Skip to content

Commit 50d1dc0

Browse files
authored
fix(security): upgrade moment to 2.29.4 to fix a vulnerability (#986)
1 parent a0891ed commit 50d1dc0

File tree

2 files changed

+13
-25
lines changed

2 files changed

+13
-25
lines changed

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,10 +28,10 @@
2828
"@babel/runtime": "7.15.4",
2929
"bluebird": "2.9.25",
3030
"core-js": "3.6.5",
31-
"forest-express": "9.5.1",
31+
"forest-express": "9.5.4",
3232
"http-errors": "1.6.1",
3333
"lodash": "4.17.21",
34-
"moment": "2.29.2",
34+
"moment": "2.29.4",
3535
"semver": "5.4.1"
3636
},
3737
"devDependencies": {

yarn.lock

Lines changed: 11 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -4581,10 +4581,10 @@ for-in@^1.0.2:
45814581
resolved "https://registry.yarnpkg.com/for-in/-/for-in-1.0.2.tgz#81068d295a8142ec0ac726c6e2200c30fb6d5e80"
45824582
integrity sha1-gQaNKVqBQuwKxybG4iAMMPttXoA=
45834583

4584-
4585-
version "9.5.1"
4586-
resolved "https://registry.yarnpkg.com/forest-express/-/forest-express-9.5.1.tgz#a5e997f2111e29709c6ec57050909317ef542feb"
4587-
integrity sha512-9AWf4wj4wL1S9kzqB0K6dbtvl1e6F9xmCh4wBnMC+pCxWmG8hdmXBAhPxDcvyKwukOvYuywm0S3ULe2AbzlrYA==
4584+
4585+
version "9.5.4"
4586+
resolved "https://registry.yarnpkg.com/forest-express/-/forest-express-9.5.4.tgz#26c8559a6dd633ecfd54e4c9a4c7a615a9073b62"
4587+
integrity sha512-ItJRtZTN6Q5hFmswGN/DvB7CDKZgXi7gT+OLPnsUg1fzckooVpd3Ob04tX02VmN9ExC44Qhpv4xVBNXLxwLDWg==
45884588
dependencies:
45894589
"@babel/runtime" "7.10.1"
45904590
"@forestadmin/context" "1.31.0"
@@ -4605,8 +4605,8 @@ [email protected]:
46054605
jsonapi-serializer "3.6.5"
46064606
jsonwebtoken "8.5.1"
46074607
lodash "4.17.21"
4608-
moment "2.29.2"
4609-
moment-timezone "0.5.26"
4608+
moment "2.29.4"
4609+
moment-timezone "0.5.34"
46104610
openid-client "4.2.0"
46114611
otplib "11.0.1"
46124612
require-all "3.0.0"
@@ -7309,29 +7309,17 @@ modify-values@^1.0.0:
73097309
resolved "https://registry.yarnpkg.com/modify-values/-/modify-values-1.0.1.tgz#b3939fa605546474e3e3e3c63d64bd43b4ee6022"
73107310
integrity sha512-xV2bxeN6F7oYjZWTe/YPAy6MN2M+sL4u/Rlm2AHCIVGfo2p1yGmBHQ6vHehl4bRTZBdHu3TSkWdYgkwpYzAGSw==
73117311

7312-
7313-
version "0.5.26"
7314-
resolved "https://registry.yarnpkg.com/moment-timezone/-/moment-timezone-0.5.26.tgz#c0267ca09ae84631aa3dc33f65bedbe6e8e0d772"
7315-
integrity sha512-sFP4cgEKTCymBBKgoxZjYzlSovC20Y6J7y3nanDc5RoBIXKlZhoYwBoZGe3flwU6A372AcRwScH8KiwV6zjy1g==
7316-
dependencies:
7317-
moment ">= 2.9.0"
7318-
7319-
moment-timezone@^0.5.21:
7312+
[email protected], moment-timezone@^0.5.21:
73207313
version "0.5.34"
73217314
resolved "https://registry.yarnpkg.com/moment-timezone/-/moment-timezone-0.5.34.tgz#a75938f7476b88f155d3504a9343f7519d9a405c"
73227315
integrity sha512-3zAEHh2hKUs3EXLESx/wsgw6IQdusOT8Bxm3D9UrHPQR7zlMmzwybC8zHEM1tQ4LJwP7fcxrWr8tuBg05fFCbg==
73237316
dependencies:
73247317
moment ">= 2.9.0"
73257318

7326-
7327-
version "2.29.2"
7328-
resolved "https://registry.yarnpkg.com/moment/-/moment-2.29.2.tgz#00910c60b20843bcba52d37d58c628b47b1f20e4"
7329-
integrity sha512-UgzG4rvxYpN15jgCmVJwac49h9ly9NurikMWGPdVxm8GZD6XjkKPxDTjQQ43gtGgnV3X0cAyWDdP2Wexoquifg==
7330-
7331-
"moment@>= 2.9.0", moment@^2.24.0:
7332-
version "2.29.3"
7333-
resolved "https://registry.yarnpkg.com/moment/-/moment-2.29.3.tgz#edd47411c322413999f7a5940d526de183c031f3"
7334-
integrity sha512-c6YRvhEo//6T2Jz/vVtYzqBzwvPT95JBQ+smCytzf7c50oMZRsR/a4w88aD34I+/QVSfnoAnSBFPJHItlOMJVw==
7319+
[email protected], "moment@>= 2.9.0", moment@^2.24.0:
7320+
version "2.29.4"
7321+
resolved "https://registry.yarnpkg.com/moment/-/moment-2.29.4.tgz#3dbe052889fe7c1b2ed966fcb3a77328964ef108"
7322+
integrity sha512-5LC9SOxjSc2HF6vO2CyuTDNivEdoz2IvyJJGj6X8DJ0eFyfszE0QiEd+iXmBvUP3WHxSjFH/vIsA0EN00cgr8w==
73357323

73367324
73377325
version "2.0.0"

0 commit comments

Comments
 (0)