Skip to content

Releases: progress/datadirect-arc-ai-model-gen

Release list

v2.1

Choose a tag to compare

@cassie-manning cassie-manning released this 18 Sep 17:41
1067a25

Security Fix: CVE-2026-91140

This release remediates CVE-2026-91140, a command-injection/unsafe-file-path issue where Swagger-derived {fileName} and {entity-name} values could be used unsafely in generated shell cleanup and file-write instructions.

Fixes:

  • Enforced a strict allowlist (^[A-Za-z0-9._-]+$) for {fileName}/{entity-name}, rejecting anything ambiguous instead of trying to sanitize it.
  • Quoted all {fileName} expansions in shell cleanup/verification commands and preferred native file deletion over shell commands.
  • Closed a Windows-specific bypass allowing trailing-dot names (e.g. foo.) and reserved device names (e.g. CON, NUL, COM1) that the allowlist alone didn't catch.

More information: https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulletin-September-2026-CVE-2026-91140

Also included: removed internal agent/document version markers in favor of tracking releases via GitHub Releases.

Full Changelog: v2.0...v2.1

v2.0

Choose a tag to compare

@cassie-manning cassie-manning released this 18 Sep 17:40

Initial Public Release

This marks the first upload of the ARC GenAI Agents project to the public-facing GitHub repository. The project provides a set of AI agents that automate generation, validation, and launch of AutoREST .rest configuration files from Swagger/OpenAPI documents.

What's included

  • ARCGenAI-Generator and its ARCGenAI-EntityGen sub-agent — generate AutoREST .rest configuration files from Swagger/OpenAPI input documents
  • ARCGenAI-StaticValidator — deterministic static validation of generated or hand-edited .rest files against the language specification
  • ARCGenAI-Launcher — opens a validated .rest file in ARC Composer via the AutoREST JAR design mode
  • Supporting documentation: global REST language specification, manual REST adjustment guidance, and reference/status templates
  • Sample generated output (ai-output/yelp-api) and a sample Swagger input document
  • Repository governance files (license, .gitignore, CODEOWNERS, PR template)

What's changed since project creation

  • Added license file and small README clarity update (#1)

Full Changelog: https://github.com/progress/datadirect-arc-ai-model-gen/commits/v2.0