Skip to content

fix(deps): bump nx to 22.7.9 for security advisories - #1685

Merged
kalverra merged 5 commits into
mainfrom
DX-5545-bump-nx-22-7-9
Oct 7, 2026
Merged

kalverra merged 5 commits into
mainfrom
DX-5545-bump-nx-22-7-9

Conversation

@kalverra

@kalverra kalverra commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps nx and all @nx/* pins from 22.5.3 to 22.7.9 to remediate three security advisories affecting the Nx monorepo toolchain:

Advisory Issue Patched in
GHSA-w2vw-w76x-qr89 OS command injection via git revisions and remote refs (nx affected / nx import) 22.7.8
GHSA-w3vv-58gj-gw77 Nx daemon and plugin worker sockets accessible to other local users 22.7.9
GHSA-vp3h-ghgh-jr7g Zip-Slip in the self-hosted remote cache 22.7.7

The affected path is the most serious: nx affected runs in CI against PR content, so a PR that only changes nx.json could execute arbitrary commands on runners with job credentials.

Changes

  • package.json: nx, @nx/devkit, @nx/esbuild, @nx/eslint, @nx/eslint-plugin, @nx/js, @nx/plugin → 22.7.9
  • pnpm-lock.yaml regenerated
  • Rebuilt bundled action artifacts (pnpm build:artifacts) — CI out-of-date check
  • Changeset added

Verification

  • pnpm lint — 4 projects pass
  • pnpm build — 18 projects pass
  • pnpm test — 19 projects pass
  • pnpm audit — no remaining hits for GHSA-w2vw-w76x-qr89 / GHSA-w3vv-58gj-gw77 / GHSA-vp3h-ghgh-jr7g
  • pnpm nx reset before verification (advisory recommends nx reset after upgrading on shared machines)

Fixes DX-5545, DX-5544, DX-5540, DX-5538, DX-4948, DX-4947

…exposure, and Zip-Slip advisories

Bump nx and @nx/* from 22.5.3 to 22.7.9:

- GHSA-w2vw-w76x-qr89: OS command injection via git revisions and
  remote refs (patched in 22.7.8)
- GHSA-w3vv-58gj-gw77: daemon and plugin worker sockets accessible to
  other local users (patched in 22.7.9)
- GHSA-vp3h-ghgh-jr7g: Zip-Slip in the self-hosted remote cache
  (patched in 22.7.7)

Verified: lint (4 projects), build (18 projects), test (19 projects),
rebuilt bundled action artifacts.

Fixes DX-5545, DX-5544, DX-5540, DX-5538, DX-4948, DX-4947
@kalverra
kalverra requested a review from a team as a code owner October 6, 2026 20:13
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

👋 kalverra, thanks for creating this pull request!

To help reviewers, please consider creating future PRs as drafts first. This allows you to self-review and make any final changes before notifying the team.

Once you're ready, you can mark it as "Ready for review" to request feedback. Thanks!

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

🦋 Changeset is good to go

Latest commit: bf431b0

We got this.

Not sure what this means? Click here to learn what changesets are.

nx pins axios@1.18.1 exactly in all versions including 22.7.9 and
latest 23.x, which fails the Dependency Review gate with 7 high-severity
advisories (GHSA-542g-h47m-68v8, GHSA-3pq3-5fj3-cg6v, GHSA-x97p-jq2g-jp4f,
GHSA-mghh-pgcx-3jjj, GHSA-c29m-xwm3-cm6r, GHSA-r4gj-5m52-g5wh,
GHSA-m8m8-qj5v-23w3). Force ^1.20.0 via pnpm.overrides and regen lockfile.

Verified: pnpm audit clean for axios and all three targeted nx GHSAs
(GHSA-w2vw-w76x-qr89, GHSA-w3vv-58gj-gw77, GHSA-vp3h-ghgh-jr7g);
dist artifacts rebuilt.
nx 22.7.9 pins brace-expansion@5.0.8 exactly, which fails the Dependency
Review gate with 3 high-severity advisories (GHSA-rgw5-rvv9-x895,
GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7). Force ^5.0.12 via
pnpm.overrides and regen lockfile.
- nx 22.7.9 itself has a moderate advisory GHSA-hrvq-x7jp-36xv
  (>=13.10.0 <22.7.10); bump all nx/@nx pins to 22.7.12.
- All nx versions pin smol-toml@1.6.1 (high GHSA-7w5x-hrqm-74c2 <=1.7.0);
  force ^1.9.0 via pnpm.overrides.
Comment thread actions/ci-grafana-alert-test/dist/index.js
chainchad
chainchad previously approved these changes Oct 7, 2026
@kalverra
kalverra merged commit 2261aa4 into main Oct 7, 2026
19 checks passed
@kalverra
kalverra deleted the DX-5545-bump-nx-22-7-9 branch October 7, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants