Skip to content

chore(deps): upgrade Nx 21.5.3 to 22.7.9 - #93

Merged
simoncodes-ca merged 1 commit into
developfrom
chore/upgrade-nx-22
Sep 5, 2026
Merged

simoncodes-ca merged 1 commit into
developfrom
chore/upgrade-nx-22

Conversation

@simoncodes-ca

Copy link
Copy Markdown
Owner

Closes #82.

Two Dependabot advisories against nx could not be closed by a patch release. Both needed the Nx 21 to 22 major migration.

Severity Advisory Summary Fixed in
High GHSA-vp3h-ghgh-jr7g Zip-Slip in the self-hosted remote cache 22.7.7
Medium GHSA-g2r8-wvmj-jf5w Permissive CORS on the nx graph dev server 22.7.2

Neither is reachable in CI or in the published package. We do not use a self-hosted Nx remote cache. Nothing in the workflows starts nx graph. This is upkeep to get the alert count to zero.

What changed

All twelve Nx packages plus nx move to 22.7.9, the latest on the 22.x line.

@nx/vitest joins them as a thirteenth package. Nx 22 split the vitest executor out of @nx/vite, so core, domain, and tracker now use @nx/vitest:test.

@swc-node/register and @swc/core move up because Nx 22 peers them.

Angular stayed on 20.3.30

nx migrate wanted to pull Angular to 21, vitest to 4, and Analog to 2 alongside the Nx bump. @nx/angular@22 peers Angular at >= 19 < 22, so none of that is required.

I limited the run to the Nx packages and their migrations. That keeps this change to one major hop.

Issue #92 tracks the Angular 21 upgrade as a separate step.

Two migration outputs needed correcting

The codemod broke nx affected -t test. It dropped testTargetName from the @nx/vite/plugin block in nx.json. The plugin then inferred a plain test target on libs/data-transfer. That project has a vite config but no spec files, so the target failed with No test files found. pr.yml runs pnpm nx affected -t test, so this check would have gone red.

Both inferred targets now keep names other than test. @nx/vite/plugin keeps vite:test and @nx/vitest uses vitest:test. This matches the existing convention, where test is only ever declared explicitly in a project.json.

Nx 22 rejects {options.reportsDirectory} as a cache output. It resolves outside the workspace and fails the target. Coverage outputs move to a single {workspaceRoot}/coverage/{projectRoot} default in nx.json, rather than repeating in three project.json files.

Verification

All of these pass locally:

  • pnpm run lint and pnpm run format:check
  • pnpm run typecheck
  • pnpm run test — 1946 tests across five projects
  • pnpm run build and pnpm run docs:build
  • pnpm nx affected -t test --base=origin/develop and pnpm nx affected -t build --base=origin/develop, the two commands pr.yml runs
  • pnpm nx build cli --skip-nx-cache, the command .releaserc.json runs
  • node dist/apps/cli/main.cjs bundle --name tracker, the prebuild:tracker hook

One note for reviewers

Nx caches the project graph. Run pnpm nx reset before any nx show project, nx run-many, or nx affected command, or you will read a stale graph.

Alerts 263, 264, 282, and 283 should close once this merges.

🤖 Generated with Claude Code

https://claude.ai/code/session_01RifJr7xyhZkaTWn4ssV1b4

Clears two Dependabot advisories that no patch release could fix:
GHSA-vp3h-ghgh-jr7g (Zip-Slip in the self-hosted remote cache, fixed in
22.7.7) and GHSA-g2r8-wvmj-jf5w (permissive CORS on the `nx graph` dev
server, fixed in 22.7.2). Both are dev-tooling only and neither is
reachable in CI or in the published package.

All twelve Nx packages plus `nx` move to 22.7.9, the latest on the 22.x
line. `@nx/vitest` joins them: Nx 22 split the vitest executor out of
`@nx/vite`, so `core`, `domain`, and `tracker` now use `@nx/vitest:test`.

`nx migrate` wanted to pull Angular 20.3 to 21, vitest 3 to 4, and Analog
1 to 2 alongside it. `@nx/angular@22` peers Angular `>= 19 < 22`, so none
of that is required — the run was limited to the Nx packages and their
migrations. `@swc-node/register` and `@swc/core` move up because Nx 22
peers them.

Two migration outputs needed correcting:

- The codemod dropped `testTargetName` from the `@nx/vite/plugin` block,
  which let the plugin infer a plain `test` target on `data-transfer`.
  That project has a vite config but no spec files, so `nx run-many -t
  test` and the `nx affected -t test` in pr.yml failed on it. Both
  inferred targets now keep non-`test` names (`vite:test`, `vitest:test`),
  matching the convention that `test` is only ever declared explicitly.
- Nx 22 rejects `{options.reportsDirectory}` as a cache output because it
  resolves outside the workspace. Coverage outputs move to a single
  `{workspaceRoot}/coverage/{projectRoot}` default in nx.json rather than
  being repeated in three project.json files.

Verified: lint, format:check, typecheck, test (1946 tests across five
projects), build, docs:build, the `prebuild:tracker` CLI bundle step, and
the `nx affected -t test|build` and `--skip-nx-cache` paths that pr.yml,
release.yml, and .releaserc.json depend on.

Closes #82

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RifJr7xyhZkaTWn4ssV1b4
@simoncodes-ca
simoncodes-ca merged commit bebd580 into develop Sep 5, 2026
1 check passed
@simoncodes-ca
simoncodes-ca deleted the chore/upgrade-nx-22 branch September 5, 2026 06:11
@lingo-tracker-release

Copy link
Copy Markdown

🎉 This PR is included in version 0.18.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Upgrade Nx 21.5.3 → 22.7.7+ to clear two open Dependabot advisories

2 participants