Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency moment to v2.19.3 [SECURITY] #78

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

kindlymachine[bot]
Copy link
Contributor

@kindlymachine kindlymachine bot commented Jan 16, 2021

This PR contains the following updates:

Package Type Update Change
moment (source) dependencies minor 2.17.1 -> 2.19.3

GitHub Vulnerability Alerts

CVE-2017-18214

Affected versions of moment are vulnerable to a low severity regular expression denial of service when parsing dates as strings.

Recommendation

Update to version 2.19.3 or later.


Release Notes

moment/moment

v2.19.3

Compare Source

  • Release Nov 29, 2017

  • #​4326 [bugfix] Fix for ReDOS vulnerability (see #​4163)

  • #​4289 [misc] Fix spelling and formatting for U.S. for es-us

v2.19.2

Compare Source

  • Release Nov 11, 2017

  • #​4255 [bugfix] Fix year setter for random days in a leap year, fixes #​4238

  • #​4242 [bugfix] updateLocale now tries to load parent, fixes #​3626

v2.19.1

Compare Source

  • Release Oct 11, 2017

Make react native and webpack both work

v2.19.0

Compare Source

  • Release Oct 10, 2017

v2.18.1

Compare Source

  • Release Mar 22, 2017

  • #​3853 [misc] Fix invalid whitespace character causing inability to parse
    moment.js

v2.18.0

Compare Source

  • Release Mar 18, 2017

Renovate configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@kindlymachine kindlymachine bot requested a review from statik as a code owner January 16, 2021 07:12
@kindlymachine kindlymachine bot added dependencies Pull requests that update a dependency file javascript labels Jan 16, 2021
Base automatically changed from master to main February 3, 2021 02:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants