$ date
--- stdout ---
Thu May 21 18:20:06 UTC 2026
--- end ---
$ git clone file:///srv/git/mediawiki-extensions-Push.git /src/repo --depth=1 -b REL1_45
--- stderr ---
Cloning into '/src/repo'...
--- stdout ---
--- end ---
$ git config user.name libraryupgrader
--- stdout ---
--- end ---
$ git config user.email tools.libraryupgrader@tools.wmflabs.org
--- stdout ---
--- end ---
$ git submodule update --init
--- stdout ---
--- end ---
$ grr init
--- stdout ---
Installed commit-msg hook.
--- end ---
$ git show-ref refs/heads/REL1_45
--- stdout ---
02a1cc1d2c0fe6046abacb0db7cff56c0ca1ff3e refs/heads/REL1_45
--- end ---
$ /usr/bin/npm audit --json
--- stdout ---
{
"auditReportVersion": 2,
"vulnerabilities": {
"brace-expansion": {
"name": "brace-expansion",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1119088,
"name": "brace-expansion",
"dependency": "brace-expansion",
"title": "brace-expansion: Large numeric range defeats documented `max` DoS protection",
"url": "https://github.com/advisories/GHSA-jxxr-4gwj-5jf2",
"severity": "moderate",
"cwe": [
"CWE-400"
],
"cvss": {
"score": 6.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"range": ">=5.0.0 <5.0.6"
}
],
"effects": [],
"range": "5.0.2 - 5.0.5",
"nodes": [
"node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion"
],
"fixAvailable": true
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 1,
"high": 0,
"critical": 0,
"total": 1
},
"dependencies": {
"prod": 1,
"dev": 347,
"optional": 6,
"peer": 7,
"peerOptional": 0,
"total": 347
}
}
}
--- end ---
$ /usr/bin/composer install
--- stderr ---
No composer.lock file present. Updating dependencies to latest instead of installing from lock file. See https://getcomposer.org/install for more information.
Loading composer repositories with package information
Updating dependencies
Lock file operations: 20 installs, 0 updates, 0 removals
- Locking composer/semver (3.4.4)
- Locking composer/spdx-licenses (1.5.10)
- Locking dealerdirect/phpcodesniffer-composer-installer (v1.2.1)
- Locking mediawiki/mediawiki-codesniffer (v48.0.0)
- Locking mediawiki/minus-x (1.1.3)
- Locking php-parallel-lint/php-console-color (v1.0.1)
- Locking php-parallel-lint/php-console-highlighter (v1.0.0)
- Locking php-parallel-lint/php-parallel-lint (v1.4.0)
- Locking phpcsstandards/phpcsextra (1.4.0)
- Locking phpcsstandards/phpcsutils (1.1.1)
- Locking psr/container (2.0.2)
- Locking squizlabs/php_codesniffer (3.13.2)
- Locking symfony/console (v7.4.11)
- Locking symfony/deprecation-contracts (v3.7.0)
- Locking symfony/polyfill-ctype (v1.37.0)
- Locking symfony/polyfill-intl-grapheme (v1.37.0)
- Locking symfony/polyfill-intl-normalizer (v1.37.0)
- Locking symfony/polyfill-mbstring (v1.37.0)
- Locking symfony/service-contracts (v3.7.0)
- Locking symfony/string (v8.0.11)
Writing lock file
Installing dependencies from lock file (including require-dev)
Package operations: 20 installs, 0 updates, 0 removals
0 [>---------------------------] 0 [->--------------------------]
- Installing squizlabs/php_codesniffer (3.13.2): Extracting archive
- Installing dealerdirect/phpcodesniffer-composer-installer (v1.2.1): Extracting archive
- Installing phpcsstandards/phpcsutils (1.1.1): Extracting archive
- Installing phpcsstandards/phpcsextra (1.4.0): Extracting archive
- Installing symfony/polyfill-mbstring (v1.37.0): Extracting archive
- Installing composer/spdx-licenses (1.5.10): Extracting archive
- Installing composer/semver (3.4.4): Extracting archive
- Installing mediawiki/mediawiki-codesniffer (v48.0.0): Extracting archive
- Installing symfony/polyfill-intl-normalizer (v1.37.0): Extracting archive
- Installing symfony/polyfill-intl-grapheme (v1.37.0): Extracting archive
- Installing symfony/polyfill-ctype (v1.37.0): Extracting archive
- Installing symfony/string (v8.0.11): Extracting archive
- Installing symfony/deprecation-contracts (v3.7.0): Extracting archive
- Installing psr/container (2.0.2): Extracting archive
- Installing symfony/service-contracts (v3.7.0): Extracting archive
- Installing symfony/console (v7.4.11): Extracting archive
- Installing mediawiki/minus-x (1.1.3): Extracting archive
- Installing php-parallel-lint/php-console-color (v1.0.1): Extracting archive
- Installing php-parallel-lint/php-console-highlighter (v1.0.0): Extracting archive
- Installing php-parallel-lint/php-parallel-lint (v1.4.0): Extracting archive
0/18 [>---------------------------] 0%
18/18 [============================] 100%
Generating autoload files
14 packages you are using are looking for funding.
Use the `composer fund` command to find out more!
--- stdout ---
PHP CodeSniffer Config installed_paths set to ../../mediawiki/mediawiki-codesniffer,../../phpcsstandards/phpcsextra,../../phpcsstandards/phpcsutils
--- end ---
$ /usr/bin/npm audit --json
--- stdout ---
{
"auditReportVersion": 2,
"vulnerabilities": {
"brace-expansion": {
"name": "brace-expansion",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1119088,
"name": "brace-expansion",
"dependency": "brace-expansion",
"title": "brace-expansion: Large numeric range defeats documented `max` DoS protection",
"url": "https://github.com/advisories/GHSA-jxxr-4gwj-5jf2",
"severity": "moderate",
"cwe": [
"CWE-400"
],
"cvss": {
"score": 6.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"range": ">=5.0.0 <5.0.6"
}
],
"effects": [],
"range": "5.0.2 - 5.0.5",
"nodes": [
"node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion"
],
"fixAvailable": true
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 1,
"high": 0,
"critical": 0,
"total": 1
},
"dependencies": {
"prod": 1,
"dev": 347,
"optional": 6,
"peer": 7,
"peerOptional": 0,
"total": 347
}
}
}
--- end ---
Attempting to npm audit fix
$ /usr/bin/npm audit fix --dry-run --only=dev --json
--- stderr ---
npm WARN invalid config only="dev" set in command line options
npm WARN invalid config Must be one of: null, prod, production
--- stdout ---
{
"added": 347,
"removed": 0,
"changed": 0,
"audited": 348,
"funding": 84,
"audit": {
"auditReportVersion": 2,
"vulnerabilities": {
"brace-expansion": {
"name": "brace-expansion",
"severity": "moderate",
"isDirect": false,
"via": [
{
"source": 1119088,
"name": "brace-expansion",
"dependency": "brace-expansion",
"title": "brace-expansion: Large numeric range defeats documented `max` DoS protection",
"url": "https://github.com/advisories/GHSA-jxxr-4gwj-5jf2",
"severity": "moderate",
"cwe": [
"CWE-400"
],
"cvss": {
"score": 6.5,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"range": ">=5.0.0 <5.0.6"
}
],
"effects": [],
"range": "5.0.2 - 5.0.5",
"nodes": [
""
],
"fixAvailable": true
}
},
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 1,
"high": 0,
"critical": 0,
"total": 1
},
"dependencies": {
"prod": 1,
"dev": 347,
"optional": 6,
"peer": 7,
"peerOptional": 0,
"total": 347
}
}
}
}
--- end ---
{"added": 347, "removed": 0, "changed": 0, "audited": 348, "funding": 84, "audit": {"auditReportVersion": 2, "vulnerabilities": {"brace-expansion": {"name": "brace-expansion", "severity": "moderate", "isDirect": false, "via": [{"source": 1119088, "name": "brace-expansion", "dependency": "brace-expansion", "title": "brace-expansion: Large numeric range defeats documented `max` DoS protection", "url": "https://github.com/advisories/GHSA-jxxr-4gwj-5jf2", "severity": "moderate", "cwe": ["CWE-400"], "cvss": {"score": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}, "range": ">=5.0.0 <5.0.6"}], "effects": [], "range": "5.0.2 - 5.0.5", "nodes": [""], "fixAvailable": true}}, "metadata": {"vulnerabilities": {"info": 0, "low": 0, "moderate": 1, "high": 0, "critical": 0, "total": 1}, "dependencies": {"prod": 1, "dev": 347, "optional": 6, "peer": 7, "peerOptional": 0, "total": 347}}}}
$ /usr/bin/npm audit fix --only=dev
--- stderr ---
npm WARN invalid config only="dev" set in command line options
npm WARN invalid config Must be one of: null, prod, production
npm WARN deprecated @humanwhocodes/config-array@0.13.0: Use @eslint/config-array instead
npm WARN deprecated @humanwhocodes/object-schema@2.0.3: Use @eslint/object-schema instead
npm WARN deprecated glob@7.1.7: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me
npm WARN deprecated eslint@8.57.1: This version is no longer supported. Please see https://eslint.org/version-support for other options.
--- stdout ---
added 347 packages, and audited 348 packages in 4s
84 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
--- end ---
Verifying that tests still pass
$ /usr/bin/npm ci
--- stderr ---
npm WARN deprecated @humanwhocodes/config-array@0.13.0: Use @eslint/config-array instead
npm WARN deprecated @humanwhocodes/object-schema@2.0.3: Use @eslint/object-schema instead
npm WARN deprecated glob@7.1.7: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me
npm WARN deprecated eslint@8.57.1: This version is no longer supported. Please see https://eslint.org/version-support for other options.
--- stdout ---
added 347 packages, and audited 348 packages in 4s
84 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
--- end ---
$ /usr/bin/npm test
--- stdout ---
> test
> grunt test
Running "eslint:all" (eslint) task
/src/repo/modules/ext.push.special.js
57:4 warning Prefer .then to .done no-jquery/no-done-fail
57:4 warning Prefer .then to .fail no-jquery/no-done-fail
84:3 warning Prefer .then to .done no-jquery/no-done-fail
93:1 warning This line has a length of 126. Maximum allowed is 100 max-len
95:1 warning This line has a length of 104. Maximum allowed is 100 max-len
130:4 warning Prefer .then to .done no-jquery/no-done-fail
/src/repo/modules/ext.push.tab.js
11:3 warning 'targetData' is never reassigned. Use 'const' instead prefer-const
12:3 warning '$pushButton' is never reassigned. Use 'const' instead prefer-const
13:3 warning '$pushAllButton' is never reassigned. Use 'const' instead prefer-const
14:3 warning '$txtTemplateList' is never reassigned. Use 'const' instead prefer-const
15:3 warning '$txtFileList' is never reassigned. Use 'const' instead prefer-const
16:3 warning '$checkIncFiles' is never reassigned. Use 'const' instead prefer-const
26:3 warning Prefer CSS transitions to .fadeOut no-jquery/no-fade
57:4 warning Prefer CSS transitions to .fadeTo no-jquery/no-fade
63:4 warning Prefer CSS transitions to .fadeTo no-jquery/no-fade
81:4 warning Prefer CSS transitions to .fadeTo no-jquery/no-fade
87:4 warning Prefer CSS transitions to .fadeTo no-jquery/no-fade
147:1 warning This line has a length of 103. Maximum allowed is 100 max-len
178:6 warning Prefer CSS transitions to .fadeIn no-jquery/no-fade
196:1 warning This line has a length of 114. Maximum allowed is 100 max-len
204:1 warning This line has a length of 115. Maximum allowed is 100 max-len
213:5 warning Prefer CSS transitions to .fadeIn no-jquery/no-fade
220:5 warning Prefer CSS transitions to .fadeOut no-jquery/no-fade
223:4 warning Prefer CSS transitions to .fadeOut no-jquery/no-fade
230:1 warning This line has a length of 115. Maximum allowed is 100 max-len
239:5 warning Prefer CSS transitions to .fadeIn no-jquery/no-fade
246:5 warning Prefer CSS transitions to .fadeOut no-jquery/no-fade
249:4 warning Prefer CSS transitions to .fadeOut no-jquery/no-fade
253:33 warning 'pages' is already declared in the upper scope on line 10 column 6 no-shadow
256:3 warning Prefer .then to .done no-jquery/no-done-fail
256:3 warning Prefer .then to .fail no-jquery/no-done-fail
283:39 warning 'pages' is already declared in the upper scope on line 10 column 6 no-shadow
295:38 warning 'pages' is already declared in the upper scope on line 10 column 6 no-shadow
296:3 warning Prefer .then to .done no-jquery/no-done-fail
296:3 warning Prefer .then to .fail no-jquery/no-done-fail
378:3 warning Prefer CSS transitions to .fadeIn no-jquery/no-fade
✖ 36 problems (0 errors, 36 warnings)
Running "banana:all" (banana) task
>> 1 message directory checked.
Done.
--- end ---
{"1119088": {"source": 1119088, "name": "brace-expansion", "dependency": "brace-expansion", "title": "brace-expansion: Large numeric range defeats documented `max` DoS protection", "url": "https://github.com/advisories/GHSA-jxxr-4gwj-5jf2", "severity": "moderate", "cwe": ["CWE-400"], "cvss": {"score": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}, "range": ">=5.0.0 <5.0.6"}}
Upgrading n:brace-expansion from 1.1.13, 2.0.3, 5.0.5 -> 1.1.13, 2.0.3, 5.0.6
$ package-lock-lint /src/repo/package-lock.json
--- stdout ---
Checking /src/repo/package-lock.json
--- end ---
build: Updating brace-expansion to 1.1.13, 2.0.3, 5.0.6
* https://github.com/advisories/GHSA-jxxr-4gwj-5jf2
$ git add .
--- stdout ---
--- end ---
$ git commit -F /tmp/tmpergcxm70
--- stdout ---
[REL1_45 a648124] build: Updating brace-expansion to 1.1.13, 2.0.3, 5.0.6
1 file changed, 6 insertions(+), 6 deletions(-)
--- end ---
$ git format-patch HEAD~1 --stdout
--- stdout ---
From a6481247e89cd240baa4d69b78442ee64e4cd830 Mon Sep 17 00:00:00 2001
From: libraryupgrader <tools.libraryupgrader@tools.wmflabs.org>
Date: Thu, 21 May 2026 18:20:28 +0000
Subject: [PATCH] build: Updating brace-expansion to 1.1.13, 2.0.3, 5.0.6
* https://github.com/advisories/GHSA-jxxr-4gwj-5jf2
Change-Id: Ief2e41b5cec6bdec80ff6e234565d126cf75c224
---
package-lock.json | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/package-lock.json b/package-lock.json
index 5479c91..9eb1a55 100644
--- a/package-lock.json
+++ b/package-lock.json
@@ -659,9 +659,9 @@
}
},
"node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion": {
- "version": "5.0.5",
- "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.5.tgz",
- "integrity": "sha512-VZznLgtwhn+Mact9tfiwx64fA9erHH/MCXEUfB/0bX/6Fz6ny5EGTXYltMocqg4xFAQZtnO3DHWWXi8RiuN7cQ==",
+ "version": "5.0.6",
+ "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
+ "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
"dev": true,
"dependencies": {
"balanced-match": "^4.0.2"
@@ -4735,9 +4735,9 @@
"dev": true
},
"brace-expansion": {
- "version": "5.0.5",
- "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.5.tgz",
- "integrity": "sha512-VZznLgtwhn+Mact9tfiwx64fA9erHH/MCXEUfB/0bX/6Fz6ny5EGTXYltMocqg4xFAQZtnO3DHWWXi8RiuN7cQ==",
+ "version": "5.0.6",
+ "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
+ "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
"dev": true,
"requires": {
"balanced-match": "^4.0.2"
--
2.47.3
--- end ---