taTanStack
GitHubaiWorkspace
GitHub
  • CI Pipeline Executions
    • Current executionSucceeded
      feat/coverage-reporting
    • Runs and Agents
    • Configuration
    • Self-Healing CI
    • Project Graph
    • Resource Usage
    • Analysis
    • Conformance
  • Runs
    • Current runSucceeded
    • Tasks
    • Resource Usage
Insights
  • Compare tasks
  • Analytics
    fix(ci): pass the project list via env to satisfy zizmor zizmor flagged both `${{ steps.affected.outputs.list }}` uses inside run blocks as code injection via template expansion (pr.yml:69, pr.yml:85), and it's right: the list is built from package names in the PR's own files, so on a fork PR a package named with shell metacharacters would be interpolated straight into the script. Passing it through env keeps it out of the shell source entirely. Confirmed clean by running zizmor v1.28.0 locally over both workflows.
    nx affected --targets=test:sherif,test:knip,test:docs,test:kiira,test:maintainer,test:oxlint,test:lib,test:types,test:build,build
Succeeded
Linux
4 CPU cores
read-write access token used
002924a51036
95%

Cache hits

303 of 320 tasks used cache.

Get faster results

Learn how to enable distribution.

Atomizer enabled

77 groups of tasks optimized.

© 2026 - Nx Cloud

Terms of ServicePrivacy PolicyChangelogStatusDocsContact Nx CloudPricingCompany@NxDevTools