me-ventures / microservice-toolkit

MIT License
3 stars 1 forks source link

moment regular expression dos dependency vulnerability #24

Closed EvaLok closed 6 years ago

EvaLok commented 6 years ago

apparently david-dm.org says we're affected by this: https://github.com/moment/moment/issues/4163

tried updating to latest version of dependency but no good; the issue is still open so i suppose we need to wait.

EvaLok commented 6 years ago

@MaikelH updating the dependency version didn't seem to fix it - any thoughts? i mean this isn't a big deal given what we use this for, but it's still annoying to have it show up as insecure, you know? https://david-dm.org/me-ventures/microservice-toolkit

EvaLok commented 6 years ago

it was another regexp issue, this one: https://github.com/moment/moment/issues/4163