Skip to content

fix(deps, frontend): update dependency ajv to v8.18.0 [security] - #6908

Merged
aglinxinyuan merged 4 commits into
apache:mainfrom
renovate-bot:renovate/npm-ajv-vulnerability
Jul 29, 2026
Merged

fix(deps, frontend): update dependency ajv to v8.18.0 [security]#6908
aglinxinyuan merged 4 commits into
apache:mainfrom
renovate-bot:renovate/npm-ajv-vulnerability

Conversation

@renovate-bot

@renovate-bot renovate-bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
ajv (source) 8.10.08.18.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


ajv has ReDoS when using $data option

CVE-2025-69873 / GHSA-2g4f-4pwh-qvx6

More information

Details

ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation.

Severity

  • CVSS Score: 5.5 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


ajv has ReDoS when using $data option

CVE-2025-69873 / GHSA-2g4f-4pwh-qvx6

More information

Details

ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation.

Severity

  • CVSS Score: 5.5 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

ajv-validator/ajv (ajv)

v8.18.0

Compare Source

What's Changed

New Contributors

Full Changelog: ajv-validator/ajv@v8.17.1...v8.18.0

v8.17.1

Compare Source

What's Changed

Full Changelog: ajv-validator/ajv@v8.17.0...v8.17.1

Plus everything in 8.17.0 which failed to release

The only functional change is to switch from uri-js (which is no longer supported), to fast-uri. This is the second attempt and the team on fast-uri have been really helpful addressing the issues we found last time.

Revert "Revert fast-uri change (#​2444)" by @​gurgunday in #​2448
fix: ignore new eslint error for @​typescript-eslint/no-extraneous-class by @​jasoniangreen in #​2455
docs: clarify behaviour of addVocabulary by @​jasoniangreen in #​2454
docs: refactor to improve legibility by @​blottn in #​2432
Fix grammatical typo in managing-schemas.md by @​wetneb in #​2305
docs: Fix broken strict-mode link by @​alexanderjsx in #​2459
feat: add test for encoded refs and bump fast-uri by @​jasoniangreen in #​2449
fix: changes for @​typescript-eslint/array-type rule by @​jasoniangreen in #​2467
fixes #​2217 - clarify custom keyword naming by @​jasoniangreen in #​2457

v8.16.0

Compare Source

What's Changed

Full Changelog: ajv-validator/ajv@v8.15.0...v8.16.0

v8.15.0

Compare Source

What's Changed

New Contributors

Full Changelog: ajv-validator/ajv@v8.14.0...v8.15.0

v8.14.0

Compare Source

What's Changed

New Contributors

Full Changelog: ajv-validator/ajv@v8.13.0...v8.14.0

v8.13.0

Compare Source

  • add named exports
  • update dependencies
  • update node.js

v8.12.0

Compare Source

v8.11.2

Compare Source

Update dependencies

Export ValidationError and MissingRefError (#​1840, @​dannyb648)

v8.11.1

Compare Source

Update dependencies

Export ValidationError and MissingRefError (#​1840, @​dannyb648)

v8.11.0

Compare Source

Use root schemaEnv when resolving references in oneOf (#​1901, @​asprouse)

Only use equal function in generated code when it is used (#​1922, @​bhvngt)


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate Bot added dependencies Pull requests that update a dependency file release/v1.2 back porting to release/v1.2 security labels Jul 26, 2026
@renovate-bot renovate-bot added dependencies Pull requests that update a dependency file release/v1.2 back porting to release/v1.2 security labels Jul 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

👋 Thanks for opening this pull request, @renovate-bot!

It looks like the pull request description doesn't quite follow our template yet:

  • The What changes were proposed in this PR? section is missing; please keep the template's headings.
  • The How was this PR tested? section is missing; please keep the template's headings.
  • The Was this PR authored or co-authored using generative AI tooling? section is missing; please keep the template's headings.

Filling out the template helps reviewers understand and triage your contribution faster. Please edit the description to complete it. This message will disappear automatically once the template is followed.

You can find the template prompts by editing the description, or see CONTRIBUTING.md for the full contribution flow.

@github-actions github-actions Bot added the frontend Changes related to the frontend GUI label Jul 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Automated Reviewer Suggestions

Based on the git blame history of the changed files, we recommend the following reviewers:

  • No candidates found from git blame history.

@codecov-commenter

codecov-commenter commented Jul 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.92%. Comparing base (ee41d9a) to head (123f6f8).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff              @@
##               main    #6908      +/-   ##
============================================
- Coverage     78.98%   77.92%   -1.07%     
+ Complexity     3786     3596     -190     
============================================
  Files          1160     1161       +1     
  Lines         46105    46046      -59     
  Branches       5115     5092      -23     
============================================
- Hits          36418    35881     -537     
- Misses         8067     8580     +513     
+ Partials       1620     1585      -35     
Flag Coverage Δ *Carryforward flag
access-control-service 70.00% <ø> (ø) Carriedforward from 1507bc0
agent-service 76.76% <ø> (ø) Carriedforward from 1507bc0
amber 70.08% <ø> (-2.13%) ⬇️ Carriedforward from 1507bc0
computing-unit-managing-service 20.49% <ø> (ø) Carriedforward from 1507bc0
config-service 66.66% <ø> (ø) Carriedforward from 1507bc0
file-service 67.21% <ø> (ø) Carriedforward from 1507bc0
frontend 82.99% <ø> (ø)
notebook-migration-service 78.94% <ø> (ø) Carriedforward from 1507bc0
pyamber 92.41% <ø> (-2.98%) ⬇️ Carriedforward from 1507bc0
workflow-compiling-service 54.81% <ø> (+28.49%) ⬆️ Carriedforward from 1507bc0

*This pull request uses carry forward flags. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@Yicong-Huang Yicong-Huang removed the release/v1.2 back porting to release/v1.2 label Jul 27, 2026
@aglinxinyuan
aglinxinyuan enabled auto-merge July 27, 2026 20:30
@aglinxinyuan
aglinxinyuan disabled auto-merge July 27, 2026 20:30
ajv 8.18.0 replaced uri-js with fast-uri, so the bundled deps changed:
- ajv 8.10.0 -> 8.18.0
- add fast-uri@3.1.4 (BSD-3-Clause)
- drop uri-js@4.4.1 (no longer bundled; BSD-2-Clause section now empty)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@forking-renovate

Copy link
Copy Markdown

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@aglinxinyuan
aglinxinyuan enabled auto-merge July 27, 2026 23:46
@aglinxinyuan
aglinxinyuan added this pull request to the merge queue Jul 27, 2026
@Yicong-Huang
Yicong-Huang removed this pull request from the merge queue due to a manual request Jul 28, 2026
@Yicong-Huang

Copy link
Copy Markdown
Contributor

we need to backport. let's wait for a CI fix of backport

@xuang7 xuang7 added the release/v1.2 back porting to release/v1.2 label Jul 28, 2026
@aglinxinyuan
aglinxinyuan added this pull request to the merge queue Jul 29, 2026
Merged via the queue into apache:main with commit 469e8f0 Jul 29, 2026
41 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Backport PR opened: draft #6984 (#6984) to release/v1.2, assigned to @renovate-bot — needs manual work because the cherry-pick conflicts.

Yicong-Huang added a commit that referenced this pull request Jul 29, 2026
Keep release/v1.2 versions (@vscode/iconv-lite-umd@0.7.0, quill@1.3.7)
and apply only the #6908 intent: bump ajv to 8.18.0 and add its new
fast-uri@3.1.4 dependency. Does not pull in main-only entries
(parchment@3.0.0, quill@2.0.3).
Yicong-Huang pushed a commit that referenced this pull request Jul 29, 2026
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [ajv](https://ajv.js.org)
([source](https://redirect.github.com/ajv-validator/ajv)) | [`8.10.0` →
`8.18.0`](https://renovatebot.com/diffs/npm/ajv/8.10.0/8.18.0) |
![age](https://developer.mend.io/api/mc/badges/age/npm/ajv/8.18.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/ajv/8.10.0/8.18.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/6912) for more information.

---

### ajv has ReDoS when using `$data` option
[CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) /
[GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)

<details>
<summary>More information</summary>

#### Details
ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable
to Regular Expression Denial of Service (ReDoS) when the `$data` option
is enabled. The pattern keyword accepts runtime data via JSON Pointer
syntax (`$data` reference), which is passed directly to the JavaScript
`RegExp()` constructor without validation. An attacker can inject a
malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted
input to cause catastrophic backtracking. A 31-character payload causes
approximately 44 seconds of CPU blocking, with each additional character
doubling execution time. This enables complete denial of service with a
single HTTP request against any API using ajv with `$data`: true for
dynamic schema validation.

#### Severity
- CVSS Score: 5.5 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P`

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873)
-
[https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md)
-
[https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
-
[https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5)
-
[https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)
-
[https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588)
-
[https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0)
-
[https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
-
[https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590)
-
[https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### ajv has ReDoS when using `$data` option
[CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) /
[GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)

<details>
<summary>More information</summary>

#### Details
ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable
to Regular Expression Denial of Service (ReDoS) when the `$data` option
is enabled. The pattern keyword accepts runtime data via JSON Pointer
syntax (`$data` reference), which is passed directly to the JavaScript
`RegExp()` constructor without validation. An attacker can inject a
malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted
input to cause catastrophic backtracking. A 31-character payload causes
approximately 44 seconds of CPU blocking, with each additional character
doubling execution time. This enables complete denial of service with a
single HTTP request against any API using ajv with `$data`: true for
dynamic schema validation.

#### Severity
- CVSS Score: 5.5 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P`

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873)
-
[https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)
-
[https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588)
-
[https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590)
-
[https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991)
-
[https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5)
-
[https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md)
-
[https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6)
-
[https://github.com/ajv-validator/ajv](https://redirect.github.com/ajv-validator/ajv)
-
[https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0)
-
[https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)

This data is provided by
[OSV](https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6) and the [GitHub
Advisory Database](https://redirect.github.com/github/advisory-database)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>ajv-validator/ajv (ajv)</summary>

###
[`v8.18.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0)

#### What's Changed

- feat: allow tree-shaking by adding `"sideEffects": false` to
`package.json` by
[@&#8203;josdejong](https://redirect.github.com/josdejong) in
[#&#8203;2480](https://redirect.github.com/ajv-validator/ajv/pull/2480)
- fix:
[#&#8203;2482](https://redirect.github.com/ajv-validator/ajv/issues/2482)
Infinity and NaN serialise to null by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2487](https://redirect.github.com/ajv-validator/ajv/pull/2487)
- fix: small grammatical error in managing-schemas.md by
[@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato)
in
[#&#8203;2508](https://redirect.github.com/ajv-validator/ajv/pull/2508)
- fix: typos in schema-language.md by
[@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato)
in
[#&#8203;2507](https://redirect.github.com/ajv-validator/ajv/pull/2507)
- fix(pattern): use configured RegExp engine with $data keyword to
mitigate ReDoS attacks (CVE-2025-69873) by
[@&#8203;epoberezkin](https://redirect.github.com/epoberezkin) in
[#&#8203;2586](https://redirect.github.com/ajv-validator/ajv/pull/2586)

#### New Contributors

- [@&#8203;josdejong](https://redirect.github.com/josdejong) made their
first contribution in
[#&#8203;2480](https://redirect.github.com/ajv-validator/ajv/pull/2480)
- [@&#8203;monteiro-renato](https://redirect.github.com/monteiro-renato)
made their first contribution in
[#&#8203;2508](https://redirect.github.com/ajv-validator/ajv/pull/2508)

**Full Changelog**:
<ajv-validator/ajv@v8.17.1...v8.18.0>

###
[`v8.17.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.17.1)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.16.0...v8.17.1)

#### What's Changed

- bump version to 8.17.1 by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2472](https://redirect.github.com/ajv-validator/ajv/pull/2472)

**Full Changelog**:
<ajv-validator/ajv@v8.17.0...v8.17.1>

#### Plus everything in 8.17.0 which failed to release

The only functional change is to switch from uri-js (which is no longer
supported), to fast-uri. This is the second attempt and the team on
fast-uri have been really helpful addressing the issues we found last
time.

Revert "Revert fast-uri change
([#&#8203;2444](https://redirect.github.com/ajv-validator/ajv/pull/2444))"
by [@&#8203;gurgunday](https://redirect.github.com/gurgunday) in
[#&#8203;2448](https://redirect.github.com/ajv-validator/ajv/pull/2448)
fix: ignore new eslint error for
[@&#8203;typescript-eslint/no-extraneous-class](https://redirect.github.com/typescript-eslint/no-extraneous-class)
by [@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2455](https://redirect.github.com/ajv-validator/ajv/pull/2455)
docs: clarify behaviour of addVocabulary by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2454](https://redirect.github.com/ajv-validator/ajv/pull/2454)
docs: refactor to improve legibility by
[@&#8203;blottn](https://redirect.github.com/blottn) in
[#&#8203;2432](https://redirect.github.com/ajv-validator/ajv/pull/2432)
Fix grammatical typo in managing-schemas.md by
[@&#8203;wetneb](https://redirect.github.com/wetneb) in
[#&#8203;2305](https://redirect.github.com/ajv-validator/ajv/pull/2305)
docs: Fix broken strict-mode link by
[@&#8203;alexanderjsx](https://redirect.github.com/alexanderjsx) in
[#&#8203;2459](https://redirect.github.com/ajv-validator/ajv/pull/2459)
feat: add test for encoded refs and bump fast-uri by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2449](https://redirect.github.com/ajv-validator/ajv/pull/2449)
fix: changes for
[@&#8203;typescript-eslint/array-type](https://redirect.github.com/typescript-eslint/array-type)
rule by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2467](https://redirect.github.com/ajv-validator/ajv/pull/2467)
fixes
[#&#8203;2217](https://redirect.github.com/ajv-validator/ajv/issues/2217)
- clarify custom keyword naming by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2457](https://redirect.github.com/ajv-validator/ajv/pull/2457)

###
[`v8.16.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.16.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0)

#### What's Changed

- Revert fast-uri change by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2444](https://redirect.github.com/ajv-validator/ajv/pull/2444)

**Full Changelog**:
<ajv-validator/ajv@v8.15.0...v8.16.0>

###
[`v8.15.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.15.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0)

#### What's Changed

- Replace `uri-js` with `fast-uri` by
[@&#8203;vixalien](https://redirect.github.com/vixalien) in
[#&#8203;2415](https://redirect.github.com/ajv-validator/ajv/pull/2415)
- Bump to 8.15.0 by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2442](https://redirect.github.com/ajv-validator/ajv/pull/2442)

#### New Contributors

- [@&#8203;vixalien](https://redirect.github.com/vixalien) made their
first contribution in
[#&#8203;2415](https://redirect.github.com/ajv-validator/ajv/pull/2415)

**Full Changelog**:
<ajv-validator/ajv@v8.14.0...v8.15.0>

###
[`v8.14.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.14.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0)

#### What's Changed

- readme: build badge by
[@&#8203;epoberezkin](https://redirect.github.com/epoberezkin) in
[#&#8203;2424](https://redirect.github.com/ajv-validator/ajv/pull/2424)
- Update workflows by [@&#8203;rotu](https://redirect.github.com/rotu)
in
[#&#8203;2410](https://redirect.github.com/ajv-validator/ajv/pull/2410)
- docs: add warning to maxLength / minLength by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2428](https://redirect.github.com/ajv-validator/ajv/pull/2428)
- fix: broken link in docs warning by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2431](https://redirect.github.com/ajv-validator/ajv/pull/2431)
- compileAsync a schema with discriminator and $ref, fixes
[#&#8203;2427](https://redirect.github.com/ajv-validator/ajv/issues/2427)
by [@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2433](https://redirect.github.com/ajv-validator/ajv/pull/2433)
- bump version to 8.14.0 for publishing by
[@&#8203;jasoniangreen](https://redirect.github.com/jasoniangreen) in
[#&#8203;2440](https://redirect.github.com/ajv-validator/ajv/pull/2440)

#### New Contributors

- [@&#8203;rotu](https://redirect.github.com/rotu) made their first
contribution in
[#&#8203;2410](https://redirect.github.com/ajv-validator/ajv/pull/2410)

**Full Changelog**:
<ajv-validator/ajv@v8.13.0...v8.14.0>

###
[`v8.13.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.13.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.12.0...v8.13.0)

- add named exports
- update dependencies
- update node.js

###
[`v8.12.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.12.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.2...v8.12.0)

- fix JTD serialisation (remove leading comma in objects with only
optional properties)
([#&#8203;2190](https://redirect.github.com/ajv-validator/ajv/issues/2190),
[@&#8203;piliugin-anton](https://redirect.github.com/piliugin-anton))
- empty JTD "values" schema
([#&#8203;2191](https://redirect.github.com/ajv-validator/ajv/issues/2191))
- empty object to work with JTD utility type
([#&#8203;2158](https://redirect.github.com/ajv-validator/ajv/issues/2158),
[@&#8203;erikbrinkman](https://redirect.github.com/erikbrinkman))
- fix JTD "discriminator" schema for objects with more than 8 properties
([#&#8203;2194](https://redirect.github.com/ajv-validator/ajv/issues/2194))
- correctly narrow "number" type to "integer"
([#&#8203;2192](https://redirect.github.com/ajv-validator/ajv/issues/2192),
[@&#8203;JacobLey](https://redirect.github.com/JacobLey))
- update Node.js versions in CI to 14, 16, 18 and 19

###
[`v8.11.2`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.2)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.1...v8.11.2)

Update dependencies

Export ValidationError and MissingRefError
([#&#8203;1840](https://redirect.github.com/ajv-validator/ajv/pull/1840),
[@&#8203;dannyb648](https://redirect.github.com/dannyb648))

###
[`v8.11.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.1)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.0...v8.11.1)

Update dependencies

Export ValidationError and MissingRefError
([#&#8203;1840](https://redirect.github.com/ajv-validator/ajv/issues/1840),
[@&#8203;dannyb648](https://redirect.github.com/dannyb648))

###
[`v8.11.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.0)

[Compare
Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.10.0...v8.11.0)

Use root schemaEnv when resolving references in oneOf
([#&#8203;1901](https://redirect.github.com/ajv-validator/ajv/issues/1901),
[@&#8203;asprouse](https://redirect.github.com/asprouse))

Only use equal function in generated code when it is used
([#&#8203;1922](https://redirect.github.com/ajv-validator/ajv/issues/1922),
[@&#8203;bhvngt](https://redirect.github.com/bhvngt))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Etc/UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/apache/texera).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZWxlYXNlL3YxLjIiLCJzZWN1cml0eSJdfQ==-->

---------

(backported from commit 469e8f0)

Co-authored-by: Xinyuan Lin <xinyual3@uci.edu>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Yicong-Huang added a commit that referenced this pull request Jul 29, 2026
Keep release/v1.2 versions (@vscode/iconv-lite-umd@0.7.0, quill@1.3.7)
and apply only the #6908 intent: bump ajv to 8.18.0 and add its new
fast-uri@3.1.4 dependency. Does not pull in main-only entries
(parchment@3.0.0, quill@2.0.3).
xuang7 pushed a commit that referenced this pull request Jul 29, 2026
#6984)

### What changes were proposed in this PR?

Automated backport of #6908 to `release/v1.2`.

Source: 469e8f0 · [automation
run](https://github.com/apache/texera/actions/runs/30414369328)

### Any related issues, documentation, discussions?

Backport of #6908. Fixes CVE-2025-69873 (see #6908 for details).

### How was this PR tested?

Release-branch CI runs on this branch once the conflicts are resolved
and this PR is marked ready for review.

### Was this PR authored or co-authored using generative AI tooling?

No.

---------

Co-authored-by: Mend Renovate <renovate@whitesourcesoftware.com>
Co-authored-by: Xinyuan Lin <xinyual3@uci.edu>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Yicong Huang <17627829+Yicong-Huang@users.noreply.github.com>
renovate-bot pushed a commit to renovate-bot/apache-_-texera that referenced this pull request Jul 29, 2026
…pache#7022)

### What changes were proposed in this PR?

The `Report backport decisions` step in `backport-auto-label.yml` is
skipped on every run, so the report comment and release-manager review
request added in apache#6962 never fire.

Root cause: the step's guard reads `steps.label.outputs.result`.
`actions/github-script` always writes the script's return value to an
output named `result` after the body runs. The `Label fix PRs` script
has no `return`, so that post-run write blanks out the explicit
`core.setOutput("result", …)` — the guard is therefore always false.

Fix: rename the output to `decisions` (github-script only reserves
`result`), and update the guard and the `RESULT` env reference to match.
No logic in either step changes.

### Any related issues, documentation, discussions?

Closes apache#7021.

### How was this PR tested?

- Confirmed the failure on run `30423275226` (PR apache#7013): the `Report
backport decisions` step shows `skipped`.
- Verified 0 `<!-- backport-auto-label-report -->` comments across
apache#7013, apache#6983, apache#6958, apache#6908 (including PRs that were auto-labeled),
confirming the step is systemically skipped.
- Change is name-only; the report/review logic is untouched, so it runs
unchanged once the guard sees the output.

### Was this PR authored or co-authored using generative AI tooling?

Generated-by: Claude Code (Claude Opus 4.8)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file frontend Changes related to the frontend GUI release/v1.2 back porting to release/v1.2 security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants