Files
twenty/packages/twenty-sdk
Charles Bochet 6e30405489 Bump vulnerable dependencies flagged by ECR image scanning (#23813)
## Context

The Oneleet monitor **"AWS ECR repository image vulnerabilities are
remediated"** is alerting on `prod-twenty` images: 1 CRITICAL + 6 HIGH
advisories breach their SLA in 7 days, plus a set of MEDIUMs. All of
them are npm packages baked into the image.

## Changes

| Package | Before | After | How | Advisories |
|---|---|---|---|---|
| undici | 7.28.0 / 6.27.0 | 8.9.0 | jsdom `^30` bump + node-gyp
refresh; global `undici: ^8.9.0` resolution for
@module-federation/dts-plugin, e2b and miniflare, which still pin 7.28.0
at latest (replaces the old scoped dts-plugin resolution) |
CVE-2026-13697 (critical), CVE-2026-14643, CVE-2026-15157/16728/16729 |
| sharp | 0.34.5 | 0.35.3 | direct bump in twenty-sdk; @argos-ci
refresh; `next/sharp` resolution (next 16.3.0 with the fix is still
quarantined by yarn's minimal-age gate) | GHSA-f88m-g3jw-g9cj |
| axios | 1.17.0 | 1.19.0 | lockfile refresh | GHSA-gcfj-64vw-6mp9 + 10
medium |
| ip-address | 10.2.0 | 10.4.0 | lockfile refresh | CVE-2026-69192,
CVE-2026-54272, CVE-2026-69198 |
| brace-expansion | 2.1.2 | 2.1.4 | lockfile refresh (backport exists;
Inspector only lists 5.x) | CVE-2026-69152, CVE-2026-14257,
CVE-2026-13149 |
| typeorm | 0.3.29 | 0.3.31 | pin bump; the local yarn patch applies
unchanged | GHSA-2rp8-mm9q-fp49 |

## Validation

- `yarn.lock` contains no remaining vulnerable versions (undici resolves
only to 8.9.0)
- `yarn npm audit`: no remaining advisories among the bumped packages
- `nx build` green for twenty-server, twenty-front (exercises
module-federation dts-plugin on undici 8), twenty-sdk, twenty-website;
twenty-server typecheck green (typeorm patch is type-level)
- Runtime smoke: jsdom 30 DOM parse, sharp 0.35.3 png encode, undici
8.9.0 load

## Not covered

- **react-router / react-router-dom 6.30.4** (medium, 1–3 month SLA):
react-router-dom 6.x has **no fixed release**; the fix is the v7
migration (~225 files) — separate effort.
- `prod-business-dash` body-parser 2.2.2 → 2.3.0 lives in its own repo.

<!-- This is an auto-generated description by cubic. -->
<a
href="https://cubic.dev/pr/twentyhq/twenty/pull/23813?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>
<!-- End of auto-generated description by cubic. -->
2026-08-05 14:42:43 +00:00
..
2026-03-09 15:32:13 +00:00

Twenty logo

Twenty SDK

NPM version License Join the community on Discord

A CLI and SDK to develop, build, and publish applications that extend Twenty CRM.

Quick start

The recommended way to start is with create-twenty-app:

npx create-twenty-app@latest my-twenty-app
cd my-twenty-app
yarn twenty dev

Documentation

Full documentation is available at docs.twenty.com/developers/extend/apps:

  • Getting Started — scaffolding, local server, authentication, dev mode
  • Building Apps — entity definitions, API clients, testing, CLI reference
  • Publishing — deploy, npm publish, marketplace

Guides in this repository:

Manual installation

If you are adding twenty-sdk to an existing project instead of using create-twenty-app:

yarn add twenty-sdk twenty-client-sdk

Then add a twenty script to your package.json:

{
  "scripts": {
    "twenty": "twenty"
  }
}

Run yarn twenty help to see all available commands.

Configuration

The CLI stores credentials per remote in ~/.twenty/config.json. Run yarn twenty remote:add to configure a remote, or yarn twenty remote:list to see existing ones.

Troubleshooting

  • Auth errors: run yarn twenty remote:add to re-authenticate.
  • Typings out of date: restart yarn twenty dev to refresh the client and types.
  • Not seeing changes in dev: make sure dev mode is running (yarn twenty dev).

Contributing

Development setup

git clone https://github.com/twentyhq/twenty.git
cd twenty
yarn install

Development mode

npx nx run twenty-sdk:dev

Production build

npx nx run twenty-sdk:build

Running the CLI locally

npx nx run twenty-sdk:start -- <command>

Resources