mediawiki/services/service-scaffold-node: main (log #947617)

sourcepatches

This run took 14 seconds.

$ date
--- stdout ---
Sat Mar 11 23:51:55 UTC 2023

--- end ---
$ git clone file:///srv/git/mediawiki-services-service-scaffold-node.git repo --depth=1 -b main
--- stderr ---
Cloning into 'repo'...
--- stdout ---

--- end ---
$ git config user.name libraryupgrader
--- stdout ---

--- end ---
$ git config user.email tools.libraryupgrader@tools.wmflabs.org
--- stdout ---

--- end ---
$ git submodule update --init
--- stdout ---

--- end ---
$ grr init
--- stdout ---
Installed commit-msg hook.

--- end ---
$ git show-ref refs/heads/main
--- stdout ---
cebbd28cee71f290d6dd642d15b00adf241debd7 refs/heads/main

--- end ---
$ /usr/bin/npm audit --json --legacy-peer-deps
--- stdout ---
{
  "auditReportVersion": 2,
  "vulnerabilities": {
    "@wikimedia/servicelib-node-examples": {
      "name": "@wikimedia/servicelib-node-examples",
      "severity": "moderate",
      "isDirect": true,
      "via": [
        "@wikimedia/servicelib-node-utils"
      ],
      "effects": [],
      "range": "",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-examples"
      ],
      "fixAvailable": false
    },
    "@wikimedia/servicelib-node-init": {
      "name": "@wikimedia/servicelib-node-init",
      "severity": "moderate",
      "isDirect": true,
      "via": [
        "swagger-ui-dist"
      ],
      "effects": [],
      "range": "",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init"
      ],
      "fixAvailable": false
    },
    "@wikimedia/servicelib-node-utils": {
      "name": "@wikimedia/servicelib-node-utils",
      "severity": "high",
      "isDirect": true,
      "via": [
        "preq",
        "swagger-ui-dist"
      ],
      "effects": [
        "@wikimedia/servicelib-node-examples"
      ],
      "range": "",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils",
        "node_modules/@wikimedia/servicelib-node-utils"
      ],
      "fixAvailable": false
    },
    "ansi-regex": {
      "name": "ansi-regex",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1091189,
          "name": "ansi-regex",
          "dependency": "ansi-regex",
          "title": "Inefficient Regular Expression Complexity in chalk/ansi-regex",
          "url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
          "severity": "high",
          "cwe": [
            "CWE-697",
            "CWE-1333"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=4.0.0 <4.1.1"
        }
      ],
      "effects": [],
      "range": "4.0.0 - 4.1.0",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init/node_modules/ansi-regex",
        "node_modules/cliui/node_modules/ansi-regex",
        "node_modules/service-runner/node_modules/ansi-regex",
        "node_modules/wrap-ansi/node_modules/ansi-regex",
        "node_modules/yargs/node_modules/ansi-regex"
      ],
      "fixAvailable": true
    },
    "body-parser": {
      "name": "body-parser",
      "severity": "high",
      "isDirect": false,
      "via": [
        "qs",
        "qs"
      ],
      "effects": [],
      "range": "1.19.0 - 1.19.1 || 2.0.0-beta.1",
      "nodes": [
        "../servicelib-node/utils/node_modules/body-parser",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/body-parser",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/express/node_modules/body-parser",
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/body-parser",
        "node_modules/@wikimedia/servicelib-node-utils/node_modules/body-parser",
        "node_modules/body-parser"
      ],
      "fixAvailable": true
    },
    "cookiejar": {
      "name": "cookiejar",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        {
          "source": 1088659,
          "name": "cookiejar",
          "dependency": "cookiejar",
          "title": "cookiejar Regular Expression Denial of Service via Cookie.parse function",
          "url": "https://github.com/advisories/GHSA-h452-7996-h45h",
          "severity": "moderate",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": "<2.1.4"
        }
      ],
      "effects": [],
      "range": "<2.1.4",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/cookiejar"
      ],
      "fixAvailable": true
    },
    "express": {
      "name": "express",
      "severity": "high",
      "isDirect": true,
      "via": [
        "body-parser",
        "body-parser",
        "qs",
        "qs"
      ],
      "effects": [],
      "range": "4.17.0 - 4.17.2 || >=5.0.0-alpha.1",
      "nodes": [
        "../servicelib-node/utils/node_modules/express",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/express",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/express",
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/express",
        "node_modules/@wikimedia/servicelib-node-utils/node_modules/express",
        "node_modules/express"
      ],
      "fixAvailable": true
    },
    "ini": {
      "name": "ini",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1091252,
          "name": "ini",
          "dependency": "ini",
          "title": "ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse",
          "url": "https://github.com/advisories/GHSA-qqgx-2p2h-9c37",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
          },
          "range": "<1.3.6"
        }
      ],
      "effects": [],
      "range": "<1.3.6",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/ini",
        "node_modules/gc-stats/node_modules/ini"
      ],
      "fixAvailable": true
    },
    "json5": {
      "name": "json5",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1091148,
          "name": "json5",
          "dependency": "json5",
          "title": "Prototype Pollution in JSON5 via Parse Method",
          "url": "https://github.com/advisories/GHSA-9c47-m6qq-7p4h",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.1,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H"
          },
          "range": ">=2.0.0 <2.2.2"
        }
      ],
      "effects": [],
      "range": "2.0.0 - 2.2.1",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/json5"
      ],
      "fixAvailable": true
    },
    "limitation": {
      "name": "limitation",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        "wikimedia-kad-fork"
      ],
      "effects": [],
      "range": ">=0.2.3",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init/node_modules/limitation",
        "node_modules/limitation"
      ],
      "fixAvailable": true
    },
    "minimatch": {
      "name": "minimatch",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1091174,
          "name": "minimatch",
          "dependency": "minimatch",
          "title": "minimatch ReDoS vulnerability",
          "url": "https://github.com/advisories/GHSA-f8q6-p94x-37v3",
          "severity": "high",
          "cwe": [
            "CWE-400"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": "<3.0.5"
        }
      ],
      "effects": [
        "mocha"
      ],
      "range": "<3.0.5",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/minimatch",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/minimatch",
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/minimatch",
        "node_modules/gc-stats/node_modules/minimatch",
        "node_modules/minimatch"
      ],
      "fixAvailable": {
        "name": "mocha",
        "version": "10.2.0",
        "isSemVerMajor": true
      }
    },
    "minimist": {
      "name": "minimist",
      "severity": "critical",
      "isDirect": false,
      "via": [
        {
          "source": 1090097,
          "name": "minimist",
          "dependency": "minimist",
          "title": "Prototype Pollution in minimist",
          "url": "https://github.com/advisories/GHSA-vh95-rmgr-6w4m",
          "severity": "moderate",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 5.6,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
          },
          "range": ">=1.0.0 <1.2.3"
        },
        {
          "source": 1090098,
          "name": "minimist",
          "dependency": "minimist",
          "title": "Prototype Pollution in minimist",
          "url": "https://github.com/advisories/GHSA-vh95-rmgr-6w4m",
          "severity": "moderate",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 5.6,
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
          },
          "range": "<0.2.1"
        },
        {
          "source": 1091172,
          "name": "minimist",
          "dependency": "minimist",
          "title": "Prototype Pollution in minimist",
          "url": "https://github.com/advisories/GHSA-xvch-5gv4-984h",
          "severity": "critical",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 9.8,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
          },
          "range": "<0.2.4"
        },
        {
          "source": 1091173,
          "name": "minimist",
          "dependency": "minimist",
          "title": "Prototype Pollution in minimist",
          "url": "https://github.com/advisories/GHSA-xvch-5gv4-984h",
          "severity": "critical",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 9.8,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
          },
          "range": ">=1.0.0 <1.2.6"
        }
      ],
      "effects": [
        "mkdirp"
      ],
      "range": "<=0.2.3 || 1.0.0 - 1.2.5",
      "nodes": [
        "../servicelib-node/utils/node_modules/minimist",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/minimist",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/minimist",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/rc/node_modules/minimist",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/minimist",
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/minimist",
        "node_modules/@wikimedia/servicelib-node-utils/node_modules/minimist",
        "node_modules/gc-stats/node_modules/minimist",
        "node_modules/gc-stats/node_modules/rc/node_modules/minimist",
        "node_modules/minimist"
      ],
      "fixAvailable": {
        "name": "mocha",
        "version": "10.2.0",
        "isSemVerMajor": true
      }
    },
    "mkdirp": {
      "name": "mkdirp",
      "severity": "critical",
      "isDirect": false,
      "via": [
        "minimist"
      ],
      "effects": [
        "mocha"
      ],
      "range": "0.4.1 - 0.5.1",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/mkdirp",
        "node_modules/gc-stats/node_modules/mkdirp",
        "node_modules/mkdirp"
      ],
      "fixAvailable": {
        "name": "mocha",
        "version": "10.2.0",
        "isSemVerMajor": true
      }
    },
    "mocha": {
      "name": "mocha",
      "severity": "critical",
      "isDirect": true,
      "via": [
        "minimatch",
        "mkdirp"
      ],
      "effects": [],
      "range": "1.21.5 - 9.2.1",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/mocha",
        "node_modules/mocha"
      ],
      "fixAvailable": {
        "name": "mocha",
        "version": "10.2.0",
        "isSemVerMajor": true
      }
    },
    "moment": {
      "name": "moment",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1090141,
          "name": "moment",
          "dependency": "moment",
          "title": "Moment.js vulnerable to Inefficient Regular Expression Complexity",
          "url": "https://github.com/advisories/GHSA-wc69-rhjr-hc9g",
          "severity": "high",
          "cwe": [
            "CWE-400",
            "CWE-1333"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=2.18.0 <2.29.4"
        },
        {
          "source": 1090142,
          "name": "moment",
          "dependency": "moment",
          "title": "Path Traversal: 'dir/../../filename' in moment.locale",
          "url": "https://github.com/advisories/GHSA-8hfj-j24r-96c4",
          "severity": "high",
          "cwe": [
            "CWE-22",
            "CWE-27"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
          },
          "range": "<2.29.2"
        }
      ],
      "effects": [],
      "range": "<=2.29.3",
      "nodes": [
        "../servicelib-node/utils/node_modules/moment",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/moment",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/moment",
        "node_modules/@wikimedia/servicelib-node-utils/node_modules/moment",
        "node_modules/moment"
      ],
      "fixAvailable": true
    },
    "ms": {
      "name": "ms",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        {
          "source": 1088818,
          "name": "ms",
          "dependency": "ms",
          "title": "Vercel ms Inefficient Regular Expression Complexity vulnerability",
          "url": "https://github.com/advisories/GHSA-w9mr-4mfr-499f",
          "severity": "moderate",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": "<2.0.0"
        }
      ],
      "effects": [
        "wikimedia-kad-fork"
      ],
      "range": "<2.0.0",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init/node_modules/wikimedia-kad-fork/node_modules/ms",
        "node_modules/wikimedia-kad-fork/node_modules/ms"
      ],
      "fixAvailable": true
    },
    "preq": {
      "name": "preq",
      "severity": "high",
      "isDirect": false,
      "via": [
        "requestretry"
      ],
      "effects": [],
      "range": ">=0.5.7",
      "nodes": [
        "../servicelib-node/utils/node_modules/preq",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/preq",
        "node_modules/@wikimedia/servicelib-node-utils/node_modules/preq"
      ],
      "fixAvailable": {
        "name": "preq",
        "version": "0.5.6",
        "isSemVerMajor": true
      }
    },
    "qs": {
      "name": "qs",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1090137,
          "name": "qs",
          "dependency": "qs",
          "title": "qs vulnerable to Prototype Pollution",
          "url": "https://github.com/advisories/GHSA-hrpp-h998-j3pp",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=6.7.0 <6.7.3"
        },
        {
          "source": 1090139,
          "name": "qs",
          "dependency": "qs",
          "title": "qs vulnerable to Prototype Pollution",
          "url": "https://github.com/advisories/GHSA-hrpp-h998-j3pp",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=6.9.0 <6.9.7"
        },
        {
          "source": 1090140,
          "name": "qs",
          "dependency": "qs",
          "title": "qs vulnerable to Prototype Pollution",
          "url": "https://github.com/advisories/GHSA-hrpp-h998-j3pp",
          "severity": "high",
          "cwe": [
            "CWE-1321"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
          },
          "range": ">=6.10.0 <6.10.3"
        }
      ],
      "effects": [
        "body-parser",
        "express"
      ],
      "range": "6.7.0 - 6.7.2 || 6.9.0 - 6.9.6 || 6.10.0 - 6.10.2",
      "nodes": [
        "../servicelib-node/utils/node_modules/qs",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/body-parser/node_modules/qs",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/express/node_modules/qs",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/qs",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/qs",
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/body-parser/node_modules/qs",
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/express/node_modules/qs",
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/qs",
        "node_modules/@wikimedia/servicelib-node-utils/node_modules/qs",
        "node_modules/qs"
      ],
      "fixAvailable": true
    },
    "requestretry": {
      "name": "requestretry",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1090420,
          "name": "requestretry",
          "dependency": "requestretry",
          "title": "Cookie exposure in requestretry",
          "url": "https://github.com/advisories/GHSA-hjp8-2cm3-cc45",
          "severity": "high",
          "cwe": [
            "CWE-200"
          ],
          "cvss": {
            "score": 7.5,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
          },
          "range": "<7.0.0"
        }
      ],
      "effects": [
        "preq"
      ],
      "range": "<7.0.0",
      "nodes": [
        "../servicelib-node/utils/node_modules/requestretry",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/requestretry",
        "node_modules/@wikimedia/servicelib-node-utils/node_modules/requestretry"
      ],
      "fixAvailable": {
        "name": "preq",
        "version": "0.5.6",
        "isSemVerMajor": true
      }
    },
    "swagger-ui-dist": {
      "name": "swagger-ui-dist",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        {
          "source": 1085394,
          "name": "swagger-ui-dist",
          "dependency": "swagger-ui-dist",
          "title": "Server side request forgery in SwaggerUI",
          "url": "https://github.com/advisories/GHSA-qrmm-w75w-3wpx",
          "severity": "moderate",
          "cwe": [
            "CWE-918"
          ],
          "cvss": {
            "score": 0,
            "vectorString": null
          },
          "range": "<4.1.3"
        },
        {
          "source": 1088759,
          "name": "swagger-ui-dist",
          "dependency": "swagger-ui-dist",
          "title": "Spoofing attack in swagger-ui-dist",
          "url": "https://github.com/advisories/GHSA-6c9x-mj3g-h47x",
          "severity": "moderate",
          "cwe": [
            "CWE-1021"
          ],
          "cvss": {
            "score": 6.1,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
          },
          "range": "<4.1.3"
        }
      ],
      "effects": [
        "@wikimedia/servicelib-node-init",
        "@wikimedia/servicelib-node-utils",
        "swagger-ui-express"
      ],
      "range": "<=4.1.2",
      "nodes": [
        "../servicelib-node/utils/node_modules/swagger-ui-dist",
        "node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/swagger-ui-dist",
        "node_modules/@wikimedia/servicelib-node-init/node_modules/swagger-ui-dist",
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/swagger-ui-dist",
        "node_modules/@wikimedia/servicelib-node-utils/node_modules/swagger-ui-dist"
      ],
      "fixAvailable": false
    },
    "swagger-ui-express": {
      "name": "swagger-ui-express",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        "swagger-ui-dist"
      ],
      "effects": [],
      "range": "4.0.0 - 4.1.6",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/swagger-ui-express"
      ],
      "fixAvailable": true
    },
    "tar": {
      "name": "tar",
      "severity": "high",
      "isDirect": false,
      "via": [
        {
          "source": 1089138,
          "name": "tar",
          "dependency": "tar",
          "title": "Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links",
          "url": "https://github.com/advisories/GHSA-qq89-hq3f-393p",
          "severity": "high",
          "cwe": [
            "CWE-22",
            "CWE-59"
          ],
          "cvss": {
            "score": 8.2,
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
          },
          "range": "<4.4.18"
        },
        {
          "source": 1089141,
          "name": "tar",
          "dependency": "tar",
          "title": "Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links",
          "url": "https://github.com/advisories/GHSA-9r2w-394v-53qc",
          "severity": "high",
          "cwe": [
            "CWE-22",
            "CWE-59"
          ],
          "cvss": {
            "score": 8.2,
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
          },
          "range": "<4.4.16"
        },
        {
          "source": 1089663,
          "name": "tar",
          "dependency": "tar",
          "title": "Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization",
          "url": "https://github.com/advisories/GHSA-5955-9wpr-37jh",
          "severity": "high",
          "cwe": [
            "CWE-22"
          ],
          "cvss": {
            "score": 8.2,
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
          },
          "range": "<4.4.18"
        },
        {
          "source": 1089684,
          "name": "tar",
          "dependency": "tar",
          "title": "Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization",
          "url": "https://github.com/advisories/GHSA-3jfq-g458-7qm9",
          "severity": "high",
          "cwe": [
            "CWE-22"
          ],
          "cvss": {
            "score": 8.2,
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
          },
          "range": ">=4.0.0 <4.4.14"
        },
        {
          "source": 1091313,
          "name": "tar",
          "dependency": "tar",
          "title": "Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning",
          "url": "https://github.com/advisories/GHSA-r628-mhmh-qjhw",
          "severity": "high",
          "cwe": [
            "CWE-22",
            "CWE-23",
            "CWE-59"
          ],
          "cvss": {
            "score": 8.2,
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
          },
          "range": ">=4.0.0 <4.4.15"
        }
      ],
      "effects": [],
      "range": "<=4.4.17",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/tar",
        "node_modules/gc-stats/node_modules/tar"
      ],
      "fixAvailable": true
    },
    "validator": {
      "name": "validator",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        {
          "source": 1088241,
          "name": "validator",
          "dependency": "validator",
          "title": "Inefficient Regular Expression Complexity in Validator.js",
          "url": "https://github.com/advisories/GHSA-xx4c-jj58-r7x6",
          "severity": "moderate",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": ">=11.1.0 <13.7.0"
        },
        {
          "source": 1089600,
          "name": "validator",
          "dependency": "validator",
          "title": "Inefficient Regular Expression Complexity in validator.js",
          "url": "https://github.com/advisories/GHSA-qgmg-gppg-76g5",
          "severity": "moderate",
          "cwe": [
            "CWE-1333"
          ],
          "cvss": {
            "score": 5.3,
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
          },
          "range": "<13.7.0"
        }
      ],
      "effects": [],
      "range": "<=13.6.0",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-spec/node_modules/validator"
      ],
      "fixAvailable": true
    },
    "wikimedia-kad-fork": {
      "name": "wikimedia-kad-fork",
      "severity": "moderate",
      "isDirect": false,
      "via": [
        "ms"
      ],
      "effects": [
        "limitation"
      ],
      "range": "*",
      "nodes": [
        "node_modules/@wikimedia/servicelib-node-init/node_modules/wikimedia-kad-fork",
        "node_modules/wikimedia-kad-fork"
      ],
      "fixAvailable": true
    }
  },
  "metadata": {
    "vulnerabilities": {
      "info": 0,
      "low": 0,
      "moderate": 9,
      "high": 12,
      "critical": 3,
      "total": 24
    },
    "dependencies": {
      "prod": 749,
      "dev": 544,
      "optional": 507,
      "peer": 284,
      "peerOptional": 0,
      "total": 1515
    }
  }
}

--- end ---
$ /usr/bin/npm install
--- stderr ---
npm ERR! code E404
npm ERR! 404 Not Found - GET https://registry.npmjs.org/@wikimedia%2fservicelib-node-examples - Not found
npm ERR! 404 
npm ERR! 404  '@wikimedia/servicelib-node-examples@^1.0.0' is not in this registry.
npm ERR! 404 
npm ERR! 404 Note that you can also install from a
npm ERR! 404 tarball, folder, http url, or git url.

npm ERR! A complete log of this run can be found in:
npm ERR!     /cache/_logs/2023-03-11T23_52_00_603Z-debug-0.log
--- stdout ---

--- end ---
Traceback (most recent call last):
  File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1400, in main
    libup.run(args.repo, args.output, args.branch)
  File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1331, in run
    self.fix_remove_eslint_stylelint_if_grunt()
  File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 630, in fix_remove_eslint_stylelint_if_grunt
    self.check_call(['npm', 'install'])
  File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/shell2.py", line 54, in check_call
    res.check_returncode()
  File "/usr/lib/python3.9/subprocess.py", line 460, in check_returncode
    raise CalledProcessError(self.returncode, self.args, self.stdout,
subprocess.CalledProcessError: Command '['/usr/bin/npm', 'install']' returned non-zero exit status 1.
Source code is licensed under the AGPL.