Repository navigation
[Aikido] Fix 5 security issues in axios, nx, yaml and 1 more - #1762
Open
aikido-autofix[bot] wants to merge 2 commits into
Open
aikido-autofix[bot] wants to merge 2 commits into
aikido-autofix[bot] wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade axios, nx, yaml, and yargs to fix buffer overflow, command injection, prototype pollution, and stack exhaustion vulnerabilities. This update includes breaking changes that require manual migration.
Where your code is affected:
jest.config.ts(line 1)Impact: The
getJestProjectsfunction was removed in nx v21.0.0. The code imports and uses this function to configure Jest projects, which will cause a runtime error after the upgrade.Remediation: Replace
getJestProjects()with the new approach of manually listing project paths or using the nx jest plugin configuration to auto-discover projects.All breaking changes by upgrading axios from version 1.18.1 to 1.20.0 (CHANGELOG)
All breaking changes by upgrading nx from version 20.8.4 to 22.7.8 (CHANGELOG)
cliproperty from migration definitionsreadWorkspaceConfiggetJestProjectstsConfigoption from the@nx/jest:jestexecutortsConfigandcopyFilesoptions from the@nx/cypress:cypressexecutoruseLegacyVersioningis false by default in release configurationNX_DISABLE_DBenvironment variable has been removed.tscandswcexecutors (theexternalandexternalBuildTargetsoptions are no longer available).decorate-cliscript has been removed.nx formatcommand and generators no longer default to sorting TypeScript path mappings (use--sort-root-tsconfig-pathsflag or setNX_FORMAT_SORT_TSCONFIG_PATHS=trueto keep previous behavior).deleteOutputPathandsassImplementationoptions have been removed from webpack executors.deleteOutputPathandsassImplementationoptions have been removed from rspack executors.useLegacyTypescriptPluginhas changed tofalsefor bundling.simpleNameoption has been removed from library generators.--legacy-peer-depsbehavior is no longer forced by default (configure your package manager if needed).preserveMatchingDependencyRanges(nowtrueby default), andstrictPreidin release configuration.updateDependentsoption now defaults toalwaysinstead ofautoin release configuration.releaseTag*properties have been refactored to a nestedreleaseTagobject.init()onVersionActionshas changed (no longer accepts a second argument; validation now occurs via separatevalidate()method).nx affectedbehavior, which may result in more projects receiving version bumps.config.conventionalCommitsConfigforDefaultChangelogRendereris no longer nullable.componentTestingPreset.reportsDirectoryis now resolved against workspace root instead of project root, which may change the output location for Vitest reports (#34720)All breaking changes by upgrading yargs from version 17.7.2 to 18.1.0 (CHANGELOG)
command.^20.19.0 || ^22.12.0 || >=23.✅ 5 CVEs resolved by this upgrade
This PR will resolve the following CVEs:
adapter,proxy, ortransformResponse.__proto__keys are not filtered, allowing attackers to pollute object prototypes and manipulate property lookups through malicious configuration objects.🤖 Remediation details
Fix five security advisories in nx, axios, yaml, yargs, and smol-toml
Short summary
This PR remediates security vulnerabilities in five packages:
nx,axios,yaml,yargs, andsmol-toml. The fix involves bumpingnxand all sibling@nx/*devDependencies in the rootpackage.jsonfrom20.8.4to22.7.8, and adding fourresolutionsentries in the rootpackage.jsonto override exact transitive pins thatnx@22.7.8itself declares and that no publishednxrelease in the reachable range resolves to a patched version. Theyarn.lockat the repo root is the only lockfile affected.nx
nxis declared as a direct devDependency in the rootpackage.jsonat the exact version20.8.4, which falls within the vulnerable range. It was bumped to22.7.8(the minimum patched release). All seven sibling@nx/*packages (@nx/esbuild,@nx/eslint,@nx/eslint-plugin,@nx/jest,@nx/js,@nx/node,@nx/workspace) were declared at the same exact version and moved together as a group to22.7.8, since they form a tightly coupled release family and mismatching versions would break the toolchain.axios
axiosis a direct dependency of two workspace packages (@aligent/cdk-header-change-detectionand@aligent/cdk-prerender-proxy) under^1.18.0, and is also pinned exactly at1.18.1bynx@22.7.8itself. The^1.18.0workspace ranges were resolved to1.20.0via a recursive lockfile refresh (yarn up -R axios). The exact1.18.1pin fromnxrequired aresolutionsentry ("axios": "1.20.0") because no publishednxversion in the 20.x–22.x range ships a patchedaxios, making a parent bump alone insufficient.yaml
yamlis a direct dependency of the@aligent/cdk-graphql-mesh-serverworkspace package under^2.9.0, and is also pinned exactly at2.9.0bynx@22.7.8. The^2.9.0workspace range was resolved to2.9.1via a recursive lockfile refresh (yarn up -R yaml). The exact2.9.0pin fromnxrequired aresolutionsentry ("yaml": "2.9.1") for the same reason asaxios— nonxrelease in the reachable range declares a patchedyamltransitively.yargs
yargsis a transitive dependency pulled in by bothnx(spec^17.6.2) andjest-cli(spec^17.3.1). Analysis confirmed that every published version of both parents — including the latestnxandjest-clireleases — still declaresyargsat^17.7.2or17.7.2, meaning no parent bump can ever resolveyargs >= 18.1.0. Aresolutionsentry ("yargs": "18.1.0") was added as the only viable path to the patched version.smol-toml
smol-tomlis a transitive dependency pinned exactly at1.6.1bynx@22.7.8. Nonxrelease between22.7.8and the latest stable adoptssmol-toml >= 1.7.1(the latest publishednxpre-release is the first to declare1.7.1), so a parent bump within the currentnxmajor cannot resolve the vulnerability. Aresolutionsentry ("smol-toml": "1.7.1") was added, following the same pattern used foraxiosandyaml, to override the exact pin.Version changes
nx20.8.422.7.8@nx/esbuild20.8.422.7.8nxbump@nx/eslint20.8.422.7.8nxbump@nx/eslint-plugin20.8.422.7.8nxbump@nx/jest20.8.422.7.8nxbump@nx/js20.8.422.7.8nxbump@nx/node20.8.422.7.8nxbump@nx/workspace20.8.422.7.8nxbumpaxios1.18.11.20.0^1.18.0workspace ranges refreshed viayarn up -R; exactnxpin overridden viaresolutionsyaml2.9.0/2.8.32.9.1^2.9.0workspace range refreshed viayarn up -R; exactnxpin overridden viaresolutionsyargs17.7.218.1.0resolutionsoverridesmol-toml1.6.11.7.1nxpin overridden viaresolutions