vuejs-datatable
vuejs-datatable copied to clipboard
chore: 🤖 Renovate auto-bump Update dependency moment to v2.29.2 [SECURITY]
This PR contains the following updates:
Package | Change | Age | Adoption | Passing | Confidence |
---|---|---|---|---|---|
moment (source) | 2.24.0 -> 2.29.2 |
GitHub Vulnerability Alerts
CVE-2022-24785
Impact
This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg fr
is directly used to switch moment locale.
Patches
This problem is patched in 2.29.2, and the patch can be applied to all affected versions (from 1.0.1 up until 2.29.1, inclusive).
Workarounds
Sanitize user-provided locale name before passing it to moment.js.
References
Are there any links users can visit to find out more?
For more information
If you have any questions or comments about this advisory:
- Open an issue in moment repo
Release Notes
moment/moment (moment)
v2.29.2
- Release Apr 3 2022
Address https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4
v2.29.1
- Release Oct 6, 2020
Updated deprecation message, bugfix in hi locale
v2.29.0
- Release Sept 22, 2020
New locales (es-mx, bn-bd). Minor bugfixes and locale improvements. More tests. Moment is in maintenance mode. Read more at this link: https://momentjs.com/docs/#/-project-status/
v2.28.0
- Release Sept 13, 2020
Fix bug where .format() modifies original instance, and locale updates
v2.27.0
- Release June 18, 2020
Added Turkmen locale, other locale improvements, slight TypeScript fixes
v2.26.0
- Release May 19, 2020
TypeScript fixes and many locale improvements
v2.25.3
- Release May 4, 2020
Remove package.json module property. It looks like webpack behaves differently for modules loaded via module vs jsnext:main.
v2.25.2
- Release May 4, 2020
This release includes ES Module bundled moment, separate from it's source code under dist/ folder. This might alleviate issues with finding the `./locale subfolder for loading locales. This might also mean now webpack will bundle all locales automatically, unless told otherwise.
v2.25.1
- Release May 1, 2020
This is a quick patch release to address some of the issues raised after releasing 2.25.0.
- 2e268635 [misc] Revert #​5269 due to webpack warning
- 226799e1 [locale] fil: Fix metadata comment
- a83a521 [bugfix] Fix typeoff usages
- e324334 [pkg] Add ts3.1-typings in npm package
- 28cc23e [misc] Remove deleted generated locale en-SG
v2.25.0
-
Release May 1, 2020
-
#​4611 022dc038 [feature] Support for strict string parsing, fixes #​2469
-
#​4599 4b615b9d [feature] Add support for eras in en and jp
-
#​4296 757d4ff8 [feature] Accept custom relative thresholds in duration.humanize
-
18 bigfixes
-
36 locale fixes
-
5 new locales (oc-lnc, zh-mo, en-in, gom-deva, fil)
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
â™» Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.