Skip to content

pnpm catalog pins vulnerable enquirer@~2.3.6 #36592

Description

@benknoble

Current Behavior

enquirer/enquirer#487 led to CVE-2026-15187, which doesn’t look likely to be fixed.

Although other comments point out it is unlikely to affect real usage, this shows up in enterprise scanners.

Expected Behavior

Dependency tree should be vulnerability free (or permit updating dependencies to pick up security updates; see also #36553

GitHub Repo

No response

Steps to Reproduce

Install nx and examine dependency tree.

Nx Report

n/a

Failure Logs

Package Manager Version

npm 11.13.0

Operating System

  • macOS
  • Linux
  • Windows
  • Other (Please specify)

Additional Information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions