Skip to content

build(deps-dev): bump shell-quote from 1.7.3 to 1.11.0 - #179

Merged
ianmcburnie merged 1 commit into
gh-pagesfrom
dependabot/npm_and_yarn/shell-quote-1.10.0
Sep 29, 2026
Merged

ianmcburnie merged 1 commit into
gh-pagesfrom
dependabot/npm_and_yarn/shell-quote-1.10.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Bumps shell-quote from 1.7.3 to 1.11.0.

Changelog

Sourced from shell-quote's changelog.

v1.11.0 - 2026-09-29

Fixed

Commits

  • [Fix] quote: reject line terminators in tokens after a comment 6002b2e
  • [Fix] parse: preserve text after special shell parameters 81b08a5
  • [Fix] parse: an escaped backslash does not escape the character after it d708019
  • [Fix] quote: preserve ! in arguments that also contain ' ad39927
  • [Fix] parse: treat $_name as a variable name, not $_ followed by text 28f88cd
  • [Fix] quote: preserve empty glob patterns 35c9b97
  • [Fix] quote: escape ~ in glob patterns to prevent shell tilde-expansion 239d49c
  • [Dev Deps] update @ljharb/eslint-config, auto-changelog, eslint, evalmd b1e406e
  • [meta] npmignore some files ebfc308
  • [actions] add permissions 3429b0d
  • [actions] set least-privilege cache-mode 36f2394
  • [Dev Deps] update eslint 6de9a41

v1.10.0 - 2026-07-10

Merged

Commits

  • [Fix] parse: match nested ${...} braces so nested parameter expansion is consumed as one substitution c0842c8
  • [Tests] parse: pin single-quote literalness and unmatched-quote handling a0d03e3
  • [readme] remove the space in js code fences so evalmd evaluates them 2116fa3
  • [Tests] quote: pin conservative escaping of =, @, ^, ,, :, ! (#11) 1c36f3f
  • [readme] document that quote outputs POSIX quoting, not cmd.exe/PowerShell 100e96e
  • [readme] document parse's supported parameter-expansion subset e1c75cd
  • [Fix] parse: a backslash inside single quotes must not escape the closing quote 5d460a3
  • [readme] fix stale example outputs 2de86f5
  • [Tests] quote: pin that a backslash with whitespace is not doubled in single quotes (#14) 190e236
  • [readme] quote: use output verbatim; do not re-quote it (#11) 1b36468
  • [Refactor] parse: fix swapped SINGLE_QUOTE/DOUBLE_QUOTE variable names 801af5c
  • [types] fix an error TS v6 ignores but v7 fails on 59bbf8b
  • [Dev Deps] update @arethetypeswrong/cli, evalmd a04d475
  • [Dev Deps] update @arethetypeswrong/ci, eslint d390f9a
  • [Tests] quote: the tilde test escapes every ~, not just a leading one (#9) 617d119

v1.9.0 - 2026-06-24

Commits

... (truncated)

Commits
  • 88241f8 v1.11.0
  • ebfc308 [meta] npmignore some files
  • c4385ec [Refactor] quote: drop a replace that can never match in the single-quote b...
  • e455649 [New] parse: support bash ANSI-C quoting ($'...')
  • d708019 [Fix] parse: an escaped backslash does not escape the character after it
  • b1e406e [Dev Deps] update @ljharb/eslint-config, auto-changelog, eslint, evalmd
  • ad39927 [Fix] quote: preserve ! in arguments that also contain '
  • 6002b2e [Fix] quote: reject line terminators in tokens after a comment
  • 36f2394 [actions] set least-privilege cache-mode
  • 28f88cd [Fix] parse: treat $_name as a variable name, not $_ followed by text
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by ljharb, a new releaser for shell-quote since your current version.

Install script changes

This version adds prepublish script that runs during installation. Review the package contents before updating.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 25, 2026
@ianmcburnie

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.7.3 to 1.11.0.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.7.3...v1.11.0)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.10.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps-dev): bump shell-quote from 1.7.3 to 1.10.0 build(deps-dev): bump shell-quote from 1.7.3 to 1.11.0 Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/shell-quote-1.10.0 branch from 8f40862 to cf34a44 Compare September 29, 2026 21:50

@ianmcburnie ianmcburnie left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security patch, lock file only. CI passing.

@ianmcburnie
ianmcburnie merged commit 6a57c57 into gh-pages Sep 29, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/shell-quote-1.10.0 branch September 29, 2026 23:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant