Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency moment to v2.29.4 - autoclosed #64

Closed

Conversation

mend-for-github-com[bot]
Copy link
Contributor

@mend-for-github-com mend-for-github-com bot commented Aug 13, 2022

This PR contains the following updates:

Package Type Update Change
moment (source) dependencies patch 2.29.1 -> 2.29.4

By merging this PR, the issue #55 will be automatically resolved and closed:

Severity CVSS Score CVE Reachability
High High 7.5 CVE-2022-24785
High High 7.5 CVE-2022-31129

Release Notes

moment/moment (moment)

v2.29.4

Compare Source

  • Release Jul 6, 2022
    • #​6015 [bugfix] Fix ReDoS in preprocessRFC2822 regex

v2.29.3

Compare Source

  • Release Apr 17, 2022

v2.29.2

Compare Source

  • Release Apr 3 2022

Address GHSA-8hfj-j24r-96c4


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Aug 13, 2022
Copy link
Contributor

@marcioaffonso marcioaffonso left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mend-for-github-com mend-for-github-com bot changed the title Update dependency moment to v2.29.4 Update dependency moment to v2.29.4 - autoclosed Feb 15, 2023
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/moment-2.x-lockfile branch February 15, 2023 00:27
@mend-for-github-com mend-for-github-com bot changed the title Update dependency moment to v2.29.4 - autoclosed Update dependency moment to v2.29.4 Feb 15, 2023
@mend-for-github-com mend-for-github-com bot reopened this Feb 15, 2023
@mend-for-github-com mend-for-github-com bot restored the whitesource-remediate/moment-2.x-lockfile branch February 15, 2023 01:35
@mend-for-github-com mend-for-github-com bot changed the title Update dependency moment to v2.29.4 Update dependency moment to v2.29.4 - autoclosed Apr 29, 2024
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/moment-2.x-lockfile branch April 29, 2024 13:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant