From a41b64e2d258e76bc02b12b7ff911de708c3f38d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 5 Apr 2022 19:15:02 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MOMENT-2440688 --- package.json | 2 +- yarn.lock | 7 ++++--- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/package.json b/package.json index 83f76f3..660c74f 100644 --- a/package.json +++ b/package.json @@ -30,7 +30,7 @@ "babel-runtime": "6.23.0", "dotenv": "^4.0.0", "lodash": "^4.17.19", - "moment": "^2.19.3", + "moment": "^2.29.2", "pg-promise": "^6.3.6" } } diff --git a/yarn.lock b/yarn.lock index 4cf118a..4ae4c3d 100644 --- a/yarn.lock +++ b/yarn.lock @@ -2448,9 +2448,10 @@ minimist@^1.2.5: dependencies: minimist "^1.2.5" -moment@^2.19.3: - version "2.19.3" - resolved "https://registry.yarnpkg.com/moment/-/moment-2.19.3.tgz#bdb99d270d6d7fda78cc0fbace855e27fe7da69f" +moment@^2.29.2: + version "2.29.2" + resolved "https://registry.yarnpkg.com/moment/-/moment-2.29.2.tgz#00910c60b20843bcba52d37d58c628b47b1f20e4" + integrity sha512-UgzG4rvxYpN15jgCmVJwac49h9ly9NurikMWGPdVxm8GZD6XjkKPxDTjQQ43gtGgnV3X0cAyWDdP2Wexoquifg== ms@0.7.2: version "0.7.2"