Skip to content

CLI dependency issues #5217

@traumschule

Description

@traumschule

joystream/cli$ npm i

npm warn deprecated @substrate/connect@0.7.21: versions below 1.x are no longer maintained

added 54 packages, removed 2 packages, changed 16 packages, and audited 3951 packages in 56s

294 packages are looking for funding
  run `npm fund` for details

72 vulnerabilities (8 low, 13 moderate, 32 high, 19 critical)

npm warn deprecated rimraf@3.0.2: Rimraf versions prior to v4 are no longer supported                                                                                                                              
npm warn deprecated rimraf@3.0.2: Rimraf versions prior to v4 are no longer supported                    
npm warn deprecated mkdirp@0.5.1: Legacy versions of mkdirp are no longer supported. Please update to mkdirp 1.x. (Note that the API surface has changed to use Promises in 1.x.)                                  

# npm audit report                                 
                                                                                                         
@babel/traverse  <7.23.2                                                                                                                                                                                           
Severity: critical                                                                                                                                                                                                 
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code - https://github.com/advisories/GHSA-67hx-6x53-jw92                                                                
fix available via `npm audit fix`                                                                        

axios  <=0.30.1
Severity: high
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx

form-data  4.0.0 - 4.0.3
Severity: critical
form-data uses unsafe random function in form-data for choosing boundary - https://github.com/advisories/GHSA-fjxv-7rqg-78g4
fix available via `npm audit fix`

got  <11.8.5
Severity: moderate
Got allows a redirect to a UNIX socket - https://github.com/advisories/GHSA-pfrx-2q88-qq97
fix available via `npm audit fix`

47 vulnerabilities (6 low, 8 moderate, 22 high, 11 critical)

npm install -g @joystream/cli

npm WARN deprecated inflight@1.0.6: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
npm WARN deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported
npm WARN deprecated multibase@1.0.1: This module has been superseded by the multiformats module
npm WARN deprecated multibase@1.0.1: This module has been superseded by the multiformats module
npm WARN deprecated multibase@1.0.1: This module has been superseded by the multiformats module
npm WARN deprecated multibase@1.0.1: This module has been superseded by the multiformats module
npm WARN deprecated npmlog@4.1.2: This package is no longer supported.
npm WARN deprecated are-we-there-yet@1.1.7: This package is no longer supported.
npm WARN deprecated multiaddr@7.5.0: This module is deprecated, please upgrade to @multiformats/multiaddr
npm WARN deprecated multicodec@1.0.4: This module has been superseded by the multiformats module
npm WARN deprecated multicodec@1.0.4: This module has been superseded by the multiformats module
npm WARN deprecated multiaddr@7.5.0: This module is deprecated, please upgrade to @multiformats/multiaddr
npm WARN deprecated stable@0.1.8: Modern JS already guarantees Array#sort() is a stable sort, so this library is deprecated. See the compatibility table on MDN: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Array/sort#browser_compatibili
ty
npm WARN deprecated deferred-leveldown@5.3.0: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated level-concat-iterator@2.0.1: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated level-errors@2.0.1: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated gauge@2.7.4: This package is no longer supported.
npm WARN deprecated node-domexception@1.0.0: Use your platform's native DOMException instead
npm WARN deprecated encoding-down@6.3.0: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated level-codec@9.0.2: Superseded by level-transcoder (https://github.com/Level/community#faq)
npm WARN deprecated levelup@4.4.0: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.6.1: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated left-pad@1.3.0: use String.prototype.padStart()
npm WARN deprecated multiaddr-to-uri@6.0.0: This module is deprecated, please upgrade to @multiformats/multiaddr-to-uri
npm WARN deprecated ipld-raw@2.0.1: This module has been superseded by the multiformats module
npm WARN deprecated uuid@3.4.0: Please upgrade to version 7 or higher. Older versions may use Math.random() in certain circumstances, which is known to be problematic. See https://v8.dev/blog/math-random for details.
npm WARN deprecated ipld-raw@6.0.0: This module has been superseded by the multiformats module
npm WARN deprecated multicodec@1.0.4: This module has been superseded by the multiformats module
npm WARN deprecated multicodec@1.0.4: This module has been superseded by the multiformats module
npm WARN deprecated @oclif/screen@1.0.4: Deprecated in favor of @oclif/core
npm WARN deprecated @oclif/color@0.1.2: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated cids@1.1.9: This module has been superseded by the multiformats module
npm WARN deprecated multiaddr@8.1.2: This module is deprecated, please upgrade to @multiformats/multiaddr
npm WARN deprecated abstract-leveldown@2.4.1: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated ipfs-block-service@0.15.2: This module has been merged into ipfs
npm WARN deprecated multibase@3.1.2: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.6.1: This module has been superseded by the multiformats module
npm WARN deprecated ipld-dag-cbor@0.17.1: This module has been superseded by @ipld/dag-cbor and multiformats
npm WARN deprecated rabin@1.6.0: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated multibase@0.6.1: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated ipfs-core-utils@0.4.0: js-IPFS has been deprecated in favour of Helia - please see ipfs/js-ipfs#4336 for details
npm WARN deprecated multibase@4.0.6: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated abstract-leveldown@6.2.3: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated abstract-leveldown@6.3.0: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated multibase@0.6.1: This module has been superseded by the multiformats module
npm WARN deprecated @oclif/help@1.0.15: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.6.1: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated ipld-dag-pb@0.20.0: This module has been superseded by @ipld/dag-pb and multiformats
npm WARN deprecated abstract-leveldown@6.2.3: Superseded by abstract-level (https://github.com/Level/community#faq)
npm WARN deprecated @oclif/errors@1.3.6: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated multicodec@0.5.7: This module has been superseded by the multiformats module
npm WARN deprecated protons@1.2.1: This module is no longer maintained
npm WARN deprecated multicodec@0.5.7: This module has been superseded by the multiformats module
npm WARN deprecated multiaddr@6.1.1: This module is deprecated, please upgrade to @multiformats/multiaddr
npm WARN deprecated @oclif/parser@3.8.17: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated @oclif/config@1.18.16: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated @types/vfile@4.0.0: This is a stub types definition. vfile provides its own type definitions, so you do not need this installed.
npm WARN deprecated multicodec@3.2.1: This module has been superseded by the multiformats module
npm WARN deprecated multicodec@3.2.1: This module has been superseded by the multiformats module
npm WARN deprecated multicodec@2.1.3: This module has been superseded by the multiformats module
npm WARN deprecated multibase@4.0.6: This module has been superseded by the multiformats module
npm WARN deprecated cids@0.5.8: This module has been superseded by the multiformats module
npm WARN deprecated cids@0.5.8: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.7.0: This module has been superseded by the multiformats module
npm WARN deprecated multibase@0.6.1: This module has been superseded by the multiformats module
npm WARN deprecated multicodec@0.5.7: This module has been superseded by the multiformats module
npm WARN deprecated @oclif/errors@1.3.5: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated @oclif/command@1.8.36: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated cli-ux@5.6.7: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated @oclif/config@1.18.2: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated multihashing-async@0.5.2: This module has been superseded by the multiformats module
npm WARN deprecated cids@0.5.8: This module has been superseded by the multiformats module
npm WARN deprecated @oclif/config@1.18.17: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated cli-ux@5.6.6: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated ipld-dag-cbor@0.13.1: This module has been superseded by @ipld/dag-cbor and multiformats
npm WARN deprecated datastore-fs@0.8.1: This package is deprecated. Instead, use datastore-level in Node.js, and datastore-idb in browsers
npm WARN deprecated ipld-dag-pb@0.15.3: This module has been superseded by @ipld/dag-pb and multiformats
npm WARN deprecated @oclif/command@1.8.11: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
npm WARN deprecated ipld-dag-pb@0.15.3: This module has been superseded by @ipld/dag-pb and multiformats
npm WARN deprecated cids@0.8.3: This module has been superseded by the multiformats module
npm WARN deprecated cids@0.8.3: This module has been superseded by the multiformats module
npm WARN deprecated cids@0.7.5: This module has been superseded by the multiformats module
npm WARN deprecated cids@0.7.5: This module has been superseded by the multiformats module
npm WARN deprecated cids@0.7.5: This module has been superseded by the multiformats module
npm WARN deprecated ipfs-http-client@47.0.1: js-IPFS has been deprecated in favour of Helia - please see ipfs/js-ipfs#4336 for details
npm WARN deprecated ipld@0.20.2: Please use the multiformats module instead
npm WARN deprecated @substrate/connect@0.7.26: versions below 1.x are no longer maintained
npm WARN deprecated leveldown@5.6.0: Superseded by classic-level (https://github.com/Level/community#faq)
npm WARN deprecated fluent-ffmpeg@2.1.3: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions