Skip to content

chore: enable Nx Cloud Self-Healing CI - #24

Merged
ThePlenkov merged 11 commits into
wave-15-documentationfrom
nx-cloud/setup-self-healing-ci-1786388238228
Aug 11, 2026
Merged

ThePlenkov merged 11 commits into
wave-15-documentationfrom
nx-cloud/setup-self-healing-ci-1786388238228

Conversation

@nx-cloud

@nx-cloud nx-cloud Bot commented Aug 10, 2026

Copy link
Copy Markdown

🔧 Enable Nx Cloud Self-Healing CI

This PR creates a CI workflow with the nx-cloud fix-ci command included. When CI fails, Nx Cloud will automatically:

  1. Analyze the failure logs and codebase
  2. Generate a verified fix using AI
  3. Create a commit with the fix (if auto-apply is enabled) or suggest changes for review

Created Files

  • .github/workflows/ci.yml

What was added

A complete CI workflow file with the nx fix-ci step included. This workflow:

  • Runs on pushes to the main branch and on pull requests
  • Installs dependencies and runs nx affected -t lint test build
  • Includes a fix-ci step that runs when CI fails, using nx fix-ci
  • Analyzes failure logs and generates verified fixes using AI

Learn more


This PR was automatically generated by Nx Cloud

@codeant-ai

codeant-ai Bot commented Aug 10, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@nx-cloud

nx-cloud Bot commented Aug 10, 2026 •

Copy link
Copy Markdown
Author

View your CI Pipeline Execution ↗ for commit 64b452d

Command Status Duration Result
nx affected -t lint test ✅ Succeeded 1s View ↗
nx affected -t build ✅ Succeeded 1s View ↗

💡 Verify your cache is correct by running tasks in a sandbox. Read docs ↗


☁️ Nx Cloud last updated this comment at 2026-08-11 16:21:26 UTC

Base automatically changed from feat/nx-cloud/setup to wave-15-documentation August 10, 2026 18:58
@codacy-production

codacy-production Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The PR introduces the Nx Cloud Self-Healing CI workflow, but the implementation contains critical gaps that prevent the 'self-healing' functionality from operating as described. Specifically, the workflow lacks the necessary write permissions and environment variables required to commit and push automated fixes to the repository.

Codacy analysis indicates that the PR is not up to standards. While the workflow triggers are correctly configured, the analysis and fix steps require further refinement to ensure they only run on failures and have the necessary authorization to perform repository updates.

About this PR

  • The PR description indicates that the tool can 'Create a commit with the fix', but the workflow's permissions are currently set to 'contents: read'. This configuration is insufficient for the GitHub Action to push fixes back to the repository. To enable the 'auto-apply' feature, the contents permission must be elevated to 'write'.

Test suggestions

  • Workflow triggers correctly on push to main branch
  • Workflow triggers correctly on pull request events
  • Bun environment is initialized and dependencies are installed via frozen-lockfile
  • nx fix-ci executes following task failures to provide self-healing capabilities

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread .github/workflows/ci.yml Outdated
@ThePlenkov
ThePlenkov force-pushed the nx-cloud/setup-self-healing-ci-1786388238228 branch from b5a533e to 9edc4e2 Compare August 10, 2026 19:01
@ThePlenkov

Copy link
Copy Markdown
Contributor

Fixed in 8e7dc15 — changed contents: read → contents: write so nx fix-ci can push automated fixes. Codacy thread resolved.

ThePlenkov added a commit that referenced this pull request Aug 10, 2026
Cherry-picks the nx fix-ci step from PR #24 (Nx Cloud bot) into our
existing ci.yml instead of letting PR #24 overwrite the whole workflow.

- Adds `bunx nx fix-ci` with if: always() after the Test step
- continue-on-error: true so the gate stays green before the
  NX_CLOUD_ACCESS_TOKEN secret is configured
- Wires NX_CLOUD_ACCESS_TOKEN env var (secret to be set by human)

PR #24 can be closed; its only valuable contribution is this step.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@ThePlenkov

Copy link
Copy Markdown
Contributor

Closing this PR — we cherry-picked only the nx fix-ci self-healing step into our existing ci.yml (commit 24ebbeb on ci-cd-oxlint-biome-husky / PR #22) rather than letting this PR overwrite the whole workflow.

Our ci.yml retains: oxlint, biome, CodeQL with SARIF→annotations, SonarCloud, pinned SHAs, format check, typecheck, GitHub Actions cache — plus the new bunx nx fix-ci step (if: always(), continue-on-error: true until the NX_CLOUD_ACCESS_TOKEN secret is set).

Action needed: set the NX_CLOUD_ACCESS_TOKEN repo secret for fix-ci to actively self-heal.

@ThePlenkov ThePlenkov closed this Aug 10, 2026
@ThePlenkov ThePlenkov reopened this Aug 10, 2026
@ThePlenkov
ThePlenkov marked this pull request as draft August 10, 2026 19:45
@ThePlenkov
ThePlenkov marked this pull request as ready for review August 10, 2026 19:47

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Codacy analysis indicates the PR is up to standards, with no critical security flaws or major logic bugs identified. The integration of Nx Cloud Self-Healing CI is correctly structured, though the configuration includes an inefficient execution condition for the fix-ci step. Please note that the transition to the Bun runtime and the addition of Dependabot were not documented in the PR description and should be acknowledged to ensure team alignment.

About this PR

  • The inclusion of '.github/dependabot.yml' was not mentioned in the PR description. It is recommended to keep descriptions synchronized with the files introduced.
  • The PR introduces Bun as the package manager and runtime without explicit mention in the description. Ensure this change is intended and documented for the rest of the team.

Test suggestions

  • Workflow triggers on push to the main branch
  • Workflow triggers on pull request events
  • Execution of nx affected targets (lint, test, build)
  • Execution of nx fix-ci step upon build failure
  • Dependabot weekly updates for GitHub Actions and npm packages
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Workflow triggers on push to the main branch
2. Workflow triggers on pull request events
3. Execution of nx affected targets (lint, test, build)
4. Execution of nx fix-ci step upon build failure
5. Dependabot weekly updates for GitHub Actions and npm packages

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread .github/workflows/ci.yml
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Enable Nx Cloud Self-Healing CI workflow and add Dependabot updates

⚙️ Configuration changes ✨ Enhancement 🕐 10-20 Minutes

Grey Divider

AI Description

• Add GitHub Actions CI running Nx affected lint/test/build on pushes and PRs.
• Run nx fix-ci to let Nx Cloud analyze failures and propose/apply fixes.
• Add Dependabot configuration for weekly GitHub Actions and npm updates.
Diagram

graph TD
  A["GitHub Events"] --> B["CI workflow"] --> C["Checkout repo"] --> D["Setup Bun"] --> E["Install deps"] --> F["nx affected (lint/test/build)"] --> G["nx fix-ci (always)"] --> H{{"Nx Cloud"}}
  I["Dependabot"] --> J["Update PRs (actions/npm)"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Split self-healing into a separate job with scoped write permissions
  • ➕ Limits contents: write exposure to only the self-healing path
  • ➕ Clearer audit trail: normal CI remains read-only
  • ➕ Can be gated to run only when the main job fails
  • ➖ Slightly more complex workflow (needs/if conditions, passing context)
  • ➖ May require ensuring logs/artifacts are available to the fix job
2. Run `fix-ci` only on failure (instead of `always()`)
  • ➕ Avoids running the step on successful builds
  • ➕ Reduces CI time and Nx Cloud calls on green runs
  • ➖ May miss certain non-failure terminations (e.g., cancellations/timeouts) unless explicitly handled
  • ➖ Depends on desired Nx Cloud behavior/documentation for best gating condition
3. Adopt an official Nx/Nx Cloud reusable workflow (if available)
  • ➕ Less maintenance burden; upstream updates handle best practices
  • ➕ Often comes with recommended caching/permissions defaults
  • ➖ Less flexibility for repo-specific steps and policies
  • ➖ Couples CI behavior to external workflow changes

Recommendation: The current approach is a solid baseline (pinned actions, explicit permissions, and deterministic Nx invocation). If this repo is security-sensitive, consider isolating contents: write into a separate self-heal job that only runs when the main CI job fails, keeping the primary CI path read-only.

Files changed (2) +51 / -0

Other (2) +51 / -0
dependabot.ymlAdd Dependabot for weekly GitHub Actions and npm updates +21/-0

Add Dependabot for weekly GitHub Actions and npm updates

• Introduces Dependabot configuration to open weekly update PRs for GitHub Actions workflows and npm dependencies. Applies dependency-related labels and caps concurrent PRs per ecosystem.

.github/dependabot.yml

ci.ymlCreate CI workflow with Nx affected checks and Nx Cloud self-healing +30/-0

Create CI workflow with Nx affected checks and Nx Cloud self-healing

• Adds a GitHub Actions CI workflow for pushes to main and pull requests using Bun + Nx. Runs 'nx affected -t lint test build', then always runs 'nx fix-ci' to enable Nx Cloud self-healing; actions are pinned to commit SHAs and the workflow uses 'contents: write' to allow automated fix commits.

.github/workflows/ci.yml

@qodo-code-review

qodo-code-review Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (3) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Unpinned Bun version 🐞 Bug ☼ Reliability
Description
CI installs bun-version: latest even though the repo declares packageManager: bun@1.3.14, making
CI non-reproducible and prone to breaking when Bun releases a new version. This can cause CI to
behave differently from local development and from past CI runs.
Code

.github/workflows/ci.yml[R22-25]

+      - uses: oven-sh/setup-bun@f4d14e03ff726c06358e5557344e1da148b56cf7 # v1
+        with:
+          bun-version: latest
+      - run: bun install --frozen-lockfile --ignore-scripts
Evidence
The workflow explicitly installs Bun latest, while package.json pins Bun to 1.3.14, creating a
toolchain mismatch between CI and the repo’s declared package manager version.

.github/workflows/ci.yml[22-25]
package.json[5-7]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The workflow uses `bun-version: latest`, but the repository pins Bun via `packageManager`.

### Issue Context
Set `bun-version` to the same version as `package.json#packageManager` (currently `1.3.14`), or derive it in a single place so CI and developers stay aligned.

### Fix Focus Areas
- .github/workflows/ci.yml[22-25]
- package.json[5-7]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


2. Nx Cloud token not wired 🐞 Bug ☼ Reliability
Description
The workflow runs nx fix-ci but does not provide NX_CLOUD_ACCESS_TOKEN (and nx.json has an
empty nxCloudAccessToken), so Nx Cloud Self-Healing CI is not actually configured for CI
authentication. As a result, nx fix-ci cannot operate with the intended CI access model described
by Nx Cloud docs.
Code

.github/workflows/ci.yml[R28-30]

+      - run: bunx nx@21.0.0 affected -t lint test build
+      - run: bunx nx@21.0.0 fix-ci
+        if: always()
Evidence
nx fix-ci is invoked from CI, but there is no env: wiring for NX_CLOUD_ACCESS_TOKEN. The
repo’s nx.json shows nxCloudAccessToken as an empty string. Nx Cloud documentation says CI
access tokens should be configured via NX_CLOUD_ACCESS_TOKEN (or nxCloudAccessToken).

.github/workflows/ci.yml[28-30]
nx.json[51-53]
🌐 Docs say to configure a CI access token by setting the NX_CLOUD_ACCESS_TOKEN environment variable.
🌐 Docs state CI access tokens can be provided via NX_CLOUD_ACCESS_TOKEN/NX_CLOUD_AUTH_TOKEN or nxCloudAccessToken in nx.json.

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`nx fix-ci` is executed but the workflow does not set `NX_CLOUD_ACCESS_TOKEN`, and `nx.json` does not contain a token. Nx Cloud docs require a CI access token to be provided via environment variables (or in `nx.json`, though that should not be committed).

### Issue Context
Add a repo/org secret (e.g. `NX_CLOUD_ACCESS_TOKEN`) and map it into the job env. Consider separate read-only vs read-write tokens per branch protection model.

### Fix Focus Areas
- .github/workflows/ci.yml[13-30]
- nx.json[51-53]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Nx version mismatch in CI ✓ Resolved 🐞 Bug ☼ Reliability
Description
CI forces nx@21.0.0 via bunx, but the workspace lockfile resolves Nx 21.6.11, so CI is not
running the same Nx version the repo actually installs. This can yield inconsistent affected
selection and different fix-ci behavior versus local/dev and other CI contexts.
Code

.github/workflows/ci.yml[R28-29]

+      - run: bunx nx@21.0.0 affected -t lint test build
+      - run: bunx nx@21.0.0 fix-ci
Evidence
The workflow runs bunx nx@21.0.0 ..., while bun.lock pins Nx to 21.6.11 and package.json
uses a caret range. This means the CI command can diverge from the repo’s resolved Nx version.

.github/workflows/ci.yml[28-29]
package.json[14-18]
bun.lock[855-856]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The workflow pins Nx to `21.0.0` for execution, but the repo installs a different version.

### Issue Context
Prefer running the workspace-installed binary (e.g., `bunx nx affected ...` without a version specifier, or a `bun run` script), or pin the dependency and CI command to the same exact Nx version.

### Fix Focus Areas
- .github/workflows/ci.yml[28-29]
- package.json[14-18]
- bun.lock[855-856]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


View review recommended (1)
4. Overbroad token write access 🐞 Bug ⛨ Security
Description
The workflow grants contents: write at the workflow level for both push and pull_request,
allowing this job (and any action it runs) to push commits/tags or modify repo contents using
GITHUB_TOKEN. This is broader than required for the current steps (notably nx-set-shas) and
increases impact of any compromised CI step or dependency.
Code

.github/workflows/ci.yml[R9-12]

+permissions:
+  actions: read
+  contents: write
+
Evidence
ci.yml grants contents: write for the whole workflow. The nx-set-shas action documents that it
needs contents: read and actions: read. Nx Cloud’s GitHub integration explicitly uses `Contents:
Write` for “Creating commits and pushing fixes,” so granting it broadly enables repo mutation from
CI.

.github/workflows/ci.yml[9-12]
🌐 README shows recommended job permissions include contents: &#x27;read&#x27; and actions: &#x27;read&#x27; for nx-set-shas.
🌐 States Contents: Write is used for creating commits and pushing fixes for Self-Healing CI.

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The workflow sets `permissions: contents: write` globally, which enables repo writes from all runs. For the shown steps, `nx-set-shas` only requires read permissions.

### Issue Context
If Self-Healing CI will ever auto-commit fixes, keep write permissions but scope them (e.g., only on `push` to protected branches or in a dedicated job that runs conditionally).

### Fix Focus Areas
- .github/workflows/ci.yml[9-12]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context
✅ Web pages:
  +11 more
Review mode: ⚖️ Balanced: This adds runtime CI configuration with write permissions and an AI-driven self-healing command, creating meaningful workflow and security blast radius that warrants a careful single-pass review.

Grey Divider

Tip of the day
💡 Did you know, you can group findings by type and pick your Finding display, from Minimal to Full

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread .github/workflows/ci.yml
Comment thread .github/workflows/ci.yml Outdated
Comment thread .github/workflows/ci.yml
Comment thread .github/workflows/ci.yml Outdated
@ThePlenkov
ThePlenkov force-pushed the nx-cloud/setup-self-healing-ci-1786388238228 branch from ba33259 to 50f1abe Compare August 10, 2026 20:20
ThePlenkov added a commit that referenced this pull request Aug 10, 2026
Cherry-picks the nx fix-ci step from PR #24 (Nx Cloud bot) into our
existing ci.yml instead of letting PR #24 overwrite the whole workflow.

- Adds `bunx nx fix-ci` with if: always() after the Test step
- continue-on-error: true so the gate stays green before the
  NX_CLOUD_ACCESS_TOKEN secret is configured
- Wires NX_CLOUD_ACCESS_TOKEN env var (secret to be set by human)

PR #24 can be closed; its only valuable contribution is this step.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@ThePlenkov
ThePlenkov force-pushed the nx-cloud/setup-self-healing-ci-1786388238228 branch from 115cdb8 to f5210d2 Compare August 10, 2026 20:47
nx-cloud[bot]

This comment was marked as outdated.

@ThePlenkov
ThePlenkov force-pushed the nx-cloud/setup-self-healing-ci-1786388238228 branch from f5210d2 to 42e8a64 Compare August 10, 2026 20:53
nx-cloud[bot]

This comment was marked as outdated.

@ThePlenkov
ThePlenkov force-pushed the nx-cloud/setup-self-healing-ci-1786388238228 branch from 42e8a64 to 31941d9 Compare August 10, 2026 20:58
nx-cloud[bot]

This comment was marked as outdated.

@ThePlenkov
ThePlenkov force-pushed the nx-cloud/setup-self-healing-ci-1786388238228 branch from 6351b6c to acd6457 Compare August 11, 2026 14:34
nx-cloud[bot]

This comment was marked as outdated.

@ThePlenkov
ThePlenkov force-pushed the nx-cloud/setup-self-healing-ci-1786388238228 branch from acd6457 to e6ad624 Compare August 11, 2026 14:39
nx-cloud[bot]

This comment was marked as outdated.

nx-cloud[bot]

This comment was marked as outdated.

nx-cloud[bot]

This comment was marked as outdated.

@sonarqubecloud

Copy link
Copy Markdown

1 similar comment
@sonarqubecloud

Copy link
Copy Markdown

nx-cloud[bot]

This comment was marked as outdated.

nx-cloud[bot]

This comment was marked as outdated.

nx-cloud[bot]

This comment was marked as outdated.

nx-cloud[bot]

This comment was marked as outdated.

nx-cloud[bot]

This comment was marked as outdated.

nx-cloud[bot]

This comment was marked as outdated.

nx-cloud[bot]

This comment was marked as outdated.

@nx-cloud nx-cloud Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nx Cloud is proposing a fix for your failed CI:

We changed command: "node" to command: process.execPath in the SARIF extraction test to fix the sdk:test failure. The HostExecutor spawns child processes with an empty environment (no PATH), so the bare "node" command cannot be resolved when Node.js lives outside the default execvp search path (/bin:/usr/bin). Using the absolute path via process.execPath bypasses PATH lookup entirely and ensures the runtime is always found.

Note

⏳ We are verifying this fix by re-running sdk:test.

Suggested Fix changes
diff --git a/nx.json b/nx.json
index 1aca0a9..a5f0c11 100644
--- a/nx.json
+++ b/nx.json
@@ -1,10 +1,7 @@
 {
   "$schema": "./node_modules/nx/schemas/nx-schema.json",
   "namedInputs": {
-    "default": [
-      "{projectRoot}/**/*",
-      "sharedGlobals"
-    ],
+    "default": ["{projectRoot}/**/*", "sharedGlobals"],
     "production": [
       "default",
       "!{projectRoot}/**/__tests__/**/*",
@@ -14,47 +11,26 @@
   },
   "targetDefaults": {
     "build": {
-      "dependsOn": [
-        "^build"
-      ],
-      "inputs": [
-        "production",
-        "^production"
-      ],
-      "outputs": [
-        "{projectRoot}/dist"
-      ],
+      "dependsOn": ["^build"],
+      "inputs": ["production", "^production"],
+      "outputs": ["{projectRoot}/dist"],
       "cache": true
     },
     "test": {
-      "dependsOn": [
-        "build",
-        "^build"
-      ],
-      "inputs": [
-        "default",
-        "^production"
-      ],
+      "dependsOn": ["build", "^build"],
+      "inputs": ["default", "^production"],
       "cache": true
     },
     "lint": {
-      "inputs": [
-        "default",
-        "{workspaceRoot}/.eslintrc.json"
-      ],
+      "inputs": ["default", "{workspaceRoot}/.eslintrc.json"],
       "cache": true
     },
     "typecheck": {
-      "dependsOn": [
-        "^build"
-      ],
-      "inputs": [
-        "default",
-        "^production"
-      ],
+      "dependsOn": ["^build"],
+      "inputs": ["default", "^production"],
       "cache": true
     }
   },
   "nxCloudAccessToken": "",
   "nxCloudId": "6a7a1f08cff5d2abcf167263"
-}
\ No newline at end of file
+}
diff --git a/packages/sdk/src/__tests__/execute-mode.test.ts b/packages/sdk/src/__tests__/execute-mode.test.ts
index 7b669cd..c6fff37 100644
--- a/packages/sdk/src/__tests__/execute-mode.test.ts
+++ b/packages/sdk/src/__tests__/execute-mode.test.ts
@@ -1,7 +1,13 @@
 import { describe, it, expect, afterEach } from "vitest";
 import { execute, createSverka } from "../index.js";
 import type { CheckResolver } from "../index.js";
-import { makeTempGitRepo, makeTempGitRepoWithPackageJson, cleanupTempDir, writeSimpleConfig, writeFailingConfig } from "./helpers/fixtures.js";
+import {
+  makeTempGitRepo,
+  makeTempGitRepoWithPackageJson,
+  cleanupTempDir,
+  writeSimpleConfig,
+  writeFailingConfig,
+} from "./helpers/fixtures.js";
 
 describe("execute mode", { timeout: 30_000 }, () => {
   const dirs: string[] = [];
@@ -125,8 +131,11 @@ describe("execute mode", { timeout: 30_000 }, () => {
             kind: "check",
             name: check.checkId,
             description: check.reason,
-            command: "node",
-            args: ["-e", `require('fs').writeFileSync('findings.sarif', '${sarif}')`],
+            command: process.execPath,
+            args: [
+              "-e",
+              `require('fs').writeFileSync('findings.sarif', '${sarif}')`,
+            ],
           },
           outputs: [{ path: "findings.sarif", format: "sarif" }],
         };
@@ -158,8 +167,8 @@ describe("execute mode", { timeout: 30_000 }, () => {
         };
       },
     };
-    await expect(execute({ root: dir, executor: "docker", resolver: customResolver })).rejects.toThrow(
-      "docker executor requires container images",
-    );
+    await expect(
+      execute({ root: dir, executor: "docker", resolver: customResolver }),
+    ).rejects.toThrow("docker executor requires container images");
   });
 });

Apply fix via Nx Cloud  Reject fix via Nx Cloud


Or Apply changes locally with:

npx nx-cloud apply-locally R8EP-qh9V

Apply fix locally with your editor ↗   View interactive diff ↗



🎓 Learn more about Self-Healing CI on nx.dev

ThePlenkov and others added 10 commits August 11, 2026 16:16
This commit sets up Nx Cloud for your Nx workspace, enabling distributed caching and the Nx Cloud GitHub integration for fast CI and improved developer experience.

You can access your Nx Cloud workspace by going to
https://cloud.nx.app/orgs/6a7a1e77cff5d2abcf16725d/workspaces/6a7a1f08cff5d2abcf167263

> [!TIP]
> Run `npx nx generate ci-workflow` if you don't have a CI script configured yet.

**Note:** This commit attempts to maintain formatting of the nx.json file, however you may need to correct formatting by running an nx format command and committing the changes.
nx fix-ci needs write access to push automated fixes back to the
repository. Changed contents: read → contents: write per Codacy review.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Codacy and SonarCloud both flagged unpinned actions as security risk.
Pinned:
- actions/checkout@v4 → 11d5960a326750d5838078e36cf38b85af677262
- oven-sh/setup-bun@v1 → f4d14e03ff726c06358e5557344e1da148b56cf7
- nrwl/nx-set-shas@v4 → 3e9ad7370203c1e93d109be57f3b72eb0eb511b1

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- Add --ignore-scripts to bun install (S6505)
- Pin nx to 21.0.0 in bunx calls (S8543)
- Add dependabot.yml for github-actions + npm weekly updates

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
@sonarqubecloud

Copy link
Copy Markdown

❌ The last analysis has failed.

See analysis details on SonarQube Cloud

Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant