[DPEDE-1784](deps): Bump shell-quote from 1.8.3 to 1.8.4 - #2094
[DPEDE-1784](deps): Bump shell-quote from 1.8.3 to 1.8.4#2094dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4. - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.8.3...v1.8.4) --- updated-dependencies: - dependency-name: shell-quote dependency-version: 1.8.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
SonarQube Quality Gate |
|
The CI pipeline has run successfully in https://jenkinsprod.corp.intranet:8443/job/UX-CHI/job/Productive/job/Chi/job/PR-2094/1/. ✅ |
|
You can check this PRs instance in https://nginx-pr-2094-ux-chi.rke-odc-test.corp.intranet (internal) |
|
🔖 AiFEL verdict — 🚨 Escalate (ci-health) — human review required
TL;DR
📋 Why this route + what AiFEL checked (click to expand)Why this route?escalate because: critical CI confidence is Escalation category: Confidence breakdown — score:
What AiFEL checked
Will merging break your code?✅ Per AiFEL analysis, most likely won't impact your code. shell-quote is not imported anywhere in this repo's source, so no change in this bump — including the tilde-escaping and linear-time parse fixes — can reach your code paths. Security advisories✅ Nothing still affects ✅ Resolved by this bump (1): The two other advisories on record were historical and never applicable to the installed version range: ✅ This bump resolves all known advisories and none affect Packages — what you have vs what this PR installs
Machine-readable verdict{
"schema_version": "1.1",
"classification": "patch",
"risk_band": "low",
"ci_confidence": "low",
"decision_route": "escalate",
"data_completeness": "complete",
"escalate_reason": "risk",
"missing_signals": [],
"confidence": 0.85,
"packages": [{"ecosystem": "npm", "name": "shell-quote", "old_version": "1.8.3", "new_version": "1.8.4"}],
"breaking_changes": [],
"cascade_conflicts": [],
"summary": "Patch bump shell-quote 1.8.3→1.8.4: package unused in repo (blast radius zero), fixes GHSA-w7jw-789q-3m8p (CVSS 8.1), no advisories affect v1.8.4. Escalated on ci-health only (64.3% pass rate, 28 critical runs on default branch).",
"upgrade_risk_note": null,
"cross_repo_signal": "standalone",
"api_usage_found": false,
"advisory_ids": [],
"max_cvss": null,
"feedback_capture_marker": "aifel-CenturyLink-Chi-2094",
"agent_version": "1.1.1-aw"
}
|
|
Superseded by #2128. |
|
Removed the Kubernetes allocated resources |
1 similar comment
|
Removed the Kubernetes allocated resources |








Bumps shell-quote from 1.8.3 to 1.8.4.
Changelog
Sourced from shell-quote's changelog.
Commits
ff166e2v1.8.44378a6e[Fix]quote: validate object-token shapes22ebec0[Dev Deps] update@ljharb/eslint-config,auto-changelog,eslint, `npmig...9f3caa3[Tests] increase coverage3344a04[readme] replace runkit CI badge with shields.io check-runs badge699c511[Dev Deps] update@ljharb/eslint-configYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.