Skip to content

Add JSON Schema for bot definitions - #72

Merged
davidmytton merged 3 commits into
arcjet:mainfrom
szepeviktor:schema
Sep 9, 2026
Merged

davidmytton merged 3 commits into
arcjet:mainfrom
szepeviktor:schema

Conversation

@szepeviktor

Copy link
Copy Markdown
Contributor

@davidmytton I hope a JSON schema will help you maintain this list of bots.

@szepeviktor
szepeviktor requested a review from a team as a code owner September 5, 2026 17:45
@arcjet-review arcjet-review Bot added the needs review Awaiting human review label Sep 5, 2026
davidmytton and others added 2 commits September 9, 2026 08:41
Reject malformed IPv4 and IPv6 CIDR ranges, including invalid prefix lengths, while supporting compressed IPv6 and embedded IPv4 addresses. Cross-check the schema patterns against Node's IP parser and run schema validation in CI.

Builds on Viktor Szépe's JSON Schema contribution in #72; the original commit and authorship are preserved.

Co-authored-by: Codex <codex@openai.com>
Replace on-demand npx execution with an isolated tools/schema package and a committed dependency lockfile. Install with npm ci --ignore-scripts and invoke Ajv directly, removing ajv-cli and its extra dependencies.

Use releases older than seven days and cover the validator exit status for malformed bot definitions and CIDR ranges.

Co-authored-by: Codex <codex@openai.com>
@socket-security

socket-security Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedajv-formats@​3.0.110010010083100
Addedajv@​8.20.09910010084100

View full report

@arcjet-review arcjet-review Bot removed the needs review Awaiting human review label Sep 9, 2026
@socket-security

socket-security Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Low
Debug access: npm require-from-string in module module

Module: module

Location: Package overview

From: tools/schema/package-lock.json → npm/ajv@8.20.0 → npm/require-from-string@2.0.2

ℹ Read more on: This package | This alert | What is debug access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Removing the use of debug will reduce the risk of any reflection and dynamic code execution.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/require-from-string@2.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Ignoring alerts on:

  • ajv@8.20.0

View full report

@davidmytton

Copy link
Copy Markdown
Contributor

@SocketSecurity ignore npm/ajv@8.20.0

@arcjet-review arcjet-review Bot added the needs review Awaiting human review label Sep 9, 2026
@davidmytton

Copy link
Copy Markdown
Contributor

Thanks for contributing @szepeviktor

@arcjet-review arcjet-review Bot removed the needs review Awaiting human review label Sep 9, 2026
@davidmytton
davidmytton merged commit eaf821d into arcjet:main Sep 9, 2026
2 checks passed
@szepeviktor

Copy link
Copy Markdown
Contributor Author

Glad to contribute.

@szepeviktor
szepeviktor deleted the schema branch September 9, 2026 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants