Repository navigation
Releases: progress/datadirect-arc-ai-model-gen
Release list
v2.1
Security Fix: CVE-2026-91140
This release remediates CVE-2026-91140, a command-injection/unsafe-file-path issue where Swagger-derived {fileName} and {entity-name} values could be used unsafely in generated shell cleanup and file-write instructions.
Fixes:
- Enforced a strict allowlist (
^[A-Za-z0-9._-]+$) for{fileName}/{entity-name}, rejecting anything ambiguous instead of trying to sanitize it. - Quoted all
{fileName}expansions in shell cleanup/verification commands and preferred native file deletion over shell commands. - Closed a Windows-specific bypass allowing trailing-dot names (e.g.
foo.) and reserved device names (e.g.CON,NUL,COM1) that the allowlist alone didn't catch.
More information: https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulletin-September-2026-CVE-2026-91140
Also included: removed internal agent/document version markers in favor of tracking releases via GitHub Releases.
Full Changelog: v2.0...v2.1
v2.0
Initial Public Release
This marks the first upload of the ARC GenAI Agents project to the public-facing GitHub repository. The project provides a set of AI agents that automate generation, validation, and launch of AutoREST .rest configuration files from Swagger/OpenAPI documents.
What's included
- ARCGenAI-Generator and its ARCGenAI-EntityGen sub-agent — generate AutoREST
.restconfiguration files from Swagger/OpenAPI input documents - ARCGenAI-StaticValidator — deterministic static validation of generated or hand-edited
.restfiles against the language specification - ARCGenAI-Launcher — opens a validated
.restfile in ARC Composer via the AutoREST JAR design mode - Supporting documentation: global REST language specification, manual REST adjustment guidance, and reference/status templates
- Sample generated output (
ai-output/yelp-api) and a sample Swagger input document - Repository governance files (license,
.gitignore,CODEOWNERS, PR template)
What's changed since project creation
- Added license file and small README clarity update (#1)
Full Changelog: https://github.com/progress/datadirect-arc-ai-model-gen/commits/v2.0