wikimedia/toolhub: main (log #573597)

sourcepatches

This run took 135 seconds.

$ date
--- stdout ---
Wed Apr 27 14:09:26 UTC 2022

--- end ---
$ git clone file:///srv/git/wikimedia-toolhub.git repo --depth=1 -b main
--- stderr ---
Cloning into 'repo'...
--- stdout ---

--- end ---
$ git config user.name libraryupgrader
--- stdout ---

--- end ---
$ git config user.email tools.libraryupgrader@tools.wmflabs.org
--- stdout ---

--- end ---
$ git submodule update --init
--- stdout ---

--- end ---
$ grr init
--- stdout ---
Installed commit-msg hook.

--- end ---
$ git show-ref refs/heads/main
--- stdout ---
18d94da679c52d4d7c2e11c6a3b755b97a076282 refs/heads/main

--- end ---
$ /usr/bin/npm audit --json --legacy-peer-deps
--- stdout ---
{
  "auditReportVersion": 2,
  "vulnerabilities": {
    "@vue/cli-plugin-unit-mocha": {
      "name": "@vue/cli-plugin-unit-mocha",
      "severity": "moderate",
      "via": [
        "mocha"
      ],
      "effects": [],
      "range": ">=5.0.0-alpha.0",
      "nodes": [
        "node_modules/@vue/cli-plugin-unit-mocha"
      ],
      "fixAvailable": {
        "name": "@vue/cli-plugin-unit-mocha",
        "version": "4.5.17",
        "isSemVerMajor": true
      }
    },
    "ansi-regex": {
      "name": "ansi-regex",
      "severity": "high",
      "via": [
        {
          "source": 1070250,
          "name": "ansi-regex",
          "dependency": "ansi-regex",
          "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
          "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
          "severity": "high",
          "range": ">=3.0.0 <3.0.1"
        },
        {
          "source": 1070251,
          "name": "ansi-regex",
          "dependency": "ansi-regex",
          "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
          "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
          "severity": "high",
          "range": ">=4.0.0 <4.1.1"
        },
        {
          "source": 1070252,
          "name": "ansi-regex",
          "dependency": "ansi-regex",
          "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
          "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
          "severity": "high",
          "range": ">=5.0.0 <5.0.1"
        }
      ],
      "effects": [],
      "range": "3.0.0 || 4.0.0 - 4.1.0 || 5.0.0",
      "nodes": [
        "node_modules/ansi-regex",
        "node_modules/inquirer/node_modules/ansi-regex",
        "node_modules/log-update/node_modules/ansi-regex",
        "node_modules/mocha/node_modules/ansi-regex",
        "node_modules/nyc/node_modules/ansi-regex",
        "node_modules/wide-align/node_modules/ansi-regex"
      ],
      "fixAvailable": true
    },
    "async": {
      "name": "async",
      "severity": "high",
      "via": [
        {
          "source": 1070206,
          "name": "async",
          "dependency": "async",
          "title": "Prototype Pollution in async",
          "url": "https://github.com/advisories/GHSA-fwr7-v2mv-hh25",
          "severity": "high",
          "range": "<2.6.4"
        }
      ],
      "effects": [
        "jake"
      ],
      "range": "<2.6.4",
      "nodes": [
        "node_modules/async",
        "node_modules/portfinder/node_modules/async"
      ],
      "fixAvailable": true
    },
    "jake": {
      "name": "jake",
      "severity": "high",
      "via": [
        "async"
      ],
      "effects": [],
      "range": "8.0.1 - 10.8.4",
      "nodes": [
        "node_modules/jake"
      ],
      "fixAvailable": true
    },
    "json-pointer": {
      "name": "json-pointer",
      "severity": "moderate",
      "via": [
        {
          "source": 1067536,
          "name": "json-pointer",
          "dependency": "json-pointer",
          "title": "Prototype Pollution in json-pointer",
          "url": "https://github.com/advisories/GHSA-v5vg-g7rq-363w",
          "severity": "moderate",
          "range": "<=0.6.1"
        }
      ],
      "effects": [],
      "range": "<=0.6.1",
      "nodes": [
        "node_modules/json-pointer"
      ],
      "fixAvailable": true
    },
    "marked": {
      "name": "marked",
      "severity": "high",
      "via": [
        {
          "source": 1070026,
          "name": "marked",
          "dependency": "marked",
          "title": "Inefficient Regular Expression Complexity in marked",
          "url": "https://github.com/advisories/GHSA-rrrm-qjm4-v8hf",
          "severity": "high",
          "range": "<4.0.10"
        }
      ],
      "effects": [
        "rapidoc"
      ],
      "range": "<4.0.10",
      "nodes": [
        "node_modules/marked"
      ],
      "fixAvailable": true
    },
    "minimist": {
      "name": "minimist",
      "severity": "critical",
      "via": [
        {
          "source": 1067342,
          "name": "minimist",
          "dependency": "minimist",
          "title": "Prototype Pollution in minimist",
          "url": "https://github.com/advisories/GHSA-xvch-5gv4-984h",
          "severity": "critical",
          "range": "<1.2.6"
        }
      ],
      "effects": [],
      "range": "<1.2.6",
      "nodes": [
        "node_modules/minimist"
      ],
      "fixAvailable": true
    },
    "mocha": {
      "name": "mocha",
      "severity": "moderate",
      "via": [
        "nanoid"
      ],
      "effects": [
        "@vue/cli-plugin-unit-mocha"
      ],
      "range": "8.2.0 - 9.1.4",
      "nodes": [
        "node_modules/@vue/cli-plugin-unit-mocha/node_modules/mocha"
      ],
      "fixAvailable": {
        "name": "@vue/cli-plugin-unit-mocha",
        "version": "4.5.17",
        "isSemVerMajor": true
      }
    },
    "moment": {
      "name": "moment",
      "severity": "high",
      "via": [
        {
          "source": 1070245,
          "name": "moment",
          "dependency": "moment",
          "title": "Path Traversal: 'dir/../../filename' in moment.locale",
          "url": "https://github.com/advisories/GHSA-8hfj-j24r-96c4",
          "severity": "high",
          "range": "<2.29.2"
        }
      ],
      "effects": [],
      "range": "<2.29.2",
      "nodes": [
        "node_modules/moment"
      ],
      "fixAvailable": true
    },
    "nanoid": {
      "name": "nanoid",
      "severity": "moderate",
      "via": [
        {
          "source": 1067367,
          "name": "nanoid",
          "dependency": "nanoid",
          "title": "Exposure of Sensitive Information to an Unauthorized Actor in nanoid",
          "url": "https://github.com/advisories/GHSA-qrpm-p2h7-hrv2",
          "severity": "moderate",
          "range": ">=3.0.0 <3.1.31"
        }
      ],
      "effects": [
        "mocha"
      ],
      "range": "3.0.0 - 3.1.30",
      "nodes": [
        "node_modules/@vue/cli-plugin-unit-mocha/node_modules/nanoid"
      ],
      "fixAvailable": {
        "name": "@vue/cli-plugin-unit-mocha",
        "version": "4.5.17",
        "isSemVerMajor": true
      }
    },
    "node-forge": {
      "name": "node-forge",
      "severity": "high",
      "via": [
        {
          "source": 1067364,
          "name": "node-forge",
          "dependency": "node-forge",
          "title": "Improper Verification of Cryptographic Signature in node-forge",
          "url": "https://github.com/advisories/GHSA-cfm4-qjh2-4765",
          "severity": "high",
          "range": "<1.3.0"
        }
      ],
      "effects": [],
      "range": "<1.3.0",
      "nodes": [
        "node_modules/node-forge"
      ],
      "fixAvailable": true
    },
    "prismjs": {
      "name": "prismjs",
      "severity": "high",
      "via": [
        {
          "source": 1067401,
          "name": "prismjs",
          "dependency": "prismjs",
          "title": "Cross-site Scripting in Prism",
          "url": "https://github.com/advisories/GHSA-3949-f494-cm99",
          "severity": "high",
          "range": ">=1.14.0 <1.27.0"
        }
      ],
      "effects": [],
      "range": "1.14.0 - 1.26.0",
      "nodes": [
        "node_modules/prismjs"
      ],
      "fixAvailable": true
    },
    "rapidoc": {
      "name": "rapidoc",
      "severity": "high",
      "via": [
        "marked"
      ],
      "effects": [],
      "range": "<=9.1.3 || 9.1.5",
      "nodes": [
        "node_modules/rapidoc"
      ],
      "fixAvailable": true
    },
    "shelljs": {
      "name": "shelljs",
      "severity": "moderate",
      "via": [
        {
          "source": 1067451,
          "name": "shelljs",
          "dependency": "shelljs",
          "title": "Improper Privilege Management in shelljs",
          "url": "https://github.com/advisories/GHSA-64g7-mvw6-v9qj",
          "severity": "moderate",
          "range": "<0.8.5"
        }
      ],
      "effects": [],
      "range": "<0.8.5",
      "nodes": [
        "node_modules/shelljs"
      ],
      "fixAvailable": true
    }
  },
  "metadata": {
    "vulnerabilities": {
      "info": 0,
      "low": 0,
      "moderate": 5,
      "high": 8,
      "critical": 1,
      "total": 14
    },
    "dependencies": {
      "prod": 68,
      "dev": 2087,
      "optional": 3,
      "peer": 3,
      "peerOptional": 0,
      "total": 2154
    }
  }
}

--- end ---
$ /usr/bin/npm audit --json --legacy-peer-deps
--- stdout ---
{
  "auditReportVersion": 2,
  "vulnerabilities": {
    "@vue/cli-plugin-unit-mocha": {
      "name": "@vue/cli-plugin-unit-mocha",
      "severity": "moderate",
      "via": [
        "mocha"
      ],
      "effects": [],
      "range": ">=5.0.0-alpha.0",
      "nodes": [
        "node_modules/@vue/cli-plugin-unit-mocha"
      ],
      "fixAvailable": {
        "name": "@vue/cli-plugin-unit-mocha",
        "version": "4.5.17",
        "isSemVerMajor": true
      }
    },
    "ansi-regex": {
      "name": "ansi-regex",
      "severity": "high",
      "via": [
        {
          "source": 1070250,
          "name": "ansi-regex",
          "dependency": "ansi-regex",
          "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
          "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
          "severity": "high",
          "range": ">=3.0.0 <3.0.1"
        },
        {
          "source": 1070251,
          "name": "ansi-regex",
          "dependency": "ansi-regex",
          "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
          "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
          "severity": "high",
          "range": ">=4.0.0 <4.1.1"
        },
        {
          "source": 1070252,
          "name": "ansi-regex",
          "dependency": "ansi-regex",
          "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
          "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
          "severity": "high",
          "range": ">=5.0.0 <5.0.1"
        }
      ],
      "effects": [],
      "range": "3.0.0 || 4.0.0 - 4.1.0 || 5.0.0",
      "nodes": [
        "node_modules/ansi-regex",
        "node_modules/inquirer/node_modules/ansi-regex",
        "node_modules/log-update/node_modules/ansi-regex",
        "node_modules/mocha/node_modules/ansi-regex",
        "node_modules/nyc/node_modules/ansi-regex",
        "node_modules/wide-align/node_modules/ansi-regex"
      ],
      "fixAvailable": true
    },
    "async": {
      "name": "async",
      "severity": "high",
      "via": [
        {
          "source": 1070206,
          "name": "async",
          "dependency": "async",
          "title": "Prototype Pollution in async",
          "url": "https://github.com/advisories/GHSA-fwr7-v2mv-hh25",
          "severity": "high",
          "range": "<2.6.4"
        }
      ],
      "effects": [
        "jake"
      ],
      "range": "<2.6.4",
      "nodes": [
        "node_modules/async",
        "node_modules/portfinder/node_modules/async"
      ],
      "fixAvailable": true
    },
    "jake": {
      "name": "jake",
      "severity": "high",
      "via": [
        "async"
      ],
      "effects": [],
      "range": "8.0.1 - 10.8.4",
      "nodes": [
        "node_modules/jake"
      ],
      "fixAvailable": true
    },
    "json-pointer": {
      "name": "json-pointer",
      "severity": "moderate",
      "via": [
        {
          "source": 1067536,
          "name": "json-pointer",
          "dependency": "json-pointer",
          "title": "Prototype Pollution in json-pointer",
          "url": "https://github.com/advisories/GHSA-v5vg-g7rq-363w",
          "severity": "moderate",
          "range": "<=0.6.1"
        }
      ],
      "effects": [],
      "range": "<=0.6.1",
      "nodes": [
        "node_modules/json-pointer"
      ],
      "fixAvailable": true
    },
    "marked": {
      "name": "marked",
      "severity": "high",
      "via": [
        {
          "source": 1070026,
          "name": "marked",
          "dependency": "marked",
          "title": "Inefficient Regular Expression Complexity in marked",
          "url": "https://github.com/advisories/GHSA-rrrm-qjm4-v8hf",
          "severity": "high",
          "range": "<4.0.10"
        }
      ],
      "effects": [
        "rapidoc"
      ],
      "range": "<4.0.10",
      "nodes": [
        "node_modules/marked"
      ],
      "fixAvailable": true
    },
    "minimist": {
      "name": "minimist",
      "severity": "critical",
      "via": [
        {
          "source": 1067342,
          "name": "minimist",
          "dependency": "minimist",
          "title": "Prototype Pollution in minimist",
          "url": "https://github.com/advisories/GHSA-xvch-5gv4-984h",
          "severity": "critical",
          "range": "<1.2.6"
        }
      ],
      "effects": [],
      "range": "<1.2.6",
      "nodes": [
        "node_modules/minimist"
      ],
      "fixAvailable": true
    },
    "mocha": {
      "name": "mocha",
      "severity": "moderate",
      "via": [
        "nanoid"
      ],
      "effects": [
        "@vue/cli-plugin-unit-mocha"
      ],
      "range": "8.2.0 - 9.1.4",
      "nodes": [
        "node_modules/@vue/cli-plugin-unit-mocha/node_modules/mocha"
      ],
      "fixAvailable": {
        "name": "@vue/cli-plugin-unit-mocha",
        "version": "4.5.17",
        "isSemVerMajor": true
      }
    },
    "moment": {
      "name": "moment",
      "severity": "high",
      "via": [
        {
          "source": 1070245,
          "name": "moment",
          "dependency": "moment",
          "title": "Path Traversal: 'dir/../../filename' in moment.locale",
          "url": "https://github.com/advisories/GHSA-8hfj-j24r-96c4",
          "severity": "high",
          "range": "<2.29.2"
        }
      ],
      "effects": [],
      "range": "<2.29.2",
      "nodes": [
        "node_modules/moment"
      ],
      "fixAvailable": true
    },
    "nanoid": {
      "name": "nanoid",
      "severity": "moderate",
      "via": [
        {
          "source": 1067367,
          "name": "nanoid",
          "dependency": "nanoid",
          "title": "Exposure of Sensitive Information to an Unauthorized Actor in nanoid",
          "url": "https://github.com/advisories/GHSA-qrpm-p2h7-hrv2",
          "severity": "moderate",
          "range": ">=3.0.0 <3.1.31"
        }
      ],
      "effects": [
        "mocha"
      ],
      "range": "3.0.0 - 3.1.30",
      "nodes": [
        "node_modules/@vue/cli-plugin-unit-mocha/node_modules/nanoid"
      ],
      "fixAvailable": {
        "name": "@vue/cli-plugin-unit-mocha",
        "version": "4.5.17",
        "isSemVerMajor": true
      }
    },
    "node-forge": {
      "name": "node-forge",
      "severity": "high",
      "via": [
        {
          "source": 1067364,
          "name": "node-forge",
          "dependency": "node-forge",
          "title": "Improper Verification of Cryptographic Signature in node-forge",
          "url": "https://github.com/advisories/GHSA-cfm4-qjh2-4765",
          "severity": "high",
          "range": "<1.3.0"
        }
      ],
      "effects": [],
      "range": "<1.3.0",
      "nodes": [
        "node_modules/node-forge"
      ],
      "fixAvailable": true
    },
    "prismjs": {
      "name": "prismjs",
      "severity": "high",
      "via": [
        {
          "source": 1067401,
          "name": "prismjs",
          "dependency": "prismjs",
          "title": "Cross-site Scripting in Prism",
          "url": "https://github.com/advisories/GHSA-3949-f494-cm99",
          "severity": "high",
          "range": ">=1.14.0 <1.27.0"
        }
      ],
      "effects": [],
      "range": "1.14.0 - 1.26.0",
      "nodes": [
        "node_modules/prismjs"
      ],
      "fixAvailable": true
    },
    "rapidoc": {
      "name": "rapidoc",
      "severity": "high",
      "via": [
        "marked"
      ],
      "effects": [],
      "range": "<=9.1.3 || 9.1.5",
      "nodes": [
        "node_modules/rapidoc"
      ],
      "fixAvailable": true
    },
    "shelljs": {
      "name": "shelljs",
      "severity": "moderate",
      "via": [
        {
          "source": 1067451,
          "name": "shelljs",
          "dependency": "shelljs",
          "title": "Improper Privilege Management in shelljs",
          "url": "https://github.com/advisories/GHSA-64g7-mvw6-v9qj",
          "severity": "moderate",
          "range": "<0.8.5"
        }
      ],
      "effects": [],
      "range": "<0.8.5",
      "nodes": [
        "node_modules/shelljs"
      ],
      "fixAvailable": true
    }
  },
  "metadata": {
    "vulnerabilities": {
      "info": 0,
      "low": 0,
      "moderate": 5,
      "high": 8,
      "critical": 1,
      "total": 14
    },
    "dependencies": {
      "prod": 68,
      "dev": 2087,
      "optional": 3,
      "peer": 3,
      "peerOptional": 0,
      "total": 2154
    }
  }
}

--- end ---
Attempting to npm audit fix
$ /usr/bin/npm audit fix --dry-run --only=dev --json --legacy-peer-deps
--- stdout ---
{
  "added": 2163,
  "removed": 0,
  "changed": 0,
  "audited": 2164,
  "funding": 179,
  "audit": {
    "auditReportVersion": 2,
    "vulnerabilities": {
      "@vue/cli-plugin-unit-mocha": {
        "name": "@vue/cli-plugin-unit-mocha",
        "severity": "moderate",
        "via": [
          "mocha"
        ],
        "effects": [],
        "range": ">=5.0.0-alpha.0",
        "nodes": [
          ""
        ],
        "fixAvailable": {
          "name": "@vue/cli-plugin-unit-mocha",
          "version": "4.5.17",
          "isSemVerMajor": true
        }
      },
      "ansi-regex": {
        "name": "ansi-regex",
        "severity": "high",
        "via": [
          {
            "source": 1070250,
            "name": "ansi-regex",
            "dependency": "ansi-regex",
            "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
            "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
            "severity": "high",
            "range": ">=3.0.0 <3.0.1"
          },
          {
            "source": 1070251,
            "name": "ansi-regex",
            "dependency": "ansi-regex",
            "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
            "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
            "severity": "high",
            "range": ">=4.0.0 <4.1.1"
          },
          {
            "source": 1070252,
            "name": "ansi-regex",
            "dependency": "ansi-regex",
            "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
            "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
            "severity": "high",
            "range": ">=5.0.0 <5.0.1"
          }
        ],
        "effects": [],
        "range": "3.0.0 || 4.0.0 - 4.1.0 || 5.0.0",
        "nodes": [
          "",
          "",
          "",
          "",
          "",
          ""
        ],
        "fixAvailable": true
      },
      "async": {
        "name": "async",
        "severity": "high",
        "via": [
          {
            "source": 1070206,
            "name": "async",
            "dependency": "async",
            "title": "Prototype Pollution in async",
            "url": "https://github.com/advisories/GHSA-fwr7-v2mv-hh25",
            "severity": "high",
            "range": "<2.6.4"
          }
        ],
        "effects": [
          "jake"
        ],
        "range": "<2.6.4",
        "nodes": [
          "",
          ""
        ],
        "fixAvailable": true
      },
      "jake": {
        "name": "jake",
        "severity": "high",
        "via": [
          "async"
        ],
        "effects": [],
        "range": "8.0.1 - 10.8.4",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      },
      "json-pointer": {
        "name": "json-pointer",
        "severity": "moderate",
        "via": [
          {
            "source": 1067536,
            "name": "json-pointer",
            "dependency": "json-pointer",
            "title": "Prototype Pollution in json-pointer",
            "url": "https://github.com/advisories/GHSA-v5vg-g7rq-363w",
            "severity": "moderate",
            "range": "<=0.6.1"
          }
        ],
        "effects": [],
        "range": "<=0.6.1",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      },
      "marked": {
        "name": "marked",
        "severity": "high",
        "via": [
          {
            "source": 1070026,
            "name": "marked",
            "dependency": "marked",
            "title": "Inefficient Regular Expression Complexity in marked",
            "url": "https://github.com/advisories/GHSA-rrrm-qjm4-v8hf",
            "severity": "high",
            "range": "<4.0.10"
          }
        ],
        "effects": [
          "rapidoc"
        ],
        "range": "<4.0.10",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      },
      "minimist": {
        "name": "minimist",
        "severity": "critical",
        "via": [
          {
            "source": 1067342,
            "name": "minimist",
            "dependency": "minimist",
            "title": "Prototype Pollution in minimist",
            "url": "https://github.com/advisories/GHSA-xvch-5gv4-984h",
            "severity": "critical",
            "range": "<1.2.6"
          }
        ],
        "effects": [],
        "range": "<1.2.6",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      },
      "mocha": {
        "name": "mocha",
        "severity": "moderate",
        "via": [
          "nanoid"
        ],
        "effects": [
          "@vue/cli-plugin-unit-mocha"
        ],
        "range": "8.2.0 - 9.1.4",
        "nodes": [
          "node_modules/@vue/cli-plugin-unit-mocha/node_modules/mocha"
        ],
        "fixAvailable": {
          "name": "@vue/cli-plugin-unit-mocha",
          "version": "4.5.17",
          "isSemVerMajor": true
        }
      },
      "moment": {
        "name": "moment",
        "severity": "high",
        "via": [
          {
            "source": 1070245,
            "name": "moment",
            "dependency": "moment",
            "title": "Path Traversal: 'dir/../../filename' in moment.locale",
            "url": "https://github.com/advisories/GHSA-8hfj-j24r-96c4",
            "severity": "high",
            "range": "<2.29.2"
          }
        ],
        "effects": [],
        "range": "<2.29.2",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      },
      "nanoid": {
        "name": "nanoid",
        "severity": "moderate",
        "via": [
          {
            "source": 1067367,
            "name": "nanoid",
            "dependency": "nanoid",
            "title": "Exposure of Sensitive Information to an Unauthorized Actor in nanoid",
            "url": "https://github.com/advisories/GHSA-qrpm-p2h7-hrv2",
            "severity": "moderate",
            "range": ">=3.0.0 <3.1.31"
          }
        ],
        "effects": [
          "mocha"
        ],
        "range": "3.0.0 - 3.1.30",
        "nodes": [
          "node_modules/@vue/cli-plugin-unit-mocha/node_modules/nanoid"
        ],
        "fixAvailable": {
          "name": "@vue/cli-plugin-unit-mocha",
          "version": "4.5.17",
          "isSemVerMajor": true
        }
      },
      "node-forge": {
        "name": "node-forge",
        "severity": "high",
        "via": [
          {
            "source": 1067364,
            "name": "node-forge",
            "dependency": "node-forge",
            "title": "Improper Verification of Cryptographic Signature in node-forge",
            "url": "https://github.com/advisories/GHSA-cfm4-qjh2-4765",
            "severity": "high",
            "range": "<1.3.0"
          }
        ],
        "effects": [],
        "range": "<1.3.0",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      },
      "prismjs": {
        "name": "prismjs",
        "severity": "high",
        "via": [
          {
            "source": 1067401,
            "name": "prismjs",
            "dependency": "prismjs",
            "title": "Cross-site Scripting in Prism",
            "url": "https://github.com/advisories/GHSA-3949-f494-cm99",
            "severity": "high",
            "range": ">=1.14.0 <1.27.0"
          }
        ],
        "effects": [],
        "range": "1.14.0 - 1.26.0",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      },
      "rapidoc": {
        "name": "rapidoc",
        "severity": "high",
        "via": [
          "marked"
        ],
        "effects": [],
        "range": "<=9.1.3 || 9.1.5",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      },
      "shelljs": {
        "name": "shelljs",
        "severity": "moderate",
        "via": [
          {
            "source": 1067451,
            "name": "shelljs",
            "dependency": "shelljs",
            "title": "Improper Privilege Management in shelljs",
            "url": "https://github.com/advisories/GHSA-64g7-mvw6-v9qj",
            "severity": "moderate",
            "range": "<0.8.5"
          }
        ],
        "effects": [],
        "range": "<0.8.5",
        "nodes": [
          ""
        ],
        "fixAvailable": true
      }
    },
    "metadata": {
      "vulnerabilities": {
        "info": 0,
        "low": 0,
        "moderate": 5,
        "high": 8,
        "critical": 1,
        "total": 14
      },
      "dependencies": {
        "prod": 68,
        "dev": 2096,
        "optional": 3,
        "peer": 0,
        "peerOptional": 0,
        "total": 2163
      }
    }
  }
}

--- end ---
{"added": 2163, "removed": 0, "changed": 0, "audited": 2164, "funding": 179, "audit": {"auditReportVersion": 2, "vulnerabilities": {"@vue/cli-plugin-unit-mocha": {"name": "@vue/cli-plugin-unit-mocha", "severity": "moderate", "via": ["mocha"], "effects": [], "range": ">=5.0.0-alpha.0", "nodes": [""], "fixAvailable": {"name": "@vue/cli-plugin-unit-mocha", "version": "4.5.17", "isSemVerMajor": true}}, "ansi-regex": {"name": "ansi-regex", "severity": "high", "via": [{"source": 1070250, "name": "ansi-regex", "dependency": "ansi-regex", "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex", "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw", "severity": "high", "range": ">=3.0.0 <3.0.1"}, {"source": 1070251, "name": "ansi-regex", "dependency": "ansi-regex", "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex", "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw", "severity": "high", "range": ">=4.0.0 <4.1.1"}, {"source": 1070252, "name": "ansi-regex", "dependency": "ansi-regex", "title": " Inefficient Regular Expression Complexity in chalk/ansi-regex", "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw", "severity": "high", "range": ">=5.0.0 <5.0.1"}], "effects": [], "range": "3.0.0 || 4.0.0 - 4.1.0 || 5.0.0", "nodes": ["", "", "", "", "", ""], "fixAvailable": true}, "async": {"name": "async", "severity": "high", "via": [{"source": 1070206, "name": "async", "dependency": "async", "title": "Prototype Pollution in async", "url": "https://github.com/advisories/GHSA-fwr7-v2mv-hh25", "severity": "high", "range": "<2.6.4"}], "effects": ["jake"], "range": "<2.6.4", "nodes": ["", ""], "fixAvailable": true}, "jake": {"name": "jake", "severity": "high", "via": ["async"], "effects": [], "range": "8.0.1 - 10.8.4", "nodes": [""], "fixAvailable": true}, "json-pointer": {"name": "json-pointer", "severity": "moderate", "via": [{"source": 1067536, "name": "json-pointer", "dependency": "json-pointer", "title": "Prototype Pollution in json-pointer", "url": "https://github.com/advisories/GHSA-v5vg-g7rq-363w", "severity": "moderate", "range": "<=0.6.1"}], "effects": [], "range": "<=0.6.1", "nodes": [""], "fixAvailable": true}, "marked": {"name": "marked", "severity": "high", "via": [{"source": 1070026, "name": "marked", "dependency": "marked", "title": "Inefficient Regular Expression Complexity in marked", "url": "https://github.com/advisories/GHSA-rrrm-qjm4-v8hf", "severity": "high", "range": "<4.0.10"}], "effects": ["rapidoc"], "range": "<4.0.10", "nodes": [""], "fixAvailable": true}, "minimist": {"name": "minimist", "severity": "critical", "via": [{"source": 1067342, "name": "minimist", "dependency": "minimist", "title": "Prototype Pollution in minimist", "url": "https://github.com/advisories/GHSA-xvch-5gv4-984h", "severity": "critical", "range": "<1.2.6"}], "effects": [], "range": "<1.2.6", "nodes": [""], "fixAvailable": true}, "mocha": {"name": "mocha", "severity": "moderate", "via": ["nanoid"], "effects": ["@vue/cli-plugin-unit-mocha"], "range": "8.2.0 - 9.1.4", "nodes": ["node_modules/@vue/cli-plugin-unit-mocha/node_modules/mocha"], "fixAvailable": {"name": "@vue/cli-plugin-unit-mocha", "version": "4.5.17", "isSemVerMajor": true}}, "moment": {"name": "moment", "severity": "high", "via": [{"source": 1070245, "name": "moment", "dependency": "moment", "title": "Path Traversal: 'dir/../../filename' in moment.locale", "url": "https://github.com/advisories/GHSA-8hfj-j24r-96c4", "severity": "high", "range": "<2.29.2"}], "effects": [], "range": "<2.29.2", "nodes": [""], "fixAvailable": true}, "nanoid": {"name": "nanoid", "severity": "moderate", "via": [{"source": 1067367, "name": "nanoid", "dependency": "nanoid", "title": "Exposure of Sensitive Information to an Unauthorized Actor in nanoid", "url": "https://github.com/advisories/GHSA-qrpm-p2h7-hrv2", "severity": "moderate", "range": ">=3.0.0 <3.1.31"}], "effects": ["mocha"], "range": "3.0.0 - 3.1.30", "nodes": ["node_modules/@vue/cli-plugin-unit-mocha/node_modules/nanoid"], "fixAvailable": {"name": "@vue/cli-plugin-unit-mocha", "version": "4.5.17", "isSemVerMajor": true}}, "node-forge": {"name": "node-forge", "severity": "high", "via": [{"source": 1067364, "name": "node-forge", "dependency": "node-forge", "title": "Improper Verification of Cryptographic Signature in node-forge", "url": "https://github.com/advisories/GHSA-cfm4-qjh2-4765", "severity": "high", "range": "<1.3.0"}], "effects": [], "range": "<1.3.0", "nodes": [""], "fixAvailable": true}, "prismjs": {"name": "prismjs", "severity": "high", "via": [{"source": 1067401, "name": "prismjs", "dependency": "prismjs", "title": "Cross-site Scripting in Prism", "url": "https://github.com/advisories/GHSA-3949-f494-cm99", "severity": "high", "range": ">=1.14.0 <1.27.0"}], "effects": [], "range": "1.14.0 - 1.26.0", "nodes": [""], "fixAvailable": true}, "rapidoc": {"name": "rapidoc", "severity": "high", "via": ["marked"], "effects": [], "range": "<=9.1.3 || 9.1.5", "nodes": [""], "fixAvailable": true}, "shelljs": {"name": "shelljs", "severity": "moderate", "via": [{"source": 1067451, "name": "shelljs", "dependency": "shelljs", "title": "Improper Privilege Management in shelljs", "url": "https://github.com/advisories/GHSA-64g7-mvw6-v9qj", "severity": "moderate", "range": "<0.8.5"}], "effects": [], "range": "<0.8.5", "nodes": [""], "fixAvailable": true}}, "metadata": {"vulnerabilities": {"info": 0, "low": 0, "moderate": 5, "high": 8, "critical": 1, "total": 14}, "dependencies": {"prod": 68, "dev": 2096, "optional": 3, "peer": 0, "peerOptional": 0, "total": 2163}}}}
$ /usr/bin/npm audit fix --only=dev --legacy-peer-deps
--- stderr ---
npm WARN deprecated source-map-url@0.4.1: See https://github.com/lydell/source-map-url#deprecated
npm WARN deprecated @hapi/bourne@1.3.2: This version has been deprecated and is no longer supported or maintained
npm WARN deprecated urix@0.1.0: Please see https://github.com/lydell/urix#deprecated
npm WARN deprecated resolve-url@0.2.1: https://github.com/lydell/resolve-url#deprecated
npm WARN deprecated apollo-tracing@0.15.0: The `apollo-tracing` package is no longer part of Apollo Server 3. See https://www.apollographql.com/docs/apollo-server/migration/#tracing for details
npm WARN deprecated source-map-resolve@0.5.3: See https://github.com/lydell/source-map-resolve#deprecated
npm WARN deprecated graphql-extensions@0.15.0: The `graphql-extensions` API has been removed from Apollo Server 3. Use the plugin API instead: https://www.apollographql.com/docs/apollo-server/integrations/plugins/
npm WARN deprecated querystring@0.2.0: The querystring API is considered Legacy. new code should use the URLSearchParams API instead.
npm WARN deprecated uuid@3.4.0: Please upgrade  to version 7 or higher.  Older versions may use Math.random() in certain circumstances, which is known to be problematic.  See https://v8.dev/blog/math-random for details.
npm WARN deprecated apollo-cache-control@0.14.0: The functionality provided by the `apollo-cache-control` package is built in to `apollo-server-core` starting with Apollo Server 3. See https://www.apollographql.com/docs/apollo-server/migration/#cachecontrol for details.
npm WARN deprecated subscriptions-transport-ws@0.9.19: The `subscriptions-transport-ws` package is no longer maintained. We recommend you use `graphql-ws` instead. For help migrating Apollo software to `graphql-ws`, see https://www.apollographql.com/docs/apollo-server/data/subscriptions/#switching-from-subscriptions-transport-ws    For general help using `graphql-ws`, see https://github.com/enisdenjo/graphql-ws/blob/master/README.md
npm WARN deprecated graphql-tools@4.0.8: This package has been deprecated and now it only exports makeExecutableSchema.\nAnd it will no longer receive updates.\nWe recommend you to migrate to scoped packages such as @graphql-tools/schema, @graphql-tools/utils and etc.\nCheck out https://www.graphql-tools.com to learn what package you should use instead
npm WARN deprecated core-js@2.6.12: core-js@<3.4 is no longer maintained and not recommended for usage due to the number of issues. Because of the V8 engine whims, feature detection in old core-js versions could cause a slowdown up to 100x even if nothing is polyfilled. Please, upgrade your dependencies to the actual version of core-js.
--- stdout ---

added 2163 packages, and audited 2164 packages in 26s

179 packages are looking for funding
  run `npm fund` for details

# npm audit report

nanoid  3.0.0 - 3.1.30
Severity: moderate
Exposure of Sensitive Information to an Unauthorized Actor in nanoid - https://github.com/advisories/GHSA-qrpm-p2h7-hrv2
fix available via `npm audit fix --force`
Will install @vue/cli-plugin-unit-mocha@4.5.17, which is a breaking change
node_modules/@vue/cli-plugin-unit-mocha/node_modules/nanoid
  mocha  8.2.0 - 9.1.4
  Depends on vulnerable versions of nanoid
  node_modules/@vue/cli-plugin-unit-mocha/node_modules/mocha
    @vue/cli-plugin-unit-mocha  >=5.0.0-alpha.0
    Depends on vulnerable versions of mocha
    node_modules/@vue/cli-plugin-unit-mocha

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force

--- end ---
$ package-lock-lint package-lock.json
--- stdout ---
Checking package-lock.json

--- end ---
Verifying that tests still pass
$ /usr/bin/npm ci
--- stderr ---
npm WARN deprecated source-map-url@0.4.1: See https://github.com/lydell/source-map-url#deprecated
npm WARN deprecated @hapi/bourne@1.3.2: This version has been deprecated and is no longer supported or maintained
npm WARN deprecated urix@0.1.0: Please see https://github.com/lydell/urix#deprecated
npm WARN deprecated resolve-url@0.2.1: https://github.com/lydell/resolve-url#deprecated
npm WARN deprecated apollo-tracing@0.15.0: The `apollo-tracing` package is no longer part of Apollo Server 3. See https://www.apollographql.com/docs/apollo-server/migration/#tracing for details
npm WARN deprecated source-map-resolve@0.5.3: See https://github.com/lydell/source-map-resolve#deprecated
npm WARN deprecated graphql-extensions@0.15.0: The `graphql-extensions` API has been removed from Apollo Server 3. Use the plugin API instead: https://www.apollographql.com/docs/apollo-server/integrations/plugins/
npm WARN deprecated querystring@0.2.0: The querystring API is considered Legacy. new code should use the URLSearchParams API instead.
npm WARN deprecated uuid@3.4.0: Please upgrade  to version 7 or higher.  Older versions may use Math.random() in certain circumstances, which is known to be problematic.  See https://v8.dev/blog/math-random for details.
npm WARN deprecated apollo-cache-control@0.14.0: The functionality provided by the `apollo-cache-control` package is built in to `apollo-server-core` starting with Apollo Server 3. See https://www.apollographql.com/docs/apollo-server/migration/#cachecontrol for details.
npm WARN deprecated subscriptions-transport-ws@0.9.19: The `subscriptions-transport-ws` package is no longer maintained. We recommend you use `graphql-ws` instead. For help migrating Apollo software to `graphql-ws`, see https://www.apollographql.com/docs/apollo-server/data/subscriptions/#switching-from-subscriptions-transport-ws    For general help using `graphql-ws`, see https://github.com/enisdenjo/graphql-ws/blob/master/README.md
npm WARN deprecated graphql-tools@4.0.8: This package has been deprecated and now it only exports makeExecutableSchema.\nAnd it will no longer receive updates.\nWe recommend you to migrate to scoped packages such as @graphql-tools/schema, @graphql-tools/utils and etc.\nCheck out https://www.graphql-tools.com to learn what package you should use instead
npm WARN deprecated core-js@2.6.12: core-js@<3.4 is no longer maintained and not recommended for usage due to the number of issues. Because of the V8 engine whims, feature detection in old core-js versions could cause a slowdown up to 100x even if nothing is polyfilled. Please, upgrade your dependencies to the actual version of core-js.
--- stdout ---

added 2163 packages, and audited 2164 packages in 29s

179 packages are looking for funding
  run `npm fund` for details

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force

Run `npm audit` for details.

--- end ---
$ /usr/bin/npm test
--- stderr ---
Error: Cannot resolve custom syntax module "postcss-html". Check that module "postcss-html" is available and spelled correctly.

Caused by: Error: Cannot find module 'postcss-html'
Require stack:
- /src/repo/node_modules/stylelint/lib/getPostcssResult.js
- /src/repo/node_modules/stylelint/lib/createStylelint.js
- /src/repo/node_modules/stylelint/lib/resolveConfig.js
- /src/repo/node_modules/stylelint/lib/printConfig.js
- /src/repo/node_modules/stylelint/lib/cli.js
- /src/repo/node_modules/stylelint/bin/stylelint.js
    at getCustomSyntax (/src/repo/node_modules/stylelint/lib/getPostcssResult.js:105:11)
    at getPostcssResult (/src/repo/node_modules/stylelint/lib/getPostcssResult.js:41:5)
    at lintSource (/src/repo/node_modules/stylelint/lib/lintSource.js:79:20)
    at async /src/repo/node_modules/stylelint/lib/standalone.js:227:27
    at async Promise.all (index 0)
    at async standalone (/src/repo/node_modules/stylelint/lib/standalone.js:266:22)
npm ERR! code 1
npm ERR! path /src/repo
npm ERR! command failed
npm ERR! command sh -c stylelint -f verbose '{toolhub,vue}/**/*.{css,scss,sass,vue}'

npm ERR! A complete log of this run can be found in:
npm ERR!     /cache/_logs/2022-04-27T14_11_35_810Z-debug.log
npm ERR! code 1
npm ERR! path /src/repo
npm ERR! command failed
npm ERR! command sh -c npm run lint:eslint && npm run lint:vue && npm run lint:stylelint && npm run lint:banana && npm run lint:css-rtl

npm ERR! A complete log of this run can be found in:
npm ERR!     /cache/_logs/2022-04-27T14_11_35_857Z-debug.log
npm ERR! code 1
npm ERR! path /src/repo
npm ERR! command failed
npm ERR! command sh -c npm run lint && npm run unit

npm ERR! A complete log of this run can be found in:
npm ERR!     /cache/_logs/2022-04-27T14_11_35_892Z-debug.log
--- stdout ---

> toolhub@1.0.0 test
> npm run lint && npm run unit


> toolhub@1.0.0 lint
> npm run lint:eslint && npm run lint:vue && npm run lint:stylelint && npm run lint:banana && npm run lint:css-rtl


> toolhub@1.0.0 lint:eslint
> eslint .


> toolhub@1.0.0 lint:vue
> vue-cli-service lint

 DONE  No lint errors found!

> toolhub@1.0.0 lint:stylelint
> stylelint -f verbose '{toolhub,vue}/**/*.{css,scss,sass,vue}'


--- end ---
Traceback (most recent call last):
  File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1395, in main
    libup.run(args.repo, args.output, args.branch)
  File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1339, in run
    self.npm_audit_fix(new_npm_audit)
  File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 242, in npm_audit_fix
    self.check_call(['npm', 'test'])
  File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/shell2.py", line 54, in check_call
    res.check_returncode()
  File "/usr/lib/python3.9/subprocess.py", line 460, in check_returncode
    raise CalledProcessError(self.returncode, self.args, self.stdout,
subprocess.CalledProcessError: Command '['/usr/bin/npm', 'test']' returned non-zero exit status 1.
Source code is licensed under the AGPL.