Skip to content

chore(deps): update dependency nx to v22.7.10 [security] - #520

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-nx-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-nx-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
nx (source) 22.1.3 → 22.7.10 age confidence

nx graph dev server permissive CORS policy

CVE-2026-54753 / GHSA-g2r8-wvmj-jf5w

More information

Details

Summary

The local HTTP server started by nx graph sent Access-Control-Allow-Origin: * on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the /help endpoint, which runs a target's configured help command. The practical impact is typically cross-origin information disclosure, but can be arbitrary command injection in rare cases.

Severity

Exploitation requires the developer to be running nx graph and to visit an attacker page. Any execution beyond benign help commands also requires a malicious target to already be present in the workspace (see Details).

Affected & Patched Versions

Package: nx (npm).

  • Affected: >= 17.0.4, < 22.7.2 and >= 23.0.0-beta.0, < 23.0.0-beta.2
  • Patched: 22.7.2+ (backport) and 23.0.0 (first in 23.0.0-beta.2)

The wildcard CORS header was introduced in 17.0.4; the /help execution endpoint in 19.4.0. The 21.x line is not patched — 21.x users should upgrade to 22.7.2 or later.

Details

nx graph starts a local server (default http://127.0.0.1:4211). Before the fix, its request handler set a wildcard CORS header on every response:

res.setHeader('Access-Control-Allow-Origin', '*');

The /help endpoint runs a target's configured command:

const command = target.metadata?.help?.command;
return execSync(command, { cwd: target.options?.cwd ?? workspaceRoot }).toString();

A GET /help is a CORS "simple request", so a malicious page could fetch() it with no preflight, and the wildcard header let the page read the result. This exposes the project graph (project names, file paths, dependencies, build configuration) and the output of any configured help command.

The command is not attacker-controlled through the request — it comes from the workspace's project configuration, and first-party plugins (jest, vite, cypress) populate it with benign, read-only help commands. For /help to run anything malicious, a target carrying a malicious help.command must already exist in the project graph, which can only be introduced by installing a malicious package or by altering the workspace's own code/configuration — both of which already grant code execution independent of this flaw.

The fix (#​35494) removes the header; the browser's same-origin policy then blocks cross-origin reads.

References
Credits

Thanks to Nozomu Sasaki (Paul) (@​morimori-dev) for finding and responsibly reporting this issue.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Nx: Zip-Slip in the self-hosted remote cache

CVE-2026-71476 / GHSA-vp3h-ghgh-jr7g

More information

Details

Summary

The Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on the machine running Nx. This arbitrary file write can be escalated to remote code execution. The directly exploitable issue is the self-hosted HTTP remote cache.

Affected Packages

[!IMPORTANT]
Nx's default local cache and Nx Cloud are NOT affected. The default local cache and Nx Cloud use separate cache retrieval and extraction mechanisms that does not have this vulnerability. Only workspaces that use a self-hosted remote cache (NX_SELF_HOSTED_REMOTE_CACHE_SERVER, @nx/s3-cache, etc.) are affected.

Two self-hosted cache surfaces are affected:

  1. The built-in HTTP remote cache (NX_SELF_HOSTED_REMOTE_CACHE_SERVER, in nx) — fixed in the patched release.
  2. The self-hosted cache packages — @nx/s3-cache, @nx/gcs-cache, @nx/azure-cache, @nx/shared-fs-cache (and their @nx/powerpack-* predecessors) — the same flaw in their own extractor. Deprecated (CVE-2025-36852) and not patched; migrate off (see Remediation).

The shared step that copies cached outputs into the workspace was also part of the exposure and is hardened in the patched nx release.

Remediation

Upgrade to Nx 22.7.7 or 23.0.2 (or later). The patched extractor is a drop-in — no configuration change is required.

If you use the S3, GCS, Azure, or shared-filesystem cache packages

@nx/s3-cache, @nx/gcs-cache, @nx/azure-cache, and @nx/shared-fs-cache (and their @nx/powerpack-* predecessors) are separately versioned packages and are already deprecated (see CVE-2025-36852). Upgrading nx hardens the shared restore step, but it does not fully secure these packages. The remediation for them is to migrate off — to Nx Cloud or the self-hosted OpenAPI/HTTP remote cache — per the deprecation guidance: https://nx.dev/docs/reference/deprecated/self-hosted-cache-packages

Details

When Nx retrieves an artifact from the self-hosted HTTP remote cache, it downloads a gzipped tar archive and extracts it. The extractor joined each untrusted tar entry name directly onto the output directory and unpacked it with tar's unguarded Entry::unpack(), which performs no containment check:

// vulnerable
let path_on_disk = output_dir.join(entry_path); // entry_path is attacker-controlled
fs::create_dir_all(path_on_disk.parent()…)?;
entry.unpack(&path_on_disk)?;

In addition, restore now copies only the declared task outputs (never the whole cache directory), confined to the workspace root; parent directories are realized as real directories so a write can never traverse a symlink; declared outputs that resolve outside the workspace are rejected; and the malformed-input cases return errors instead of panicking.

References
Credits
  • Lidor B., Novee Security — Reporter
  • Assaf Levkovich, Novee Security — Reporter

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Nx: Path traversal in nx migrate package-migrations extraction

CVE-2026-104853 / GHSA-hrvq-x7jp-36xv

More information

Details

Summary

nx migrate reads each target package's nx-migrations.migrations value from its manifest and extracts the referenced file to a path built by joining that value onto a temporary directory. The value is never validated, so a package whose migrations field contains .. segments (or an absolute path) steers the extraction to write outside the temporary directory. A hostile package — or any package pulled in transitively through a trusted package's packageGroup — can write attacker-controlled content, or truncate an existing file, anywhere the running user can write. This happens during migration planning, before the user reviews the migration list and before --run-migrations, so it does not require the user to approve or execute anything.

Most workspaces need no action. By default nx migrate does not run the nx installed in your workspace — it installs nx@latest into a temporary directory and performs the upgrade planning, including this extraction, with that copy. Now that a patched nx is the latest release, a default nx migrate run is unaffected whatever version the workspace has installed. The installed version only runs, and is only then exposed, when that hand-off is bypassed — see Remediation.

Severity

Exploitable when the victim runs nx migrate against a package the attacker controls, directly or through a trusted package's packageGroup. The primary impact is a file write with attacker-controlled content and no path confinement; overwriting an auto-loaded file (a shell rc, a git hook, a CI script) escalates that write to code execution. There is no known evidence of exploitation in the wild.

Affected & Patched Versions
Package Vulnerable Patched
nx >= 13.10.0, < 22.7.10; >= 23.0.0, < 23.2.1 22.7.10, 23.2.1

Every version in the ranges above is affected. The lower bound is 13.10.0, the first release where nx migrate extracted a package's migrations file from its tarball; earlier versions resolved migrations without that extraction.

[!IMPORTANT]
nx migrate normally fetches and runs nx@latest rather than the nx installed in your workspace. The ranges above therefore say where the vulnerable code ships, not who is exposed — it only runs when that hand-off is bypassed.

Remediation

If you run nx migrate normally, there is nothing to do. It resolves and runs the latest nx, which is patched, so your workspace's own nx version does not matter for this flaw.

Upgrade only if you bypass that hand-off and run the workspace's nx instead — that is, if you set NX_USE_LOCAL or NX_MIGRATE_USE_LOCAL, pin NX_MIGRATE_CLI_VERSION to an affected version, resume an existing run with --run-id, or run where the temporary install fails and nx migrate falls back to the local nx. In those cases upgrade to 22.7.10 (22.x line) or 23.2.1 (23.x line) or later:

nx migrate 23.2.1

The fix is a drop-in — no configuration changes are required, and no legitimate migrations value is affected (real packages reference ./migrations.json or another path within their own directory, all of which remain valid). Either way, do not run nx migrate against packages, or packageGroup members, that you do not trust.

Details

While planning an upgrade, nx migrate extracts each target package's migrations file to a destination built by joining the package's own nx-migrations.migrations value onto a temporary directory. That value is read from the manifest without validation, and it is handled asymmetrically: the name Nx matches against the archive entries is normalized (so its .. segments collapse), while the destination path it writes to is a raw join that keeps the .. segments and resolves outside the temporary directory. Because the attacker controls the tarball, they name their entry to equal the normalized form; the match then succeeds and the bytes are written to the un-normalized, escaping destination. The normalization is not a defence — it only dictates what the attacker must name their entry.

The same value also seeds the directory used for prompt-file extraction, which has the same shape, so both writes are steerable from the one field.

Two distinct primitives fall out of this:

  • Truncation — the destination write stream is opened, and truncates, before any tar entry is inspected. So a package that points migrations at an existing file empties that file even when no tar entry matches — no crafted archive required.
  • Controlled write — when a tar entry's name matches, its bytes are written to the escaping destination. The extractor performs no path containment of its own.
Credits
  • Arkadiusz Marta (RE:SOURCE) — Reporter

Severity

  • CVSS Score: 5.8 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Nx daemon and plugin worker sockets are accessible to other local users

CVE-2026-104854 / GHSA-w3vv-58gj-gw77

More information

Details

Summary

Nx creates the Unix domain sockets for its daemon and its plugin workers in a shared temporary directory with default permissions, so any other user on the same machine can connect to them. The daemon accepts a PROCESS_IN_BACKGROUND request that names a module to load and invokes its default export, which turns socket access into code execution inside the daemon process. On a multi-user machine — a shared build server, a shared developer box, or a container running several accounts — one local user can execute code as another user running Nx.

Severity

Exploitable by any other unprivileged local user on a shared host while a daemon or plugin worker is running, with no user interaction. There is no known evidence of exploitation in the wild.

Affected & Patched Versions
Package Vulnerable Patched
nx >= 14.6.0, < 22.7.9; >= 23.0.0, < 23.1.2 22.7.9, 23.1.2

Every version in the ranges above is affected. The lower bound is 14.6.0, when the daemon request handler that turns socket access into code execution was added.

[!IMPORTANT]
Single-user machines are not exposed. The vulnerability requires another local account on the same host, so an ordinary laptop with one user account is unaffected — the exposure is shared CI runners, shared build and development servers, and containers or images that run more than one uid.

Disabling the daemon is not sufficient on its own: the plugin worker sockets used by plugin isolation are created in the same directory with the same permissions, and those are used during normal command runs whether or not the daemon is enabled.

Remediation

Upgrade to 22.7.9 (22.x line) or 23.1.2 (23.x line) or later:

nx migrate 23.1.2

On a shared machine, run nx reset after upgrading so that any sockets and directories created by an older version are removed rather than reused.

If you cannot upgrade, point NX_SOCKET_DIR at a directory you own with mode 0700, which is already honoured by the vulnerable versions, and disable the daemon with NX_DAEMON=false to reduce the reachable surface — though, per the callout above, that does not remove the plugin worker sockets.

Details

The daemon and the plugin workers communicate over Unix domain sockets placed in a subdirectory of the shared OS temporary directory. That directory is created with default permissions, which on a typical system leave it readable and traversable by every user on the machine, and nothing narrows the socket files themselves. The directory name is derived from a hash of the workspace path and the process id, so it is unique but not secret — any local user who lists the temporary directory can find it.

The connection carries no authentication: the containment is meant to be the filesystem permissions alone, and those are too broad. Any local process that can reach the socket is treated as a fully trusted client.

The impact of that access is set by what the daemon's request handlers allow. One handler takes a module path from the request and loads and invokes it; because an absolute path resolves regardless of the lookup constraints in place, a caller who can write a file anywhere on the machine — their own home directory suffices — and connect to the socket can have the daemon execute it, as the user running the daemon. Other handlers expose workspace file contents, the project graph, and task hashes to the same unauthenticated caller.

Credits

Reported by researchers at the University of Sydney:

  • Liyi
  • Ziyue
  • Strick
  • Maurice
  • Chenchen

Severity

  • CVSS Score: 8.5 / 10 (High)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Nx: OS command injection via git revisions and remote refs

GHSA-w2vw-w76x-qr89

More information

Details

Summary

Nx core builds several git invocations as shell command strings with untrusted values interpolated into them, so a value that should be a git revision or ref is parsed by /bin/sh instead. Two entry points are reachable by an attacker: affected commands, where defaultBase / affected.defaultBase from nx.json (and the NX_BASE / NX_HEAD environment variables) reach git merge-base and git diff; and nx import, where a branch name advertised by a remote repository reaches git fetch, git checkout, and git config. In both cases an attacker who controls a repository — or who opens a pull request against one — gets arbitrary command execution on the machine of anyone who runs an ordinary Nx command against it, including CI runners.

The affected path is the more serious of the two. nx affected and nx show projects --affected run constantly in CI, so a pull request that changes nothing but nx.json is enough to execute code on the runner with whatever credentials that job holds.

Severity

Exploitable by anyone who controls repository content — a fork's pull request, or a repository the victim clones — that the victim then runs an ordinary nx affected or nx import against; no access to the victim's machine is required. We have no evidence of exploitation in the wild.

Affected & Patched Versions
Package Vulnerable Patched
nx >= 14.0.0, < 22.7.8; >= 23.0.0, < 23.1.1 22.7.8, 23.1.1

Treat every version below the patched ones as affected.

Remediation

Upgrade to 22.7.8 (22.x line) or 23.1.1 (23.x line) or later:

nx migrate 23.1.1

The fix is a drop-in — no configuration changes are required. If you cannot upgrade, treat nx.json from untrusted sources as executable content, do not run affected commands against pull requests you have not reviewed, and do not run nx import against repositories you do not trust.

Details
affected commands

Nx computes the merge base and the changed-file set by building git merge-base and git diff command lines as strings and running them through a shell. The base and head revisions in those strings come from nx.json's defaultBase / affected.defaultBase or from the NX_BASE / NX_HEAD environment variables, and a related code path reads file contents with git show <revision>:<path> the same way. Because a shell parses the whole line, a revision value containing shell syntax is executed rather than passed to git.

The revisions are wrapped in double quotes, which looks protective but is not: POSIX shells still perform command substitution inside double quotes, so a value of $(…) runs without needing to break out of the quotes.

nx import

The GitRepository helper runs every git operation — fetch, checkout, reset, config, and others — by interpolating its arguments into a shell command string. The untrusted argument is a branch name: nx import lists the branches a remote advertises, offers them to the user to choose from, and feeds the chosen name back into those commands. A hostile repository controls the names of its own branches, so it controls the command that runs when one is selected.

Credits
  • Arkadiusz Marta (RE:SOURCE) — Reporter

Severity

  • CVSS Score: 8.5 / 10 (High)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nrwl/nx (nx)

v22.7.10

Compare Source

22.7.10 (2026-09-09)

🩹 Fixes
  • core: validate the migrations path before extracting package migrations (#​36887)
❤️ Thank You

v22.7.9

Compare Source

22.7.9 (2026-09-01)

🩹 Fixes
❤️ Thank You

v22.7.8

Compare Source

22.7.8 (2026-07-30)

🩹 Fixes
  • angular-rspack: dispose stylesheet bundler so one-shot builds exit (#​35869)
  • core: use workspace package manager when fetching migrations via install (#​35866)
  • core: omit peer dependencies when installing packages to a temp dir (#​36295)
  • core: prevent shell injection in nx import (#​36348)
  • core: stop passing git revisions through a shell in affected commands (#​36379)
  • core: allow nx build scripts in generated pnpm-workspace.yaml (#​35564)
  • core: acknowledge @​swc/core build script in generated pnpm-workspace.yaml (#​35608)
  • core: keep real dependencies when omitting peers from npm temp installs (#​36518, #​36295)
  • core: bump pinned axios and brace-expansion past vulnerable versions (#​36507, #​36474)
  • detox: resolve jest versions locally instead of importing @​nx/jest internals (3ce3f6ab6e)
  • docker: run release pipeline docker commands without a shell (#​36505)
  • js: exclude typescript 7 from supported versions on 22.7.x (dc804964e9)
  • js: resolve the verdaccio bin through its package.json (#​36479)
  • misc: use default import for chalk in @​nx/workspace output.ts (#​35523, #​35521, #​34111, #​21201, #​26667)
  • repo: use default inputs instead of the '...' token in nx-dev on 22.7.x (#​35530)
  • repo: trust wix/brew tap so macOS detox CI can install applesimutils (#​36146)
  • testing: seed typescript before plugins in e2e workspaces to avoid TS7 stub (7f5ffbfcbc)
❤️ Thank You

v22.7.7

Compare Source

22.7.7 (2026-07-10)

🩹 Fixes
  • core: prevent path traversal / zip-slip in self-hosted remote cache (#​36116)
  • core: warn when the self-hosted remote cache disables TLS verification (NXC-4593) (#​36132, #​36116)
  • dotnet: declare obj as a publish output to fix sandbox violation (#​35858)
  • dotnet: declare directory build props input for analyzer dotnet tasks (df7540195a)
  • dotnet: declare directory build props on the separate release build target (6545ee2222)
  • dotnet: declare directory build props on the analyzer tests dotnet targets (e72ee0dd79)
❤️ Thank You

v22.7.6

Compare Source

22.7.6 (2026-06-23)

🩹 Fixes
  • misc: bump happy-dom, tmp, and form-data to patched versions (#​36013)
❤️ Thank You

v22.7.5

Compare Source

22.7.5 (2026-05-27)

🩹 Fixes
❤️ Thank You

v22.7.4

Compare Source

22.7.4 (2026-05-25)

🩹 Fixes
  • core: update brace-expansion and yaml (#​35790)
❤️ Thank You

v22.7.3

Compare Source

22.7.3 (2026-05-22)

🚀 Features
🩹 Fixes
  • angular: only add @​oxc-project/runtime on the vitest-analog path (#​35734)
  • angular-rspack: exclude eslint config from tailwind v4 source scan (#​35663)
  • core: warn before installing unknown npm packages as preset (#​35644)
  • core: preserve input order in createNodes plugin results (#​35595)
  • core: resolve local plugin subpath imports from source (#​35631)
  • core: treat undefined task parallelism as parallel when scheduling (#​35736)
  • core: handle object form of bin field in getPrettierPath (#​35680)
  • core: detect vscode copilot ai agent (#​35757)
  • core: allow local plugin subpath imports without custom conditions (#​35751, #​35631)
  • dotnet: include Directory.. files in inputs (#​35738)
  • gradle: add transitive:true to all tasks (#​35677)
  • gradle: pin generated e2e project toolchain to installed JDK (#​35703)
  • js: fall back to npm publish when bun publish fails with auth error (#​35756)
  • linter: improve convert-to-flat-config output fidelity (#​35330)
  • linter: only rewrite workspace-package peer deps to workspace:* (#​35423, #​35318, #​33417)
  • misc: stop inferring projects: 'self' in dependsOn entries (#​35686)
  • misc: skip $ escaping in file paths on windows (#​35692)
  • repo: run dotnet restore before publish (#​35771)
  • repo: run dotnet restore before macos e2e job (#​35774)
  • rsbuild: infer build outputs from distPath.root directly (#​35707)
  • rsbuild: lazy-require @​rsbuild/core in plugin so spec mocks work after jest.resetModules (#​35707)
  • testing: correct yargs-parser import in getJestProjectsAsync (#​35672, #​35654)
❤️ Thank You

v22.7.2

Compare Source

22.7.2 (2026-05-14)

🚀 Features
  • gradle: stream batch task results to nx as they finish (#​35487)
  • nx-dev: track docs analytics for code copy, LLM prompt, YouTube (#​35526)
  • testing: add migration for Jest 30 snapshot guide link (#​35629)
🩹 Fixes
  • angular: disable vitest watch by default (#​35493)
  • angular-rspack: keep root-scoped assets out of per-locale i18n emit (#​35621)
  • bundling: include tsconfig solution input for rollup (#​35476)
  • bundling: include tsconfig solution input for webpack (#​35477, #​35476)
  • core: bump axios to 1.16.0 for all packages (#​35568)
  • core: add provenance check in nx console status path (#​35485)
  • core: remove access control header from graph app (#​35494)
  • core: ensure verbose logs go to stderr and daemon logs are properly decorated (#​34358)
  • core: show flaky-task count in run summary (#​35491)
  • core: unique telemetry user_id; expose workspace_id dimension (#​35553)
  • core: update minimatch to 10.2.5 (#​35569, #​34660)
  • core: restore use-legacy-versioning shim for @​nx/js@21 ensurePackage path (#​35574)
  • core: isolate NX_PARALLEL env var in parallel-related specs (#​35579)
  • core: skip handleimport miss path when nx key packages are absent (#​35596)
  • core: use gethostuuid(3) instead of ioreg on macOS (#​35599)
  • core: isolate cache env vars in splitArgs spec (#​35584)
  • core: enable node's native v8 compile cache support (#​35415, #​20454)
  • core: support skipped batch tasks end-to-end and fix TUI double logs (#​35617)
  • core: keep TUI task selection on the in-progress section (#​35640)
  • core: allow nx mcp to run outside of an Nx workspace (#​35655)
  • core: cast perf entries to PerformanceMeasure for detail access (43c0c821ba)
  • devkit: exclude dist from jest module path scan (#​35615)
  • devkit: expand @​nx/devkit/internal re-exports for cherry-picked v23 deep-import migration (#​35541)
  • dotnet: correct output paths for Web SDK and centralized dist setups (#​35398)
  • gradle: exclude batch-runner from jest haste-map crawl (#​35501)
  • gradle: exclude project-graph from jest module path scan (#​35609)
  • gradle: support Windows file paths (#​35184, #​34987)
  • js: strip glob from inferred outputs before resolving as path (#​35463, #​35452)
  • js: reference vitest.config in eslint dep-checks for vitest libs (#​35460, #​33670, #​35450)
  • js: include transitive workspace deps in pruned pnpm lockfile (#​35532, #​35347, #​34655)
  • linter: prevent ENOENT crash in getRelativeImportPath for unresolvable paths (#​35007, #​13872, #​34066, #​30491, #​16716, #​35006, #​21889, #​32190)
  • maven: skip attached artifacts that fail to materialize in batch record (#​35473)
  • maven: serialize Maven 4 build state recording (#​35555)
  • maven: widen runCLI timeout for --no-batch maven.test.ts cases (#​35589)
  • nx-dev: document nested CLI subcommands beyond two levels (#​35519)
  • nx-dev: short-circuit bot probes in framer rewrite edge function (#​35527)
  • react: withSvgr migration preserves other properties (#​35484)
  • repo: clear NX_INVOCATION_ROOT_PID in run-native-target to avoid recursion false-positive (443dee0b22)
  • repo: revert deep-import rewrites that targeted v23-only @​nx/devkit/internal entry (ac8187963d)
  • repo: unblock 22.7.x cargo tests and nx-build e2e (#​34285)
  • repo: expand "..." spread token in graph typecheck inputs (#​34285, #​35458)
  • testing: pin jest to ~30.3.0 to avoid jest-runtime 30.4 RN incompat (#​35618)
  • testing: handle absolute cypress screenshotsFolder/videosFolder paths (#​35624)
  • testing: exclude dist and out-tsc from default jest module path scan (#​35619)
  • testing: update remaining snapshot guide links missed by migration (cd350c1140)
❤️ Thank You

v22.7.1

Compare Source

22.7.1 (2026-04-28)

🩹 Fixes
  • core: prevent spinner flicker when sync applying (#​35445)
  • core: exclude hyperfine env vars from daemon env reflection (5095b4be7d)
  • core: provide actionable feedback when running migrations and pre-install fails with npm peer dep errors (#​33961, #​33942)
  • core: consider virtual trees in multiGlobWithWorkspaceContext (#​35447, #​31805, #​35373, #​32588)
  • core: surface ./nx --version stderr and force devDeps install (#​35469)
  • core: keep continuous children alive when nx:noop orchestrator completes (#​35388)
  • core: start TUI event reader synchronously in enter() to prevent stdin race (#​35465, #​34619, #​34144)
  • core: use require for global to local Nx handoff so Windows drive paths work (#​35478)
  • core: prevent daemon shutdown from cache-poisoned in-process nx loads (#​35482, #​35444, #​34463, #​34111)
  • detox: generate valid JSON in .detoxrc for non-expo apps (eb2fa8ced4)
  • js: include extended tsconfigs from project references in typecheck inputs (#​35457)
  • linter: detect root lint target added in same generator run (#​35296, #​23147, #​34531)
  • misc: exclude stories and specs from tailwind content scanning (#​35470)
  • misc: resolve pnpm catalog: refs in version lookups (#​35459, #​35453)
  • nextjs: use cached project graph in withNx (#​35475, #​34518, #​32880)
  • node: include tsconfig input in node-app esbuild scaffold (#​35466)
  • release: handle short and full project names in commit scopes (#​34219)
  • testing: convert executor-based jest.config.ts and preserve type-only imports (#​35286, #​34593)
❤️ Thank You

v22.7.0

Compare Source

22.7.0 (2026-04-24)

🚀 Features
  • core: add .nx/self-healing to .gitignore (#​34855)
  • core: decouple DB version from Nx version and share DB across worktrees (#​34942)
  • core: auto-open browser for Cloud setup URL during create-nx-workspace (#​35014)
  • core: allow generate command to skip project graph creation (#​35170)
  • core: remove polygraph cloud passthrough (#​35153)
  • core: use CNW variant 1 cloud prompt in nx init (#​35155)
  • core: add source map annotations to nx show target (#​35225)
  • core: prompt for setup mode when running nx init in empty git directory (#​35226)
  • core: add json input type for selective JSON field hashing (#​35248)
  • core: update nx-set-shas usage to v5 (#​34934)
  • core: add NX_BAIL environment variable (#​34711)
  • core: add page up/down to tui shortcuts (#​34525)
  • core: add logging and progress message types to daemon (#​35342)
  • dotnet: add ci-workflow generator (#​33321)
  • js: support nx.sync.ignoredDependencies in typescript-sync (#​35401)
  • misc: a/b test cloud prompt copy in create-nx-workspace (#​35039)
  • misc: update nx init telemetry meta from CSV to JSON format (#​35076)
  • misc: lock in CNW cloud prompt A/B winner and add new variants (#​35154)
  • nx-dev: add conditional blog/changelog proxy in edge function (#​35043)
  • nx-dev: add nx-blog sitemap to root sitemap index (#​35363)
  • repo: add nx-labs repo target and use glob pattern for update-all-repos (#​34999)
  • repo: enable tsgo compiler for nx package (#​35047)
  • repo: enforce no-disabled-tests via ESLint with per-project warning caps (#​35122)
  • repo: add e2e test for nx build process verification (#​35119)
  • vite: add compiler option to vite plugin for tsgo support (#​35429, #​33821, #​35047, #​35167)
🩹 Fixes
  • angular: update duplicate migration keys (#​34961)
  • angular: add storybook and playwright as implicit dependencies (#​35224)
  • angular: preserve specific file paths in tsconfig when adding secondary entry point (#​35254, #​33051)
  • angular: fall back to addUndefinedDefaults when addUndefinedObjectDefaults is unavailable (#​35290)
  • **

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
Scope: all 50 workspace projects
Progress: resolved 1, reused 0, downloaded 0, added 0
.                                        | [WARN] deprecated eslint@9.39.4
Progress: resolved 51, reused 0, downloaded 1, added 0
Progress: resolved 57, reused 0, downloaded 1, added 0
Progress: resolved 79, reused 0, downloaded 2, added 0
Progress: resolved 97, reused 0, downloaded 9, added 0
Progress: resolved 104, reused 0, downloaded 9, added 0
Progress: resolved 134, reused 0, downloaded 9, added 0
[ERR_PNPM_TRUST_DOWNGRADE] High-risk trust downgrade for "undici-types@6.21.0" (possible package takeover)

This error happened while installing the dependencies of @types/node@22.19.15

Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Earlier versions had provenance attestation, but this version has no trust evidence. A trust downgrade may indicate a supply chain incident.

@renovate
renovate Bot force-pushed the renovate/npm-nx-vulnerability branch from 6b20283 to ca6f5e4 Compare September 16, 2026 00:17
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: TanStack/devtools/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: fae0c5df-c566-4f9f-a500-dd035d05f08a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/npm-nx-vulnerability branch from ca6f5e4 to 961bc1f Compare September 24, 2026 23:10
@renovate
renovate Bot force-pushed the renovate/npm-nx-vulnerability branch from 961bc1f to a8ae27b Compare October 11, 2026 17:27
@renovate renovate Bot changed the title chore(deps): update dependency nx to v22.7.7 [security] chore(deps): update dependency nx to v22.7.10 [security] Oct 11, 2026
@changeset-bot

changeset-bot Bot commented Oct 11, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: a8ae27b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants