Repository navigation
release: publish Web Console 1.6.179 with official shell-quote fix - #183
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Web Console 1.6.178 predates the reviewed dependency updates merged in #180 and #182. The first 1.6.179 validation failed closed on newly published Critical GHSA-pqg4-j6r4-53mv in shell-quote 1.10.0, and produced no artifact. This PR prepares 1.6.179 from main at 629e571 and fixes that dependency in both npm and the packaged browser copy with official minimum-fixed 1.11.0.
The shell-quote browser wrapper and application callers are unchanged; module bodies come from the integrity-verified official package. Existing product callers do not establish the advisory's comment-then-string attack precondition, so this is library remediation rather than a confirmed product command-injection claim. Changes also include numeric release metadata, matching reviewed lock files, existing gate version constants, focused npm/browser regressions, vendor provenance, README and the release note. The dependency node set, workflow, Critical/High threshold and dated vendor-pending decision are unchanged.
Validation: the old vendored library accepted all four hostile line terminators; the patched vendor and official npm source reject 16 hostile cases and preserve 14 legitimate controls. Exact-source formal CI https://github.com/PastureStack/web-console/actions/runs/37502593612 passed 851/851 Chrome unit tests with zero failure, skip or todo, all source/supply-chain gates, cold Node 24 lock restoration and two byte-identical production archives. Its live unchanged audit gate reports Critical 0 / High 7 / Moderate 28, with only the existing exact High vendor-pending closure. Required CodeQL checks pass. Source 826bff5 has a verified signature; tested tree e81c53f72a1ed9b04cb8523af10c98e4c666c3b7. The retained archive is 2,987,712 bytes, SHA-256 1bb7e0acf7040738f2c6413046553609cbbaf14b833abb6ef2c7237b453eaf90. Local metadata checks confirm matching numeric roots, byte-identical reviewed lock files and no other changed dependency node; git diff --check and syntax checks pass. First failed CI https://github.com/PastureStack/web-console/actions/runs/37500749166 remains recorded. Publication reuses the retained CI archive and checksum after normal signed squash merge with a new numeric tag; existing tags and assets remain immutable. Server assembly and deployed acceptance are separate results.