Skip to content

fix(deps): bump shell-quote override past GHSA-pqg4-j6r4-53mv - #91

Merged
aaronjmars merged 1 commit into
mainfrom
fix/shell-quote-override
Oct 10, 2026
Merged

aaronjmars merged 1 commit into
mainfrom
fix/shell-quote-override

Conversation

@Svector-anu

@Svector-anu Svector-anu commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

#64's override pinned shell-quote to ^1.9.0 for an older advisory, but that resolves to 1.10.0 — inside the current critical advisory GHSA-pqg4-j6r4-53mv (1.8.4-1.10.0, CVE-2026-102422), which npm audit flags today.

only reachable through web-ext's firefox-launch chain (devDependency, never ships in dist/chrome or dist/firefox), so exposure is low — but the override doesn't do what it was written for anymore.

bumped to ^1.11.0 (first patched release, 2026-10-06). npm ls now resolves 1.12.0.

verified: npm audit clean on shell-quote, build/validate/test-extension/web-ext lint all pass (same checks #88 used).

PR #64's override pinned shell-quote to ^1.9.0 to clear an older advisory,
but that range resolves to 1.10.0 - squarely inside the critical command-
injection advisory GHSA-pqg4-j6r4-53mv (1.8.4-1.10.0, CVE-2026-102422),
which npm audit flags on this repo today. shell-quote only reaches this
extension through web-ext's Firefox-launch chain (a devDependency), so
exposure is bounded, but the override itself no longer does what it was
written for.

1.11.0 (released 2026-10-06) is the first patched release per the
advisory. Bumped the override there; npm ls now resolves 1.12.0 (current
latest), clear of the vulnerable range.

Verified: npm audit no longer flags shell-quote; npm run build, node
build.js validate, node test-extension.js, and npx web-ext lint
--source-dir=dist/firefox --self-hosted all pass clean (same checks
PR #88 used for the adjacent brace-expansion override bump).
@aaronjmars
aaronjmars merged commit 8f379e2 into main Oct 10, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants