The GitHub Actions job "Release Auditing" on texera.git/backport/6908-update-dependency-ajv-to-v8-18-0-securit-v1.2 has succeeded. Run started by GitHub user github-actions[bot] (triggered by aglinxinyuan).
Head commit for run: 12520a3f509b9570889623810a470d1b8fcbdd52 / Mend Renovate <[email protected]> fix(deps, frontend): update dependency ajv to v8.18.0 [security] (#6908) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [ajv](https://ajv.js.org) ([source](https://redirect.github.com/ajv-validator/ajv)) | [`8.10.0` → `8.18.0`](https://renovatebot.com/diffs/npm/ajv/8.10.0/8.18.0) |  |  | --- > [!WARNING] > Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/6912) for more information. --- ### ajv has ReDoS when using `$data` option [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) / [GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) <details> <summary>More information</summary> #### Details ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the `$data` option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax (`$data` reference), which is passed directly to the JavaScript `RegExp()` constructor without validation. An attacker can inject a malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with `$data`: true for dynamic schema validation. #### Severity - CVSS Score: 5.5 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) - [https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md) - [https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) - [https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5) - [https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) - [https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588) - [https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0) - [https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) - [https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590) - [https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### ajv has ReDoS when using `$data` option [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) / [GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) <details> <summary>More information</summary> #### Details ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the `$data` option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax (`$data` reference), which is passed directly to the JavaScript `RegExp()` constructor without validation. An attacker can inject a malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with `$data`: true for dynamic schema validation. #### Severity - CVSS Score: 5.5 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) - [https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) - [https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588) - [https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590) - [https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991) - [https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5) - [https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md) - [https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) - [https://github.com/ajv-validator/ajv](https://redirect.github.com/ajv-validator/ajv) - [https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0) - [https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>ajv-validator/ajv (ajv)</summary> ### [`v8.18.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0) #### What's Changed - feat: allow tree-shaking by adding `"sideEffects": false` to `package.json` by [@​josdejong](https://redirect.github.com/josdejong) in [#​2480](https://redirect.github.com/ajv-validator/ajv/pull/2480) - fix: [#​2482](https://redirect.github.com/ajv-validator/ajv/issues/2482) Infinity and NaN serialise to null by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2487](https://redirect.github.com/ajv-validator/ajv/pull/2487) - fix: small grammatical error in managing-schemas.md by [@​monteiro-renato](https://redirect.github.com/monteiro-renato) in [#​2508](https://redirect.github.com/ajv-validator/ajv/pull/2508) - fix: typos in schema-language.md by [@​monteiro-renato](https://redirect.github.com/monteiro-renato) in [#​2507](https://redirect.github.com/ajv-validator/ajv/pull/2507) - fix(pattern): use configured RegExp engine with $data keyword to mitigate ReDoS attacks (CVE-2025-69873) by [@​epoberezkin](https://redirect.github.com/epoberezkin) in [#​2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) #### New Contributors - [@​josdejong](https://redirect.github.com/josdejong) made their first contribution in [#​2480](https://redirect.github.com/ajv-validator/ajv/pull/2480) - [@​monteiro-renato](https://redirect.github.com/monteiro-renato) made their first contribution in [#​2508](https://redirect.github.com/ajv-validator/ajv/pull/2508) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0> ### [`v8.17.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.17.1) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.16.0...v8.17.1) #### What's Changed - bump version to 8.17.1 by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2472](https://redirect.github.com/ajv-validator/ajv/pull/2472) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.17.0...v8.17.1> #### Plus everything in 8.17.0 which failed to release The only functional change is to switch from uri-js (which is no longer supported), to fast-uri. This is the second attempt and the team on fast-uri have been really helpful addressing the issues we found last time. Revert "Revert fast-uri change ([#​2444](https://redirect.github.com/ajv-validator/ajv/pull/2444))" by [@​gurgunday](https://redirect.github.com/gurgunday) in [#​2448](https://redirect.github.com/ajv-validator/ajv/pull/2448) fix: ignore new eslint error for [@​typescript-eslint/no-extraneous-class](https://redirect.github.com/typescript-eslint/no-extraneous-class) by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2455](https://redirect.github.com/ajv-validator/ajv/pull/2455) docs: clarify behaviour of addVocabulary by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2454](https://redirect.github.com/ajv-validator/ajv/pull/2454) docs: refactor to improve legibility by [@​blottn](https://redirect.github.com/blottn) in [#​2432](https://redirect.github.com/ajv-validator/ajv/pull/2432) Fix grammatical typo in managing-schemas.md by [@​wetneb](https://redirect.github.com/wetneb) in [#​2305](https://redirect.github.com/ajv-validator/ajv/pull/2305) docs: Fix broken strict-mode link by [@​alexanderjsx](https://redirect.github.com/alexanderjsx) in [#​2459](https://redirect.github.com/ajv-validator/ajv/pull/2459) feat: add test for encoded refs and bump fast-uri by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2449](https://redirect.github.com/ajv-validator/ajv/pull/2449) fix: changes for [@​typescript-eslint/array-type](https://redirect.github.com/typescript-eslint/array-type) rule by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2467](https://redirect.github.com/ajv-validator/ajv/pull/2467) fixes [#​2217](https://redirect.github.com/ajv-validator/ajv/issues/2217) - clarify custom keyword naming by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2457](https://redirect.github.com/ajv-validator/ajv/pull/2457) ### [`v8.16.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.16.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0) #### What's Changed - Revert fast-uri change by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2444](https://redirect.github.com/ajv-validator/ajv/pull/2444) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0> ### [`v8.15.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.15.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0) #### What's Changed - Replace `uri-js` with `fast-uri` by [@​vixalien](https://redirect.github.com/vixalien) in [#​2415](https://redirect.github.com/ajv-validator/ajv/pull/2415) - Bump to 8.15.0 by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2442](https://redirect.github.com/ajv-validator/ajv/pull/2442) #### New Contributors - [@​vixalien](https://redirect.github.com/vixalien) made their first contribution in [#​2415](https://redirect.github.com/ajv-validator/ajv/pull/2415) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0> ### [`v8.14.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.14.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0) #### What's Changed - readme: build badge by [@​epoberezkin](https://redirect.github.com/epoberezkin) in [#​2424](https://redirect.github.com/ajv-validator/ajv/pull/2424) - Update workflows by [@​rotu](https://redirect.github.com/rotu) in [#​2410](https://redirect.github.com/ajv-validator/ajv/pull/2410) - docs: add warning to maxLength / minLength by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2428](https://redirect.github.com/ajv-validator/ajv/pull/2428) - fix: broken link in docs warning by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2431](https://redirect.github.com/ajv-validator/ajv/pull/2431) - compileAsync a schema with discriminator and $ref, fixes [#​2427](https://redirect.github.com/ajv-validator/ajv/issues/2427) by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2433](https://redirect.github.com/ajv-validator/ajv/pull/2433) - bump version to 8.14.0 for publishing by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2440](https://redirect.github.com/ajv-validator/ajv/pull/2440) #### New Contributors - [@​rotu](https://redirect.github.com/rotu) made their first contribution in [#​2410](https://redirect.github.com/ajv-validator/ajv/pull/2410) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0> ### [`v8.13.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.13.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.12.0...v8.13.0) - add named exports - update dependencies - update node.js ### [`v8.12.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.12.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.2...v8.12.0) - fix JTD serialisation (remove leading comma in objects with only optional properties) ([#​2190](https://redirect.github.com/ajv-validator/ajv/issues/2190), [@​piliugin-anton](https://redirect.github.com/piliugin-anton)) - empty JTD "values" schema ([#​2191](https://redirect.github.com/ajv-validator/ajv/issues/2191)) - empty object to work with JTD utility type ([#​2158](https://redirect.github.com/ajv-validator/ajv/issues/2158), [@​erikbrinkman](https://redirect.github.com/erikbrinkman)) - fix JTD "discriminator" schema for objects with more than 8 properties ([#​2194](https://redirect.github.com/ajv-validator/ajv/issues/2194)) - correctly narrow "number" type to "integer" ([#​2192](https://redirect.github.com/ajv-validator/ajv/issues/2192), [@​JacobLey](https://redirect.github.com/JacobLey)) - update Node.js versions in CI to 14, 16, 18 and 19 ### [`v8.11.2`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.2) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.1...v8.11.2) Update dependencies Export ValidationError and MissingRefError ([#​1840](https://redirect.github.com/ajv-validator/ajv/pull/1840), [@​dannyb648](https://redirect.github.com/dannyb648)) ### [`v8.11.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.1) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.0...v8.11.1) Update dependencies Export ValidationError and MissingRefError ([#​1840](https://redirect.github.com/ajv-validator/ajv/issues/1840), [@​dannyb648](https://redirect.github.com/dannyb648)) ### [`v8.11.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.10.0...v8.11.0) Use root schemaEnv when resolving references in oneOf ([#​1901](https://redirect.github.com/ajv-validator/ajv/issues/1901), [@​asprouse](https://redirect.github.com/asprouse)) Only use equal function in generated code when it is used ([#​1922](https://redirect.github.com/ajv-validator/ajv/issues/1922), [@​bhvngt](https://redirect.github.com/bhvngt)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Etc/UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/apache/texera). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZWxlYXNlL3YxLjIiLCJzZWN1cml0eSJdfQ==--> --------- (backported from commit 469e8f031c9b95282ff2cab1388f6c95f4a0045d) Co-authored-by: Xinyuan Lin <[email protected]> Co-authored-by: Claude Fable 5 <[email protected]> Report URL: https://github.com/apache/texera/actions/runs/30414395739 With regards, GitHub Actions via GitBox
