Skip to content

Version Packages - #1164

Merged
steveukx merged 1 commit into
mainfrom
changeset-release/main
Sep 25, 2026
Merged

steveukx merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented May 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@simple-git/argv-parser@2.0.0

Major Changes

  • 98864c6: Updates ahead of the v4 release for simple-git.

    • Adds support for TypeScript declaration maps

    • Exports the isGitEnvKey helper to detect whether an environment variable can be used to configure a git operation

    • Adds detection for includeIf.<condition>.path, thanks to @NotAFlightRisk for identifying the vulnerability

Patch Changes

  • c427fba: Additional argument parser vulnerability checks:

    • Thanks to @mrillicit for identifying include.path, filter.*.process
    • Thanks to @tejas619 for identifying url.*.insteadOf
  • 1bb14df: Vulnerability detection expanded to include pager.*, uploadpack.packObjectsHook, difftool.*.cmd and use of the GIT_CONFIG_PARAMETERS environment variable

    Thanks to @threalwinky and @nuc13us for identifying.

  • dfeb116: Vulnerability detection expanded to cover configuration delivered through path-taking global options, where
    the dangerous value is a file on disk rather than a token simple-git can inspect:

    • --exec-path names the directory git loads built-in commands and remote helpers from, and is blocked
      under the new allowUnsafeExec category along with the GIT_EXEC_PATH environment variable (previously
      grouped under allowUnsafeConfigPaths)
    • --git-dir, --work-tree and -C cause git to read the configuration of the repository they name, and
      are blocked under allowUnsafeConfigPaths

    These options are only detected when supplied before the git sub-command and with a value - used as getters
    (git.raw('rev-parse', '--git-dir')) or as task options (git.raw('commit', '-C', 'HEAD~1')) they are
    unaffected.

  • d762810: Add allowUnsafeExec detection to rebase -x and rebase --exec.

    Thanks to @gdegrange for the vulnerability report.

  • d762810: Add allowUnsafeCommandBinaries detection to configuring trailer.<token>.cmd and trailer.<token>.command.

    Thanks to @sec-reex for the vulnerability report.

  • Updated dependencies [98864c6]

    • @simple-git/args-pathspec@1.0.4

simple-git@4.0.0

Major Changes

  • 98864c6: Major upgrade to v4. In this version:

    • Removed previously available default export, now uses a consistently named simpleGit export.
    • Removed previously deprecated import simple-git/promise (change to using the main simple-git import).
    • Removed legacy gitP export (change to using the main simpleGit export).
    // v3 - previously supported imports
    import simpleGit from "simple-git";
    import { gitP } from "simple-git";
    import simpleGit from "simple-git/promise";
    const simpleGit = require("simple-git");
    
    // v4 - consolidates to a single supported import
    import { simpleGit } from "simple-git";
    const { simpleGit } = require("simple-git");
    • Prevents the use of abbreviated long-form git options:
    // v3 - allowed the use of unambiguous long-form options
    git.raw("clone", "--conf=user.name=me", "...");
    
    // v4 - requires full option names, abbreviated option names will now throw a GitConfigurationError
    git.raw("fetch", "--config=user.name=me", "...");
    • Ambient environment variables are filtered before passing into the git child process.
    // v3
    process.env.FOO = "bar";
    process.env.GIT_TEMPLATE_DIR = "./some/path";
    simpleGit().raw("clone"); // git child process can see both environment variables
    
    // v4
    process.env.FOO = "bar";
    process.env.GIT_TEMPLATE_DIR = "./some/path";
    simpleGit().raw("clone"); // git child process now sees only FOO
    
    simpleGit({
      // explicitly allow the named environment variable so it can pass through.
      allowEnvoronment: ["GIT_TEMPLATE_DIR"],
      // and enable the use of an unsafe behaviour
      unsafe: { allowUnsafeTemplateDir: true },
    });
    • Explicitly supplied disallowed environment variables will throw when used.
    // v3 used a single opt-in to potential unsafe actiity
    simpleGit({ unsafe: { allowUnsafeTemplateDir: true } })
      .env({ GIT_TEMPLATE_DIR: "./foo" })
      .init();
    
    // v4 uses a double opt-in, allow the behaviour and the mechanism
    simpleGit({
      allowEnvoronment: ["GIT_TEMPLATE_DIR"],
      unsafe: { allowUnsafeTemplateDir: true },
    })
      .env({ GIT_TEMPLATE_DIR: "./foo" })
      .init();
    • Removed content deprecated during the v2 to v3 major change
      • simpleGit.silent() logging is configured through environment variables in the debug package
      • simpleGit.clearQueue() this has been a noop since v3, switch to using the abort plugin
      • Accessing parsed properties of a GitResponseError through a trailing callback function are available only through the error.git property (previously properties were also spread onto the error itself with a deprecation notice).

Minor Changes

  • 98864c6: Support one-shot stdin via git.input(data) (string or Buffer).

    Thanks to @felipecrs for the feature request and initial implementation.

Patch Changes

  • d762810: Add allowUnsafeExec detection to rebase -x and rebase --exec.

    Thanks to @gdegrange for the vulnerability report.

  • 76f308e: Parse binary rename entries without byte counts in diff summaries.

  • Updated dependencies [c427fba]

  • Updated dependencies [1bb14df]

  • Updated dependencies [dfeb116]

  • Updated dependencies [d762810]

  • Updated dependencies [d762810]

  • Updated dependencies [98864c6]

    • @simple-git/argv-parser@2.0.0
    • @simple-git/args-pathspec@1.0.4

@simple-git/args-pathspec@1.0.4

Patch Changes

  • 98864c6: Updates ahead of the v4 release for simple-git.

    • Adds support for TypeScript declaration maps

    • Exports the isGitEnvKey helper to detect whether an environment variable can be used to configure a git operation

    • Adds detection for includeIf.<condition>.path, thanks to @NotAFlightRisk for identifying the vulnerability

@simple-git/test-javascript-cjs-consumer@1.0.2

Patch Changes

  • Updated dependencies [98864c6]
  • Updated dependencies [d762810]
  • Updated dependencies [98864c6]
  • Updated dependencies [76f308e]
    • simple-git@4.0.0

@simple-git/test-javascript-esm-consumer@1.0.2

Patch Changes

  • Updated dependencies [98864c6]
  • Updated dependencies [d762810]
  • Updated dependencies [98864c6]
  • Updated dependencies [76f308e]
    • simple-git@4.0.0

@simple-git/test-typescript-cjs-consumer@1.0.2

Patch Changes

  • Updated dependencies [98864c6]
  • Updated dependencies [d762810]
  • Updated dependencies [98864c6]
  • Updated dependencies [76f308e]
    • simple-git@4.0.0

@simple-git/test-typescript-esm-consumer@1.0.2

Patch Changes

  • Updated dependencies [98864c6]
  • Updated dependencies [d762810]
  • Updated dependencies [98864c6]
  • Updated dependencies [76f308e]
    • simple-git@4.0.0

@simple-git/test-typescript-strict-cjs-consumer@1.0.2

Patch Changes

  • Updated dependencies [98864c6]
  • Updated dependencies [d762810]
  • Updated dependencies [98864c6]
  • Updated dependencies [76f308e]
    • simple-git@4.0.0

@simple-git/test-typescript-strict-esm-consumer@1.0.2

Patch Changes

  • Updated dependencies [98864c6]
  • Updated dependencies [d762810]
  • Updated dependencies [98864c6]
  • Updated dependencies [76f308e]
    • simple-git@4.0.0

@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 87cdd64 to f1d1b4b Compare May 10, 2026 20:40
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from 8cf37d0 to 812d8a6 Compare September 25, 2026 07:56
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 812d8a6 to 3971917 Compare September 25, 2026 09:49
@steveukx
steveukx merged commit 0e9ebab into main Sep 25, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant