Skip to content
This repository was archived by the owner on Sep 6, 2026. It is now read-only.

Add Socket patch for CVE-2026-9277 in pkg:npm/shell-quote@1.8.3 - #512

Open
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551818837-272d1e62
Open

Add Socket patch for CVE-2026-9277 in pkg:npm/shell-quote@1.8.3#512
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551818837-272d1e62

Conversation

@socket-security

Copy link
Copy Markdown

Summary

This PR updates Socket security patches for your dependencies.

These patches are applied via the Socket patch agent — .socket/manifest.json + a package.json postinstall hook.

Changes

  • Added: CVE-2026-9277 in pkg:npm/shell-quote@1.8.3 (Socket Patch)
    • Severity: CRITICAL
    • Summary: shell-quote quote() does not escape newlines in object .op values

Testing

Review the patches and test your application to ensure compatibility.


🔒 Powered by Socket Security

Updates:
- 1 blob(s) added
- 0 blob(s) removed
- Manifest updated
@linux-foundation-easycla

Copy link
Copy Markdown

CLA Not Signed

@codecov

codecov Bot commented Aug 12, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.85%. Comparing base (e20ec25) to head (73f733c).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #512   +/-   ##
=======================================
  Coverage   77.85%   77.85%           
=======================================
  Files           4        4           
  Lines         745      745           
  Branches      300      300           
=======================================
  Hits          580      580           
  Misses        136      136           
  Partials       29       29           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant