Skip to content

fix(deps): update dependency simple-git to v4 - autoclosed - #85

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/simple-git-4.x
Closed

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/simple-git-4.x

Conversation

@renovate

@renovate renovate Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
simple-git (source) ^3.0.0 → ^4.0.0 age confidence

Release Notes

steveukx/git-js (simple-git)

v4.0.2

Compare Source

Patch Changes

v4.0.1

Compare Source

Patch Changes
  • 365f52d: Prepare package.json before publishing.

v4.0.0

Compare Source

Major Changes
  • 98864c6: Major upgrade to v4. In this version:

    • Removed previously available default export, now uses a consistently named simpleGit export.
    • Removed previously deprecated import simple-git/promise (change to using the main simple-git import).
    • Removed legacy gitP export (change to using the main simpleGit export).
    // v3 - previously supported imports
    import simpleGit from "simple-git";
    import { gitP } from "simple-git";
    import simpleGit from "simple-git/promise";
    const simpleGit = require("simple-git");
    
    // v4 - consolidates to a single supported import
    import { simpleGit } from "simple-git";
    const { simpleGit } = require("simple-git");
    • Prevents the use of abbreviated long-form git options:
    // v3 - allowed the use of unambiguous long-form options
    git.raw("clone", "--conf=user.name=me", "...");
    
    // v4 - requires full option names, abbreviated option names will now throw a GitConfigurationError
    git.raw("fetch", "--config=user.name=me", "...");

    Thanks to @​anir0y, @​CFionaBF, @​Leeziao, @​internetteletubbie, @​idisdi, @​the-vibe-dev,
    @​D7EAD, @​dellalibera, @​gdegrange, @​bilguunbicktivism, @​cruzryan, @​b1ue0ceanRun, @​oss-security-shopify
    for identifying the vulnerability.

    • Ambient environment variables are filtered before passing into the git child process.
    // v3
    process.env.FOO = "bar";
    process.env.GIT_TEMPLATE_DIR = "./some/path";
    simpleGit().raw("clone"); // git child process can see both environment variables
    
    // v4
    process.env.FOO = "bar";
    process.env.GIT_TEMPLATE_DIR = "./some/path";
    simpleGit().raw("clone"); // git child process now sees only FOO
    
    simpleGit({
      // explicitly allow the named environment variable so it can pass through.
      allowEnvoronment: ["GIT_TEMPLATE_DIR"],
      // and enable the use of an unsafe behaviour
      unsafe: { allowUnsafeTemplateDir: true },
    });
    • Explicitly supplied disallowed environment variables will throw when used.
    // v3 used a single opt-in to potential unsafe actiity
    simpleGit({ unsafe: { allowUnsafeTemplateDir: true } })
      .env({ GIT_TEMPLATE_DIR: "./foo" })
      .init();
    
    // v4 uses a double opt-in, allow the behaviour and the mechanism
    simpleGit({
      allowEnvoronment: ["GIT_TEMPLATE_DIR"],
      unsafe: { allowUnsafeTemplateDir: true },
    })
      .env({ GIT_TEMPLATE_DIR: "./foo" })
      .init();
    • Removed content deprecated during the v2 to v3 major change
      • simpleGit.silent() logging is configured through environment variables in the debug package
      • simpleGit.clearQueue() this has been a noop since v3, switch to using the abort plugin
      • Accessing parsed properties of a GitResponseError through a trailing callback function are available only through the error.git property (previously properties were also spread onto the error itself with a deprecation notice).
Minor Changes
  • 98864c6: Support one-shot stdin via git.input(data) (string or Buffer).

    Thanks to @​felipecrs for the feature request and initial implementation.

Patch Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from rishitank as a code owner September 26, 2026 12:12
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 430cd0a9-de0e-491b-86ef-63f5e8585d89

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot enabled auto-merge (squash) September 26, 2026 12:12
@renovate
renovate Bot force-pushed the renovate/simple-git-4.x branch 3 times, most recently from c07380c to 774225a Compare October 3, 2026 00:25
@renovate
renovate Bot force-pushed the renovate/simple-git-4.x branch from 774225a to 4597c71 Compare October 5, 2026 22:06
rishitank added a commit that referenced this pull request Oct 8, 2026
…fresh

- package.json: override tsup's esbuild to ^0.28.1. tsup 8.5.1 asks for
  ^0.27.0, and GHSA-g7r4-m6w7-qqqr affects esbuild >=0.27.3 <0.28.1, so no
  0.27.x fix exists. `npm run build` passes with 0.28.2.
- .github/workflows/deps-refresh-once.yml: one-shot runner job running
  `npm update` within the declared ranges. This clears hono, ip-address,
  js-yaml, minimatch, nanoid, path-to-regexp, picomatch, postcss,
  proxy-addr, qs, rollup, sharp, source-map-js and vite. Checked locally on
  the refreshed lock: typecheck, lint (same 22 warnings as before, 0
  errors), all 240 tests and the build pass. Deleted in the next commit.

Not fixable here without a major upgrade: simple-git 3 -> 4
(GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr, GHSA-x6jw-m9v5-85vh; Renovate
#85/#91) and vitest/@vitest/coverage-v8 3 -> 4.1.11+ (GHSA-82fw-gwwq-j7x9,
plus tinypool through vitest; Renovate #74/#82).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi
rishitank added a commit that referenced this pull request Oct 8, 2026
…; hold TypeScript 7

- simple-git ^3 -> ^4.0.2: GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr,
  GHSA-x6jw-m9v5-85vh and @simple-git/argv-parser GHSA-v5rq-49vh-5v5c are
  fixed only in 4.x (Renovate #85 / Dependabot #91 show it is compatible).
- vitest and @vitest/coverage-v8 ^3 -> ^4.1.11 together: GHSA-82fw-gwwq-j7x9
  (vitest/@vitest/mocker) and tinypool GHSA-5gmw-xhrv-c9v3 /
  GHSA-85c8-ppgw-ccpr. coverage-v8 peers the exact vitest version, which is
  why #74 (vitest only) and #82 (coverage-v8 5 only) each fail npm ci.
- @eslint/js is imported by eslint.config.js but was never declared; it
  only resolved because eslint 9 depends on it. ESLint 10 no longer does
  (#83), so declare it explicitly.
- renovate.json: hold TypeScript 7 (typescript-eslint 8.x peers
  typescript <6.1.0, #84) and group vitest with @vitest/* so they can't
  split again.
- Lockfile refreshed on a runner by the one-shot deps-refresh-once workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi
github-actions Bot added a commit that referenced this pull request Oct 8, 2026
…simple-git 4 and vitest 4 (#94)

* ci: add shared security scan and actionlint workflows

- security.yml: osv-scanner and full-history gitleaks via
  rishitank/.github security.yml@v1 (ecosystem node). Runs alongside the
  existing CodeQL and npm audit jobs in ci.yml, which stay as they are.
- workflows-lint.yml: actionlint via the shared workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(renovate): extend the house preset instead of config:base

config:base is deprecated (renamed config:recommended), and
matchPackagePatterns is deprecated in favour of regex entries in
matchPackageNames. Switch the base to github>rishitank/.github:node
(which already includes config:recommended) and convert the patterns to
/regex/ matchPackageNames. Both custom packageRules are kept.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): override tsup's esbuild; prepare an in-range lockfile refresh

- package.json: override tsup's esbuild to ^0.28.1. tsup 8.5.1 asks for
  ^0.27.0, and GHSA-g7r4-m6w7-qqqr affects esbuild >=0.27.3 <0.28.1, so no
  0.27.x fix exists. `npm run build` passes with 0.28.2.
- .github/workflows/deps-refresh-once.yml: one-shot runner job running
  `npm update` within the declared ranges. This clears hono, ip-address,
  js-yaml, minimatch, nanoid, path-to-regexp, picomatch, postcss,
  proxy-addr, qs, rollup, sharp, source-map-js and vite. Checked locally on
  the refreshed lock: typecheck, lint (same 22 warnings as before, 0
  errors), all 240 tests and the build pass. Deleted in the next commit.

Not fixable here without a major upgrade: simple-git 3 -> 4
(GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr, GHSA-x6jw-m9v5-85vh; Renovate
#85/#91) and vitest/@vitest/coverage-v8 3 -> 4.1.11+ (GHSA-82fw-gwwq-j7x9,
plus tinypool through vitest; Renovate #74/#82).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): refresh lockfile to pick up patched versions

Ran on a runner by the one-shot deps-refresh-once workflow: npm update --package-lock-only --ignore-scripts --no-audit --no-fund

* ci: remove the one-shot deps-refresh-once workflow

It refreshed package-lock.json in ed5ae35 (`npm update` within the
declared ranges, tsup's esbuild override applied). This commit is what
runs CI against the refreshed lockfile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* fix(deps): simple-git 4, vitest + coverage-v8 4.1, declare @eslint/js; hold TypeScript 7

- simple-git ^3 -> ^4.0.2: GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr,
  GHSA-x6jw-m9v5-85vh and @simple-git/argv-parser GHSA-v5rq-49vh-5v5c are
  fixed only in 4.x (Renovate #85 / Dependabot #91 show it is compatible).
- vitest and @vitest/coverage-v8 ^3 -> ^4.1.11 together: GHSA-82fw-gwwq-j7x9
  (vitest/@vitest/mocker) and tinypool GHSA-5gmw-xhrv-c9v3 /
  GHSA-85c8-ppgw-ccpr. coverage-v8 peers the exact vitest version, which is
  why #74 (vitest only) and #82 (coverage-v8 5 only) each fail npm ci.
- @eslint/js is imported by eslint.config.js but was never declared; it
  only resolved because eslint 9 depends on it. ESLint 10 no longer does
  (#83), so declare it explicitly.
- renovate.json: hold TypeScript 7 (typescript-eslint 8.x peers
  typescript <6.1.0, #84) and group vitest with @vitest/* so they can't
  split again.
- Lockfile refreshed on a runner by the one-shot deps-refresh-once workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): refresh lockfile to pick up patched versions

Ran on a runner by the one-shot deps-refresh-once workflow: npm install --package-lock-only --ignore-scripts --no-audit --no-fund

* ci: remove the one-shot deps-refresh-once workflow

Its job is done: a5e9414 committed the lockfile resolved on a runner.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@renovate renovate Bot changed the title fix(deps): update dependency simple-git to v4 fix(deps): update dependency simple-git to v4 - autoclosed Oct 8, 2026
@renovate renovate Bot closed this Oct 8, 2026
auto-merge was automatically disabled October 8, 2026 23:16

Pull request was closed

@renovate
renovate Bot deleted the renovate/simple-git-4.x branch October 8, 2026 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants