$ date
--- stdout ---
Wed Mar 27 18:07:08 UTC 2024
--- end ---
$ git clone file:///srv/git/unicodejs.git repo --depth=1 -b master
--- stderr ---
Cloning into 'repo'...
--- stdout ---
--- end ---
$ git config user.name libraryupgrader
--- stdout ---
--- end ---
$ git config user.email tools.libraryupgrader@tools.wmflabs.org
--- stdout ---
--- end ---
$ git submodule update --init
--- stdout ---
--- end ---
$ grr init
--- stdout ---
Installed commit-msg hook.
--- end ---
$ git show-ref refs/heads/master
--- stdout ---
3ed89465e22cb15dcba51be252eaa87dddc8f295 refs/heads/master
--- end ---
$ /usr/bin/npm audit --json
--- stdout ---
{
"auditReportVersion": 2,
"vulnerabilities": {
"jsdoc-wmf-theme": {
"name": "jsdoc-wmf-theme",
"severity": "high",
"isDirect": true,
"via": [
"taffydb"
],
"effects": [],
"range": "<=0.0.12",
"nodes": [
"node_modules/jsdoc-wmf-theme"
],
"fixAvailable": {
"name": "jsdoc-wmf-theme",
"version": "0.0.13",
"isSemVerMajor": true
}
},
"taffydb": {
"name": "taffydb",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1089386,
"name": "taffydb",
"dependency": "taffydb",
"title": "TaffyDB can allow access to any data items in the DB",
"url": "https://github.com/advisories/GHSA-mxhp-79qh-mcx6",
"severity": "high",
"cwe": [
"CWE-20",
"CWE-668"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"range": "<=2.7.3"
}
],
"effects": [
"jsdoc-wmf-theme"
],
"range": "*",
"nodes": [
"node_modules/taffydb"
],
"fixAvailable": {
"name": "jsdoc-wmf-theme",
"version": "0.0.13",
"isSemVerMajor": true
}
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 0,
"high": 2,
"critical": 0,
"total": 2
},
"dependencies": {
"prod": 1,
"dev": 526,
"optional": 1,
"peer": 1,
"peerOptional": 0,
"total": 526
}
}
}
--- end ---
$ /usr/bin/npm audit --json
--- stdout ---
{
"auditReportVersion": 2,
"vulnerabilities": {
"jsdoc-wmf-theme": {
"name": "jsdoc-wmf-theme",
"severity": "high",
"isDirect": true,
"via": [
"taffydb"
],
"effects": [],
"range": "<=0.0.12",
"nodes": [
"node_modules/jsdoc-wmf-theme"
],
"fixAvailable": {
"name": "jsdoc-wmf-theme",
"version": "0.0.13",
"isSemVerMajor": true
}
},
"taffydb": {
"name": "taffydb",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1089386,
"name": "taffydb",
"dependency": "taffydb",
"title": "TaffyDB can allow access to any data items in the DB",
"url": "https://github.com/advisories/GHSA-mxhp-79qh-mcx6",
"severity": "high",
"cwe": [
"CWE-20",
"CWE-668"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"range": "<=2.7.3"
}
],
"effects": [
"jsdoc-wmf-theme"
],
"range": "*",
"nodes": [
"node_modules/taffydb"
],
"fixAvailable": {
"name": "jsdoc-wmf-theme",
"version": "0.0.13",
"isSemVerMajor": true
}
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 0,
"high": 2,
"critical": 0,
"total": 2
},
"dependencies": {
"prod": 1,
"dev": 526,
"optional": 1,
"peer": 1,
"peerOptional": 0,
"total": 526
}
}
}
--- end ---
Attempting to npm audit fix
$ /usr/bin/npm audit fix --dry-run --only=dev --json
--- stderr ---
npm WARN invalid config only="dev" set in command line options
npm WARN invalid config Must be one of: null, prod, production
--- stdout ---
{
"added": 526,
"removed": 0,
"changed": 0,
"audited": 527,
"funding": 72,
"audit": {
"auditReportVersion": 2,
"vulnerabilities": {
"jsdoc-wmf-theme": {
"name": "jsdoc-wmf-theme",
"severity": "high",
"isDirect": true,
"via": [
"taffydb"
],
"effects": [],
"range": "<=0.0.12",
"nodes": [
"node_modules/jsdoc-wmf-theme"
],
"fixAvailable": {
"name": "jsdoc-wmf-theme",
"version": "0.0.13",
"isSemVerMajor": true
}
},
"taffydb": {
"name": "taffydb",
"severity": "high",
"isDirect": false,
"via": [
{
"source": 1089386,
"name": "taffydb",
"dependency": "taffydb",
"title": "TaffyDB can allow access to any data items in the DB",
"url": "https://github.com/advisories/GHSA-mxhp-79qh-mcx6",
"severity": "high",
"cwe": [
"CWE-20",
"CWE-668"
],
"cvss": {
"score": 7.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"range": "<=2.7.3"
}
],
"effects": [
"jsdoc-wmf-theme"
],
"range": "*",
"nodes": [
"node_modules/taffydb"
],
"fixAvailable": {
"name": "jsdoc-wmf-theme",
"version": "0.0.13",
"isSemVerMajor": true
}
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 0,
"high": 2,
"critical": 0,
"total": 2
},
"dependencies": {
"prod": 1,
"dev": 526,
"optional": 1,
"peer": 1,
"peerOptional": 0,
"total": 526
}
}
}
}
--- end ---
{"added": 526, "removed": 0, "changed": 0, "audited": 527, "funding": 72, "audit": {"auditReportVersion": 2, "vulnerabilities": {"jsdoc-wmf-theme": {"name": "jsdoc-wmf-theme", "severity": "high", "isDirect": true, "via": ["taffydb"], "effects": [], "range": "<=0.0.12", "nodes": ["node_modules/jsdoc-wmf-theme"], "fixAvailable": {"name": "jsdoc-wmf-theme", "version": "0.0.13", "isSemVerMajor": true}}, "taffydb": {"name": "taffydb", "severity": "high", "isDirect": false, "via": [{"source": 1089386, "name": "taffydb", "dependency": "taffydb", "title": "TaffyDB can allow access to any data items in the DB", "url": "https://github.com/advisories/GHSA-mxhp-79qh-mcx6", "severity": "high", "cwe": ["CWE-20", "CWE-668"], "cvss": {"score": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}, "range": "<=2.7.3"}], "effects": ["jsdoc-wmf-theme"], "range": "*", "nodes": ["node_modules/taffydb"], "fixAvailable": {"name": "jsdoc-wmf-theme", "version": "0.0.13", "isSemVerMajor": true}}}, "metadata": {"vulnerabilities": {"info": 0, "low": 0, "moderate": 0, "high": 2, "critical": 0, "total": 2}, "dependencies": {"prod": 1, "dev": 526, "optional": 1, "peer": 1, "peerOptional": 0, "total": 526}}}}
$ /usr/bin/npm audit fix --only=dev
--- stderr ---
npm WARN invalid config only="dev" set in command line options
npm WARN invalid config Must be one of: null, prod, production
--- stdout ---
added 525 packages, and audited 526 packages in 5s
72 packages are looking for funding
run `npm fund` for details
# npm audit report
taffydb *
Severity: high
TaffyDB can allow access to any data items in the DB - https://github.com/advisories/GHSA-mxhp-79qh-mcx6
fix available via `npm audit fix --force`
Will install jsdoc-wmf-theme@0.0.13, which is a breaking change
node_modules/taffydb
jsdoc-wmf-theme <=0.0.12
Depends on vulnerable versions of taffydb
node_modules/jsdoc-wmf-theme
2 high severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
--- end ---
$ package-lock-lint package-lock.json
--- stdout ---
Checking package-lock.json
--- end ---
Verifying that tests still pass
$ /usr/bin/npm ci
--- stdout ---
added 525 packages, and audited 526 packages in 6s
72 packages are looking for funding
run `npm fund` for details
2 high severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
--- end ---
$ /usr/bin/npm test
--- stdout ---
> unicodejs@13.0.3 test
> grunt test
Running "set-meta" task
Running "set-dev" task
Running "clean:dist" (clean) task
>> 0 paths cleaned.
Running "concat:all" (concat) task
Running "copy:dist" (copy) task
Copied 4 files
Running "eslint:all" (eslint) task
Running "karma:chrome" (karma) task
[32m27 03 2024 18:07:31.777:INFO [karma-server]: [39mKarma v6.4.2 server started at http://localhost:9876/
[32m27 03 2024 18:07:31.779:INFO [launcher]: [39mLaunching browsers ChromeCustom with concurrency unlimited
[32m27 03 2024 18:07:31.784:INFO [launcher]: [39mStarting browser ChromeHeadless
[32m27 03 2024 18:07:32.432:INFO [Chrome Headless 122.0.6261.128 (Linux x86_64)]: [39mConnected on socket 8-AEnPFRe8alqUwVAAAB with id 75759378
.........
Chrome Headless 122.0.6261.128 (Linux x86_64): Executed 9 of 9 SUCCESS (0.103 secs / 0.082 secs)
=============================== Coverage summary ===============================
Statements : 100% ( 252/252 )
Branches : 100% ( 238/238 )
Functions : 100% ( 25/25 )
Lines : 100% ( 250/250 )
================================================================================
Running "karma:firefox" (karma) task
[32m27 03 2024 18:07:32.949:INFO [karma-server]: [39mKarma v6.4.2 server started at http://localhost:9876/
[32m27 03 2024 18:07:32.950:INFO [launcher]: [39mLaunching browsers FirefoxHeadless with concurrency unlimited
[32m27 03 2024 18:07:32.952:INFO [launcher]: [39mStarting browser FirefoxHeadless
[32m27 03 2024 18:07:35.069:INFO [Firefox 115.0 (Linux x86_64)]: [39mConnected on socket d2c1Y1YhP9zlaMJQAAAD with id 1933766
.........
Firefox 115.0 (Linux x86_64): Executed 9 of 9 SUCCESS (0.129 secs / 0.11 secs)
=============================== Coverage summary ===============================
Statements : 100% ( 252/252 )
Branches : 100% ( 238/238 )
Functions : 100% ( 25/25 )
Lines : 100% ( 250/250 )
================================================================================
Done.
--- end ---
$ package-lock-lint package-lock.json
--- stdout ---
Checking package-lock.json
--- end ---
[DNM] there are no updates
$ git add .
--- stdout ---
--- end ---
$ git commit -F /tmp/tmpqxrbxhtr
--- stdout ---
On branch master
Your branch is up to date with 'origin/master'.
nothing to commit, working tree clean
--- end ---