Skip to content

fix(deps): shell-quote critical 脆弱性を override で解消#8

Merged
april418 merged 2 commits into
masterfrom
chore/override-shell-quote
Jun 9, 2026
Merged

fix(deps): shell-quote critical 脆弱性を override で解消#8
april418 merged 2 commits into
masterfrom
chore/override-shell-quote

Conversation

@april418

@april418 april418 commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

advisory GHSA-w7jw-789q-3m8p(shell-quote, critical、2026-06-09 に GitHub Advisory DB 収録)により Security audit が落ちるため、override で >=1.8.4 に固定する。

  • shell-quote 1.8.4 は 2026-05-22 公開=release-age クリア
  • audit exit 0(critical 消失)/ frozen install OK を確認

🤖 Generated with Claude Code

april418 and others added 2 commits June 10, 2026 04:47
advisory GHSA-w7jw-789q-3m8p (shell-quote, critical) を override で >=1.8.4 に固定。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
publish workflow は master push 毎に pnpm publish するため、version 据え置き
だと既存 0.1.0 と衝突して publish が失敗する(#7 マージ後の publish が実際に
失敗済み)。0.1.1 に上げて publish を通す。published 物の内容は同一
(shell-quote override は dev 依存のみで影響なし)。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@april418 april418 merged commit eb9862b into master Jun 9, 2026
2 checks passed
@april418 april418 deleted the chore/override-shell-quote branch June 9, 2026 19:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant