chore(deps): bump ajv to fix ReDoS in $data option - #5710

Merged
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv
Mar 2, 2026
Merged

chore(deps): bump ajv to fix ReDoS in $data option#5710
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv

Conversation

@antonis

Copy link
Copy Markdown
Contributor

Summary

  • Adds resolutions to fix ReDoS vulnerability when using the $data option in ajv
  • 8.x consumers: bumped appium's exact 8.12.0 pin and all ^8.x consumers to 8.18.0
  • 6.x consumers (eslint, @eslint/eslintrc): consolidated onto 8.18.0 via unscoped resolution — build and tests pass with ajv 8.x

Dependabot alerts

Test plan

  • yarn install resolves all ajv consumers to 8.18.0
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump ajv to fix ReDoS in $data option by antonis in #5710
  • chore(deps): update CLI to v3.2.3 by github-actions in #5743
  • Fixes the issue with unit mismatch in adjustTransactionDuration by alwx in #5740
  • Handle inactive state for spans by alwx in #5742
  • chore(deps): bump actions/github-script from 7 to 8 by dependabot in #5737
  • chore(deps): bump actions/upload-artifact from 6 to 7 by dependabot in #5739
  • chore(deps): bump futureware-tech/simulator-action from 4 to 5 by dependabot in #5735
  • chore(deps): bump actions/download-artifact from 7 to 8 by dependabot in #5736
  • chore(deps): bump path-to-regexp to 0.1.12 by antonis in #5706
  • fix(ios): resolve relative SOURCEMAP_FILE against project root in Xcode build script by antonis in #5730
  • test(metro): Add type tests for SentryExpoConfigOptions.getDefaultConfig by antonis in #5733
  • chore(deps): bump axios to ^1.13.5 by antonis in #5708
  • chore(deps): bump on-headers to ^1.1.0 by antonis in #5704
  • chore(deps): bump dottie from 2.0.6 to 2.0.7 by dependabot in #5731
  • Cirrus Labs runners for other important workflows (where it makes sense to do so) + Ubuntu update (22.04 -> 24.04) by alwx in #5696
  • chore(deps): bump diff to ^5.2.2 by antonis in #5705
  • chore(deps): update Bundler Plugins to v5.1.1 by github-actions in #5700
  • chore(deps): update JavaScript SDK to v10.40.0 by github-actions in #5715
  • ci: Cancel in-progress CI jobs when a PR is closed or merged by antonis in #5725

🤖 This preview updates automatically when you update the PR.

@antonisantonis mentioned this pull request Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time1210.85 ms1217.55 ms6.70 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1229.13 ms1228.46 ms-0.67 ms
80e4616+dirty1221.32 ms1225.64 ms4.32 ms
818a608+dirty1205.76 ms1208.00 ms2.24 ms
77061ed+dirty1233.16 ms1234.88 ms1.71 ms
bef3709+dirty1222.07 ms1220.24 ms-1.83 ms
a206511+dirty1185.00 ms1186.35 ms1.35 ms
74979ac+dirty1210.49 ms1213.31 ms2.82 ms
a2bb688+dirty1223.53 ms1232.90 ms9.37 ms
8a868fe+dirty1221.50 ms1230.78 ms9.28 ms
d590428+dirty1211.77 ms1220.51 ms8.75 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty2.63 MiB3.91 MiB1.28 MiB
77061ed+dirty2.63 MiB3.98 MiB1.34 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty2.63 MiB3.99 MiB1.36 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1216.40 ms1212.08 ms-4.32 ms
cddbba5+dirty1218.63 ms1220.67 ms2.04 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonis
antonis marked this pull request as ready for review February 24, 2026 13:07
Comment threadpackage.json
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time416.26 ms433.42 ms17.16 ms
Size43.75 MiB48.46 MiB4.71 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
86584b7+dirty463.83 ms500.31 ms36.48 ms
9a81842+dirty412.23 ms416.56 ms4.33 ms
c637fc7+dirty433.70 ms467.76 ms34.06 ms
d73150f+dirty411.21 ms465.86 ms54.65 ms
fa7bb7e+dirty350.37 ms377.02 ms26.65 ms
3bd3f0d+dirty447.21 ms472.31 ms25.10 ms
88890fe+dirty350.94 ms365.74 ms14.80 ms
95aaf8a437.89 ms419.45 ms-18.44 ms
c0842e7+dirty527.76 ms566.69 ms38.93 ms
1e7a472+dirty348.80 ms362.55 ms13.75 ms

App size

RevisionPlainWith SentryDiff
86584b7+dirty43.75 MiB48.08 MiB4.33 MiB
9a81842+dirty43.75 MiB48.08 MiB4.33 MiB
c637fc7+dirty43.75 MiB48.40 MiB4.64 MiB
d73150f+dirty43.75 MiB48.55 MiB4.80 MiB
fa7bb7e+dirty17.75 MiB19.75 MiB2.00 MiB
3bd3f0d+dirty17.75 MiB19.70 MiB1.95 MiB
88890fe+dirty17.75 MiB19.71 MiB1.96 MiB
95aaf8a17.75 MiB19.68 MiB1.93 MiB
c0842e7+dirty43.75 MiB48.41 MiB4.66 MiB
1e7a472+dirty17.75 MiB19.70 MiB1.96 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty395.96 ms423.90 ms27.94 ms
cddbba5+dirty387.39 ms446.46 ms59.07 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.75 MiB48.46 MiB4.71 MiB
cddbba5+dirty43.75 MiB48.46 MiB4.71 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time438.00 ms477.32 ms39.32 ms
Size43.94 MiB49.34 MiB5.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
7480abe+dirty363.80 ms431.34 ms67.54 ms
2b89ce9+dirty372.22 ms417.06 ms44.84 ms
170d5ea+dirty348.79 ms406.94 ms58.15 ms
b1579bc+dirty391.87 ms456.26 ms64.39 ms
73f2455+dirty369.33 ms398.90 ms29.57 ms
0b64753+dirty358.55 ms429.16 ms70.61 ms
6a70a7e+dirty382.45 ms424.54 ms42.09 ms
2adbd1e+dirty366.13 ms419.49 ms53.36 ms
f8d19f8+dirty374.17 ms383.40 ms9.23 ms
7be1f99+dirty369.02 ms399.60 ms30.58 ms

App size

RevisionPlainWith SentryDiff
7480abe+dirty7.15 MiB8.41 MiB1.26 MiB
2b89ce9+dirty7.15 MiB8.41 MiB1.26 MiB
170d5ea+dirty7.15 MiB8.42 MiB1.27 MiB
b1579bc+dirty43.94 MiB49.27 MiB5.33 MiB
73f2455+dirty43.94 MiB48.82 MiB4.88 MiB
0b64753+dirty7.15 MiB8.42 MiB1.27 MiB
6a70a7e+dirty7.15 MiB8.42 MiB1.26 MiB
2adbd1e+dirty7.15 MiB8.43 MiB1.28 MiB
f8d19f8+dirty43.94 MiB48.91 MiB4.97 MiB
7be1f99+dirty7.15 MiB8.42 MiB1.27 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty365.94 ms393.20 ms27.27 ms
cddbba5+dirty434.37 ms478.51 ms44.14 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.94 MiB49.33 MiB5.39 MiB
cddbba5+dirty43.94 MiB49.34 MiB5.40 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time1226.06 ms1226.24 ms0.18 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1216.61 ms1214.15 ms-2.47 ms
80e4616+dirty1206.90 ms1205.94 ms-0.96 ms
818a608+dirty1218.84 ms1223.18 ms4.34 ms
77061ed+dirty1210.77 ms1218.45 ms7.68 ms
bef3709+dirty1217.79 ms1225.33 ms7.54 ms
a206511+dirty1225.02 ms1223.74 ms-1.28 ms
74979ac+dirty1212.33 ms1212.54 ms0.21 ms
a2bb688+dirty1244.82 ms1238.60 ms-6.22 ms
8a868fe+dirty1206.85 ms1215.04 ms8.19 ms
d590428+dirty1221.23 ms1225.27 ms4.03 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty3.19 MiB4.48 MiB1.29 MiB
77061ed+dirty3.19 MiB4.54 MiB1.36 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty3.19 MiB4.56 MiB1.37 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1207.61 ms1209.47 ms1.86 ms
cddbba5+dirty1207.78 ms1210.07 ms2.29 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 26, 2026
Comment threadpackage.json Outdated
Uses scoped yarn resolutions to bump ajv:
- eslint/eslintrc consumers: 6.12.6 → 6.14.0 (fixes alert #423)
- appium, detox, expo-dev-launcher: → 8.18.0 (fixes alert #424)
Parent-scoped resolutions avoid the unscoped override that would force
eslint onto incompatible ajv v8.
https://github.com/getsentry/sentry-react-native/security/dependabot/423https://github.com/getsentry/sentry-react-native/security/dependabot/424
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both review comments:

  • sentry[bot]: Correct — the unscoped "ajv": "^8.18.0" was overriding the parent-scoped 6.x resolutions, forcing eslint onto incompatible ajv v8. This broke yarn lint:lerna with TypeError: Cannot set properties of undefined (setting 'defaultMeta').
  • cursor[bot]: Also correct — the scoped eslint resolutions were dead code because the unscoped resolution took precedence.

Fix: Removed the unscoped resolution entirely. Now using only parent-scoped resolutions:

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

Comment threadpackage.json
Comment threadyarn.lock Outdated
Comment on lines 13697 to 13700
"ajv@npm:^8.0.0":
version: 8.17.1
resolution: "ajv@npm:8.17.1"
dependencies:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The fix for the ajv ReDoS vulnerability is incomplete. The ajv-formats package is not covered by the scoped resolutions and still resolves to a vulnerable ajv version.
Severity: HIGH

Suggested Fix

To fully mitigate the vulnerability, either add a specific scoped resolution for ajv-formats like "ajv-formats@npm:2.1.1/ajv": "^8.18.0", or add a global unscoped resolution like "ajv": "^8.18.0" to force all consumers to the patched version.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: yarn.lock#L13697-L13700
Potential issue: The pull request attempts to mitigate a ReDoS vulnerability in the
`ajv` package by adding scoped resolutions to `yarn.lock`. However, this fix is
incomplete. The `ajv-formats` package, a dependency in the project, requires `ajv:
"^8.0.0"` and is not covered by any of the new scoped resolutions. As a result, it
resolves to the vulnerable version `8.17.1` instead of the patched version `8.18.0`.
This leaves the application exposed to the ReDoS vulnerability (CVE-2025-69873) through
any code path that utilizes `ajv-formats`.

…ajv 8.17.1
ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still
resolving to vulnerable 8.17.1. Adding a scoped resolution for
ajv-formats ensures it also gets ajv 8.18.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both new comments:

  • cursor[bot] / sentry[bot]: Correct — ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still resolving to vulnerable 8.17.1.

Fix: Added "ajv-formats@npm:2.1.1/ajv": "^8.18.0" scoped resolution. No more 8.17.1 in the lockfile — all 8.x consumers now resolve to 8.18.0, and all 6.x (eslint) consumers resolve to 6.14.0.

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) February 27, 2026 14:21

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! once when tests are green

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman

Copy link
Copy Markdown
Collaborator

@antonis should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@antonis
antonis disabled auto-merge February 27, 2026 14:56
@antonis

antonis commented Feb 27, 2026

Copy link
Copy Markdown
ContributorAuthor

should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@lucas-zimerman I'm not sure. We already have 10.40.0 with #5715 but the sec alert is still open.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) March 2, 2026 15:46

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor
Fails
🚫Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against e5819e7

@lucas-zimerman
lucas-zimerman merged commit a02d765 into mainMar 2, 2026
33 of 44 checks passed
@lucas-zimerman
lucas-zimerman deleted the antonis/bump-ajv branch March 2, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@antonis@lucas-zimerman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps): bump ajv to fix ReDoS in $data option - #5710

Merged
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv
Mar 2, 2026
Merged

chore(deps): bump ajv to fix ReDoS in $data option#5710
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv

Conversation

@antonis

Copy link
Copy Markdown
Contributor

Summary

  • Adds resolutions to fix ReDoS vulnerability when using the $data option in ajv
  • 8.x consumers: bumped appium's exact 8.12.0 pin and all ^8.x consumers to 8.18.0
  • 6.x consumers (eslint, @eslint/eslintrc): consolidated onto 8.18.0 via unscoped resolution — build and tests pass with ajv 8.x

Dependabot alerts

Test plan

  • yarn install resolves all ajv consumers to 8.18.0
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump ajv to fix ReDoS in $data option by antonis in #5710
  • chore(deps): update CLI to v3.2.3 by github-actions in #5743
  • Fixes the issue with unit mismatch in adjustTransactionDuration by alwx in #5740
  • Handle inactive state for spans by alwx in #5742
  • chore(deps): bump actions/github-script from 7 to 8 by dependabot in #5737
  • chore(deps): bump actions/upload-artifact from 6 to 7 by dependabot in #5739
  • chore(deps): bump futureware-tech/simulator-action from 4 to 5 by dependabot in #5735
  • chore(deps): bump actions/download-artifact from 7 to 8 by dependabot in #5736
  • chore(deps): bump path-to-regexp to 0.1.12 by antonis in #5706
  • fix(ios): resolve relative SOURCEMAP_FILE against project root in Xcode build script by antonis in #5730
  • test(metro): Add type tests for SentryExpoConfigOptions.getDefaultConfig by antonis in #5733
  • chore(deps): bump axios to ^1.13.5 by antonis in #5708
  • chore(deps): bump on-headers to ^1.1.0 by antonis in #5704
  • chore(deps): bump dottie from 2.0.6 to 2.0.7 by dependabot in #5731
  • Cirrus Labs runners for other important workflows (where it makes sense to do so) + Ubuntu update (22.04 -> 24.04) by alwx in #5696
  • chore(deps): bump diff to ^5.2.2 by antonis in #5705
  • chore(deps): update Bundler Plugins to v5.1.1 by github-actions in #5700
  • chore(deps): update JavaScript SDK to v10.40.0 by github-actions in #5715
  • ci: Cancel in-progress CI jobs when a PR is closed or merged by antonis in #5725

🤖 This preview updates automatically when you update the PR.

@antonisantonis mentioned this pull request Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time1210.85 ms1217.55 ms6.70 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1229.13 ms1228.46 ms-0.67 ms
80e4616+dirty1221.32 ms1225.64 ms4.32 ms
818a608+dirty1205.76 ms1208.00 ms2.24 ms
77061ed+dirty1233.16 ms1234.88 ms1.71 ms
bef3709+dirty1222.07 ms1220.24 ms-1.83 ms
a206511+dirty1185.00 ms1186.35 ms1.35 ms
74979ac+dirty1210.49 ms1213.31 ms2.82 ms
a2bb688+dirty1223.53 ms1232.90 ms9.37 ms
8a868fe+dirty1221.50 ms1230.78 ms9.28 ms
d590428+dirty1211.77 ms1220.51 ms8.75 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty2.63 MiB3.91 MiB1.28 MiB
77061ed+dirty2.63 MiB3.98 MiB1.34 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty2.63 MiB3.99 MiB1.36 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1216.40 ms1212.08 ms-4.32 ms
cddbba5+dirty1218.63 ms1220.67 ms2.04 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonis
antonis marked this pull request as ready for review February 24, 2026 13:07
Comment threadpackage.json
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time416.26 ms433.42 ms17.16 ms
Size43.75 MiB48.46 MiB4.71 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
86584b7+dirty463.83 ms500.31 ms36.48 ms
9a81842+dirty412.23 ms416.56 ms4.33 ms
c637fc7+dirty433.70 ms467.76 ms34.06 ms
d73150f+dirty411.21 ms465.86 ms54.65 ms
fa7bb7e+dirty350.37 ms377.02 ms26.65 ms
3bd3f0d+dirty447.21 ms472.31 ms25.10 ms
88890fe+dirty350.94 ms365.74 ms14.80 ms
95aaf8a437.89 ms419.45 ms-18.44 ms
c0842e7+dirty527.76 ms566.69 ms38.93 ms
1e7a472+dirty348.80 ms362.55 ms13.75 ms

App size

RevisionPlainWith SentryDiff
86584b7+dirty43.75 MiB48.08 MiB4.33 MiB
9a81842+dirty43.75 MiB48.08 MiB4.33 MiB
c637fc7+dirty43.75 MiB48.40 MiB4.64 MiB
d73150f+dirty43.75 MiB48.55 MiB4.80 MiB
fa7bb7e+dirty17.75 MiB19.75 MiB2.00 MiB
3bd3f0d+dirty17.75 MiB19.70 MiB1.95 MiB
88890fe+dirty17.75 MiB19.71 MiB1.96 MiB
95aaf8a17.75 MiB19.68 MiB1.93 MiB
c0842e7+dirty43.75 MiB48.41 MiB4.66 MiB
1e7a472+dirty17.75 MiB19.70 MiB1.96 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty395.96 ms423.90 ms27.94 ms
cddbba5+dirty387.39 ms446.46 ms59.07 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.75 MiB48.46 MiB4.71 MiB
cddbba5+dirty43.75 MiB48.46 MiB4.71 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time438.00 ms477.32 ms39.32 ms
Size43.94 MiB49.34 MiB5.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
7480abe+dirty363.80 ms431.34 ms67.54 ms
2b89ce9+dirty372.22 ms417.06 ms44.84 ms
170d5ea+dirty348.79 ms406.94 ms58.15 ms
b1579bc+dirty391.87 ms456.26 ms64.39 ms
73f2455+dirty369.33 ms398.90 ms29.57 ms
0b64753+dirty358.55 ms429.16 ms70.61 ms
6a70a7e+dirty382.45 ms424.54 ms42.09 ms
2adbd1e+dirty366.13 ms419.49 ms53.36 ms
f8d19f8+dirty374.17 ms383.40 ms9.23 ms
7be1f99+dirty369.02 ms399.60 ms30.58 ms

App size

RevisionPlainWith SentryDiff
7480abe+dirty7.15 MiB8.41 MiB1.26 MiB
2b89ce9+dirty7.15 MiB8.41 MiB1.26 MiB
170d5ea+dirty7.15 MiB8.42 MiB1.27 MiB
b1579bc+dirty43.94 MiB49.27 MiB5.33 MiB
73f2455+dirty43.94 MiB48.82 MiB4.88 MiB
0b64753+dirty7.15 MiB8.42 MiB1.27 MiB
6a70a7e+dirty7.15 MiB8.42 MiB1.26 MiB
2adbd1e+dirty7.15 MiB8.43 MiB1.28 MiB
f8d19f8+dirty43.94 MiB48.91 MiB4.97 MiB
7be1f99+dirty7.15 MiB8.42 MiB1.27 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty365.94 ms393.20 ms27.27 ms
cddbba5+dirty434.37 ms478.51 ms44.14 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.94 MiB49.33 MiB5.39 MiB
cddbba5+dirty43.94 MiB49.34 MiB5.40 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time1226.06 ms1226.24 ms0.18 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1216.61 ms1214.15 ms-2.47 ms
80e4616+dirty1206.90 ms1205.94 ms-0.96 ms
818a608+dirty1218.84 ms1223.18 ms4.34 ms
77061ed+dirty1210.77 ms1218.45 ms7.68 ms
bef3709+dirty1217.79 ms1225.33 ms7.54 ms
a206511+dirty1225.02 ms1223.74 ms-1.28 ms
74979ac+dirty1212.33 ms1212.54 ms0.21 ms
a2bb688+dirty1244.82 ms1238.60 ms-6.22 ms
8a868fe+dirty1206.85 ms1215.04 ms8.19 ms
d590428+dirty1221.23 ms1225.27 ms4.03 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty3.19 MiB4.48 MiB1.29 MiB
77061ed+dirty3.19 MiB4.54 MiB1.36 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty3.19 MiB4.56 MiB1.37 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1207.61 ms1209.47 ms1.86 ms
cddbba5+dirty1207.78 ms1210.07 ms2.29 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 26, 2026
Comment threadpackage.json Outdated
Uses scoped yarn resolutions to bump ajv:
- eslint/eslintrc consumers: 6.12.6 → 6.14.0 (fixes alert #423)
- appium, detox, expo-dev-launcher: → 8.18.0 (fixes alert #424)
Parent-scoped resolutions avoid the unscoped override that would force
eslint onto incompatible ajv v8.
https://github.com/getsentry/sentry-react-native/security/dependabot/423https://github.com/getsentry/sentry-react-native/security/dependabot/424
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both review comments:

  • sentry[bot]: Correct — the unscoped "ajv": "^8.18.0" was overriding the parent-scoped 6.x resolutions, forcing eslint onto incompatible ajv v8. This broke yarn lint:lerna with TypeError: Cannot set properties of undefined (setting 'defaultMeta').
  • cursor[bot]: Also correct — the scoped eslint resolutions were dead code because the unscoped resolution took precedence.

Fix: Removed the unscoped resolution entirely. Now using only parent-scoped resolutions:

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

Comment threadpackage.json
Comment threadyarn.lock Outdated
Comment on lines 13697 to 13700
"ajv@npm:^8.0.0":
version: 8.17.1
resolution: "ajv@npm:8.17.1"
dependencies:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The fix for the ajv ReDoS vulnerability is incomplete. The ajv-formats package is not covered by the scoped resolutions and still resolves to a vulnerable ajv version.
Severity: HIGH

Suggested Fix

To fully mitigate the vulnerability, either add a specific scoped resolution for ajv-formats like "ajv-formats@npm:2.1.1/ajv": "^8.18.0", or add a global unscoped resolution like "ajv": "^8.18.0" to force all consumers to the patched version.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: yarn.lock#L13697-L13700
Potential issue: The pull request attempts to mitigate a ReDoS vulnerability in the
`ajv` package by adding scoped resolutions to `yarn.lock`. However, this fix is
incomplete. The `ajv-formats` package, a dependency in the project, requires `ajv:
"^8.0.0"` and is not covered by any of the new scoped resolutions. As a result, it
resolves to the vulnerable version `8.17.1` instead of the patched version `8.18.0`.
This leaves the application exposed to the ReDoS vulnerability (CVE-2025-69873) through
any code path that utilizes `ajv-formats`.

…ajv 8.17.1
ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still
resolving to vulnerable 8.17.1. Adding a scoped resolution for
ajv-formats ensures it also gets ajv 8.18.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both new comments:

  • cursor[bot] / sentry[bot]: Correct — ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still resolving to vulnerable 8.17.1.

Fix: Added "ajv-formats@npm:2.1.1/ajv": "^8.18.0" scoped resolution. No more 8.17.1 in the lockfile — all 8.x consumers now resolve to 8.18.0, and all 6.x (eslint) consumers resolve to 6.14.0.

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) February 27, 2026 14:21

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! once when tests are green

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman

Copy link
Copy Markdown
Collaborator

@antonis should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@antonis
antonis disabled auto-merge February 27, 2026 14:56
@antonis

antonis commented Feb 27, 2026

Copy link
Copy Markdown
ContributorAuthor

should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@lucas-zimerman I'm not sure. We already have 10.40.0 with #5715 but the sec alert is still open.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) March 2, 2026 15:46

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor
Fails
🚫Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against e5819e7

@lucas-zimerman
lucas-zimerman merged commit a02d765 into mainMar 2, 2026
33 of 44 checks passed
@lucas-zimerman
lucas-zimerman deleted the antonis/bump-ajv branch March 2, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@antonis@lucas-zimerman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): bump ajv to fix ReDoS in $data option - #5710

Merged
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv
Mar 2, 2026
Merged

chore(deps): bump ajv to fix ReDoS in $data option#5710
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv

Conversation

@antonis

Copy link
Copy Markdown
Contributor

Summary

  • Adds resolutions to fix ReDoS vulnerability when using the $data option in ajv
  • 8.x consumers: bumped appium's exact 8.12.0 pin and all ^8.x consumers to 8.18.0
  • 6.x consumers (eslint, @eslint/eslintrc): consolidated onto 8.18.0 via unscoped resolution — build and tests pass with ajv 8.x

Dependabot alerts

Test plan

  • yarn install resolves all ajv consumers to 8.18.0
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump ajv to fix ReDoS in $data option by antonis in #5710
  • chore(deps): update CLI to v3.2.3 by github-actions in #5743
  • Fixes the issue with unit mismatch in adjustTransactionDuration by alwx in #5740
  • Handle inactive state for spans by alwx in #5742
  • chore(deps): bump actions/github-script from 7 to 8 by dependabot in #5737
  • chore(deps): bump actions/upload-artifact from 6 to 7 by dependabot in #5739
  • chore(deps): bump futureware-tech/simulator-action from 4 to 5 by dependabot in #5735
  • chore(deps): bump actions/download-artifact from 7 to 8 by dependabot in #5736
  • chore(deps): bump path-to-regexp to 0.1.12 by antonis in #5706
  • fix(ios): resolve relative SOURCEMAP_FILE against project root in Xcode build script by antonis in #5730
  • test(metro): Add type tests for SentryExpoConfigOptions.getDefaultConfig by antonis in #5733
  • chore(deps): bump axios to ^1.13.5 by antonis in #5708
  • chore(deps): bump on-headers to ^1.1.0 by antonis in #5704
  • chore(deps): bump dottie from 2.0.6 to 2.0.7 by dependabot in #5731
  • Cirrus Labs runners for other important workflows (where it makes sense to do so) + Ubuntu update (22.04 -> 24.04) by alwx in #5696
  • chore(deps): bump diff to ^5.2.2 by antonis in #5705
  • chore(deps): update Bundler Plugins to v5.1.1 by github-actions in #5700
  • chore(deps): update JavaScript SDK to v10.40.0 by github-actions in #5715
  • ci: Cancel in-progress CI jobs when a PR is closed or merged by antonis in #5725

🤖 This preview updates automatically when you update the PR.

@antonisantonis mentioned this pull request Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time1210.85 ms1217.55 ms6.70 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1229.13 ms1228.46 ms-0.67 ms
80e4616+dirty1221.32 ms1225.64 ms4.32 ms
818a608+dirty1205.76 ms1208.00 ms2.24 ms
77061ed+dirty1233.16 ms1234.88 ms1.71 ms
bef3709+dirty1222.07 ms1220.24 ms-1.83 ms
a206511+dirty1185.00 ms1186.35 ms1.35 ms
74979ac+dirty1210.49 ms1213.31 ms2.82 ms
a2bb688+dirty1223.53 ms1232.90 ms9.37 ms
8a868fe+dirty1221.50 ms1230.78 ms9.28 ms
d590428+dirty1211.77 ms1220.51 ms8.75 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty2.63 MiB3.91 MiB1.28 MiB
77061ed+dirty2.63 MiB3.98 MiB1.34 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty2.63 MiB3.99 MiB1.36 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1216.40 ms1212.08 ms-4.32 ms
cddbba5+dirty1218.63 ms1220.67 ms2.04 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonis
antonis marked this pull request as ready for review February 24, 2026 13:07
Comment threadpackage.json
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time416.26 ms433.42 ms17.16 ms
Size43.75 MiB48.46 MiB4.71 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
86584b7+dirty463.83 ms500.31 ms36.48 ms
9a81842+dirty412.23 ms416.56 ms4.33 ms
c637fc7+dirty433.70 ms467.76 ms34.06 ms
d73150f+dirty411.21 ms465.86 ms54.65 ms
fa7bb7e+dirty350.37 ms377.02 ms26.65 ms
3bd3f0d+dirty447.21 ms472.31 ms25.10 ms
88890fe+dirty350.94 ms365.74 ms14.80 ms
95aaf8a437.89 ms419.45 ms-18.44 ms
c0842e7+dirty527.76 ms566.69 ms38.93 ms
1e7a472+dirty348.80 ms362.55 ms13.75 ms

App size

RevisionPlainWith SentryDiff
86584b7+dirty43.75 MiB48.08 MiB4.33 MiB
9a81842+dirty43.75 MiB48.08 MiB4.33 MiB
c637fc7+dirty43.75 MiB48.40 MiB4.64 MiB
d73150f+dirty43.75 MiB48.55 MiB4.80 MiB
fa7bb7e+dirty17.75 MiB19.75 MiB2.00 MiB
3bd3f0d+dirty17.75 MiB19.70 MiB1.95 MiB
88890fe+dirty17.75 MiB19.71 MiB1.96 MiB
95aaf8a17.75 MiB19.68 MiB1.93 MiB
c0842e7+dirty43.75 MiB48.41 MiB4.66 MiB
1e7a472+dirty17.75 MiB19.70 MiB1.96 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty395.96 ms423.90 ms27.94 ms
cddbba5+dirty387.39 ms446.46 ms59.07 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.75 MiB48.46 MiB4.71 MiB
cddbba5+dirty43.75 MiB48.46 MiB4.71 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time438.00 ms477.32 ms39.32 ms
Size43.94 MiB49.34 MiB5.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
7480abe+dirty363.80 ms431.34 ms67.54 ms
2b89ce9+dirty372.22 ms417.06 ms44.84 ms
170d5ea+dirty348.79 ms406.94 ms58.15 ms
b1579bc+dirty391.87 ms456.26 ms64.39 ms
73f2455+dirty369.33 ms398.90 ms29.57 ms
0b64753+dirty358.55 ms429.16 ms70.61 ms
6a70a7e+dirty382.45 ms424.54 ms42.09 ms
2adbd1e+dirty366.13 ms419.49 ms53.36 ms
f8d19f8+dirty374.17 ms383.40 ms9.23 ms
7be1f99+dirty369.02 ms399.60 ms30.58 ms

App size

RevisionPlainWith SentryDiff
7480abe+dirty7.15 MiB8.41 MiB1.26 MiB
2b89ce9+dirty7.15 MiB8.41 MiB1.26 MiB
170d5ea+dirty7.15 MiB8.42 MiB1.27 MiB
b1579bc+dirty43.94 MiB49.27 MiB5.33 MiB
73f2455+dirty43.94 MiB48.82 MiB4.88 MiB
0b64753+dirty7.15 MiB8.42 MiB1.27 MiB
6a70a7e+dirty7.15 MiB8.42 MiB1.26 MiB
2adbd1e+dirty7.15 MiB8.43 MiB1.28 MiB
f8d19f8+dirty43.94 MiB48.91 MiB4.97 MiB
7be1f99+dirty7.15 MiB8.42 MiB1.27 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty365.94 ms393.20 ms27.27 ms
cddbba5+dirty434.37 ms478.51 ms44.14 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.94 MiB49.33 MiB5.39 MiB
cddbba5+dirty43.94 MiB49.34 MiB5.40 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time1226.06 ms1226.24 ms0.18 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1216.61 ms1214.15 ms-2.47 ms
80e4616+dirty1206.90 ms1205.94 ms-0.96 ms
818a608+dirty1218.84 ms1223.18 ms4.34 ms
77061ed+dirty1210.77 ms1218.45 ms7.68 ms
bef3709+dirty1217.79 ms1225.33 ms7.54 ms
a206511+dirty1225.02 ms1223.74 ms-1.28 ms
74979ac+dirty1212.33 ms1212.54 ms0.21 ms
a2bb688+dirty1244.82 ms1238.60 ms-6.22 ms
8a868fe+dirty1206.85 ms1215.04 ms8.19 ms
d590428+dirty1221.23 ms1225.27 ms4.03 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty3.19 MiB4.48 MiB1.29 MiB
77061ed+dirty3.19 MiB4.54 MiB1.36 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty3.19 MiB4.56 MiB1.37 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1207.61 ms1209.47 ms1.86 ms
cddbba5+dirty1207.78 ms1210.07 ms2.29 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 26, 2026
Comment threadpackage.json Outdated
Uses scoped yarn resolutions to bump ajv:
- eslint/eslintrc consumers: 6.12.6 → 6.14.0 (fixes alert #423)
- appium, detox, expo-dev-launcher: → 8.18.0 (fixes alert #424)
Parent-scoped resolutions avoid the unscoped override that would force
eslint onto incompatible ajv v8.
https://github.com/getsentry/sentry-react-native/security/dependabot/423https://github.com/getsentry/sentry-react-native/security/dependabot/424
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both review comments:

  • sentry[bot]: Correct — the unscoped "ajv": "^8.18.0" was overriding the parent-scoped 6.x resolutions, forcing eslint onto incompatible ajv v8. This broke yarn lint:lerna with TypeError: Cannot set properties of undefined (setting 'defaultMeta').
  • cursor[bot]: Also correct — the scoped eslint resolutions were dead code because the unscoped resolution took precedence.

Fix: Removed the unscoped resolution entirely. Now using only parent-scoped resolutions:

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

Comment threadpackage.json
Comment threadyarn.lock Outdated
Comment on lines 13697 to 13700
"ajv@npm:^8.0.0":
version: 8.17.1
resolution: "ajv@npm:8.17.1"
dependencies:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The fix for the ajv ReDoS vulnerability is incomplete. The ajv-formats package is not covered by the scoped resolutions and still resolves to a vulnerable ajv version.
Severity: HIGH

Suggested Fix

To fully mitigate the vulnerability, either add a specific scoped resolution for ajv-formats like "ajv-formats@npm:2.1.1/ajv": "^8.18.0", or add a global unscoped resolution like "ajv": "^8.18.0" to force all consumers to the patched version.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: yarn.lock#L13697-L13700
Potential issue: The pull request attempts to mitigate a ReDoS vulnerability in the
`ajv` package by adding scoped resolutions to `yarn.lock`. However, this fix is
incomplete. The `ajv-formats` package, a dependency in the project, requires `ajv:
"^8.0.0"` and is not covered by any of the new scoped resolutions. As a result, it
resolves to the vulnerable version `8.17.1` instead of the patched version `8.18.0`.
This leaves the application exposed to the ReDoS vulnerability (CVE-2025-69873) through
any code path that utilizes `ajv-formats`.

…ajv 8.17.1
ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still
resolving to vulnerable 8.17.1. Adding a scoped resolution for
ajv-formats ensures it also gets ajv 8.18.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both new comments:

  • cursor[bot] / sentry[bot]: Correct — ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still resolving to vulnerable 8.17.1.

Fix: Added "ajv-formats@npm:2.1.1/ajv": "^8.18.0" scoped resolution. No more 8.17.1 in the lockfile — all 8.x consumers now resolve to 8.18.0, and all 6.x (eslint) consumers resolve to 6.14.0.

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) February 27, 2026 14:21

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! once when tests are green

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman

Copy link
Copy Markdown
Collaborator

@antonis should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@antonis
antonis disabled auto-merge February 27, 2026 14:56
@antonis

antonis commented Feb 27, 2026

Copy link
Copy Markdown
ContributorAuthor

should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@lucas-zimerman I'm not sure. We already have 10.40.0 with #5715 but the sec alert is still open.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) March 2, 2026 15:46

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor
Fails
🚫Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against e5819e7

@lucas-zimerman
lucas-zimerman merged commit a02d765 into mainMar 2, 2026
33 of 44 checks passed
@lucas-zimerman
lucas-zimerman deleted the antonis/bump-ajv branch March 2, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@antonis@lucas-zimerman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): bump ajv to fix ReDoS in $data option - #5710

Merged
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv
Mar 2, 2026
Merged

chore(deps): bump ajv to fix ReDoS in $data option#5710
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv

Conversation

@antonis

Copy link
Copy Markdown
Contributor

Summary

  • Adds resolutions to fix ReDoS vulnerability when using the $data option in ajv
  • 8.x consumers: bumped appium's exact 8.12.0 pin and all ^8.x consumers to 8.18.0
  • 6.x consumers (eslint, @eslint/eslintrc): consolidated onto 8.18.0 via unscoped resolution — build and tests pass with ajv 8.x

Dependabot alerts

Test plan

  • yarn install resolves all ajv consumers to 8.18.0
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump ajv to fix ReDoS in $data option by antonis in #5710
  • chore(deps): update CLI to v3.2.3 by github-actions in #5743
  • Fixes the issue with unit mismatch in adjustTransactionDuration by alwx in #5740
  • Handle inactive state for spans by alwx in #5742
  • chore(deps): bump actions/github-script from 7 to 8 by dependabot in #5737
  • chore(deps): bump actions/upload-artifact from 6 to 7 by dependabot in #5739
  • chore(deps): bump futureware-tech/simulator-action from 4 to 5 by dependabot in #5735
  • chore(deps): bump actions/download-artifact from 7 to 8 by dependabot in #5736
  • chore(deps): bump path-to-regexp to 0.1.12 by antonis in #5706
  • fix(ios): resolve relative SOURCEMAP_FILE against project root in Xcode build script by antonis in #5730
  • test(metro): Add type tests for SentryExpoConfigOptions.getDefaultConfig by antonis in #5733
  • chore(deps): bump axios to ^1.13.5 by antonis in #5708
  • chore(deps): bump on-headers to ^1.1.0 by antonis in #5704
  • chore(deps): bump dottie from 2.0.6 to 2.0.7 by dependabot in #5731
  • Cirrus Labs runners for other important workflows (where it makes sense to do so) + Ubuntu update (22.04 -> 24.04) by alwx in #5696
  • chore(deps): bump diff to ^5.2.2 by antonis in #5705
  • chore(deps): update Bundler Plugins to v5.1.1 by github-actions in #5700
  • chore(deps): update JavaScript SDK to v10.40.0 by github-actions in #5715
  • ci: Cancel in-progress CI jobs when a PR is closed or merged by antonis in #5725

🤖 This preview updates automatically when you update the PR.

@antonisantonis mentioned this pull request Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time1210.85 ms1217.55 ms6.70 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1229.13 ms1228.46 ms-0.67 ms
80e4616+dirty1221.32 ms1225.64 ms4.32 ms
818a608+dirty1205.76 ms1208.00 ms2.24 ms
77061ed+dirty1233.16 ms1234.88 ms1.71 ms
bef3709+dirty1222.07 ms1220.24 ms-1.83 ms
a206511+dirty1185.00 ms1186.35 ms1.35 ms
74979ac+dirty1210.49 ms1213.31 ms2.82 ms
a2bb688+dirty1223.53 ms1232.90 ms9.37 ms
8a868fe+dirty1221.50 ms1230.78 ms9.28 ms
d590428+dirty1211.77 ms1220.51 ms8.75 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty2.63 MiB3.91 MiB1.28 MiB
77061ed+dirty2.63 MiB3.98 MiB1.34 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty2.63 MiB3.99 MiB1.36 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1216.40 ms1212.08 ms-4.32 ms
cddbba5+dirty1218.63 ms1220.67 ms2.04 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonis
antonis marked this pull request as ready for review February 24, 2026 13:07
Comment threadpackage.json
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time416.26 ms433.42 ms17.16 ms
Size43.75 MiB48.46 MiB4.71 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
86584b7+dirty463.83 ms500.31 ms36.48 ms
9a81842+dirty412.23 ms416.56 ms4.33 ms
c637fc7+dirty433.70 ms467.76 ms34.06 ms
d73150f+dirty411.21 ms465.86 ms54.65 ms
fa7bb7e+dirty350.37 ms377.02 ms26.65 ms
3bd3f0d+dirty447.21 ms472.31 ms25.10 ms
88890fe+dirty350.94 ms365.74 ms14.80 ms
95aaf8a437.89 ms419.45 ms-18.44 ms
c0842e7+dirty527.76 ms566.69 ms38.93 ms
1e7a472+dirty348.80 ms362.55 ms13.75 ms

App size

RevisionPlainWith SentryDiff
86584b7+dirty43.75 MiB48.08 MiB4.33 MiB
9a81842+dirty43.75 MiB48.08 MiB4.33 MiB
c637fc7+dirty43.75 MiB48.40 MiB4.64 MiB
d73150f+dirty43.75 MiB48.55 MiB4.80 MiB
fa7bb7e+dirty17.75 MiB19.75 MiB2.00 MiB
3bd3f0d+dirty17.75 MiB19.70 MiB1.95 MiB
88890fe+dirty17.75 MiB19.71 MiB1.96 MiB
95aaf8a17.75 MiB19.68 MiB1.93 MiB
c0842e7+dirty43.75 MiB48.41 MiB4.66 MiB
1e7a472+dirty17.75 MiB19.70 MiB1.96 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty395.96 ms423.90 ms27.94 ms
cddbba5+dirty387.39 ms446.46 ms59.07 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.75 MiB48.46 MiB4.71 MiB
cddbba5+dirty43.75 MiB48.46 MiB4.71 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time438.00 ms477.32 ms39.32 ms
Size43.94 MiB49.34 MiB5.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
7480abe+dirty363.80 ms431.34 ms67.54 ms
2b89ce9+dirty372.22 ms417.06 ms44.84 ms
170d5ea+dirty348.79 ms406.94 ms58.15 ms
b1579bc+dirty391.87 ms456.26 ms64.39 ms
73f2455+dirty369.33 ms398.90 ms29.57 ms
0b64753+dirty358.55 ms429.16 ms70.61 ms
6a70a7e+dirty382.45 ms424.54 ms42.09 ms
2adbd1e+dirty366.13 ms419.49 ms53.36 ms
f8d19f8+dirty374.17 ms383.40 ms9.23 ms
7be1f99+dirty369.02 ms399.60 ms30.58 ms

App size

RevisionPlainWith SentryDiff
7480abe+dirty7.15 MiB8.41 MiB1.26 MiB
2b89ce9+dirty7.15 MiB8.41 MiB1.26 MiB
170d5ea+dirty7.15 MiB8.42 MiB1.27 MiB
b1579bc+dirty43.94 MiB49.27 MiB5.33 MiB
73f2455+dirty43.94 MiB48.82 MiB4.88 MiB
0b64753+dirty7.15 MiB8.42 MiB1.27 MiB
6a70a7e+dirty7.15 MiB8.42 MiB1.26 MiB
2adbd1e+dirty7.15 MiB8.43 MiB1.28 MiB
f8d19f8+dirty43.94 MiB48.91 MiB4.97 MiB
7be1f99+dirty7.15 MiB8.42 MiB1.27 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty365.94 ms393.20 ms27.27 ms
cddbba5+dirty434.37 ms478.51 ms44.14 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.94 MiB49.33 MiB5.39 MiB
cddbba5+dirty43.94 MiB49.34 MiB5.40 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time1226.06 ms1226.24 ms0.18 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1216.61 ms1214.15 ms-2.47 ms
80e4616+dirty1206.90 ms1205.94 ms-0.96 ms
818a608+dirty1218.84 ms1223.18 ms4.34 ms
77061ed+dirty1210.77 ms1218.45 ms7.68 ms
bef3709+dirty1217.79 ms1225.33 ms7.54 ms
a206511+dirty1225.02 ms1223.74 ms-1.28 ms
74979ac+dirty1212.33 ms1212.54 ms0.21 ms
a2bb688+dirty1244.82 ms1238.60 ms-6.22 ms
8a868fe+dirty1206.85 ms1215.04 ms8.19 ms
d590428+dirty1221.23 ms1225.27 ms4.03 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty3.19 MiB4.48 MiB1.29 MiB
77061ed+dirty3.19 MiB4.54 MiB1.36 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty3.19 MiB4.56 MiB1.37 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1207.61 ms1209.47 ms1.86 ms
cddbba5+dirty1207.78 ms1210.07 ms2.29 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 26, 2026
Comment threadpackage.json Outdated
Uses scoped yarn resolutions to bump ajv:
- eslint/eslintrc consumers: 6.12.6 → 6.14.0 (fixes alert #423)
- appium, detox, expo-dev-launcher: → 8.18.0 (fixes alert #424)
Parent-scoped resolutions avoid the unscoped override that would force
eslint onto incompatible ajv v8.
https://github.com/getsentry/sentry-react-native/security/dependabot/423https://github.com/getsentry/sentry-react-native/security/dependabot/424
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both review comments:

  • sentry[bot]: Correct — the unscoped "ajv": "^8.18.0" was overriding the parent-scoped 6.x resolutions, forcing eslint onto incompatible ajv v8. This broke yarn lint:lerna with TypeError: Cannot set properties of undefined (setting 'defaultMeta').
  • cursor[bot]: Also correct — the scoped eslint resolutions were dead code because the unscoped resolution took precedence.

Fix: Removed the unscoped resolution entirely. Now using only parent-scoped resolutions:

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

Comment threadpackage.json
Comment threadyarn.lock Outdated
Comment on lines 13697 to 13700
"ajv@npm:^8.0.0":
version: 8.17.1
resolution: "ajv@npm:8.17.1"
dependencies:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The fix for the ajv ReDoS vulnerability is incomplete. The ajv-formats package is not covered by the scoped resolutions and still resolves to a vulnerable ajv version.
Severity: HIGH

Suggested Fix

To fully mitigate the vulnerability, either add a specific scoped resolution for ajv-formats like "ajv-formats@npm:2.1.1/ajv": "^8.18.0", or add a global unscoped resolution like "ajv": "^8.18.0" to force all consumers to the patched version.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: yarn.lock#L13697-L13700
Potential issue: The pull request attempts to mitigate a ReDoS vulnerability in the
`ajv` package by adding scoped resolutions to `yarn.lock`. However, this fix is
incomplete. The `ajv-formats` package, a dependency in the project, requires `ajv:
"^8.0.0"` and is not covered by any of the new scoped resolutions. As a result, it
resolves to the vulnerable version `8.17.1` instead of the patched version `8.18.0`.
This leaves the application exposed to the ReDoS vulnerability (CVE-2025-69873) through
any code path that utilizes `ajv-formats`.

…ajv 8.17.1
ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still
resolving to vulnerable 8.17.1. Adding a scoped resolution for
ajv-formats ensures it also gets ajv 8.18.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both new comments:

  • cursor[bot] / sentry[bot]: Correct — ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still resolving to vulnerable 8.17.1.

Fix: Added "ajv-formats@npm:2.1.1/ajv": "^8.18.0" scoped resolution. No more 8.17.1 in the lockfile — all 8.x consumers now resolve to 8.18.0, and all 6.x (eslint) consumers resolve to 6.14.0.

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) February 27, 2026 14:21

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! once when tests are green

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman

Copy link
Copy Markdown
Collaborator

@antonis should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@antonis
antonis disabled auto-merge February 27, 2026 14:56
@antonis

antonis commented Feb 27, 2026

Copy link
Copy Markdown
ContributorAuthor

should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@lucas-zimerman I'm not sure. We already have 10.40.0 with #5715 but the sec alert is still open.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) March 2, 2026 15:46

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor
Fails
🚫Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against e5819e7

@lucas-zimerman
lucas-zimerman merged commit a02d765 into mainMar 2, 2026
33 of 44 checks passed
@lucas-zimerman
lucas-zimerman deleted the antonis/bump-ajv branch March 2, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@antonis@lucas-zimerman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps): bump ajv to fix ReDoS in $data option - #5710

Merged
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv
Mar 2, 2026
Merged

chore(deps): bump ajv to fix ReDoS in $data option#5710
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv

Conversation

@antonis

Copy link
Copy Markdown
Contributor

Summary

  • Adds resolutions to fix ReDoS vulnerability when using the $data option in ajv
  • 8.x consumers: bumped appium's exact 8.12.0 pin and all ^8.x consumers to 8.18.0
  • 6.x consumers (eslint, @eslint/eslintrc): consolidated onto 8.18.0 via unscoped resolution — build and tests pass with ajv 8.x

Dependabot alerts

Test plan

  • yarn install resolves all ajv consumers to 8.18.0
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump ajv to fix ReDoS in $data option by antonis in #5710
  • chore(deps): update CLI to v3.2.3 by github-actions in #5743
  • Fixes the issue with unit mismatch in adjustTransactionDuration by alwx in #5740
  • Handle inactive state for spans by alwx in #5742
  • chore(deps): bump actions/github-script from 7 to 8 by dependabot in #5737
  • chore(deps): bump actions/upload-artifact from 6 to 7 by dependabot in #5739
  • chore(deps): bump futureware-tech/simulator-action from 4 to 5 by dependabot in #5735
  • chore(deps): bump actions/download-artifact from 7 to 8 by dependabot in #5736
  • chore(deps): bump path-to-regexp to 0.1.12 by antonis in #5706
  • fix(ios): resolve relative SOURCEMAP_FILE against project root in Xcode build script by antonis in #5730
  • test(metro): Add type tests for SentryExpoConfigOptions.getDefaultConfig by antonis in #5733
  • chore(deps): bump axios to ^1.13.5 by antonis in #5708
  • chore(deps): bump on-headers to ^1.1.0 by antonis in #5704
  • chore(deps): bump dottie from 2.0.6 to 2.0.7 by dependabot in #5731
  • Cirrus Labs runners for other important workflows (where it makes sense to do so) + Ubuntu update (22.04 -> 24.04) by alwx in #5696
  • chore(deps): bump diff to ^5.2.2 by antonis in #5705
  • chore(deps): update Bundler Plugins to v5.1.1 by github-actions in #5700
  • chore(deps): update JavaScript SDK to v10.40.0 by github-actions in #5715
  • ci: Cancel in-progress CI jobs when a PR is closed or merged by antonis in #5725

🤖 This preview updates automatically when you update the PR.

@antonisantonis mentioned this pull request Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time1210.85 ms1217.55 ms6.70 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1229.13 ms1228.46 ms-0.67 ms
80e4616+dirty1221.32 ms1225.64 ms4.32 ms
818a608+dirty1205.76 ms1208.00 ms2.24 ms
77061ed+dirty1233.16 ms1234.88 ms1.71 ms
bef3709+dirty1222.07 ms1220.24 ms-1.83 ms
a206511+dirty1185.00 ms1186.35 ms1.35 ms
74979ac+dirty1210.49 ms1213.31 ms2.82 ms
a2bb688+dirty1223.53 ms1232.90 ms9.37 ms
8a868fe+dirty1221.50 ms1230.78 ms9.28 ms
d590428+dirty1211.77 ms1220.51 ms8.75 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty2.63 MiB3.91 MiB1.28 MiB
77061ed+dirty2.63 MiB3.98 MiB1.34 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty2.63 MiB3.99 MiB1.36 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1216.40 ms1212.08 ms-4.32 ms
cddbba5+dirty1218.63 ms1220.67 ms2.04 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonis
antonis marked this pull request as ready for review February 24, 2026 13:07
Comment threadpackage.json
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time416.26 ms433.42 ms17.16 ms
Size43.75 MiB48.46 MiB4.71 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
86584b7+dirty463.83 ms500.31 ms36.48 ms
9a81842+dirty412.23 ms416.56 ms4.33 ms
c637fc7+dirty433.70 ms467.76 ms34.06 ms
d73150f+dirty411.21 ms465.86 ms54.65 ms
fa7bb7e+dirty350.37 ms377.02 ms26.65 ms
3bd3f0d+dirty447.21 ms472.31 ms25.10 ms
88890fe+dirty350.94 ms365.74 ms14.80 ms
95aaf8a437.89 ms419.45 ms-18.44 ms
c0842e7+dirty527.76 ms566.69 ms38.93 ms
1e7a472+dirty348.80 ms362.55 ms13.75 ms

App size

RevisionPlainWith SentryDiff
86584b7+dirty43.75 MiB48.08 MiB4.33 MiB
9a81842+dirty43.75 MiB48.08 MiB4.33 MiB
c637fc7+dirty43.75 MiB48.40 MiB4.64 MiB
d73150f+dirty43.75 MiB48.55 MiB4.80 MiB
fa7bb7e+dirty17.75 MiB19.75 MiB2.00 MiB
3bd3f0d+dirty17.75 MiB19.70 MiB1.95 MiB
88890fe+dirty17.75 MiB19.71 MiB1.96 MiB
95aaf8a17.75 MiB19.68 MiB1.93 MiB
c0842e7+dirty43.75 MiB48.41 MiB4.66 MiB
1e7a472+dirty17.75 MiB19.70 MiB1.96 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty395.96 ms423.90 ms27.94 ms
cddbba5+dirty387.39 ms446.46 ms59.07 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.75 MiB48.46 MiB4.71 MiB
cddbba5+dirty43.75 MiB48.46 MiB4.71 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time438.00 ms477.32 ms39.32 ms
Size43.94 MiB49.34 MiB5.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
7480abe+dirty363.80 ms431.34 ms67.54 ms
2b89ce9+dirty372.22 ms417.06 ms44.84 ms
170d5ea+dirty348.79 ms406.94 ms58.15 ms
b1579bc+dirty391.87 ms456.26 ms64.39 ms
73f2455+dirty369.33 ms398.90 ms29.57 ms
0b64753+dirty358.55 ms429.16 ms70.61 ms
6a70a7e+dirty382.45 ms424.54 ms42.09 ms
2adbd1e+dirty366.13 ms419.49 ms53.36 ms
f8d19f8+dirty374.17 ms383.40 ms9.23 ms
7be1f99+dirty369.02 ms399.60 ms30.58 ms

App size

RevisionPlainWith SentryDiff
7480abe+dirty7.15 MiB8.41 MiB1.26 MiB
2b89ce9+dirty7.15 MiB8.41 MiB1.26 MiB
170d5ea+dirty7.15 MiB8.42 MiB1.27 MiB
b1579bc+dirty43.94 MiB49.27 MiB5.33 MiB
73f2455+dirty43.94 MiB48.82 MiB4.88 MiB
0b64753+dirty7.15 MiB8.42 MiB1.27 MiB
6a70a7e+dirty7.15 MiB8.42 MiB1.26 MiB
2adbd1e+dirty7.15 MiB8.43 MiB1.28 MiB
f8d19f8+dirty43.94 MiB48.91 MiB4.97 MiB
7be1f99+dirty7.15 MiB8.42 MiB1.27 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty365.94 ms393.20 ms27.27 ms
cddbba5+dirty434.37 ms478.51 ms44.14 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.94 MiB49.33 MiB5.39 MiB
cddbba5+dirty43.94 MiB49.34 MiB5.40 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time1226.06 ms1226.24 ms0.18 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1216.61 ms1214.15 ms-2.47 ms
80e4616+dirty1206.90 ms1205.94 ms-0.96 ms
818a608+dirty1218.84 ms1223.18 ms4.34 ms
77061ed+dirty1210.77 ms1218.45 ms7.68 ms
bef3709+dirty1217.79 ms1225.33 ms7.54 ms
a206511+dirty1225.02 ms1223.74 ms-1.28 ms
74979ac+dirty1212.33 ms1212.54 ms0.21 ms
a2bb688+dirty1244.82 ms1238.60 ms-6.22 ms
8a868fe+dirty1206.85 ms1215.04 ms8.19 ms
d590428+dirty1221.23 ms1225.27 ms4.03 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty3.19 MiB4.48 MiB1.29 MiB
77061ed+dirty3.19 MiB4.54 MiB1.36 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty3.19 MiB4.56 MiB1.37 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1207.61 ms1209.47 ms1.86 ms
cddbba5+dirty1207.78 ms1210.07 ms2.29 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 26, 2026
Comment threadpackage.json Outdated
Uses scoped yarn resolutions to bump ajv:
- eslint/eslintrc consumers: 6.12.6 → 6.14.0 (fixes alert #423)
- appium, detox, expo-dev-launcher: → 8.18.0 (fixes alert #424)
Parent-scoped resolutions avoid the unscoped override that would force
eslint onto incompatible ajv v8.
https://github.com/getsentry/sentry-react-native/security/dependabot/423https://github.com/getsentry/sentry-react-native/security/dependabot/424
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both review comments:

  • sentry[bot]: Correct — the unscoped "ajv": "^8.18.0" was overriding the parent-scoped 6.x resolutions, forcing eslint onto incompatible ajv v8. This broke yarn lint:lerna with TypeError: Cannot set properties of undefined (setting 'defaultMeta').
  • cursor[bot]: Also correct — the scoped eslint resolutions were dead code because the unscoped resolution took precedence.

Fix: Removed the unscoped resolution entirely. Now using only parent-scoped resolutions:

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

Comment threadpackage.json
Comment threadyarn.lock Outdated
Comment on lines 13697 to 13700
"ajv@npm:^8.0.0":
version: 8.17.1
resolution: "ajv@npm:8.17.1"
dependencies:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The fix for the ajv ReDoS vulnerability is incomplete. The ajv-formats package is not covered by the scoped resolutions and still resolves to a vulnerable ajv version.
Severity: HIGH

Suggested Fix

To fully mitigate the vulnerability, either add a specific scoped resolution for ajv-formats like "ajv-formats@npm:2.1.1/ajv": "^8.18.0", or add a global unscoped resolution like "ajv": "^8.18.0" to force all consumers to the patched version.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: yarn.lock#L13697-L13700
Potential issue: The pull request attempts to mitigate a ReDoS vulnerability in the
`ajv` package by adding scoped resolutions to `yarn.lock`. However, this fix is
incomplete. The `ajv-formats` package, a dependency in the project, requires `ajv:
"^8.0.0"` and is not covered by any of the new scoped resolutions. As a result, it
resolves to the vulnerable version `8.17.1` instead of the patched version `8.18.0`.
This leaves the application exposed to the ReDoS vulnerability (CVE-2025-69873) through
any code path that utilizes `ajv-formats`.

…ajv 8.17.1
ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still
resolving to vulnerable 8.17.1. Adding a scoped resolution for
ajv-formats ensures it also gets ajv 8.18.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both new comments:

  • cursor[bot] / sentry[bot]: Correct — ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still resolving to vulnerable 8.17.1.

Fix: Added "ajv-formats@npm:2.1.1/ajv": "^8.18.0" scoped resolution. No more 8.17.1 in the lockfile — all 8.x consumers now resolve to 8.18.0, and all 6.x (eslint) consumers resolve to 6.14.0.

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) February 27, 2026 14:21

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! once when tests are green

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman

Copy link
Copy Markdown
Collaborator

@antonis should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@antonis
antonis disabled auto-merge February 27, 2026 14:56
@antonis

antonis commented Feb 27, 2026

Copy link
Copy Markdown
ContributorAuthor

should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@lucas-zimerman I'm not sure. We already have 10.40.0 with #5715 but the sec alert is still open.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) March 2, 2026 15:46

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor
Fails
🚫Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against e5819e7

@lucas-zimerman
lucas-zimerman merged commit a02d765 into mainMar 2, 2026
33 of 44 checks passed
@lucas-zimerman
lucas-zimerman deleted the antonis/bump-ajv branch March 2, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@antonis@lucas-zimerman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): bump ajv to fix ReDoS in $data option - #5710

Merged
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv
Mar 2, 2026
Merged

chore(deps): bump ajv to fix ReDoS in $data option#5710
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv

Conversation

@antonis

Copy link
Copy Markdown
Contributor

Summary

  • Adds resolutions to fix ReDoS vulnerability when using the $data option in ajv
  • 8.x consumers: bumped appium's exact 8.12.0 pin and all ^8.x consumers to 8.18.0
  • 6.x consumers (eslint, @eslint/eslintrc): consolidated onto 8.18.0 via unscoped resolution — build and tests pass with ajv 8.x

Dependabot alerts

Test plan

  • yarn install resolves all ajv consumers to 8.18.0
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump ajv to fix ReDoS in $data option by antonis in #5710
  • chore(deps): update CLI to v3.2.3 by github-actions in #5743
  • Fixes the issue with unit mismatch in adjustTransactionDuration by alwx in #5740
  • Handle inactive state for spans by alwx in #5742
  • chore(deps): bump actions/github-script from 7 to 8 by dependabot in #5737
  • chore(deps): bump actions/upload-artifact from 6 to 7 by dependabot in #5739
  • chore(deps): bump futureware-tech/simulator-action from 4 to 5 by dependabot in #5735
  • chore(deps): bump actions/download-artifact from 7 to 8 by dependabot in #5736
  • chore(deps): bump path-to-regexp to 0.1.12 by antonis in #5706
  • fix(ios): resolve relative SOURCEMAP_FILE against project root in Xcode build script by antonis in #5730
  • test(metro): Add type tests for SentryExpoConfigOptions.getDefaultConfig by antonis in #5733
  • chore(deps): bump axios to ^1.13.5 by antonis in #5708
  • chore(deps): bump on-headers to ^1.1.0 by antonis in #5704
  • chore(deps): bump dottie from 2.0.6 to 2.0.7 by dependabot in #5731
  • Cirrus Labs runners for other important workflows (where it makes sense to do so) + Ubuntu update (22.04 -> 24.04) by alwx in #5696
  • chore(deps): bump diff to ^5.2.2 by antonis in #5705
  • chore(deps): update Bundler Plugins to v5.1.1 by github-actions in #5700
  • chore(deps): update JavaScript SDK to v10.40.0 by github-actions in #5715
  • ci: Cancel in-progress CI jobs when a PR is closed or merged by antonis in #5725

🤖 This preview updates automatically when you update the PR.

@antonisantonis mentioned this pull request Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time1210.85 ms1217.55 ms6.70 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1229.13 ms1228.46 ms-0.67 ms
80e4616+dirty1221.32 ms1225.64 ms4.32 ms
818a608+dirty1205.76 ms1208.00 ms2.24 ms
77061ed+dirty1233.16 ms1234.88 ms1.71 ms
bef3709+dirty1222.07 ms1220.24 ms-1.83 ms
a206511+dirty1185.00 ms1186.35 ms1.35 ms
74979ac+dirty1210.49 ms1213.31 ms2.82 ms
a2bb688+dirty1223.53 ms1232.90 ms9.37 ms
8a868fe+dirty1221.50 ms1230.78 ms9.28 ms
d590428+dirty1211.77 ms1220.51 ms8.75 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty2.63 MiB3.91 MiB1.28 MiB
77061ed+dirty2.63 MiB3.98 MiB1.34 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty2.63 MiB3.99 MiB1.36 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1216.40 ms1212.08 ms-4.32 ms
cddbba5+dirty1218.63 ms1220.67 ms2.04 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonis
antonis marked this pull request as ready for review February 24, 2026 13:07
Comment threadpackage.json
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time416.26 ms433.42 ms17.16 ms
Size43.75 MiB48.46 MiB4.71 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
86584b7+dirty463.83 ms500.31 ms36.48 ms
9a81842+dirty412.23 ms416.56 ms4.33 ms
c637fc7+dirty433.70 ms467.76 ms34.06 ms
d73150f+dirty411.21 ms465.86 ms54.65 ms
fa7bb7e+dirty350.37 ms377.02 ms26.65 ms
3bd3f0d+dirty447.21 ms472.31 ms25.10 ms
88890fe+dirty350.94 ms365.74 ms14.80 ms
95aaf8a437.89 ms419.45 ms-18.44 ms
c0842e7+dirty527.76 ms566.69 ms38.93 ms
1e7a472+dirty348.80 ms362.55 ms13.75 ms

App size

RevisionPlainWith SentryDiff
86584b7+dirty43.75 MiB48.08 MiB4.33 MiB
9a81842+dirty43.75 MiB48.08 MiB4.33 MiB
c637fc7+dirty43.75 MiB48.40 MiB4.64 MiB
d73150f+dirty43.75 MiB48.55 MiB4.80 MiB
fa7bb7e+dirty17.75 MiB19.75 MiB2.00 MiB
3bd3f0d+dirty17.75 MiB19.70 MiB1.95 MiB
88890fe+dirty17.75 MiB19.71 MiB1.96 MiB
95aaf8a17.75 MiB19.68 MiB1.93 MiB
c0842e7+dirty43.75 MiB48.41 MiB4.66 MiB
1e7a472+dirty17.75 MiB19.70 MiB1.96 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty395.96 ms423.90 ms27.94 ms
cddbba5+dirty387.39 ms446.46 ms59.07 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.75 MiB48.46 MiB4.71 MiB
cddbba5+dirty43.75 MiB48.46 MiB4.71 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time438.00 ms477.32 ms39.32 ms
Size43.94 MiB49.34 MiB5.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
7480abe+dirty363.80 ms431.34 ms67.54 ms
2b89ce9+dirty372.22 ms417.06 ms44.84 ms
170d5ea+dirty348.79 ms406.94 ms58.15 ms
b1579bc+dirty391.87 ms456.26 ms64.39 ms
73f2455+dirty369.33 ms398.90 ms29.57 ms
0b64753+dirty358.55 ms429.16 ms70.61 ms
6a70a7e+dirty382.45 ms424.54 ms42.09 ms
2adbd1e+dirty366.13 ms419.49 ms53.36 ms
f8d19f8+dirty374.17 ms383.40 ms9.23 ms
7be1f99+dirty369.02 ms399.60 ms30.58 ms

App size

RevisionPlainWith SentryDiff
7480abe+dirty7.15 MiB8.41 MiB1.26 MiB
2b89ce9+dirty7.15 MiB8.41 MiB1.26 MiB
170d5ea+dirty7.15 MiB8.42 MiB1.27 MiB
b1579bc+dirty43.94 MiB49.27 MiB5.33 MiB
73f2455+dirty43.94 MiB48.82 MiB4.88 MiB
0b64753+dirty7.15 MiB8.42 MiB1.27 MiB
6a70a7e+dirty7.15 MiB8.42 MiB1.26 MiB
2adbd1e+dirty7.15 MiB8.43 MiB1.28 MiB
f8d19f8+dirty43.94 MiB48.91 MiB4.97 MiB
7be1f99+dirty7.15 MiB8.42 MiB1.27 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty365.94 ms393.20 ms27.27 ms
cddbba5+dirty434.37 ms478.51 ms44.14 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.94 MiB49.33 MiB5.39 MiB
cddbba5+dirty43.94 MiB49.34 MiB5.40 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time1226.06 ms1226.24 ms0.18 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1216.61 ms1214.15 ms-2.47 ms
80e4616+dirty1206.90 ms1205.94 ms-0.96 ms
818a608+dirty1218.84 ms1223.18 ms4.34 ms
77061ed+dirty1210.77 ms1218.45 ms7.68 ms
bef3709+dirty1217.79 ms1225.33 ms7.54 ms
a206511+dirty1225.02 ms1223.74 ms-1.28 ms
74979ac+dirty1212.33 ms1212.54 ms0.21 ms
a2bb688+dirty1244.82 ms1238.60 ms-6.22 ms
8a868fe+dirty1206.85 ms1215.04 ms8.19 ms
d590428+dirty1221.23 ms1225.27 ms4.03 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty3.19 MiB4.48 MiB1.29 MiB
77061ed+dirty3.19 MiB4.54 MiB1.36 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty3.19 MiB4.56 MiB1.37 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1207.61 ms1209.47 ms1.86 ms
cddbba5+dirty1207.78 ms1210.07 ms2.29 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 26, 2026
Comment threadpackage.json Outdated
Uses scoped yarn resolutions to bump ajv:
- eslint/eslintrc consumers: 6.12.6 → 6.14.0 (fixes alert #423)
- appium, detox, expo-dev-launcher: → 8.18.0 (fixes alert #424)
Parent-scoped resolutions avoid the unscoped override that would force
eslint onto incompatible ajv v8.
https://github.com/getsentry/sentry-react-native/security/dependabot/423https://github.com/getsentry/sentry-react-native/security/dependabot/424
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both review comments:

  • sentry[bot]: Correct — the unscoped "ajv": "^8.18.0" was overriding the parent-scoped 6.x resolutions, forcing eslint onto incompatible ajv v8. This broke yarn lint:lerna with TypeError: Cannot set properties of undefined (setting 'defaultMeta').
  • cursor[bot]: Also correct — the scoped eslint resolutions were dead code because the unscoped resolution took precedence.

Fix: Removed the unscoped resolution entirely. Now using only parent-scoped resolutions:

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

Comment threadpackage.json
Comment threadyarn.lock Outdated
Comment on lines 13697 to 13700
"ajv@npm:^8.0.0":
version: 8.17.1
resolution: "ajv@npm:8.17.1"
dependencies:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The fix for the ajv ReDoS vulnerability is incomplete. The ajv-formats package is not covered by the scoped resolutions and still resolves to a vulnerable ajv version.
Severity: HIGH

Suggested Fix

To fully mitigate the vulnerability, either add a specific scoped resolution for ajv-formats like "ajv-formats@npm:2.1.1/ajv": "^8.18.0", or add a global unscoped resolution like "ajv": "^8.18.0" to force all consumers to the patched version.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: yarn.lock#L13697-L13700
Potential issue: The pull request attempts to mitigate a ReDoS vulnerability in the
`ajv` package by adding scoped resolutions to `yarn.lock`. However, this fix is
incomplete. The `ajv-formats` package, a dependency in the project, requires `ajv:
"^8.0.0"` and is not covered by any of the new scoped resolutions. As a result, it
resolves to the vulnerable version `8.17.1` instead of the patched version `8.18.0`.
This leaves the application exposed to the ReDoS vulnerability (CVE-2025-69873) through
any code path that utilizes `ajv-formats`.

…ajv 8.17.1
ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still
resolving to vulnerable 8.17.1. Adding a scoped resolution for
ajv-formats ensures it also gets ajv 8.18.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both new comments:

  • cursor[bot] / sentry[bot]: Correct — ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still resolving to vulnerable 8.17.1.

Fix: Added "ajv-formats@npm:2.1.1/ajv": "^8.18.0" scoped resolution. No more 8.17.1 in the lockfile — all 8.x consumers now resolve to 8.18.0, and all 6.x (eslint) consumers resolve to 6.14.0.

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) February 27, 2026 14:21

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! once when tests are green

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman

Copy link
Copy Markdown
Collaborator

@antonis should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@antonis
antonis disabled auto-merge February 27, 2026 14:56
@antonis

antonis commented Feb 27, 2026

Copy link
Copy Markdown
ContributorAuthor

should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@lucas-zimerman I'm not sure. We already have 10.40.0 with #5715 but the sec alert is still open.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) March 2, 2026 15:46

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor
Fails
🚫Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against e5819e7

@lucas-zimerman
lucas-zimerman merged commit a02d765 into mainMar 2, 2026
33 of 44 checks passed
@lucas-zimerman
lucas-zimerman deleted the antonis/bump-ajv branch March 2, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@antonis@lucas-zimerman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): bump ajv to fix ReDoS in $data option - #5710

Merged
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv
Mar 2, 2026
Merged

chore(deps): bump ajv to fix ReDoS in $data option#5710
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv

Conversation

@antonis

Copy link
Copy Markdown
Contributor

Summary

  • Adds resolutions to fix ReDoS vulnerability when using the $data option in ajv
  • 8.x consumers: bumped appium's exact 8.12.0 pin and all ^8.x consumers to 8.18.0
  • 6.x consumers (eslint, @eslint/eslintrc): consolidated onto 8.18.0 via unscoped resolution — build and tests pass with ajv 8.x

Dependabot alerts

Test plan

  • yarn install resolves all ajv consumers to 8.18.0
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump ajv to fix ReDoS in $data option by antonis in #5710
  • chore(deps): update CLI to v3.2.3 by github-actions in #5743
  • Fixes the issue with unit mismatch in adjustTransactionDuration by alwx in #5740
  • Handle inactive state for spans by alwx in #5742
  • chore(deps): bump actions/github-script from 7 to 8 by dependabot in #5737
  • chore(deps): bump actions/upload-artifact from 6 to 7 by dependabot in #5739
  • chore(deps): bump futureware-tech/simulator-action from 4 to 5 by dependabot in #5735
  • chore(deps): bump actions/download-artifact from 7 to 8 by dependabot in #5736
  • chore(deps): bump path-to-regexp to 0.1.12 by antonis in #5706
  • fix(ios): resolve relative SOURCEMAP_FILE against project root in Xcode build script by antonis in #5730
  • test(metro): Add type tests for SentryExpoConfigOptions.getDefaultConfig by antonis in #5733
  • chore(deps): bump axios to ^1.13.5 by antonis in #5708
  • chore(deps): bump on-headers to ^1.1.0 by antonis in #5704
  • chore(deps): bump dottie from 2.0.6 to 2.0.7 by dependabot in #5731
  • Cirrus Labs runners for other important workflows (where it makes sense to do so) + Ubuntu update (22.04 -> 24.04) by alwx in #5696
  • chore(deps): bump diff to ^5.2.2 by antonis in #5705
  • chore(deps): update Bundler Plugins to v5.1.1 by github-actions in #5700
  • chore(deps): update JavaScript SDK to v10.40.0 by github-actions in #5715
  • ci: Cancel in-progress CI jobs when a PR is closed or merged by antonis in #5725

🤖 This preview updates automatically when you update the PR.

@antonisantonis mentioned this pull request Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time1210.85 ms1217.55 ms6.70 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1229.13 ms1228.46 ms-0.67 ms
80e4616+dirty1221.32 ms1225.64 ms4.32 ms
818a608+dirty1205.76 ms1208.00 ms2.24 ms
77061ed+dirty1233.16 ms1234.88 ms1.71 ms
bef3709+dirty1222.07 ms1220.24 ms-1.83 ms
a206511+dirty1185.00 ms1186.35 ms1.35 ms
74979ac+dirty1210.49 ms1213.31 ms2.82 ms
a2bb688+dirty1223.53 ms1232.90 ms9.37 ms
8a868fe+dirty1221.50 ms1230.78 ms9.28 ms
d590428+dirty1211.77 ms1220.51 ms8.75 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty2.63 MiB3.91 MiB1.28 MiB
77061ed+dirty2.63 MiB3.98 MiB1.34 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty2.63 MiB3.99 MiB1.36 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1216.40 ms1212.08 ms-4.32 ms
cddbba5+dirty1218.63 ms1220.67 ms2.04 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonis
antonis marked this pull request as ready for review February 24, 2026 13:07
Comment threadpackage.json
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time416.26 ms433.42 ms17.16 ms
Size43.75 MiB48.46 MiB4.71 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
86584b7+dirty463.83 ms500.31 ms36.48 ms
9a81842+dirty412.23 ms416.56 ms4.33 ms
c637fc7+dirty433.70 ms467.76 ms34.06 ms
d73150f+dirty411.21 ms465.86 ms54.65 ms
fa7bb7e+dirty350.37 ms377.02 ms26.65 ms
3bd3f0d+dirty447.21 ms472.31 ms25.10 ms
88890fe+dirty350.94 ms365.74 ms14.80 ms
95aaf8a437.89 ms419.45 ms-18.44 ms
c0842e7+dirty527.76 ms566.69 ms38.93 ms
1e7a472+dirty348.80 ms362.55 ms13.75 ms

App size

RevisionPlainWith SentryDiff
86584b7+dirty43.75 MiB48.08 MiB4.33 MiB
9a81842+dirty43.75 MiB48.08 MiB4.33 MiB
c637fc7+dirty43.75 MiB48.40 MiB4.64 MiB
d73150f+dirty43.75 MiB48.55 MiB4.80 MiB
fa7bb7e+dirty17.75 MiB19.75 MiB2.00 MiB
3bd3f0d+dirty17.75 MiB19.70 MiB1.95 MiB
88890fe+dirty17.75 MiB19.71 MiB1.96 MiB
95aaf8a17.75 MiB19.68 MiB1.93 MiB
c0842e7+dirty43.75 MiB48.41 MiB4.66 MiB
1e7a472+dirty17.75 MiB19.70 MiB1.96 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty395.96 ms423.90 ms27.94 ms
cddbba5+dirty387.39 ms446.46 ms59.07 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.75 MiB48.46 MiB4.71 MiB
cddbba5+dirty43.75 MiB48.46 MiB4.71 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time438.00 ms477.32 ms39.32 ms
Size43.94 MiB49.34 MiB5.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
7480abe+dirty363.80 ms431.34 ms67.54 ms
2b89ce9+dirty372.22 ms417.06 ms44.84 ms
170d5ea+dirty348.79 ms406.94 ms58.15 ms
b1579bc+dirty391.87 ms456.26 ms64.39 ms
73f2455+dirty369.33 ms398.90 ms29.57 ms
0b64753+dirty358.55 ms429.16 ms70.61 ms
6a70a7e+dirty382.45 ms424.54 ms42.09 ms
2adbd1e+dirty366.13 ms419.49 ms53.36 ms
f8d19f8+dirty374.17 ms383.40 ms9.23 ms
7be1f99+dirty369.02 ms399.60 ms30.58 ms

App size

RevisionPlainWith SentryDiff
7480abe+dirty7.15 MiB8.41 MiB1.26 MiB
2b89ce9+dirty7.15 MiB8.41 MiB1.26 MiB
170d5ea+dirty7.15 MiB8.42 MiB1.27 MiB
b1579bc+dirty43.94 MiB49.27 MiB5.33 MiB
73f2455+dirty43.94 MiB48.82 MiB4.88 MiB
0b64753+dirty7.15 MiB8.42 MiB1.27 MiB
6a70a7e+dirty7.15 MiB8.42 MiB1.26 MiB
2adbd1e+dirty7.15 MiB8.43 MiB1.28 MiB
f8d19f8+dirty43.94 MiB48.91 MiB4.97 MiB
7be1f99+dirty7.15 MiB8.42 MiB1.27 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty365.94 ms393.20 ms27.27 ms
cddbba5+dirty434.37 ms478.51 ms44.14 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.94 MiB49.33 MiB5.39 MiB
cddbba5+dirty43.94 MiB49.34 MiB5.40 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time1226.06 ms1226.24 ms0.18 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1216.61 ms1214.15 ms-2.47 ms
80e4616+dirty1206.90 ms1205.94 ms-0.96 ms
818a608+dirty1218.84 ms1223.18 ms4.34 ms
77061ed+dirty1210.77 ms1218.45 ms7.68 ms
bef3709+dirty1217.79 ms1225.33 ms7.54 ms
a206511+dirty1225.02 ms1223.74 ms-1.28 ms
74979ac+dirty1212.33 ms1212.54 ms0.21 ms
a2bb688+dirty1244.82 ms1238.60 ms-6.22 ms
8a868fe+dirty1206.85 ms1215.04 ms8.19 ms
d590428+dirty1221.23 ms1225.27 ms4.03 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty3.19 MiB4.48 MiB1.29 MiB
77061ed+dirty3.19 MiB4.54 MiB1.36 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty3.19 MiB4.56 MiB1.37 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1207.61 ms1209.47 ms1.86 ms
cddbba5+dirty1207.78 ms1210.07 ms2.29 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 26, 2026
Comment threadpackage.json Outdated
Uses scoped yarn resolutions to bump ajv:
- eslint/eslintrc consumers: 6.12.6 → 6.14.0 (fixes alert #423)
- appium, detox, expo-dev-launcher: → 8.18.0 (fixes alert #424)
Parent-scoped resolutions avoid the unscoped override that would force
eslint onto incompatible ajv v8.
https://github.com/getsentry/sentry-react-native/security/dependabot/423https://github.com/getsentry/sentry-react-native/security/dependabot/424
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both review comments:

  • sentry[bot]: Correct — the unscoped "ajv": "^8.18.0" was overriding the parent-scoped 6.x resolutions, forcing eslint onto incompatible ajv v8. This broke yarn lint:lerna with TypeError: Cannot set properties of undefined (setting 'defaultMeta').
  • cursor[bot]: Also correct — the scoped eslint resolutions were dead code because the unscoped resolution took precedence.

Fix: Removed the unscoped resolution entirely. Now using only parent-scoped resolutions:

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

Comment threadpackage.json
Comment threadyarn.lock Outdated
Comment on lines 13697 to 13700
"ajv@npm:^8.0.0":
version: 8.17.1
resolution: "ajv@npm:8.17.1"
dependencies:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The fix for the ajv ReDoS vulnerability is incomplete. The ajv-formats package is not covered by the scoped resolutions and still resolves to a vulnerable ajv version.
Severity: HIGH

Suggested Fix

To fully mitigate the vulnerability, either add a specific scoped resolution for ajv-formats like "ajv-formats@npm:2.1.1/ajv": "^8.18.0", or add a global unscoped resolution like "ajv": "^8.18.0" to force all consumers to the patched version.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: yarn.lock#L13697-L13700
Potential issue: The pull request attempts to mitigate a ReDoS vulnerability in the
`ajv` package by adding scoped resolutions to `yarn.lock`. However, this fix is
incomplete. The `ajv-formats` package, a dependency in the project, requires `ajv:
"^8.0.0"` and is not covered by any of the new scoped resolutions. As a result, it
resolves to the vulnerable version `8.17.1` instead of the patched version `8.18.0`.
This leaves the application exposed to the ReDoS vulnerability (CVE-2025-69873) through
any code path that utilizes `ajv-formats`.

…ajv 8.17.1
ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still
resolving to vulnerable 8.17.1. Adding a scoped resolution for
ajv-formats ensures it also gets ajv 8.18.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both new comments:

  • cursor[bot] / sentry[bot]: Correct — ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still resolving to vulnerable 8.17.1.

Fix: Added "ajv-formats@npm:2.1.1/ajv": "^8.18.0" scoped resolution. No more 8.17.1 in the lockfile — all 8.x consumers now resolve to 8.18.0, and all 6.x (eslint) consumers resolve to 6.14.0.

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) February 27, 2026 14:21

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! once when tests are green

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman

Copy link
Copy Markdown
Collaborator

@antonis should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@antonis
antonis disabled auto-merge February 27, 2026 14:56
@antonis

antonis commented Feb 27, 2026

Copy link
Copy Markdown
ContributorAuthor

should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@lucas-zimerman I'm not sure. We already have 10.40.0 with #5715 but the sec alert is still open.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) March 2, 2026 15:46

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor
Fails
🚫Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against e5819e7

@lucas-zimerman
lucas-zimerman merged commit a02d765 into mainMar 2, 2026
33 of 44 checks passed
@lucas-zimerman
lucas-zimerman deleted the antonis/bump-ajv branch March 2, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@antonis@lucas-zimerman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps): bump ajv to fix ReDoS in $data option - #5710

Merged
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv
Mar 2, 2026
Merged

chore(deps): bump ajv to fix ReDoS in $data option#5710
lucas-zimerman merged 9 commits into
mainfrom
antonis/bump-ajv

Conversation

@antonis

Copy link
Copy Markdown
Contributor

Summary

  • Adds resolutions to fix ReDoS vulnerability when using the $data option in ajv
  • 8.x consumers: bumped appium's exact 8.12.0 pin and all ^8.x consumers to 8.18.0
  • 6.x consumers (eslint, @eslint/eslintrc): consolidated onto 8.18.0 via unscoped resolution — build and tests pass with ajv 8.x

Dependabot alerts

Test plan

  • yarn install resolves all ajv consumers to 8.18.0
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump ajv to fix ReDoS in $data option by antonis in #5710
  • chore(deps): update CLI to v3.2.3 by github-actions in #5743
  • Fixes the issue with unit mismatch in adjustTransactionDuration by alwx in #5740
  • Handle inactive state for spans by alwx in #5742
  • chore(deps): bump actions/github-script from 7 to 8 by dependabot in #5737
  • chore(deps): bump actions/upload-artifact from 6 to 7 by dependabot in #5739
  • chore(deps): bump futureware-tech/simulator-action from 4 to 5 by dependabot in #5735
  • chore(deps): bump actions/download-artifact from 7 to 8 by dependabot in #5736
  • chore(deps): bump path-to-regexp to 0.1.12 by antonis in #5706
  • fix(ios): resolve relative SOURCEMAP_FILE against project root in Xcode build script by antonis in #5730
  • test(metro): Add type tests for SentryExpoConfigOptions.getDefaultConfig by antonis in #5733
  • chore(deps): bump axios to ^1.13.5 by antonis in #5708
  • chore(deps): bump on-headers to ^1.1.0 by antonis in #5704
  • chore(deps): bump dottie from 2.0.6 to 2.0.7 by dependabot in #5731
  • Cirrus Labs runners for other important workflows (where it makes sense to do so) + Ubuntu update (22.04 -> 24.04) by alwx in #5696
  • chore(deps): bump diff to ^5.2.2 by antonis in #5705
  • chore(deps): update Bundler Plugins to v5.1.1 by github-actions in #5700
  • chore(deps): update JavaScript SDK to v10.40.0 by github-actions in #5715
  • ci: Cancel in-progress CI jobs when a PR is closed or merged by antonis in #5725

🤖 This preview updates automatically when you update the PR.

@antonisantonis mentioned this pull request Feb 24, 2026
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time1210.85 ms1217.55 ms6.70 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1229.13 ms1228.46 ms-0.67 ms
80e4616+dirty1221.32 ms1225.64 ms4.32 ms
818a608+dirty1205.76 ms1208.00 ms2.24 ms
77061ed+dirty1233.16 ms1234.88 ms1.71 ms
bef3709+dirty1222.07 ms1220.24 ms-1.83 ms
a206511+dirty1185.00 ms1186.35 ms1.35 ms
74979ac+dirty1210.49 ms1213.31 ms2.82 ms
a2bb688+dirty1223.53 ms1232.90 ms9.37 ms
8a868fe+dirty1221.50 ms1230.78 ms9.28 ms
d590428+dirty1211.77 ms1220.51 ms8.75 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty2.63 MiB3.91 MiB1.28 MiB
77061ed+dirty2.63 MiB3.98 MiB1.34 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty2.63 MiB3.99 MiB1.36 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1216.40 ms1212.08 ms-4.32 ms
cddbba5+dirty1218.63 ms1220.67 ms2.04 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonis
antonis marked this pull request as ready for review February 24, 2026 13:07
Comment threadpackage.json
@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

PlainWith SentryDiff
Startup time416.26 ms433.42 ms17.16 ms
Size43.75 MiB48.46 MiB4.71 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
86584b7+dirty463.83 ms500.31 ms36.48 ms
9a81842+dirty412.23 ms416.56 ms4.33 ms
c637fc7+dirty433.70 ms467.76 ms34.06 ms
d73150f+dirty411.21 ms465.86 ms54.65 ms
fa7bb7e+dirty350.37 ms377.02 ms26.65 ms
3bd3f0d+dirty447.21 ms472.31 ms25.10 ms
88890fe+dirty350.94 ms365.74 ms14.80 ms
95aaf8a437.89 ms419.45 ms-18.44 ms
c0842e7+dirty527.76 ms566.69 ms38.93 ms
1e7a472+dirty348.80 ms362.55 ms13.75 ms

App size

RevisionPlainWith SentryDiff
86584b7+dirty43.75 MiB48.08 MiB4.33 MiB
9a81842+dirty43.75 MiB48.08 MiB4.33 MiB
c637fc7+dirty43.75 MiB48.40 MiB4.64 MiB
d73150f+dirty43.75 MiB48.55 MiB4.80 MiB
fa7bb7e+dirty17.75 MiB19.75 MiB2.00 MiB
3bd3f0d+dirty17.75 MiB19.70 MiB1.95 MiB
88890fe+dirty17.75 MiB19.71 MiB1.96 MiB
95aaf8a17.75 MiB19.68 MiB1.93 MiB
c0842e7+dirty43.75 MiB48.41 MiB4.66 MiB
1e7a472+dirty17.75 MiB19.70 MiB1.96 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty395.96 ms423.90 ms27.94 ms
cddbba5+dirty387.39 ms446.46 ms59.07 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.75 MiB48.46 MiB4.71 MiB
cddbba5+dirty43.75 MiB48.46 MiB4.71 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time438.00 ms477.32 ms39.32 ms
Size43.94 MiB49.34 MiB5.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
7480abe+dirty363.80 ms431.34 ms67.54 ms
2b89ce9+dirty372.22 ms417.06 ms44.84 ms
170d5ea+dirty348.79 ms406.94 ms58.15 ms
b1579bc+dirty391.87 ms456.26 ms64.39 ms
73f2455+dirty369.33 ms398.90 ms29.57 ms
0b64753+dirty358.55 ms429.16 ms70.61 ms
6a70a7e+dirty382.45 ms424.54 ms42.09 ms
2adbd1e+dirty366.13 ms419.49 ms53.36 ms
f8d19f8+dirty374.17 ms383.40 ms9.23 ms
7be1f99+dirty369.02 ms399.60 ms30.58 ms

App size

RevisionPlainWith SentryDiff
7480abe+dirty7.15 MiB8.41 MiB1.26 MiB
2b89ce9+dirty7.15 MiB8.41 MiB1.26 MiB
170d5ea+dirty7.15 MiB8.42 MiB1.27 MiB
b1579bc+dirty43.94 MiB49.27 MiB5.33 MiB
73f2455+dirty43.94 MiB48.82 MiB4.88 MiB
0b64753+dirty7.15 MiB8.42 MiB1.27 MiB
6a70a7e+dirty7.15 MiB8.42 MiB1.26 MiB
2adbd1e+dirty7.15 MiB8.43 MiB1.28 MiB
f8d19f8+dirty43.94 MiB48.91 MiB4.97 MiB
7be1f99+dirty7.15 MiB8.42 MiB1.27 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty365.94 ms393.20 ms27.27 ms
cddbba5+dirty434.37 ms478.51 ms44.14 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty43.94 MiB49.33 MiB5.39 MiB
cddbba5+dirty43.94 MiB49.34 MiB5.40 MiB

@github-actions

github-actionsBot commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

PlainWith SentryDiff
Startup time1226.06 ms1226.24 ms0.18 ms
Size3.38 MiB4.78 MiB1.40 MiB

Baseline results on branch: main

Startup times

RevisionPlainWith SentryDiff
ea3e26e+dirty1216.61 ms1214.15 ms-2.47 ms
80e4616+dirty1206.90 ms1205.94 ms-0.96 ms
818a608+dirty1218.84 ms1223.18 ms4.34 ms
77061ed+dirty1210.77 ms1218.45 ms7.68 ms
bef3709+dirty1217.79 ms1225.33 ms7.54 ms
a206511+dirty1225.02 ms1223.74 ms-1.28 ms
74979ac+dirty1212.33 ms1212.54 ms0.21 ms
a2bb688+dirty1244.82 ms1238.60 ms-6.22 ms
8a868fe+dirty1206.85 ms1215.04 ms8.19 ms
d590428+dirty1221.23 ms1225.27 ms4.03 ms

App size

RevisionPlainWith SentryDiff
ea3e26e+dirty3.41 MiB4.58 MiB1.17 MiB
80e4616+dirty3.38 MiB4.60 MiB1.22 MiB
818a608+dirty3.19 MiB4.48 MiB1.29 MiB
77061ed+dirty3.19 MiB4.54 MiB1.36 MiB
bef3709+dirty3.38 MiB4.78 MiB1.40 MiB
a206511+dirty3.41 MiB4.67 MiB1.25 MiB
74979ac+dirty3.38 MiB4.60 MiB1.22 MiB
a2bb688+dirty3.19 MiB4.56 MiB1.37 MiB
8a868fe+dirty3.38 MiB4.60 MiB1.22 MiB
d590428+dirty3.38 MiB4.78 MiB1.39 MiB

Previous results on branch: antonis/bump-ajv

Startup times

RevisionPlainWith SentryDiff
53ddf21+dirty1207.61 ms1209.47 ms1.86 ms
cddbba5+dirty1207.78 ms1210.07 ms2.29 ms

App size

RevisionPlainWith SentryDiff
53ddf21+dirty3.38 MiB4.78 MiB1.40 MiB
cddbba5+dirty3.38 MiB4.78 MiB1.40 MiB

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 26, 2026
Comment threadpackage.json Outdated
Uses scoped yarn resolutions to bump ajv:
- eslint/eslintrc consumers: 6.12.6 → 6.14.0 (fixes alert #423)
- appium, detox, expo-dev-launcher: → 8.18.0 (fixes alert #424)
Parent-scoped resolutions avoid the unscoped override that would force
eslint onto incompatible ajv v8.
https://github.com/getsentry/sentry-react-native/security/dependabot/423https://github.com/getsentry/sentry-react-native/security/dependabot/424
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both review comments:

  • sentry[bot]: Correct — the unscoped "ajv": "^8.18.0" was overriding the parent-scoped 6.x resolutions, forcing eslint onto incompatible ajv v8. This broke yarn lint:lerna with TypeError: Cannot set properties of undefined (setting 'defaultMeta').
  • cursor[bot]: Also correct — the scoped eslint resolutions were dead code because the unscoped resolution took precedence.

Fix: Removed the unscoped resolution entirely. Now using only parent-scoped resolutions:

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

Comment threadpackage.json
Comment threadyarn.lock Outdated
Comment on lines 13697 to 13700
"ajv@npm:^8.0.0":
version: 8.17.1
resolution: "ajv@npm:8.17.1"
dependencies:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The fix for the ajv ReDoS vulnerability is incomplete. The ajv-formats package is not covered by the scoped resolutions and still resolves to a vulnerable ajv version.
Severity: HIGH

Suggested Fix

To fully mitigate the vulnerability, either add a specific scoped resolution for ajv-formats like "ajv-formats@npm:2.1.1/ajv": "^8.18.0", or add a global unscoped resolution like "ajv": "^8.18.0" to force all consumers to the patched version.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: yarn.lock#L13697-L13700
Potential issue: The pull request attempts to mitigate a ReDoS vulnerability in the
`ajv` package by adding scoped resolutions to `yarn.lock`. However, this fix is
incomplete. The `ajv-formats` package, a dependency in the project, requires `ajv:
"^8.0.0"` and is not covered by any of the new scoped resolutions. As a result, it
resolves to the vulnerable version `8.17.1` instead of the patched version `8.18.0`.
This leaves the application exposed to the ReDoS vulnerability (CVE-2025-69873) through
any code path that utilizes `ajv-formats`.

…ajv 8.17.1
ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still
resolving to vulnerable 8.17.1. Adding a scoped resolution for
ajv-formats ensures it also gets ajv 8.18.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis

Copy link
Copy Markdown
ContributorAuthor

Addressed both new comments:

  • cursor[bot] / sentry[bot]: Correct — ajv-formats@2.1.1 (via appium) depends on ajv@^8.0.0 which was still resolving to vulnerable 8.17.1.

Fix: Added "ajv-formats@npm:2.1.1/ajv": "^8.18.0" scoped resolution. No more 8.17.1 in the lockfile — all 8.x consumers now resolve to 8.18.0, and all 6.x (eslint) consumers resolve to 6.14.0.

Verified: yarn build, yarn test, and yarn lint:lerna all pass.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) February 27, 2026 14:21

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! once when tests are green

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Feb 27, 2026
@lucas-zimerman

Copy link
Copy Markdown
Collaborator

@antonis should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@antonis
antonis disabled auto-merge February 27, 2026 14:56
@antonis

antonis commented Feb 27, 2026

Copy link
Copy Markdown
ContributorAuthor

should we wait for this fix? getsentry/sentry-javascript#19434
I noticed this issue coming from Sentry JavaScript 10.40.0 on Capacitor.

@lucas-zimerman I'm not sure. We already have 10.40.0 with #5715 but the sec alert is still open.

@antonisantonis added the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@lucas-zimerman
lucas-zimerman enabled auto-merge (squash) March 2, 2026 15:46

@lucas-zimermanlucas-zimerman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@antonisantonis removed the ready-to-merge Triggers the full CI test suite label Mar 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor
Fails
🚫Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against e5819e7

@lucas-zimerman
lucas-zimerman merged commit a02d765 into mainMar 2, 2026
33 of 44 checks passed
@lucas-zimerman
lucas-zimerman deleted the antonis/bump-ajv branch March 2, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@antonis@lucas-zimerman