Skip to content

chore(deps): bump mvdan.cc/sh/v3 from 3.13.1 to 3.14.0 - #508

Merged
josegonzalez merged 1 commit into
mainfrom
dependabot/go_modules/mvdan.cc/sh/v3-3.14.0
Sep 1, 2026
Merged

chore(deps): bump mvdan.cc/sh/v3 from 3.13.1 to 3.14.0#508
josegonzalez merged 1 commit into
mainfrom
dependabot/go_modules/mvdan.cc/sh/v3-3.14.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps mvdan.cc/sh/v3 from 3.13.1 to 3.14.0.

Release notes

Sourced from mvdan.cc/sh/v3's releases.

v3.14.0

This release drops support for Go 1.25 and includes many enhancements, particularly in the interpreter, which implements more shell features and fixes many divergences from Bash.

  • cmd/shfmt
    • Add --detect to find shell files by executable bit or shebang - #944
  • syntax
    • Add Preorder, an iterator over all nodes, complementing Walk
    • Add encoding.TextUnmarshaler implementations for each operator type
    • Support ${ foo;} and ${|foo;} inside double quotes - #1368
    • Support array elements in {varname} redirects, like exec {fds[3]}>&- - #719
    • Backslashes inside backquotes within double quotes escape double quotes - #1083
    • Allow pound signs in associative array keys like ${args[cmd,#]} - #1285
    • Don't treat # as the start of a comment inside [[ ]] tests - #1326
    • Don't join then or do with a semicolon when heredocs are pending - #1047
    • Print a space after ! in arithmetic expressions, avoiding history expansion - #987
    • Space nested closing parentheses like the opening ones - #876
    • Make SplitBraces reject malformed sequences and skip backslash escapes - #1330
    • Zsh: support the ${=name}, ${~name}, and ${^name} prefixes - #1238
    • Zsh: support the ;| case terminator and leading parentheses for globs - #1293, #1279
    • Zsh: parse subscript flag arguments as patterns, and allow [ globs in arrays - #1278, #1322
  • syntax/typedjson
    • Encode operators as their syntax form, such as ">>", rather than integers - #1321
    • Return errors rather than panicking on malformed input
  • interp
    • Add BashOpts to set Bash options like shopt - #962
    • Add AccessHandler to control file access checks, used by -r and cd - #1318
    • Add HandlerContext.LastExitStatus, and provide a HandlerContext to stat handlers
    • Implement the help and times builtins, as well as $- - #1398
    • Implement the ;& and ;;& case terminators - #1391
    • Implement the -N test operator, and make -nt and -ot follow POSIX - #1340
    • Support sparse indexed arrays such as a=([5]=x) - #1373
    • Run files as shell scripts when exec fails with ENOEXEC - #1065
    • Support empty here-documents, and don't expand quoted ones - #1390
    • Support js/wasm, where subprocesses and pipes are unavailable
    • Keep the redirections applied by exec with no arguments
    • Only fire the exit trap when the shell exits, rather than after every Run
  • expand
    • Add BracesSeq with a config and error reporting, deprecating Braces
    • Add Variable.Indexes to describe sparse indexed arrays
    • Support integer bases in arithmetic - #339
    • Short-circuit the arithmetic && and || operators - #1371
    • Apply per-element operators to quoted array expansions like "${a[@]%o}" - #1081
    • Make unquoted ${!arr[@]} consistent with the quoted form - #672
    • Fix many divergences from Bash in arithmetic, string, and brace expansions
    • Reject unsupported Zsh syntax rather than panicking - #1363
  • pattern
    • Treat an unmatched [ as a literal character, like Bash - #1372
    • Fix panics and mismatches in bracket expressions, such as [![:space:]]
  • fileutil
    • Recognize dash shebangs as POSIX shell for -ln=auto - #1307

... (truncated)

Changelog

Sourced from mvdan.cc/sh/v3's changelog.

[3.14.0] - 2026-08-28

This release drops support for Go 1.25 and includes many enhancements, particularly in the interpreter, which implements more shell features and fixes many divergences from Bash.

  • cmd/shfmt
    • Add --detect to find shell files by executable bit or shebang - #944
  • syntax
    • Add Preorder, an iterator over all nodes, complementing Walk
    • Add encoding.TextUnmarshaler implementations for each operator type
    • Support ${ foo;} and ${|foo;} inside double quotes - #1368
    • Support array elements in {varname} redirects, like exec {fds[3]}>&- - #719
    • Backslashes inside backquotes within double quotes escape double quotes - #1083
    • Allow pound signs in associative array keys like ${args[cmd,#]} - #1285
    • Don't treat # as the start of a comment inside [[ ]] tests - #1326
    • Don't join then or do with a semicolon when heredocs are pending - #1047
    • Print a space after ! in arithmetic expressions, avoiding history expansion - #987
    • Space nested closing parentheses like the opening ones - #876
    • Make SplitBraces reject malformed sequences and skip backslash escapes - #1330
    • Zsh: support the ${=name}, ${~name}, and ${^name} prefixes - #1238
    • Zsh: support the ;| case terminator and leading parentheses for globs - #1293, #1279
    • Zsh: parse subscript flag arguments as patterns, and allow [ globs in arrays - #1278, #1322
  • syntax/typedjson
    • Encode operators as their syntax form, such as ">>", rather than integers - #1321
    • Return errors rather than panicking on malformed input
  • interp
    • Add BashOpts to set Bash options like shopt - #962
    • Add AccessHandler to control file access checks, used by -r and cd - #1318
    • Add HandlerContext.LastExitStatus, and provide a HandlerContext to stat handlers
    • Implement the help and times builtins, as well as $- - #1398
    • Implement the ;& and ;;& case terminators - #1391
    • Implement the -N test operator, and make -nt and -ot follow POSIX - #1340
    • Support sparse indexed arrays such as a=([5]=x) - #1373
    • Run files as shell scripts when exec fails with ENOEXEC - #1065
    • Support empty here-documents, and don't expand quoted ones - #1390
    • Support js/wasm, where subprocesses and pipes are unavailable
    • Keep the redirections applied by exec with no arguments
    • Only fire the exit trap when the shell exits, rather than after every Run
  • expand
    • Add BracesSeq with a config and error reporting, deprecating Braces
    • Add Variable.Indexes to describe sparse indexed arrays
    • Support integer bases in arithmetic - #339
    • Short-circuit the arithmetic && and || operators - #1371
    • Apply per-element operators to quoted array expansions like "${a[@]%o}" - #1081
    • Make unquoted ${!arr[@]} consistent with the quoted form - #672
    • Fix many divergences from Bash in arithmetic, string, and brace expansions
    • Reject unsupported Zsh syntax rather than panicking - #1363
  • pattern
    • Treat an unmatched [ as a literal character, like Bash - #1372

... (truncated)

Commits
  • 868c8e8 CHANGELOG: add entry for v3.14.0
  • 0d67740 interp: define the shortPathName test stub just once
  • 8976822 interp: fix getAtime on the BSDs, Solaris, and AIX
  • 48af1f3 expand: detect reading a file as a directory via syscall.ENOTDIR
  • cd3ef1f interp: retry executing a program on ETXTBSY
  • 13c4e98 interp: add regression test for the exec ETXTBSY race
  • a64648d README: replace gosh and fuzzing with a sponsorship summary
  • 1599bef syntax: allow pound signs in associative array keys
  • 971ffa8 syntax: add test cases for issue #1285
  • 4da6033 interp: note that Params should be split in v4
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mvdan.cc/sh/v3](https://github.com/mvdan/sh) from 3.13.1 to 3.14.0.
- [Release notes](https://github.com/mvdan/sh/releases)
- [Changelog](https://github.com/mvdan/sh/blob/master/CHANGELOG.md)
- [Commits](mvdan/sh@v3.13.1...v3.14.0)

---
updated-dependencies:
- dependency-name: mvdan.cc/sh/v3
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 1, 2026
@josegonzalez
josegonzalez merged commit 4f491b6 into main Sep 1, 2026
19 checks passed
@josegonzalez
josegonzalez deleted the dependabot/go_modules/mvdan.cc/sh/v3-3.14.0 branch September 1, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant