-
Notifications
You must be signed in to change notification settings - Fork 450
Description
meteor npm install
found 14 vulnerabilities (5 moderate, 8 high, 1 critical)
run npm audit fix to fix them, or npm audit for details
meteor npm audit fix
- [email protected]
- [email protected]
- [email protected]
- [email protected]
added 25 packages from 14 contributors, removed 2 packages and updated 24 packages in 6.855s
21 packages are looking for funding
run npm fund for details
fixed 12 of 14 vulnerabilities in 260 scanned packages
2 vulnerabilities required manual review and could not be updated
meteor npm audit
=== npm audit security report ===
┌──────────────────────────────────────────────────────────────────────────────┐
│ Manual Review │
│ Some vulnerabilities require your attention to resolve │
│ │
│ Visit https://go.npm.me/audit-guide for additional guidance │
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Got allows a redirect to a UNIX socket │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ got │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=11.8.5 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ download │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ download > got │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ GHSA-pfrx-2q88-qq97 │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ http-cache-semantics vulnerable to Regular Expression Denial │
│ │ of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ http-cache-semantics │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.1.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ download │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ download > got > cacheable-request > http-cache-semantics │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ GHSA-rc47-6667-2j5j │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 2 vulnerabilities (1 moderate, 1 high) in 283 scanned packages
2 vulnerabilities require manual review. See the full report for details.
meteor npm start
[email protected] start /home/cyy/tools/semantic-segmentation-editor
meteor run --settings settings.json --exclude-archs "web.browser.legacy, web.cordova"
[[[[[ ~/tools/semantic-segmentation-editor ]]]]]
=> Started proxy.
/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/meteor-promise/promise_server.js:218
throw error;
^
SyntaxError: Unexpected end of JSON input
at JSON.parse ()
at /home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/tools/fs/tools/fs/optimistic.ts:321:17
at wrap.makeCacheKey (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/tools/fs/tools/fs/optimistic.ts:36:15)
at recomputeNewValue (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/optimism/src/entry.ts:182:31)
at Slot.withValue (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/@wry/context/lib/context.js:73:29)
at reallyRecompute (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/optimism/src/entry.ts:165:19)
at Entry.recompute (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/optimism/src/entry.ts:85:9)
at optimistic (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/optimism/src/index.ts:101:25)
at /home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/tools/fs/tools/fs/optimistic.ts:366:19
at recomputeNewValue (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/optimism/src/entry.ts:182:31)
at Slot.withValue (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/@wry/context/lib/context.js:73:29)
at reallyRecompute (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/optimism/src/entry.ts:165:19)
at Entry.recompute (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/optimism/src/entry.ts:85:9)
at optimistic (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/optimism/src/index.ts:101:25)
at find (/tools/isobuild/package-source.js:1337:30)
at /tools/isobuild/package-source.js:1393:27
at Array.forEach ()
at find (/tools/isobuild/package-source.js:1372:22)
at /tools/isobuild/package-source.js:1393:27
at Array.forEach ()
at find (/tools/isobuild/package-source.js:1372:22)
at /tools/isobuild/package-source.js:1393:27
at Array.forEach ()
at find (/tools/isobuild/package-source.js:1372:22)
at /tools/isobuild/package-source.js:1393:27
at Array.forEach ()
at find (/tools/isobuild/package-source.js:1372:22)
at find (/tools/isobuild/package-source.js:1404:25)
at /tools/isobuild/package-source.js:1416:34
at Object.withCache (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/tools/fs/tools/fs/files.ts:1659:18)
at PackageSource.findSources (/tools/isobuild/package-source.js:1416:18)
at SourceArch.getFiles (/tools/isobuild/package-source.js:960:32)
at /tools/isobuild/compiler.js:406:23
at /tools/isobuild/compiler.js:186:28
at Object.withCache (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/tools/fs/tools/fs/files.ts:1659:18)
at /tools/isobuild/compiler.js:185:11
at Function..each._.forEach (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/underscore/underscore.js:186:9)
at Object.compile (/tools/isobuild/compiler.js:180:5)
at /tools/isobuild/bundler.js:3222:24
at Object.capture (/tools/utils/buildmessage.js:283:5)
at bundle (/tools/isobuild/bundler.js:3169:31)
at /tools/isobuild/bundler.js:3113:32
at Slot.withValue (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/dev_bundle/lib/node_modules/@wry/context/lib/context.js:73:29)
at Object.withCache (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/tools/fs/tools/fs/files.ts:1659:39)
at Object.bundle (/tools/isobuild/bundler.js:3113:16)
at /tools/runners/run-app.js:572:24
at Function.run (/home/cyy/.meteor/packages/meteor-tool/.1.12.0.rmh4j4.m6y4n++os.linux.x86_64+web.browser+web.browser.legacy+web.cordova/mt-os.linux.x86_64/tools/tool-env/tools/tool-env/profile.ts:289:14)
at bundleApp (/tools/runners/run-app.js:571:34)
at AppRunner._runOnce (/tools/runners/run-app.js:617:35)
at AppRunner._fiber (/tools/runners/run-app.js:931:28)
at /tools/runners/run-app.js:401:12
npm ERR! code ELIFECYCLE
npm ERR! errno 1
npm ERR! [email protected] start: meteor run --settings settings.json --exclude-archs "web.browser.legacy, web.cordova"
npm ERR! Exit status 1
npm ERR!
npm ERR! Failed at the [email protected] start script.
npm ERR! This is probably not a problem with npm. There is likely additional logging output above.
npm ERR! A complete log of this run can be found in:
npm ERR! /home/cyy/.npm/_logs/2023-05-31T07_46_36_604Z-debug.log
/home/cyy/.npm/_logs/2023-05-31T07_46_36_604Z-debug.log