Repository navigation
[Aikido] Fix 4 security issues in nx, axios, yaml and 1 more - #1761
Open
aikido-autofix[bot] wants to merge 2 commits into
Open
aikido-autofix[bot] wants to merge 2 commits into
aikido-autofix[bot] wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade nx, axios, yaml, and yargs to fix command injection (RCE), prototype pollution, and denial-of-service vulnerabilities. This update includes breaking changes that require manual migration.
nx (20.8.4 => 22.7.8)
1. Removed deprecated
getJestProjectsfunction (21.0.0)Where your code is affected:
jest.config.ts:1- The root Jest configuration imports and usesgetJestProjectsfrom@nx/jestImpact: The
getJestProjects()function has been removed in nx v21.0.0, which will cause the Jest configuration to fail when loading, breaking all test execution across the monorepoRemediation: Replace
getJestProjects()with the new approach using Nx's inference plugins or manually configure Jest projects array2. Node.js version requirement (21.0.0)
Where your code is affected:
.nvmrcspecifiesv24.15.0, but nx v21+ requires Node.js^20.19.0minimumImpact: While the current Node.js version (24.15.0) meets the minimum requirement, the breaking change enforces stricter version checking that could affect CI/CD pipelines or developer environments using older Node.js versions
Remediation: Ensure all environments use Node.js >= 20.19.0; current
.nvmrcversion is already compliantOther Packages
axios (1.18.1 => 1.20.0): No breaking changes affect this codebase. The code uses basic axios functionality (
axios.get(),axios.create(),validateStatus,maxRedirects) which remain unchanged. The breaking changes around navigation-canceled XHR requests, DNS lookup errors, and status code additions don't impact the current usage patterns.yargs (17.7.2 => 18.1.0): Not used in this codebase.
All breaking changes by upgrading nx from version 20.8.4 to 22.7.8 (CHANGELOG)
cliproperty from migration definitionsreadWorkspaceConfiggetJestProjectstsConfigoption from the@nx/jest:jestexecutortsConfigandcopyFilesoptions from the@nx/cypress:cypressexecutoruseLegacyVersioningis false by default in release configurationNX_DISABLE_DBenvironment variable has been removed.tscandswcexecutors (theexternalandexternalBuildTargetsoptions are no longer available).decorate-cliscript has been removed.nx formatcommand and generators no longer default to sorting TypeScript path mappings (use--sort-root-tsconfig-pathsflag or setNX_FORMAT_SORT_TSCONFIG_PATHS=trueto keep previous behavior).deleteOutputPathandsassImplementationoptions have been removed from webpack executors.deleteOutputPathandsassImplementationoptions have been removed from rspack executors.useLegacyTypescriptPluginhas changed tofalsefor bundling.simpleNameoption has been removed from library generators.--legacy-peer-depsbehavior is no longer forced by default (configure your package manager if needed).preserveMatchingDependencyRanges(nowtrueby default), andstrictPreidin release configuration.updateDependentsoption now defaults toalwaysinstead ofautoin release configuration.releaseTag*properties have been refactored to a nestedreleaseTagobject.init()onVersionActionshas changed (no longer accepts a second argument; validation now occurs via separatevalidate()method).nx affectedbehavior, which may result in more projects receiving version bumps.config.conventionalCommitsConfigforDefaultChangelogRendereris no longer nullable.componentTestingPreset.reportsDirectoryis now resolved against workspace root instead of project root, which may change the output location for Vitest reports (#34720)All breaking changes by upgrading axios from version 1.18.1 to 1.20.0 (CHANGELOG)
All breaking changes by upgrading yargs from version 17.7.2 to 18.1.0 (CHANGELOG)
command.^20.19.0 || ^22.12.0 || >=23.✅ 4 CVEs resolved by this upgrade
This PR will resolve the following CVEs:
adapter,proxy, ortransformResponse.__proto__keys are not filtered, allowing attackers to pollute object prototypes and manipulate property lookups through malicious configuration objects.🤖 Remediation details
Fix five transitive security vulnerabilities introduced via nx and jest dependency chains
Short summary
This PR remediates security vulnerabilities in five packages:
nx,axios,yaml,yargs, andsmol-toml. The rootpackage.jsonwas updated to bumpnxand all@nx/*sibling packages from20.8.4to22.7.8, and fourresolutionsentries were added to force patched versions of transitive dependencies thatnx@22.7.8pins exactly. Theyarn.lockwas refreshed to reflect all resolved version changes.nx
nxis declared directly in the rootpackage.jsonat an exact version (20.8.4), which falls within the vulnerable range. It was bumped to22.7.8(the minimum patched release in the22.xline) as a direct manifest edit. All seven@nx/*sibling packages (@nx/esbuild,@nx/eslint,@nx/eslint-plugin,@nx/jest,@nx/js,@nx/node,@nx/workspace) were pinned at the same exact version and moved to22.7.8in the same edit, as required by the group-alignment policy for packages sharing an identical declared version.axios
axios@1.18.1was a transitive dependency pulled in by both workspace packages (@aligent/cdk-header-change-detection,@aligent/cdk-prerender-proxy) via^1.18.0and bynxvia an exact pin of1.18.1. The workspace^1.18.0selector was refreshed to resolve1.20.0viayarn up -R axios. However,nx@22.7.8continued to pinaxiosat the exact version1.18.1in its own published dependencies, which no parent bump can override; aresolutionsentry ("axios": "1.20.0") was therefore added as a last resort to force the single consolidated lockfile entry to1.20.0.yaml
Two vulnerable
yaml@2.xinstances existed: one at2.8.3(selectors*and^2.6.0) and one at2.9.0(selectors^2.9.0and an exact2.9.0pin fromnx@22.7.8). The^2.9.0and*selectors were refreshed to2.9.1viayarn up -R yaml. The exact2.9.0pin fromnxcould not be resolved by a parent bump, so targetedresolutionsentries (yaml@npm:^2.6.0,yaml@npm:^2.9.0,yaml@npm:2.9.0) were added to force all2.xselectors to2.9.1. A separateyaml@1.10.3instance (requested byaws-cdk-libandcosmiconfigvia^1.10.0) is outside the vulnerable range (>=2.0.0) and was intentionally preserved by using targeted rather than blanket resolutions.yargs
yargs@17.7.2is a transitive dependency of bothjest-cli@29.7.0(via^17.3.1) andnx@22.7.8(via^17.6.2). Analysis confirmed that no published version of either parent — up tojest-cli@30.5.1andnx@23.x— shipsyargs@18.x; both chains declareyargsat^17.xthroughout. With no viable parent-bump path, aresolutionsentry ("yargs": "18.1.0") was added as a last resort to force the resolved version to the minimum patched release.smol-toml
smol-toml@1.6.1is a transitive dependency pulled in bynx@22.7.8via an exact pin of1.6.1. Because the pin is exact, no parent bump can resolve it to a higher version. A targetedresolutionsentry ("smol-toml@npm:1.6.1": "1.7.1") was added to override only that specific selector and bring the resolved version to the minimum patched release1.7.1.Version changes
nx20.8.422.7.8@nx/esbuild20.8.422.7.8nx@nx/eslint20.8.422.7.8nx@nx/eslint-plugin20.8.422.7.8nx@nx/jest20.8.422.7.8nx@nx/js20.8.422.7.8nx@nx/node20.8.422.7.8nx@nx/workspace20.8.422.7.8nxaxios1.18.11.20.0nxyaml(v2.x instances)2.8.3/2.9.02.9.1nxyargs17.7.218.1.0yargs@18.x)smol-toml1.6.11.7.1nx