Dependency health Workspace

nxnpm

Documented supply-chain history

This package has dated incident reports relevant to its trust history. Check the affected releases and the response before drawing conclusions about its current version.

Read the incident coverage →

Supply-chain news and reputation

Dated reporting about this package. These events are separate from its current maintenance score.

· npm

Nx publishes its s1ngularity compromise post-mortem ↗

Nx described how a GitHub Actions injection exposed a publishing token and enabled malicious releases that collected sensitive files. Its response included trusted publishing and manual release approval.

Affected versions: See Nx’s linked advisory for the package-specific affected versions.

Packages: nx

Source: Nx maintainers

All supply-chain news →
What the project says about itself
  • Build provenance — the latest release, 23.2.0, carries a signed provenance attestation. Source: the registry.
  • Publishers on the registry — 8. Source: the registry.
  • Security policypublished. Source: the repository.
  • OpenSSF Scorecard7 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.

Third-party facts checked today; registry facts on every crawl.

State history 1
WhenChange
2026-09-05 first verdict: active
Supply-chain history 1
  1. account hijacked 2025-08 20.9.0–20.12.0, 21.5.0–21.8.0

    A pull-request title injection in a GitHub Actions workflow leaked a token that triggered the publish pipeline; the published nx and @nx/* versions ran a post-install script that used local AI CLIs to hunt for secrets and pushed them to public repositories.

    Removed after about four hours; npm revoked the tokens; Nx moved to trusted publishing with manual approval.

    Source: Nx post-mortem "s1ngularity", 5 September 2025. History, not a warning about today — the verdict above is about maintenance now.

Badge

maintenance: active

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/npm/nx.svg)](https://isitdeadyet.dev/npm/nx)

Watch it

Get told when nx changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.