https://sonarly.com/issue/41619?type=bug Multiple runtime packages still resolve axios to vulnerable versions, leaving outbound HTTP paths exposed to recently disclosed high-severity axios CVEs. The issue is not a crash; it is a current security exposure in shipped dependency versions. Fix: Upgraded direct axios dependency declarations to the patched range (^1.16.1) in every affected runtime package identified by the RCA: - `packages/twenty-server/package.json` from `^1.13.5` → `^1.16.1` - `packages/twenty-sdk/package.json` from `^1.13.5` → `^1.16.1` - `packages/twenty-companion/package.json` from `^1.9.0` → `^1.16.1` - `packages/twenty-website/package.json` from `^1.14.0` → `^1.16.1` This removes the vulnerable declared version windows and aligns affected packages on the requested patched baseline. Authored by Sonarly by autonomous analysis (run 47476).
A CLI and SDK to develop, build, and publish applications that extend Twenty CRM.
Quick start
The recommended way to start is with create-twenty-app:
npx create-twenty-app@latest my-twenty-app
cd my-twenty-app
yarn twenty dev
Documentation
Full documentation is available at docs.twenty.com/developers/extend/apps:
- Getting Started — scaffolding, local server, authentication, dev mode
- Building Apps — entity definitions, API clients, testing, CLI reference
- Publishing — deploy, npm publish, marketplace
Manual installation
If you are adding twenty-sdk to an existing project instead of using create-twenty-app:
yarn add twenty-sdk twenty-client-sdk
Then add a twenty script to your package.json:
{
"scripts": {
"twenty": "twenty"
}
}
Run yarn twenty help to see all available commands.
Configuration
The CLI stores credentials per remote in ~/.twenty/config.json. Run yarn twenty remote:add to configure a remote, or yarn twenty remote:list to see existing ones.
Troubleshooting
- Auth errors: run
yarn twenty remote:addto re-authenticate. - Typings out of date: restart
yarn twenty devto refresh the client and types. - Not seeing changes in dev: make sure dev mode is running (
yarn twenty dev).
Contributing
Development setup
git clone https://github.com/twentyhq/twenty.git
cd twenty
yarn install
Development mode
npx nx run twenty-sdk:dev
Production build
npx nx run twenty-sdk:build
Running the CLI locally
npx nx run twenty-sdk:start -- <command>