$ date
--- stdout ---
Tue Mar 21 22:15:50 UTC 2023
--- end ---
$ git clone file:///srv/git/mediawiki-services-service-scaffold-node.git repo --depth=1 -b main
--- stderr ---
Cloning into 'repo'...
--- stdout ---
--- end ---
$ git config user.name libraryupgrader
--- stdout ---
--- end ---
$ git config user.email tools.libraryupgrader@tools.wmflabs.org
--- stdout ---
--- end ---
$ git submodule update --init
--- stdout ---
--- end ---
$ grr init
--- stdout ---
Installed commit-msg hook.
--- end ---
$ git show-ref refs/heads/main
--- stdout ---
cebbd28cee71f290d6dd642d15b00adf241debd7 refs/heads/main
--- end ---
$ /usr/bin/npm audit --json --legacy-peer-deps
--- stdout ---
{
"auditReportVersion": 2,
"vulnerabilities": {
"@wikimedia/servicelib-node-examples": {
"name": "@wikimedia/servicelib-node-examples",
"severity": "moderate",
"isDirect": true,
"via": [
"@wikimedia/servicelib-node-utils"
],
"effects": [],
"range": "",
"nodes": [
"node_modules/@wikimedia/servicelib-node-examples"
],
"fixAvailable": false
},
"@wikimedia/servicelib-node-init": {
"name": "@wikimedia/servicelib-node-init",
"severity": "moderate",
"isDirect": true,
"via": [
"swagger-ui-dist"
],
"effects": [],
"range": "",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init"
],
"fixAvailable": false
},
"@wikimedia/servicelib-node-utils": {
"name": "@wikimedia/servicelib-node-utils",
"severity": "moderate",
"isDirect": true,
"via": [
"preq",
"swagger-ui-dist"
],
"effects": [
"@wikimedia/servicelib-node-examples"
],
"range": "",
"nodes": [
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils",
"node_modules/@wikimedia/servicelib-node-utils"
],
"fixAvailable": false
},
"ansi-regex": {
"name": "ansi-regex",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1091189,
"name": "ansi-regex",
"dependency": "ansi-regex",
"title": "Inefficient Regular Expression Complexity in chalk/ansi-regex",
"url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
"severity": "high",
"cwe": [
"CWE-697",
"CWE-1333"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
"range": ">=4.0.0 <4.1.1"
}
],
"effects": [],
"range": "4.0.0 - 4.1.0",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init/node_modules/ansi-regex",
"node_modules/cliui/node_modules/ansi-regex",
"node_modules/service-runner/node_modules/ansi-regex",
"node_modules/wrap-ansi/node_modules/ansi-regex",
"node_modules/yargs/node_modules/ansi-regex"
],
"fixAvailable": true
},
"body-parser": {
"name": "body-parser",
"severity": "high",
"isDirect": false,
"via": [
"qs",
"qs"
],
"effects": [],
"range": "1.19.0 - 1.19.1 || 2.0.0-beta.1",
"nodes": [
"../servicelib-node/utils/node_modules/body-parser",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/body-parser",
"node_modules/@wikimedia/servicelib-node-init/node_modules/express/node_modules/body-parser",
"node_modules/@wikimedia/servicelib-node-spec/node_modules/body-parser",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/body-parser",
"node_modules/body-parser"
],
"fixAvailable": true
},
"cookiejar": {
"name": "cookiejar",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1088659,
"name": "cookiejar",
"dependency": "cookiejar",
"title": "cookiejar Regular Expression Denial of Service via Cookie.parse function",
"url": "https://github.com/advisories/GHSA-h452-7996-h45h",
"severity": "moderate",
"cwe": [
"CWE-1333"
],
"cvss": {
"score": 5.3,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
"range": "<2.1.4"
}
],
"effects": [],
"range": "<2.1.4",
"nodes": [
"node_modules/@wikimedia/servicelib-node-spec/node_modules/cookiejar"
],
"fixAvailable": true
},
"express": {
"name": "express",
"severity": "high",
"isDirect": true,
"via": [
"body-parser",
"body-parser",
"qs",
"qs"
],
"effects": [],
"range": "4.17.0 - 4.17.2 || >=5.0.0-alpha.1",
"nodes": [
"../servicelib-node/utils/node_modules/express",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/express",
"node_modules/@wikimedia/servicelib-node-init/node_modules/express",
"node_modules/@wikimedia/servicelib-node-spec/node_modules/express",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/express",
"node_modules/express"
],
"fixAvailable": true
},
"ini": {
"name": "ini",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1091252,
"name": "ini",
"dependency": "ini",
"title": "ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse",
"url": "https://github.com/advisories/GHSA-qqgx-2p2h-9c37",
"severity": "high",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 7.3,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"range": "<1.3.6"
}
],
"effects": [],
"range": "<1.3.6",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/ini",
"node_modules/gc-stats/node_modules/ini"
],
"fixAvailable": true
},
"json5": {
"name": "json5",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1091148,
"name": "json5",
"dependency": "json5",
"title": "Prototype Pollution in JSON5 via Parse Method",
"url": "https://github.com/advisories/GHSA-9c47-m6qq-7p4h",
"severity": "high",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 7.1,
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H"
},
"range": ">=2.0.0 <2.2.2"
}
],
"effects": [],
"range": "2.0.0 - 2.2.1",
"nodes": [
"node_modules/@wikimedia/servicelib-node-spec/node_modules/json5"
],
"fixAvailable": true
},
"limitation": {
"name": "limitation",
"severity": "moderate",
"isDirect": false,
"via": [
"wikimedia-kad-fork"
],
"effects": [],
"range": ">=0.2.3",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init/node_modules/limitation",
"node_modules/limitation"
],
"fixAvailable": true
},
"minimatch": {
"name": "minimatch",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1091174,
"name": "minimatch",
"dependency": "minimatch",
"title": "minimatch ReDoS vulnerability",
"url": "https://github.com/advisories/GHSA-f8q6-p94x-37v3",
"severity": "high",
"cwe": [
"CWE-400"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
"range": "<3.0.5"
}
],
"effects": [
"mocha"
],
"range": "<3.0.5",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/minimatch",
"node_modules/@wikimedia/servicelib-node-init/node_modules/minimatch",
"node_modules/@wikimedia/servicelib-node-spec/node_modules/minimatch",
"node_modules/gc-stats/node_modules/minimatch",
"node_modules/minimatch"
],
"fixAvailable": {
"name": "mocha",
"version": "10.2.0",
"isSemVerMajor": true
}
},
"minimist": {
"name": "minimist",
"severity": "critical",
"isDirect": false,
"via": [
{
"source": 1090097,
"name": "minimist",
"dependency": "minimist",
"title": "Prototype Pollution in minimist",
"url": "https://github.com/advisories/GHSA-vh95-rmgr-6w4m",
"severity": "moderate",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 5.6,
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"range": ">=1.0.0 <1.2.3"
},
{
"source": 1090098,
"name": "minimist",
"dependency": "minimist",
"title": "Prototype Pollution in minimist",
"url": "https://github.com/advisories/GHSA-vh95-rmgr-6w4m",
"severity": "moderate",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 5.6,
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"range": "<0.2.1"
},
{
"source": 1091172,
"name": "minimist",
"dependency": "minimist",
"title": "Prototype Pollution in minimist",
"url": "https://github.com/advisories/GHSA-xvch-5gv4-984h",
"severity": "critical",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 9.8,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"range": "<0.2.4"
},
{
"source": 1091173,
"name": "minimist",
"dependency": "minimist",
"title": "Prototype Pollution in minimist",
"url": "https://github.com/advisories/GHSA-xvch-5gv4-984h",
"severity": "critical",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 9.8,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"range": ">=1.0.0 <1.2.6"
}
],
"effects": [
"mkdirp"
],
"range": "<=0.2.3 || 1.0.0 - 1.2.5",
"nodes": [
"../servicelib-node/utils/node_modules/minimist",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/minimist",
"node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/minimist",
"node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/rc/node_modules/minimist",
"node_modules/@wikimedia/servicelib-node-init/node_modules/minimist",
"node_modules/@wikimedia/servicelib-node-spec/node_modules/minimist",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/minimist",
"node_modules/gc-stats/node_modules/minimist",
"node_modules/gc-stats/node_modules/rc/node_modules/minimist",
"node_modules/minimist"
],
"fixAvailable": {
"name": "mocha",
"version": "10.2.0",
"isSemVerMajor": true
}
},
"mkdirp": {
"name": "mkdirp",
"severity": "critical",
"isDirect": false,
"via": [
"minimist"
],
"effects": [
"mocha"
],
"range": "0.4.1 - 0.5.1",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/mkdirp",
"node_modules/gc-stats/node_modules/mkdirp",
"node_modules/mkdirp"
],
"fixAvailable": {
"name": "mocha",
"version": "10.2.0",
"isSemVerMajor": true
}
},
"mocha": {
"name": "mocha",
"severity": "critical",
"isDirect": true,
"via": [
"minimatch",
"mkdirp"
],
"effects": [],
"range": "1.21.5 - 9.2.1",
"nodes": [
"node_modules/@wikimedia/servicelib-node-spec/node_modules/mocha",
"node_modules/mocha"
],
"fixAvailable": {
"name": "mocha",
"version": "10.2.0",
"isSemVerMajor": true
}
},
"moment": {
"name": "moment",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1091430,
"name": "moment",
"dependency": "moment",
"title": "Path Traversal: 'dir/../../filename' in moment.locale",
"url": "https://github.com/advisories/GHSA-8hfj-j24r-96c4",
"severity": "high",
"cwe": [
"CWE-22",
"CWE-27"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
},
"range": "<2.29.2"
},
{
"source": 1091441,
"name": "moment",
"dependency": "moment",
"title": "Moment.js vulnerable to Inefficient Regular Expression Complexity",
"url": "https://github.com/advisories/GHSA-wc69-rhjr-hc9g",
"severity": "high",
"cwe": [
"CWE-400",
"CWE-1333"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
"range": ">=2.18.0 <2.29.4"
}
],
"effects": [],
"range": "<=2.29.3",
"nodes": [
"../servicelib-node/utils/node_modules/moment",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/moment",
"node_modules/@wikimedia/servicelib-node-init/node_modules/moment",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/moment",
"node_modules/moment"
],
"fixAvailable": true
},
"ms": {
"name": "ms",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1088818,
"name": "ms",
"dependency": "ms",
"title": "Vercel ms Inefficient Regular Expression Complexity vulnerability",
"url": "https://github.com/advisories/GHSA-w9mr-4mfr-499f",
"severity": "moderate",
"cwe": [
"CWE-1333"
],
"cvss": {
"score": 5.3,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
"range": "<2.0.0"
}
],
"effects": [
"wikimedia-kad-fork"
],
"range": "<2.0.0",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init/node_modules/wikimedia-kad-fork/node_modules/ms",
"node_modules/wikimedia-kad-fork/node_modules/ms"
],
"fixAvailable": true
},
"preq": {
"name": "preq",
"severity": "high",
"isDirect": false,
"via": [
"request",
"requestretry"
],
"effects": [],
"range": "*",
"nodes": [
"../servicelib-node/utils/node_modules/preq",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/preq",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/preq"
],
"fixAvailable": false
},
"qs": {
"name": "qs",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1090137,
"name": "qs",
"dependency": "qs",
"title": "qs vulnerable to Prototype Pollution",
"url": "https://github.com/advisories/GHSA-hrpp-h998-j3pp",
"severity": "high",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
"range": ">=6.7.0 <6.7.3"
},
{
"source": 1090139,
"name": "qs",
"dependency": "qs",
"title": "qs vulnerable to Prototype Pollution",
"url": "https://github.com/advisories/GHSA-hrpp-h998-j3pp",
"severity": "high",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
"range": ">=6.9.0 <6.9.7"
},
{
"source": 1090140,
"name": "qs",
"dependency": "qs",
"title": "qs vulnerable to Prototype Pollution",
"url": "https://github.com/advisories/GHSA-hrpp-h998-j3pp",
"severity": "high",
"cwe": [
"CWE-1321"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
"range": ">=6.10.0 <6.10.3"
}
],
"effects": [
"body-parser",
"express"
],
"range": "6.7.0 - 6.7.2 || 6.9.0 - 6.9.6 || 6.10.0 - 6.10.2",
"nodes": [
"../servicelib-node/utils/node_modules/qs",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/body-parser/node_modules/qs",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/express/node_modules/qs",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/qs",
"node_modules/@wikimedia/servicelib-node-init/node_modules/qs",
"node_modules/@wikimedia/servicelib-node-spec/node_modules/body-parser/node_modules/qs",
"node_modules/@wikimedia/servicelib-node-spec/node_modules/express/node_modules/qs",
"node_modules/@wikimedia/servicelib-node-spec/node_modules/qs",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/qs",
"node_modules/qs"
],
"fixAvailable": true
},
"request": {
"name": "request",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1091410,
"name": "request",
"dependency": "request",
"title": "Server-Side Request Forgery in Request",
"url": "https://github.com/advisories/GHSA-p8p7-x288-28g6",
"severity": "moderate",
"cwe": [
"CWE-918"
],
"cvss": {
"score": 0,
"vectorString": null
},
"range": "<=2.88.2"
}
],
"effects": [
"preq"
],
"range": "*",
"nodes": [
"../servicelib-node/utils/node_modules/request",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/request",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/request"
],
"fixAvailable": false
},
"requestretry": {
"name": "requestretry",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1090420,
"name": "requestretry",
"dependency": "requestretry",
"title": "Cookie exposure in requestretry",
"url": "https://github.com/advisories/GHSA-hjp8-2cm3-cc45",
"severity": "high",
"cwe": [
"CWE-200"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"range": "<7.0.0"
}
],
"effects": [
"preq"
],
"range": "<7.0.0",
"nodes": [
"../servicelib-node/utils/node_modules/requestretry",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/requestretry",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/requestretry"
],
"fixAvailable": false
},
"swagger-ui-dist": {
"name": "swagger-ui-dist",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1085394,
"name": "swagger-ui-dist",
"dependency": "swagger-ui-dist",
"title": "Server side request forgery in SwaggerUI",
"url": "https://github.com/advisories/GHSA-qrmm-w75w-3wpx",
"severity": "moderate",
"cwe": [
"CWE-918"
],
"cvss": {
"score": 0,
"vectorString": null
},
"range": "<4.1.3"
},
{
"source": 1088759,
"name": "swagger-ui-dist",
"dependency": "swagger-ui-dist",
"title": "Spoofing attack in swagger-ui-dist",
"url": "https://github.com/advisories/GHSA-6c9x-mj3g-h47x",
"severity": "moderate",
"cwe": [
"CWE-1021"
],
"cvss": {
"score": 6.1,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"range": "<4.1.3"
}
],
"effects": [
"@wikimedia/servicelib-node-init",
"@wikimedia/servicelib-node-utils",
"swagger-ui-express"
],
"range": "<=4.1.2",
"nodes": [
"../servicelib-node/utils/node_modules/swagger-ui-dist",
"node_modules/@wikimedia/servicelib-node-examples/node_modules/@wikimedia/servicelib-node-utils/node_modules/swagger-ui-dist",
"node_modules/@wikimedia/servicelib-node-init/node_modules/swagger-ui-dist",
"node_modules/@wikimedia/servicelib-node-spec/node_modules/swagger-ui-dist",
"node_modules/@wikimedia/servicelib-node-utils/node_modules/swagger-ui-dist"
],
"fixAvailable": false
},
"swagger-ui-express": {
"name": "swagger-ui-express",
"severity": "moderate",
"isDirect": false,
"via": [
"swagger-ui-dist"
],
"effects": [],
"range": "4.0.0 - 4.1.6",
"nodes": [
"node_modules/@wikimedia/servicelib-node-spec/node_modules/swagger-ui-express"
],
"fixAvailable": true
},
"tar": {
"name": "tar",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1089684,
"name": "tar",
"dependency": "tar",
"title": "Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization",
"url": "https://github.com/advisories/GHSA-3jfq-g458-7qm9",
"severity": "high",
"cwe": [
"CWE-22"
],
"cvss": {
"score": 8.2,
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
},
"range": ">=4.0.0 <4.4.14"
},
{
"source": 1091313,
"name": "tar",
"dependency": "tar",
"title": "Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning",
"url": "https://github.com/advisories/GHSA-r628-mhmh-qjhw",
"severity": "high",
"cwe": [
"CWE-22",
"CWE-23",
"CWE-59"
],
"cvss": {
"score": 8.2,
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
},
"range": ">=4.0.0 <4.4.15"
},
{
"source": 1091343,
"name": "tar",
"dependency": "tar",
"title": "Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links",
"url": "https://github.com/advisories/GHSA-9r2w-394v-53qc",
"severity": "high",
"cwe": [
"CWE-22",
"CWE-59"
],
"cvss": {
"score": 8.2,
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
},
"range": "<4.4.16"
},
{
"source": 1091346,
"name": "tar",
"dependency": "tar",
"title": "Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization",
"url": "https://github.com/advisories/GHSA-5955-9wpr-37jh",
"severity": "high",
"cwe": [
"CWE-22"
],
"cvss": {
"score": 8.2,
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
},
"range": "<4.4.18"
},
{
"source": 1091349,
"name": "tar",
"dependency": "tar",
"title": "Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links",
"url": "https://github.com/advisories/GHSA-qq89-hq3f-393p",
"severity": "high",
"cwe": [
"CWE-22",
"CWE-59"
],
"cvss": {
"score": 8.2,
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
},
"range": "<4.4.18"
}
],
"effects": [],
"range": "<=4.4.17",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init/node_modules/gc-stats/node_modules/tar",
"node_modules/gc-stats/node_modules/tar"
],
"fixAvailable": true
},
"validator": {
"name": "validator",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1088241,
"name": "validator",
"dependency": "validator",
"title": "Inefficient Regular Expression Complexity in Validator.js",
"url": "https://github.com/advisories/GHSA-xx4c-jj58-r7x6",
"severity": "moderate",
"cwe": [
"CWE-1333"
],
"cvss": {
"score": 5.3,
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
"range": ">=11.1.0 <13.7.0"
},
{
"source": 1089600,
"name": "validator",
"dependency": "validator",
"title": "Inefficient Regular Expression Complexity in validator.js",
"url": "https://github.com/advisories/GHSA-qgmg-gppg-76g5",
"severity": "moderate",
"cwe": [
"CWE-1333"
],
"cvss": {
"score": 5.3,
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
},
"range": "<13.7.0"
}
],
"effects": [],
"range": "<=13.6.0",
"nodes": [
"node_modules/@wikimedia/servicelib-node-spec/node_modules/validator"
],
"fixAvailable": true
},
"wikimedia-kad-fork": {
"name": "wikimedia-kad-fork",
"severity": "moderate",
"isDirect": false,
"via": [
"ms"
],
"effects": [
"limitation"
],
"range": "*",
"nodes": [
"node_modules/@wikimedia/servicelib-node-init/node_modules/wikimedia-kad-fork",
"node_modules/wikimedia-kad-fork"
],
"fixAvailable": true
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 11,
"high": 11,
"critical": 3,
"total": 25
},
"dependencies": {
"prod": 749,
"dev": 544,
"optional": 507,
"peer": 284,
"peerOptional": 0,
"total": 1515
}
}
}
--- end ---
$ /usr/bin/npm install
--- stderr ---
npm ERR! code E404
npm ERR! 404 Not Found - GET https://registry.npmjs.org/@wikimedia%2fservicelib-node-examples - Not found
npm ERR! 404
npm ERR! 404 '@wikimedia/servicelib-node-examples@^1.0.0' is not in this registry.
npm ERR! 404
npm ERR! 404 Note that you can also install from a
npm ERR! 404 tarball, folder, http url, or git url.
npm ERR! A complete log of this run can be found in:
npm ERR! /cache/_logs/2023-03-21T22_15_55_095Z-debug-0.log
--- stdout ---
--- end ---
Traceback (most recent call last):
File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1400, in main
libup.run(args.repo, args.output, args.branch)
File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1331, in run
self.fix_remove_eslint_stylelint_if_grunt()
File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 630, in fix_remove_eslint_stylelint_if_grunt
self.check_call(['npm', 'install'])
File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/shell2.py", line 54, in check_call
res.check_returncode()
File "/usr/lib/python3.9/subprocess.py", line 460, in check_returncode
raise CalledProcessError(self.returncode, self.args, self.stdout,
subprocess.CalledProcessError: Command '['/usr/bin/npm', 'install']' returned non-zero exit status 1.