taTanStack
GitHubdevtoolsWorkspace
GitHub
  • CI Pipeline Executions
    • Current executionSucceeded
      fix/464-validate-install-package
    • Runs and Agents
    • TimelineBeta
    • Configuration
    • Self-Healing CI
    • Project Graph
    • Circular DependenciesEnterprise
    • Resource Usage
    • Analysis
    • ConformanceEnterprise
  • Runs
    • Current runSucceeded
    • Tasks
    • Resource Usage
Insights
  • Compare tasks
  • Analytics
    fix(devtools-bundler-core): validate package and import names from the event bus The install-devtools and bump-package-version events come from the unauthenticated event bus. installPackage put the package name into a shell string for exec(), so "x; touch /tmp/pwned; #" ran the second command. installPackage now accepts only an npm package name with an optional version and no leading "-". On macOS and Linux it runs the package manager with execFile and no shell. Windows still needs a shell for the .cmd shims, and the pattern allows no cmd.exe syntax. The plugin import name from the same events is written into the user's devtools file as code, so it must now be a JavaScript identifier. Refs #464
    nx affected --targets=test:eslint,test:sherif,test:knip,test:lib,test:types,test:build,build
Succeeded
Linux
4 CPU cores
read-write access token used
16334b5a545
30%

Cache hits

14 of 47 tasks used cache.

Get faster results

Learn how to enable distribution.

Atomizer enabled

27 groups of tasks optimized.

Resource usage reports are turned off for this workspace

Your organization has the Resource usage add-on, but this workspace does not collect metrics for non distributed runs. Turn it back on in workspace settings.

© 2026 - Nx Cloud

Terms of ServicePrivacy PolicyChangelogStatusDocsContact Nx CloudPricingCompany@NxDevTools
GitHubdevtoolsWorkspace