apollographql / apollographql/apollo-tooling

Bump vulnerable version of moment

Open
#2,677 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
TypeScript
Stars
3k
Forks
460
PR merge metrics
No merged PRs in 30d

Description

**Intended outcome:**

Install the package `apollo` v2.34.0 should be "safe". A new package should be published containing the patch version for `moment`.

**Actual outcome:**

Apollo v2.34.0 contains as dependency `moment` v2.29.3 which reports the following vulnerability:

```
├─ moment: 2.29.3
│ ├─ Issue: Moment.js vulnerable to Inefficient Regular Expression Complexity
│ ├─ URL: https://github.com/advisories/GHSA-wc69-rhjr-hc9g
│ ├─ Severity: high
│ ├─ Vulnerable Versions: >=2.18.0 <2.29.4
│ ├─ Patched Versions: >=2.29.4
│ ├─ Via: moment, moment-timezone, @sl/fusion.common-utils, @sl/fusion.common-static, @sl/fusion.common-components, @sl/fusion.widgets-manager, @sl/fusion.common-wizpack, @sl/fusion.widgets-certificate
│ └─ Recommendation: Upgrade to version 2.29.4 or later
```

**How to reproduce the issue:**

**Versions**

apollo v2.34.0

Contributor guide

Open the contributing guide

Research direction

Check the package manifest and lockfile that define Apollo v2.34.0, then trace why moment is resolved to 2.29.3. Update the dependency to a patched version at or above 2.29.4, verify the installed dependency no longer reports the advisory, and publish the requested patch release.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.