This run took 13 seconds.
$ date --- stdout --- Thu Nov 21 23:47:49 UTC 2024 --- end --- $ git clone file:///srv/git/mediawiki-extensions-SemanticGenealogy.git repo --depth=1 -b REL1_43 --- stderr --- Cloning into 'repo'... --- stdout --- --- end --- $ git config user.name libraryupgrader --- stdout --- --- end --- $ git config user.email tools.libraryupgrader@tools.wmflabs.org --- stdout --- --- end --- $ git submodule update --init --- stdout --- --- end --- $ grr init --- stdout --- Installed commit-msg hook. --- end --- $ git show-ref refs/heads/REL1_43 --- stdout --- c6bf6ff993b98b7faa29854fa125e5c7160dd852 refs/heads/REL1_43 --- end --- $ /usr/bin/npm audit --json --- stdout --- { "auditReportVersion": 2, "vulnerabilities": { "cross-spawn": { "name": "cross-spawn", "severity": "high", "isDirect": false, "via": [ { "source": 1100562, "name": "cross-spawn", "dependency": "cross-spawn", "title": "Regular Expression Denial of Service (ReDoS) in cross-spawn", "url": "https://github.com/advisories/GHSA-3xgq-45jj-v275", "severity": "high", "cwe": [ "CWE-1333" ], "cvss": { "score": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" }, "range": "<6.0.6" }, { "source": 1100563, "name": "cross-spawn", "dependency": "cross-spawn", "title": "Regular Expression Denial of Service (ReDoS) in cross-spawn", "url": "https://github.com/advisories/GHSA-3xgq-45jj-v275", "severity": "high", "cwe": [ "CWE-1333" ], "cvss": { "score": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" }, "range": ">=7.0.0 <7.0.5" } ], "effects": [ "grunt-contrib-sass" ], "range": "<6.0.6 || >=7.0.0 <7.0.5", "nodes": [ "node_modules/cross-spawn", "node_modules/eslint/node_modules/cross-spawn" ], "fixAvailable": { "name": "grunt-contrib-sass", "version": "2.0.0", "isSemVerMajor": true } }, "grunt-contrib-sass": { "name": "grunt-contrib-sass", "severity": "high", "isDirect": true, "via": [ "cross-spawn" ], "effects": [], "range": "0.9.0 - 1.0.0", "nodes": [ "node_modules/grunt-contrib-sass" ], "fixAvailable": { "name": "grunt-contrib-sass", "version": "2.0.0", "isSemVerMajor": true } } }, "metadata": { "vulnerabilities": { "info": 0, "low": 0, "moderate": 0, "high": 2, "critical": 0, "total": 2 }, "dependencies": { "prod": 1, "dev": 379, "optional": 0, "peer": 1, "peerOptional": 0, "total": 379 } } } --- end --- $ /usr/bin/composer install --- stderr --- No composer.lock file present. Updating dependencies to latest instead of installing from lock file. See https://getcomposer.org/install for more information. Loading composer repositories with package information Updating dependencies Lock file operations: 43 installs, 0 updates, 0 removals - Locking composer/installers (dev-main a24c987) - Locking composer/semver (3.4.3) - Locking composer/spdx-licenses (1.5.8) - Locking data-values/common (1.1.0) - Locking data-values/data-values (dev-master 4c557b2) - Locking data-values/interfaces (1.0.0) - Locking data-values/validators (1.0.0) - Locking dealerdirect/phpcodesniffer-composer-installer (v1.0.0) - Locking jeroen/file-fetcher (6.1.0) - Locking justinrainbow/json-schema (5.x-dev feb2ca6) - Locking mediawiki/http-request (dev-master 5c0ca08) - Locking mediawiki/mediawiki-codesniffer (v45.0.0) - Locking mediawiki/minus-x (1.1.3) - Locking mediawiki/parser-hooks (dev-master 35e4513) - Locking mediawiki/semantic-media-wiki (dev-master 2993054) - Locking onoi/blob-store (dev-master 7753172) - Locking onoi/cache (dev-master 9a8e3ea) - Locking onoi/callback-container (dev-master 70d2266) - Locking onoi/event-dispatcher (dev-master 2af64e3) - Locking onoi/message-reporter (dev-master 5381702) - Locking param-processor/param-processor (dev-master 0850dc2) - Locking php-parallel-lint/php-console-color (v1.0.1) - Locking php-parallel-lint/php-console-highlighter (v1.0.0) - Locking php-parallel-lint/php-parallel-lint (v1.4.0) - Locking phpcsstandards/phpcsextra (1.2.1) - Locking phpcsstandards/phpcsutils (dev-develop 9b2671b) - Locking psr/container (dev-master 7079847) - Locking psr/log (1.1.4) - Locking seld/jsonlint (1.11.0) - Locking serialization/serialization (dev-master dc380fe) - Locking squizlabs/php_codesniffer (3.10.3) - Locking symfony/console (7.2.x-dev 23c8aae) - Locking symfony/css-selector (5.4.x-dev 4f7f3c3) - Locking symfony/deprecation-contracts (dev-main 63afe74) - Locking symfony/polyfill-ctype (1.x-dev a3cc8b0) - Locking symfony/polyfill-intl-grapheme (1.x-dev b912392) - Locking symfony/polyfill-intl-normalizer (1.x-dev 3833d72) - Locking symfony/polyfill-mbstring (1.x-dev 2369cb9) - Locking symfony/polyfill-php80 (1.x-dev 60328e3) - Locking symfony/service-contracts (dev-main 5ad3869) - Locking symfony/string (7.2.x-dev 446e0d1) - Locking wikimedia/cdb (3.0.0) - Locking wikimedia/textcat (2.0.0) Writing lock file Installing dependencies from lock file (including require-dev) Package operations: 43 installs, 0 updates, 0 removals 0 [>---------------------------] 0 [->--------------------------] - Installing composer/installers (dev-main a24c987): Extracting archive - Installing squizlabs/php_codesniffer (3.10.3): Extracting archive - Installing dealerdirect/phpcodesniffer-composer-installer (v1.0.0): Extracting archive - Installing symfony/polyfill-php80 (1.x-dev 60328e3): Extracting archive - Installing phpcsstandards/phpcsutils (dev-develop 9b2671b): Extracting archive - Installing phpcsstandards/phpcsextra (1.2.1): Extracting archive - Installing symfony/polyfill-mbstring (1.x-dev 2369cb9): Extracting archive - Installing composer/spdx-licenses (1.5.8): Extracting archive - Installing composer/semver (3.4.3): Extracting archive - Installing mediawiki/mediawiki-codesniffer (v45.0.0): Extracting archive - Installing symfony/polyfill-intl-normalizer (1.x-dev 3833d72): Extracting archive - Installing symfony/polyfill-intl-grapheme (1.x-dev b912392): Extracting archive - Installing symfony/polyfill-ctype (1.x-dev a3cc8b0): Extracting archive - Installing symfony/string (7.2.x-dev 446e0d1): Extracting archive - Installing symfony/deprecation-contracts (dev-main 63afe74): Extracting archive - Installing psr/container (dev-master 7079847): Extracting archive - Installing symfony/service-contracts (dev-main 5ad3869): Extracting archive - Installing symfony/console (7.2.x-dev 23c8aae): Extracting archive - Installing mediawiki/minus-x (1.1.3): Extracting archive - Installing wikimedia/textcat (2.0.0): Extracting archive - Installing wikimedia/cdb (3.0.0): Extracting archive - Installing symfony/css-selector (5.4.x-dev 4f7f3c3): Extracting archive - Installing serialization/serialization (dev-master dc380fe): Extracting archive - Installing seld/jsonlint (1.11.0): Extracting archive - Installing psr/log (1.1.4): Extracting archive - Installing data-values/interfaces (1.0.0): Extracting archive - Installing data-values/data-values (dev-master 4c557b2): Extracting archive - Installing data-values/validators (1.0.0): Extracting archive - Installing data-values/common (1.1.0): Extracting archive - Installing param-processor/param-processor (dev-master 0850dc2): Extracting archive - Installing onoi/message-reporter (dev-master 5381702): Extracting archive - Installing onoi/event-dispatcher (dev-master 2af64e3): Extracting archive - Installing onoi/callback-container (dev-master 70d2266): Extracting archive - Installing onoi/cache (dev-master 9a8e3ea): Extracting archive - Installing onoi/blob-store (dev-master 7753172): Extracting archive - Installing mediawiki/parser-hooks (dev-master 35e4513): Extracting archive - Installing mediawiki/http-request (dev-master 5c0ca08): Extracting archive - Installing justinrainbow/json-schema (5.x-dev feb2ca6): Extracting archive - Installing jeroen/file-fetcher (6.1.0): Extracting archive - Installing mediawiki/semantic-media-wiki (dev-master 2993054): Extracting archive - Installing php-parallel-lint/php-console-color (v1.0.1): Extracting archive - Installing php-parallel-lint/php-console-highlighter (v1.0.0): Extracting archive - Installing php-parallel-lint/php-parallel-lint (v1.4.0): Extracting archive 0/40 [>---------------------------] 0% 19/40 [=============>--------------] 47% 32/40 [======================>-----] 80% 38/40 [==========================>-] 95% 40/40 [============================] 100% 4 package suggestions were added by new dependencies, use `composer suggest` to see details. Generating autoload files 24 packages you are using are looking for funding. Use the `composer fund` command to find out more! --- stdout --- PHP CodeSniffer Config installed_paths set to ../../mediawiki/mediawiki-codesniffer,../../phpcsstandards/phpcsextra,../../phpcsstandards/phpcsutils --- end --- $ /usr/bin/npm audit --json --- stdout --- { "auditReportVersion": 2, "vulnerabilities": {}, "metadata": { "vulnerabilities": { "info": 0, "low": 0, "moderate": 0, "high": 0, "critical": 0, "total": 0 }, "dependencies": { "prod": 1, "dev": 379, "optional": 0, "peer": 1, "peerOptional": 0, "total": 379 } } } --- end --- $ package-lock-lint package-lock.json --- stdout --- Checking package-lock.json --- end --- [DNM] there are no updates $ git add . --- stdout --- --- end --- $ git commit -F /tmp/tmpu_4hmp1a --- stdout --- On branch REL1_43 Your branch is up to date with 'origin/REL1_43'. nothing to commit, working tree clean --- end ---