renovate-bot opened a new pull request, #6908: URL: https://github.com/apache/texera/pull/6908
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [ajv](https://ajv.js.org) ([source](https://redirect.github.com/ajv-validator/ajv)) | [`8.10.0` → `8.18.0`](https://renovatebot.com/diffs/npm/ajv/8.10.0/8.18.0) |  |  | --- > [!WARNING] > Some dependencies could not be looked up. Check the Dependency Dashboard for more information. --- ### ajv has ReDoS when using `$data` option [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) / [GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) <details> <summary>More information</summary> #### Details ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the `$data` option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax (`$data` reference), which is passed directly to the JavaScript `RegExp()` constructor without validation. An attacker can inject a malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with `$data`: true for dynamic schema validation. #### Severity - CVSS Score: 5.5 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) - [https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md) - [https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) - [https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5) - [https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) - [https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588) - [https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0) - [https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) - [https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590) - [https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### ajv has ReDoS when using `$data` option [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) / [GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) <details> <summary>More information</summary> #### Details ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the `$data` option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax (`$data` reference), which is passed directly to the JavaScript `RegExp()` constructor without validation. An attacker can inject a malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with `$data`: true for dynamic schema validation. #### Severity - CVSS Score: 5.5 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) - [https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) - [https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588) - [https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590) - [https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991) - [https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5) - [https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md) - [https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) - [https://github.com/ajv-validator/ajv](https://redirect.github.com/ajv-validator/ajv) - [https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0) - [https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>ajv-validator/ajv (ajv)</summary> ### [`v8.18.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0) #### What's Changed - feat: allow tree-shaking by adding `"sideEffects": false` to `package.json` by [@​josdejong](https://redirect.github.com/josdejong) in [#​2480](https://redirect.github.com/ajv-validator/ajv/pull/2480) - fix: [#​2482](https://redirect.github.com/ajv-validator/ajv/issues/2482) Infinity and NaN serialise to null by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2487](https://redirect.github.com/ajv-validator/ajv/pull/2487) - fix: small grammatical error in managing-schemas.md by [@​monteiro-renato](https://redirect.github.com/monteiro-renato) in [#​2508](https://redirect.github.com/ajv-validator/ajv/pull/2508) - fix: typos in schema-language.md by [@​monteiro-renato](https://redirect.github.com/monteiro-renato) in [#​2507](https://redirect.github.com/ajv-validator/ajv/pull/2507) - fix(pattern): use configured RegExp engine with $data keyword to mitigate ReDoS attacks (CVE-2025-69873) by [@​epoberezkin](https://redirect.github.com/epoberezkin) in [#​2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) #### New Contributors - [@​josdejong](https://redirect.github.com/josdejong) made their first contribution in [#​2480](https://redirect.github.com/ajv-validator/ajv/pull/2480) - [@​monteiro-renato](https://redirect.github.com/monteiro-renato) made their first contribution in [#​2508](https://redirect.github.com/ajv-validator/ajv/pull/2508) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0> ### [`v8.17.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.17.1) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.16.0...v8.17.1) #### What's Changed - bump version to 8.17.1 by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2472](https://redirect.github.com/ajv-validator/ajv/pull/2472) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.17.0...v8.17.1> #### Plus everything in 8.17.0 which failed to release The only functional change is to switch from uri-js (which is no longer supported), to fast-uri. This is the second attempt and the team on fast-uri have been really helpful addressing the issues we found last time. Revert "Revert fast-uri change ([#​2444](https://redirect.github.com/ajv-validator/ajv/pull/2444))" by [@​gurgunday](https://redirect.github.com/gurgunday) in [#​2448](https://redirect.github.com/ajv-validator/ajv/pull/2448) fix: ignore new eslint error for [@​typescript-eslint/no-extraneous-class](https://redirect.github.com/typescript-eslint/no-extraneous-class) by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2455](https://redirect.github.com/ajv-validator/ajv/pull/2455) docs: clarify behaviour of addVocabulary by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2454](https://redirect.github.com/ajv-validator/ajv/pull/2454) docs: refactor to improve legibility by [@​blottn](https://redirect.github.com/blottn) in [#​2432](https://redirect.github.com/ajv-validator/ajv/pull/2432) Fix grammatical typo in managing-schemas.md by [@​wetneb](https://redirect.github.com/wetneb) in [#​2305](https://redirect.github.com/ajv-validator/ajv/pull/2305) docs: Fix broken strict-mode link by [@​alexanderjsx](https://redirect.github.com/alexanderjsx) in [#​2459](https://redirect.github.com/ajv-validator/ajv/pull/2459) feat: add test for encoded refs and bump fast-uri by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2449](https://redirect.github.com/ajv-validator/ajv/pull/2449) fix: changes for [@​typescript-eslint/array-type](https://redirect.github.com/typescript-eslint/array-type) rule by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2467](https://redirect.github.com/ajv-validator/ajv/pull/2467) fixes [#​2217](https://redirect.github.com/ajv-validator/ajv/issues/2217) - clarify custom keyword naming by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2457](https://redirect.github.com/ajv-validator/ajv/pull/2457) ### [`v8.16.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.16.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0) #### What's Changed - Revert fast-uri change by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2444](https://redirect.github.com/ajv-validator/ajv/pull/2444) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0> ### [`v8.15.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.15.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0) #### What's Changed - Replace `uri-js` with `fast-uri` by [@​vixalien](https://redirect.github.com/vixalien) in [#​2415](https://redirect.github.com/ajv-validator/ajv/pull/2415) - Bump to 8.15.0 by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2442](https://redirect.github.com/ajv-validator/ajv/pull/2442) #### New Contributors - [@​vixalien](https://redirect.github.com/vixalien) made their first contribution in [#​2415](https://redirect.github.com/ajv-validator/ajv/pull/2415) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0> ### [`v8.14.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.14.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0) #### What's Changed - readme: build badge by [@​epoberezkin](https://redirect.github.com/epoberezkin) in [#​2424](https://redirect.github.com/ajv-validator/ajv/pull/2424) - Update workflows by [@​rotu](https://redirect.github.com/rotu) in [#​2410](https://redirect.github.com/ajv-validator/ajv/pull/2410) - docs: add warning to maxLength / minLength by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2428](https://redirect.github.com/ajv-validator/ajv/pull/2428) - fix: broken link in docs warning by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2431](https://redirect.github.com/ajv-validator/ajv/pull/2431) - compileAsync a schema with discriminator and $ref, fixes [#​2427](https://redirect.github.com/ajv-validator/ajv/issues/2427) by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2433](https://redirect.github.com/ajv-validator/ajv/pull/2433) - bump version to 8.14.0 for publishing by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2440](https://redirect.github.com/ajv-validator/ajv/pull/2440) #### New Contributors - [@​rotu](https://redirect.github.com/rotu) made their first contribution in [#​2410](https://redirect.github.com/ajv-validator/ajv/pull/2410) **Full Changelog**: <https://github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0> ### [`v8.13.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.13.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.12.0...v8.13.0) - add named exports - update dependencies - update node.js ### [`v8.12.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.12.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.2...v8.12.0) - fix JTD serialisation (remove leading comma in objects with only optional properties) ([#​2190](https://redirect.github.com/ajv-validator/ajv/issues/2190), [@​piliugin-anton](https://redirect.github.com/piliugin-anton)) - empty JTD "values" schema ([#​2191](https://redirect.github.com/ajv-validator/ajv/issues/2191)) - empty object to work with JTD utility type ([#​2158](https://redirect.github.com/ajv-validator/ajv/issues/2158), [@​erikbrinkman](https://redirect.github.com/erikbrinkman)) - fix JTD "discriminator" schema for objects with more than 8 properties ([#​2194](https://redirect.github.com/ajv-validator/ajv/issues/2194)) - correctly narrow "number" type to "integer" ([#​2192](https://redirect.github.com/ajv-validator/ajv/issues/2192), [@​JacobLey](https://redirect.github.com/JacobLey)) - update Node.js versions in CI to 14, 16, 18 and 19 ### [`v8.11.2`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.2) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.1...v8.11.2) Update dependencies Export ValidationError and MissingRefError ([#​1840](https://redirect.github.com/ajv-validator/ajv/pull/1840), [@​dannyb648](https://redirect.github.com/dannyb648)) ### [`v8.11.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.1) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.0...v8.11.1) Update dependencies Export ValidationError and MissingRefError ([#​1840](https://redirect.github.com/ajv-validator/ajv/issues/1840), [@​dannyb648](https://redirect.github.com/dannyb648)) ### [`v8.11.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.10.0...v8.11.0) Use root schemaEnv when resolving references in oneOf ([#​1901](https://redirect.github.com/ajv-validator/ajv/issues/1901), [@​asprouse](https://redirect.github.com/asprouse)) Only use equal function in generated code when it is used ([#​1922](https://redirect.github.com/ajv-validator/ajv/issues/1922), [@​bhvngt](https://redirect.github.com/bhvngt)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Etc/UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/apache/texera). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZWxlYXNlL3YxLjIiLCJzZWN1cml0eSJdfQ==--> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
