fix(deps, frontend, v1.2): update dependency ajv to v8.18.0 [security] - #6984
Merged
xuang7 merged 2 commits intoJul 29, 2026
Merged
Conversation
Contributor
Author
|
The cherry-pick conflicted and was committed with conflict markers. Resolve the conflicts on this branch, then mark this PR ready for review. Conflicting files:
|
Contributor
|
@aglinxinyuan let's resolve the conflict before marking it as ready for review, thanks! |
aglinxinyuan
marked this pull request as draft
July 29, 2026 02:27
Contributor
Author
Automated Reviewer SuggestionsBased on the
|
Yicong-Huang
marked this pull request as ready for review
July 29, 2026 02:33
This was referenced Jul 29, 2026
Open
Yicong-Huang
added a commit
that referenced
this pull request
Jul 29, 2026
…owlist (#6990) ### What changes were proposed in this PR? `release/v1.2` pins `sbt/setup-sbt@508b753e53cb6095967669e0911487d2b9bc9f41` (v1.1.22), which is **not on the ASF GitHub Enterprise actions allowlist**. GitHub rejects the workflow while building the graph, so the **Required Checks** workflow ends in `startup_failure` and no CI runs on `release/v1.2` — the `precheck` job never executes, which is why CI appears to "not trigger by label". This bumps all 6 pins to the allowlisted version already used on `main` (green there): ``` - sbt/setup-sbt@508b753 # v1.1.22 + sbt/setup-sbt@6444f4c # v1.5.2 ``` - `.github/workflows/build.yml` (×3) - `.github/workflows/build-and-push-images.yml` (×3) Minimal targeted change rather than backporting the large github-actions group bump (#6187), which touches 15 actions across 17 files and conflicts heavily against v1.2. ### Any related issues, documentation, discussions? Fixes #6989. `main` reached v1.5.2 via #6710 (`d28b761ae`). Unblocks backport PRs #6982 and #6984. ### How was this PR tested? This PR's own Required Checks run is the test: because the head branch already uses the allowlisted `sbt/setup-sbt@6444f4c8` (v1.5.2), the workflow should now start successfully instead of `startup_failure`. Diff is limited to the 6 action pins (verified no other `508b753e` references remain in `.github/workflows/`). ### Was this PR authored or co-authored using generative AI tooling? Yes — authored with Claude Code. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [ajv](https://ajv.js.org) ([source](https://redirect.github.com/ajv-validator/ajv)) | [`8.10.0` → `8.18.0`](https://renovatebot.com/diffs/npm/ajv/8.10.0/8.18.0) |  |  | --- > [!WARNING] > Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/6912) for more information. --- ### ajv has ReDoS when using `$data` option [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) / [GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) <details> <summary>More information</summary> #### Details ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the `$data` option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax (`$data` reference), which is passed directly to the JavaScript `RegExp()` constructor without validation. An attacker can inject a malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with `$data`: true for dynamic schema validation. #### Severity - CVSS Score: 5.5 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) - [https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md) - [https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) - [https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5) - [https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) - [https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588) - [https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0) - [https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) - [https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590) - [https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### ajv has ReDoS when using `$data` option [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) / [GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) <details> <summary>More information</summary> #### Details ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the `$data` option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax (`$data` reference), which is passed directly to the JavaScript `RegExp()` constructor without validation. An attacker can inject a malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with `$data`: true for dynamic schema validation. #### Severity - CVSS Score: 5.5 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873) - [https://github.com/ajv-validator/ajv/pull/2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) - [https://github.com/ajv-validator/ajv/pull/2588](https://redirect.github.com/ajv-validator/ajv/pull/2588) - [https://github.com/ajv-validator/ajv/pull/2590](https://redirect.github.com/ajv-validator/ajv/pull/2590) - [https://github.com/github/advisory-database/pull/6991](https://redirect.github.com/github/advisory-database/pull/6991) - [https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5](https://redirect.github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5) - [https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md](https://redirect.github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md) - [https://github.com/advisories/GHSA-2g4f-4pwh-qvx6](https://redirect.github.com/advisories/GHSA-2g4f-4pwh-qvx6) - [https://github.com/ajv-validator/ajv](https://redirect.github.com/ajv-validator/ajv) - [https://github.com/ajv-validator/ajv/releases/tag/v6.14.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v6.14.0) - [https://github.com/ajv-validator/ajv/releases/tag/v8.18.0](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6) and the [GitHub Advisory Database](https://redirect.github.com/github/advisory-database) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>ajv-validator/ajv (ajv)</summary> ### [`v8.18.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.18.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0) #### What's Changed - feat: allow tree-shaking by adding `"sideEffects": false` to `package.json` by [@​josdejong](https://redirect.github.com/josdejong) in [#​2480](https://redirect.github.com/ajv-validator/ajv/pull/2480) - fix: [#​2482](https://redirect.github.com/ajv-validator/ajv/issues/2482) Infinity and NaN serialise to null by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2487](https://redirect.github.com/ajv-validator/ajv/pull/2487) - fix: small grammatical error in managing-schemas.md by [@​monteiro-renato](https://redirect.github.com/monteiro-renato) in [#​2508](https://redirect.github.com/ajv-validator/ajv/pull/2508) - fix: typos in schema-language.md by [@​monteiro-renato](https://redirect.github.com/monteiro-renato) in [#​2507](https://redirect.github.com/ajv-validator/ajv/pull/2507) - fix(pattern): use configured RegExp engine with $data keyword to mitigate ReDoS attacks (CVE-2025-69873) by [@​epoberezkin](https://redirect.github.com/epoberezkin) in [#​2586](https://redirect.github.com/ajv-validator/ajv/pull/2586) #### New Contributors - [@​josdejong](https://redirect.github.com/josdejong) made their first contribution in [#​2480](https://redirect.github.com/ajv-validator/ajv/pull/2480) - [@​monteiro-renato](https://redirect.github.com/monteiro-renato) made their first contribution in [#​2508](https://redirect.github.com/ajv-validator/ajv/pull/2508) **Full Changelog**: <ajv-validator/ajv@v8.17.1...v8.18.0> ### [`v8.17.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.17.1) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.16.0...v8.17.1) #### What's Changed - bump version to 8.17.1 by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2472](https://redirect.github.com/ajv-validator/ajv/pull/2472) **Full Changelog**: <ajv-validator/ajv@v8.17.0...v8.17.1> #### Plus everything in 8.17.0 which failed to release The only functional change is to switch from uri-js (which is no longer supported), to fast-uri. This is the second attempt and the team on fast-uri have been really helpful addressing the issues we found last time. Revert "Revert fast-uri change ([#​2444](https://redirect.github.com/ajv-validator/ajv/pull/2444))" by [@​gurgunday](https://redirect.github.com/gurgunday) in [#​2448](https://redirect.github.com/ajv-validator/ajv/pull/2448) fix: ignore new eslint error for [@​typescript-eslint/no-extraneous-class](https://redirect.github.com/typescript-eslint/no-extraneous-class) by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2455](https://redirect.github.com/ajv-validator/ajv/pull/2455) docs: clarify behaviour of addVocabulary by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2454](https://redirect.github.com/ajv-validator/ajv/pull/2454) docs: refactor to improve legibility by [@​blottn](https://redirect.github.com/blottn) in [#​2432](https://redirect.github.com/ajv-validator/ajv/pull/2432) Fix grammatical typo in managing-schemas.md by [@​wetneb](https://redirect.github.com/wetneb) in [#​2305](https://redirect.github.com/ajv-validator/ajv/pull/2305) docs: Fix broken strict-mode link by [@​alexanderjsx](https://redirect.github.com/alexanderjsx) in [#​2459](https://redirect.github.com/ajv-validator/ajv/pull/2459) feat: add test for encoded refs and bump fast-uri by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2449](https://redirect.github.com/ajv-validator/ajv/pull/2449) fix: changes for [@​typescript-eslint/array-type](https://redirect.github.com/typescript-eslint/array-type) rule by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2467](https://redirect.github.com/ajv-validator/ajv/pull/2467) fixes [#​2217](https://redirect.github.com/ajv-validator/ajv/issues/2217) - clarify custom keyword naming by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2457](https://redirect.github.com/ajv-validator/ajv/pull/2457) ### [`v8.16.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.16.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.15.0...v8.16.0) #### What's Changed - Revert fast-uri change by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2444](https://redirect.github.com/ajv-validator/ajv/pull/2444) **Full Changelog**: <ajv-validator/ajv@v8.15.0...v8.16.0> ### [`v8.15.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.15.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.14.0...v8.15.0) #### What's Changed - Replace `uri-js` with `fast-uri` by [@​vixalien](https://redirect.github.com/vixalien) in [#​2415](https://redirect.github.com/ajv-validator/ajv/pull/2415) - Bump to 8.15.0 by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2442](https://redirect.github.com/ajv-validator/ajv/pull/2442) #### New Contributors - [@​vixalien](https://redirect.github.com/vixalien) made their first contribution in [#​2415](https://redirect.github.com/ajv-validator/ajv/pull/2415) **Full Changelog**: <ajv-validator/ajv@v8.14.0...v8.15.0> ### [`v8.14.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.14.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.13.0...v8.14.0) #### What's Changed - readme: build badge by [@​epoberezkin](https://redirect.github.com/epoberezkin) in [#​2424](https://redirect.github.com/ajv-validator/ajv/pull/2424) - Update workflows by [@​rotu](https://redirect.github.com/rotu) in [#​2410](https://redirect.github.com/ajv-validator/ajv/pull/2410) - docs: add warning to maxLength / minLength by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2428](https://redirect.github.com/ajv-validator/ajv/pull/2428) - fix: broken link in docs warning by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2431](https://redirect.github.com/ajv-validator/ajv/pull/2431) - compileAsync a schema with discriminator and $ref, fixes [#​2427](https://redirect.github.com/ajv-validator/ajv/issues/2427) by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2433](https://redirect.github.com/ajv-validator/ajv/pull/2433) - bump version to 8.14.0 for publishing by [@​jasoniangreen](https://redirect.github.com/jasoniangreen) in [#​2440](https://redirect.github.com/ajv-validator/ajv/pull/2440) #### New Contributors - [@​rotu](https://redirect.github.com/rotu) made their first contribution in [#​2410](https://redirect.github.com/ajv-validator/ajv/pull/2410) **Full Changelog**: <ajv-validator/ajv@v8.13.0...v8.14.0> ### [`v8.13.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.13.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.12.0...v8.13.0) - add named exports - update dependencies - update node.js ### [`v8.12.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.12.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.2...v8.12.0) - fix JTD serialisation (remove leading comma in objects with only optional properties) ([#​2190](https://redirect.github.com/ajv-validator/ajv/issues/2190), [@​piliugin-anton](https://redirect.github.com/piliugin-anton)) - empty JTD "values" schema ([#​2191](https://redirect.github.com/ajv-validator/ajv/issues/2191)) - empty object to work with JTD utility type ([#​2158](https://redirect.github.com/ajv-validator/ajv/issues/2158), [@​erikbrinkman](https://redirect.github.com/erikbrinkman)) - fix JTD "discriminator" schema for objects with more than 8 properties ([#​2194](https://redirect.github.com/ajv-validator/ajv/issues/2194)) - correctly narrow "number" type to "integer" ([#​2192](https://redirect.github.com/ajv-validator/ajv/issues/2192), [@​JacobLey](https://redirect.github.com/JacobLey)) - update Node.js versions in CI to 14, 16, 18 and 19 ### [`v8.11.2`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.2) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.1...v8.11.2) Update dependencies Export ValidationError and MissingRefError ([#​1840](https://redirect.github.com/ajv-validator/ajv/pull/1840), [@​dannyb648](https://redirect.github.com/dannyb648)) ### [`v8.11.1`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.1) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.11.0...v8.11.1) Update dependencies Export ValidationError and MissingRefError ([#​1840](https://redirect.github.com/ajv-validator/ajv/issues/1840), [@​dannyb648](https://redirect.github.com/dannyb648)) ### [`v8.11.0`](https://redirect.github.com/ajv-validator/ajv/releases/tag/v8.11.0) [Compare Source](https://redirect.github.com/ajv-validator/ajv/compare/v8.10.0...v8.11.0) Use root schemaEnv when resolving references in oneOf ([#​1901](https://redirect.github.com/ajv-validator/ajv/issues/1901), [@​asprouse](https://redirect.github.com/asprouse)) Only use equal function in generated code when it is used ([#​1922](https://redirect.github.com/ajv-validator/ajv/issues/1922), [@​bhvngt](https://redirect.github.com/bhvngt)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Etc/UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/apache/texera). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZWxlYXNlL3YxLjIiLCJzZWN1cml0eSJdfQ==--> --------- (backported from commit 469e8f0) Co-authored-by: Xinyuan Lin <xinyual3@uci.edu> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Keep release/v1.2 versions (@vscode/iconv-lite-umd@0.7.0, quill@1.3.7) and apply only the #6908 intent: bump ajv to 8.18.0 and add its new fast-uri@3.1.4 dependency. Does not pull in main-only entries (parchment@3.0.0, quill@2.0.3).
Yicong-Huang
force-pushed
the
backport/6908-update-dependency-ajv-to-v8-18-0-securit-v1.2
branch
from
July 29, 2026 03:41
a291a9f to
bb301e3
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release/v1.2 #6984 +/- ##
==================================================
+ Coverage 53.95% 53.96% +0.01%
Complexity 1441 1441
==================================================
Files 809 809
Lines 34144 34144
Branches 3448 3448
==================================================
+ Hits 18421 18426 +5
+ Misses 14815 14807 -8
- Partials 908 911 +3
*This pull request uses carry forward flags. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
xuang7
approved these changes
Jul 29, 2026
xuang7
deleted the
backport/6908-update-dependency-ajv-to-v8-18-0-securit-v1.2
branch
July 29, 2026 18:01
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes were proposed in this PR?
Automated backport of #6908 to
release/v1.2.Source: 469e8f0 · automation run
Any related issues, documentation, discussions?
Backport of #6908. Fixes CVE-2025-69873 (see #6908 for details).
How was this PR tested?
Release-branch CI runs on this branch once the conflicts are resolved and this PR is marked ready for review.
Was this PR authored or co-authored using generative AI tooling?
No.