NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #94 most downloaded on crates.io
Split a string into shell words, like Python's shlex.
Last release 4 months ago
17 May 2026
Release timing varies
gaps range from 5 months to 5.6 years
Nearly every release is documented
notes for 9 of 9 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
9 releases · first in 2015
Fixes a compile error when building the documentation.
Breaking: Items that were marked as deprecated in 1.x have been removed: join, quote, bytes::join, and bytes::quote.
join, quote, bytes::join, and bytes::quote.DerefMut impl for Shlex has been removed since it was unsound. New unsafe APIs have been added in its place: Shlex::from_bytes, Shlex::as_bytes_mut.One column per quarter.
Since this is a security fix, ideally the MSRV wouldn't be bumped at all, but that's not really feasible since the new API uses #[non_exhaustive] , wh…
Ref: GHSA-r7qv-8r2h-pg27
Deprecate quote APIs in favor of try_ equivalents that complain
about nul bytes.
Also add a builder API, which allows re-enabling nul bytes without
using the deprecated interface, and in the future can allow other
things (as discussed in quoting_warning).
Add documentation about various security risks that remain,
particularly with interactive shells.
Add fuzzers that actually verify round-trippability of the quote APIs
against various shells, Python shlex, and C wordexp.
These are separate crates (as opposed to just being different files
under fuzz/fuzz_targets) because they have different dependencies
and build steps, and I don't want to agglomerate them all together.
I've put them in the same workspace at least.
Also, check in Cargo.lock for the fuzzers, since they are binaries.
Add explicit MSRV of 1.46.0.
This crate didn't previously have an explicit MSRV, but cargo msrv
tells me that shlex 1.2.0 works down to Rust 1.36.0.
Since this is a security fix, ideally the MSRV wouldn't be bumped at
all, but that's not really feasible since the new API uses
#[non_exhaustive], which was unstable in Rust 1.36.0. In case anyone
is stuck on old Rust versions, I separately released a shlex 1.2.1 that
only has the fix for {/}/\xa0, without the API changes.
However, even for the full release I'd still like to keep the MSRV
reasonably old. I picked 1.46.0 because it's the first version that
wouldn't require completely redoing the const fn bitmask.
Add more authors to Cargo.toml based on Git commits.
try_ equivalents that complain about nul bytes.Ref: GHSA-r7qv-8r2h-pg27
Ref: GHSA-r7qv-8r2h-pg27
{ and \xa0 are now escaped by quoting functions.Adds bytes module to support operating directly on byte strings.
bytes module to support operating directly on byte strings.Adds the std feature (enabled by default).
std feature (enabled by default).std feature makes the crate work in #![no_std] mode, assuming presence of the alloc crate.Adds the join convenience function.
join convenience function.'\\n' to match the behavior of bash/Zsh/Python shlex. The result was previously \n, now it is \\n.add # quotes, which I forgot about
add # quotes, which I forgot about
This is the initial release.
This is the initial release.
Your coding agent can read these notes before it upgrades. Set up the MCP server →