fix: bump shell-quote to 1.8.4 to remediate CVE-2026-9277 (#1557)

shell-quote 1.8.3 (root and base-action dependency) is affected by
CVE-2026-9277, a CRITICAL severity vulnerability. 1.8.4 contains the fix.

Co-authored-by: Ashwin Bhat <ashwin@anthropic.com>
This commit is contained in:
Dhaval Doshi
2026-08-14 16:46:34 -07:00
committed by GitHub
co-authored by Ashwin Bhat
parent a2cac87e27
commit 5da4c76dde
5 changed files with 8 additions and 8 deletions
+1 -1
View File
@@ -18,7 +18,7 @@
"@octokit/rest": "^21.1.1",
"@octokit/webhooks-types": "^7.6.1",
"node-fetch": "^3.3.2",
"shell-quote": "^1.8.3",
"shell-quote": "^1.8.4",
"zod": "^3.24.4"
},
"devDependencies": {