Update dependency moment to v2.19.3 [SECURITY] #78
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.17.1
->2.19.3
GitHub Vulnerability Alerts
CVE-2017-18214
Affected versions of
moment
are vulnerable to a low severity regular expression denial of service when parsing dates as strings.Recommendation
Update to version 2.19.3 or later.
Release Notes
moment/moment
v2.19.3
Compare Source
Release Nov 29, 2017
#4326 [bugfix] Fix for ReDOS vulnerability (see #4163)
#4289 [misc] Fix spelling and formatting for U.S. for es-us
v2.19.2
Compare Source
Release Nov 11, 2017
#4255 [bugfix] Fix year setter for random days in a leap year, fixes #4238
#4242 [bugfix] updateLocale now tries to load parent, fixes #3626
v2.19.1
Compare Source
Make react native and webpack both work
v2.19.0
Compare Source
v2.18.1
Compare Source
Release Mar 22, 2017
#3853 [misc] Fix invalid whitespace character causing inability to parse
moment.js
v2.18.0
Compare Source
Renovate configuration
📅 Schedule: "" (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.