Skip to content

chore: upgrade shell-quote to ^1.10.0 to address CVE-2026-13311#1469

Merged
jsourcebot merged 4 commits into
mainfrom
linear/sou-1550-sourcebot-devsourcebot-cve-2026-13311-shell-quote-shell-9e91
Jul 23, 2026
Merged

chore: upgrade shell-quote to ^1.10.0 to address CVE-2026-13311#1469
jsourcebot merged 4 commits into
mainfrom
linear/sou-1550-sourcebot-devsourcebot-cve-2026-13311-shell-quote-shell-9e91

Conversation

@linear-code

@linear-code linear-code Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1550

Resolves CVE-2026-13311 (HIGH), a denial-of-service in shell-quote's parse() where finalizing tokens with Array.prototype.concat as a reduce accumulator makes parsing run in O(n²). It reaches us transitively via npm-run-all and concurrently.

Both existing ranges (^1.6.1, ^1.8.4) already admit the patched release, so this is a lockfile refresh only (yarn up -R shell-quote) — no package.json change or resolutions override needed. shell-quote now resolves to 1.10.0, above the fixed 1.9.0.


Note

Low Risk
Lockfile-only transitive dependency bump for a dev-tooling package with no application code changes.

Overview
Bumps the transitive shell-quote dependency from 1.8.4 to 1.10.0 via a yarn.lock refresh only (no package.json edits), addressing CVE-2026-13311 (DoS in parse() from O(n²) token handling). The dependency is pulled in through dev tooling such as npm-run-all and concurrently.

Documents the upgrade under [Unreleased] → Fixed in CHANGELOG.md.

Reviewed by Cursor Bugbot for commit 70b88f3. Bugbot is set up for automated code reviews on this repo. Configure here.

linear-code Bot added 2 commits July 21, 2026 13:38
Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>
Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2222
Resolved (non-standard) 8
Unresolved 0
Strong copyleft 0
Weak copyleft 39

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.0.5 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-wasm32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.11 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (8)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/codemirror-lang-elixir LICENSE file)
khroma 2.1.0 UNKNOWN MIT npm registry metadata (license field)
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 npm registry metadata (license field)
map-stream 0.1.0 UNKNOWN MIT npm registry metadata (license field)
memorystream 0.3.1 UNKNOWN MIT extracted from licenses object type field (npm registry metadata)
pause-stream 0.0.11 MIT,Apache2 (MIT OR Apache-2.0) extracted from license array (npm registry metadata); Apache2 normalized to Apache-2.0
posthog-js 1.369.0 SEE LICENSE IN LICENSE MIT npm registry metadata (license field)
valid-url 1.0.9 UNKNOWN MIT GitHub repo (ogt/valid-url LICENSE file)

@brendan-kellam
brendan-kellam marked this pull request as ready for review July 21, 2026 14:08
@jsourcebot
jsourcebot merged commit 906af93 into main Jul 23, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant