This is an automated email from the ASF dual-hosted git repository.
github-merge-queue[bot] pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/texera.git
The following commit(s) were added to refs/heads/main by this push:
new 469e8f031c fix(deps, frontend): update dependency ajv to v8.18.0
[security] (#6908)
469e8f031c is described below
commit 469e8f031c9b95282ff2cab1388f6c95f4a0045d
Author: Mend Renovate <[email protected]>
AuthorDate: Wed Jul 29 02:19:40 2026 +0100
fix(deps, frontend): update dependency ajv to v8.18.0 [security] (#6908)
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [ajv](https://ajv.js.org)
([source](https://redirect.github.com/ajv-validator/ajv)) | [`8.10.0` →
`8.18.0`](https://renovatebot.com/diffs/npm/ajv/8.10.0/8.18.0) |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/6912) for more information.
---
### ajv has ReDoS when using `$data` option
[CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) /
[GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
<details>
<summary>More information</summary>
#### Details
ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable
to Regular Expression Denial of Service (ReDoS) when the `$data` option
is enabled. The pattern keyword accepts runtime data via JSON Pointer
syntax (`$data` reference), which is passed directly to the JavaScript
`RegExp()` constructor without validation. An attacker can inject a
malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted
input to cause catastrophic backtracking. A 31-character payload causes
approximately 44 seconds of CPU blocking, with each additional character
doubling execution time. This enables complete denial of service with a
single HTTP request against any API using ajv with `$data`: true for
dynamic schema validation.
#### Severity
- CVSS Score: 5.5 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P`
#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873)
-
[https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md)
-
[https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
-
[https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5)
-
[https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)
-
[https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588)
-
[https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0)
-
[https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
-
[https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590)
-
[https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991)
This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>
---
### ajv has ReDoS when using `$data` option
[CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) /
[GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
<details>
<summary>More information</summary>
#### Details
ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable
to Regular Expression Denial of Service (ReDoS) when the `$data` option
is enabled. The pattern keyword accepts runtime data via JSON Pointer
syntax (`$data` reference), which is passed directly to the JavaScript
`RegExp()` constructor without validation. An attacker can inject a
malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted
input to cause catastrophic backtracking. A 31-character payload causes
approximately 44 seconds of CPU blocking, with each additional character
doubling execution time. This enables complete denial of service with a
single HTTP request against any API using ajv with `$data`: true for
dynamic schema validation.
#### Severity
- CVSS Score: 5.5 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P`
#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873)
-
[https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
-
[https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588)
-
[https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590)
-
[https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991)
-
[https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5)
-
[https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md)
-
[https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
-
[https://github.com/ajv-validator/ajv](https://redirect.github.com/ajv-validator/ajv)
-
[https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0)
-
[https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)
This data is provided by
[OSV](https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6) and the [GitHub
Advisory Database](https://redirect.github.com/github/advisory-database)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>
---
### Release Notes
<details>
<summary>ajv-validator/ajv (ajv)</summary>
###
[`v8.18.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0)
#### What's Changed
- feat: allow tree-shaking by adding `"sideEffects": false` to
`package.json` by
[@​josdejong](https://redirect.github.com/josdejong) in
[#​2480](https://redirect.github.com/ajv-validator/ajv/pull/2480)
- fix:
[#​2482](https://redirect.github.com/ajv-validator/ajv/issues/2482)
Infinity and NaN serialise to null by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2487](https://redirect.github.com/ajv-validator/ajv/pull/2487)
- fix: small grammatical error in managing-schemas.md by
[@​monteiro-renato](https://redirect.github.com/monteiro-renato)
in
[#​2508](https://redirect.github.com/ajv-validator/ajv/pull/2508)
- fix: typos in schema-language.md by
[@​monteiro-renato](https://redirect.github.com/monteiro-renato)
in
[#​2507](https://redirect.github.com/ajv-validator/ajv/pull/2507)
- fix(pattern): use configured RegExp engine with $data keyword to
mitigate ReDoS attacks (CVE-2025-69873) by
[@​epoberezkin](https://redirect.github.com/epoberezkin) in
[#​2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
#### New Contributors
- [@​josdejong](https://redirect.github.com/josdejong) made their
first contribution in
[#​2480](https://redirect.github.com/ajv-validator/ajv/pull/2480)
- [@​monteiro-renato](https://redirect.github.com/monteiro-renato)
made their first contribution in
[#​2508](https://redirect.github.com/ajv-validator/ajv/pull/2508)
**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0>
###
[`v8.17.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.17.1)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.16.0...v8.17.1)
#### What's Changed
- bump version to 8.17.1 by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2472](https://redirect.github.com/ajv-validator/ajv/pull/2472)
**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.17.0...v8.17.1>
#### Plus everything in 8.17.0 which failed to release
The only functional change is to switch from uri-js (which is no longer
supported), to fast-uri. This is the second attempt and the team on
fast-uri have been really helpful addressing the issues we found last
time.
Revert "Revert fast-uri change
([#​2444](https://redirect.github.com/ajv-validator/ajv/pull/2444))"
by [@​gurgunday](https://redirect.github.com/gurgunday) in
[#​2448](https://redirect.github.com/ajv-validator/ajv/pull/2448)
fix: ignore new eslint error for
[@​typescript-eslint/no-extraneous-class](https://redirect.github.com/typescript-eslint/no-extraneous-class)
by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2455](https://redirect.github.com/ajv-validator/ajv/pull/2455)
docs: clarify behaviour of addVocabulary by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2454](https://redirect.github.com/ajv-validator/ajv/pull/2454)
docs: refactor to improve legibility by
[@​blottn](https://redirect.github.com/blottn) in
[#​2432](https://redirect.github.com/ajv-validator/ajv/pull/2432)
Fix grammatical typo in managing-schemas.md by
[@​wetneb](https://redirect.github.com/wetneb) in
[#​2305](https://redirect.github.com/ajv-validator/ajv/pull/2305)
docs: Fix broken strict-mode link by
[@​alexanderjsx](https://redirect.github.com/alexanderjsx) in
[#​2459](https://redirect.github.com/ajv-validator/ajv/pull/2459)
feat: add test for encoded refs and bump fast-uri by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2449](https://redirect.github.com/ajv-validator/ajv/pull/2449)
fix: changes for
[@​typescript-eslint/array-type](https://redirect.github.com/typescript-eslint/array-type)
rule by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2467](https://redirect.github.com/ajv-validator/ajv/pull/2467)
fixes
[#​2217](https://redirect.github.com/ajv-validator/ajv/issues/2217)
- clarify custom keyword naming by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2457](https://redirect.github.com/ajv-validator/ajv/pull/2457)
###
[`v8.16.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.16.0)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0)
#### What's Changed
- Revert fast-uri change by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2444](https://redirect.github.com/ajv-validator/ajv/pull/2444)
**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0>
###
[`v8.15.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.15.0)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0)
#### What's Changed
- Replace `uri-js` with `fast-uri` by
[@​vixalien](https://redirect.github.com/vixalien) in
[#​2415](https://redirect.github.com/ajv-validator/ajv/pull/2415)
- Bump to 8.15.0 by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2442](https://redirect.github.com/ajv-validator/ajv/pull/2442)
#### New Contributors
- [@​vixalien](https://redirect.github.com/vixalien) made their
first contribution in
[#​2415](https://redirect.github.com/ajv-validator/ajv/pull/2415)
**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0>
###
[`v8.14.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.14.0)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0)
#### What's Changed
- readme: build badge by
[@​epoberezkin](https://redirect.github.com/epoberezkin) in
[#​2424](https://redirect.github.com/ajv-validator/ajv/pull/2424)
- Update workflows by [@​rotu](https://redirect.github.com/rotu)
in
[#​2410](https://redirect.github.com/ajv-validator/ajv/pull/2410)
- docs: add warning to maxLength / minLength by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2428](https://redirect.github.com/ajv-validator/ajv/pull/2428)
- fix: broken link in docs warning by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2431](https://redirect.github.com/ajv-validator/ajv/pull/2431)
- compileAsync a schema with discriminator and $ref, fixes
[#​2427](https://redirect.github.com/ajv-validator/ajv/issues/2427)
by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2433](https://redirect.github.com/ajv-validator/ajv/pull/2433)
- bump version to 8.14.0 for publishing by
[@​jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#​2440](https://redirect.github.com/ajv-validator/ajv/pull/2440)
#### New Contributors
- [@​rotu](https://redirect.github.com/rotu) made their first
contribution in
[#​2410](https://redirect.github.com/ajv-validator/ajv/pull/2410)
**Full Changelog**:
<https://github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0>
###
[`v8.13.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.13.0)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.12.0...v8.13.0)
- add named exports
- update dependencies
- update node.js
###
[`v8.12.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.12.0)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.2...v8.12.0)
- fix JTD serialisation (remove leading comma in objects with only
optional properties)
([#​2190](https://redirect.github.com/ajv-validator/ajv/issues/2190),
[@​piliugin-anton](https://redirect.github.com/piliugin-anton))
- empty JTD "values" schema
([#​2191](https://redirect.github.com/ajv-validator/ajv/issues/2191))
- empty object to work with JTD utility type
([#​2158](https://redirect.github.com/ajv-validator/ajv/issues/2158),
[@​erikbrinkman](https://redirect.github.com/erikbrinkman))
- fix JTD "discriminator" schema for objects with more than 8 properties
([#​2194](https://redirect.github.com/ajv-validator/ajv/issues/2194))
- correctly narrow "number" type to "integer"
([#​2192](https://redirect.github.com/ajv-validator/ajv/issues/2192),
[@​JacobLey](https://redirect.github.com/JacobLey))
- update Node.js versions in CI to 14, 16, 18 and 19
###
[`v8.11.2`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.2)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.1...v8.11.2)
Update dependencies
Export ValidationError and MissingRefError
([#​1840](https://redirect.github.com/ajv-validator/ajv/pull/1840),
[@​dannyb648](https://redirect.github.com/dannyb648))
###
[`v8.11.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.1)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.0...v8.11.1)
Update dependencies
Export ValidationError and MissingRefError
([#​1840](https://redirect.github.com/ajv-validator/ajv/issues/1840),
[@​dannyb648](https://redirect.github.com/dannyb648))
###
[`v8.11.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.0)
[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.10.0...v8.11.0)
Use root schemaEnv when resolving references in oneOf
([#​1901](https://redirect.github.com/ajv-validator/ajv/issues/1901),
[@​asprouse](https://redirect.github.com/asprouse))
Only use equal function in generated code when it is used
([#​1922](https://redirect.github.com/ajv-validator/ajv/issues/1922),
[@​bhvngt](https://redirect.github.com/bhvngt))
</details>
---
### Configuration
📅 **Schedule**: (in timezone Etc/UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/apache/texera).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZWxlYXNlL3YxLjIiLCJzZWN1cml0eSJdfQ==-->
---------
Co-authored-by: Xinyuan Lin <[email protected]>
Co-authored-by: Claude Fable 5 <[email protected]>
---
frontend/LICENSE-binary | 10 ++--------
frontend/package.json | 2 +-
frontend/yarn.lock | 14 +-------------
3 files changed, 4 insertions(+), 22 deletions(-)
diff --git a/frontend/LICENSE-binary b/frontend/LICENSE-binary
index 19a514813a..bd8b12cb52 100644
--- a/frontend/LICENSE-binary
+++ b/frontend/LICENSE-binary
@@ -290,7 +290,7 @@ Angular / npm packages:
- @ngx-formly/[email protected]
- @ngx-formly/[email protected]
- @vscode/[email protected]
- - [email protected]
+ - [email protected]
- [email protected]
- [email protected]
- [email protected]
@@ -354,16 +354,10 @@ Dependencies under the BSD 3-Clause License
Angular / npm packages:
- [email protected]
+ - [email protected]
- [email protected]
- [email protected]
---------------------------------------------------------------------------------
-Dependencies under the BSD 2-Clause License
---------------------------------------------------------------------------------
-
-Angular / npm packages:
- - [email protected]
-
--------------------------------------------------------------------------------
Dependencies under the ISC License
--------------------------------------------------------------------------------
diff --git a/frontend/package.json b/frontend/package.json
index fd511f20f9..c964ed562f 100644
--- a/frontend/package.json
+++ b/frontend/package.json
@@ -40,7 +40,7 @@
"@ngx-formly/core": "7.1.0",
"@ngx-formly/ng-zorro-antd": "7.1.0",
"ai": "5.0.93",
- "ajv": "8.10.0",
+ "ajv": "8.18.0",
"concaveman": "2.0.0",
"d3-shape": "2.1.0",
"dagre": "0.8.5",
diff --git a/frontend/yarn.lock b/frontend/yarn.lock
index 5f0d316839..572ce399e0 100644
--- a/frontend/yarn.lock
+++ b/frontend/yarn.lock
@@ -7607,18 +7607,6 @@ __metadata:
languageName: node
linkType: hard
-"ajv@npm:8.10.0":
- version: 8.10.0
- resolution: "ajv@npm:8.10.0"
- dependencies:
- fast-deep-equal: "npm:^3.1.1"
- json-schema-traverse: "npm:^1.0.0"
- require-from-string: "npm:^2.0.2"
- uri-js: "npm:^4.2.2"
- checksum:
10c0/cc2c02a89289420ea96720f728d39d4d19dbcb2c1d0363481d0a9973282b69d94c8c1a02f4c424a89a1bd888e6049f87d0f82d21b5d056546cdbb364dd043f23
- languageName: node
- linkType: hard
-
"ajv@npm:8.18.0":
version: 8.18.0
resolution: "ajv@npm:8.18.0"
@@ -11006,7 +10994,7 @@ __metadata:
"@vitest/browser-playwright": "npm:4.1.10"
"@vitest/coverage-v8": "npm:4.1.10"
ai: "npm:5.0.93"
- ajv: "npm:8.10.0"
+ ajv: "npm:8.18.0"
buffer: "npm:5.7.1"
build-number-generator: "npm:3.1.0"
concaveman: "npm:2.0.0"