Skip to content

fix(deps): update dependency nx to v23.2.1 [security] - autoclosed - #1187

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-nx-vulnerability
Closed

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-nx-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
nx (source) 23.1.1 → 23.2.1 age confidence

Nx: Path traversal in nx migrate package-migrations extraction

CVE-2026-104853 / GHSA-hrvq-x7jp-36xv

More information

Details

Summary

nx migrate reads each target package's nx-migrations.migrations value from its manifest and extracts the referenced file to a path built by joining that value onto a temporary directory. The value is never validated, so a package whose migrations field contains .. segments (or an absolute path) steers the extraction to write outside the temporary directory. A hostile package — or any package pulled in transitively through a trusted package's packageGroup — can write attacker-controlled content, or truncate an existing file, anywhere the running user can write. This happens during migration planning, before the user reviews the migration list and before --run-migrations, so it does not require the user to approve or execute anything.

Most workspaces need no action. By default nx migrate does not run the nx installed in your workspace — it installs nx@latest into a temporary directory and performs the upgrade planning, including this extraction, with that copy. Now that a patched nx is the latest release, a default nx migrate run is unaffected whatever version the workspace has installed. The installed version only runs, and is only then exposed, when that hand-off is bypassed — see Remediation.

Severity

Exploitable when the victim runs nx migrate against a package the attacker controls, directly or through a trusted package's packageGroup. The primary impact is a file write with attacker-controlled content and no path confinement; overwriting an auto-loaded file (a shell rc, a git hook, a CI script) escalates that write to code execution. There is no known evidence of exploitation in the wild.

Affected & Patched Versions
Package Vulnerable Patched
nx >= 13.10.0, < 22.7.10; >= 23.0.0, < 23.2.1 22.7.10, 23.2.1

Every version in the ranges above is affected. The lower bound is 13.10.0, the first release where nx migrate extracted a package's migrations file from its tarball; earlier versions resolved migrations without that extraction.

[!IMPORTANT]
nx migrate normally fetches and runs nx@latest rather than the nx installed in your workspace. The ranges above therefore say where the vulnerable code ships, not who is exposed — it only runs when that hand-off is bypassed.

Remediation

If you run nx migrate normally, there is nothing to do. It resolves and runs the latest nx, which is patched, so your workspace's own nx version does not matter for this flaw.

Upgrade only if you bypass that hand-off and run the workspace's nx instead — that is, if you set NX_USE_LOCAL or NX_MIGRATE_USE_LOCAL, pin NX_MIGRATE_CLI_VERSION to an affected version, resume an existing run with --run-id, or run where the temporary install fails and nx migrate falls back to the local nx. In those cases upgrade to 22.7.10 (22.x line) or 23.2.1 (23.x line) or later:

nx migrate 23.2.1

The fix is a drop-in — no configuration changes are required, and no legitimate migrations value is affected (real packages reference ./migrations.json or another path within their own directory, all of which remain valid). Either way, do not run nx migrate against packages, or packageGroup members, that you do not trust.

Details

While planning an upgrade, nx migrate extracts each target package's migrations file to a destination built by joining the package's own nx-migrations.migrations value onto a temporary directory. That value is read from the manifest without validation, and it is handled asymmetrically: the name Nx matches against the archive entries is normalized (so its .. segments collapse), while the destination path it writes to is a raw join that keeps the .. segments and resolves outside the temporary directory. Because the attacker controls the tarball, they name their entry to equal the normalized form; the match then succeeds and the bytes are written to the un-normalized, escaping destination. The normalization is not a defence — it only dictates what the attacker must name their entry.

The same value also seeds the directory used for prompt-file extraction, which has the same shape, so both writes are steerable from the one field.

Two distinct primitives fall out of this:

  • Truncation — the destination write stream is opened, and truncates, before any tar entry is inspected. So a package that points migrations at an existing file empties that file even when no tar entry matches — no crafted archive required.
  • Controlled write — when a tar entry's name matches, its bytes are written to the escaping destination. The extractor performs no path containment of its own.
Credits
  • Arkadiusz Marta (RE:SOURCE) — Reporter

Severity

  • CVSS Score: 5.8 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Nx daemon and plugin worker sockets are accessible to other local users

CVE-2026-104854 / GHSA-w3vv-58gj-gw77

More information

Details

Summary

Nx creates the Unix domain sockets for its daemon and its plugin workers in a shared temporary directory with default permissions, so any other user on the same machine can connect to them. The daemon accepts a PROCESS_IN_BACKGROUND request that names a module to load and invokes its default export, which turns socket access into code execution inside the daemon process. On a multi-user machine — a shared build server, a shared developer box, or a container running several accounts — one local user can execute code as another user running Nx.

Severity

Exploitable by any other unprivileged local user on a shared host while a daemon or plugin worker is running, with no user interaction. There is no known evidence of exploitation in the wild.

Affected & Patched Versions
Package Vulnerable Patched
nx >= 14.6.0, < 22.7.9; >= 23.0.0, < 23.1.2 22.7.9, 23.1.2

Every version in the ranges above is affected. The lower bound is 14.6.0, when the daemon request handler that turns socket access into code execution was added.

[!IMPORTANT]
Single-user machines are not exposed. The vulnerability requires another local account on the same host, so an ordinary laptop with one user account is unaffected — the exposure is shared CI runners, shared build and development servers, and containers or images that run more than one uid.

Disabling the daemon is not sufficient on its own: the plugin worker sockets used by plugin isolation are created in the same directory with the same permissions, and those are used during normal command runs whether or not the daemon is enabled.

Remediation

Upgrade to 22.7.9 (22.x line) or 23.1.2 (23.x line) or later:

nx migrate 23.1.2

On a shared machine, run nx reset after upgrading so that any sockets and directories created by an older version are removed rather than reused.

If you cannot upgrade, point NX_SOCKET_DIR at a directory you own with mode 0700, which is already honoured by the vulnerable versions, and disable the daemon with NX_DAEMON=false to reduce the reachable surface — though, per the callout above, that does not remove the plugin worker sockets.

Details

The daemon and the plugin workers communicate over Unix domain sockets placed in a subdirectory of the shared OS temporary directory. That directory is created with default permissions, which on a typical system leave it readable and traversable by every user on the machine, and nothing narrows the socket files themselves. The directory name is derived from a hash of the workspace path and the process id, so it is unique but not secret — any local user who lists the temporary directory can find it.

The connection carries no authentication: the containment is meant to be the filesystem permissions alone, and those are too broad. Any local process that can reach the socket is treated as a fully trusted client.

The impact of that access is set by what the daemon's request handlers allow. One handler takes a module path from the request and loads and invokes it; because an absolute path resolves regardless of the lookup constraints in place, a caller who can write a file anywhere on the machine — their own home directory suffices — and connect to the socket can have the daemon execute it, as the user running the daemon. Other handlers expose workspace file contents, the project graph, and task hashes to the same unauthenticated caller.

Credits

Reported by researchers at the University of Sydney:

  • Liyi
  • Ziyue
  • Strick
  • Maurice
  • Chenchen

Severity

  • CVSS Score: 8.5 / 10 (High)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nrwl/nx (nx)

v23.2.1

Compare Source

23.2.1 (2026-09-09)

🚀 Features
🩹 Fixes
  • angular: correct declaration maps and exports of buildable libraries (#​36373, #​36357)
  • core: separate daemon runtime env from graph identity (#​36565, #​36564)
  • core: validate the migrations path before extracting package migrations (#​36887)
  • core: release per-run process listeners and task history results (#​36866)
  • core: read the pnpm 12 min-release-age policy instead of deferring to an install (#​36915, #​36914)
  • core: carry minimumReleaseAge into pruned pnpm deploy output (#​36900, #​36899)
  • core: report how a plugin worker was lost instead of always calling it an exit (#​36894)
  • core: keep the cache in the workspace on CI (#​36922)
  • core: restore the wasm walker imports dropped by a stray cfg attribute (#​36924)
  • core: avoid mutating target options when resolving configurations (#​36934)
  • js: resolve tsconfig to absolute path so ${configDir} paths type-check without baseUrl (#​36445)
  • misc: scan package projects for env vars (#​36847)
  • release: exclude AI coding agents from the changelog Thank You section (#​36892)
  • release: use the release group name when resolving the previous tag for fixed groups (#​36554)
  • repo: provision JDK 17 for Gradle builds with mise (#​36965)
  • repo: guard JAVA17_HOME against an uninstalled JDK (#​36969)
  • rspack: write the normalized cache option in NxAppRspackPlugin (#​36905, #​36878)
❤️ Thank You

v23.2.0

Compare Source

23.2.0 (2026-09-02)
🚀 Features
  • angular: add support for Angular v22.1 (#​36521)
  • core: confirm before creating migration commits on the default branch (#​36314)
  • core: add a full-width TUI status bar and vim-style pane search (#​36263)
  • core: forward mouse and resize events to tasks running in the TUI's pty (#​36322)
  • core: add bun dependency-catalog support (#​36434)
  • core: derive stable repo key from normalized remote and relative path (#​36439)
  • core: add nx migrate --run-migration to run a single migration (#​36407)
  • core: let migration generators skip their AI step (#​36532)
  • core: show Cloud app link for remote cache instead of docs (#​36460)
  • core: add durable run state and a dark orchestration loop to nx migrate (#​36403)
  • core: add built-in support for oxfmt formatter alongside prettier (#​35089, #​30403)
  • core: filter static task output to failures and restore CI log grouping (#​36453)
  • core: let the daemon and plugin workers run inside agent sandboxes (#​36586)
  • dotnet: infer OpenApiDocumentsDirectory as a build output (#​36788)
  • linter: add the @​nx/oxlint plugin (#​36491)
  • linter: hash only lintable files for inferred oxlint tasks (#​36828)
  • misc: support vitest generation for node, nest, and express generators (#​36665)
  • nx-cloud: generate .nx/ci-config.yaml for agent distribution (#​36504)
  • nx-cloud: add nx start-nx-agents as an alias for nx-cloud start-nx-agents (#​36572)
  • nx-plugin: add vitest support for e2e tests (#​34041)
  • release: support tag-based project selection (#​36537)
  • repo: add react + vite + vitest + playwright example (#​35921)
  • storybook: adopt the storybook vitest addon for story testing (#​36648, #​33759)
  • testing: offer vitest consistently across generators with a unitTestRunner option (#​36715)
🩹 Fixes
  • angular: make webpack-related packages optional peer dependencies (#​36310)
  • angular: keep buildable libraries private (#​36545)
  • angular: import optional ng-packagr lazily (#​36632)
  • angular-rspack: speed up builds and align behavior with the esbuild application builder (#​36268, #​34936)
  • angular-rspack: stop builds crashing on non-array styleUrls (#​36550)
  • angular-rspack: rebuild components when their templates or styles change on Windows (#​36641, #​36619)
  • bundling: support TypeScript esbuildConfig files in the esbuild executor (#​36352, #​36349)
  • bundling: acknowledge @​swc/core build scripts when configuring rollup (#​36412)
  • bundling: resolve esbuild paths from workspace root instead of cwd (#​36830, #​34027)
  • bundling: allow overriding the css module hash algorithm (#​36837, #​36829)
  • core: speed up npm lockfile parsing (#​36216)
  • core: speed up lockfile parsing and catalog resolution (#​36223)
  • core: show performance report recommendations only when actionable (#​36344)
  • core: close daemon log descriptors after spawn to avoid Node 26 crash (#​36280)
  • core: prevent shell injection in nx import (#​36348)
  • core: correct the 22.6.0 gitignore and analytics migration wiring (#​36356)
  • core: support npm 12 and pnpm in the package provenance check (#​36354, #​36338)
  • core: honor pnpm minimumReleaseAge config on pnpm 11 (#​36335, #​36330)
  • core: support pnpm 11 patched dependency hashes (#​36360)
  • core: resolve name refs copied into pattern-matched target arrays (#​36359)
  • core: resolve source-loaded plugin transitive workspace imports (#​36296)
  • core: unbreak pnpm 11 installs by acknowledging build-script deps from generators (#​36302)
  • core: include continuous and default-config dependencies in show target (#​36374)
  • core: make unit tests pass locally regardless of invoking package manager (#​35994)
  • core: respect --aiAgents none to skip AI agent file generation (#​34944, #​34692)
  • core: use --config.frozen-lockfile=false for pnpm add during migrate (#​36337)
  • core: run selected projects with --exclude-task-dependencies (#​35562)
  • core: stop passing git revisions through a shell in affected commands (#​36379)
  • core: collect trickling watcher bursts fully on daemon force-flush (#​36391)
  • core: report tasks running in another Nx process in the inline TUI (#​36341)
  • core: stop ratatui cursor queries from racing the TUI event stream (#​36318)
  • core: render critical-path tasks as a nested list in the job summary (#​36394)
  • core: keep pnpm-workspace.yaml comments and read package.json as jsonc (#​36411)
  • core: support multiple brace groups in workspace glob matching (#​36395)
  • core: handle CRLF line endings in pnpm multi-document lockfiles (#​36419, #​35828, #​35840)
  • core: correct glob pattern expansion for ZeroOrOne groups (#​31857)
  • core: stop re-querying confirmed cache misses in task orchestrator (#​36301, #​35632)
  • core: sample project graph perf span telemetry per session at 10% (#​36420)
  • core: strip terminal query sequences when replaying task output (#​36432)
  • core: preserve FORCE_COLOR=0 intent for forked child tasks (#​35293)
  • core: handle colons in target name when resolving inputs to generate graph (#​36429, #​33710)
  • core: merge default plugins through the source-map-aware merge path (#​36257)
  • core: keep nx migrate on the requested version when release-age gates interfere (#​36444)
  • core: avoid bogus duplicate project name errors when generating nested apps (#​36458)
  • core: make tui cloud icon visible on light terminal themes (#​36495)
  • core: pin typescript in preset dependencies so npm cannot hoist typescript 7 (#​36497)
  • core: bump pinned axios and brace-expansion past vulnerable versions (#​36507, #​36474)
  • core: parse pnpm lockfiles that omit the packages block (#​36512)
  • core: keep real dependencies when omitting peers from npm temp installs (#​36518)
  • core: normalize resolved module paths (#​36556, #​36549)
  • core: stop pruneProjectGraph from mutating the source project graph (#​36517, #​36470)
  • core: make preset empty work without github.com and improve template download errors (#​36508)
  • core: drain to stdout before exiting nx affected (#​36569, #​36568)
  • core: update brace-expansion to 5.0.9 for CVE-2026-14257 (#​36577)
  • core: restrict daemon and plugin worker socket access to the owning user (#​36370)
  • core: drain stdout before exiting nx run-many and nx run (#​36607, #​36606)
  • core: re-spawn nx migrate without a shell to preserve argv exactly (#​36215)
  • core: resolve main worktree root without a Windows verbatim prefix (#​36649, #​35637)
  • core: accept bun.lock lockfileVersion 2 and 3 (#​36666)
  • core: maintain cacheability when an executor target default applies (#​36477)
  • core: don't leave an unkillable nx process when a terminal closes (#​36683, #​36682)
  • core: honor the package manager's registry config in nx migrate (#​35954, #​35843)
  • core: resolve telemetry DNS in-process to avoid a getenv segfault (#​36673)
  • core: skip target group members without a target (#​36711, #​36712)
  • core: stop resending accumulated task hash results to the daemon when hashing tasks (#​36716)
  • core: apply package.json updates unblocked by later package groups (#​36636)
  • core: create external nodes for out-of-workspace link dependencies (#​36745)
  • core: point duplicate project names from worktrees at the fix (#​36734)
  • core: exclude volatile shell and editor env vars from the daemon (#​36642, #​36610)
  • core: stop the daemon before nx add installs a package (#​36767)
  • core: do not allowlist the analytics domain when analytics are off (#​36663, #​36486)
  • core: isolate pnpm version detection from workspace (#​36728, #​36727)
  • core: key the main-worktree-root cache on the workspace root (#​36768)
  • core: give pnpm a fresh cache dir per e2e run (#​36802)
  • core: apply targetDefaults options to an inferred target that is not redeclared (#​36717, #​36700)
  • core: devkit util - detect esm config with top level await (#​33644)
  • core: share worktree cache under ~/.nx so agent sandboxes can reach it (#​36514)
  • core: compare daemon workspace roots case-insensitively on Windows (#​36835, #​36722)
  • core: raise the nx package vitest timeout to cover the graph recompute spec (#​36850)
  • core: single-inference convert-to-inferred engine with centralized config (#​36547)
  • core: fall back to v8 for oversized daemon responses and length-prefix the wire protocol (#​36838)
  • core: use scoped config form for pnpm 11+ publish (#​36867, #​36860)
  • devkit: resolve ensurePackage against the workspace (#​36496)
  • devkit: honour cascading ignore files in tree walks and generator formatting (#​36575)
  • devkit: correct version floor validation for ranges and prereleases (#​36724)
  • devkit: reload TS config files fresh instead of serving stale cached modules (#​36656)
  • docker: run release pipeline docker commands without a shell (#​36505)
  • docker: skip unchanged version action projects (#​36542)
  • dotnet: make msbuild-analyzer run cancellable and kill it when the host process exits (#​36813)
  • dotnet: derive output paths from MSBuild instead of hardcoded assumptions (#​36804)
  • expo: keep the expo dev server alive under jest (#​36635)
  • expo: derive metro projectRoot and node_modules from the app being bundled (#​36650, #​36531)
  • gradle: emit valid Groovy when applying the plugin to an existing allprojects block (#​36697)
  • gradle: surface project graph timeout errors when the process ignores the kill signal (#​36713)
  • gradle: compile Kotlin in-process in the e2e fixture (#​36803)
  • gradle: support builds that configure subprojects from an ancestor build file (#​36693, #​36668)
  • gradle: retry nxProjectGraph on lock timeout and kill orphaned gradle builds on exit (#​36806)
  • js: support private methods and static blocks in babel preset (#​36218, #​36205)
  • js: parse pnpm/npm publish JSON containing braces in file paths (#​36241, #​36236)
  • js: resolve the verdaccio bin through its package.json (#​36479)
  • js: resolve package and extension-less tsconfig extends read from the tree (#​36271)
  • js: avoid duplicate node start without watch (#​36695, #​36694)
  • js: resolve override selectors in affected detection (#​36699, #​36698)
  • js: make pruned pnpm output installable and run its workspace modules (#​36139, #​36055, #​36066, #​36140, #​35425, #​18402)
  • js: keep the deprecated-prepend warning in the task's terminal output (#​36789)
  • js: detect all files changed during lock file update (#​34856)
  • linter: keep override parser when convert-to-flat-config uses FlatCompat (#​36363)
  • linter: use projectService for typed linting in flat configs (#​35727)
  • linter: restore the nx subpath ban in the create-* oxlint configs (#​36821)
  • linter: declare .gitignore as an input for inferred oxlint tasks (#​36869)
  • linter: flag banned external imports reached through internal projects (#​36654, #​36519)
  • linter: stop an inferred oxlint task from linting nested projects (#​36873)
  • maven: stop running maven and gradle graph analysis through a shell (#​36626)
  • maven: stop writing a failing task's output three times (#​36790)
  • misc: resolve CSS url() assets on Windows in postcss-cli-resources (#​36353, #​36336)
  • misc: suppress outdated disclaimer for unsupported AI agents with AGENTS.md (#​36324, #​36264)
  • misc: bump ci-workflow generator to node 24 and current action majors (#​36364)
  • misc: preserve package alias keys in generated package.json (#​35207)
  • misc: prevent crash when opening browser in Podman+WSL container (#​34639)
  • misc: move plugin internal imports to devkit/internal (#​36430)
  • misc: use workspaceRoot in workspaceModule path (#​35142)
  • misc: bump css-loader so npm can resolve rspack core 2 (#​36643)
  • misc: make generated code lint-clean under oxlint defaults (#​36749)
  • misc: de-flake the nx watch e2e suite (#​36758)
  • misc: ignore bundled snapshots when pruning npm lockfiles (#​36763, #​36672)
  • module-federation: do not cache static remote assets in the dev-server plugin (#​36279, #​36278)
  • module-federation: strip version suffix from npm dependency names for bun compatibility (#​34960)
  • nextjs: stop installing unused Next.js ESLint packages from the library generator (#​36779)
  • nextjs: describe the library generator and export its server entry (#​36776)
  • nextjs: stop installing unused babel-jest for generated apps (#​36765)
  • nextjs: respect the src option when setting sourceRoot in the application generator (#​36833, #​35181)
  • nextjs: expose compiler and inSourceTests options in the library generator (#​36780)
  • nextjs: make built next.config load without @​nx/next installed (#​36655, #​36511)
  • nx-dev: keep the kb index working for uncommitted articles (#​36588)
  • nx-dev: update docs pricing link (#​36625)
  • nx-dev: let six legacy backlink paths reach their redirects (#​36819)
  • nx-dev: show repository path in light mode (#​36818)
  • react: make module federation packages optional peer dependencies (#​36492)
  • react: write the dev-server port onto the generated serve target (#​36589)
  • react-native: include migration docs in the built package (#​36378)
  • release: only extract body issue references linked via closing keywords (#​36326, #​123)
  • release: ignore deleted projects in historical affectedness (#​36538)
  • release: support custom conventional commit types (#​36539)
  • release: skip changelog resolution for unversioned projects (#​36544)
  • release: preserve package.json formatting (#​36540)
  • release: Don't attribute commits with no author email to @find (#​36526)
  • release: resolve out-of-set local dependency versions (#​36334)
  • repo: bump decompress to safe version (#​36333)
  • repo: drop stale e2e dependsOn overrides that omit the local registry (#​36482)
  • repo: serialize cypress installs and skip the binary when unused (#​36493)
  • repo: tell review-pr agents to compare base and HEAD with git (#​36644)
  • repo: restore missing linux native binding entries to pnpm-lock (#​36785)
  • repo: stop CI cache churn from evicting the cargo caches (#​36801)
  • repo: serve nx executor schema reads from source in unit tests (#​36809)
  • repo: stop pnpm from installing inside nx script tasks (#​36839)
  • repo: stop parallel sandbox reviews from clobbering each other's registry (#​36840)
  • rspack: lazy-load @​rspack/core in create-compiler to avoid eager ESM resolution (#​36476)
  • rspack: preload @​rspack/core before loading rspack config files (#​36687, #​36685)
  • storybook: update configuration generator nx.json (#​34880, #​34879)
  • testing: add @​swc/core when configuring jest with the swc compiler (#​36409)
  • testing: reserve dev-server ports in the react-router e2e suite (#​36585)
  • testing: install typescript in npm e2e workspaces to keep tsquery off TypeScript 7 (#​36478)
  • testing: unblock Cypress component testing on Angular 22.1 (#​36637)
  • testing: prevent playwright from launching a redundant web server (#​36402, #​34698)
  • vite: prevent watch false leaking into dev server config (#​36080, #​36078)
  • vitest: honor watch config and keep --ui open in the test executor (#​36237, #​30263)
  • vitest: generate root vitest.config.ts instead of deprecated vitest.workspace (#​36316, #​36311)
  • vitest: prevent out-of-memory crash during atomized test graph creation (#​36339, #​36315)
  • vitest: use esm config files and import.meta.dirname (#​36605)
  • vitest: generate the requested e2e target in inferred workspaces and de-flake the generated plugin e2e (#​36623)
  • vitest: do not set projectType when inferring targets (#​36831, #​33989)
  • vitest: write each atomized target's coverage to its own directory (#​36658, #​36503)
  • webpack: disable extractComments on the swc terser minimizer (#​36238, #​36233)
  • webpack: bundle non-buildable library subpaths with fallback-array exports (#​36313, #​36309)
  • webpack: propagate watch option from executor to webpack config (#​34927, #​22945)
  • webpack: set optimization.minimize to its normalized object form (#​36815)
  • webpack: add development configuration to inferred build target (#​36832, #​33004)
❤️ Thank You

v23.1.3

Compare Source

23.1.3 (2026-08-31)
🩹 Fixes
  • angular: import optional ng-packagr lazily (#​36632)
  • core: compare daemon workspace roots case-insensitively on Windows (#​36835, #​36722)
  • devkit: reload TS config files fresh instead of serving stale cached modules (#​36656)
  • nextjs: expose compiler and inSourceTests options in the library generator (#​36780)
  • nextjs: make built next.config load without @​nx/next installed (#​36655, #​36511)
  • nx-dev: let six legacy backlink paths reach their redirects (#​36819)
  • nx-dev: show repository path in light mode (#​36818)
❤️ Thank You

v23.1.2

Compare Source

23.1.2 (2026-08-26)

🩹 Fixes
  • angular: make webpack-related packages optional peer dependencies (#​36310)
  • angular: keep buildable libraries private (#​36545)
  • angular-rspack: stop builds crashing on non-array styleUrls (#​36550)
  • angular-rspack: rebuild components when their templates or styles change on Windows (#​36641, #​36619)
  • core: normalize resolved module paths (#​36556, #​36549)
  • core: stop pruneProjectGraph from mutating the source project graph (#​36517, #​36470)
  • core: make preset empty work without github.com and improve template download errors (#​36508)
  • core: drain to stdout before exiting nx affected (#​36569, #​36568)
  • core: update brace-expansion to 5.0.9 for CVE-2026-14257 (#​36577)
  • core: restrict daemon and plugin worker socket access to the owning user (#​36370)
  • core: drain stdout before exiting nx run-many and nx run (#​36607, #​36606)
  • core: resolve main worktree root without a Windows verbatim prefix (#​36649, #​35637)
  • core: accept bun.lock lockfileVersion 2 and 3 (#​36666)
  • core: maintain cacheability when an executor target default applies (#​36477)
  • core: don't leave an unkillable nx process when a terminal closes (#​36683, #​36682)
  • core: honor the package manager's registry config in nx migrate (#​35954, #​35843)
  • core: resolve telemetry DNS in-process to avoid a getenv segfault (#​36673)
  • core: skip target group members without a target (#​36711, #​36712)
  • core: port quoteShellArg helper for no-shell spawn fixes (a9e493bf5f)
  • core: stop resending accumulated task hash results to the daemon when hashing tasks (#​36716)
  • core: apply package.json updates unblocked by later package groups (#​36636)
  • core: adapt held-updates spec to enquirer prompt shape (8fe6dab9d2)
  • core: create external nodes for

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 1a00e757-a34f-43ac-bb0f-8185107c070c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@socket-security

socket-security Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednx@​23.1.1 ⏵ 23.2.168 +10100 +1893 +1100100

View full report

@renovate
renovate Bot force-pushed the renovate/npm-nx-vulnerability branch from fe1fc50 to c30070c Compare October 6, 2026 05:37
Signed-off-by: Renovate Bot <bot@renovateapp.com>
@renovate
renovate Bot force-pushed the renovate/npm-nx-vulnerability branch from c30070c to 3c3346c Compare October 6, 2026 12:09
@renovate renovate Bot changed the title fix(deps): update dependency nx to v23.2.1 [security] fix(deps): update dependency nx to v23.2.1 [security] - autoclosed Oct 6, 2026
@renovate renovate Bot closed this Oct 6, 2026
@renovate
renovate Bot deleted the renovate/npm-nx-vulnerability branch October 6, 2026 13:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants