Files
twenty/packages/twenty-sdk
sonarly-bot 475ffba2d7 fix: upgrade axios to 1.16.1 across affected packages
https://sonarly.com/issue/41619?type=bug

Multiple runtime packages still resolve axios to vulnerable versions, leaving outbound HTTP paths exposed to recently disclosed high-severity axios CVEs. The issue is not a crash; it is a current security exposure in shipped dependency versions.

Fix: Upgraded direct axios dependency declarations to the patched range (^1.16.1) in every affected runtime package identified by the RCA:

- `packages/twenty-server/package.json` from `^1.13.5` → `^1.16.1`
- `packages/twenty-sdk/package.json` from `^1.13.5` → `^1.16.1`
- `packages/twenty-companion/package.json` from `^1.9.0` → `^1.16.1`
- `packages/twenty-website/package.json` from `^1.14.0` → `^1.16.1`

This removes the vulnerable declared version windows and aligns affected packages on the requested patched baseline.

Authored by Sonarly by autonomous analysis (run 47476).
2026-05-30 06:54:45 +00:00
..
2026-03-09 15:32:13 +00:00
2026-05-20 15:12:39 +00:00

Twenty logo

Twenty SDK

NPM version License Join the community on Discord

A CLI and SDK to develop, build, and publish applications that extend Twenty CRM.

Quick start

The recommended way to start is with create-twenty-app:

npx create-twenty-app@latest my-twenty-app
cd my-twenty-app
yarn twenty dev

Documentation

Full documentation is available at docs.twenty.com/developers/extend/apps:

  • Getting Started — scaffolding, local server, authentication, dev mode
  • Building Apps — entity definitions, API clients, testing, CLI reference
  • Publishing — deploy, npm publish, marketplace

Manual installation

If you are adding twenty-sdk to an existing project instead of using create-twenty-app:

yarn add twenty-sdk twenty-client-sdk

Then add a twenty script to your package.json:

{
  "scripts": {
    "twenty": "twenty"
  }
}

Run yarn twenty help to see all available commands.

Configuration

The CLI stores credentials per remote in ~/.twenty/config.json. Run yarn twenty remote:add to configure a remote, or yarn twenty remote:list to see existing ones.

Troubleshooting

  • Auth errors: run yarn twenty remote:add to re-authenticate.
  • Typings out of date: restart yarn twenty dev to refresh the client and types.
  • Not seeing changes in dev: make sure dev mode is running (yarn twenty dev).

Contributing

Development setup

git clone https://github.com/twentyhq/twenty.git
cd twenty
yarn install

Development mode

npx nx run twenty-sdk:dev

Production build

npx nx run twenty-sdk:build

Running the CLI locally

npx nx run twenty-sdk:start -- <command>

Resources