Files
twenty/packages/twenty-sdk/package.json
T
Charles Bochet 37b986aa4b security: vendor @genql/cli codegen to drop undici/native-fetch (#21339)
## What

Vendors a narrowed copy of
[`@genql/cli@3.0.5`](https://github.com/remorses/genql) (MIT) into
`packages/twenty-client-sdk/src/generate/genql/` and repoints the two
client generators at it, then removes `@genql/cli` from
`twenty-client-sdk`, `twenty-sdk` and `create-twenty-app`.

## Why

`@genql/cli` was used **only** to generate the typed GraphQL client from
an SDL string. It is unmaintained and pulls in vulnerable/abandoned
transitives — `undici@5` (**30 Dependabot alerts**), `native-fetch`,
`listr`, `yargs`, etc. None of these were ever executed by Twenty: the
sole consumer of `undici`/`native-fetch` is `@genql/cli`'s live-endpoint
schema-introspection path, and Twenty always passes a schema string,
never an endpoint.

Removing the package eliminates the dependency at the source — for
Twenty and for scaffolded end-user apps.

## What changed vs upstream

The vendored copy (`genql/README.md` + `genql/LICENSE`) keeps the
`render/` and `runtime/` trees verbatim and narrows the orchestration:

- **Dropped the endpoint/introspection path** (`schema/fetchSchema.ts`)
— the only `undici`/`native-fetch`/`qs` consumer.
- **Dropped `listr`** — generation tasks run as plain sequential `async`
functions (file contents unchanged).
- **Replaced `fs-extra`/`mkdirp`/`rimraf`** with `node:fs`.
- **Runtime templates are imported as `?raw`** and bundled, instead of
read from `node_modules` at generation time.
- **Kept `prettier@^2.8` and `@graphql-tools/*`** so the generated
output is byte-for-byte identical.

## Verification

- **Byte-identical output**: regenerating the metadata client from its
committed schema produces a recursive-diff-clean result vs the previous
`@genql/cli` output (including the copied `runtime/` folder). The core
client generates and esbuild-bundles cleanly.
- The public `twenty-client-sdk/generate` barrel API is unchanged
(twenty-server / twenty-sdk consumers unaffected).
- `undici@^5`, `native-fetch`, `@genql/cli`, `listr`, `yargs@^15` and
`subscriptions-transport-ws@0.9` are gone from `yarn.lock` (net −364
lines).
- `twenty-client-sdk` and `twenty-sdk` typecheck, lint and build;
`twenty-client-sdk` tests pass (9/9).

## Notes

- The vendored folder is excluded from `oxlint`/`oxfmt` (it is
third-party code, with `@ts-nocheck` on the verbatim renderers,
mirroring the generated output).
- Stacks conceptually on #21334 (drops `@genql/runtime`); the two are
independent and only overlap trivially in `yarn.lock`. `@genql/runtime`
is intentionally left for that PR.
2026-06-08 20:46:45 +02:00

148 lines
3.8 KiB
JSON

{
"name": "twenty-sdk",
"version": "2.11.0",
"sideEffects": false,
"bin": {
"twenty": "dist/cli.cjs"
},
"files": [
"dist",
"README.md",
"CHANGELOG.md",
"package.json"
],
"scripts": {
"build": "npx rimraf dist && npx vite build"
},
"keywords": [
"twenty",
"cli",
"sdk",
"crm",
"application",
"development"
],
"exports": {
"./billing": {
"types": "./dist/billing/index.d.ts",
"import": "./dist/billing/index.mjs",
"require": "./dist/billing/index.cjs"
},
"./define": {
"types": "./dist/define/index.d.ts",
"import": "./dist/define/index.mjs",
"require": "./dist/define/index.cjs"
},
"./front-component": {
"types": "./dist/front-component/index.d.ts",
"import": "./dist/front-component/index.mjs",
"require": "./dist/front-component/index.cjs"
},
"./logic-function": {
"types": "./dist/logic-function/index.d.ts",
"import": "./dist/logic-function/index.mjs",
"require": "./dist/logic-function/index.cjs"
},
"./utils": {
"types": "./dist/utils/index.d.ts",
"import": "./dist/utils/index.mjs",
"require": "./dist/utils/index.cjs"
},
"./ui": {
"types": "./dist/ui/index.d.ts",
"import": "./dist/ui/index.mjs",
"require": "./dist/ui/index.cjs"
},
"./cli": {
"types": "./dist/cli/operations/index.d.ts",
"import": "./dist/operations.mjs",
"require": "./dist/operations.cjs"
},
"./front-component-renderer": {
"types": "./dist/front-component-renderer/index.d.ts",
"import": "./dist/front-component-renderer.mjs",
"require": "./dist/front-component-renderer.cjs"
},
"./front-component-renderer/build": {
"types": "./dist/front-component-renderer/build/index.d.ts",
"import": "./dist/front-component-renderer/build.mjs",
"require": "./dist/front-component-renderer/build.cjs"
}
},
"license": "AGPL-3.0",
"dependencies": {
"@sniptt/guards": "^0.2.0",
"axios": "^1.16.0",
"chalk": "^5.3.0",
"chokidar": "^4.0.0",
"commander": "^12.0.0",
"esbuild": "^0.25.0",
"graphql": "^16.8.1",
"graphql-sse": "^2.5.4",
"ink": "^6.8.0",
"inquirer": "^14.0.0",
"jsonc-parser": "^3.2.0",
"preact": "^10.28.3",
"react": "^19.0.0",
"react-dom": "^19.0.0",
"tinyglobby": "^0.2.15",
"twenty-client-sdk": "workspace:*",
"typescript": "^5.9.3",
"uuid": "^13.0.0"
},
"devDependencies": {
"@prettier/sync": "^0.5.2",
"@types/node": "^24.0.0",
"@types/react": "^19.0.0",
"@types/react-dom": "^19.0.0",
"@typescript/native-preview": "^7.0.0-dev.20260116.1",
"@vitest/coverage-v8": "^4.0.18",
"prettier": "^3.1.1",
"rollup-plugin-dts": "^6.4.1",
"ts-morph": "^25.0.0",
"tsc-alias": "^1.8.16",
"tsx": "^4.7.0",
"twenty-shared": "workspace:*",
"twenty-ui-deprecated": "workspace:*",
"vite": "^7.0.0",
"vite-plugin-dts": "^4.5.4",
"vite-tsconfig-paths": "^4.2.1",
"wait-on": "^7.2.0"
},
"engines": {
"node": "^24.5.0",
"yarn": "^4.0.2"
},
"typesVersions": {
"*": {
"billing": [
"dist/billing/index.d.ts"
],
"define": [
"dist/define/index.d.ts"
],
"front-component": [
"dist/front-component/index.d.ts"
],
"logic-function": [
"dist/logic-function/index.d.ts"
],
"utils": [
"dist/utils/index.d.ts"
],
"cli": [
"dist/cli/operations/index.d.ts"
],
"ui": [
"dist/ui/index.d.ts"
],
"front-component-renderer": [
"dist/front-component-renderer/index.d.ts"
],
"front-component-renderer/build": [
"dist/front-component-renderer/build/index.d.ts"
]
}
}
}