Skip to content

chore(deps): bump nx from 22.7.7 to 22.7.12 - #6857

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/nx-22.7.12
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/nx-22.7.12

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps nx from 22.7.7 to 22.7.12.

Release notes

Sourced from nx's releases.

22.7.12 (2026-09-10)

🩹 Fixes

❤️ Thank You

22.7.11 (2026-09-09)

🩹 Fixes

  • core: release per-run process listeners and task history results (#36974, #36866)

❤️ Thank You

22.7.10 (2026-09-09)

🩹 Fixes

  • core: validate the migrations path before extracting package migrations (#36887)

❤️ Thank You

22.7.9 (2026-09-01)

🩹 Fixes

  • core: restrict daemon and plugin worker socket access to the owning user (#36370, #36586, #36463)
  • core: compare daemon workspace roots case-insensitively on Windows (#36835, #36722)
  • core: close daemon log descriptors after spawn to avoid Node 26 crash (#36280)

... (truncated)

Commits
  • 7c5b4dc docs(core): correct the NX_MAX_MESSAGE_SIZE row and drop a stale clause
  • 3163430 chore(core): format daemon client with prettier
  • ab613f7 chore(core): satisfy cargo fmt on the backported hash planner
  • 1cffd59 fix(core): avoid mutating target options when resolving configurations (#36934)
  • 8d81ae2 fix(core): reduce task hashing memory usage on large workspaces (#36267)
  • bfd3e51 fix(core): share workspace fileset hash results instead of deep-cloning per t...
  • 02f82fa cleanup(core): persist file-set hash caches on the TaskHasher instance (#36118)
  • 2c34a3b fix(core): remove redundant allWorkspaceFiles from the project graph pipeli...
  • 73a415b fix(core): fall back to v8 for oversized daemon responses and length-prefix t...
  • a25009d fix(core): intern hash instructions in a pool and plan with id lists (#36249)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [nx](https://github.com/nrwl/nx/tree/HEAD/packages/nx) from 22.7.7 to 22.7.12.
- [Release notes](https://github.com/nrwl/nx/releases)
- [Commits](https://github.com/nrwl/nx/commits/22.7.12/packages/nx)

---
updated-dependencies:
- dependency-name: nx
  dependency-version: 22.7.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 8, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

⚪ None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump nx from 22.7.7 to 22.7.12 by dependabot[bot] in #6857
  • ci: Pass craft_version to the Craft release action by alwx in #6851
  • chore(tracing): Remove unused maxTransactionDurationExceeded span attribute by antonis in #6820
  • fix(core): preserve Hermes internal bytecode frames in Expo by Trancever in #6848
  • chore(core): Re-enable sdk/no-regexp-constructor lint rule by antonis in #6841
  • chore(deps): update Android SDK to v8.60.0 by github-actions in #6850
  • chore(deps): update Cocoa SDK to v9.30.1 by github-actions in #6849
  • feat(core): Report cellular network technology by alwx in #6827
  • test(e2e): Re-enable iOS view_names assertion in captureMessage test by antonis in #6846
  • fix(core): Strip callback options before the native SDK starts by alwx in #6847
  • fix(android): Resolve @sentry/react-native from rootDir in Expo plugin by alwx in #6840
  • chore: Clean up non-actionable TODOs by antonis in #6843
  • chore(deps): update JavaScript SDK to v10.76.0 by antonis in #6831
  • chore(expo): bump sample to Expo 57.0.26 by antonis in #6838
  • chore(deps): Bump basic-ftp to 6.2.2 by alwx in #6837
  • fix(core): Mark package as side-effect free by devclaimjuimperai in #6829
  • chore(deps): bump getsentry/craft/.github/workflows/changelog-preview.yml from 2.31.0 to 2.33.1 by dependabot in #6833
  • chore(deps): bump gradle/actions/setup-gradle from 6.3.0 to 6.4.0 by dependabot in #6834
  • chore(deps): bump getsentry/craft from 2.31.2 to 2.33.1 by dependabot in #6835
  • chore(deps): bump getsentry/github-workflows/validate-pr from 4013fc6e1aeb1be1f9d3b4d232624f0ec1afa613 to 36c729264d2edc29ebae61950c50e1e9f043ad7e by dependabot in #6832
  • fix(android): Settle initNativeReactNavigationNewFrameTracking promise by antonis in #6823
  • fix(spotlight): Forward image attachments to Spotlight by antonis in #6818
  • fix(ios): Prevent crash when initialized with an invalid DSN by antonis in #6825
  • chore(core): Resolve non-actionable TODOs by antonis in #6826

Plus 2 more


🤖 This preview updates automatically when you update the PR.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f06738c. Configure here.

Comment thread yarn.lock
balanced-match: "npm:^4.0.2"
checksum: 10c0/73304caafd00fdc5b0168e693ac15bf25b6357dec76d1195fcd628fe2cf99c46f9c889a7ecfa3cfe236dbd2d5ce3e27a6ccc4370b46d475d0d19081e11f86019
languageName: node
linkType: hard

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Vulnerable brace-expansion bypasses resolutions

Medium Severity

The nx 22.7.12 bump now depends on exact brace-expansion@5.0.8, which is not covered by the existing Yarn resolutions that remap 5.0.6 and the ^5.0.x ranges to ^5.0.9. That leaves vulnerable 5.0.8 (CVE-2026-69152) in the lockfile. Flagged from the dependency-update review guidance.

Additional Locations (1)
Fix in Cursor Fix in Web

Triggered by project rule: PR Review Guidelines for Cursor Bot

Reviewed by Cursor Bugbot for commit f06738c. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants