <li>[actions] add permissions <a 
href="https://github.com/ljharb/shell-quote/commit/3429b0d349211786765e9e68478e029d96ad44e9";><code>3429b0d</code></a></li>
   <li>[actions] set least-privilege <code>cache-mode</code> <a 
href="https://github.com/ljharb/shell-quote/commit/36f23944db50dd3f0df4da9c7cba0bb63df05f64";><code>36f2394</code></a></li>
   <li>[Dev Deps] update <code>eslint</code> <a 
href="https://github.com/ljharb/shell-quote/commit/6de9a41ecfc4fe9f9546df08866c8ead039f8909";><code>6de9a41</code></a></li>
   </ul>
   <h2><a 
href="https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.10.0";>v1.10.0</a>
 - 2026-07-10</h2>
   <h3>Merged</h3>
   <ul>
   <li>[New] <code>parse</code>: add opt-in <code>splitUnquoted</code> option 
for shell field-splitting of unquoted expansions <a 
href="https://redirect.github.com/ljharb/shell-quote/pull/1";><code>[#1](https://github.com/ljharb/shell-quote/issues/1)</code></a></li>
   </ul>
   <h3>Commits</h3>
   <ul>
   <li>[Fix] <code>parse</code>: match nested <code>${...}</code> braces so 
nested parameter expansion is consumed as one substitution <a 
href="https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c";><code>c0842c8</code></a></li>
   <li>[Tests] <code>parse</code>: pin single-quote literalness and 
unmatched-quote handling <a 
href="https://github.com/ljharb/shell-quote/commit/a0d03e35c8ede24016502c4433b8f5d6b3100a62";><code>a0d03e3</code></a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/6ecb8aa618ba6dc6c3b087fce6d7660320d2adeb";><code>6ecb8aa</code></a>
 v1.12.0</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/3a7b4ae3960c3ff4413932e276c5b0ecb3a2b456";><code>3a7b4ae</code></a>
 [Dev Deps] update <code>@ljharb/eslint-config</code></li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/7d688b9bec1917a22cccd4d4c887128a9c66e8a0";><code>7d688b9</code></a>
 [New] <code>parse</code>: support the <code>case</code> test-next terminator 
(<code>;;&amp;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/f27010ed04bcd925795b350afb1c49e36bbd1ba3";><code>f27010e</code></a>
 [New] <code>parse</code>: support the <code>case</code> fall-through 
terminator (<code>;&amp;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/90cde9cfd8af30fcb65e9fd2cb2f9e181d3f103b";><code>90cde9c</code></a>
 [New] <code>parse</code>: support appending stdout and stderr 
(<code>&amp;&gt;&gt;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/6ad6cd215f89adcc29dd601e085fa54083c2f911";><code>6ad6cd2</code></a>
 [New] <code>parse</code>: support redirecting stdout and stderr 
(<code>&amp;&gt;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/20533154bb57809c80f55318b8493aef49505f4e";><code>2053315</code></a>
 [New] <code>parse</code>: support output process substitution 
(<code>&gt;(</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/b78d19c14da6356cc12c46b3478203247ab8a295";><code>b78d19c</code></a>
 [New] <code>parse</code>: support redirecting output despite 
<code>noclobber</code> (<code>&gt;|</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/21cc333eb0ce5bf094f595b7fdc01b3447ffd4b0";><code>21cc333</code></a>
 [New] <code>parse</code>: support opening a file for reading and writing 
(<code>\&lt;&gt;</code>)</li>
   <li><a 
href="https://github.com/ljharb/shell-quote/commit/dbfac376d4065d37539d3abdb5e76847f93797d3";><code>dbfac37</code></a>
 [New] <code>parse</code>: support tab-stripping here-documents 
(<code>&lt;&lt;-</code>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.12.0";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `simple-git` from 3.36.0 to 4.0.2
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/steveukx/git-js/releases";>simple-git's 
releases</a>.</em></p>
   <blockquote>
   <h2>[email protected]</h2>
   <h3>Patch Changes</h3>
   <ul>
   <li>
   <p>68874c2: Add <code>VISUAL</code> environment variable to set of 
<code>allowUnsafeEditor</code> environment variables.</p>
   <p>Thanks to <a 
href="https://github.com/oss-security-shopify";><code>@​oss-security-shopify</code></a>
 for identifying the vulnerability.</p>
   </li>
   <li>
   <p>Updated dependencies [68874c2]</p>
   <ul>
   <li><code>@​simple-git/argv-parser</code><a 
href="https://github.com/2";><code>@​2</code></a>.0.1</li>
   </ul>
   </li>
   </ul>
   <h2>[email protected]</h2>
   <h3>Patch Changes</h3>
   <ul>
   <li>365f52d: Prepare package.json before publishing.</li>
   </ul>
   <h2>[email protected]</h2>
   <h3>Major Changes</h3>
   <ul>
   <li>
   <p>98864c6: Major upgrade to v4. In this version:</p>
   <ul>
   <li>Removed previously available default export, now uses a consistently 
named <code>simpleGit</code> export.</li>
   <li>Removed previously deprecated import <code>simple-git/promise</code> 
(change to using the main <code>simple-git</code> import).</li>
   <li>Removed legacy <code>gitP</code> export (change to using the main 
<code>simpleGit</code> export).</li>
   </ul>
   <pre lang="typescript"><code>// v3 - previously supported imports
   import simpleGit from &quot;simple-git&quot;;
   import { gitP } from &quot;simple-git&quot;;
   import simpleGit from &quot;simple-git/promise&quot;;
   const simpleGit = require(&quot;simple-git&quot;);
   <p>// v4 - consolidates to a single supported import
   import { simpleGit } from &quot;simple-git&quot;;
   const { simpleGit } = require(&quot;simple-git&quot;);
   </code></pre></p>
   <ul>
   <li>Prevents the use of abbreviated long-form <code>git</code> options:</li>
   </ul>
   <pre lang="typescript"><code>// v3 - allowed the use of unambiguous 
long-form options
   git.raw(&quot;clone&quot;, &quot;--conf=user.name=me&quot;, &quot;...&quot;);
   <p>// v4 - requires full option names, abbreviated option names will now 
throw a GitConfigurationError
   git.raw(&quot;fetch&quot;, &quot;--config=user.name=me&quot;, 
&quot;...&quot;);
   </code></pre></p>
   <ul>
   <li>Ambient environment variables are filtered before passing into the 
<code>git</code> child process.</li>
   </ul>
   <pre lang="typescript"><code>// v3
   </code></pre>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md";>simple-git's
 changelog</a>.</em></p>
   <blockquote>
   <h2>4.0.2</h2>
   <h3>Patch Changes</h3>
   <ul>
   <li>
   <p>68874c2: Add <code>VISUAL</code> environment variable to set of 
<code>allowUnsafeEditor</code> environment variables.</p>
   <p>Thanks to <a 
href="https://github.com/oss-security-shopify";><code>@​oss-security-shopify</code></a>
 for identifying the vulnerability.</p>
   </li>
   <li>
   <p>Updated dependencies [68874c2]</p>
   <ul>
   <li><code>@​simple-git/argv-parser</code><a 
href="https://github.com/2";><code>@​2</code></a>.0.1</li>
   </ul>
   </li>
   </ul>
   <h2>4.0.1</h2>
   <h3>Patch Changes</h3>
   <ul>
   <li>365f52d: Prepare package.json before publishing.</li>
   </ul>
   <h2>4.0.0</h2>
   <h3>Major Changes</h3>
   <ul>
   <li>
   <p>98864c6: Major upgrade to v4. In this version:</p>
   <ul>
   <li>Removed previously available default export, now uses a consistently 
named <code>simpleGit</code> export.</li>
   <li>Removed previously deprecated import <code>simple-git/promise</code> 
(change to using the main <code>simple-git</code> import).</li>
   <li>Removed legacy <code>gitP</code> export (change to using the main 
<code>simpleGit</code> export).</li>
   </ul>
   <pre lang="typescript"><code>// v3 - previously supported imports
   import simpleGit from &quot;simple-git&quot;;
   import { gitP } from &quot;simple-git&quot;;
   import simpleGit from &quot;simple-git/promise&quot;;
   const simpleGit = require(&quot;simple-git&quot;);
   <p>// v4 - consolidates to a single supported import
   import { simpleGit } from &quot;simple-git&quot;;
   const { simpleGit } = require(&quot;simple-git&quot;);
   </code></pre></p>
   <ul>
   <li>Prevents the use of abbreviated long-form <code>git</code> options:</li>
   </ul>
   <pre lang="typescript"><code>// v3 - allowed the use of unambiguous 
long-form options
   git.raw(&quot;clone&quot;, &quot;--conf=user.name=me&quot;, &quot;...&quot;);
   <p>// v4 - requires full option names, abbreviated option names will now 
throw a GitConfigurationError
   git.raw(&quot;fetch&quot;, &quot;--config=user.name=me&quot;, 
&quot;...&quot;);
   </code></pre></p>
   <p>Thanks to <a href="https://github.com/anir0y";><code>@​anir0y</code></a>, 
<a href="https://github.com/CFionaBF";><code>@​CFionaBF</code></a>, <a 
href="https://github.com/Leeziao";><code>@​Leeziao</code></a>, <a 
href="https://github.com/internetteletubbie";><code>@​internetteletubbie</code></a>,
 <a href="https://github.com/idisdi";><code>@​idisdi</code></a>, <a 
href="https://github.com/the-vibe-dev";><code>@​the-vibe-dev</code></a>,</p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/steveukx/git-js/commit/f09081b793daa75e282794e92982efa9000a3514";><code>f09081b</code></a>
 Version Packages</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4";><code>68874c2</code></a>
 Add <code>VISUAL</code> to tracked environment variables for 
<code>allowUnsafeEditor</code> (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1201";>#1201</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/f26086d0cd649adda54a44f6e20e3e81318c5029";><code>f26086d</code></a>
 Version Packages</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/365f52d4c8deaf55ac88769ca89ce160e7bb1405";><code>365f52d</code></a>
 Prepare the main <code>simple-git</code> <code>package.json</code> immediately 
before publishing.</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/3971917d3c3d65d9935383ed88970a3578cb462d";><code>3971917</code></a>
 Version Packages</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3";><code>d762810</code></a>
 Fix/vulnerability rebase exec (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1198";>#1198</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/76f308ed445013d8dd973bc515e7815b59426e3e";><code>76f308e</code></a>
 Pr/1180 (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1195";>#1195</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/dfeb11648190b2d82a98c91768ec6e3a65bb401c";><code>dfeb116</code></a>
 Fix/exec path vulnerability (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1197";>#1197</a>)</li>
   <li><a 
href="https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7";><code>98864c6</code></a>
 V4 (<a 
href="https://github.com/steveukx/git-js/tree/HEAD/simple-git/issues/1193";>#1193</a>)</li>
   <li>See full diff in <a 
href="https://github.com/steveukx/git-js/commits/[email protected]/simple-git";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore <dependency name> major version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
major version (unless you unignore this specific dependency's major version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name> minor version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
minor version (unless you unignore this specific dependency's minor version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name>` will close this group update PR and 
stop Dependabot creating any more for the specific dependency (unless you 
unignore this specific dependency or upgrade to it yourself)
   - `@dependabot unignore <dependency name>` will remove all of the ignore 
conditions of the specified dependency
   - `@dependabot unignore <dependency name> <ignore condition>` will remove 
the ignore condition of the specified dependency and ignore conditions
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/superset/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to