Skip to content

[dep] Bump simple-git to 3.33.0#2155

Merged
Drarig29 merged 1 commit into
masterfrom
corentin.girard/simple-git
Mar 11, 2026
Merged

[dep] Bump simple-git to 3.33.0#2155
Drarig29 merged 1 commit into
masterfrom
corentin.girard/simple-git

Conversation

@Drarig29

Copy link
Copy Markdown
Contributor

What and why?

Closes #2154

This PR bumps simple-git to fix a vulnerability.

How?

Bump all our direct dependencies.

Review checklist

  • Feature or bugfix MUST have appropriate tests (unit, integration)

@Drarig29 Drarig29 added the dependencies Pull requests that update a dependency file label Mar 11, 2026
@Drarig29 Drarig29 marked this pull request as ready for review March 11, 2026 11:41
@Drarig29 Drarig29 requested review from a team as code owners March 11, 2026 11:41
@Drarig29 Drarig29 merged commit ba6f3ac into master Mar 11, 2026
28 checks passed
@Drarig29 Drarig29 deleted the corentin.girard/simple-git branch March 11, 2026 11:51
@kushalraid

Copy link
Copy Markdown

Thank you for this fix. do you have any timeline to release this?

@Drarig29 Drarig29 mentioned this pull request Mar 12, 2026
@Drarig29

Copy link
Copy Markdown
Contributor Author

Hi @kushalraid! It's released in v5.9.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2026-28292 - simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

3 participants