Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade moment to 2.19.3 #304

Closed
alltouch opened this issue Nov 29, 2017 · 8 comments
Closed

Upgrade moment to 2.19.3 #304

alltouch opened this issue Nov 29, 2017 · 8 comments

Comments

@alltouch
Copy link

NSP check fails with Regular Expression Denial of Service error. Required moment upgrade to 2.19.3

@YasharF
Copy link
Contributor

YasharF commented Dec 16, 2017

Snyk report on vulnerability in Snyk: https://snyk.io/test/npm/twilio

The underlying moment vulnerability was disclosed on 05 Sep, 2017, and published on 28 Nov, 2017

@cilindrox
Copy link

Any updates on this?

@jhdielman
Copy link
Contributor

@cilindrox @YasharF @alltouch There's an open PR to resolve this. Should be merged soon :)

@YasharF
Copy link
Contributor

YasharF commented Dec 18, 2017

PR: #305

@cilindrox
Copy link

Thanks @jhdielman @YasharF !

@esetnik
Copy link

esetnik commented Jan 14, 2018

I have the same issue. Any idea when this is expected to land in the next moment version?

@kuryaki
Copy link

kuryaki commented Jan 22, 2018

Gonna add twilio to .nsprc ignore in the meantime

@YasharF
Copy link
Contributor

YasharF commented Jan 23, 2018

Confirming that the issue is now resolved with the release of twilio@3.11.1 and the package is no longer being flagged by nsp.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants