chore(deps): upgrade Nx 21.5.3 to 22.7.9 - #93
Merged
Merged
Conversation
Clears two Dependabot advisories that no patch release could fix: GHSA-vp3h-ghgh-jr7g (Zip-Slip in the self-hosted remote cache, fixed in 22.7.7) and GHSA-g2r8-wvmj-jf5w (permissive CORS on the `nx graph` dev server, fixed in 22.7.2). Both are dev-tooling only and neither is reachable in CI or in the published package. All twelve Nx packages plus `nx` move to 22.7.9, the latest on the 22.x line. `@nx/vitest` joins them: Nx 22 split the vitest executor out of `@nx/vite`, so `core`, `domain`, and `tracker` now use `@nx/vitest:test`. `nx migrate` wanted to pull Angular 20.3 to 21, vitest 3 to 4, and Analog 1 to 2 alongside it. `@nx/angular@22` peers Angular `>= 19 < 22`, so none of that is required — the run was limited to the Nx packages and their migrations. `@swc-node/register` and `@swc/core` move up because Nx 22 peers them. Two migration outputs needed correcting: - The codemod dropped `testTargetName` from the `@nx/vite/plugin` block, which let the plugin infer a plain `test` target on `data-transfer`. That project has a vite config but no spec files, so `nx run-many -t test` and the `nx affected -t test` in pr.yml failed on it. Both inferred targets now keep non-`test` names (`vite:test`, `vitest:test`), matching the convention that `test` is only ever declared explicitly. - Nx 22 rejects `{options.reportsDirectory}` as a cache output because it resolves outside the workspace. Coverage outputs move to a single `{workspaceRoot}/coverage/{projectRoot}` default in nx.json rather than being repeated in three project.json files. Verified: lint, format:check, typecheck, test (1946 tests across five projects), build, docs:build, the `prebuild:tracker` CLI bundle step, and the `nx affected -t test|build` and `--skip-nx-cache` paths that pr.yml, release.yml, and .releaserc.json depend on. Closes #82 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RifJr7xyhZkaTWn4ssV1b4
|
🎉 This PR is included in version 0.18.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #82.
Two Dependabot advisories against
nxcould not be closed by a patch release. Both needed the Nx 21 to 22 major migration.22.7.7nx graphdev server22.7.2Neither is reachable in CI or in the published package. We do not use a self-hosted Nx remote cache. Nothing in the workflows starts
nx graph. This is upkeep to get the alert count to zero.What changed
All twelve Nx packages plus
nxmove to22.7.9, the latest on the 22.x line.@nx/vitestjoins them as a thirteenth package. Nx 22 split the vitest executor out of@nx/vite, socore,domain, andtrackernow use@nx/vitest:test.@swc-node/registerand@swc/coremove up because Nx 22 peers them.Angular stayed on 20.3.30
nx migratewanted to pull Angular to 21, vitest to 4, and Analog to 2 alongside the Nx bump.@nx/angular@22peers Angular at>= 19 < 22, so none of that is required.I limited the run to the Nx packages and their migrations. That keeps this change to one major hop.
Issue #92 tracks the Angular 21 upgrade as a separate step.
Two migration outputs needed correcting
The codemod broke
nx affected -t test. It droppedtestTargetNamefrom the@nx/vite/pluginblock innx.json. The plugin then inferred a plaintesttarget onlibs/data-transfer. That project has a vite config but no spec files, so the target failed withNo test files found.pr.ymlrunspnpm nx affected -t test, so this check would have gone red.Both inferred targets now keep names other than
test.@nx/vite/pluginkeepsvite:testand@nx/vitestusesvitest:test. This matches the existing convention, wheretestis only ever declared explicitly in aproject.json.Nx 22 rejects
{options.reportsDirectory}as a cache output. It resolves outside the workspace and fails the target. Coverage outputs move to a single{workspaceRoot}/coverage/{projectRoot}default innx.json, rather than repeating in threeproject.jsonfiles.Verification
All of these pass locally:
pnpm run lintandpnpm run format:checkpnpm run typecheckpnpm run test— 1946 tests across five projectspnpm run buildandpnpm run docs:buildpnpm nx affected -t test --base=origin/developandpnpm nx affected -t build --base=origin/develop, the two commandspr.ymlrunspnpm nx build cli --skip-nx-cache, the command.releaserc.jsonrunsnode dist/apps/cli/main.cjs bundle --name tracker, theprebuild:trackerhookOne note for reviewers
Nx caches the project graph. Run
pnpm nx resetbefore anynx show project,nx run-many, ornx affectedcommand, or you will read a stale graph.Alerts 263, 264, 282, and 283 should close once this merges.
🤖 Generated with Claude Code
https://claude.ai/code/session_01RifJr7xyhZkaTWn4ssV1b4