diff --git a/.changeset/nx-security-bump-22-7-9.md b/.changeset/nx-security-bump-22-7-9.md deleted file mode 100644 index 257e2a09f..000000000 --- a/.changeset/nx-security-bump-22-7-9.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"dot-github": patch ---- - -Bump nx and @nx/* from 22.5.3 to 22.7.12 for security advisories GHSA-w2vw-w76x-qr89 (OS command injection via git revisions), GHSA-w3vv-58gj-gw77 (daemon/plugin worker socket exposure), GHSA-vp3h-ghgh-jr7g (Zip-Slip in self-hosted remote cache), and GHSA-hrvq-x7jp-36xv (Nx vulnerability in versions <22.7.10). Add overrides for smol-toml, brace-expansion, and axios. Fixes DX-5545, DX-5544, DX-5540, DX-5538, DX-4948, DX-4947 diff --git a/.changeset/security-overrides-wave3.md b/.changeset/security-overrides-wave3.md deleted file mode 100644 index 7faf7686b..000000000 --- a/.changeset/security-overrides-wave3.md +++ /dev/null @@ -1,17 +0,0 @@ ---- -"dot-github": patch ---- - -Bump transitive dependencies via pnpm overrides to remediate Dependabot advisories: - -- shell-quote 1.11.0 — GHSA-pqg4-j6r4-53mv, CVE-2026-102422 (quote() command injection) -- vite 7.3.7 — GHSA-fx2h-pf6j-xcff, GHSA-p9ff-h696-f583, GHSA-v2wj-q39q-566r (server.fs.deny bypasses, dev server WebSocket file read) -- undici 6.29.0 — GHSA-vxpw-j846-p89q, GHSA-vrm6-8vpv-qv8q, GHSA-v9p9-hfj2-hcw8 (WebSocket DoS) -- form-data 4.0.6 — GHSA-hmw2-7cc7-3qxx, CVE-2026-12143 (CRLF injection in multipart) -- @graphql-tools/utils 12.0.1 — GHSA-7mx3-vvmw-hjmv (mergeDeep prototype pollution) -- @fastify/busboy 3.2.2 — GHSA-x8mw-p69m-v3mx, CVE-2026-19481 (prototype-named multipart header DoS) -- http-cache-semantics 4.3.0 — GHSA-ch52-4w7c-c8xp, CVE-2026-93748 (cross-user cached response disclosure) -- source-map-js 1.2.2 — GHSA-68fv-2mgg-jv7q, CVE-2026-93749 (event-loop DoS via section offsets) -- picomatch 4.0.7 — GHSA-c2c7-rcm5-vvqj (ReDoS via extglob quantifiers) - -Fixes DX-5556, DX-4463, DX-4458, DX-3679, DX-3677, DX-4480, DX-3434, DX-3433, DX-5543, DX-5542, DX-5541, DX-5546, DX-3573 diff --git a/.github/workflows/changesets-check.yml b/.github/workflows/changesets-check.yml index d0e49eab0..3987fd957 100644 --- a/.github/workflows/changesets-check.yml +++ b/.github/workflows/changesets-check.yml @@ -49,3 +49,29 @@ jobs: run: | echo "No releasable packages were modified - a changeset is not required." \ >> "$GITHUB_STEP_SUMMARY" + + # Runs the same `changeset version` that cd-release runs on push to main, so + # an invalid changeset (e.g. one naming a non-workspace package) fails here + # instead of blocking every release after it merges. + validate: + name: Changesets Validate + if: github.event.pull_request.title != 'Version Packages' + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - uses: actions/checkout@v7 + with: + fetch-depth: 0 + persist-credentials: false + + - name: Setup pnpm + uses: ./actions/setup-nodejs + with: + pnpm-version: "^10.0.0" + + - name: Dry-run changeset version + env: + # @changesets/changelog-github looks up PR metadata for each changeset. + GITHUB_TOKEN: ${{ github.token }} + run: pnpm changeset version