Skip to content

fix(build): bump shell-quote to 1.11.0 to clear critical grype finding - #863

Open
Alain Uyidi (auyidi1) wants to merge 1 commit into
mainfrom
fix/shell-quote-critical
Open

Alain Uyidi (auyidi1) wants to merge 1 commit into
mainfrom
fix/shell-quote-critical

Conversation

@auyidi1

Copy link
Copy Markdown
Contributor

Pull Request

Description

Fixes the critical Grype finding that currently fails Security Scan on every pull request: shell-quote 1.10.0 (GHSA-pqg4-j6r4-53mv, fixed in 1.11.0). The package is a transitive dependency of launch-editor in docs/docusaurus.

  • docs/docusaurus/package.json: the existing shell-quote override goes from ^1.8.4 to ^1.11.0.
  • docs/docusaurus/package-lock.json: only the node_modules/shell-quote entry changes, to 1.11.0, with its registry tarball and integrity. Regenerating the full lockfile with the local npm version would have rewritten unrelated libc fields, so I left those alone.

Related Issue

None. Security Scan fails on main-based PRs, including #846, #847, #849, and #851.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Blueprint modification or addition
  • Component modification or addition
  • Documentation update
  • CI/CD pipeline change
  • Other (please describe): dependency security update

Testing Performed

  • Terraform plan/apply
  • Blueprint deployment test
  • Unit tests
  • Integration tests
  • Bug fix includes regression test (see Test Policy)
  • Manual validation
  • Other: Grype scan

Validation Steps

  1. npm ci --dry-run --ignore-scripts in docs/docusaurus accepts the lockfile.
  2. grype dir:. --config .grype.yaml --fail-on high, the Security Scan threshold, exits 0.
  3. shell-quote 1.11.0 has no runtime dependencies and the same engines (node >= 0.4).

Checklist

  • I have updated the documentation accordingly
  • I have added tests to cover my changes
  • All new and existing tests passed
  • I have run terraform fmt on all Terraform code
  • I have run terraform validate on all Terraform code
  • I have run az bicep format on all Bicep code
  • I have run az bicep build to validate all Bicep code
  • I have checked for any sensitive data/tokens that should not be committed
  • Lint checks pass (run applicable linters for changed file types)

Security Review

  • No credentials, secrets, or tokens are hardcoded or logged
  • RBAC and identity changes follow least-privilege principles
  • No new network exposure or public endpoints introduced without justification
  • Dependency additions or updates have been reviewed for known vulnerabilities
  • Container image changes use pinned digests or SHA references

- raise the docs/docusaurus shell-quote override to ^1.11.0
- update the lockfile entry to 1.11.0 (GHSA-pqg4-j6r4-53mv)

🔒 - Generated by Copilot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

📚 Documentation Health Report

Generated on: 2026-10-07 17:57:19 UTC

📈 Documentation Statistics

Category File Count
Main Documentation 223
Infrastructure Components 232
Blueprints 40
GitHub Resources 26
AI Assistant Guides (Copilot) 17
Total 538

🏗️ Three-Tree Architecture Status

  • ✅ Bicep Documentation Tree: Auto-generated navigation
  • ✅ Terraform Documentation Tree: Auto-generated navigation
  • ✅ README Documentation Tree: Manual README organization

🔍 Quality Metrics

  • Frontmatter Validation:
    success
  • Link Validation: success

This report is automatically generated by the Documentation Automation workflow.

Comment thread docs/docusaurus/package-lock.json

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants