taTanStack
GitHubaiWorkspace
GitHub
  • CI Pipeline Executions
    • Current executionSucceededfeat/coverage-reporting
    • Configuration
    • Self-Healing CI
    • Project Graph
    • Resource Usage
    • Analysis
    • Conformance
  • Runs
    • Current runSucceeded
    • Tasks
    • Resource Usage
Insights
  • Compare tasks
  • Analytics
    fix(ci): pass the project list via env to satisfy zizmor zizmor flagged both `${{ steps.affected.outputs.list }}` uses inside run blocks as code injection via template expansion (pr.yml:69, pr.yml:85), and it's right: the list is built from package names in the PR's own files, so on a fork PR a package named with shell metacharacters would be interpolated straight into the script. Passing it through env keeps it out of the shell source entirely. Confirmed clean by running zizmor v1.28.0 locally over both workflows.
    nx run-many --targets=build --exclude=examples/**,testing/**
Succeeded
Linux
4 CPU cores
read-write access token used
7a72defc1036
100%

Cache hits

50 of 50 tasks used cache.

Get faster results

Learn how to enable distribution.

Atomizer enabled

50 groups of tasks optimized.

© 2026 - Nx Cloud

Terms of ServicePrivacy PolicyChangelogStatusDocsContact Nx CloudPricingCompany@NxDevTools