Skip to content

V4 - #1193

Merged
steveukx merged 54 commits into
mainfrom
v4/playground
Sep 23, 2026
Merged

V4#1193
steveukx merged 54 commits into
mainfrom
v4/playground

Conversation

@steveukx

@steveukx steveukx commented Sep 1, 2026 •

Copy link
Copy Markdown
Owner

Early versions of simple-git would rely solely on the caller to sanitise data, acting primarily as a tool to help create, schedule, chain and parse git tasks. As v3 introduced the unsafe plugin to detect and block potentially vulnerable task configurations, allowing a greater level of protection for callers that are not sanitising their input data, the approach to date has been to add vulnerabilities as they are identified.

The v4 approach extends v3's unsafe plugin to now reject abbreviated option names and to filter/reject git impacting environment variables without explicitly opting in to this behaviour.

As part of the v4 major change, simple-git will also drop support for the "default" export in both cjs and esm formats, and remove the gitP and /promise exports that were deprecated during the v2-v3 update.

@changeset-bot

changeset-bot Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d5f9cd

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 9 packages
Name Type
simple-git Major
@simple-git/args-pathspec Patch
@simple-git/argv-parser Major
@simple-git/test-javascript-cjs-consumer Patch
@simple-git/test-javascript-esm-consumer Patch
@simple-git/test-typescript-cjs-consumer Patch
@simple-git/test-typescript-esm-consumer Patch
@simple-git/test-typescript-strict-cjs-consumer Patch
@simple-git/test-typescript-strict-esm-consumer Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

…ent variable to disable abbreviations in `git` commands
…ent variable to disable abbreviations in `git` commands
… and remove test asserting ability to use a default export on `simple-git`
- Remove duplication in consumer tests
- Remove babel configuration, obsolete following move to vitest
- remove `console.warn` when permitting unsafe (configured through `unsafe.allowUnsafeCustomBinary`)
…er than full removal of `scripts` and `devDependencies`.

- `typescript-esm-consumer` package updated to build ESM JavaScript (includes type check) then run directly with node (includes validation of exported functionality).
…unning (directly via node to avoid any inline TS transpilation by TSX)

- removed obsolete block from biome config
- `simple-git` depends on current workspace version rather than `^` version of arv-parser, avoids inconsistency in vulnerability detection expectations, noting an upgrade to argv-parser will require a new release of `simple-git`.
@steveukx

Copy link
Copy Markdown
Owner Author

Closes #1194
Closes #1190

@steveukx
steveukx merged commit 98864c6 into main Sep 23, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant