Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Moment.js version added on assets has vulnerabilities #4106

Open
Jose96GIT opened this issue Mar 24, 2023 · 3 comments
Open

Moment.js version added on assets has vulnerabilities #4106

Jose96GIT opened this issue Mar 24, 2023 · 3 comments
Labels

Comments

@Jose96GIT
Copy link

Details

Doing a security scan on a website made using the latest version from Apostrohe v2, I've noticed that the moment.js version which is being imported on apostrophe-assets module is outdated and has some vulnerabilities as it's indicated on this link.

https://security.snyk.io/package/npm/moment

Can this be updated to solve the security issue?

Thanks in advance!

@BoDonkey
Copy link
Contributor

I just looked through a repo using the latest v2 and it is using Moment.js v2.29.4. That is the latest version and doesn't have the listed vulnerabilities.
image
Are you sure your Apostrophe is up to date?
Cheers,
Bob

@Jose96GIT
Copy link
Author

I don't mean the one installed via npm, but the one that's included on apostrophe-assets.

https://github.com/apostrophecms/apostrophe/blob/2.227.0/lib/modules/apostrophe-assets/public/js/vendor/moment.js

@BoDonkey
Copy link
Contributor

Ahh - missed that. Ticket submitted for the update. Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants