Files
twenty/package.json
T
Charles Bochet e53f877559 security: clear picomatch High alert via @angular-devkit/core resolution (#21398)
## What

Clears the root `picomatch` High alert (GHSA-c2c7-rcm5-vvqj, range
`>=4.0.0 <4.0.4`).

`picomatch@4.0.2` is exact-pinned by `@angular-devkit/core@19.2.x`,
pulled by NestJS's codegen tooling (`@nestjs/schematics` + `@nestjs/cli`
use Angular's schematics engine). angular-devkit/core backported the
picomatch 4.0.4 fix in **19.2.24**.

## Why a resolution here (not a parent bump)

The clean parent-bump — bumping `@nestjs/cli` so it pulls patched
angular-devkit — **breaks `nest build`**. `@nestjs/cli` 11.0.17+ has an
SWC-builder output-path change: it writes compiled files under
`dist/`**`src/`**`…` instead of `dist/…`, breaking every `node
dist/<path>` reference (`main`, `command`, worker,
`database/scripts/*`). This is what failed in the first revision of this
PR (`Cannot find module '…/dist/database/scripts/truncate-db.js'`).

- The cli's angular-devkit pin is **exact**, so there's no clean
refresh.
- Every `@nestjs/cli` ≥11.0.17 (incl. the latest 11.0.23) has the
regression.
- There's no stable NestJS 12/13 to move to (12 is alpha-only).
- `tsconfig` `rootDir` doesn't override the output base.

So a one-patch resolution is genuinely the cleaner, lower-risk fix:

```jsonc
"@angular-devkit/core": "19.2.24"   // patch within the same 19.2 minor
```

`@nestjs/cli` stays 11.0.16 (correct `dist/` layout), and picomatch
resolves to 4.0.4.

## Verification
- picomatch now **4.0.4 + 2.3.2** (both patched); no 4.0.2 in the
lockfile
- `nx build twenty-server` emits `dist/main.js` and
`dist/database/scripts/*.js` at the correct paths (the prior CI failure)
- `yarn install --immutable` clean
2026-06-10 13:22:05 +02:00

85 lines
2.5 KiB
JSON

{
"private": true,
"devDependencies": {
"@nx/jest": "22.7.5",
"@nx/js": "22.7.5",
"@nx/react": "22.7.5",
"@nx/storybook": "22.7.5",
"@nx/vite": "22.7.5",
"@nx/web": "22.7.5",
"@types/react": "^18.2.39",
"@types/react-dom": "^18.2.15",
"@yarnpkg/types": "^4.0.0",
"concurrently": "^8.2.2",
"http-server": "^14.1.1",
"nx": "22.7.5",
"oxfmt": "0.50.0",
"tsx": "^4.17.0",
"verdaccio": "^6.3.1"
},
"engines": {
"node": "^24.5.0",
"npm": "please-use-yarn",
"yarn": ">=4.0.2"
},
"license": "AGPL-3.0",
"name": "twenty",
"packageManager": "yarn@4.13.0",
"resolutions": {
"graphql": "16.8.1",
"type-fest": "4.10.1",
"typescript": "5.9.3",
"nodemailer": "8.0.10",
"graphql-redis-subscriptions/ioredis": "^5.6.0",
"@lingui/core": "5.1.2",
"@types/qs": "6.9.16",
"@opentelemetry/api": "1.9.1",
"chokidar": "^3.6.0",
"tmp": "^0.2.7",
"node-gyp": "^12.4.0",
"cacache": "^20.0.0",
"make-fetch-happen": "^15.0.0",
"@electron/rebuild/tar": "npm:^7.5.16",
"@electron/node-gyp/tar": "npm:^7.5.16",
"pacote/tar": "npm:^7.5.16",
"@angular-devkit/core": "19.2.24"
},
"version": "0.2.1",
"nx": {},
"scripts": {
"docs:generate": "tsx packages/twenty-docs/scripts/generate-docs-json.ts",
"docs:generate-navigation-template": "tsx packages/twenty-docs/scripts/generate-navigation-template.ts",
"docs:generate-paths": "tsx packages/twenty-docs/scripts/generate-documentation-paths.ts",
"start": "npx concurrently --kill-others 'npx nx run-many -t start -p twenty-server twenty-front' 'npx wait-on tcp:3000 && npx nx run twenty-server:worker'"
},
"workspaces": {
"packages": [
"packages/twenty-front",
"packages/twenty-server",
"packages/twenty-emails",
"packages/twenty-ui",
"packages/twenty-ui-deprecated",
"packages/twenty-utils",
"packages/twenty-zapier",
"packages/twenty-website",
"packages/twenty-docs",
"packages/twenty-e2e-testing",
"packages/twenty-shared",
"packages/twenty-sdk",
"packages/twenty-front-component-renderer",
"packages/twenty-client-sdk",
"packages/twenty-cli",
"packages/create-twenty-app",
"packages/twenty-codex-plugin",
"packages/twenty-oxlint-rules",
"packages/twenty-companion",
"packages/twenty-claude-skills"
]
},
"prettier": {
"singleQuote": true,
"trailingComma": "all",
"endOfLine": "lf"
}
}