Bump moment-timezone from 0.5.34 to 0.5.41
Closed
Number: #6
Type: Pull Request
State: Closed
Type: Pull Request
State: Closed
Author:
dependabot[bot]
Association: None
Comments: 0
![dependabot[bot]](https://github.com/dependabot.png)
Association: None
Comments: 0
Created:
February 28, 2023 at 12:56 PM UTC
(over 2 years ago)
(over 2 years ago)
Updated:
July 28, 2025 at 11:23 AM UTC
(about 2 months ago)
(about 2 months ago)
Closed:
July 28, 2025 at 11:23 AM UTC
(about 2 months ago)
(about 2 months ago)
Time to Close:
over 2 years
Labels:
dependencies
dependencies
Description:
> **Note**
> Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
Bumps moment-timezone from 0.5.34 to 0.5.41.
Release notes
Sourced from moment-timezone's releases.
Release 0.5.41
- Updated
moment
npm dependency to2.29.4
to remove automated warnings about insecure dependencies #1004. Moment Timezone still works with core Moment2.9.0
and higher.- Updated all dev dependencies including UglifyJS, which produces the minified builds.
- Added deprecation warning to the pre-built
moment-timezone-with-data-2012-2022
bundles #1035. Use the rollingmoment-timezone-with-data-10-year-range
files instead.Release 0.5.40
- Updated data to IANA TZDB
2022g
Release 0.5.39
- Updated data to IANA TZDB
2022f
Release 0.5.38
- Updated data to IANA TZDB
2022e
- Added
moment.tz.dataVersion
property to TypeScript definitions #930- Removed temporary
.tar.gz
files from npm releases #1000Release 0.5.37
- Re-publish npm package, because of extra folder present in 0.5.36, check moment/moment-timezone#999
Release 0.5.36
- Updated data to IANA TZDB
2022c
- Improvements/fixes to data pipeline
Release 0.5.35
- Fix command injection in data pipeline https://github.com/moment/moment-timezone/security/advisories/GHSA-56x4-j7p9-fcf9
- Fix cleartext transmission of sensitive information https://github.com/moment/moment-timezone/security/advisories/GHSA-v78c-4p63-2j6c
Thanks to the OpenSSF Alpha-Omega project for reporting these!
Changelog
Sourced from moment-timezone's changelog.
0.5.41
2023-02-25
- Updated
moment
npm dependency to2.29.4
to remove automated warnings about insecure dependencies. Moment Timezone still works with core Moment2.9.0
and higher.- Updated all dev dependencies including UglifyJS, which produces the minified builds.
- Added deprecation warning to the pre-built
moment-timezone-with-data-2012-2022
bundles #1035. Use the rollingmoment-timezone-with-data-10-year-range
files instead.
0.5.40
2022-12-11
- Updated data to IANA TZDB
2022g
0.5.39
2022-11-13
- Updated data to IANA TZDB
2022f
0.5.38
2022-10-15
- Updated data to IANA TZDB
2022e
- Added
moment.tz.dataVersion
property to TypeScript definitions #930- Removed temporary
.tar.gz
files from npm releases #1000
0.5.37
2022-08-25
- Re-publish npm package, because of extra folder present in 0.5.36, check moment/moment-timezone#999
0.5.36
2022-08-25
- IANA TZDB 2022c
- improvements/fixes to data pipeline
0.5.35
2022-08-23
- Fix command injection in data pipeline https://github.com/moment/moment-timezone/security/advisories/GHSA-56x4-j7p9-fcf9
- Fix cleartext transmission of sensitive information https://github.com/moment/moment-timezone/security/advisories/GHSA-v78c-4p63-2j6c
Thanks to the OpenSSF Alpha-Omega project for reporting these!
Commits
98d3add
Build moment-timezone 0.5.4178cf3ad
changelog: Add 0.5.41cd35dc6
Bump version to 0.5.4176f5a75
Re-number build tasks to match new running orderace9a77
Fix broken badges in README8080504
Bump moment dependency to 2.29.4 (#1004)61b14d6
Add deprecation warning to 2012-2022 pre-built files (#1036)fc29369
Bump remaining grunt-contrib packagesc83479e
tests: Fix guess tests for 2023e501621
Bump y18n from 4.0.0 to 4.0.3 (#1026)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by gilmoreorless, a new releaser for moment-timezone since your current version.
You can trigger a rebase of this PR by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.
Pull Request Statistics
Commits:
1
1
Files Changed:
1
1
Additions:
+11
+11
Deletions:
-4
-4
Package Dependencies
Security Advisories
Command Injection in moment-timezone
GHSA-56x4-j7p9-fcf9
LOW
### Impact
All versions of moment-timezone from 0.1.0 contain build tasks vulnerable to command injection.
* if Alice uses tzdata pipeline to package moment-timezone on her own (for example via `...
Cleartext Transmission of Sensitive Information in moment-timezone
GHSA-v78c-4p63-2j6c
MODERATE
### Impact
* if Alice uses `grunt data` (or `grunt release`) to prepare a custom-build, moment-timezone with the latest tzdata from IANA's website
* and Mallory intercepts the request to IANA's un...
Technical Details
ID: | 4230654 |
UUID: | 1257089168 |
Node ID: | PR_kwDOJDhQF85K7aiQ |
Host: | GitHub |
Repository: | OpenWebconcept/plugin-owc-gravityforms-zaaksysteem |
Merge State: | Dirty |