Skip to content

Bump shell-quote from 1.8.3 to 1.8.4#6027

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/shell-quote-1.8.4
Open

Bump shell-quote from 1.8.3 to 1.8.4#6027
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/shell-quote-1.8.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 10, 2026

Copy link
Copy Markdown
Contributor

Bumps shell-quote from 1.8.3 to 1.8.4.

Changelog

Sourced from shell-quote's changelog.

v1.8.4 - 2026-05-22

Commits

  • [Fix] quote: validate object-token shapes 4378a6e
  • [Dev Deps] update @ljharb/eslint-config, auto-changelog, eslint, npmignore 22ebec0
  • [Tests] increase coverage 9f3caa3
  • [readme] replace runkit CI badge with shields.io check-runs badge 3344a04
  • [Dev Deps] update @ljharb/eslint-config 699c511
Commits
  • ff166e2 v1.8.4
  • 4378a6e [Fix] quote: validate object-token shapes
  • 22ebec0 [Dev Deps] update @ljharb/eslint-config, auto-changelog, eslint, `npmig...
  • 9f3caa3 [Tests] increase coverage
  • 3344a04 [readme] replace runkit CI badge with shields.io check-runs badge
  • 699c511 [Dev Deps] update @ljharb/eslint-config
  • See full diff in compare view


Note

Low Risk
Patch-level transitive dependency update with no direct app code changes; minor hardening in quoting behavior only affects dev-tooling paths.

Overview
Updates the lockfile so shell-quote resolves to 1.8.4 (from 1.8.3), including registry resolved and integrity metadata.

That release tightens quote by validating object-token shapes (per upstream changelog). The package remains a transitive dependency (e.g. via launch-editor and react-devtools-core); no application source changes.

The diff also drops a stale nested chain-registry entry under @chain-registry/utils, consistent with lockfile cleanup from the dependency refresh.

Reviewed by Cursor Bugbot for commit ccdb19e. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 10, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/shell-quote-1.8.4 branch from b7224a1 to 3051676 Compare June 15, 2026 22:23
Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.3...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/shell-quote-1.8.4 branch from 3051676 to ccdb19e Compare June 17, 2026 02:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants