Bumps the npm_and_yarn group with 2 updates in the / directory: shell-quote [QUARANTINED_URL: github.com] and tar [QUARANTINED_URL: github.com].
Updates shell-quote from 1.8.4 to 1.10.0
Changelog
Sourced from shell-quote's changelog.
Merged
Commits
- [Fix]
parse: match nested ${...} braces so nested parameter expansion is consumed as one substitution c0842c8
- [Tests]
parse: pin single-quote literalness and unmatched-quote handling a0d03e3
- [readme] remove the space in js code fences so evalmd evaluates them
2116fa3
- [Tests]
quote: pin conservative escaping of =, @, ^, ,, :, ! (#11) 1c36f3f
- [readme] document that
quote outputs POSIX quoting, not cmd.exe/PowerShell 100e96e
- [readme] document
parse's supported parameter-expansion subset e1c75cd
- [Fix]
parse: a backslash inside single quotes must not escape the closing quote 5d460a3
- [readme] fix stale example outputs
2de86f5
- [Tests]
quote: pin that a backslash with whitespace is not doubled in single quotes (#14) 190e236
- [readme]
quote: use output verbatim; do not re-quote it (#11) 1b36468
- [Refactor]
parse: fix swapped SINGLE_QUOTE/DOUBLE_QUOTE variable names 801af5c
- [types] fix an error TS v6 ignores but v7 fails on
59bbf8b
- [Dev Deps] update
@arethetypeswrong/cli, evalmd a04d475
- [Dev Deps] update
@arethetypeswrong/ci, eslint d390f9a
- [Tests]
quote: the tilde test escapes every ~, not just a leading one (#9) 617d119
v1.9.0 - 2026-06-24
Commits
- [New] add types
dca6e21
- [Dev Deps] update
eslint 9aa9e8f
- [Fix]
parse: finalize tokens in linear time (GHSA-395f-4hp3-45gv) 7ff5488
- [actions] update workflows
75e8497
- [actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10
@types/esrecurse 3fb739d
- [actions] retry
npm install on Windows to survive npm 2/3 staging-rename flake abe0163
- [actions] Windows + node 5/7: install deps with a modern node
b4bafa2
- [Fix]
quote: escape leading ~ to prevent shell tilde-expansion 7a76c1a
- [Dev Deps] update
auto-changelog, tape 7184b44
- [Dev Deps] apparently
jackspeak is no longer in the graph 9ba368a
Commits
64988d9 v1.10.0
617d119 [Tests] quote: the tilde test escapes every ~, not just a leading one (#9)
59bbf8b [types] fix an error TS v6 ignores but v7 fails on
190e236 [Tests] quote: pin that a backslash with whitespace is not doubled in singl...
a04d475 [Dev Deps] update @arethetypeswrong/cli, evalmd
b9545b3 [New] parse: add opt-in splitUnquoted option for shell field-splitting of...
1b36468 [readme] quote: use output verbatim; do not re-quote it (#11)
1c36f3f [Tests] quote: pin conservative escaping of =, @, ^, ,, :, ! (#11)
e1c75cd [readme] document parse's supported parameter-expansion subset
c0842c8 [Fix] parse: match nested ${...} braces so nested parameter expansion is ...
- Additional commits viewable in compare view
Updates tar from 7.5.16 to 7.5.20
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the Security Alerts page [QUARANTINED_URL: github.com].
Bumps the npm_and_yarn group with 2 updates in the / directory: shell-quote [QUARANTINED_URL: github.com] and tar [QUARANTINED_URL: github.com].
Updates
shell-quotefrom 1.8.4 to 1.10.0Changelog
Sourced from shell-quote's changelog.
Commits
64988d9v1.10.0617d119[Tests]quote: the tilde test escapes every~, not just a leading one (#9)59bbf8b[types] fix an error TS v6 ignores but v7 fails on190e236[Tests]quote: pin that a backslash with whitespace is not doubled in singl...a04d475[Dev Deps] update@arethetypeswrong/cli,evalmdb9545b3[New]parse: add opt-insplitUnquotedoption for shell field-splitting of...1b36468[readme]quote: use output verbatim; do not re-quote it (#11)1c36f3f[Tests]quote: pin conservative escaping of=,@,^,,,:,!(#11)e1c75cd[readme] documentparse's supported parameter-expansion subsetc0842c8[Fix]parse: match nested${...}braces so nested parameter expansion is ...Updates
tarfrom 7.5.16 to 7.5.20Commits
ebbb7207.5.202f27196fix: fully disable and dispose of unzip when aborting parserbe440da7.5.192812e93add maxDecompressionRatio guard against explosive decompression9ecd4d27.5.189e78bf0refuse to let header size be less than 0e02a4e9pax: parse values according to known types9cbdb317.5.177a635c2terminate pax strings on nul bytesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page [QUARANTINED_URL: github.com].