$ date
--- stdout ---
Thu Apr 25 06:41:37 UTC 2024
--- end ---
$ git clone file:///srv/git/mediawiki-extensions-GlobalWatchlist.git repo --depth=1 -b master
--- stderr ---
Cloning into 'repo'...
--- stdout ---
--- end ---
$ git config user.name libraryupgrader
--- stdout ---
--- end ---
$ git config user.email tools.libraryupgrader@tools.wmflabs.org
--- stdout ---
--- end ---
$ git submodule update --init
--- stdout ---
--- end ---
$ grr init
--- stdout ---
Installed commit-msg hook.
--- end ---
$ git show-ref refs/heads/master
--- stdout ---
56c1dae55c078f2e69bf093fe8a7ef57972d2e11 refs/heads/master
--- end ---
$ /usr/bin/npm audit --json
--- stdout ---
{
"auditReportVersion": 2,
"vulnerabilities": {
"mwbot": {
"name": "mwbot",
"severity": "moderate",
"isDirect": false,
"via": [
"request"
],
"effects": [
"wdio-mediawiki"
],
"range": ">=0.1.6",
"nodes": [
"node_modules/mwbot"
],
"fixAvailable": false
},
"request": {
"name": "request",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1096727,
"name": "request",
"dependency": "request",
"title": "Server-Side Request Forgery in Request",
"url": "https://github.com/advisories/GHSA-p8p7-x288-28g6",
"severity": "moderate",
"cwe": [
"CWE-918"
],
"cvss": {
"score": 6.1,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"range": "<=2.88.2"
},
"tough-cookie"
],
"effects": [
"mwbot"
],
"range": "*",
"nodes": [
"node_modules/request"
],
"fixAvailable": false
},
"tough-cookie": {
"name": "tough-cookie",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1096643,
"name": "tough-cookie",
"dependency": "tough-cookie",
"title": "tough-cookie Prototype Pollution vulnerability",
"url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3",
"severity": "moderate",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 6.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
},
"range": "<4.1.3"
}
],
"effects": [
"request"
],
"range": "<4.1.3",
"nodes": [
"node_modules/tough-cookie"
],
"fixAvailable": false
},
"wdio-mediawiki": {
"name": "wdio-mediawiki",
"severity": "moderate",
"isDirect": true,
"via": [
"mwbot"
],
"effects": [],
"range": "*",
"nodes": [
"node_modules/wdio-mediawiki"
],
"fixAvailable": false
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 4,
"high": 0,
"critical": 0,
"total": 4
},
"dependencies": {
"prod": 1,
"dev": 913,
"optional": 2,
"peer": 1,
"peerOptional": 0,
"total": 913
}
}
}
--- end ---
$ /usr/bin/composer install
--- stderr ---
No composer.lock file present. Updating dependencies to latest instead of installing from lock file. See https://getcomposer.org/install for more information.
Loading composer repositories with package information
Updating dependencies
Lock file operations: 39 installs, 0 updates, 0 removals
- Locking composer/pcre (3.1.3)
- Locking composer/semver (3.4.0)
- Locking composer/spdx-licenses (1.5.8)
- Locking composer/xdebug-handler (3.0.4)
- Locking dealerdirect/phpcodesniffer-composer-installer (v1.0.0)
- Locking doctrine/deprecations (1.1.3)
- Locking felixfbecker/advanced-json-rpc (v3.2.1)
- Locking mediawiki/mediawiki-codesniffer (v43.0.0)
- Locking mediawiki/mediawiki-phan-config (0.14.0)
- Locking mediawiki/minus-x (1.1.1)
- Locking mediawiki/phan-taint-check-plugin (6.0.0)
- Locking microsoft/tolerant-php-parser (v0.1.2)
- Locking netresearch/jsonmapper (v4.4.1)
- Locking phan/phan (5.4.3)
- Locking php-parallel-lint/php-console-color (v1.0.1)
- Locking php-parallel-lint/php-console-highlighter (v1.0.0)
- Locking php-parallel-lint/php-parallel-lint (v1.3.2)
- Locking phpcsstandards/phpcsextra (1.1.2)
- Locking phpcsstandards/phpcsutils (1.0.9)
- Locking phpdocumentor/reflection-common (2.2.0)
- Locking phpdocumentor/reflection-docblock (5.4.0)
- Locking phpdocumentor/type-resolver (1.8.2)
- Locking phpstan/phpdoc-parser (1.28.0)
- Locking psr/container (2.0.2)
- Locking psr/log (2.0.0)
- Locking sabre/event (5.1.4)
- Locking squizlabs/php_codesniffer (3.8.1)
- Locking symfony/console (v5.4.36)
- Locking symfony/deprecation-contracts (v3.4.0)
- Locking symfony/polyfill-ctype (v1.29.0)
- Locking symfony/polyfill-intl-grapheme (v1.29.0)
- Locking symfony/polyfill-intl-normalizer (v1.29.0)
- Locking symfony/polyfill-mbstring (v1.29.0)
- Locking symfony/polyfill-php73 (v1.29.0)
- Locking symfony/polyfill-php80 (v1.29.0)
- Locking symfony/service-contracts (v3.4.2)
- Locking symfony/string (v6.4.4)
- Locking tysonandre/var_representation_polyfill (0.1.3)
- Locking webmozart/assert (1.11.0)
Writing lock file
Installing dependencies from lock file (including require-dev)
Package operations: 39 installs, 0 updates, 0 removals
0 [>---------------------------] 0 [->--------------------------]
- Installing squizlabs/php_codesniffer (3.8.1): Extracting archive
- Installing dealerdirect/phpcodesniffer-composer-installer (v1.0.0): Extracting archive
- Installing composer/pcre (3.1.3): Extracting archive
- Installing symfony/polyfill-php80 (v1.29.0): Extracting archive
- Installing phpcsstandards/phpcsutils (1.0.9): Extracting archive
- Installing phpcsstandards/phpcsextra (1.1.2): Extracting archive
- Installing symfony/polyfill-mbstring (v1.29.0): Extracting archive
- Installing composer/spdx-licenses (1.5.8): Extracting archive
- Installing composer/semver (3.4.0): Extracting archive
- Installing mediawiki/mediawiki-codesniffer (v43.0.0): Extracting archive
- Installing tysonandre/var_representation_polyfill (0.1.3): Extracting archive
- Installing symfony/polyfill-intl-normalizer (v1.29.0): Extracting archive
- Installing symfony/polyfill-intl-grapheme (v1.29.0): Extracting archive
- Installing symfony/polyfill-ctype (v1.29.0): Extracting archive
- Installing symfony/string (v6.4.4): Extracting archive
- Installing psr/container (2.0.2): Extracting archive
- Installing symfony/service-contracts (v3.4.2): Extracting archive
- Installing symfony/polyfill-php73 (v1.29.0): Extracting archive
- Installing symfony/deprecation-contracts (v3.4.0): Extracting archive
- Installing symfony/console (v5.4.36): Extracting archive
- Installing sabre/event (5.1.4): Extracting archive
- Installing netresearch/jsonmapper (v4.4.1): Extracting archive
- Installing microsoft/tolerant-php-parser (v0.1.2): Extracting archive
- Installing webmozart/assert (1.11.0): Extracting archive
- Installing phpstan/phpdoc-parser (1.28.0): Extracting archive
- Installing phpdocumentor/reflection-common (2.2.0): Extracting archive
- Installing doctrine/deprecations (1.1.3): Extracting archive
- Installing phpdocumentor/type-resolver (1.8.2): Extracting archive
- Installing phpdocumentor/reflection-docblock (5.4.0): Extracting archive
- Installing felixfbecker/advanced-json-rpc (v3.2.1): Extracting archive
- Installing psr/log (2.0.0): Extracting archive
- Installing composer/xdebug-handler (3.0.4): Extracting archive
- Installing phan/phan (5.4.3): Extracting archive
- Installing mediawiki/phan-taint-check-plugin (6.0.0): Extracting archive
- Installing mediawiki/mediawiki-phan-config (0.14.0): Extracting archive
- Installing mediawiki/minus-x (1.1.1): Extracting archive
- Installing php-parallel-lint/php-console-color (v1.0.1): Extracting archive
- Installing php-parallel-lint/php-console-highlighter (v1.0.0): Extracting archive
- Installing php-parallel-lint/php-parallel-lint (v1.3.2): Extracting archive
0/37 [>---------------------------] 0%
22/37 [================>-----------] 59%
36/37 [===========================>] 97%
37/37 [============================] 100%
3 package suggestions were added by new dependencies, use `composer suggest` to see details.
Generating autoload files
16 packages you are using are looking for funding.
Use the `composer fund` command to find out more!
--- stdout ---
PHP CodeSniffer Config installed_paths set to ../../mediawiki/mediawiki-codesniffer,../../phpcsstandards/phpcsextra,../../phpcsstandards/phpcsutils
--- end ---
Upgrading n:jsdoc-wmf-theme from 0.0.13 -> 1.0.0
$ /usr/bin/npm install
--- stderr ---
npm WARN EBADENGINE Unsupported engine {
npm WARN EBADENGINE package: 'wdio-mediawiki@2.5.0',
npm WARN EBADENGINE required: { node: '>=18.17.0', npm: '>=9.6.7' },
npm WARN EBADENGINE current: { node: 'v18.19.0', npm: '9.2.0' }
npm WARN EBADENGINE }
npm WARN deprecated @types/easy-table@1.2.0: This is a stub types definition. easy-table provides its own type definitions, so you do not need this installed.
npm WARN deprecated har-validator@5.1.5: this library is no longer supported
npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details.
npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142
npm WARN deprecated stylelint-stylistic@0.4.3: This package has been deprecated in favor of @stylistic/stylelint-plugin
--- stdout ---
added 913 packages, and audited 914 packages in 8s
160 packages are looking for funding
run `npm fund` for details
4 moderate severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
Run `npm audit` for details.
--- end ---
$ package-lock-lint package-lock.json
--- stdout ---
Checking package-lock.json
--- end ---
$ /usr/bin/npm ci
--- stderr ---
npm WARN EBADENGINE Unsupported engine {
npm WARN EBADENGINE package: 'wdio-mediawiki@2.5.0',
npm WARN EBADENGINE required: { node: '>=18.17.0', npm: '>=9.6.7' },
npm WARN EBADENGINE current: { node: 'v18.19.0', npm: '9.2.0' }
npm WARN EBADENGINE }
npm WARN deprecated @types/easy-table@1.2.0: This is a stub types definition. easy-table provides its own type definitions, so you do not need this installed.
npm WARN deprecated har-validator@5.1.5: this library is no longer supported
npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details.
npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142
npm WARN deprecated stylelint-stylistic@0.4.3: This package has been deprecated in favor of @stylistic/stylelint-plugin
--- stdout ---
added 913 packages, and audited 914 packages in 11s
160 packages are looking for funding
run `npm fund` for details
4 moderate severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
Run `npm audit` for details.
--- end ---
$ /usr/bin/npm test
--- stdout ---
> test
> npm run lint
> lint
> npm run lint:eslint && npm run lint:styles && npm run lint:i18n
> lint:eslint
> eslint --cache .
/src/repo/modules/EntryBase.js
36:2 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
36:15 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
50:1 warning The type 'GlobalWatchlistWikibaseHandler' is undefined jsdoc/no-undefined-types
56:1 warning The type 'GlobalWatchlistWikibaseHandler' is undefined jsdoc/no-undefined-types
/src/repo/modules/MultiSiteWrapper.js
9:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
10:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
60:9 warning ES2015 'Promise' class is forbidden es-x/no-promise
78:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
86:22 warning ES2015 'Promise' class is forbidden es-x/no-promise
101:6 warning ES2015 'Promise' class is forbidden es-x/no-promise
/src/repo/modules/SiteBase.js
8:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
9:1 warning The type 'GlobalWatchlistLinker' is undefined jsdoc/no-undefined-types
12:1 warning The type 'GlobalWatchlistWatchlistUtils' is undefined jsdoc/no-undefined-types
98:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
145:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
225:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
244:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
261:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
286:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
324:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
368:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
370:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
379:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
384:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
405:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
424:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
433:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
443:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
/src/repo/modules/SiteDisplay.js
14:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
15:1 warning The type 'GlobalWatchlistLinker' is undefined jsdoc/no-undefined-types
18:1 warning The type 'GlobalWatchlistWatchlistUtils' is undefined jsdoc/no-undefined-types
48:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
82:7 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
84:33 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
233:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
/src/repo/modules/SpecialGlobalWatchlist.display.js
105:14 warning ES2015 'Promise' class is forbidden es-x/no-promise
/src/repo/modules/WatchlistUtils.js
7:1 warning The type 'GlobalWatchlistLinker' is undefined jsdoc/no-undefined-types
314:1 warning The type 'GlobalWatchlistSiteBase' is undefined jsdoc/no-undefined-types
326:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
343:1 warning The type 'GlobalWatchlistEntryEdits' is undefined jsdoc/no-undefined-types
343:1 warning The type 'GlobalWatchlistEntryLog' is undefined jsdoc/no-undefined-types
346:1 warning The type 'GlobalWatchlistEntryEdits' is undefined jsdoc/no-undefined-types
346:1 warning The type 'GlobalWatchlistEntryLog' is undefined jsdoc/no-undefined-types
376:4 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
378:4 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
428:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
434:1 warning The type 'GlobalWatchlistEntryEdits' is undefined jsdoc/no-undefined-types
434:1 warning The type 'GlobalWatchlistEntryLog' is undefined jsdoc/no-undefined-types
/src/repo/modules/WikibaseHandler.js
9:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
99:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
180:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
214:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
221:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
225:24 warning ES2015 'Array.prototype.entries' method is forbidden es-x/no-array-prototype-entries
/src/repo/modules/getSettings.js
24:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
/src/repo/tests/qunit/WatchlistUtils.tests.js
8:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
351:5 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
353:5 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
✖ 58 problems (0 errors, 58 warnings)
> lint:styles
> stylelint "**/*.{css,less}"
> lint:i18n
> banana-checker --requireLowerCase=0 i18n/
Checked 1 message directory.
--- end ---
Upgrading c:php-parallel-lint/php-parallel-lint from 1.3.2 -> 1.4.0
$ /usr/bin/composer update
--- stderr ---
Loading composer repositories with package information
Updating dependencies
Lock file operations: 0 installs, 1 update, 0 removals
- Upgrading php-parallel-lint/php-parallel-lint (v1.3.2 => v1.4.0)
Writing lock file
Installing dependencies from lock file (including require-dev)
Package operations: 0 installs, 1 update, 0 removals
- Upgrading php-parallel-lint/php-parallel-lint (v1.3.2 => v1.4.0): Extracting archive
Generating autoload files
16 packages you are using are looking for funding.
Use the `composer fund` command to find out more!
No security vulnerability advisories found
--- stdout ---
--- end ---
$ /usr/bin/composer install
--- stderr ---
Installing dependencies from lock file (including require-dev)
Verifying lock file contents can be installed on current platform.
Nothing to install, update or remove
Generating autoload files
16 packages you are using are looking for funding.
Use the `composer fund` command to find out more!
--- stdout ---
--- end ---
$ /usr/bin/composer test
--- stderr ---
> parallel-lint . --exclude vendor --exclude node_modules
> phpcs -sp --cache
> minus-x check .
--- stdout ---
PHP 8.2.7 | 10 parallel jobs
.................. 18/18 (100%)
Checked 18 files in 0.1 seconds
No syntax error found
.................. 18 / 18 (100%)
Time: 252ms; Memory: 8MB
MinusX
======
Processing /src/repo...
.............................................................
.............................................................
.............................................................
......
All good!
--- end ---
$ /usr/bin/npm audit --json
--- stdout ---
{
"auditReportVersion": 2,
"vulnerabilities": {
"mwbot": {
"name": "mwbot",
"severity": "moderate",
"isDirect": false,
"via": [
"request"
],
"effects": [
"wdio-mediawiki"
],
"range": ">=0.1.6",
"nodes": [
"node_modules/mwbot"
],
"fixAvailable": false
},
"request": {
"name": "request",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1096727,
"name": "request",
"dependency": "request",
"title": "Server-Side Request Forgery in Request",
"url": "https://github.com/advisories/GHSA-p8p7-x288-28g6",
"severity": "moderate",
"cwe": [
"CWE-918"
],
"cvss": {
"score": 6.1,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"range": "<=2.88.2"
},
"tough-cookie"
],
"effects": [
"mwbot"
],
"range": "*",
"nodes": [
"node_modules/request"
],
"fixAvailable": false
},
"tough-cookie": {
"name": "tough-cookie",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1096643,
"name": "tough-cookie",
"dependency": "tough-cookie",
"title": "tough-cookie Prototype Pollution vulnerability",
"url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3",
"severity": "moderate",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 6.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
},
"range": "<4.1.3"
}
],
"effects": [
"request"
],
"range": "<4.1.3",
"nodes": [
"node_modules/tough-cookie"
],
"fixAvailable": false
},
"wdio-mediawiki": {
"name": "wdio-mediawiki",
"severity": "moderate",
"isDirect": true,
"via": [
"mwbot"
],
"effects": [],
"range": "*",
"nodes": [
"node_modules/wdio-mediawiki"
],
"fixAvailable": false
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 4,
"high": 0,
"critical": 0,
"total": 4
},
"dependencies": {
"prod": 1,
"dev": 914,
"optional": 2,
"peer": 1,
"peerOptional": 0,
"total": 914
}
}
}
--- end ---
Attempting to npm audit fix
$ /usr/bin/npm audit fix --dry-run --only=dev --json
--- stderr ---
npm WARN invalid config only="dev" set in command line options
npm WARN invalid config Must be one of: null, prod, production
npm WARN EBADENGINE Unsupported engine {
npm WARN EBADENGINE package: 'wdio-mediawiki@2.5.0',
npm WARN EBADENGINE required: { node: '>=18.17.0', npm: '>=9.6.7' },
npm WARN EBADENGINE current: { node: 'v18.19.0', npm: '9.2.0' }
npm WARN EBADENGINE }
--- stdout ---
{
"added": 1,
"removed": 0,
"changed": 0,
"audited": 915,
"funding": 160,
"audit": {
"auditReportVersion": 2,
"vulnerabilities": {
"mwbot": {
"name": "mwbot",
"severity": "moderate",
"isDirect": false,
"via": [
"request"
],
"effects": [
"wdio-mediawiki"
],
"range": ">=0.1.6",
"nodes": [
"node_modules/mwbot"
],
"fixAvailable": false
},
"request": {
"name": "request",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1096727,
"name": "request",
"dependency": "request",
"title": "Server-Side Request Forgery in Request",
"url": "https://github.com/advisories/GHSA-p8p7-x288-28g6",
"severity": "moderate",
"cwe": [
"CWE-918"
],
"cvss": {
"score": 6.1,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"range": "<=2.88.2"
},
"tough-cookie"
],
"effects": [
"mwbot"
],
"range": "*",
"nodes": [
"node_modules/request"
],
"fixAvailable": false
},
"tough-cookie": {
"name": "tough-cookie",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1096643,
"name": "tough-cookie",
"dependency": "tough-cookie",
"title": "tough-cookie Prototype Pollution vulnerability",
"url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3",
"severity": "moderate",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 6.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
},
"range": "<4.1.3"
}
],
"effects": [
"request"
],
"range": "<4.1.3",
"nodes": [
"node_modules/tough-cookie"
],
"fixAvailable": false
},
"wdio-mediawiki": {
"name": "wdio-mediawiki",
"severity": "moderate",
"isDirect": true,
"via": [
"mwbot"
],
"effects": [],
"range": "*",
"nodes": [
"node_modules/wdio-mediawiki"
],
"fixAvailable": false
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 4,
"high": 0,
"critical": 0,
"total": 4
},
"dependencies": {
"prod": 1,
"dev": 914,
"optional": 2,
"peer": 1,
"peerOptional": 0,
"total": 914
}
}
}
}
--- end ---
{"added": 1, "removed": 0, "changed": 0, "audited": 915, "funding": 160, "audit": {"auditReportVersion": 2, "vulnerabilities": {"mwbot": {"name": "mwbot", "severity": "moderate", "isDirect": false, "via": ["request"], "effects": ["wdio-mediawiki"], "range": ">=0.1.6", "nodes": ["node_modules/mwbot"], "fixAvailable": false}, "request": {"name": "request", "severity": "moderate", "isDirect": false, "via": [{"source": 1096727, "name": "request", "dependency": "request", "title": "Server-Side Request Forgery in Request", "url": "https://github.com/advisories/GHSA-p8p7-x288-28g6", "severity": "moderate", "cwe": ["CWE-918"], "cvss": {"score": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}, "range": "<=2.88.2"}, "tough-cookie"], "effects": ["mwbot"], "range": "*", "nodes": ["node_modules/request"], "fixAvailable": false}, "tough-cookie": {"name": "tough-cookie", "severity": "moderate", "isDirect": false, "via": [{"source": 1096643, "name": "tough-cookie", "dependency": "tough-cookie", "title": "tough-cookie Prototype Pollution vulnerability", "url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3", "severity": "moderate", "cwe": ["CWE-1321"], "cvss": {"score": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}, "range": "<4.1.3"}], "effects": ["request"], "range": "<4.1.3", "nodes": ["node_modules/tough-cookie"], "fixAvailable": false}, "wdio-mediawiki": {"name": "wdio-mediawiki", "severity": "moderate", "isDirect": true, "via": ["mwbot"], "effects": [], "range": "*", "nodes": ["node_modules/wdio-mediawiki"], "fixAvailable": false}}, "metadata": {"vulnerabilities": {"info": 0, "low": 0, "moderate": 4, "high": 0, "critical": 0, "total": 4}, "dependencies": {"prod": 1, "dev": 914, "optional": 2, "peer": 1, "peerOptional": 0, "total": 914}}}}
$ /usr/bin/npm audit fix --only=dev
--- stderr ---
npm WARN invalid config only="dev" set in command line options
npm WARN invalid config Must be one of: null, prod, production
npm WARN EBADENGINE Unsupported engine {
npm WARN EBADENGINE package: 'wdio-mediawiki@2.5.0',
npm WARN EBADENGINE required: { node: '>=18.17.0', npm: '>=9.6.7' },
npm WARN EBADENGINE current: { node: 'v18.19.0', npm: '9.2.0' }
npm WARN EBADENGINE }
--- stdout ---
up to date, audited 914 packages in 2s
160 packages are looking for funding
run `npm fund` for details
# npm audit report
request *
Severity: moderate
Server-Side Request Forgery in Request - https://github.com/advisories/GHSA-p8p7-x288-28g6
Depends on vulnerable versions of tough-cookie
No fix available
node_modules/request
mwbot >=0.1.6
Depends on vulnerable versions of request
node_modules/mwbot
wdio-mediawiki *
Depends on vulnerable versions of mwbot
node_modules/wdio-mediawiki
tough-cookie <4.1.3
Severity: moderate
tough-cookie Prototype Pollution vulnerability - https://github.com/advisories/GHSA-72xf-g2v4-qvf3
No fix available
node_modules/tough-cookie
4 moderate severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
--- end ---
$ package-lock-lint package-lock.json
--- stdout ---
Checking package-lock.json
--- end ---
Verifying that tests still pass
$ /usr/bin/npm ci
--- stderr ---
npm WARN EBADENGINE Unsupported engine {
npm WARN EBADENGINE package: 'wdio-mediawiki@2.5.0',
npm WARN EBADENGINE required: { node: '>=18.17.0', npm: '>=9.6.7' },
npm WARN EBADENGINE current: { node: 'v18.19.0', npm: '9.2.0' }
npm WARN EBADENGINE }
npm WARN deprecated @types/easy-table@1.2.0: This is a stub types definition. easy-table provides its own type definitions, so you do not need this installed.
npm WARN deprecated har-validator@5.1.5: this library is no longer supported
npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details.
npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142
npm WARN deprecated stylelint-stylistic@0.4.3: This package has been deprecated in favor of @stylistic/stylelint-plugin
--- stdout ---
added 913 packages, and audited 914 packages in 8s
160 packages are looking for funding
run `npm fund` for details
4 moderate severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
Run `npm audit` for details.
--- end ---
$ /usr/bin/npm test
--- stdout ---
> test
> npm run lint
> lint
> npm run lint:eslint && npm run lint:styles && npm run lint:i18n
> lint:eslint
> eslint --cache .
/src/repo/modules/EntryBase.js
36:2 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
36:15 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
50:1 warning The type 'GlobalWatchlistWikibaseHandler' is undefined jsdoc/no-undefined-types
56:1 warning The type 'GlobalWatchlistWikibaseHandler' is undefined jsdoc/no-undefined-types
/src/repo/modules/MultiSiteWrapper.js
9:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
10:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
60:9 warning ES2015 'Promise' class is forbidden es-x/no-promise
78:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
86:22 warning ES2015 'Promise' class is forbidden es-x/no-promise
101:6 warning ES2015 'Promise' class is forbidden es-x/no-promise
/src/repo/modules/SiteBase.js
8:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
9:1 warning The type 'GlobalWatchlistLinker' is undefined jsdoc/no-undefined-types
12:1 warning The type 'GlobalWatchlistWatchlistUtils' is undefined jsdoc/no-undefined-types
98:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
145:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
225:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
244:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
261:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
286:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
324:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
368:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
370:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
379:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
384:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
405:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
424:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
433:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
443:1 warning The type 'GlobalWatchlistSiteDisplay' is undefined jsdoc/no-undefined-types
/src/repo/modules/SiteDisplay.js
14:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
15:1 warning The type 'GlobalWatchlistLinker' is undefined jsdoc/no-undefined-types
18:1 warning The type 'GlobalWatchlistWatchlistUtils' is undefined jsdoc/no-undefined-types
48:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
82:7 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
84:33 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
233:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
/src/repo/modules/SpecialGlobalWatchlist.display.js
105:14 warning ES2015 'Promise' class is forbidden es-x/no-promise
/src/repo/modules/WatchlistUtils.js
7:1 warning The type 'GlobalWatchlistLinker' is undefined jsdoc/no-undefined-types
314:1 warning The type 'GlobalWatchlistSiteBase' is undefined jsdoc/no-undefined-types
326:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
343:1 warning The type 'GlobalWatchlistEntryEdits' is undefined jsdoc/no-undefined-types
343:1 warning The type 'GlobalWatchlistEntryLog' is undefined jsdoc/no-undefined-types
346:1 warning The type 'GlobalWatchlistEntryEdits' is undefined jsdoc/no-undefined-types
346:1 warning The type 'GlobalWatchlistEntryLog' is undefined jsdoc/no-undefined-types
376:4 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
378:4 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
428:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
434:1 warning The type 'GlobalWatchlistEntryEdits' is undefined jsdoc/no-undefined-types
434:1 warning The type 'GlobalWatchlistEntryLog' is undefined jsdoc/no-undefined-types
/src/repo/modules/WikibaseHandler.js
9:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
99:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
180:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
214:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
221:13 warning ES2015 'Promise' class is forbidden es-x/no-promise
225:24 warning ES2015 'Array.prototype.entries' method is forbidden es-x/no-array-prototype-entries
/src/repo/modules/getSettings.js
24:1 warning The type 'GlobalWatchlistDebugger' is undefined jsdoc/no-undefined-types
/src/repo/tests/qunit/WatchlistUtils.tests.js
8:1 warning The type 'GlobalWatchlistEntryBase' is undefined jsdoc/no-undefined-types
351:5 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
353:5 warning ES2015 'RegExp.prototype.flags' property is forbidden es-x/no-regexp-prototype-flags
✖ 58 problems (0 errors, 58 warnings)
> lint:styles
> stylelint "**/*.{css,less}"
> lint:i18n
> banana-checker --requireLowerCase=0 i18n/
Checked 1 message directory.
--- end ---
$ package-lock-lint package-lock.json
--- stdout ---
Checking package-lock.json
--- end ---
build: Updating dependencies
composer:
* php-parallel-lint/php-parallel-lint: 1.3.2 → 1.4.0
npm:
* jsdoc-wmf-theme: 0.0.13 → 1.0.0
$ git add .
--- stdout ---
--- end ---
$ git commit -F /tmp/tmpwe3o66aw
--- stdout ---
[master a7cc2c7] build: Updating dependencies
3 files changed, 31 insertions(+), 9 deletions(-)
--- end ---
$ git format-patch HEAD~1 --stdout
--- stdout ---
From a7cc2c7044b86a77daccfe506d44b8ee0ceebf52 Mon Sep 17 00:00:00 2001
From: libraryupgrader <tools.libraryupgrader@tools.wmflabs.org>
Date: Thu, 25 Apr 2024 06:42:42 +0000
Subject: [PATCH] build: Updating dependencies
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
composer:
* php-parallel-lint/php-parallel-lint: 1.3.2 → 1.4.0
npm:
* jsdoc-wmf-theme: 0.0.13 → 1.0.0
Change-Id: I82ff9e3c47c6ef2dcbc5999a8d514b5311ff8859
---
composer.json | 2 +-
package-lock.json | 36 +++++++++++++++++++++++++++++-------
package.json | 2 +-
3 files changed, 31 insertions(+), 9 deletions(-)
diff --git a/composer.json b/composer.json
index ec3ee84..f9591be 100644
--- a/composer.json
+++ b/composer.json
@@ -4,7 +4,7 @@
"mediawiki/mediawiki-phan-config": "0.14.0",
"mediawiki/minus-x": "1.1.1",
"php-parallel-lint/php-console-highlighter": "1.0.0",
- "php-parallel-lint/php-parallel-lint": "1.3.2"
+ "php-parallel-lint/php-parallel-lint": "1.4.0"
},
"scripts": {
"test": [
diff --git a/package-lock.json b/package-lock.json
index 42d2c30..8603800 100644
--- a/package-lock.json
+++ b/package-lock.json
@@ -14,7 +14,7 @@
"eslint-config-wikimedia": "0.27.0",
"grunt-banana-checker": "0.11.1",
"jsdoc": "4.0.2",
- "jsdoc-wmf-theme": "0.0.13",
+ "jsdoc-wmf-theme": "1.0.0",
"stylelint-config-wikimedia": "0.16.1",
"wdio-mediawiki": "2.5.0"
}
@@ -6394,18 +6394,31 @@
}
},
"node_modules/jsdoc-wmf-theme": {
- "version": "0.0.13",
- "resolved": "https://registry.npmjs.org/jsdoc-wmf-theme/-/jsdoc-wmf-theme-0.0.13.tgz",
- "integrity": "sha512-H8h0Xut3J9UGBJECAQAFbF8MVGGNA2PKFpNW4z9Go2DC/wby4Q/hn3reBJ3lB9/j+molyt8UVrO0Z+eA5nOyhw==",
+ "version": "1.0.0",
+ "resolved": "https://registry.npmjs.org/jsdoc-wmf-theme/-/jsdoc-wmf-theme-1.0.0.tgz",
+ "integrity": "sha512-DAR0Rna+X5/Hzlmt297Y05BLPGdUfBUBXfdMwiSJjh8cpLZxt9lHjw2SYnzOpPAPuJYWW3t6MkoJMG0i9cv+uQ==",
"dev": true,
"dependencies": {
"@jsdoc/salty": "^0.2.7",
"@wikimedia/codex-design-tokens": "1.1.1",
"domino": "^2.1.6",
"lunr": "2.3.9",
+ "marked": "^12.0.1",
"normalize.css": "8.0.1"
}
},
+ "node_modules/jsdoc-wmf-theme/node_modules/marked": {
+ "version": "12.0.2",
+ "resolved": "https://registry.npmjs.org/marked/-/marked-12.0.2.tgz",
+ "integrity": "sha512-qXUm7e/YKFoqFPYPa3Ukg9xlI5cyAtGmyEIzMfW//m6kXwCy2Ps9DYf5ioijFKQ8qyuscrHoY04iJGctu2Kg0Q==",
+ "dev": true,
+ "bin": {
+ "marked": "bin/marked.js"
+ },
+ "engines": {
+ "node": ">= 18"
+ }
+ },
"node_modules/jsdoc/node_modules/escape-string-regexp": {
"version": "2.0.0",
"resolved": "https://registry.npmjs.org/escape-string-regexp/-/escape-string-regexp-2.0.0.tgz",
@@ -15452,16 +15465,25 @@
"dev": true
},
"jsdoc-wmf-theme": {
- "version": "0.0.13",
- "resolved": "https://registry.npmjs.org/jsdoc-wmf-theme/-/jsdoc-wmf-theme-0.0.13.tgz",
- "integrity": "sha512-H8h0Xut3J9UGBJECAQAFbF8MVGGNA2PKFpNW4z9Go2DC/wby4Q/hn3reBJ3lB9/j+molyt8UVrO0Z+eA5nOyhw==",
+ "version": "1.0.0",
+ "resolved": "https://registry.npmjs.org/jsdoc-wmf-theme/-/jsdoc-wmf-theme-1.0.0.tgz",
+ "integrity": "sha512-DAR0Rna+X5/Hzlmt297Y05BLPGdUfBUBXfdMwiSJjh8cpLZxt9lHjw2SYnzOpPAPuJYWW3t6MkoJMG0i9cv+uQ==",
"dev": true,
"requires": {
"@jsdoc/salty": "^0.2.7",
"@wikimedia/codex-design-tokens": "1.1.1",
"domino": "^2.1.6",
"lunr": "2.3.9",
+ "marked": "^12.0.1",
"normalize.css": "8.0.1"
+ },
+ "dependencies": {
+ "marked": {
+ "version": "12.0.2",
+ "resolved": "https://registry.npmjs.org/marked/-/marked-12.0.2.tgz",
+ "integrity": "sha512-qXUm7e/YKFoqFPYPa3Ukg9xlI5cyAtGmyEIzMfW//m6kXwCy2Ps9DYf5ioijFKQ8qyuscrHoY04iJGctu2Kg0Q==",
+ "dev": true
+ }
}
},
"jsesc": {
diff --git a/package.json b/package.json
index c9febe0..b320a81 100644
--- a/package.json
+++ b/package.json
@@ -21,7 +21,7 @@
"eslint-config-wikimedia": "0.27.0",
"grunt-banana-checker": "0.11.1",
"jsdoc": "4.0.2",
- "jsdoc-wmf-theme": "0.0.13",
+ "jsdoc-wmf-theme": "1.0.0",
"stylelint-config-wikimedia": "0.16.1",
"wdio-mediawiki": "2.5.0"
},
--
2.39.2
--- end ---