Skip to content

chore(deps): bump simple-git from 3.36.0 to 4.0.2 - #91

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/simple-git-4.0.2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/simple-git-4.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps simple-git from 3.36.0 to 4.0.2.

Release notes

Sourced from simple-git's releases.

simple-git@4.0.2

Patch Changes

  • 68874c2: Add VISUAL environment variable to set of allowUnsafeEditor environment variables.

    Thanks to @​oss-security-shopify for identifying the vulnerability.

  • Updated dependencies [68874c2]

    • @​simple-git/argv-parser@​2.0.1

simple-git@4.0.1

Patch Changes

  • 365f52d: Prepare package.json before publishing.

simple-git@4.0.0

Major Changes

  • 98864c6: Major upgrade to v4. In this version:

    • Removed previously available default export, now uses a consistently named simpleGit export.
    • Removed previously deprecated import simple-git/promise (change to using the main simple-git import).
    • Removed legacy gitP export (change to using the main simpleGit export).
    // v3 - previously supported imports
    import simpleGit from "simple-git";
    import { gitP } from "simple-git";
    import simpleGit from "simple-git/promise";
    const simpleGit = require("simple-git");
    // v4 - consolidates to a single supported import
    import { simpleGit } from "simple-git";
    const { simpleGit } = require("simple-git");

    • Prevents the use of abbreviated long-form git options:
    // v3 - allowed the use of unambiguous long-form options
    git.raw("clone", "--conf=user.name=me", "...");
    // v4 - requires full option names, abbreviated option names will now throw a GitConfigurationError
    git.raw("fetch", "--config=user.name=me", "...");

    • Ambient environment variables are filtered before passing into the git child process.
    // v3

... (truncated)

Changelog

Sourced from simple-git's changelog.

4.0.2

Patch Changes

  • 68874c2: Add VISUAL environment variable to set of allowUnsafeEditor environment variables.

    Thanks to @​oss-security-shopify for identifying the vulnerability.

  • Updated dependencies [68874c2]

    • @​simple-git/argv-parser@​2.0.1

4.0.1

Patch Changes

  • 365f52d: Prepare package.json before publishing.

4.0.0

Major Changes

  • 98864c6: Major upgrade to v4. In this version:

    • Removed previously available default export, now uses a consistently named simpleGit export.
    • Removed previously deprecated import simple-git/promise (change to using the main simple-git import).
    • Removed legacy gitP export (change to using the main simpleGit export).
    // v3 - previously supported imports
    import simpleGit from "simple-git";
    import { gitP } from "simple-git";
    import simpleGit from "simple-git/promise";
    const simpleGit = require("simple-git");
    // v4 - consolidates to a single supported import
    import { simpleGit } from "simple-git";
    const { simpleGit } = require("simple-git");

    • Prevents the use of abbreviated long-form git options:
    // v3 - allowed the use of unambiguous long-form options
    git.raw("clone", "--conf=user.name=me", "...");
    // v4 - requires full option names, abbreviated option names will now throw a GitConfigurationError
    git.raw("fetch", "--config=user.name=me", "...");

    Thanks to @​anir0y, @​CFionaBF, @​Leeziao, @​internetteletubbie, @​idisdi, @​the-vibe-dev,

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from rishitank as a code owner October 5, 2026 09:14
@github-actions
github-actions Bot enabled auto-merge (squash) October 5, 2026 09:14
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: c47a5d74-de81-4602-9867-737542908ce4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Bumps [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git) from 3.36.0 to 4.0.2.
- [Release notes](https://github.com/steveukx/git-js/releases)
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md)
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@4.0.2/simple-git)

---
updated-dependencies:
- dependency-name: simple-git
  dependency-version: 4.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/simple-git-4.0.2 branch from 21a2f3a to 36ba436 Compare October 5, 2026 22:07
rishitank added a commit that referenced this pull request Oct 8, 2026
…fresh

- package.json: override tsup's esbuild to ^0.28.1. tsup 8.5.1 asks for
  ^0.27.0, and GHSA-g7r4-m6w7-qqqr affects esbuild >=0.27.3 <0.28.1, so no
  0.27.x fix exists. `npm run build` passes with 0.28.2.
- .github/workflows/deps-refresh-once.yml: one-shot runner job running
  `npm update` within the declared ranges. This clears hono, ip-address,
  js-yaml, minimatch, nanoid, path-to-regexp, picomatch, postcss,
  proxy-addr, qs, rollup, sharp, source-map-js and vite. Checked locally on
  the refreshed lock: typecheck, lint (same 22 warnings as before, 0
  errors), all 240 tests and the build pass. Deleted in the next commit.

Not fixable here without a major upgrade: simple-git 3 -> 4
(GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr, GHSA-x6jw-m9v5-85vh; Renovate
#85/#91) and vitest/@vitest/coverage-v8 3 -> 4.1.11+ (GHSA-82fw-gwwq-j7x9,
plus tinypool through vitest; Renovate #74/#82).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi
rishitank added a commit that referenced this pull request Oct 8, 2026
…; hold TypeScript 7

- simple-git ^3 -> ^4.0.2: GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr,
  GHSA-x6jw-m9v5-85vh and @simple-git/argv-parser GHSA-v5rq-49vh-5v5c are
  fixed only in 4.x (Renovate #85 / Dependabot #91 show it is compatible).
- vitest and @vitest/coverage-v8 ^3 -> ^4.1.11 together: GHSA-82fw-gwwq-j7x9
  (vitest/@vitest/mocker) and tinypool GHSA-5gmw-xhrv-c9v3 /
  GHSA-85c8-ppgw-ccpr. coverage-v8 peers the exact vitest version, which is
  why #74 (vitest only) and #82 (coverage-v8 5 only) each fail npm ci.
- @eslint/js is imported by eslint.config.js but was never declared; it
  only resolved because eslint 9 depends on it. ESLint 10 no longer does
  (#83), so declare it explicitly.
- renovate.json: hold TypeScript 7 (typescript-eslint 8.x peers
  typescript <6.1.0, #84) and group vitest with @vitest/* so they can't
  split again.
- Lockfile refreshed on a runner by the one-shot deps-refresh-once workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi
github-actions Bot added a commit that referenced this pull request Oct 8, 2026
…simple-git 4 and vitest 4 (#94)

* ci: add shared security scan and actionlint workflows

- security.yml: osv-scanner and full-history gitleaks via
  rishitank/.github security.yml@v1 (ecosystem node). Runs alongside the
  existing CodeQL and npm audit jobs in ci.yml, which stay as they are.
- workflows-lint.yml: actionlint via the shared workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(renovate): extend the house preset instead of config:base

config:base is deprecated (renamed config:recommended), and
matchPackagePatterns is deprecated in favour of regex entries in
matchPackageNames. Switch the base to github>rishitank/.github:node
(which already includes config:recommended) and convert the patterns to
/regex/ matchPackageNames. Both custom packageRules are kept.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): override tsup's esbuild; prepare an in-range lockfile refresh

- package.json: override tsup's esbuild to ^0.28.1. tsup 8.5.1 asks for
  ^0.27.0, and GHSA-g7r4-m6w7-qqqr affects esbuild >=0.27.3 <0.28.1, so no
  0.27.x fix exists. `npm run build` passes with 0.28.2.
- .github/workflows/deps-refresh-once.yml: one-shot runner job running
  `npm update` within the declared ranges. This clears hono, ip-address,
  js-yaml, minimatch, nanoid, path-to-regexp, picomatch, postcss,
  proxy-addr, qs, rollup, sharp, source-map-js and vite. Checked locally on
  the refreshed lock: typecheck, lint (same 22 warnings as before, 0
  errors), all 240 tests and the build pass. Deleted in the next commit.

Not fixable here without a major upgrade: simple-git 3 -> 4
(GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr, GHSA-x6jw-m9v5-85vh; Renovate
#85/#91) and vitest/@vitest/coverage-v8 3 -> 4.1.11+ (GHSA-82fw-gwwq-j7x9,
plus tinypool through vitest; Renovate #74/#82).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): refresh lockfile to pick up patched versions

Ran on a runner by the one-shot deps-refresh-once workflow: npm update --package-lock-only --ignore-scripts --no-audit --no-fund

* ci: remove the one-shot deps-refresh-once workflow

It refreshed package-lock.json in ed5ae35 (`npm update` within the
declared ranges, tsup's esbuild override applied). This commit is what
runs CI against the refreshed lockfile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* fix(deps): simple-git 4, vitest + coverage-v8 4.1, declare @eslint/js; hold TypeScript 7

- simple-git ^3 -> ^4.0.2: GHSA-858h-whjf-mvg5, GHSA-g4wm-2vf7-vfgr,
  GHSA-x6jw-m9v5-85vh and @simple-git/argv-parser GHSA-v5rq-49vh-5v5c are
  fixed only in 4.x (Renovate #85 / Dependabot #91 show it is compatible).
- vitest and @vitest/coverage-v8 ^3 -> ^4.1.11 together: GHSA-82fw-gwwq-j7x9
  (vitest/@vitest/mocker) and tinypool GHSA-5gmw-xhrv-c9v3 /
  GHSA-85c8-ppgw-ccpr. coverage-v8 peers the exact vitest version, which is
  why #74 (vitest only) and #82 (coverage-v8 5 only) each fail npm ci.
- @eslint/js is imported by eslint.config.js but was never declared; it
  only resolved because eslint 9 depends on it. ESLint 10 no longer does
  (#83), so declare it explicitly.
- renovate.json: hold TypeScript 7 (typescript-eslint 8.x peers
  typescript <6.1.0, #84) and group vitest with @vitest/* so they can't
  split again.
- Lockfile refreshed on a runner by the one-shot deps-refresh-once workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

* chore(deps): refresh lockfile to pick up patched versions

Ran on a runner by the one-shot deps-refresh-once workflow: npm install --package-lock-only --ignore-scripts --no-audit --no-fund

* ci: remove the one-shot deps-refresh-once workflow

Its job is done: a5e9414 committed the lockfile resolved on a runner.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rYJxu978iUSGFZ1UuqTsi

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Looks like simple-git is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 8, 2026
auto-merge was automatically disabled October 8, 2026 23:18

Pull request was closed

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/simple-git-4.0.2 branch October 8, 2026 23:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants