Skip to content

Pin patched shell-quote#717

Merged
natew merged 1 commit into
mainfrom
fix/shell-quote-audit
Jun 11, 2026
Merged

Pin patched shell-quote#717
natew merged 1 commit into
mainfrom
fix/shell-quote-audit

Conversation

@natew

@natew natew commented Jun 11, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • pin shell-quote to 1.8.4 via the existing root resolutions block
  • regenerate bun.lock so transitive consumers resolve outside GHSA-w7jw-789q-3m8p

Validation

  • bun install --frozen-lockfile
  • bun run build
  • bun audit --audit-level high --ignore GHSA-3ppc-4f35-3m26
  • bun run check
  • bun run lint
  • bun run typecheck

Note: I also tried a local full bun run test before switching to PR-based iteration; it failed in test-loaders due a dev-server/browser-context issue unrelated to this lockfile audit change. Per follow-up direction, I stopped full-suite local iteration and will use branch CI for the broader suite.

@railway-app railway-app Bot temporarily deployed to onestack.dev / one-pr-717 June 11, 2026 17:46 Destroyed
@railway-app

railway-app Bot commented Jun 11, 2026

Copy link
Copy Markdown

🚅 Deployed to the one-pr-717 environment in onestack.dev

Service Status Web Updated (UTC)
one ✅ Success (View Logs) Web Jun 11, 2026 at 5:49 pm

@natew natew added this pull request to the merge queue Jun 11, 2026
Merged via the queue into main with commit 8e2cba1 Jun 11, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant