DEV-REPO-URIEL / AsafFindingBugs

0 stars 0 forks source link

Update dependency moment to v2.29.4 #11

Open dev-mend-for-github-com[bot] opened 1 year ago

dev-mend-for-github-com[bot] commented 1 year ago

This PR contains the following updates:

Package Type Update Change
moment (source) dependencies minor 2.19.3 -> 2.29.4

By merging this PR, the issue #7 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 7.5 CVE-2022-24785
High High 7.5 CVE-2022-31129

Release Notes

moment/moment (moment) ### [`v2.29.4`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2294) [Compare Source](https://togithub.com/moment/moment/compare/2.29.3...2.29.4) - Release Jul 6, 2022 - [#​6015](https://togithub.com/moment/moment/pull/6015) \[bugfix] Fix ReDoS in preprocessRFC2822 regex ### [`v2.29.3`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2293-Full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.29.2...2.29.3) - Release Apr 17, 2022 - [#​5995](https://togithub.com/moment/moment/pull/5995) \[bugfix] Remove const usage - [#​5990](https://togithub.com/moment/moment/pull/5990) misc: fix advisory link ### [`v2.29.2`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2292-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.29.1...2.29.2) - Release Apr 3 2022 Address https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4 ### [`v2.29.1`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2291-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.29.0...2.29.1) - Release Oct 6, 2020 Updated deprecation message, bugfix in hi locale ### [`v2.29.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2290-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.28.0...2.29.0) - Release Sept 22, 2020 New locales (es-mx, bn-bd). Minor bugfixes and locale improvements. More tests. Moment is in maintenance mode. Read more at this link: https://momentjs.com/docs/#/-project-status/ ### [`v2.28.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2280-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.27.0...2.28.0) - Release Sept 13, 2020 Fix bug where .format() modifies original instance, and locale updates ### [`v2.27.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2270-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.26.0...2.27.0) - Release June 18, 2020 Added Turkmen locale, other locale improvements, slight TypeScript fixes ### [`v2.26.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2260-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.25.3...2.26.0) - Release May 19, 2020 TypeScript fixes and many locale improvements ### [`v2.25.3`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2253) [Compare Source](https://togithub.com/moment/moment/compare/2.25.2...2.25.3) - Release May 4, 2020 Remove package.json module property. It looks like webpack behaves differently for modules loaded via module vs jsnext:main. ### [`v2.25.2`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2252) [Compare Source](https://togithub.com/moment/moment/compare/2.25.1...2.25.2) - Release May 4, 2020 This release includes ES Module bundled moment, separate from it's source code under dist/ folder. This might alleviate issues with finding the \`./locale subfolder for loading locales. This might also mean now webpack will bundle all locales automatically, unless told otherwise. ### [`v2.25.1`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2251) [Compare Source](https://togithub.com/moment/moment/compare/2.25.0...2.25.1) - Release May 1, 2020 This is a quick patch release to address some of the issues raised after releasing 2.25.0. - [2e268635](https://togithub.com/moment/moment/commit/2e268635) \[misc] Revert [#​5269](https://togithub.com/moment/moment/issues/5269) due to webpack warning - [226799e1](https://togithub.com/moment/moment/commit/226799e1) \[locale] fil: Fix metadata comment - [a83a521](https://togithub.com/moment/moment/commit/a83a521) \[bugfix] Fix typeoff usages - [e324334](https://togithub.com/moment/moment/commit/e324334) \[pkg] Add ts3.1-typings in npm package - [28cc23e](https://togithub.com/moment/moment/commit/28cc23e) \[misc] Remove deleted generated locale en-SG ### [`v2.25.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2250-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.24.0...2.25.0) - Release May 1, 2020 - [#​4611](https://togithub.com/moment/moment/issues/4611) [022dc038](https://togithub.com/moment/moment/commit/022dc038) \[feature] Support for strict string parsing, fixes [#​2469](https://togithub.com/moment/moment/issues/2469) - [#​4599](https://togithub.com/moment/moment/issues/4599) [4b615b9d](https://togithub.com/moment/moment/commit/4b615b9d) \[feature] Add support for eras in en and jp - [#​4296](https://togithub.com/moment/moment/issues/4296) [757d4ff8](https://togithub.com/moment/moment/commit/757d4ff8) \[feature] Accept custom relative thresholds in duration.humanize - 18 bigfixes - 36 locale fixes - 5 new locales (oc-lnc, zh-mo, en-in, gom-deva, fil) ### [`v2.24.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2240-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.23.0...2.24.0) - Release Jan 21, 2019 - [#​4338](https://togithub.com/moment/moment/pull/4338) \[bugfix] Fix startOf/endOf DST issues while boosting performance - [#​4553](https://togithub.com/moment/moment/pull/4553) \[feature] Add localeSort param to Locale weekday methods - [#​4887](https://togithub.com/moment/moment/pull/4887) \[bugfix] Make Duration#as work with quarters - 3 new locales (it-ch, ga, en-SG) - Lots of locale improvements ### [`v2.23.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2230-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.22.2...2.23.0) - Release Dec 12, 2018 - [#​4863](https://togithub.com/moment/moment/pull/4863) \[new locale] added Kurdish language (ku) - [#​4417](https://togithub.com/moment/moment/pull/4417) \[bugfix] isBetween should return false for invalid dates - [#​4700](https://togithub.com/moment/moment/pull/4700) \[bugfix] Fix [#​4698](https://togithub.com/moment/moment/pull/4698): Use ISO WeekYear for HTML5\_FMT.WEEK - [#​4563](https://togithub.com/moment/moment/pull/4563) \[feature] Fix [#​4518](https://togithub.com/moment/moment/pull/4518): Add support to add/subtract ISO weeks - other locale changes, build process changes, typos ### [`v2.22.2`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2222-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.22.1...2.22.2) - Release May 31, 2018 - [#​4564](https://togithub.com/moment/moment/pull/4564) \[bugfix] Avoid using trim() - [#​4453](https://togithub.com/moment/moment/pull/4453) \[bugfix] Treat periods as periods, not regex-anything period, for weekday parsing in strict mode. - Minor locale improvements (pa-in, be, az) ### [`v2.22.1`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2221-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.22.0...2.22.1) - Release Apr 14, 2018 - [#​4495](https://togithub.com/moment/moment/pull/4495) \[bugfix] Added HTML5\_FMT to moment.d.ts - Minor locale improvements - QUnit upgrade and coveralls reporting ### [`v2.22.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2220-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.21.0...2.22.0) - Release Mar 30, 2018 - [#​4423](https://togithub.com/moment/moment/pull/4423) \[new locale] Added Mongolian locale mn - Various locale improvements - Minor misc changes ### [`v2.21.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2210-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.20.1...2.21.0) - Release Mar 2, 2018 - [#​4391](https://togithub.com/moment/moment/pull/4391) \[bugfix] Fix [#​4390](https://togithub.com/moment/moment/pull/4390): use offset properly in toISOString - [#​4310](https://togithub.com/moment/moment/pull/4310) \[bugfix] Fix [#​3883](https://togithub.com/moment/moment/pull/3883) lazy load parentLocale in defineLocale, fallback to global if missing - [#​4085](https://togithub.com/moment/moment/pull/4085) \[misc] Print console warning when setting non-existent locales - [#​4371](https://togithub.com/moment/moment/pull/4371) \[misc] fix deprecated rollup options - New locales: ug-cn, en-il, tg - Various locale improvements ### [`v2.20.1`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2201-See-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.20.0...2.20.1) - Release Dec 18, 2017 - [#​4359](https://togithub.com/moment/moment/pull/4359) \[locale] Fix Arabic locale for months (again) - [#​4357](https://togithub.com/moment/moment/pull/4357) \[misc] Add optional parameter keepOffset to toISOString ### [`v2.20.0`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2200-See-full-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.19.4...2.20.0) - Release Dec 16, 2017 - [#​4312](https://togithub.com/moment/moment/pull/4312) \[bugfix] Fix [#​4251](https://togithub.com/moment/moment/pull/4251): Avoid RFC2822 in utc() test - [#​4240](https://togithub.com/moment/moment/pull/4240) \[bugfix] Fix incorrect strict parsing with full-width parentheses - [#​4341](https://togithub.com/moment/moment/pull/4341) \[feature] Prevent toISOString converting to UTC (issue [#​1751](https://togithub.com/moment/moment/pull/1751)) - [#​4154](https://togithub.com/moment/moment/pull/4154) \[feature] add format constants to support output to HTML5 input type formats (see [#​3928](https://togithub.com/moment/moment/pull/3928)) - [#​4143](https://togithub.com/moment/moment/pull/4143) \[new locale] mt: Maltese language - [#​4183](https://togithub.com/moment/moment/pull/4183) \[locale] Relative seconds i18n - Various other locale improvements ### [`v2.19.4`](https://togithub.com/moment/moment/blob/HEAD/CHANGELOG.md#2194-See-changelog) [Compare Source](https://togithub.com/moment/moment/compare/2.19.3...2.19.4) - Release Dec 10, 2017 - [#​4332](https://togithub.com/moment/moment/pull/4332) \[bugfix] Fix weekday verification for UTC and offset days (fixes [#​4227](https://togithub.com/moment/moment/pull/4227)) - [#​4336](https://togithub.com/moment/moment/pull/4336) \[bugfix] Fix [#​4334](https://togithub.com/moment/moment/pull/4334): Remove unused function call argument - [#​4246](https://togithub.com/moment/moment/pull/4246) \[misc] Add 'ss' relative time key to typescript definition

dev-mend-for-github-com[bot] commented 1 year ago

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

The artifact failure details are included below:

File name: package-lock.json
dev-mend-for-github-com[bot] commented 2 weeks ago

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

The artifact failure details are included below:

File name: package-lock.json