NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2815 most downloaded on npm
Simple GIT interface for node.js
Last release 9 days ago
26 Sep 2026
Release timing varies
gaps range from 8 days to 9 months
Most releases are documented
notes for 53 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
277 releases · first in 2013
Thanks to @oss-security-shopify for identifying the vulnerability.
68874c2: Add VISUAL environment variable to set of allowUnsafeEditor environment variables.
Thanks to @oss-security-shopify for identifying the vulnerability.
Updated dependencies [68874c2]
365f52d : Prepare package.json before publishing.
One column per quarter.
Thanks to @gdegrange for the vulnerability report.
98864c6: Major upgrade to v4. In this version:
simpleGit export.simple-git/promise (change to using the main simple-git import).gitP export (change to using the main simpleGit export).// v3 - previously supported imports
import simpleGit from "simple-git";
import { gitP } from "simple-git";
import simpleGit from "simple-git/promise";
const simpleGit = require("simple-git");
// v4 - consolidates to a single supported import
import { simpleGit } from "simple-git";
const { simpleGit } = require("simple-git");git options:// v3 - allowed the use of unambiguous long-form options
git.raw("clone", "--conf=user.name=me", "...");
// v4 - requires full option names, abbreviated option names will now throw a GitConfigurationError
git.raw("fetch", "--config=user.name=me", "...");git child process.// v3
process.env.FOO = "bar";
process.env.GIT_TEMPLATE_DIR = "./some/path";
simpleGit().raw("clone"); // git child process can see both environment variables
// v4
process.env.FOO = "bar";
process.env.GIT_TEMPLATE_DIR = "./some/path";
simpleGit().raw("clone"); // git child process now sees only FOO
simpleGit({
// explicitly allow the named environment variable so it can pass through.
allowEnvoronment: ["GIT_TEMPLATE_DIR"],
// and enable the use of an unsafe behaviour
unsafe: { allowUnsafeTemplateDir: true },
});// v3 used a single opt-in to potential unsafe actiity
simpleGit({ unsafe: { allowUnsafeTemplateDir: true } })
.env({ GIT_TEMPLATE_DIR: "./foo" })
.init();
// v4 uses a double opt-in, allow the behaviour and the mechanism
simpleGit({
allowEnvoronment: ["GIT_TEMPLATE_DIR"],
unsafe: { allowUnsafeTemplateDir: true },
})
.env({ GIT_TEMPLATE_DIR: "./foo" })
.init();simpleGit.silent() logging is configured through environment variables in the debug packagesimpleGit.clearQueue() this has been a noop since v3, switch to using the abort pluginGitResponseError through a trailing callback function are available only through the error.git property (previously properties were also spread onto the error itself with a deprecation notice).98864c6: Support one-shot stdin via git.input(data) (string or Buffer).
Thanks to @felipecrs for the feature request and initial implementation.
d762810: Add allowUnsafeExec detection to rebase -x and rebase --exec.
Thanks to @gdegrange for the vulnerability report.
76f308e: Parse binary rename entries without byte counts in diff summaries.
Updated dependencies [c427fba]
Updated dependencies [1bb14df]
Updated dependencies [dfeb116]
Updated dependencies [d762810]
Updated dependencies [d762810]
Updated dependencies [98864c6]
Note - ParsedVulnerabilities from argv-parser is removed in favour of a readonly array of Vulnerability to match usage in simple-git , rolled into the…
89a2294: Extend known exploitable configuration keys and per-task environment variables.
Note - ParsedVulnerabilities from argv-parser is removed in favour of a readonly array of Vulnerability to match usage in simple-git, rolled into the new vulnerabilityCheck for simpler access to the identified issues.
Thanks to @zebbern for identifying the need to block core.fsmonitor.
Thanks to @kodareef5 for identifying the need to block GIT_CONFIG_COUNT environment variables and --template / merge related config.
0cf9d8c : Improvements for mono-repo publishing pipeline
0de400e : Update monorepo version handling during publish
3d8708b: Updating publish config
2b68331: Revised dependency tree to add helper modules as dependencies in main simple-git
simple-git2e1f51c: Enhances scanning of arguments before passing on to the spawned child_process.
Caters for -c flags prefixing the git task (used when setting global inline config) and suffixing with either -c, --config or --config-env. Detects git config operations that write to the configuration.
Updated dependencies [2e1f51c]
a263635: Use pathspec wrappers for remote and local paths when running either git.clone or git.mirror to avoid leaving them less open for unexpected o
pathspec wrappers for remote and local paths when running either git.clone or git.mirror to
avoid leaving them less open for unexpected outcomes when passing unsanitised data into these tasks.e253a0d: Enhanced git -c checks in unsafe plugin.
Thanks to @JohannesLks for identifying the issue
f704208: Enhanced protocol.allow checks in allowUnsafeExtProtocol handling.
f704208: Enhanced protocol.allow checks in allowUnsafeExtProtocol handling.
Thanks to @CodeAnt-AI-Security for identifying the issue
8d02097: Enhanced clone unsafe switch detection.
23b070f: Fix regex for detecting unsafe clone options
23b070f: Fix regex for detecting unsafe clone options
Thanks to @stevenwdv for reporting this issue.
Thanks to @JuHwiSang for identifying this as vulnerability.
1effd8e: Enhances the unsafe plugin to block additional cases where the -u switch may be disguised
along with other single character options.
Thanks to @JuHwiSang for identifying this as vulnerability.
a44184f: Resolve NPM publish steps
bc77774: Correctly identify current branch name when using git.status in a cloned empty repo.
bc77774: Correctly identify current branch name when using git.status in a cloned empty repo.
Previously git.status would report the current branch name as No. Thank you to @MaddyGuthridge for identifying this issue.
240ec64: Support for absolute paths on Windows when using git.checkIngore, previously Windows would report paths with duplicate separators \\\\ betwee
240ec64: Support for absolute paths on Windows when using git.checkIngore, previously Windows would report
paths with duplicate separators \\\\ between directories.
Following this change all paths returned from git.checkIgnore will be normalized through node:path,
this should have no impact on non-windows users where the git binary doesn't wrap absolute paths with
quotes.
Thanks to @Maxim-Mazurok for reporting this issue.
9872f84: Support the use of git.branch(['--show-current']) to limit the branch list to only the current branch.
Thanks to @peterbe for pointing out the use-case.
5736bd8: Change to biome for lint and format
2adf47d: Allow repeating git options like {'--opt': ['value1', 'value2']}
{'--opt': ['value1', 'value2']}52f767b: Add similarity to the DiffResultNameStatusFile interface used when fetching log/diff with the --name-status option.
similarity to the DiffResultNameStatusFile interface used when fetching log/diff with the --name-status option.--name-status option.files array returned by git.status.
Thank you @mark-codesphere for the contribution.28d545b: Upgrade build tools and typescript
0a5378d: Add support for parsing count-objects
count-objectsc355317: Enable the use of a two part custom binary
9bfdf08: Bump package manager from yarn v1 to v4
df14065: add status to DiffResult when using --name-status
709d80e: Add firstCommit utility interface
2eda817: Use pathspec in git.log to allow use of previously deleted files in file argument
pathspec in git.log to allow use of previously deleted files in file argument2ab1936: keep path splitter without path specs
f702b61: Create a utility to append pathspec / file lists to tasks through the TaskOptions array/object
5100f04: Add new interface for showBuffer to allow using git show on binary files.
git show on binary files.a63cfc2: Timeout plugin can now be configured to ignore data on either stdOut or stdErr in the git process when determining whether to kill the spawne
066b228: Fix overly permissive regex in push parser
0a623e5: Adds vulnerability detection to prevent use of --upload-pack and --receive-pack without explicitly opting in.
-B in place of the default -b in checkout methods--upload-pack and --receive-pack without explicitly opting in.de570ac: Resolves an issue whereby non-strings can be passed into the config switch detector.
7746480: Disables the use of inline configuration arguments to prevent unitentionally allowing non-standard remote protocols without explicitly opting
allowUnsafeProtocolOverride property having been enabled.5a2e7e4: Add version parsing support for non-numeric patches (including "built from source" style 1.11.GIT)
1.11.GIT)19029fc: Create the abort plugin to allow cancelling all pending and future tasks.
.version to return git version information, including whether the git binary is installed.87b0d75: Increase the level of deprecation notices for use of simple-git/promise, which will be fully removed in the next major
simple-git/promise, which will be fully removed in the next majorbfd652b: Add a new configuration option to enable trimming white-space from the response to git.raw
git.raw80d54bd: Added fields updated + deleted branch info to fetch response, closes #823
2f021e7: Support for importing as an ES module with TypeScript moduleResolution node16 or newer by adding simpleGit as a named export.
node16 or newer by adding
simpleGit as a named export.a0d4eb8: Branches that have been checked out as a linked work tree will now be included in the BranchSummary output, with a linkedWorkTree property se
BranchSummary output, with a linkedWorkTree property set to true in the BranchSummaryBranch.25230cb: Support for additional log formats in diffSummary / log / stashList.
25230cb: Support for additional log formats in diffSummary / log / stashList.
Adds support for the --numstat, --name-only and --name-stat in addition to the existing --stat option.
debug dependency to latest 4.xadb4346: Resolves issue whereby renamed files no longer appear correctly in the response to git.status.
git.status.fa2c7f7: Enable the use of types when loading with module-resolution
f2fc5c9: Show full commit hash in a CommitResult, prior to this change git.commit would result in a partial hash in the commit property if core.abbrev
CommitResult, prior to this change git.commit would result in a partial hash in the commit property if core.abbrev is unset or has a value under 40. Following this change the commit property will contain the full commit hash.2040de6: Resolves potential command injection vulnerability by preventing use of --upload-pack in git.clone
--upload-pack in git.cloneed412ef: Use null separators in git.status to allow for non-ascii file names
d119ec4: Resolves potential command injection vulnerability by preventing use of --upload-pack in git.fetch
--upload-pack in git.fetch80651d5: Resolve issue in prePublish script
d35987b: Release with changesets
Nothing published for this version
Backward compatibility - permit loading simple-git/promise with deprecation notice until mid-2022.
latest (5db4434)simple-git/promise with deprecation notice until mid-2022. (4413c47)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
StatusResult returned by git.status() should include detached state of the working copy.
Nothing published for this version
### Features - git-grep
completion plugin to allow configuring when simple-git determines the git tasks to be complete.
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →