NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4807 most downloaded on npm
Last release 8 days ago
26 Sep 2026
Too new to tell
only 2 release windows
Nearly every release is documented
notes for 6 of 6 stable releases
1 version withdrawn
withdrawn after publishing
6 months old
7 releases · first in 2026
One column per month.
Thanks to @oss-security-shopify for identifying the vulnerability.
68874c2: Add VISUAL environment variable to set of allowUnsafeEditor environment variables.
Thanks to @oss-security-shopify for identifying the vulnerability.
Adds detection for includeIf.<condition>.path , thanks to @NotAFlightRisk for identifying the vulnerability
98864c6: Updates ahead of the v4 release for simple-git.
Adds support for TypeScript declaration maps
Exports the isGitEnvKey helper to detect whether an environment variable can be used to configure a git operation
Adds detection for includeIf.<condition>.path, thanks to @NotAFlightRisk for identifying the vulnerability
c427fba: Additional argument parser vulnerability checks:
include.path, filter.*.processurl.*.insteadOf1bb14df: Vulnerability detection expanded to include pager.*, uploadpack.packObjectsHook, difftool.*.cmd and use of the GIT_CONFIG_PARAMETERS environment variable
Thanks to @threalwinky and @nuc13us for identifying.
dfeb116: Vulnerability detection expanded to cover configuration delivered through path-taking global options, where
the dangerous value is a file on disk rather than a token simple-git can inspect:
--exec-path names the directory git loads built-in commands and remote helpers from, and is blockedallowUnsafeExec category along with the GIT_EXEC_PATH environment variable (previouslyallowUnsafeConfigPaths)--git-dir, --work-tree and -C cause git to read the configuration of the repository they name, andallowUnsafeConfigPathsThese options are only detected when supplied before the git sub-command and with a value - used as getters
(git.raw('rev-parse', '--git-dir')) or as task options (git.raw('commit', '-C', 'HEAD~1')) they are
unaffected.
d762810: Add allowUnsafeExec detection to rebase -x and rebase --exec.
Thanks to @gdegrange for the vulnerability report.
d762810: Add allowUnsafeCommandBinaries detection to configuring trailer.<token>.cmd and trailer.<token>.command.
Thanks to @sec-reex for the vulnerability report.
Updated dependencies [98864c6]
c38a674 : Add backward compatible API, resolves issue caused by using simple-git@3.35.2 with @simple-git/argv-parser@1.1.0
Note - ParsedVulnerabilities from argv-parser is removed in favour of a readonly array of Vulnerability to match usage in simple-git , rolled into the…
89a2294: Extend known exploitable configuration keys and per-task environment variables.
Note - ParsedVulnerabilities from argv-parser is removed in favour of a readonly array of Vulnerability to match usage in simple-git, rolled into the new vulnerabilityCheck for simpler access to the identified issues.
Thanks to @zebbern for identifying the need to block core.fsmonitor.
Thanks to @kodareef5 for identifying the need to block GIT_CONFIG_COUNT environment variables and --template / merge related config.
0cf9d8c: Improvements for mono-repo publishing pipeline
0de400e: Update monorepo version handling during publish
3d8708b: Updating publish config
Your coding agent can read these notes before it upgrades. Set up the MCP server →