The GitHub Actions job "Release Auditing" on 
texera.git/backport/6908-update-dependency-ajv-to-v8-18-0-securit-v1.2 has 
succeeded.
Run started by GitHub user github-actions[bot] (triggered by aglinxinyuan).

Head commit for run:
12520a3f509b9570889623810a470d1b8fcbdd52 / Mend Renovate 
<[email protected]>
fix(deps, frontend): update dependency ajv to v8.18.0 [security] (#6908)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [ajv](https://ajv.js.org)
([source](https://redirect.github.com/ajv-validator/ajv)) | [`8.10.0` →
`8.18.0`](https://renovatebot.com/diffs/npm/ajv/8.10.0/8.18.0) |
![age](https://developer.mend.io/api/mc/badges/age/npm/ajv/8.18.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/ajv/8.10.0/8.18.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/6912) for more information.

---

### ajv has ReDoS when using `$data` option
[CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) /
[GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)

<details>
<summary>More information</summary>

#### Details
ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable
to Regular Expression Denial of Service (ReDoS) when the `$data` option
is enabled. The pattern keyword accepts runtime data via JSON Pointer
syntax (`$data` reference), which is passed directly to the JavaScript
`RegExp()` constructor without validation. An attacker can inject a
malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted
input to cause catastrophic backtracking. A 31-character payload causes
approximately 44 seconds of CPU blocking, with each additional character
doubling execution time. This enables complete denial of service with a
single HTTP request against any API using ajv with `$data`: true for
dynamic schema validation.

#### Severity
- CVSS Score: 5.5 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P`

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873)
-
[https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md)
-
[https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
-
[https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5)
-
[https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)
-
[https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588)
-
[https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0)
-
[https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
-
[https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590)
-
[https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### ajv has ReDoS when using `$data` option
[CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) /
[GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)

<details>
<summary>More information</summary>

#### Details
ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable
to Regular Expression Denial of Service (ReDoS) when the `$data` option
is enabled. The pattern keyword accepts runtime data via JSON Pointer
syntax (`$data` reference), which is passed directly to the JavaScript
`RegExp()` constructor without validation. An attacker can inject a
malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted
input to cause catastrophic backtracking. A 31-character payload causes
approximately 44 seconds of CPU blocking, with each additional character
doubling execution time. This enables complete denial of service with a
single HTTP request against any API using ajv with `$data`: true for
dynamic schema validation.

#### Severity
- CVSS Score: 5.5 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P`

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873)
-
[https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
-
[https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588)
-
[https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590)
-
[https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991)
-
[https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5)
-
[https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md)
-
[https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
-
[https://github.com/ajv-validator/ajv](https://redirect.github.com/ajv-validator/ajv)
-
[https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0)
-
[https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)

This data is provided by
[OSV](https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6) and the [GitHub
Advisory Database](https://redirect.github.com/github/advisory-database)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>ajv-validator/ajv (ajv)</summary>

###
[`v8.18.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0)

#### What's Changed

- feat: allow tree-shaking by adding `"sideEffects": false` to
`package.json` by
[@&#8203;josdejong](https://redirect.github.com/josdejong) in
[#&#8203;2480](https://redirect.github.com/ajv-validator/ajv/pull/2480)
- fix:
[#&#8203;2482](https://redirect.github.com/ajv-validator/ajv/issues/2482)
Infinity and NaN serialise to null by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2487](https://redirect.github.com/ajv-validator/ajv/pull/2487)
- fix: small grammatical error in managing-schemas.md by
[@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato)
in
[#&#8203;2508](https://redirect.github.com/ajv-validator/ajv/pull/2508)
- fix: typos in schema-language.md by
[@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato)
in
[#&#8203;2507](https://redirect.github.com/ajv-validator/ajv/pull/2507)
- fix(pattern): use configured RegExp engine with $data keyword to
mitigate ReDoS attacks (CVE-2025-69873) by
[@&#8203;epoberezkin](https://redirect.github.com/epoberezkin) in
[#&#8203;2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)

#### New Contributors

- [@&#8203;josdejong](https://redirect.github.com/josdejong) made their
first contribution in
[#&#8203;2480](https://redirect.github.com/ajv-validator/ajv/pull/2480)
- [@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato)
made their first contribution in
[#&#8203;2508](https://redirect.github.com/ajv-validator/ajv/pull/2508)

**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0>

###
[`v8.17.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.17.1)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.16.0...v8.17.1)

#### What's Changed

- bump version to 8.17.1 by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2472](https://redirect.github.com/ajv-validator/ajv/pull/2472)

**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.17.0...v8.17.1>

#### Plus everything in 8.17.0 which failed to release

The only functional change is to switch from uri-js (which is no longer
supported), to fast-uri. This is the second attempt and the team on
fast-uri have been really helpful addressing the issues we found last
time.

Revert "Revert fast-uri change
([#&#8203;2444](https://redirect.github.com/ajv-validator/ajv/pull/2444))"
by [@&#8203;gurgunday](https://redirect.github.com/gurgunday) in
[#&#8203;2448](https://redirect.github.com/ajv-validator/ajv/pull/2448)
fix: ignore new eslint error for
[@&#8203;typescript-eslint/no-extraneous-class](https://redirect.github.com/typescript-eslint/no-extraneous-class)
by [@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2455](https://redirect.github.com/ajv-validator/ajv/pull/2455)
docs: clarify behaviour of addVocabulary by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2454](https://redirect.github.com/ajv-validator/ajv/pull/2454)
docs: refactor to improve legibility by
[@&#8203;blottn](https://redirect.github.com/blottn) in
[#&#8203;2432](https://redirect.github.com/ajv-validator/ajv/pull/2432)
Fix grammatical typo in managing-schemas.md by
[@&#8203;wetneb](https://redirect.github.com/wetneb) in
[#&#8203;2305](https://redirect.github.com/ajv-validator/ajv/pull/2305)
docs: Fix broken strict-mode link by
[@&#8203;alexanderjsx](https://redirect.github.com/alexanderjsx) in
[#&#8203;2459](https://redirect.github.com/ajv-validator/ajv/pull/2459)
feat: add test for encoded refs and bump fast-uri by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2449](https://redirect.github.com/ajv-validator/ajv/pull/2449)
fix: changes for
[@&#8203;typescript-eslint/array-type](https://redirect.github.com/typescript-eslint/array-type)
rule by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2467](https://redirect.github.com/ajv-validator/ajv/pull/2467)
fixes
[#&#8203;2217](https://redirect.github.com/ajv-validator/ajv/issues/2217)
- clarify custom keyword naming by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2457](https://redirect.github.com/ajv-validator/ajv/pull/2457)

###
[`v8.16.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.16.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0)

#### What's Changed

- Revert fast-uri change by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2444](https://redirect.github.com/ajv-validator/ajv/pull/2444)

**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0>

###
[`v8.15.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.15.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0)

#### What's Changed

- Replace `uri-js` with `fast-uri` by
[@&#8203;vixalien](https://redirect.github.com/vixalien) in
[#&#8203;2415](https://redirect.github.com/ajv-validator/ajv/pull/2415)
- Bump to 8.15.0 by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2442](https://redirect.github.com/ajv-validator/ajv/pull/2442)

#### New Contributors

- [@&#8203;vixalien](https://redirect.github.com/vixalien) made their
first contribution in
[#&#8203;2415](https://redirect.github.com/ajv-validator/ajv/pull/2415)

**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0>

###
[`v8.14.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.14.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0)

#### What's Changed

- readme: build badge by
[@&#8203;epoberezkin](https://redirect.github.com/epoberezkin) in
[#&#8203;2424](https://redirect.github.com/ajv-validator/ajv/pull/2424)
- Update workflows by [@&#8203;rotu](https://redirect.github.com/rotu)
in
[#&#8203;2410](https://redirect.github.com/ajv-validator/ajv/pull/2410)
- docs: add warning to maxLength / minLength by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2428](https://redirect.github.com/ajv-validator/ajv/pull/2428)
- fix: broken link in docs warning by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2431](https://redirect.github.com/ajv-validator/ajv/pull/2431)
- compileAsync a schema with discriminator and $ref, fixes
[#&#8203;2427](https://redirect.github.com/ajv-validator/ajv/issues/2427)
by [@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2433](https://redirect.github.com/ajv-validator/ajv/pull/2433)
- bump version to 8.14.0 for publishing by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2440](https://redirect.github.com/ajv-validator/ajv/pull/2440)

#### New Contributors

- [@&#8203;rotu](https://redirect.github.com/rotu) made their first
contribution in
[#&#8203;2410](https://redirect.github.com/ajv-validator/ajv/pull/2410)

**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0>

###
[`v8.13.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.13.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.12.0...v8.13.0)

- add named exports
- update dependencies
- update node.js

###
[`v8.12.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.12.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.2...v8.12.0)

- fix JTD serialisation (remove leading comma in objects with only
optional properties)
([#&#8203;2190](https://redirect.github.com/ajv-validator/ajv/issues/2190),
[@&#8203;piliugin-anton](https://redirect.github.com/piliugin-anton))
- empty JTD "values" schema
([#&#8203;2191](https://redirect.github.com/ajv-validator/ajv/issues/2191))
- empty object to work with JTD utility type
([#&#8203;2158](https://redirect.github.com/ajv-validator/ajv/issues/2158),
[@&#8203;erikbrinkman](https://redirect.github.com/erikbrinkman))
- fix JTD "discriminator" schema for objects with more than 8 properties
([#&#8203;2194](https://redirect.github.com/ajv-validator/ajv/issues/2194))
- correctly narrow "number" type to "integer"
([#&#8203;2192](https://redirect.github.com/ajv-validator/ajv/issues/2192),
[@&#8203;JacobLey](https://redirect.github.com/JacobLey))
- update Node.js versions in CI to 14, 16, 18 and 19

###
[`v8.11.2`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.2)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.1...v8.11.2)

Update dependencies

Export ValidationError and MissingRefError
([#&#8203;1840](https://redirect.github.com/ajv-validator/ajv/pull/1840),
[@&#8203;dannyb648](https://redirect.github.com/dannyb648))

###
[`v8.11.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.1)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.0...v8.11.1)

Update dependencies

Export ValidationError and MissingRefError
([#&#8203;1840](https://redirect.github.com/ajv-validator/ajv/issues/1840),
[@&#8203;dannyb648](https://redirect.github.com/dannyb648))

###
[`v8.11.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.10.0...v8.11.0)

Use root schemaEnv when resolving references in oneOf
([#&#8203;1901](https://redirect.github.com/ajv-validator/ajv/issues/1901),
[@&#8203;asprouse](https://redirect.github.com/asprouse))

Only use equal function in generated code when it is used
([#&#8203;1922](https://redirect.github.com/ajv-validator/ajv/issues/1922),
[@&#8203;bhvngt](https://redirect.github.com/bhvngt))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Etc/UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/apache/texera).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZWxlYXNlL3YxLjIiLCJzZWN1cml0eSJdfQ==-->

---------

(backported from commit 469e8f031c9b95282ff2cab1388f6c95f4a0045d)

Co-authored-by: Xinyuan Lin <[email protected]>
Co-authored-by: Claude Fable 5 <[email protected]>

Report URL: https://github.com/apache/texera/actions/runs/30414395739

With regards,
GitHub Actions via GitBox

Reply via email to