Skip to content

Commit 812d8a6

Browse files
Version Packages
1 parent 76f308e commit 812d8a6

25 files changed

Lines changed: 207 additions & 136 deletions

File tree

‎.changeset/calm-birds-listen.md‎

Lines changed: 0 additions & 7 deletions
This file was deleted.

‎.changeset/cyan-suits-sleep.md‎

Lines changed: 0 additions & 7 deletions
This file was deleted.

‎.changeset/hungry-kings-love.md‎

Lines changed: 0 additions & 7 deletions
This file was deleted.

‎.changeset/lucky-guards-block.md‎

Lines changed: 0 additions & 16 deletions
This file was deleted.

‎.changeset/sha-zam-four.md‎

Lines changed: 0 additions & 11 deletions
This file was deleted.

‎.changeset/slow-pens-hear.md‎

Lines changed: 0 additions & 74 deletions
This file was deleted.

‎.changeset/tiny-diffs-smile.md‎

Lines changed: 0 additions & 5 deletions
This file was deleted.

‎packages/args-pathspec/CHANGELOG.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,16 @@
11
# @simple-git/args-pathspec
22

3+
## 1.0.4
4+
5+
### Patch Changes
6+
7+
- 98864c6: Updates ahead of the v4 release for `simple-git`.
8+
9+
- Adds support for TypeScript declaration maps
10+
- Exports the `isGitEnvKey` helper to detect whether an environment variable can be used to configure a `git` operation
11+
12+
- Adds detection for `includeIf.<condition>.path`, thanks to @NotAFlightRisk for identifying the vulnerability
13+
314
## 1.0.3
415

516
### Patch Changes

‎packages/args-pathspec/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@simple-git/args-pathspec",
3-
"version": "1.0.3",
3+
"version": "1.0.4",
44
"publish": {
55
"main": "dist/index.cjs",
66
"module": "dist/index.mjs",

‎packages/argv-parser/CHANGELOG.md‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,41 @@
11
# @simple-git/argv-parser
22

3+
## 2.0.0
4+
5+
### Major Changes
6+
7+
- 98864c6: Updates ahead of the v4 release for `simple-git`.
8+
9+
- Adds support for TypeScript declaration maps
10+
- Exports the `isGitEnvKey` helper to detect whether an environment variable can be used to configure a `git` operation
11+
12+
- Adds detection for `includeIf.<condition>.path`, thanks to @NotAFlightRisk for identifying the vulnerability
13+
14+
### Patch Changes
15+
16+
- c427fba: Additional argument parser vulnerability checks:
17+
- Thanks to @mrillicit for identifying `include.path`, `filter.*.process`
18+
- Thanks to @tejas619 for identifying `url.*.insteadOf`
19+
- 1bb14df: Vulnerability detection expanded to include `pager.*`, `uploadpack.packObjectsHook`, `difftool.*.cmd` and use of the `GIT_CONFIG_PARAMETERS` environment variable
20+
21+
Thanks to @threalwinky and @nuc13us for identifying.
22+
23+
- dfeb116: Vulnerability detection expanded to cover configuration delivered through path-taking global options, where
24+
the dangerous value is a file on disk rather than a token `simple-git` can inspect:
25+
26+
- `--exec-path` names the directory `git` loads built-in commands and remote helpers from, and is blocked
27+
under the new `allowUnsafeExec` category along with the `GIT_EXEC_PATH` environment variable (previously
28+
grouped under `allowUnsafeConfigPaths`)
29+
- `--git-dir`, `--work-tree` and `-C` cause `git` to read the configuration of the repository they name, and
30+
are blocked under `allowUnsafeConfigPaths`
31+
32+
These options are only detected when supplied before the git sub-command and with a value - used as getters
33+
(`git.raw('rev-parse', '--git-dir')`) or as task options (`git.raw('commit', '-C', 'HEAD~1')`) they are
34+
unaffected.
35+
36+
- Updated dependencies [98864c6]
37+
- @simple-git/args-pathspec@1.0.4
38+
339
## 1.1.1
440

541
### Patch Changes

0 commit comments

Comments
 (0)