shx icon indicating copy to clipboard operation
shx copied to clipboard

Publish a new release to fix security issue

Open fwielstra opened this issue 3 months ago • 0 comments

Our (Gitlab) based security scanner flagged up an issue in Execa 1.0.0, which was in our dependency chain via shx and shelljs. Shelljs was fixed in April (https://github.com/shelljs/shelljs/pull/1216) and it was updated in shx in May (https://github.com/shelljs/shx/commit/0f1ea07de7816304e8d1d8ebd7dc030e7cd6c7b0), fixing the security issue, but the latest release of shx (0.4.0) was done in March.

Please publish a new version so that any users of shx can update. It's not a huge security issue for us, it's just the security dashboard being a bit panicky.

fwielstra avatar Oct 14 '25 14:10 fwielstra