Skip to content

chore(deps-dev): Bump just-bash from 3.4.2 to 3.6.0 - #402

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/just-bash-3.6.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/just-bash-3.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps just-bash from 3.4.2 to 3.6.0.

Release notes

Sourced from just-bash's releases.

just-bash@3.6.0

Minor Changes

  • #377 cc35fab Thanks @​trieloff! - Add the mktemp command. It creates a unique temporary file (mode 0600) or directory (-d, mode 0700) and prints its path, supporting -p/--tmpdir[=DIR], -t, -u/--dry-run, -q/--quiet, --suffix=SUFF, GNU-style TEMPLATE expansion, --help and --version. The default directory is $TMPDIR when set and non-empty, otherwise /tmp, so sandboxed embedders that point TMPDIR at a writable directory get a usable path. Random name characters come from the platform CSPRNG (crypto.getRandomValues), and existing paths are never returned.

    Adds an optional createExclusive(path, { mode, directory }) method to IFileSystem, which creates an entry only if the name is free and applies the mode at creation time rather than via a follow-up chmod. All built-in filesystems implement it. The member is optional, so external IFileSystem implementations remain source compatible; mktemp reports that such a filesystem cannot create atomically rather than substituting a non-atomic sequence. The accompanying CreateExclusiveOptions type is exported alongside the existing MkdirOptions/RmOptions.

  • #409 5d19cc3 Thanks @​trieloff! - Add the yes command. yes [STRING]... repeats a line built from its operands (y when there are none), so yes | head -3 and yes | some-prompt work instead of failing with exit 127. Because pipeline stages here run to completion rather than streaming, the stream is finite: it ends after executionLimits.maxLoopIterations lines, or earlier if the repeated line would exceed the output size limit.

Patch Changes

  • #445 7313062 Thanks @​trieloff! - interpreter: preserve complete associative-array values in declare -A compound assignments

    Quoted values containing whitespace were reconstructed without quoting before the declare builtin parsed them, so every value was silently truncated at its first space. Associative-array declarations now retain whitespace and other quoted content.

  • #346 52a5617 Thanks @​iroiro147! - fs: keep the Buffer-less fromBuffer fallback under the argument limit

    Without Buffer (for example in a Chrome extension service worker), fromBuffer converted base64, binary and latin1 content by spreading 64KB chunks into String.fromCharCode, which can exceed the engine's argument limit and throw RangeError: Maximum call stack size exceeded on a 64KB cat. The fallback now converts in 8KB chunks.

  • #443 a36c324 Thanks @​RyanGarber! - Handle accessor descriptors when installing module defense-in-depth proxies on Bun, preserving blocking behavior and original descriptors on teardown.

  • #414 31ac823 Thanks @​mutewinter! - find: report a directory it cannot read and keep going

    A readdir failure inside the traversal threw out of the whole search, so one unreadable directory ended find with no results: exit 1 and find: EACCES: permission denied, scandir '<path>' on its own, and exit 0 with nothing at all once piped through head with stderr silenced. Every macOS home directory holds such a directory (.Trash, several under Library), so a recursive find over a mounted home directory never returned anything.

    GNU find names the directory on stderr, continues with everything else, and exits 1 at the end. It now does the same here. The message is find: <path>: Permission denied, with the phrase taken from the errno alone, so nothing from the underlying error's text reaches the output. A failure that is not one of the errnos a directory read can produce (a cancellation, an execution limit, a filesystem policy refusal) still ends the search as before.

    Messages are emitted in traversal order beside the node's own output, whatever order the parallel batch settled in, and a failed read still counts toward the trace's readdirCalls and readdirTime.

  • #384 e0cca16 Thanks @​taoche! - Match real jq behavior for to_entries on arrays (numeric-key entries instead of null) and tonumber on empty or whitespace-only strings (error instead of 0).

  • #417 017a911 Thanks @​trieloff! - interpreter: give a loop left via break/continue status 0 instead of the last command's

    break and continue are builtins that return 0, and they are the last command a loop body runs. A loop exited through them reported the status of whatever ran before the break instead:

    while :; do false; break; done; echo $?            # was 1, bash says 0
    for i in 1; do false; break; done; echo $?         # was 1, bash says 0
    for i in 1 2; do false; continue; done; echo $?    # was 1, bash says 0

    All four loop forms were affected — for, C-style for, while, until — as was a break/continue in a while condition and a multi-level break 2 unwinding through an enclosing loop.

    The stale status is invisible until something reads $?, and under set -e the phantom failing loop ends the script with no output and no diagnostic:

    set -euo pipefail
    while :; do
      [ 5 -eq 0 ] && break     # correctly exempt from errexit as the left operand of &&
      break

... (truncated)

Commits
  • 7537a26 chore: release (#504)
  • 632090a chore(deps): update undici and smol-toml to patched versions (#509)
  • e0cca16 Fix jq to_entries on arrays and tonumber on empty strings (#384)
  • d91dce8 refactor(expansion): share pattern-removal compilation (#518)
  • 2d79d8b refactor(fs): simplify mount storage and routing (#517)
  • e9bc741 chore(network): remove unused request-owned DNS transport (#516)
  • f77efbd chore: make CONTRIBUTING.md the source of truth for commands and labels (#511)
  • d959d9f fix(curl): support request data from stdin (#411)
  • 9503e06 fix(expansion): assign array-valued parameter defaults (#519)
  • 701f8e5 fix(expansion): reject default assignment to positional parameters (#520)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [just-bash](https://github.com/vercel-labs/just-bash) from 3.4.2 to 3.6.0.
- [Release notes](https://github.com/vercel-labs/just-bash/releases)
- [Commits](https://github.com/vercel-labs/just-bash/compare/just-bash@3.4.2...just-bash@3.6.0)

---
updated-dependencies:
- dependency-name: just-bash
  dependency-version: 3.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants