node-etl
node-etl copied to clipboard
fix: removing moment to resolve path traversal vulnerability in moment dependency
Updates moment
to version 2.29.2
to resolve this vulnerability.
any tips on getting circleci to be able to pull from my fork?
@ZJONSSON Any way I can support in getting this merged in? We are using unzipper
and this appears to be a transitive dependency.
I don't see moment being used, can we just remove?
I don't see moment being used, can we just remove?
ooh, didn't even check that. went ahead and removed moment
in the PR.