Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 26, 2025

Bumps the nx group in /lambdas with 3 updates: @nx/eslint, @nx/js and @nx/vite.

Updates @nx/eslint from 21.4.0 to 21.4.1

Release notes

Sourced from @​nx/eslint's releases.

21.4.1 (2025-08-22)

🚀 Features

  • graph: task graph support multiple targets (#32418)
  • js: add includeIgnoredAssetFiles option and per-asset includeIgnoredFiles (#31813)
  • js: detect duplicate project references in @nx/js:typescript-sync (#32443)
  • nx: use platform certificate trust store (#31999)
  • nx-dev: link ukg article on homepage (8d16697547)
  • nx-dev: configure rewrite to astro-docs when NEXT_PUBLIC_ASTRO_URL is set (#32424)
  • repo: add GitHub Actions workflow to validate PR titles (#32458)
  • rspack: add support for converting webpack plugin configs #30292 (#32382, #30292)
  • tools: add repository update system for automated Nx migrations (#32124)
  • webpack: migrate from deprecated url.parse() to WHATWG URL API (70fb618785)

🩹 Fixes

  • angular: set the tsConfig option when possible to aid with angular migrations (#32355, #32138)
  • angular: do not update project configuration when not changes were made in migration (#32448)
  • angular-rspack: do not error on server budget violation (#32445)
  • core: improve Cursor editor detection and extension installation (#32374)
  • core: ensure deterministic dummy task generation in task graphs (#32414)
  • core: handle unsupported platforms in Cursor IDE install command (#32419)
  • core: only prompt for NX Console installation in TTY environments (#32425)
  • core: enhance validation for continuous task dependencies (#31786)
  • core: retry current message when receiving NX_VERSION_CHANGED from daemon (#32417, #29446)
  • core: use black for all fg elements when in light theme (#32415)
  • core: fail fast when running commands in parallel (#32386, #28477)
  • core: handle no daemon when stopping (#32455)
  • core: create pnpm peer deps settings in the appropriate location when creating workspace (#32470)
  • core: repair nx mcp in pnpm/yarn (#32452)
  • devkit: restore peer dep range to 2 majors (#32406, #31801)
  • devkit: include UPDATE changes in findCreatedProjectFiles for generator callbacks (#31429, #29852)
  • expo: export output should be within project directory (#32477)
  • gradle: use AST parsing to migrate updates to version catalogs (#32463)
  • gradle: allow test target name to be configuration from nx.json (#32416)
  • graph: some misc fixes to the graph (#32401)
  • graph: nxArgs.projects can be an empty array (#32479)
  • js: esm loader should handle absolute paths on windows #32376 (#32383, #32376)
  • js: improve @nx/js/typescript plugin check for buildable libraries (#32405, #32116, #32290)
  • js: do not infer the project type in the @nx/js/typescript plugin (#32421)
  • misc: update @​types/node to v20.19.9 to support fetch API (#32092, #31637)
  • misc: respect string values in alwaysAddToPackageJson migration flag (#32433, #30586)
  • misc: check for packages existence to detect pnpm workspaces setup (#32474)
  • module-federation: do not rely on virtualRuntimeEntry #31831 (#32387, #31831, #32404)
  • nx-dev: update navbar CTA buttons and updates event tracking (#32392)
  • plugin: handle directory paths correctly in executor and generator generators (#31856, #31803, #31776)
  • testing: support NX_CACHE_PROJECT_GRAPH when reading inferred config from jest cache file (#32380)
  • testing: fall back to tsconfig.json in the jest resolver (#32083)
  • webpack: migrate from deprecated url.parse() to WHATWG URL API (#32399)

... (truncated)

Commits

Updates @nx/js from 21.4.0 to 21.4.1

Release notes

Sourced from @​nx/js's releases.

21.4.1 (2025-08-22)

🚀 Features

  • graph: task graph support multiple targets (#32418)
  • js: add includeIgnoredAssetFiles option and per-asset includeIgnoredFiles (#31813)
  • js: detect duplicate project references in @nx/js:typescript-sync (#32443)
  • nx: use platform certificate trust store (#31999)
  • nx-dev: link ukg article on homepage (8d16697547)
  • nx-dev: configure rewrite to astro-docs when NEXT_PUBLIC_ASTRO_URL is set (#32424)
  • repo: add GitHub Actions workflow to validate PR titles (#32458)
  • rspack: add support for converting webpack plugin configs #30292 (#32382, #30292)
  • tools: add repository update system for automated Nx migrations (#32124)
  • webpack: migrate from deprecated url.parse() to WHATWG URL API (70fb618785)

🩹 Fixes

  • angular: set the tsConfig option when possible to aid with angular migrations (#32355, #32138)
  • angular: do not update project configuration when not changes were made in migration (#32448)
  • angular-rspack: do not error on server budget violation (#32445)
  • core: improve Cursor editor detection and extension installation (#32374)
  • core: ensure deterministic dummy task generation in task graphs (#32414)
  • core: handle unsupported platforms in Cursor IDE install command (#32419)
  • core: only prompt for NX Console installation in TTY environments (#32425)
  • core: enhance validation for continuous task dependencies (#31786)
  • core: retry current message when receiving NX_VERSION_CHANGED from daemon (#32417, #29446)
  • core: use black for all fg elements when in light theme (#32415)
  • core: fail fast when running commands in parallel (#32386, #28477)
  • core: handle no daemon when stopping (#32455)
  • core: create pnpm peer deps settings in the appropriate location when creating workspace (#32470)
  • core: repair nx mcp in pnpm/yarn (#32452)
  • devkit: restore peer dep range to 2 majors (#32406, #31801)
  • devkit: include UPDATE changes in findCreatedProjectFiles for generator callbacks (#31429, #29852)
  • expo: export output should be within project directory (#32477)
  • gradle: use AST parsing to migrate updates to version catalogs (#32463)
  • gradle: allow test target name to be configuration from nx.json (#32416)
  • graph: some misc fixes to the graph (#32401)
  • graph: nxArgs.projects can be an empty array (#32479)
  • js: esm loader should handle absolute paths on windows #32376 (#32383, #32376)
  • js: improve @nx/js/typescript plugin check for buildable libraries (#32405, #32116, #32290)
  • js: do not infer the project type in the @nx/js/typescript plugin (#32421)
  • misc: update @​types/node to v20.19.9 to support fetch API (#32092, #31637)
  • misc: respect string values in alwaysAddToPackageJson migration flag (#32433, #30586)
  • misc: check for packages existence to detect pnpm workspaces setup (#32474)
  • module-federation: do not rely on virtualRuntimeEntry #31831 (#32387, #31831, #32404)
  • nx-dev: update navbar CTA buttons and updates event tracking (#32392)
  • plugin: handle directory paths correctly in executor and generator generators (#31856, #31803, #31776)
  • testing: support NX_CACHE_PROJECT_GRAPH when reading inferred config from jest cache file (#32380)
  • testing: fall back to tsconfig.json in the jest resolver (#32083)
  • webpack: migrate from deprecated url.parse() to WHATWG URL API (#32399)

... (truncated)

Commits
  • 11cf02c feat(js): detect duplicate project references in @nx/js:typescript-sync (#3...
  • a3e3f5f fix(misc): check for packages existence to detect pnpm workspaces setup (#3...
  • 726de02 feat(js): add includeIgnoredAssetFiles option and per-asset includeIgnoredFil...
  • 43b9b74 fix(js): do not infer the project type in the @nx/js/typescript plugin (#32...
  • 251a7d9 fix(js): improve @nx/js/typescript plugin check for buildable libraries (#3...
  • 1628af5 fix(misc): update @​types/node to v20.19.9 to support fetch API (#32092)
  • 748d681 fix(js): esm loader should handle absolute paths on windows #32376 (#32383)
  • See full diff in compare view

Updates @nx/vite from 21.4.0 to 21.4.1

Release notes

Sourced from @​nx/vite's releases.

21.4.1 (2025-08-22)

🚀 Features

  • graph: task graph support multiple targets (#32418)
  • js: add includeIgnoredAssetFiles option and per-asset includeIgnoredFiles (#31813)
  • js: detect duplicate project references in @nx/js:typescript-sync (#32443)
  • nx: use platform certificate trust store (#31999)
  • nx-dev: link ukg article on homepage (8d16697547)
  • nx-dev: configure rewrite to astro-docs when NEXT_PUBLIC_ASTRO_URL is set (#32424)
  • repo: add GitHub Actions workflow to validate PR titles (#32458)
  • rspack: add support for converting webpack plugin configs #30292 (#32382, #30292)
  • tools: add repository update system for automated Nx migrations (#32124)
  • webpack: migrate from deprecated url.parse() to WHATWG URL API (70fb618785)

🩹 Fixes

  • angular: set the tsConfig option when possible to aid with angular migrations (#32355, #32138)
  • angular: do not update project configuration when not changes were made in migration (#32448)
  • angular-rspack: do not error on server budget violation (#32445)
  • core: improve Cursor editor detection and extension installation (#32374)
  • core: ensure deterministic dummy task generation in task graphs (#32414)
  • core: handle unsupported platforms in Cursor IDE install command (#32419)
  • core: only prompt for NX Console installation in TTY environments (#32425)
  • core: enhance validation for continuous task dependencies (#31786)
  • core: retry current message when receiving NX_VERSION_CHANGED from daemon (#32417, #29446)
  • core: use black for all fg elements when in light theme (#32415)
  • core: fail fast when running commands in parallel (#32386, #28477)
  • core: handle no daemon when stopping (#32455)
  • core: create pnpm peer deps settings in the appropriate location when creating workspace (#32470)
  • core: repair nx mcp in pnpm/yarn (#32452)
  • devkit: restore peer dep range to 2 majors (#32406, #31801)
  • devkit: include UPDATE changes in findCreatedProjectFiles for generator callbacks (#31429, #29852)
  • expo: export output should be within project directory (#32477)
  • gradle: use AST parsing to migrate updates to version catalogs (#32463)
  • gradle: allow test target name to be configuration from nx.json (#32416)
  • graph: some misc fixes to the graph (#32401)
  • graph: nxArgs.projects can be an empty array (#32479)
  • js: esm loader should handle absolute paths on windows #32376 (#32383, #32376)
  • js: improve @nx/js/typescript plugin check for buildable libraries (#32405, #32116, #32290)
  • js: do not infer the project type in the @nx/js/typescript plugin (#32421)
  • misc: update @​types/node to v20.19.9 to support fetch API (#32092, #31637)
  • misc: respect string values in alwaysAddToPackageJson migration flag (#32433, #30586)
  • misc: check for packages existence to detect pnpm workspaces setup (#32474)
  • module-federation: do not rely on virtualRuntimeEntry #31831 (#32387, #31831, #32404)
  • nx-dev: update navbar CTA buttons and updates event tracking (#32392)
  • plugin: handle directory paths correctly in executor and generator generators (#31856, #31803, #31776)
  • testing: support NX_CACHE_PROJECT_GRAPH when reading inferred config from jest cache file (#32380)
  • testing: fall back to tsconfig.json in the jest resolver (#32083)
  • webpack: migrate from deprecated url.parse() to WHATWG URL API (#32399)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the nx group in /lambdas with 3 updates: [@nx/eslint](https://github.com/nrwl/nx/tree/HEAD/packages/eslint), [@nx/js](https://github.com/nrwl/nx/tree/HEAD/packages/js) and [@nx/vite](https://github.com/nrwl/nx/tree/HEAD/packages/vite).


Updates `@nx/eslint` from 21.4.0 to 21.4.1
- [Release notes](https://github.com/nrwl/nx/releases)
- [Commits](https://github.com/nrwl/nx/commits/21.4.1/packages/eslint)

Updates `@nx/js` from 21.4.0 to 21.4.1
- [Release notes](https://github.com/nrwl/nx/releases)
- [Commits](https://github.com/nrwl/nx/commits/21.4.1/packages/js)

Updates `@nx/vite` from 21.4.0 to 21.4.1
- [Release notes](https://github.com/nrwl/nx/releases)
- [Commits](https://github.com/nrwl/nx/commits/21.4.1/packages/vite)

---
updated-dependencies:
- dependency-name: "@nx/eslint"
  dependency-version: 21.4.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: nx
- dependency-name: "@nx/js"
  dependency-version: 21.4.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: nx
- dependency-name: "@nx/vite"
  dependency-version: 21.4.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: nx
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 26, 2025
@dependabot dependabot bot requested a review from a team as a code owner August 26, 2025 09:29
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 26, 2025
Copy link
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/@nx/eslint 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/js ^21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/vite ^21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/devkit 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/eslint 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/js 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-darwin-arm64 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-darwin-x64 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-freebsd-x64 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-linux-arm-gnueabihf 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-linux-arm64-gnu 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-linux-arm64-musl 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-linux-x64-gnu 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-linux-x64-musl 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-win32-arm64-msvc 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/nx-win32-x64-msvc 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/vite 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/@nx/workspace 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected
npm/nx 21.4.1 🟢 3.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ 0dangerous workflow patterns detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 7binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities⚠️ 094 existing vulnerabilities detected

Scanned Files

  • lambdas/package.json
  • lambdas/yarn.lock

@npalm npalm merged commit ff5308f into main Aug 26, 2025
6 checks passed
@npalm npalm deleted the dependabot/npm_and_yarn/lambdas/nx-860ffa7d89 branch August 26, 2025 12:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant