Skip to content

Conversation

lexpank
Copy link

@lexpank lexpank commented Oct 4, 2025

Current Behavior

Nx is currently using a vulnerable version of axios (<1.12.0) which has a reported high-level vulnerability CVE-2025-58754. This is being flagged by GitHub Advanced Security. This is a lighter version of #32712 (also rebased), going from branch to make is easier for me to rebase.

Expected Behavior

Nx should be using a patched version of axios (≥1.12.0) that addresses said vulnerability.

@lexpank lexpank requested a review from a team as a code owner October 4, 2025 07:03
@lexpank lexpank requested a review from Cammisuli October 4, 2025 07:03
Copy link

netlify bot commented Oct 4, 2025

‼️ Deploy request for nx-docs rejected.

Name Link
🔨 Latest commit e4edf32

Copy link

vercel bot commented Oct 4, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Updated (UTC)
nx-dev Ready Ready Preview Oct 4, 2025 7:16am

@lexpank
Copy link
Author

lexpank commented Oct 5, 2025

@JamesHenry / @FrozenPandaz nice to meet you all! I would really appreciate if you could review it and push downstream (mostly to reduce noise). Happy to address some more vulnerabilities later as well!

@JamesHenry
Copy link
Collaborator

Thanks @lexpank, I've updated the original PR to resolve the conflicts. This PR would not have been possible to proceed with because of what it changed in the lockfile around optionalDependencies as well FYI

@JamesHenry JamesHenry closed this Oct 6, 2025
Copy link
Contributor

This pull request has already been merged/closed. If you experience issues related to these changes, please open a new issue referencing this pull request.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Oct 12, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants