Running with gitlab-runner 13.5.0 (ece86343)  on System Shared Runner J9EsdQ92 section_start:1642233817:resolve_secrets Resolving secrets section_end:1642233817:resolve_secrets section_start:1642233817:prepare_executor Preparing the "docker" executor Using Docker executor with image registry.gitlab.com/gitlab-org/security-products/analyzers/gemnasium-python:2 ... Pulling docker image gitlab/gitlab-runner-helper:x86_64-6fbc7474 ... Using docker image sha256:4ab73fe41bd466dff16a0e732b568862dce676f1d49de2a85309349266c882f8 for gitlab/gitlab-runner-helper:x86_64-6fbc7474 with digest gitlab/gitlab-runner-helper@sha256:6275194f2d67051ee4538cbd086c4c61b35e15d4439f76b5b5b710bee7344895 ... Pulling docker image registry.gitlab.com/gitlab-org/security-products/analyzers/gemnasium-python:2 ... Using docker image sha256:d39986ae4d705990609012e8138400acb83473cf2ea649d6729fbdd2327daaa5 for registry.gitlab.com/gitlab-org/security-products/analyzers/gemnasium-python:2 with digest registry.gitlab.com/gitlab-org/security-products/analyzers/gemnasium-python@sha256:090361ad6025f9aea0a8d532a6505cf6c4fc243bf0993e95b65abf1a8af860a4 ... section_end:1642233823:prepare_executor section_start:1642233823:prepare_script Preparing environment Running on osm-gitlab via 7dbf9d05aeed... section_end:1642233824:prepare_script section_start:1642233824:get_sources Getting source from Git repository Fetching changes with git depth set to 50... Reinitialized existing Git repository in /builds/gitlab/osm/pol/.git/ Checking out cb1df501 as master... Removing dist/ Removing gl-dependency-scanning-report.json Removing pipdeptree.json Skipping Git submodules setup section_end:1642233829:get_sources section_start:1642233829:step_script Executing "step_script" stage of the job script $ /analyzer run [INFO] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ GitLab gemnasium-python analyzer v2.19.3 [DEBU] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ inspect directory: . [DEBU] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ skip ignored directory: .git [DEBU] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ electing pip for pypi because this is the first match [DEBU] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ rejecting setup.py as handled by setuptools [DEBU] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ electing pip for pypi because this is the first match [DEBU] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ rejecting setup.py as handled by setuptools [INFO] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ Detected supported dependency files in '.'. Dependency files detected in this directory will be processed. Dependency files in other directories will be skipped. [DEBU] [gemnasium-python] [2022-01-15T08:03:50Z] ▶ Exporting dependencies for /builds/gitlab/osm/pol/requirements.txt [DEBU] [gemnasium-python] [2022-01-15T08:03:57Z] ▶ /usr/local/bin/pip download --disable-pip-version-check --dest ./dist -r requirements.txt Collecting aiokafka==0.7.0 Downloading aiokafka-0.7.0-cp36-cp36m-manylinux2010_x86_64.whl (1.1 MB) Collecting cached-property==1.5.2 Downloading cached_property-1.5.2-py2.py3-none-any.whl (7.6 kB) Collecting certifi==2020.12.5 Downloading certifi-2020.12.5-py2.py3-none-any.whl (147 kB) Collecting chardet==4.0.0 Downloading chardet-4.0.0-py2.py3-none-any.whl (178 kB) Collecting click==7.1.2 Downloading click-7.1.2-py2.py3-none-any.whl (82 kB) Collecting idna==2.10 Downloading idna-2.10-py2.py3-none-any.whl (58 kB) Collecting jsonschema==2.6.0 Downloading jsonschema-2.6.0-py2.py3-none-any.whl (39 kB) Collecting kafka-python==2.0.2 Downloading kafka_python-2.0.2-py2.py3-none-any.whl (246 kB) Collecting mock==4.0.3 Downloading mock-4.0.3-py3-none-any.whl (28 kB) Collecting peewee-migrate==1.1.6 Downloading peewee_migrate-1.1.6-py2.py3-none-any.whl (16 kB) Collecting peewee==3.8.2 Downloading peewee-3.8.2.tar.gz (816 kB) Collecting pymysql==0.9.3 Downloading PyMySQL-0.9.3-py2.py3-none-any.whl (47 kB) Collecting pyyaml==5.4.1 Downloading PyYAML-5.4.1-cp36-cp36m-manylinux1_x86_64.whl (640 kB) Collecting requests==2.25.1 Downloading requests-2.25.1-py2.py3-none-any.whl (61 kB) Collecting urllib3==1.26.4 Downloading urllib3-1.26.4-py2.py3-none-any.whl (153 kB) Saved ./dist/aiokafka-0.7.0-cp36-cp36m-manylinux2010_x86_64.whl Saved ./dist/cached_property-1.5.2-py2.py3-none-any.whl Saved ./dist/certifi-2020.12.5-py2.py3-none-any.whl Saved ./dist/chardet-4.0.0-py2.py3-none-any.whl Saved ./dist/click-7.1.2-py2.py3-none-any.whl Saved ./dist/idna-2.10-py2.py3-none-any.whl Saved ./dist/jsonschema-2.6.0-py2.py3-none-any.whl Saved ./dist/kafka_python-2.0.2-py2.py3-none-any.whl Saved ./dist/mock-4.0.3-py3-none-any.whl Saved ./dist/peewee_migrate-1.1.6-py2.py3-none-any.whl Saved ./dist/peewee-3.8.2.tar.gz Saved ./dist/PyMySQL-0.9.3-py2.py3-none-any.whl Saved ./dist/PyYAML-5.4.1-cp36-cp36m-manylinux1_x86_64.whl Saved ./dist/requests-2.25.1-py2.py3-none-any.whl Saved ./dist/urllib3-1.26.4-py2.py3-none-any.whl Successfully downloaded aiokafka cached-property certifi chardet click idna jsonschema kafka-python mock peewee-migrate peewee pymysql pyyaml requests urllib3 [DEBU] [gemnasium-python] [2022-01-15T08:04:06Z] ▶ /usr/local/bin/pip install --disable-pip-version-check --find-links ./dist --requirement requirements.txt Looking in links: ./dist Collecting aiokafka==0.7.0 Using cached aiokafka-0.7.0-cp36-cp36m-manylinux2010_x86_64.whl (1.1 MB) Collecting cached-property==1.5.2 Using cached cached_property-1.5.2-py2.py3-none-any.whl (7.6 kB) Collecting certifi==2020.12.5 Using cached certifi-2020.12.5-py2.py3-none-any.whl (147 kB) Collecting chardet==4.0.0 Using cached chardet-4.0.0-py2.py3-none-any.whl (178 kB) Collecting click==7.1.2 Using cached click-7.1.2-py2.py3-none-any.whl (82 kB) Collecting idna==2.10 Using cached idna-2.10-py2.py3-none-any.whl (58 kB) Collecting jsonschema==2.6.0 Using cached jsonschema-2.6.0-py2.py3-none-any.whl (39 kB) Collecting kafka-python==2.0.2 Using cached kafka_python-2.0.2-py2.py3-none-any.whl (246 kB) Collecting mock==4.0.3 Using cached mock-4.0.3-py3-none-any.whl (28 kB) Collecting peewee-migrate==1.1.6 Using cached peewee_migrate-1.1.6-py2.py3-none-any.whl (16 kB) Collecting peewee==3.8.2 Using cached peewee-3.8.2.tar.gz (816 kB) Collecting pymysql==0.9.3 Using cached PyMySQL-0.9.3-py2.py3-none-any.whl (47 kB) Collecting pyyaml==5.4.1 Using cached PyYAML-5.4.1-cp36-cp36m-manylinux1_x86_64.whl (640 kB) Collecting requests==2.25.1 Using cached requests-2.25.1-py2.py3-none-any.whl (61 kB) Collecting urllib3==1.26.4 Using cached urllib3-1.26.4-py2.py3-none-any.whl (153 kB) Building wheels for collected packages: peewee Building wheel for peewee (setup.py): started Building wheel for peewee (setup.py): finished with status 'done' Created wheel for peewee: filename=peewee-3.8.2-cp36-cp36m-linux_x86_64.whl size=121076 sha256=b31e91918505ca112a458dabab62849fdcbd0913403021a3fcbf522952ba17bf Stored in directory: /tmp/.cache/pip/wheels/ba/45/94/eb40c33ff09cabd09e193fb650cbed94a83f47fc4345b0fea9 Successfully built peewee Installing collected packages: urllib3, peewee, mock, kafka-python, idna, click, chardet, certifi, cached-property, requests, pyyaml, pymysql, peewee-migrate, jsonschema, aiokafka Attempting uninstall: certifi Found existing installation: certifi 2019.11.28 Uninstalling certifi-2019.11.28: Successfully uninstalled certifi-2019.11.28 Attempting uninstall: jsonschema Found existing installation: jsonschema 3.1.1 Uninstalling jsonschema-3.1.1: Successfully uninstalled jsonschema-3.1.1 Successfully installed aiokafka-0.7.0 cached-property-1.5.2 certifi-2020.12.5 chardet-4.0.0 click-7.1.2 idna-2.10 jsonschema-2.6.0 kafka-python-2.0.2 mock-4.0.3 peewee-3.8.2 peewee-migrate-1.1.6 pymysql-0.9.3 pyyaml-5.4.1 requests-2.25.1 urllib3-1.26.4 WARNING: Running pip as the 'root' user can result in broken permissions and conflicting behaviour with the system package manager. It is recommended to use a virtual environment instead: https://pip.pypa.io/warnings/venv [DEBU] [gemnasium-python] [2022-01-15T08:04:07Z] ▶ /usr/bin/git -C /gemnasium-db remote set-url origin https://gitlab.com/gitlab-org/security-products/gemnasium-db.git [DEBU] [gemnasium-python] [2022-01-15T08:04:09Z] ▶ /usr/bin/git -C /gemnasium-db fetch --force --tags origin master From https://gitlab.com/gitlab-org/security-products/gemnasium-db * branch master -> FETCH_HEAD * [new tag] v2.0.416 -> v2.0.416 * [new tag] v2.0.417 -> v2.0.417 * [new tag] v2.0.418 -> v2.0.418 * [new tag] v2.0.419 -> v2.0.419 * [new tag] v2.0.420 -> v2.0.420 * [new tag] v2.0.421 -> v2.0.421 * [new tag] v2.0.422 -> v2.0.422 * [new tag] v2.0.423 -> v2.0.423 * [new tag] v2.0.424 -> v2.0.424 * [new tag] v2.0.425 -> v2.0.425 * [new tag] v2.0.426 -> v2.0.426 * [new tag] v2.0.427 -> v2.0.427 * [new tag] v2.0.428 -> v2.0.428 * [new tag] v2.0.429 -> v2.0.429 * [new tag] v2.0.430 -> v2.0.430 * [new tag] v2.0.431 -> v2.0.431 * [new tag] v2.0.432 -> v2.0.432 * [new tag] v2.0.433 -> v2.0.433 * [new tag] v2.0.434 -> v2.0.434 * [new tag] v2.0.435 -> v2.0.435 * [new tag] v2.0.436 -> v2.0.436 * [new tag] v2.0.437 -> v2.0.437 * [new tag] v2.0.438 -> v2.0.438 t [tag update] version_latest -> version_latest 7ee6db442..ee33e8a9c master -> origin/master [DEBU] [gemnasium-python] [2022-01-15T08:04:10Z] ▶ /usr/bin/git -C /gemnasium-db checkout master Already on 'master' Your branch is behind 'origin/master' by 165 commits, and can be fast-forwarded. (use "git pull" to update your local branch) [DEBU] [gemnasium-python] [2022-01-15T08:04:10Z] ▶ /usr/bin/git -C /gemnasium-db symbolic-ref -q HEAD [DEBU] [gemnasium-python] [2022-01-15T08:04:10Z] ▶ /usr/bin/git -C /gemnasium-db reset --hard origin/master HEAD is now at ee33e8a9c Merge branch 'invalidate-npm-advisory' into 'master' [DEBU] [gemnasium-python] [2022-01-15T08:04:10Z] ▶ /usr/bin/git -C /gemnasium-db rev-parse HEAD ee33e8a9cceee31c7de0390c630be006445750c4 [INFO] [gemnasium-python] [2022-01-15T08:04:10Z] ▶ Using commit ee33e8a9cceee31c7de0390c630be006445750c4 of vulnerability database section_end:1642233850:step_script section_start:1642233850:upload_artifacts_on_success Uploading artifacts for successful job Uploading artifacts... gl-dependency-scanning-report.json: found 1 matching files and directories Uploading artifacts as "dependency_scanning" to coordinator... ok id=22013 responseStatus=201 Created token=auB3csiM section_end:1642233852:upload_artifacts_on_success section_start:1642233852:cleanup_file_variables Cleaning up file based variables section_end:1642233853:cleanup_file_variables Job succeeded