$ date
--- stdout ---
Tue May 24 04:19:30 UTC 2022
--- end ---
$ git clone file:///srv/git/wikimedia-toolhub.git repo --depth=1 -b main
--- stderr ---
Cloning into 'repo'...
--- stdout ---
--- end ---
$ git config user.name libraryupgrader
--- stdout ---
--- end ---
$ git config user.email tools.libraryupgrader@tools.wmflabs.org
--- stdout ---
--- end ---
$ git submodule update --init
--- stdout ---
--- end ---
$ grr init
--- stdout ---
Installed commit-msg hook.
--- end ---
$ git show-ref refs/heads/main
--- stdout ---
58849b9d15afcbe85250f6bf5a31528549fc7042 refs/heads/main
--- end ---
$ /usr/bin/npm audit --json --legacy-peer-deps
--- stdout ---
{
"auditReportVersion": 2,
"vulnerabilities": {
"@vue/cli-plugin-unit-mocha": {
"name": "@vue/cli-plugin-unit-mocha",
"severity": "moderate",
"via": [
"mocha"
],
"effects": [],
"range": ">=5.0.0-alpha.0",
"nodes": [
"node_modules/@vue/cli-plugin-unit-mocha"
],
"fixAvailable": {
"name": "@vue/cli-plugin-unit-mocha",
"version": "4.5.17",
"isSemVerMajor": true
}
},
"ansi-regex": {
"name": "ansi-regex",
"severity": "high",
"via": [
{
"source": 1070273,
"name": "ansi-regex",
"dependency": "ansi-regex",
"title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
"url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
"severity": "high",
"range": ">=3.0.0 <3.0.1"
},
{
"source": 1070274,
"name": "ansi-regex",
"dependency": "ansi-regex",
"title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
"url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
"severity": "high",
"range": ">=4.0.0 <4.1.1"
},
{
"source": 1070275,
"name": "ansi-regex",
"dependency": "ansi-regex",
"title": " Inefficient Regular Expression Complexity in chalk/ansi-regex",
"url": "https://github.com/advisories/GHSA-93q8-gq69-wqmw",
"severity": "high",
"range": ">=5.0.0 <5.0.1"
}
],
"effects": [],
"range": "3.0.0 || 4.0.0 - 4.1.0 || 5.0.0",
"nodes": [
"node_modules/ansi-regex",
"node_modules/inquirer/node_modules/ansi-regex",
"node_modules/log-update/node_modules/ansi-regex",
"node_modules/mocha/node_modules/ansi-regex",
"node_modules/nyc/node_modules/ansi-regex",
"node_modules/wide-align/node_modules/ansi-regex"
],
"fixAvailable": true
},
"async": {
"name": "async",
"severity": "high",
"via": [
{
"source": 1070206,
"name": "async",
"dependency": "async",
"title": "Prototype Pollution in async",
"url": "https://github.com/advisories/GHSA-fwr7-v2mv-hh25",
"severity": "high",
"range": "<2.6.4"
}
],
"effects": [
"jake"
],
"range": "<2.6.4",
"nodes": [
"node_modules/async",
"node_modules/portfinder/node_modules/async"
],
"fixAvailable": true
},
"ejs": {
"name": "ejs",
"severity": "high",
"via": [
{
"source": 1070256,
"name": "ejs",
"dependency": "ejs",
"title": "Template injection in ejs",
"url": "https://github.com/advisories/GHSA-phwq-j96m-2c2q",
"severity": "high",
"range": "<3.1.7"
}
],
"effects": [],
"range": "<3.1.7",
"nodes": [
"node_modules/ejs"
],
"fixAvailable": true
},
"jake": {
"name": "jake",
"severity": "high",
"via": [
"async"
],
"effects": [],
"range": "8.0.1 - 10.8.4",
"nodes": [
"node_modules/jake"
],
"fixAvailable": true
},
"json-pointer": {
"name": "json-pointer",
"severity": "moderate",
"via": [
{
"source": 1067536,
"name": "json-pointer",
"dependency": "json-pointer",
"title": "Prototype Pollution in json-pointer",
"url": "https://github.com/advisories/GHSA-v5vg-g7rq-363w",
"severity": "moderate",
"range": "<=0.6.1"
}
],
"effects": [],
"range": "<=0.6.1",
"nodes": [
"node_modules/json-pointer"
],
"fixAvailable": true
},
"marked": {
"name": "marked",
"severity": "high",
"via": [
{
"source": 1070026,
"name": "marked",
"dependency": "marked",
"title": "Inefficient Regular Expression Complexity in marked",
"url": "https://github.com/advisories/GHSA-rrrm-qjm4-v8hf",
"severity": "high",
"range": "<4.0.10"
}
],
"effects": [
"rapidoc"
],
"range": "<4.0.10",
"nodes": [
"node_modules/marked"
],
"fixAvailable": true
},
"minimist": {
"name": "minimist",
"severity": "critical",
"via": [
{
"source": 1067342,
"name": "minimist",
"dependency": "minimist",
"title": "Prototype Pollution in minimist",
"url": "https://github.com/advisories/GHSA-xvch-5gv4-984h",
"severity": "critical",
"range": "<1.2.6"
}
],
"effects": [],
"range": "<1.2.6",
"nodes": [
"node_modules/minimist"
],
"fixAvailable": true
},
"mocha": {
"name": "mocha",
"severity": "moderate",
"via": [
"nanoid"
],
"effects": [
"@vue/cli-plugin-unit-mocha"
],
"range": "8.2.0 - 9.1.4",
"nodes": [
"node_modules/@vue/cli-plugin-unit-mocha/node_modules/mocha"
],
"fixAvailable": {
"name": "@vue/cli-plugin-unit-mocha",
"version": "4.5.17",
"isSemVerMajor": true
}
},
"moment": {
"name": "moment",
"severity": "high",
"via": [
{
"source": 1070245,
"name": "moment",
"dependency": "moment",
"title": "Path Traversal: 'dir/../../filename' in moment.locale",
"url": "https://github.com/advisories/GHSA-8hfj-j24r-96c4",
"severity": "high",
"range": "<2.29.2"
}
],
"effects": [],
"range": "<2.29.2",
"nodes": [
"node_modules/moment"
],
"fixAvailable": true
},
"nanoid": {
"name": "nanoid",
"severity": "moderate",
"via": [
{
"source": 1067367,
"name": "nanoid",
"dependency": "nanoid",
"title": "Exposure of Sensitive Information to an Unauthorized Actor in nanoid",
"url": "https://github.com/advisories/GHSA-qrpm-p2h7-hrv2",
"severity": "moderate",
"range": ">=3.0.0 <3.1.31"
}
],
"effects": [
"mocha"
],
"range": "3.0.0 - 3.1.30",
"nodes": [
"node_modules/@vue/cli-plugin-unit-mocha/node_modules/nanoid"
],
"fixAvailable": {
"name": "@vue/cli-plugin-unit-mocha",
"version": "4.5.17",
"isSemVerMajor": true
}
},
"node-forge": {
"name": "node-forge",
"severity": "high",
"via": [
{
"source": 1070356,
"name": "node-forge",
"dependency": "node-forge",
"title": "Improper Verification of Cryptographic Signature in node-forge",
"url": "https://github.com/advisories/GHSA-cfm4-qjh2-4765",
"severity": "high",
"range": "<1.3.0"
}
],
"effects": [],
"range": "<1.3.0",
"nodes": [
"node_modules/node-forge"
],
"fixAvailable": true
},
"prismjs": {
"name": "prismjs",
"severity": "high",
"via": [
{
"source": 1067401,
"name": "prismjs",
"dependency": "prismjs",
"title": "Cross-site Scripting in Prism",
"url": "https://github.com/advisories/GHSA-3949-f494-cm99",
"severity": "high",
"range": ">=1.14.0 <1.27.0"
}
],
"effects": [],
"range": "1.14.0 - 1.26.0",
"nodes": [
"node_modules/prismjs"
],
"fixAvailable": true
},
"rapidoc": {
"name": "rapidoc",
"severity": "high",
"via": [
"marked"
],
"effects": [],
"range": "<=9.1.3 || 9.1.5",
"nodes": [
"node_modules/rapidoc"
],
"fixAvailable": true
},
"shelljs": {
"name": "shelljs",
"severity": "moderate",
"via": [
{
"source": 1067451,
"name": "shelljs",
"dependency": "shelljs",
"title": "Improper Privilege Management in shelljs",
"url": "https://github.com/advisories/GHSA-64g7-mvw6-v9qj",
"severity": "moderate",
"range": "<0.8.5"
}
],
"effects": [],
"range": "<0.8.5",
"nodes": [
"node_modules/shelljs"
],
"fixAvailable": true
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 5,
"high": 9,
"critical": 1,
"total": 15
},
"dependencies": {
"prod": 68,
"dev": 2087,
"optional": 3,
"peer": 3,
"peerOptional": 0,
"total": 2154
}
}
}
--- end ---
Upgrading n:stylelint-config-wikimedia from ^0.12.2 -> 0.13.0
$ /usr/bin/npm install
--- stderr ---
npm WARN deprecated source-map-url@0.4.1: See https://github.com/lydell/source-map-url#deprecated
npm WARN deprecated @hapi/bourne@1.3.2: This version has been deprecated and is no longer supported or maintained
npm WARN deprecated urix@0.1.0: Please see https://github.com/lydell/urix#deprecated
npm WARN deprecated resolve-url@0.2.1: https://github.com/lydell/resolve-url#deprecated
npm WARN deprecated apollo-tracing@0.15.0: The `apollo-tracing` package is no longer part of Apollo Server 3. See https://www.apollographql.com/docs/apollo-server/migration/#tracing for details
npm WARN deprecated source-map-resolve@0.5.3: See https://github.com/lydell/source-map-resolve#deprecated
npm WARN deprecated graphql-extensions@0.15.0: The `graphql-extensions` API has been removed from Apollo Server 3. Use the plugin API instead: https://www.apollographql.com/docs/apollo-server/integrations/plugins/
npm WARN deprecated querystring@0.2.0: The querystring API is considered Legacy. new code should use the URLSearchParams API instead.
npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details.
npm WARN deprecated apollo-cache-control@0.14.0: The functionality provided by the `apollo-cache-control` package is built in to `apollo-server-core` starting with Apollo Server 3. See https://www.apollographql.com/docs/apollo-server/migration/#cachecontrol for details.
npm WARN deprecated subscriptions-transport-ws@0.9.19: The `subscriptions-transport-ws` package is no longer maintained. We recommend you use `graphql-ws` instead. For help migrating Apollo software to `graphql-ws`, see https://www.apollographql.com/docs/apollo-server/data/subscriptions/#switching-from-subscriptions-transport-ws For general help using `graphql-ws`, see https://github.com/enisdenjo/graphql-ws/blob/master/README.md
npm WARN deprecated graphql-tools@4.0.8: This package has been deprecated and now it only exports makeExecutableSchema.\nAnd it will no longer receive updates.\nWe recommend you to migrate to scoped packages such as @graphql-tools/schema, @graphql-tools/utils and etc.\nCheck out https://www.graphql-tools.com to learn what package you should use instead
npm WARN deprecated core-js@2.6.12: core-js@<3.4 is no longer maintained and not recommended for usage due to the number of issues. Because of the V8 engine whims, feature detection in old core-js versions could cause a slowdown up to 100x even if nothing is polyfilled. Please, upgrade your dependencies to the actual version of core-js.
--- stdout ---
added 2141 packages, and audited 2142 packages in 26s
180 packages are looking for funding
run `npm fund` for details
15 vulnerabilities (5 moderate, 9 high, 1 critical)
To address issues that do not require attention, run:
npm audit fix
To address all issues (including breaking changes), run:
npm audit fix --force
Run `npm audit` for details.
--- end ---
$ package-lock-lint package-lock.json
--- stdout ---
Checking package-lock.json
--- end ---
$ ./node_modules/.bin/stylelint vue/static/vue/css/loading.css docs/_static/css/custom.css vue/src/assets/styles/index.css static/css/oauth.css toolhub/apps/crawler/static/css/admin.css -f json
--- stderr ---
Error: Could not find "stylelint-config-wikimedia/grade-a". Do you need a `configBasedir`?
at module.exports (/src/repo/node_modules/stylelint/lib/utils/configurationError.js:11:49)
at getModulePath (/src/repo/node_modules/stylelint/lib/utils/getModulePath.js:28:9)
at loadExtendedConfig (/src/repo/node_modules/stylelint/lib/augmentConfig.js:230:21)
at extendConfig (/src/repo/node_modules/stylelint/lib/augmentConfig.js:201:30)
at augmentConfigBasic (/src/repo/node_modules/stylelint/lib/augmentConfig.js:52:26)
at augmentConfigFull (/src/repo/node_modules/stylelint/lib/augmentConfig.js:106:30)
at Object.transform (/src/repo/node_modules/stylelint/lib/getConfigForFile.js:51:37)
at run (/src/repo/node_modules/cosmiconfig/dist/Explorer.js:42:49)
at async cacheWrapper (/src/repo/node_modules/cosmiconfig/dist/cacheWrapper.js:16:18)
at async cacheWrapper (/src/repo/node_modules/cosmiconfig/dist/cacheWrapper.js:16:18)
--- stdout ---
--- end ---
Traceback (most recent call last):
File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1395, in main
libup.run(args.repo, args.output, args.branch)
File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1333, in run
self.npm_upgrade(plan)
File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1041, in npm_upgrade
hook(update)
File "/venv/lib/python3.9/site-packages/runner-0.1.0-py3.9.egg/runner/__init__.py", line 1076, in _handle_stylelint
errors = json.loads(self.check_call(['./node_modules/.bin/stylelint'] + files + [
File "/usr/lib/python3.9/json/__init__.py", line 346, in loads
return _default_decoder.decode(s)
File "/usr/lib/python3.9/json/decoder.py", line 337, in decode
obj, end = self.raw_decode(s, idx=_w(s, 0).end())
File "/usr/lib/python3.9/json/decoder.py", line 355, in raw_decode
raise JSONDecodeError("Expecting value", s, err.value) from None
json.decoder.JSONDecodeError: Expecting value: line 1 column 1 (char 0)