Skip to content

chore(deps): bump shell-quote from 1.8.3 to 1.8.4 in /docs#29

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/docs/shell-quote-1.8.4
Open

chore(deps): bump shell-quote from 1.8.3 to 1.8.4 in /docs#29
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/docs/shell-quote-1.8.4

chore(deps): bump shell-quote from 1.8.3 to 1.8.4 in /docs

3924fa8
Select commit
Loading
Failed to load commit list.
Kusari Inspector / Kusari Inspector succeeded Jun 10, 2026 in 50s

Security Analysis Passed

No security issues found

Details

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both analyses independently recommend proceeding. The dependency update resolves a HIGH severity shell command injection vulnerability (CVE-2026-9277 / GHSA-w7jw-789q-3m8p) in shell-quote by upgrading from 1.8.3 to 1.8.4. The vulnerability allowed newline character injection via the quote() function, enabling command injection in shells. The patched version (1.8.4) is confirmed clean and is the latest available. Risk is further reduced by the fact that this is a transitive dependency under @docusaurus/preset-classic, scoped only to the docs build toolchain and not runtime application code. The code analysis returned zero findings across all severity levels — no secrets, no workflow issues, and no code vulnerabilities were introduced. Combined, this PR strictly improves the security posture with no new risks identified.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 3924fa8, performed at: 2026-06-10T20:16:34Z