Change Request: update ajv to 8.18.0
envgap__eslint__eslint-20508
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
61a24054411fa56ce74bef554846caa9d8cb01f5- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
eslint/eslint #20508 · read the original issue
### ESLint version 10.0.0 ### What problem do you want to solve? ESLint currently uses version `6.12.4` of `ajv`. The authors of `ajv` have released version `8.18.0` to mitigate [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873). I realise the [ESLint Security Policy](https://github.com/eslint/eslint/security/policy) mentions: > there are no security concerns related to regular expression performance So, there is no reason to hurry upgrading `ajv`, but in the long run I would still recommend upgrading `ajv` because: 1. the version used in ESLint was released 5+ years ago 2. ESLint is 2 major versions behind on `ajv`, which is no longer updated 3. even though a Regex DoS is very unlikely in the case of ESLint, ESLint is still reported to be vulnerable by tools used in enterprise organizations to scan dependencies ### What do you think is the correct solution? Update `ajv` to `8.18.0` or higher. ### Participation - [ ] I am willing to submit a pull request for this change. ### Additional comments _No response_
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]