Skip to content

Commit

Permalink
chore(deps): bump shell-quote from 1.6.1 to 1.8.0 (#1725)
Browse files Browse the repository at this point in the history
Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.6.1 to
1.8.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md">shell-quote's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/ljharb/shell-quote/compare/v1.7.4...v1.8.0">v1.8.0</a>
- 2023-01-30</h2>
<h3>Commits</h3>
<ul>
<li>[New] extract <code>parse</code> and <code>quote</code> to their own
deep imports <a
href="https://github.com/ljharb/shell-quote/commit/553fdfc32cc41b4c2f77e061b6957703958ca575"><code>553fdfc</code></a></li>
<li>[Tests] add <code>nyc</code> coverage <a
href="https://github.com/ljharb/shell-quote/commit/fd7ddcdd84bfef064c6d9a06b055a95531b26897"><code>fd7ddcd</code></a></li>
<li>[New] Add support for here strings
(<code>&amp;lt;&amp;lt;&amp;lt;</code>) <a
href="https://github.com/ljharb/shell-quote/commit/9802fb37c7946e18c672b81122520dc296bde271"><code>9802fb3</code></a></li>
<li>[New] <code>parse</code>: Add syntax support for duplicating input
file descriptors <a
href="https://github.com/ljharb/shell-quote/commit/216b19894f76b14d164c4c5a68f05a51b06336c4"><code>216b198</code></a></li>
<li>[Dev Deps] update <code>@ljharb/eslint-config</code>,
<code>aud</code>, <code>tape</code> <a
href="https://github.com/ljharb/shell-quote/commit/85f8e31dd80e1dde63d58204b653e497a53857e6"><code>85f8e31</code></a></li>
<li>[Tests] add <code>evalmd</code> <a
href="https://github.com/ljharb/shell-quote/commit/c5549fcd82d70046bdc2b1c34184ae9f9d0191f9"><code>c5549fc</code></a></li>
<li>[actions] update checkout action <a
href="https://github.com/ljharb/shell-quote/commit/62e9b4958cfa2f9009b7069076612fe33528c1fb"><code>62e9b49</code></a></li>
</ul>
<h2><a
href="https://github.com/ljharb/shell-quote/compare/1.7.3...v1.7.4">v1.7.4</a>
- 2022-10-12</h2>
<h3>Merged</h3>
<ul>
<li>Add node_modules to .gitignore <a
href="https://github-redirect.dependabot.com/ljharb/shell-quote/pull/48"><code>[#48](https://github.com/ljharb/shell-quote/issues/48)</code></a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[eslint] fix indentation and whitespace <a
href="https://github.com/ljharb/shell-quote/commit/aaa9d1f65bf3445e6af1efaa4a8f8c13a21aa593"><code>aaa9d1f</code></a></li>
<li>[eslint] additional cleanup <a
href="https://github.com/ljharb/shell-quote/commit/397cb628f3d96e4e47763147c0d6074997a13880"><code>397cb62</code></a></li>
<li>[meta] add <code>auto-changelog</code> <a
href="https://github.com/ljharb/shell-quote/commit/497fca509af3b7d6daaba459bad1f45ac0af3ff1"><code>497fca5</code></a></li>
<li>[actions] add reusable workflows <a
href="https://github.com/ljharb/shell-quote/commit/4763c36274c5881a2d141ce9f2b17b7d1d95e8cd"><code>4763c36</code></a></li>
<li>[eslint] add eslint <a
href="https://github.com/ljharb/shell-quote/commit/6ee1437df1b10a79bdf2aaa04f2bacc9f420dc15"><code>6ee1437</code></a></li>
<li>[readme] rename, add badges <a
href="https://github.com/ljharb/shell-quote/commit/7eb513483d931602452ec572ed456714148acd2b"><code>7eb5134</code></a></li>
<li>[meta] update URLs <a
href="https://github.com/ljharb/shell-quote/commit/67381b61fa95e57819333463f491428747893186"><code>67381b6</code></a></li>
<li>[meta] create FUNDING.yml; add <code>funding</code> in package.json
<a
href="https://github.com/ljharb/shell-quote/commit/86415722d875578adf1f95f9e649ba42c805bc32"><code>8641572</code></a></li>
<li>[meta] use <code>npmignore</code> to autogenerate an npmignore file
<a
href="https://github.com/ljharb/shell-quote/commit/2e2007a393f90bf079fc556a921120b3508c4fc3"><code>2e2007a</code></a></li>
<li>Only apps should have lockfiles <a
href="https://github.com/ljharb/shell-quote/commit/f97411ef4d2f183200fc8a28beca9faf9b08a640"><code>f97411e</code></a></li>
<li>[Dev Deps] update <code>tape</code> <a
href="https://github.com/ljharb/shell-quote/commit/051f60857ad5035280208abdc348bf5ba42a6254"><code>051f608</code></a></li>
<li>[meta] add <code>safe-publish-latest</code> <a
href="https://github.com/ljharb/shell-quote/commit/18cadf95357392fcd78ea8619956fd41eed62649"><code>18cadf9</code></a></li>
<li>[Tests] add <code>aud</code> in <code>posttest</code> <a
href="https://github.com/ljharb/shell-quote/commit/dc1cc12b956ccd93d58aaaad263bee7d50576d27"><code>dc1cc12</code></a></li>
</ul>
<!-- raw HTML omitted -->
<h2>1.7.3</h2>
<ul>
<li>Fix a security issue where the regex for windows drive letters
allowed some shell meta-characters
to escape the quoting rules. (CVE-2021-42740)</li>
</ul>
<h2>1.7.2</h2>
<ul>
<li>Fix a regression introduced in 1.6.3. This reverts the Windows path
quoting fix. (<a
href="https://github.com/ljharb/shell-quote/commit/144e1c20cd57549a414c827fb3032e60b7b8721c">144e1c2</a>)</li>
</ul>
<h2>1.7.1</h2>
<ul>
<li>Fix <code>$</code> being removed when not part of an environment
variable name. (<a
href="https://github.com/Admin"><code>@​Adman</code></a> in <a
href="https://github-redirect.dependabot.com/ljharb/shell-quote/pull/32">#32</a>)</li>
</ul>
<h2>1.7.0</h2>
<ul>
<li>Add support for parsing <code>&gt;&gt;</code> and
<code>&gt;&amp;</code> redirection operators. (<a
href="https://github.com/forivall"><code>@​forivall</code></a> in <a
href="https://github-redirect.dependabot.com/ljharb/shell-quote/pull/16">#16</a>)</li>
<li>Add support for parsing <code>&lt;(</code> process substitution
operator. (<a
href="https://github.com/cuonglm"><code>@​cuonglm</code></a> in <a
href="https://github-redirect.dependabot.com/ljharb/shell-quote/pull/15">#15</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ljharb/shell-quote/commit/508e2f9c6439706cc696407d52fec36f78248a19"><code>508e2f9</code></a>
v1.8.0</li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/fd7ddcdd84bfef064c6d9a06b055a95531b26897"><code>fd7ddcd</code></a>
[Tests] add <code>nyc</code> coverage</li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/9802fb37c7946e18c672b81122520dc296bde271"><code>9802fb3</code></a>
[New] Add support for here strings (<code>&lt;&lt;&lt;</code>)</li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/216b19894f76b14d164c4c5a68f05a51b06336c4"><code>216b198</code></a>
[New] <code>parse</code>: Add syntax support for duplicating input file
descriptors</li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/c5549fcd82d70046bdc2b1c34184ae9f9d0191f9"><code>c5549fc</code></a>
[Tests] add <code>evalmd</code></li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/553fdfc32cc41b4c2f77e061b6957703958ca575"><code>553fdfc</code></a>
[New] extract <code>parse</code> and <code>quote</code> to their own
deep imports</li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/85f8e31dd80e1dde63d58204b653e497a53857e6"><code>85f8e31</code></a>
[Dev Deps] update <code>@ljharb/eslint-config</code>, <code>aud</code>,
<code>tape</code></li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/62e9b4958cfa2f9009b7069076612fe33528c1fb"><code>62e9b49</code></a>
[actions] update checkout action</li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/5409e72ef6c905c4d1637883cd394f6f07abd934"><code>5409e72</code></a>
v1.7.4</li>
<li><a
href="https://github.com/ljharb/shell-quote/commit/4763c36274c5881a2d141ce9f2b17b7d1d95e8cd"><code>4763c36</code></a>
[actions] add reusable workflows</li>
<li>Additional commits viewable in <a
href="https://github.com/ljharb/shell-quote/compare/1.6.1...v1.8.0">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~ljharb">ljharb</a>, a new releaser for
shell-quote since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=shell-quote&package-manager=npm_and_yarn&previous-version=1.6.1&new-version=1.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the
default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as
the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as
the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the
default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/software-mansion/react-native-screens/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
  • Loading branch information
dependabot[bot] authored Feb 24, 2023
1 parent 4cbd9cb commit bdf860e
Showing 1 changed file with 7 additions and 56 deletions.
63 changes: 7 additions & 56 deletions yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -1738,18 +1738,6 @@
serve-static "^1.13.1"
ws "^7.5.1"

"@react-native-community/cli-tools@^5.0.1":
version "5.0.1"
resolved "https://registry.yarnpkg.com/@react-native-community/cli-tools/-/cli-tools-5.0.1.tgz#9ee564dbe20448becd6bce9fbea1b59aa5797919"
integrity sha512-XOX5w98oSE8+KnkMZZPMRT7I5TaP8fLbDl0tCu40S7Epz+Zz924n80fmdu6nUDIfPT1nV6yH1hmHmWAWTDOR+Q==
dependencies:
chalk "^3.0.0"
lodash "^4.17.15"
mime "^2.4.1"
node-fetch "^2.6.0"
open "^6.2.0"
shell-quote "1.6.1"

"@react-native-community/cli-tools@^9.2.1":
version "9.2.1"
resolved "https://registry.yarnpkg.com/@react-native-community/cli-tools/-/cli-tools-9.2.1.tgz#c332324b1ea99f9efdc3643649bce968aa98191c"
Expand Down Expand Up @@ -2519,11 +2507,6 @@ arr-union@^3.1.0:
resolved "https://registry.yarnpkg.com/arr-union/-/arr-union-3.1.0.tgz#e39b09aea9def866a8f206e288af63919bae39c4"
integrity sha512-sKpyeERZ02v1FeCZT8lrfJq5u6goHCtpTAzPwJYe7c8SPFOboNjNg1vz2L4VTn9T4PQxEx13TbXLmYUcS6Ug7Q==

array-filter@~0.0.0:
version "0.0.1"
resolved "https://registry.yarnpkg.com/array-filter/-/array-filter-0.0.1.tgz#7da8cf2e26628ed732803581fd21f67cacd2eeec"
integrity sha512-VW0FpCIhjZdarWjIz8Vpva7U95fl2Jn+b+mmFFMLn8PIVscOQcAgEznwUzTEuUHuqZqIxwzRlcaN/urTFFQoiw==

array-includes@^3.1.5, array-includes@^3.1.6:
version "3.1.6"
resolved "https://registry.yarnpkg.com/array-includes/-/array-includes-3.1.6.tgz#9e9e720e194f198266ba9e18c29e6a9b0e4b225f"
Expand All @@ -2535,16 +2518,6 @@ array-includes@^3.1.5, array-includes@^3.1.6:
get-intrinsic "^1.1.3"
is-string "^1.0.7"

array-map@~0.0.0:
version "0.0.1"
resolved "https://registry.yarnpkg.com/array-map/-/array-map-0.0.1.tgz#d1bf3cc8813a7daaa335e5c8eb21d9d06230c1a7"
integrity sha512-sxHIeJTGEsRC8/hYkZzdJNNPZ41EXHVys7pqMw1iwE/Kx8/hto0UbDuGQsSJ0ujPovj9qUZl6EOY/EiZ2g3d9Q==

array-reduce@~0.0.0:
version "0.0.0"
resolved "https://registry.yarnpkg.com/array-reduce/-/array-reduce-0.0.0.tgz#173899d3ffd1c7d9383e4479525dbe278cab5f2b"
integrity sha512-8jR+StqaC636u7h3ye1co3lQRefgVVUQUhuAmRbDqIMeR2yuXzRvkCNQiQ5J/wbREmoBLNtp13dhaaVpZQDRUw==

array-union@^1.0.1:
version "1.0.2"
resolved "https://registry.yarnpkg.com/array-union/-/array-union-1.0.2.tgz#9a34410e4f4e3da23dea375be5be70f24778ec39"
Expand Down Expand Up @@ -3478,7 +3451,7 @@ cosmiconfig@8.0.0:
parse-json "^5.0.0"
path-type "^4.0.0"

cosmiconfig@^5.0.5:
cosmiconfig@^5.0.5, cosmiconfig@^5.1.0:
version "5.2.1"
resolved "https://registry.yarnpkg.com/cosmiconfig/-/cosmiconfig-5.2.1.tgz#040f726809c591e77a17c0a3626ca45b4f168b1a"
integrity sha512-H65gsXo1SKjf8zmrJ67eJk8aIRKV5ff2D4uKZIBZShbhGSpEmsQOPW/SKMKYhSTrqR7ufy6RP69rPogdaPh/kA==
Expand Down Expand Up @@ -3637,6 +3610,11 @@ deep-is@^0.1.3, deep-is@~0.1.3:
resolved "https://registry.yarnpkg.com/deep-is/-/deep-is-0.1.4.tgz#a6f2dce612fadd2ef1f519b73551f17e85199831"
integrity sha512-oIPzksmTg4/MriiaYGO+okXDT7ztn/w3Eptv/+gSIdMdKsJo0u4CfYNFJPy+4SKMuCqGw2wxnA+URMg3t8a/bQ==

deepmerge@^3.2.0:
version "3.3.0"
resolved "https://registry.yarnpkg.com/deepmerge/-/deepmerge-3.3.0.tgz#d3c47fd6f3a93d517b14426b0628a17b0125f5f7"
integrity sha512-GRQOafGHwMHpjPx9iCvTgpu9NojZ49q794EEL94JVEw6VaeA8XTUyBKvAkOOjBX9oJNiV6G3P+T+tihFjo2TqA==

deepmerge@^4.2.2:
version "4.3.0"
resolved "https://registry.yarnpkg.com/deepmerge/-/deepmerge-4.3.0.tgz#65491893ec47756d44719ae520e0e2609233b59b"
Expand Down Expand Up @@ -6353,7 +6331,7 @@ jest@^26.2.2:
import-local "^3.0.2"
jest-cli "^26.6.3"

jetifier@^1.6.2, jetifier@^1.6.6:
jetifier@^1.6.6:
version "1.6.8"
resolved "https://registry.yarnpkg.com/jetifier/-/jetifier-1.6.8.tgz#e88068697875cbda98c32472902c4d3756247798"
integrity sha512-3Zi16h6L5tXDRQJTb221cnRoVG9/9OvreLdLU2/ZjRv/GILL+2Cemt0IKvkowwkDpvouAU1DQPOJ7qaiHeIdrw==
Expand Down Expand Up @@ -6562,11 +6540,6 @@ jsonfile@^6.0.1:
optionalDependencies:
graceful-fs "^4.1.6"

jsonify@~0.0.0:
version "0.0.1"
resolved "https://registry.yarnpkg.com/jsonify/-/jsonify-0.0.1.tgz#2aa3111dae3d34a0f151c63f3a45d995d9420978"
integrity sha512-2/Ki0GcmuqSrgFyelQq9M05y7PS0mEwuIzrf3f1fPqkVDVRvZrPZtVSMHxdgo8Aq0sxAOb/cr2aqqA3LeWHVPg==

"jsx-ast-utils@^2.4.1 || ^3.0.0":
version "3.3.3"
resolved "https://registry.yarnpkg.com/jsx-ast-utils/-/jsx-ast-utils-3.3.3.tgz#76b3e6e6cece5c69d49a5792c3d01bd1a0cdc7ea"
Expand Down Expand Up @@ -9141,11 +9114,6 @@ sane@^4.0.3:
minimist "^1.1.1"
walker "~1.0.5"

sax@^1.2.4:
version "1.2.4"
resolved "https://registry.yarnpkg.com/sax/-/sax-1.2.4.tgz#2816234e2378bddc4e5354fab5caa895df7100d9"
integrity sha512-NqVDv9TpANUjFm0N8uM5GxL36UgKi9/atZw+x7YFnQ8ckwFGKrl4xX4yWtrey3UJm5nP1kUbnYgLopqWNSRhWw==

saxes@^5.0.1:
version "5.0.1"
resolved "https://registry.yarnpkg.com/saxes/-/saxes-5.0.1.tgz#eebab953fa3b7608dbe94e5dadb15c888fa6696d"
Expand Down Expand Up @@ -9295,16 +9263,6 @@ shebang-regex@^3.0.0:
resolved "https://registry.yarnpkg.com/shebang-regex/-/shebang-regex-3.0.0.tgz#ae16f1644d873ecad843b0307b143362d4c42172"
integrity sha512-7++dFhtcx3353uBaq8DDR4NuxBetBzC7ZQOhmTQInHEd6bSrXdiEyzCvG07Z44UYdLShWUyXt5M/yhz8ekcb1A==

shell-quote@1.6.1:
version "1.6.1"
resolved "https://registry.yarnpkg.com/shell-quote/-/shell-quote-1.6.1.tgz#f4781949cce402697127430ea3b3c5476f481767"
integrity sha512-V0iQEZ/uoem3NmD91rD8XiuozJnq9/ZJnbHVXHnWqP1ucAhS3yJ7sLIIzEi57wFFcK3oi3kFUC46uSyWr35mxg==
dependencies:
array-filter "~0.0.0"
array-map "~0.0.0"
array-reduce "~0.0.0"
jsonify "~0.0.0"

shell-quote@^1.6.1, shell-quote@^1.7.3:
version "1.8.0"
resolved "https://registry.yarnpkg.com/shell-quote/-/shell-quote-1.8.0.tgz#20d078d0eaf71d54f43bd2ba14a1b5b9bfa5c8ba"
Expand Down Expand Up @@ -10541,13 +10499,6 @@ xmlchars@^2.2.0:
resolved "https://registry.yarnpkg.com/xmlchars/-/xmlchars-2.2.0.tgz#060fe1bcb7f9c76fe2a17db86a9bc3ab894210cb"
integrity sha512-JZnDKK8B0RCDw84FNdDAIpZK+JuJw+s7Lz8nksI7SIuU3UXJJslUthsi+uWBUYOwPFwW7W7PRLRfUKpxjtjFCw==

xmldoc@^1.1.2:
version "1.2.0"
resolved "https://registry.yarnpkg.com/xmldoc/-/xmldoc-1.2.0.tgz#7554371bfd8c138287cff01841ae4566d26e5541"
integrity sha512-2eN8QhjBsMW2uVj7JHLHkMytpvGHLHxKXBy4J3fAT/HujsEtM6yU84iGjpESYGHg6XwK0Vu4l+KgqQ2dv2cCqg==
dependencies:
sax "^1.2.4"

xpath@^0.0.27:
version "0.0.27"
resolved "https://registry.yarnpkg.com/xpath/-/xpath-0.0.27.tgz#dd3421fbdcc5646ac32c48531b4d7e9d0c2cfa92"
Expand Down

0 comments on commit bdf860e

Please sign in to comment.