Current Behavior
enquirer/enquirer#487 led to CVE-2026-15187, which doesn’t look likely to be fixed.
Although other comments point out it is unlikely to affect real usage, this shows up in enterprise scanners.
Expected Behavior
Dependency tree should be vulnerability free (or permit updating dependencies to pick up security updates; see also #36553
GitHub Repo
No response
Steps to Reproduce
Install nx and examine dependency tree.
Nx Report
Failure Logs
Package Manager Version
npm 11.13.0
Operating System
Additional Information
No response
Current Behavior
enquirer/enquirer#487 led to CVE-2026-15187, which doesn’t look likely to be fixed.
Although other comments point out it is unlikely to affect real usage, this shows up in enterprise scanners.
Expected Behavior
Dependency tree should be vulnerability free (or permit updating dependencies to pick up security updates; see also #36553
GitHub Repo
No response
Steps to Reproduce
Install nx and examine dependency tree.
Nx Report
Failure Logs
Package Manager Version
npm 11.13.0
Operating System
Additional Information
No response