renovate-bot opened a new pull request, #6908:
URL: https://github.com/apache/texera/pull/6908

   This PR contains the following updates:
   
   | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | 
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
   |---|---|---|---|
   | [ajv](https://ajv.js.org) 
([source](https://redirect.github.com/ajv-validator/ajv)) | [`8.10.0` → 
`8.18.0`](https://renovatebot.com/diffs/npm/ajv/8.10.0/8.18.0) | 
![age](https://developer.mend.io/api/mc/badges/age/npm/ajv/8.18.0?slim=true) | 
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/ajv/8.10.0/8.18.0?slim=true)
 |
   
   ---
   
   > [!WARNING]
   > Some dependencies could not be looked up. Check the Dependency Dashboard 
for more information.
   
   ---
   
   ### ajv has ReDoS when using `$data` option
   [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) / 
[GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to 
Regular Expression Denial of Service (ReDoS) when the `$data` option is 
enabled. The pattern keyword accepts runtime data via JSON Pointer syntax 
(`$data` reference), which is passed directly to the JavaScript `RegExp()` 
constructor without validation. An attacker can inject a malicious regex 
pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause 
catastrophic backtracking. A 31-character payload causes approximately 44 
seconds of CPU blocking, with each additional character doubling execution 
time. This enables complete denial of service with a single HTTP request 
against any API using ajv with `$data`: true for dynamic schema validation.
   
   #### Severity
   - CVSS Score: 5.5 / 10 (Medium)
   - Vector String: 
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P`
   
   #### References
   - 
[https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873)
   - 
[https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md)
   - 
[https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
   - 
[https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5)
   - 
[https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)
   - 
[https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588)
   - 
[https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0)
   - 
[https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
   - 
[https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590)
   - 
[https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991)
   
   This data is provided by the [GitHub Advisory 
Database](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) ([CC-BY 
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
   </details>
   
   ---
   
   ### ajv has ReDoS when using `$data` option
   [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) / 
[GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to 
Regular Expression Denial of Service (ReDoS) when the `$data` option is 
enabled. The pattern keyword accepts runtime data via JSON Pointer syntax 
(`$data` reference), which is passed directly to the JavaScript `RegExp()` 
constructor without validation. An attacker can inject a malicious regex 
pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause 
catastrophic backtracking. A 31-character payload causes approximately 44 
seconds of CPU blocking, with each additional character doubling execution 
time. This enables complete denial of service with a single HTTP request 
against any API using ajv with `$data`: true for dynamic schema validation.
   
   #### Severity
   - CVSS Score: 5.5 / 10 (Medium)
   - Vector String: 
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P`
   
   #### References
   - 
[https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873)
   - 
[https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
   - 
[https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588)
   - 
[https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590)
   - 
[https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991)
   - 
[https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5)
   - 
[https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md)
   - 
[https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
   - 
[https://github.com/ajv-validator/ajv](https://redirect.github.com/ajv-validator/ajv)
   - 
[https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0)
   - 
[https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)
   
   This data is provided by 
[OSV](https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6) and the [GitHub 
Advisory Database](https://redirect.github.com/github/advisory-database) 
([CC-BY 
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
   </details>
   
   ---
   
   ### Release Notes
   
   <details>
   <summary>ajv-validator/ajv (ajv)</summary>
   
   ### 
[`v8.18.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0)
   
   #### What's Changed
   
   - feat: allow tree-shaking by adding `"sideEffects": false` to 
`package.json` by [@&#8203;josdejong](https://redirect.github.com/josdejong) in 
[#&#8203;2480](https://redirect.github.com/ajv-validator/ajv/pull/2480)
   - fix: 
[#&#8203;2482](https://redirect.github.com/ajv-validator/ajv/issues/2482) 
Infinity and NaN serialise to null by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2487](https://redirect.github.com/ajv-validator/ajv/pull/2487)
   - fix: small grammatical error in managing-schemas.md by 
[@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato) in 
[#&#8203;2508](https://redirect.github.com/ajv-validator/ajv/pull/2508)
   - fix: typos in schema-language.md by 
[@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato) in 
[#&#8203;2507](https://redirect.github.com/ajv-validator/ajv/pull/2507)
   - fix(pattern): use configured RegExp engine with $data keyword to mitigate 
ReDoS attacks (CVE-2025-69873) by 
[@&#8203;epoberezkin](https://redirect.github.com/epoberezkin) in 
[#&#8203;2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
   
   #### New Contributors
   
   - [@&#8203;josdejong](https://redirect.github.com/josdejong) made their 
first contribution in 
[#&#8203;2480](https://redirect.github.com/ajv-validator/ajv/pull/2480)
   - [@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato) 
made their first contribution in 
[#&#8203;2508](https://redirect.github.com/ajv-validator/ajv/pull/2508)
   
   **Full Changelog**: 
<https://github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0>
   
   ### 
[`v8.17.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.17.1)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.16.0...v8.17.1)
   
   #### What's Changed
   
   - bump version to 8.17.1 by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2472](https://redirect.github.com/ajv-validator/ajv/pull/2472)
   
   **Full Changelog**: 
<https://github.com/ajv-validator/ajv/compare/v8.17.0...v8.17.1>
   
   #### Plus everything in 8.17.0 which failed to release
   
   The only functional change is to switch from uri-js (which is no longer 
supported), to fast-uri. This is the second attempt and the team on fast-uri 
have been really helpful addressing the issues we found last time.
   
   Revert "Revert fast-uri change 
([#&#8203;2444](https://redirect.github.com/ajv-validator/ajv/pull/2444))" by 
[@&#8203;gurgunday](https://redirect.github.com/gurgunday) in 
[#&#8203;2448](https://redirect.github.com/ajv-validator/ajv/pull/2448)
   fix: ignore new eslint error for 
[@&#8203;typescript-eslint/no-extraneous-class](https://redirect.github.com/typescript-eslint/no-extraneous-class)
 by [@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2455](https://redirect.github.com/ajv-validator/ajv/pull/2455)
   docs: clarify behaviour of addVocabulary by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2454](https://redirect.github.com/ajv-validator/ajv/pull/2454)
   docs: refactor to improve legibility by 
[@&#8203;blottn](https://redirect.github.com/blottn) in 
[#&#8203;2432](https://redirect.github.com/ajv-validator/ajv/pull/2432)
   Fix grammatical typo in managing-schemas.md by 
[@&#8203;wetneb](https://redirect.github.com/wetneb) in 
[#&#8203;2305](https://redirect.github.com/ajv-validator/ajv/pull/2305)
   docs: Fix broken strict-mode link by 
[@&#8203;alexanderjsx](https://redirect.github.com/alexanderjsx) in 
[#&#8203;2459](https://redirect.github.com/ajv-validator/ajv/pull/2459)
   feat: add test for encoded refs and bump fast-uri by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2449](https://redirect.github.com/ajv-validator/ajv/pull/2449)
   fix: changes for 
[@&#8203;typescript-eslint/array-type](https://redirect.github.com/typescript-eslint/array-type)
 rule by [@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2467](https://redirect.github.com/ajv-validator/ajv/pull/2467)
   fixes 
[#&#8203;2217](https://redirect.github.com/ajv-validator/ajv/issues/2217) - 
clarify custom keyword naming by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2457](https://redirect.github.com/ajv-validator/ajv/pull/2457)
   
   ### 
[`v8.16.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.16.0)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0)
   
   #### What's Changed
   
   - Revert fast-uri change by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2444](https://redirect.github.com/ajv-validator/ajv/pull/2444)
   
   **Full Changelog**: 
<https://github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0>
   
   ### 
[`v8.15.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.15.0)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0)
   
   #### What's Changed
   
   - Replace `uri-js` with `fast-uri` by 
[@&#8203;vixalien](https://redirect.github.com/vixalien) in 
[#&#8203;2415](https://redirect.github.com/ajv-validator/ajv/pull/2415)
   - Bump to 8.15.0 by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2442](https://redirect.github.com/ajv-validator/ajv/pull/2442)
   
   #### New Contributors
   
   - [@&#8203;vixalien](https://redirect.github.com/vixalien) made their first 
contribution in 
[#&#8203;2415](https://redirect.github.com/ajv-validator/ajv/pull/2415)
   
   **Full Changelog**: 
<https://github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0>
   
   ### 
[`v8.14.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.14.0)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0)
   
   #### What's Changed
   
   - readme: build badge by 
[@&#8203;epoberezkin](https://redirect.github.com/epoberezkin) in 
[#&#8203;2424](https://redirect.github.com/ajv-validator/ajv/pull/2424)
   - Update workflows by [@&#8203;rotu](https://redirect.github.com/rotu) in 
[#&#8203;2410](https://redirect.github.com/ajv-validator/ajv/pull/2410)
   - docs: add warning to maxLength / minLength by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2428](https://redirect.github.com/ajv-validator/ajv/pull/2428)
   - fix: broken link in docs warning by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2431](https://redirect.github.com/ajv-validator/ajv/pull/2431)
   - compileAsync a schema with discriminator and $ref, fixes 
[#&#8203;2427](https://redirect.github.com/ajv-validator/ajv/issues/2427)  by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2433](https://redirect.github.com/ajv-validator/ajv/pull/2433)
   - bump version to 8.14.0 for publishing by 
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in 
[#&#8203;2440](https://redirect.github.com/ajv-validator/ajv/pull/2440)
   
   #### New Contributors
   
   - [@&#8203;rotu](https://redirect.github.com/rotu) made their first 
contribution in 
[#&#8203;2410](https://redirect.github.com/ajv-validator/ajv/pull/2410)
   
   **Full Changelog**: 
<https://github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0>
   
   ### 
[`v8.13.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.13.0)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.12.0...v8.13.0)
   
   - add named exports
   - update dependencies
   - update node.js
   
   ### 
[`v8.12.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.12.0)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.2...v8.12.0)
   
   - fix JTD serialisation (remove leading comma in objects with only optional 
properties) 
([#&#8203;2190](https://redirect.github.com/ajv-validator/ajv/issues/2190), 
[@&#8203;piliugin-anton](https://redirect.github.com/piliugin-anton))
   - empty JTD "values" schema 
([#&#8203;2191](https://redirect.github.com/ajv-validator/ajv/issues/2191))
   - empty object to work with JTD utility type 
([#&#8203;2158](https://redirect.github.com/ajv-validator/ajv/issues/2158), 
[@&#8203;erikbrinkman](https://redirect.github.com/erikbrinkman))
   - fix JTD "discriminator" schema for objects with more than 8 properties 
([#&#8203;2194](https://redirect.github.com/ajv-validator/ajv/issues/2194))
   - correctly narrow "number" type to "integer" 
([#&#8203;2192](https://redirect.github.com/ajv-validator/ajv/issues/2192), 
[@&#8203;JacobLey](https://redirect.github.com/JacobLey))
   - update Node.js versions in CI to 14, 16, 18 and 19
   
   ### 
[`v8.11.2`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.2)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.1...v8.11.2)
   
   Update dependencies
   
   Export ValidationError and MissingRefError 
([#&#8203;1840](https://redirect.github.com/ajv-validator/ajv/pull/1840), 
[@&#8203;dannyb648](https://redirect.github.com/dannyb648))
   
   ### 
[`v8.11.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.1)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.0...v8.11.1)
   
   Update dependencies
   
   Export ValidationError and MissingRefError 
([#&#8203;1840](https://redirect.github.com/ajv-validator/ajv/issues/1840), 
[@&#8203;dannyb648](https://redirect.github.com/dannyb648))
   
   ### 
[`v8.11.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.0)
   
   [Compare 
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.10.0...v8.11.0)
   
   Use root schemaEnv when resolving references in oneOf 
([#&#8203;1901](https://redirect.github.com/ajv-validator/ajv/issues/1901), 
[@&#8203;asprouse](https://redirect.github.com/asprouse))
   
   Only use equal function in generated code when it is used 
([#&#8203;1922](https://redirect.github.com/ajv-validator/ajv/issues/1922), 
[@&#8203;bhvngt](https://redirect.github.com/bhvngt))
   
   </details>
   
   ---
   
   ### Configuration
   
   📅 **Schedule**: (in timezone Etc/UTC)
   
   - Branch creation
     - At any time (no schedule defined)
   - Automerge
     - At any time (no schedule defined)
   
   🚦 **Automerge**: Disabled by config. Please merge this manually once you are 
satisfied.
   
   ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry 
checkbox.
   
   🔕 **Ignore**: Close this PR and you won't be reminded about this update 
again.
   
   ---
   
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this 
box
   
   ---
   
   This PR was generated by [Mend Renovate](https://mend.io/renovate/). View 
the [repository job log](https://developer.mend.io/github/apache/texera).
   
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZWxlYXNlL3YxLjIiLCJzZWN1cml0eSJdfQ==-->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to