Skip to content

[release-1.9] chore(deps): bump shell-quote to 1.8.4#4904

Merged
openshift-merge-bot[bot] merged 1 commit into
redhat-developer:release-1.9from
JessicaJHee:cve-medic-CVE20269277
May 29, 2026
Merged

[release-1.9] chore(deps): bump shell-quote to 1.8.4#4904
openshift-merge-bot[bot] merged 1 commit into
redhat-developer:release-1.9from
JessicaJHee:cve-medic-CVE20269277

Conversation

@JessicaJHee
Copy link
Copy Markdown
Member

Description

bump shell-quote to 1.8.4, fixes CVE-2026-9277 which is patched in 1.8.4

Which issue(s) does this PR fix

PR acceptance criteria

Please make sure that the following steps are complete:

  • GitHub Actions are completed and successful
  • Unit Tests are updated and passing
  • E2E Tests are updated and passing
  • Documentation is updated if necessary (requirement for new features)
  • Add a screenshot if the change is UX/UI related

How to test changes / Special notes to the reviewer

Signed-off-by: Jessica He <jhe@redhat.com>
@openshift-ci openshift-ci Bot requested review from divyanshiGupta and polasudo May 29, 2026 19:07
@sonarqubecloud
Copy link
Copy Markdown

@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

Copy link
Copy Markdown
Member

@kim-tsao kim-tsao left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

safe update, only affects @backstage/cli which is a devdependency

@openshift-ci openshift-ci Bot added the lgtm label May 29, 2026
@openshift-merge-bot openshift-merge-bot Bot merged commit e9694e4 into redhat-developer:release-1.9 May 29, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants