This run took 116 seconds.
$ date --- stdout --- Thu Mar 27 16:45:16 UTC 2025 --- end --- $ git clone file:///srv/git/mediawiki-services-citoid.git repo --depth=1 -b master --- stderr --- Cloning into 'repo'... --- stdout --- --- end --- $ git config user.name libraryupgrader --- stdout --- --- end --- $ git config user.email tools.libraryupgrader@tools.wmflabs.org --- stdout --- --- end --- $ git submodule update --init --- stdout --- --- end --- $ grr init --- stdout --- Installed commit-msg hook. --- end --- $ git show-ref refs/heads/master --- stdout --- 944d27599c7a442dba9259ac94ea978f97aa1759 refs/heads/master --- end --- $ /usr/bin/npm audit --json --- stdout --- { "auditReportVersion": 2, "vulnerabilities": { "ip": { "name": "ip", "severity": "high", "isDirect": true, "via": [ { "source": 1101851, "name": "ip", "dependency": "ip", "title": "ip SSRF improper categorization in isPublic", "url": "https://github.com/advisories/GHSA-2p57-rm9w-gvfp", "severity": "high", "cwe": [ "CWE-918" ], "cvss": { "score": 8.1, "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" }, "range": "<=2.0.1" } ], "effects": [], "range": "*", "nodes": [ "node_modules/ip" ], "fixAvailable": false }, "limitation": { "name": "limitation", "severity": "moderate", "isDirect": false, "via": [ "wikimedia-kad-fork" ], "effects": [ "service-runner" ], "range": ">=0.2.3", "nodes": [ "node_modules/limitation" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "ms": { "name": "ms", "severity": "moderate", "isDirect": false, "via": [ { "source": 1094419, "name": "ms", "dependency": "ms", "title": "Vercel ms Inefficient Regular Expression Complexity vulnerability", "url": "https://github.com/advisories/GHSA-w9mr-4mfr-499f", "severity": "moderate", "cwe": [ "CWE-1333" ], "cvss": { "score": 5.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" }, "range": "<2.0.0" } ], "effects": [ "wikimedia-kad-fork" ], "range": "<2.0.0", "nodes": [ "node_modules/wikimedia-kad-fork/node_modules/ms" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "preq": { "name": "preq", "severity": "high", "isDirect": true, "via": [ "request", "requestretry" ], "effects": [], "range": "*", "nodes": [ "node_modules/preq" ], "fixAvailable": false }, "request": { "name": "request", "severity": "moderate", "isDirect": true, "via": [ { "source": 1096727, "name": "request", "dependency": "request", "title": "Server-Side Request Forgery in Request", "url": "https://github.com/advisories/GHSA-p8p7-x288-28g6", "severity": "moderate", "cwe": [ "CWE-918" ], "cvss": { "score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" }, "range": "<=2.88.2" }, "tough-cookie" ], "effects": [ "preq", "requestretry" ], "range": "*", "nodes": [ "node_modules/request" ], "fixAvailable": false }, "requestretry": { "name": "requestretry", "severity": "high", "isDirect": false, "via": [ { "source": 1090420, "name": "requestretry", "dependency": "requestretry", "title": "Cookie exposure in requestretry", "url": "https://github.com/advisories/GHSA-hjp8-2cm3-cc45", "severity": "high", "cwe": [ "CWE-200" ], "cvss": { "score": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" }, "range": "<7.0.0" }, "request" ], "effects": [ "preq" ], "range": "*", "nodes": [ "node_modules/requestretry" ], "fixAvailable": false }, "service-runner": { "name": "service-runner", "severity": "moderate", "isDirect": true, "via": [ "limitation" ], "effects": [], "range": ">=3.1.0", "nodes": [ "node_modules/service-runner" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "swagger-ui-dist": { "name": "swagger-ui-dist", "severity": "moderate", "isDirect": true, "via": [ { "source": 1088759, "name": "swagger-ui-dist", "dependency": "swagger-ui-dist", "title": "Spoofing attack in swagger-ui-dist", "url": "https://github.com/advisories/GHSA-6c9x-mj3g-h47x", "severity": "moderate", "cwe": [ "CWE-1021" ], "cvss": { "score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" }, "range": "<4.1.3" }, { "source": 1092160, "name": "swagger-ui-dist", "dependency": "swagger-ui-dist", "title": "Server side request forgery in SwaggerUI", "url": "https://github.com/advisories/GHSA-qrmm-w75w-3wpx", "severity": "moderate", "cwe": [ "CWE-918" ], "cvss": { "score": 0, "vectorString": null }, "range": "<4.1.3" } ], "effects": [], "range": "<=4.1.2", "nodes": [ "node_modules/swagger-ui-dist" ], "fixAvailable": { "name": "swagger-ui-dist", "version": "5.20.2", "isSemVerMajor": true } }, "tough-cookie": { "name": "tough-cookie", "severity": "moderate", "isDirect": false, "via": [ { "source": 1097682, "name": "tough-cookie", "dependency": "tough-cookie", "title": "tough-cookie Prototype Pollution vulnerability", "url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3", "severity": "moderate", "cwe": [ "CWE-1321" ], "cvss": { "score": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" }, "range": "<4.1.3" } ], "effects": [ "request" ], "range": "<4.1.3", "nodes": [ "node_modules/tough-cookie" ], "fixAvailable": false }, "wikimedia-kad-fork": { "name": "wikimedia-kad-fork", "severity": "moderate", "isDirect": false, "via": [ "ms" ], "effects": [ "limitation" ], "range": "*", "nodes": [ "node_modules/wikimedia-kad-fork" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } } }, "metadata": { "vulnerabilities": { "info": 0, "low": 0, "moderate": 7, "high": 3, "critical": 0, "total": 10 }, "dependencies": { "prod": 247, "dev": 397, "optional": 15, "peer": 1, "peerOptional": 0, "total": 657 } } } --- end --- $ /usr/bin/npm audit --json --- stdout --- { "auditReportVersion": 2, "vulnerabilities": { "ip": { "name": "ip", "severity": "high", "isDirect": true, "via": [ { "source": 1101851, "name": "ip", "dependency": "ip", "title": "ip SSRF improper categorization in isPublic", "url": "https://github.com/advisories/GHSA-2p57-rm9w-gvfp", "severity": "high", "cwe": [ "CWE-918" ], "cvss": { "score": 8.1, "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" }, "range": "<=2.0.1" } ], "effects": [], "range": "*", "nodes": [ "node_modules/ip" ], "fixAvailable": false }, "limitation": { "name": "limitation", "severity": "moderate", "isDirect": false, "via": [ "wikimedia-kad-fork" ], "effects": [ "service-runner" ], "range": ">=0.2.3", "nodes": [ "node_modules/limitation" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "ms": { "name": "ms", "severity": "moderate", "isDirect": false, "via": [ { "source": 1094419, "name": "ms", "dependency": "ms", "title": "Vercel ms Inefficient Regular Expression Complexity vulnerability", "url": "https://github.com/advisories/GHSA-w9mr-4mfr-499f", "severity": "moderate", "cwe": [ "CWE-1333" ], "cvss": { "score": 5.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" }, "range": "<2.0.0" } ], "effects": [ "wikimedia-kad-fork" ], "range": "<2.0.0", "nodes": [ "node_modules/wikimedia-kad-fork/node_modules/ms" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "preq": { "name": "preq", "severity": "high", "isDirect": true, "via": [ "request", "requestretry" ], "effects": [], "range": "*", "nodes": [ "node_modules/preq" ], "fixAvailable": false }, "request": { "name": "request", "severity": "moderate", "isDirect": true, "via": [ { "source": 1096727, "name": "request", "dependency": "request", "title": "Server-Side Request Forgery in Request", "url": "https://github.com/advisories/GHSA-p8p7-x288-28g6", "severity": "moderate", "cwe": [ "CWE-918" ], "cvss": { "score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" }, "range": "<=2.88.2" }, "tough-cookie" ], "effects": [ "preq", "requestretry" ], "range": "*", "nodes": [ "node_modules/request" ], "fixAvailable": false }, "requestretry": { "name": "requestretry", "severity": "high", "isDirect": false, "via": [ { "source": 1090420, "name": "requestretry", "dependency": "requestretry", "title": "Cookie exposure in requestretry", "url": "https://github.com/advisories/GHSA-hjp8-2cm3-cc45", "severity": "high", "cwe": [ "CWE-200" ], "cvss": { "score": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" }, "range": "<7.0.0" }, "request" ], "effects": [ "preq" ], "range": "*", "nodes": [ "node_modules/requestretry" ], "fixAvailable": false }, "service-runner": { "name": "service-runner", "severity": "moderate", "isDirect": true, "via": [ "limitation" ], "effects": [], "range": ">=3.1.0", "nodes": [ "node_modules/service-runner" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "swagger-ui-dist": { "name": "swagger-ui-dist", "severity": "moderate", "isDirect": true, "via": [ { "source": 1088759, "name": "swagger-ui-dist", "dependency": "swagger-ui-dist", "title": "Spoofing attack in swagger-ui-dist", "url": "https://github.com/advisories/GHSA-6c9x-mj3g-h47x", "severity": "moderate", "cwe": [ "CWE-1021" ], "cvss": { "score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" }, "range": "<4.1.3" }, { "source": 1092160, "name": "swagger-ui-dist", "dependency": "swagger-ui-dist", "title": "Server side request forgery in SwaggerUI", "url": "https://github.com/advisories/GHSA-qrmm-w75w-3wpx", "severity": "moderate", "cwe": [ "CWE-918" ], "cvss": { "score": 0, "vectorString": null }, "range": "<4.1.3" } ], "effects": [], "range": "<=4.1.2", "nodes": [ "node_modules/swagger-ui-dist" ], "fixAvailable": { "name": "swagger-ui-dist", "version": "5.20.2", "isSemVerMajor": true } }, "tough-cookie": { "name": "tough-cookie", "severity": "moderate", "isDirect": false, "via": [ { "source": 1097682, "name": "tough-cookie", "dependency": "tough-cookie", "title": "tough-cookie Prototype Pollution vulnerability", "url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3", "severity": "moderate", "cwe": [ "CWE-1321" ], "cvss": { "score": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" }, "range": "<4.1.3" } ], "effects": [ "request" ], "range": "<4.1.3", "nodes": [ "node_modules/tough-cookie" ], "fixAvailable": false }, "wikimedia-kad-fork": { "name": "wikimedia-kad-fork", "severity": "moderate", "isDirect": false, "via": [ "ms" ], "effects": [ "limitation" ], "range": "*", "nodes": [ "node_modules/wikimedia-kad-fork" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } } }, "metadata": { "vulnerabilities": { "info": 0, "low": 0, "moderate": 7, "high": 3, "critical": 0, "total": 10 }, "dependencies": { "prod": 247, "dev": 397, "optional": 15, "peer": 1, "peerOptional": 0, "total": 657 } } } --- end --- Attempting to npm audit fix $ /usr/bin/npm audit fix --dry-run --only=dev --json --- stderr --- npm WARN invalid config only="dev" set in command line options npm WARN invalid config Must be one of: null, prod, production npm WARN EBADENGINE Unsupported engine { npm WARN EBADENGINE package: 'citoid@1.3.0', npm WARN EBADENGINE required: { node: '20' }, npm WARN EBADENGINE current: { node: 'v18.19.0', npm: '9.2.0' } npm WARN EBADENGINE } --- stdout --- { "added": 657, "removed": 0, "changed": 0, "audited": 658, "funding": 117, "audit": { "auditReportVersion": 2, "vulnerabilities": { "ip": { "name": "ip", "severity": "high", "isDirect": true, "via": [ { "source": 1101851, "name": "ip", "dependency": "ip", "title": "ip SSRF improper categorization in isPublic", "url": "https://github.com/advisories/GHSA-2p57-rm9w-gvfp", "severity": "high", "cwe": [ "CWE-918" ], "cvss": { "score": 8.1, "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" }, "range": "<=2.0.1" } ], "effects": [], "range": "*", "nodes": [ "node_modules/ip" ], "fixAvailable": false }, "limitation": { "name": "limitation", "severity": "moderate", "isDirect": false, "via": [ "wikimedia-kad-fork" ], "effects": [ "service-runner" ], "range": ">=0.2.3", "nodes": [ "node_modules/limitation" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "ms": { "name": "ms", "severity": "moderate", "isDirect": false, "via": [ { "source": 1094419, "name": "ms", "dependency": "ms", "title": "Vercel ms Inefficient Regular Expression Complexity vulnerability", "url": "https://github.com/advisories/GHSA-w9mr-4mfr-499f", "severity": "moderate", "cwe": [ "CWE-1333" ], "cvss": { "score": 5.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" }, "range": "<2.0.0" } ], "effects": [ "wikimedia-kad-fork" ], "range": "<2.0.0", "nodes": [ "node_modules/wikimedia-kad-fork/node_modules/ms" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "preq": { "name": "preq", "severity": "high", "isDirect": true, "via": [ "request", "requestretry" ], "effects": [], "range": "*", "nodes": [ "node_modules/preq" ], "fixAvailable": false }, "request": { "name": "request", "severity": "moderate", "isDirect": true, "via": [ { "source": 1096727, "name": "request", "dependency": "request", "title": "Server-Side Request Forgery in Request", "url": "https://github.com/advisories/GHSA-p8p7-x288-28g6", "severity": "moderate", "cwe": [ "CWE-918" ], "cvss": { "score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" }, "range": "<=2.88.2" }, "tough-cookie" ], "effects": [ "preq", "requestretry" ], "range": "*", "nodes": [ "node_modules/request" ], "fixAvailable": false }, "requestretry": { "name": "requestretry", "severity": "high", "isDirect": false, "via": [ { "source": 1090420, "name": "requestretry", "dependency": "requestretry", "title": "Cookie exposure in requestretry", "url": "https://github.com/advisories/GHSA-hjp8-2cm3-cc45", "severity": "high", "cwe": [ "CWE-200" ], "cvss": { "score": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" }, "range": "<7.0.0" }, "request" ], "effects": [ "preq" ], "range": "*", "nodes": [ "node_modules/requestretry" ], "fixAvailable": false }, "service-runner": { "name": "service-runner", "severity": "moderate", "isDirect": true, "via": [ "limitation" ], "effects": [], "range": ">=3.1.0", "nodes": [ "node_modules/service-runner" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } }, "swagger-ui-dist": { "name": "swagger-ui-dist", "severity": "moderate", "isDirect": true, "via": [ { "source": 1088759, "name": "swagger-ui-dist", "dependency": "swagger-ui-dist", "title": "Spoofing attack in swagger-ui-dist", "url": "https://github.com/advisories/GHSA-6c9x-mj3g-h47x", "severity": "moderate", "cwe": [ "CWE-1021" ], "cvss": { "score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" }, "range": "<4.1.3" }, { "source": 1092160, "name": "swagger-ui-dist", "dependency": "swagger-ui-dist", "title": "Server side request forgery in SwaggerUI", "url": "https://github.com/advisories/GHSA-qrmm-w75w-3wpx", "severity": "moderate", "cwe": [ "CWE-918" ], "cvss": { "score": 0, "vectorString": null }, "range": "<4.1.3" } ], "effects": [], "range": "<=4.1.2", "nodes": [ "node_modules/swagger-ui-dist" ], "fixAvailable": { "name": "swagger-ui-dist", "version": "5.20.2", "isSemVerMajor": true } }, "tough-cookie": { "name": "tough-cookie", "severity": "moderate", "isDirect": false, "via": [ { "source": 1097682, "name": "tough-cookie", "dependency": "tough-cookie", "title": "tough-cookie Prototype Pollution vulnerability", "url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3", "severity": "moderate", "cwe": [ "CWE-1321" ], "cvss": { "score": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" }, "range": "<4.1.3" } ], "effects": [ "request" ], "range": "<4.1.3", "nodes": [ "node_modules/tough-cookie" ], "fixAvailable": false }, "wikimedia-kad-fork": { "name": "wikimedia-kad-fork", "severity": "moderate", "isDirect": false, "via": [ "ms" ], "effects": [ "limitation" ], "range": "*", "nodes": [ "node_modules/wikimedia-kad-fork" ], "fixAvailable": { "name": "service-runner", "version": "3.0.0", "isSemVerMajor": true } } }, "metadata": { "vulnerabilities": { "info": 0, "low": 0, "moderate": 7, "high": 3, "critical": 0, "total": 10 }, "dependencies": { "prod": 247, "dev": 397, "optional": 15, "peer": 1, "peerOptional": 0, "total": 657 } } } } --- end --- {"added": 657, "removed": 0, "changed": 0, "audited": 658, "funding": 117, "audit": {"auditReportVersion": 2, "vulnerabilities": {"ip": {"name": "ip", "severity": "high", "isDirect": true, "via": [{"source": 1101851, "name": "ip", "dependency": "ip", "title": "ip SSRF improper categorization in isPublic", "url": "https://github.com/advisories/GHSA-2p57-rm9w-gvfp", "severity": "high", "cwe": ["CWE-918"], "cvss": {"score": 8.1, "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}, "range": "<=2.0.1"}], "effects": [], "range": "*", "nodes": ["node_modules/ip"], "fixAvailable": false}, "limitation": {"name": "limitation", "severity": "moderate", "isDirect": false, "via": ["wikimedia-kad-fork"], "effects": ["service-runner"], "range": ">=0.2.3", "nodes": ["node_modules/limitation"], "fixAvailable": {"name": "service-runner", "version": "3.0.0", "isSemVerMajor": true}}, "ms": {"name": "ms", "severity": "moderate", "isDirect": false, "via": [{"source": 1094419, "name": "ms", "dependency": "ms", "title": "Vercel ms Inefficient Regular Expression Complexity vulnerability", "url": "https://github.com/advisories/GHSA-w9mr-4mfr-499f", "severity": "moderate", "cwe": ["CWE-1333"], "cvss": {"score": 5.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}, "range": "<2.0.0"}], "effects": ["wikimedia-kad-fork"], "range": "<2.0.0", "nodes": ["node_modules/wikimedia-kad-fork/node_modules/ms"], "fixAvailable": {"name": "service-runner", "version": "3.0.0", "isSemVerMajor": true}}, "preq": {"name": "preq", "severity": "high", "isDirect": true, "via": ["request", "requestretry"], "effects": [], "range": "*", "nodes": ["node_modules/preq"], "fixAvailable": false}, "request": {"name": "request", "severity": "moderate", "isDirect": true, "via": [{"source": 1096727, "name": "request", "dependency": "request", "title": "Server-Side Request Forgery in Request", "url": "https://github.com/advisories/GHSA-p8p7-x288-28g6", "severity": "moderate", "cwe": ["CWE-918"], "cvss": {"score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}, "range": "<=2.88.2"}, "tough-cookie"], "effects": ["preq", "requestretry"], "range": "*", "nodes": ["node_modules/request"], "fixAvailable": false}, "requestretry": {"name": "requestretry", "severity": "high", "isDirect": false, "via": [{"source": 1090420, "name": "requestretry", "dependency": "requestretry", "title": "Cookie exposure in requestretry", "url": "https://github.com/advisories/GHSA-hjp8-2cm3-cc45", "severity": "high", "cwe": ["CWE-200"], "cvss": {"score": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}, "range": "<7.0.0"}, "request"], "effects": ["preq"], "range": "*", "nodes": ["node_modules/requestretry"], "fixAvailable": false}, "service-runner": {"name": "service-runner", "severity": "moderate", "isDirect": true, "via": ["limitation"], "effects": [], "range": ">=3.1.0", "nodes": ["node_modules/service-runner"], "fixAvailable": {"name": "service-runner", "version": "3.0.0", "isSemVerMajor": true}}, "swagger-ui-dist": {"name": "swagger-ui-dist", "severity": "moderate", "isDirect": true, "via": [{"source": 1088759, "name": "swagger-ui-dist", "dependency": "swagger-ui-dist", "title": "Spoofing attack in swagger-ui-dist", "url": "https://github.com/advisories/GHSA-6c9x-mj3g-h47x", "severity": "moderate", "cwe": ["CWE-1021"], "cvss": {"score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}, "range": "<4.1.3"}, {"source": 1092160, "name": "swagger-ui-dist", "dependency": "swagger-ui-dist", "title": "Server side request forgery in SwaggerUI", "url": "https://github.com/advisories/GHSA-qrmm-w75w-3wpx", "severity": "moderate", "cwe": ["CWE-918"], "cvss": {"score": 0, "vectorString": null}, "range": "<4.1.3"}], "effects": [], "range": "<=4.1.2", "nodes": ["node_modules/swagger-ui-dist"], "fixAvailable": {"name": "swagger-ui-dist", "version": "5.20.2", "isSemVerMajor": true}}, "tough-cookie": {"name": "tough-cookie", "severity": "moderate", "isDirect": false, "via": [{"source": 1097682, "name": "tough-cookie", "dependency": "tough-cookie", "title": "tough-cookie Prototype Pollution vulnerability", "url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3", "severity": "moderate", "cwe": ["CWE-1321"], "cvss": {"score": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}, "range": "<4.1.3"}], "effects": ["request"], "range": "<4.1.3", "nodes": ["node_modules/tough-cookie"], "fixAvailable": false}, "wikimedia-kad-fork": {"name": "wikimedia-kad-fork", "severity": "moderate", "isDirect": false, "via": ["ms"], "effects": ["limitation"], "range": "*", "nodes": ["node_modules/wikimedia-kad-fork"], "fixAvailable": {"name": "service-runner", "version": "3.0.0", "isSemVerMajor": true}}}, "metadata": {"vulnerabilities": {"info": 0, "low": 0, "moderate": 7, "high": 3, "critical": 0, "total": 10}, "dependencies": {"prod": 247, "dev": 397, "optional": 15, "peer": 1, "peerOptional": 0, "total": 657}}}} $ /usr/bin/npm audit fix --only=dev --- stderr --- npm WARN invalid config only="dev" set in command line options npm WARN invalid config Must be one of: null, prod, production npm WARN EBADENGINE Unsupported engine { npm WARN EBADENGINE package: 'citoid@1.3.0', npm WARN EBADENGINE required: { node: '20' }, npm WARN EBADENGINE current: { node: 'v18.19.0', npm: '9.2.0' } npm WARN EBADENGINE } npm WARN deprecated kad-fs@0.0.4: This package is no longer maintained. npm WARN deprecated har-validator@5.1.5: this library is no longer supported npm WARN deprecated kad-memstore@0.0.1: This package is no longer maintained. npm WARN deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm WARN deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details. npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details. npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142 --- stdout --- added 657 packages, and audited 658 packages in 10s 117 packages are looking for funding run `npm fund` for details # npm audit report ip * Severity: high ip SSRF improper categorization in isPublic - https://github.com/advisories/GHSA-2p57-rm9w-gvfp No fix available node_modules/ip ms <2.0.0 Severity: moderate Vercel ms Inefficient Regular Expression Complexity vulnerability - https://github.com/advisories/GHSA-w9mr-4mfr-499f fix available via `npm audit fix --force` Will install service-runner@3.0.0, which is a breaking change node_modules/wikimedia-kad-fork/node_modules/ms wikimedia-kad-fork * Depends on vulnerable versions of ms node_modules/wikimedia-kad-fork limitation >=0.2.3 Depends on vulnerable versions of wikimedia-kad-fork node_modules/limitation service-runner >=3.1.0 Depends on vulnerable versions of limitation node_modules/service-runner request * Severity: moderate Server-Side Request Forgery in Request - https://github.com/advisories/GHSA-p8p7-x288-28g6 Depends on vulnerable versions of tough-cookie No fix available node_modules/request preq * Depends on vulnerable versions of request Depends on vulnerable versions of requestretry node_modules/preq requestretry * Depends on vulnerable versions of request node_modules/requestretry swagger-ui-dist <=4.1.2 Severity: moderate Spoofing attack in swagger-ui-dist - https://github.com/advisories/GHSA-6c9x-mj3g-h47x Server side request forgery in SwaggerUI - https://github.com/advisories/GHSA-qrmm-w75w-3wpx fix available via `npm audit fix --force` Will install swagger-ui-dist@5.20.2, which is a breaking change node_modules/swagger-ui-dist tough-cookie <4.1.3 Severity: moderate tough-cookie Prototype Pollution vulnerability - https://github.com/advisories/GHSA-72xf-g2v4-qvf3 No fix available node_modules/tough-cookie 10 vulnerabilities (7 moderate, 3 high) To address all issues possible (including breaking changes), run: npm audit fix --force Some issues need review, and may require choosing a different dependency. --- end --- Verifying that tests still pass $ /usr/bin/npm ci --- stderr --- npm WARN EBADENGINE Unsupported engine { npm WARN EBADENGINE package: 'citoid@1.3.0', npm WARN EBADENGINE required: { node: '20' }, npm WARN EBADENGINE current: { node: 'v18.19.0', npm: '9.2.0' } npm WARN EBADENGINE } npm WARN deprecated kad-fs@0.0.4: This package is no longer maintained. npm WARN deprecated har-validator@5.1.5: this library is no longer supported npm WARN deprecated kad-memstore@0.0.1: This package is no longer maintained. npm WARN deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm WARN deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details. npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details. npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142 --- stdout --- added 657 packages, and audited 658 packages in 9s 117 packages are looking for funding run `npm fund` for details 10 vulnerabilities (7 moderate, 3 high) To address all issues possible (including breaking changes), run: npm audit fix --force Some issues need review, and may require choosing a different dependency. Run `npm audit` for details. --- end --- $ /usr/bin/npm test --- stdout --- > citoid@1.3.0 test > npm run lint && mocha ./test/features/unit/* && mocha ./test/features/errors/* && mocha ./test/features/app/* > citoid@1.3.0 lint > eslint --max-warnings 0 --cache . cachedTypes zotero methods ✔ returns false if no base types exist ✔ gets base types - no creators ✔ gets base types - with creators creator types methods ✔ gets creator type ids ✔ returns empty list if no create type ids exist ✔ gets primary creator id from type ✔ gets creator name from id ✔ gets primary creator id from name ✔ determines if creatorType valid for type- true ✔ determines if creatorType valid for type- false item fields methods ✔ determines if id is valid for type- false ✔ determines if id is valid for type- true ✔ determines if creator field is valid for type- true ✔ determines if creator field is valid for type- false ✔ get field id from type and base ✔ get base id from type and field ✔ get item type fields ✔ gets field name from id ✔ gets id from field name lib/Exporter.js functions: validation functions: fixURL: ✔ discards url with no host ✔ adds protocol to url when missing fixWebsiteTitle: ✔ Adds missing website title ✔ Does not add missing website title if itemType is missing ✔ Does not add missing website title if url is relative addIDSToCitation: ✔ cleans script and html out of title stripCitation: ✔ cleans script and html out of title ✔ does not clean doi fixDate: ✔ Contains copyright symbol ✔ Is in brackets for some unfathomable reason ✔ Contains copyright symbol & whitespace ✔ Contains c symbol ✔ sets year only date to year only date ✔ converts American style date to ISO ✔ Unable to parse so leaves as written; season (226ms) ✔ Chooses worldcat publication year ✔ Multilingual date - Spanish - leaves as written ✔ Multilingual date - Russian - leaves as written (38ms) ✔ Normal date ✔ Normal date with ordinal indicator ✔ Correctly sets normal date with ordinal number ✔ Date on the fence: ISO with - notation ✔ Date on the fence; ISO with + notation ✔ Date on the fence; toString output ✔ Date on the fence; ISO with Z notation ✔ Year first date ✔ Partial ISO date no preceeding 0 ✔ Full ISO date no preceeding 0 ✔ Full ISO date no preceeding 0 month or day ✔ Slashes full date ✔ Slashes partial date ✔ Slashes partial date with 0 month - Slashes partial date with 00s ✔ Slashes partial year with 00s ✔ XX partial date ✔ XX partial year ✔ unix timestamp ✔ unix timestamp with space fixDOI: ✔ Correctly gets DOI from full citation ✔ Correctly removes DOI that is not a DOI ✔ Correctly gets DOI when only DOI is present fixISBN: ✔ Correctly hyphenates single ISBN-10 ✔ Correctly handles ISBN-13s that have spaces in them ✔ Correctly extracts two ISBN-10s ✔ Correctly extracts ISBN-13 ✔ Correctly extracts ISBN-10 and ISBN-13 ✔ Correctly handles and normalizes hyphenated ISBN ✔ Correctly handles ISBNs with and without hyphens ✔ Correctly handles multiple ISBN-13s that have spaces in them ✔ Correctly handles out comma separated ISBNs fixISSN: ✔ Correctly ignores None ISSN ✔ Correctly adds valid ISSN ✔ Correctly adds valid ISSN with X ✔ Correctly adds valid ISSN with x ✔ Correctly ignores invalid ISSN without hyphen ✔ Correctly ignores invalid ISSN fixPages: ✔ converts hyphen minus to en dash replaceCreators: ✔ Correctly adds name with firstName and lastName present ✔ Correctly adds names with only lastName or firstName present ✔ Adds names with name field ✔ Doesn't add names with incorrect field name export formats: wikibase: different search term types ✔ url from search, doi from result ✔ doi from search, no url ✔ qid, no url ✔ pmid, no url ✔ pmcid, no url different item types ✔ itemType webpage ✔ itemType book ✔ itemType journalArticle lib/Scraper.js functions: matchIDs function: ✔ gets doi from bePress string ✔ gets doi from bePress Array ✔ gets doi from highwirePress string ✔ gets doi from highwirePress Array ✔ gets doi from dublinCore string ✔ gets doi from dublinCore Array ✔ Returns empty metadata from empty object ✔ Multiple metadata types parsing ✔ should scrape meta tag charset content Tests for Translator.js : translate function on html: ✔ translates bePress metadata from movie file ✔ translates bePress metadata from article file ✔ translates bePress metadata from song file ✔ translates highwirePress metadata from movie file ✔ translates highwirePress metadata from article file ✔ translates highwirePress metadata from song file ✔ translates coins metadata from movie file ✔ translates coins metadata from article file ✔ translates coins metadata from song file ✔ translates dublinCore metadata from movie file ✔ translates dublinCore metadata from article file ✔ translates dublinCore metadata from song file ✔ translates general metadata from movie file ✔ translates general metadata from article file ✔ translates general metadata from song file ✔ translates openGraph metadata from movie file ✔ translates openGraph metadata from article file ✔ translates openGraph metadata from song file translate function on json: ✔ sets right info from journal-article crossRef metadata ✔ sets right info from book-section crossRef metadata ✔ tests every itemType for crossRef translator on every sample crossRef file addItemType function: ✔ sets videoRecording itemType ✔ sets article itemType ✔ sets audioRecording itemType from openGraph ✔ sets itemType webpage if no relevant metadata available check specific results: ✔ sets right info from webpage for general metadata ✔ sets right info from webpage for bepress metadata coins metadata ✔ Correctly adds pages from spage and epage ✔ Correctly fixes en dash in pages fields ✔ Correctly adds date exports.other.addCreators function ✔ Doesn't add empty creators field ✔ Doesn't add creators field if missing itemType - Doesn't add duplicate author names - Doesn't add duplicate author names with nbsp present ✔ Correctly adds name with missing firstname ✔ Correctly adds name with missing lastname ✔ Correctly uses aulast, auinit1 and auinitm ✔ Correctly uses auinit1 and auinitm ✔ Correctly adds corporation names ✔ Does split names in au field crossRef translator unit ✔ Creator translate function adds lists of strings dateParts function ✔ Translates full date ✔ Translates year and day ✔ Translates year only ✔ Fails with object ✔ Fails with list not nested ✔ Works with strings date - Does not work with unexpected input dublinCore translator unit ✔ Creator translate function adds lists of strings ✔ Correctly adds an author string with one word ✔ Correctly adds an author string with two words ✔ Correctly adds an author string with three words general translator unit ✔ Author function adds lists of strings ✔ Correctly adds an author string with one word ✔ Correctly adds an author string with two words ✔ Correctly adds an author string with three words ✔ Does not try to split Harry Potter author field from worldcat translator utilities: makeTranslator function: ✔ strips leading and trailing whitespace ✔ replaces nonbreaking space characters with spaces ✔ correctly adds date with fixDate validate function ✔ correctly uses fixLang validate function makePagesTranslator function: ✔ Uses spage and epage ✔ Uses optional pages arg and converts - to en dash makeListTranslator function: ✔ Correctly adds one isbn ✔ Correctly uses isbn validate function ✔ Correctly uses issn validate function ✔ Correctly adds two issn and one eissn ✔ Correctly adds two isbn makeCreatorsTranslator function: ✔ Name as written ✔ Has multiple authors in the field ✔ Format Last name, first name ✔ Adds two different contributor types lib/unshorten.js debug/unshorten Unshortening: http://www.example.com debug/unshorten Already unshortened to: http://www.example.com ✔ Returns successful Promise if already unshortened 166 passing (704ms) 4 pending address restrictions {"name":"citoid","hostname":"dec48984f856","pid":437,"level":50,"levelPath":"error/metrics","msg":"No such metrics client: 'undefined'","time":"2025-03-27T16:45:54.261Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/hostIsAllowed","request_id":"f3799990-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2Flocalhost%3A1970","headers":{"content-length":"0","x-request-id":"f3799990-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://localhost:1970"},"remoteAddress":"127.0.0.1","remotePort":35470},"msg":"http://localhost:1970 is not public, and is disallowed","time":"2025-03-27T16:45:54.989Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://localhost:1970","outgoingReqResult":{"error":"AddressError"},"request_id":"f3799990-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2Flocalhost%3A1970","headers":{"content-length":"0","x-request-id":"f3799990-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://localhost:1970"},"remoteAddress":"127.0.0.1","remotePort":35470},"levelPath":"warn/CitoidService","time":"2025-03-27T16:45:58.291Z","v":0} ✔ http://localhost:1970 (3352ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/hostIsAllowed","request_id":"f574a640-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2F127.0.0.1%3A1970","headers":{"content-length":"0","x-request-id":"f574a640-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://127.0.0.1:1970"},"remoteAddress":"127.0.0.1","remotePort":35482},"msg":"http://127.0.0.1:1970 is not public, and is disallowed","time":"2025-03-27T16:45:58.311Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://127.0.0.1:1970","outgoingReqResult":{"error":"AddressError"},"request_id":"f574a640-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2F127.0.0.1%3A1970","headers":{"content-length":"0","x-request-id":"f574a640-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://127.0.0.1:1970"},"remoteAddress":"127.0.0.1","remotePort":35482},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:03.543Z","v":0} ✔ http://127.0.0.1:1970 (5244ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://foobarbaz.example.com/","outgoingReqResult":{"error":"AddressError"},"request_id":"f8952020-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2Ffoobarbaz.example.com%2F","headers":{"content-length":"0","x-request-id":"f8952020-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://foobarbaz.example.com/"},"remoteAddress":"127.0.0.1","remotePort":50530},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:08.070Z","v":0} ✔ non-existing (4526ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/hostIsAllowed","request_id":"fb47e410-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2F10.0.0.5%2F","headers":{"content-length":"0","x-request-id":"fb47e410-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://10.0.0.5/"},"remoteAddress":"127.0.0.1","remotePort":50538},"msg":"http://10.0.0.5/ is not public, and is disallowed","time":"2025-03-27T16:46:08.084Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://10.0.0.5/","outgoingReqResult":{"error":"AddressError"},"request_id":"fb47e410-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2F10.0.0.5%2F","headers":{"content-length":"0","x-request-id":"fb47e410-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://10.0.0.5/"},"remoteAddress":"127.0.0.1","remotePort":50538},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:12.623Z","v":0} ✔ 10.0.0.5 (4551ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/hostIsAllowed","request_id":"fdfe9fa0-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2F192.168.1.2","headers":{"content-length":"0","x-request-id":"fdfe9fa0-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://192.168.1.2"},"remoteAddress":"127.0.0.1","remotePort":50546},"msg":"http://192.168.1.2 is not public, and is disallowed","time":"2025-03-27T16:46:12.637Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://192.168.1.2","outgoingReqResult":{"error":"AddressError"},"request_id":"fdfe9fa0-0b2a-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2F192.168.1.2","headers":{"content-length":"0","x-request-id":"fdfe9fa0-0b2a-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://192.168.1.2"},"remoteAddress":"127.0.0.1","remotePort":50546},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:17.809Z","v":0} ✔ private ip (5183ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/zotero","request_id":"0115f1c0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fen.wikipedia.org%2Fw%2Findex.php%3Ftitle%3DInternet_Assigned_Numbers_Authority%26oldid%3D664999436","headers":{"content-length":"0","x-request-id":"0115f1c0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://en.wikipedia.org/w/index.php?title=Internet_Assigned_Numbers_Authority&oldid=664999436"},"remoteAddress":"127.0.0.1","remotePort":58008},"msg":"No Zot response available for https://en.wikipedia.org/w/index.php?title=Internet_Assigned_Numbers_Authority&oldid=664999436","time":"2025-03-27T16:46:18.850Z","v":0} ✔ acceptable domain, with scheme (1381ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/zotero","request_id":"01e8ab10-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=en.wikipedia.org%2Fw%2Findex.php%3Ftitle%3DInternet_Assigned_Numbers_Authority%26oldid%3D664999436","headers":{"content-length":"0","x-request-id":"01e8ab10-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"en.wikipedia.org/w/index.php?title=Internet_Assigned_Numbers_Authority&oldid=664999436"},"remoteAddress":"127.0.0.1","remotePort":58022},"msg":"No Zot response available for https://en.wikipedia.org/w/index.php?title=internet_assigned_numbers_authority&oldid=664999436","time":"2025-03-27T16:46:19.443Z","v":0} ✔ acceptable domain, without scheme (452ms) encoding {"name":"citoid","hostname":"dec48984f856","pid":437,"level":50,"levelPath":"error/metrics","msg":"No such metrics client: 'undefined'","time":"2025-03-27T16:46:19.655Z","v":0} ✔ javascript in format {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/pubmed","request_id":"0231e910-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=10.1000%2Ff%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E","headers":{"content-length":"0","x-request-id":"0231e910-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"10.1000/f<script>alert(1);</script>"},"remoteAddress":"127.0.0.1","remotePort":58056},"msg":"Unknown pubmed error","time":"2025-03-27T16:46:19.717Z","v":0} ✔ javascript in doi (334ms) ✔ json in format {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://www.example.com/spaces%20in%20url","outgoingReqResult":{"status":404,"error":"HTTPError","hostname":"www.example.com","uri":"http://www.example.com/spaces%20in%20url"},"request_id":"02663f80-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2Fwww.example.com%2Fspaces%20in%20url","headers":{"content-length":"0","x-request-id":"02663f80-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://www.example.com/spaces in url"},"remoteAddress":"127.0.0.1","remotePort":58078},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:22.717Z","v":0} ✔ spaces in fully qualified url (2698ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://www.example.com/spaces%20in%20url","outgoingReqResult":{"status":404,"error":"HTTPError","hostname":"www.example.com","uri":"http://www.example.com/spaces%20in%20url"},"request_id":"04023c40-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=www.example.com%2Fspaces%20in%20url","headers":{"content-length":"0","x-request-id":"04023c40-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"www.example.com/spaces in url"},"remoteAddress":"127.0.0.1","remotePort":58088},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:22.872Z","v":0} ✔ spaces in url missing http:// (155ms) errors {"name":"citoid","hostname":"dec48984f856","pid":437,"level":50,"levelPath":"error/metrics","msg":"No such metrics client: 'undefined'","time":"2025-03-27T16:46:22.880Z","v":0} ✔ missing search in query (39ms) ✔ missing format in query ✔ bad format in query {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for https://example./com","outgoingReqResult":{"error":"AddressError"},"request_id":"04263f00-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=example.%2Fcom","headers":{"content-length":"0","x-request-id":"04263f00-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"example./com"},"remoteAddress":"127.0.0.1","remotePort":50736},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:27.678Z","v":0} ✔ bad domain (4726ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for https://en.wikipedia.org/404","outgoingReqResult":{"status":404,"error":"HTTPError","hostname":"en.wikipedia.org","uri":"https://en.wikipedia.org/404"},"request_id":"06f823b0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fen.wikipedia.org%2F404","headers":{"content-length":"0","x-request-id":"06f823b0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://en.wikipedia.org/404"},"remoteAddress":"127.0.0.1","remotePort":50752},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:32.874Z","v":0} ✔ resource has http errors (5195ms) ✔ unknown doi (214ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/pubmed","request_id":"0a3155b0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2FDOI.org%2F10.1007%2F11926078_68%27","headers":{"content-length":"0","x-request-id":"0a3155b0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://DOI.org/10.1007/11926078_68'"},"remoteAddress":"127.0.0.1","remotePort":56998},"msg":"Unknown pubmed error","time":"2025-03-27T16:46:33.300Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://DOI.org/10.1007/11926078_68'","outgoingReqResult":{"status":404,"error":"HTTPError","hostname":"doi.org","uri":"https://doi.org/10.1007/11926078_68%27"},"request_id":"0a3155b0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2FDOI.org%2F10.1007%2F11926078_68%27","headers":{"content-length":"0","x-request-id":"0a3155b0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://DOI.org/10.1007/11926078_68'"},"remoteAddress":"127.0.0.1","remotePort":56998},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:38.285Z","v":0} ✔ doi url with single quote (5372ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/pubmed","request_id":"0a3155b0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2FDOI.org%2F10.1007%2F11926078_68%27","headers":{"content-length":"0","x-request-id":"0a3155b0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://DOI.org/10.1007/11926078_68'"},"remoteAddress":"127.0.0.1","remotePort":56998},"msg":"Unknown pubmed error","time":"2025-03-27T16:46:38.688Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for http://DOI.org/10.1007/11926078_68%22","outgoingReqResult":{"status":404,"error":"HTTPError","hostname":"doi.org","uri":"https://doi.org/10.1007/11926078_68%22"},"request_id":"0d653080-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2FDOI.org%2F10.1007%2F11926078_68%22","headers":{"content-length":"0","x-request-id":"0d653080-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://DOI.org/10.1007/11926078_68\""},"remoteAddress":"127.0.0.1","remotePort":57014},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:43.658Z","v":0} ✔ doi url with double quote (5352ms) ✔ doi with single quote (187ms) - bad pmid - bad pmcid redirects {"name":"citoid","hostname":"dec48984f856","pid":437,"level":50,"levelPath":"error/metrics","msg":"No such metrics client: 'undefined'","time":"2025-03-27T16:46:44.015Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/pubmed","request_id":"10962520-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=10.1007%2F11926078_68%27","headers":{"content-length":"0","x-request-id":"10962520-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"10.1007/11926078_68'"},"remoteAddress":"127.0.0.1","remotePort":54384},"msg":"Unknown pubmed error","time":"2025-03-27T16:46:44.052Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/zotero","request_id":"10b7ddf0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttp%3A%2F%2Fwww.example.com","headers":{"content-length":"0","x-request-id":"10b7ddf0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=http://www.example.com"},"remoteAddress":"127.0.0.1","remotePort":54402},"msg":"No Zot response available for http://www.example.com","time":"2025-03-27T16:46:44.157Z","v":0} ✔ redirect supported (151ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/hostIsAllowed","request_id":"10cdd6f0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttp%3A%2F%2F192.168.1.2","headers":{"content-length":"0","x-request-id":"10cdd6f0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=http://192.168.1.2"},"remoteAddress":"127.0.0.1","remotePort":54412},"msg":"http://192.168.1.2 is not public, and is disallowed","time":"2025-03-27T16:46:44.199Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for https://httpbin.org/redirect-to?url=http://192.168.1.2","outgoingReqResult":{"error":"AddressError"},"request_id":"10cdd6f0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttp%3A%2F%2F192.168.1.2","headers":{"content-length":"0","x-request-id":"10cdd6f0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=http://192.168.1.2"},"remoteAddress":"127.0.0.1","remotePort":54412},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:49.369Z","v":0} ✔ redir-to-private (5184ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/hostIsAllowed","request_id":"13e57730-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttp%3A%2F%2F192.168.1.2","headers":{"content-length":"0","x-request-id":"13e57730-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=http://192.168.1.2"},"remoteAddress":"127.0.0.1","remotePort":54416},"msg":"http://192.168.1.2 is not public, and is disallowed","time":"2025-03-27T16:46:49.399Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=http://192.168.1.2","outgoingReqResult":{"error":"AddressError"},"request_id":"13e57730-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttp%3A%2F%2F192.168.1.2","headers":{"content-length":"0","x-request-id":"13e57730-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=http://192.168.1.2"},"remoteAddress":"127.0.0.1","remotePort":54416},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:54.556Z","v":0} ✔ redir-to-redir-private (5184ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/zotero","request_id":"16fcf060-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3D%2Fredirect-to%3Furl%3Dhttp%3A%2F%2Fexample.com","headers":{"content-length":"0","x-request-id":"16fcf060-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=/redirect-to?url=http://example.com"},"remoteAddress":"127.0.0.1","remotePort":47038},"msg":"No Zot response available for http://example.com","time":"2025-03-27T16:46:54.604Z","v":0} ✔ follows relative redirects (90ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/hostIsAllowed","request_id":"170a5de0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttp%3A%2F%2F192.168.1.2","headers":{"content-length":"0","x-request-id":"170a5de0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=http://192.168.1.2"},"remoteAddress":"127.0.0.1","remotePort":47040},"msg":"http://192.168.1.2 is not public, and is disallowed","time":"2025-03-27T16:46:54.677Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=http://192.168.1.2","outgoingReqResult":{"error":"AddressError"},"request_id":"170a5de0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttp%3A%2F%2F192.168.1.2","headers":{"content-length":"0","x-request-id":"170a5de0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=http://192.168.1.2"},"remoteAddress":"127.0.0.1","remotePort":47040},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:55.731Z","v":0} ✔ redir-to-redir-to-redir-to-private (1083ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/zotero","request_id":"17b03ad0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fen.wikipedia.org%2Fwiki%2FZotero","headers":{"content-length":"0","x-request-id":"17b03ad0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://en.wikipedia.org/wiki/Zotero"},"remoteAddress":"127.0.0.1","remotePort":47048},"msg":"No Zot response available for https://en.wikipedia.org/wiki/Zotero","time":"2025-03-27T16:46:55.812Z","v":0} ✔ five-redirect-max-by-default-under (432ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"levelPath":"warn/zotero","request_id":"17f24ce0-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fen.wikipedia.org%2Fwiki%2FZotero","headers":{"content-length":"0","x-request-id":"17f24ce0-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://en.wikipedia.org/wiki/Zotero"},"remoteAddress":"127.0.0.1","remotePort":47050},"msg":"No Zot response available for https://en.wikipedia.org/wiki/Zotero","time":"2025-03-27T16:46:56.222Z","v":0} ✔ five-redirect-max-by-default-equal (210ms) {"name":"citoid","hostname":"dec48984f856","pid":437,"level":40,"msg":"requestFromURL failed for https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://en.wikipedia.org/wiki/Zotero","outgoingReqResult":{"error":"AddressError"},"request_id":"18125800-0b2b-11f0-9cc3-7d4a74d268c4","request":{"url":"/api?format=mediawiki&search=https%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fhttpbin.org%2Fredirect-to%3Furl%3Dhttps%3A%2F%2Fen.wikipedia.org%2Fwiki%2FZotero","headers":{"content-length":"0","x-request-id":"18125800-0b2b-11f0-9cc3-7d4a74d268c4"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://httpbin.org/redirect-to?url=https://en.wikipedia.org/wiki/Zotero"},"remoteAddress":"127.0.0.1","remotePort":47056},"levelPath":"warn/CitoidService","time":"2025-03-27T16:46:56.926Z","v":0} ✔ five-redirect-max-by-default-over (546ms) 29 passing (1m) 2 pending citoid routing {"name":"citoid","hostname":"dec48984f856","pid":448,"level":50,"levelPath":"error/metrics","msg":"No such metrics client: 'undefined'","time":"2025-03-27T16:47:02.127Z","v":0} {"name":"citoid","hostname":"dec48984f856","pid":448,"level":40,"levelPath":"warn/zotero","request_id":"1be495b0-0b2b-11f0-be45-25c3db8e64d8","request":{"url":"/mediawiki/http%3A%2F%2Fwww.example.com","headers":{"user-agent":"undici","x-request-id":"1be495b0-0b2b-11f0-be45-25c3db8e64d8"},"method":"GET","params":{"0":"/mediawiki/http://www.example.com"},"query":{"format":"mediawiki","search":"http://www.example.com"},"remoteAddress":"127.0.0.1","remotePort":47058},"msg":"No Zot response available for http://www.example.com","time":"2025-03-27T16:47:02.874Z","v":0} ✔ should get restbase style shim request for uri (175ms) ✔ should error for missing search param {"name":"citoid","hostname":"dec48984f856","pid":448,"level":40,"levelPath":"warn/zotero","request_id":"1bfbc730-0b2b-11f0-be45-25c3db8e64d8","request":{"url":"/mediawiki/10.1371%2Fjournal.pcbi.1002947","headers":{"user-agent":"undici","x-request-id":"1bfbc730-0b2b-11f0-be45-25c3db8e64d8"},"method":"GET","params":{"0":"/mediawiki/10.1371/journal.pcbi.1002947"},"query":{"format":"mediawiki","search":"10.1371/journal.pcbi.1002947"},"remoteAddress":"127.0.0.1","remotePort":47058},"msg":"No Zot response available for https://journals.plos.org/ploscompbiol/article?id=10.1371/journal.pcbi.1002947","time":"2025-03-27T16:47:03.733Z","v":0} ✔ should get restbase style shim request for doi (1640ms) {"name":"citoid","hostname":"dec48984f856","pid":448,"level":40,"levelPath":"warn/zotero","request_id":"1cf653d0-0b2b-11f0-be45-25c3db8e64d8","request":{"url":"/api?format=mediawiki&search=http%3A%2F%2Fexample.com","headers":{"content-length":"0","x-request-id":"1cf653d0-0b2b-11f0-be45-25c3db8e64d8"},"method":"GET","params":{"0":"/api"},"query":{"format":"mediawiki","search":"http://example.com"},"remoteAddress":"127.0.0.1","remotePort":41694},"msg":"No Zot response available for http://example.com","time":"2025-03-27T16:47:04.601Z","v":0} ✔ should get non-restbase style request for uri (39ms) express app {"name":"citoid","hostname":"dec48984f856","pid":448,"level":50,"levelPath":"error/metrics","msg":"No such metrics client: 'undefined'","time":"2025-03-27T16:47:04.633Z","v":0} ✔ should get robots.txt ✔ get landing page ✔ should set CORS headers ✔ should set CSP headers service information {"name":"citoid","hostname":"dec48984f856","pid":448,"level":50,"levelPath":"error/metrics","msg":"No such metrics client: 'undefined'","time":"2025-03-27T16:47:04.671Z","v":0} ✔ should get the service name ✔ should get the service version ✔ should redirect to the service home page ✔ should get the service info ✔ should fail to get the service info for invalid endpoint 13 passing (3s) --- end --- $ package-lock-lint package-lock.json --- stdout --- Checking package-lock.json --- end --- [DNM] there are no updates $ git add . --- stdout --- --- end --- $ git commit -F /tmp/tmphpgc9i02 --- stdout --- On branch master Your branch is up to date with 'origin/master'. nothing to commit, working tree clean --- end ---