Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade simple-git from 1.132.0 to 3.27.0 #3

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-io[bot]
Copy link

@snyk-io snyk-io bot commented Nov 10, 2024

snyk-top-banner

Snyk has created this PR to upgrade simple-git from 1.132.0 to 3.27.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

  • The recommended version is 101 versions ahead of your current version.

  • The recommended version was released on 2 months ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Command Injection
SNYK-JS-SIMPLEGIT-2421199
726 Proof of Concept
high severity Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
SNYK-JS-SIMPLEGIT-2434306
726 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-SIMPLEGIT-3112221
726 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-SIMPLEGIT-3177391
726 Proof of Concept
Release notes
Package name: simple-git
  • 3.27.0 - 2024-09-19

    Minor Changes

    • 52f767b: Add similarity to the DiffResultNameStatusFile interface used when fetching log/diff with the --name-status option.
    • 739b0d9: Diff summary includes original name of renamed files when run wiht the --name-status option.
    • bc90e7e: Fixes an issue with reporting name changes in the files array returned by git.status.
      Thank you @ mark-codesphere for the contribution.

    Patch Changes

    • 03e1c64: Resolve error in log parsing when fields have empty values.
  • 3.26.0 - 2024-09-01

    Minor Changes

    • 28d545b: Upgrade build tools and typescript
  • 3.25.0 - 2024-06-10

    Minor Changes

    • 0a5378d: Add support for parsing count-objects

    Patch Changes

    • 4aceb15: Upgrade dependencies and build tools
  • 3.24.0 - 2024-03-28

    Minor Changes

    • c355317: Enable the use of a two part custom binary
  • 3.23.0 - 2024-03-17

    Minor Changes

    • 9bfdf08: Bump package manager from yarn v1 to v4

    Patch Changes

    • 8a3118d: Fixed a performance issue when parsing stat diff summaries
    • 9f1a174: Update build tools and workflows for Yarn 4 compatibility
  • 3.22.0 - 2023-12-29

    Minor Changes

    • df14065: add status to DiffResult when using --name-status
  • 3.21.0 - 2023-11-20

    Minor Changes

    • 709d80e: Add firstCommit utility interface

    Patch Changes

    • b4ab430: Add trailing callback support to git.firstCommit
    • d3f9320: chore(deps): bump @ babel/traverse from 7.9.5 to 7.23.2
    • b76857f: chore(deps): bump axios from 1.1.3 to 1.6.1
  • 3.20.0 - 2023-09-23

    Minor Changes

    • 2eda817: Use pathspec in git.log to allow use of previously deleted files in file argument
  • 3.19.1 - 2023-06-26

    Patch Changes

    • 2ab1936: keep path splitter without path specs
  • 3.19.0 - 2023-05-24

    Minor Changes

    • f702b61: Create a utility to append pathspec / file lists to tasks through the TaskOptions array/object
  • 3.18.0 - 2023-04-25
  • 3.17.0 - 2023-03-04
  • 3.16.1 - 2023-02-15
  • 3.16.0 - 2023-01-16
  • 3.15.1 - 2022-11-30
  • 3.15.0 - 2022-11-12
  • 3.14.1 - 2022-09-17
  • 3.14.0 - 2022-09-04
  • 3.13.0 - 2022-08-22
  • 3.12.0 - 2022-08-08
  • 3.11.0 - 2022-07-30
  • 3.10.0 - 2022-06-25
  • 3.9.0 - 2022-06-22
  • 3.8.0 - 2022-06-18
  • 3.7.1 - 2022-04-23
  • 3.7.0 - 2022-04-19
  • 3.6.0 - 2022-04-10
  • 3.5.0 - 2022-03-29
  • 3.4.0 - 2022-03-18
  • 3.3.0 - 2022-03-11
  • 3.2.6 - 2022-02-17
  • 3.2.4 - 2022-02-13
  • 3.1.1 - 2022-01-26
  • 3.1.0 - 2022-01-23
  • 3.0.4 - 2022-01-23
  • 3.0.3 - 2022-01-20
  • 3.0.2 - 2022-01-18
  • 3.0.1 - 2022-01-18
  • 2.48.0 - 2021-12-01
  • 2.47.1 - 2021-11-29
  • 2.47.0 - 2021-10-19
  • 2.46.0 - 2021-09-29
  • 2.45.1 - 2021-09-04
  • 2.45.0 - 2021-08-27
  • 2.44.0 - 2021-08-14
  • 2.43.0 - 2021-08-13
  • 2.42.0 - 2021-07-31
  • 2.41.2 - 2021-07-29
  • 2.41.1 - 2021-07-11
  • 2.41.0 - 2021-07-11
  • 2.40.0 - 2021-06-14
  • 2.39.1 - 2021-06-09
  • 2.39.0 - 2021-05-13
  • 2.38.1 - 2021-05-10
  • 2.38.0 - 2021-04-14
  • 2.37.0 - 2021-03-15
  • 2.36.2 - 2021-03-11
  • 2.36.1 - 2021-03-07
  • 2.36.0 - 2021-03-03
  • 2.35.2 - 2021-02-23
  • 2.35.1 - 2021-02-19
  • 2.35.0 - 2021-02-16
  • 2.34.2 - 2021-02-07
  • 2.32.0 - 2021-02-04
  • 2.31.0 - 2020-12-17
  • 2.30.0 - 2020-12-16
  • 2.29.0 - 2020-12-15
  • 2.28.0 - 2020-12-15
  • 2.27.0 - 2020-12-11
  • 2.26.0 - 2020-12-09
  • 2.25.0 - 2020-12-08
  • 2.24.0 - 2020-11-27
  • 2.23.0 - 2020-11-20
  • 2.22.0 - 2020-11-13
  • 2.21.0 - 2020-10-07
  • 2.20.1 - 2020-08-24
  • 2.20.0 - 2020-08-24
  • 2.19.0 - 2020-08-21
  • 2.18.0 - 2020-08-19
  • 2.17.0 - 2020-08-03
  • 2.16.0 - 2020-08-02
  • 2.15.0 - 2020-07-23
  • 2.14.0 - 2020-07-20
  • 2.13.2 - 2020-07-17
  • 2.13.1 - 2020-07-16
  • 2.13.0 - 2020-07-16
  • 2.12.0 - 2020-07-08
  • 2.11.0 - 2020-06-25
  • 2.10.0 - 2020-06-23
  • 2.9.0 - 2020-06-20
  • 2.8.0 - 2020-06-19
  • 2.7.2 - 2020-06-18
  • 2.7.1 - 2020-06-18
  • 2.7.0 - 2020-06-16
  • 2.6.0 - 2020-06-07
  • 2.5.0 - 2020-05-17
  • 2.4.0 - 2020-05-05
  • 2.3.0 - 2020-05-03
  • 2.2.0 - 2020-04-30
  • 2.1.0 - 2020-04-28
  • 2.0.0 - 2020-04-28
  • 1.132.0 - 2020-03-12
from simple-git GitHub release notes

Important

  • Warning: This PR contains a major version upgrade, and may be a breaking change.
  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade simple-git from 1.132.0 to 3.27.0.

See this package in npm:
simple-git

See this project in Snyk:
https://app.snyk.io/org/doperiddle/project/d0ea5fc1-9aea-4ced-9d22-6dafc745de0d?utm_source=github-cloud-app&utm_medium=referral&page=upgrade-pr
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants